Zero Knowledge Podcast

lean Ethereum Part 6: Formal Verification with Alex Hicks

March 25, 2026·58 min·3 clips
Alex Hicks cites empirical studies showing any codebase has 1-50 bugs per 1,000 lines of code — meaning large ZK proving systems 'statistically have bugs basically.'
The miniseries closes with formal verification as the big target, but the conversation keeps its feet on the ground. Nico talks with Alex Hicks from the Ethereum Foundation about where formal verification fits inside Lean Ethereum. The aim is stack wide: RISC-V, ZKVM, circuits, constraint systems, compilers, and cryptographic primitives would ideally all carry machine checked guarantees. That sounds clean until code has to cross languages. Alex makes the important distinction: translating development code into Lean is not the same thing as proving the original code correct. If the source language does not have formal semantics to compare against, the translation still has to be trusted. Tests still earn their keep here. Smart reviewers, audits, and careful comparisons can build confidence, but they do not turn into a proof of equivalence. A Lean proof may say something solid about the Lean model, while the relationship between that model and the real code still needs its own argument. Some code is easier to handle than other code. Purely functional code gives proof tools less to fight with than imperative code full of side effects or mutable borrows. Tooling gets a practical look too, with Alex pointing to systems such as Aeneas and Hacks that move source code toward Lean or SMT-style representations. Even the label matters. He suggests high assurance may be more honest than formal verification when testing, auditing, and trusted translation are doing part of the work. The Lean VM idea still has teeth: narrow the stack, shrink what has to be trusted, and compile through a tiny instruction set. Nico wraps by thanking Alex, and the series leaves formal verification as a hard engineering road, not a magic stamp.

As heard by us

A careful look at where proof ends and trust still begins in the ZK stack.

Formal verification is the main thread here, but the discussion keeps widening into a practical question about trust across the ZK stack. Alex Hicks and Nico move from Lean Ethereum's vision to what can actually be machine checked, and where the ecosystem still relies on models,…

Read the full review in PlayNext →

Why you'd press play

You want the real constraint behind Lean Ethereum, not the slogan.

Read the full recommendation in PlayNext →
Listen to the show on