# Merkle Proofs: When Leaves Leave You Vulnerable

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 05:35
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt-5aAjU_79ErA
- YouTube: https://www.youtube.com/watch?v=5aAjU_79ErA

## Description

A Merkle proof is a cryptographically authenticated data structure widely used to minimize on-chain data storage. The Merkle algorithm is neat yet non-trivial to implement correctly and securely; its leaves may leave you vulnerable if not handled properly.

## Transcript

[Music] [Music] security engineer from CH security I'm very happy to hear to share my insights about merro proofs today today especially I'm going to talk about one lives will leave you vulnerable so I believe in your life you have seen many treats with different shapes different structures for example it's a very simple tree it could be bigger and more complex and in addition this is GR like it's not doesn't look like a tree it could also be Earth tree in the game's outen ring and for merco tree it's very similar it could be a very balanced and simple Mer tree where data is at the bottom and it's balanced it could also be very imbalanced in this case and be sure to distinguish Merk's tree from merco tree it's very different and in addition we all know the merco Patricia tree which is a very important data structure in the etherum global storage so with all these trees there are very different mer culture algorithms however I believe you can find all the important checklist that you should use to ensure a security proof in your uh protocols but even though we have this checklist we cannot ensure that we can find all the vulnerabilities in very different micro algorithms and that is when you when the leaves can leave your protocal vulnerable the answer is very clear the the answer is about the beginning if you don't recognize a note as a leaf you will never ensure the property from the checklist against it and make it secure so today I'm just going to share you one example of this kind of attack that is about meron range I'm not sure if you have all heard about this algorithm so let me first introduce what is merco monor range it is a very simple data structure uh it's just like a group of sub merco trees you just add the data at the bottom of this merom mon range and once you keep adding new data if there are two siblings we add a parent if there are two parent we we add another parent you do this recursively and eventually you will get uh several merco trees in this merco mountain range with different depths and different size and we call the top node of this subri PS and why do we use merom man range as I tell you uh if you are adding a new node here it's very easy to build the tree and you don't need to rec computed the all not industry you just append only and uh now we have this uh subri if we only want to store a constant size of commitment on the blockchain what we do is we compute a root the root will be a nested hash of all the sub tree paks and this process we call it a bing process so once you have the root you can do a normal existence proof of any data within this mer man range how do you do that that's also very simple we first do a proof of any of the leaf within the sub tree and once we have that proof we can also add more pigs within this proof so we can reconstruct the root at the top and just take a minute think about what can go wrong in this algorithm if you want to prove any data within any of the leaves so we must have some assumption so let's assume the people who is adding data to this merro monange is trusted so he won't add any malicious state it won't add a sub tree into this leaves in addition let's assume you have sufficient validation of the index and the depth of the leaves when you do the proof so that you can easily use another intermediate node as a leaf here like for example the P1 and D1 they are very different not right the P1 has depth one but D1 has depths two so you can't use the intermed node in this proof even with this constraints can you break this system the answer is yes if we just take one step back and look at this meron range again we will find there's actually a hidden tree when you build the route that makes up of this pigs so we have three pigs of the sub trees here and now we are building another merco tree with this pigs to the route and we as you can see we have no validation of the paks in the previous assumptions and that means you can easily find a vulnerability here and here is one example of this attack so on the left side this is the mer man range on the right side I do the attack by just removing the D5 and D6 live node and now as you can see the P4 the interm node becomes the Lea and more surprisingly Z has the same depth as the node D5 so now if I'm going to prove P4 in the sub tree of N1 it will have depth one that satisfy all the properties we have validated before but we have never validated the pics so this is a trick that now you can prove something nonexisting in your Merk tree so that's the example I want to show you today and the summary is very simple a nonleaf with Bela could be a Lea so please ensure that you check all the input and validate all the properties you desire in your protocol otherwise it could become vulnerable easily and thank you very much for listening if you want to know more about CH security and our work
