mediumOracle manipulationOther
Brevis Pico ZKVM: Malicious verifier will recover private witness values breaking zero-knowledge property
- Payout
- $0
- Protocol
- Brevis Pico ZKVM
- Disclosed
- Sep 29, 2025
- Source
- sherlock
Brevis Pico, a privacy-preserving zkVM, relies on a fork of the gnark proving library (v0.1.0) that carries CVE-2024-45040: the Groth16 proving system emits Pedersen commitments without blinding factors. Because the BabyBear, KoalaBear, and verifier circuits i …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.