ZK/SEC Research notes from zkSecurity
All posts
ZPrize · Part 1 of 2

zkSecurity partners with ZPrize to make you win hundreds of thousands of dollars!

zprize

There's one big competition in ZK, and it is called ZPrize. Every year, ZPrize rewards contestants who come up with the most performant implementations for a series of challenges. The goal is to push the limits of what's possible with ZK, and to make sure that the best implementations are open-source and available to everyone.

This year, zkSecurity is proud to announce it'll play the role of one of the three external architects for the competition, hosting the High Throughput Signature Verification ZPrize category.

For this prize, participants will attempt to produce the most performant implementation of a signature verification circuit using Varuna, the latest update of Aleo's proof system. The goal is to be able to verify as many proofs of signatures as possible in a given time frame. Contestants will target ECDSA on the secp256k1 curve (the Bitcoin and Ethereum curve) and keccak256 hash function (the Ethereum hash function). In addition, they will have access to the latest version of the Varuna proof system, which includes lookups.

Verifying ECDSA signatures will involve the two hot problems of arithmetic circuits: non-native arithmetic (arithmetic in fields that are different from the circuit field) and bitwise operations (e.g. XOR, ROT, etc.). Optimizing these low-level primitives should impact all sorts of applications (and non-SNARK-friendly cryptographic algorithms).

We're currently looking to obtain feedback on the current prize specification which you can find on the discord channel (you might have to register here before). We're excited to see people compete and push the limits of what's possible with ZK!

Keep reading
Recommended

A Year of ZK Security

A year after launching, we've grown and evolved alongside the world of zero-knowledge proofs, uncovering bugs and learning the ins and outs of ZK technology. From circuit audits to developing our own tools like Circomscribe, it’s been a wild ride. We've discovered how easy it is to misstep with ZK code, especially as these systems grow complex and impact financial security. As zkVMs gain popularity, we're excited about the challenges ahead and are expanding our expertise. Want to dive into the world of ZK with us? Check out our latest projects and even take on our zkBank challenge!

David Wong · May 30, 2024

Uncovering and Fixing an Inflation Bug in Aleo

In November 2024, we found a significant inflation bug in the Aleo mainnet that could have allowed token minting without proper checks. We immediately informed the Aleo team, who swiftly addressed the issue with no detected exploitation. This post dives into the inner workings of Aleo and explains how transitions and records operate, providing insight into how the vulnerability was discovered and resolved. It's an intriguing look at blockchain security, zero-knowledge proofs, and the importance of thorough type checks to ensure robust protocol integrity.

Suneal Gong · February 19, 2025

Public report of Aleo's consensus (Bullshark)

We recently audited Aleo's blockchain consensus and found it to be impressively well-documented and high-quality. Our collaboration with Aleo's cooperative team helped us uncover several key issues, and the insights from this audit were well-received. In the blog, we dive into Aleo's Bullshark consensus protocol, explaining its step-by-step process and unique pipelining techniques. We also explore how leaders ensure commitments in even rounds and discuss essential aspects like quorum intersection and garbage collection. Whether you're a blockchain enthusiast or just curious about cutting-edge consensus protocols, this post has got some fascinating details to offer!

ZK/SEC · January 02, 2024
More to explore

Exploring Leo: A Primer on Aleo Program Security

In this blog post, we dive into Aleo, a blockchain platform that leverages zero-knowledge cryptography for creating private and scalable decentralized applications. You'll discover how Leo, its Rust-like programming language, simplifies app development by allowing developers to focus on robust privacy features without delving deep into cryptographic complexities. We also explore Leo's unique design, offering practical tips on avoiding common pitfalls and potential vulnerabilities like underflows and unauthorized access. Whether you're a developer curious about building privacy-focused solutions or just intrigued by blockchain innovation, you'll find valuable insights here.

Suneal Gong · August 07, 2024

Cryptography challenges @KalmarCTF 2026

Minsun shares a high-level overview of the hard cryptography challenges he authored for KalmarCTF 2026, focusing on the broader ideas behind their design and solutions. The post reflects on how subtle randomness failures and algebraic structure can lead to deep vulnerabilities.

Minsun Kim · April 28, 2026

A challenge on the Jolt zkVM

Last weekend, we had a blast crafting challenges for a CTF event at the MOCA Italian hacker camp. One cryptography challenge, "2+2=5," involved the Jolt zkVM and a RISC-V program. In this post, we share the ins and outs of the challenge, the clever use of a modified Jolt library, and how we managed to prove an invalid execution without triggering verification alarms. Get ready to dive into the world of Jolt and pick up some nifty insights on exploiting cryptographic systems like a true hacker.

Giorgio Dell'Immagine · September 24, 2024