Spent a week testing AI for vulnerability research. 14 confirmed bugs in 20 min on one target. 5% hit rate on a hardened one. Same AI, same setup. 4 approaches, what worked, what failed, why target selection matters more than model sophistication. https://t.co/R5ofHyXQem
Math, Inc. is proud to announce an all-star group of Veritas Fellows:
Renowned professor Kevin Buzzard, alongside Fields Medalists Maryna Viazovska and Terence Tao.
They will lead teams to build formal mathematics at unprecedented scale. 🧵
»...it means rationalizing growth itself: producing not for the accumulation of value, but for the sake of our flourishing as the rational kind of animals we are.«
https://t.co/eluG2LgnSg
Cool deep dive into the subtle kind of bugs that can lurk in ZK VMs: https://t.co/dEciV93WWe HT David Wong’s new site, https://t.co/wZe6cQVymZ . Bugs that can lurk silently until an attacker finds them. Scary!
⤵️
🧵 Formal Verification for ZK Safety
ZK circuits provide developers with the ability to offload expensive computations and just check they were done right on chain. Formal Verification is crucial to making sure these often-complex protocols are secure, and Reilabs recently proved the correctness of Worldcoin’s World ID.
[1/6]
1.
I'm happy to share with you zk-fhe, a joint work with @yurikonishijima to achieve Verifiable Fully Homomorphic Encryption.
The circuit was built within @axiom_xyz Open Source Program.
Prover time is less than 10s on a M2 Pro!
https://t.co/rVErmdbMna
@VitalikButerin There is a strand of literature on worker morale affecting productivity/effort based on fair wages, started with Akerlof/Yellen 1990 https://t.co/uv7UXIeaGO
Recursive STARKs: in addition to proving the correctness of transaction execution, we also can prove (off-chain), the correct execution of a STARK verifier that verified the proof. The on-chain verifier running time is now shorter by orders of magnitude.
h/t @OhadBarta
A big difference between the "new idealistic movement" scene 10-15 years ago vs today is that back then it felt possible to be on all the good-guy teams at the same time. Today, much more adversarial thinking and conflict.
I've been trying to understand.. where to from here?
We can do it, we can help Test The Merge!
Here's a quick thread on how you can help Test The Merge, get some rewards, and make a difference ✨without being deeply technical✨
👇1/5
0/ Many successful heists in DeFi and Web3 have nothing to do with bugs in the code.
If you want to be safe, you need to understand all the ways in which a protocol can be attacked.
🧵Here are 9 attack patterns in DeFi that everyone should know
Welp. It’s the crypto bug of the year. Mark it down for April. Java 15-18 ECDSA doesn’t sanity check that the random x coordinate and signature proof are nonzero; a (0,0) signature validates any message. Breaks JWT, SAML, &c. https://t.co/t2WgnS0g3A