Skip to content

LibraryScaling2023Design paperCorpus record

Scroll: a zkEVM rollup design

Scroll zkEVM. Scroll.

Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
6

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    zkEVM is a family, not a compatibility promise. Bytecode, gas, and precompiles either match or they are a different machine.

  2. Claim 02 · Paper model

    The proposal

    Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.

  3. Claim 03 · Paper model

    The mechanism

    The prover attests a batch. The settlement contract is the object that may advance the root.

  4. Claim 04 · Paper model

    The bound

    This note does not score bytecode equivalence and does not quote a proving time.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    zkEVM is a family, not a compatibility promise. Bytecode, gas, and precompiles either match or they are a different machine.

    Model

    What has to hold

    You are reading Scroll's public design documents, not an audit and not a compatibility matrix.

    Falsifier

    What would retire it

    Which opcodes does the project itself say differ from the EVM?

  2. 02 The proposal

    Observation

    What the study says

    Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.

    Model

    What has to hold

    You are reading Scroll's public design documents, not an audit and not a compatibility matrix.

    Falsifier

    What would retire it

    Which contract accepts the proof?

  3. 03 The mechanism

    Observation

    What the study says

    The prover attests a batch. The settlement contract is the object that may advance the root.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    Which contract accepts the proof?

  4. 04 The bound

    Observation

    What the study says

    This note does not score bytecode equivalence and does not quote a proving time.

    Model

    What has to hold

    You are reading Scroll's public design documents, not an audit and not a compatibility matrix.

    Falsifier

    What would retire it

    Which opcodes does the project itself say differ from the EVM?

03 Sequence

One action, as an operating tape

  1. 01The prover attests a batch. The settlement contract is the object that may advance the root.
  2. 02Equivalence to the EVM is a claim you test opcode by opcode. A docs page that says zkEVM has not, by itself, finished that test.
  3. 03The sequencer can be centralised at the ordering layer and still not be allowed to forge a proof.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A testnet proof system and a settlement bridge on Ethereum mainnet are different deployments.

  2. What actually moves

    The cut

    Equivalence to the EVM is a claim you test opcode by opcode. A docs page that says zkEVM has not, by itself, finished that test.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    This note does not score bytecode equivalence and does not quote a proving time.

  3. What a later deployment may change

    The cut

    The sequencer can be centralised at the ordering layer and still not be allowed to forge a proof.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A testnet proof system and a settlement bridge on Ethereum mainnet are different deployments.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading Scroll's public design documents, not an audit and not a compatibility matrix.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

Data availability is a separate question from the validity of the trace.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

zkEVM is a family, not a compatibility promise. Bytecode, gas, and precompiles either match or they are a different machine.

What the design proposes

  • The prover attests a batch. The settlement contract is the object that may advance the root.
  • Equivalence to the EVM is a claim you test opcode by opcode. A docs page that says zkEVM has not, by itself, finished that test.
  • The sequencer can be centralised at the ordering layer and still not be allowed to forge a proof.

How the mechanism is specified

  • The prover attests a batch. The settlement contract is the object that may advance the root.
  • Equivalence to the EVM is a claim you test opcode by opcode. A docs page that says zkEVM has not, by itself, finished that test.
  • The sequencer can be centralised at the ordering layer and still not be allowed to forge a proof.

What this page does not treat as proven

  • This note does not score bytecode equivalence and does not quote a proving time.
  • A testnet proof system and a settlement bridge on Ethereum mainnet are different deployments.
  • Data availability is a separate question from the validity of the trace.

Why the desk still reads it

Scroll's design is a zkEVM: a proof that an Ethereum-like execution trace is valid, checked by a settlement contract rather than re-executed by every validator.

09 Lexicon

Terms, opened into the record

zkEVM
A proof system aimed at an Ethereum-like execution trace. The aim is not a certificate of equivalence.
Batch
The set of transactions one proof is supposed to cover.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.