LibraryPrivacy2017Design paperCorpus record
Scalable Multi-party Computation for zk-SNARK Parameters
Powers of Tau. Sean Bowe, Ariel Gabizon and Ian Miers.
Powers of Tau is a multi-party computation that builds the structured reference string so that if one participant deletes their randomness, the trapdoor is gone.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
When a project points at a ceremony, ask who can still have the toxic waste and how a stranger checks the transcript.
The five-minute read
The defect
A SNARK setup done by one machine is a single party who can forge proofs if they keep the randomness.
The proposal
Powers of Tau is a multi-party computation that builds the structured reference string so that if one participant deletes their randomness, the trapdoor is gone.
One honest deletion is the security claim.
The transcript is public and checkable.
The bound
A ceremony with no honest participant is a trusted party.
One action, walked through
- Each participant mixes in randomness and publishes a proof they did it correctly.
- The next participant starts from that transcript.
- Verifiers recompute the checks instead of trusting the ceremony operator.
- Can a stranger verify the transcript?
The argument, unpacked
What the paper is for
When a project points at a ceremony, ask who can still have the toxic waste and how a stranger checks the transcript.
What happened after
Sapling and later universal setups used this pattern. The transcript of a ceremony is a separate artefact from this paper.
What has to be true
- A ceremony with no honest participant is a trusted party.
- The paper does not audit a particular ceremony.
- Universal parameters are not a circuit. A second phase still specialises them for many systems.
What happened after the paper
Sapling and later universal setups used this pattern. The transcript of a ceremony is a separate artefact from this paper.
What to check before you use the idea
- What happens if one participant was honest?
- Can a stranger verify the transcript?
- Does this output a circuit, or parameters for later circuits?
Terms
- Toxic waste
- The randomness that must be deleted.
- SRS
- The structured reference string the proofs are verified against.
The problem the paper names
A SNARK setup done by one machine is a single party who can forge proofs if they keep the randomness.
What the design proposes
- One honest deletion is the security claim.
- The transcript is public and checkable.
- The output is parameters, not proofs about a particular circuit, until a later phase specialises them.
How the mechanism is specified
- Each participant mixes in randomness and publishes a proof they did it correctly.
- The next participant starts from that transcript.
- Verifiers recompute the checks instead of trusting the ceremony operator.
What this page does not treat as proven
- A ceremony with no honest participant is a trusted party.
- The paper does not audit a particular ceremony.
- Universal parameters are not a circuit. A second phase still specialises them for many systems.
Why a venture studio still reads it
When a project points at a ceremony, ask who can still have the toxic waste and how a stranger checks the transcript.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
