Ethereum's better.codes contest now measures a cryptographic proof gap that researchers can attack from both sides.
Ethereum's better.codes contest now measures a cryptographic proof gap that researchers can attack from both sides.

Ethereum's better.codes contest now measures a cryptographic proof gap that researchers can attack from both sides.
A 52.14-bit gap separates the soundness and attack certificates on Ethereum's better.codes leaderboard, leaving the zkEVM proof system short of the 128-bit target the Foundation set for early December.
The Ethereum Foundation's launch announcement pins the theorem statement, parameter point, and verification harness, with each submission exported, checked against the target by a comparator, and verified by the Lean kernel before promotion.
At 15:44:47 UTC on Aug. 21, the live leaderboard showed a 63.99-bit lower certificate and a 116.13-bit upper certificate for koalaIRS12, a fixed parameter profile for an interleaved Reed–Solomon reduction used in proof-system research. Nine promoted submissions from seven solvers left the interval open.
The December M3 milestone requires 128-bit provable security, a final proof size of 300 KiB or less, and a formal soundness argument for the recursion architecture — a production case that depends on how the koalaIRS12 component evidence fits into the larger proof.
The contest uses two tracks to close the interval. The soundness track raises the lower certificate: at a certified radius, a successful submission proves the benchmark's executable reduction-error bound meets the encoded target, then maps that radius to the score. The attack track lowers the upper certificate, certifying an unsafe suffix under the benchmark's winning-set-density condition.
The challenge repository defines the score as a spot-check quantity and expressly excludes interpreting it as minus-log2 of whole-system soundness or full-protocol security. An accepted result proves the submitted theorem inside the pinned environment; production assurance must also cover the model's completeness, embedded assumptions, implementation fidelity, and the composition of separately analyzed components.
The Foundation's May review of an SP1 formal-verification effort shows why those layers matter: specifications and theorem statements are code, inputs and versions need reproducible pinning, and component-level results require broader reasoning before they support conclusions about a full system. An academic paper by Gal Arnon, Dan Boneh and Giacomo Fenzi identifies list decoding, Reed–Solomon proximity gaps, correlated agreement and mutual correlated agreement as open questions for succinct proof systems.
The Foundation's December 2025 zkEVM security roadmap called for 128-bit provable security, a final proof size of 300 KiB or less, and a formal soundness argument for the recursion architecture. A February security-sprint update moved the M3 deadline to early December 2026 and aligned the architecture-security argument with a Dec. 1 deliverable.
For koalaIRS12, a lower certificate reaching the encoded 128-bit target would settle the soundness side of this benchmark at its fixed parameter point. A production zkEVM claim would additionally need soundness accounting across every relevant component, proof-size compliance, a documented recursion topology, and evidence that specifications match implementations.
The Foundation's public progress page, last synced Aug. 20, lists zkVM readiness and ISA compliance results and names real-time proving and soundcalc integration as criteria, but contains no completion marker for the full early-December package. A May update on optional execution proofs described a non-consensus-critical phase in which zkEVM proofs supplement mainnet testing while ordinary execution-client re-execution continues to drive attestation.
That optional role keeps the leaderboard's immediate consequence in the research domain. Movement in the certificates changes the evidence available for future security arguments without changing Ethereum's current consensus-critical validation path. On better.codes, soundness submissions can lift the 63.99-bit lower certificate and attack submissions can pull the 116.13-bit upper certificate down. At present, the 52.14-bit interval is a live measure of unfinished work on koalaIRS12, and Ethereum's 128-bit production case will depend on how that component evidence fits into the larger proof.
This article is for informational purposes only and does not constitute investment advice.