{
  "slug": "nethermind",
  "name": "Nethermind (Formal Verification team)",
  "url": "https://www.nethermind.io/formal-verification",
  "hq": "London, United Kingdom",
  "focus": "Lean and EasyCrypt verification: Halva (Halo2), Plonky3 circuits, SP1 chips, ZKsync verifier honesty proof",
  "summary": "Nethermind's formal verification team works in Lean 4 and EasyCrypt. It built Halva for Halo2 (finding a critical bug in Scroll's deprecated Keccak circuit), co-developed sp1-lean with Succinct, maintains an ArkLib FRI fork and a Lean EVM model (EvmYul), and produced the first honesty proof of a production ZK verifier for ZKsync in EasyCrypt.",
  "why_first": "",
  "services": [
    "Halo2 and Plonky3 circuit verification in Lean",
    "zkVM chip verification (SP1, Pico, OpenVM)",
    "EasyCrypt proofs for verifiers and protocols",
    "EVM semantics and equivalence proofs"
  ],
  "tools": [
    "halva",
    "sp1-lean",
    "arklib",
    "easycrypt",
    "lean4"
  ],
  "evidence": [
    [
      "Halva and the Scroll Keccak finding (2025-07-02)",
      "https://www.nethermind.io/blog/formal-verification-of-halo2-circuits-in-lean"
    ],
    [
      "SP1 Hypercube Lean verification (2025-10-09)",
      "https://blog.succinct.xyz/nethermind-lean/"
    ]
  ],
  "fit": [
    "Choose Nethermind for Halo2 or Plonky3 circuits and for zkVM chip verification, especially in Ethereum L2 stacks."
  ],
  "rank": 4,
  "page": "https://sorryfree.com/firms/nethermind/",
  "updated": "2026-09-13"
}