Shows Fiat-Shamir can certify false R1CS when the instance generator is too expressive, then patches it with a better first challenge.
1 comment
If the prover can already pick the program, why does moving the first Fiat-Shamir challenge to the generated statement stop the attack, is it just because the statement is no longer under the prover's control at that point?