Course content.
8 weeks (self-paced) · 68 hours · 6 lessons
Mathematical Foundations for ZK Audit
Finite fields, elliptic curves, polynomial commitments · From R1CS to PLONKish arithmetisation · A working mental model of KZG and FRI
Circuit Languages & Common Bug Classes
Circom, Noir, and Halo2 — syntax and foot-guns compared · Under-constrained signals, missing range checks, aliasing · Non-determinism and the witness/constraint asymmetry
Soundness & Completeness Analysis
Proving soundness of a custom gate by hand · Fuzzing circuits with Picus and Coda · Writing proof-level specifications with ease of review
Trusted-Setup Ceremonies
Powers-of-tau structure and MPC parameter generation · Toxic waste, contributor verification, and reproducibility · Reviewing a ceremony transcript end-to-end
ZK-Rollup Security
Prover, verifier, sequencer: a layered threat model · Data availability and the escape hatch problem · Upgrade governance and proof-system liveness risks
Case Studies & Capstone
Walkthrough of a real under-constrained bug in production · Capstone: full audit of a non-trivial Circom circuit · Reporting findings for a mixed cryptographer + dev audience