Market Cap: $2.618T 0.19%
Volume(24h): $75.0718B -10.16%
  • Market Cap: $2.618T 0.19%
  • Volume(24h): $75.0718B -10.16%
  • Fear & Greed Index:
  • Market Cap: $2.618T 0.19%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$78040.437257 USD

0.52%

ethereum
ethereum

$2412.308117 USD

-0.53%

tether
tether

$0.999509 USD

-0.01%

bnb
bnb

$698.384233 USD

1.45%

xrp
xrp

$1.373032 USD

1.75%

usd-coin
usd-coin

$0.999942 USD

0.01%

solana
solana

$101.191032 USD

0.93%

tron
tron

$0.326391 USD

1.07%

hyperliquid
hyperliquid

$82.279738 USD

-1.13%

dogecoin
dogecoin

$0.083520 USD

2.01%

zcash
zcash

$834.380549 USD

-0.43%

monero
monero

$514.961282 USD

-1.77%

unus-sed-leo
unus-sed-leo

$9.309351 USD

0.36%

chainlink
chainlink

$11.262165 USD

-0.09%

cardano
cardano

$0.206160 USD

4.12%

Cryptocurrency News Articles

Circuit Layer Vulnerabilities Pose the Most Significant Threat to SNARK-Based Systems, Researchers Find

Aug 09, 2024 at 05:03 am

According to researchers at Imperial College London, vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge, or SNARKs.

Circuit Layer Vulnerabilities Pose the Most Significant Threat to SNARK-Based Systems, Researchers Find

Researchers at Imperial College London have found that vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge (SNARKs).

The investigation examined 141 vulnerabilities from 107 audit reports, 16 vulnerability disclosures, and various bug trackers associated with popular SNARK projects. The findings were presented on Aug. 7 at the Science of Blockchain Conference at Columbia University.

SNARKs are a type of zero-knowledge (ZK) proof that allows one to demonstrate that a statement is true without revealing any information about the statement. They are used extensively in Web3 to compress large computations and enable efficient on-chain verification.

However, the complexity and abstraction of ZK circuits can introduce vulnerabilities that might go unnoticed during the development and auditing processes.

To identify and categorize these vulnerabilities, the research team, led by Stefanos Chaliasos, a Ph.D. candidate at Imperial College London, proposed a vulnerability taxonomy and applied it to the analysis of vulnerabilities in circuit layers of several SNARK systems.

The team identified three main types of vulnerabilities in circuit layers: under-constrained, over-constrained and computational/hints error. The most frequent vulnerability found on zero knowledge circuits arises from insufficient constraints, which cause a verifier to accept invalid proofs, thus compromising a system’s soundness or completeness.

According to the research, 95 of the identified issues on SNARK-based systems affected soundness and four affected completeness. For instance, an attacker could exploit an insufficient input constraint to forge a valid proof for an invalid statement or to create a valid proof for a different statement than the one being proven.

“The primary challenge for developers lies in adapting to a different level of abstraction and optimizing circuits for efficiency, which directly impacts the cost of using SNARKs,” the paper notes.

Other root causes for vulnerabilities on ZK circuits include distinguishing between assignments and constraints, missing input constraints and unsafe reuse of circuits, among others.

The research team also highlighted the importance of clear documentation and tooling to help developers identify and fix vulnerabilities early on in the development process.

“The goal is to integrate these findings into a vulnerability scanner that will automatically identify and classify vulnerabilities in ZK circuits,” Chaliasos told Blockworks.

Weighted VRFsThe first day of the conference also featured the Aptos team presenting their recently implemented weighted verifiable random functions, or weighted VRFs — a mechanism designed to enhance the randomness in the consensus process.

The approach extends the concept of VRFs by incorporating weights into the random selection process of verifying inputs and outputs on-chain. With weights, participants in the consensus mechanism have different probabilities of being chosen based on their stake (weights).

Aptos deployed the mechanism on its mainnet in June. “As far as you can tell, this is the first time you see a previously granular script that is unbiaseable, unpredictable, and operates as fast as the network,” said Alin Tomescu, head of cryptography at Aptos, during the presentation.

According to Tomescu, Aptos has processed half a million calls through the new randomness API, with the distributed key generation (DKG) lasting about 20 seconds.

Original source:cointelegraph

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 03, 2026