That’s an interesting use case, just skimming over the paper it looks like the proof sizes make it infeasible for a production blockchain like Zcash?
@str4d would probably know.
Yeah, that’s way too big. Even if we assume the cost of a full Sapling-like spend circuit is equivalent to the cost of a single SHA-256 invocation, that’s still 220kB per proof.
Its too big. But what is the actual limit for TX size for a PoW consensus system?