Zero-knowledge circuit audits
Audits of ZK circuits, their on-chain verifiers and the contracts that use them. Circom, Noir, Halo2, gnark and Cairo. $999 per audit. If we find no High or Critical issues, it costs $499.
Circom, Noir, Halo2, gnark, Cairo, Solidity verifiers
We already audit on
- Sherlock
- Cantina
- Immunefi
What we check in ZK code
Under-constrained circuits
Signals that are assigned but never constrained, missing range checks, and witnesses that let more than one proof pass for the same statement.
Soundness
Field overflow and aliasing, and hints computed outside the circuit that nothing checks.
Nullifiers and replay
How nullifiers are derived, whether double spends are blocked, and whether public inputs are bound to the chain, contract and user.
Verifier contracts
Public input validation, curve point checks, and how the verification key is stored and set.
Fiat-Shamir
Transcripts that leave out values the prover controls, and biased hash-to-field.
Rollup and bridge contracts
State commitments, forced inclusion, escape hatches and L1 to L2 message checks.
Questions
Which proving systems do you cover?
Groth16, PLONK variants and STARKs. Circuits in Circom, Noir, Halo2, gnark and Cairo, and the Solidity verifiers that check their proofs.
Do you audit the contracts around the circuit?
Yes. Many ZK bugs sit where the circuit meets the contract: public inputs, nullifier storage and verifier wiring. We audit both together.
How much does an audit cost?
$999 per audit. If we find no High or Critical issues, the price drops to $499. You pay a $10 deposit when you submit, and we subtract it from the invoice.
Why is it cheaper when there are no High or Critical findings?
If your code only has Medium or Low issues, the audit was less useful to you, so you pay $499, about half.
Who does the audits?
AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.