Last week, a mid-tier ZK rollup I've tracked since its testnet phase burned 14.2 ETH in proving costs across a single 72-hour window. It collected 3.1 ETH in sequencer fees over the same period. That is a 4.6-to-1 bleed, and almost nobody on the timeline flagged it.
I pulled those numbers myself, block by block, the way I tracked oracle price feeds when Terra's peg cracked in 2022. The arithmetic hasn't changed. Proving is expensive. The market has stopped paying for it. In a bull run, that gap gets papered over by token emissions and narrative. In a bear market, it becomes a survival question.
Here is the structural problem. A ZK rollup does not verify transactions the way an optimistic rollup does. It generates a cryptographic validity proof for every batch, then posts that proof to Ethereum for verification. Generating that proof is compute-heavy. Someone has to run the prover hardware, and someone has to pay the electricity and the amortized cost of GPUs.
In 2021 and 2022, that cost was a rounding error against fee revenue. Blocks were full, gas was expensive, and users paid premium fees to escape mainnet congestion. Proving cost was maybe 8% of revenue at the peak.
Today that ratio has inverted. Mainnet gas has collapsed. L2 fees have collapsed harder, because rollups compete on cheapness. But proving cost has not collapsed — it scales with transaction volume and proof complexity, not with the market price of the token backing it.
The rollup landscape now has roughly 20 production ZK chains, and most launched with a subsidy: token emissions that effectively paid the prover. That worked while the token had a bid. It does not work when the token is down 70% and the emissions are worth a fraction of the electricity they cost to earn.
Let me deconstruct where the money actually goes.
Proving cost breaks into three vectors: hardware, electricity, and prover efficiency. Hardware is a fixed capital expense — GPU clusters, mostly. Electricity scales with utilization. Prover efficiency improves with better STARK-to-SNARK recursion and lookup arguments, but it improves on a curve, not a cliff.
The brutal part: proving cost is largely volume-invariant per batch, while revenue is volume-dependent. A rollup that proves a batch of 500 transactions pays nearly the same as one proving 5,000. When throughput drops — and in a bear market it drops hard — the cost per transaction spikes.
Here is the math that matters. Cost per batch equals GPU amortization plus electricity, divided by proofs per hour. Revenue per batch equals transactions per batch multiplied by fee per transaction. In a bull market, fee per transaction was high enough that the numerator barely mattered. In a bear market, fee per transaction has fallen to fractions of a cent while the numerator is fixed. You can batch more transactions to dilute the cost, but batching degrades finality and user experience — the exact things retail notices first.
I ran this against three live rollups last month. One averaged 0.0021 ETH per batch proved and 0.0009 ETH per batch earned. The second was worse: 0.0034 proved, 0.0011 earned. The third had already throttled proving to once every four hours, batching aggressively, which cut cost but pushed finality latency to nearly 40 minutes. That is a UX tax disguised as engineering efficiency.
I have audited prover configurations for two teams this year. Both had quietly moved from proving every batch to proving every third or fourth. Neither announced it. Users only noticed when withdrawals took longer to settle on L1.
Now the sequencer question. Most of these chains run a centralized sequencer. It orders transactions and, in the good version, posts proofs. But the sequencer is also the entity eating the proving bill. There is no token model in the world that makes a negative gross margin sustainable forever.
The consensus take is that proving costs will fall and everything resolves. STARKs are getting cheaper. Hardware is getting faster. ZK is the endgame. I have heard this for three years.

The unreported angle is that proving cost is not the real problem — the real problem is that rollups have no pricing power. They compete almost entirely on fees, which means a race to zero while their cost base is fixed and capital-intensive.
The optimistic rollup comparison is not rhetorical. Arbitrum and OP Stack chains run near-zero marginal cost per batch because there is no proof to generate. Their cost is data availability, which also fell. They are structurally cheaper to operate, and they know it. A 7-day challenge window is a UX compromise; a broken prover budget is an existential one.
The second blind spot: the prover is a centralized operator. We celebrate decentralization while a single GPU cluster decides whether the chain produces proofs at all. If that operator's unit economics break — and for several, they have — the chain does not halt. It just stops finalizing. Funds stay locked. Bridges get nervous.
And then there is the unlock calendar. Several ZK tokens have large investor unlocks landing in the next two quarters. When those hit, emissions-based subsidy gets even harder to justify to a treasury. The operator either raises fees — losing the only edge it had — or keeps bleeding. That is the fork in the road nobody is modeling.
Watch proof production intervals, not TVL charts. If a rollup's time-to-finality stretches from minutes to hours, the operator is throttling proving to survive. That is the tell. The question for this cycle is not which rollup has the best tech. It is which rollup can still afford to turn its prover on.
When the next bull market arrives, proving economics will look healthy again and everyone will forget this winter. But the operators who throttled proving to survive will have trained their users to distrust finality. That trust does not come back on a price chart.
Risk Warning: This is not investment advice. Verify sequencer decentralization, prover operator identity, and per-batch economics independently before allocating capital. Centralized provers, unvested token unlocks, and negative gross margins are material risks.