Margulus

839 posts

Margulus banner
Margulus

Margulus

@MariusMargulus

Researching hardware acceleration for zero knowledge proofs. https://t.co/pgLQxb4qQN CS @LehighU Engineering @TachyonZcash @penumbrazone

Katılım Kasım 2021
1.4K Takip Edilen774 Takipçiler
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
Ironwood goes live in ten days. The possibility of counterfeiting bugs in our project has kept me awake at night. No more. Mathematical proof that undetectable counterfeiting bugs don't exist in Ironwood changes how even *I* feel about Zcash, as a protocol dev of ~10 years.
Zakura@ZakuraZcash

Ironwood goes live in 10 days. The Great Ironwood Migration achieves three goals: - Provide a credibly sound shielded pool - Give evidence no counterfeiting occurred in Orchard - Re-establish the circulating supply of ZEC. Here's what you need to know... 🧵

English
31
70
445
261.4K
Margulus retweetledi
Zakura
Zakura@ZakuraZcash·
Ironwood goes live in 10 days. The Great Ironwood Migration achieves three goals: - Provide a credibly sound shielded pool - Give evidence no counterfeiting occurred in Orchard - Re-establish the circulating supply of ZEC. Here's what you need to know... 🧵
Zakura tweet media
English
13
32
164
131.3K
Margulus retweetledi
Zakura
Zakura@ZakuraZcash·
Announcing Zakura: a new Zcash node built for scale.
English
51
77
408
303.8K
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
Zcash's Ironwood mainnet activation height has been set and tagged! All of the major organizations are committed to activation of NU6.3 at height 3428143, which is approximately July 28th at 8AM EST.
English
55
125
587
168.9K
Margulus retweetledi
Arjun Khemani
Arjun Khemani@arjunkhemani·
A comparison of Bitcoin and Zcash on counterfeit detection. The greatest risk in private money is hidden inflation. Ironwood rules out specification bugs and puts Zcash essentially on par with Bitcoin in supply verifiability. A historic feat for private money.
Arjun Khemani tweet media
Project Tachyon@TachyonZcash

Zcash's new Ironwood pool is being formally verified to rule out all undetectable counterfeiting bugs, up to the underlying cryptographic assumptions. tachyon.z.cash/blog/detecting…

English
14
33
210
13.3K
Margulus retweetledi
zooko🛡🦓🦓🦓 ⓩ
Tachyon's Formal Verification project is on the verge of producing a mathematical proof that there are no undetectable counterfeiting bugs in the latest Zcash shielded pools.
English
5
52
311
24.8K
Margulus retweetledi
Project Tachyon
Project Tachyon@TachyonZcash·
Zcash's new Ironwood pool is being formally verified to rule out all undetectable counterfeiting bugs, up to the underlying cryptographic assumptions. tachyon.z.cash/blog/detecting…
English
64
145
632
457.1K
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
UPDATE: Over the last couple weeks we've made huge progress on Ironwood activation in Zcash! 1. All of the consensus rule changes have been implemented, and have been undergoing auditing for some time now. Specifications / ZIPs are published and nearing their final state. 2. Stay tuned for a mainnet activation height. We should absolutely be ready for a ~July 21 activation. 3. Official testnet activation scheduled for tomorrow. Zebra release with support should be out ~today! Ironwood's prompt and safe activation on Zcash mainnet is extremely important to our users, in addition to the formal verification work we're doing in parallel to provide reassurance that there aren't any supply integrity concerns. More details on this forthcoming! Sufficient hashrate is signalling technical readiness for the mainnet upgrade; the outstanding concern is that some wallets will not be prepared for the upgrade in time. This does not justify delaying Ironwood, given there will be adequate alternatives and sufficient time on testnet for anyone who needs it. We've been working really hard on every front to make this happen, particularly the folks at @ValarGroup and @zodl_co, and we're very thankful for the countless engineers and ecosystem partners that have been assisting.
Dev 🌸@zkDragon

Zcash testnet is updating for Ironwood tomorrow! We have two independently developed consensus implementations of it. One by @valargroup, and another by @ZcashFoundation. @valargroup's is in audit as well. We have a desktop wallet fork with migration code you can try! If you have a Keystone dev device, you can even update your firmware to try it out on the testnet! Sign 11+ txs with one QR code. This is a record for Zcash testnet readiness to my knowledge!

English
18
87
344
44.4K
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
Quick update on the last ~48 hours of Zcash Ironwood! 1. Protocol devs from across all the orgs met twice to discuss specification and implementation progress. Agreement on a couple additional changes: disabling Orchard pool bundles in coinbases, anchors as auth data for migration UX with hardware wallets, and the order that ZIPs and specs will be handled. 2. Ironwood circuit and ZIP 2005 integration drafts are going through the review process. @ValarGroup has already spun up testnets and his team has done a wonderful job scoping out and implementing some of the wallet-facing changes. We are beginning an Ironwood upgrade book for eventual consumption by auditors, wallets, protocol developers, etc.. 3. Formal verification work on Ironwood continues. A collection of different individuals who either have or will continue to work on formalization efforts will be meeting tomorrow where we'll settle on the specific strategy for getting the Ironwood SNARK formally verified. I'm hosting this and will post minutes and details after. Efforts from teams will be ideally combined where useful, existing approaches and progress unified and we'll figure out the easiest path for the next couple weeks. I've paused my own work on this to do Ironwood circuit stuff, but I'll be resuming on that tomorrow. These are the big pieces, there are also some major security auditing tasks taking place in the background -- at least three major firms are auditing Orchard currently, and multiple new AI auditing suites are hammering the codebases to ensure nothing else critical is sitting around anywhere. So far so good! Really proud of how much progress is being made every hour on this by all five of our major teams/orgs and our supporters inside and outside the community. Also love the general wartime vibe shift. Let's go!
Sean Bowe@ebfull

UPDATE: The various orgs and protocol developers mentioned have agreed on the specific consensus rule changes for Ironwood, after settling the finer details. Here's a summary: 1. Ironwood introduces a new pool using the Orchard protocol, just like the existing pool. 2. The circuit for the Orchard protocol—which applies to both the existing Orchard pool and the new Ironwood pool—will have a flag that consensus rules can toggle. This flag disables payments to *other* users within that pool, while maintaining the ability to create change notes. (This enables a privacy safeguard.) 3. The old Orchard pool will have this flag enabled after the network upgrade, and payments to the old pool will also be disabled by constraining valueBalance. 4. Because payments are disabled on the old pool, wallets must send new payments to Orchard receivers (inside existing unified addresses) via the new pool, and they should also migrate funds away from the old pool. This combination enforces a bound on the circulating supply of ZEC through the use of the existing turnstile mechanism; the amount of ZEC that anyone can transact with is no more than the amount that is supposed to exist. Meanwhile, users' wallets can migrate funds to protect them from risk, which also gradually provides evidence that counterfeiting never took place. Now that we have this decided, we'll collectively move on to the implementations, specifications, and ecosystem support/outreach. (We also have many different auditing and formal verification efforts taking place behind the scenes to provide assurance about the circuit correctness. More on that soon!)

English
21
73
404
127.9K
Car Battery LB
Car Battery LB@Battery__LB·
The guy who found the Zec exploit; • Senior Security Engineer at the Elecrtric Coin Company • Board member of the Zcash Foundation • found similar exploit on Feb 23, 2026 why not found the exploit earlier 🤔
Car Battery LB tweet mediaCar Battery LB tweet media
English
13
12
89
10.2K
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
Really excited to audit the Orchard pool's supply with a very elegant and wonderful approach @ShieldedLabs suggested. More about that later today. But it's funny that the whole time we're fixing it I'm going be paying bills etc. with my Orchard funds! I love it. 😆
English
25
69
371
31.3K
Margulus retweetledi
Sean Bowe
Sean Bowe@ebfull·
Shielded protocols give you privacy in exchange for placing supply integrity in the faith of cryptographic assumptions. This is true for all of these protocols, every one of them, without exception. There is no cheap trick that lets you get around this, like another technique that verifies what's "really happening" inside the pool. You will always find yourself just repeating what the SNARKs are already doing, using (possibly different) cryptographic assumptions. The only thing we can do is rely on safe assumptions, and make our code flawless. Prior to a few years ago neither of these were practical, but we're beyond this. We can formally verify our shielded protocols and their implementations so that their correctness mathematically reduces to these cryptographic assumptions. We may soon even do this with the current version of Orchard itself (there are at least three different teams competing to implement a fully verified proof of Orchard's circuit right now, for example). These proofs don't have to be checked by humans in their entirety, just the small theorems that describe the security notions and specifications. Perfect shielded pools.
English
32
73
442
123.7K