Paper 2026/812

Mosaic: Practical Malicious Security for Garbled Circuits on Bitcoin

Nakul Khambhati, Alpen Labs, University of California, Los Angeles
Mukesh Tiwari, Alpen Labs
Azz, Alpen Labs
Sapin Bajracharya, Alpen Labs
Manish Bista, Alpen Labs
Liam Eagen, Ideal Group
Christian Lewe, Alpen Labs
Aaron Feickert, Alpen Labs
Abstract

Bitcoin's scripting language cannot verify arbitrary computation natively, yet applications such as trust-minimized bridges depend on this capability. Recent techniques employ garbled circuits: the prover commits off chain to a garbled circuit encoding a verifier, designed so that evaluating it on an invalid witness reveals a secret. Posting that secret on chain serves as a fraud proof, allowing the verifier to claim the prover's stake without any on-chain computation. To evaluate the garbled circuit and recover the secret, the verifier needs the prover's input labels, which the prover must post on chain. Since Bitcoin charges permanently for block space, minimizing this on-chain footprint is a primary design concern. Achieving malicious security via cut-and-choose compounds this: the prover must produce multiple independently garbled copies of the circuit, requiring one set of labels per copy. We present Mosaic, a protocol that achieves malicious security via cut-and-choose but reduces the on-chain footprint so that it is independent of the number of garbled copies. The key technique, first introduced by Eagen (Glock, 2025) in this setting, is polynomial label correlation: labels across all $N$ garbled copies are arranged as evaluations of a degree-$t$ polynomial, so the $t$ shares revealed during cut-and-choose fall one short of the reconstruction threshold. We use adaptor signatures to arrange that the prover's on-chain witness commitment reveals the missing share as a byproduct; the evaluator then reconstructs labels for all unchallenged copies by interpolation. We sketch why Mosaic is secure against a malicious prover and verifier and instantiate it for trust-minimized Bitcoin bridging with a Groth16 verifier circuit, a full protocol specification, and a Rust implementation.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Garbled CircuitsBitcoin
Contact author(s)
nakul @ alpenlabs io
mukesh @ alpenlabs io
aaron @ alpenlabs io
History
2026-07-15: revised
2026-04-24: received
See all versions
Short URL
https://ia.cr/2026/812
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/812,
      author = {Nakul Khambhati and Mukesh Tiwari and Azz and Sapin Bajracharya and Manish Bista and Liam Eagen and Christian Lewe and Aaron Feickert},
      title = {Mosaic: Practical Malicious Security for Garbled Circuits on Bitcoin},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/812},
      year = {2026},
      url = {https://eprint.iacr.org/2026/812}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.