Uploaded July 2026 | Updated September 2026, 2 hours ago
At nearly ten years old, Groth16 is still one of the most widely used ZK proof systems today.
So in Session 10 (!) of Proof is in the Pudding, David Wong works backward from Groth16’s famously compact verifier equation to explain why the protocol is structured the way it is.
He walks through how R1CS constraints become polynomial identities, why elliptic curve pairings are needed to multiply hidden commitments, and how random linear combinations enforce consistency across the prover’s witness via the Schwartz–Zippel lemma.
Along the way, David also introduces the “Lego pieces” mental model for the common reference string and explains how separating factors like gamma and delta restrict which pieces the prover can use.
To join a future session of Proof is in the Pudding, please reach out to an Archetype team member!
📬 You can also receive invites to other Archetype events by signing up for our newsletter here: eepurl.com/iCApL2
—
⌛️ TIMESTAMPS
0:00 Intro
02:10 Why Groth16 Is Still Used
04:10 Downsides of Groth16
06:00 R1CS Recap
11:30 From R1CS to Polynomial Identities
14:00 Vanishing Polynomials
17:32 Schwartz-Zippel Lemma
22:45 Why Groth16 Needs Pairings
28:10 The Initial Verification Check
29:45 Witness Consistency and Random Linear Combinations
34:39 Encoding the Circuit in the CRS
36:19 Constructing the C Proof Element
37:53 The CRS as Lego Pieces and Separating Factors
43:16 Enforcing the Quotient Polynomial
48:14 Merging the Verification Checks
54:04 Deriving the Final Groth16 Equation
58:44 Enforcing Public Inputs
—
👋 FOLLOW US
David: https://x.com/cryptodavidw
zkSecurity: https://x.com/zksecurityXYZ
Archetype: https://x.com/archetypevc
🌐 LINKS
Groth16 Blog Post by ZKSecurity: https://blog.zksecurity.xyz/posts/groth16/
Session 01 on Arithmetization: youtu.be/QjNVYgEorec
zkSecurity: https://www.zksecurity.xyz/
Archetype: https://www.archetype.fund/
—
DISCLAIMER: The information in this video is the opinion of the speaker(s) only and is for informational purposes only. You should not construe it as investment advice, tax advice, or legal advice, and it does not represent any entity's opinion but those of the speaker(s). For investment or legal advice, please seek a duly licensed professional.
At nearly ten years old, Groth16 is still one of the most widely used ZK proof systems today.
So in Session 10 (!) of Proof is in the Pudding, David Wong works backward from Groth16’s famously compact verifier equation to explain why the protocol is structured the way it is.
He walks through how R1CS constraints become polynomial identities, why elliptic curve pairings are needed to multiply hidden commitments, and how random linear combinations enforce consistency across the prover’s witness via the Schwartz–Zippel lemma.
Along the way, David also introduces the “Lego pieces” mental model for the common reference string and explains how separating factors like gamma and delta restrict which pieces the prover can use.
To join a future session of Proof is in the Pudding, please reach out to an Archetype team member!
📬 You can also receive invites to other Archetype events by signing up for our newsletter here: eepurl.com/iCApL2
—
⌛️ TIMESTAMPS
0:00 Intro
02:10 Why Groth16 Is Still Used
04:10 Downsides of Groth16
06:00 R1CS Recap
11:30 From R1CS to Polynomial Identities
14:00 Vanishing Polynomials
17:32 Schwartz-Zippel Lemma
22:45 Why Groth16 Needs Pairings
28:10 The Initial Verification Check
29:45 Witness Consistency and Random Linear Combinations
34:39 Encoding the Circuit in the CRS
36:19 Constructing the C Proof Element
37:53 The CRS as Lego Pieces and Separating Factors
43:16 Enforcing the Quotient Polynomial
48:14 Merging the Verification Checks
54:04 Deriving the Final Groth16 Equation
58:44 Enforcing Public Inputs
—
👋 FOLLOW US
David: https://x.com/cryptodavidw
zkSecurity: https://x.com/zksecurityXYZ
Archetype: https://x.com/archetypevc
🌐 LINKS
Groth16 Blog Post by ZKSecurity: https://blog.zksecurity.xyz/posts/groth16/
Session 01 on Arithmetization: youtu.be/QjNVYgEorec
zkSecurity: https://www.zksecurity.xyz/
Archetype: https://www.archetype.fund/
—
DISCLAIMER: The information in this video is the opinion of the speaker(s) only and is for informational purposes only. You should not construe it as investment advice, tax advice, or legal advice, and it does not represent any entity's opinion but those of the speaker(s). For investment or legal advice, please seek a duly licensed professional.










