Search

Search for projects by name or address

ZK Catalog

SP1 Hypercube logo
SP1 HypercubeSuccinct

About

SP1 Hypercube is a zk proving system for RISC-V programs built by Succinct, release v6.


  • Total Value SecuredTVS
    $302.93 M0.86%

  • Trusted Setups

    Used in

    Projects used in

    Search for projects used in

    Verifiers

    1by

    Used in

    Verifiers

    1by

    Used in

    Projects used in

    Search for projects used in

    Verifiers

    1by

    Used in

    Verifiers

    1by

    Tech Stack

    zkVM
    Plonky3
    RISC-V 64bit
    Baby Bear
    Koala Bear
    Final wrap
    Gnark
    Gnark
    BN254
  • Total Value SecuredTVS
    $302.93 M0.86%
  • About

    SP1 Hypercube is a zk proving system for RISC-V programs built by Succinct, release v6.



    Total
    Canonically BridgedCanonically Bridged ValueCanonical
    Natively MintedNatively Minted TokensNative
    Externally BridgedExternally Bridged ValueExternal

    ETH & derivatives
    Stablecoins
    BTC & derivatives
    Other

    Description

    SP1 Hypercube is the latest Succint’s RISC-V zkVM using the Plonky3 stack. The zkVM execution is proven recursively and is wrapped into a SNARK for final verification. It provides tools to generate onchain Groth16 or Plonk verifiers. SP1 Hypercube provides 98 bits of proven security, as per Ethereum Foundation’s soundcalc evaluation.

    Proof system

    SP1 Hypercube is an iteration of the previous zkVM version, SP1 Turbo, introducing architectural changes that improve prover performance and memory efficiency.

    Hypercube proves execution of a 64-bit RISC-V VM using several ZK circuits, or chips, connected by lookup arguments (LogUp based on GKR protocol). VM execution trace is split into several shards of size approximately 2^22, that could be proven in parallel with a STARK proving system. Additional arguments prove memory consistency across shards.

    The parallelized proofs are recursively checked by the next layer of STARK circuits. The correctness of the final STARK proof is verified with the final wrap SNARK program, the wrap SNARK proof is verified onchain.

    Hypercube vs. Turbo

    Proving time and memory optimizations of SP1 Hypercube are based on several design improvements compared to SP1 Turbo.

    Hypercube implements a multilinear polynomial STARK compared to univariate polynomials in Turbo. Multilinear polynomial based proving systems are more efficient than univariate because manipulating them reduces usage of log-linear FFT algorithm.

    Multilinear polynomials also allow Hypercube to innovate on a polynomial commitment scheme, implementing Jagged PCS (defined in this preprint). Jagged PCS allows efficient packing of computation traces of zkVM chips with different lengths, optimizing the prover memory requirement. More efficient LogUp based on GKR is also made possible because of multilinear polynomials.

    Recursion circuits

    SP1 Hypercube provides tools for recursive proof generation by verifying proofs in a zkVM. This uses the same toolkit as top-level proof system, but proves the correct verification of all proofs generated on the previous step.

    First, proofs for correctness of separate shards are generated. These shards may have different trace shape, so in the next step they are normalized. Finally, normalized shard proofs are recursively compressed in batches of 3-4 to a single zkVM proof. For further details see this page.

    Final wrap

    SP1 Hypercube supports Plonk (with KZG polynomial commitments) or Groth16 final SNARK wrap of the STARK proof for performant onchain proof verification (link). The https://github.com/Consensys/gnark implementation of these proof systems over BN254 curve is used. For Plonk, Aztec Ignition trusted setup ceremony is used, for Groth16 Succinct run internal circuit-dependent phase 2 trusted setup (todo: link to trusted setups section).

    Aztec Ignition

    Gnark

    Detailed description

    Aztec Ignition is a trusted setup ceremony for KZG commitments over BN254 curve that was run by Aztec for KZG commitment over BN254 curve in 2019. It included 176 participants and was publicly open for participation.


    SP1 Hypercube Groth16 circuit-specific setup

    Gnark

    Detailed description

    Ceremony was run among 12 participants affiliated with Across Protocol, OP Labs, Offchain Labs, Succinct Labs, Conduit, Ethrealize and 1 independent participant. It generated circuit-specific setup parameters for Groth16 wrapper of SP1 Hypercube zkVM.

    List of different onchain verifiers for this proving system. Unique ID distinguishes differents deployments of the same verifier from different verifiers (e.g. different versions).

    Gnark
    verifier hashes
    Gnark
    verifier hashes

    List of known guest zkVM programs used by this prover. Each program represents a piece of offchain execution that is verified onchain. The program hash serves as the program's unique identifier.

    Name
    Hash
    Repository
    Verification
    Used in
    0x0057...6ad1
    Code unknown
    None
    0x00de...0bef
    Code unknown
    None
    0x00b3...8afd
    0x05ca...1a29
    0x0039...772e
    0x4906...6872