# Keccacheck: solving the Keccak bottleneck in zk SNARKs | Greg Swirski (Reilabs) at ETHConf

- Channel: [ETHGlobal](https://streameth.org/ethglobal)
- Date: 2026-07-09
- Duration: 15:24
- Topics: Keccacheck, Reilabs, ETHConf, Keccak, zk SNARKs, zero knowledge proofs, ZKPs, ZK circuits, Ethereum scaling, transaction volume, ZK-KYC, credit scoring, risk scoring, hash function, EVM, state commitment, storage proofs, Poseidon, STARK, SNARK, GKR, polynomials, sublinear scaling, ZKVM, proving, privacy, mobile proving, accredited investor, sanctions, block hash, state root, batch proving, GPU, CPU, institutional, on-chain agents, white paper
- Watch: https://streameth.org/watch/yt-xCHMYHMtv8k
- YouTube: https://www.youtube.com/watch?v=xCHMYHMtv8k

## Description

In this more technical talk, Greg Swirski from Reilabs explains how his team solved the Keccak bottleneck in zero knowledge SNARKs. He opens by grounding zero knowledge cryptography, often called the future of Ethereum and blockchain scaling, in three concrete uses. First, increasing transaction volume: today every Ethereum node must re-execute transactions to check they followed the rules, which caps throughput, but if validators only need to verify a proof rather than re-execute, the whole network can scale. Second, onboarding institutions safely through ZK-KYC, where you never upload passport data to a public chain but instead attest that you are not from a sanctioned country or are an accredited investor via a small proof revealing nothing else. Third, as volume and counterparties grow, private credit or risk scoring lets a party prove they have funds somewhere without revealing positions or strategies. The roadblock across all three is Keccak, the hash function Ethereum and every EVM chain uses to commit to blockchain state, which is fast on CPU but extremely expensive to prove inside ZK circuits, and far too entrenched to replace.

Greg's key insight is that you almost never prove a single Keccak hash, always hundreds or thousands at once, and his team leveraged that to beat the state of the art. He shows why: modern ZKVMs spend around 40% of their time proving hidden Keccak hashes you never see in Solidity, storage proofs chain from block hash through state root to account to storage slot, and ZK-KYC wraps a fast but large STARK inner proof inside a tiny SNARK outer proof that must itself compute thousands of hashes. Whereas many use the ZK-friendly but CPU-slow Poseidon hash, their protocol Keccacheck lets you switch back to Keccak (about 10x faster than Poseidon on CPU) for roughly a 5x inner-proof improvement at small outer overhead. The approach builds on the GKR protocol, which expresses programs as polynomials and scales sublinearly (analogous to a GPU versus a CPU), but base GKR was too slow, so they custom-built every Keccak operation to run batch-wise across all instances at once. The result breaks even against a popular state of the art framework at roughly 16 to 32 Keccak instances and runs 10 to 30x faster at 200 to 500 instances. He closes on future applications like mobile proving where passport data never leaves your phone and privacy-preserving institutional ZK-KYC with on-chain agents, pointing to a blog post, white paper, and GitHub repo via QR code.

00:00 Introduction
00:11 A More Technical Talk
00:34 Who Works With ZK Circuits
00:55 Three Aspects of Zero Knowledge
01:03 Increasing Transaction Volume
01:25 From Re-Executing to Verifying Proofs
01:48 Onboarding Institutions With ZK-KYC
02:10 Attesting Without Revealing Passport Data
02:45 Private Credit and Risk Scoring
03:06 The Roadblock: Keccak
03:31 How Keccak Commits to State
03:56 Why Keccak Is Hard to Prove in ZK
04:18 Why We Cannot Just Replace It
04:43 The Key Insight: Proving Many Hashes at Once
05:07 Why We Always Deal With Many Instances
05:30 The Hidden Keccaks in Every Transaction
06:13 Proving Wallet Properties for Risk Scoring
06:33 Chaining Trust From Balance to Block Hash
07:00 The ZK-KYC Problem
07:27 Wrapping a STARK in a SNARK
08:11 Why the Outer Layer Needs Thousands of Hashes
08:35 The Hash Function Trade-Off
08:58 Poseidon vs Keccak
09:21 Introducing the Keccacheck Protocol
09:52 Building on the GKR Protocol
10:20 GKR and Sublinear Scaling
10:49 The CPU vs GPU Analogy
11:13 Applying GKR to Keccak
11:45 Why Base GKR Was Too Slow
12:17 Applying Operations Batch-Wise at Once
12:44 Breaking Even at 16 to 32 Instances
13:19 10 to 30x Faster at Scale
13:45 Still Room to Improve ZK Circuits
14:00 Accelerating Mobile Proving
14:19 Privacy-Preserving Institutional ZK-KYC
14:50 Where to Learn More
15:11 Closing

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

*ETHConf 2026*
ETHConf is a 3 day event for founders, industry leaders, and builders who are excited about the possibilities of building on top of Ethereum.

Connect with 2,000+ top innovators in crypto, finance, technology, and policy at our inaugural three-day event packed with showcases, demos, partnerships, and conversations shaping the future of the global economy.

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

✅ *Follow ETHConf*
X: https://x.com/ethconf
Website: https://ethconf.com

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

🎟️ Get your early bird tickets for ETHConf 2027: https://ethconf.com/2027#tickets
🎤 View the full ETHConf 2026 Speaker Schedule: https://ethconf.com/schedule

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
