Yes, that's true. With Dory we will have to work on some pairing-friendly curve. Not secp256k1. On Tuesday, July 23, 2024 at 3:01:59 AM UTC+8 Weikeng Chen wrote: I need to point out that Dory requires pairing, and therefore it cannot work with secp256k1? Please circle back. On Monday, July 22, 2024 at 9:16:18 AM UTC-5 Weiji Guo wrote: ———What-ifs——— What if the open issue cannot be resolved? We might consider Dory. It is transparent, requires pairing, and has logarithmic proof size but concretely larger -- You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/bitcoindev/8d3084bc-aece-48ba-a08d-01b53392b64dn%40googlegroups.com.