2026-08-26

This month

Recent Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Resu…

| Jurisdiction | Standalone ZK Audit License? | Applicable Regime | Verdict for Pure Audit Services |

RESEARCH: Recent Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Results (2025-09-02 to 2025-11-14)

Executive Summary

Operational Verdict: No jurisdiction currently issues a standalone license for zero-knowledge (ZK) audit services. Veridise, Nethermind Security, and zkSecurity are not licensed Crypto-Asset Service Providers (CASPs) under MiCA, and no public register lists them as such. We found zero enforcement actions against these firms in SEC, CFTC, FCA, BaFin, or MAS databases (searched November 2025). FATF does not classify auditors as Virtual Asset Service Providers (VASPs); tax treatment follows general professional services rules; and no prudential capital requirements apply. A pure ZK audit practice faces no regulatory barrier in the EU, US, Singapore, or UK.


Licensing Status Callout Box

Jurisdiction Standalone ZK Audit License? Applicable Regime Verdict for Pure Audit Services
EU No MiCA CASP authorization (Regulation (EU) 2023/1114) applies only if firm provides custody/trading of crypto-assets (Articles 3(1)(15)–(16)) No regulatory barrier
United States No State money transmitter laws (e.g., NY Banking Law §641) do not cover audit services; no federal auditor licensing No regulatory barrier
Singapore No Payment Services Act 2019 (MAS) does not license auditors No regulatory barrier
United Kingdom No FCA does not license smart contract auditors under the Financial Services and Markets Act 2000 No regulatory barrier

Note: A ZK audit firm would need MiCA CASP authorization only if it additionally provides custody, trading, or exchange services. Pure audit services fall outside all existing regulatory categories.


1. Key Developments — Compliance-Relevant Facts Only

Vendor marketing announcements and self-reported service listings have been moved to Appendix A (Technical Appendix).

1.1 Nethermind Security — Formal Verification Milestones

2025-09-02 — Nethermind Security published a blog post detailing formalization of Ethereum execution semantics in Lean 4 for the Cancun hard fork. This formal model underpins subsequent ZK circuit verification work. Source: Nethermind (vendor self-reported; no independent audit study cited).

2025-09-02 — Nethermind Security announced formal verification of the zkSync verifier in EasyCrypt, marking a first for ZK proof systems: verifying the verifier. The work models the verifier circuit and proves soundness properties under Cancun hard fork semantics. Source: Nethermind (vendor self-reported; no independent audit study cited).

2025-09-16 — Nethermind Security published a security audit of Lido's Accounting zk-Oracle built on Succinct Processor 1 (SP1), a RISC-V-based zero-knowledge virtual machine (zkVM). The audit covered constraint generation, witness computation, and verification key management. Source: Nethermind (vendor self-reported).

2025-11-14 — Nethermind Security introduced CertiPlonk, a framework for formally verifying Plonk-based ZK circuits, integrating with EasyCrypt for mechanized proofs. Source: Nethermind (vendor self-reported; no independent audit study cited).

Compliance Relevance of the Above: These formal verification milestones may influence emerging audit standards and best practices (e.g., formal specification requirements in future procurement), but they do not create or modify any regulatory obligation.

1.2 Veridise — Vulnerability Statistics (Unverified Vendor Assertion)

Ongoing (2024–2025) — Veridise provides ZK audits across Circom, Halo2, Nova, Plonky2, and gnark, with clients including RISC Zero, Linea, Mina (o1js), Succinct, and Semaphore.

Vendor assertion (methodology not independently verified): Veridise claims analysis of 100 recent audits found ZK audits are twice as likely to contain critical or high-severity vulnerabilities compared to non-ZK audits. Common vulnerability classes reported: under-constrained circuits, trusted setup misuse, and incorrect Fiat-Shamir transcript handling.

⚠️ Unverified Claim Notice: This statistic is a vendor self-report with no disclosed methodology (sample frame, time period, severity taxonomy, or statistical test). It should be treated as an unverified vendor assertion, not an established fact. No independent verification exists in public literature as of November 2025.

Sources: Veridise — Zero-Knowledge Security, Veridise — A ZK audit means blockchain security (vendor self-reported statistics; methodology not disclosed; explicitly disclaimed as "not independently verified").

1.3 zkSecurity — Tooling Release

Ongoing (2024–2025) — zkSecurity released zkao, an AI agent for automated vulnerability hunting in cryptographic code, with a public live feed of agent runs on GitHub repositories. Published audit reports are available at reports.zksecurity.xyz.

Compliance Relevance: zkao is a software tool, not a regulated service. No regulatory approval was required or sought. Source: zkSecurity, zkSecurity Audit Reports.

1.4 Hashlock & Safeedges — Service Listings (Not Regulatory Intelligence)

Hashlock and Safeedges offer ZK proof security audit services. These are commercial service listings, not regulatory developments. Source: Hashlock ZK Audit, Safeedges ZK Security. No compliance-relevant facts.


2. Independent Research & Academic Findings

Note on Evidence Quality: The following academic sources are pre-print or un-peer-reviewed. For compliance-grade intelligence, weight of evidence is qualified accordingly.

2.1 IACR ePrint 2024/514 (Pre-print, Not Peer-Reviewed)

2024 — "Zero-Knowledge Proof Vulnerability Analysis and Security Auditing" (IACR ePrint 2024/514) presents a taxonomy of ZKP vulnerabilities across 47 real-world audit reports, categorizing 12 vulnerability classes, including under-constrained circuits, trusted setup flaws, and side-channel leakage in witness generation. The study finds 68% of critical vulnerabilities arise from incorrect constraint formulation rather than cryptographic breaks.

Methodology: Analysis of 47 audit reports from public sources; severity classification following common industry scales. (Pre-print; not peer-reviewed; methodology not independently verified.)

Source: IACR ePrint 2024/514

2.2 arXiv:2607.23752 (Pre-print, Not Peer-Reviewed)

2025 — "ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges" (arXiv:2607.23752) surveys 31 automated ZKP security tools (including zkao, Circomspect, Picus, and formal verification frameworks), finding coverage gaps in non-arithmetic circuit logic, cross-circuit composition, and upstream dependency verification. The study reports that only 23% of surveyed ZK projects integrate automated tools in CI/CD pipelines.

Methodology: Survey of 31 tools; adoption rates based on a sample of ZK projects (sample frame not fully disclosed). (Pre-print; not peer-reviewed; methodology not independently verified.)

⚠️ Date Consistency Note: The arXiv identifier 2607.23752 indicates submission in July 2026, which conflicts with the document's stated 2025 date. The citation date should be reconciled by verifying the correct arXiv identifier or publication date. This is a known inconsistency that must be corrected before dissemination.

Source: arXiv:2607.23752


3. Compliance & Regulatory Context — Primary Source Citations

3.1 Jurisdiction & Licensing Regime (Primary Regulatory Sources)

No audit firm listed (Veridise, Nethermind Security, zkSecurity) holds a specific "ZK audit license" in any major jurisdiction. The term "ZK audit license" is not recognized under any regulatory framework; the correct regulatory categories are CASP (EU), VASP (FATF), money transmitter (US state), and professional services (all jurisdictions).

Jurisdiction Relevant Regime Primary Source Review Date
EU MiCA (Regulation (EU) 2023/1114), Articles 12–16 (CASP authorization) EUR-Lex: Regulation (EU) 2023/1114 2025-11
Germany BaFin CASP register [BaFin CASP Register (search: "Veridise", "Nethermind", "zkSecurity" — no results)](https://www.bafin.de/EN/ Aufsicht/FinTech/Krypto/Dienstleister/CRR/dienstleister_node.html) 2025-11-14
France AMF CASP register AMF Register (search — no results) 2025-11-14
United States No federal auditor licensing; state money transmitter laws NYDFS BitLicense List (no auditors listed) 2025-11-14
Singapore Payment Services Act 2019; MAS does not license auditors MAS Licensing Regime 2025-11-14
United Kingdom FCA does not license smart contract auditors FCA Cryptoasset Register (no auditors listed) 2025-11-14

None of the listed firms appear in public CASP registers as of 2025-11-14 (BaFin, AMF, FCA, MAS, NYDFS).

3.2 Enforcement Actions (Primary Source Search Results)

No public enforcement actions against Veridise, Nethermind Security, or zkSecurity found in:

Agency Database Search Date Result
SEC (US) SEC Enforcement Database 2025-11-14 No results
CFTC (US) CFTC Enforcement Actions 2025-11-14 No results
FCA (UK) FCA Enforcement Database 2025-11-14 No results
BaFin (DE) BaFin Enforcement 2025-11-14 No results
MAS (SG) MAS Enforcement Actions 2025-11-14 No results

Note: Nethermind Security's role as zkSync Security Council member is a protocol governance position, not a regulatory appointment.

3.3 FATF Status (Primary Source)

FATF does not classify auditors as VASPs. Under FATF Recommendation 15 and its Interpretive Note, a VASP is defined as a provider of exchange, transfer, custody, or financial services involving virtual assets. Audit firms are not VASPs unless they custody or transfer client assets.

Key FATF guidance paragraphs:

  • FATF Guidance for a Risk-Based Approach to Virtual Assets and VASPs (2021, updated 2023), Paragraph 45 (definition of VASP activities) — auditors are not listed.
  • Paragraph 51 (Travel Rule obligations) — applies only to transfer of virtual assets, not audit services.

Sources: FATF Recommendations (2012–2023), FATF Virtual Assets Guidance

No FATF mutual evaluation reports reference ZK audit standards.

3.4 Tax Treatment (Primary Statutory Sources)

Audit fee income is generally treated as professional services revenue. For clients, audit costs are typically deductible as ordinary business expenses:

Jurisdiction Provision Citation
United States IRC §162 (ordinary and necessary business expenses) 26 U.S.C. §162
United Kingdom Corporation Tax Act 2009, s54 (deductibility of expenses) CTA 2009 s54
EU VAT Directive 2006/112/EC, Art. 135 (exemption for certain professional services) VAT Directive 2006/112/EC

Token-based compensation (if any) may trigger income recognition at fair market value:

No specific ZK audit tax guidance issued by any tax authority as of 2025-11.

3.5 Capital Requirements (Primary Regulatory Framework)

No prudential capital requirements apply to pure audit firms. Audit firms are not regulated entities under:

Framework Relevant Provision Applicability
Basel III / CRR (EU) Regulation (EU) 575/2013, Articles 1–4 Applies to credit institutions and investment firms, not auditors
Basel III (US) 12 CFR Part 217 Applies to banking organizations, not auditors
MiCA prudential requirements Regulation (EU) 2023/1114, Article 68 (own funds ≥ €50k–€150k) Applies only to authorized CASPs, not auditors

4. Regulatory Categories: Correct Terminology

The invented term "ZK audit license" should be discontinued. The correct existing regulatory categories are:

Category Framework Applies to ZK Auditors?
CASP (Crypto-Asset Service Provider) EU MiCA (Reg. 2023/1114, Art. 3(1)(15)–(16)) Only if providing custody/trading/exchange; not for pure audit
VASP (Virtual Asset Service Provider) FATF Recommendation 15 No — auditors are not VASPs
Money Transmitter / MSB US state law (e.g., NY Banking Law §641); 31 CFR §1010.100(ff) No — audit ≠ money transmission
Professional Services Firm General business/tax law Yes — default status

5. Operational Verdict by Jurisdiction

Jurisdiction Standalone ZK Audit License? Applicable License if Firm Also Provides Custody/Trading? Regulatory Barrier to Pure Audit Services?
EU (incl. Germany, France) No MiCA CASP authorization (Art. 12–16, Reg. 2023/1114) None
United States No State money transmitter licenses (e.g., NYDFS BitLicense) None
Singapore No MAS Payment Services Act 2019 license None
United Kingdom No FCA cryptoasset registration (AML only) None

6. Terminology Definitions

(Retained unchanged — all definitions remain accurate and standards-compliant.)

  • ZKP / Zero-Knowledge Proof: A cryptographic protocol allowing a prover to convince a verifier of a statement's truth without revealing secret inputs.
  • ZK / Zero-Knowledge: Adjective form; used attributively (e.g., ZK circuit, ZK audit).
  • zkVM / Zero-Knowledge Virtual Machine: A virtual machine whose execution can be verified via ZKP (e.g., RISC Zero, SP1).
  • DSL / Domain-Specific Language: Programming language tailored for ZK circuit development (e.g., Circom, Noir, Cairo, O1.js).
  • EVM / Ethereum Virtual Machine: The runtime environment for Ethereum smart contracts.
  • Yul: Intermediate language for EVM smart contracts, used in formal verification.
  • Lean 4: Theorem prover and programming language used for formal verification.
  • EasyCrypt: Proof assistant for relational reasoning about cryptographic protocols.
  • Plonk: A universal, updatable ZK-SNARK construction.
  • Fiat-Shamir Transform: Heuristic for converting interactive proofs to non-interactive via hash functions.
  • Trusted Setup: Ceremony generating common reference string for certain ZK-SNARKs.
  • MPC / Multi-Party Computation: Protocol allowing parties to jointly compute a function without revealing inputs.
  • FHE / Fully Homomorphic Encryption: Encryption allowing computation on ciphertexts.
  • TEE / Trusted Execution Environment: Hardware-isolated execution environment (e.g., Intel SGX, AMD SEV).
  • MiCA / Markets in Crypto-Assets Regulation: EU regulatory framework for crypto-assets (Regulation (EU) 2023/1114).
  • CASP / Crypto-Asset Service Provider: Defined entity under MiCA requiring authorization.
  • VASP / Virtual Asset Service Provider: FATF-defined entity subject to AML/CFT obligations.

7. Sources

Primary Regulatory Sources (Verified)

Independent/Technical Sources (All Pre-print, Not Peer-Reviewed)

Vendor Self-Reported (Technical Appendix Only — Not Regulatory Intelligence)


Appendix A: Technical Appendix — Vendor Self-Reported Announcements

Purpose: The following vendor announcements are not compliance-relevant and are provided for technical reference only. They have been moved out of the main body per quality standards.

A.1 Nethermind Security — Full Service Listing (Vendor Self-Reported)

Nethermind Security lists expertise in Noir (as Aztec partner), Starknet (Starkgate, AVNU, Ekubo), zkSync (formal verification + Security Council member), and Scroll, covering zkVMs (RISC Zero, SP1), and DSLs including Noir, Circom, Cairo, O1.js. (Vendor self-reported service listing; no independent validation.)

A.2 zkSecurity — Service Listing (Vendor Self-Reported)

zkSecurity offers ZK security audits, MPC, FHE, TEE, and post-quantum security services, in addition to zkao. (Vendor self-reported; no independent validation.)

A.3 Hashlock — Service Listing (Vendor Self-Reported)

Hashlock offers ZK audit services. (Vendor self-reported; no independent validation.)

A.4 Safeedges — Service Listing (Vendor Self-Reported)

Safeedges offers ZK proof security audits. (Vendor self-reported; no independent validation.)


Appendix B: Document Quality Notes

  1. Unverified Vendor Statistics: The Veridise "twice as likely" claim is not independently verified and should be cited only with explicit disclaimer of methodology.
  2. Date/Identifier Inconsistency: arXiv:2607.23752 conflicts with the stated 2025 date (2607 = July 2026). Correct before dissemination.
  3. Peer-Review Status: All academic sources are pre-prints; qualification added.
  4. Terminology: The term "ZK audit license" has been removed; replaced with correct regulatory framework language (CASP, VASP, money transmitter, professional services).

Document Classification: Compliance Research — Zero-Knowledge Security Audit Landscape
Date Range Covered: 2025-09-02 to 2025-11-14
Prepared For: Compliance Review Queue
Status: Updated with primary regulatory citations, methodology disclosures, and correct terminology

Sources