Stickybit.PortuguêsSection · zero-knowledge proofs · 2026
0k-proof · prove without showing

Prove it without showing it.

To get into an adults-only site today, you show your whole ID: name, ID number, date of birth, photo. You only needed to prove one thing: I am over 18. A zero-knowledge proof does exactly that: it convinces someone that something is true without handing over the data that makes it true. The idea is 40 years old; what changed is that it now fits in a phone.

Specimen · the cave with the secret door

The cave is a ring with two corridors, A and B, joined at the back by a door that only opens with the password. The prover goes in on a side you do not see. You shout which side she must come out of.

0rounds
0came out on the requested side
–chance it was all luck
0times you saw the password

The story is from 1989 (Quisquater and Guillou, "How to explain zero-knowledge protocols to your children"). Real proofs swap the cave for arithmetic, but the logic is the same: a challenge you choose, which only someone who knows the secret can meet every time.

First things first

Four words of this section.

The prover

Whoever holds the secret and wants to convince: you, your phone, the supplier's system. →

The verifier

Whoever needs to be convinced without learning the secret: the site, the bank, the auditor. →

The statement

The sentence being proved: "I am over 18", "my balance is above R$ 10,000", "I am on the list". Public, short and exact. →

The secret

The data that makes the statement true and never leaves where it is: the date of birth, the balance, which name on the list. →

In everyday life

Proving your age without showing your ID.

Since March 17, 2026, Brazil's Digital Statute for Children and Adolescents (Law 15.211/2025, known as ECA Digital) has been in force. Social networks, games, app stores and adult content services need reliable age verification; simple self-declaration ("I am an adult") no longer counts. And data collected for that purpose may only be used for it.

The obvious way to comply is to ask for the ID. It settles the age and hands over everything else: name, number, photo, address, exact date. Every site ends up keeping a copy of your ID, and every copy is a leak waiting to happen.

With a zero-knowledge proof, the ID stays on your phone. The issuing authority already signed your data once. The phone generates a proof that that signed data says you were born more than 18 years ago, and the site receives only that: a true sentence and the mathematical guarantee that it is true.

WHO KNOWS WHAT Issuing authoritysigns the dataonce born05/14/1990 ID •••••• signed over 18? yes ✓ Your phonekeeps the signedID over 18? yes ✓ The sitereceives onlythe sentence signedID proof164 bytes checked in 1.4 ms the date of birth never leaves the phone
The issuer signs once; after that, for each site, the phone generates a new proof. Sizes and times come from our bench.
Today · the site receives the ID

Everything, to learn one thing

  • Full namehanded over
  • ID numberhanded over
  • Date of birthhanded over
  • Photohanded over
  • Parents and addresshanded over
  • Over 18?yes
With the proof · the site receives one sentence

Only what it needed

  • Full namestays on the phone
  • ID numberstays on the phone
  • Date of birthstays on the phone
  • Photostays on the phone
  • Parents and addressstays on the phone
  • Over 18?yes, proved

This is not just theory: in 2025 the European Commission published a blueprint for an age verification app that uses exactly this kind of proof, being piloted in seven countries in 2026, and Google open-sourced the age proof it uses in its digital wallet. Details and sources in practical uses.

How it works, in three steps

A sealed envelope, a challenge, an answer.

Every zero-knowledge proof, from the cave to the phone, has the same structure. The how it works page shows each step with real cryptography running in your browser.

Seal

The prover commits to the answer before seeing the question, like putting a note in a sealed envelope. After that, the content cannot be swapped without breaking the seal.

Challenge

The verifier picks a random question the prover had no way of predicting. In the cave: "come out at B".

Answer

The prover opens only the part of the envelope that answers that question. Someone who knows the secret always gets it right; a bluffer fails half the time, and each extra round halves the chance of a successful bluff.

In the proofs used today, the challenge does not come from a person: it comes from a scrambled calculation over the envelope itself, which nobody controls. That way the proof becomes a single message anyone can check later, without talking to the prover.

We measured

What proving costs, in milliseconds.

We built four practical proofs and measured them on an ordinary machine (Apple M2, 8 GB), with the open-source gnark library, in Go. The age proof takes 26 milliseconds to generate and 1.4 milliseconds to check, and takes up 164 bytes, less than this sentence.

The cost grows with what is being proved. Proving you are on a list of a million names, without saying which, takes 220 ms. Proving you know the text behind a SHA-256 fingerprint takes 1.6 seconds and needs a 51 MB key. Checking, in every case, takes a few milliseconds.

We also tried to cheat: a 16-year-old, someone else's ID, a proof reused with a different year, a balance below the amount. None of the four produced an accepted proof.

GENERATING THE PROOF · LOG SCALE 10 ms100 ms1 s Over 1826 ms Balance above X25 ms On a list of 1 million220 ms Text behind the SHA-2561.6 s checking: 1.4 to 3.3 ms in all · proof: 164 to 196 bytes
Groth16 on the BN254 curve, best of five runs, on the Apple M2 using all cores. The full numbers, with the second proof system (PLONK), are on the bench page.
The section

For use in practice.

Limits

What the proof does not solve.

The proof is worth what the issuer attested

The math guarantees the sentence follows from the signed data. If the issuing authority signed a wrong date, the proof proves the wrong date, perfectly.

The proved program can be wrong

What gets proved is that a program was followed. If the program says "greater than 17" where the rule says "18 or older", the proof stays correct and the rule is broken. The program needs its own audit.

Some systems need a ceremony

The most compact proof system needs an initial setup with a secret that must be destroyed. If it is not, whoever kept it can forge proofs. There are systems without that requirement, with larger proofs.

The proof hides the data, not the context

The verifier does not see your date of birth, but does see that someone proved their age, from which site, at what time. That trail needs care of its own.

Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← stickybit.com.br

Sources