Seven ZK proof configurations mapped on prover time vs. on-chain verification gas. Click any system to see proof size, setup requirements, and zkML viability. The annotated wrapper band shows the constant-gas region only reachable by STARK→SNARK wrapping.
FRI-STARKs are fast and trustless, but their proofs are megabytes wide. Groth16 is 256 bytes but needs a ceremony. STARK→SNARK wrapping resolves the tension — and it's why SP1 and RISC Zero can settle any ML inference on L1 for under 300k gas.