Research · Papers · The SHA-256 record and exact synthesis · ML-063
SHA-256 compilation record and status of conditional sub-22,215 alternatives
SHA-256 record = 22215 rows; hypothetical alternatives at 20612, 20531, and 22185 remain conditional without full witnesses
Published 2026-09-04
For everyone
Plain summary
Zero-knowledge proof systems often run cryptographic hash functions like SHA-256 inside mathematical circuits. Circuit size is measured in rows. Fewer rows mean faster verification and lower computing costs.
The verified compilation record for SHA-256 stands at 22,215 rows. Literature mentions smaller totals like 20,612, 20,531, and 22,185 rows, but none of these is a working, assembled circuit. They are conditional projections based on unverified assumptions. They lack valid witness values and complete assembly orders. As a result, 22,215 rows remains the only verified benchmark record for this construction.
Result
Under the GF(2) XOR-free XAG cost model, the verified minimal compilation record for SHA-256 is 22,215 rows. The record is realized by an ordered identity-C artifact satisfying full component reconciliation with an authorized row delta of zero.
Hypothetical sub-22,215 configurations remain conditional and unachieved:
- The 20,612-row configuration assumes every J block and red block compiles at 92.
- The 20,531-row configuration assumes an unverified all-five-interface scenario.
- The 22,185-row configuration assumes an isolated 61-product Canon33 block.
None of these three alternatives provides valid witness generators or an end-to-end ordered compilation.
Setting and definitions
The target is the arithmetization of the SHA-256 compression function within a GF(2) XOR-free XAG cost model.
A compilation record requires an end-to-end ordered circuit realization with an explicit witness assignment pipeline, exact component reconciliation across all sub-blocks (message schedule expansion, round functions, and modular additions), and an authorized row delta of zero. Candidate configurations lacking an ordered identity layout or complete witness pipelines are designated conditional.
Method
Formal component reconciliation and full verification of the ordered identity-C artifact establish the 22,215-row record at formal evidence tier P + FR.
Artifact verification is documented across four reports:
- zkgolf-decomp/reports/RECORD-BOM.md
- zkgolf-decomp/reports/CONST-THEORY.md
- zkgolf-decomp/reports/CERT-SYNTH.md
- zkgolf-decomp/reports/STATE-OF-PROGRAM-V2.md
The record is supported by two AX162 receipts:
zkgolf-decomp/synth-n-scratch/recompute_capstone.receipt.json(SHA-256:3c23b130a6dbe5dc0f22226d653870d4a204e4c28e1b2af18192e5688efd9843)zkgolf-decomp/const-theory-scratch/heap-and-width32.receipt.json(SHA-256:97495ea7cb13222225e45598ceef9956d61e9684d0c2001e96613a41f83a4da0)
Auditing the alternative row counts (20,612, 20,531, and 22,185) against these compilation requirements confirmed that each relies on unproven local optimizations lacking end-to-end witness generation and global pipeline compatibility, assigning them to evidence tier conditional/N/E.
Discussion
The scope of the verified record is restricted to the 22,215-row ordered identity-C artifact.
Auditing resolves the status of proposed sub-22,215 candidate designs:
- The 20,612 candidate fails because compiling all J and red blocks at 92 cost units lacks a global witness realization.
- The 20,531 candidate is an older decomposition based on a theoretical all-five-interface model without ordered integration.
- The 22,185 candidate isolates a 61-product Canon33 assumption without full end-to-end assembly.
These alternatives cannot be cited as realized circuit sizes; the proved boundary remains 22,215 rows. Related analyses are indexed under MF-108 and MF-126.
For everyone — the takeaway
What this means
Circuit designers building zero-knowledge applications must use 22,215 rows as the definitive, realized size for this SHA-256 design. Theoretical papers sometimes explore whether SHA-256 could reach smaller row counts, but those proposals lack working circuit generators and full proofs. Treating conditional numbers as working implementations breaks production pipelines. The verified 22,215-row design is the only active record with complete end-to-end artifacts.
Register references
- Entry: ML-063
- Related entries: MF-108, MF-126
- Reports:
zkgolf-decomp/reports/RECORD-BOM.mdzkgolf-decomp/reports/CONST-THEORY.mdzkgolf-decomp/reports/CERT-SYNTH.mdzkgolf-decomp/reports/STATE-OF-PROGRAM-V2.md- Receipts:
zkgolf-decomp/synth-n-scratch/recompute_capstone.receipt.json(SHA-256:3c23b130a6dbe5dc0f22226d653870d4a204e4c28e1b2af18192e5688efd9843)zkgolf-decomp/const-theory-scratch/heap-and-width32.receipt.json(SHA-256:97495ea7cb13222225e45598ceef9956d61e9684d0c2001e96613a41f83a4da0)
Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.
Evidence pack
Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 4 of 6 receipt files bundled (41 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.
Changelog
Last reviewed 2026-09-04
- 2026-09-04Published on this site.