Skip to content
Research noteZK-2026-0208

Keeping the hash function out of the circuit

Symphony folds many statements into one without embedding a hash in the verified circuit, and reads its input in O(log log n) passes.

2 minZero-Knowledge Proofs

Binyi Chen of Tsinghua University revised Symphony on 20 August, a minor revision of an ASIACRYPT 2026 paper. It presents a lattice-based folding scheme that compresses a large number of NP-complete statements into a single one, giving a SNARK with polylogarithmic proof size and verification and, the author argues, plausible post-quantum security.

The design choice worth noting

Symphony avoids embedding a cryptographic hash function inside the circuits being verified. That is the recurring cost in recursive proof systems: the verifier must be expressed as a circuit, the verifier hashes, and hashing inside a circuit is expensive. Removing it addresses both the performance and the security concerns that come with modelling a hash inside the proven statement.

The prover reads its input in O(log log n) passes, with cost dominated by committing to the witnesses, and is described as memory-efficient and parallelisable. Passes over data matter for the same reason they matter in any large computation: at scale, the working set stops fitting anywhere convenient.

What the abstract does not give is a comparison. There are no timings and no baseline — no figure against Nova, Plonky3 or any other system a reader might be running. The claims are asymptotic and structural.

That places it alongside the other lattice-based folding work appearing this month. The interesting question for anyone choosing a stack is not which paper claims the better asymptotics but which has been measured on the same hardware, and none of them has yet.

Retold from IACR ePrint. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined