@cipherscan_app@cypherpunk@zooko@jswihart@zkDragon I notice this as well. Been running a fuck ton of numbers, I criticized hard on the issue, but I simply do not see any sign of there being a huge amount of counterfeit ZEC.
Hackers can be smarts, so we need to 100% be sure, but this is looking better everyday.
To be clear, even the Halo2 FV work builds on a lot of related art. People have been compiling AIR's etc to FV languages. (@zksecurityXYZ made a great framework for it: https://t.co/2XqAwo6Kxt )
Not trying to FUD that, just you could tell me in 3 months there was a compiler bug in some AIR edgecase, and I'd believe you. I wouldn't for R1CS
I know this is marketing spiel, but this is what you have to understand. There is no cryptography more elegant, no cryptographic team with more expertise than Zcash. Just look at the call to arms during this debacle, military grade.
If you want to ignore that, it’s your own prerogative.
@Real_Crypto_X@GoodTexture Ps @Real_Crypto_X your retweets of Hbar and Qbic gives me the impression that you’re still looking for the 100x trade and you’re salty af that you missed the initial Zcash pump.
News for you, you still have times but first must open your eyes.
I love all this uncertainty as all these Zcash tourists who bought have $600 have no idea the level of cryptographic expertise working for the protocol from Shielded labs, Zodl, Zcash foundation and ZK security. You are about to be left in the dust as Zcash goes on a disbelief rally not seen since 2013 bitcoin. Gg
Ginormous update:
What this means for Zcash’s architecture. Four concrete connections:
First, it’s the cure for the exact bug class, not a band-aid. The June patch was a one-line fix to one gadget found by luck (AI luck, but luck). Clean represents the other path: a discipline where “the spec follows from the constraints regardless of witness” is a proof obligation you can’t skip. An Orchard built this way couldn’t have shipped the missing-constraint bug, because the soundness proof for variable-base scalar mul would not close.
Second, and most importantly, it attacks the composition problem that’s been the blocker for verifying Orchard as a whole. Orchard’s Action statement isn’t one gadget — it’s Sinsemilla, Poseidon, ECC scalar mul, Merkle paths, and lookup/range-check tables all interacting. Verifying each piece in isolation was already possible (zkSecurity has even formally verified Poseidon, one of Orchard’s hashes — it’s in their recommended reading). What was missing was a principled way to glue locally-verified gadgets into a single soundness theorem for the full circuit. Channels — which the post explicitly says cover lookups and the PLONK permutation argument — are that glue. This is the machinery that makes “formally verify the entire Orchard circuit,” not just its parts, actually tractable.
Third, it operationalizes @ebfull “humans only check the small theorems” claim from earlier in our thread. The untrusted-guarantees design means the trusted base collapses to the global spec (“this is what a valid spend is / no counterfeiting”) and the assumptions. That’s the de Bruijn criterion in practice — exactly the property that would let a regulator or auditor get comfort from a Zcash supply-soundness proof without reading a gigabyte of Lean.
Fourth, the completeness emphasis matters for the migration plan we discussed. A formally-verified new shielded pool — the destination of the turnstile migration — has to be proven complete as well as sound, or honest holders could find themselves unable to spend or migrate. The post’s candor that whole-system completeness verification is unfinished is a real, relevant limitation: the tooling that would let Zcash ship a provably sound-and-complete replacement pool is maturing but not all the way there yet.
Together with @zodl_co, @ZcashFoundation, @ValarGroup and @ShieldedLabs, we're advocating for a network upgrade that would make ZEC's circulating supply auditable, providing additional reassurance that no counterfeiting occurred in the Orchard pool before this week's bugfix.
https://t.co/uPeinopdgf