This report checks new papers across four areas: Poseidon2b resultant attacks, malicious matrix selection, Fiat-Shamir self-reference in recursion, and quantum permutation and Reed-Solomon bounds. All 296 production Poseidon2b values match the authors' reference. The mainnet v2 soundness output was reproduced byte for byte. The new resultant method has not been established for Parano1d's binary feed-forward compression, and the concrete recursive compiler analysis remains open.
New September papers touch four parts of Parano1d's security argument: Poseidon2b resultants, matrix provenance, Fiat-Shamir inside recursion, and quantum permutation and Reed-Solomon bounds. We checked each against the fixed production code and parameters.
Two papers develop resultant solvers; two examine malicious matrix selection; one analyzes Fiat-Shamir self-reference; and two revisit quantum or code bounds. The production Poseidon2b values match the authors' reference, and the mainnet v2 soundness rerun is byte-identical. The technical report records paper versions, PDF hashes and reproduction commands.
Poseidon2b: two resultant methods
A Better Bivariate Resultant Attack on Round-Reduced Poseidon proposes a faster heuristic solver for bivariate CICO-2 systems. Applying its no-skip formal degrees to Parano1d's width-four, x^7, 8+58-round tuple gives delta = 7^66 and D_I <= 7^74. At matrix-multiplication exponent two, the soft-O monomial is 7^107, or about 2^300.387. We added this exact calculation to the executable soundness audit as a screening result.
That number is a screening calculation, not an attack cost for Parano1d. The paper's generic-coordinate theorem assumes the field characteristic exceeds D_I; our field has characteristic two. Its experiments use other parameters and prime fields. Its equations constrain two output coordinates of a permutation, while our Merkle compressor includes the input in the output through feed-forward. Applying the faster algorithm to those equations still needs a proof or experiment. Efficient Polynomial System Solving via Dixon Resultants: Applications to AO Primitives offers another route, but its fastest determinant setting explicitly excludes binary extension fields.
The earlier feed-forward analysis still applies to its own attack model. Its 2^409.874 projection does not answer whether the newer method transfers. The two figures describe different algorithms and equations.
Matrix provenance: Nothing Up My Matrix and Slipway
Nothing Up My Matrix: Kleptographic Backdoors in ZK-friendly Hash Functions shows how an adversary who controls the choice of a linear matrix can install a backdoor while passing ordinary matrix checks. The revised Slipway: Accessing Finite Subspace Trails in Poseidon likewise selects a matrix in response to round constants. Both papers make the origin of the fixed production matrices worth checking.
We compared the production constants with the Poseidon2b authors' pinned reference: 264 round constants and 32 matrix entries, all 296 values, matched exactly. A regression test now checks their canonical digest. This rules out a local parameter substitution relative to that reference. It does not prove the reference itself free of weaknesses.
Fiat-Shamir inside recursion
How to instantiate Fiat-Shamir Provably and Practically? revisits diagonalization when a prover can build statements that refer to the verifier's own challenge computation. Parano1d's recursive proof verifies earlier proofs, so we checked the actual boundary: framed hash operations, separated transcript domains, pinned verifier-key digests and fixed circuit shapes. Contract programs run inside a bounded interpreter rather than selecting an arbitrary verifier circuit.
These checks limit how a prover can construct such a statement. They do not establish a concrete Fiat-Shamir security theorem for the recursive compiler. The paper's suggested secret-key VRF needs a separate noncolluding evaluator and cannot directly replace a permissionless public transcript. Its formal result also stops short of multi-round GKR. The certificate therefore retains its ideal-compiler premise.
Quantum permutation and Reed-Solomon bounds
Improved Soundness for Compressed Permutation Oracles and Tight Quantum Preimage and Collision Bounds for the Sponge studies a uniformly random permutation. Parano1d uses a public fixed Poseidon2b instance, so that bound cannot replace the fixed-permutation condition in its certificate. Reed-Solomon Codes Beyond Johnson: Efficient Decoding and Smaller Cryptographic Proofs improves an asymptotic agreement bound in every characteristic; its beyond-Johnson results need large characteristic. Neither paper supplies a complete finite-parameter replacement for Parano1d's typed recursive openings. No consensus query count was changed.
We reran the mainnet v2 soundness calculator against the pinned bank. Its JSON output matched the saved result byte for byte; the conditional arithmetic and limiting event are unchanged. The audit now includes the new screening calculation and a test of the production constants. Applying the resultant algorithm to our binary feed-forward compressor and analyzing the concrete recursive Fiat-Shamir compiler remain open tasks.
