zkVM and Fraud Proofs
Optimistic-ZK execution verification — any party can challenge incorrect state transitions.
Design
Vela uses an optimistic-ZK design. Batches are published optimistically — the operator does not need to produce a validity proof for every batch, which would be computationally expensive. Instead, batches are assumed correct unless challenged.
Any party with access to the DA layer data can challenge any batch by running the fraud proof verification locally. If the operator published an incorrect state root, the verification will detect the discrepancy and produce a fraud proof. In the target post-M6 system, this fraud proof can be submitted on-chain to slash the operator.
How Fraud Proof Generation Works
- The challenger fetches the pre-batch state snapshot and the batch transaction log from the DA layer.
- A fresh matching engine instance is seeded from the pre-batch state snapshot. This recreates the exact engine state at the beginning of the challenged batch.
- The challenger re-executes all requests in the batch, in order, using the same deterministic matching algorithm.
- The resulting state is hashed to produce a local state root.
- The local state root is compared to the state root published by the operator in the DA layer.
- If the roots match: the batch is correct. If they diverge: a fraud proof is generated, containing the pre-batch snapshot, the batch data, and the diverging outputs.
Determinism Requirement
The entire system depends on the matching engine being perfectly deterministic. Given the same pre-state and the same ordered sequence of requests, it must produce byte-for-byte identical output every time, on every machine. This is why the engine uses fixed-point arithmetic, a single thread with no concurrency, and no system calls on the hot path.
Current Status
The zkvm crate implements the fraud proof logic and can be run locally against any published batch. On-chain verification — where a smart contract validates the fraud proof and enforces slashing — is the M6 roadmap milestone. Until then, fraud proofs are informational: they prove operator misbehavior but cannot enforce consequences.