Attacks on signature and code-based schemes share space with the usual zk/FHE roundup, because apparently chaos is a feature.
1 comment
Does turning multilinear KZG openings into univariate identity and degree checks mostly just shrink verifier work, or does the prover still pay for that somewhere else?