Stickybit.← 0k-proofPortuguêsMeasurement · 0k-proof · Sep 30, 2026
Measurement · our own bench

What proving costs.

We built four proofs that serve real purposes (being over 18, having a balance above a value, being on a list of a million, knowing the text behind a digital fingerprint) and measured each in two proof systems, on an ordinary machine. Proving costs 25 ms to 40 s. Checking, 1.4 to 3.3 ms, every time. And none of the four cheats we tried got through.

Specimen · choose what to prove and with which system
The claim
The proof system
–constraints (steps of the computation)
–to generate the proof
–to check it
–proof size
–proving key
–machine hours to prove
–machine hours to check
–of proofs in transit
–one proof costs this many checks

Times and sizes measured on an Apple M2 (8 GB) with the gnark library. The per-day figures are our own arithmetic: measured time times quantity, assuming an identical machine dedicated to it, with no queue or network. In the real world, the prover is usually each person's phone, and the checker is the server.

Before the numbers

Four words for this page.

Constraint

Each elementary step of the computation the proof covers. "Born 18 or more years ago" becomes about two thousand steps; checking a SHA-256 becomes two hundred thousand. More steps, costlier proof.

Setup

Work done once before any proof, producing the keys for proving and for checking. It is not part of the cost of each proof.

Proving key

The file the prover needs at hand. It can be large: 371 kB to 51 MB here. It is public; it holds nobody's secret.

Proof system

The mathematical recipe that turns the computation into a proof. We measured two of the most used, Groth16 and PLONK, which trade size for convenience.

How we measured

Four claims, two systems, one machine.

Everything ran on an Apple M2 with 8 GB of memory, using gnark (version 0.16.3), an open-source Go library, over the BN254 curve, the most common one for this kind of proof. The library uses all of the machine's cores when proving and checking.

For each claim, we counted the steps in the computation, measured the setup once, and then the time to generate the proof (best of five attempts with Groth16, of three with PLONK) and to check it (best of twenty). "Best of" means the fastest time: what the machine can do when nothing else gets in the way.

The claims are not toys. Age and balance are tied to a commitment, a seal published beforehand by the issuer, so you cannot prove the age on a made-up document. The list uses a tree with 1,048,576 leaves. SHA-256 is the fingerprint used in almost everything on the internet.

ClaimSystemConstraintsSetupGenerate proofCheckProof sizeProving key
Over 18Groth162,184184 ms26 ms1.42 ms164 B371 kB
PLONK4,08565 ms91 ms2.11 ms520 B–
Balance above XGroth162,249236 ms25 ms1.38 ms164 B381 kB
PLONK4,21254 ms169 ms2.12 ms520 B–
On the list of 1 millionGroth1613,2611.9 s220 ms1.94 ms164 B2.5 MB
PLONK17,781414 ms859 ms2.82 ms520 B–
Text behind the SHA-256Groth16200,59945.7 s1.6 s3.25 ms196 B51.3 MB
PLONK601,6017.3 s40.6 s2.49 ms584 B–

For PLONK, the proving key was not measured, and the setup used was a test version generated on the spot. In production it would come from a public ceremony done once for all claims. That does not change the time to prove or to check.

The asymmetry

Proving is expensive. Checking is cheap.

The time to generate the proof grows with the size of the computation: 26 ms for age, 220 ms for the list, 1.6 s for SHA-256 with Groth16, and up to 40 s with PLONK. Checking stays between 1.4 and 3.3 milliseconds in every case, no matter how big the computation behind it.

That difference is what makes the idea useful. The prover pays once, on their own device. The checker, a website with millions of visits or an auditor with thousands of reports, pays almost nothing per proof. For age, one proof costs as much as about 18 checks; for SHA-256 with PLONK, about 16 thousand.

Why is SHA-256 so much costlier? It was designed for ordinary computers, built from bit operations. Inside a proof, every bit becomes a computation. The fingerprint we used for age, balance and the list (MiMC) was designed precisely to fit inside proofs: it plays the same role with hundreds of times fewer steps.

GENERATING THE PROOF · LOG SCALE10 ms100 ms1 s10 s100 sOver 1826 ms91 msBalance above X25 ms169 msOn a list of 1 million220 ms859 msText behind the SHA-2561.6 s40.6 sGroth16PLONK
Time to generate the proof, on the Apple M2. Each tick on the scale multiplies by ten.
CHECKING THE PROOF · LOG SCALE1 ms2 ms5 ms10 msOver 181.42 ms2.11 msBalance above X1.38 ms2.12 msOn a list of 1 million1.94 ms2.82 msText behind the SHA-2563.25 ms2.49 msGroth16PLONK
Time to check. The scale only runs from 1 to 10 ms: all eight bars fit in the same handful of milliseconds.
SIZE · LOG SCALE100 B10 kB1 MB100 MBOver 18164 B520 B371 kBBalance above X164 B520 B381 kBOn a list of 1 million164 B520 B2.5 MBText behind the SHA-256196 B584 B51.3 MBproof Groth16proof PLONKproving key (Groth16)
The proof fits easily in a QR code. What weighs is the key the prover has to keep: 51 MB for SHA-256 with Groth16.
The two systems

Smaller and faster, or easier to set up.

Groth16 · 2016

The most compact proof

Proofs of 164 bytes for almost any claim, and the fastest to generate on this bench. The price is in the setup: each claim needs its own, and it uses a secret number that has to be destroyed afterwards.

If someone keeps that number, they can forge false proofs that pass the check. That is why a real setup is done in a ceremony with many participants: it takes just one of them destroying their share for the whole to be safe.

PLONK · 2019

One setup for all

A single setup, done once, works for any claim up to a certain size. If the rule changes, no new ceremony is needed.

The price: proofs of 520 bytes, three times larger, and here 3 to 25 times slower to generate. Checking costs the same. On this bench, the setup was a test version, not fit for real use.

There are also systems that need no secret setup at all, known as STARKs, generally with much larger proofs. We did not measure them here.

The cheats

We tried to cheat. No false proof got through.

A test that only shows the right case does not say much. So we asked for proofs that should be impossible, and checked that the library refused to generate or accept them.

AttemptHowResult
MinorBorn in 2010, proving over 18 in 2026rejected
Someone else's documentA date of birth that does not match the seal published by the issuerrejected
Reused proofA proof valid for 2026, presented as if it were for the year 2000rejected
Insufficient balanceA balance of 9,000 proving it is above 10,000rejected
What we do not know yet

What this bench did not measure.

The phone

In real life, whoever proves their age does it on a phone, with less memory and no fan. An eight-core M2 is optimistic. The 51 MB key for SHA-256 would weigh on a basic device.

The browser

Proofs generated inside a web page tend to be much slower than the same code running directly on the machine. We did not measure it.

Other libraries

The age proof Google open-sourced in 2025 (Longfellow) uses a different design, built for phone credentials. Its numbers are not these.

One run, one machine

"Best of five" shows what the machine can do without interference, not the average of a busy server. And the memory used while proving was left out.

Reproduce

Run it yourself.

The bench code is a little over 200 lines of Go and is published here: main.go, falsa_test.go, go.mod and go.sum (with a README, in Portuguese). Download the four into one folder and, with Go installed, run two commands:

# prints the table on this page
go run .
# tries the four cheats; passes if all are rejected
go test -run TestFalsa -count=1 .
The section

To go deeper.

Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← 0k-proof · stickybit.com.br

Sources