LibraryScaling2022Design paperCorpus record
SuperNova: Proving Universal Machine Executions without Universal Circuits
SuperNova. Abhiram Kothapalli and Srinath Setty.
SuperNova folds a universal machine by switching among circuits without a universal circuit that contains every instruction.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
A zkVM pitch should say whether each instruction is folded, or whether one giant circuit is proven every step.
The five-minute read
The defect
A folding scheme that only folds one circuit cannot cheaply prove a machine that switches programs.
The proposal
SuperNova folds a universal machine by switching among circuits without a universal circuit that contains every instruction.
Non-uniform computation is the point. The program may change.
Folding commits to the running instance instead of proving it from scratch.
The bound
The paper is not a zkVM product.
One action, walked through
- Represent the machine step as a circuit from a set.
- Fold the current instance into a running claim.
- Prove the final claim once.
- What is the running instance?
The argument, unpacked
What the paper is for
A zkVM pitch should say whether each instruction is folded, or whether one giant circuit is proven every step.
What happened after
Nova is the predecessor for a single circuit. HyperNova generalises the arithmetisation further.
What has to be true
- The paper is not a zkVM product.
- The set of circuits still has to be the instruction set you claim.
- Folding errors compound if the instance relation is wrong.
What happened after the paper
Nova is the predecessor for a single circuit. HyperNova generalises the arithmetisation further.
What to check before you use the idea
- Does the proof switch circuits?
- What is the running instance?
- Is there a universal circuit hiding in the implementation?
Terms
- Folding
- Compressing two instances of a relation into one instance.
- Universal circuit
- One circuit that interprets every program, which this paper avoids.
The problem the paper names
A folding scheme that only folds one circuit cannot cheaply prove a machine that switches programs.
What the design proposes
- Non-uniform computation is the point. The program may change.
- Folding commits to the running instance instead of proving it from scratch.
- A universal circuit is the design this paper refuses.
How the mechanism is specified
- Represent the machine step as a circuit from a set.
- Fold the current instance into a running claim.
- Prove the final claim once.
What this page does not treat as proven
- The paper is not a zkVM product.
- The set of circuits still has to be the instruction set you claim.
- Folding errors compound if the instance relation is wrong.
Why a venture studio still reads it
A zkVM pitch should say whether each instruction is folded, or whether one giant circuit is proven every step.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
