ZK/SEC Research notes from zkSecurity
All series
Series

zkvmBlast

1 part August 2026 17 min in total Stefanos Chaliasos · Martín Ochoa · Varun Thakore
  1. Part 1

    Introducing zkvmBlast: Differential Fuzzing for Ethereum's zkVMs

    zkVMs are moving to the center of Ethereum's roadmap, which means a bug in a zkVM is turning into a bug in Ethereum itself. We built zkvmBlast, a zkVM-agnostic differential fuzzer that runs the same program across SP1, RISC0, OpenVM, Pico, Zisk, and Airbender against a reference simulator and flags any disagreement. It hunts for both soundness and completeness bugs, with a deliberate focus on completeness, an under-explored class that can turn a single valid block into a liveness failure. We share the first batch of findings.

Other series see all →