Changing the utreexo hash function to using SHA-256 (which has a Risc0 precompile) reduces proving time to 22s using this approach:
Now again the two EC multiplications (blinding the key and creating the taproot output key) dominates (in addition to ZKVM serde).