Modulus Read the documentation

Performance

4.82 milliseconds against 3.7 to 49 seconds.

The same claim, the same algorithm, one desktop CPU, and the current release of every system compared.

766–10,200×faster to prove
30–1,700×less prover memory
4–56×smaller proof

fib(10,000) mod 7919

Every system, the same algorithm, one machine.

Fast doubling throughout: fourteen rounds rather than ten thousand steps. The zkVM guests run a hand-written doubling routine. zkFOL is handed the naive two-call recurrence and its compiler rewrites that into the doubling form itself.

SystemProveVerifyProofProver memory
zkFOL4.82 ms1.4 ms49.8 KBunder 10 MB
RISC Zero, composite3.69 s11.8 ms209.6 KB312 MB
RISC Zero, succinct14.73 s12.4 ms223.3 KB1.39 GB
SP1, core13.32 s74.3 ms2.78 MB9.39 GB
SP1, compressed49.24 s32.9 ms1.27 MB17.00 GB

AMD Ryzen 7 5700X, eight cores, Linux, CPU proving only, one prover at a time. zkFOL 0.4.0, RISC Zero 3.0.5, SP1 6.3.1. Every cell is the median of three runs.

Sudoku

16 milliseconds, and not a single square revealed.

The two sides are proving different things here, and the difference matters more than the timings do. The comparators take a finished grid, publish it, and prove that the published grid is valid. zkFOL proves that a grid exists satisfying the clues, and publishes none of it.

SystemWhat is provedProveVerifyProver memory
zkFOLa solution exists, nothing disclosed15.95 ms3.38 ms~25 MB
RISC Zero, compositethis published grid is valid7.252 s12.46 ms606 MB
RISC Zero, succinctthis published grid is valid18.040 s12.44 ms1.43 GB
SP1, corethis published grid is valid13.687 s75.92 ms9.57 GB
SP1, compressedthis published grid is valid50.329 s33.21 ms16.80 GB

zkFOL makes the stronger of the two claims and reaches it roughly 450 times faster than the quickest comparator. Replace the grid with a balance sheet, a set of positions or a counterparty exposure, and the property is identical.

The floor

A bounds check costs 1.53 milliseconds.

Prove that a committed value lies between 10 and 100. There is nothing to compute, so this is the price of a proof at all, and it is the atomic unit of nearly every risk check in finance: collateral above a threshold, a position inside a limit, an age, a balance, an exposure.

The zkVM columns barely move from the table above. RISC Zero charges the same 32,768 cycles here as it does for fast doubling, because the work never leaves the floor its own machine sets. That floor is the gap.

SystemProveVerifyProofProver memory
zkFOL1.53 ms0.54 ms28.0 KB~3 MB
RISC Zero, composite3.70 s11.5 ms209.6 KB311 MB
RISC Zero, succinct14.68 s12.3 ms223.2 KB1.39 GB
SP1, core13.23 s78.2 ms2.78 MB9.36 GB
SP1, compressed49.20 s32.6 ms1.27 MB17.01 GB

Prove time, zkVM over zkFOL: 2,420×, 9,600×, 8,650× and 32,200×. Prover memory: 100×, 460×, 3,100× and 5,700×.

Each system's own route

The exact 2,090-digit integer, in 8.36 milliseconds.

Here the zkVMs run the published benchmark program unchanged, in their headline proof mode, and zkFOL runs Fibonacci the way a user would actually write it. The second row proves the exact integer with no modular reduction anywhere, which is a strictly harder claim than the one every other row makes, and it is the fastest row on the page.

SystemWhat is provedProveVerifyProof
zkFOL, exact integerexact fib(10,000)8.36 ms3.1 ms664 KB
RISC Zero, succinctfib(10,000) mod 791940.67 s12.5 ms223.3 KB
SP1, compressedfib(10,000) mod 791950.39 s35.2 ms1.27 MB

The compiler is what makes that row possible. Handed the same recurrence written as a plain loop, zkFOL proves it in 1.06 s; rewritten to doubling, 8.36 ms. That rewrite is the default route a user gets.

Hardware

One desktop CPU, start to finish.

No accelerator, no cluster, no specialist machine. Producing and verifying proofs for your own transactions sits inside the envelope published on this page, which means no proving farms, no rented trust and no queue. That was the promise of this industry before it got complicated.

Full methodology, the guest programs each system was given, how memory was measured, and the commands to reproduce every cell, are in the documentation.