Web Hack List

Preliminary research

zkLogin: when ZKP is not enough

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Zero-knowledge authorization proves possession of a signed credential without revealing it, and its security is usually argued from the proof alone. zkLogin, the most widely deployed such system, is shown to depend as much on non-cryptographic assumptions - JWT and JSON parsing, issuer trust policy, architectural binding, execution-environment integrity - none enforced at protocol level.

Record

Researcher
@brave and Brave Software
Published by
Brave
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @brave and Brave Software, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .