Blog

World – Mobile IrisCode Self-Custody Upgrade (2nd Review)

We performed a second security audit of World’s MPC Circuit within the Mobile IrisCode Self-Custody Upgrade project, which allows users to self-host biometric data on their personal device while supporting high-integrity authentication for the World ID service. Our final audit report was completed on March 7, 2025. To read the

Read More »

World – SMPC Protocol (3rd Review)

Our team performed a review of the recent changes to World‘s secure multi-party computation protocol V2 (SMPC Protocol), which is used to match a given iris against a database of iris shares. In this third review, we audited the changes implemented in the second version of the protocol since our

Read More »

World – Mobile IrisCode Self-Custody Upgrade

We performed a security audit of World‘s Mobile IrisCode Self-Custody Upgrade project, which allows users to self-host biometric data on their personal device while supporting authentication for the World ID service. Our final audit report was completed on January 2, 2025. To read the full report, including our findings, click

Read More »

World – SMPC Protocol (2nd Review)

Our team performed a security audit of World‘s secure multi-party computation protocol (SMPC Protocol), which is used to match a given iris against a database of iris shares. Our team previously reviewed this implementation and delivered a Final Audit Report on April 4, 2024. In this review, we examined the

Read More »

World – Protocol Cryptography (2nd Review)

Our team conducted a second review of the upgrades to World‘s semaphore-mtb and the signup sequencer. Previously, our team had conducted a review of an earlier version of the codebase, which included World’s Rust implementation of the semaphore protocol and the Go implementation of the Semaphore Merkle Tree Batcher (SMTB).

Read More »
Archives