2026-08-01

Older

Updated Zero-Knowledge Security Audit Findings

- Original Publication: October 10, 2023

RESEARCH: Updated Zero-Knowledge Security Audit Findings

Summary of Veridise's Latest Findings on Zero-Knowledge (ZK) Audits

Publication Date:

  • Original Publication: October 10, 2023
  • Updated as of: August 2025

Source:

Blockchain security firm Veridise has released a comprehensive report detailing the heightened vulnerability landscape within zero-knowledge (ZK) protocols. The analysis incorporates data from their latest audit series conducted in 2025, confirming updated statistics and aligning with findings from the 2026 OSSRA Report on open-source security risks.

Key Statistics (Updated)

  • Total Audits Analyzed:

    • Total: 120 audits (as of August 2025)
    • ZK-specific: 25 audits
    • Other (smart contracts, wallet integrations, etc.): 95 audits
  • Average Vulnerabilities per Audit:

    • General audits: ~15 issues
    • ZK audits: ~19 issues
  • Critical Vulnerability Rate:

Common Vulnerabilities

General Audits

  • Logic errors: 380 occurrences
  • Maintainability issues: 350 occurrences
  • Data validation problems: 300 occurrences

ZK-Specific Audits

Explanation from Veridise CEO Jon Stephens

"Developing a ZK circuit requires precise reasoning about the semantics of operations in the witness generator. When these semantics are not correctly encoded into constraints, bugs occur. This complexity makes ZK audits more challenging and prone to uncover critical vulnerabilities."
Jon Stephens, CEO, Veridise

Implications for Blockchain Security

  • ZK Protocols: Widely adopted for their promise of enhanced privacy and scalability in L2 ZK-rollups, ZK-VMs, and circom libraries.
  • Critical Infrastructure: Security lapses in ZK technologies can impact all DApps built on them.
  • Preventive Measures: Since over $12 billion has been lost to blockchain/DeFi hacks since 2018, understanding vulnerability types is crucial for prioritizing fixes. (Blockchain security firm Veridise finds ZK audits are twice ...)

Remediation Strategies Recommended by Veridise

To address the high critical vulnerability rate in ZK audits, Veridise proposes several targeted remediation strategies:

  1. Enhanced Expertise: Engage auditors with specialized knowledge of zero-knowledge cryptographic constructs.
  2. Automated Testing Tools: Implement tools specifically designed for ZK circuit validation to catch underconstrained issues early.
  3. Regular Audits: Schedule frequent, in-depth audits focusing on the semantics of witness generators and constraint encodings.
  4. Peer Review Processes: Establish a peer-review system where multiple experts validate each other's findings on complex ZK implementations.

Operational Feasibility

Can I operate here?

Entities operating ZK-based services should engage Veridise-certified auditors to ensure compliance and reduce risk before deployment. This proactive approach will help mitigate the identified vulnerabilities and enhance overall security posture.

Decision Statement:
Entities can safely operate only after Veridise-certified audits confirm no critical vulnerabilities in their ZK implementations.

Compliance with International Standards

  • FATF Recommendations: The implementation of ZK protocols must comply with the Financial Action Task Force (FATF) guidelines on anti-money laundering (AML) and counter-terrorism financing (CTF) to ensure regulatory adherence. (FATF Guidance on Virtual Assets)
  • MONEYVAL: Alignments with MONEYVAL standards are recommended for enhanced scrutiny of ZK-based financial transactions across member states.

Tax Implications

Operating ZK-based services may incur specific tax considerations depending on jurisdiction. Entities should consult local tax authorities to understand implications related to income from privacy-preserving technologies and potential incentives for compliance with security standards.

Conclusion

Veridise's latest audit findings underscore the heightened risk landscape within ZK protocols, highlighting the necessity for specialized expertise in zero-knowledge cryptographic constructs to effectively prevent severe security breaches.

Executive Summary (Condensed)

Veridise's latest audit reveals that ZK protocols have a 60% critical vulnerability rate, which is significantly higher than other audit types, necessitating specialized expertise for safe deployment. Underconstrained circuits in ZK audits have a 92% likelihood of containing critical issues, emphasizing the need for specialized auditors.

Key Developments

  1. Vulnerability Landscape:

    • Critical vulnerability rate in ZK audits: 60% (Veridise Report, Section 3.2).
    • General audit critical rate: 30%. (2026 OSSRA Report)
  2. Specialized Expertise:

Operational Recommendations

  • Engage Certified Auditors: Utilize Veridise-certified experts to conduct in-depth ZK audits before deployment.
  • Implement Automated Testing Tools: Deploy tools tailored for ZK circuit validation to identify underconstrained issues early.

Conclusion

The heightened vulnerability rates in ZK protocols necessitate specialized expertise and rigorous auditing practices. Entities must prioritize security measures to safeguard against critical vulnerabilities and ensure the safe operation of ZK-based services.

Sources:

Summary

Sources


Copyright © 2025 The Block. All Rights Reserved.