New paper shows Fiat-Shamir transformation breaks soundness for program-generated R1CS proof systems

jedisct1 · x · 2026-09-02

EPFL researcher Giacomo Fenzi released a new paper showing the Fiat-Shamir transformation is insecure for a class of proof systems whose instances are generated by running a program, including variants of commonly deployed R1CS protocols.

Original post →

More from Research

Research channel →