Published August 10, 2026
| Version v0.21.0
Software
Open
Consensys/gnark-crypto: v0.21.0
Authors/Creators
- Gautam Botrel1
- Youssef El Housni2
- Arya Tabaie1
- ThomasPiellard2
- Gus Gutoski
- Ivo Kubjas3
- AlexandreBelling
- Ignacio Hagopian4
- Justin Traglia5
- Yao J. Galteland
- ASIC
- zhiqiangxu6
- hussein7
- Ömer Faruk Irmak
- witmicko
- waskow-consensys
- radik878
- omahs
- leopardracer
- leo8
- feltroid Prime
- drawdrop
- devon1209
- cuibuwei
- ZhengXingRu
- VolodymyrBg
- 0xAlexKorn
- Ragnar
- Peter Chen J.
- 1. Consensys / Linea
- 2. Consensys
- 3. @ConsenSys
- 4. @ethereum
- 5. EF (@ethereum)
- 6. used to be qtt, now onchain
- 7. Block 6.282e+10
- 8. Alibaba
Description
⚠️ Breaking Changes
- FRI & Plookup relocated — The
friandplookuppackages are gone from all curves. FRI primitives now live underfield/koalabear. - Parallel goes public —
internal/parallelis now exported asparallel; the worker pool moved toutils. - Stricter EdDSA key parsing:
PublicKey.SetBytesnow rejects points outside the prime-order subgroup.PrivateKey.SetBytesnow rejects malformed scalars and public keys that don't match their scalar.- Keys that used to load may now error.
🔒 Security
- shplonk & fflonk were missing subgroup membership checks on digests and proof points before verifying.
- KZG MPC setup —
Verifywas checking the ratio on the previous SRS instead of the contributed one, and never bound the G1 update to the proof. - Subgroup membership tests added to all
twistededwardscurves. Fp2.Sqrtreturned a wrong result on(non-QR, 0)inputs.- Fixed a 4-byte overread in the
innerProdVecAVX-512 path.
✨ New
- Cube roots in
FpandFp2. - FFT over degree-6 extensions for
koalabearandbabybear. - Generic
BitReverse/BitReverseCopyhelpers inutils. - Fixed-base scalar multiplication on twisted Edwards curves (used by
eddsa). - secp256r1:
Fp2tower + Cardano cube-root solver.
⚡ Faster
- 4-bit sliding window exponentiation across all fields.
- Lazy-reduction 𝔽p2 multiplication assembly for BLS12-381, BLS12-377, BLS24-315 & BLS24-317, plus improved
Expt/mulBySeedchains and faster hash-to-G1 in the highly 2-adicFpcase. - New SIMD work on the small fields:
- AVX-512 & NEON kernels for Poseidon2 compression and VectorE6
- AVX-512 batch ops for E6 FFT (2.97×)
- Inlined E6 arithmetic for 31-bit primes (2.07×)
- Unrolled FFT kernels
Files
Consensys/gnark-crypto-v0.21.0.zip
Files
(5.1 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:2cf1d0aa984dbf722d1a57d37b138c86
|
5.1 MB | Preview Download |
Additional details
Related works
- Is supplement to
- Software: https://github.com/Consensys/gnark-crypto/tree/v0.21.0 (URL)
Software
- Repository URL
- https://github.com/Consensys/gnark-crypto