<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-06T08:35:11Z</updated>
  <generator>https://njump.me</generator>

  <title>Nostr notes by techleaks24</title>
  <author>
    <name>techleaks24</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://njump.me/npub1dnrfq2gva4hzxsj92quywygxp9sl2a5ezfnt034hagm3ap3j9dmq6ker2h.rss" />
  <link href="https://njump.me/npub1dnrfq2gva4hzxsj92quywygxp9sl2a5ezfnt034hagm3ap3j9dmq6ker2h" />
  <id>https://njump.me/npub1dnrfq2gva4hzxsj92quywygxp9sl2a5ezfnt034hagm3ap3j9dmq6ker2h</id>
  <icon>https://blossom.primal.net/42b2d0d1c31cfec92d70cfb660281810761d924370c7c963a379d5873f39747d.png</icon>
  <logo>https://blossom.primal.net/42b2d0d1c31cfec92d70cfb660281810761d924370c7c963a379d5873f39747d.png</logo>




  <entry>
    <id>https://njump.me/nevent1qqspyuz6gy6gzuzu74alun0js2995xznwp29dvtn6s0p3c3vck0mqygzypkvdypfpnkkug6zg4grs3c3qcykratknyfxdd7xkl4rw85xxg4hvqeeghc</id>
    
      <title type="html">Due to their complexity, no review is rigorous enough for SNARKs ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqspyuz6gy6gzuzu74alun0js2995xznwp29dvtn6s0p3c3vck0mqygzypkvdypfpnkkug6zg4grs3c3qcykratknyfxdd7xkl4rw85xxg4hvqeeghc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv2nnu2d0gfxjrd4k9fnqs2fmhqx0npxwhe3k4unsmqyzfhxyen0ghcda8w&#39;&gt;nevent1q…da8w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Due to their complexity, no review is rigorous enough for SNARKs and FCMPs. Think of it this way:&lt;br/&gt;&lt;br/&gt;1) Local witnessing phase: you show your wallet the actual outputs you&amp;#39;re spending and the public meta-address where you want to send the money. Your wallet&amp;#39;s local FCMP (or SNARK) circuit generates a proof, after checking everything, saying everything adds up. From the public meta address it generates the new outputs that will belong to the receiver.&lt;br/&gt;&lt;br/&gt;2) You broadcast this FCMP receipt generated by your wallet to the network with the new outputs: The other nodes verify the FCMP is valid and accept the outputs&lt;br/&gt;&lt;br/&gt;3) The trust problem: A proof generated this way, requires blind trust in the binary circuit which happens to have highly abstract math that compresses multiple proofs at once. As a node you&amp;#39;re not verifying the inputs of any transaction (like homomorphic math on Pedersen Commitments today). You&amp;#39;re blindly trusting the FCMP or SNARK receipt. &lt;br/&gt;&lt;br/&gt;The attack vector: these systems can be attacked by finding and exploiting weaknesses in the ZK proof (FCMP or SNARK). With Zcash it happened already twice: once in 2018 with Ariel Gabizon, and another time in July 2025 with ZkSecurity. &lt;br/&gt;&lt;br/&gt;The optional privacy solution: By concentrating liquidity on the transparent UTXOs, you create an audit of last resort in the exiting stage of any inflation exploit that went undetected due to the highly complex math involved. &lt;br/&gt;&lt;br/&gt;This is not a &amp;#34;scare&amp;#34;, it&amp;#39;s a reality, the risk profile changes completely and make no mistake, MRL devs are well aware of it but they&amp;#39;re counting on most people having no clue where the new trust bottlenecks and privacy vulnerabilities are. &lt;br/&gt;&lt;br/&gt;The reason why Monero is taking this immense risk is because people have caught up with the fact that there is no privacy in RingCT because it&amp;#39;s extremely easy to filter out decoys. They&amp;#39;re trying to flip to another model that sounds good due to complexity but in reality would be the same, or much weaker. Because trading off verifiability for &amp;#34;better privacy&amp;#34; also requires concentrating liquidity on a transparent pool. This transparent pool in Monero will be built by compiling a database of all outputs whose full view keys (that will be introduced by CARROT, which is bundled together with FCMP) have been leaked. &lt;br/&gt;&lt;br/&gt;These could be simply exchange addresses, but also open source wallets with non reproducible code that have a line hidden somewhere that leaks the public view keys of its users&amp;#39; outputs.
    </content>
    <updated>2026-04-26T05:30:49Z</updated>
  </entry>

</feed>