Skip to content

LibraryConfidential compute2024Design paperCorpus record

SP1: a zkVM for RISC-V programs

SP1. Succinct.

SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
5

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    Two RISC-V zkVMs are not interchangeable. The image identity and the verifier keys differ.

  2. Claim 02 · Paper model

    The proposal

    SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.

  3. Claim 03 · Paper model

    The mechanism

    The program is identified by an image. A proof for a different image is a proof of a different program, even if the source looks similar.

  4. Claim 04 · Paper model

    The bound

    No cycle count and no cost is stated here.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    Two RISC-V zkVMs are not interchangeable. The image identity and the verifier keys differ.

    Model

    What has to hold

    You are reading the SP1 introduction. A particular proving cluster's uptime is not the VM.

    Falsifier

    What would retire it

    Which verifier is on the settlement chain: the zkVM verifier or a wrapper?

  2. 02 The proposal

    Observation

    What the study says

    SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.

    Model

    What has to hold

    The document is the one at the source URL. A marketing page with the same brand is not this text.

    Falsifier

    What would retire it

    Which verifier is on the settlement chain: the zkVM verifier or a wrapper?

  3. 03 The mechanism

    Observation

    What the study says

    The program is identified by an image. A proof for a different image is a proof of a different program, even if the source looks similar.

    Model

    What has to hold

    The document is the one at the source URL. A marketing page with the same brand is not this text.

    Falsifier

    What would retire it

    What image id does the application expect?

  4. 04 The bound

    Observation

    What the study says

    No cycle count and no cost is stated here.

    Model

    What has to hold

    You are reading the SP1 introduction. A particular proving cluster's uptime is not the VM.

    Falsifier

    What would retire it

    Which verifier is on the settlement chain: the zkVM verifier or a wrapper?

03 Sequence

One action, as an operating tape

  1. 01The program is identified by an image. A proof for a different image is a proof of a different program, even if the source looks similar.
  2. 02A wrapper proof attests the zkVM proof. The wrapper is what a chain verifies when the zkVM proof is too heavy. Both statements have to be the right ones.
  3. 03Precompiles for hash or signature operations change the cost model. They do not change what 'this program ran' means, unless they change the VM.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    SP1 is not RISC Zero's receipt format.

  2. What actually moves

    The cut

    A wrapper proof attests the zkVM proof. The wrapper is what a chain verifies when the zkVM proof is too heavy. Both statements have to be the right ones.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A proof does not attest that the inputs were fetched honestly from some website.

  3. What a later deployment may change

    The cut

    Precompiles for hash or signature operations change the cost model. They do not change what 'this program ran' means, unless they change the VM.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading the SP1 introduction. A particular proving cluster's uptime is not the VM.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

A proof does not attest that the inputs were fetched honestly from some website.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

Two RISC-V zkVMs are not interchangeable. The image identity and the verifier keys differ.

What the design proposes

  • The program is identified by an image. A proof for a different image is a proof of a different program, even if the source looks similar.
  • A wrapper proof attests the zkVM proof. The wrapper is what a chain verifies when the zkVM proof is too heavy. Both statements have to be the right ones.
  • Precompiles for hash or signature operations change the cost model. They do not change what 'this program ran' means, unless they change the VM.

How the mechanism is specified

  • The program is identified by an image. A proof for a different image is a proof of a different program, even if the source looks similar.
  • A wrapper proof attests the zkVM proof. The wrapper is what a chain verifies when the zkVM proof is too heavy. Both statements have to be the right ones.
  • Precompiles for hash or signature operations change the cost model. They do not change what 'this program ran' means, unless they change the VM.

What this page does not treat as proven

  • No cycle count and no cost is stated here.
  • SP1 is not RISC Zero's receipt format.
  • A proof does not attest that the inputs were fetched honestly from some website.

Why the desk still reads it

SP1 publishes a zkVM that proves RISC-V execution, with a receipt a Groth16 or PLONK wrapper can compress for a settlement contract.

09 Lexicon

Terms, opened into the record

Image id
The commitment to the program being proved.
Wrapper proof
A second proof whose statement is that the zkVM proof verified. It is a different circuit.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.