Security guides every decision we make at zkSync. Here’s a look at the measures we’ve taken to secure zkSync Era as a part of our zero-compromise approach to security. #securingthemission
1/10
Since zkSync Era launched on Testnet, we’ve run:
• Multiple internal audits testing the entire system
• Public audits with @OpenZeppelin and @HalbornSecurity, covering the full scope of the system
• Public contests with @code4rena featuring $345k in prizes
(cont'd)
2/
(cont'd)
• A public bug bounty with @immunefi, featuring a $100k expansion in scope and rewards
• Audits with independent researchers for specific parts of the system
3/
Building a secure network requires a multi-dimensional approach to protect users against all threats. Combining methods such as audits, contests, bug bounties & independent reviews is valuable because each delivers unique strengths & helps us catch even the most subtle bugs.
4/
Audit Contests
Contests like @code4rena’s are ideal for finding unique bugs. Auditors aim to find the most unusual bugs because the reward increases as a function of the uniqueness of the bug.
Tier-1 auditors like @OpenZeppelin & @HalbornSecurity provide independent insights from their experience with issues in other codebases. Audits are about the quality of the auditors, which is why we chose the best.
Responsible disclosure and community contributions to security are very important for zkSync Era. Bug bounties like @immunefi incentivize whitehats to search for bugs and report them directly to us for a bounty.
We work with independent security experts for more specialized topics, like identifying critical bugs in bridges, and ZK circuits. If you’re an independent researcher with a record of public disclosure looking to do work on zkSync Era, get in touch.
8/
User Education
We do our best to warn the community about potential scams, but there are many out there. Always check our official Twitter page or Discord for updates. Tips on how to spot a scam ⬇️
Beyond these measures, we constantly invest in security through automated tooling, code reviews, and internal audits to ensure zkSync Era is a future-proof zkEVM. Security is not about checking boxes; it’s a continuous state of mind.
10/
• • •
Missing some Tweet in this thread? You can try to
force a refresh
The mission continues. The wave of projects joining zkSync Era shows no signs of slowing down, and we’re excited to share another five updates from our fast-growing ecosystem. #jointhemission
🧵(1/7)
Immersive gaming project @HorizonLandMeta announced their collaboration with zkSync Era to build a decentralized platform for builders constructing their own open and accessible metaverse solutions.
On-chain data services solution @OKLink announced their zkSync explorer, providing multi-dimensional on-chain data for zkSync Era ahead of our Full Launch Alpha milestone.
The mission continues. More projects are joining the new zkSync Era every week, and we’re excited to share another five updates from our fast-growing ecosystem. #jointhemission
🧵(1/7)
Secure interchain communication is coming to zkSync Era with @axelarcore, who just announced their interoperable virtual machine. Read about what it will bring to the zkSync ecosystem, and how it aims to unlock widespread web3 adoption, below.
Game-Fi project @MetaMechaverse announced that their game MechaGacha is coming to zkSync Era, and all their digital assets will also be integrated with the protocol.
Security is a function of (time) x (money at stake).
Here is our 4-phase plan of gradually removing the training wheels while keeping the @zkSync Era∎ secure:
1/10
PHASE 1: Ignition
👉 you are here 👈
- Initial audits are complete
- Code 4rena contest for L1 is done
- Code is open sourced
- Bug bounties are open
- Team can instantly upgrade contracts
- Whitelisted users can deposit up to 10 ETH
- 2FA via whitelisted sequencer is on 2/10
PHASE 2: Ascent
Will begin with the Full Launch Alpha.
- Code 4rena contest for L2 is done
- Team can still instantly upgrade contracts
- Withdrawals is capped at 10% of the total token value per day; more requires manual approval 3/10
Visit our workshops, keynotes, panel talks, and registration booth so we can swag you out with freebies and free BUIDLBux Food Truck tokens to refuel between #BUIDLing.👇🏼
The mission continues. There was some big news for zkSync last week, and the wave of projects joining zkSync Era shows no signs of slowing down. We’re excited to share another five updates from our fast-growing ecosystem. #jointhemission
🧵(1/7)
Web3 browser @trycarbonio announced they will be bringing light speed browsing to zkSync Era, and explained why they’re excited to create the best possible ZK-rollup user experience.