Crypto glossary

zk-STARK

A zk-STARK is a type of zero-knowledge proof that lets one party prove a computation was done correctly without a trusted setup, relying only on hash functions and public randomness.

Auf Deutsch lesen

What the letters mean

STARK stands for Scalable Transparent Argument of Knowledge. A zero-knowledge proof lets a prover convince a verifier that a statement is true, for example that thousands of transactions were processed correctly, without the verifier redoing all the work and, if wanted, without revealing the underlying data.

Transparent is the key word. Some other proof systems, including many zk-SNARKs, need a one-time ceremony that creates secret parameters, often called toxic waste. If those secrets leaked, someone could forge proofs. STARKs need no such ceremony: all their parameters are public, so there is no secret to leak. That is true of STARKs by design, not just of some implementations.

How a STARK proof is built

The computation is turned into a set of polynomial equations. The prover commits to the results using a Merkle tree of hashes and then answers random spot checks chosen from public randomness. If the prover cheated anywhere, the spot checks catch it with overwhelming probability.

Because security rests on hash functions rather than elliptic-curve math, STARKs are widely considered resistant to future quantum computers, a property many SNARKs lack.

Where you meet them

The best-known use is in zero-knowledge rollups, layer-2 systems that bundle many transactions off the main chain and post a single proof to Ethereum. StarkNet and StarkEx, built by StarkWare, use STARKs. Verifying one proof is far cheaper than re-executing every transaction, which is how rollups lower fees.

Trade-offs and limits

STARK proofs are much larger than SNARK proofs, often tens to hundreds of kilobytes instead of a few hundred bytes. Posting that data on-chain costs gas, so projects sometimes wrap a STARK inside a smaller SNARK before publishing it.

A proof also only shows that the program ran as written. If the program or the verifier contract has a bug, a valid proof can still certify a wrong result, so audits and careful engineering still matter.

Ask Coach about it

Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.

How do zk-STARKs compare with zk-SNARKs for scaling Ethereum rollups?Ask Coach →

Frequently asked questions

What is the difference between a zk-STARK and a zk-SNARK?

Both prove computations succinctly. STARKs need no trusted setup and rely on hashes, while SNARKs usually produce much smaller proofs but often depend on a setup ceremony and elliptic-curve assumptions.

Are zk-STARKs quantum-resistant?

They are generally considered post-quantum secure because they rely on collision-resistant hash functions, not on the elliptic-curve problems a large quantum computer could break.

Do zk-STARKs hide my data?

They can, but not every use does. Many rollups use STARKs mainly for scaling, so the transactions themselves stay public; the zero-knowledge property is optional depending on the design.

Related terms

Zero-Knowledge Proof (ZK)Zero-Knowledge RollupRollupLayer 2 (L2)HashCryptography

Learn it step by step

AC Learning explains these ideas in interactive lessons — the first eight sections are free.

Open AC Learning → Create a free account

All glossary terms · Educational reference only — not investment, legal, tax or financial advice.