4W
...
This is a segment from the 0xResearch newsletter. To read full editions, subscribe.
Succinct’s SP1 ZKVM has come under scrutiny after LambdaClass disclosed a critical security vulnerability in its proof generation. The exploit in version 3 of SP1, discovered in collaboration with 3Mi Labs and Aligned, stemmed from the interaction of two separate security flaws.
Succinct previously disclosed the potential exploit to its customers via Github and Telegram.
Here’s what happened in simple terms:
Missing Verification Step — The system relied on a list to track key proof components but didn’t properly verify that the list was accurate. Consequently, a malicious prover… Read more on Blockworks