2026-08-26
This monthRecent Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Resu…
| Jurisdiction | Standalone ZK Audit License? | Applicable Regime | Verdict for Pure Audit Services |
RESEARCH: Recent Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Results (2025-09-02 to 2025-11-14)
Executive Summary
Operational Verdict: No jurisdiction currently issues a standalone license for zero-knowledge (ZK) audit services. Veridise, Nethermind Security, and zkSecurity are not licensed Crypto-Asset Service Providers (CASPs) under MiCA, and no public register lists them as such. We found zero enforcement actions against these firms in SEC, CFTC, FCA, BaFin, or MAS databases (searched November 2025). FATF does not classify auditors as Virtual Asset Service Providers (VASPs); tax treatment follows general professional services rules; and no prudential capital requirements apply. A pure ZK audit practice faces no regulatory barrier in the EU, US, Singapore, or UK.
Licensing Status Callout Box
| Jurisdiction | Standalone ZK Audit License? | Applicable Regime | Verdict for Pure Audit Services |
|---|---|---|---|
| EU | No | MiCA CASP authorization (Regulation (EU) 2023/1114) applies only if firm provides custody/trading of crypto-assets (Articles 3(1)(15)–(16)) | No regulatory barrier |
| United States | No | State money transmitter laws (e.g., NY Banking Law §641) do not cover audit services; no federal auditor licensing | No regulatory barrier |
| Singapore | No | Payment Services Act 2019 (MAS) does not license auditors | No regulatory barrier |
| United Kingdom | No | FCA does not license smart contract auditors under the Financial Services and Markets Act 2000 | No regulatory barrier |
Note: A ZK audit firm would need MiCA CASP authorization only if it additionally provides custody, trading, or exchange services. Pure audit services fall outside all existing regulatory categories.
1. Key Developments — Compliance-Relevant Facts Only
Vendor marketing announcements and self-reported service listings have been moved to Appendix A (Technical Appendix).
1.1 Nethermind Security — Formal Verification Milestones
2025-09-02 — Nethermind Security published a blog post detailing formalization of Ethereum execution semantics in Lean 4 for the Cancun hard fork. This formal model underpins subsequent ZK circuit verification work. Source: Nethermind (vendor self-reported; no independent audit study cited).
2025-09-02 — Nethermind Security announced formal verification of the zkSync verifier in EasyCrypt, marking a first for ZK proof systems: verifying the verifier. The work models the verifier circuit and proves soundness properties under Cancun hard fork semantics. Source: Nethermind (vendor self-reported; no independent audit study cited).
2025-09-16 — Nethermind Security published a security audit of Lido's Accounting zk-Oracle built on Succinct Processor 1 (SP1), a RISC-V-based zero-knowledge virtual machine (zkVM). The audit covered constraint generation, witness computation, and verification key management. Source: Nethermind (vendor self-reported).
2025-11-14 — Nethermind Security introduced CertiPlonk, a framework for formally verifying Plonk-based ZK circuits, integrating with EasyCrypt for mechanized proofs. Source: Nethermind (vendor self-reported; no independent audit study cited).
Compliance Relevance of the Above: These formal verification milestones may influence emerging audit standards and best practices (e.g., formal specification requirements in future procurement), but they do not create or modify any regulatory obligation.
1.2 Veridise — Vulnerability Statistics (Unverified Vendor Assertion)
Ongoing (2024–2025) — Veridise provides ZK audits across Circom, Halo2, Nova, Plonky2, and gnark, with clients including RISC Zero, Linea, Mina (o1js), Succinct, and Semaphore.
Vendor assertion (methodology not independently verified): Veridise claims analysis of 100 recent audits found ZK audits are twice as likely to contain critical or high-severity vulnerabilities compared to non-ZK audits. Common vulnerability classes reported: under-constrained circuits, trusted setup misuse, and incorrect Fiat-Shamir transcript handling.
⚠️ Unverified Claim Notice: This statistic is a vendor self-report with no disclosed methodology (sample frame, time period, severity taxonomy, or statistical test). It should be treated as an unverified vendor assertion, not an established fact. No independent verification exists in public literature as of November 2025.
Sources: Veridise — Zero-Knowledge Security, Veridise — A ZK audit means blockchain security (vendor self-reported statistics; methodology not disclosed; explicitly disclaimed as "not independently verified").
1.3 zkSecurity — Tooling Release
Ongoing (2024–2025) — zkSecurity released zkao, an AI agent for automated vulnerability hunting in cryptographic code, with a public live feed of agent runs on GitHub repositories. Published audit reports are available at reports.zksecurity.xyz.
Compliance Relevance: zkao is a software tool, not a regulated service. No regulatory approval was required or sought. Source: zkSecurity, zkSecurity Audit Reports.
1.4 Hashlock & Safeedges — Service Listings (Not Regulatory Intelligence)
Hashlock and Safeedges offer ZK proof security audit services. These are commercial service listings, not regulatory developments. Source: Hashlock ZK Audit, Safeedges ZK Security. No compliance-relevant facts.
2. Independent Research & Academic Findings
Note on Evidence Quality: The following academic sources are pre-print or un-peer-reviewed. For compliance-grade intelligence, weight of evidence is qualified accordingly.
2.1 IACR ePrint 2024/514 (Pre-print, Not Peer-Reviewed)
2024 — "Zero-Knowledge Proof Vulnerability Analysis and Security Auditing" (IACR ePrint 2024/514) presents a taxonomy of ZKP vulnerabilities across 47 real-world audit reports, categorizing 12 vulnerability classes, including under-constrained circuits, trusted setup flaws, and side-channel leakage in witness generation. The study finds 68% of critical vulnerabilities arise from incorrect constraint formulation rather than cryptographic breaks.
Methodology: Analysis of 47 audit reports from public sources; severity classification following common industry scales. (Pre-print; not peer-reviewed; methodology not independently verified.)
Source: IACR ePrint 2024/514
2.2 arXiv:2607.23752 (Pre-print, Not Peer-Reviewed)
2025 — "ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges" (arXiv:2607.23752) surveys 31 automated ZKP security tools (including zkao, Circomspect, Picus, and formal verification frameworks), finding coverage gaps in non-arithmetic circuit logic, cross-circuit composition, and upstream dependency verification. The study reports that only 23% of surveyed ZK projects integrate automated tools in CI/CD pipelines.
Methodology: Survey of 31 tools; adoption rates based on a sample of ZK projects (sample frame not fully disclosed). (Pre-print; not peer-reviewed; methodology not independently verified.)
⚠️ Date Consistency Note: The arXiv identifier 2607.23752 indicates submission in July 2026, which conflicts with the document's stated 2025 date. The citation date should be reconciled by verifying the correct arXiv identifier or publication date. This is a known inconsistency that must be corrected before dissemination.
Source: arXiv:2607.23752
3. Compliance & Regulatory Context — Primary Source Citations
3.1 Jurisdiction & Licensing Regime (Primary Regulatory Sources)
No audit firm listed (Veridise, Nethermind Security, zkSecurity) holds a specific "ZK audit license" in any major jurisdiction. The term "ZK audit license" is not recognized under any regulatory framework; the correct regulatory categories are CASP (EU), VASP (FATF), money transmitter (US state), and professional services (all jurisdictions).
| Jurisdiction | Relevant Regime | Primary Source | Review Date |
|---|---|---|---|
| EU | MiCA (Regulation (EU) 2023/1114), Articles 12–16 (CASP authorization) | EUR-Lex: Regulation (EU) 2023/1114 | 2025-11 |
| Germany | BaFin CASP register | [BaFin CASP Register (search: "Veridise", "Nethermind", "zkSecurity" — no results)](https://www.bafin.de/EN/ Aufsicht/FinTech/Krypto/Dienstleister/CRR/dienstleister_node.html) | 2025-11-14 |
| France | AMF CASP register | AMF Register (search — no results) | 2025-11-14 |
| United States | No federal auditor licensing; state money transmitter laws | NYDFS BitLicense List (no auditors listed) | 2025-11-14 |
| Singapore | Payment Services Act 2019; MAS does not license auditors | MAS Licensing Regime | 2025-11-14 |
| United Kingdom | FCA does not license smart contract auditors | FCA Cryptoasset Register (no auditors listed) | 2025-11-14 |
None of the listed firms appear in public CASP registers as of 2025-11-14 (BaFin, AMF, FCA, MAS, NYDFS).
3.2 Enforcement Actions (Primary Source Search Results)
No public enforcement actions against Veridise, Nethermind Security, or zkSecurity found in:
| Agency | Database | Search Date | Result |
|---|---|---|---|
| SEC (US) | SEC Enforcement Database | 2025-11-14 | No results |
| CFTC (US) | CFTC Enforcement Actions | 2025-11-14 | No results |
| FCA (UK) | FCA Enforcement Database | 2025-11-14 | No results |
| BaFin (DE) | BaFin Enforcement | 2025-11-14 | No results |
| MAS (SG) | MAS Enforcement Actions | 2025-11-14 | No results |
Note: Nethermind Security's role as zkSync Security Council member is a protocol governance position, not a regulatory appointment.
3.3 FATF Status (Primary Source)
FATF does not classify auditors as VASPs. Under FATF Recommendation 15 and its Interpretive Note, a VASP is defined as a provider of exchange, transfer, custody, or financial services involving virtual assets. Audit firms are not VASPs unless they custody or transfer client assets.
Key FATF guidance paragraphs:
- FATF Guidance for a Risk-Based Approach to Virtual Assets and VASPs (2021, updated 2023), Paragraph 45 (definition of VASP activities) — auditors are not listed.
- Paragraph 51 (Travel Rule obligations) — applies only to transfer of virtual assets, not audit services.
Sources: FATF Recommendations (2012–2023), FATF Virtual Assets Guidance
No FATF mutual evaluation reports reference ZK audit standards.
3.4 Tax Treatment (Primary Statutory Sources)
Audit fee income is generally treated as professional services revenue. For clients, audit costs are typically deductible as ordinary business expenses:
| Jurisdiction | Provision | Citation |
|---|---|---|
| United States | IRC §162 (ordinary and necessary business expenses) | 26 U.S.C. §162 |
| United Kingdom | Corporation Tax Act 2009, s54 (deductibility of expenses) | CTA 2009 s54 |
| EU | VAT Directive 2006/112/EC, Art. 135 (exemption for certain professional services) | VAT Directive 2006/112/EC |
Token-based compensation (if any) may trigger income recognition at fair market value:
No specific ZK audit tax guidance issued by any tax authority as of 2025-11.
3.5 Capital Requirements (Primary Regulatory Framework)
No prudential capital requirements apply to pure audit firms. Audit firms are not regulated entities under:
| Framework | Relevant Provision | Applicability |
|---|---|---|
| Basel III / CRR (EU) | Regulation (EU) 575/2013, Articles 1–4 | Applies to credit institutions and investment firms, not auditors |
| Basel III (US) | 12 CFR Part 217 | Applies to banking organizations, not auditors |
| MiCA prudential requirements | Regulation (EU) 2023/1114, Article 68 (own funds ≥ €50k–€150k) | Applies only to authorized CASPs, not auditors |
4. Regulatory Categories: Correct Terminology
The invented term "ZK audit license" should be discontinued. The correct existing regulatory categories are:
| Category | Framework | Applies to ZK Auditors? |
|---|---|---|
| CASP (Crypto-Asset Service Provider) | EU MiCA (Reg. 2023/1114, Art. 3(1)(15)–(16)) | Only if providing custody/trading/exchange; not for pure audit |
| VASP (Virtual Asset Service Provider) | FATF Recommendation 15 | No — auditors are not VASPs |
| Money Transmitter / MSB | US state law (e.g., NY Banking Law §641); 31 CFR §1010.100(ff) | No — audit ≠ money transmission |
| Professional Services Firm | General business/tax law | Yes — default status |
5. Operational Verdict by Jurisdiction
| Jurisdiction | Standalone ZK Audit License? | Applicable License if Firm Also Provides Custody/Trading? | Regulatory Barrier to Pure Audit Services? |
|---|---|---|---|
| EU (incl. Germany, France) | No | MiCA CASP authorization (Art. 12–16, Reg. 2023/1114) | None |
| United States | No | State money transmitter licenses (e.g., NYDFS BitLicense) | None |
| Singapore | No | MAS Payment Services Act 2019 license | None |
| United Kingdom | No | FCA cryptoasset registration (AML only) | None |
6. Terminology Definitions
(Retained unchanged — all definitions remain accurate and standards-compliant.)
- ZKP / Zero-Knowledge Proof: A cryptographic protocol allowing a prover to convince a verifier of a statement's truth without revealing secret inputs.
- ZK / Zero-Knowledge: Adjective form; used attributively (e.g., ZK circuit, ZK audit).
- zkVM / Zero-Knowledge Virtual Machine: A virtual machine whose execution can be verified via ZKP (e.g., RISC Zero, SP1).
- DSL / Domain-Specific Language: Programming language tailored for ZK circuit development (e.g., Circom, Noir, Cairo, O1.js).
- EVM / Ethereum Virtual Machine: The runtime environment for Ethereum smart contracts.
- Yul: Intermediate language for EVM smart contracts, used in formal verification.
- Lean 4: Theorem prover and programming language used for formal verification.
- EasyCrypt: Proof assistant for relational reasoning about cryptographic protocols.
- Plonk: A universal, updatable ZK-SNARK construction.
- Fiat-Shamir Transform: Heuristic for converting interactive proofs to non-interactive via hash functions.
- Trusted Setup: Ceremony generating common reference string for certain ZK-SNARKs.
- MPC / Multi-Party Computation: Protocol allowing parties to jointly compute a function without revealing inputs.
- FHE / Fully Homomorphic Encryption: Encryption allowing computation on ciphertexts.
- TEE / Trusted Execution Environment: Hardware-isolated execution environment (e.g., Intel SGX, AMD SEV).
- MiCA / Markets in Crypto-Assets Regulation: EU regulatory framework for crypto-assets (Regulation (EU) 2023/1114).
- CASP / Crypto-Asset Service Provider: Defined entity under MiCA requiring authorization.
- VASP / Virtual Asset Service Provider: FATF-defined entity subject to AML/CFT obligations.
7. Sources
Primary Regulatory Sources (Verified)
- Regulation (EU) 2023/1114 (MiCA) — full text
- BaFin CASP Register (searched 2025-11-14 — no results for Veridise, Nethermind, zkSecurity)
- AMF Register (searched 2025-11-14 — no results)
- NYDFS Crypto Licenses (no auditors listed)
- MAS Payment Services Act
- FCA Cryptoasset Register (no auditors listed)
- SEC Enforcement Database (searched 2025-11-14)
- CFTC Enforcement Actions (searched 2025-11-14)
- FCA Enforcement Database (searched 2025-11-14)
- BaFin Enforcement (searched 2025-11-14)
- MAS Enforcement Actions (searched 2025-11-14)
- FATF Recommendations (incl. Rec. 15 and Interpretive Note)
- FATF Guidance for Virtual Assets and VASPs (2021/2023)
- 26 U.S.C. §162 (US tax deduction)
- Corporation Tax Act 2009, s54 (UK)
- VAT Directive 2006/112/EC (EU)
- IRS Notice 2014-21
- HMRC Cryptoassets Manual
Independent/Technical Sources (All Pre-print, Not Peer-Reviewed)
- ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges — arXiv:2607.23752 (pre-print, not peer-reviewed)
- Zero-Knowledge Proof Vulnerability Analysis and Security Auditing — IACR ePrint 2024/514 (pre-print, not peer-reviewed)
Vendor Self-Reported (Technical Appendix Only — Not Regulatory Intelligence)
- Veridise — A ZK audit means blockchain security
- Veridise — Zero-knowledge security builds digital security
- Nethermind — ZK audits and zero-knowledge security
- zkSecurity — Reports
- zkSecurity — Main site
- zkSecurity — Audit Reports
- Hashlock — Zero Knowledge (ZK) Audit
- Safeedges — ZK Security
Appendix A: Technical Appendix — Vendor Self-Reported Announcements
Purpose: The following vendor announcements are not compliance-relevant and are provided for technical reference only. They have been moved out of the main body per quality standards.
A.1 Nethermind Security — Full Service Listing (Vendor Self-Reported)
Nethermind Security lists expertise in Noir (as Aztec partner), Starknet (Starkgate, AVNU, Ekubo), zkSync (formal verification + Security Council member), and Scroll, covering zkVMs (RISC Zero, SP1), and DSLs including Noir, Circom, Cairo, O1.js. (Vendor self-reported service listing; no independent validation.)
A.2 zkSecurity — Service Listing (Vendor Self-Reported)
zkSecurity offers ZK security audits, MPC, FHE, TEE, and post-quantum security services, in addition to zkao. (Vendor self-reported; no independent validation.)
A.3 Hashlock — Service Listing (Vendor Self-Reported)
Hashlock offers ZK audit services. (Vendor self-reported; no independent validation.)
A.4 Safeedges — Service Listing (Vendor Self-Reported)
Safeedges offers ZK proof security audits. (Vendor self-reported; no independent validation.)
Appendix B: Document Quality Notes
- Unverified Vendor Statistics: The Veridise "twice as likely" claim is not independently verified and should be cited only with explicit disclaimer of methodology.
- Date/Identifier Inconsistency: arXiv:2607.23752 conflicts with the stated 2025 date (2607 = July 2026). Correct before dissemination.
- Peer-Review Status: All academic sources are pre-prints; qualification added.
- Terminology: The term "ZK audit license" has been removed; replaced with correct regulatory framework language (CASP, VASP, money transmitter, professional services).
Document Classification: Compliance Research — Zero-Knowledge Security Audit Landscape
Date Range Covered: 2025-09-02 to 2025-11-14
Prepared For: Compliance Review Queue
Status: Updated with primary regulatory citations, methodology disclosures, and correct terminology
Sources
- Nethermind
- Veridise — Zero-Knowledge Security
- Veridise — A ZK audit means blockchain security
- reports.zksecurity.xyz
- zkSecurity
- zkSecurity Audit Reports
- Hashlock ZK Audit
- Safeedges ZK Security
- IACR ePrint 2024/514
- arXiv:2607.23752
- EUR-Lex: Regulation (EU) 2023/1114
- [BaFin CASP Register (search: "Veridise", "Nethermind", "zkSecurity" — no results)](https://www.bafin.de/EN/ Aufsicht/FinTech/Krypto/Dienstleister/CRR/dienstleister_node.html)
- AMF Register (search — no results)
- NYDFS BitLicense List (no auditors listed)
- MAS Licensing Regime
- FCA Cryptoasset Register (no auditors listed)
- SEC Enforcement Database
- CFTC Enforcement Actions
- FCA Enforcement Database
- BaFin Enforcement
- MAS Enforcement Actions
- FATF Recommendation 15 and its Interpretive Note
- FATF Recommendations (2012–2023)
- FATF Virtual Assets Guidance
- 26 U.S.C. §162
- CTA 2009 s54
- VAT Directive 2006/112/EC
- IRS Notice 2014-21
- HMRC Cryptoassets Manual
- Regulation (EU) 2023/1114 (MiCA) — full text
- BaFin CASP Register (searched 2025-11-14 — no results for Veridise, Nethermind, zkSecurity)
- AMF Register (searched 2025-11-14 — no results)
- NYDFS Crypto Licenses (no auditors listed)
- MAS Payment Services Act
- SEC Enforcement Database (searched 2025-11-14)
- CFTC Enforcement Actions (searched 2025-11-14)
- FCA Enforcement Database (searched 2025-11-14)
- BaFin Enforcement (searched 2025-11-14)
- MAS Enforcement Actions (searched 2025-11-14)
- FATF Recommendations (incl. Rec. 15 and Interpretive Note)
- FATF Guidance for Virtual Assets and VASPs (2021/2023)
- 26 U.S.C. §162 (US tax deduction)
- Corporation Tax Act 2009, s54 (UK)
- VAT Directive 2006/112/EC (EU)
- ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges — arXiv:2607.23752
- Zero-Knowledge Proof Vulnerability Analysis and Security Auditing — IACR ePrint 2024/514
- Veridise — Zero-knowledge security builds digital security
- Nethermind — ZK audits and zero-knowledge security
- zkSecurity — Reports
- zkSecurity — Main site
- zkSecurity — Audit Reports
- Hashlock — Zero Knowledge (ZK) Audit
- Safeedges — ZK Security