Lune

CCS2026Top-tier venue

The Billion Dollar Merkle Tree

Thomas Coratger, Dmitry Khovratovich, Bart Mennink, Benedikt Wagner

2026Year

Abstract

The Plonky3 Merkle tree implementation has become one of the most widely deployed Merkle tree constructions due to its high efficiency, and-through its integration into numerous succinct-argument systems-it currently helps secure an estimated $4 billion in assets. Somewhat paradoxically, however, the underlying 2-to-1 compression function is not collision-resistant, nor even one-way, which at first glance appears to undermine the security of the entire Merkle tree. The prevailing ad-hoc countermeasure is to pre-hash data before using them as leaves in this otherwise insecure Merkle tree. In this work, we provide the first rigorous security analysis of this Merkle tree design and show that the Plonky3 approach is, in fact, sound. Concretely, we show (strong) position-binding and extractability.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 3e13f408-6475-4e07-a5ba-800a8eaf7b03

Builds on4

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines