Zero-Knowledge Proofs
zkp.science
zkp.science
Also, the code powering each cryptocurencies isn’t immutable. People adopt changes; just not at the same pace as most other pieces of software.
Also, argument of authority: I work for a wallet provider
These proof systems are parameterized to ensure a certain soundness error, like 2^-128. So as long as certain cryptographic assumptions hold (in the case of SNARKs, the hardness of knowledge-of-exponent and commitments), it would take an attacker an expected 2^128 brute force attempts to generate an invalid proof. That should remain the same no matter how deep the recursion goes.
Also, though I haven't read the CODA paper either, I think they would only need a single fixed circuit containing a SNARK verifier. Since for a given security level, SNARK sizes and verification steps are constant.
[0] https://benchmarksgame-team.pages.debian.net/benchmarksgame/ [1] https://eprint.iacr.org/2017/1132.pdf (Section 8) [2] https://eprint.iacr.org/2018/046.pdf (Section 1.3.2)
It has very practical proof times and sizes for a certain range of circuit sizes. E.g. we can prove knowledge of a LowMC-256 key with ~40kb, making it on par with SPHINCS for post-quantum signatures. No implementation yet, but they're working on one.
[1]: https://jeremykun.com/2016/07/05/zero-knowledge-proofs-a-pri...
[2]: https://jeremykun.com/2016/08/01/zero-knowledge-proofs-for-n...
[3]: https://jeremykun.com/2016/09/19/zero-knowledge-definitions-...