Skip to content
News briefAU-2026-0283

A standard way to hash several values

Trail of Bits has published SequenceHash and SequenceMAC, hash-agnostic multihashing aimed at the encodings that quietly break Fiat-Shamir.

2 minSmart Contract AuditsFresh · 2 Oct

Trail of Bits has released SequenceHash and SequenceMAC, a pair of constructions for hashing several values together, and contributed the specification to the Community Cryptography Specification Project. Implementations in Rust, Go and Python ship with it, along with test vectors that include intermediate values so developers can debug their own ports.

The problem they address looks trivial and is not. Feeding three inputs into a hash through separate update calls does not separate them: the firm's example shows three different groupings of the same bytes producing one identical SHA256 digest. Where that ambiguity matters most is the Fiat-Shamir transform at the heart of zero-knowledge proofs, and, as the post puts it, a mistake there is sometimes measured in millions of dollars.

NIST's TupleHash already solves this, but it is defined only for Keccak; swap in another hash and guarantees such as length-extension resistance can disappear. Given how little SHA3 adoption there has been, and that CNSA 2.0 mandates SHA384 and SHA512 for nearly everything, that leaves a large part of the field improvising with separator characters and ad-hoc encodings that audits keep finding broken.

  • Unambiguous encoding: no other sequence of inputs, of any length, can produce the same input to the underlying hash.
  • Length-extension prevention through a double-hash construction, which plain SHA256 and SHA512 do not offer.
  • Optional customization strings, applied only in the outer layer, so the inner hash can be reused across contexts.
  • A keyed mode, SequenceMAC, structurally similar to HMAC but without its key pseudocollision issues.

Where TupleHash length-prefixes its inputs, SequenceHash writes a fixed 128-bit byte count as a suffix. That choice is deliberate: suffix encoding lets implementers stream data whose length is not known in advance, and a fixed-width field is simple to pad on both 32-bit and 64-bit systems. The firm is explicit that none of this rescues a weak hash, and assumes a sensible choice such as SHA256 underneath.

Retold from Trail of Bits. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined