All reports
mediumAccess controlEVM-Solidity

zkSync: Wrong encoding of the data in the `sendCompressedBytecode` function

Payout
$0
Protocol
zkSync
Disclosed
Feb 29, 2024
Source
code4rena

zkSync's bootloader intentionally validates that the calldata it forwards to Compressor::publishCompressedBytecode is strictly ABI-encoded, but that validation is incomplete and its offset arithmetic is unsafe. Because the code never checks that originalByteco …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.