Trusted setup & audits

Two pillars underpin Murk's safety: a proper trusted-setup ceremony for the zero-knowledge circuits, and independent security review.

Trusted setup

Groth16 proofs require a one-time trusted setup for each circuit. The setup produces the proving and verifying keys — and, as a byproduct, secret "toxic waste" that must be destroyed. If anyone kept it, they could forge proofs and mint value the pool doesn't back.

Murk uses a multi-party ceremony (Phase 2 MPC): many independent participants each contribute randomness, and the setup stays secure as long as at least one of them discarded their secret. The verifying keys the ceremony produces are exactly what the on-chain program enforces, and the ceremony transcript is published so anyone can independently check the contributions.

Audits

The circuits, the on-chain program, the proof/blob binding, and the swap flow are reviewed by an independent security auditor. Internally, the protocol has been through repeated fund-loss and soundness reviews and a large adversarial test suite — double-spend, over-draw, fee-floor, emergency-pause, malformed-proof, and swap-reclaim attack tests all pass.

What's hardened

  • On-chain proof verification rejects non-canonical inputs (no verifier shortcuts).
  • Value conservation, double-spend prevention, and mint-confusion defenses are enforced in-circuit and on-chain.
  • A specific swap over-refund drain and an unbounded-fee confiscation vector were found and fixed, with regression tests.
  • Spend and viewing keys are cryptographically separated (view-only compliance without spend power).
  • The program's upgrade authority is held by a Squads multisig.

results matching ""

    No results matching ""