Skip to content
Research noteZK-2026-0206

A SHA-256 circuit folded in 91 milliseconds

NeutronNova reports roughly ten times Nova's speed on a million-constraint circuit, with a recursive verifier down to three scalar multiplications.

2 minZero-Knowledge Proofs

Abhiram Kothapalli and Srinath Setty of Microsoft Research have revised NeutronNova, a folding scheme built on the reductions-of-knowledge framework and organised around zero-check. The paper was first received in October 2024; this revision is dated 18 August.

The headline measurement is concrete: a SHA-256 circuit with 2^20 constraints folded in 91 milliseconds, which the authors put at roughly a tenfold improvement over Nova.

Why the verifier cost matters most

The recursive verifier needs three group scalar multiplications and a constant number of hash computations, leaving witness commitment as the dominant cost. In a recursive setting the verifier runs inside the next circuit, so its size sets the floor on recursion overhead — three scalar multiplications is a small floor.

The claimed combination is five properties at once: constant recursion overheads, multi-folding, linear scaling in the number of instances, no extraneous commitments, and modularity. Each is common enough alone; the argument is that they have not previously held together.

One signal is worth more than the benchmark. Since the first version appeared, other work has built on NeutronNova for space-efficient SNARKs, packed sum-check protocols and client-side proving. A construction that other people build on has been read carefully by people with reason to find fault in it.

Retold from IACR ePrint. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined