Coratger et al. conducted the first rigorous security analysis of the Plonky3 Merkle tree in their paper, proving its position-binding and extractability, ensuring security for ~$4B in assets despite compression function flaws. Coratger等人在论文中首次对Plonky3 Merkle树进行了严格的安全分析,证明了其位置绑定和可提取性,尽管其压缩函数存在安全缺陷,但通过预哈希等对策仍能保障约40亿美元资产的安全。
Notes
Widely used Plonky3 Merkle tree secures ~$4B in assets
Its underlying 2-to-1 compression function lacks collision-resistance and one-wayness, potentially undermining security
Common countermeasure is pre-hashing data before use as leaves
First rigorous security analysis of this Merkle tree design, showing Plonky3 approach is sound
Demonstrates (strong) position-binding and extractability
Enhances confidence in Plonky3 for SNARKs and vector commitments applications