Paper 2026/586
Bulletproofs*: Verifier-Efficient Arithmetic Circuit Proofs via Folding
Abstract
We present Bulletproofs* (BP*, BulletproofsStar), a folding scheme for arithmetic circuit proofs under standard assumptions and without preprocessing, i.e., for the arithmetic circuit satisfiability language of Bulletproofs (S&P 18), following the recipe of ProtoStar (ePrint 2023/620). To this end, we first adapt the algebraic verifiers of the arithmetic circuit proof of Bulletproofs to the algebraic form required by ProtoStar, and prove that the modified protocol remains secure. Then, we design the Bulletproofs* folding scheme that is complete and knowledge-sound. Finally, we analyze the resulting verifier cost after the folding-to-IVC transformation. The result shows an asymptotic linear gain compared to repeated invocations of the monolithic Bulletproofs verifier.
Note: Preprint. Revised version. This revision adds the complete proofs of Theorem 1 and Theorem 2, introduces the Commit-and-Open variant, and updates the folding construction, complexity analysis, and comparison accordingly.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Folding SchemeBulletproofsProtoStarZero-Knowledge ProofsIncremental Verifiable ComputationRecursive Proofs
- Contact author(s)
-
emsczkp @ proton me
daniele bartoli @ unipg it - History
- 2026-06-24: revised
- 2026-03-24: received
- See all versions
- Short URL
- https://ia.cr/2026/586
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/586,
author = {Emanuele Scala and Daniele Bartoli},
title = {Bulletproofs*: Verifier-Efficient Arithmetic Circuit Proofs via Folding},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/586},
year = {2026},
url = {https://eprint.iacr.org/2026/586}
}