<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Filipe Casal on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/filipe-casal/</link><description>Recent content in Filipe Casal on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 30 May 2025 00:00:00 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/filipe-casal/index.xml" rel="self" type="application/rss+xml"/><item><title>A deep dive into Axiom’s Halo2 circuits</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/05/30/a-deep-dive-into-axioms-halo2-circuits/</link><pubDate>Fri, 30 May 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/05/30/a-deep-dive-into-axioms-halo2-circuits/</guid><description>Over two audits in 2023, we reviewed a blockchain system developed by Axiom that allows computing over the entire history of Ethereum, all verified by zero-knowledge proofs (ZKPs) on-chain using ZK-verified elliptic curve and SNARK recursion operations. This system is built using the Halo2 framework—a complex, emerging technology that presents many challenges when building a secure application, including potential under-constrained issues resulting from its low-level API.</description></item><item><title>Read code like a pro with our weAudit VSCode extension</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/</link><pubDate>Tue, 19 Mar 2024 09:30:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/</guid><description>Today, we’re releasing weAudit, the collaborative code-reviewing tool that we use during our security audits. With weAudit, we review code more efficiently by taking notes and tracking bugs in a codebase directly inside VSCode, reducing our reliance on external tools, ensuring we never lose track of bugs we find, and enabling us […]</description></item><item><title>Amarna: Static analysis for Cairo programs</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/04/20/amarna-static-analysis-for-cairo-programs/</link><pubDate>Wed, 20 Apr 2022 07:00:04 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/04/20/amarna-static-analysis-for-cairo-programs/</guid><description>We are open-sourcing Amarna, our new static analyzer and linter for the Cairo programming language. Cairo is a programming language powering several trading exchanges with millions of dollars in assets (such as dYdX, driven by StarkWare) and is the programming language for StarkNet contracts. But, not unlike other languages, it has its […]</description></item><item><title>Disclosing Shamir’s Secret Sharing vulnerabilities and announcing ZKDocs</title><link>https://miscreants.github.io/blog.trailofbits.com/2021/12/21/disclosing-shamirs-secret-sharing-vulnerabilities-and-announcing-zkdocs/</link><pubDate>Tue, 21 Dec 2021 07:00:04 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2021/12/21/disclosing-shamirs-secret-sharing-vulnerabilities-and-announcing-zkdocs/</guid><description>Trail of Bits is publicly disclosing two bugs that affect Shamir’s Secret Sharing implementation of Binance’s threshold signature scheme library (tss-lib) and most of its active forks. Here is the full list of affected repositories: Binance’s tss-lib Clover Network’s threshold-crypto Keep Network’s keep-ecdsa Swingby’s tss-lib THORchain’s tss-lib ZenGo X’s […]</description></item></channel></rss>