0xPARC / zk-bug-tracker

A community-maintained collection of bugs, vulnerabilities, and exploits in apps using ZK crypto.
MIT License
617 stars 55 forks source link

Overflow vulnerability in Polygon's zkEVM Storage machine #18

Open georgwiese opened 6 months ago

georgwiese commented 6 months ago

Just came across this bug tracker, very cool :)

I found a bug in the Polygon zkEVM which allows a malicious prover to return "0" when reading any storage slot (and possibly also exploit other CRUD operations). Sounds like it fits in well here! All the details are in the blog post.