1 comment

Sign in to comment.

ivan98 days ago
If the prover can already pick the program, why does moving the first Fiat-Shamir challenge to the generated statement stop the attack, is it just because the statement is no longer under the prover's control at that point?
zknews