Zeeka saysA SNARK proves a computation by first rewriting it as an arithmetic circuit, then as R1CS: a list of constraints of the form (A·w)(B·w) = (C·w).
To prove a computation you first turn it into an arithmetic circuit of add and multiply gates over a field, then flatten that into R1CS (Rank-1 Constraint System). Each gate becomes one constraint (A·w) × (B·w) = (C·w), where w is the witness vector: the constant 1, the public inputs, and every intermediate wire value.
A valid witness satisfies all constraints at once. R1CS is the universal bridge from "a program" to "something a SNARK can prove" — Groth16 and PLONK both start here. The demo encodes Vitalik's classic example, proving you know x with x³ + x + 5 = 35 (answer x = 3), and checks that the witness satisfies every constraint.
Power-ups you unlock
Computations become circuits of add and multiply gates over a field
R1CS encodes each gate as (A·w) × (B·w) = (C·w)
w is the witness: 1, public inputs, and all intermediate wires
A valid witness satisfies every constraint simultaneously
This is the bridge from a program to something provable
The Collision attacks — common mistakes
Forgetting the constant 1 entry in the witness vector
Adding more constraints than the computation needs (bloats the proof)
Leaving a wire under-constrained — lets a prover cheat
Doing the arithmetic outside the field
Boss battleEncode x³ + x + 5 = 35 as R1CS and verify the witness for x = 3 satisfies all constraints.