New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Fast ZK is here - and now what? | Marcin | ETHWarsaw [4]

ETH WarsawSun, Nov 9, 2025, 12:00 AM

Marcin from zkSync explores what faster proofs unlock for privacy, interoperability, and apps that actually talk to each other. 🎥 Recorded at ETHWarsaw 2025 Follow ETHWarsaw on social media for the latest updates! X (Twitter): https://x.com/ETHWarsaw LinkedIn: https://www.linkedin.com/company/ethwarsaw Telegram chat: https://t.me/joinethwarsaw

Transcript

Now let's have a huge round of applause for Marin and let's get started the clicker. Welcome folks. One of the big challenge of giving talks to such a group of people is that I need to keep you focused on on the talk. Each one of you has a phone in your hand means that I have about 30 seconds per each slide to keep you entertained and hopefully I will before your mind will switch. Let's check something on the phone.

So I hope this will be a fast and quick talk that will teach you something about ZK and about the exciting future. So without further ado, let's go. So first ZK is here. Yay. Like

let's go. Okay, you know things that we've been talking about zero knowledge since 2012 when it started as this side project this side math project we've been improving and improving over this and now it's fast now we can do all these things but where is the excitement should be celebrating about it it's like lunar landing for Ethereum but it's quiet h so why is that some people are talking about it There is some excitement but it's still on the low level. It still did not reach the Ethereum masses. One of the reasons might be that many of us here don't fully know what it means. People know like yeah there is some ZK something there is some complex math.

Yes cool Ethereum is going towards ZK people are talking about it. There will be some risk VMs. Fine. We'll figure it out when it gets there. So during this talk, my challenge, my mission is to teach you just a little bit for you to get enough excited so that you understand the possibilities, understand the new things, the new frontiers that it opens, not only for Ethereum, but also for other startups, for other ideas that can be now built on top.

things that were really not possible a couple years back now are as this is a short talk. This is what ZK is. You take a computation, you do a polinomials and you do a proof. In the past, I really tried to teach people ZK in half an hour. I failed.

I mean, the way it looked is like I've been doing this. people were like mhm mhm and then nothing. So three things I I did. I actually did a children's book. We'll talk about this later.

Some Twitter posts, what not. So here I will not try to explain the detailed math. It's fascinating by the way. This is actually the way when you can say, "Hey, I'm doing crypto and I'm doing real math." This is not the scammy thing.

It's like real math. If you do have time, one thing I encourage you is to try to learn a little bit how ZK works. But in the current world with ZK being fast, this is equivalent of learning how exactly CPU works. If you're a computer scientist, if you're passionate about this, yes, you can, but you don't need that in order to use the computer. So instead, what I want is I want to give you a little bit of intuition of what ZK is, how you can use it and go beyond.

And again, if you find it fascinating, by all means, please reach out. We can talk about how it actually works under the hood. But for now, let's focus on the intuition. Let's focus on how to use the computer, not necessarily how it's built. So if you were to sum up ZK intuition in one slide, this is this hashing that I hope all of you are familiar with.

If not, hey blockchain 101 is the way of quote unquote compressing data. It's not really compressing. You cannot decompress it. But like for a given amount of data, you create a one hash. Done.

ZK proves the way you can explain it in two seconds is like compressing computation. It sounds strange when you hear it about you're like what do you mean computation but the same analogy the way how you say this hash can represent pabytes xabytes of data the same way you can say this zk proof can represent hours thousands millions of hours of computation same logic now what does it mean a little bit in practice this means means that imagine imagine Wau had a program that he shared with us. It's an open source program and he said margin I put some secret inputs in there and I got some output. We don't know what went in but we know that he generated something. Now he can generate a proof out of that.

can generate a small proof that will contain this output and will prove to everybody here that yes he actually had some inputs to this problem. The small concept means that he can run something for hours for days come up with the result and then create a small proof to show this. So again this is the the magic of what I'm calling compressing of the computation of the proof. Of course, today we use it where mostly in case of a different L2s, different ZK processors as a way of proving that the whole L2 computation, these thousands and millions of transactions were actually valid and boom, we just send a small proof to Ethereum. Now, the problem we had was how fast ZK is.

If I was giving this talk four years ago, I would be talking about clusters of super powerful GPUs in order to be able to compute a very small specific path. When we were doing provers four years ago, they literally were like measured in kilohertz. How many trans how not so many transactions how many operations can do per second per GPU what not whatin four years thanks to by the way a lot of work from many many people from many many companies because this is the beauty of blockchains we are building in open source meaning people can build on each other and this allowed us as a community to jump from 10 kHz to 13 meghertz right now on a single GPU So what does it mean? This means that at home on a single GPU and again now we know how to do things in parallel. You can basically run the 286 machine.

It will be live proven. Exciting.

Yeah.

Good. Some of you did run 286 in the past. So you know how exciting it was to get a machine like this. So everything you've been running 30 years ago now you can do with ZK proven. This means it can be straight proven on Ethereum.

But more seriously what this oops sorry more seriously what this means is that on top of that ZK proofs can also be folding. You can use the machine to verify the ZK proof that you generated before. This is a trick that we could not do 30 years ago. Meaning that now you can actually run hundreds upon thousands of these, generate a thousand proofs and then put them on another machine to verify it. Then generate a proof of this verification, then verify it and verify it, then verify, you end up with one.

This kind of going deeper allows you to in theory prove a lot and lot of computations even without having you know 13 mehz right now at your desk. So what does it mean now that you know that hey we are on 286 level and again if we keep going like this of course this will slow down a little bit we're going to reach you know 100 megahertz level gigahertz we'll see so what you can do the very first thing that will impact most of people here at least if you're a developer is we'll finally be able to go to sane languages don't Don't get me wrong, Solidity great. The same way how we were doing DOS development back in the days, you know, single threaded very careful assembly inserting to optimize this to doing magic to fit on a this kit 144 megabytes just to you know compression whatnot. We're doing these things right now on YouTube because we have to with ZK what you're able to do and you see more and more people pushing towards this. You will be able to run risk 5 instructions.

This means risk 5 is like simplified x86 whatnot. This means that you are able to run to write rust code, write C++ code, Java code, whatnot. Compile into this and run. This will remove the problem of us having to squeeze all the computation to run on this let's call DOSBox of solidity right now and go to really unblock developers because think about how much faster you are let's say writing rust code than writing sorry solidity on whatnot. So this will open up the world to many many developers.

But that's not all cuz now with ZK the fact that we're able to prove so much cycles means we can be wasteful. I mean sorry like faster means that we don't have to think again about like every single cycle we can be like rather than reimplementing everything in solidity. Imagine your task was to take some business logic that some insurance company is doing and put it on chain. What you would have to do today is sit down probably with charge and start rewriting it painstakingly into solidity to make sure you didn't screw up with ZK. What you're able to do is you're able to take that code, whatever Java magic is in there.

You don't want to look compile it into Risk 5 and just run it. Sure, you might have to do some patches like on the inside and outside, but you don't have to mess with the core code. This will allow us to be so much faster in moving the world on chain because again we will not rebuild it. We'll just move it. But ZK is not only the succinctness.

It's not only the compression of computation. It's also the ability to choose what is public, what is private. Blockchain is amazing. Great. But everything has to be public right now because that's the only way how we can make sure that the computation is valid.

With ZK, if you remember the slides before, we said the input is public is private. So you can choose what you're sharing. You can be okay this part will be shared, this part will be private. This gives a lot of possibilities. This opens up the world to scenarios where you want to prove to someone that you did a computation, but you don't want to share all the info.

And we'll talk about examples in in in two slides. Sorry, in one slide I lied. So some concrete ideas what you can do just from listening what what I've been talking about. Think about data have hospitals, lawyers, banks, they have data that they cannot share. At the same time there are plenty of places where they want to run computation over this data.

hospital claim claiming that they have 2,000 patients with with cancer of a given type with ZK they can actually run this over lawyers saying that yes they have a given deals with ZK you can actually take the solidity sorry take the PDF parser code there are plenty of these that actually can can verify the PDF signatures can extract the data you can do all this computation they can do on all this computation on their GPU just send the proof to Ethereum And you know they did that the same thing with like all the things with R&D clinical studies verifiable research. How many times researchers say yeah I've been running this experiment for many many days and here's the result. And by the way to rerun it please get a million GPUs and off you go. Such thing okay with 30 MHz they will not be able to do that yet. Sorry.

But like for smaller cases, they will be able they will be able to I run all this re research. Here's the ZK proof. I'm not sharing with you the inputs. That's kind of my still say my university secret. But here's the proof that they actually did that and they actually got the results I wanted.

And there are many many many more cases including some things like hey uh was the data provenence? Who generated this image? Was it Was it JPT? We don't know. You don't know.

I know. But how can I prove to you today? I don't have in theory with this. I could show you a ZK proof that hey, I actually run the I put some movement into it and this was the result. Done.

This was shut GPD. By the way, I was too lazy to use And sorry, and last but not least, this is the thing that will come in the future as we get more and more performance. It's basically machine learning model inference. The problem we're going to have very very soon, we have it already. People don't know this yet.

Is many of the results we're seeing, people will be saying machine said so your insurance was rejected. Sorry sir, the GP the machine learning model said that you rejected your healthare your healthcare claim got rejected. Sorry, that's the machine. Over time when we have technology like this you'll be like okay fair but can you show me the zk proof that you really run that model that your CEO publicly claimed is running with this data or did you just say no? So as you can see future is very exciting because we're able to move from trust but verify to just verify able to just take the data and now the mission I have for you is learn how to use a key you don't have to know the details the same way as I said how you don't need to know the details of the CPU how to how to use it but learn the boundaries figure out what type of new thing that we did not think in the past could be now settling on Ethereum.

What kind of proofs of real world use cases you can now move on to ZK and then proven on Ethereum because this will really unlock a lot and lot of new technologies and a lot brighter future for Ethereum. So, as I promised, but if you're interested in how ZK works, please, this is the Eli 5 book. I try to make it as simple as it gets. There are also some, let's call it Eli 12, Eli 15 slides in there. You'll see it on my old old Twitter that try to explain you the details.

This will allow you to say, "I'm doing math, honey." Really am. This is really the crypto of the crypto part. And that's it. Thank you, folks.

And there you have it, guys. I have to say I do have this book from ECC last year and it's a very it's a very interesting way to explain it and my family even got it. I was like this is the kind of stuff I go do and they're like oh wow this is pretty cool. And do we have any questions? Yes.

Sorry. Uh yeah, you mentioned that you can run pretty much any code written in let's say Java or whatever language you have. Uh but I'm more interested in the architecture. Let's say that uh we have some code that is using some specific instructions that um do not exist on risk 5 or um not purely um 64-bit ones. So there's no um clean translation to risk 65.

How is it handled or is it just uh not possible to run them?

You have two options. Option number one, if you're lazy, you try to put some shim to compile it to risk to to risk instructions. Yes, some of them will be very slow, but you know, you kind of do a transpiler what not, what not to end up with risk. Now, if you really want to be using a different instruction set, this means, oh, we need to talk dude, you have to do actually go very deep into these things and write your own custom circuit to do this. So kind of depending on your needs, I would definitely start with option number one, meaning transpiling whatever you have into risk 5, running it potentially at some computation cost because this will be slower, right?

Some larger sets what not, but this will allow you to kind of get started and then when you see like, okay, I really need this to be cheaper, then think about custom circuits for your instructions. In some case

in some edge cases it could be even uh way faster but it's uh because of how uh x 86 handles like uh partial uh memory right

yeah so you know the reason why we why we why we as an ecosystem chosen risk 5 is that r stands for reduced so we're lazy right we wanted to start with something that has as small instruction set as possible but I'm guessing that as as the whole industry progresses probably in a couple years there will be just x86, you know, direct running for for for ZK.

That's not really how Someone wants to do it for themselves.

It's open source, man. Try it. But still in

Okay, sorry guys. We can have a one more question.

Yes. Uh practical question. Um when you are talking about risk 5 which is basically just another VM just like you know DVM today what requires compression you know to be available in in the case of ZK to actually make this work why not just use risk 5 the way I used EVM today what what what does the snark or zk as you call it actually unlock

so what's happening is like this imagine you you compile your code to risk 5 you were running it for 5 hours like your code requires 5 hours to run and now you like if you if you try to put this into Ethereum transaction and run it on Ethereum well right so so basically it is not the VM support itself is that you are opening the bounds of how much computation you're going to do you're making this effectively gasless and so on and so forth

yes you're kind of able to run this yourself and then end up with a small proof that you can then verify on Ethereum right

right and the only thing that actually will burn gas is the verification of the proof that you post on. Okay.

I have a also a quick question. I'm from like an academic PhD research background. How do you approach institutions and research to let's say prove because like I will tell you honestly is when you go to talk with researchers half the stuff they sometimes say is just a lie. And I feel like they would

only half

maybe not half. Okay, I maybe over exaggerating, but it they don't want to necessarily prove it because I feel like they will get caught out because that's how kind of like research is. They just basically fight each other until someone

look the way the way it works and I'll use the example of you know a great comparison here would be something TLDDR peer pressure for example the amazing work that L2B is doing for L2 is kind of being like guys guys please you know you're red here please improve the same thing once the tools are there would happen to researchers because once once those conferences will start like you know putting a small are saying like yeah this proof this this thing is not verified versus verified what not then this will create the pressure for this to happen but it's still going to take a couple years because we have to go a lot further than just 13 MHz

okay also we have time for one more question very quick one when air bender coming for zik sync

it's already there

no I mean when the chain is being proven by air bender and the proof of air bender is posted on a serum

so if not for this conference it will be literally today but because I screwed up things it will probably next next week what not we're in the process of like develop deploying it etc etc so but very very very soon but yes one thing I did not mention is those 13 mehz are coming from like zk sync air bender if you google it you will find the github repo that is as simple to use as I could have made it meaning you can actually take your small fibonacci program examples from this and just you know create the proof and be a proud zk proof generator on your machine at home on your single GPU as I said it's an excuse for you to get proper GPU at home and be yes honey this is for work 5090 recommended but 3090 works too

I didn't realize what time was we do have time for more questions hi Carol here um so yeah ZK fast zk is here as you mentioned air bender being fast on the kind of home machine potentially 1590 um and obviously as as you also mentioned the privacy is important aspect uh but when you mentioned privacy you did mention uh mainly running it on a cluster of GPUs. Do you believe client side proving is something that going to happen sooner? Is it not something that we do require for privacy and is 5090 not steep enough for for users to use as the kind of insight. So one of the things I'm running at home and this is kind of something that we'll be announcing more widely as Zik is saying is what I used to call like bank in a box meaning I started a small L2 L2 network is literally running on my machine at home on the 3090 yes it takes 20 seconds to generate a proof but you know for a small that's why I'm calling we're calling it prividiums for a small network that's kind of enough meaning that any transaction I send to it within 20 to 30 seconds, you know, I can generate a proof and send it to to Ethereum, right? So, TLDDR, TLDDR is like, yes, you can do the privacy solutions on your home machine if you're tolerating this.

Again, if you don't have a GPU, you can actually run it on CPU. This will take like two three minutes, but it's also workable. So, yeah, but the point is that you don't need a cluster. You can just literally for small set of transactions, you can do it like right now at home.

And do you think industry will generally go in this way? because looking at the other ZKVMs like SP1 and risk zero that's kind of proven networks required at this point. So that's the thing I think that yes, we'll be going like you've seen the speed how we improve the performance of ZK. This means that things that required clusters can now be run on like single machines. My hope is that we might still need proven networks because just the amount of things will grow to be proven.

But like a single proof will not require like 50 GPUs working in sync unless you really care about some crazy low, you know, millisecond level latencies. But for normal use cases, if you're happy with couple seconds, you should be fine with a single GPU. Please try the air bender. Let me know how it works.

Amazing. Thank you so much. Let's give one more huge round of applause.

Automatic transcript — names and jargon may be misspelled.