This is a known operational risk with Groth16. We chose universal SNARKs (Noir/UltraHonk) specifically to eliminate this failure mode โ no circuit-specific ceremony means this entire class of vulnerability doesn't exist.
Privacy infrastructure shouldn't require a pinky promise.
The first two known exploits against live ZK circuits just happened, and they weren't subtle underconstrained bugs.
They were Groth16 verifiers deployed without completing the trusted setup ceremony. One was white-hat rescued for ~$1.5M, the other drained for 5 ETH.
๐งต