Reposted by NicoePrint Updates @eprint.ing.bot · 31/05/2026Extending FRIDA Beyond Unique Decoding for Free (Nicolas Mohnblatt, Benedikt Wagner) ia.cr/2026/1055 041
Reposted by NicoePrint Updates @eprint.ing.bot · 12/02/2026Analysis and Vulnerabilities in zkLogin (Sofia Celi, Hamed Haddadi, Kyle Den Hartog) ia.cr/2026/227 071
Nico @nmohnblatt.me · 07/02/2026On using LLMs for research (beyond basic prompts). Section 3.2 is specifically about catching a bug in a recent SNARG paper arxiv.org/abs/2602.03837arxiv.orgAccelerating Scientific Research with Gemini: Case Studies and Common TechniquesRecent advances in large language models (LLMs) have opened new avenues for accelerating scientific research. While models are increasingly capable of assisting with routine tasks, their ability to co... 041
Nico @nmohnblatt.me · 27/01/2026Amazing work from Yoichi giving a Lean proof of my recent FRI security paper (w/ Albert Garreta and Benedikt Wagner) Super interesting workflow as well, combining TeX-to-Lean models with regular coding agents. I think we'll see a lot more of this moving forward! 030
Nico @nmohnblatt.me · 24/12/2025I haven't had a look actually. But I suspect that's the only viable option for now 010
Nico @nmohnblatt.me · 24/12/2025Great short article from Moxie. Right in time for family dinners and questions about AI and privacy confer.to/blog/2025/12...confer.toConfessions to a data lakeI’ve been building Confer: end-to-end encryption for AI chats. With Confer, your conversations are encrypted so that nobody else can see them. Confer can’t read them, train on them, or hand them over ... 241
Reposted by NicoePrint Updates @eprint.ing.bot · 22/12/2025Laminate: Succinct SIMD-Friendly Verifiable FHE (Kabir Peshawaria, Zeyu Liu, Ben Fisch, Eran Tromer) ia.cr/2025/2285 042
Nico @nmohnblatt.me · 17/12/2025agreed. Although I would love to see it run in a TEE, same way Signal are doing theirs. Otherwise, we are still uploading our contacts to an untrusted server 000
Nico @nmohnblatt.me · 30/10/2025Also wrote a blog post that explains the proof in a shorter format and with less formality blog.zksecurity.xyz/posts/fri-se...blog.zksecurity.xyzWhy does FRI work?This blog post explains the security intuition behind the FRI protocol, which proves that a function is close to a valid Reed-Solomon codeword. It introduces the “prover message graph,” a layered stru... 051
Reposted by NicoZK Hack @zkhack.dev · 03/09/2025It’s time to reveal the ZK Whiteboard S3 Module 1... because it's LIVE! 🥁🥁🥁🥁 How to Build Hash Functions, with Jean-Philippe (JP) Aumasson @aumasson.jp & @nicomnbl.bsky.social Watch the full module here: zkhack.dev/whiteboard/s... 043
Reposted by NicoZK Hack @zkhack.dev · 10/07/2025The ZK Podcast released an episode on local-first software this week! @arro.bsky.social and @nicomnbl.bsky.social chat w @grjte.sh & @goblinoats.com about the foundations of local-first architecture, CRDTs and how ZK can be incorporated into these models. zeroknowledge.fm/podcast/367/zeroknowledge.fmLocal-First with grjte and Goblin Oats - ZK PODCASTIn this episode, Anna Rose and Nico Mohnblatt speak with Goblin Oats from Tonk and grjte from Bain Capital Crypto […] 0155
Nico @nmohnblatt.me · 23/06/2025Don't think this was the case for everyone but for me it was about keeping my phone number private (before Signal introduced usernames) 020
Nico @nmohnblatt.me · 23/06/2025I'm kind of conflicted over this. Up to now my Signal has been almost exclusively for personal use and Telegram exclusively for connecting at conferences. And I've come to value this clean separation To the point where I have said no to connecting over Signal 210
Reposted by Nicoweijie @kohweijie.com · 11/06/20252/ As such, I wrote a research note to help cryptography engineers fully understand both techniques: baincapitalcrypto.com/a-deep-dive-...baincapitalcrypto.comA Deep Dive into Logjumps: a Faster Modular Reduction AlgorithmLogjumps is a recently discovered technique for modular reduction over large prime fields. 131
Reposted by NicoChristian Knabenhans @cknabs.bsky.social · 20/05/2025I'm happy to finally open-source lattirust, a library for lattice-based zero-knowledge/succinct arguments! Lattirust is somewhat like arkworks, but for lattices; and like lattigo, but for arguments. ➔ github.com/lattirustgithub.comlattirustLattice zero-knowledge/succinct arguments, and more - lattirust 23216
Nico @nmohnblatt.me · 09/05/2025I wrote a thing on my colleagues Andrija and Guille's latest work 020
Nico @nmohnblatt.me · 03/03/2025Story of the ZK whiteboard series S2! The grant that supported it, how we came up with the topics, participation of our esteemed speakers, some crazy editing and how the bonus modules came to be 020
Nico @nmohnblatt.me · 28/02/2025But this might not work in your case depending on how strict you want to be on the caveat you mentioned 030
Nico @nmohnblatt.me · 28/02/2025The usual pattern is: 1. arrange the keys into a Merkle tree and give each signer their authentication path in that tree 2. signer produces a signature on the data 3. signer produces a ZKP that signature verifies against some public key, and that this public key is included in the Merkle tree 130
Nico @nmohnblatt.me · 26/02/2025Part 2 starts with important terminology (pre-quantum vs post-quantum vs quantum). Or then explains how to make Bitcoin and Ethereum post-quantum secure via signature lifting and then talks about using quantum computers to make digital money zeroknowledge.fm/podcast/297/ 2/2 000
Nico @nmohnblatt.me · 26/02/2025from the archive: Or Sattath came on the ZKPodcast to discuss quantum computing and its impact on cryptography. These two are some of my 𝐟𝐚𝐯𝐨𝐮𝐫𝐢𝐭𝐞 episodes of the show. Part 1 covers the computation model, why it breaks some cryptography and effects on mining zeroknowledge.fm/podcast/288/ 1/2 110
Nico @nmohnblatt.me · 25/02/2025A step towards fixing the recent attack on a Fiat-Shamir'd variant of GKR. Tl;dr: do proof-of-work before deriving the FS challenge, this will make the hash prohibitively expensive to compute in-circuit. Caveat: they only prove the security of their transform for 1-round protocols 001
Nico @nmohnblatt.me · 07/02/2025Bit of a tradeoff. We have O(1) proofs and verifiers using univariate polynomials, whereas sumcheck gives at best O(log(circuit)) 110
Nico @nmohnblatt.me · 06/02/2025It replaces the "quotient polynomial". This was the method used to succinctly check that all the Plonk contraints or AIR rows are satisfied. The advantage is that with sumcheck the prover no longer needs to perform polynomial division and therefore can run in linear time 100
Nico @nmohnblatt.me · 06/02/2025The original description has it as an IP (no oracles). And the messages are actually super short: for a MV polynomial with degree at most d in each variable, the prover only needs to send d field elements in each round 110
Reposted by NicoMatthew Green @matthewdgreen.bsky.social · 30/01/2025Look folks. I want BlueSky to succeed, because we need an alternative to X. I also know this is an insane time. But if we want to create a usable alternative, people are going to have to start posting occasionally about something else. 1917614
Nico @nmohnblatt.me · 29/01/2025These two lectures by @danboneh.bsky.social for @zkhack.bsky.social are the best explanation of IOPPs, FRI and its variants by a country mile. Cannot recommend them enough zkhack.dev/whiteboard/s... zkhack.dev/whiteboard/s... 0117
Nico @nmohnblatt.me · 27/01/2025programmable* cryptography * programming difficulty may vary, developer discretion is advised. 031
Reposted by Nicoweijie @kohweijie.com · 24/01/2025Want to send crypto to Bluesky users? It's possible! Their keypairs are for the secp256k1 curve, which Ethereum also uses. That means you can derive an ETH address from their publicly accessible signing keys. 5193
Reposted by NicoePrint Updates @eprint.ing.bot · 09/01/2025ZODA: Zero-Overhead Data Availability (Alex Evans, Nicolas Mohnblatt, Guillermo Angeris) ia.cr/2025/034 021
Nico @nmohnblatt.me · 05/12/2024I agree, blindly subscribing to a block list is giving a lot of power to the list's creator. But is it more dangerous than X? Over there, a single entity has the power to choose which accounts/keywords get boosted or ignored, without users ever knowing 010
Nico @nmohnblatt.me · 04/12/2024if someone tells you “succinct proofs are too short to leak information about the witness”, please send them this. The ZK property is not just a cool acronym. baincapitalcrypto.com/chosen-insta... This was also the theme of the "Zeitgeist" puzzle at ZK Hack 5! 074