Zero-knowledge and post-quantum verifiers in Bitcoin Script
- Problem
- Verify modern proofs and signatures directly in layer-1 script, with no protocol change and no trusted off-chain verifier.
- Built
- RSA, BLS12-381 pairing, Groth16 and SLH-DSA verifiers written as BSV Script, plus an equivalence-proven superoptimizer for Script.
- Result
- All four executed on mainnet in ~1.25 MB transactions. The optimizer cut a 333 KB pairing script by 40%.