ZCG-Funded V12 Credits for AI Security Scans: Applications Open

Zcash Community Grants (ZCG) is now taking applications from Zcash ecosystem teams for ZCG-funded credits on V12, the autonomous security system built by the team behind Zellic.

What is V12?

V12 is an AI auditor that looks for vulnerabilities in your code. For each finding, it tries to produce a working proof-of-concept exploit and a suggested patch. It supports:

  • Pull request scans, so new code is checked as it’s written

  • Full repository scans of an existing codebase

V12 runs on its own dashboard and doesn’t change your GitHub workflows unless you choose to integrate it, so trying it out is low-risk.

Why we’re doing this

ZCG has been running a pilot of V12, sharing credits with a few ecosystem teams. So far:

  • A scan of Zaino turned up 15 findings, all confirmed by the maintainers and addressed.

  • The Zcash Foundation has been running V12 on pull requests across its codebases, and it has become a valuable part of their security review process.

  • Several other ecosystem teams are already using the platform.

Most AI code review tools we’ve tried are hit-and-miss. V12 has had a noticeably better signal-to-noise ratio, and its reports are short and actionable. Every bug caught by a scan before release is one fewer bug that reaches users. We’d like the rest of the ecosystem to have the same chance to find these bugs early.

Who can apply?

Any team or individual building open-source software for the Zcash ecosystem, including (but not limited to):

  • Wallets (mobile, desktop, hardware, web)

  • Full nodes, indexers and light client infrastructure

  • Libraries, SDKs and cryptographic code

  • Tooling, explorers and services that handle user funds or data

You don’t need to be a current ZCG grantee.

How to apply

Fill in the V12 Credits Application form on GitHub. It asks for:

  1. Project name and repository link(s) you’d like to scan

  2. The open source license your repositories are released under

  3. A short description of the project and its role in the Zcash ecosystem

  4. Expected PR volume, if you know it (for example, PRs per week)

The form also asks you to accept a few terms, including adding a ZCG committee member to your V12 organization to help manage funding and ongoing costs.

ZCG will review applications on a rolling basis and allocate credits from the ZCG-funded pool. We’ll contact approved teams to set up V12 access, and credits will be assigned to their organization.

The program starts with ongoing PR scans. Checking each change as it’s made is the most cost-effective way to catch bugs early, so that’s where we’re focusing the pool. Once your team is in the program, you can ask ZCG for a one-off full repository scan. Full scans use far more credits than PR scans, so we’ll consider these requests case by case.

Findings and disclosure

You’re responsible for triaging and fixing what V12 reports. Please follow responsible disclosure for any security issue that affects users or other projects.

Zellic and V12 have offered to help teams get set up, including integrating V12 into your development workflow so that every PR is checked.

Questions?

Ask in this thread or contact the committee directly. We’d also like to hear how V12 works for your project, both the good and the bad. We’ll pass your feedback on to the Zellic and V12 team, and share tips and tricks from teams that have had success with V12 so everyone can get more out of it.

Thanks to the Zellic and V12 teams for their support of the Zcash ecosystem.

The Zcash Community Grants Committee

5 Likes

Thanks for V12 this great news going to sign up now.