BABE: Cheaper Off-Chain SNARK Verification for Bitcoin
A new research paper introduces BABE, a protocol that makes verifying succinct proofs on Bitcoin up to 1000× cheaper off-chain, preserving BitVM3’s on-chain savings while dramatically reducing storage and setup costs.
eprint.iacr.org
🔗
BABE: Verifying Proofs on Bitcoin Made 1000x Cheaper

This paper introduces BABE, a new proof verification protocol on Bitcoin, which preserves BitVM3’s savings of on-chain costs but reduces its off-chain storage and setup costs by three orders-of-magnitude. BABE uses a witness encryption scheme for linear pairing relations [GKPW24] to verify Groth16 proofs. Since Groth16 verification involves non-linear pairings, this witness encryption scheme is augmented with a secure two-party computation protocol implemented using a very efficient garbled circuit for scalar multiplication on elliptic curves.