LibraryScaling2023Design paperCorpus record
HyperNova: Recursive Arguments for Customizable Constraint Systems
HyperNova. Abhiram Kothapalli and Srinath Setty.
HyperNova generalises folding to customisable constraint systems so a recursive proof can follow the arithmetisation the circuit actually uses.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
Ask which constraint system is folded. If the answer is 'R1CS' and the circuit is lookups, they are not describing this paper.
The five-minute read
The defect
Nova folds R1CS. Systems people wanted to ship were using higher-degree constraints and lookups, which do not fit that relation.
The proposal
HyperNova generalises folding to customisable constraint systems so a recursive proof can follow the arithmetisation the circuit actually uses.
The relation being folded is no longer fixed as plain R1CS.
Recursion is how a long computation becomes one proof.
The bound
This does not make proving free.
One action, walked through
- Choose the constraint system.
- Fold successive steps.
- Compress the folding transcript in the recursive argument.
- What is recursed, the step or only the final proof?
The argument, unpacked
What the paper is for
Ask which constraint system is folded. If the answer is 'R1CS' and the circuit is lookups, they are not describing this paper.
What happened after
Production folding stacks cite Nova and then this generalisation when they leave R1CS.
What has to be true
- This does not make proving free.
- A custom constraint that is wrong is a wrong proof of the wrong statement.
- It is not a consensus change.
What happened after the paper
Production folding stacks cite Nova and then this generalisation when they leave R1CS.
What to check before you use the idea
- What is the constraint system?
- What is recursed, the step or only the final proof?
- What does the verifier recompute?
Terms
- CCS
- A customisable constraint system, not a single fixed arithmetisation.
- Recursion
- A proof that verifies a previous proof.
The problem the paper names
Nova folds R1CS. Systems people wanted to ship were using higher-degree constraints and lookups, which do not fit that relation.
What the design proposes
- The relation being folded is no longer fixed as plain R1CS.
- Recursion is how a long computation becomes one proof.
- Custom constraints are a benefit only if the verifier's check matches them.
How the mechanism is specified
- Choose the constraint system.
- Fold successive steps.
- Compress the folding transcript in the recursive argument.
What this page does not treat as proven
- This does not make proving free.
- A custom constraint that is wrong is a wrong proof of the wrong statement.
- It is not a consensus change.
Why a venture studio still reads it
Ask which constraint system is folded. If the answer is 'R1CS' and the circuit is lookups, they are not describing this paper.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
