ZK/SEC Research notes from zkSecurity
All posts
educative · zk

Unveiling the Magic Behind Starknet: A Deep Dive into New Specifications

In our partnership with Starknet, we have performed a number of security audits on some of the network's cryptographic components.

One challenge we encountered was the lack of comprehensive specifications – a common hurdle in the ZKP space. To navigate this, we had to reverse-engineer the protocol, piecing together its logic from various sources and observations.

In this quest to understand the true protocol being implemented, we wrote and published draft specifications for a number of the protocols that we looked at. You can find them here.

starknet rfcs

The specifications are still work-in-progress, and with the support of the community, we aim to refine and enhance them in the near future.

We wrote 4 specifications in total:

Starknet Channels for Fiat-Shamir Instantiation and Starknet Merkle Tree Polynomial Commitments . Both specifications can be seen as self-contained components, building blocks used by the other Starknet schemes.

Starknet FRI Verifier. This document specifies the verification of FRI proofs in the Starknet ecosystem. It builds on top of both of the previous specifications.

Starknet STARK Verifier. This document specifies the verification of STARK proofs in the Starknet ecosystem. It builds on top of all previous specifications, instantiating the FRI specification.

webpage

Feel free to open PRs or issues on the RFCs repository in order to help us improve these specifications.

Keep reading
More to explore

Introducing bugs.zksecurity.xyz a knowledge base for ZK bugs

We're thrilled to introduce our new site, [bugs.zksecurity.xyz](https://bugs.zksecurity.xyz/), a hub for exploring past vulnerabilities in ZK circuits. Dive into our growing catalog of documented bugs and learn how we've reproduced some with comprehensive scripts. Discover evaluations of prominent security tools like Circomspect and Picus, and see where they shine or stumble. We're calling on the community to join us in expanding this invaluable resource, whether by adding bugs, reproducing them, or improving our platform. Let's collaborate to elevate ZK security together!

Stefanos Chaliasos · February 17, 2025

Uncovering and Fixing an Inflation Bug in Aleo

In November 2024, we found a significant inflation bug in the Aleo mainnet that could have allowed token minting without proper checks. We immediately informed the Aleo team, who swiftly addressed the issue with no detected exploitation. This post dives into the inner workings of Aleo and explains how transitions and records operate, providing insight into how the vulnerability was discovered and resolved. It's an intriguing look at blockchain security, zero-knowledge proofs, and the importance of thorough type checks to ensure robust protocol integrity.

Suneal Gong · February 19, 2025

Lean4 formalization of "A Simplified Round-by-round Soundness Proof of FRI"

A Lean4 formalization of the paper "A Simplified Round-by-round Soundness Proof of FRI" by Albert Garreta, Nicolas Mohnblatt, and Benedikt Wagner, completed using Harmonic's Aristotle agent and Claude Code. Welcome to the strange world of machine-led formalization of cryptography.

Yoichi Hirai · January 26, 2026