0x37294bbd3729…37294bc0
Stwo Prover Cuts Peak Memory to 2.1 GiB, Enabling Phone-Based STARK Proofs
Stwo, the prover behind Starknet, has reduced its peak memory from 13.9 GiB to 2.1 GiB, allowing smartphones to generate STARK proofs for individual transactions in production.

Outputs
Peak memory for Stwo transaction proofs fell from 13.9 GiB to 2.1 GiB, a 6.6x reduction.
Stwo went live on Starknet mainnet on November 3, 2025, replacing the Stone prover.
Stwo now handles proving duties for every Starknet block in production.
Starkware reports 'millions of local ZK proofs' generated across thousands of smartphone models.
Broader benchmarks show Stwo memory still reaching 20+ GiB for full block workloads.
Stwo, the prover powering Starknet, has cut its peak memory requirement from 13.9 GiB to 2.1 GiB, according to research results circulated by Starkware. The reduction lets smartphones generate STARK proofs for individual Starknet transactions.
Stwo went live on Starknet mainnet on November 3, 2025, replacing the earlier Stone prover and now handling proving duties for every Starknet block. The memory optimization emerged from open, community-driven research rather than a single internal team's work, Starkware said.
Why does peak memory matter for a prover?
A prover produces a cryptographic proof — a compact mathematical receipt confirming a batch of computation ran correctly. Peak memory captures the most RAM the prover demands at any single moment during that job. Past community audits had flagged peaks above 13 GiB in earlier builds, and separate benchmarks placed Stwo's typical footprint between roughly 10 GiB and 20+ GiB depending on workload.
Against that baseline, the 2.1 GiB peak represents a 6.6x reduction. The figure applies specifically to transaction proofs. Larger workloads — proving whole blocks rather than individual transactions — still push memory past 20 GiB.
What does this change for users?
"Local" is the operative word. When a phone generates its own proof, sensitive transaction data does not have to leave the device. Starkware framed the upgrade as a direct lever for decentralized applications built around privacy and security.
The phone claim rests on operational evidence rather than a lab demo. Starkware reported that "millions of local ZK proofs have been generated across thousands of smartphone models." For an industry where "runs on a phone" has frequently meant a controlled demonstration, that scale is a sturdier benchmark.
How does Stwo fit into Starkware's broader roadmap?
Stwo anchors a multi-pronged push toward client-side and decentralized proving at lower cost. Client-side proving puts the burden on the user's device. Decentralized proving distributes the work across many participants rather than concentrating it with a handful of specialized operators.
The roadmap also includes recursive proving techniques, which compress proofs that verify other proofs into a smaller final package. Starkware separately continues work on post-quantum signatures, designed to keep accounts secure against future quantum-capable adversaries.
What's the catch?
The 2.1 GiB figure is workload-specific. A phone proving its own transactions operates in a different regime than infrastructure proving whole blocks. Network-level memory needs still scale with block size, and the broader 10 GiB to 20+ GiB benchmarks describe that heavier workload.
The operational question is whether wallet and dApp developers ship proofs by default on-device. Research results become product features only when integration follows.
What happens next?
Stwo now handles every Starknet block. The November 3 mainnet cutover means the disclosed memory profile applies to production traffic, not testnet speculation. Watch whether the first consumer wallets ship on-device proof generation as a default, and whether recursive proving reaches mainnet in a subsequent release. Those two milestones will determine whether the 2.1 GiB figure remains a benchmark or becomes a product specification.
via Crypto Briefing (Source)