ZKsync security review
ZKsync is an Ethereum layer-2 that settles with validity proofs and ships native account abstraction and paymasters. Hackerbane audits ZKsync Era contracts, smart accounts, and the parts of the proof system your safety claims depend on.
What we review
ZKsync's virtual machine is close to Ethereum's but not identical, and account abstraction is the default, so “an ordinary wallet signed this” is often the wrong assumption. When a safety property depends on the proof system, we review the circuit boundary and who can update it.
- Contracts that assume Ethereum edge cases ZKsync does not share.
- Paymasters and the gas a stranger can make you spend.
- Bridges and the messages you treat as proven.
- Automation acting as the smart account.
When the proof is part of your guarantee
If a circuit is what makes a contract safe, we review the parts that decide what the circuit accepts. A valid proof of a weak specification is still a weak specification, and our report says which one you have.
Other pages
Next step
Request an audit
Share your repo, whether you deploy on ZKsync Era or another ZK Stack chain, and your timeline – we'll propose an audit plan and estimate.