We are looking forward to working with the ZCG Committee and some teams to plan potential audit projects.
As always, please let us know if you need assistance with security related questions or projects! You can post here or reach out to us directly: Security Consulting - Least Authority
We completed another iteration of review and feedback for the ZavaX Oracle Threat Model.
We delivered the Final Audit Report for our previous security audit of Zkool2.
We delivered the Final Audit Report for our previous security audit of ZIP 233 + Implementation (NU7).
No consultations were completed this month.
Community engagement and upcoming work:
We received a list of potential security audits from the ZCG Committee. We planned and estimated most of the items on the list and should finish the remaining plans in April, along with starting some of this work.
We started and completed a security audit of the NEAR Intents Swap.
We started and completed a security audit of Warp 2.
We started a security audit of Zkool GraphQL + JWT authentication and expect to complete this in May.
We started a security audit of pepper-sync and expect to complete this in May.
We started a security audit of zingo-mobile and expect to complete this in June.
No consultations were completed this month.
Special Projects:
We started a special project to deploy autonomous, tool-using AI security agents with expert human validation to identify and responsibly disclose critical attacker-relevant vulnerabilities in the Zcash Ecosystem. As part of this project, we are rigorously assessing model cybersecurity capabilities and plan to open-source the defensive workflow.
Community engagement and upcoming work:
We have a few more audits starting in May.
As always, please let us know if you have security related questions or projects! You can post here or reach out to us directly.
We completed a security audit of Zkool GraphQL + JWT authentication.
We completed a security audit of pepper-sync.
We continued a security audit of zingo-mobile and expect to complete this in June.
We started a security audit of NSM ZIP 235 and expect to complete this in June.
We started a security audit of the Maya Protocol Integration and expect to complete this in June.
No consultations were completed this month.
Special Projects:
We completed a special project to deploy autonomous, tool-using AI security agents with expert human validation to identify and responsibly disclose critical attacker-relevant vulnerabilities in the Zcash Ecosystem. As part of this project, we shared our findings with the in-scope projects and hope to share more about the outcomes of this review soon.
Community engagement and upcoming work:
We will continue to engage in the ecosystem about the use of AI for vulnerability discovery and triaging reported issues.
As always, please let us know if you have security related questions or projects! You can post here or reach out to us directly.
Hey, I got a message from a core member at HackenProof from a post i made about my finding that have been patched and published on Zebra. One of the best web3 bug bounty platforms out there and he is looking for who he could reach out to in the security team. He would like to offer Zcash their platform for bug bounty hosting.
I personally think it would really be a great idea because a lot of top protocols out there actually host their bug programs there and they have a very effective triage team and other mechanisms in place to cut down the AI slop submissions. He personally assured of that
In light of the recent discovery of a critical counterfeiting vulnerability in Zcash’s orchard pool using the most advanced AI model Opus 4.8, I believe it is in the best interests of the zcash community to understand how you are using it to undertake your day to day security work?
Does the community have access to the work done you mention in your monthly report?
We’re working on a blog post that will provide more details about our experience on the AI-assisted Zcash audit. It will include our AI usage techniques in this audit and a high-level overview on how we use it in our security work in general. We hope to have this published in the next few days.
As for the audit reports, they are shared with the respective Zcash developers, will be made public once the issues have been resolved (given the consent of the Zcash team).