
blog.zksecurity.xyz
July 17, 2026
13 min read
50/100
Summary
AI auditor zkao identified a critical soundness bug in OpenVM's zkVM guest library openvm-pairing, allowing a malicious prover to forge any pairing equality. This vulnerability does not affect the zkVM's proving system itself but impacts code relying on the flawed library.
Key Takeaways