ZERO-KNOWLEDGE AUDITS

Audits for zero-knowledge systems

Our past audits include Elusiv, Solana’s confidential transfer extensions, and ZK Login, a circom-based JWT validation service we audited as part of our partnership with Mysten Labs.

$36.82B+ On-chain TVL secured66% Core-severity findings120+ Projects audited

QUESTIONS

Frequently asked questions

What ZK systems has OtterSec audited?

Our past audits include Elusiv, the SDK behind Solana’s confidential transfer extensions, and ZK Login, a circom-based JWT validation service we audited as part of our partnership with Mysten Labs. Public reports also include Zircuit and Light Protocol Zero Copy.

ZK SPECIALTY

Proof systems, circuits, and verifiers

We have extensive experience when it comes to zero-knowledge proofs.

Breaking zkVMs

Our research “Unfaithful claims: breaking 6 zkVMs” found six systems where a zkVM verifier’s guarantee about its public claims breaks.

Dusk’s PLONK verifier

Our research found that dusk-plonk’s verifier never validated four of the prover’s polynomial commitments, enough to mint DUSK from nothing.

ZK reports on the record

Public audit reports include Light Protocol Zero Copy, Pallad, Auro Wallet, Zircuit, and Mysten ZK Login.

Circuit languages

Circom and Halo 2 are among the languages we’ve audited.

AUDIT EXPERIENCE

ZK work across Solana and Sui

  1. Audited Elusiv, a compliant privacy-preserving payment protocol built on zero-knowledge proofs on Solana.
  2. Audited the SDK behind Solana’s confidential transfer extensions, which contains code utilized by the token-2022 extension.
  3. Audited ZK Login, a circom-based JWT validation service, as part of our partnership with Mysten Labs.

GET SECURED

Get your ZK system audited

Tell us where the highest-risk parts of your circuits and verifiers live, and we will route the request to the right security team.

Get an audit