Day after tomorrow📅8.17 TGE,
📅8.25 TGE—this month is going to be great!
Last night, the $KII I received could have been sold for 45, but I chose to hold with a bigger picture. Now it’s worth 23. Who else is still waiting for miracles like me?

Last night, when I was holding with a “bigger picture” on KII, my cousin came over and drank at my place. While drinking, he was flipping through Dusk’s documentation and muttering: “Moonlight here, Phoenix there—privacy and compliance are both trying to have it all.” I leaned over and looked for a bit, and when I read the page about Phoenix’s PLONK proof logic, my fingers paused on the keyboard.

This project really does have some substance. Dusk uses a dual-transaction model—Moonlight is a public account model: transfer amounts and addresses are completely transparent, designed specifically for exchange deposits/withdrawals and auditing scenarios. Phoenix is a UTXO-based privacy transaction model: funds exist in encrypted “notes,” and their validity is verified through zero-knowledge proofs. This hides amounts and addresses while also allowing key viewing to be selectively opened to regulators for audits. Users can switch between the two models with one click, and the whitepaper calls it “balancing privacy and compliance.”

But once I dissected Phoenix’s underlying cryptography, the problems surfaced.

Each Phoenix privacy transaction carries a PLONK proof. And this proof system has already been broken. In April 2026, OtterSec found a vulnerability in dusk-plonk: the verifier uses polynomial evaluations provided by the prover, but never checks whether those evaluations match the trusted commitments. A malicious prover can forge a proof, bypass every constraint in the transaction circuit, mint any amount of DUSK on the already-live Rusk network, and transfer via the Phoenix route. This is a severe vulnerability directly affecting about $60 million.

Another vulnerability came from the AEGIS audit—discovered in March 2026 issues like VM sandbox aliases, unsafe deserialization, and Phoenix fee-to-refund binding failure. Even though they’ve all been fixed, Dusk’s cryptography stack has already demonstrated one thing: it had a漏洞 bad enough to zero out the entire network.

The idea behind the dual-transaction model—resolving the privacy vs. compliance trade-off—does seem novel. But the core security of the privacy layer relies entirely on the correctness of the PLONK proof system, and PLONK has been shown to be forgeable. Cryptographic proofs can’t guarantee where the next PLONK vulnerability is hidden—in which line of code.
#dusk $DUSK @Dusk