Library · Crypto, word by word · Cryptography

What is a zk-STARK?

A zk-STARK is a kind of zero-knowledge proof that needs no secret setup ceremony and relies on hash functions. It lets anyone check that a large computation was done correctly far faster than redoing it, at the cost of proofs larger than zk-SNARK proofs.

What it means for you

Because there is no secret setup, there is no hidden value someone could have kept to forge proofs; you still rely on the proving code and the program being proven being correct. Larger proofs cost more to verify on a base chain, which is part of what systems using them pay.

How it works

Ben-Sasson, Bentov, Horesh and Riabzev introduced STARKs in 2018: Scalable Transparent ARguments of Knowledge. Transparent means setup uses only public randomness, with no reliance on any single party and no trapdoor. Scalable means verification runs exponentially faster than the computation it checks. Security rests on collision-resistant hash functions rather than number-theoretic problems, which is why the authors present it as resistant to quantum attack and ethereum.org describes it as immune to that threat. The trade-off is proof size: STARK proofs are larger than SNARK proofs, raising verification costs.

Sources: Ben-Sasson et al., Scalable, transparent, and post-quantum secure computational integrity (IACR ePrint 2018/046), ethereum.org: Zero-knowledge proofs · checked 4 October 2026

Often confused with

zk-STARK vs zk-SNARK

Related words

Zero-knowledge proofZK-rollupzk-SNARKQuantum riskHash

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.