Paper 2026/089
The Billion Dollar Merkle Tree
Abstract
The Plonky3 Merkle tree implementation has become one of the most widely deployed Merkle tree constructions due to its high efficiency, and—through its integration into numerous succinct-argument systems—it currently helps secure an estimated \$4 billion in assets. Somewhat paradoxically, however, the underlying 2-to-1 compression function is not collision-resistant, nor even one-way, which at first glance appears to undermine the security of the entire Merkle tree. The prevailing ad-hoc countermeasure is to pre-hash data before using them as leaves in this otherwise insecure Merkle tree. In this work, we provide the first rigorous security analysis of this Merkle tree design and show that the Plonky3 approach is, in fact, sound. Concretely, we show (strong) position-binding and extractability.
Note: Added acks and publication note.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2026
- Keywords
- Merkle TreesPlonky3SNARKsVector Commitments
- Contact author(s)
-
thomas coratger @ ethereum org
khovratovich @ gmail com
bart mennink @ maastrichtuniversity nl
benedikt wagner @ ethereum org - History
- 2026-07-22: revised
- 2026-01-20: received
- See all versions
- Short URL
- https://ia.cr/2026/089
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/089,
author = {Thomas Coratger and Dmitry Khovratovich and Bart Mennink and Benedikt Wagner},
title = {The Billion Dollar Merkle Tree},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/089},
year = {2026},
url = {https://eprint.iacr.org/2026/089}
}