Fun

Researchers identify key circuit layer vulnerabilities in SNARK systems

News Feed - 2024-08-09 05:08:42

Ana Paula Pereira3 hours agoResearchers identify key circuit layer vulnerabilities in SNARK systemsA study by Imperial College London examined 141 vulnerabilities in SNARK systems, mostly impacting system soundness and completeness.419 Total views1 Total sharesListen to article 0:00EventOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onAccording to researchers at Imperial College London, vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge, or SNARKs. 


The investigation examined 141 vulnerabilities from 107 audit reports, 16 vulnerability disclosures, and various bug trackers associated with popular SNARK projects. The findings were presented on Aug. 7 at the Science of Blockchain Conference held at Columbia University.


SNARKs are a type of zero-knowledge (ZK) proof that allows one to demonstrate that a statement is true without revealing any information about the statement.


According to Stefanos Chaliasos, a PhD candidate at Imperial College London, the research team identified three main types of vulnerabilities in circuit layers — under-constrained, over-constrained and computational/hints error:“The majority of vulnerabilities are in the circuit layer, and the majority is also soundness response, which is the worst part that can happen when you use Zkps because basically, in the context of a ZK-rollup, if there is such a bug and someone wants to exploit it, then all the funds could be drained from the circuit layer.”


The most frequent vulnerability found on zero knowledge circuits arises from insufficient constraints, which cause a verifier to accept invalid proofs, compromising a system’s soundness or completeness. Per the research, 95 of the identified issues on SNARK-based systems affected soundness and four affected completeness.


“The primary challenge for developers lies in adapting to a different level of abstraction and optimizing circuits for efficiency, which directly impacts the cost of using SNARKs,” notes the paper.


Root causes for vulnerabilities on ZK circuits include distinguishing between assignments and constraints, missing input constraints, and unsafe reuse of circuits, among others.Source: SoK: What Don’t We Know? Understanding Security Vulnerabilities in SNARKsWeighted VRFs


The first day of the conference also featured the Aptos team presenting their recently implemented weighted verifiable random functions, or weighted VRFs — a mechanism designed to enhance the randomness in the consensus process.


The approach extends the concept of VRFs by incorporating weights into the random selection process of verifying inputs and outputs onchain. With weights, participants in the consensus mechanism have different probabilities of being chosen based on their stake (weights).


Aptos deployed the mechanism on its mainnet in June. “As far as you can tell, this is the first time you see a previously granular script that is unbiaseable, unpredictable, and operates as fast as the network,” noted Alin Tomescu, head of cryptography at Aptos.


According to Tomescu, Aptos has processed half a million calls through the new randomness API, with the distributed key generation (DKG) lasting about 20 seconds.“Our randomness latency, which is the latency measured from the time a block is committed to the time the randomness for that block is available, was initially 160 milliseconds. But we were able to bring this down to 25 milliseconds using some optimizations.”# Blockchain# Research# zk-RollupAdd reaction

News Feed

Former Ethereum adviser files $9.6B lawsuit against US gov't
Helen Partz10 hours agoFormer Ethereum adviser files $9.6B lawsuit against US gov"tFormer Ethereum adviser Steven Nerayoff wants the U.S. government to repay $9.6 billion in damages for extortion charges that were eventu
‘Noxious Poison’ – Bitcoin’s Market Cap Surpasses Warren Buffet’s Berkshire Hathaway Valuation
"Noxious Poison" - Bitcoin"s Market Cap Surpasses Warren Buffet"s Berkshire Hathaway Valuation For many years, the business tycoon Warren Buffet has condemned bi
Robinhood is now available in Hawaii and select US territories
Vince Quill6 hours agoRobinhood is now available in Hawaii and select US territoriesThe brokerage platform took advantage of Hawaii’s recent change to money transmitter licensing to expand to the non-contiguous United
Frodo Tech Aims to Create Environmentally-Friendly Blockchain Ecosystem That Is Open to Everyone
Frodo Tech Aims to Create Environmentally-Friendly Blockchain Ecosystem That Is Open to Everyone sponsored Frodo Tech aims to create an environmentally-friendly blockchain ecosystem
Traders Withdraw $3.6 Billion in Ethereum From Crypto Exchanges in 17 Days
Traders Withdraw $3.6 Billion in Ethereum From Crypto Exchanges in 17 Days The pencilled-in preliminary date for The Merge, revealed by the Ethereum developer Superphiz, is less th
Ethereum price will be ‘sensitive’ to ETF inflows in the coming days — Kaiko
Tom Mitchelhill5 hours agoEthereum price will be ‘sensitive’ to ETF inflows in the coming days — KaikoAnother firm estimates that Ether’s price will rise no more than 24% by the end of 2024 due to underwhelming d
KyberSwap DEX hacker sends an on-chain message: Be nice, or else
Brayden Lindrea4 hours agoKyberSwap DEX hacker sends an on-chain message: Be nice, or elseThe exploiter behind the $46 million KyberSwap hack says they plan to outline a treaty for the potential return of funds on Nov. 3
Lazarus Group moves $12M from HTX, HECO hacks to Tornado Cash
Ana Paula Pereira3 hours agoLazarus Group moves $12M from HTX, HECO hacks to Tornado CashDespite U.S. sanctions, North Korea’s Lazarus Group has resumed laundering stolen crypto funds through Tornado Cash.660 Total vie
Bitcoin Set To Gain Over $300 Billion From Companies In Next 5 Years, Analysts Say
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Japanese Gaming Company Gumi Partners With Square Enix and SBI Holdings to Strengthen Metaverse Pivot
Japanese Gaming Company Gumi Partners With Square Enix and SBI Holdings to Strengthen Metaverse Pivot Gumi, a Japanese mobile gaming company, has partnered with Square Enix and SBI
Degen Chain L3 now tops the TPS charts within the Ethereum ecosystem
Brayden Lindrea5 hours agoDegen Chain L3 now tops the TPS charts within the Ethereum ecosystemThe average value transacted on Degen Chain is rather small at $0.27, however, compared to Ethereum and Base at $1,867 and $17
US Treasury Warns NFTs May Present New Illicit Finance Risks
US Treasury Warns NFTs May Present New Illicit Finance Risks The U.S. treasury department has warned that non-fungible tokens (NFTs) may present new illicit finance risks. Accordin