freecoding.school100% FREE · NO SIGNUP
Proof PeaksISSUE #21 of 38

halo2 · recursive accumulation

ZeekaVSThe Collision
Zeeka saysHalo2 needs no trusted setup and supports recursion through accumulation: instead of re-verifying every proof, you fold each one into a constant-size accumulator.

Halo2 dropped the trusted setup by using inner-product (IPA) commitments, and introduced accumulation (folding) for cheap recursion. Rather than re-verifying a growing pile of proofs, each new proof is folded into a single, constant-size accumulator; only that accumulator is verified at the end.

This makes deep recursion practical — proofs of proofs of proofs — which is exactly what proof-carrying data and incrementally-verifiable computation need. The demo folds a stream of instances into one accumulator and shows its size never grows, no matter how many you add. Halo2 and the folding-scheme family (Nova) are central to modern rollup proving.

Power-ups you unlock

The Collision attacks — common mistakes

Boss battleFold a stream of proof instances into one accumulator and show its size stays constant no matter how many you add.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// Halo2: no trusted setup, recursion via ACCUMULATION — fold into a constant-size object.
const F=97, mod=(n)=>((n%F)+F)%F;
let acc=0; const sizes=[];
const instances=[12, 34, 7, 88, 5, 60];
instances.forEach((x,i)=>{ const r=(i*13+5)%F; acc=mod(acc*r + x); sizes.push(1); });
document.getElementById('o').textContent = [
  'folded ' + instances.length + ' proofs into one accumulator',
  'accumulator value = ' + acc + '   (a single field element)',
  'accumulator size after each fold: [' + sizes.join(', ') + ']  → CONSTANT',
  'verify the accumulator ONCE, not ' + instances.length + ' proofs separately',
  'no trusted setup: Halo2 uses inner-product (IPA) commitments'
].join('\n');
</script></body></html>
▶ Open the interactive comic issue
‹ Lookup Arguments · Plookup · LogupStarks · Transparent · Post-Quantum ›