Trail of Bits found a high-severity underconstrained-input vulnerability in Miden’s zero-knowledge virtual machine core cryptographic library that could let a malicious prover forge Falcon signatures and steal funds from accounts using Falcon key pairs. The flaw in the MASM mod_12289 procedure allowed a prover-supplied remainder to reach a 32-bit subtraction without first being validated as a 64-bit value.
Auditors developed AI-assisted tooling for the MASM-based stack, including a language server, decompiler, static-analysis engine, linter, and Lean formal model of the VM executor. The static analysis identified more than 400 publicly reachable instances of insufficient type validation, while formal verification generated 95 machine-checked proofs and found additional defects in rotr and wrapping_mul; Miden has adopted the static-analysis engine for future core-library changes.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Trail of Bits' Lean model and MASM translator generated 95 machine-checked proofs and found bugs in the 64-bit rotr and 256-bit wrapping_mul procedures that existing unit tests had not detected.
Reviewers found a high-severity underconstrained prover-advice vulnerability in mod_12289: an unvalidated remainder could cause an incorrect modular-reduction result. A malicious prover could use the flaw to forge Falcon signatures and drain Miden accounts controlled by Falcon key pairs.
AI-assisted static analysis identified more than 400 unique publicly reachable locations in the Miden core library where type validation could be improved.
The Miden team commissioned Trail of Bits to review parts of the Miden zero-knowledge VM and its MASM-based cryptographic core library before launch.
The Miden team adopted the static-analysis engine developed during the review to help secure future changes to the Miden core library.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.