Skip to content

LibraryPrivacy2019Design paperCorpus record

Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS

Marlin. Alessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra, Noah Vesely and Nicholas Ward.

A preprocessing zkSNARK whose structured reference string is universal and can be updated, rather than baked for one circuit in a ceremony that must be trusted forever. The paper improves on Sonic's costs. It is still a SNARK, with a setup.

Marlin is a preprocessing zkSNARK with a structured reference string that is universal and updatable. One setup can serve many circuits, and a later participant can update the string so that soundness holds if any contributor was honest. It is not a transparent proof system. Groth16's per-circuit ceremony is what it is trying to get away from.

The five-minute read

Universal means many circuits

The SRS is not specialised to one arithmetic circuit. Specialising is a later, cheaper step. The expensive ceremony is not repeated for every application.

Updatable means one honest contributor

The string can be improved by new randomness. The soundness story is that a single honest update denies the toxic waste to everyone else. A ceremony with no honest participant is still a broken setup.

Holography is the technique

The verifier is fast because the statement is presented in an encoded form. That encoding is part of the protocol, not a compression trick you can skip.

Still a SNARK

Proofs are constant size. The prover does the heavy work. A universal setup does not move the work onto the verifier.

One action, walked through

  1. Participants generate and optionally update a universal SRS.
  2. A circuit is preprocessed against that SRS.
  3. The prover produces a constant-size argument for a satisfying witness.
  4. The verifier checks the argument, using the encoded statement, in time that does not replay the computation.
  5. Zero knowledge hides the witness if the protocol is used in that mode.

The argument, unpacked

Compare setups, not logos

Against Groth16, the question is whether you can bear a per-circuit ceremony. Against STARKs, the question is whether you accept a structured string at all. Marlin sits between them. Putting it in either other box is a mistake.

The model is part of the result

The tightest efficiency claims are in the algebraic group model, which Sonic also used. A reader who needs a different assumption has to read the paper's alternative, not the abstract's timing table.

What has to be true

  • At least one SRS contributor was honest if you are relying on updatability.
  • The implementation uses the preprocessing for the circuit it claims to prove.
  • Knowledge assumptions or the algebraic group model, as in the theorem being cited.
  • Public inputs are the statement. A proof does not make private inputs true to the world.

What happened after the paper

Marlin is the 2019 citation for a universal updatable SRS, beside Sonic and before PLONK became the system most applications actually shipped. PLONK is a different paper with a different proving strategy.

What to check before you use the idea

  • Is the SRS universal, and was it updated?
  • Is the proof system Marlin, PLONK, or Groth16?
  • What assumption does the cited theorem use?
  • What is the public statement, as opposed to the witness?

Terms

Universal SRS
A structured reference string that is not tied to a single circuit.
Updatable setup
A ceremony any later party can contribute to, sound if one contributor was honest.

The problem the paper names

Groth16's setup is specific to one circuit. A new circuit wants a new ceremony. Marlin asks for one setup that many circuits can share, and that later parties can update so the toxic waste is harder to keep.

What the design proposes

  • A universal SRS is created once and can be updated.
  • The statement is given to the verifier in an encoded form, which is the holography idea the paper uses.
  • The argument is constant size. Proving is the expensive side, as usual.

How the mechanism is specified

  • Updatable means a new participant can contribute randomness and the result is sound if any one contributor was honest. That is the ceremony assumption, stated rather than wished away.
  • The efficient version is proved in the algebraic group model. The paper also discusses concrete knowledge assumptions.
  • Universal does not mean setup-free. A transparent setup is a different design, closer to STARKs.

What this page does not treat as proven

  • A universal SRS is still a structured string. Losing the assumption means losing the proof system.
  • The paper's benchmarks are the authors' implementation, not a network.
  • A SNARK of a computation does not make the inputs true.

Why a venture studio still reads it

Ask three questions of any SNARK citation: circuit-specific or universal, updatable or trusted once, transparent or structured. Marlin is universal, updatable, and structured.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.