The algebraic FreeLunch attack proposed by Bariant et al. challenges the security of fullround instances of some ZK-friendly hash functions, namely Anemoi, Arion and Griffin.

keyboard_arrow_up