When developing a credential verification system for a DeFi protocol, we faced the need to verify users' KYC status without disclosing their personal data. Standard blockchain verification reveals all credential attributes, violating privacy. The solution is verifiable credentials using ZK-proof (Groth16 or PLONK), which allow proving only the required fact. This infrastructure is standardized by W3C (W3C Verifiable Credentials Standard) and supported by wallets (MetaMask, WalletConnect) and protocols. We implement the full cycle: issuance, storage, verification, and revocation of digital credentials based on W3C Verifiable Credentials standards. The system can integrate with existing KYC providers (Persona, Jumio) and run on Ethereum, Polygon, or Arbitrum. Gas savings with ZK-proof on L2 amount to up to 70% — with 1000 verifications per day, this saves over $500 per month.
Architecture of Verification on the Blockchain
The system is built from three key components:
- Issuer — a trusted organization (KYC provider, educational institution, DAO) that issues signed credentials via its own DID.
- Holder — a user storing credentials (e.g., in a wallet or via Polygon ID).
- Verifier — a protocol or dApp that checks credentials before granting access.
The verifier generates a unique challenge (nonce); the holder includes it in the Verifiable Presentation and signs it. This prevents replay attacks: the presentation is valid only for that specific request.
// User creates a presentation const presentation = { "@context": ["https://www.w3.org/2018/credentials/v1"], "type": ["VerifiablePresentation"], "verifiableCredential": [kycCredential], "proof": { "type": "Ed25519Signature2020", "challenge": nonce, "domain": "app.example.com", "created": new Date().toISOString(), "verificationMethod": `did:ethr:${userAddress}#controller`, "proofPurpose": "authentication", "jws": await signPresentation(nonce) } }; Necessity of ZK-Verification
Standard verification reveals the entire credential: the protocol sees the issuer, issuance date, and all attributes. ZK-proof (Groth16 or PLONK) changes this: the user proves a fact ("I have a valid KYC credential") without revealing its content. This approach is required for:
- DeFi lending — verify that a borrower passed KYC without disclosing their identity.
- DAO governance — grant voting rights only to holders of Contributor SBTs, without showing who holds them.
- Compliant DEX — allow trading only for verified addresses from allowed jurisdictions.
ZK-proof accelerates verification by 3–5 times compared to full verification (when using Plookup-based frameworks) and provides the confidentiality required by GDPR.
How ZK-proof Protects Privacy?
A ZK-proof allows the verifier to be convinced of a statement's truth without seeing the original data. For example, a user proves they are over 18 without presenting their passport. This is achieved with circuits written in circom and snarkjs. An on-chain registry stores only a hash or state snapshot; full credentials remain with the user.
What is On-chain Registry?
An on-chain registry is a smart contract that stores references to current credentials or their fingerprints. When a credential is revoked, the issuer updates the registry, and the verifier checks the status. This approach ensures transparency and immutability but requires gas management. We optimize gas consumption by storing only data necessary for verification.
Our Approach: What's Included in Development
We design the system turnkey from scratch or integrate with an existing architecture. Our development includes:
- Select the standard (W3C VC + DID or Polygon ID for ZK).
- Deploy an on-chain Registry smart contract on Ethereum/Polygon/Arbitrum (your choice).
- Integrate trusted issuers (Persona, Jumio, Onfido, or your own).
- Develop a Verifier SDK (ethers.js, viem) for use in the protocol.
- Implement ZK circuits (circom + snarkjs) and a verifier smart contract (if needed).
- Conduct a security audit (Slither, Mythril, Echidna fuzzing).
- Deliver documentation, tests, and deployment instructions.
Comparison of Verification Methods
| Method | Privacy | Gas cost (L2) | Verification time | Standard support |
|---|---|---|---|---|
| Standard VC verification | Low (reveals all data) | ~50,000 gas | <1 sec | W3C VC + DID |
| ZK-proof (Groth16) | High (only fact) | ~300,000 gas | 2–3 sec | Polygon ID, circom |
| ZK-proof (PLONK) | High (only fact) | ~200,000 gas | 1–2 sec | PLONK, Halo2 |
| On-chain commitment + off-chain verification | Medium (hash) | ~30,000 gas | <1 sec | Custom |
Development Stages
| Stage | Duration | Result |
|---|---|---|
| Analytics | 1–2 weeks | Technical specification, stack selection |
| Design | 1–2 weeks | Smart contract and ZK circuit architecture |
| Implementation | 4–8 weeks | Contracts, circuits, SDK, tests |
| Audit | 1–2 weeks | Security report |
| Deployment | 1 week | Network deployment, integration |
| Support | 3 months | Documentation, training, refinements |
Process
- Analytics — clarify credential types, number of issuers, privacy requirements.
- Design — choose stack (Foundry/Hardhat, circom/snarkjs), smart contract architecture.
- Implementation — write contracts, ZK circuits, SDK, tests (unit + integration).
- Audit — internal and external security audit.
- Deployment — deploy on the chosen network, integrate with your protocol.
- Support — documentation, team training, 3-month warranty support.
Example circom configuration for KYC
pragma circom 2.0.0; include "../../node_modules/circomlib/circuits/comparators.circom"; template KYCCredential(ageThreshold) { signal input age; signal input country; signal input isKYC; signal output valid; component ageCheck = GreaterThan(32); ageCheck.in[0] <== age; ageCheck.in[1] <== ageThreshold; valid <== ageCheck.out * isKYC; } Timeline and What You Get
Development of a complete credential verification system takes 8–16 weeks depending on complexity. The cost is calculated individually after requirements audit. To assess your project, reach out to us for a consultation.
Note what you will receive:
- Deployable smart contracts (Registry + Verifier) with open source.
- Verifier SDK (TypeScript) for integration into your protocol.
- ZK circuits (if required) with audited code.
- Architecture, deployment, and operation documentation.
- 3 months of support and refinements per your specification.
Our team's experience: 5+ years in blockchain development, 10+ projects in DeFi, NFT, and identity. We guarantee functionality and passing security audits. Order development and get a reliable verification infrastructure.







