Security

Half Ounce Research runs one capability, certified adversarial verification, and applies it to zero-knowledge proof systems, post-quantum signature verifiers and open questions in mathematics. Every finding travels with a machine-checkable witness that the client replays in their own verifier, without trusting the software that found it.

One computation

Each of these lanes reduces to the same computation:

given     a map  A : prover messages → verifier checks
find      the lightest x ≠ 0 with A(x) = 0 outside the intended relation
or prove  that none exists below a bound

The map is a verifier's acceptance rule as built, and its kernel is what that verifier cannot see: a second witness for the same public input, a transcript it cannot tell from an honest one, a second encoding of one signature. A reading of the code looks for what is missing; the kernel shows what is extra. The lightest such element is the adversary's cheapest deviation; the work is to find it and prove the measurement, or to prove that none exists below a bound. For a stabilizer code the computation is literal; for a circuit, a transcript or an encoding it is the framing of the question, and the certificate carries the claim.

Lanes

The bugs cited are public examples of each class, credited to their discoverers. None is a finding of this program.

Zero-knowledge proof systems
Soundness review — polynomial-commitment binding, sumcheck and FRI, recursion and aggregation, Fiat–Shamir, under-constrained circuits. “Frozen Heart”, disclosed by Trail of Bits in 2022: Bulletproofs and PlonK implementations had left public inputs out of the Fiat–Shamir transcript, and proofs could be forged.
Post-quantum cryptography
Verify-path review — ML-DSA, Falcon and SLH-DSA on the accepting side: acceptance-boundary defects and non-canonical encodings. CVE-2026-24850, reported by Oren Yomtov (Fireblocks), advisory GHSA-5x2r-hc65-25f9: the RustCrypto ml-dsa crate accepted repeated hint indices where FIPS 204 requires strictly increasing ones, so one valid signature had two encodings.
Mathematics
Machine-verified results — open questions in mathematics, published in the library with certificates, dated prior-art records and archival DOIs. The minimum-distance certificates for stabilizer codes are the kernel computation itself: where a distance is closed, an explicit logical operator of that weight plus a proof that nothing lighter exists, with no solver and no proof assistant in the trusted base. Also k(3,4) = 21, a 346-case LRAT-certified exhaustion replayed by a standard-library checker, and two public correction rounds.

What is delivered

A specification review asks whether the constraints the design calls for are present; it is a reading, and can miss what it was not told to look for. This is a search: the cheapest input the verifier, as built, accepts and the relation forbids. Each finding ships as the witness itself, a short checker in standard-library Python that reads it, and the replay command. The client runs the witness through their own verifier; if it accepts, the finding stands on the client's tooling, and nothing of this program's needs to be trusted. Where nothing exists below the bound, that ships as a certificate too — a statement about that map and that bound, not a security proof of the whole system.

Disclosure

The security record to date: confirmed critical-severity soundness findings in zero-knowledge proof systems and post-quantum cryptography implementations, disclosed responsibly. Findings go privately to the vendor; no live exploit is published; no finding of this program is named or described on this page.

Contact

Write to daniel@halfounce.io naming the proof system or signature scheme, its verifier, and where the source can be read. Audit firms may write to the same address.