Skip to content
Blockchain

Why does a missing constraint in my ZK circuit survive five separate audits?

84

Fırsat

ZK circuits can contain constraints that are syntactically valid but logically incomplete, leaving the witness underconstrained so an attacker can construct a fake proof the verifier accepts. The Zcash Orchard circuit had exactly this bug, disclosed in June 2026 after sitting undetected for four years through multiple professional audits. Existing static analysis tools catch simple cases but cannot prove completeness over a full production circuit. Fuzzing finds individual bugs but generates no soundness guarantee. No workflow in standard use today can tell you, before deployment, that your circuit has no underconstrained witness.

Neden önemli

A single missing constraint is enough to let an attacker mint value from nothing, and no standard pre-deployment workflow gives a completeness guarantee over a full production circuit.

Fırsatı nasıl puanlıyorum

Fırsat Puanı benim kendi değerlendirmem, bir ölçüm değil: ne kadar acı verdiği, ne sıklıkla etkisi olduğu ve bugün için ne kadar az çözüm bulunduğu. Daha yüksek puan, inşa etmeye daha değer olduğunu düşündüğüm anlamına gelir.

Ciddiyet9/10

Ortaya çıktığında ne kadar sorun yarattığı.

Sıklık6/10

İnsanların bununla gerçekte ne sıklıkla karşılaştığı.

Boşluk8/10

Bugün bunun için ne kadar az iyi araç bulunduğu.

Çözmeye değer daha fazla sorun