LibraryPrivacy2020Design paperCorpus record
Spartan: Efficient and General-Purpose zkSNARKs without Trusted Setup
Spartan. Srinath Setty.
Spartan encodes the circuit as a sparse matrix and uses a polynomial commitment so the prover's work tracks the number of constraints more tightly than a dense encoding.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
A prover-time claim should say whether the circuit is sparse in the sense this paper uses. Otherwise the comparison is advertising.
The five-minute read
The defect
General-purpose SNARKs without a setup were still too slow in the prover for the circuits people wanted to ship.
The proposal
Spartan encodes the circuit as a sparse matrix and uses a polynomial commitment so the prover's work tracks the number of constraints more tightly than a dense encoding.
Sparsity is the saving. A dense encoding pays for zeros.
There is no trusted setup.
The bound
The paper's costs are asymptotic and experimental for its implementation, not a quote for a product.
One action, walked through
- Compile to R1CS.
- Treat the matrices as sparse.
- Prove the satisfying assignment with the polynomial protocol in the paper.
- Is there a setup?
The argument, unpacked
What the paper is for
A prover-time claim should say whether the circuit is sparse in the sense this paper uses. Otherwise the comparison is advertising.
What happened after
Later lookups and folding schemes attack the same prover cost from other directions.
What has to be true
- The paper's costs are asymptotic and experimental for its implementation, not a quote for a product.
- No setup does not mean no cryptographic assumption.
- It is not a consensus protocol.
What happened after the paper
Later lookups and folding schemes attack the same prover cost from other directions.
What to check before you use the idea
- Is the encoding sparse?
- Is there a setup?
- Which commitment is the verifier relying on?
Terms
- Sparse matrix
- A constraint matrix that is mostly zeros, which the prover should not have to touch.
- Polynomial commitment
- A short object that binds a polynomial.
The problem the paper names
General-purpose SNARKs without a setup were still too slow in the prover for the circuits people wanted to ship.
What the design proposes
- Sparsity is the saving. A dense encoding pays for zeros.
- There is no trusted setup.
- The commitment scheme is part of the proof system, not a chain primitive.
How the mechanism is specified
- Compile to R1CS.
- Treat the matrices as sparse.
- Prove the satisfying assignment with the polynomial protocol in the paper.
What this page does not treat as proven
- The paper's costs are asymptotic and experimental for its implementation, not a quote for a product.
- No setup does not mean no cryptographic assumption.
- It is not a consensus protocol.
Why a venture studio still reads it
A prover-time claim should say whether the circuit is sparse in the sense this paper uses. Otherwise the comparison is advertising.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
