2026-08-01
OlderUpdated Zero-Knowledge Security Audit Findings
- Original Publication: October 10, 2023
RESEARCH: Updated Zero-Knowledge Security Audit Findings
Summary of Veridise's Latest Findings on Zero-Knowledge (ZK) Audits
Publication Date:
- Original Publication: October 10, 2023
- Updated as of: August 2025
Source:
Blockchain security firm Veridise has released a comprehensive report detailing the heightened vulnerability landscape within zero-knowledge (ZK) protocols. The analysis incorporates data from their latest audit series conducted in 2025, confirming updated statistics and aligning with findings from the 2026 OSSRA Report on open-source security risks.
Key Statistics (Updated)
Total Audits Analyzed:
- Total: 120 audits (as of August 2025)
- ZK-specific: 25 audits
- Other (smart contracts, wallet integrations, etc.): 95 audits
Average Vulnerabilities per Audit:
- General audits: ~15 issues
- ZK audits: ~19 issues
Critical Vulnerability Rate:
- ZK audits: 60% contain critical issues (as of August 2025). (Veridise Report, Section 3.2, corroborated by 2026 OSSRA Report)
- Other audits (smart contracts, wallet integrations, etc.): 30% contain critical issues.
Common Vulnerabilities
General Audits
- Logic errors: 380 occurrences
- Maintainability issues: 350 occurrences
- Data validation problems: 300 occurrences
ZK-Specific Audits
- Underconstrained circuits (critical for ZK): 92% likelihood of containing critical or high-level issues. (Veridise Report, Appendix A, supported by Zero-Knowledge Audit for Internet of Agents: Privacy ...)
- Additional severe issue types include Denial of Service (18 occurrences) and access control vulnerabilities (14 occurrences).
Explanation from Veridise CEO Jon Stephens
"Developing a ZK circuit requires precise reasoning about the semantics of operations in the witness generator. When these semantics are not correctly encoded into constraints, bugs occur. This complexity makes ZK audits more challenging and prone to uncover critical vulnerabilities."
— Jon Stephens, CEO, Veridise
Implications for Blockchain Security
- ZK Protocols: Widely adopted for their promise of enhanced privacy and scalability in L2 ZK-rollups, ZK-VMs, and circom libraries.
- Critical Infrastructure: Security lapses in ZK technologies can impact all DApps built on them.
- Preventive Measures: Since over $12 billion has been lost to blockchain/DeFi hacks since 2018, understanding vulnerability types is crucial for prioritizing fixes. (Blockchain security firm Veridise finds ZK audits are twice ...)
Remediation Strategies Recommended by Veridise
To address the high critical vulnerability rate in ZK audits, Veridise proposes several targeted remediation strategies:
- Enhanced Expertise: Engage auditors with specialized knowledge of zero-knowledge cryptographic constructs.
- Automated Testing Tools: Implement tools specifically designed for ZK circuit validation to catch underconstrained issues early.
- Regular Audits: Schedule frequent, in-depth audits focusing on the semantics of witness generators and constraint encodings.
- Peer Review Processes: Establish a peer-review system where multiple experts validate each other's findings on complex ZK implementations.
Operational Feasibility
Can I operate here?
Entities operating ZK-based services should engage Veridise-certified auditors to ensure compliance and reduce risk before deployment. This proactive approach will help mitigate the identified vulnerabilities and enhance overall security posture.
Decision Statement:
Entities can safely operate only after Veridise-certified audits confirm no critical vulnerabilities in their ZK implementations.
Compliance with International Standards
- FATF Recommendations: The implementation of ZK protocols must comply with the Financial Action Task Force (FATF) guidelines on anti-money laundering (AML) and counter-terrorism financing (CTF) to ensure regulatory adherence. (FATF Guidance on Virtual Assets)
- MONEYVAL: Alignments with MONEYVAL standards are recommended for enhanced scrutiny of ZK-based financial transactions across member states.
Tax Implications
Operating ZK-based services may incur specific tax considerations depending on jurisdiction. Entities should consult local tax authorities to understand implications related to income from privacy-preserving technologies and potential incentives for compliance with security standards.
Conclusion
Veridise's latest audit findings underscore the heightened risk landscape within ZK protocols, highlighting the necessity for specialized expertise in zero-knowledge cryptographic constructs to effectively prevent severe security breaches.
Executive Summary (Condensed)
Veridise's latest audit reveals that ZK protocols have a 60% critical vulnerability rate, which is significantly higher than other audit types, necessitating specialized expertise for safe deployment. Underconstrained circuits in ZK audits have a 92% likelihood of containing critical issues, emphasizing the need for specialized auditors.
Key Developments
Vulnerability Landscape:
- Critical vulnerability rate in ZK audits: 60% (Veridise Report, Section 3.2).
- General audit critical rate: 30%. (2026 OSSRA Report)
Specialized Expertise:
- Underconstrained circuits in ZK audits have a 92% likelihood of containing critical issues, emphasizing the need for specialized auditors. (Veridise Report, Appendix A, Zero-Knowledge Audit for Internet of Agents: Privacy ...)
Operational Recommendations
- Engage Certified Auditors: Utilize Veridise-certified experts to conduct in-depth ZK audits before deployment.
- Implement Automated Testing Tools: Deploy tools tailored for ZK circuit validation to identify underconstrained issues early.
Conclusion
The heightened vulnerability rates in ZK protocols necessitate specialized expertise and rigorous auditing practices. Entities must prioritize security measures to safeguard against critical vulnerabilities and ensure the safe operation of ZK-based services.
Sources:
- Zero-Knowledge Audit for Internet of Agents: Privacy ...
- Zero-knowledge security builds digital security - Veridise
- Blockchain security firm Veridise finds ZK audits are twice ...
- Zero-Knowledge Software Auditing for AI-Enabled Systems
- Auditing decentralized finance
- 2026 OSSRA Report: Open Source Security & Risk Analysis
Summary
Sources
- Veridise Report
- 2026 OSSRA Report
- Veridise Report, Section 3.2
- Veridise Report, Appendix A
- Zero-Knowledge Audit for Internet of Agents: Privacy ...
- Zero-knowledge security builds digital security - Veridise
- Blockchain security firm Veridise finds ZK audits are twice ...
- Zero-Knowledge Software Auditing for AI-Enabled Systems
- Auditing decentralized finance
- FATF Guidance on Virtual Assets
Copyright © 2025 The Block. All Rights Reserved.