← All stories
● Covered by 1 source · 2 reportsMedium impact

AI-Powered Audits Uncover Bugs in Cloudflare and OpenVM Cryptographic Libraries

🔄 Updated 77d ago — new reporting from Hacker News Front Page
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • zkao AI detected bugs in Cloudflare's CIRCL and OpenVM's zkVM.
  • Critical vulnerabilities included precision loss and access-control break in CIRCL.
  • CVE-2026-46669 was assigned to a bug in OpenVM's zkVM.
  • All identified bugs have been fixed in updated versions.
  • AI audit tools are proving effective in finding cryptographic vulnerabilities.

AI Tools Detect Cryptographic Bugs

The AI audit tool, zkao, developed by zkSecurity, has identified bugs in prominent cryptographic libraries, Cloudflare's CIRCL and OpenVM's zkVM. These discoveries were part of an effort to enhance security in cryptographic systems.

During the audit of Cloudflare's CIRCL, zkao found seven bugs, including a critical precision loss bug and an access-control issue in attribute-based encryption. All bugs have since been fixed by the upstream developers.

In the case of OpenVM's zkVM, a critical soundness bug was found, allowing pairing equality forgery, which led to its classification as CVE-2026-46669. This bug was addressed in OpenVM version 1.6.0.

AI Auditing Process

The zkao audit process involves the use of AI to initially identify potential vulnerabilities. Human experts then verify these findings to confirm their exploitability and impact.

The audits of CIRCL and zkVM are part of an ongoing series that highlights the potential of AI to find security issues that might be missed by traditional methods. The tool helped produce candidate findings with detailed reports for human evaluation.

Zkao's approach to continuous code review and its integration of AI and human expertise may serve as a model for future security auditing.

Implications for Cryptographic Security

The use of AI in auditing cryptographic code is demonstrating significant potential to improve security postures by uncovering complex vulnerabilities in experimental libraries.

The quick fixes to the vulnerabilities identified by zkao show a proactive approach towards security, ensuring that current systems are using the most robust and secure code available.

The findings reinforce the role of AI auditing tools in the future of cybersecurity, emphasizing their utility in maintaining secure cryptographic frameworks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

An AI-powered audit identified a critical soundness bug in OpenVM's zkVM guest library, allowing forgery of pairing equality. This vulnerability was assigned CVE-2026-46669 and fixed in the latest version, OpenVM 1.6.0, indicating the efficacy of AI in identifying complex security issues in cryptographic systems.

zkSecurity's zkao AI audit detected seven bugs in Cloudflare's CIRCL library, including critical vulnerabilities. These findings highlight the effectiveness of AI in identifying issues in cryptographic code and contribute to ongoing improvements in automated security auditing tools.