Zero Knowledge Podcast

lean Ethereum Part 3: Security of PQ SNARKs and an update about the Proximity Prize

March 4, 2026·37 min·2 clips
After a three-bit attack and a ten-bit attack on deployed SNARKs, Antonio Sanso explains why Ethereum can't accept even a one-bit drop below 128 bits of security.
The episode starts with the stack. Post-quantum SNARKs sit inside Lean Ethereum, where hash based proof systems support LeanVM and signature aggregation. The security question is narrower than it first sounds. The group walks through the range where constructions were understood up to one corruption fraction, then known to fail beyond capacity. The unresolved part was the middle. Recent papers on correlated agreement error push into that gap and show failure before the old capacity line. Nico slows down the distinction. The result sits close to the Elias bound, a classical information theoretic coding quantity, not some brand-new cryptographic trick. The practical hit is modest, but it is still a hit. For deployments aiming at 128-bit conjectural security, the analysis may cost roughly three to five bits. In this setting, that matters. LeanVM and signature aggregation depend on confidence in these assumptions, so small degradations deserve to be named instead of waved away. The historical twist is a good one. One result leans on a bound from 1964, which makes the modern security story feel less like pure invention and more like old math returning at the right moment. The episode then opens back up. The Ethereum Foundation's proximity prizes put serious money behind work on these conjectures. Poseidon gets pulled into focus too. By the end, Poseidon and Poseidon2 come across as central hash functions across the system, not interchangeable plumbing. The close points to another million-dollar prize for Poseidon security, more curious than certain.

As heard by us

A clear look at the math and security behind Lean Ethereum's post-quantum path.

Lean Ethereum spends time on the part of post-quantum Ethereum that usually stays buried: how the SNARKs work, where the security claims actually sit, and what recent research says about the gap between proof and trust.

Read the full review in PlayNext →

Why you'd press play

You want the theory and security behind post-quantum SNARKs in the Lean Ethereum miniseries.

Read the full recommendation in PlayNext →
Listen to the show on