How to Prove False Statements: Practical Attacks on Fiat-Shamir

How to Prove False Statements: Practical Attacks on Fiat-Shamir

Source: YouTube · a16z crypto · published Feb 2, 2026 · 1:02:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk presents new attacks on deployed proof systems using the Fiat-Shamir transform, showing vulnerabilities in practical implementations 0:19. The Fiat-Shamir transform converts interactive protocols to non-interactive ones using hash functions, which is critical in most SNARK constructions 0:50.

Key Takeaways:
• The Fiat-Shamir transform is essential for making interactive proofs non-interactive, enabling verification by anyone, such as on blockchains 0:50
• Previous attacks on Fiat-Shamir were considered "contrived" - explicitly designed to fail and not relevant to practical implementations 0:37
• The researchers demonstrate a real-world attack on deployed systems using a combination of GKR protocol and multilinear polynomial commitment schemes 0:19
• Their attack circuit can convince verifiers that a false statement is true, even though the circuit never outputs the claimed result 0:37
• The attack has been confirmed in real-world systems, with Polyhedra's "Expander" protocol implementing a fix after the researchers disclosed the vulnerability 31:04

The attacks demonstrate that security doesn't just depend on the function being proved but also on the actual circuit implementation, raising concerns for circuit auditing 0:33.

Sources:

  • 0:19 Introduction to attacks on deployed proof systems
  • 0:37 Discussion of "contrived" vs. practical attacks
  • 0:50 Explanation of Fiat-Shamir t

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So, I'm excited to introduce Ron Rothblum, who's an associate professor at Techneon and uh head of cryptography at Succinct, and he's going to tell us about some uh exciting and slightly concerning uh new attacks on deployed proof systems. Go ahead, Ryan. >> Thanks, Justin. Uh great to be back here. Um I'm usually in the business of uh proving security uh but this talk is going to be about breaking security for a change. So hopefully it be uh interesting. So this is a joint work with wonderful collaborators Dimmitri uh Kovtovich and Lavukunov. So let's uh get right into it and I'll try to explain what these things uh mean. So this talk is about the Fiat Shamir transform. Fat Shamir transformed is named after this beautiful paper by Amos Fiat and Adi Shamir uh from all the way back in 1986 …