Fiat-Shamir Bulletproofs are Non-Malleable (in the Algebraic Group Model)
Chaya Ganesh, Claudio Orlandi, Mahak Pancholi, Akira Takahashi, Daniel Tschudi
Abstract
Bulletproofs (Bünz et al. IEEE S&P 2018) are a celebrated ZK proof system that allows for short and efficient proofs, and have been implemented and deployed in several real-world systems. In practice, they are most often implemented in their non-interactive version obtained using the Fiat-Shamir transform, despite the lack of a formal proof of security for this setting. Prior to this work, there was no evidence that malleability attacks were not possible against Fiat-Shamir Bulletproofs. Malleability attacks can lead to very severe vulnerabilities, as they allow an adversary to forge proofs re-using or modifying parts of the proofs provided by the honest parties. In this paper, we show for the first time that Bulletproofs (or any other similar multi-round proof system satisfying some form of weak unique response property) achieve simulation-extractability in the algebraic group model . This implies that Fiat-Shamir Bulletproofs are non-malleable .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers6
- Riggs: Decentralized Sealed-Bid AuctionsNirvan Tyagi, Arasu Arun, Cody Freitag, Riad S. Wahby et al.CCS 2023 · 15 citations
- SNARKs for Virtual Machines Are Non-malleableMatteo Campanelli, Antonio Faonio, Luigi RussoEUROCRYPT 2025 · 6 citations
- Real-World Universal zkSNARKs are Non-MalleableAntonio Faonio, Dario Fiore, Luigi RussoCCS 2024 · 5 citations
- Universally Composable SNARKs with Transparent Setup without Programmable Random OracleChristian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo et al.CRYPTO 2025 · 3 citations
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael ReichleS&P 2026 · 2 citations
Related papers
- Spartan and Bulletproofs are Simulation-Extractable (for Free!)Quang Dao, Paul GrubbsEUROCRYPT 2023 · 26 citations
- Tight State-Restoration Soundness in the Algebraic Group ModelAshrujit Ghoshal, Stefano TessaroCRYPTO 2021 · 27 citations
- Weak Fiat-Shamir Attacks on Modern Proof SystemsQuang Dao, Jim Miller, Opal Wright, Paul GrubbsS&P 2023
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Fiat-Shamir for Repeated Squaring with Applications to PPAD-Hardness and VDFsAlex Lombardi, Vinod VaikuntanathanCRYPTO 2020 · 40 citations
