Skip to content

LibraryScaling2024Design paperCorpus record

Citrea: a zk-rollup that settles to Bitcoin

Citrea. Citrea.

Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
6

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A Bitcoin rollup that cannot say how a proof is checked inside Bitcoin's script limits is a sidechain with extra words.

  2. Claim 02 · Paper model

    The proposal

    Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.

  3. Claim 03 · Paper model

    The mechanism

    The virtual machine runs off Bitcoin. A proof of its transition is what Bitcoin is asked to verify, under the script the docs specify.

  4. Claim 04 · Paper model

    The bound

    This note does not say the system is live on mainnet.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A Bitcoin rollup that cannot say how a proof is checked inside Bitcoin's script limits is a sidechain with extra words.

    Model

    What has to hold

    You are reading Citrea's technical docs. BitVM is a related method, not automatically this implementation.

    Falsifier

    What would retire it

    What does a Bitcoin transaction actually check?

  2. 02 The proposal

    Observation

    What the study says

    Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.

    Model

    What has to hold

    You are reading Citrea's technical docs. BitVM is a related method, not automatically this implementation.

    Falsifier

    What would retire it

    What does a Bitcoin transaction actually check?

  3. 03 The mechanism

    Observation

    What the study says

    The virtual machine runs off Bitcoin. A proof of its transition is what Bitcoin is asked to verify, under the script the docs specify.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    What does a Bitcoin transaction actually check?

  4. 04 The bound

    Observation

    What the study says

    This note does not say the system is live on mainnet.

    Model

    What has to hold

    You are reading Citrea's technical docs. BitVM is a related method, not automatically this implementation.

    Falsifier

    What would retire it

    What does a Bitcoin transaction actually check?

03 Sequence

One action, as an operating tape

  1. 01The virtual machine runs off Bitcoin. A proof of its transition is what Bitcoin is asked to verify, under the script the docs specify.
  2. 02Data availability is a separate choice. If the data is not on Bitcoin, say where it is.
  3. 03BitVM-style verification, if that is what the docs use, is a challenge game or a proof-checking method. Cite which one the page describes.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Verification in script is limited by Bitcoin's opcodes. The docs' method of fitting a proof into those opcodes is the design.

  2. What actually moves

    The cut

    Data availability is a separate choice. If the data is not on Bitcoin, say where it is.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Verification in script is limited by Bitcoin's opcodes. The docs' method of fitting a proof into those opcodes is the design.

  3. What a later deployment may change

    The cut

    BitVM-style verification, if that is what the docs use, is a challenge game or a proof-checking method. Cite which one the page describes.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    Verification in script is limited by Bitcoin's opcodes. The docs' method of fitting a proof into those opcodes is the design.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading Citrea's technical docs. BitVM is a related method, not automatically this implementation.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

Verification in script is limited by Bitcoin's opcodes. The docs' method of fitting a proof into those opcodes is the design.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A Bitcoin rollup that cannot say how a proof is checked inside Bitcoin's script limits is a sidechain with extra words.

What the design proposes

  • The virtual machine runs off Bitcoin. A proof of its transition is what Bitcoin is asked to verify, under the script the docs specify.
  • Data availability is a separate choice. If the data is not on Bitcoin, say where it is.
  • BitVM-style verification, if that is what the docs use, is a challenge game or a proof-checking method. Cite which one the page describes.

How the mechanism is specified

  • The virtual machine runs off Bitcoin. A proof of its transition is what Bitcoin is asked to verify, under the script the docs specify.
  • Data availability is a separate choice. If the data is not on Bitcoin, say where it is.
  • BitVM-style verification, if that is what the docs use, is a challenge game or a proof-checking method. Cite which one the page describes.

What this page does not treat as proven

  • This note does not say the system is live on mainnet.
  • It quotes no throughput.
  • Verification in script is limited by Bitcoin's opcodes. The docs' method of fitting a proof into those opcodes is the design.

Why the desk still reads it

Citrea publishes a rollup whose proof is verified in Bitcoin script, so Bitcoin is the settlement layer rather than a checkpoint someone tweets.

09 Lexicon

Terms, opened into the record

Bitcoin settlement
A proof or challenge whose outcome is enforced by Bitcoin transactions.
Guest execution
The rollup's own machine. Bitcoin does not run it directly.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.