Project Information

CATEGORY

Zero-knowledge

NETWORK

Aztec

DESCRIPTION

From Nov. 11, 2024 to Nov. 25, 2024, Mach34 engaged Veridise to conduct a security assessment of their zkemail.nr. The security assessment covered the zero-knowledge circuits involved in validating the DKIM signature of an email. The circuit focuses on extracting the body hash of the email from the provided header and validating that a given RSA public key has signed the email. Veridise conducted the assessment over 6 person-weeks, with 3 security analysts reviewing the project over 2 weeks. Due to the Noir zero knowledge language exposing many utilities to developers, Veridise engineers also investigated some of the utilities’ implementations invoked by Mach34’s circuit.

Audit Report

DURATION

6 person-weeks

COMPLETED

February 25, 2025

SCOPE

The scope of this security assessment is limited to the lib/src and js/src folders of the source code provided by the zkemail.nr developers, which contains the zero-knowledge circuit implementation of the zkemail.nr along with the typescript libraries to generate inputs for the circuits.

Total Findings
0
Mitigated
0
Critical Severity
0
High Severity
0
Medium Severity
0
Low Severity
0

Considering an audit?
Contact us today!