Engineering Director for Cryptography at Trail of Bits

My teammate “proved” Fermat’s Last Theorem and did something Fermat or anyone else couldn’t do: made it small enough to fit in the margin
Last week, @AnthropicAI formalized Fermat's Last Theorem in 13 million lines of Lean code. We "proved" that same theorem in 20 lines by exploiting a bug we found in Lean. blog.trailofbits.com/2026/09…
1
2
24
1,414
Patch the Planet is our joint initiative with @OpenAI to help maintainers strengthen critical open-source software. In one week, we used Codex and GPT-5.5-Cyber to find hundreds of bugs inside OSS like cURL, Python, and the Go project. 37 patches merged, with more in flight. 🧵
1
4
203
Re Zcash vuln: yes, ZK exploits are undetectable. Here's a slide from my 2023 RWC Fiat-Shamir talk where we found Incognito Chain had an undetectable print free money vuln for over 4 years. These issues happen all the time in ZK systems. Formal verification is not a silver bullet
8
15
71
9,614
ZK-based systems are difficult to build correctly- this combined with the undetectability of their failure modes creates huge risk. You need secondary controls to mitigate this risk.
6
392
ZK is a sharp double-edged sword. The same technology that offers private transactions, private identity services, and private voting also enables undetectable money theft, undetectable identify theft, and undetectable election hacking
1
1
7
430
What a class act. Please don’t forget how kind, hard working, generous, and cracked you are too, my friend.
Since this has blown up, I’d like to shout out all the other trans founders. I won’t name them out of respect for their privacy. There aren’t a lot of us out there and it’s hard. All the ones I’ve met are incredibly hard working, kind, and generous people, not to mention completely fucking cracked. Shit like this happens all the time but that’s life, can’t make everyone like you. :/ Life is not easy—for anyone
5
162
Jim Miller retweeted
Congrats to Ryan Keegan for being the first to exploit the simulator we used to validate the secret quantum circuits: blog.trailofbits.com/2026/04… It kills me that the (now fixed) bugs were simple (we didn't port the op validation code from C++ to Rust!), but that's to be expected.
6
11
80
7,571
Jim Miller retweeted
Replying to @trailofbits
Going further, there’s a way to protect the guest program even against potential compiler bugs: formally verify the guest RISC-V assembly code, like I’m experimenting with in evm-asm.
1
2
12
5,338
Jim Miller retweeted
Google used a ZK proof to disclose a quantum breakthrough that cuts the cost of breaking cryptocurrency by 20x without handing attackers the circuit. We found anyone could forge a “proof” of an even stronger attack. 🧵
14
90
716
81,045
Jim Miller retweeted
Lets break down these attacks: nitter.net/tjade273/status/197310… First up is wiretap.fail The key insight is that TEEs do not randomize their memory encryption. This is because the encrypted data needs to fit in the same space as the plaintext, so there is no room for a nonce or IV. The typical cipher mode is AES-XEX or the related AES-XTS. en.m.wikipedia.org/wiki/Xor%… Every memory location acts like an independently keyed cipher, so it’s not quite ECB Tux level bad, there is a sort of _temporal tux_ problem. Every time a value is encrypted at a particular memory location, the ciphertext is the same.
IMO these two attacks spell the beginning of the end for SGX, TDX and SEV-SNP in self-hosted contexts. These DRAM bus attacks were always the glaring hole in the threat model, and I expect DDR5 to fall soon as well. These attacks are explicitly written out of the threat model so they won’t be patched by Intel and AMD, and it’s not clear how they could do so anyway.
2
9
22
4,854
My colleagues wrote a great explainer on the historic hack from today and what it means for the industry. Must read 👇
The $1.5B Bybit hack marks a new era in cryptocurrency security. Attackers have moved beyond technical exploits to sophisticated operational attacks. Read our initial analysis of this historic breach and its industry-wide implications: blog.trailofbits.com/2025/02…
1
12
498
Jim Miller retweeted
The $1.5B Bybit hack marks a new era in cryptocurrency security. Attackers have moved beyond technical exploits to sophisticated operational attacks. Read our initial analysis of this historic breach and its industry-wide implications: blog.trailofbits.com/2025/02…
9
66
249
330,107
Start the year off right and register/submit a talk for the Real World MPC workshop! The MPC Alliance is hosting this as a co-located event for Real World Crypto, and the CFP is now open and accepting talks across a wide variety of MPC topics 🙂. Details and links are in 🧵
1
2
7
1,648
The RWMPC workshop will be a 1 day event on March 25 in Sofia, Bulgaria. The content will cover a variety of practical MPC use cases: currently accepting potential talks across real-world deployments, standards, security, formal verification, legal implications, and more!
1
1
131
I am honored to be selected as part of the program committee by the MPCA, so please don't hesitate to reach out with any questions. This will be a great event showcasing the practical side/challenges of MPC. I hope to see you all in Sofia ❤️
1
1
99
The first ever Queer in Cryptography conference will be held in Rochester, NY on March 6th and 7th 2025! Register now and come celebrate the many great cryptography contributions from the LGBTQ+ community- allies welcome! cryptography.lgbt/
7
34
3,794