All reports
mediumLogic errorEVM-Solidity

zkSync: Potential Gas Manipulation via Bytecode Compression

Payout
$0
Protocol
zkSync
Disclosed
Feb 29, 2024
Source
code4rena

The zkSync Compressor's `publishCompressedBytecode` function validates that dictionary chunks are within bounds and that referenced chunks match the original bytecode, but it never requires every dictionary chunk to actually be referenced. A malicious sequence …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.