USENIX Security2026Top-tier venue
Arguzz: Testing zkVMs for Soundness and Completeness Bugs
Christoph Hochrainer, Valentin Wüstholz, Maria Christakis
Abstract
Zero-knowledge virtual machines (zkVMs) are increasingly deployed in decentralized applications and blockchain rollups since they enable verifiable off-chain computation. These VMs execute general-purpose programs, frequently written in Rust, and produce succinct cryptographic proofs. However, zkVMs are complex, and bugs in their constraint systems or execution logic can cause critical soundness (accepting invalid executions) or completeness (rejecting valid ones) issues. We present ARGUZZ, the first automated tool for testing zkVMs for soundness and completeness bugs. To detect such bugs, ARGUZZ combines a novel variant of metamorphic testing with fault injection. In particular, it generates semantically equivalent program pairs, merges them into a single Rust program with a known output, and runs it inside a zkVM. By injecting faults into the VM, ARGUZZ mimics malicious or buggy provers to uncover overly weak constraints. We used ARGUZZ to test six real-world zkVMs—RISC Zero, Nexus, Jolt, SP1, OpenVM, and Pico—and found eleven bugs in three of them. One RISC Zero bug resulted in a $50,000 bounty, despite prior audits, demonstrating the critical need for systematic testing of zkVMs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fb4370fa-14e1-4909-864e-e43c4418bb22Cited by top-tier papers1
Ask how each one uses itBuilds on20
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek et al.S&P 2021 · 126 citations
- Validating SMT solvers via semantic fusionDominik Winterer, Chengyu Zhang, Zhendong SuPLDI 2020 · 80 citations
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 79 citations
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 51 citations
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 46 citations
Related papers
- Evaluating Compiler Optimization Impacts on zkVM PerformanceThomas Gassmann, Stefanos Chaliasos, Thodoris Sotiropoulos, Zhendong SuASPLOS 2026 · 2 citations
- Fuzzing Processing Pipelines for Zero-Knowledge CircuitsChristoph Hochrainer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisCCS 2025 · 1 citation
- MTZK: Testing and Exploring Bugs in Zero-Knowledge (ZK) CompilersDongwei Xiao, Zhibo Liu, Yiteng Peng, Shuai WangNDSS 2025
- zkFuzz: Foundation and Framework for Effective Fuzzing of Zero-Knowledge CircuitsHideaki Takahashi, Jihwan Kim, Suman Jana, Junfeng YangS&P 2026 · 8 citations
- Automated Soundness and Completeness Vetting of Polygon zkEVMXinghao Peng, Zhiyuan Sun, Kunsong Zhao, Zuchao Ma et al.USENIX Security 2025
