4 Dec 2024 [research]

Generalized Bulletproofs 'suitable for use' according to Brandon Goodell security review

Brandon Goodell (aka Surae Noether)1 has concluded2 that Generalized Bulletproofs (GBPs)3 are suitable for use after completing a review4 of the security proofs5 produced by CypherStack6:

My general results: Overall, GBPs are suitable for use, I think they are secure. [..] If the proofs of security for BPs are up to industry standards for a classically-secure cryptosystem, then the proofs of security for GBPs probably are, also.

Justin Berman7 has praised the work suggesting that the report gives confidence in GBP’s used in FCMP++8 and echoed the author’s recommendation to prioritize research into potential Bulletproofs and GBPs attack vectors.

To learn more about this story, consult the previous Monero Observer report9.

This is an ongoing story and the report will be updated when new information is available.


  1. https://github.com/b-g-goodell 

  2. https://repo.getmonero.org/monero-project/ccs-proposals/-/merge_requests/449#note_27508 

  3. https://github.com/AaronFeickert/curve-trees/blob/main/bulletproofs/generalized-bulletproofs.md 

  4. (!PDF) https://repo.getmonero.org/-/project/54/uploads/b2d5c8198f55d72b588f1ef138126850/GBP_Security_Review.pdf 

  5. /rehrar-submits-ccs-proposal-generalized-bulletproofs-review-by-cypherstack/, https://github.com/cypherstack/generalized-bulletproofs/releases/tag/final 

  6. https://cypherstack.com 

  7. https://github.com/j-berman 

  8. https://github.com/kayabaNerve/full-chain-membership-proofs 

  9. /kayabanerve-submits-ccs-proposal-full-chain-membership-proofs/