Paper 2026/2165

Argo: Leaking a Secret from an Invalid Groth16 Proof

Liam Eagen, Glass Coins
Ying Tong Lai, Glass Coins
Abstract

We present Argo, a randomized encoding scheme for the invalidity of pairing-based SNARKs like Groth16. Argo allows an encoder to encode a proof such that a decoder can derive a secret if the proof is invalid. We prove the selective security of invalidity Argo, as well as the adaptive security of validity Argo, under DDH in one source group of a bilinear pairing in the standard model, a standard assumption that holds in the generic group model used to analyze Groth16. We show how to couple invalidity Argo with a projective garbling scheme like Argo MAC or Duty-Free Bits to construct a garbled circuit for Groth16 invalidity as a function of the proof bits, and how to use it with BitVM to construct a permissionless, optimistic Groth16 verifier for Bitcoin: a decoder proves a proof invalid by publishing a secret, and the decoder can be anyone, not necessarily known in advance. When instantiated with BN254, Argo has an offline encoding size of about 21 kB, a thousand times smaller than the projective garbling scheme, and an end-to-end protocol size more than three orders of magnitude smaller than existing Yao-based approaches. Generating an Argo + Argo MAC garbled circuit takes tens of milliseconds on a laptop, compared to minutes for a Yao GC. Argo is the first protocol that makes permissionless, optimistic SNARK verification on Bitcoin practical.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Garbled CircuitsZero-Knowledge Proofs
Contact author(s)
liameagen @ protonmail com
yingtong lai @ gmail com
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2165
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2165,
      author = {Liam Eagen and Ying Tong Lai},
      title = {Argo: Leaking a Secret from an Invalid Groth16 Proof},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2165},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2165}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.