Sample audit report — see how a Hackerbane report is structured. Open the report →

ZKsync security review

ZKsync is an Ethereum layer-2 that settles with validity proofs and ships native account abstraction and paymasters. Hackerbane audits ZKsync Era contracts, smart accounts, and the parts of the proof system your safety claims depend on.

What we review

ZKsync's virtual machine is close to Ethereum's but not identical, and account abstraction is the default, so “an ordinary wallet signed this” is often the wrong assumption. When a safety property depends on the proof system, we review the circuit boundary and who can update it.

  • Contracts that assume Ethereum edge cases ZKsync does not share.
  • Paymasters and the gas a stranger can make you spend.
  • Bridges and the messages you treat as proven.
  • Automation acting as the smart account.

When the proof is part of your guarantee

If a circuit is what makes a contract safe, we review the parts that decide what the circuit accepts. A valid proof of a weak specification is still a weak specification, and our report says which one you have.

Next step

Request an audit

Share your repo, whether you deploy on ZKsync Era or another ZK Stack chain, and your timeline – we'll propose an audit plan and estimate.