Engineering
The major engineering efforts inside Zakura: what each one changes, why it matters, and where it stands.
Consensus · Measured
Our 80-node, equal-hashpower Zakura stressnet spread evenly across 11 regions measured a 3.43% orphan rate while mining full 2MB blocks every 25 seconds.
Read about Testing 25-Second Blocks for NU7
Performance · In development
Halo 2 verification ends with a multiscalar multiplication whose result is only tested against the identity, and most of its bases never change. Preparing those fixed bases and recoding the scalars over the Eisenstein integers cuts one-Action Ironwood bundle validation time by 29% on one worker and 21% on eight.
Read about Prepared Multiscalar Zero-Checks
Performance · In development
Building Halo 2's Lagrange-basis commitment key takes an inverse FFT over elliptic-curve points, where every nontrivial twiddle is a full scalar multiplication. Mixed-radix 8- and 16-point codelets let us perform fewer of them.
Read about Fastest ecFFT in the West
Performance · Landed
A large part of the cost of Pasta field multiplication is Montgomery reduction. By delaying reductions until they are actually needed, we can remove substantial amounts of work from the halo2 prover and from lower-level curve arithmetic.
Read about Avoiding Montgomery Reductions
Performance · Landed
Counting field multiplications misses how a modern CPU actually runs them. Splitting one serial chain into two independent chains lets the multiplier overlap them, cutting field-multiplication time by about 35% and speeding up batch inversion and wallet scanning.
Read about Data Dependencies in Field Multiplication
Performance · Landed
pasta_curves computed field inverses with Fermat's little theorem: hundreds of dependent squarings and multiplications. We ported Peter Dettman's signed-62 safegcd inversion from libsecp256k1 and specialized it for Montgomery form and the unusually sparse Pasta moduli, taking Fp::invert from about 3.44 μs to 756 ns, a speedup of about 4.6×.
Read about Porting libsecp256k1's Modular Inversion to Pasta
Cryptography · Landed
Ironwood and Orchard hash the internal nodes of their note commitment trees with Sinsemilla, a Pedersen-hash variant that wallets evaluate to keep funds spendable and full nodes evaluate many times for every block. Every parent hash has exactly 52 words, so every doubling can move into a precomputed position-weighted table, leaving one mixed addition per word: about 3.5× faster in our benchmarks.
Read about Position-Weighted Sinsemilla
Cryptography · In development
Wallet scanning multiplies every incoming point by the same secret viewing key. Recoding that key once as a single Eisenstein integer, then sharing batched inversions across a wide affine ladder, benchmarks 16–20% faster than the current GLV approach in batch trial decryption at 64 outputs and up.
Read about Batch Affine Ladders with Eisenstein Recoding