Algorand subset-sum hash is not collision-resistant. Details in our blog post
Dmitry Khovratovich
377 posts
Researcher at Ethereum Foundation
Founder of ABDK Consulting
Luxembourg
Joined May 2012
- This is Ethereum Foundation (joint work with TU/e) first attempt to design hash-based signatures tailored to SNARK aggregation! We seek new implementations, and we would love to collaborate with Explore Expander bootcamp participants. Come build with us. eprint.iacr.org/2025/055.pdf
- The deadline for Short Term #Poseidon Grants has been extended to 15th March 2025 poseidon-initiative.info/#h.igyegrb8v5vn All researchers from the academia #iacr and the industry are welcome to apply!
- Ethereum Foundation boosts the third-party cryptanalysis of Poseidon hash. It provides bounties for breaking small versions, awards for new attacks, and short-term grants to fill the gaps the existing analysis. Total Fund: $500 000 poseidon-initiative.info #Ethereum
- New RSA assumptions are needed for VDFs. Ethereum Foundation supports analysis of them with a number of bounties. rsa.cash
- WARNING! Account Khovr_ (with underscore) is impersonating me. Don't get tricked, i know there were PMs.
- Why all the IACR "paper submission" websites are all on the same domain, but the login/passwords can't be reused? This creates a total mess all the time. Who designed that? Why not using 3d/4th level domain name for every new conference? #iacr
- Log N faster Verifier, twice bigger proofs, same Prover. Please find errors in "Time-Communication Tradeoffs for Bulletproofs"
- Fastest hash functions for Snark/Stark/Bulletproofs[New] Starkad and Poseidon: New Hash Functions for Zero Knowledge Proof Systems (Lorenzo Grassi and Daniel Kales and Dmitry Khovratovich and Arnab Roy and Christian Rechberger and Markus Schofnegger) ia.cr/2019/458
- Cryptanalysis of STARK-friendly primitives Jarvis and Friday. drive.google.com/open?id=16NOFi… . Preimage attack of 2^83, key recovery in 2^100 and other.
- Some comment on eprint.iacr.org/2023/537 1) All instances of Poseidon used in practice are still secure and have the same security margin. 2) See item 1.
- Unprecedented cryptanalysis bounties on recent algebraic designs!$172k in new bounties for breaking ZK-friendly hash functions! Rescue Prime, Feistel-MiMC, Poseidon and Reinforced concrete: zkhashbounties.info Happy #Cryptanalysis!






