Zeeka saysGroth16 is the classic SNARK: tiny proofs (three group elements), constant-time verification, and a per-circuit trusted setup — the price of that succinctness.
Groth16 set the bar for succinct proofs: every proof is just three group elements and verification is a fixed handful of pairings, no matter whether the circuit has ten gates or a hundred million. That is what "succinct" means — proof size and verify cost stay constant as the computation grows.
The trade-off is a per-circuit trusted setup: change the circuit and you need a fresh ceremony. Proving is also heavy even though verifying is cheap. The demo tabulates proof size and verification cost across circuit sizes to make the constant-size property concrete; the full scheme's pairing checks are described in the lesson.
Power-ups you unlock
Proof is always 3 group elements, regardless of circuit size
Verification is constant time (a fixed number of pairings)
Requires a fresh trusted setup for each distinct circuit
Among the smallest, fastest-to-verify proofs in production
Widely used in older zk-rollups and privacy systems
The Collision attacks — common mistakes
Reusing a setup from one circuit for a different circuit
Assuming a small proof means it is cheap to generate (proving is heavy)
Ignoring the trusted-setup risk in the threat model
Expecting circuit upgrades for free — they need a new setup
Boss battleTabulate Groth16 proof size and verification cost as the circuit grows from 10 to 100M gates and confirm both stay constant.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// Groth16: proof is ALWAYS 3 group elements; verify is constant-time. (full scheme needs pairings.)
const groth16=()=>({ proofBytes:3*32, verifyPairings:3 });
const rows=[10, 1000, 1000000, 100000000].map(g=>{
const p=groth16();
return 'circuit ' + g.toLocaleString().padStart(13) + ' gates → proof ' + p.proofBytes + ' bytes, ' + p.verifyPairings + ' pairings';
});
document.getElementById('o').textContent = [
'Groth16 — succinct & non-interactive:',
...rows,
'proof size & verify cost are CONSTANT as the circuit grows → "succinct"',
'trade-off: a new trusted setup per circuit'
].join('\n');
</script></body></html>