Sabanaku77 Profile Banner
Lvl2 Pekka Profile
Lvl2 Pekka

@Sabanaku77

Followers
284
Following
1K
Media
10
Statuses
96

Web3 Researcher | ZK | Senior Threat Researcher @zscaler

Joined September 2012
Don't wanna be here? Send us removal request.
@Sabanaku77
Lvl2 Pekka
5 months
Secured 2nd place in @stabilitydao competition on @cantinaxyz with 1H and 2M(1M solo). More miles to go, more lessons to learn. 🙌✨
10
1
118
@Sabanaku77
Lvl2 Pekka
1 month
Thanks @cantinaxyz and @monad. I am Cooked for real
0
0
1
@Sabanaku77
Lvl2 Pekka
2 months
Since the whiteboard session was very informative and technical, here are my notes for the same
Tweet card summary image
github.com
Contribute to prajjwal001/zk_stuffs development by creating an account on GitHub.
0
0
4
@Sabanaku77
Lvl2 Pekka
2 months
I have spent the last week delving into zkVMs, examining how zero-knowledge proofs can verify general computations, the RISC-V architecture underlying them, and how @SuccinctLabs' SP1 brings it all together for on-chain, verifiable execution. If you want to explore too, here’s
2
0
16
@Sabanaku77
Lvl2 Pekka
2 months
9/9 > Takeaway: SNARKs are mathematically elegant but practically fragile. Robust zk-systems need: - safer languages - stronger tooling - end-to-end audits - defense-in-depth at all layers.
0
0
0
@Sabanaku77
Lvl2 Pekka
2 months
8/9 > Insights: - Low-level DSLs (Circom, Gnark) = bug-prone like early C. - Exploits may remain invisible (e.g., infinite coin printing in shielded pools). - Multi-provers + better DSLs + formal verification = urgent next steps.
1
0
1
@Sabanaku77
Lvl2 Pekka
2 months
7/9 > Defenses: Tools exist (Circomspect, Picus, Korrect, SNARKProbe). But → DSL-specific, circuit-focused, poor coverage. Integration layer defenses = basically absent.
1
0
1
@Sabanaku77
Lvl2 Pekka
2 months
6/9 > Integration bugs: unchecked nullifiers, flawed proof delegation, poor design → privacy and DoS risks. Circuits alone aren’t enough.
1
0
0
@Sabanaku77
Lvl2 Pekka
2 months
5/9 > Notable bugs: - Tornado Cash MiMC under-constrained → potential pool drain - Scroll zkEVM ltChip → missing range checks - Plonk “Frozen Heart” FS bug → proof forgery
1
0
0
@Sabanaku77
Lvl2 Pekka
2 months
4/9 > Impacts: - 124 soundness breaks - 14 completeness failures - 3 zero-knowledge leaks So yes, SNARKs can fail across all core properties.
1
0
0
@Sabanaku77
Lvl2 Pekka
2 months
3/9 > Most common flaw: under-constrained circuits (95 cases). Missing or weak constraints → soundness failures. Other circuit issues: unsafe gadget reuse, arithmetic field errors, out-of-circuit leaks.
1
0
1
@Sabanaku77
Lvl2 Pekka
2 months
2/9 > 4-layer model of an SNARK system: - Circuit (arith constraints) - Frontend (compilers/arithmetization) - Backend (setup, prover, verifier) - Integration (contracts/app logic) All layers had bugs.
1
0
1
@Sabanaku77
Lvl2 Pekka
2 months
1/9 > Paper systematizes 141 vulnerabilities (2018–2024) across SNARKs → audits, disclosures, bug trackers. First large-scale dataset of its kind.
1
0
0
@Sabanaku77
Lvl2 Pekka
2 months
Just read "SoK: What Don’t We Know? Understanding Security Vulnerabilities in SNARKs." by @cryptodavidw @schaliasosvons @0xSerious @MMJahanara @convoluted_code Turns out: SNARKs aren’t “just math.” 141 real-world bugs show why end-to-end security and better tooling are critical
2
4
22
@Sabanaku77
Lvl2 Pekka
2 months
Continuing with the @RareSkills_io ZK Book, just wrapped up Module 3. After completing the maths and ZK-SNARK pipeline in Modules 1 & 2, this module provided hands-on experience with Circom, including writing circuits, templates, loops, asserts, intermediate signals, stateful
Tweet card summary image
github.com
Contribute to prajjwal001/rareskill-zkbook-circom development by creating an account on GitHub.
0
1
12
@Sabanaku77
Lvl2 Pekka
3 months
Over the past 10 days, I worked through Modules 1 & 2 of the RareSkills ZK Book Learned the math foundations for ZK (finite fields, group theory, elliptic curves) and then built up to ZK-SNARKs step by step — circuits → R1CS → QAPs → pairings → trusted setup → Groth16. Big
1
2
23
@pashov
pashov
3 months
Just found some very handy tools for the everyday EVM dev Decoding, hashing, bit manipulation, merkle trees, wallet/signatures EIPs, Uniswap hooks and more - a bit of everything, make sure to add it to your toolbelt🫡 https://t.co/STCUnwUG3l
7
44
300
@cantinaxyz
Cantina 🪐
5 months
Final standings from the @stabilitydao competition have landed. 🥇 kalyanSingh: $5,159.36 🥈 @sabanaku77: $1,784.24 🥉 @Nicks_block: $1,541.17 Appreciate everyone who contributed. Full leaderboard below.
2
4
33
@Sabanaku77
Lvl2 Pekka
5 months
Just wrapped up a great conversation on Web3 security, learning curves, and audit life with @RealJohnnyTime We covered: – My Web2 to Web3 jump – How SCH & Cyfrin Updraft shaped my audit journey – Real contest prep & mindset – Tips for new auditors
@RealJohnnyTime
JohnnyTime 🤓🔥
5 months
He started ACING audit contests in just a few months! How do you do it?🤔 Learn how to stay consistent, build real skills & juicy tips to succeed from someone who made it in Web3 security, even while working his full-time Web2 job, in the latest episode w. @Sabanaku77 👇
3
3
40