Andraž Strgar
Andraž is an auditor and security researcher at OtterSec, focusing on securing cryptographic implementations of blockchain projects. He is also an active CTF player for DragonSec SI, 0rganizers and ICC Team Europe.
Session
A Zero Knowledge Virtual Machine verifier should be faithful to one thing above all else: its public claims. That is, the proof of a statement should depend on the statement itself. As it turns out, this is not always the case, which can lead to disastrous consequences. In this talk, we will take a journey through six systems where we discovered critical vulnerabilities caused by such issues. Learn how a subtle ordering bug or a tiny omission can let an attacker bypass the cryptography entirely and prove mathematically impossible statements.