Starknetās Stwo prover cuts peak memory to 2.1 GiB, putting STARK proofs on phones
Open research slashed the prover's memory needs from 13.9 GiB, making smartphone-generated Starknet transaction proofs possible
Generating a zero-knowledge proof has long been a job for serious hardware. Now a phone can do it.
Open research on Stwo, the prover powering Starknet, has reduced its peak memory use from 13.9 GiB to 2.1 GiB. That reduction is what allows a smartphone to generate proofs for Starknet transactions.
From workstation territory to your pocket
A prover is software that produces a cryptographic proof. Think of the proof as a compact mathematical receipt showing that a batch of computation was done correctly.
Anyone can check that receipt quickly without redoing the work. STARK proofs, the type Starknet relies on, are one way to build those receipts.
Peak memory is the most RAM the prover needs at any single moment during that job. The research narrowed that doorway requirement dramatically. A job that once demanded 13.9 GiB at its worst moment now tops out at 2.1 GiB.
Community contributors had already flagged memory peaks above 13 GiB in earlier builds, before the latest round of optimizations arrived.
Separate benchmarks put Stwo’s typical memory footprint somewhere between roughly 10 GiB and 20+ GiB, scaling with the size of the workload. Against that backdrop, a 2.1 GiB peak for transaction proofs looks less like a trim and more like a full renovation.
The phone claim is not purely theoretical. Millions of local ZK proofs have been generated across thousands of smartphone models.
“Local” is the key word. The proof is created on the device itself, rather than handed off to a remote server to crunch.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
How Stwo got here
Starknet is a Layer 2 network built on top of Ethereum, designed to make transactions more efficient and accessible. Proofs are central to how it works, which makes the prover one of its most important pieces of infrastructure.
Stwo went live on Starknet mainnet on November 3, 2025. It replaced the earlier Stone prover and now handles proving for all Starknet blocks.
Starkware made the move as part of a roadmap that emphasizes client-side and decentralized proving at lower cost.
Client-side proving means the user’s own device generates the proof. Decentralized proving spreads that work across many participants instead of concentrating it with a handful of specialized operators.
The effort also leaned on open, community-driven research. That collaborative approach produced substantial optimizations, rather than leaving every improvement to a single internal team.
Stwo is not the only item on Starkware’s list. The company is also advancing recursive proving techniques, which significantly shrink proof sizes, and is working to integrate post-quantum signatures.
Recursive proving is roughly the cryptographic version of nesting dolls: proofs that verify other proofs, compressing a lot of work into a smaller final package. Post-quantum signatures aim to keep accounts secure even if future quantum computers become capable of breaking today’s cryptography.
What this means for Starknet and its users
The most direct implication is for privacy. When a phone can generate its own proof, sensitive transaction data does not need to leave the device to be processed elsewhere.
That is why the upgrade is expected to boost the performance of decentralized applications, particularly those built around privacy and security.
The 2.1 GiB figure applies to transaction proofs, while broader benchmarks show Stwo’s memory needs climbing past 20 GiB for larger workloads. In other words, phones handling their own transactions is a different job from proving entire blocks. The heavy lifting for the network as a whole still scales with workload size.
If developers begin shipping wallets and dApps that generate proofs on-device by default, the memory breakthrough becomes a product feature rather than a research result.
For a field where “runs on a phone” has often meant “runs a demo on a phone,” millions of proofs across thousands of handset models is a notably sturdier claim.