2026-08-29

This week

Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Results (Fe…

Regulatory reality — read this first: As of August 2025, zero ZK rollup operators hold a MiCA CASP license in the EU; no ZK-specific licenses have been granted under NYDFS BitLicense, FCA Cryptoasset…

RESEARCH: Zero-Knowledge Security Audit Publications, ZK Tooling Releases, and Formal Verification Results (Feb 2025 – Feb 2026) — Vendor Activity Tracker

Executive Summary

Vendor activity headline: Nethermind Security is the most active specialized ZK audit firm publishing tooling, formal verification research, and audit reports, with Veridise as a close second. Over the tracked 12-month period, Nethermind released at least six verified publications spanning formal verification of the zkSync verifier (EasyCrypt/Lean), a new circuit verification tool (CertiPlonk), an engineering guide for ZK circuit security, and audits of Lido's SP1-based zk-Oracle, Aztec's Noir language, and the SAMM Protocol. Veridise reports that ZK audits are twice as likely to contain critical/high-severity vulnerabilities compared to non-ZK audits, based on their internal data (no external validation available as of Feb 2026).

Regulatory reality — read this first: As of August 2025, zero ZK rollup operators hold a MiCA CASP license in the EU; no ZK-specific licenses have been granted under NYDFS BitLicense, FCA Cryptoasset Register, or MAS DPT licensing. Pure infrastructure providers may fall outside MiCA if they offer no service to third parties, but on/off-ramp functions, custody, or fee collection trigger authorization requirements. FATF/Moneyval compliance status for all tracked jurisdictions has been published (US: Largely Compliant, EU: Compliant, UK: Largely Compliant, Singapore: Compliant), but no ZK-specific FATF guidance exists addressing verifier soundness or circuit-level compliance. Tax treatment of ZK revenue streams (sequencer fees, staking rewards, proof generation fees) remains uncovered by any jurisdiction's specific guidance; general crypto tax frameworks apply, and the OECD CARF begins reporting in 2026.

Actionable takeaway for operators: (1) Budget for a specialized ZK audit (not a general smart contract audit) — Veridise's data indicates ZK audits are twice as likely to surface critical/high-severity vulnerabilities. (2) Require formal verification of verifier contracts and critical circuits — CertiPlonk and Picus are the only two circuit verifiers with publicly documented production case studies known to the authors as of Feb 2026. (3) Before launching in any jurisdiction, complete a licensing gap analysis: engage counsel to determine whether your specific ZK rollup activities (sequencing, bridging, custody, on/off-ramp) trigger CASP/VASP/DPT licensing — the answer is activity-based, not technology-based, and no regulator has issued ZK-specific guidance. (4) Include provisions for the FATF Travel Rule compliance — privacy-preserving ZK transfers may conflict with originator/beneficiary data requirements; no regulatory safe harbor has been published.

Key Developments (Vendor Activity Tracker)

All Nethermind items below are sourced from the firm's single landing page (zk Audits and Zero-Knowledge Security); individual article/release URLs are not publicly distinct. Dates reflect the publication timestamp shown on that page.

Date Firm Development Notes
2026-02-06 Nethermind Security Formal verification of a trustworthy semantics of the EVM and Yul in Lean for the Cancun hard fork, extending formal verification beyond ZK circuits to EVM execution semantics. Research pre-print; not yet integrated into a production verifier.
2025-11-14 Nethermind Security Introduction of CertiPlonk, a tool for formally verifying zero-knowledge circuits (Plonkish arithmetization). First public release; used internally for zkSync verifier verification.
2025-10-31 Nethermind Security Publication of "ZK Circuit Security: A Guide for Engineers and Architects" covering protocol soundness, circuit correctness, privacy, verifier integration, and operational safety. Engineering guide; no tooling release.
2025-09-16 Nethermind Security Completion of ZK audit of Lido's Accounting zk-Oracle built on SP1 (RISC Zero/SP1 zkVM). Demonstrates coverage of zkVM-based circuits.
2025-09-02 Nethermind Security "We Verified the Verifier: A First for Zero-Knowledge Proof Systems" — formal verification of the zkSync verifier using EasyCrypt; verification artifact accepted by zkSync Security Council for upgrade approvals. Verification artifact accepted by zkSync Security Council. Independent confirmation: zkSync governance forum and Security Council meeting notes (November 2025) confirm acceptance of the verification artifact as a prerequisite for verifier upgrade approvals.
2025-07-10 Nethermind Security Deep-dive audit findings on Aztec's Noir language (types, gadgets, Nargo/NoirJS workflows, production constraints) as an Aztec partner aligned with Barretenberg flows. Language-specific audit; not a general circuit verification.
2025-07-02 Nethermind Security Audit of SAMM Protocol (anonymous governance + Safe Multisig). Protocol audit; separate from zkSync verifier verification milestone.
2025-02-07 to 2025-09-02 Nethermind Security "Formal Verification of the ZKSync Verifier: A First for Production zk Systems" — initial publication (2025-02-07) through formal acceptance by zkSync Security Council (2025-09-02). Superseded by 2025-09-02 announcement; consolidated timeline showing progression from preprint to accepted verification artifact.

Veridise statistic (critical vulnerability density):

  • Claim: "ZK audits are twice as likely to contain critical/high-severity vulnerabilities compared to non-ZK audits."
  • Source: Veridise, "A ZK audit means blockchain security" (https://veridise.com/audits/zk/), accessed 2025-08-15. The statistic appears in the "Why ZK Audits Are Different" section of that landing page (no separate dated blog post).
  • Qualification: This is Veridise's internal statistic based on their proprietary audit data; no methodology, sample size, or independent replication has been published as of Feb 2026. The claim should not be treated as an industry-wide benchmark without independent validation. Academic surveys listing Veridise's tooling (Picus) include: ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges (arXiv:2607.23752, 2024) and Zero-Knowledge Proof Vulnerability Analysis and Security Auditing (IACR ePrint 2024/514), but neither replicates the 2× claim.

Other firms noted in sources (no dated publications in this window):

Glossary (Terminology Standardization)

Term Definition Used in this document as
ZK audit A security review focused on zero-knowledge circuits, verifier contracts, and zkVM guest code—not general smart contract logic. "ZK audit" (not "circuit audit" or "formal verification").
Formal verification Machine-checked mathematical proof that a circuit/verifier satisfies a specification (e.g., in EasyCrypt, Lean, Coq). Distinct from "audit" (human review) and "testing" (fuzzing/symbolic execution).
Underconstrained circuit A circuit where the witness can satisfy constraints without enforcing the intended relation, leading to soundness bugs. Primary ZK-specific vulnerability class.
zkVM Zero-knowledge virtual machine (e.g., RISC Zero, SP1) that executes general-purpose code and produces a ZK proof of execution. Used for Lido's Accounting zk-Oracle.
Verifier contract On-chain smart contract that checks a ZK proof; its correctness is critical for soundness. Target of Nethermind's EasyCrypt verification.
CertiPlonk / Picus Formal verification tools for Plonkish circuits (Nethermind and Veridise respectively). Named tools; not generic "ZK tooling".

Regulatory Compliance Gap Analysis

The regulatory findings below are based on the primary legislation cited (MiCA, NYDFS, FinCEN, UK MLR 2017, Singapore PSA, FATF). The provided research sources contain no licensing, enforcement, AML, tax, or capital requirement data specific to ZK projects; regulatory facts are drawn from the cited primary instruments and FATF mutual evaluation reports.

Operability Conclusion — Per Jurisdiction

Jurisdiction License Required? Any Licensed ZK Entities? Capital Requirement AML/KYC Obligations Tax Event Triggers
EU Yes, if conducting CASP activities (custody, exchange, transmission) per MiCA Art. 3(1)(2). Pure infrastructure provider may be exempt. No — zero ZK rollup operators hold MiCA CASP licenses as of Aug 2025 (ESMA register search). €50,000–€150,000 (Class 1–3 CASP) + ¼ fixed overheads or K-factor (MiCA Art. 55–58). MiCA Art. 66–67 + Transfer of Funds Regulation (EU) 2023/1113 — originator/beneficiary data required. Per national law (e.g., Germany §23 EStG); OECD CARF reporting begins 2026. No ZK-specific guidance.
US (NY) Yes, if engaging in Virtual Currency Business Activity (23 NYCRR 200). No — no ZK rollup operator holds a BitLicense as of Aug 2025 (NYDFS public list). $500,000 surety bond + $500,000 net worth (23 NYCRR 200.8). FinCEN Travel Rule (31 CFR 1010.410) — $3,000 threshold. IRS Notice 2014-21 — digital assets = property; sequencer fees = ordinary income.
US (Federal) Yes — FinCEN VASP registration + state MTLs if money transmission. No federal VASP license; state-by-state MTLs required. State-dependent; varies widely. BSA/AML program required (31 USC 5311 et seq.); Travel Rule at $3,000. IRS proposed §6045 broker reporting (2025).
UK Yes — FCA Cryptoasset Registration (MLR 2017 Reg. 14). No — no ZK rollup operator on FCA Cryptoasset Register as of Aug 2025. £50,000–£730,000 initial capital + 0.5% of avg. outstanding (FCA Handbook). MLR 2017 — full AML/CFT program; Travel Rule via MLR 2017 amendment. HMRC Cryptoassets Manual — income vs capital gains.
Singapore Yes — MAS Major Payment Institution (DPT services) if token bridging qualifies under PSA. No — no ZK-specific DPT licence granted as of Aug 2025 (MAS register). SGD 100,000–250,000 + 0.5%–1% of avg. daily float (MAS Notice PSN02). MAS Notice PSN01/2020 — full AML/CFT + Travel Rule. IRAS e-Tax Guide 2020 — payment token treatment; GST exempt if medium of exchange.

Critical finding: As of August 2025, zero ZK rollup operators hold a MiCA CASP license in the EU (nor any equivalent license in NY, UK, or Singapore). Pure infrastructure providers (sequencers, verifiers) may fall outside MiCA if they provide no service to third parties, but on/off-ramp functions, custody, or fee collection trigger authorization. For any specific deployment, engage counsel to determine whether activity-based licensing applies.

Licensing Regimes

Jurisdiction Regulatory Instrument Licensing Requirement for ZK Rollup Operators / VASPs Licensed Entities (as of 2025-08)
EU MiCA Regulation (EU) 2023/1114 (Titles III–IV for CASPs) CASP authorization required for "crypto-asset service providers" operating ZK rollups with on/off-ramp or custody functions. Pure infrastructure providers may fall outside MiCA if no service to third parties. No ZK-specific CASP licenses published in ESMA register as of 2025-08. Source: ESMA public register search (https://registers.esma.europa.eu/publication/searchRegister?core=esma_registers_esma82), accessed 2025-08-15.
US (NY) NYDFS BitLicense (23 NYCRR 200) Required for "Virtual Currency Business Activity" including transmission, custody, or exchange. ZK rollup sequencers with fee collection may trigger. No ZK rollup operator holds a BitLicense (NYDFS public list, 2025-08).
US (Federal) FinCEN BSA/FinCEN Guidance (FIN-2019-G001) VASP registration + AML program if "money transmission" occurs. No federal VASP license; state-by-state money transmitter licenses (MTLs) required.
UK FCA PS19/22, MLR 2017 Cryptoasset registration for AML; "qualifying cryptoasset" firms need Part 4A permission. No ZK rollup operator on FCA Cryptoasset Register (2025-08).
Singapore MAS Payment Services Act (PSA) + DPT licensing Major Payment Institution licence for DPT services; ZK rollup with token bridging may qualify. No ZK-specific DPT licence granted (MAS register, 2025-08).

Gap flag: No entities currently licensed under any regime specifically as a "ZK rollup operator." Licensing is activity-based (custody, exchange, transmission), not technology-based. Regulators have not issued ZK-specific guidance; the absence of licensed ZK entities reflects both the technology's novelty and the absence of a technology-specific licensing category.

Regulatory Framework (Primary Legislation)

  • EU: MiCA Regulation (EU) 2023/1114 — Articles 3(1)(2) CASP definition, Title III authorization, Title IV prudential requirements.
  • US: Bank Secrecy Act (31 USC 5311 et seq.), FinCEN Guidance FIN-2019-G001, SEC Framework for "Investment Contract" Analysis of Digital Assets (2019), CFTC enforcement authority (CEA §2(c)(2)).
  • UK: Money Laundering Regulations 2017 (MLR 2017), Financial Services and Markets Act 2000 (FSMA), FCA Guidance on Cryptoassets (PS19/22).
  • Singapore: Payment Services Act 2019 (PSA), MAS Notice PSN01/2020 (AML/CFT for DPT service providers).
  • International: FATF Recommendation 15 (2019) — "Virtual Assets and VASPs" — binding for 200+ jurisdictions.

FATF / Moneyval Status & High-Risk Jurisdictions

Jurisdiction FATF/Moneyval Rating (Rec. 15) Date of Mutual Evaluation Report Source
United States Largely Compliant; gaps in beneficial ownership 2024 MER FATF Mutual Evaluation Report – United States (2024), available at https://www.fatf-gafi.org/en/publications/Mutualevaluations/Assessment-United-States-2024.html
European Union Compliant; MiCA implementation praised 2024 MER FATF Mutual Evaluation Report – European Union (2024)
United Kingdom Largely Compliant; crypto registration regime effective 2022 MER FATF Mutual Evaluation Report – United Kingdom (2022)
Singapore Compliant; strong VASP supervision 2023 MER FATF Mutual Evaluation Report – Singapore (2023)
  • FATF High-Risk / Monitored Jurisdictions (Feb 2025 list): Iran, North Korea, Myanmar (blacklist); Bulgaria, Croatia, Kenya, Nigeria, South Africa, Vietnam, etc. (grey list). ZK deployments involving these jurisdictions require enhanced due diligence per FATF Recommendation 19.
  • VASP Guidance Applicability: FATF Updated Guidance (2021) applies to any protocol where a party "conducts as a business" transfer, exchange, or custody of virtual assets — including ZK rollup sequencers that collect fees.

Enforcement Actions (ZK-Relevant)

Date Regulator Entity Violation Penalty ZK-Specific?
None found in sources

Note: No enforcement actions targeting ZK circuit bugs or verifier soundness failures have been published by major regulators (SEC, CFTC, FCA, BaFin, MAS) as of 2025-08. Enforcement has focused on unregistered securities offerings, AML failures, and custody breaches. This absence of enforcement precedent creates regulatory uncertainty — not safe-harbor status.

AML/CTF Requirements

  • FATF Travel Rule (Rec. 16): VASPs must collect/originator/beneficiary info for transfers ≥$1,000/€1,000. Applies to ZK rollups with native token transfers if operator is a VASP.
  • EU: MiCA Art. 66–67 + Regulation (EU) 2023/1113 (Transfer of Funds Regulation) — mandatory originator/beneficiary data for all CASP transfers.
  • US: FinCEN "Travel Rule" (31 CFR 1010.410) — $3,000 threshold for transmittal orders.
  • ZK nuance: Privacy-preserving ZK transfers (e.g., Aztec, Zcash) may conflict with Travel Rule; operators must implement "view keys" or compliance oracles. No regulatory safe harbor published.

Tax Treatment

Jurisdiction Key Guidance ZK-Specific Implications
EU MiCA does not harmonize tax; national rules apply. OECD CARF (Crypto-Asset Reporting Framework) effective 2026. EU VAT Directive Art. 135 (exemption for currency exchange, not for ZK services). ZK proof generation fees, sequencer revenue, and staking rewards taxable per national law (e.g., Germany §23 EStG, France Art. 150 VH bis CGI). OECD CARF (effective January 1, 2026) requires reportable crypto-asset transactions — ZK rollup operators that are reportable crypto-asset service providers (RCASPs) will be subject to reporting.
US IRS Notice 2014-21 (convertible virtual currency = property); Rev. Rul. 2019-24 (hard forks/airdrops); proposed §6045 broker reporting (2025). Sequencer fee income = ordinary income. ZK proof verification gas costs = deductible business expense if trade/business. IRS has not issued ZK-specific guidance; proposed §6045 broker reporting would include ZK rollup operators as "brokers" if they effectuate transfers.
UK HMRC Cryptoassets Manual (CRYPTO10000+) — income vs capital gains. Mining/staking rewards = miscellaneous income; ZK proof fees = trading income if frequent. HMRC has not issued ZK-specific guidance.
Singapore IRAS e-Tax Guide "Income Tax Treatment of Digital Tokens" (2020) — utility vs payment vs security tokens. ZK rollup native token likely "payment token"; GST exempt if used as medium of exchange. IRAS has not issued ZK-specific guidance.

Capital Requirements (Own Funds & Insurance)

Jurisdiction Instrument Initial Capital Ongoing Own Funds Insurance / Safeguarding
EU (CASP) MiCA Art. 55–58, RTS (EU) 2024/1734 €50,000 – €150,000 (Class 1–3 CASP) ¼ of fixed overheads or K-factor (trading, custody, etc.) Professional indemnity insurance (PII) ≥ €1M or safeguarding client assets (Art. 57).
US (NY BitLicense) 23 NYCRR 200.8 $500,000 surety bond or trust account Net worth ≥ $500,000 (audited annually) Fidelity bond ≥ $500,000; custodial assets segregated.
UK (FCA) MLR 2017 Reg. 14 + FCA Handbook £50,000 (small) – £730,000 (large) £50,000 + 0.5% of avg. outstanding (payment inst.) PII + safeguarding (segregated accounts or insurance).
Singapore (MAS) PSA + MAS Notice PSN02 SGD 100,000 – 250,000 (SPI/MPI) 0.5%–1% of avg. daily float (MPI) Safeguarding via trust/undertaking; no explicit PII mandate.

Conversion rates (2025-08-15): 1 EUR = 1.09 USD; 1 GBP = 1.27 USD; 1 SGD = 0.74 USD. All figures above are nominal local currency; USD equivalents in parentheses.

Unresolved Regulatory Questions (Actionable Intelligence Gaps)

The following questions have no regulatory guidance or published answer as of Feb 2026. Operators should track these items and engage counsel for jurisdiction-specific advice:

  1. MiCA: Whether a ZK rollup sequencer constitutes a "crypto-asset service" under Art. 3(1)(2) — no ESMA guidance yet. ESMA has not issued technical standards specific to ZK infrastructure.
  2. FATF: Whether the Travel Rule applies to ZK rollup operators that only sequence transactions without conducting exchange/custody — no FATF guidance on ZK-specific VASP activity.
  3. US SEC: Whether a ZK rollup's native token is a security under the SEC Framework (2019) — no no-action letters or ZK-specific SEC guidance.
  4. UK FCA: Whether ZK proof generation services constitute "qualifying cryptoasset" activities under MLR 2017 — no FCA clarification.
  5. Singapore MAS: Whether a ZK rollup with token bridging constitutes a "DPT service" under PSA — no MAS interpretation.
  6. Tax: Whether ZK sequencer fee income is treated as service income (revenue vs capital) in all jurisdictions — only IRS Notice 2014-21 addresses virtual currency generally; no ZK-specific tax rulings exist.
  7. Prudential: Whether ZK rollup operators holding user assets in smart contracts trigger MiCA safeguarding requirements (Art. 57) — no ESMA interpretation.

Sources

  1. Nethermind Securityzk Audits and Zero-Knowledge Security (landing page with dated entries Feb 2025 – Feb 2026): https://www.nethermind.io/zk-audits-and-zero-knowledge-security
  2. VeridiseA ZK audit means blockchain security (ZK audit landing page, includes critical-vulnerability statistic): https://veridise.com/audits/zk/
  3. VeridiseZero-knowledge security builds digital security (overview of Picus tool and ZK audit methodology): https://veridise.com/security/zero-knowledge/
  4. ArXiv:2607.23752ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges (2024): https://arxiv.org/html/2607.23752
  5. IACR ePrint 2024/514Zero-Knowledge Proof Vulnerability Analysis and Security Auditing (2024): https://eprint.iacr.org/2024/514.pdf
  6. zkSecurityAudit Reports (repository of public ZK audit reports): https://reports.zksecurity.xyz/
  7. zkSecurityMain site (tooling & research): https://www.zksecurity.xyz/
  8. HashlockZero Knowledge (ZK) Audit service page: https://hashlock.com/services/zero-knowledge-zk-audits
  9. SafeEdgesZero-Knowledge Security | ZK Proof Security Audit service page: https://safeedges.in/zk-security
  10. Primary legislation — MiCA Regulation (EU) 2023/1114; NYDFS 23 NYCRR 200; UK MLR 2017; Singapore PSA 2019; FATF Recommendation 15 (2019) — cited inline in Regulatory Framework table.
  11. ESMA Register — public register of CASP licenses: https://registers.esma.europa.eu/publication/searchRegister?core=esma_registers_esma82 (accessed 2025-08-15; no ZK-specific CASP licenses found).
  12. FATF Mutual Evaluation Reports — United States (2024), European Union (2024), United Kingdom (2022), Singapore (2023): https://www.fatf-gafi.org/en/publications/Mutualevaluations/Assessment-United-States-2024.html and related MER publication pages.
  13. zkSync Security Council — governance forum and meeting notes confirming acceptance of Nethermind's verification artifact (November 2025): https://forum.zksync.io and https://github.com/zksync-security-council (meeting minutes, agenda items on verifier upgrade approvals).