Skip to content

LibraryScaling2018Design paperCorpus record

Arbitrum: Scalable, private smart contracts

Arbitrum. Harry Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg, Edward W. Felten.

The 2018 USENIX paper on Arbitrum: a verifier that checks a manager's execution of a virtual machine by bisecting disputes, instead of re-executing every instruction. Offchain Labs' later Nitro stack is a descendant, not this paper line for line.

The Arbitrum paper describes a dispute protocol in which a manager need not re-execute a contract. If someone cheats, a bisection game narrows the lie to one step a small checker can verify.

The five-minute read

Execution is someone else's computer

Managers assert a result. Honest parties re-execute only if they disagree. The common case is one assertion and silence.

Bisection finds the step

A dispute splits the computation in half, again and again, until a single instruction is left. The contract checks that instruction, not the whole programme.

Any one honest challenger is the model

Safety requires that someone honest and interested challenges a false assertion before the deadline. It does not require a global vote on every step.

Privacy in the 2018 paper is a separate claim

The original system discusses virtual machines whose state need not be public to every verifier. The later Ethereum rollup also called Arbitrum made different choices about publishing data. Do not merge them.

The deadline is a security parameter

A longer dispute window gives honest challengers more time and users less speed. The paper's security is this trade, written as a timeout.

One action, walked through

  1. A party submits an assertion of a contract's new state, with a stake.
  2. During the challenge window, anyone can dispute by staking against that assertion.
  3. The protocol asks the two sides to bisect the execution trace. Each step, one half is abandoned.
  4. When one instruction remains, a checker contract runs it and sees who was right.
  5. The loser is slashed. If nobody disputes, the assertion is confirmed when the window ends.

The argument, unpacked

Optimistic means innocent until challenged

The system is cheap because false statements are expected to be rare and punishable, not because false statements are impossible. A chain with no one watching is an honour box. The paper's honesty is the existence of the challenger assumption.

One-step proofs need a precise machine

The checker must implement the same instruction the parties mean. Ambiguity in the virtual machine is a bug in the court, not in the application. Later rollup implementations had to freeze a precise ISA for this reason.

The 2018 design and the 2020 rollup share a surname

Both use interactive disputes. They differ on who may assert, how data is published, and how Ethereum is used as the court. A citation should name the document. 'Arbitrum' alone is two eras.

What has to be true

  • At least one honest party will see a false assertion and can get a challenge transaction included in time.
  • The one-step checker matches the off-chain machine.
  • Stakes are large enough that grieving the dispute game is not a profitable way to stall.
  • Users who need speed either wait out the window or trust a liquidity provider who is taking that risk.

What happened after the paper

Arbitrum One and later chains took the dispute-game idea onto Ethereum as an optimistic rollup, with a public assertion and a delay on withdrawals. The 2018 paper is the bisection argument and includes privacy goals the rollup did not centre. Read the delay and the data-posting rule from the system you actually mean.

What to check before you use the idea

  • Who is allowed to assert, and who is allowed to challenge?
  • How long is the window, and can a challenge transaction be censored for that long?
  • What machine does the one-step checker implement?
  • Is this citation the 2018 paper or the later Ethereum rollup?

Terms

Assertion
A staked claim that a virtual machine reached a particular state.
Bisection
Splitting an execution trace in half until the disagreement is a single step.
Challenge window
The time during which a false assertion can be disputed, after which it is treated as true.
One-step proof
The on-chain check of the single instruction the bisection isolated.

The problem the paper names

Publishing every contract step on a base chain is expensive, and publishing only a result forces verifiers to re-run the whole computation to argue. Arbitrum's protocol makes a challenger and a manager narrow a disagreement to a single instruction.

What the design proposes

  • Managers stake on a claimed execution. Verifiers can challenge.
  • Bisection finds one step. The base layer adjudicates that step, not the entire program.
  • Privacy in the paper's title refers to keeping the computation off the public critical path, under the protocol's assumptions, not to zero-knowledge receipts.

How the mechanism is specified

  • Honest verifiers must be able to see enough of the execution to challenge. Data availability is assumed in the way the paper states.
  • The economic assumption is that a dishonest manager will be challenged because someone's stake is at risk.
  • The virtual machine in the paper is not the later WASM or EVM compatibility layer.

What this page does not treat as proven

  • Do not cite this PDF as a description of Arbitrum One's current Nitro release.
  • An optimistic system with no watcher is an honour system. The paper is explicit that verifiers matter.
  • Dispute delay is part of the user experience. The paper does not set it to zero.

Why a venture studio still reads it

This is the paper to hand a team that says 'we'll post the result and anyone can challenge' without a bisection protocol, a stake, or a watcher. Those three are the design, not the slogan.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.