LibraryPrivacy2022Design paperCorpus record
HyperPlonk: Plonk with Linear-Time Prover and High-Degree Custom Gates
HyperPlonk. Binyi Chen, Benedikt Bünz, Dan Boneh and Zhenfei Zhang.
HyperPlonk replaces that transform with a sumcheck so the prover is linear in the number of gates, and it allows higher-degree custom gates.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
When a team says they left PLONK for prover time, ask whether they mean this sumcheck change or a different arithmetisation.
The five-minute read
The defect
PLONK's prover does a number-theoretic transform that is quasilinear but painful, and its custom gates are degree-limited.
The proposal
HyperPlonk replaces that transform with a sumcheck so the prover is linear in the number of gates, and it allows higher-degree custom gates.
Sumcheck is the new backbone.
A custom gate of higher degree can express constraints that previously needed many rows.
The bound
Linear time is not free in constants. The paper is not a benchmark of a product.
One action, walked through
- Arithmetise the circuit as a PLONK-style constraint system.
- Prove the sum over the hypercube by sumcheck.
- Open the committed polynomials at the points the protocol names.
- What degree of custom gate is allowed?
The argument, unpacked
What the paper is for
When a team says they left PLONK for prover time, ask whether they mean this sumcheck change or a different arithmetisation.
What happened after
Production provers forked the PLONK line in several directions. HyperPlonk is one of them, not all of them.
What has to be true
- Linear time is not free in constants. The paper is not a benchmark of a product.
- High-degree gates move work. They do not remove the need to audit the constraint.
- This is not vanilla PLONK.
What happened after the paper
Production provers forked the PLONK line in several directions. HyperPlonk is one of them, not all of them.
What to check before you use the idea
- Is the prover using an NTT or sumcheck?
- What degree of custom gate is allowed?
- Which commitment is on the hot path?
Terms
- Sumcheck
- An interactive proof that a sum over a boolean hypercube has a claimed value.
- Custom gate
- A constraint row that is not the plain PLONK equation.
The problem the paper names
PLONK's prover does a number-theoretic transform that is quasilinear but painful, and its custom gates are degree-limited.
What the design proposes
- Sumcheck is the new backbone.
- A custom gate of higher degree can express constraints that previously needed many rows.
- The verifier still depends on the polynomial commitment.
How the mechanism is specified
- Arithmetise the circuit as a PLONK-style constraint system.
- Prove the sum over the hypercube by sumcheck.
- Open the committed polynomials at the points the protocol names.
What this page does not treat as proven
- Linear time is not free in constants. The paper is not a benchmark of a product.
- High-degree gates move work. They do not remove the need to audit the constraint.
- This is not vanilla PLONK.
Why a venture studio still reads it
When a team says they left PLONK for prover time, ask whether they mean this sumcheck change or a different arithmetisation.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
