ZK-Hammer: Leaking Secrets from Zero-Knowledge Proofs via Rowhammer
Junkai Liang, Xin Zhang, Daqi Hu, Qingni Shen, Yuejian Fang, Zhonghai Wu
Abstract
Zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK) schemes have been a promising technique in verified computation. Zk-SNARK schemes were designed to be mathematically secure against cryptographic attacks and it remains unclear whether they are vulnerable to fault injection attacks. In this work, we provide a positive answer by presenting ZK-Hammer, which leaks secrets from zk-SNARK schemes via Rowhammer. We incur faults in the exponentiate variables in the Quadratic Arithmetic Program (QAP) problem. Then we analyze the faulty proof using the bilinear pairing technique and manage to recover the secret. We employ a Rowhammer fault evaluation in libsnark and identify 3 CVEs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b1da001f-c1f8-4b97-b615-a809b3eb19e4Builds on17
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel et al.USENIX Security 2016 · 306 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- ZEXE: Enabling Decentralized Private ComputationSean Bowe, Alessandro Chiesa, Matthew Green, Ian Miers et al.S&P 2020 · 257 citations
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 239 citations
Related papers
- Achilles: A Formal Framework of Leaking Secrets from Signature Schemes via RowhammerJunkai Liang, Zhi Zhang, Xin Zhang, Qingni Shen et al.USENIX Security 2025
- Ligero: Lightweight Sublinear Arguments Without a Trusted SetupScott Ames, Carmit Hazay, Yuval Ishai, Muthuramakrishnan VenkitasubramaniamCCS 2017 · 338 citations
- Phecda: Post-Quantum Transparent zkSNARKs from Improved Polynomial Commitment and VOLE-in-the-Head with Application in Publicly Verifiable AESChangchang Ding, Yan HuangS&P 2025
- Hobbit: Space-Efficient zkSNARK with Optimal Prover TimeChristodoulos Pappas, Dimitrios PapadopoulosUSENIX Security 2025
- SoK: Understanding zk-SNARKs: The Gap Between Research and PracticeJunkai Liang, Daqi Hu, Pengfei Wu, Yunbo Yang et al.USENIX Security 2025
