AI meets Cryptography 2: What AI Found in OpenVM's zkVM
Summary
The post highlights how zkao, an AI auditor, found a critical soundness bug in OpenVM's zkVM pairing check, tracked as CVE-2026-46669, and fixed in OpenVM 1.6.0. It explains that the vulnerability stemmed from a missing subfield test on the scaling factor, which allowed forgery of pairing checks, and discusses the broader implications for zk-based protocols. The piece also reflects on the challenges of AI triage in complex codebases and the need for robust human verification.