# $ Whoami

> Source: https://rot256.dev/post/whoami/
> Author: Mathias Hall-Andersen
> Date: 2026-06-14
> License: CC BY 4.0 — reuse permitted with attribution to Mathias Hall-Andersen (rot256.dev).

Math macros in scope (KaTeX, `\name = expansion`):

```text
\Div = \mathrm{Div}
\FF = \mathbb{F}
\GG = \mathbb{G}
\NN = \mathbb{N}
\Norm = \mathrm{N}
\PRF = \mathsf{PRF}
\RR = \mathbb{R}
\Tr = \mathrm{Tr}
\ZZ = \mathbb{Z}
\adv = \mathscr{A}
\bin = \{0, 1\}
\coloneqq = \mathrel{\mathop:}=
\defeq = \coloneqq
\deg = \text{deg}
\divides =  \ | \ 
\gcd = \text{gcd}
\hash = \mathsf{H}
\img = \text{img}
\ker = \text{ker}
\language = \mathcal{L}
\lc = \mathrm{lc}
\lcm = \text{lcm}
\msg = \mathsf{msg}
\negl = \text{negl}(\lambda)
\pk = \mathsf{pk}
\prob = \mathbb{P}
\sample = \overset{\$}{\gets}
\secpar = \lambda
\sig = \sigma
\sign = \mathsf{Sign}
\sk = \mathsf{sk}
\support = \mathrm{Supp}
\tensor = \otimes
\verify = \mathsf{Verify}
```


<br>

I am Mathias Hall-Andersen ("rot256" on the internet),
a PhD in theoretical cryptology (from [Aarhus University](https://users-cs.au.dk/orlandi/cryptogroup/))
with a broad interest in both theoretical and practical information security, as well as privacy enhancing technologies including:
cryptography, cryptanalysis, coding theory, reverse engineering, vulnerability research and anything that lies at the intersection.
I love building and breaking real-world systems; particularly when they involve cryptography, with a soft spot for succinct arguments (SNARKs).
Together with [David Wong](https://cryptologie.net/) and [Gregor Mitscha-Baude](https://plusepsilon.com/)
I helped cofound [zkSecurity](https://zksecurity.xyz)
which does security auditing and engineering for advanced cryptography
with a focus on zero-knowledge type applications: SNARKs, recursive proofs, anonymous credentials etc.
If you are building with such technologies, or planning to build with them, you should reach out.

In my free time I play/organize [CTFs](https://ctftime.org/ctf-wtf/) with [Kalmarunionen](https://ctftime.org/team/114856) / [Norsecode](https://norsecode.team/),
I also work on open source software and enjoy various types of swing dancing.
On this site I post cryptography related technical content, ideas too small for a paper,
projects I have been working on and write-ups for CTF challenges (usually exploitation / reversing / cryptography challenges).

The image at the top of this page is a dithered collage of a picture I took of Arthur Ganson's "Machine with Concrete" at the MIT Museum.
This kinetic sculpture nicely illustrates the power of exponentials:
the motor turns at 200 revolutions per minute, each gear has a reduction ratio of 1/50, and there are 12 gears in total,
and the last one is fixed in a block of concrete;
it will take it roughly two trillion years to make one complete revolution.

## Education

| Period                 | Title                                                                     | Institution                     |
|:----------------------:| ------------------------------------------------------------------------- | ------------------------------- |
| 2024  | [PhD Thesis](thesis-phd.pdf) (Either/Or)  | Aarhus University (CS Dept.)               |
| 2020 - 2024 | PhD in Theoretical Cryptography                                       | Aarhus University (CS Dept.)               |
| 2022            | Visiting Researcher                                            | Boston University (BUSec)       |
| 2017 - 2020 | Master in Computer Science                                                | University of Copenhagen        |
| 2019  | [Master Thesis](thesis-master.pdf) (Contingent Payments)      | Aarhus University               |
| 2018        | Exchange                                                                  | ETH Zürich (D-INFK)             |
| 2017        | [Bachelor Thesis](thesis-bachelor.pdf) (Linear Cryptanalysis) | Technical University of Denmark |
| 2014 - 2017 | Bachelor in Computer Science                                              | University of Copenhagen        |

## Work

| Period               | Title                                                                                         | Institution                     |
|:--------------------:| --------------------------------------------------------------------------------------------- | ------------------------------- |
| 2024 -               | Co-founder/Cryptographer.                                                              | [zkSecurity](https://zksecurity.xyz/) & [Cryptographic](https://cryptographic.dk/) |
| 2020 - 2024 | PhD Student                                                                                            | Aarhus University               |
| 2023                 | Internship, Research / Engineering, [Fromager](https://galois.com/project/fromager/)                                           | [Galois](https://galois.com/)   |
| 2022                 | Internship, Cryptographic Engineering (Rust)                                                  | [O(1) Labs](https://www.o1labs.org/)      |
| 2021                 | Internship (Development/Research on [DARPA SIEVE](https://www.darpa.mil/program/securing-information-for-encrypted-verification-and-evaluation)) | [Trail of Bits](https://www.trailofbits.com/)          |
| 2020                 | Instructor in Distributed Systems and Security | Aarhus University |
| 2020                 | Internship (Development/Research on [DARPA SIEVE](https://www.darpa.mil/program/securing-information-for-encrypted-verification-and-evaluation))| [Trail of Bits](https://www.trailofbits.com/) |
| 2020                 | External lecturer in [Proactive Computer Security](https://kurser.ku.dk/course/ndaa09031u/2020-2021) | University of Copenhagen |
| 2019                 | Open source development on [WireGuard-rs](https://git.zx2c4.com/wireguard-rs/about/) <br> (NGI; Next-Generation Internet grant)                        | [NLnet](https://nlnet.nl/) (Sponsor)                           |
| 2019                 | Instructor in [Proactive Computer Security](https://kurser.ku.dk/course/ndaa09031u/2019-2020) | University of Copenhagen |
| 2018                 | Internship (Security Consultant -- Cryptography)                                              | NCC Group, New York <br/> ([Cryptography Services](https://www.nccgroup.com/us/our-services/cyber-security/specialist-practices/cryptography-services)) |
| 2017 - 2018          | Teaching Assistant in [Practical Cryptology](http://kurser.dtu.dk/course/2017-2018/02255)                     | Technical University of Denmark |
| 2017                 | Google Summer of Code (created [WireGuard-go](https://github.com/WireGuard/wireguard-go))                                      | WireGuard (Linux Foundation)    |
| 2016                 | Instructor in [Computer Systems](http://kurser.ku.dk/course/NDAB16005U/2016-2017)             | University of Copenhagen        |
| 2016                 | Student Assistant                                                                             | Deloitte Cyber Risk Services                    |
| 2015                 | Java Programmer                                                                               | Skandinaviska Enskilda Banken   |

## Research

### Publications

- [General Techniques for Building SNARKs over the Integers](https://eprint.iacr.org/2024/1548) for PKC 2026. \
  Matteo Campanelli and Mathias Hall-Andersen.
- [Foundations of Data Availability Sampling](https://eprint.iacr.org/2023/1079) for CIC 2025. \
  Mathias Hall-Andersen, Mark Simkin and Benedikt Wagner.
- [Jackpot: Non-Interactive Aggregatable Lotteries](https://eprint.iacr.org/2023/1570) for Asiacrypt 2024. \
  Nils Fleischhacker, Mathias Hall-Andersen, Mark Simkin and Benedikt Wagner.
- [Extractable Witness Encryption for KZG Commitments and Efficient Laconic OT](https://dblp.org/pid/225/9829.html) for Asiacrypt 2024. \
  Nils Fleischhacker, Mathias Hall-Andersen and Mark Simkin.
  [Presentation](https://www.youtube.com/watch?v=81Hq7Ij94vE),
  [Presentation](https://www.youtube.com/watch?v=WZU2ckWNtzM) (by me).
- [Dora: Processor Expressiveness is (Nearly) Free in Zero-Knowledge for RAM Programs](https://eprint.iacr.org/2023/1749) for CCS 2024. \
  Aarushi Goel, Mathias Hall-Andersen and Gabriel Kaptchuk.
- [FRIDA: Data Availability Sampling from FRI](https://eprint.iacr.org/2024/248) for Crypto 2024. \
  Mathias Hall-Andersen, Mark Simkin and Benedikt Wagner.
- [Curve Trees: Practical and Transparent Zero-Knowledge Accumulators](https://eprint.iacr.org/2022/756) for USENIX 2023. \
  Matteo Campanelli, Mathias Hall-Andersen and Simon Holmgaard Kamp.
- [Speed-Stacking: Fast Sublinear Zero-Knowledge Proofs for Disjunctions](https://eprint.iacr.org/2022/1419) for Eurocrypt 2023. \
  Aarushi Goel, Mathias Hall-Andersen, Gabriel Kaptchuk and Nicholas Spooner. [Presentation](https://youtu.be/vL48j6HXfIw?t=20)
- [On Valiant's Conjecture: Impossibility of IVC from Random Oracles](https://eprint.iacr.org/2022/542) for Eurocrypt 2023. \
  Mathias Hall-Andersen and Jesper Buus Nielsen. [Presentation](https://youtu.be/48OpM7T7ePQ?t=1119) (*by me*)
- [Efficient Proofs of Software Exploitability for Real-world Processors](https://eprint.iacr.org/2022/1223) for PoPETs 2023. \
  Matthew Green, Mathias Hall-Andersen, Eric Hennenfent, Gabriel Kaptchuk, Benjamin Perez and Gijs Van Laer.
- [Automated Analysis of Halo2 Circuits](https://eprint.iacr.org/2023/1051) for SMT 2023. \
  Fatemeh Heidari Soureshjani, Mathias Hall-Andersen, \
  Mohammad Mahdi Jahanara, Jeffrey Kam, Jan Gorzny, Mohsen Ahmadvand.
- [Secure Multiparty Computation with Free Branching](https://eprint.iacr.org/2023/901) for Eurocrypt 2022. \
  Aarushi Goel, Mathias Hall-Andersen, Aditya Hegde and Abhishek Jain. [Presentation](https://www.youtube.com/watch?v=95F1nlj8jjg).
- [Stacking Sigmas: A Framework to Compose Σ-Protocols for Disjunctions](https://eprint.iacr.org/2021/422) for Eurocrypt 2022. \
  Aarushi Goel, Matthew Green, Mathias Hall-Andersen and Gabriel Kaptchuk. [Presentation](https://www.youtube.com/watch?v=RtLnKSFEu0w) (*by me*).
- [Efficient Set Membership Proofs using MPC-in-the-Head](https://eprint.iacr.org/2021/1656) for PoPETs 2022. \
  Aarushi Goel, Matthew Green, Mathias Hall-Andersen, and Gabriel Kaptchuk. [Presentation](https://www.youtube.com/watch?v=sBQhB-If55E).
- [Count me in! Extendability for Threshold Ring Signatures](https://eprint.iacr.org/2021/1240) for Asiacrypt 2022. \
  Diego F. Aranha, Mathias Hall-Andersen, Anca Nitulescu, Elena Pagnin and Sophia Yakoubov. [Presentation](https://www.youtube.com/watch?v=2glB7Cr6Jhw).
- [Veksel: Simple, Efficient, Anonymous Payments with Large Anonymity Sets...](https://eprint.iacr.org/2021/327) for AsiaCCS 2022.  \
  Matteo Campanelli and Mathias Hall-Andersen. [Presentation](https://dl.acm.org/doi/10.1145/3488932.3517424) (*by me*)
- [Game Theory on the Blockchain: A Model for Games with Smart Contracts](https://arxiv.org/pdf/2107.04393.pdf), for SAGT 2021. \
  Mathias Hall-Andersen and Nikolaj I. Schwartzbach
- [Generating Graphs Packed with Paths](https://eprint.iacr.org/2018/764), for IACR-FSE-2019. \
  Mathias Hall-Andersen and Philip S. Vejre [Presentation](https://www.youtube.com/watch?v=kR8x-tdge3g) (*by me*).
- [nQUIC: Noise-Based QUIC Packet Protection](https://dl.acm.org/doi/10.1145/3284850.3284854), for EPIQ'18 (ACM) \
  Mathias Hall-Andersen, David Wong, Nick Sullivan and Alishah Chator.

## Languages

Fluent in Danish, English, Rust, Python, Sage, C, Go, LaTeX, a slew of assembly languages and cryptographic jargon.

Shaky in a lot more...

## Writing

A few examples of my technical writing:

- [Blog post series about Circle STARKs](https://blog.zksecurity.xyz/posts/circle-starks-1/) (STARKs / algebraic geometry)
- [Blog post about WE-KZG](https://www.zksecurity.xyz/blog/posts/kzg-we/) (advanced primitives)
- [Blog post about FRI proximity test.](/post/fri) (SNARKs / coding theory)
- [Blog post about git-ring.](/post/git-ring) (ring signatures)
- [Blog post about differential fault attacks.](/post/glitch) (hardware attacks)
- [Blog post about zero-correlation linear cryptanalysis.](/post/zero-correlation) (symmetric cryptanalysis)
- [Documentation/explainer of accumulation schemes.](https://o1-labs.github.io/proof-systems/pickles/accumulation.html) (recursive zero-knowledge proofs)
- [Blog post about Reverie.](https://blog.trailofbits.com/2020/12/14/reverie-an-optimized-zero-knowledge-proof-system/) (fast zero-knowledge proofs)


## Contact

|          |                                       |
| -----      | ------------------------------------- |
| GitHub   | https://github.com/rot256             |
| Email   | $\text{math}\text{ias}@\text{hall-an}\text{dersen.dk}$ |
| PGP Key  | [/key.asc](/key.asc) or [on GitHub](https://gist.github.com/rot256/def6be789efa8a55cbc67cb1e50bea42), FP: `71E1EC2B778745710667D51DAE331B20B3C8A5C2` |
| Website  | [rot256.dev](/) -- you are looking at it.              |
| Publications | [Semantic Scholar](https://www.semanticscholar.org/author/Mathias-Hall-Andersen/1403594144) |
| Signal   | rot.256   |

Questions? Comments? Interesting projects? Need help building/breaking cryptography?

Feel free to drop me an email :)

