Find out why Risc Zero chose us for crypto security

RiscZero: Steel audit report

Project Information

CATEGORY

Zero-Knowledge Virtual Machines (zkVM)

NETWORK

RISC Zero zkVM

DESCRIPTION

From April 14, 2025 to April 24, 2025, Risc Zero engaged Veridise to conduct a security assessment of their Steel library. The security assessment covered the updates made to the Steel zkVM application library. Compared to the previous version, which Veridise has audited previously, the new version adds several new features, including the ability to create historical proofs for older execution blocks, the ability to prove that an event was emitted in a block and the ability to verify a steel commitment with respect to another environment. Veridise conducted the assessment over 27 person-days, with 3 security analysts reviewing the project over 9 days The review strategy involved a tool-assisted analysis of the program source code performed by Veridise security analysts as well as thorough code review.

Audit Report

DURATION

27 person-days

COMPLETED

May 7, 2025

SCOPE

The scope of this security assessment is limited to the additions/modifications made to the risc0-ethereum/crates/steel/src directory from commit ee1c455 to commit 2c99f46. This directory provided by the Steel developers contains the source code for the Steel library.

Total Findings
0
Mitigated
0
Critical Severity
0
High Severity
0
Medium Severity
0
Low Severity
0

Considering an audit?
Contact us today!

Contact us for a security audit quote

Secure an earlier audit slot by reaching out early.