SP1 SECURITY DISCLOSURE
Two weeks ago, we publicly disclosed security issues in a previous version of SP1 (V3) on our Github Security Advisory and developer TG. We have thoroughly investigated all reported issues and resolved them in SP1 Turbo (V4). All production customers have been upgraded.
Thank you to
@alignedlayer,
@class_lambda,
@3miLabs,
@levs57, and
@kiliconu for responsible disclosure of these issues and working with us to resolve them.
We have shared more details on the issues on our blog
and also updated our release notes for SP1 Turbo.
We take security seriously at Succinct. We have undergone multiple audits for SP1 (
github.com/succinctlabs/sp1/…), hosted an external audit competition (
cantina.xyz/competitions/b92…), employed an internal auditor to thoroughly review all security-critical components of our codebase, and work closely with all our partners to ensure that production systems we deploy have necessary fail-safes.
In addition, we maintain several continuously updated resources that clearly define our security policy (
github.com/succinctlabs/sp1/…) and security model (
docs.succinct.xyz/docs/secur…).
Overall, while auditors provide valuable insights, they are not infallible, and we remain committed to continuously improving and working hard to ensure our systems are safe and secure for everyone.
Blog:
blog.succinct.xyz/sp1-securi…