ChainLight has discovered a soundness bug in the ZK circuit of the zkSync Era mainnet, and Matter Labs has deployed a fix.
On November 3rd, security company ChainLight disclosed that its researchers discovered a soundness bug in the ZK circuit of the zkSync Era mainnet on September 15th, and reported it on the 19th. The bug could potentially drain all tokens passed through cross-chain bridges, allowing malicious provers to generate proofs for invalidly executed blocks, which would be accepted by the verifier smart contracts on L1. Matter Labs has deployed a fix for the issue and awarded ChainLight 50,000 USDC as a reward.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Megabit will officially launch PENGU USDT perpetual contract at 20:00 today
Avalanche founder: Meme coins on Avalanche can not only be pledged, but also used as Gas tokens