BABE: Verifying Proofs on Bitcoin Made 1000x Cheaper

Dr. Srivatsan Sridhar
Wednesday, 8th April 2026 | 4:00 PM – 5:00 PM IST
CC105

Endowing Bitcoin with the ability to verify succinct proofs has been a longstanding problem with important applications such as scaling Bitcoin and allowing the Bitcoin asset to be used in other blockchains trustlessly.

It is a challenging problem due to the lack of expressiveness in the Bitcoin scripting language and the small Bitcoin block space. BitVM2, the verification protocol used in several mainnets and testnets, suffers from very high on-chain Bitcoin transaction fees in the unhappy path (over $14,000). BitVM3 dramatically reduced this on-chain cost by using a garbled SNARK verifier circuit to shift most of the verification off-chain, but each garbled circuit is 42 Gibytes in size, so the off-chain storage and setup costs are huge. This talk introduces BABE, a new proof verification protocol on Bitcoin, which preserves BitVM3’s savings of on-chain costs but reduces its off-chain storage and setup costs by three orders of magnitude.

BABE uses a witness encryption scheme for linear pairing relations to verify Groth16 proofs. Since Groth16 verification involves non-linear pairings, this witness encryption scheme is augmented with a secure two-party computation protocol implemented using a very efficient garbled circuit for scalar multiplication on elliptic curves. This is joint work with Dimitris Kolonelos and Sanjam Garg from UC Berkeley and with the Babylon team

 

Speaker Biography

Srivatsan Sridhar is Head of Research at Babylon, building trustless Bitcoin vaults, the first protocol for trustlessly integrating Bitcoin with Ethereum smart contracts. Srivatsan obtained his PhD from Stanford University, advised by Prof. David Tse, where he studied the theory and practice of secure decentralized protocols. Before that, Srivatsan obtained his BTech from IIT Bombay. Srivatsan will be soon joining UC Berkeley as a postdoctoral scholar under the guidance of Prof. Sanjam Garg.