zkFMI
日本語

Measurements

Every reported number has an artifact under artifacts/ and a Rust binary that produced it. Where a measurement needs something not shipped (MP-SPDZ, a second host, a market feed) the binary says so and fails rather than substituting a default. Hosts are labelled, not named. Compare calibrations before comparing anything else.

Calibration

hostscalar multiplication40-bit range proofused for
host-c38.4 ± 4.1 µs20.88 msmost DeFMI tables, linear backend, vetting
host-a25.8 µsBulletproof backend, rings, PvP, one-chain unlinkability, VOLEitH

The same machine has been half again slower at another time. Cross-host ratios include host differences; rerun both arms on one host before using them as promotion evidence.

Settlement

Settlement cost against balance width 0 10 20 30 40 50 0 10 20 30 40 50 60 70 balance width, bits ms per DvP linear backend, settle (host-c): balance width, bits 8, 8.5 linear backend, settle (host-c): balance width, bits 16, 14.8 linear backend, settle (host-c): balance width, bits 24, 21.2 linear backend, settle (host-c): balance width, bits 32, 27.6 linear backend, settle (host-c): balance width, bits 40, 34 linear backend, settle (host-c): balance width, bits 48, 40.6 Bulletproof backend, settle (host-a): balance width, bits 8, 2.09 Bulletproof backend, settle (host-a): balance width, bits 16, 2.78 Bulletproof backend, settle (host-a): balance width, bits 32, 4.26 Bulletproof backend, settle (host-a): balance width, bits 64, 7.02 linear backend, settle (host-c) Bulletproof backend, settle (host-a)
Verification is linear in the width for the bit-decomposition backend (0.80 ms/bit, 2.1 ms intercept for the instruction itself) and roughly logarithmic for Bulletproofs. Hosts differ; see calibration. Artifacts: defmi.json, rust_bench.json.
whatfigureartifact
settle one DvP, 40-bit rails, linear backend34.0 ms · 57,939 Bdefmi.json
settle one DvP, 64-bit rails, Bulletproof backend7.02 ms · 3,424 Brust_bench.json
settlement cost slope (linear backend)0.80 ms/bit · 896 B/bitdefmi.json
zkPI verification inside settlement (intercept)2.1 msdefmi.json
securities 24-bit, cash 48-bit vs both 48−24% time · −10,752 Bdefmi.json
one node, 8 workers, verification only216.6 settlements/s (7.40×)defmi.json
asset tag per settlement+32 B · time inside 0.2 ms noisedefmi.json
asset membership at issue, 64 instrumentsverify 2.24 ms · 1,344 Bdefmi.json
note DvP in Rust, ring 8, incl. 3-of-7 FROST ceremonybuild 37.6 ms · settle 51.9 ms · 5,476 Bnote_dvp_rust.json
state root kept vs walked, 4,096 notes0.23 µs vs 15,325 µsnote_dvp_rust.json

Instruction and quote proof

whatfigureartifact
zkPI v2 product vector9,726 Bzkpi_vectors/accepted-v2.bin
zkPI v1 compatibility vector1,572 Bzkpi_vectors/
quote proof, 4 makersprove 152 ms · verify 173 msquote_proof.json (host-a)
quote proof, 8 makersprove 307 ms · verify 350 msquote_proof.json
auditability overhead (matched field)1.07× wall · 2.00× traffic · 1.00× roundsbinding_chain.json
per-party input check+1 round · +0.39% traffic · soundness 2⁻²⁴⁵input_check.json
Pedersen vs VOLE-in-the-Head, 167 values, n=3018.6/15.5 ms, 5,440 B vs 73.1/69.9 ms, 45,616 Bvoleith.json (host-a)

Privacy, priced

Note ring: who pays for the anonymity set 0 10 20 30 40 50 2 4 8 16 32 64 128 256 512 ring size (log scale) ms prove, payer's device: ring size (log scale) 2, 10.9 prove, payer's device: ring size (log scale) 4, 11.2 prove, payer's device: ring size (log scale) 8, 11.3 prove, payer's device: ring size (log scale) 16, 11.7 prove, payer's device: ring size (log scale) 32, 12.7 prove, payer's device: ring size (log scale) 64, 14.5 prove, payer's device: ring size (log scale) 128, 18.2 prove, payer's device: ring size (log scale) 256, 26.2 prove, payer's device: ring size (log scale) 512, 40.3 verify, settlement node: ring size (log scale) 2, 1.8 verify, settlement node: ring size (log scale) 4, 2.1 verify, settlement node: ring size (log scale) 8, 2.4 verify, settlement node: ring size (log scale) 16, 2.6 verify, settlement node: ring size (log scale) 32, 3.1 verify, settlement node: ring size (log scale) 64, 3.7 verify, settlement node: ring size (log scale) 128, 4.7 verify, settlement node: ring size (log scale) 256, 6.4 verify, settlement node: ring size (log scale) 512, 9.3 prove, payer's device verify, settlement node
The wire grows 224 B per doubling and verification stays under 10 ms to a ring of 512. Proving is what grows, so the payer caps the ring, not the node. Artifact: defmi.json.
whatfigureartifact
ring of 64: prove / verify / wire14.5 ms / 3.7 ms / 38,144 Bdefmi.json
ring of 512: prove / verify40.3 ms / 9.3 msdefmi.json
payee scan, per note0.063 msdefmi.json
observer vs ring 16, uniform decoys, 16 traffic0.359 (nominal 0.062)rings.json
observer vs ring 16, recent decoys, 16 traffic0.062rings.json
PvP: second mover's reaction0.06 mspvp.json (host-a)
one-chain adaptor vs single transaction, 16 swaps+3.0% verification · 4× callssame_chain.json
observer joining PvP legs, per-venue handles, 16 in flight0.062same_chain.json
observer joining PvP legs, one name everywhere1.000same_chain.json
real vs cover MPC slotsame rounds (286), same bytes (22.2 MB), Δ 0.01 saudit_slots.json
scoped viewing grant: issue / check0.08 / 0.07 msviewing.json
DP publication in MPC, n=728 rounds · 63.9 MB (92.9% of rounds is noise)distributed_publication.json

Clearing and reconciliation

whatfigureartifact
net-net vs gross-gross, 64 trades, 8 participants1.62×defmi.json
cycle-level attestation vs gross-gross19.40×defmi.json
DeCCP cleared cycle, 256 trades38.3 ms vs 794.6 ms net-net (20.7×)deccp.json, ccp_rust.json
novation per trade0.53 µsdeccp.json
intraday limit: coverage proof with / without9.2 / 9.4 msdefmi.json
default waterfall per tranchebuild 11.2 ms · verify ~1.4 msdefmi.json
reconciliation proof, any size96 B · check 0.65 ms at 4,096reconcile.json, reconcile_rust.json
vetting crowd 128: prove / verify / proof9.02 / 3.84 ms / 1,676 Bvetting.json

Network and consensus

One RFQ quote, 16 makers, by node placement 0.1 1 10 100 seconds (log scale) same rack|0 ms: 0.17 s 0.17 s same rack 0 ms same metro|1 ms: 0.62 s 0.62 s same metro 1 ms domestic|5 ms: 1.62 s 1.62 s domestic 5 ms Tokyo–Singapore|15 ms: 3.88 s 3.88 s Tokyo–Singapore 15 ms six near,|one at 120 ms: 23.0 s 23.0 s six near, one at 120 ms all far|120 ms: 26.1 s 26.1 s all far 120 ms
70 rounds, flat in makers and assets, so the wall clock is 70 × RTT of the slowest link. One distant node costs 86% of moving all seven. Artifacts: placement.json, sites.json (delay proxy on one host).
Requests per MPC job against time per quote 0 1,000 2,000 3,000 4,000 1 2 4 8 16 32 requests in one job, Q (log scale) ms per quote ms per quote at 15 ms one way: requests in one job, Q (log scale) 1, 3,425 ms per quote at 15 ms one way: requests in one job, Q (log scale) 2, 1,839 ms per quote at 15 ms one way: requests in one job, Q (log scale) 4, 1,007 ms per quote at 15 ms one way: requests in one job, Q (log scale) 8, 574 ms per quote at 15 ms one way: requests in one job, Q (log scale) 16, 377 ms per quote at 15 ms one way: requests in one job, Q (log scale) 32, 284 ms per quote at 15 ms one way
Rounds belong to the job, not the request: 69 rounds at Q=1, 5.5 per quote at Q=32. The job itself takes 9.1 s at Q=32, so one user's wait rises as throughput improves. Artifact: rounds.json.
whatfigureartifact
Avalanche L1: validators · settlement acceptance · restart recovery5 · 207.3 ms · 1,454.7 msavalanche_l1_acceptance.json
full QOMM path on L1: two RFQs atomically at height 53, claim at 54, restart with identical rootsacceptedavalanche_qomm_full_acceptance.json
one RFQ quote, M=16, 7 nodes: same rack / metro / 15 ms / 120 ms0.17 / 0.62 / 3.88 / 26.1 splacement.json, sites.json
six near, one far (120 ms)23.0 s (86% of all-far)sites.json
MPC rounds per quote70, flat in makers and assetsrounds.json
price drift over one cross-region quote vs within-block dispersion (UniswapX)1.01× medianstaleness.json
robust ATLAS, n=9, t=2: elements per party per multiplication18.2 vs 64.2 deployedrobust_atlas.json, robust_atlas_host_c.json
EVM: one ed25519 scalar multiplication302,401 gasstylus_gas.json
Solana: one-of-many verifier, crowd 32951,503 CU (ceiling 1.4M)solana_cu.json

Classical against post-quantum, side by side

Each row pairs one classical measurement with its post-quantum counterpart under the same method and host; the method, the predictions written before each run and the receipts are on the post-quantum page. One run each.

quantityclassicalpost-quantum (hybrid)ratiowhere measured
signature, make one (median)13.6 µs (Ed25519)359.3 µs (Ed25519 + ML-DSA-65)26.4×one core of the build host, RustCrypto backends, 2026-09-07
signature, check one (median)38.4 µs173.7 µs4.5×same
key exchange, encapsulate / decapsulate48.9 / 37.0 µs (X25519)88.1 / 79.6 µs (X25519 + ML-KEM-768)1.8× / 2.2×same
signature bytes / public key bytes64 / 32 B3,373 / 1,984 B52.7× / 62.0×FIPS 204 sizes, confirmed by the bench
TLS 1.3 handshake with mutual authentication, loopback1.07 ms (RSA-2048 certificates, as deployed) · 0.56 ms (Ed25519)2.19 ms (ML-DSA-65 certificates, X25519MLKEM768)2.0× · 3.9×OpenSSL 3.5.5 for every row, 2026-09-08
OCLOB order that rests, wall time (median)1,211.6 ms1,268.0 ms1.05×the two deployed images, idle 64-core host, 20 rounds each, 2026-09-08
OCLOB order that fills and settles (median)1,707.2 ms1,781.0 ms1.04×same
OCLOB order that rests, after the runner kept its parties alive (median)1,195.5 ms1,018.5 ms0.85×second run the same day, new hybrid image against the same classical image
OCLOB order that fills and settles, same change (median)1,707.2 ms1,505.4 ms0.88×same

The two order rows are what a user of the demo sees. Most of that time is the MPC round itself, which both images pay; the post-quantum share was 56 ms and 74 ms per order in the first run, and the causes (the per-round engine receipt hash, the 42 mutually authenticated handshakes, the hybrid application signatures) are separated on the post-quantum page. Once the receipt is hashed once per process and the seven parties stay alive between rounds, the hybrid image is 177 ms and 202 ms faster than the classical one.

Predictions that missed

The documents record predictions before runs, and the misses are kept beside the results because they are what the measurement was for.

  • Net-net was predicted at an eighth of gross-gross; measured 1.62×, because the zkPI verification per trade does not net away.
  • Note DvP was predicted by adding parts and was off by more than a factor of two.
  • Vetting verification was predicted to double with the crowd and grew 1.4×; that miss raised the default crowd from 16 to 128.
  • The 120 ms placement was predicted at 18 s from a model validated to 1.4% at 15 ms; measured 23 s, a 28% under-prediction.
  • Robust reconstruction was predicted 1.6× low.
  • "About ten probes" appeared in the paper three times and in no artifact; measured, the correlation does not grow with the budget, only the confidence does.
  • Two arms read 413 ms with 9 and 20 ms standard deviations on a loaded machine against a gap that should have been 14 ms. It was not measured to be zero; it was not measurable, and it was rerun.