LibraryConfidential compute2022Design paperCorpus record
Plonky2: a recursive SNARK stack
Plonky2. Polygon Zero.
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
- Evidence
- Primary paper
- Re-measured
- No
- Assumptions
- 3
- Records linked
- 6
01 Claim ledger
What the paper is allowed to say
Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.
Claim 01 · Paper model
The defect
Recursion is not a virtual machine. It is a way to compose proofs. The machine has to be specified elsewhere.
Claim 02 · Paper model
The proposal
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
Claim 03 · Paper model
The mechanism
The field, the hash, and the gates are the proof system. A circuit written against them is an application.
Claim 04 · Paper model
The bound
This note does not quote a proving speed.
02 Three cuts
Observation, model, falsifier
A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.
01 The defect
Observation
What the study says
Recursion is not a virtual machine. It is a way to compose proofs. The machine has to be specified elsewhere.
Model
What has to hold
You are reading the Plonky2 repository. A zkEVM built on it is a second project.
Falsifier
What would retire it
Is the Ethereum-like machine a separate repository from this proof system?
02 The proposal
Observation
What the study says
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
Model
What has to hold
You are reading the Plonky2 repository. A zkEVM built on it is a second project.
Falsifier
What would retire it
What is being recursed: which circuit verifies which other circuit?
03 The mechanism
Observation
What the study says
The field, the hash, and the gates are the proof system. A circuit written against them is an application.
Model
What has to hold
No price, supply, yield, or adoption figure is added by this desk.
Falsifier
What would retire it
What is being recursed: which circuit verifies which other circuit?
04 The bound
Observation
What the study says
This note does not quote a proving speed.
Model
What has to hold
You are reading the Plonky2 repository. A zkEVM built on it is a second project.
Falsifier
What would retire it
What is being recursed: which circuit verifies which other circuit?
03 Sequence
One action, as an operating tape
- 01The field, the hash, and the gates are the proof system. A circuit written against them is an application.
- 02A recursive verifier inside the circuit is how traces get combined. That verifier must be the same system the outer proof expects.
- 03FRI-style proximity, as used here, is an assumption about the polynomial. It is not a validity proof of Ethereum by itself.
04 Load-bearing
The argument, and where a pitch drops it
What the name has to mean
The cut
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
Plonky2 is not Plonky3, and it is not PLONK as in the original paper, though it is in that family.
What actually moves
The cut
A recursive verifier inside the circuit is how traces get combined. That verifier must be the same system the outer proof expects.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
A circuit bug is an application bug. The proof will vouch for the bug.
What a later deployment may change
The cut
FRI-style proximity, as used here, is an assumption about the polynomial. It is not a validity proof of Ethereum by itself.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
A circuit bug is an application bug. The proof will vouch for the bug.
05 Register
What has to be true
Model · Not re-measured
You are reading the Plonky2 repository. A zkEVM built on it is a second project.
Model · Not re-measured
The document is the one at the source URL. A marketing page with the same brand is not this text.
Model · Not re-measured
No price, supply, yield, or adoption figure is added by this desk.
06 Divergence
What happened after the paper
A circuit bug is an application bug. The proof will vouch for the bug.
A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.
07 Pre-mortem
What to check before you use the idea
- 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.
08 Anatomy
The paper, in the order a builder needs
The problem it names
Recursion is not a virtual machine. It is a way to compose proofs. The machine has to be specified elsewhere.
What the design proposes
- The field, the hash, and the gates are the proof system. A circuit written against them is an application.
- A recursive verifier inside the circuit is how traces get combined. That verifier must be the same system the outer proof expects.
- FRI-style proximity, as used here, is an assumption about the polynomial. It is not a validity proof of Ethereum by itself.
How the mechanism is specified
- The field, the hash, and the gates are the proof system. A circuit written against them is an application.
- A recursive verifier inside the circuit is how traces get combined. That verifier must be the same system the outer proof expects.
- FRI-style proximity, as used here, is an assumption about the polynomial. It is not a validity proof of Ethereum by itself.
What this page does not treat as proven
Why the desk still reads it
Plonky2 publishes a SNARK aimed at fast recursion: a proof can verify other proofs, which is the property a zkEVM uses to fold a large trace.
09 Lexicon
Terms, opened into the record
- Recursive proof
- A proof whose statement includes the verification of another proof.
- Circuit
- The constraint system for one computation. It is not the proof system.
10 Repository
Every linked record on this page
Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
