Pro

Zero Knowledge Bug

This was originally sent to subscribers of Messari's Unqualified Opinions. Click here to become a subscriber and access all of our historical content.

Dan McArdle- February 5, 2019

A massive story today (Fortunegot the deets) regarding a security vulnerability in ZCash’s core zk-snarks cryptography. The ZCash team confirmed that one of their internal engineers discovered an “infinite inflation bug” in March, and subsequently patched the vulnerability discreetly during the network’s October "Sapling" upgrade.

The bug could have allowed an attacker to mint an unlimited amount of tokens without being identified by the broader ecosystem by circumventing a crucial protocol check point, and transforming a zero-knowledge proof of one statement into a valid-looking proof of a different statement. Incredibly, this issue likely existed/exists in all platformsusing zero knowledge proofs, but the Zcash team claims it doesn't believe the vulnerability was exploited before the upgrade.

Unfortunately, there’s no way to be sure one way or another.

Dan weighs in…

  • This is the actual “worst-case” bug for ZCash. Even Zooko referred to it as such earlier today. People mistakenly focused on the “trusted setup” of the ZCash network, but the auditability of z-addr supply has always been the bigger concern for smart fundamentals investors.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Get an edge with
Blockworks Intel
Upgrade For $4,500/Yr
Upgrade to unlock 300+ industry leading reports from our researchers, including: