I printed out DUSK’s underlying dependency list line by line. There are two lines that are most worth highlighting: curves and hashes. Today, I’ll talk only about these two.
On the curve line, early on it was written as ZeroCaf. DUSK didn’t fully reuse off-the-shelf secp256k1 or Ed25519. Instead, it chose a path related to Ristretto scalar fields. If you know what you’re looking at, you’ll immediately see the significance of this choice: Ristretto’s point compression is uniform, and the low-order point traps left by the cofactor are also blocked off. Proofs like Bulletproofs run smoothly on this path—generation and verification both go smoothly. If something goes wrong in this step, the entire chain suffers. Picking the right curve has nuances that outsiders rarely notice, but insiders weigh heavily. $BTC .
On the hash line, it says Poseidon. In zero-knowledge circuits, the most expensive part is the constraints. If you put in SHA-256, the number of constraints can drag the proof performance down. Poseidon was designed specifically for circuits—do the same job, but with far fewer constraints. Even DUSK’s hashing is swapped for a ZK-specific version, and many chains don’t even realize they should go change this detail.
After I marked these two lines, my overall impression of DUSK was set: even its cryptography foundation is built according to the needs of zero-knowledge proofs, not assembled from generic components. Projects like this usually know exactly what they want. Going forward, whatever changes DUSK makes, I’ll have a sense of its direction in my mind. #dusk $DUSK @Dusk
On the curve line, early on it was written as ZeroCaf. DUSK didn’t fully reuse off-the-shelf secp256k1 or Ed25519. Instead, it chose a path related to Ristretto scalar fields. If you know what you’re looking at, you’ll immediately see the significance of this choice: Ristretto’s point compression is uniform, and the low-order point traps left by the cofactor are also blocked off. Proofs like Bulletproofs run smoothly on this path—generation and verification both go smoothly. If something goes wrong in this step, the entire chain suffers. Picking the right curve has nuances that outsiders rarely notice, but insiders weigh heavily. $BTC .
On the hash line, it says Poseidon. In zero-knowledge circuits, the most expensive part is the constraints. If you put in SHA-256, the number of constraints can drag the proof performance down. Poseidon was designed specifically for circuits—do the same job, but with far fewer constraints. Even DUSK’s hashing is swapped for a ZK-specific version, and many chains don’t even realize they should go change this detail.
After I marked these two lines, my overall impression of DUSK was set: even its cryptography foundation is built according to the needs of zero-knowledge proofs, not assembled from generic components. Projects like this usually know exactly what they want. Going forward, whatever changes DUSK makes, I’ll have a sense of its direction in my mind. #dusk $DUSK @Dusk