Advertise
PRICES
AI summary of a third-party reportNewsDesk

Zero-knowledge framework aims to make bridge hacks unviable

Americanfortress has published a zero-knowledge framework that proves links between a wallet's keys without exposing seed phrases, which its CEO says makes cross-chain bridge attacks economically unviable.

InvestIn.News NewsDesk · 2 min read

← Back to NewsDesk

Illustration of a cryptographic proof linking two blockchain wallet addresses behind a shield
Reported by Bitcoin.com NewsReporter: Terence ZimwaraRead the original

Key points

  • Americanfortress detailed the ZK-POSP framework in a research paper released on Sept. 24.
  • The paper's authors are Vincenzo Botta, Michal Pospieszalski, Emanuele Ragnoli and Justus Ranvier.
  • CEO Michal Pospieszalski said attackers would need to commit equal personal funds to bypass verification.
  • An SDK integration into MetaMask generates proofs automatically in roughly three seconds, he said.
  • The framework offers three disclosure options and is designed to work with post-quantum standards.

Researchers at cryptography firm Americanfortress have unveiled a zero-knowledge framework that proves ownership relationships between a wallet's keys without revealing seed phrases or public transaction histories, Bitcoin.com News reports. The company says the approach, called ZK-POSP, could make cross-chain bridge attacks economically unviable.

The technique was detailed in a research paper released on Sept. 24. It expands on existing zero-knowledge cryptography, which can already prove that a single address was created legitimately from a real wallet. Real-world finance often needs to show links between several keys, and until now that meant either exposing secret recovery phrases or revealing every address in the wallet.

The paper's authors, Vincenzo Botta, Michal Pospieszalski, Emanuele Ragnoli and Justus Ranvier, created three flexible disclosure options so users can control how much information they reveal. Americanfortress chief executive Michal Pospieszalski told Bitcoin.com News that when the framework is built into a DeFi protocol, every transaction must pass an extra security check before it is processed.

Proving links without seed phrases

Pospieszalski said the party initiating a transaction must prove that the source of funds and the destination address belong to the same entity. That makes stealing from a cross-chain bridge significantly harder, he argued, because an attacker would first have to commit an equal amount of their own capital and start a legitimate transaction. At that point, he said, exploiting the bridge becomes economically unviable.

He added that the user experience should remain uninterrupted. Americanfortress is integrating its software development kit into MetaMask, which generates the required proofs automatically, with a status notification shown in the interface. The process takes roughly three seconds, and a DeFi-side oracle verifies the proof before the transaction is finalised. If verification fails, funds return automatically to the source address.

The framework also targets compliance. Pospieszalski said a user can generate a zero-knowledge proof tied to an individual on-chain transaction, letting a verifier confirm a specific address without exposing unrelated wallet history. Because only transaction-specific data already on the public ledger is disclosed, external auditors cannot reconstruct broader off-chain transaction graphs.

Making bridge attacks costly

Other uses outlined by the research team include address books that check a new payment address belongs to a verified recipient, and exchanges verifying anti-money laundering status on incoming deposits while preserving anonymity. The system can also prove continuity when users rotate keys after a breach, and the proofs are designed to work alongside post-quantum cryptographic standards.

Read the full article on Bitcoin.com News →

We can’t find that page

The link may be old, or the address may have a typo. Search the site, or pick up from one of the desks.

Search the Site NewsFeeds NewsDesk Markets Originals PRDesk Home

No tracking hereWe set no cookies for readers and use no third-party analytics or ad trackers; we count story views ourselves, anonymously. Your theme choice, and a note that you’ve seen this message, are kept in your own browser. Read the Cookie Notice.