nethermind security

Formal Verification for Zero-Knowledge and Blockchain Infrastructure

The Formal Verification team at Nethermind Security provides formal verification for zero-knowledge systems, cryptographic infrastructure, blockchain protocols, and execution environments. The work focuses on mathematical correctness assurances and reusable verification infrastructure for production blockchain systems.
Proof tooling and systems the team verifies in:

Lean

Halo2

Plonky3

Circom

EVM / Yul

In-house verification infrastructure

CLAP

CertiPlonk

Halva

Surveyor

ArkLib

Bluebell

ZK Circuit Verification

Verification of zk circuit correctness and proving-system behavior across Halo2 and Plonky3 systems. Includes work on CLAP, a Lean-based zk circuit compiler carrying correctness assurances from source specifications through generated constraint systems.

ZK Cryptographic Protocol Verification

Formal verification of zk proof systems, verifiers, and their implementations. Includes development of the FRI formalization in ArkLib and ongoing work toward STIR/WHIR formalization.

Protocol Verification

Mathematical modeling and verification of blockchain protocols and distributed systems.

Verification Infrastructure & Tooling

Reusable verification infrastructure, formal semantics, and theorem-proving tooling for Ethereum and zk systems.

Smart Contract Verification

Formal reasoning about smart contract execution behavior for systems requiring stronger correctness assurances.

commonly includes:

zk proof systems & zkVMs

Blockchain protocols

Cryptographic infrastructure

Execution environments

High-value smart contract systems

relevant when:

Systems secure significant value

Protocol correctness is foundational

Cryptographic assumptions are critical

Infrastructure dependencies expand

Failures are difficult to detect through testing alone

Current areas of focus include:

Reusable zk verification infrastructure

zkVM verification systems

Probabilistic program logics

Proof-system verification

Post-quantum cryptography

Contributions also include formalization efforts related to post-quantum cryptography and emerging cryptographic standards. Formal verification is expected to become increasingly important as zero-knowledge systems and cryptographic infrastructure mature into foundational financial and internet infrastructure.

How is formal verification different from a security audit?

Audits and testing check for issues someone thought to look for. They can show that bugs exist but never prove that none remain. Formal verification uses machine-checked proofs to show a system behaves according to formally specified correctness properties across every possible execution, which is a stronger assurance for the properties that get verified.

Does formal verification replace an audit?

No, formal verification does not replace an audit. Instead, it proves a system meets the correctness properties it was specified against. Problems outside those specs, like access-control misconfigurations or economic design flaws, still need an audit and broader security review. The two are complementary.

What does formal verification actually prove?

Formal verification proves that a system matches its formally specified correctness properties across all execution paths, checked by machine rather than by example. The strength of the result depends on the properties specified, which is why scoping and specification development are central to every engagement.

What does an engagement involve?

Each engagement starts with detailed analysis of the system and the properties it needs to hold, followed by threat modeling, specification development, verification planning, formal modeling, and machine-checked proof development. Specifications come from direct technical discussion with the team building the system, not from informal documentation.

What do clients receive?

Formal specifications, correctness proofs, protocol models, a verification report, remediation guidance, and reusable tooling where the engagement produces it.

What systems and ecosystems can the team verify?

Work spans zk proof systems and verifiers, zk circuits, zkVMs, cryptographic protocols, blockchain protocols and distributed systems, execution environments, and high-value smart contracts. Past work includes systems across the Ethereum Foundation, Aptos Foundation, ZKsync, Succinct, Axiom, Brevis, RISC Zero, and INTMAX.

Which tools does the team use?

The Formal Verification team primarily uses Lean, with verification work across Halo2, Plonky3, Circom, and EVM/Yul, supported by in-house infrastructure including CLAP, CertiPlonk, Halva, Surveyor, and ArkLib.

Which chains does Nethermind’s formal verification team support?

The team's work centers on Ethereum and the EVM, Starknet, and the proof systems and zkVMs used across the ecosystem. Coverage is defined by the proving system and execution environment rather than a fixed chain list, spanning EVM and Yul execution, Halo2 and Plonky3 circuits, zkVMs such as SP1, OpenVM, and RISC Zero, and protocols like ZKsync and INTMAX.

get in touch

Talk to Our Team

Whether you are building zk systems, blockchain protocols, execution infrastructure, or cryptographic systems, Nethermind Security can help verify their underlying infrastructure.

Contact us

Follow Nethermind Security on X