halo2
Home
Curriculum
Home
Curriculum

halo2

From first principles to Halo2 proofs

Study the curriculum

halo2

Understand Halo2

Start with finite fields and elliptic curves. Follow the mathematics into polynomial commitments, PLONK, and a working Halo2 proof.

Explore the curriculum 18 modules
Hproof
a · b = c
∑ qᵢ · sᵢ = 0
advice
instance

Contents

Your learning path

120–150 hours, with practical exercises, review checkpoints, and explicit security assumptions.

01

3 topic groups

Build the foundations

Modules 1–6 · Learn the arithmetic and cryptographic vocabulary from scratch.

Module 01–03𝔽

Fields and curves

Statements, witnesses, finite fields, groups, and elliptic-curve arithmetic.

Open section
Module 04–05G

Encryption and commitments

ElGamal, homomorphic operations, Pedersen commitments, and hash assumptions.

Open section
Module 06↔

Interactive proofs

Schnorr proofs, transcript challenges, and the Fiat–Shamir transformation.

Open section
02

3 topic groups

Understand the protocol

Modules 7–14 · Follow computation through constraints, polynomials, and verifier checks.

Module 07–09f(X)

Arithmetization

Circuit equations, interpolation, evaluation domains, and quotient identities.

Open section
Module 10–11⟨a,b⟩

Polynomial openings

Commit to a polynomial and prove evaluations with inner-product arguments.

Open section
Module 12–14π

PLONK and Halo2

Gates, copy constraints, lookups, blinding, and the complete proof transcript.

Open section
03

3 topic groups

Build and explain a proof

Modules 15–18 · Implement circuits, test failures, and connect the theory to a working proof.

Module 15–16{ }

Circuit engineering

Learn the Rust API, bind public inputs, and discover missing constraints.

Open section
Module 17✓

Private bounded value

Prove a hidden value satisfies a public bound and matches a public commitment.

Open section
Module 18∞

Beyond the first proof

Understand recursion, curve cycles, and the differences between IPA and KZG.

Open section