Paper 2026/089

The Billion Dollar Merkle Tree

Thomas Coratger, Ethereum Foundation
Dmitry Khovratovich, Ethereum Foundation
Bart Mennink, Maastricht University
Benedikt Wagner, Ethereum Foundation
Abstract

The Plonky3 Merkle tree implementation has become one of the most widely deployed Merkle tree constructions due to its high efficiency, and—through its integration into numerous succinct-argument systems—it currently helps secure an estimated \$4 billion in assets. Somewhat paradoxically, however, the underlying 2-to-1 compression function is not collision-resistant, nor even one-way, which at first glance appears to undermine the security of the entire Merkle tree. The prevailing ad-hoc countermeasure is to pre-hash data before using them as leaves in this otherwise insecure Merkle tree. In this work, we provide the first rigorous security analysis of this Merkle tree design and show that the Plonky3 approach is, in fact, sound. Concretely, we show (strong) position-binding and extractability.

Note: Added acks and publication note.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. ACM CCS 2026
Keywords
Merkle TreesPlonky3SNARKsVector Commitments
Contact author(s)
thomas coratger @ ethereum org
khovratovich @ gmail com
bart mennink @ maastrichtuniversity nl
benedikt wagner @ ethereum org
History
2026-07-22: revised
2026-01-20: received
See all versions
Short URL
https://ia.cr/2026/089
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/089,
      author = {Thomas Coratger and Dmitry Khovratovich and Bart Mennink and Benedikt Wagner},
      title = {The Billion Dollar Merkle Tree},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/089},
      year = {2026},
      url = {https://eprint.iacr.org/2026/089}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.