Sign in

Nico

@nmohnblatt.me
309 followers 170 following 57 posts

picious until proven otherwise. Cryptography research and auditing at zkSecurity. Recurring co-host on the ZKPodcast. nmohnblatt.me

PostsRepliesMedia
Reposted by Nico
ePrint Updates @eprint.ing.bot · 31/05/2026
Extending FRIDA Beyond Unique Decoding for Free (Nicolas Mohnblatt, Benedikt Wagner) ia.cr/2026/1055
Abstract. Hall-Andersen, Simkin and Wagner (CiC 1:4) show how to construct data availability sampling schemes from code commitments. Later, in FRIDA (CRYPTO’24), the same authors describe a compiler that takes an interactive oracle proof of proximity (IOPP) for a code and produces a secure code commitment. Chaining both results allows to construct efficient data availability sampling schemes from IOPPs.

In this short note, we give a novel security analysis that extends the results of FRIDA beyond the unique decoding radius of the code being used. This strict improvement leads to data availability sampling schemes with smaller commitments.

Towards our novel analysis, we define a variant of the opening-consistency property introduced in FRIDA, which we name opening-consistency with assign. Crucially, our new property does not depend on the unique decoding radius of the code. We then show that the FRIDA compiler can be applied to IOPPs that have opening-consistency with assign to produce secure code commitments. Finally, we show that under mutual correlated agreement, the batched FRI protocol (FOCS’20) satisfies opening-consistency with assign. This latter result is enabled by a recent analysis of FRI by Garreta, Mohnblatt and Wagner (ePrint 2025/1993).
Image showing part 2 of abstract.
041
Nico @nmohnblatt.me · 12/02/2026
Help, lattice folks what does this mean?
020
Reposted by Nico
ePrint Updates @eprint.ing.bot · 12/02/2026
Analysis and Vulnerabilities in zkLogin (Sofia Celi, Hamed Haddadi, Kyle Den Hartog) ia.cr/2026/227
Abstract. Zero-Knowledge Authorization (ZKA) systems allow users to prove possession of externally issued credentials (e.g., JSON Web Tokens) without revealing the credentials in full via the usage of Zero-Knowledge Proofs (ZKP). They are increasingly promoted as privacy-preserving and decentralized alternatives for authorization, and are already deployed in practice, with proposals for higher-stakes settings such as government access-control frameworks. In this work, we show that the security and privacy of zkLogin—the most widely deployed ZKA system—cannot only be reduced to the underlying ZKP. Instead, zkLogin critically depends on non-cryptographic assumptions about JWT/JSON parsing, issuer trust policy, architectural binding, and execution-environment integrity: none of which are specified or enforced as protocol-level properties.

Via an analysis of the public documentation, source code and surveys on wallets and public endpoints, we identify three broad classes of vulnerabilities in zkLogin: (i) permissive, non-canonical claim extraction that admits malformed JWTs; (ii) transformation of short-lived authentication artifacts into durable authorization credentials without enforcing their issuance context (issuer, audience, subject and temporal validity binding), which enables cross-application impersonation and misuse—particularly in browser-based deployments that expose system’s material; and (iii) systemic centralization and privacy risks arising from reliance on a small set of issuers and outsourced proving infrastructure, including disclosure of user identity attributes to third-party services without consent. We note that none of the vulnerabilities identified are cryptographic in nature. Overall, our findings demonstrate that zkLogin inherits, and in some cases amplifies, fragilities of web-based authentication ecosystems, and that the security of the system cannot be reduced only to the ZKPs
Image showing part 2 of abstract.
071
Nico @nmohnblatt.me · 07/02/2026
On using LLMs for research (beyond basic prompts). Section 3.2 is specifically about catching a bug in a recent SNARG paper arxiv.org/abs/2602.03837
arxiv.org
Accelerating Scientific Research with Gemini: Case Studies and Common Techniques
Recent advances in large language models (LLMs) have opened new avenues for accelerating scientific research. While models are increasingly capable of assisting with routine tasks, their ability to co...
041
Nico @nmohnblatt.me · 27/01/2026
Amazing work from Yoichi giving a Lean proof of my recent FRI security paper (w/ Albert Garreta and Benedikt Wagner) Super interesting workflow as well, combining TeX-to-Lean models with regular coding agents. I think we'll see a lot more of this moving forward!
030
Nico @nmohnblatt.me · 24/12/2025
Great short article from Moxie. Right in time for family dinners and questions about AI and privacy confer.to/blog/2025/12...
confer.to
Confessions to a data lake
I’ve been building Confer: end-to-end encryption for AI chats. With Confer, your conversations are encrypted so that nobody else can see them. Confer can’t read them, train on them, or hand them over ...
241
Reposted by Nico
ePrint Updates @eprint.ing.bot · 22/12/2025
Laminate: Succinct SIMD-Friendly Verifiable FHE (Kabir Peshawaria, Zeyu Liu, Ben Fisch, Eran Tromer) ia.cr/2025/2285
Abstract. In outsourcing computation to untrusted servers, one can cryptographically ensure privacy using Fully Homomorphic Encryption (FHE) or ensure integrity using Verifiable Computation (VC) such as SNARK proofs. While each is practical for some applications in isolation, efficiently composing FHE and VC into Verifiable Computing on Encrypted Data (VCoED) remains an open problem.

We introduce Laminate, the first practical method for adding integrity to BGV-style FHE, thereby achieving VCoED. Our approach combines the blind interactive proof framework with a tailored variant of the GKR proof system that avoids committing to intermediate computation states. We further introduce variants employing transcript packing and folding techniques. The resulting encrypted proofs are concretely succinct: 270kB, compared to 1TB in prior work, to evaluate a batch of B = 2¹⁴ instances of size n = 2²⁰ and depth d = 32. Asymptotically, the proof size and verifier work is O(dlog (Bn)), compared to Ω(BNlog n) in prior work (for ring dimension N).

Unlike prior schemes, Laminate utilizes the full SIMD capabilities of FHE for both the payload circuit evaluation and proof generation; adds only constant multiplicative depth on top of payload evaluation while performing Õ(n) FHE operations; eliminates the need for witness reduction; and is field-agnostic. The resulting cost of adding integrity to FHE, compared to assuming honest evaluation, is  ∼ 12× to  ∼ 36× overhead (for deep multiplication-heavy circuits of size 2²⁰), which is  > 500× faster than the state-of-the-art.
Image showing part 2 of abstract.
042
Nico @nmohnblatt.me · 30/10/2025
Also wrote a blog post that explains the proof in a shorter format and with less formality blog.zksecurity.xyz/posts/fri-se...
blog.zksecurity.xyz
Why does FRI work?
This blog post explains the security intuition behind the FRI protocol, which proves that a function is close to a valid Reed-Solomon codeword. It introduces the “prover message graph,” a layered stru...
051
Nico @nmohnblatt.me · 30/10/2025
Trying to reduce some headaches!
010
Reposted by Nico
ZK Hack @zkhack.dev · 03/09/2025
It’s time to reveal the ZK Whiteboard S3 Module 1... because it's LIVE! 🥁🥁🥁🥁 How to Build Hash Functions, with Jean-Philippe (JP) Aumasson @aumasson.jp & @nicomnbl.bsky.social Watch the full module here: zkhack.dev/whiteboard/s...
043
Reposted by Nico
NiixARTs @niixarts.bsky.social · 01/08/2025
Time has changed
68138055050
Reposted by Nico
ZK Hack @zkhack.dev · 10/07/2025
The ZK Podcast released an episode on local-first software this week! @arro.bsky.social and @nicomnbl.bsky.social chat w @grjte.sh & @goblinoats.com about the foundations of local-first architecture, CRDTs and how ZK can be incorporated into these models. zeroknowledge.fm/podcast/367/
zeroknowledge.fm
Local-First with grjte and Goblin Oats - ZK PODCAST
In this episode, Anna Rose and Nico Mohnblatt speak with Goblin Oats from Tonk and grjte from Bain Capital Crypto […]
0155
Reposted by Nico
weijie @kohweijie.com · 11/06/2025
2/ As such, I wrote a research note to help cryptography engineers fully understand both techniques: baincapitalcrypto.com/a-deep-dive-...
baincapitalcrypto.com
A Deep Dive into Logjumps: a Faster Modular Reduction Algorithm
Logjumps is a recently discovered technique for modular reduction over large prime fields.
131
Reposted by Nico
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
I'm happy to finally open-source lattirust, a library for lattice-based zero-knowledge/succinct arguments! Lattirust is somewhat like arkworks, but for lattices; and like lattigo, but for arguments. ➔ github.com/lattirust
github.com
lattirust
Lattice zero-knowledge/succinct arguments, and more - lattirust
23216
Nico @nmohnblatt.me · 09/05/2025
I wrote a thing on my colleagues Andrija and Guille's latest work
020
Nico @nmohnblatt.me · 03/03/2025
Story of the ZK whiteboard series S2! The grant that supported it, how we came up with the topics, participation of our esteemed speakers, some crazy editing and how the bonus modules came to be
020
Nico @nmohnblatt.me · 26/02/2025
from the archive: Or Sattath came on the ZKPodcast to discuss quantum computing and its impact on cryptography. These two are some of my 𝐟𝐚𝐯𝐨𝐮𝐫𝐢𝐭𝐞 episodes of the show. Part 1 covers the computation model, why it breaks some cryptography and effects on mining zeroknowledge.fm/podcast/288/ 1/2
110
Nico @nmohnblatt.me · 25/02/2025
A step towards fixing the recent attack on a Fiat-Shamir'd variant of GKR. Tl;dr: do proof-of-work before deriving the FS challenge, this will make the hash prohibitively expensive to compute in-circuit. Caveat: they only prove the security of their transform for 1-round protocols
001
Nico @nmohnblatt.me · 23/02/2025
sigh
052
Nico @nmohnblatt.me · 21/02/2025
Terrible news
020
Nico @nmohnblatt.me · 17/02/2025
Sublinear prover?!?! Incredible result!
071
Reposted by Nico
Matthew Green @matthewdgreen.bsky.social · 30/01/2025
Look folks. I want BlueSky to succeed, because we need an alternative to X. I also know this is an insane time. But if we want to create a usable alternative, people are going to have to start posting occasionally about something else.
1917614
Nico @nmohnblatt.me · 29/01/2025
These two lectures by @danboneh.bsky.social for @zkhack.bsky.social are the best explanation of IOPPs, FRI and its variants by a country mile. Cannot recommend them enough zkhack.dev/whiteboard/s... zkhack.dev/whiteboard/s...
0117
Nico @nmohnblatt.me · 27/01/2025
programmable* cryptography * programming difficulty may vary, developer discretion is advised.
031
Reposted by Nico
weijie @kohweijie.com · 24/01/2025
Want to send crypto to Bluesky users? It's possible! Their keypairs are for the secp256k1 curve, which Ethereum also uses. That means you can derive an ETH address from their publicly accessible signing keys.
5193
Nico @nmohnblatt.me · 23/01/2025
oh hello @zkhack.bsky.social 👀👀
231
Nico @nmohnblatt.me · 09/01/2025
Straight to the reading list!
140
Reposted by Nico
ePrint Updates @eprint.ing.bot · 09/01/2025
ZODA: Zero-Overhead Data Availability (Alex Evans, Nicolas Mohnblatt, Guillermo Angeris) ia.cr/2025/034
Abstract. We introduce ZODA, short for ‘zero-overhead data availability,’ which is a protocol for proving that symbols received from an encoding (for tensor codes) were correctly constructed. ZODA has optimal overhead for both the encoder and the samplers. Concretely, the ZODA scheme incurs essentially no incremental costs (in either computation or size) beyond those of the tensor encoding itself. In particular, we show that a slight modification to the encoding scheme for tensor codes allows sampled rows and columns of this modified encoding to become proofs of their own correctness. When used as part of a data availability sampling protocol, both encoders (who encode some data using a tensor code with some slight modifications) and samplers (who sample symbols from the purported encoding and verify that these samples are correctly encoded) incur no incremental communication costs and only small additional computational costs over having done the original tensor encoding. ZODA additionally requires no trusted setup and is plausibly post-quantum secure.
021
Nico @nmohnblatt.me · 08/12/2024
mobile proving ftw
041
Nico @nmohnblatt.me · 04/12/2024
if someone tells you “succinct proofs are too short to leak information about the witness”, please send them this. The ZK property is not just a cool acronym. baincapitalcrypto.com/chosen-insta... This was also the theme of the "Zeitgeist" puzzle at ZK Hack 5!
074
Nico @nmohnblatt.me · 04/12/2024
New work!
071
Nico @nmohnblatt.me · 03/12/2024
These are incredible asymptotics! Has anyone looked into it / confirmed the result?
020
Nico @nmohnblatt.me · 28/11/2024
Latest ZKPodcast episode with @danboneh.bsky.social is such a joy to listen to. Highly recommend! zeroknowledge.fm/345-2/
zeroknowledge.fm
Episode 345: Latest ZK Research with Dan Boneh
In this week’s episode, Anna catches up with Dan Boneh, Professor of Computer Science and Electrical Engineering, Stanford University. They [...]
073
Nico @nmohnblatt.me · 26/11/2024
An empirical study of ZKP languages across Github repos, super cool way to identify past and current trends Looking forward to see Noir and Halo2 get added github.com/ArmanKolozya...
0131
Nico @nmohnblatt.me · 20/11/2024
Long time UK resident here, Bluesky feels just like home
030
Nico @nmohnblatt.me · 19/11/2024
Very excited for these puzzles to come out. I think they have huge teaching potential. Join us for this weekly online event! ZK Hack is a great way to learn about advanced cryptography and meet the cryptography-in-web3 community
043
Reposted by Nico
Olivier Simard-Casanova @o.simardcasanova.net · 16/11/2024
Newskies! Quiet Posters is such an incredible feed It shows you posts from people you follow and who post infrequently Can’t recommend it enough
23828320
Nico @nmohnblatt.me · 17/11/2024
Hopefully, the more Musk does this the fewer people there will be on X to read his boosted posting
010
Nico @nmohnblatt.me · 25/09/2023
ZK in french is incredibly not catchy: ZKP - preuve à divulgation nulle de connaissance Commitment scheme - protocole de mise en gage Hash function - fonction de hachage Lookup table - table de correspondance how am I supposed to get anyone interested in this 😩😩
030
Nico @nmohnblatt.me · 13/08/2023
Super proud of this work! Really hoping this can get deployed into real-world social apps. Happy to chat further with anyone interested
031
Nico @nmohnblatt.me · 18/04/2023
What's your favourite ZeroKnowledge Podcast episode @zkpod.ai ?
120
Nico @nmohnblatt.me · 13/04/2023
The only sangria mentioned here is *not* an alcoholic beverage
140
Reposted by Nico
⚡️🌙 @dystopiabreaker.xyz · 12/04/2023
the vibes here are immaculate
1210915