Skip to main content
Every number here is measured. Circuit size comes from bb gates; timings are on Apple Silicon (arm64); on-chain costs are the actual fees charged for real testnet transactions.

Circuit

Proving (client-side, off-chain)

Artifacts

On-chain verification cost

The load-bearing number: a real UltraHonk proof is verified on-chain inside verify_and_execute, within Soroban’s standard per-transaction resource limits.
On-chain UltraHonk verification is cheap enough to run inside a normal payment transaction on testnet — no elevated limits required.

Reproduce