ZK/SEC Research notes from zkSecurity
All series
Series

AI meets Cryptography

3 parts July 2026 45 min in total Stefanos Chaliasos · Hao Pham · False Witness team · False Witness Team
  1. Part 1

    AI meets Cryptography 1: What AI Found in Cloudflare's CIRCL

    We pointed our AI audit pipeline at Cloudflare's CIRCL experimental cryptography library and confirmed seven real bugs, from a critical float64 precision loss in threshold RSA to a complete access-control break in attribute-based encryption. All seven are now fixed upstream. This is the first post in a series on bugs our agents found across open source cryptography.

  2. Part 2

    AI meets Cryptography 2: What AI Found in OpenVM's zkVM

    We turned zkao (our AI auditor) on OpenVM, a state-of-the-art zkVM, and it found a critical soundness bug: the pairing check accepted a prover-supplied witness without proper subfield checking, which lets a malicious prover forge any pairing equality. It is fixed in OpenVM 1.6.0 and tracked as CVE-2026-46669. This is the second post in our series on bugs our agents found across open source cryptography.

  3. Part 3

    AI meets Cryptography 3: What AI Found in Bron Labs's bron-crypto

    We pointed our AI audit pipeline at bron-crypto, Bron Labs's Go library for MPC and threshold signatures, and confirmed four bugs. All of them are now fixed upstream. This is the third post in our series on bugs our agents found across open source cryptography.

Other series see all →