Quantus Network Audit
Comprehensive security audit of Quantus Network, a Substrate-based L1 with ZK wormhole circuits for private transactions, covering the Wormhole pallet, qp-plonky2 ZK circuits, Poseidon hash and chain primitives, delivered as an 82-page audit report with multiple findings.
CompletedOverview
Equilibrium conducted a security audit of the Quantus Network, a Substrate-based L1 that uses ZK wormhole circuits for private transactions. The audit covered the chain’s Wormhole pallet implementation (Quantus’s own ZK privacy mechanism, not the Wormhole cross-chain bridge), ZK circuits built on a Plonky2 fork (qp-plonky2), the Poseidon hash implementation, transaction extensions, and chain primitives.
The scope expanded during the engagement as Quantus added new features (wormhole branch forked code), requiring additional review. In practice the work comprised two audit tracks: one for the Substrate pallets and one for the ZK circuits (Plonky2), delivered as an 82-page security audit report containing multiple findings.
The report was delivered under the Equilibrium brand, reflecting the security audit practice Equilibrium carries forward from Equilibrium Labs.
Deliverables
- 82-page security audit report (two audit tracks: Substrate pallets and ZK circuits).
- Review of the Quantus chain Wormhole pallet and primitives.
- Audit of qp-plonky2 ZK circuits, including the Poseidon hash and volume fee computation.
- Review of Quantus QIPs (Quantus Improvement Proposals).
Technical highlights
- Found that Poseidon gate deserialization could cause an out-of-bounds panic at runtime when given malformed serialized data. This was a concrete security finding.
- The Wormhole implementation enables ZK-based private transactions on a Substrate chain, using Plonky2 circuits with a custom Poseidon hash.
- Audited everything added since the Plonky2 fork: the audit covered the qp-plonky2 delta, not the upstream Plonky2 codebase.
Scope notes
- Scope explicitly excluded the consensus mechanism (PoW no longer used)
and
service.rs, focusing on the ZK-related components. - The upstream Plonky2 codebase was out of scope; the audit covered the qp-plonky2 fork’s additions.
Status
Completed. The audit report was delivered in 2026.