A curated list of resources for learning and building with Zero-Knowledge Proofs (ZKPs), from foundational mathematics to production applications.
Zero-Knowledge Proofs allow one party to prove to another that a statement is true without revealing any information beyond the validity of the statement itself. This list covers theory, tools, languages, frameworks, and real-world applications.
- Getting Started
- Mathematical Foundations
- Cryptographic Theory
- Security
- Programming Languages & DSLs
- Development Tools
- Libraries & Frameworks
- Learning Resources
- Applications
- Projects
- Conferences & Events
- Communities & People
- Audits & Security Reviews
New to Zero-Knowledge Proofs? Start here.
- Zero Knowledge Proofs for Engineers - Introduction to zk-SNARKs
- An approximate introduction to how zk-SNARKs are possible - Vitalik Buterin's approachable explanation
- zkSNARKs in a nutshell - Ethereum Foundation's introduction
- Zero Knowledge privacy without mathematics - Conceptual understanding without heavy math
- Why 99% of ZK is not zk - Understanding what actually provides zero-knowledge
- Our highly subjective view on the history of Zero-Knowledge Proofs - Historical perspective
- Demystifying Zero Knowledge Proofs - Presentation deck
- 🇪🇸 El Factor ZK - Spanish introduction video
- 🇪🇸 Introducción a Zero Knowledge - Spanish masterclass
- 🇪🇸 ZK desde cero: Todo lo que debes saber - Spanish comprehensive overview
The mathematical building blocks of Zero-Knowledge Proofs.
- The MoonMath Manual - Comprehensive manual for understanding zk-SNARKs with pen-and-paper examples
- Number Theory Explained from First Principles - Foundational number theory
- 🇪🇸 Matemática básica para ZK developers - Basic mathematics for ZK developers
- 🇪🇸 Matemática avanzada para ZK developers - Advanced mathematics for ZK developers
- All the MATH you need to understand SNARKs and STARKs - Comprehensive math playlist
- zkIntro: Understanding the Math Behind ZKPs - Mathematical foundations explained
Core cryptographic concepts and constructions.
- ZK Book by RareSkills - Practical ZK cryptography
- Proofs, Arguments, and Zero-Knowledge - Comprehensive theoretical treatment by Justin Thaler
- A Graduate Course in Applied Cryptography - Advanced cryptography textbook
- Practical Cryptography for Developers - Developer-focused cryptography guide
- Lattice Cryptography - Advanced cryptographic concepts
- ZKDocs - Community-driven ZK documentation
- How to 𝒫𝔩𝔬𝔫𝒦 - Interactive PLONK protocol explainer
- Master ZKP through Sumcheck & SageMath - Interactive sumcheck learning
- Elliptic Curves Number Theory and Cryptography - Essential ECC foundations
- Baby Jubjub Elliptic Curve - ZK-friendly elliptic curve
- Why and How zk-SNARK Works - Detailed technical explanation
- 10 Must-read Papers That Shaped Modern Zero-knowledge Proofs - Essential research papers
- Succinct Non-Interactive Zero Knowledge for a von Neumann Architecture - Foundational SNARK paper
- Poseidon - ZK-friendly hash function
- Sparse Merkle Trees - Efficient authenticated data structures
- Zero Knowledge Proofs (RDI Berkeley) - University-level ZK course
- Zero Knowledge Proofs S23 (RDI Berkeley) - Spring 2023 edition
- CS 255: Introduction to Cryptography - Stanford cryptography course
- CS 355: Applied Zero Knowledge Proofs - Applied ZK course
- 🇪🇸 Curso de MPC, FHE y ZKP - Multi-Party Computation, FHE, and ZKP course
- The Incredible Machine - Explaining ZK protocols
- Setup Ceremonies - Trusted setup procedures
- Implementing Trusted Setup Ceremony for Ethereum's EIP-4844 - Practical implementation
- On-Chain Trusted Setup Ceremony - Decentralized setup approach
- Cartesian Merkle Tree - Novel Merkle tree construction
- Scaling Sparse Merkle Trees to Billions of Keys with LargeSMT - Scalable SMTs
- Keccacheck: towards a SNARK friendly Keccak - Optimizing hash functions for ZK
Security research, auditing tools, and vulnerability analysis.
- circuzz - Fuzzer for ZK circuits
- zk-mutant - Mutation testing for ZK circuits
- lampe - Circuit analysis tool
- rocq-of-noir - Formal verification for Noir
- circomspect - Circom circuit linter
- ZKSecurity Blog - Leading ZK security research
- cryptologie Blog - Cryptography and security insights
- zkBugs - Database of ZK vulnerabilities
- zk-bug-tracker - Community bug tracking
- A Practical Guide to Finding Soundness Bugs in ZK Circuits - Practical security testing
- Automated Detection of Under-Constrained Circuits in Zero-Knowledge Proofs - Automated vulnerability detection
- Practical Security Analysis of Zero-Knowledge Proof Circuits - Security analysis framework
- Zero-Knowledge Proof Vulnerability Analysis and Security Auditing - Comprehensive security guide
- What Don't We Know? Understanding Security Vulnerabilities in SNARKs - Current threat landscape
- Weak Fiat-Shamir Attacks on Modern Proof Systems - Attack vectors
- How to Prove False Statements: Practical Attacks on Fiat-Shamir - Recent attack research
- The Last Challenge Attack on Fiat-Shamir in KZG-based SNARKs - KZG-specific attacks
- Scalable Verification of Zero-Knowledge Protocols - Verification methods
- Compositional Formal Verification of Zero-Knowledge Circuits - Compositional verification
- Formal Verification of Zero-Knowledge Circuits - Formal methods
- Towards Fuzzing Zero-Knowledge Proof Circuits - Fuzzing approaches
- Automated Verification of Consistency in Zero-Knowledge Proof Circuits - Consistency checking
- Foundation and Framework for Effective Fuzzing of Zero-Knowledge Circuits - Fuzzing framework
- Testing and Exploring Bugs in Zero-Knowledge (ZK) Compilers - Compiler testing
- Fuzzing Processing Pipelines for Zero-Knowledge Circuits - Pipeline fuzzing
- Circuit Safety and an Introduction to Noir - Security-focused Noir introduction
- Secure Your ZK Code: Best Practices for Devs & Auditors - Security best practices
- ZK Security Research - Research overview
- Push button zk circuit verification - Automated verification
- Introduction to ZK Security Research - Getting started with security
- Fuzzy Knowledge: Fuzzing SNARK circuit primitives - Fuzzing techniques
- ZK Vulnerabilities and Attacks - Attack taxonomy
- Insights from and on Taxonomy of ZKP Vulnerabilities - Vulnerability classification
- Opinionated Survey of ZKP Security - Security landscape
- Leveraging AI for Automated Vulnerability Detection in ZKP - AI-assisted security
- Auditing ZK circuits for a living - Professional auditing
- Zero Knowledge Security Explained - Security fundamentals
- Developers guide to ZK Security: from Bugs to Fixes - Practical security guide
- Automated Bug Detection in ZK Circuits - Automation tools
- Audit of a ZK application on example: Tornado Cash - Case study
- zkEVM Audit Education Session - zkEVM-specific auditing
- ZK Fellowship | 2nd Cohort | zBlock2 - Security fellowship
Domain-specific languages for writing Zero-Knowledge circuits.
High-level language for writing zero-knowledge circuits with a Rust-like syntax.
Official Resources
- Noir Documentation - Official documentation
- Noir GitHub - Official repository
- VS Code Extension - IDE support
- Barretenberg - Proving backend
- Barretenberg Docs - Backend documentation
Development Tools
- Noir Static Analyzer - Code analysis
- Noir Web - Web integration
- Noir Playground - Browser-based playground
Boilerplates & Starters
- Avalanche Noir Kit - Foundry - Avalanche integration
- Hardhat Noir Starter - Hardhat integration
- noir-react-native-starter - React Native template
- noir-library-starter - Library template
Libraries
Cryptographic Primitives
- poseidon - Poseidon hash function
- keccak256 - Keccak hash
- sha256 - SHA-256 hash
- sha512 - SHA-512 hash
- mimc - MiMC hash
- noir-ripemd160 - RIPEMD-160
- noir-aes - AES encryption
- noir-chacha20 - ChaCha20 cipher
- noir-hmac - HMAC
Digital Signatures
- schnorr - Schnorr signatures
- eddsa - EdDSA signatures
- ecdsa - ECDSA signatures
- noir-rsa - RSA signatures
- ecrecover - Ethereum ecrecover
- zk-nullifier-sig - Nullifier signatures
Data Structures
- merkle - Merkle trees
- sparse_array - Sparse arrays
- Lib_LinkList - Linked lists
- indexed-merkle-noir - Indexed Merkle trees
- MPT Noir - Merkle Patricia Trees
Elliptic Curves
- noir-edwards - Edwards curves
- noir_bigcurve - Big curve operations
- noir_bls12_381_pairing - BLS12-381 pairing
- noir-v1-elgamal - ElGamal encryption
Numeric Operations
- noir-bignum - Big number arithmetic
- noir-bignum-paramgen - Parameter generation
- ZKFloat - Floating point
- IEEE754 - IEEE 754 floats
- complexnr - Complex numbers
- noir-fixed-point - Fixed point arithmetic
- quantized_arithmetic - Quantized arithmetic
- matrix_operations - Matrix operations
- statnr - Statistics
Utilities
- nodash - Utility functions
- noir_base64 - Base64 encoding
- noir-date - Date handling
- noir-json-parser - JSON parsing
- noir-sort - Sorting algorithms
- noir_string_search - String search
- noir-u2b - Unit conversions
- noir_check_shuffle - Shuffle verification
- op_rand - Random number generation
- CSPRNG - Cryptographically secure RNG
Application-Specific
- zk-regex - Regex in ZK
- noir-jwt - JWT verification
- noir-social-verify - Social verification
- noir_webauthn - WebAuthn
- noir-hydra - Hydra protocol
- 2D-Doc - 2D document handling
- poseidon2 solidity noir-compatible - Poseidon2 for Solidity
Meta
- zk-kit - ZK toolkit
- noir-examples - Example projects
Courses & Learning
- Zero-Knowledge Proofs for Blockchain - Complete blockchain course
- aztec-noir-course - Aztec-focused course
- Noir Programming And ZK Circuits - Cyfrin course
- zkml-course-Noir - zkML in Noir
- BattleZips Noir - Game development
- NodeGuardians - Interactive learning
- Noirlings - Interactive exercises
- Noir Puzzles - Practice puzzles
Workshops & Conferences
- NoirHack - Hackathon
- NoirCon 0 - First conference
- NoirCon 1 - Second conference
- NoirCon 2 - Third conference
- NoirCon 3 - Fourth conference
- Noir Xmas Camp - Winter bootcamp
- Noir on Scroll - Integration workshop
- Painless Zero-Knowledge Circuitry with Noir - Workshop
- Build your first ZK App with Noir - Getting started
- Noir the zkDSL - Language overview
- 🇪🇸 Como crear un token con privacidad - Private tokens
- The Path to Designing Awesome ZK Circuits - Circuit design
- coNoir - Collaborative proving
Articles & Guides
- Understanding the Technical Aspects of Aztec and Noir - Technical deep dive
- 🇪🇸 Noir 101 para Solidity devs - For Solidity developers
- Privacy-Preserving KYC - KYC applications
- An Incomplete Guide to zk-KYC apps - Building KYC apps
- Noirky2: how we made a Plonky2 proving backend for Noir - Backend development
- How to Build a Decentralized Voting Application with Noir - Voting tutorial
Low-level circuit language for arithmetic circuits.
Official Resources
- Circom2 Documentation - Official docs
- Circom Repository - Source code
- Circom 101 - Community gitbook
- circomlib - Standard library
Development Tools
- zkrepl - Online playground
- VS Code Plugin - Syntax highlighting
- circomspect - Circuit linter
- SHIELD - Development framework
- hardhat-zkit - Hardhat integration
Libraries
- circom-ecdsa - ECDSA signatures
- circom-pairing - Pairing operations
- zk-attestor - Attestations
- circom-keccak256 - Keccak hash
Boilerplates
- circom-starter - Basic starter
- hardhat-zkit - Hardhat template
Learning Resources
- 0xparc Circom - Official course
- Battlezips Circom Tutorial - Video series
- Circom Puzzles - Practice problems
Articles
- Introducing Hardhat ZKit - Improved development workflow
- zkSNARKS, Circom (Part 1) - Practical guide
- zkSNARKS, Circom (Part 2) - Advanced topics
- 🇪🇸 Como crear juegos 100% on-chain con ZK - ZK gaming
- 🇪🇸 Como funcionan los prestamos privados ZK - Private lending
Rust-based proving system without trusted setup.
Resources
- Halo2 Book - Official documentation
- 0xparc Halo2 - Learning course
- Halo2 zkSecurity - Security-focused guide
- Building a Zero Knowledge web app with Halo2 and Wasm - Tutorial
- Latest developments in Halo2 by Ying Tong Lai - Updates
- zk-languages - Comprehensive list of ZK languages
Frameworks, toolkits, and utilities for ZK development.
- mopro - Mobile proving toolkit
- co-snarks - Collaborative SNARK proving
- marlin - Infrastructure toolkit
- CRYPTOHACK ZKP Challenges - Practical challenges
- zkctf-2023-writeups - CTF solutions
- zkhack Puzzles - Educational puzzles
Specialized tools and protocols.
- MACI - Voting infrastructure
- MACI Workshop - Tutorial
- 🇪🇸 Construyendo votaciones privadas onchain con MACI - Building private voting
- Semaphore - Privacy layer
- Fundamentals of Zero-Knowledge Proofs (ZKPs) - Comprehensive fundamentals
- 🇪🇸 Zero Knowledge Proofs - ESP - Spanish bootcamp
- ZKML Course - Machine learning with ZK
- zkForge 2025 - Recent bootcamp
- ZK & Privacy Bootcamp - Privacy-focused
- 🇪🇸 Bootcamp de Programmable Cryptography - Programmable cryptography
- ZK Speedrun: 3 DSL in 15 minutes - Language comparison
- Solidity Dev to ZK dev - Transition guide
- 🇪🇸 ZK para devs de Solidity - For Solidity developers
- 🇪🇸 Desarrollo de ZK en Solidity para principiantes - Beginner-friendly
- 🇪🇸 el MEJOR tutorial de ZK que vas a encontrar - Comprehensive tutorial
- ZK dApps - Why, What and How? - Building dApps
- ZK Whiteboard Sessions - Video explanations
- Introduction to Zero Knowledge - Introduction
- How I learn ZK - Learning approach
- FHE eats ZK for breakfast - FHE vs ZK
- Private Machine Learning with zkML - zkML introduction
- Programmable Cryptography and Smart Contracts - Integration
- ZK Application Design Patterns - Design patterns
- ZKMPC: Bring public auditability into MPC - ZK-MPC hybrid
- The combination of ZKP +/- MPC +/- FHE - Technology combinations
- Building Consumer Apps with ZK, MPC, and FHE - Consumer applications
- Optimising AI Verifiability with zkML Proofs - AI verification
- 🇪🇸 Identidad web3 - Web3 identity
- 🇪🇸 Más allá del JWT: Autorización sin identidad con ZK proofs - Authorization
- How to ZK: Noir vs Circom - Language comparison
- Generating ZK proofs in browser today - Browser proving
- 🇪🇸 PII, privacidad y zero-knowledge proofs - Privacy and PII
- Distribute your ZK with coSNARKS - Distributed proving
- Breaking the Gas Ceiling: How I Built a ZK Coprocessor for Ethereum in Rust - Coprocessor development
- Ethereum's Next Revolution: Privacy by Default - Privacy future
- 🇪🇸 Un PM de Ethereum Foundation Comparte su Sabiduría sobre Web3 y ZK - Ethereum perspective
- 🇪🇸 Tips para aprender ZK y criptografía - Learning tips
- ZKID - Identity podcast
- ZK Regex - Regex in ZK
- What will we get if we put together ZKP, MPC, FHE, and TEE? - Technology combinations
- 🇪🇸 KZG y otra cosas criptograficas - Cryptographic concepts
Use cases and application domains for Zero-Knowledge Proofs.
- Check your user humanity, nationality or age with privacy-preserving ID proofs - Privacy-preserving verification
- Putting Identities On-Chain - On-chain identity
- ZK Badges: A new primitive for self sovereign identities - Badge system
- 🇪🇸 Identidades ZK Descentralizadas y el poder del blockchain - Decentralized identity
- ZKML: Verifiable Machine Learning using Zero-Knowledge Proof - ML verification
- Build Your Own ZK Email Proofs, ZK Email Login, or ZK Account Recovery Module - Email applications
- Privacy in Cryptocurrencies: An Overview - Privacy overview
Real-world implementations and applications.
- SafeRecover - Account recovery
- ZCaptcha - Privacy-preserving CAPTCHA
- ZKPic - Picture authentication
- SafeCat - Safe authentication
- ZKLogin - ZK-based login
- Safe Anonymization Mail Module - Anonymous email
- zkSafe - Safe wallet
- dark-safe - Privacy-focused safe
- BattleZips - ZK battleship
- Dark Forest - MMO strategy game
- Sudoku, Wordle, and Trivia - Classic games
- ZK-AntiCheat - Anti-cheat system
- terry-escape - Escape game
- zk-hangman-noir - Hangman
- MACI - Anti-collusion voting
- Semaphore - Anonymous signaling
- zkvot - Voting system
- Nouns Anonymous Voting - DAO voting
- Tornado Cash - Token mixer
- Mezcal - Privacy protocol
- Privacy Pools - Compliant privacy
- Anon Aadhaar - Anonymous Aadhaar proofs
- Self - Self-sovereign identity
- ZKPassport - Passport verification
- Rarimo - Passport circuits
- zkID - Private identity
- Worldcoin - Proof of personhood
- QuarkID - SSI implementation
- Educational zk-KYC app - KYC learning
- FruityFriends - Social connections
- Rate Limiting Nullifiers - Spam prevention
- ZKEmail - Email proofs
- Stealthnote - Anonymous notes
- anoncast - Anonymous broadcasting
- Interep - Reputation system
- Railgun - Private DeFi
- Panther Protocol - Privacy layer
- ZETH - Private transactions
- zkDocs - Document verification
- Graphite - Private graphs
- zkVRF - Verifiable randomness
- AnonRadar - Privacy analytics
- zkMaps - Private location
- stealthdrop - Anonymous airdrops
- zknftmint - NFT minting
- Past Hackathon Winners - Inspiration
Major conferences and event recordings.
- ZKProof 7 Day 1 - Latest workshop
- ZKProof 7 Day 2
- ZKProof 7 Day 3
- ZKProof 6 Day 1 - Previous edition
- ZKProof 6 Day 2
- ETHGlobal ZK - ETH-focused ZK
- Ethereum Cypherpunk Congress #2 - Privacy-focused
- Ethereum Privacy Stack 2025 - Privacy developments
- Web3Privacy stage x Dappcon 2025 - Web3 privacy
- 🇪🇸 Aleph ZK Week - ZK deep dive
- 🇪🇸 ZK Workshop By Ethereum Uruguay - ZK deep dive
- Verifying Intelligence 3.0 (Buenos Aires) - Intelligence verification
- The ZK/AI Summit - ZK and AI
Contributions are welcome! Please read the contribution guidelines first.