zkFuzz: Fuzzer for trace-constraint inconsistencies in Circom ============================================================= zkFuzz fuzzes Circom programs for disagreements between what witness generation computes and what the constraints enforce, the root of most underconstraint bugs. Its paper reports 66 bugs across 354 circuits. Maintainer: Hideaki Takahashi (Koukyosyumei) Website: https://github.com/Koukyosyumei/zkFuzz Category: ZK circuit verification Targets: Circom Approach: Fuzzing for trace-constraint consistency (TCCT) violations between witness generation and constraints Access: Open source Status: Active research (IEEE S&P 2026) Strengths: Concrete exploits, not warnings. | Scales where solvers do not. | Strong published results. Limits: No guarantee on a clean run. | Circom only. | Single-maintainer research project. Firms using it: none listed Sources: https://github.com/Koukyosyumei/zkFuzz Source page: https://sorryfree.com/frameworks/zkfuzz/ Compiled by: sorryfree editors (https://sorryfree.com/about/) Last reviewed: 2026-09-13