proof-verification

2 articles
sort: new top best
clear filter
0 7/10
vulnerability

ChainLight researchers discovered a critical soundness bug in zkSync Era's ZK-circuit that allowed malicious provers to generate fake proofs for invalidly executed blocks. The bug was responsibly disclosed to Matter Labs, which deployed a fix and awarded a 50K USDC bounty.

zkSync Era ChainLight Matter Labs EraVM zk_evm sync_vm L2EthToken MsgValueSimulator Code4rena
medium.com · ChainLight · 19 hours ago · details
0 7/10
vulnerability

zkSync Lite suffered a critical vulnerability in its packed floating-point format implementation where unconstrained witness allocation in the parse_with_exponent_le function allowed attackers to generate valid proofs with arbitrary mantissa values, enabling unauthorized token minting, freezing, and transaction tampering. The vulnerability was patched by enforcing constraints on mantissa calculations using an into_allocated_num method.

zkSync Lite zkSync Era LonelySloth Immunefi franklin-crypto ZK Rollup CVE-2023-XXXXX
medium.com · LonelySloth · 19 hours ago · details