aggregate

the K-to-1 path that keeps on-chain cost flat in N

01

the real result

what happened on testnet on 2026-06-27
verified on-chain
inner proofs4 UltraHonk private-transfer proofs
aggregator1 outer UltraHonk proof (K-to-1)
on-chain1 verify_proof tx
savings versus naive
naive · 4 verifies122,224 stroops
recursive · 1 verify136,009 stroops
absolute savings-13,785 stroops
recursivenaive · 100%
recursive is 111.3% of naive · -11.3% saved

At K=4 the recursive line costs more in absolute terms (UltraHonk verification is structurally heavier than Groth16). The crossover with naive happens around N=5; past that the flat line wins, and at N=64 the recursive path is roughly 14× cheaper. The simulator below makes that visible.

02

the simulator

drag N · 1 ≤ N ≤ 1,024
N · inner proofs64
1416642561,024
tree K4
depth3
aggregator proofs21
off-chain prove time15.8 min est.
naive · on-chain1,955,584 stroops
recursive · on-chain136,009 stroops · flat
recursive savings93% vs naive
tx count · naive64
tx count · recursive1
tree composition
L0
L1○ ○ ○ ○
L2○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○ ○
L3◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ ◦ +48 more
● root outer proof · ○ aggregator child · ◦ leaf inner proof
03

operator console

what a live aggregator service would expose
ad-hoc invocation today— no continuously running aggregator service in this deployment

Today the aggregator runs on demand via circuits/aggregator/build.sh — produces one outer proof from K queued inner proofs, then exits. The panel below shows what a continuously running service would expose to its operators: pending-K-fill bar, throughput sparkline, tree-composition depth indicator. Mock values shown.

K-fill (next batch)
0 / 4
awaiting inner proofs
throughput · last hour
ops/min
root cost · last verify
136,009 stroops
ledger 3,310,893