Research · Papers · Adders, counters and the heap law · ML-065
BLAKE3 and ARX redeployment limits from banked addition assets
Direct redeployment of banked addition assets yields ≥ 10304 products on BLAKE3, exceeding the 10298-product conditional leader
Published 2026-09-04
For everyone
Plain summary
BLAKE3 is a cryptographic hash function built on additions, bit rotations, and XORs (an ARX design). When translating these algorithms into algebraic circuits for zero-knowledge proofs, every nonlinear multiplication product adds proof cost. We checked whether dropping existing, banked adder designs into the live BLAKE3 compression board would lower its product count. It does not. Direct redeployment takes at least 10,304 products, falling short of the current 10,298-product conditional leader. Closed FullAdd substitutions do worse at 10,752 products because they compute unused carry bits, while banked width-three adders do not match the required operand shapes. Existing banked adders win zero rows on the BLAKE3 board.
Result
Direct redeployment of banked addition assets cannot improve the product count of the live BLAKE3 compression board under current arsenal constraints. Every available substitution requires >= 10,304 products, exceeding the conditionally translated 10,298-product leader.
Setting and definitions
Target architecture: the live BLAKE3 compression board under the GF(2) XOR-free multiplicative complexity cost model (allocations plus constraints).
Target board requirements:
- 112 ternary truncated width-32 additions
- 112 binary truncated width-32 additions
Candidate banked adder assets:
- Unproved (2n-3) ternary ripple adder
- Public (n-1) binary ripple adder
- Closed FullAdd substitution
- Banked width-three (9,3) and (10,3) constructions
Method
Lower-bound evaluation across all 112 ternary and 112 binary width-32 addition instances:
- Combining the (2n-3) ternary ripple with the public (n-1) binary ripple for n = 32 gives:
- The closed FullAdd substitution yields:
- The banked (9,3) and (10,3) width-three units have incompatible operand and width shapes for the truncated 32-bit addition rows.
112 * (2 * 32 - 3) + 112 * (32 - 1) = 10,304 products. This trails the conditionally translated leader (10,298 products) by 6 products.
112 * (3 * 32) + 112 * (32) = 10,752 products (454 products worse than the leader), spending budget on unneeded carry outputs.
Total rows exposed by current banked assets: zero.
Scout receipt: zkgolf-decomp/REDEPLOY-ARX-ADDITION.md.
Discussion
Direct addition asset redeployment from the current arsenal cannot beat the live BLAKE3 compression board.
The 10,298-product baseline comparison remains conditional because the public score tallies allocations plus constraints rather than pure gate complexity. Because the (2n-3) ternary ripple is an unproved optimistic bound, actual banked deployments cannot beat 10,304 products. This result does not bound novel, unbanked adder designs or joint ARX optimizations built specifically for BLAKE3.
For everyone — the takeaway
What this means
You cannot plug off-the-shelf adder components into BLAKE3 to beat current zero-knowledge efficiency records. Even under optimistic assumptions, standard adders compute unneeded outputs and fall behind custom baselines. Improving BLAKE3 circuits requires tailored additions or joint ARX optimizations rather than standard adder libraries.
Register references
- ML-065
zkgolf-decomp/REDEPLOY-ARX-ADDITION.md
Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.
Evidence pack
Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 0 of 1 receipt files bundled (1 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.
Changelog
Last reviewed 2026-09-04
- 2026-09-04Published on this site.