
How to Prove False Statements: Practical Attacks on Fiat-Shamir
Source: YouTube · a16z crypto · published Feb 2, 2026 · 1:02:56
This talk presents new attacks on deployed proof systems using the Fiat-Shamir transform, showing vulnerabilities in practical implementations 0:19. The Fiat-Shamir transform converts interactive protocols to non-interactive ones using hash functions, which is critical in most SNARK constructions 0:50.
Key Takeaways:
• The Fiat-Shamir transform is essential for making interactive proofs non-interactive, enabling verification by anyone, such as on blockchains 0:50
• Previous attacks on Fiat-Shamir were considered "contrived" - explicitly designed to fail and not relevant to practical implementations 0:37
• The researchers demonstrate a real-world attack on deployed systems using a combination of GKR protocol and multilinear polynomial commitment schemes 0:19
• Their attack circuit can convince verifiers that a false statement is true, even though the circuit never outputs the claimed result 0:37
• The attack has been confirmed in real-world systems, with Polyhedra's "Expander" protocol implementing a fix after the researchers disclosed the vulnerability 31:04
The attacks demonstrate that security doesn't just depend on the function being proved but also on the actual circuit implementation, raising concerns for circuit auditing 0:33.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, I'm excited to introduce Ron Rothblum, who's an associate professor at Techneon and uh head of cryptography at Succinct, and he's going to tell us about some uh exciting and slightly concerning uh new attacks on deployed proof systems. Go ahead, Ryan. >> Thanks, Justin. Uh great to be back here. Um I'm usually in the business of uh proving security uh but this talk is going to be about breaking security for a change. So hopefully it be uh interesting. So this is a joint work with wonderful collaborators Dimmitri uh Kovtovich and Lavukunov. So let's uh get right into it and I'll try to explain what these things uh mean. So this talk is about the Fiat Shamir transform. Fat Shamir transformed is named after this beautiful paper by Amos Fiat and Adi Shamir uh from all the way back in 1986 …