All reports
highLogic errorOther

Brevis Pico ZKVM: `operand_to_check` is not constrained to be a valid word in `eval_ecall`

Payout
$0
Protocol
Brevis Pico ZKVM
Disclosed
Sep 29, 2025
Source
sherlock

Brevis Pico, a ZKVM that executes RISC-V guest programs, has a soundness gap in its environment-call path. The FieldWordRangeChecker assumes the argument `operand_to_check` is a valid word, but the `eval_ecall` constraints never constrain that operand to be we …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.