# zkao 2.0 is here

- **Authors**: zk/sec, False Witness team
- **Date**: July 24, 2026
- **Tags**: zkao, security, zk, AI, announcement

Today we're releasing **zkao 2.0**, the biggest update to [zkao](https://zkao.io) since we [launched it](https://blog.zksecurity.xyz/posts/zkao-launch/) earlier this year. If you're new here: zkao is the automated bug-finding tool we created to find bugs in cryptography applications, and it has already caught critical bugs in the production code of many of our clients. With 2.0 we're opening it up to many more users who want to scan their own code, and at a fraction of the cost of an audit, trying it is a no-brainer. This release comes with a new pricing model, a complete redesign, and a ton of improvements under the hood.

## Pay as you go, no more subscriptions

The change we're most excited about: **zkao is now pay-as-you-go**. We're dropping subscriptions entirely.

Since day one, zkao has been built around the idea that AI security research works like fuzzing: a single scan is a coin flip, and coverage comes from running it again and again. But a monthly subscription never quite matched how people actually use a tool like that. Some weeks you're shipping a new circuit and want to hammer it with scans, other weeks nothing changes and you shouldn't be paying for idle time.

So now you simply buy credits and spend them on scans, whenever you want, at whatever tier you want (including our most thorough tier, "zkao max"). No recurring charge, no seat count, no lock-in. Your credits don't expire, and your scan history, findings, and reports stay with you.

> [!NOTE] Existing subscribers
> If you're on a subscription today, you don't need to do anything: your remaining subscription time is automatically converted into credits.

## A new design

zkao 2.0 also ships with a complete redesign of the app. Connecting a repository, kicking off a scan, and triaging findings now take fewer clicks, and the interface got a full visual overhaul to match.

The best way to appreciate the difference is to look at where we came from. Back in June we recorded a deep-dive walkthrough of zkao 1.2.0, and it's now a nice time capsule of the old design:

Everything shown in that video is still there, just faster and better looking: tiered AI-powered scans, collaborative agents that learn from your feedback to cut down on false positives, tooling to triage real bugs like proof forgeries, and public security reports you can share with your users.

## And tons of improvements

Beyond pricing and design, 2.0 rolls up months of shipping across the whole product: smarter scanning agents informed by our latest audits, better deduplication of findings across runs, and countless quality-of-life fixes in triaging and reporting. It also builds on the ecosystem work we've been doing recently, like [bringing Aleo and Leo into zkao](https://blog.zksecurity.xyz/posts/zkao-aleo-integration/).

> [!TIP] Try it
> Head over to [zkao](https://zkao.io), connect a repo, and run your first scan. With pay-as-you-go there's no commitment: buy a few credits and see what it finds.

The goal hasn't changed since launch: bridge the gap between expensive one-shot manual audits and continuous security that compounds over time. zkao 2.0 just makes that a lot easier to use, and a lot easier to pay for.

---

This article was published on the [ZK/SEC Quarterly](https://blog.zksecurity.xyz) blog by [ZK Security](https://www.zksecurity.xyz), a leading security firm specialized in zero-knowledge proofs, MPC, FHE, and advanced cryptography. ZK Security has audited some of the most critical ZK systems in production, discovered vulnerabilities in major protocols including Aleo, Solana, and Halo2, and built open-source tools like [Clean](https://github.com/Verified-zkEVM/clean) for formally verified ZK circuits. For more articles, see the [full list of posts](https://blog.zksecurity.xyz/llms.txt).
