# Apogee at a Glance

> The facts on one page. What Apogee VM proves, how it proves it, what that costs, what it assumes, and where version 1.0.0 stops.

## In one paragraph

Apogee VM is a RISC-V zkVM. It proves that an RV32IMAC program, named by a digest of its image, ran on a given public input to an exit status and wrote a given public output. It carries that proof through a recursion tree to one Groth16 proof that an Ethereum contract checks. Every circuit is a layered GKR circuit over BN254's scalar field, every committed column is opened with Mercury, and every challenge comes from a Poseidon2 transcript. The fields, curve, pairing, MSM, hash, polynomial commitment, GKR prover and Groth16 are all implemented in the repository. Its reference workload is Ethereum block validation.

## The facts

| | Apogee VM v1.0.0 |
| --- | --- |
| What a proof states | That the program with this identity, started at its entry point over its image, with this public input and some advice, executed instruction by instruction to `EXIT` with this status, having written this journal |
| Instruction set | RV32IMAC on one hart: the 59 instructions of RV32IMA (40 base, 8 M, 11 A), with compressed instructions expanded at load |
| Guest language | Rust, `#![no_std]` with `alloc`, stable 1.96.1, target `riscv32imac-unknown-none-elf` |
| Arithmetization | 23 circuit families, each a layered GKR circuit: 7 for instructions, 5 for memory windows, 6 delegations, 5 for recursion |
| Arguments | Gates by sumcheck; memory by one read/write multiset over the whole execution; lookups by LogUp |
| Field | BN254's scalar field, 254 bits |
| Commitments | Mercury, multilinear over KZG, one 704-byte opening per shard whatever the column count |
| Setup | The PSE perpetual powers of tau, contribution 80; a second, circuit-specific ceremony for the on-chain decider |
| Transcript | A Poseidon2 duplex sponge over `Fr`, width 3, rate 2 |
| Settlement | Recursion tree → Groth16 decider → `ApogeeVerifier.sol` |
| Security level | About 100 bits, set by BN254 |
| Zero knowledge | No. Proofs are succinct, not zero-knowledge, and nothing is blinded |
| Delegated operations | keccak-f[1600] rounds, SHA-256 rounds, Poseidon2, BN254 `Fr` arithmetic, 256-bit modular multiplication over four Ethereum moduli, complete point addition on secp256k1 and BN254 G1 |
| Public values | At most 16,380 bytes of input and 16,380 bytes of journal; advice up to 2 GiB |
| Execution length | Up to `2^36 − 1` cycles |
| Code size | `.text` within 7.94 MiB at a `2^22` table height; image within 4 MiB by default |
| Third-party cryptography | None on a proof path. arkworks, Plonky3 and zkhash appear only as test oracles |

## Measured

All figures are block 257,510 of `glamsterdam-devnet-8`, run through the stateless validator guest: 60 transactions, 101.5 Mgas, 198M cycles. Sources: the specification's [recursion §10](https://apogee.gweb3networks.com/docs/auditors/spec/recursion#s10) and [streaming §1](https://apogee.gweb3networks.com/docs/auditors/spec/streaming#s1).

| Stage | Result |
| --- | --- |
| Base proof | 207 shards, 14.5 MB, 2,481 s on 32 vCPUs and 247.7 GiB, peak RSS 173.92 GiB |
| Recursion tree | 116 shards: four leaves of at most 64 base shards (2,157 s together, 92 GiB peak) and a root (460 s, 1.03 MB) |
| Decider circuit | 7,896,686 constraints over a domain of `2^23` |
| Decider proof | 18.5 s and 6.1 GB on an 18-core laptop, with the key read in 1 s |
| On-chain verification | 3,620,026 gas, 34,980 bytes of calldata, 358 points folded by the contract |
| Conformance | All 67,251 `tests-zkevm` v21.0.1 pairs match natively |

## What a verifier must hold

Two values, taken from a channel the prover does not control:

- **The program identity**, one field element. Against an identity supplied by the prover, a proof shows only that some program ran.
- **The SRS digest of the ceremony.** A key built over a known `τ` is refused only by this comparison.

The verifying key itself may come from anyone: loading it recomputes both values from its own contents and holds its circuits to the verifier's registry. [The security model](https://apogee.gweb3networks.com/docs/architecture/security) has the full list of assumptions.

## Where v1.0.0 stops

- **Not zero-knowledge.** No blinding in Mercury, GKR or the decider.
- **Advice is unbound.** A guest checks it against something a proof binds.
- **Traps are not provable.** A misaligned access, an access outside mapped memory, `ebreak`, or a pc with no instruction ends the run with no proof.
- **`sc.w` always succeeds.** The one deviation from RV32IMAC: there is no reservation state.
- **Delegations are a fixed set of six.** EVM `MULMOD` with an arbitrary modulus, `MODEXP` and BLS12-381 run as ordinary instructions.
- **Proving is memory-bound.** The measured block peaked at 174 GiB; memory follows the shards in flight, not the length of the run.
- **The decider key is per root shape**, and only as trustworthy as its ceremony. The development key is forgeable.

## Who builds it

Apogee VM is the flagship of G Web3's research program toward blockchain-native application environments: one optimized environment per economic application, each settling to Ethereum with a validity proof. The program's position is set out in [the thesis](https://www.gweb3networks.com/thesis.html); where the next version goes is [Quantum Leap](https://apogee.gweb3networks.com/docs/quantum-leap).
