a16z crypto show

How Zero-Knowledge Proofs Were Invented (ft. Co-Inventor and Turing Award Winner Shafi Goldwasser)

Episode Summary

How can you prove that something is true without revealing why it is true? What began as an attempt to solve a seemingly playful problem — playing poker securely over the telephone — ultimately changed how computer scientists think about proofs, privacy, and verification. In this episode of First Principles, Turing Award–winning cryptographer Shafi Goldwasser joins a16z crypto Head of Research Tim Roughgarden and Research Partner Justin Thaler to tell the origin story of zero-knowledge proofs and interactive proof systems.

Episode Notes

How can you prove that something is true without revealing why it is true? 

That question gave rise to zero-knowledge proofs, one of the most important breakthroughs in modern cryptography. What began as an attempt to solve a seemingly playful problem — playing poker securely over the telephone — ultimately changed how computer scientists think about proofs, privacy, and verification. In this episode of First Principles, Turing Award–winning cryptographer Shafi Goldwasser joins a16z crypto Head of Research Tim Roughgarden and Research Partner Justin Thaler to tell the origin story of zero-knowledge proofs and interactive proof systems. 

Goldwasser recounts how she, Silvio Micali, and Charles Rackoff developed a new kind of proof involving interaction, randomness, and a small probability of error. Their work introduced the idea that a prover could convince a verifier that a statement is true while revealing no additional information. The conversation follows those ideas through some of theoretical computer science’s deepest results, including interactive proofs, IP = PSPACE, probabilistically checkable proofs, the sum-check protocol, and SNARKs. 

These concepts now power blockchain rollups, privacy-preserving applications, and systems for verifying computation without repeating all the work. They also explore why breakthrough ideas are often initially rejected, how toy problems can lead to foundational theories, why abstraction and narrative matter in scientific research, and whether AI systems should be required to prove their answers. 

Highlights 
0:00 — Intro 
3:36 — How mental poker inspired zero-knowledge proofs: Proving that something is true without revealing the underlying information 
6:30 — The simulation paradigm and the meaning of “zero knowledge” 
8:33 — Why the original paper was repeatedly rejected 
10:33 — How interactive proofs became more powerful than conventional proofs 
13:36 — The road to modern SNARKs 
19:02 — Why the sum-check protocol is so useful for verifiable computation 
25:31 — Why many so-called “zk proofs” are not actually zero knowledge 
34:06 — Why toy examples, playfulness, and narratives can produce deep theory 
37:23 — The role of rigor and computational assumptions in cryptography 
42:44 — Applying zero-knowledge proofs to law, evidence, and secret software 
45:23 — Training AI systems to provide proofs alongside their answers 
54:27 — Why genuinely new ideas are often difficult for experts to recognize 

About First Principles 

First Principles is a special limited series from a16z crypto about the scientific roots of modern computing — especially blockchains — told through rare conversations with the pioneers who helped shape the foundational ideas behind distributed systems, consensus protocols, economics, mechanism design, cryptography, zero knowledge, and more. 

People often tell the story of the Bitcoin whitepaper as if it appeared out of nowhere. But the ideas behind Bitcoin — and blockchains more broadly — come from decades of computer science, economics, mathematics, and cryptography. First Principles is a guide to that lineage, as told by the people who helped build it. 

Links 
Shafi Goldwasser 
MIT CSAIL: http://people.csail.mit.edu/shafi/ 
Simons Institute: https://simons.berkeley.edu/people/shafi-goldwasser 

Tim Roughgarden
a16z crypto: https://a16zcrypto.com/team/tim-roughgarden/ 
Website: https://timroughgarden.org/ "X: https://x.com/Tim_Roughgarden 

Justin Thaler 
a16z crypto: https://a16zcrypto.com/team/justin-thaler/ 
Website: https://people.cs.georgetown.edu/jthaler/ 
X: https://x.com/SuccinctJT 

a16z crypto
Subscribe: https://www.youtube.com/@a16zcrypto 
Website: https://a16zcrypto.com/ 
X: https://twitter.com/a16zcrypto 

Newsletter: https://a16zcrypto.substack.com/