ZK/SEC Research notes from zkSecurity
All posts
announcement

A Year of ZK Security

first_tweet

A year ago, on May 30th, 2023, we released zkSecurity to the world with a tweet and a blog post.

Our theory at the time was that ZK circuits were hard to write correctly, and that with the boom of ZK platforms and frameworks and languages, developers were going to write bugs. What we didn't know is how many bugs...

first_post

A year later, our team is quite different! Brandon ended up stepping down to an advisor role due to becoming the CEO of O(1) Labs. Our loss, but good for O(1) Labs :) Gregor left O(1) Labs to join us full time, and Mathias ended up joining the founding team (so that we're back to three cofounders!). It's been an exciting year of growth, and we're thrilled to now have a team of around 10 dedicated engineers!

Our theory when we started zkSecurity was that ZK platforms would launch, and we would have plenty of ZK circuits to audit. But instead, ZK platforms took their time, and we ended up going through the entire stack in the meantime. Auditing proof systems, compilers, libraries, user applications, and integrations in real-world systems. Let's say that we learned more about the whole stack in a year than in years as developers.

We also underestimated how easy it was to mess up ZK code, finding numerous soundness issues, proof forgeries, and even double spending bugs in client's code. (I highly recommend checking our blog where we post our public reports.) This led us to write tools like Circomscribe, explore how we could find bugs using taint analysis, and publish a taxonomy of ZK bugs.

circomscribe

We knew from the start that the ZK boom was handing out a new programmable abstraction to developers, a programmable abstraction that was both complicated and confusing. The ZK codebases we looked at have (on average) been large and complex; the two main ingredients for bugs (and cool applications). Moreover, useful ZK applications most often means that they implement cryptographic algorithms in their circuits, add to that that they tend to target financial systems, and the impact of a bug is magnified significantly. And of course, if you have a privacy-enhanced application, then exploits can go undetected. This might seem scary, but for us it means job security.

At the same time zkVMs came into the mix. Bringing much more familiar abstractions to developers, and shifting the bugs to the compiler and proof system layers. While the cost of that nice abstraction layer has kept decreasing in the last years, some experts seem to argue that they're not going to completely replace circuits yet. At the very least, they'll still be circuits to audit, as optimization seekers are not going anywhere. But it's not too far-fetched to see a future where zkSecurity might be much more focused on auditing the inner guts of a zkVM rather than a user application implemented as a circuit. Although, progress in proof systems hasn't seemed to slow down either in the last year, so we're not worried just yet.

This year was also the year we helped people win $500,000 of prize by hosting one of the ZPrize category. The year our post on the Nova attack blew up, and the year we launched a number of projects: wasmati, zkBitcoin, and zkNews (which we will talk about in a later post).

Where will we be in a year? It's hard to say. While we started as an auditing firm, half of our time is now being spent doing dev work. With some work funded by grants through the Ethereum Foundation and the PSE team (which we'll talk in a later blogpost), and some work funded by Starkware (which we'll have more to say about in the near future).

If you're interested in joining the adventure, and you're into zero-knowledge proofs and security, you can apply by taking our zkBank challenge here!

Keep reading
Latest

The Year Finding and Exploiting Bugs Became Cheap, and What to Do About It

The economics of security have changed. AI has made finding and exploiting bugs cheaper, including in cryptographic and zero-knowledge code, while validation and remediation remain slow. Here is our view of what happened, what comes next, and how teams should change the way they secure their stack to defend against AI-assisted attackers.

Stefanos Chaliasos · September 07, 2026

Variants of KZG: Part V, Multilinear Commitments with Mercury

In this final post of the series, we extend univariate KZG commitments to multilinear polynomials through Mercury. Building on Gemini, we fold half of the variables at once, use polynomial division to bind this large fold to the original commitment and reduce the remaining multilinear evaluations to a batched inner product check. We then walk through the end-to-end opening protocol. We conclude by examining its proof size, prover cost and verifier cost.

Varun Thakore · August 17, 2026

Variants of KZG: Part IV, Multilinear Commitments with Gemini

In this blog post, we extend univariate KZG commitments to multilinear polynomials through Gemini. We introduce recursive partial evaluations, derive the split-and-fold identity and express each fold as a univariate identity that can be checked using KZG openings. We then walk through the end-to-end opening protocol. We conclude by examining its proof size, prover cost, and verifier cost.

Varun Thakore · August 12, 2026
Recommended

Uncovering and Fixing an Inflation Bug in Aleo

In November 2024, we found a significant inflation bug in the Aleo mainnet that could have allowed token minting without proper checks. We immediately informed the Aleo team, who swiftly addressed the issue with no detected exploitation. This post dives into the inner workings of Aleo and explains how transitions and records operate, providing insight into how the vulnerability was discovered and resolved. It's an intriguing look at blockchain security, zero-knowledge proofs, and the importance of thorough type checks to ensure robust protocol integrity.

Suneal Gong · February 19, 2025

Public report of Aleo's consensus (Bullshark)

We recently audited Aleo's blockchain consensus and found it to be impressively well-documented and high-quality. Our collaboration with Aleo's cooperative team helped us uncover several key issues, and the insights from this audit were well-received. In the blog, we dive into Aleo's Bullshark consensus protocol, explaining its step-by-step process and unique pipelining techniques. We also explore how leaders ensure commitments in even rounds and discuss essential aspects like quorum intersection and garbage collection. Whether you're a blockchain enthusiast or just curious about cutting-edge consensus protocols, this post has got some fascinating details to offer!

ZK/SEC · January 02, 2024

On ZK Security, ZK Summit, and a Decade of Progress

On May 7th, we'll be in Rome sponsoring zkSummit14. A look back at a decade of progress in zero-knowledge, the current state of ZK security based on 100+ audits, and why events like zkSummit have become infrastructure for the field.

ZK/SEC · May 06, 2026
More to explore

The State of Security Tools for ZKPs

Zero-knowledge proofs (ZKPs) have come a long way from theory to real-world applications like blockchains and private transactions. We’ve been busy auditing various ZKP implementations and developing tools to improve circuit safety and security. In this blog post, we’ll explore how vulnerabilities can crop up in SNARK systems and the current state of tools designed to spot these issues. From circuit bugs to the often-overlooked frontend and backend layers, we cover how various analysis techniques and formal verification approaches are evolving to ensure robust ZKP systems. Dive in to discover the potential and current challenges in ZKP security!

ZK/SEC · June 02, 2024

BitVM: Unlocking Arbitrary Computation on Bitcoin Through Circuit Abstractions

We're diving into the world of Bitcoin's UTXO model and how recent advancements like BitVM can overcome its limitations, allowing for more complex computations without changing Bitcoin's core. This blog post explores cutting-edge techniques like covenants, statefulness, and circuit models, showing how they enable intricate logic on Bitcoin. We'll break down how these innovations make trustless cross-chain transactions possible, and highlight the potential of optimistic protocols to optimize the on-chain footprint. If you're curious about the future of Bitcoin's capabilities, this is the deep dive you need!

Katat Choi · March 03, 2025

The Final Form of Software Development

What if the final form of software development was just watching code and proof popping up while you sip a drink? Letting AI agents write assembly directly alongside Lean proofs sidesteps the whole compiler-trust problem. With a peek at real EVM 256-bit addition code and its specification, you'll see why the assembly + Lean paradigm is final in both the historical and category theoretic sense.

Yoichi Hirai · April 29, 2026