Pico 3.0: Real-Time Ethereum Proving on 4 GPUs with 100-Bit Provable Security

[read_meter]

TL;DR: Pico 3.0 brings real-time Ethereum proving down to a single machine with just 4 GPUs. On the same 7,200 mainnet blocks we used for Pico Prism 2.1, it proves 99% of them within 9.10 seconds, against 9.14 seconds on 2.1’s 16 GPUs. It runs on a completely new proving core and reaches 100 bits of provable security along the way.


Four GPUs, One Machine

When we launched Pico Prism in October 2025, proving Ethereum in real time took 64 GPUs across eight servers. By February we had it running on 16 GPUs across two machines, the setup behind both Pico Prism 2.0 and 2.1. Pico 3.0 does it on one machine with 4 GPUs, a sixteenth of where we started.

We tested it on the exact benchmark behind 2.1, the same 7,200 consecutive mainnet blocks (24,000,000 through 24,007,199):

Comparison table of Pico Prism 2.1 and Pico 3 showing specifications including GPUs, machines, P99 proving time, and benchmark blocks.

That keeps 3.0 inside the ten-second window the Ethereum Foundation uses to define real-time proving, with the average block proven in 5.01 seconds.

Bar graph showing block proving time distribution with percentages on the vertical axis and time intervals (in seconds) on the horizontal axis. The highest percentage (30.8%) is at 4 seconds, followed by 21.6% at 5 seconds. Additional statistics include an average proving time of 5.01 seconds and 7,200 blocks.

A New Proving Core

Every earlier Pico release made the same underlying proof system run faster. For 3.0, we replaced the proof system itself with a new multilinear proving pipeline.

Most of the cost of producing a proof sits in a few heavy steps: committing to data, opening those commitments, and verifying proofs recursively. The new pipeline shrinks the work as much as it can before it reaches those steps, so they have far less to process.

100 Bits of Provable Security

Alongside the hardware cut, Pico 3.0 reaches 100 bits of provable security, which means the security of every proof is something we can calculate precisely.

We get there by accounting for soundness round by round. Every interactive stage of the protocol carries a small chance of error, each of those counts against one shared security budget, and a proof is only as strong as its weakest round. In the current configuration, that’s the WHIR query phase.

Every bit of 3.0’s speed is earned inside that budget, so we can see exactly which future changes would cost security and which are pure engineering wins.

Under the Hood

For a more complete technical picture, here’s what the new core is built from and how we engineered it.

The research foundations. The pipeline builds on a broad line of public proof-system research: the classical sumcheck protocol; GKR for efficiently verifying layered computations; LogUp and LogUp-GKR for efficient lookup arguments; improvements to ZeroCheck; WHIR for multilinear polynomial openings; and ideas developed in SWIRL. Pico 3.0 combines these foundations with substantial Pico-specific work across protocol integration, security parameterization, zkVM circuits, recursion, and GPU implementation.

How the pipeline reduces work. Heterogeneous traces are stacked and batched so they move through the prover together. Sumcheck-based reductions progressively collapse many large claims into a much smaller number of claims, LogUp-GKR handles lookup-heavy interactions without requiring a large collection of additional committed columns, and WHIR handles the final polynomial openings.

Engineering it for four GPUs. Three system-level optimizations made the new pipeline practical at Ethereum scale on a single machine:

  1. 2× larger execution chunks. Lower peak GPU memory let us raise the chunk size from 2²² to 2²³ cycles, so each proof covers twice as much execution and recursion overhead drops.
  2. Much less data movement. A major host-to-GPU record shrank from 304 bytes to 80 bytes, cutting measured PCIe traffic from 25.3 GB to 8 GB. In the WHIR query path, better data reuse accelerated a core kernel by 6.89×.
  3. ~8× lighter recursion. Protocol-specific instructions for sumcheck, GKR, multilinear openings, and WHIR reduce the recursion verifier’s instruction count by 87.7%, while keeping the verifier programmable.

Beyond Real-Time

Pico Prism 2.1 proved a general-purpose zkVM can keep up with Ethereum in real time. With 3.0, the question moves on to how little hardware that should take, and how much security it can carry at the same time.

Every GPU we cut puts real-time proving within reach of more independent operators, which is what keeps a proof-verified Ethereum decentralized. Real-time is now the starting line, and the new core gives us plenty of room to keep pushing from here.

About Brevis

Brevis is a verifiable computing platform powered by zero-knowledge proofs, serving as the infinite compute layer for Web3. Applications can offload expensive computations off-chain while proving every result on-chain. The Brevis stack includes Pico zkVM for general-purpose computation, the ZK Data Coprocessor for trustless access to historical blockchain data, Pico Prism for real-time Ethereum block proving (99.8% coverage on 16 GPUs, hitting the Ethereum Foundation’s $100K hardware target), Vera for ZK-proven media authenticity, and ProverNet, the decentralized marketplace for ZK proof generation now running on mainnet. To date, Brevis has generated 340M+ proofs across 50+ protocols on 8+ blockchains.

Dive Deeper into Brevis:
Website | X | Discord | Pico zkVM | ZK Data Coprocessor | Incentra | ProverNet

Interested in building with Brevis? Reach out to us to explore ideas!