On March 14, 2025, Scroll's average proving cost per batch hit $4,200, a 300% increase from six months prior. The narrative isn't about scalability anymore; it's about solvency. The value wasn't in the throughput; it was in the subsidy.
Context: The Promise of Infinite Scalability
Zero-Knowledge Rollups were supposed to be the holy grail of Ethereum scaling. By batching thousands of transactions off-chain and submitting a single cryptographic proof, they promised to decouple transaction costs from L1 congestion. Projects like zkSync, StarkNet, Scroll, and Polygon zkEVM raised billions in valuation, riding a narrative that ZK technology would eventually replace optimistic rollups and even L1 itself. The bear market of 2023-2025, however, has exposed a raw nerve: proving costs are absurdly high, and unless gas returns to bull-market levels, operators are bleeding money. Based on my audit experience with two ZK rollup circuits in 2024, I can confirm that the economic model of these networks relies on a fragile assumption that transaction volume will remain high enough to amortize the fixed cost of proof generation. When volume drops, the narrative cracks.
Core: The Mathematics of Bleeding
Let's start with the raw data. According to L2Beat, the average daily transaction count on Scroll dropped from 1.2 million in December 2024 to 420,000 in March 2025. Meanwhile, the proving time per batch increased by 40% due to more complex circuit constraints. The cost to generate a single proof using a cloud GPU (e.g., AWS p4d.24xlarge) is around $1.20 per minute. Each batch on Scroll requires approximately 35 minutes of computation, translating to $42 per batch. However, that's just the direct compute cost. When you factor in data availability fees (calldata or blob storage on Ethereum L1), each batch submission costs an additional $150 to $300 in gas. Total per batch: $192 to $342. With a batch containing roughly 800 transactions, the cost per transaction is $0.24 to $0.43. That sounds cheap, but the problem is that Scroll charges users only $0.08 per transaction on average. The gap is covered by the treasury and token incentives. In a bear market, when token prices fall, the subsidy becomes unsustainable. The narrative isn't about scalability; it's about survival.
I recall a conversation with a lead engineer at a major ZK rollup in January 2025. He admitted that their proving infrastructure was running at 60% capacity because they couldn't justify the cost of full utilization. “We're essentially burning money to keep the narrative alive,” he said. The value wasn't in the technology; it was in the venture capital expectation that adoption would eventually justify the expense. But the data shows the opposite: as total value locked (TVL) on these rollups declined from $8 billion to $2.5 billion over the past year, the proving cost per dollar of TVL skyrocketed. The value wasn't in the proof; it was in the promise.

Contrarian: The Blind Spot of Hardware Progress
The standard counter-argument is that hardware acceleration – GPUs, FPGAs, and eventually ASICs – will bring proving costs down by orders of magnitude. This is the narrative that keeps investors pouring money into ZK start-ups. But I see a blind spot. The improvement in proving speed has been roughly 2x per year, following a trend similar to Moore's law. Yet transaction volume on Ethereum L2s has grown at a rate of 1.5x per year during the bull cycles, and in the bear market, it's contracting. The cost reduction is not outpacing the volume decline. Moreover, the complexity of circuits increases as ZK rollups add features (e.g., EVM equivalence, recursive proofs). Each new feature adds polynomial overhead to the proving time. The net effect is that the cost per transaction is not falling fast enough to make the model viable without subsidies. The contrarian truth is that ZK rollups are a luxury good for high-value transactions, not a mass-market scaling solution. The narrative that they will replace L1 is a fantasy unless we see a breakthrough in proof generation that is not on the current horizon.
Takeaway: The Next Narrative Shift
So where does this leave us? The next narrative will likely shift from “ZK rollups are the solution” to “ZK rollups are a specialized tool for specific use cases.” The general-purpose rollup may give way to application-specific rollups (app-chains) that can optimize their proving costs for a narrow set of transactions. Alternatively, we may see a resurgence of optimistic rollups, which have lower proving costs but longer finality. The real innovation will come from hybrid approaches that combine ZK proofs for security with optimistic assumptions for cost. The narrative isn't about what's possible; it's about what's sustainable. The value wasn't in the technology; it was in the subsidy. And in a bear market, subsidies disappear. The question every ZK rollup operator must answer is not “How fast can you scale?” but “How long can you bleed?”