Project Information

CATEGORY

Zero-Knowledge Virtual Machines (ZK-VM)

NETWORK

RISC-V ZKVM

DESCRIPTION

From Dec 2, 2024 to Dec 27, 2024, RISC Zero engaged Veridise to conduct a follow up security assessment of their ZKVM. The previous audit performed by Veridise covered most of their ZKVM implementation including parts of the prover, verifier, recursion circuits, default host implementation, and their new arithmetization of the RISC-V CPU in their V2 circuit DSL. The follow up engagement was intended to review a new implementation of the RISC-V big integer precompile (referred to as Bigint2). Veridise conducted the assessment over 8 person-weeks, with 2 security analysts reviewing the project over 4 weeks.

Audit Report

DURATION

8 person-weeks

COMPLETED

March 25, 2025

SCOPE

The scope of the audit was limited to the selected files in the risc0/zirgen repository.

Total Findings
0
Mitigated
0
Critical Severity
0
High Severity
0
Medium Severity
0
Low Severity
0

Considering an audit?
Contact us today!