Keeping the hash function out of the circuit
Symphony folds many statements into one without embedding a hash in the verified circuit, and reads its input in O(log log n) passes.
2 minZero-Knowledge Proofs
Binyi Chen of Tsinghua University revised Symphony on 20 August, a minor revision of an ASIACRYPT 2026 paper. It presents a lattice-based folding scheme that compresses a large number of NP-complete statements into a single one, giving a SNARK with polylogarithmic proof size and verification and, the author argues, plausible post-quantum security.
The design choice worth noting
Symphony avoids embedding a cryptographic hash function inside the circuits being verified. That is the recurring cost in recursive proof systems: the verifier must be expressed as a circuit, the verifier hashes, and hashing inside a circuit is expensive. Removing it addresses both the performance and the security concerns that come with modelling a hash inside the proven statement.
The prover reads its input in O(log log n) passes, with cost dominated by committing to the witnesses, and is described as memory-efficient and parallelisable. Passes over data matter for the same reason they matter in any large computation: at scale, the working set stops fitting anywhere convenient.
What the abstract does not give is a comparison. There are no timings and no baseline — no figure against Nova, Plonky3 or any other system a reader might be running. The claims are asymptotic and structural.
That places it alongside the other lattice-based folding work appearing this month. The interesting question for anyone choosing a stack is not which paper claims the better asymptotics but which has been measured on the same hardware, and none of them has yet.
Retold from IACR ePrint. This is a summary in our own words; follow the link for the original reporting.