Community Trust ScoreVerified
Ethereum has a problem it can’t ignore. A live cryptographic contest called better.codes has put a number on it: a 52.14-bit security gap sitting right in the middle of the zkEVM proof framework, measured as of August 21.
The gap comes from two competing certificates for the koalaIRS12 parameter profile. The lower certificate sits at 63.99 bits. The upper one sits at 116.13 bits. The distance between them — 52.14 bits — is the unresolved interval, basically the zone where researchers can’t yet say with certainty whether the proof system is safe or not. And the Ethereum Foundation wants that zone closed before a scheduled review in early December. The target it’s chasing: 128-bit provable security, a proof size under 300 KiB, and a formal soundness argument for its recursion architecture. None of that is locked in yet.
Not even close.
How the Contest Actually Works
The better.codes competition runs two parallel tracks, and they push in opposite directions. The soundness track is trying to raise the lower certificate — essentially tightening the bound on what can be proven safe. The attack track does the opposite: it tries to shrink the upper certificate by finding conditions that expose unsafe behavior within the benchmark. If both sides keep grinding, the gap narrows. If either side stalls, it doesn’t.
Every theorem submitted gets verified inside a fixed, pinned environment. That’s deliberate. The Foundation wants reproducibility baked into the process from the start, not bolted on afterward. Model completeness matters here. So does implementation fidelity — whether the actual code matches what the formal proof says it does. A gap between those two things is exactly the kind of vulnerability that could quietly undermine a system that looks secure on paper.
The leaderboard updates live. That means the 52.14-bit figure isn’t static — it shifts as teams submit new work. But as of August 21, it’s where things stand.
What Researchers Are Still Fighting Over
An academic paper from researchers Gal Arnon, Dan Boneh, and Giacomo Fenzi sits in the background of all this. Their work flags unresolved questions in succinct proof systems — specifically around list decoding and Reed-Solomon proximity gaps. Those aren’t obscure edge cases. They’re probably the hardest open problems in the space right now, and they’re directly relevant to whether Ethereum’s zkEVM can hit its security targets.
Reed-Solomon proximity testing is a core building block in how modern zero-knowledge proof systems verify that a prover isn’t cheating. If the proximity gap — the margin between “definitely close enough” and “potentially not” — isn’t nailed down formally, the whole soundness argument gets shakier. That’s the kind of thing that keeps cryptographers up at night.
The Foundation’s progress page, as of August 20, mentions zkVM readiness and ISA compliance. But it doesn’t say the December package is done. It’s not.
What Still Needs to Happen
Closing the gap isn’t just about submitting more theorems. The Foundation’s roadmap asks for something harder: full system-level accounting. That means proof sizes, recursion arguments, and component-level evidence all have to line up. Each piece has to be auditable. Each step has to be verifiable by someone who wasn’t in the room when it was built.
That’s a high bar. And the koalaIRS12 profile is just one part of a broader research push to get the zkEVM framework to production-grade security. The contest is public, which helps — it brings outside researchers into the process and creates pressure to move fast. But fast and rigorous don’t always go together.
Worth noting: the leaderboard scores don’t touch Ethereum’s current consensus-critical validation. Whatever’s happening in the contest doesn’t change how the network runs today. It’s forward-looking research, aimed at a future version of the proof system that can credibly claim 128-bit security.
The challenge repository is still open for submissions. Soundness teams keep pushing the lower bound up. Attack teams keep trying to pull the upper bound down. The gap, right now, is 52.14 bits.
Hub: Ethereum price, news, and analysis
Frequently Asked Questions
What exactly is the 52.14-bit security gap in Ethereum’s zkEVM?
It’s the distance between a 63.99-bit lower certificate and a 116.13-bit upper certificate for the koalaIRS12 parameter profile, measured as of August 21 via the better.codes contest.
What are Ethereum’s three main zkEVM security requirements for December?
The Ethereum Foundation wants a 128-bit provable security level, a final proof size under 300 KiB, and a formal soundness argument covering its recursion architecture.
Who are the researchers behind the relevant academic paper on proof system gaps?
Gal Arnon, Dan Boneh, and Giacomo Fenzi authored the paper flagging unresolved questions around list decoding and Reed-Solomon proximity gaps in succinct proof systems.
Why It Matters
The reported 52.14-bit security gap within Ethereum's zkEVM framework raises significant concerns about the protocol's robustness and its ability to maintain trust among users and developers. As Ethereum continues to drive innovations in scalability and privacy, any vulnerabilities in its cryptographic foundations could impact its adoption and competitive positioning against other blockchain platforms, potentially affecting market sentiment and investment in the ecosystem. This situation highlights the ongoing need for rigorous cryptographic advancements in the rapidly evolving landscape of decentralized finance and smart contracts.
