Akita Makes Post-Quantum ZK a Commitment-Layer Upgrade
LayerZero’s Akita proposes a lattice-based polynomial commitment scheme that targets a practical weakness in post-quantum ZK systems: proof size and verifier cost. Its integration with Jolt suggests that quantum-resistant proving may be improved by replacing one foundational component rather than rebuilding the entire zkVM.

Post-quantum zero-knowledge systems have often paid for cryptographic caution with larger proofs and heavier verification. Akita, introduced by LayerZero on September 9, 2026, takes a different route: upgrade the polynomial commitment scheme at the center of the proving stack.
A polynomial commitment lets a prover commit to a polynomial and later prove claims about it without revealing the entire polynomial. In a ZK system, that primitive sits close to the computation trace, so its security and performance affect the rest of the prover and verifier pipeline. Akita uses lattice-based assumptions, specifically Module-SIS, to provide a post-quantum alternative to elliptic-curve commitments while avoiding the very large proofs commonly associated with hash-based post-quantum approaches.
The accompanying technical paper describes three design goals that are difficult to achieve together: small proofs, fast verification, and security from standard lattice assumptions. Its central engineering move is “setup offloading”: public setup matrices are committed in advance, and the verifier’s work on those matrices is deferred and proved against the commitments. The paper says this reduces verification to a sublinear asymptotic cost for fixed configuration parameters while retaining logarithmic proof size.
The implementation is not merely theoretical. LayerZero released Akita as open-source Rust code, and the first highlighted integration is Jolt, the zkVM associated with a16z crypto and used by the Zero project. In the paper’s end-to-end measurements, Jolt with Akita achieved a 1.3× to 2.2× prover speedup and a 2.2× to 7.4× verifier speedup over Jolt with Dory, with proofs below 100 KB in the evaluated programs. LayerZero’s announcement summarizes a broader range of 65–80 KB proofs, 2–3× faster proving, and roughly half the memory use for Jolt.
Those numbers need careful framing. They are the authors’ own benchmark results, not an independent evaluation, and “production-ready” is LayerZero’s characterization; the paper itself presents a research implementation and experimental results. The figures also depend on parameter choices, workloads, and the comparison baseline.
The more important architectural signal is that post-quantum ZK need not be an all-or-nothing rewrite. If a commitment layer can supply quantum resistance while preserving the surrounding proving architecture, zkVM teams may be able to migrate incrementally: first the commitment primitive, then integrations, parameter tooling, distributed proving, and deployment operations. Akita’s paper explicitly includes batched openings, distributed proving support, and an offline parameter planner—features aimed at making that migration operational rather than purely cryptographic.
For ICP developers, the lesson is practical. A future proof-backed canister or chain-fusion service should evaluate more than proof validity: commitment assumptions, verifier cost, memory growth, parameter provenance, and whether the benchmark reflects the target workload. Akita does not prove that post-quantum ZK is solved. It does make the commitment layer a credible place to measure progress.
- [01]LayerZero Introduces Akita, the First Production-Ready, Lattice-Based Post-Quantum Polynomial Commitment Schemelayerzero.network ↗
- [02]Akita: A High-Performance Lattice-Based Polynomial Commitment Schemeassets.layerzero.network ↗
- [03]LayerZero-Labs/akita: A high-performance, lattice-based polynomial commitment schemegithub.com ↗
Get the wire in your inbox
Every new signal, straight from the generator. No noise, unsubscribe anytime.


