CertiK Formally Verifies zkWasm, Proving Mathematical Soundness of a Leading zkVM

기업 소식 공지사항
CertiK Formally Verifies zkWasm, Proving Mathematical Soundness of a Leading zkVM

Zero-knowledge virtual machines (zkVMs) are becoming foundational infrastructure for rollups, privacy-preserving applications, and cross-chain proof systems. Because these systems sit underneath everything built on top of them, a single flaw in their circuit logic can silently undermine every proof the system ever generates without anyone noticing until it's too late.

That's the problem formal verification is built to solve, and it's what CertiK's research team set out to prove with zkWasm, a general-purpose zkVM used to generate cryptographic proofs that a WebAssembly (Wasm) program executed correctly, without revealing the underlying computation.

Using the Coq proof assistant, CertiK's team translated zkWasm's Halo2 circuit logic directly into machine-checked mathematical proofs. Rather than searching for known bug patterns the way a conventional audit does, formal verification proves with mathematical certainty that the circuits behave exactly as intended, across every possible input, not just the ones a reviewer thought to test.

The result: two central guarantees, now backed by machine-checked proof rather than testing or inference. First is soundness, because every accepted computation trace represents a genuinely valid execution of the underlying Wasm program. Second is knowledge soundness, because a malicious prover cannot construct a valid-looking proof for an incorrect execution. Together, these guarantees mean that if zkWasm accepts a proof, the computation it describes can be trusted to have actually happened as claimed.

The verification effort covers the breadth of zkWasm's instruction set — arithmetic and bitwise operations, memory access, control flow, and function calls — along with the auxiliary tables that enforce range checks, memory consistency, and call-stack integrity. It represents one of the most comprehensive formal verification efforts applied to a production zkVM to date.

This work has been accepted for publication at ACM CCS 2026, one of the most competitive and respected venues in computer security research. Peer review by the academic security community places this research on a different footing than a typical audit report: it means independent experts have scrutinized the methodology and findings before publication, not just CertiK's own team.

Key Findings

zkWasm's core circuits are formally proven sound. CertiK's Coq development establishes that every accepted execution trace in zkWasm corresponds to a valid, correctly executed Wasm program, which is a guarantee based on mathematical proof rather than test coverage.

Knowledge soundness closes the door on fraudulent proofs. The verification proves that a prover cannot construct a valid zkWasm proof for a computation that didn't actually happen as claimed, a foundational security property for any zero-knowledge system.

Verification spans the full production instruction set. Coverage includes arithmetic, bitwise, memory, control-flow, and call instructions, along with the auxiliary tables (range checks, bitwise operation tables, memory table, call-stack table) that support them, which is one of the broadest formal verification efforts applied to a live zkVM.

The research has cleared peer review at ACM CCS 2026. Acceptance at a top-tier academic security conference subjects the methodology and results to independent scholarly scrutiny, distinguishing this work from a standard vendor-issued audit.

Formal methods surfaced subtleties that conventional review can miss. The verification process required precisely modeling detailed behaviors, including integer overflow handling and edge cases in the underlying Wasm specification, which illustrates the kind of nuance formal methods are built to catch.

FAQs

What is formal verification, and how is it different from a smart contract audit?

Formal verification uses mathematical proof techniques to establish that a system behaves correctly across every possible input, rather than relying on manual review, testing, or pattern-matching against known bug types. A traditional audit reduces the likelihood of bugs; formal verification mathematically proves the absence of an entire class of them within its defined scope.

What is zkWasm?

zkWasm is a general-purpose zero-knowledge virtual machine that allows developers to generate cryptographic proofs that a WebAssembly program executed correctly, without revealing the underlying computation or data.

What does it mean that zkWasm's circuits are "sound"?

Soundness means that every computation trace accepted by zkWasm's circuits genuinely corresponds to a valid execution of the underlying program; there's no way for an invalid execution to slip through and be accepted as valid.

What is "knowledge soundness," and why does it matter?

Knowledge soundness is the guarantee that a prover cannot construct a valid-looking proof for a computation that didn't actually happen as claimed. It's a foundational security property for any zero-knowledge proof system, since it's what makes the proofs trustworthy in the first place.

Why does the ACM CCS 2026 publication matter?

ACM CCS is one of the most competitive, respected venues in computer security research. Publication there means the verification methodology and findings have passed independent peer review by security researchers, not just internal validation — a stronger and more objective form of credibility than a self-published report.

관련 블로그

CertiK Successfully Formally Verifies HyperEnclave from Ant Group's Trust Native Technology

CertiK Successfully Formally Verifies HyperEnclave from Ant Group's Trust Native Technology

CertiK has successfully completed the formal verification of HyperEnclave, an innovative open and cross-platform Trusted Execution Environment (TEE) from Ant Group’s Trust Native Technology team.

Paxos PAXG Formally Verified by CertiK

Paxos PAXG Formally Verified by CertiK

CertiK is proud to have successfully completed the audit of the Paxos PAX Gold (PAXG) project — the first tradeable, regulated token backed by physical gold.

DeepSEA: Advanced Web3 Formal Verification of a Smart Contract Compiler

DeepSEA: Advanced Web3 Formal Verification of a Smart Contract Compiler

CertiK carried out a research project about how to improve a particularly important part of the execution environment, namely the compiler. We produced a formally verified compiler for smart contracts, which we call DeepSEA.