Trail of Bits disclosed that it forged a zero-knowledge proof accepted by Google Quantum AI’s unpatched verifier for a published quantum-circuit claim tied to elliptic curve cryptanalysis. The researchers said the result did not break the underlying cryptography or demonstrate a new quantum algorithm; instead, it exploited weaknesses in Google’s Rust-based prover and simulator, including unsafe deserialization of untrusted circuit bytes and logic flaws that let invalid operation types evade Toffoli-gate accounting and use register aliasing to violate reversibility constraints.
According to Trail of Bits, the forged proof reused the same verification key and reported stronger-looking metrics than Google’s published proof, including 8,288,880 operations, 1,164 qubits, and 0 Toffoli gates, while actually embedding arbitrary classical logic into what was supposed to be a quantum circuit model. The firm published a proof-of-concept repository with the forged artifact, verification steps, a circuit-generation script, and a patch affecting code outside the zkVM; it said the proof was generated on a cloud system with four NVIDIA H100 GPUs in about four hours. Google patched the proof implementation and said its underlying scientific claims were unaffected.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Trail of Bits published a blog post and GitHub repository describing how it beat Google's zero-knowledge proof of quantum cryptanalysis by exploiting implementation vulnerabilities rather than achieving a quantum algorithm breakthrough.
By the time of disclosure, Google had patched the proof implementation in version 2 of the verification workflow. Google stated that the implementation issues did not affect the underlying scientific claims.
Trail of Bits created a proof-of-concept repository containing the forged proof artifact, verification instructions, a circuit-generation script, and a patch manipulating kickmix circuit serialization. The firm said it generated the forged proof on a cloud system with four NVIDIA H100 GPUs in about four hours.
Using the identified flaws, Trail of Bits produced a forged zero-knowledge proof that reportedly verified with the same verification key as Google's published proof while claiming stronger metrics, including about 8.3 million operations, 1,164 qubits, and zero Toffoli gates.
Trail of Bits found multiple vulnerabilities in the unpatched proof system implementation, including unsafe deserialization of untrusted circuit bytes and logic flaws that let invalid operations bypass Toffoli accounting and violate reversibility constraints through register aliasing.
Before Trail of Bits' disclosure, Google Quantum AI had published a proof-verification workflow and proofs supporting claims about a quantum circuit for elliptic curve cryptanalysis. Trail of Bits' later analysis indicates the attacked target was version 1 of this workflow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
blog.trailofbits.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.