highLogic errorOther
Brevis Pico ZKVM: `operand_to_check` is not constrained to be a valid word in `eval_ecall`
- Payout
- $0
- Protocol
- Brevis Pico ZKVM
- Disclosed
- Sep 29, 2025
- Source
- sherlock
Brevis Pico, a ZKVM that executes RISC-V guest programs, has a soundness gap in its environment-call path. The FieldWordRangeChecker assumes the argument `operand_to_check` is a valid word, but the `eval_ecall` constraints never constrain that operand to be we …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.