Zeeka saysHalo2 needs no trusted setup and supports recursion through accumulation: instead of re-verifying every proof, you fold each one into a constant-size accumulator.
Halo2 dropped the trusted setup by using inner-product (IPA) commitments, and introduced accumulation (folding) for cheap recursion. Rather than re-verifying a growing pile of proofs, each new proof is folded into a single, constant-size accumulator; only that accumulator is verified at the end.
This makes deep recursion practical — proofs of proofs of proofs — which is exactly what proof-carrying data and incrementally-verifiable computation need. The demo folds a stream of instances into one accumulator and shows its size never grows, no matter how many you add. Halo2 and the folding-scheme family (Nova) are central to modern rollup proving.
Power-ups you unlock
No trusted setup — uses inner-product (IPA) commitments
Accumulation folds proofs into one constant-size object
Verify the accumulator once at the end, not each proof
Enables deep recursion (proofs of proofs of proofs)
Popular for zk-rollups and proof-carrying data
The Collision attacks — common mistakes
Confusing accumulation with simply batching proofs
Assuming no setup means no structured commitments at all
Letting the accumulator grow with each fold (it must stay constant)
Ignoring the final single verification step
Boss battleFold a stream of proof instances into one accumulator and show its size stays constant no matter how many you add.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// Halo2: no trusted setup, recursion via ACCUMULATION — fold into a constant-size object.
const F=97, mod=(n)=>((n%F)+F)%F;
let acc=0; const sizes=[];
const instances=[12, 34, 7, 88, 5, 60];
instances.forEach((x,i)=>{ const r=(i*13+5)%F; acc=mod(acc*r + x); sizes.push(1); });
document.getElementById('o').textContent = [
'folded ' + instances.length + ' proofs into one accumulator',
'accumulator value = ' + acc + ' (a single field element)',
'accumulator size after each fold: [' + sizes.join(', ') + '] → CONSTANT',
'verify the accumulator ONCE, not ' + instances.length + ' proofs separately',
'no trusted setup: Halo2 uses inner-product (IPA) commitments'
].join('\n');
</script></body></html>