Nico
@nico_mnbl
Followers
2K
Following
4K
Media
59
Statuses
741
Researching and cryptographing. Recurring co-host on @zeroknowledgefm.🪱ing at @HMLTD. ♟ 1. b3.
London, England
Joined April 2020
The ZK Jargon Decoder has moved! . It is now hosted at and finally has an appropriate license. Few more content updates below and many planned to come soon. All in time for 𝐙𝐊 𝐇𝐚𝐜𝐤 𝐌𝐨𝐧𝐭𝐫𝐞́𝐚𝐥! @__zkhack__
3
16
63
Made it to @zeroknowledgefm! Had so much fun recording this with @AnnaRRose and @GuilleAngeris. We covered *a lot*, some technical, some personal, some very general stuff and even some French. Listen at your own risk.
9
12
77
Our team has a new home, and what a home it is!.
Couldn't be more excited to welcome @kobigurk, @AndrijaNovakov6, @weijie_eth, @nico_mnbl, and @grjte to the @BainCapCrypto team.
4
3
66
soundness vs knowledge soundness? proof or argument? We covered a lot of those questions in the @__zkhack__ jargon decoding session yesterday. Drew this chart of security properties and placed some of the commons acronyms on it
0
10
60
Privacy-preserving contact discovery!. This also unlocks the possibility to build Signal without relying on phone numbers for the social graph. Could use email, twitter handles or any other identifiers.
New research: introducing Arke, a privacy-preserving contact discovery scheme by @nico_mnbl, @alberto_sonnino (@Mysten_Labs), @kobigurk and @Daeinar (@uclisec). Problem statement and an overview of their solution in the thread below.🧵⬇️
1
8
49
The true cryptographic meaning of "zero knowledge", explained in an accessible manner 🙌. This one was very dear to my heart, thanks @__zkhack__ for producing this content and @cryptodavidw for taking on the topic!.
𝐙𝐊 𝐖𝐡𝐢𝐭𝐞𝐛𝐨𝐚𝐫𝐝 𝐒𝐞𝐬𝐬𝐢𝐨𝐧𝐬 𝐒𝐞𝐚𝐬𝐨𝐧 𝟐….It starts today 😎. Module 1: What is Zero-Knowledge (like, actually)? w/ @cryptodavidw and host @nico_mnbl is OUT NOW!.
1
7
49
Sharing what's been cooking in the @__geometry__ kitchens!. Bringing Nova's folding scheme into the world of PLONK. Still plenty of work to do around this, optimisation, implementation and lookups are high on the priorities list!.
New research: Sangria, a folding scheme for PLONK by @nico_mnbl. Folding schemes were first introduced in Nova and were used to build a recursive SNARK with the lowest known recursion overhead. We apply similar ideas to the PLONK arithmetization. 1/8.
1
0
47
are applications private if proofs are not zk?. I wrote a post on the topic and introduce the notion of 𝐜𝐡𝐨𝐬𝐞𝐧-𝐢𝐧𝐬𝐭𝐚𝐧𝐜𝐞 𝐚𝐭𝐭𝐚𝐜𝐤𝐬. This secret-stealing attack was successfully performed by @__zkhack__ participants in puzzle V-1 !. tl;dr and links below.
2
13
46
world's biggest circle stark.
2¹³⁶²⁷⁹⁸⁴¹−1, discovered today, is the largest known prime. It's a Mersenne prime (2ᵖ-1), which are easier to find. It took nearly 6 years for the GIMPS software to find it after the previous largest known prime. It was also the first Mersenne prime found using GPUs.
1
0
41
Highly recommend this talk for anyone who wants to learn about folding schemes in general, and HyperNova specifically !. Big thanks to @srinathtv for the shoutouts 🙏🙏.
0
2
39
We are taking the concept of the jargon decoder and going LIVE for Session 1 of ZK Hack IV!. @AnnaRRose @kobigurk and I will be answering your live questions, explaining ZK jargon in simple terms without cutting (too many) corners. Come with requests or drop them here!
The first session is 𝐙𝐊 𝐉𝐚𝐫𝐠𝐨𝐧 𝐃𝐞𝐜𝐨𝐝𝐞𝐫. It will be given by @nico_mnbl & @kobigurk from @__geometry__ & our very own @AnnaRRose on Jan 16th. Sign up here >>>.
4
7
37
Results are in, this was a very tricky one! Correct answer is actually "agrees with" 👀. The screenshot below is from the original FRI paper While FRI is indeed an IOP of Proximity, the notion of "proximity" only comes up in the soundness guarantees (1/3)
ZK quiz, this time for the FRI-heads! FRI stands for (F)ast (R)eed-Solomon (I)nteractive Oracle Proof of Proximity. Fill in the blank:.The completeness property states that the verifier always accepts if the witness is a vector that _____ an RS codeword.
1
4
36
Massive thank yous and even bigger congratulations to @AnnaRRose @Agni_deneve and the whole team at @zeroknowledgefm and @__zkhack__ for putting on a incredible week of events! Had a blast and was an honour to be invited to speak . #TheHack #zkSummit9.
2
4
35
Btw it's not called Sangria because I have a drinking problem. It's called Sangria because it is "relaxed plonk" and I have a punning problem.
While Nova was designed for R1CS circuits, Sangria unlocks the same potential for PLONK arithmetizations. In the same way that Nova introduced “relaxed R1CS”, the main ingredient in Sangria is “relaxed PLONK”. 8/8
1
2
34
@hdevalence There's a really cool paper that uses this to mount a deanonymization attack on Tor .
1
0
33
Had so much fun getting to curate the curriculum and participate in this video series. Particularly happy that we covered the meaning of ZK and SNARKs built using proximity tests. Huge thanks to the team @zkGaylord @qosmonot @AnnaRRose and Henrik (hope I'm not missing anyone!).
ZK Whiteboard Sessions Season 2 – that's a wrap!. As we released the 8th & last module, let's thank the amazing guests & hosts from the series: @cryptodavidw @SuccinctJT @rel_zeta_tech @pumatheuma @jimpo_potamus @0xAlbertG @nico_mnbl @devloper_xyz & guest star @danboneh. 🙏🙏🙏
1
6
31
Thanks @SunscreenTech for speaking up publicly! Hope that this resolves peacefully and that the space can move towards openness and healthy competition.
If @zama_fhe and @randhindi believe in their work, we invite them to compete with @sunscreentech in a way that moves the industry forward rather than engage in secret campaigns of intimidation, IP trolling, and speech suppression. Thread 🧵👇. On December 3, following a 6+ month.
1
1
29
Proving a SNARK in browser is still slow. Can browsers also benefit from GPU speedups?. Lots of uncharted waters to explore here!. h/t @weijie_eth.
Accelerating Client-Side ZK with WebGPU by @weijie_eth. Thread below 🧵.
0
0
25
Spicy puzzles coming your way, excited to see people's reactions!.
ZK Hack V starts next week!. @AndrijaNovakov6, @nico_mnbl and I have been brewing a few puzzles that would challenge what you know about the security of widely used systems today🤭. Stay tuned 🫡.
0
3
25
Huuuge resource for learning about linear-time provers based on the Sumcheck protocol. Highly recommend you download and run the associated Sage notebook as you read through.
Today I’m happy to share two articles I've been working on for the past few weeks!.1. SuperSpartan by Hand: 2. HyperNova by Hand: It’s been fun writing them and delving into such detail has proven to be incredibly insightful for me.
0
4
25
Updated this recently!.* new look: moved to mdbook.* new entries: Oracle, PLONKish and completed many of the empty entries such as Nullifier, Polynomial Commitment Scheme, Threshold Encryption .* improved some existing entries like R1CS.
Started writing a collection of informal definitions for common ZK jargon. Hoping this can help newcomers and experts alike.
2
3
24
Very excited to be giving a talk at Encode London @encodeclub on Friday 25/10. They have an amazing event scheduled and great speaker line-up. Hope to see you there!. Registration link below
1
2
24
Come study Season 2 of the whiteboard sessions with us 📚📚.
📚 It's always better to learn with friends! 📚 . We are kicking off a new cohort of the ZK Whiteboard Study Group this Thursday at 4PM UTC, this time about the modules from Season 2!. In this Kick-off Session, we'll present the schedule and the details about the cohort. Join
0
5
23
Arke has been updated! We:.* detail how users can verify that they received correct key shares.* credit previous work that we initially missed.* expand the discussion on the benefits of only needing a key-expressible DKG (rather than a DKG with secrecy).
New research: introducing Arke, a privacy-preserving contact discovery scheme by @nico_mnbl, @alberto_sonnino (@Mysten_Labs), @kobigurk and @Daeinar (@uclisec). Problem statement and an overview of their solution in the thread below.🧵⬇️
0
1
20
So it begins. First post from the newly-merged team!.
New post with @GuilleAngeris and @nico_mnbl on DA. Leveraging the interaction inherent to DAS can make FRI-based DAS protocols more efficient.
0
4
18
this blogpost comes with an important personal update
Speedrunning ProtoStar by @benediktbuenz and @Charles_Chen533. @nico_mnbl covers the main results of the paper and summarises the important definitions. Expect to learn about folding, special-soundness, cross-terms, and how to optimise them away!. 🧵⬇️.
3
0
18
Faster verification of pairings *inside* arithmetic circuits. @AndrijaNovakov6 is a beast.
What if… verifying the execution of pairings inside SNARKs can be done much faster than already known?. @AndrijaNovakov6 and @LiamEagen have just published a paper on this!. Let’s explore this below 🧵. 1/13
0
1
16
@norswap I think what we're more interested in are cyclic groups of prime order in which the discrete log problem is hard:.discrete log -> hide values but still operate "in the exponent".cyclic -> maintain uniform distribution .prime order -> can't be broke into smaller group.
2
0
15
Want to learn what all the hype about small fields is about?.
𝗭𝗞 𝗪𝗵𝗶𝘁𝗲𝗯𝗼𝗮𝗿𝗱 𝗦𝗲𝘀𝘀𝗶𝗼𝗻𝘀 𝗠𝗼𝗱𝘂𝗹𝗲 𝟱 is coming out in 24 hours!. For Module 5, @nico_mnbl and @jimpo_potamus will explore the performance efficiencies of going smaller in:.𝗦𝗺𝗮𝗹𝗹 𝗙𝗶𝗲𝗹𝗱𝘀 / 𝗕𝗶𝗻𝗮𝗿𝘆 𝗙𝗶𝗲𝗹𝗱𝘀. #ZKWhiteboardSessions
0
1
15
Catch the replay of my ZK Summit talk. Apps can be both private and social, without requiring users to rebuild their network from scratch. Cool cryptography too!.
ZK Summit 11 was a blast! Watch @nico_mnbl present Arke (joint work with @alberto_sonnino @Daeinar @kobigurk) a privacy-preserving contact discovery scheme, and much beyond! This talk also serves as a gentle introduction to identity-based cryptography.
0
1
15
Caught up with @RiscZero one year after their first appearance on @zeroknowledgefm.
🎙️ In this week’s episode, dive into #RISCZero with hosts @annarrose & @nico_mnbl as they chat with @BrianRetford & @BruestleJeremy. They explore updates on the @RISCZero project from Bonsai to the Type Zero zkEVM, Zeth & more. Check it out here
0
0
15
The Jargon Decoder goes to ZK podcast! We cover some of the jargon that I was (and still am) stumped on when I first started. And we do sometimes venture into more technical territory, hopefully there are useful insights for all.
📽️In this week’s special video episode, @AnnaRRose and @nico_mnbl from @__geometrydev__ bring you the ZK Jargon Decoder episode. In it, they define the terms and concepts commonly used in by the ZK community. You can watch it here 🎯
1
1
12
Always keep your zk clean.
Last week, @AnnaRRose caught up with @GuilleAngeris and @nico_mnbl. recorded between @__zkhack__ & #zkSummit9, they chat about their latest research, Sangria & folding schemes, janitorial zk work, being very very tired and more! .
1
1
14
Come hang out and enjoy the views of London. (picture is not contractual, real views may differ).
>> 𝗜𝗖𝗬𝗠𝗜 <<. 🎯 London.🗓️ March 6th.🕡 6:30 PM.📢 ZK Meetup.🫂 @__zkhack__ 🤝 @zkv_xyz . 👇 Registration link below
3
2
13
Semacaulk recipe (serves millions, super cheap gas):.- 1 Semaphore protocol.- 1 efficient lookup argument (Caulk+).- a healthy dose of @weijie_eth & @AndrijaNovakov6 elbow grease.
Tired of paying a million gas just to update a Merkle tree? What if we told you that ZK apps don’t have to be so expensive? 🧵⬇️. @weijie_eth, @AndrijaNovakov6 and @kobigurk present Semacaulk!.
0
0
14
@gakonst Super basic (and not reviewed) implementation with KZG and IPA PC hard-corded. Example at the bottom of the lib file. We can extend this to abstract away from hard-coded commitment schemes and support any number of them, feel free to contribute!.
0
1
14
Another @__zkhack__ IRL wrapped! Congrats to all the participants for their awesome submissions, and as always congrats and thank you to the team for putting together an incredible event!.
0
1
13
@julesdesmit You might like the @__zkhack__ reading groups! They have one going over Justin Thaler's book, and one covering the Moon Math Manual. Both in the zkhack discord.
2
0
13
Results are in! I was trying to gage what people mean by "STARK". The original academic definition is scalable, transparent argument of knowledge. This means succinct + quasilinear prover + knowledge soundness + no trusted setup. This means that elliptic curve protocols . 1/3.
quick zk-jargon experimental poll, answer the two-part question: .Familiarity with ZK (1 = beginner, 10 = expert) || Nova is a STARK, true or false?. Please circulate and stay tuned for results!.
3
1
12
big episode!. Highly recommend you go through the book, or at least skim over the preface and first few chapters. Helped me *a lot* to clarify my thinking and understanding.
🎙️This week @annarrose and @nico_mnbl catch up with Alessandro Chiesa and Eylon Yogev to discuss their recent publication Building Cryptographic Proofs from Hash Functions . listen in full here 👇.
0
4
12
In Lisbon until the 5th for #zkhacklisbon and #zksummit DM if you want to meet up!. Or even better message me on Converse
2
0
11
Been raving about this paper for a while now, finally got round to writing an article that explains it.
Introducing the Paper Speedrun series: a collection of blog posts in which we summarise the key results of recent papers without cutting any corners. First up @nico_mnbl takes on zk-creds, a novel approach to anonymous credentials 🧵⬇️. 1/5.
0
2
11
@rel_zeta_tech @benediktbuenz Also imo one of the novel insights of Nova is that this "relaxed" form of the arithmetization is a very efficient accumulator. As opposed to using claims about polynomial commitments (halo) or claims about commitments to hadamard products (BCLMS's PCD scheme for R1CS).
1
1
11
Deep dive and Q&A on Sangria on April 19th, details in the quoted thread!. Big thanks to @CPerezz19 and @PrivacyScaling for inviting me to speak 🙏.
At @PrivacyScaling we're organizing a new 📜-learn-and-share session. This time on Sangria! The new folding Scheme for PLONK!!. I'm so grateful to @nico_mnbl and @__geometry__ for this!.
1
1
10
Stacked roster.
🇫🇷 ZK Paris 🇫🇷. Geometry is excited to announce ZK Paris, a co-hosted event with @ZKValidator on the 20th July in Paris, during EthCC. ZK Paris brings together the leaders and builders in the zero knowledge community and we are proud to announce our sponsors below!.
0
1
8