Odaily Planet Daily News Worldcoin released the security audit report. Starting in April 2023, audit firms Nethermind and Least Authority will conduct two separate security audits of the protocol.
Among them, Nethermind focuses on auditing the smart contracts of the agreement, including the World ID contract, the World ID status bridge, the World ID sample airdrop contract, the Worldcoin token (WLD) grant contract, and the WLD ERC-20 token contract and related attribution wallets. Of the 26 that emerged during this security assessment, 92.6% (24) were identified as fixed after the verification phase, while one was mitigated and the remaining one was confirmed.
Least Authority focused on auditing the protocol's use of cryptography, including its use of the Semaphore protocol and enhancements made to extend the protocol in a more gas-efficient manner. These include the protocol's cryptographic design and implementation, the Rust implementation of the Semaphore protocol, and the Go implementation of the Semaphore Merkle Tree Batcher (SMTB). Least Authority identified three issues and made six recommendations, all of which "are addressed or plan to be addressed".
“We found that the cryptographic components of the Worldcoin protocol were generally well designed and implemented,” Least Authority said.