All reports
mediumLogic errorOther

Brevis Pico ZKVM: First chunk having cpu chip is incorrectly checked in convert circuit

Payout
$0
Protocol
Brevis Pico ZKVM
Disclosed
Sep 29, 2025
Source
sherlock

Brevis Pico's convert recursion circuit enforces that the first execution chunk must carry a CPU chip, but the guard is evaluated against an already-incremented chunk counter. Because current_chunk is advanced to the 'expected next chunk' before the assert_fel …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.