I think algebraic merkle trees (curve trees) are a natural fit because you get fast verification (10-50ms without batching) and fast proof (relatively fast; a second or two), because of not having to put a cryptographic hash function through arithmetization. And you still get the same ability to emb...