halo2
From first principles to Halo2 proofs
halo2
Understand Halo2
Start with finite fields and elliptic curves. Follow the mathematics into polynomial commitments, PLONK, and a working Halo2 proof.
Contents
Your learning path
120–150 hours, with practical exercises, review checkpoints, and explicit security assumptions.
3 topic groups
Build the foundations
Modules 1–6 · Learn the arithmetic and cryptographic vocabulary from scratch.
Fields and curves
Statements, witnesses, finite fields, groups, and elliptic-curve arithmetic.
Open sectionEncryption and commitments
ElGamal, homomorphic operations, Pedersen commitments, and hash assumptions.
Open sectionInteractive proofs
Schnorr proofs, transcript challenges, and the Fiat–Shamir transformation.
Open section3 topic groups
Understand the protocol
Modules 7–14 · Follow computation through constraints, polynomials, and verifier checks.
Arithmetization
Circuit equations, interpolation, evaluation domains, and quotient identities.
Open sectionPolynomial openings
Commit to a polynomial and prove evaluations with inner-product arguments.
Open sectionPLONK and Halo2
Gates, copy constraints, lookups, blinding, and the complete proof transcript.
Open section3 topic groups
Build and explain a proof
Modules 15–18 · Implement circuits, test failures, and connect the theory to a working proof.
Circuit engineering
Learn the Rust API, bind public inputs, and discover missing constraints.
Open sectionPrivate bounded value
Prove a hidden value satisfies a public bound and matches a public commitment.
Open sectionBeyond the first proof
Understand recursion, curve cycles, and the differences between IPA and KZG.
Open section