You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@kobigurk has observed that the gnark verifier currently does not check a purported Groth16 proof to ensure that its points are actually in the correct elliptic curve subgroup (G1 or G2). It is known that these checks are necessary to thwart certain attacks on the protocol. See 2019/814 - Faster Subgroup Checks for BLS12-381 and references therein for state-of-the-art solutions to this issue.
The text was updated successfully, but these errors were encountered:
@kobigurk has observed that the
gnark
verifier currently does not check a purported Groth16 proof to ensure that its points are actually in the correct elliptic curve subgroup (G1
orG2
). It is known that these checks are necessary to thwart certain attacks on the protocol. See 2019/814 - Faster Subgroup Checks for BLS12-381 and references therein for state-of-the-art solutions to this issue.The text was updated successfully, but these errors were encountered: