惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
V
V2EX
Jina AI
Jina AI
爱范儿
爱范儿
M
MIT News - Artificial intelligence
量子位
L
LangChain Blog
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
腾讯CDC
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies PipeSC: A Resource-efficient and Pipelined Hardware Accelerator for Sumcheck Protocol Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model?
The Last Challenge Attack on Fiat-Shamir in KZG-based SNARKs
2024-03-04 · via Cryptology ePrint Archive

Paper 2024/398

The Last Challenge Attack on Fiat-Shamir in KZG-based SNARKs

Maxim Peter, General Intuition

Vesselin Velichkov, OpenZeppelin

Abstract

The Fiat-Shamir transform [11] is a fundamental technique for converting sound public-coin interactive protocols into sound non-interactive protocols. While the theoretical transformation is conceptually simple, implementation-level deviations—often motivated by performance optimisations—can introduce catastrophic security flaws. In this work, we present the Last Challenge Attack (LCA), a vulnerability arising from such a deviation in a real-world KZG-based SNARK verifier implementation. The vulnerability stems from an incorrect computation of the final KZG [17] protocol challenge, which is a batching challenge derived independently of the evaluation proofs. This flaw potentially affects any KZG implementation of batched proofs for multiple evaluation points. We demonstrate that a malicious prover can exploit this deviation to forge proofs of false statements. We provide a proof-of-concept implementation demonstrating the forgery of a proof for an arbitrary public input. This vulnerability was discovered during a security audit, responsibly disclosed, and fixed.

Note: This is the extended version of the article accepted for publication at Financial Cryptography and Data Security 2026. Updated affiliations.

BibTeX

@misc{cryptoeprint:2024/398,
      author = {Oana Ciobotaru and Maxim Peter and Vesselin Velichkov},
      title = {The Last Challenge Attack on Fiat-Shamir in {KZG}-based {SNARKs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/398},
      year = {2024},
      url = {https://eprint.iacr.org/2024/398}
}