# Union's quickstart pipes a remote script into your shell, then asks for a VM on a Mac

> A zero-knowledge interoperability layer in Rust, Go and Solidity spanning Cosmos IBC chains and EVM networks, with light clients and verifiers generated per chain. Every recent tag is a release candidate, the Cargo workspace lists all eighty crates by hand because globs break under Nix, and the pre-commit gate checks your spelling.

**unionlabs/union** — Union is a zero-knowledge interoperability protocol for transferring data and assets between blockchains without a trusted intermediary.

- Repository: https://github.com/unionlabs/union
- Website: https://union.build
- Stars: 73,786 · Forks: 3,885
- Language: Rust
- License: Apache-2.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/unionlabs-union

## The first documented command pipes a remote script into your shell

The quickstart opens with a curl to a third-party installer, piped straight into a shell.

```sh
curl --proto '=https' --tlsv1.2 -sSf -L https://install.determinate.systems/nix | sh -s -- install
```

The flags are careful. Forcing the https protocol, requiring TLS 1.2 or better, and failing loudly on an HTTP error are all sensible mitigations, and the host is a named systems vendor rather than an anonymous mirror. It is still a full remote script executed with your user's privileges, and for a repository whose entire pitch is removing trusted third parties from a protocol, that is a decision worth making deliberately rather than by copying the first line. Nix then becomes the build system for every language in the tree, which is what makes the next section a problem rather than a detail.

## On a Mac the documented path is a Linux VM, and explicitly not Nix inside it

The next paragraph is the one that decides whether you can work on this at all. It says some components can only be built on Linux, and that on macOS the recommendation is a container or virtual machine tool that sets up a NixOS virtual machine within two minutes. It adds that most Union developers use macOS with that tool, and that there is no need to install Nix inside the NixOS VM. Read together, that means a Mac contributor runs two layers: Nix on the host to drive the environment, and a Linux guest to actually compile the parts that will not build natively. Building a component is then a single command, with the result landing in a directory called result, and a dev shell is one command away, carrying cargo, rustc, node and go.

```sh
nix build .#uniond -L
nix build .#voyager -L
nix build .#app -L
```

The consequence is that the on-ramp is reproducible for the project and considerably heavier for the person, and that a contributor on an unsupported platform inherits a virtual machine in their first ten minutes.

## Every recent tag is a release candidate, and the tag names the component

There is no single version number to pin, and the tag format is doing more work than usual. The three most recent releases are a bundle for Union testnet 10 at 1.3.0-rc4, the same bundle at rc3, and the node implementation at 1.3.0-rc2. So the prefix carries the component and the network, the suffix says none of these is final, and the 1.3.0 line has only ever shipped in candidate form. The last push to the main branch was on 2026-07-25, comfortably after all three tags, so the branch is ahead of every published artefact as well. The consequence is that pinning to a release means choosing a release candidate and accepting that it may be replaced by a newer candidate of the same number, and that the practical version check is which rc you are on rather than which minor you are on.

## The Cargo workspace lists every crate by hand because globs break under Nix

The workspace manifest opens with a comment that explains an otherwise baffling choice: all paths must be listed out, with no globs, because a crate is still broken in Nix and cannot import the output of cargo metadata. The list that follows runs past eighty entries, and it is organised as a per-chain template. Base, Bob, Arbitrum, Berachain, CometBLS, Tendermint and Ethereum each get a types crate, a client, a verifier and a light-client-types crate, and the verifiers are the interesting part, including a Groth16 verifier for CometBLS, an Ethereum sync protocol crate and a Tendermint verifier. Alongside them sit shared libraries for SSZ encoding and derivation, gnark key parsing and MiMC, a Postgres-backed queue, a concurrent keyring and an IBC implementation in Solidity. The consequence is that adding one more chain means writing four more workspace entries by hand, and a forgotten entry leaves a crate silently outside both the workspace and the Nix build.

## One chain has a directory and a commented-out workspace entry, and Sui has no mainnet

The chains table and the directory listing do not tell quite the same story, and both are worth reading. The supported networks span Cosmos IBC chains, Babylon, Osmosis, Sei and Corn, alongside EVM networks including Ethereum, Arbitrum, Base, Berachain, Bob and BSC, with a mainnet and testnet identifier for each. Two rows need care. Sui has no mainnet entry at all, only a testnet identifier, so for that row the word supported means something narrower than it does for Ethereum. And the repository tree carries directories for Aptos and Cairo ecosystems that the chains table never mentions, while the workspace manifest includes a commented-out member for the Aptos IBC bindings. The consequence is that scaffolding for a chain can exist in the tree without being built, so counting directories overstates real coverage and the table is the more reliable of the two.

## The trust claim covers verification, while MPC and ceremony code sits in the tree

The project states that it has no dependencies on trusted third parties, oracles, multi-signatures or multi-party computation, and that it is based on consensus verification. That claim is about how a message is checked, and the tree is consistent with a protocol that needs a setup phase rather than a per-message one. It is still worth seeing the whole shape, because the repository contains directories for multi-party computation, a ceremony and the CometBLS curve, and workspace crates named after a concurrent keyring and a threshold encryption library. So the honest reading is that no MPC sits in the trust path of message verification, not that no threshold cryptography appears in the codebase. For anyone auditing the claim, that distinction is the difference between a design and a slogan, and it is the part you have to take from the code rather than from the summary.

## The pre-commit gate formats the repository and checks your spelling

Before each pull request you are told to run one command, and it is not only a formatter.

```sh
nix run .#pre-commit -L
```

The description says it formats the entire repository and checks your spelling. The formatting half is predictable once you see the configuration: there are separate formatter configs for Rust, for JavaScript and TypeScript, for TOML files, and a treefmt definition that ties them together, alongside a Biome config, a dprint config and a Clippy config. The spelling half is the surprise, and it is a genuine one for a protocol repository, where comments and documentation carry meaning that a spell checker will read as errors. The consequence for a contributor is that a branch can be rejected on a word rather than on a proof, and that the tool is opinionated about prose in a way that is unusual for this category of project.

## Conclusion

Adopt Union when you need a Cosmos-to-EVM message path and you are prepared to run a Nix development environment, because the per-chain light client and verifier pattern is the substance of the repository and it is well organised. Do not adopt it expecting a released version, since every recent tag is a release candidate and the tag prefix rather than a version number is what identifies a build. Three things to settle before you start. Read the install command before running it, because the documented first step executes a remote script as your user. Confirm your platform works, because some components build only on Linux and the recommended Mac setup is a virtual machine. And check whether the chain you need is actually built, since at least one chain directory is present while its workspace entry is commented out.

## FAQ

### What is the Union protocol?

It is a zero-knowledge infrastructure layer for general message passing, asset transfers, NFTs and DeFi, built on consensus verification and implementing IBC for Cosmos compatibility while connecting to EVM networks. Upgradability of contracts, connections and token configuration is described as controlled by decentralized governance.

### How do I build Union from source?

Through Nix. The quickstart installs Nix, then you run nix build with a package name, and the output lands in a directory called result. A dev shell with cargo, rustc, node and go comes from nix develop. Some components only build on Linux, so macOS users are pointed at a NixOS virtual machine.

### Which blockchains does Union support?

The table lists mainnet and testnet identifiers for Cosmos IBC chains such as Babylon, Osmosis, Sei and Corn, and for EVM networks including Ethereum, Arbitrum, Base, Berachain, Bob and BSC. Sui is listed with a testnet identifier and no mainnet, so coverage is not uniform across rows.

### What language is Union written in?

Several. The node implementation and the zero-knowledge prover are in Go, the relayer, the CosmWasm contract stack, the light clients and the node supervisor are in Rust, the EVM contracts are Solidity, and the app and site are TypeScript with Svelte and Astro. There is also a TypeScript SDK, split into cosmos and evm packages.

## Sources

- [Official documentation](https://union.build)
- [Official README](https://github.com/unionlabs/union#readme)
- [Project repository](https://github.com/unionlabs/union)
- [Release notes](https://github.com/unionlabs/union/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/unionlabs-union
