Cointime

Download App
iOS & Android

ZKP Series: Pseudonym Input Vulnerability in Circom’s Verification Contract Has Been Replicated

Overview

Earlier, a double-spending vulnerability in a zero-knowledge proof verification contract on Semaphore was uncovered by the Russian developer, Poma. As a matter of curiosity, my intention is to replicate the vulnerability’s PoC initially. However, due to the vulnerability code being old and the project being relatively complex, I opted to create a straightforward PoC to replicate the vulnerability.

Introduction

The foundation of Zero Knowledge Proof (ZKP) technology lies in an algorithm called a “proof system”. By performing a series of computations on the message, the algorithm produces a proof to demonstrate the genuineness of the message. The recipient can confirm the message’s authenticity by verifying the proof alone, without requiring additional information.

There are various implementation schemes for ZKP technology, which we discussed in our earlier article “Technical Features of ZKP Mainstream Implementation Schemes”. In this experiment, the Circom platform is employed, which utilizes Groth16 and PlonK as its proof system. During development, developers can select either system. The development framework generates proof parameters and verification contracts automatically without circuit modification.

In simpler terms, Circom creates witness data and attestation data on the client side and submits them to the contract. The verifier.sol contract verifies the submitted data to confirm whether the proof adheres to the specified rules. This approach enables rapid, efficient, and secure verification while safeguarding the message’s content and privacy.

Vulnerability Analysis

1. There isn’t much to discuss, so let’s proceed straight to the problematic code. Please refer to the “verifyHash” function in the image below. The code enclosed in the red box indicates whether specific witness data has been utilized. This method is commonly employed to prevent double spending. However, the vulnerability has arisen in the witness data “hash1”. Normally, a particular set of proof data should only correspond to a set of “hash1” values for verification purposes.

2. The “verify” function in the “verifier.sol” contract carries out elliptic curve computation verification on the input value via the “scalar_mul()” function. This function conducts calculations on elliptic curves utilizing the input parameters and matches the resulting value against the value specified in the provided proof. The function thereby confirms whether the input value is legitimate or not.

3. In a Solidity smart contract, encoding Fq necessitates the usage of the uint256 type. However, as the maximum value of uint256 is larger than the q value, several distinct integers may correspond to the same Fq value following the modulo operation. For example, “s” and “s+q” indicate the same point, namely the “sth” point. Similarly, “s+2q” and so on are also aliases for point “s”. This phenomenon is known as “Input Aliasing”, whereby these integers serve as pseudonyms for one another.

The “q” value mentioned here pertains to the cyclic group’s order, which signifies the number of values within the same Fq that can be input with numerous large integers. In essence, even if a q value is added to the hash, it can still satisfy the verification criterion. Within the uint256 type’s scope, a maximum of uint256_max/q distinct integers can indicate the same point. This signifies that a set of proofs can have up to 5 hash1 values that match and can pass the contract’s verification.

Vulnerability Recurrence

1. Develop a basic circuit that inputs two data sets and produces a witness data, i.e., “hash1,” utilized in the contract.

2. Compile the circuit to create “circuit_final.zkey”, “circuit.wasm”, and “verifier.sol”. Afterward, generate a collection of proofs, a standard hash, and a corrupted hash.

3. Subsequently, deploy the contract and employ the “checkHash” generated earlier to conduct a verification process. The verification successfully passes.

4. Next, apply the identical witness data and the previously generated “attackHash”. It is discovered that the verification is also successful. This demonstrates that a set of proofs can feature several matching hashes that meet the contract’s verification criteria. Thus, the Circom verification contract input pseudonym vulnerability has been effectively replicated.

Solutions to Vulnerabilities

The vulnerability arises from a set of proofs that can have at most 5 hash values that match and meet the contract’s verification requirements. Thus, the bug fix is straightforward: restricting all input hashes to a value less than “q”.

Summary

Input pseudonym vulnerability is a frequently encountered vulnerability in zero-knowledge proof and cryptography implementation. Its fundamental cause lies in the value being equivalent to the remainder within the finite field. Therefore, developers must focus on the verification group’s order when creating cryptography.

Get the latest news here: Cointime channel — https://t.me/cointime_en

Comments

All Comments

Recommended for you

  • BTC Falls Below $78,000

    Market data shows that BTC has fallen below $78,000, currently priced at $77,993.28, with a 24-hour increase of 1.09%. The market is experiencing significant volatility, so please ensure proper risk management.

  • U.S. Storage Stocks Weaken, SanDisk and Seagate Drop Over 4%

    On September 11, U.S. storage stocks weakened, with SanDisk and Seagate dropping over 4%. Western Digital fell by more than 2%, while Micron Technology and SK Hynix saw declines of less than 1%.

  • US Crypto Stocks Surge, Strategy Up 5.71%

    On September 11, during intraday trading, US crypto-related stocks saw widespread gains, with Strategy (MSTR) rising 5.71%; Coinbase (COIN) up 5.34%; Circle (CRCL) increasing by 5.23%; SharpLink Gaming (SBET) climbing 10.32%; MARA Holdings (MARA) up 6.69%; and BitMine Immersion (BMNR) rising 9.01%.

  • Grayscale: Zcash Mining Profits 2-4 Times Higher than Bitcoin with Hashrate Growth Exceeding 2.5 Times This Year

    According to Grayscale's research director Zach Pandl, Zcash mining profits have surged significantly due to the strong performance of ZEC prices. Data shows that the total daily miner rewards on the Bitcoin network are approximately $35 million, while for Zcash, it is about $2 million. However, the daily earnings per mining machine for Zcash are about twice that of Bitcoin, with earnings per megawatt-hour being approximately four times higher, even surpassing some AI/high-performance computing cloud services. The high profits have driven an increase in mining activities, with Zcash's total hashrate growing over 2.5 times this year, creating a virtuous cycle of 'rising coin prices → increased mining → enhanced network security → supporting coin prices.' The calculations are based on an electricity price of $0.05 per kilowatt-hour and the Bitmain Z15 Pro mining machine operating at full capacity, with data as of September 9.

  • ETH Surpasses $2600

    Market data shows that ETH has surpassed $2600, currently priced at $2601.32, with a 24-hour increase of 7.27%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $79,100

    Market data shows that BTC has surpassed $79,100, currently priced at $79,150, with a 24-hour increase of 2.53%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $79,000

    Market data shows that BTC has surpassed $79,000, currently priced at $79,012, with a 24-hour increase of 2.37%. Due to significant market fluctuations, please ensure proper risk management.

  • U.S. Optical Communication Stocks Surge, Coherent Rises Over 3%

    On September 11, U.S. optical communication stocks collectively surged, with Viavi Solutions, Amphenol, Coherent, AXT Inc, and Lumen Technologies rising over 3%. Additionally, Qioptiq, Applied Optoelectronics, and Ciena increased by more than 2%, while MaxLinear and Corning saw gains of over 1%.

  • Canadian MP Urges Trump: Relax Tariffs to Help U.S. Combat Inflation with Canadian Oil and Minerals

    On September 11, Pierre Poilievre, leader of the Conservative Party of Canada, stated that Canada possesses abundant oil and mineral resources that could help alleviate inflationary pressures in the United States, but the Trump administration needs to relax its tariff policies against Canada. Poilievre strongly promoted Canada's 'affordable energy' and mentioned that he has discussed establishing a 'strategic mineral and oil national reserve' with Canadian Prime Minister Mark Carney for allies to use in times of need. Poilievre said, 'By strengthening trade with Canada, we can lower your cost of living. We can ensure that in the event of future conflicts—hopefully never occurring—we have ample supplies while also restoring the industrial base across the North American continent. But this must be achieved through cooperation.'

  • Iran's Foreign Ministry: Regional Meeting of Gulf Countries Scheduled for Next Monday

    On September 11, Iranian Foreign Ministry spokesman Baghaei announced plans for a regional meeting involving Gulf coastal countries. This meeting represents a significant development, with hopes that it will enhance mutual understanding among regional nations and contribute to strengthening regional security. Iran, Iraq, and other Gulf coastal countries will participate in this meeting, which will take place next Monday in Oman. In addition to other regional issues, the participants will discuss the outcomes of negotiations between Iran and Oman regarding the establishment of a safe commercial shipping corridor in the Strait of Hormuz. The Iranian Foreign Ministry spokesman also mentioned a previous agreement between Iran and Oman on a temporary shipping corridor in the Strait of Hormuz, emphasizing Iran's commitment to taking action to ensure the safety of shipping in the Strait. However, he stated that as long as the U.S. acts aggressively and interferes illegally, including through maritime blockades and economic warfare, the safety of shipping in the Strait of Hormuz cannot be guaranteed.