ZK/SEC Research notes from zkSecurity
All posts
announcement

Ditch the Pump & Dump Drama: Your ZK Tech Hub Awaits

Today we're announcing the release of our new project, zkNews, a zero-knowledge link aggregator for the community. We're excited to bring you a platform where you can find all the latest news, research, and projects in the zero-knowledge space.

zknews

The zero-knowledge (ZK) space is exploding, and it can be tough to keep up with the latest developments. That's why we're thrilled to introduce zkNews – your one-stop shop for all things ZK.

What is zkNews?

zkNews is a zero-knowledge link aggregator designed specifically for the ZK community. It's your go-to source for:

  • Breaking news: Stay ahead of the curve with the most recent ZK announcements and breakthroughs.
  • In-depth research: Dive into the latest academic papers and technical discussions shaping the ZK landscape.
  • Cutting-edge projects: Discover new ZK tools, platforms, and applications pushing the boundaries of privacy and scalability.

Join the Beta!

We're launching zkNews in beta mode, and we want your feedback! Head over to https://news.zksecurity.xyz to start exploring. While we're in beta, access is limited to a smaller group of users, but we'll be expanding soon.

Your Feedback is Invaluable

We're committed to making zkNews the best resource for the ZK community. Tell us what you think! Share your suggestions, report any bugs, and let us know what kind of content you'd like to see more of.

Stay Tuned!

This is just the beginning. We have big plans for zkNews, including personalized recommendations, community features, and more. Follow us on twitter for updates and announcements.

Keep reading
Recommended

SoK: What don’t we know? Understanding Security Vulnerabilities in SNARKs

We've teamed up with some of the top minds in academia and industry to dive deep into the world of zero-knowledge proofs (ZKPs) and their vulnerabilities. Our new paper catalogues hundreds of ZK vulnerabilities, breaking down their root causes and offering strategies to sidestep these pitfalls. By digging into real-life SNARK implementations, we aim to bolster the security of these cutting-edge systems with actionable insights and recommendations. Curious about what makes ZKPs tick and how to keep them secure? You might find this study just what you need!

ZK/SEC · February 26, 2024

Listen to us on the latest episode of zeroknowledge.fm

Join our cofounder David Wong on the latest zk podcast as he dives into his compelling journey through cryptography, from his early days as a security consultant to his pivotal roles in major projects like Facebook's crypto initiatives and Mina. Get an insider's view on how we approach auditing in a Zero Knowledge context, the common pitfalls in ZK code, and how these insights shape our work. It's an engaging and informative chat for anyone fascinated by the world of cryptography and ZK technology!

ZK/SEC · August 30, 2023

The State of Security Tools for ZKPs

Zero-knowledge proofs (ZKPs) have come a long way from theory to real-world applications like blockchains and private transactions. We’ve been busy auditing various ZKP implementations and developing tools to improve circuit safety and security. In this blog post, we’ll explore how vulnerabilities can crop up in SNARK systems and the current state of tools designed to spot these issues. From circuit bugs to the often-overlooked frontend and backend layers, we cover how various analysis techniques and formal verification approaches are evolving to ensure robust ZKP systems. Dive in to discover the potential and current challenges in ZKP security!

ZK/SEC · June 02, 2024
More to explore

Nine Years to Halve a Hash Function: RFC 9861 Is Out

After nearly a decade in the making, RFC 9861: KangarooTwelve and TurboSHAKE was officially published in October 2025, with zkSecurity among its editors. This post explains why these hash functions deserve to be far more widely used than they are today. Built on the same Keccak permutation as SHA-3 and SHAKE but with the round count halved, they do the same job at the same security level roughly twice as fast. We cover why halving the rounds is safe, what the RFC actually defines, the caveats around FIPS compliance and workload-dependent speedups, and why a standard like this took nine years to land.

David Wong · July 21, 2026

Uncovering the Phantom Challenge Soundness Bug in Solana's ZK ElGamal Proof Program

In June 2025, we uncovered a serious soundness issue in Solana's ZK ElGamal Proof Program that could let attackers manipulate confidential token transfers undetected. We worked with the Anza team to quickly address the flaw by pausing and disabling vulnerable components. This post dives into the root cause, which was a subtle mistake in handling prover-generated challenges within sigma OR proofs, revealing broader lessons in zero-knowledge protocol security. If you're interested in cryptographic protocol design, this could provide valuable insights.

Suneal Gong · June 26, 2025

A challenge on the Jolt zkVM

Last weekend, we had a blast crafting challenges for a CTF event at the MOCA Italian hacker camp. One cryptography challenge, "2+2=5," involved the Jolt zkVM and a RISC-V program. In this post, we share the ins and outs of the challenge, the clever use of a modified Jolt library, and how we managed to prove an invalid execution without triggering verification alarms. Get ready to dive into the world of Jolt and pick up some nifty insights on exploiting cryptographic systems like a true hacker.

Giorgio Dell'Immagine · September 24, 2024