Skip to content
Request an audit

‹ All private audits

Keyring Credentials audit

Three Sigma·Zero-knowledge compliance·10th July 20242 High1 Medium3 Low6 Info

A private security review of Keyring (zero-knowledge compliance), conducted with Three Sigma and completed on 10th July 2024 over 5 days. 0xSimao disclosed 12 findings: 2 high severity, 1 medium, 3 low and 6 informational.

What Keyring is

Keyring is zero-knowledge compliance infrastructure: users hold credentials attesting policy eligibility (KYC, jurisdiction, sanctions state), verified on-chain through RSA/PKCS#1-style signature checks without revealing identity, so permissioned pools keep composable liquidity.

Scope

This second Three Sigma round covered the credential verifier and its key handling, credential creation timestamps and expiry, the fee transfer mechanism, and the blacklist machinery that cuts an entity's addresses off.

High severity findings

Medium severity findings

Low severity findings

Informational findings

The report