Z

Zksecurity

Research and audit firm for cryptography and blockchain security

Performances

Comparison

Details

This content is generated by RD AI and is for reference only

zkSecurity is a research-driven firm specializing in cryptography and blockchain security, covering zero-knowledge proofs (ZKP), multi-party computation (MPC), fully homomorphic encryption (FHE), and post-quantum cryptography. It offers security audits, protocol and circuit development, academic research, and automated tooling (e.g., AI-based vulnerability detection). The team is known for rigorous mathematical and engineering expertise, serving numerous well-known blockchain projects.

Follow Updates

Follow Lists

People

About Zksecurity

zksecurity is a security audit firm focused on zero-knowledge (zk) systems. Its core business combines AI-driven vulnerability discovery with manual expert validation, offering audits for zk circuits, zkVMs, and cryptographic libraries.

Key differentiators include an in-house AI pipeline that triages candidate findings, reducing the cost of locating and reproducing bugs. It also builds open-source tools like zkvmBlast, a differential fuzzer for RISC-V zkVMs, and zk.golf, a competitive platform for formally verified, highly optimized circuits. These tools address the market pain point that zk code is notoriously hard to audit manually, while pure AI outputs often flood maintainers with false positives. zksecurity solves this by combining machine-generated leads with human proof-of-concept validation and responsible disclosure.

In the past six months (March–September 2026), zksecurity published an AI audit of Cloudflare's CIRCL library, uncovering seven real bugs (including a critical CP-ABE access-control bypass) that were fixed upstream. It also launched zkvmBlast, which found seven distinct issues across SP1, Pico, and OpenVM, and released zk.golf to encourage community-driven, formally verified circuit optimization.

A notable limitation is that AI severity assessments often diverge from vendor-confirmed ratings, and the full pipeline details (false-positive rates, model configurations) are not publicly disclosed. This transparency gap means users should treat AI findings as leads, not final verdicts.

Updated: Sep 8, 2026

zkSecurity was founded on May 30, 2023, initially as a ZK circuit auditing firm. Early milestones include the departure of co-founder Brandon to become CEO of O(1) Labs, while Gregor and Mathias joined full-time, growing the team to about 10 engineers. The company expanded from pure ZK audits to broader advanced cryptography, covering MPC, FHE, TEEs, threshold signatures, and consensus protocols. In 2024, they released Circomscribe, a debugging tool for Circom circuits, and published a taxonomy of ZK vulnerabilities. A significant development came in 2026 with the launch of zkao, an AI-powered continuous security scanner that encodes patterns from their 100+ audits. That same year, they identified the first two known exploits against live ZK circuits—both stemming from Groth16 verifiers with incorrect setups—and integrated detection for this vulnerability class into zkao.

Updated: Sep 12, 2026

Since March 2026, zkSecurity's key progress includes: launched zkvmBlast, a differential fuzzing framework for RISC-V zkVMs partially funded by the Ethereum Foundation, surfacing seven completeness/correctness bugs across SP1, Pico, and OpenVM, plus a reproduction of a known RISC0 soundness bug; integrated Aleo/Leo into its AI auditing tool zkao and completed an audit of HumanityLink's aid-distribution system; and, following the first live ZK exploits (Veil and Foom) caused by missing Groth16 setup phases, added automated detection for this vulnerability class to zkao.

Future focus: continue expanding zkao's coverage of more languages and ZK DSLs, and deepen zkvmBlast development by publishing further technical details and encouraging adoption as a CI tool by more zkVM teams.

Updated: Sep 5, 2026

Co-founders and current core team:

  • David Wong: Co-founder of zkSecurity, author of Real-World Cryptography, formerly Cryptography Architect at O(1) Labs, Security Lead for Diem/Libra at Novi (Facebook), and security consultant at NCC Group's Cryptography Services. ()

  • Gregor Mitscha-Baude: Co-founder of zkSecurity, formerly zk Cryptography Engineer at O(1) Labs, PhD in applied numerical mathematics from TU Wien. ()

  • Brandon Kase: Co-founder of zkSecurity; no detailed public bio available.

  • Mathias Hall-Andersen: Co-founder of zkSecurity; no detailed public bio available.

Updated: Sep 5, 2026

Zksecurity recently welcomed Kobi Gurkan as a Research member in August 2026. Kobi brings deep expertise in applied cryptography, SNARKs, and threshold schemes, previously contributing to projects like cpsnarks-set and aggregatable-dkg. His addition strengthens Zksecurity's research capabilities for zero-knowledge security audits.

No departures were reported during this period.

Updated: Sep 8, 2026