فا
← BACK TO THE WIRE
N°0408ZK Tech2 MIN3 SOURCES

Akita Moves the ZK Bottleneck to Polynomial Commitments

LayerZero and a16z crypto have introduced Akita, a lattice-based polynomial commitment scheme integrated into a new Jolt release. The development matters because it targets post-quantum proving while reducing proof size, proving time, and memory use.

SHARE
ZK Tech
Akita Moves the ZK Bottleneck to Polynomial Commitments
IMAGE: AI-GENERATED

A new zero-knowledge development is changing the conversation from “which zkVM?” to “which cryptographic commitment layer?” On September 9, LayerZero announced Akita, a lattice-based polynomial commitment scheme designed for post-quantum proving systems. On September 10, a16z crypto described its first major deployment: Lattice Jolt, a rewritten Jolt zkVM using Akita instead of the elliptic-curve-based Dory commitment scheme.

That substitution is important because a polynomial commitment is not an optional add-on. It commits to the computation trace and lets a verifier check claims about that trace without receiving the entire computation. In Jolt’s architecture, replacing Dory with Akita changes the cryptographic foundation while leaving the broader lookup-oriented zkVM design intact.

The reported numbers are notable. LayerZero says Akita produces proofs of roughly 65–80 KB, compared with 200 KB or more for many hash-based post-quantum systems, and reports a 2–3× proving-time improvement for Jolt with about half the memory usage. The a16z account reports more than two million RISC-V cycles per second for CPU-only proving and more than ten million cycles per second with Metal on a MacBook. These are useful engineering targets, but they are not independent benchmark results.

The architectural trade-off is also clearer than the headline. Akita is based on the Module-SIS lattice assumption, while the previous Dory path relied on elliptic-curve cryptography. The move is intended to remove the quantum vulnerability associated with elliptic-curve commitments without accepting the larger proofs commonly associated with hash-based post-quantum approaches.

For ICP builders, the practical takeaway is not that a new zkVM is ready to drop into a canister. It is that commitment schemes are becoming a first-class deployment choice. A proof system used alongside ICP would need explicit checks for proof size, verifier cost, memory pressure, supported instruction set, reproducibility, and the exact security assumption behind the commitment layer. Smaller proofs can reduce transport and verification overhead, but they do not by themselves establish production safety.

One important caveat remains: the published performance and security claims come from the project teams, the Jolt repository still says the implementation is alpha and not suitable for production use, and the a16z announcement says a zero-knowledge privacy companion is forthcoming. The current release is therefore best read as an open engineering direction and a benchmark target, not as a finished privacy stack.

TAGSZK TechzkVMPost-Quantum CryptographyPolynomial Commitments
Grounded sources3 REFS
  1. [01]LayerZero Introduces Akita, the First Production-Ready, Lattice-Based Post-Quantum Polynomial Commitment Schemelayerzero.org ↗
  2. [02]How to prove software ran correctly — on a phone or GPU, in a post-quantum worlda16zcrypto.substack.com ↗
  3. [03]a16z Jolt repositorygithub.com ↗
Read next

Get the wire in your inbox

Every new signal, straight from the generator. No noise, unsubscribe anytime.

RSS AVAILABLE · NO SPAM