Fun

Researchers identify key circuit layer vulnerabilities in SNARK systems

News Feed - 2024-08-09 05:08:42

Ana Paula Pereira3 hours agoResearchers identify key circuit layer vulnerabilities in SNARK systemsA study by Imperial College London examined 141 vulnerabilities in SNARK systems, mostly impacting system soundness and completeness.419 Total views1 Total sharesListen to article 0:00EventOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onAccording to researchers at Imperial College London, vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge, or SNARKs. 


The investigation examined 141 vulnerabilities from 107 audit reports, 16 vulnerability disclosures, and various bug trackers associated with popular SNARK projects. The findings were presented on Aug. 7 at the Science of Blockchain Conference held at Columbia University.


SNARKs are a type of zero-knowledge (ZK) proof that allows one to demonstrate that a statement is true without revealing any information about the statement.


According to Stefanos Chaliasos, a PhD candidate at Imperial College London, the research team identified three main types of vulnerabilities in circuit layers — under-constrained, over-constrained and computational/hints error:“The majority of vulnerabilities are in the circuit layer, and the majority is also soundness response, which is the worst part that can happen when you use Zkps because basically, in the context of a ZK-rollup, if there is such a bug and someone wants to exploit it, then all the funds could be drained from the circuit layer.”


The most frequent vulnerability found on zero knowledge circuits arises from insufficient constraints, which cause a verifier to accept invalid proofs, compromising a system’s soundness or completeness. Per the research, 95 of the identified issues on SNARK-based systems affected soundness and four affected completeness.


“The primary challenge for developers lies in adapting to a different level of abstraction and optimizing circuits for efficiency, which directly impacts the cost of using SNARKs,” notes the paper.


Root causes for vulnerabilities on ZK circuits include distinguishing between assignments and constraints, missing input constraints, and unsafe reuse of circuits, among others.Source: SoK: What Don’t We Know? Understanding Security Vulnerabilities in SNARKsWeighted VRFs


The first day of the conference also featured the Aptos team presenting their recently implemented weighted verifiable random functions, or weighted VRFs — a mechanism designed to enhance the randomness in the consensus process.


The approach extends the concept of VRFs by incorporating weights into the random selection process of verifying inputs and outputs onchain. With weights, participants in the consensus mechanism have different probabilities of being chosen based on their stake (weights).


Aptos deployed the mechanism on its mainnet in June. “As far as you can tell, this is the first time you see a previously granular script that is unbiaseable, unpredictable, and operates as fast as the network,” noted Alin Tomescu, head of cryptography at Aptos.


According to Tomescu, Aptos has processed half a million calls through the new randomness API, with the distributed key generation (DKG) lasting about 20 seconds.“Our randomness latency, which is the latency measured from the time a block is committed to the time the randomness for that block is available, was initially 160 milliseconds. But we were able to bring this down to 25 milliseconds using some optimizations.”# Blockchain# Research# zk-RollupAdd reaction

News Feed

Soneium blockchain launched by Sony to attract Web3 developers
Pradipta Mukherjee33 minutes agoSoneium blockchain launched by Sony to attract Web3 developers Sony Block Solutions Labs, a year-old joint venture between Sony Group and Startale, has introduced an Ethereum Layer-2 bloc
AT&T Responds to Crypto Exec’s SIM Swap Suit: See You in Court
AT&T said it would fight allegations that it was negligent in a customer’s loss of $1.7 million in a SIM swap. The allegations come from Seth Shapiro, VideoCoin’s h
Coinbase Disputes SEC’s Allegation That the Exchange Lists 9 Crypto Securities
Coinbase Disputes SEC"s Allegation That the Exchange Lists 9 Crypto Securities Nasdaq-listed crypto exchange Coinbase has disputed the allegation by the U.S. Securities and Exchang
5 Major Banks Exposed for Moving Trillions for Mobsters, Onecoin, and Drug Cartels
5 Major Banks Exposed for Moving Trillions for Mobsters, Onecoin, and Drug CartelsAccording to the International Consortium of Investigative Journalists (ICIJ), five major global ba
Bitcoin weakness spurs $441M digital asset inflows
Savannah Fortis13 hours agoBitcoin weakness spurs $441M digital asset inflowsDigital asset investments see significant inflows of $441 million, driven by Bitcoin price weakness, Mt. Gox activity and a German government s
Gamefi-Focused Oasys Blockchain Launches Mainnet With Support of Sega, Ubisoft, and Bandai Namco
Gamefi-Focused Oasys Blockchain Launches Mainnet With Support of Sega, Ubisoft, and Bandai Namco Oasys, a Web3, EVM-compatible, gamefi-focused blockchain project, launched the firs
Trump wants Bitcoin ‘made in the USA’ after hosting mining industry heads
Brayden Lindrea4 hours agoTrump wants Bitcoin ‘made in the USA’ after hosting mining industry headsThe presidential candidate showed his support for the crypto mining industry after executives pitched him on how they
Pewdiepie Joins the Blockchain AR Game Wallem, Players Can Buy Youtube Star’s NFT Skin
Pewdiepie Joins the Blockchain AR Game Wallem, Players Can Buy Youtube Star"s NFT Skin The world-famous gamer and Youtuber, Pewdiepie is getting involved with an
Bitcoin Bollinger Band signal suggests BTC could double by July
Tom Mitchelhill7 hours agoBitcoin Bollinger Band signal suggests BTC could double by JulyA widely used technical analysis indicator suggests that Bitcoin could double its price within three months.6017 Total views17 Tota
Michael Dell’s Bitcoin post sparks massive BTC purchase speculations
Yashu GolaJun 22, 2024Michael Dell’s Bitcoin post sparks massive BTC purchase speculationsDell"s message on X follows his $2.1 billion cash out from his Dell Technologies Class C common stock holdings.13810 Total views
Telegram Rejects SEC Request to Hand Over Bank Records for TON
Telegram Rejects SEC Request to Hand Over Bank Records for TON Telegram Group, the company behind the TON blockchain project, has reportedly refused to share information with the
BTCDomain Makes ․btc Happen on BTC Layer 1
BTCDomain Makes ․btc Happen on BTC Layer 1 press release PRESS RELEASE. It truly is time to rejoice now that .btc domains have come to Bitcoin. BTCDomainis a user-friendly domain