Crafts–Arcium Fundraising Program
A published review of a privacy-focused fundraising program using zero-knowledge circuits and secure multiparty computation.
Read the published report ↗I’ll review application and execution-layer assumptions in Solidity or related EVM code, depending on the repository and threat model.
I’ll trace a circuit from its intended statement through witness generation, proving, verification, and the host-code boundary.
I’ll connect cryptographic design assumptions to the implementation and the protocol boundary, including FHE and MPC systems where they are in scope.
I’ll follow state and message flow across the network, execution environment, bridge, and settlement boundary rather than treating each component in isolation.
I’ll model the invariants and economic assumptions that make a financial primitive safe under normal use, edge cases, and adversarial state transitions.
I’ll focus on Solana’s account and runtime invariants, with scope defined around the program, supporting clients, and cross-program interactions.
I’ll use manual review alongside automated techniques when the repository, test harnesses, and threat model support them. These methods supplement review; they do not replace understanding the system.
I’ll trace Cosmos module behavior through message validation, deterministic execution, and interoperability boundaries.
A published review of a privacy-focused fundraising program using zero-knowledge circuits and secure multiparty computation.
Read the published report ↗Analysis of transcript-collision and state-handling failures in a Fiat–Shamir backend.
Read the analysis →Analysis of a validation failure that allowed negative slashing behavior and validator-accounting abuse.
Read the analysis →A compiler denial-of-service finding where repeated array literals can expand into a massive abstract syntax tree.
Read the Noir finding ↗Some technical review work is covered by confidentiality terms. Client names, private reports, and outcomes are not published here; additional experience can be discussed privately where appropriate.