Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
ZK rollups batch transactions and settle a validity proof on Ethereum, cutting fees to cents and finality to minutes.
A ZK rollup is a Layer 2 network that batches thousands of transactions offchain, then submits a single cryptographic validity proof to Ethereum that guarantees every transaction in the batch was executed correctly.
That one proof is the key. Ethereum does not need to re-execute every transaction. It only needs to verify the proof — a task that takes milliseconds and costs a fraction of what running those transactions on the main chain would cost. The result is dramatically lower fees and faster finality for you as a user, while security still comes from Ethereum’s own validator set.
If you have run into ZK rollups recently, it is probably because Ethereum mainnet fees have long been a barrier. Sending an ERC-20 token during a congested period in 2023 could cost $10 or more. That same transfer on a ZK rollup today costs cents. Ethereum’s March 2024 EIP-4844 upgrade made this concrete by introducing a cheap dedicated data lane — called blobspace — that cut rollup operating costs roughly tenfold. ZK rollups now handle a significant share of Ethereum stablecoin settlement volume, and Vitalik Buterin has described ZK rollups as Ethereum’s preferred long-term scaling path.
When you submit a transaction to a ZK rollup, it does not go straight to Ethereum. It enters a queue managed by the rollup’s sequencer.
The sequencer collects hundreds or thousands of pending transactions, orders them, and compresses them into a single batch. That compression is where the fee savings begin — instead of each transaction paying separately for Ethereum blockspace, everyone in the batch shares the cost.
After the sequencer builds the batch, it hands the computation off to the prover. The prover is software — sometimes purpose-built hardware — that runs a set of mathematical checks over the entire batch and produces a validity proof. That proof is a compact cryptographic object encoding one claim: every transaction in this batch executed correctly, and the resulting account balances are what I say they are.
That proof, along with the compressed batch data, is submitted to a verifier smart contract on Ethereum mainnet. The verifier checks the proof. If it passes, the batch is accepted and the rollup’s state root — a cryptographic fingerprint of every account balance and contract state on the rollup — is updated on L1. If the proof fails, the batch is rejected outright. There is no appeal. The math either works or it does not.
The phrase “zero-knowledge” can mislead. It does not mean your transactions are private. It refers to the property that the proof can convince Ethereum the batch was correct without Ethereum having to replay each individual computation. Think of it as a credential that says “I did the work — here is the proof” rather than “here is every step.” Privacy is not included by default. All transaction data is still posted publicly so Ethereum can reconstruct state if needed.
One important variant is the zkEVM. A zkEVM is simply a ZK rollup whose execution environment matches Ethereum’s own virtual machine, so standard Ethereum smart contracts and developer tools work without modification. Most production ZK rollups today are zkEVMs.
For a deeper look at how validity proofs work as a cryptographic primitive, the zero-knowledge proof guide covers the underlying math in plain English.
Two cost components show up in every ZK rollup transaction. The first is the L1 verification cost — the gas paid to the Ethereum verifier contract when a proof batch is submitted. Because this cost is split across every transaction in the batch, it becomes tiny per transaction. The second is the data availability cost — the fee paid to post compressed transaction data to Ethereum so the chain can always reconstruct the rollup’s state.
The data availability cost used to be the more expensive of the two. Rollups had to post their data as expensive Ethereum calldata, which competed directly with other L1 transactions for blockspace. EIP-4844, implemented in March 2024, changed that by introducing blob transactions — a cheaper data lane attached to Ethereum blocks that is specifically designed for rollup payloads. Blobs are priced separately from calldata and pruned automatically after about 18 days. The practical effect was a cost drop of roughly 10x for ZK rollup users almost overnight.
Here is what fees on the major ZK rollups look like today:
| Transaction Type | Typical ZK Rollup Fee (Post-EIP-4844) |
|---|---|
| Simple ETH transfer | $0.01 – $0.05 |
| ERC-20 token transfer | $0.03 – $0.10 |
| Simple DEX swap | $0.10 – $0.30 |
| Complex DeFi interaction | $0.30 – $1.00+ |
More complex transactions cost more because complexity increases both the size of the validity proof and the amount of data that must be posted. A basic ETH transfer involves almost no state change. A multi-hop liquidity pool swap touching three contracts touches far more state and produces a larger proof.
For context, a simple ETH transfer on Ethereum mainnet during moderate congestion has historically cost between $1 and $10. On a ZK rollup after EIP-4844, the same transfer costs a couple of cents. The blob fee mechanics page explains how that new pricing layer works, and the dedicated blobspace data lane explains why this separate pricing layer exists and how it fits into Ethereum’s broader roadmap.
The core split between ZK rollups and optimistic rollups is about when validity is proven. A ZK rollup proves correctness upfront — no batch gets accepted on Ethereum unless a valid proof accompanies it. An optimistic rollup assumes transactions are correct and posts them to L1 without a proof, but leaves a 7-day window for a watcher to submit a fraud proof if something was wrong. This single design choice drives nearly every other difference between the two approaches.
The most practical difference for a user is withdrawal time. ZK rollup withdrawals take 15 to 45 minutes from when the rollup submits the proof batch to Ethereum. Optimistic rollup withdrawals require the full 7-day challenge window before funds are finalized on L1. Fast-bridge protocols can shorten the wait, but they add their own smart contract layer.
The security models also differ. With a ZK rollup, the validity proof is a mathematical guarantee — no invalid state can reach L1 because the verifier contract would reject a bad proof. With an optimistic rollup, security depends on at least one honest, well-funded actor watching the chain and submitting a fraud proof in time. That assumption is probably correct in practice, but it is a social guarantee rather than a cryptographic one.
| ZK Rollup | Optimistic Rollup |
|---|---|
| Validity proof verified by Ethereum L1 contract | Fraud proof window — 7 days |
| Withdrawals: 15 – 45 minutes | Withdrawals: 7 days (without fast bridge) |
| Cryptographic guarantee of correctness | Honest-watcher assumption |
| EVM compatibility varies (most are zkEVMs now) | Generally high EVM compatibility |
| zkSync Era, Starknet, Scroll, Linea | Arbitrum, Optimism |
Fees are roughly similar for simple transfers on both rollup types today after EIP-4844. ZK rollups can be marginally more expensive for very complex contract logic because the prover must generate a larger proof. Optimistic rollups can carry higher fees when fraud-proof overhead is factored in, though this is rarely the dominant cost in practice.
Arbitrum and Optimism still lead in total value locked across all rollup types. But ZK rollups have surpassed optimistic rollups in stablecoin settlement volume — a sign of growing institutional trust in the validity-proof model.
When you ask “can the team steal my funds?” about a ZK rollup, the honest answer is no — but the reasoning is worth understanding.
The sequencer controls the order of transactions in the rollup. In most production ZK rollups today, this is a single permissioned server run by the project team. That sequencer can delay your transaction. It can prioritize certain users or decline to include yours in the next batch — a form of censorship. What it cannot do is approve an invalid state transition. The verifier contract on Ethereum L1 would reject any proof that attempts to finalize a fraudulent state, including a proof that shows your balance drained without your authorization. The validity proof is what protects against theft, and it is not under the sequencer’s control.
Most production ZK rollups have a forced-transaction escape hatch for exactly this scenario. If the sequencer censors your transaction, you can submit it directly to the L1 smart contract, bypassing the sequencer entirely. The sequencer must then include your transaction or the rollup stops processing new batches. This mechanism exists in zkSync Era, Starknet, and Scroll, though the exact rules vary by implementation.
The prover role carries a different kind of risk. Generating a validity proof is computationally expensive — today, provers are high-memory servers or specialized hardware. Most production rollups run a single permissioned prover. If that prover goes offline, new batches stop being finalized on L1, which halts new withdrawals. But it does not endanger your funds. The state is always reconstructable from the data posted to L1, and withdrawals resume as soon as proving resumes.
Both zkSync and Starknet have announced timelines for permissionless proving — allowing anyone to run a prover and earn fees for proof generation. As of mid-2026, full decentralization of proving is not complete on any major ZK rollup. The direction is there, but progress is slower than the roadmaps suggested.
Every ZK rollup uses one of two main families of proof systems: ZK-SNARKs or ZK-STARKs. The choice has real implications for security assumptions and, to a smaller degree, for fees.
SNARKs (Succinct Non-interactive Arguments of Knowledge) produce small, fast-to-verify proofs. Their main historical criticism is that they required a trusted setup ceremony — a multi-party computation event used to generate cryptographic parameters. If participants in that ceremony collude and retain their secret contributions, they could theoretically forge proofs. Modern SNARK systems such as UltraPlonk and Halo2 use universal or updatable setups that substantially reduce this risk. The ceremony is no longer a single one-time event, and later participants can update the parameters to eliminate any prior participant’s advantage. For a user of audited production systems like zkSync Era, Scroll, or Linea — all SNARK-based — the practical risk from the trusted setup is minimal.
STARKs (Scalable Transparent Arguments of Knowledge) require no trusted setup at all. Their parameters are derived from public randomness. There is no ceremony, no secret to keep, and no theoretical forgery risk from a compromised setup. STARKs also use hash-based cryptography rather than elliptic-curve pairings, which gives them one important advantage: they are post-quantum resistant. The downside is that STARK proofs are larger than SNARK proofs, which makes them slightly more expensive to verify on Ethereum L1. Starknet is the main production ZK rollup using STARKs.
| Proof System | Projects Using It |
|---|---|
| ZK-SNARK | zkSync Era, Scroll, Linea |
| ZK-STARK | Starknet |
| Proof System | Trusted Setup Required |
|---|---|
| ZK-SNARK | Minimal with modern systems |
| ZK-STARK | None |
| Proof System | Post-Quantum Resistant |
|---|---|
| ZK-SNARK | No |
| ZK-STARK | Yes |
For most users, this distinction rarely decides which ZK rollup to choose. All four major rollups have been audited, run in production, and have not experienced proof-system failures. The SNARK vs STARK question becomes relevant only if you are particularly sensitive to quantum computing risk — in which case Starknet’s STARK-based system is the only production choice today.
Four ZK rollups are meaningfully active on Ethereum as of mid-2026. They differ in proof system, EVM compatibility, developer tooling, and the depth of their DeFi activity. Here is where each one stands.
| ZK Rollup | Key Distinguishing Feature |
|---|---|
| zkSync Era | Native account abstraction, large DeFi ecosystem, SNARK-based |
| Starknet | STARK-based (no trusted setup, post-quantum), Cairo contract language |
| Scroll | Bytecode-equivalent zkEVM, highest EVM compatibility |
| Linea | ConsenSys/MetaMask integration, high daily wallet activity |
zkSync Era, built by Matter Labs, is the largest ZK rollup by TVL and DeFi activity. Its native account abstraction model lets wallets work differently from standard Ethereum wallets — users can pay gas fees in tokens other than ETH and execute batch operations in a single transaction. Most major DeFi protocols are deployed on it.
Starknet, built by StarkWare, is the only major STARK-based rollup in production. Its smart contracts are written in Cairo, a language designed specifically for provable computation. Ethereum Solidity contracts cannot run on Starknet without being rewritten — a meaningful barrier to adoption, but also the reason Starknet can offer tighter control over proving efficiency.
Scroll prioritizes bytecode-level EVM equivalence — a stricter standard than most zkEVMs. Ethereum contracts can be deployed to Scroll with minimal or no modification. The trade-off is that opcode-level proving increases the size of the validity proof and pushes fees slightly higher than some competitors.
Linea, built by ConsenSys, is tightly integrated with MetaMask. A large share of its daily wallet activity comes from MetaMask users who interact with Linea-native DeFi and NFT applications without needing to change their tooling.
One project worth addressing directly: Polygon zkEVM shut down its sequencer on July 1, 2025. The shutdown followed a failure to add EIP-4844 blob support — a costly miss that kept fees high while competitors dropped — combined with operating losses. Funds were automatically moved back to Ethereum L1 for users who had not already withdrawn. The Polygon team pivoted to AggLayer, a cross-chain settlement layer that does not operate as a standalone ZK rollup. The shutdown is a cautionary data point about project survival in a competitive Layer 2 market, not an indictment of ZK technology itself.
For architectures that blend ZK and optimistic approaches, the hybrid rollup page covers where those designs are heading.
Getting funds onto a ZK rollup is a three-step process: hold assets on Ethereum L1, bridge them to the rollup, then transact on the rollup at much lower cost.
The bridge is a smart contract on Ethereum mainnet. You connect your wallet to the rollup’s official bridge interface, select the asset and amount, approve the transaction, and your funds move to the rollup within a few minutes. Once there, your wallet shows your balance on the ZK rollup’s chain, and you can interact with any app deployed on it.
Withdrawing works in reverse. You initiate a withdrawal through the official bridge, the rollup batches your exit transaction with other withdrawals, the prover generates a proof, and when the verifier contract accepts that proof, your funds are released on L1. For ZK rollups, this takes 15 to 45 minutes — far shorter than the 7-day wait on optimistic rollups.
Before you bridge, run through this checklist:
Third-party fast bridges like Across and Stargate can offer faster or cheaper routes in some cases. They carry their own smart contract risk, and the additional protocol layer is worth evaluating before use. The real risk in ZK rollup bridging lives in the bridge contract itself — a bug in the bridge code is a more realistic attack vector than a failure in the proof system. Official bridges are audited. Choosing audited infrastructure is the most practical risk reduction available to you.
If you are moving ETH to a ZK rollup to earn yield, many DeFi strategies on rollups also involve liquid staking tokens rather than raw ETH. Staked ETH derivatives are widely used as collateral and liquidity pool inputs across ZK rollup DeFi.
No. Most ZK rollups are fully transparent. The “zero-knowledge” label refers to the validity proof mechanism, not to transaction privacy. The proof lets Ethereum verify a batch without re-executing every transaction, but all transaction data is still posted publicly on L1 so the rollup state can be reconstructed. Some ZK rollup projects offer optional privacy layers, but that is not a default feature of the ZK rollup model.
Withdrawals typically clear in 15 to 45 minutes once the ZK rollup’s proof batch is accepted on Ethereum. That is far faster than optimistic rollups, which require a 7-day challenge window before funds reach L1. The exact time depends on how frequently the rollup batches transactions and submits proofs — during low activity, batches may take longer to fill.
The ZK rollup security model rests on three things: the soundness of the proof system, the correctness of the verifier contract on Ethereum L1, and data availability. The validity proof means no invalid state can be finalized — the math prevents it. The main residual risks are bugs in the bridge or verifier contract, and sequencer censorship — which can be bypassed via the forced-transaction queue. Your funds cannot be stolen by the operator, because no invalid withdrawal can pass the verifier.
A ZK rollup submits a validity proof with every batch — Ethereum only accepts the batch if the proof verifies. An optimistic rollup assumes transactions are valid and relies on a watcher to submit a fraud proof within 7 days if something is wrong. ZK rollups deliver faster finality and a stronger cryptographic security guarantee. Optimistic rollups have historically had broader EVM compatibility and larger ecosystems, though that gap has narrowed considerably through 2025 and 2026.
It depends on the proof system. ZK rollups using ZK-SNARKs — zkSync Era, Scroll, and Linea — historically required a multi-party trusted setup ceremony. Modern SNARK systems use universal or updatable setups that significantly reduce the trust requirement. Starknet uses ZK-STARKs, which require no trusted setup at all. For a user of any of the audited production ZK rollups running today, the practical risk from any trusted setup ceremony is minimal.
Polygon zkEVM shut down its sequencer on July 1, 2025. The project failed to add EIP-4844 blob support, which kept its fees high while competitors’ fees dropped sharply. Combined with operating losses, the team decided to shut down the rollup and pivot to AggLayer, a cross-chain settlement architecture. Users’ funds were automatically returned to Ethereum L1. The shutdown showed how competitive the ZK rollup market has become — falling behind on infrastructure upgrades is an existential risk for a rollup operator.
If you want to move from reading to using, here are five concrete steps.
The ZK rollup market is competitive and still maturing. Polygon zkEVM’s shutdown is a reminder that even well-funded teams can fall behind. Stick to audited, actively maintained rollups, use official bridges, and check L2Fees.info before bridging a large amount. The technology is sound — the operational hygiene is on you.