Skip to content

LibraryPrivacy2020Design paperCorpus record

Halo 2: a proving system without a trusted setup, as published by Zcash

Halo 2. Electric Coin Company.

Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
4

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    No trusted setup is a claim about the proof system. It is not a claim that a particular circuit, or a particular shielded pool, has no bugs.

  2. Claim 02 · Paper model

    The proposal

    Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.

  3. Claim 03 · Paper model

    The mechanism

    The book specifies the arithmetisation and the argument. A circuit for a transaction is a separate artefact.

  4. Claim 04 · Paper model

    The bound

    This note does not say every Zcash transaction uses Halo 2.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    No trusted setup is a claim about the proof system. It is not a claim that a particular circuit, or a particular shielded pool, has no bugs.

    Model

    What has to hold

    You are reading the Halo 2 book. The original Halo paper and a Zcash ZIP are different documents.

    Falsifier

    What would retire it

    Does the document you need specify the proof system or the transaction circuit?

  2. 02 The proposal

    Observation

    What the study says

    Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.

    Model

    What has to hold

    You are reading the Halo 2 book. The original Halo paper and a Zcash ZIP are different documents.

    Falsifier

    What would retire it

    Does the document you need specify the proof system or the transaction circuit?

  3. 03 The mechanism

    Observation

    What the study says

    The book specifies the arithmetisation and the argument. A circuit for a transaction is a separate artefact.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    Does the document you need specify the proof system or the transaction circuit?

  4. 04 The bound

    Observation

    What the study says

    This note does not say every Zcash transaction uses Halo 2.

    Model

    What has to hold

    You are reading the Halo 2 book. The original Halo paper and a Zcash ZIP are different documents.

    Falsifier

    What would retire it

    Does the document you need specify the proof system or the transaction circuit?

03 Sequence

One action, as an operating tape

  1. 01The book specifies the arithmetisation and the argument. A circuit for a transaction is a separate artefact.
  2. 02Inner product arguments in this line do not require the toxic waste of a Groth16 setup. That is the difference to name.
  3. 03Zcash's orchard pool, if it uses this system, is a deployment. The book is not the pool's consensus rule.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This note does not say every Zcash transaction uses Halo 2.

  2. What actually moves

    The cut

    Inner product arguments in this line do not require the toxic waste of a Groth16 setup. That is the difference to name.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A circuit still has to be audited. The absence of a setup does not audit it.

  3. What a later deployment may change

    The cut

    Zcash's orchard pool, if it uses this system, is a deployment. The book is not the pool's consensus rule.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This note does not say every Zcash transaction uses Halo 2.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading the Halo 2 book. The original Halo paper and a Zcash ZIP are different documents.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

A circuit still has to be audited. The absence of a setup does not audit it.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

No trusted setup is a claim about the proof system. It is not a claim that a particular circuit, or a particular shielded pool, has no bugs.

What the design proposes

  • The book specifies the arithmetisation and the argument. A circuit for a transaction is a separate artefact.
  • Inner product arguments in this line do not require the toxic waste of a Groth16 setup. That is the difference to name.
  • Zcash's orchard pool, if it uses this system, is a deployment. The book is not the pool's consensus rule.

How the mechanism is specified

  • The book specifies the arithmetisation and the argument. A circuit for a transaction is a separate artefact.
  • Inner product arguments in this line do not require the toxic waste of a Groth16 setup. That is the difference to name.
  • Zcash's orchard pool, if it uses this system, is a deployment. The book is not the pool's consensus rule.

What this page does not treat as proven

  • This note does not say every Zcash transaction uses Halo 2.
  • It does not compare speeds.
  • A circuit still has to be audited. The absence of a setup does not audit it.

Why the desk still reads it

Halo 2 publishes a proving system that removes the trusted setup of the earlier SNARK deployments Zcash had used, by using a different polynomial argument.

09 Lexicon

Terms, opened into the record

Trusted setup
A ceremony that produces parameters which must be destroyed in part. Halo 2's claim is to avoid that for its argument.
Circuit
The application constraints. They remain a source of bugs.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.