Key Points

  • A zk-rollup is a Layer 2 network that bundles many transactions, runs them off Ethereum, and posts the results to Ethereum with a cryptographic proof that they are correct.
  • The proof, called a validity proof, lets Ethereum confirm a whole batch without re-running every transaction.
  • Because each batch is proven rather than assumed, withdrawals to Ethereum do not need the week-long challenge period that optimistic rollups use.
  • Generating proofs takes heavy computation, and most zk-rollups still rely on a single operator and upgradeable contracts.
  • Not every network that uses zero-knowledge proofs is a rollup. If the transaction data is not posted to Ethereum, it is a validium, which carries different risks.

Quick Answer

A zk-rollup is a way to scale Ethereum by processing transactions off the main chain and then proving to Ethereum, with cryptography, that the results are correct. It collects thousands of transactions into a batch, posts the compressed data to Ethereum and attaches a validity proof that Ethereum checks before accepting the batch. Read it as a Layer 2 that inherits Ethereum's security through maths rather than through a waiting period. The common misread is that "zero-knowledge" means your transactions are private. On most zk-rollups they are just as public as on Ethereum.

What is a zk-rollup?

A zk-rollup is a Layer 2 network that executes transactions away from Ethereum and settles them on Ethereum with a proof of correctness. It gives users lower fees and faster confirmation while keeping Ethereum as the final record.

It is one of two main rollup designs. The other is the optimistic rollup, which assumes batches are valid unless someone challenges them. Our guide to Layer 1 and Layer 2 blockchains compares the two and explains why rollups exist in the first place.

How does a zk-rollup work?

  1. Collect. Users send transactions to the rollup, usually through an operator called a sequencer, which puts them in order.
  2. Execute. The rollup runs the transactions on its own system and works out the new balances.
  3. Prove. A prover generates a validity proof showing that the new balances follow correctly from the old ones and the transactions.
  4. Post. The rollup posts the compressed transaction data and the proof to a contract on Ethereum.
  5. Verify. The Ethereum contract checks the proof. If it is valid, the new state is accepted as final.

Checking a proof is far cheaper than re-running every transaction, which is where the saving comes from. And because the data itself is posted to Ethereum, anyone can rebuild the rollup's balances from it if the operator disappears.

What is a validity proof?

A validity proof is a short piece of cryptography that shows a computation was done correctly without anyone needing to repeat it. The two main families are SNARKs and STARKs.

  • SNARKs produce very small proofs that are cheap to verify on Ethereum. Many designs rely on an initial setup step that has to be done honestly.
  • STARKs avoid that setup step and are considered more resistant to future advances in computing, but their proofs are larger. Starknet uses STARKs.

The "zero-knowledge" in the name refers to proof systems that can show something is true without revealing the underlying details. In practice, most zk-rollups use these proofs for correctness, not secrecy, and publish the transaction data openly.

How are zk-rollups different from optimistic rollups?

The difference is how Ethereum is convinced a batch is correct.

  • Optimistic rollups such as Arbitrum One, OP Mainnet and Base assume batches are valid and give anyone about seven days to submit a fraud proof. Withdrawals through the official bridge wait out that window.
  • Zk-rollups such as zkSync Era, Starknet, Linea and Scroll prove every batch up front. Once the proof is verified, the batch is final, so withdrawals usually take hours rather than a week, depending on how often proofs are posted and any safety delay the network adds.

Optimistic rollups have been simpler to build and to make compatible with existing Ethereum applications. Zk-rollups have faster finality but harder engineering, especially when they try to run Ethereum's smart contracts exactly as Ethereum does.

What is a zkEVM?

A zkEVM is a zk-rollup that can run Ethereum-style smart contracts and generate proofs for them. The EVM, or Ethereum Virtual Machine, is the engine that runs Ethereum's smart contracts. Early zk-rollups could only handle simple payments; zkEVMs let developers deploy many of the same applications they use on Ethereum.

zkEVMs differ in how closely they match Ethereum. The closer the match, the easier it is for existing applications to move across, but the harder and more expensive the proofs become. Some networks, such as Starknet, use their own programming language instead and accept that developers must write code specifically for them.

What is the difference between a zk-rollup and a validium?

A zk-rollup posts its transaction data to Ethereum. A validium uses the same kind of validity proofs but keeps the data elsewhere, often with a small committee.

That makes a validium cheaper to run, but it changes the risk. If the data is withheld, users may be unable to prove what they own and withdraw, even though the proofs show the balances are correct. When you see a network described as using zero-knowledge technology, check where its data is posted before treating it as a rollup.

What are the risks of using a zk-rollup?

  • Upgradeable contracts. Most zk-rollups can still have their Ethereum contracts changed by a small group or a security council.
  • A single sequencer and prover. If the operator stops, transactions can stall. Some networks offer a slower route that lets users force a withdrawal through Ethereum.
  • Complex cryptography. Proof systems are new and intricate. A bug in a circuit or a verifier could, in principle, let an invalid batch through.
  • Bridge choices. Third-party bridges can be faster than the official route but add their own smart contract risk. Our bridges guide covers what to look for.

L2BEAT, an independent research site, rates rollups in stages from 0 to 2 according to how much they depend on their operators. Checking a network's stage before you hold funds there is a quick way to see how much trust you are placing in people rather than code.

Frequently Asked Questions

Are zk-rollup transactions private?

On most zk-rollups, no. The proofs confirm correctness, and the transaction data is published. A few projects use zero-knowledge proofs for privacy, but that is a separate design goal.

Do I need a special wallet?

For Ethereum-compatible zk-rollups, common Ethereum wallets work once you add the network. Starknet uses its own account model, so it needs a wallet that supports it.

Which token pays the fees?

On most Ethereum zk-rollups, fees are paid in ETH. Some networks also accept or prefer their own token, so check the network's documentation.

Are zk-rollups better than optimistic rollups?

Neither is better in every case. Zk-rollups offer faster finality on withdrawals; optimistic rollups have been simpler to build and run. How a specific network is governed often matters more to users than which design it uses.

Every call, scored

We publish each market call with its date and the condition that would prove it wrong, then score it when it resolves, misses included. Anyone can check.

See the record

Further Reading

Sources

  • Ethereum documentation, zero-knowledge rollups: ethereum.org/developers/docs/scaling/zk-rollups
  • L2BEAT, rollup risk framework and stages: l2beat.com

This article is for education only and is not financial, investment or legal advice. Crypto assets are volatile and you can lose some or all of the money you put in. Layer 2 networks, bridges and smart contracts carry technical risks, including bugs, operator failure and loss of funds. Do your own research and consider independent advice before making any financial decision.