Paper 2025/1291
A note on the security of the BitVM3 garbling scheme
Abstract
We provide minimal counterexamples for the security of the BitVM3 garbling scheme: our attack allows the evaluator to forge input and output wires. Then we use the same idea to exhibit an attack on the forward label propagation garbling scheme proposed in a more recent paper. In both cases, the authenticity property of the garbling scheme is broken.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- authenticityBitVM3garbling schemeRSA
- Contact author(s)
-
futo @ fairgate io
glaroton @ dm uba ar
fadi barbara @ fairgate io - History
- 2025-07-18: revised
- 2025-07-15: received
- See all versions
- Short URL
- https://ia.cr/2025/1291
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1291,
author = {Ariel Futoransky and Gabriel Larotonda and Fadi Barbara},
title = {A note on the security of the {BitVM3} garbling scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1291},
year = {2025},
url = {https://eprint.iacr.org/2025/1291}
}