Skip to content

LibraryConfidential compute2022Design paperCorpus record

RISC Zero zkVM: proving RISC-V execution

RISC Zero. RISC Zero.

RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
2

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A proof of execution is a proof of a program. If the program is wrong, the proof is a proof of the wrong thing.

  2. Claim 02 · Paper model

    The proposal

    RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.

  3. Claim 03 · Paper model

    The mechanism

    The guest program is ordinary code compiled to the VM. The host supplies inputs. The receipt binds the image, the inputs, and the outputs the docs say it binds.

  4. Claim 04 · Paper model

    The bound

    This note does not quote proving time or cost.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A proof of execution is a proof of a program. If the program is wrong, the proof is a proof of the wrong thing.

    Model

    What has to hold

    You are reading RISC Zero's public design materials, not a benchmark.

    Falsifier

    What would retire it

    Who supplies the inputs the proof treats as given?

  2. 02 The proposal

    Observation

    What the study says

    RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.

    Model

    What has to hold

    The document is the one at the source URL. A marketing page with the same brand is not this text.

    Falsifier

    What would retire it

    What does the receipt commit to: image id, journal, both?

  3. 03 The mechanism

    Observation

    What the study says

    The guest program is ordinary code compiled to the VM. The host supplies inputs. The receipt binds the image, the inputs, and the outputs the docs say it binds.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    What does the receipt commit to: image id, journal, both?

  4. 04 The bound

    Observation

    What the study says

    This note does not quote proving time or cost.

    Model

    What has to hold

    You are reading RISC Zero's public design materials, not a benchmark.

    Falsifier

    What would retire it

    What does the receipt commit to: image id, journal, both?

03 Sequence

One action, as an operating tape

  1. 01The guest program is ordinary code compiled to the VM. The host supplies inputs. The receipt binds the image, the inputs, and the outputs the docs say it binds.
  2. 02The verifier checks the receipt. It does not understand the application's intent.
  3. 03A continuation or a proof composition feature, if documented, is an extra statement and has to be named.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

  2. What actually moves

    The cut

    The verifier checks the receipt. It does not understand the application's intent.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

  3. What a later deployment may change

    The cut

    A continuation or a proof composition feature, if documented, is an extra statement and has to be named.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading RISC Zero's public design materials, not a benchmark.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

This is not SP1 and not Jolt. The instruction set commitment differs.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A proof of execution is a proof of a program. If the program is wrong, the proof is a proof of the wrong thing.

What the design proposes

  • The guest program is ordinary code compiled to the VM. The host supplies inputs. The receipt binds the image, the inputs, and the outputs the docs say it binds.
  • The verifier checks the receipt. It does not understand the application's intent.
  • A continuation or a proof composition feature, if documented, is an extra statement and has to be named.

How the mechanism is specified

  • The guest program is ordinary code compiled to the VM. The host supplies inputs. The receipt binds the image, the inputs, and the outputs the docs say it binds.
  • The verifier checks the receipt. It does not understand the application's intent.
  • A continuation or a proof composition feature, if documented, is an extra statement and has to be named.

What this page does not treat as proven

  • This note does not quote proving time or cost.
  • A zkVM does not make the inputs true. It makes the execution follow the inputs.
  • This is not SP1 and not Jolt. The instruction set commitment differs.

Why the desk still reads it

RISC Zero publishes a zkVM that proves a RISC-V program ran, so a contract can verify a receipt instead of re-running the program.

09 Lexicon

Terms, opened into the record

zkVM
A virtual machine whose execution can be proved, rather than re-executed, by a verifier.
Receipt
The object a verifier checks. It is not the guest program's source code.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.