@ProjectZKM

Ziren: Universal Proving Toolstack

ZK
Joined June 2023
The solution of post-quantum safe BitVM is coming soon!
Of the two families in the comparison, the lattice side is where we're headed: ML-DSA is the scheme GOAT Network's validator consensus keys are migrating to. With the @AppliedPQC playground, anyone can run it in browser and see what that means. The post-quantum work continues.
2
14
3,416
ZK does not remove trust while what ZK is good at is narrower, and more useful. It can prove one fact, age, wealth etc., not on a sanctions list, without handing over the passport, address, or income behind that fact. It changes what you have to trust. Today’s KYC/AML model treats a full identity file as proof of compliance. Every institution collects the same personal data, stores it, and hopes a bigger database will catch more crime. That is the “data haystack”: more records, more breach risk, not necessarily more signal. But the trust root remains. A proof only shows that some inputs satisfy a rule. It does not prove those inputs were honest. Someone still has to issue the credential, screen the wallet, or sign the risk score. If that issuer is compromised, the math will still verify a bad claim. So the real world stays responsible for issuance and accountability. ZK keeps disclosure small, the chain stores a checkable proof instead of a personal file. ZK can shrink the haystack. It cannot certify the needle. #zkvm
🚨 LATEST: SEC Commissioner Hester Peirce says zero-knowledge proofs could verify compliance without collecting users’ personal data. She warns current KYC/AML practices create “data haystacks.”
1
17
3,671
Our piece on why "hash-based is not the same as post-quantum" drew a lot of attention from the ZK research community, but the best way to understand the argument is to run the schemes for yourself. The @AppliedPQC playground puts SLH-DSA (hash-based) and the lattice schemes (ML-DSA, ML-KEM, Falcon) side by side, in your browser. The code is fetched straight from the repo, so what runs is exactly what's documented. → appliedpqc.io/playground.htm…
16
15
3
42
105,262
Machine-checked proofs are becoming the standard for serious proof systems. Different systems need different properties pinned down. For a privacy protocol, zero knowledge is the product, so that is the property to prove. For a zkVM proving a Bitcoin bridge, the property that matters most is soundness: a proof that should not exist must be impossible to construct. Formal verification has been part of Ziren for more than a year - @VeridiseInc formally checked constraint determinism with Picus alongside a full independent audit, before @ConsensysAudits stress-tested the system. Ziren 2.0 extends this with machine-checked proofs in Lean 4.
18
14
3
38
8,429
Formal verification becomes one of the fundamental feature of proof system. Ziren 1.x @ProjectZKM was formally verified by Veridise, and the upcoming 2.0 is already formal verified by Lean4.
1
13
3,569
@ProjectZKM tackled the claim doing the most damage in this conversation: "STARKs are hash-based, so they must be post-quantum". True of a commitment scheme, false of a proof system. ZKM audited Ziren under that rule, found one thing, and shows how it closes. This piece has been resonating with ZK researchers for a reason. zkm.io/blog/hash-based-is-no…
1
1
8
2,101
Make GOAT Network PQ safe step by step.
A network built to secure the next economy with Bitcoin has to outlive the quantum computer. The signatures securing most blockchains today will not. GOAT Network is moving its validator consensus keys from secp256k1 to ML-DSA-65, the NIST post-quantum signature standard: one validator at a time, while the chain keeps producing blocks. Full engineering writeup below: what broke, what it costs, and the playbook for any chain looking to do the same. hackmd.io/@goatresearch/B1f3…
2
15
3,576
Ziren powers a network that keeps hitting new major milestones in agent infrastructure. GOAT Flow is the latest. Merchants can now plug into the AI agent economy and begin selling in minutes. No code required.
Introducing GOAT Flow. Your next customer might not be a person. AI agents are starting to buy things, and most businesses have no way to sell to them. Now any merchant can. No code, in just a few minutes. Simple agent commerce, secured by Bitcoin. → goat.network/flow
17
14
27
4,237
This covenant assessment includes the measured, end-to-end construction of @GOATNetwork's BitVM3 bridge - and Ziren is inside it. Ziren generates a STARK proof in every peg-in setup: instead of publishing labels for all seven garbled-circuit instances, the verifier publishes one, and Ziren proves the rest are consistent with it. Full setup runs in roughly 25 minutes on CPUs, no SRS ceremony, no GPUs.
8
15
27
3,371
Today, builders who spent a summer shipping agent products put their work in front of a live audience. Joining to judge: @GOATNetwork CEO @kevinliu, @ProjectZKM CTO @sd_eigen, and @MetisL2's @ElenaCryptoChic and Andrei S. Live here at 9am EST.
11
15
1
46
63,236
A look at the security report from our audit of Ziren, a zkVM, assessed through our Vulnerability Mining workflow and ZK fuzzing, in close collaboration with @ProjectZKM ↓
The past week at GOAT: Last week was largely about @ProjectZKM. From the release of the Ziren security report with @ConsensysAudits to new work on Poseidon2 and long-term cryptographic assumptions, much of the week focused on the proving and security layer that sits beneath GOAT Network. Also this week: ◦ @0x1164 hosted Part 2 of From Demo to Demand, with the full resource pack now available ◦ Our team showed support for BIP-448 ◦ We gave a clear view of "What We Want Built on GOAT" And more. Dive in below 🧵
5
18
3,829
Finally, ZKM published new work on the industry's reassessment of Poseidon2 and what it means for where cryptographic risk should sit. Ziren is already evolving with it - its public-input digest recently migrated from Poseidon2 to BLAKE3, keeping its most critical components on the most battle-tested cryptography available. Full article below. zkm.io/blog/why-ethereum-wal…
2
6
2,451
One comment in the report carried particular weight. Consensys Diligence CEO @T_Birb described Ziren as a credible contender in the proving space. That assessment comes from a world-class research team that has audited much of the leading ZK ecosystem. Not to be taken lightly.
1
1
9
2,505
The biggest release this week came from our zk R&D branch, @ProjectZKM. ZKM published the full story behind Ziren's security collaboration with @ConsensysAudits and the @ethereumfndn: what was reviewed, how the work evolved, what changed as a result, and what the process says about building a production-ready zkVM. zkm.io/blog/inside-zirens-se…
1
1
8
2,559
When binary fields operations become efficient, hash functions with more strict security assumptions come back.
1
11
23
6,504
Nearly every production zkVM runs Poseidon2 - Ziren included. So this lands on all of us. It is also the right call. The least-reported step in the reasoning is the most important one: this is NOT swapping a young hash for a young proof system. A weakened hash is an assumption-layer failure - forgeable signatures, commitments that open two ways, nothing on chain repairable afterward. A proof system defect is a mechanism-layer failure - patch the verifier, swap the backend, every existing commitment survives. Binary fields move the young component from the layer you cannot fix to the layer you can, and the reduction bottoms out at SHA-2/BLAKE: the most battle-tested assumption available. That same asymmetry is why L1 had to move now and zkVMs can move deliberately. In a zkVM the hash is a swappable backend component. Nothing published breaks deployed parameters - and we have already started moving: Ziren recently migrated its public-input digest from Poseidon2 to BLAKE3. Pivoting to BLAKE is one of our objectives too. First step, not the last. Full write-up to follow.
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
56
62
1
93
2,893
Pivoting to BLAKE is one of our objectives too. We recently migrated the digest function of public inputs in Ziren from Poseidon2 to BLAKE3. @ProjectZKM @GOATNetwork
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
2
6
3
20
21,625
We completed seven months of zk fuzzing (@vwuestholz) and Vulnerability Mining (@nicht_tintin) with @ProjectZKM on Ziren, a MIPS32 zkVM. Ziren proves production workloads, including @GOATNetwork's BitVM3 bridge. Five bugs found: → Completeness bug - MIPS div register allocation: root cause traced to MipsAsmParser::expandDivRem in LLVM's MIPS assembly parser. → Completeness bug - MIPS div instruction: dividing i32::MIN by -1 caused an arithmetic overflow error. → Soundness bug - MIPS teq instruction: an unbound rs register let a prover forge results (demoed via a gcd() proof of concept). → Soundness bug - MIPS ins instruction: a shift amount of 32 exceeded the supported range (0-31), enabling invalid proofs. → Soundness bug - syscall path: a window where a prover could overwrite a syscall's return value before the V0 register write-back. Arguzz, the fuzzer for zkVMs, was used for this engagement. It combines metamorphic testing with fault injection, generating semantically equivalent program variants and flagging divergence across the pipeline. The final step ran Vulnerability Mining across the Ziren codebase. Candidate findings were shared with the Ziren team through minr, our self-service triage platform, and ranked by priority and exploitability. Special thanks to @tu_wien and @ethereumfndn for the collaboration. Full findings breakdown in the write-up:
11
24
4,354