Real-World Universal zkSNARKs are Non-Malleable
Antonio Faonio, Dario Fiore, Luigi Russo
Abstract
Simulation extractability is a strong security notion of zkSNARKs that guarantees that an attacker who produces a valid proof must know the corresponding witness, even if the attacker had prior access to proofs generated by other users. Notably, simulation extractability implies that proofs are non-malleable and is of fundamental importance for applications of zkSNARKs in distributed systems. In this work, we study sufficient and necessary conditions for constructing simulation-extractable universal zkSNARKs via the popular design approach based on compiling polynomial interactive oracle proofs (PIOP). Our main result is the first security proof that popular universal zkSNARKs, such as PLONK and Marlin, as deployed in the real world, are simulation-extractable. Our result fills a gap left from previous work (Faonio et al. TCC'23, and Kohlweiss et al. TCC'23) which could only prove the simulation extractability of the "textbook" versions of these schemes and does not capture their optimized variants, with all the popular optimization tricks in place, that are eventually implemented and deployed in software libraries. CCS CONCEPTS • Security and privacy → Cryptography.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8a22aeb-7065-41b2-98c0-1da12601119aCited by top-tier papers3
- SNARKs for Virtual Machines Are Non-malleableMatteo Campanelli, Antonio Faonio, Luigi RussoEUROCRYPT 2025 · 6 citations
- TACITA: Threshold Aggregation without Client InteractionVarun Madathil, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2026 · 2 citations
- Sumcheck-Based zkSNARKs are Non-malleableAntonio Faonio, Luigi RussoCRYPTO 2026
Builds on11
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference StringsMary Maller, Sean Bowe, Markulf Kohlweiss, Sarah MeiklejohnCCS 2019 · 412 citations
- Marlin: Preprocessing zkSNARKs with Universal and Updatable SRSAlessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra et al.EUROCRYPT 2020 · 356 citations
- Transparent SNARKs from DARK CompilersBenedikt Bünz, Ben Fisch, Alan SzepieniecEUROCRYPT 2020 · 240 citations
- HyperPlonk: Plonk with Linear-Time Prover and High-Degree Custom GatesBinyi Chen, Benedikt Bünz, Dan Boneh, Zhenfei ZhangEUROCRYPT 2023 · 132 citations
Related papers
- Witness-Succinct Universally-Composable SNARKsChaya Ganesh, Yashvanth Kondi, Claudio Orlandi, Mahak Pancholi et al.EUROCRYPT 2023 · 24 citations
- Spartan and Bulletproofs are Simulation-Extractable (for Free!)Quang Dao, Paul GrubbsEUROCRYPT 2023 · 26 citations
- zkSaaS: Zero-Knowledge SNARKs as a ServiceSanjam Garg, Aarushi Goel, Abhishek Jain, Guru-Vamsi Policharla et al.USENIX Security 2023
- Constant-Size zk-SNARKs in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimEUROCRYPT 2024 · 14 citations
- On Knowledge-Soundness of Plonk in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimCRYPTO 2025 · 10 citations
