It's disheartening to see so many root against Zcash.
We owe so much to the courage of the Zcash team: ten years ago, Zcash was a moonshot.
They were the 1st to deploy a *fully* anonymous payment system and the 1st to deploy a zkSNARK-based cryptosystem.
Rooting against the team being able to recover from this bug is rooting against all other serious privacy efforts for cryptocurrencies: they are all based on the same nullifier techniques via circuit-based zkSNARKs.
This is not a zero-sum game.
Zcash has been showing us the way for over a decade and will continue to do so.
e.g., Zcash will soon be the 1st team to deploy a *formally-verified* zkSNARK circuit implementation for anonymous payments.
1/ Very happy to share a new paper with Benedikt Wagner on data availability sampling (DAS). In this one we extend FRIDA with our recent findings on FRI
FRIDA was a 2024 paper in which they showed that we can construct DAS from proofs of proximity that satisfy 3 conditions
Our team is very grateful for @zksecurityXYZ’s research and tooling for building secure cryptographic software, including formal verification, fuzzing, and extensive auditing expertise.
We recently added more Circom bugs to zkbugs, bringing the total to 70 Circom and 139 ZK bugs. We aim to reach 300 bugs, focusing more on zkVMs. We also began evaluating security tools and are currently building open-source AI tools that the community can use while developing ZK code and before audits. Any contribution to the QF round will help us focus more on it and give opportunities to junior researchers through internships.
We collaborated with Aptos Labs to audit their Confidential Assets protocol, a system enabling confidential balances and transfers on the Aptos blockchain. 👇🏼
Confidential Assets v1.1 is now open-source: the first Move smart contract that lets you confidentially transfer your assets from your encrypted balance.
Here's what it does 🧵👇
https://t.co/XCxC4FvVNH
The first two known exploits against live ZK circuits just happened, and they weren't subtle underconstrained bugs.
They were Groth16 verifiers deployed without completing the trusted setup ceremony. One was white-hat rescued for ~$1.5M, the other drained for 5 ETH.
🧵
The first two known exploits against live ZK circuits just happened, and they weren't subtle underconstrained bugs.
They were Groth16 verifiers deployed without completing the trusted setup ceremony. One was white-hat rescued for ~$1.5M, the other drained for 5 ETH.
🧵
Security flex
✅ $500K bug bounty
✅ Audited contracts
✅ 32,000+ ETH in treasury
✅ Withdrawals work even if paused
https://t.co/fHlHHtmaXx isn’t a game. It’s war-grade DeFi.
@moo9000 Publishing a blog post tomorrow, but this wasn't a deep cryptography bug. This was not following a quick start guide thoroughly (with a bit of a conducted API, to be frank)