LibraryPrivacy2019Design paperCorpus record
Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS
Marlin. Alessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra, Noah Vesely and Nicholas Ward.
A preprocessing zkSNARK whose structured reference string is universal and can be updated, rather than baked for one circuit in a ceremony that must be trusted forever. The paper improves on Sonic's costs. It is still a SNARK, with a setup.
Marlin is a preprocessing zkSNARK with a structured reference string that is universal and updatable. One setup can serve many circuits, and a later participant can update the string so that soundness holds if any contributor was honest. It is not a transparent proof system. Groth16's per-circuit ceremony is what it is trying to get away from.
The five-minute read
Universal means many circuits
The SRS is not specialised to one arithmetic circuit. Specialising is a later, cheaper step. The expensive ceremony is not repeated for every application.
Updatable means one honest contributor
The string can be improved by new randomness. The soundness story is that a single honest update denies the toxic waste to everyone else. A ceremony with no honest participant is still a broken setup.
Holography is the technique
The verifier is fast because the statement is presented in an encoded form. That encoding is part of the protocol, not a compression trick you can skip.
Still a SNARK
Proofs are constant size. The prover does the heavy work. A universal setup does not move the work onto the verifier.
One action, walked through
- Participants generate and optionally update a universal SRS.
- A circuit is preprocessed against that SRS.
- The prover produces a constant-size argument for a satisfying witness.
- The verifier checks the argument, using the encoded statement, in time that does not replay the computation.
- Zero knowledge hides the witness if the protocol is used in that mode.
The argument, unpacked
Compare setups, not logos
Against Groth16, the question is whether you can bear a per-circuit ceremony. Against STARKs, the question is whether you accept a structured string at all. Marlin sits between them. Putting it in either other box is a mistake.
The model is part of the result
The tightest efficiency claims are in the algebraic group model, which Sonic also used. A reader who needs a different assumption has to read the paper's alternative, not the abstract's timing table.
What has to be true
- At least one SRS contributor was honest if you are relying on updatability.
- The implementation uses the preprocessing for the circuit it claims to prove.
- Knowledge assumptions or the algebraic group model, as in the theorem being cited.
- Public inputs are the statement. A proof does not make private inputs true to the world.
What happened after the paper
Marlin is the 2019 citation for a universal updatable SRS, beside Sonic and before PLONK became the system most applications actually shipped. PLONK is a different paper with a different proving strategy.
What to check before you use the idea
- Is the SRS universal, and was it updated?
- Is the proof system Marlin, PLONK, or Groth16?
- What assumption does the cited theorem use?
- What is the public statement, as opposed to the witness?
Terms
- Universal SRS
- A structured reference string that is not tied to a single circuit.
- Updatable setup
- A ceremony any later party can contribute to, sound if one contributor was honest.
The problem the paper names
Groth16's setup is specific to one circuit. A new circuit wants a new ceremony. Marlin asks for one setup that many circuits can share, and that later parties can update so the toxic waste is harder to keep.
What the design proposes
- A universal SRS is created once and can be updated.
- The statement is given to the verifier in an encoded form, which is the holography idea the paper uses.
- The argument is constant size. Proving is the expensive side, as usual.
How the mechanism is specified
- Updatable means a new participant can contribute randomness and the result is sound if any one contributor was honest. That is the ceremony assumption, stated rather than wished away.
- The efficient version is proved in the algebraic group model. The paper also discusses concrete knowledge assumptions.
- Universal does not mean setup-free. A transparent setup is a different design, closer to STARKs.
What this page does not treat as proven
- A universal SRS is still a structured string. Losing the assumption means losing the proof system.
- The paper's benchmarks are the authors' implementation, not a network.
- A SNARK of a computation does not make the inputs true.
Why a venture studio still reads it
Ask three questions of any SNARK citation: circuit-specific or universal, updatable or trusted once, transparent or structured. Marlin is universal, updatable, and structured.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
