Paper 2026/586

Bulletproofs*: Verifier-Efficient Arithmetic Circuit Proofs via Folding

Emanuele Scala, Independent Researcher
Daniele Bartoli, University of Perugia
Abstract

We present Bulletproofs* (BP*, BulletproofsStar), a folding scheme for arithmetic circuit proofs under standard assumptions and without preprocessing, i.e., for the arithmetic circuit satisfiability language of Bulletproofs (S&P 18), following the recipe of ProtoStar (ePrint 2023/620). To this end, we first adapt the algebraic verifiers of the arithmetic circuit proof of Bulletproofs to the algebraic form required by ProtoStar, and prove that the modified protocol remains secure. Then, we design the Bulletproofs* folding scheme that is complete and knowledge-sound. Finally, we analyze the resulting verifier cost after the folding-to-IVC transformation. The result shows an asymptotic linear gain compared to repeated invocations of the monolithic Bulletproofs verifier.

Note: Preprint. Revised version. This revision adds the complete proofs of Theorem 1 and Theorem 2, introduces the Commit-and-Open variant, and updates the folding construction, complexity analysis, and comparison accordingly.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Folding SchemeBulletproofsProtoStarZero-Knowledge ProofsIncremental Verifiable ComputationRecursive Proofs
Contact author(s)
emsczkp @ proton me
daniele bartoli @ unipg it
History
2026-06-24: revised
2026-03-24: received
See all versions
Short URL
https://ia.cr/2026/586
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/586,
      author = {Emanuele Scala and Daniele Bartoli},
      title = {Bulletproofs*: Verifier-Efficient Arithmetic Circuit Proofs via Folding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/586},
      year = {2026},
      url = {https://eprint.iacr.org/2026/586}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.