WI Is Not Enough: Zero-Knowledge Contingent (Service) Payments Revisited
Georg Fuchsbauer
Abstract
While fair exchange of goods is known to be impossible without assuming a trusted party, smart contracts in cryptocurrencies forgo such parties by assuming trust in the currency system. They allow a seller to sell a digital good, which the buyer will obtain if and only if she pays. Zero-knowledge contingent payments (zkCP) show that, despite the limited expressiveness of its scripting language, this is even possible in Bitcoin by using zero-knowledge proofs. At CCS'17, Campanelli, Gennaro, Goldfeder and Nizzardo showed that the zkCP protocol was flawed, in that the buyer could obtain information about the good without paying. They proposed countermeasures to repair zkCP and moreover observed that zkCP cannot be used when a service is sold. They introduce the notion of ZK contingent payments for services and give an instantiation based on a witness-indistinguishable (WI) proof system. We show that some of their proposed countermeasures are not sufficient by presenting an attack against their fixed zkCP scheme. We also show that their realization of zkCP for services is insecure, as the buyer could learn the desired information (i.e., whether the service was provided) without paying; in particular, we show that WI of the used proof system is not enough.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 21e88615-aa0c-4406-be5b-d9110a67d910Cited by top-tier papers5
- MAD-HTLC: Because HTLC is Crazy-Cheap to AttackItay Tsabary, Matan Yechieli, Alex Manuskin, Ittay EyalS&P 2021 · 87 citations
- Lift-and-Shift: Obtaining Simulation Extractable Subversion and Updatable SNARKs GenericallyBehzad Abdolmaleki, Sebastian Ramacher, Daniel SlamanigCCS 2020 · 31 citations
- ZKCPlus: Optimized Fair-exchange Protocol Supporting Practical and Flexible Data ExchangeYun Li, Cun Ye, Yuguang Hu, Ivring Morpheus et al.CCS 2021 · 26 citations
- Atomic and Fair Data Exchange via BlockchainErtem Nusret Tas, István András Seres, Yinuo Zhang, Márk Melczer et al.CCS 2024 · 15 citations
- A Secure Sequencer and Data Availability Committee for RollupsMargarita Capretto, Martín Ceresa, Antonio Fernández Anta, Pedro Moreno-Sanchez et al.CCS 2025
Related papers
- Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesMatteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca NizzardoCCS 2017 · 170 citations
- WI is Almost Enough: Contingent Payment All Over AgainKy Nguyen, Miguel Ambrona, Masayuki AbeCCS 2020 · 13 citations
- GZKP: A GPU Accelerated Zero-Knowledge Proof SystemWeiliang Ma, Qian Xiong, Xuanhua Shi, Xiaosong Ma et al.ASPLOS 2023 · 47 citations
- FairSwap: How To Fairly Exchange Digital GoodsStefan Dziembowski, Lisa Eckey, Sebastian FaustCCS 2018 · 229 citations
- DIZK: A Distributed Zero Knowledge Proof SystemHoward Wu, Wenting Zheng, Alessandro Chiesa, Raluca Ada Popa et al.USENIX Security 2018 · 152 citations
