Paper 2026/1901

Nothing Up My Matrix: Kleptographic Backdoors in ZK-friendly Hash Functions

Hyunsik Jeong, Zellic
Malte Sander Leip, Zellic
Mincheol Son, Zellic, Korea Advanced Institute of Science and Technology
Abstract

ZK-friendly hash functions are often built from algebraic SPN permutations. The matrix provides diffusion by mixing the state elements after the S-box layer. However, there is no uniform convention for selecting matrices for the linear layer across primitives. Matrix selection may follow a transparent nothing-up-my-sleeve procedure or prioritize implementation efficiency. Some specifications instead treat any MDS matrix as admissible. This parameter-selection freedom also persists in practice, as some deployed implementations replace the concrete matrix proposed in the original specification with an alternative instantiation. We show that adversarial use of this freedom can create a kleptographic attack surface. In this paper, we study kleptographic backdoors embedded in the matrices of ZK-friendly hash functions. Assuming that a malicious designer controls matrix selection, the designer can choose a matrix that maps a chosen input to a chosen output under appropriate round and parameter conditions. The resulting matrix is MDS and passes the additional matrix security checks required by the target primitive. Three case studies show that such a backdoor could have critical security consequences in real-world deployments. In Plonky3, it would allow a prover to control a Fiat--Shamir challenge and make the verifier accept an invalid claim. In Neptune Cash, it would permit creating a digest collision between the program that checks whether a transaction is valid and one that omits this check, enabling counterfeit currency. Finally, in Plonky2, it would enable a forged Merkle-tree membership proof for an attacker-chosen element. Our results show that satisfying the MDS condition and other security requirements is insufficient to establish that a matrix is trustworthy. Its generation process must also be transparent and verifiable.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
KleptographyZK-Friendly Hash FunctionsSPN PermutationsAlgebraic Cryptanalysis
Contact author(s)
hyunsik @ zellic io
malte @ zellic io
mincheol @ zellic io
History
2026-09-10: approved
2026-09-06: received
See all versions
Short URL
https://ia.cr/2026/1901
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1901,
      author = {Hyunsik Jeong and Malte Sander Leip and Mincheol Son},
      title = {Nothing Up My Matrix: Kleptographic Backdoors in {ZK}-friendly Hash Functions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1901},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1901}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.