ZK/SEC Research notes from zkSecurity
All posts
announcement

Ditch the Pump & Dump Drama: Your ZK Tech Hub Awaits

Today we're announcing the release of our new project, zkNews, a zero-knowledge link aggregator for the community. We're excited to bring you a platform where you can find all the latest news, research, and projects in the zero-knowledge space.

zknews

The zero-knowledge (ZK) space is exploding, and it can be tough to keep up with the latest developments. That's why we're thrilled to introduce zkNews – your one-stop shop for all things ZK.

What is zkNews?

zkNews is a zero-knowledge link aggregator designed specifically for the ZK community. It's your go-to source for:

  • Breaking news: Stay ahead of the curve with the most recent ZK announcements and breakthroughs.
  • In-depth research: Dive into the latest academic papers and technical discussions shaping the ZK landscape.
  • Cutting-edge projects: Discover new ZK tools, platforms, and applications pushing the boundaries of privacy and scalability.

Join the Beta!

We're launching zkNews in beta mode, and we want your feedback! Head over to https://news.zksecurity.xyz to start exploring. While we're in beta, access is limited to a smaller group of users, but we'll be expanding soon.

Your Feedback is Invaluable

We're committed to making zkNews the best resource for the ZK community. Tell us what you think! Share your suggestions, report any bugs, and let us know what kind of content you'd like to see more of.

Stay Tuned!

This is just the beginning. We have big plans for zkNews, including personalized recommendations, community features, and more. Follow us on twitter for updates and announcements.

Keep reading
Recommended

SoK: What don’t we know? Understanding Security Vulnerabilities in SNARKs

We've teamed up with some of the top minds in academia and industry to dive deep into the world of zero-knowledge proofs (ZKPs) and their vulnerabilities. Our new paper catalogues hundreds of ZK vulnerabilities, breaking down their root causes and offering strategies to sidestep these pitfalls. By digging into real-life SNARK implementations, we aim to bolster the security of these cutting-edge systems with actionable insights and recommendations. Curious about what makes ZKPs tick and how to keep them secure? You might find this study just what you need!

ZK/SEC · February 26, 2024

Listen to us on the latest episode of zeroknowledge.fm

Join our cofounder David Wong on the latest zk podcast as he dives into his compelling journey through cryptography, from his early days as a security consultant to his pivotal roles in major projects like Facebook's crypto initiatives and Mina. Get an insider's view on how we approach auditing in a Zero Knowledge context, the common pitfalls in ZK code, and how these insights shape our work. It's an engaging and informative chat for anyone fascinated by the world of cryptography and ZK technology!

ZK/SEC · August 30, 2023

The State of Security Tools for ZKPs

Zero-knowledge proofs (ZKPs) have come a long way from theory to real-world applications like blockchains and private transactions. We’ve been busy auditing various ZKP implementations and developing tools to improve circuit safety and security. In this blog post, we’ll explore how vulnerabilities can crop up in SNARK systems and the current state of tools designed to spot these issues. From circuit bugs to the often-overlooked frontend and backend layers, we cover how various analysis techniques and formal verification approaches are evolving to ensure robust ZKP systems. Dive in to discover the potential and current challenges in ZKP security!

ZK/SEC · June 02, 2024
More to explore

noname: ZK app developers should be able to see down to the constraints

Zero-knowledge apps are evolving, and we've been diving into their two main forms: VM instructions and arithmetic circuits. Understanding the "assembly" layer is crucial for developers, especially when optimizing and ensuring security. We’ve played around with a new toy language called **noname**, blending Golang and Rust vibes to make zkApps more understandable. With **noname**, you get detailed insights about how your code translates into gates, offering a clearer picture of the underlying "assembly" and helping pinpoint compiler bugs. If you're curious about enhancing your low-level programming skills or peeking into circuit construction, check out our experiments and see if this inspires you to create better debugging tools!

David Wong · June 03, 2023

Sigma dance: commit, challenge, respond

Learn the fundamentals of Σ-protocols through the classic Schnorr protocol, exploring the three-step dance of commit, challenge, and respond. This post walks through knowledge soundness and witness extraction, then shows how to compose Sigma proofs with AND/OR logic and Pedersen commitments. See working SageMath implementations, discover how Fiat-Shamir transforms interactive proofs into non-interactive signatures, and understand the deeper mathematical structure as proofs of knowledge of homomorphism pre-images.

teddav · November 18, 2025

Kocher's Timing Attack: A Journey from Theory to Practice

Paul Kocher's 1996 timing attack showed how microsecond differences in execution time could leak private keys from RSA implementations. This tutorial recreates the attack journey from clean operation counting through noisy wall-clock measurements to sophisticated engineering solutions. Learn the variance distinguisher, explore schoolbook modular arithmetic, and discover the measurement techniques that make practical timing attacks possible despite system noise.

Martín Ochoa · September 19, 2025