#zero-knowledge #snark #lego-snark #lego-groth16 #circom


An implementation of the LegoGroth16, the Legosnark variant of Groth16 zkSNARK proof system

2 unstable releases

Uses new Rust 2021

new 0.3.0 Sep 21, 2022
0.2.0 May 2, 2022

#207 in Cryptography

Download history 7/week @ 2022-06-07 8/week @ 2022-06-14 10/week @ 2022-06-21 7/week @ 2022-06-28 10/week @ 2022-07-05 32/week @ 2022-07-12 17/week @ 2022-07-19 22/week @ 2022-07-26 37/week @ 2022-08-02 29/week @ 2022-08-09 51/week @ 2022-08-16 27/week @ 2022-08-23 18/week @ 2022-08-30 25/week @ 2022-09-06 15/week @ 2022-09-13 83/week @ 2022-09-20

144 downloads per month
Used in 2 crates


5.5K SLoC


The arkworks ecosystem consist of Rust libraries for designing and working with zero knowledge succinct non-interactive arguments (zkSNARKs). This repository contains an implementation of the LegoGroth16, the LegoSNARK variant of Groth16 zkSNARK proof system.
This project started as fork of this but is updated to

  • commit to a subset of the witnesses by specifying the count, say n, of the witnesses to commit during CRS generation. By convention, it commits to the first n variables allocated for witnesses in the circuit and the proof contains that commitment
  • either contain CP_link as well or omit it but only have the proof contain the commitment. The proof here contains 2 commitments (one is same as above) to the witness variables but with different commitment keys and randomness.

The zkSNARK for Linear Subspaces from appendix D of LegoSNARK paper is here.

This library is released under the MIT License and the Apache v2 License (see License).

WARNING: This is an academic proof-of-concept prototype, and in particular has not received careful code review. This implementation is NOT ready for production use.

Build guide

The library compiles on the stable toolchain of the Rust compiler. To install the latest version of Rust, first install rustup by following the instructions here, or via your platform's package manager. Once rustup is installed, install the Rust toolchain by invoking:

rustup install stable

After that, use cargo, the standard Rust build tool, to build the library:

git clone https://github.com/lovesh/legogroth16
cargo build --release

This library comes with unit tests for each of the provided crates. Run the tests with:

cargo test


This library is licensed under either of the following licenses, at your discretion.

Unless you explicitly state otherwise, any contribution submitted for inclusion in this library by you shall be dual licensed as above (as defined in the Apache v2 License), without any additional terms or conditions.


This work was supported by: a Google Faculty Award; the National Science Foundation; the UC Berkeley Center for Long-Term Cybersecurity; and donations from the Ethereum Foundation, the Interchain Foundation, and Qtum.

An earlier version of this library was developed as part of the paper "ZEXE: Enabling Decentralized Private Computation".


~119K SLoC