Research noteZK-2026-0197
Circuit bugs are the new contract bugs
An under-constrained circuit proves statements that are not true, and nothing about it looks wrong.
SeverityHigh
7 minZero-Knowledge Proofs
A missing constraint does not produce an error. It produces a valid proof of a false statement, which the verifier accepts exactly as it should. There is no runtime symptom to observe.
The review discipline this demands is closer to formal specification than to code reading, and the pool of people who can do it well remains very small.