A curated list of awesome ZKP Security resources, papers, tutorials, and tools. Inspired by Awesome-Smart-Contract-Security.
If you want to add a new resource, please submit a pull request to improve this file. Thank you!
- Xor0v0/awesome-zero-knowledge-proofs-security
- sCrypt-Inc: Awesome zero knowledge proofs
- matter-labs: Awesome zero knowledge proofs
- ventali/awesome-zk
- zkp.science
- Zero-Knowledge Proofs Starter Pack
- gakonst/awesome-starknet
- Zero Knowledge Canon by a16z
- ZKP Knowledge Base by Delendum Research
- Zero Knowledge Proofs MOOC
- MIT's Modern Zero Knowledge Cryptography
- 0xParc's Circom and Halo2 learning groups
- The MoonMath Manual to zk-SNARKs: minimal experience in cryptography required
- A Graduate Course in Applied Cryptography (Dan Boneh and Victor Shoup, 2023)
- Proofs, Arguments, and Zero-Knowledge (Justin Thaler, 2022)
- Building Cryptography Proofs from Hash Functions (Alessandro Chiesa and Eylon Yogev, 2024)
- zkSecurity's Blog
- 0xParc's Blog
- Trail of Bits' Blog
- OZ's Security Insights Blog
- Veridise's Blog
- Zellic's Blog
- David Wong's Blog
- The State of Security Tools for ZKPs (Jun 2, 2024)
- Detecting boomerang values in zero-knowledge circuits using tag analysis (Aug 25, 2023)
- The zero-knowledge attack of the year might just have happened, or how Nova got broken (Jul 2, 2023)
- Do in secret. Assert in public. Don't under-constrain your prover's witness computation in ZK programs (Jun 1, 2023)
- Ecne: Automated Verification of ZK Circuits (May 12, 2022)
- What Is a ZK Audit? (Jan 25, 2024)
- ZK-SNARKS & The Last Challenge Attack: Mind Your Fiat-Shamir! (Dec 14, 2023)
- The Frozen Heart vulnerability in PlonK (Apr 18, 2022)
- The Frozen Heart vulnerability in Bulletproofs (Apr 15, 2022)
- Coordinated disclosure of vulnerabilities affecting Girault, Bulletproofs, and PlonK (Apr 13, 2022)
- It pays to be Circomspect (Sep 15, 2022)
- Disarming Fiat-Shamir footguns (Jun 24, 2024)
- Zcash Counterfeiting Vulnerability Successfully Remediated (Feb 5, 2019)
- Security Vulnerabilities in ZK (Sep 1, 2023)
- Circom-Pairing: A Million-Dollar ZK Bug Caught Early (Jan 3, 2023)
- Developing securely on Aleo blockchain: Common Vulnerability Patterns (Jun 26, 2024)
- Satisfiability Modulo Finite Fields: Unlocking SMT for ZK Verification (Aug 17, 2023)
- ZK Vulnerabilities: Sharp rocks hidden in deep water (May 2, 2023)
- Medjai: Protecting Cairo code from Bugs (Jul 22, 2022)
- Patch Thursday -- Uncovering a ZK-EVM Soundness Bug in zkSync Era (Nov 2, 2023)
- Common Vulnerabilities in ZK Proof (Oct 30, 2023)
- ChainLight saved zkSync Era from $1.9B exploit (Nov 3, 2023)
- ZKPs for Engineers: A look at the Dark Forest ZKPs (Sep 29, 2020)
- Facebook: Critical bugs in Facebook/Polygon Winterfell library (Apr 12, 2023)
- Vulnerabilities patched in Aztec 2.0 (Sep 16, 2021)
- 00 PLONK Bug (15 Dec 2021)
- Aztec: Disclosure of recent vulnerabilities (Jan 11, 2022)
- Tornado.cash got hacked. By us. (Oct 12, 2019)
- Filecoin -- one PoREP vulnerability found by Trapdoor Tech (May 7, 2020)
- Formal Verification of ZK Constraint Systems (Sep 4, 2022)
- Groth16 Malleability (Last updated: Aug 1, 2022)
- SP1 Security Update (2 vulns disclosure) (Jan 27, 2025)
- Introducing Clean, a Formal Verification DSL for ZK Circuits in Lean4 (Mar 27, 2025)
- Solana says zero-knowledge proofs were root of mid-April bug (fix) (May 5, 2025)
- Comparison of Formal Verification Frameworks for Arithmetic Circuits (Nov 19, 2025)
- Unfaithful Claims: Breaking 6 zkVMs (Mar 3, 2026)
- We beat Google's zero-knowledge proof of quantum cryptanalysis (Apr 17, 2026)
- Verifying Poseidon in Clean: Why the Last 'sorry' Is About Primality (May 4, 2026)
- On Formal Verification and a Bug in SP1 Hypercube (May 20, 2026)
- Circuit Breaker: The Missing Constraint That Compromised RISC Zero's zkVM (Jun 11, 2026)
- Collection of security reviews of ZK Protocols
- zksecurity audit reports
- openzeppelin audit reports
- veridise audit reports
- ZKP MOOC Lecture 15: Secure ZK Circuits with Formal Methods (Uploaded: Apr 26, 2023)
- zkStudyClub: Zero-Knowledge Proofs Security, in Practice -- JP Aumasson, Taurus (Uploaded: Mar 31, 2022)
- 0xParc: (Workshop) ZK Security Research (Uploaded: Mar 24, 2023)
- Are Your Zero-Knowledge Proofs Correct? by Jon Stephens | Devcon Bogotá (Uploaded: Oct 16, 2022)
- Shankara Pailoor - Picus: Push button zk circuit verification (Jul 18, 2023)
- Introduction to ZK Security Research | David Theodore | PROGCRYPTO (Uploaded: Jan 25, 2024)
- ZK7: Security of ZKP projects: same but different - JP Aumasson - Taurus (Uploaded: May 1, 2022)
- ZK9: Fuzzy Knowledge Fuzzing SNARK circuit primitives – Innokentii Sennovskii (Aztec Network) (Uploaded: Apr 12, 2023)
- ZK10: ZK Vulnerabilities and Attacks - Stefanos Chaliasos (Uploaded: Sep 29, 2023)
- ZK11: Insights from and on Taxonomy of ZKP Vulnerabilities - Gyumin Roh (Uploaded: Apr 19, 2024)
- ETH Seoul 2023: Opinionated Survey of ZKP Security by Gyumin Roh, KALOS/HAECHI LABS (Uploaded: Jun 25, 2023)
- ZKProof 6: The Last Challenge Attack -- Exploiting a Vulnerable Implementation of the Fiat-Shamir Transform in a KZG-based SNARK - Oana Ciobotaru (May 24, 2024)
- ZKProof 6: Why Verifying the Verifier Opens Up Longer-Term ZK Innovation - Ben Livshits (Matter Labs) (May 23, 2024)
- ZKProof 6: Practical Formal Verification for Arithmetic Circuits - Marcin Kostrzewa (Reilabs) (May 23, 2024)
- ZKProof 6: SoK: Understanding Security Vulnerabilities in SNARKs - Stefanos Chaliasos (Imperial College London) (May 24, 2024)
- ETHCC[7]: Analysis and Auditing of ZKP Vulnerabilities (Jul 11, 2024)
- Plonky3 -- Missing final polynomial degree check in FRI verifier
- ZK-Kit -- Under-Constrained Bug in BinaryMerkleRoot Circuit
- SoK: What don't we know? Understanding Security Vulnerabilities in SNARKs
- Zero-Knowledge Proof Vulnerability Analysis and Security Auditing
- The Ouroboros of ZK: Why Verifying the Verifier Unlocks Longer-Term ZK Innovation
- CLAP: a Semantic-Preserving Optimizing eDSL for Plonkish Proof Systems
- An SMT-LIB Theory of Finite Fields
- Weak Fiat-Shamir Attacks on Modern Proof Systems
- Practical Security Analysis of Zero-Knowledge Proof Circuits
- Automated Detection of Under-Constrained Circuits in Zero-Knowledge Proofs
- Certifying Zero-Knowledge Circuits with Refinement Types
- Bounded Verification for Finite-Field-Blasting (In a Compiler for Zero Knowledge Proofs)
- Automated Analysis of Halo2 Circuits
- Formal Verification of Zero-Knowledge Circuits
- SMT Solving over Finite Field Arithmetic
- Compositional Formal Verification of Zero-Knowledge Circuits
- Satisfiability Modulo Finite Fields
- Leo: A Programming Language for Formally Verified, Zero-Knowledge Applications
- SNARKProbe: An Automated Security Analysis Framework for zkSNARK Implementations
- Scalable Verification of Zero-Knowledge Protocols
- The Last Challenge Attack: Exploiting a Vulnerable Implementation of the Fiat-Shamir Transform in a KZG-based SNARK
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollup
- Fuzzing Processing Pipelines for Zero-Knowledge Circuits
- How to Prove False Statements: Practical Attacks on Fiat-Shamir
- MTZK: Testing and Exploring Bugs in Zero-Knowledge (ZK) Compilers
- zkFuzz: Foundation and Framework for Effective Fuzzing of Zero-Knowledge Circuits
- ConsCS: Effective and Efficient Verification of Circom Circuits
- AC4: Algebraic Computation Checker for Circuit Constraints
- Automated Verification of Consistency in Zero-Knowledge Proof Circuits
- Towards Fuzzing Zero-Knowledge Proof Circuits (Short Paper)
- Automated Soundness and Completeness Vetting of Polygon zkEVM
- ScaleCirc: Scaling the Analysis over Circom Circuits
- SoK: Understanding zkVM: From Research to Practice
- Verifying Jolt zkVM Lookup Semantics
- Consistency Verification for Zero-Knowledge Virtual Machine on Circuit-Irrelevant Representation
- Formal Verification of the S-two AIR
- Split Gröbner Bases for Satisfiability Modulo Finite Fields
- MCSat-based Finite Field Reasoning in the Yices2 SMT Solver
- An Effective Orchestral Approach to Satisfiability Modulo Prime Fields
- Language-Agnostic Detection of Computation-Constraint Inconsistencies in ZKP Programs via Value Inference
If the link points to a paper, then it means that the tool is not open-sourced.
| Tool | Layer | DSL / Target | Analysis |
|---|---|---|---|
| Circomspect | Circuit | Circom | Static Analysis |
| ZKAP | Circuit | Circom | Static Analysis |
| halo2-analyzer | Circuit | halo2 | Static Analysis / Symbolic Analysis |
| Coda | Circuit | Circom | Formal Verification (Coq) |
| Picus | Circuit | Circom, GNARK (R1CS) | Formal Verification |
| Ecne | Circuit | Circom (R1CS) | Formal Verification |
| SNARKProbe | Circuit/Backend | R1CS | Fuzzing |
| circom_civer | Circuit | Circom | Formal Verification (SMT) |
| gnark-lean-extractor | Circuit | Gnark | Formal Verification (Lean) |
| fAmulet | Circuit/zk(E)VM | Polygon zkEVM | Fuzzing |
| zkwasm-fv | Circuit/zk(E)VM | zkWasm | Formal Verification (Coq) |
| MTZK | Frontend | ZoKrates, Noir, Cairo, Leo | Fuzzing (Metamorphing Testing) |
| Circuzz | Frontend/Backend | Circom, Corset, GNARK, Noir | Fuzzing (Metamorphing Testing) |
| aztec_fuzzing | Frontend | Noir | Fuzzing (Generation-based) |
| sierra_analyzer | Circuit | Cairo | Static Analysis / Symbolic Execution |
| Pilspector | Circuit | PIL | Symbolic Analysis |
| zkFuzz | Circuit | Circom | Fuzzing |
| garden | Circuit | Circom | Formal Verification (Coq) |
| CCC-Check | Circuit | IR-based | Static Analysis (Abstract Interpretation) |
| acl2-jolt | zk(E)VM | Jolt | Formal Verification (ACL2) |
| ZIVER | Circuit/zk(E)VM | zkVM | Formal Verification |