ZK/SEC Research notes from zkSecurity
All posts
educative · zk · plonk

𝒫𝔩𝔬𝔫𝒦: A Hands-On Deep Dive

PLONK

Understanding 𝒫𝔩𝔬𝔫𝒦 can be daunting given its multiple building blocks. Selector polynomials, wiring permutations, quotient tests, random challenges, and KZG commitments can be overwhelming at first sight. At zkSecurity, we have created a hands-on tutorial to demystify each piece through a progressive running example: you'll build tables of intermediate values, interpolate low-degree polynomials over the BN254 field, encode gate and wiring constraints, and perform both deterministic and probabilistic zero-tests.

📖 Access the tutorial

Whether you are already familiar with the protocol or curious to learn more about it, this tutorial helps you understand the inner workings of 𝒫𝔩𝔬𝔫𝒦, turning a complex proof system into an accessible, step-by-step learning journey.

Choose how to solve: Download a Jupyter Notebook version of the tutorial and solve with Sage or on Cocalc. But you may also solve in some other programming language, we guide you with test cases along the way!

Deep Dives into building blocks: Each algebraic construction is motivated through the running example, from vanishing polynomials to the grand-product argument, bridging theory and practice.

Progressive Complexity: Start with a simple circuit, then incrementally introduce selectors, quotient polynomials, random challenges, and KZG commitments, culminating in a full non-interactive Fiat–Shamir 𝒫𝔩𝔬𝔫𝒦 proof.

Keep reading
Recommended

Groth16, Intuitively

Groth16 is still the gold standard for succinct SNARKs: 128-byte proofs, constant-size verification, and a decade of real-world deployment. But despite its ubiquity, almost nobody explains *why* it works the way it does. In this post, we build Groth16 from the ground up, starting from R1CS and QAPs, then layer in pairings, trusted setup parameters, and the separator tricks (α, β, γ, δ) that make the scheme sound. By the end, you should have an intuitive grasp of every term in the final verifier equation.

David Wong · May 01, 2026

Learn Sumcheck, MLE, and HyperPlonk: An Interactive Tutorial with SageMath

A new interactive tutorial on Sumcheck, Multilinear Extensions, and HyperPlonk with complete SageMath implementations and exercises. Go beyond the theory and understand how these protocols actually work by implementing them yourself.

Marco Gaglianese · November 22, 2025

Sum-Check as an Algebraic Tensor Reduction: Part I

This post introduces algebraic tensor reductions as a unifying framework for understanding recursive proof protocols, using sum-check as the main motivating example. It walks through one recursive step of sum-check, showing how the prover sends a univariate summary, the verifier checks sum consistency, and the original claim is reduced to a smaller claim with one fewer variable. A small bivariate example illustrates how this “peel off one variable, check, then fold with randomness” pattern works concretely. The post sets up the rest of the series, which will introduce the tensor language needed to recover classical sum-check as an algebraic tensor reduction.

Marco Besier · April 27, 2026
More to explore

Archetype x zkSecurity (Whiteboard Session) - Proof is in the Pudding: Arithmetization

Join us for a deep dive into the fascinating world of arithmetization as David from our team breaks down the process of converting logical statements into algebraic forms to create arithmetic circuits, essential for constructing ZK proofs. This unedited recording from our "Proof is in the Pudding" series offers a unique opportunity to grasp these foundational concepts, perfect for anyone keen on unlocking the mechanics behind zero-knowledge proofs. Curious? Check out the session on Archetype's channel!

ZK/SEC · October 03, 2024

AI meets Cryptography 2: What AI Found in OpenVM's zkVM

We turned zkao (our AI auditor) on OpenVM, a state-of-the-art zkVM, and it found a critical soundness bug: the pairing check accepted a prover-supplied witness without proper subfield checking, which lets a malicious prover forge any pairing equality. It is fixed in OpenVM 1.6.0 and tracked as CVE-2026-46669. This is the second post in our series on bugs our agents found across open source cryptography.

Stefanos Chaliasos, Hao Pham · July 17, 2026

You like Circom but you find it confusing? Introducing Circomscribe

Dive into our exploration of Circomscribe, a nifty tool designed to illuminate the mysterious process of how your Circom code gets translated into constraints. We share insights from our experience with Circom circuit audits, highlighting common pitfalls developers face when their high-level intentions meet low-level reality. By showcasing how Circomscribe can help visualize this transition, we aim to empower developers to craft more bug-free, secure ZK applications. If you're keen on understanding the inner workings of Circom and enhancing your coding prowess, this post is your guide.

ZK/SEC · August 26, 2023