Register and share your invite link to earn from video plays and referrals.

Thomas Coratger
@tcoratger
Research at Ethereum Foundation
2.3K Following    3.9K Followers
Fantastic progress on binary field techniques in Plonky3 lately. We just opened a bunch of AArch64 performance issues if you want to dig in. The optimizations get quite subtle, so we highly recommend throwing your best LLM at them :)
Show more
We just merged Lean4 implementation of SSZ! Still a huge amount to iterate on, especially making the Astra-generated proofs more human-readable. But Lean/Python cross-testing in CI has already caught a few subtle bugs in the Python spec :)
Show more
Performant formally verified software by @leonardoalt One of the most interesting consequences of formal verification: you can optimize much more aggressively when every rewrite has to preserve a proof.
Show more
On the Navier–Stokes Millennium Prize Problem by @OpenAI. This one hits differently for me after spending 3 years of my PhD implementing numerical methods for Navier–Stokes. Seeing a Lean-formalized resolution of the problem is quite something.
Show more
Fiat-Shamir is easy to get subtly wrong. Inspired by SpongeFish, Plonky3 now has a strongly typed, IETF draft-compliant Fiat-Shamir API; making transcript structure explicit and harder to misuse.
Show more
One optimistic and still very-non-consensus belief I have about the far future of cryptography: I think that there is a 33% chance that, for average real-world computation, there exist ways to implement all three of what I call the Egyptian God Protocols (SNARK, FHE, iO) with 1+ε factor overhead (meaning, for large enough instances, the added overhead of cryptographizing a computation becomes arbitrarily small compared to the base cost of doing the computation itself) And a 60% chance that all three can be done with single-digit overhead (ie. <10x, measured in total cost of energy plus amortized compute) I think there's a good chance we'll get one of these (probably SNARKs with single-digit overhead) by the end of this decade. After all, we're already there for specialized hash functions and for some LLM inference.
Show more
0
398
2.1K
197
Forward to community
Thanks to @RobinSalen, Plonky3 is progressively incorporating binary field code (field arithmetic, sumcheck, etc)! You should check it if interested! We need you and the best of your agents :)
Show more
Interesting to see Bitcoin and Ethereum PQ discussions converging on very similar questions. Block-wide PQ signature aggregation brings us to the same design space: circuits vs VMs, recursion, proof size, aggregators, soundness...
Show more
Formalizing Fermat's Last Theorem by @AnthropicAI What a crazy world we are living in right now!
As models like Opus/Astra make code increasingly cheap to write, my bet is that software development becomes spec-centric. Lean has been around for years, but feels increasingly relevant to that future. I'm learning it deeply through Ethereum specs. Will document the journey.
Show more
We've been working on a modern Python implementation of the SSZ spec: idiomatic, type-safe, and fast. More exciting work coming here soon.
Binary fields are beautiful. After months of exploration, I'm still surprised to find significant optimizations almost every day. Agentic workflows are accelerating this tremendously. Lots of recent progress in Binius64:
Show more
New @Edge_Pod Lean Ethereum series is out! Google's Willow quantum chip spooked a lot of us last year. So will Ethereum be ready for quantum computers? We asked an @ethereumfndn quantum researcher. Short answer: Yes, but more on why and when is in the pod with @tcoratger.
Show more
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10#, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
Show more
0
141
2K
347
Forward to community
How to keep thinking! Very interesting thoughts about human in an LLM centric future!
SHA256 arithmetization just merged in Plonky3 👇
Heads-up! ⚠️ We just merged STIR into Plonky3's main branch! This is a first step towards fully supporting yet another PCS which will hopefully be included in our next big release! If you're interested in helping, please give it a look!
Show more
With Flock and the recent progress around binary fields, development of Binius64 is moving quickly. If you haven't looked at it yet, it's definitely worth checking out.
1/ It's not everyday that my primary cryptographic interests (PQC and ZK) collide. But today is one of those days! Excited to announce this collaboration between @projecteleven and @jimpo_potamus (lead maintainer of Binius) for post Q-Day wallet recovery using a ZK proof-of-seed-phrase.
Show more
Building an Unverified Compiler with Agents