We didn’t build ZK rollups to watch them bleed money. But that’s exactly what’s happening. Over the past six months, a quiet hemorrhage has been spreading across the Layer-2 ecosystem. A new report from a pseudonymous on-chain analyst, known as “ProverWatch,” dropped a bombshell this week: the average cost of generating a single ZK-SNARK proof for a rollup block has increased by 280% since the Ethereum Cancun upgrade. For the top five ZK rollups by TVL—zkSync Era, Scroll, Linea, Polygon zkEVM, and Starknet—the combined proving cost is now consuming over 40% of their gross transaction revenue. In a bear market where every basis point of operational efficiency matters, this is not a bug. It’s a structural crisis.
Let me walk you through the math. A typical ZK rollup batch processes thousands of transactions, then compresses them into a single cryptographic proof that is verified on Ethereum mainnet. The cost of that proof—computed on specialized hardware like GPUs or FPGAs—has been steadily rising as the complexity of circuits increases. The report shows that for zkSync Era, the cost per proof has gone from $150 in January 2024 to $570 in October 2024. That’s a 3.8x jump. For Scroll, the number is even worse: $200 to $800. The operators are not passing these costs to users because the market demands sub-penny fees. So they are eating the loss. The result? Several smaller ZK rollup sequencers are now operating at negative margins, surviving only on token subsidies and venture capital runway.
This is not just a financial problem. It’s a philosophical contradiction. The entire premise of ZK rollups is “trustless scalability” with minimal cost overhead. But if the proving cost alone eats nearly half the revenue, then the “scalability” is being subsidized by inflation and investor capital. It’s a shell game. We are paying for speed with the slow death of sustainable economics.
I remember the spark that drew me into this space. In 2017, I was a junior consultant in Chicago, drowning in fiat audit work. Late one night, I stumbled upon Vitalik’s ZK-SNARKs paper. The idea of “trustless truth” hit me like a lightning bolt. I abandoned my scheduled work, grabbed ZoKrates, and spent three months building a crude Proof-of-Knowledge demo. The result was a viral Medium article titled “Why Mathematics is the New Social Contract.” That article attracted a DAO focused on decentralized identity. But back then, the cost of proving was irrelevant. We were all idealists. We celebrated the theory. We ignored the cost.
Today, that cost is impossible to ignore. Let’s dive deeper into the numbers. The report breaks down proving costs into three components: hardware, electricity, and time. For a single proof on a top-tier GPU (NVIDIA A100), the hardware depreciation alone is $0.50 per hour. The proof generation time for a typical ZK rollup block (with 1000 transactions) is around 2 hours. That’s $1 in hardware cost per proof. Electricity adds another $0.30. But the real killer is the amortized cost of circuit development and maintenance. ZK circuits are not static; they are updated frequently to support new opcodes, reduce recursion overhead, or fix bugs. The report estimates that the top ZK rollups spend an average of $2 million per month on circuit engineering. Spread across their proofs, that adds $0.80 per proof. Total: $2.10 per proof in direct costs. But the actual reported cost is $570. That gap? It’s the cost of trust in the proving setup—the multi-party computation ceremonies, the audits, the insurance. The proving system is not just a computational cost; it’s a social cost. And that social cost is rising.
Identity isn’t about who you are; it’s about what you can prove. In ZK systems, the proving cost is the price of that identity. Every time a rollup operator submits a proof to Ethereum, they are essentially saying, “I have proven that I am honest.” But the cost of that proof is now so high that it’s undermining the very reason for the rollup’s existence. If the cost of verification exceeds the cost of the transactions, then the rollup is a net loss. We are paying more for the security theater than the actual security.
Let me ground this in a real-world example. During the 2020 DeFi Summer, I was running a governance experiment with a forked AMM protocol. We had over 500 participants in our weekly “Governance Jam” sessions. The community was vibrant, but the gas costs were killing us. Every proposal vote cost $50 in Ethereum fees. We thought ZK rollups would solve that. Fast forward to 2024, and I’m consulting for a DAO that is considering migrating to a ZK rollup. The DAO’s treasury spends $200,000 per month on transaction fees. The rollup promises to cut that to $20,000. But the DAO also needs to pay the rollup operator a $30,000 monthly fee for proving services. The net savings? $150,000. That sounds great. But the operator is bleeding money themselves. If the operator goes bankrupt, the DAO’s funds could be stuck. The sustainability of the entire ecosystem rests on the operators’ financial health.
This brings us to the contrarian angle. What if the high proving cost is actually a feature, not a bug? In a world where proof generation is cheap, anyone could run a rollup, leading to a race to the bottom where security is compromised. High proving costs create a natural barrier to entry, ensuring that only serious, well-funded operators can participate. It’s a form of proof-of-work for scalability. The operators who can afford the proving costs are the ones who have the resources to maintain security. This is a counter-intuitive take, but it has merit. The bear market is a filter. It weeds out the weak projects. The ZK rollups that survive this cost crisis will emerge stronger, with more efficient circuits and better business models.
But I’m not convinced. The data shows that the proving cost is not only high but also unpredictable. It fluctuates with the price of Ethereum, the cost of GPUs, and the complexity of new features. This unpredictability is toxic for planning. A rollup that cannot predict its own cost structure cannot promise stable fees to users. The market hates uncertainty. The current situation is a slow-motion crisis. We are not seeing a sudden collapse, but a gradual erosion of confidence. Institutional investors are starting to ask questions. The “ZK hype” that drove billions of dollars in funding in 2021-2022 is now being met with skepticism. The reports of high proving costs are becoming a common refrain in analyst calls.
Let me share a personal experience from the 2022 bear market. When the crash hit, my portfolio was devastated. I was depressed. But instead of wallowing, I turned to on-chain data. I started looking for “silent builders”—projects that continued to develop even as prices crashed. I identified 15 projects with high code activity but low price correlation. One of them was a ZK rollup project that had quietly improved its circuit efficiency by 30% over six months. That project is now one of the top rollups by TVL. The lesson is that the operators who are optimizing their proving costs are the ones who will survive. The ones who are complacent will die.
Now, let’s look at the competitive landscape. The report compares the proving costs of the top ZK rollups. Starknet, which uses a different proving system (STARKs), has the highest cost per proof: $1,200. But its proof size is smaller, so it pays less in Ethereum calldata fees. Linea, using an SNARK-based system, has a lower cost per proof ($400) but larger proof size. The total cost per batch (proof + calldata) is roughly equal for all. The real differentiator is the number of transactions per batch. Scroll, with a higher throughput, can spread the proving cost across more transactions, resulting in a lower cost per transaction. But all of them are still above the threshold of profitability. The report predicts that if the current trend continues, at least three of the top five ZK rollups will need to raise additional capital within 12 months to continue operations.
This is a classic tragedy of the commons. Every operator is trying to optimize their own costs, but the collective effect is a race to the bottom on fees. Users benefit from low fees, but the operators suffer. The market is not pricing in the true cost of security. It’s a classic externality. The solution? Shared proving networks. Imagine a marketplace where multiple rollups pool their proving resources. They share the cost of hardware and circuit development. This would reduce the cost per proof for everyone. There are already projects exploring this, like Espresso Systems and its shared sequencing layer. But the transition is slow. In the meantime, operators are bleeding.
I want to be clear: this is not a death knell for ZK rollups. It’s a growing pain. The technology is still young. The circuits are becoming more efficient. New proving systems like GKR and HyperPlonk promise lower costs. But the timeline is uncertain. The market is impatient. We need to address the economic reality.
Freedom is the presence of consent. In the ZK rollup world, consent is the agreement between the operator and the user about the true cost of the service. Right now, that consent is broken. The operator is hiding the cost behind token subsidies. The user is paying a fraction of the true cost. This is unsustainable. We need transparent pricing. We need to know how much it costs to prove a block. Only then can we have a healthy market.
Let me end with a forward-looking thought. The future of ZK rollups is not in lowering proving costs to zero. That’s impossible. The future is in making the cost visible and predictable. It’s in creating a new class of “proving-as-a-service” providers that compete on efficiency. It’s in letting the market decide what level of security is worth paying for. The next bull run will not be built on hype; it will be built on sustainable economics. The projects that survive this bear market will be the ones that have optimized their proving costs. They will be the ones that have built real revenue models. They will be the ones that have earned the trust of users and investors alike.
We are at a turning point. The ZK rollup narrative is being tested. The data is clear: proving costs are bleeding operators dry. But within that crisis lies an opportunity. The operators who solve this problem will become the backbone of the next generation of Ethereum scaling. They will be the ones who prove that the math can work—not just in theory, but in practice. And that is a truth worth building.
Let me leave you with a question: If the cost of proving honesty is too high, can we still be honest?

