whitepaperScaling2018
Scalable, transparent, and post-quantum secure computational integrity
StarkWare. Eli Ben-Sasson, Iddo Bentov, Yinon Horesh, Michael Riabzev.
The STARK paper: proofs of computational integrity that are succinct, do not need a trusted setup, and are argued to resist quantum attackers on the underlying hashes. StarkWare's later systems, including StarkEx and Starknet, are built on this proof system. They are not identical to it.
The problem the paper names
Many succinct proofs require a structured setup whose toxic waste must be destroyed. STARKs aim at a proof that is only as trusted as public randomness and a hash function, and that stays small relative to the computation.
What the design proposes
- An algebraic intermediate representation of a computation is proved by an interactive oracle proof, then made non-interactive.
- Transparency means the randomness is public. There is no structured reference string in the construction.
- Post-quantum security is argued from hash-based assumptions, not from elliptic-curve pairings.
How the mechanism is specified
- The prover commits to an execution trace. The verifier queries a small number of positions.
- Proof size and prover cost are the engineering trade the paper quantifies for its construction, not for a particular L2 today.
- A proof shows the trace satisfied the constraints that were encoded. Encoding the wrong program yields a valid proof of the wrong thing.
What this page does not treat as proven
- This paper is not the Starknet documentation, the Cairo language spec, or a token paper.
- Transparent does not mean trustless in the casual sense. Verifiers still trust the hash and the circuit.
- We do not repeat the paper's performance tables as current product metrics.
Why a venture studio still reads it
When a venture says 'zk' , ask whether there is a setup ceremony and what the proof actually constrains. STARKs are the citation for the transparent, hash-based branch of that answer.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.