LibraryPrivacy2019Design paperCorpus record
Halo: Recursive Proof Composition without a Trusted Setup
Halo. Sean Bowe, Jack Grigg and Daira Hopwood.
Recursion for inner-product arguments, without a structured setup. A proof can attest that another proof was checked. That is how a chain can fold a long history into one object. Halo 2 is a later system.
Halo composes inner-product proofs recursively without a Groth-style trusted setup, so one proof can say that a previous proof was checked. Folding a long history into one verifier is the point.
The five-minute read
Recursion was stuck on pairings
To verify a SNARK inside a SNARK you needed a curve cycle and, often, a setup. Halo targets the inner-product argument used by Bulletproofs, which has no such setup, and shows how to nest it.
Amortisation is the trick
The expensive part of the inner-product verifier is not re-run from scratch at every level. It is deferred and combined. That deferral is the paper. It is also where an implementation bug would hide.
A curve cycle still shows up
The concrete construction uses two curves whose fields fit each other's groups. That is not a trusted setup. It is a constraint on which curves can be used, and it is part of the engineering risk.
Halo 2 is a sequel
Halo 2 changes the polynomial commitment and the circuit language. Zcash's later work sits closer to that sequel. Citing Halo for a Halo 2 deployment is a version error.
One action, walked through
- A prover produces an inner-product proof of some step.
- A second proof attests that the verifier of the first would have accepted, without the outer verifier redoing the whole check.
- The deferred checks accumulate.
- At the end, one verifier checks the accumulated argument.
- Anyone who wants to verify a long chain of steps checks that one object, then trusts the recursion circuit.
The argument, unpacked
Compression is not truth
Recursion lets a chain keep a short witness of a long computation. If the circuit that verifies the inner proof is wrong, every folded proof inherits the mistake efficiently. Audit cost moves to the recursion circuit and stays there.
No setup is a real distinction
Compared with Groth16 recursion stories, Halo removes a ceremony. It does not remove cryptographic assumptions, curve choices, or the need to implement Fiat-Shamir correctly.
What has to be true
- The inner-product argument's assumptions hold in the groups being used.
- The curve cycle is the one the proofs expect. A mismatched curve is not a proof.
- The recursion circuit really verifies the inner verifier, including its edge cases.
- Transcripts are bound with Fiat-Shamir so a prover cannot replay challenges.
What happened after the paper
The Halo line fed Zcash's move away from per-circuit setups and influenced other recursive proof systems. Production clients diverged into Halo 2 and then into whatever those clients shipped. The 2019 paper is the citation for setup-free recursion of inner-product proofs, not for a shielded pool's current circuit.
What to check before you use the idea
- Is the deployment Halo or Halo 2?
- Which curve cycle is used?
- What exactly does the recursion circuit verify?
- Is there still a trusted setup hiding in a different part of the stack?
Terms
- Recursive composition
- A proof that attests to the checking of another proof, so verification can be folded.
- Curve cycle
- Two curves arranged so each can efficiently reason about the other's field.
The problem the paper names
SNARK recursion had wanted cycles of pairing-friendly curves and a setup. Halo tries to verify an inner-product argument inside another proof without those pairings.
What the design proposes
- Nested amortization of the inner-product argument.
- No trusted setup of the Groth16 kind.
- A cycle of curves still appears in the concrete instantiation. The cycle is an engineering object, not a slogan.
How the mechanism is specified
- The verifier does not re-run every previous proof. It checks one proof that claims those checks happened.
- A bug in the recursion circuit is a bug in every folded proof. The paper does not remove auditor duty.
- Zcash's later deployment path used this research. Orchard is not the 2019 PDF.
What this page does not treat as proven
- Recursion does not make the statement true. It compresses verification of whatever was proved.
- No trusted setup is not the same as no cryptographic assumption.
- Halo 2 changes the polynomial commitment. Do not mix the citations.
Why a venture studio still reads it
Ask what is inside the recursion: a step of a virtual machine, a transaction, or a claim about a reserve. Then ask who wrote the circuit that checks the inner proof.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
