Skip to content

10b. Integrate Keccak primitive β€” replace persistentHash message hashingΒ #827

Description

@0xisk

🧐 Motivation

The signatures the stateless presets verify are produced by EVM HSMs over a Keccak-256 digest. The contracts currently hash the signed payload with persistentHash, so the on-chain message never matches what the signer actually signed. Verification can only be correct once the message hash is Keccak.

πŸ“ Details

Split out of #475, which combined the ECDSA and Keccak work. The signature-verification half is tracked in #826.

Scope:

  • Switch the signed-message hash from persistentHash to the keccak256 primitive in EcdsaSignerManager and the stateless presets.
  • Align the message encoding and domain separation with what the EVM signing infrastructure produces, so an HSM signature validates without re-encoding on the client.
  • Measure real per-circuit cost (@circuitInfo k / rows) of keccak256 on the RC toolchain. Keccak sits on every gated circuit, so its row cost is load-bearing for the block budget.

Blocked on Midnight Foundation primitive delivery (Keccak GA). Blocks mainnet deployment of ShieldedMultiSigV2 and ShieldedMultiSigToken, and the corresponding audit scope.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

0-highShip-driving / do firsteffort: 3-MMedium effortfeat:cryptoFeature: cryptography (signatures, curves, hashers, nullifiers, primitives)

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions