Circuit and contract bugs allowed forged proofs
On this page
CriticalDemonstrated attackMitigated
Trail of Bits found three high-severity soundness bugs in EZKL's circuits: an unsound shuffle argument for min, max and top-k, a decomposition that did not fix the sign of zero, and missing range checks for division and reciprocals. Each would let a malicious prover convince a verifier of incorrect calculations, for example that [1,1,1] is a valid permutation of [1,2,3]. It also found four ways to bypass the data attestation and KZG commitments in EZKL's smart contracts. All were resolved at the March 2025 fix review. Some fixes were first made in private repositories, to allow disclosure to projects using the contracts in production 3.
Sources: [3]