The AI audit tool, zkao, developed by zkSecurity, has identified bugs in prominent cryptographic libraries, Cloudflare's CIRCL and OpenVM's zkVM. These discoveries were part of an effort to enhance security in cryptographic systems.
During the audit of Cloudflare's CIRCL, zkao found seven bugs, including a critical precision loss bug and an access-control issue in attribute-based encryption. All bugs have since been fixed by the upstream developers.
In the case of OpenVM's zkVM, a critical soundness bug was found, allowing pairing equality forgery, which led to its classification as CVE-2026-46669. This bug was addressed in OpenVM version 1.6.0.
The zkao audit process involves the use of AI to initially identify potential vulnerabilities. Human experts then verify these findings to confirm their exploitability and impact.
The audits of CIRCL and zkVM are part of an ongoing series that highlights the potential of AI to find security issues that might be missed by traditional methods. The tool helped produce candidate findings with detailed reports for human evaluation.
Zkao's approach to continuous code review and its integration of AI and human expertise may serve as a model for future security auditing.
The use of AI in auditing cryptographic code is demonstrating significant potential to improve security postures by uncovering complex vulnerabilities in experimental libraries.
The quick fixes to the vulnerabilities identified by zkao show a proactive approach towards security, ensuring that current systems are using the most robust and secure code available.
The findings reinforce the role of AI auditing tools in the future of cybersecurity, emphasizing their utility in maintaining secure cryptographic frameworks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An AI-powered audit identified a critical soundness bug in OpenVM's zkVM guest library, allowing forgery of pairing equality. This vulnerability was assigned CVE-2026-46669 and fixed in the latest version, OpenVM 1.6.0, indicating the efficacy of AI in identifying complex security issues in cryptographic systems.
zkSecurity's zkao AI audit detected seven bugs in Cloudflare's CIRCL library, including critical vulnerabilities. These findings highlight the effectiveness of AI in identifying issues in cryptographic code and contribute to ongoing improvements in automated security auditing tools.