zkSync ∎ Profile picture
Mar 21 10 tweets 5 min read
Security guides every decision we make at zkSync. Here’s a look at the measures we’ve taken to secure zkSync Era as a part of our zero-compromise approach to security. #securingthemission

1/10
Since zkSync Era launched on Testnet, we’ve run:

• Multiple internal audits testing the entire system
• Public audits with @OpenZeppelin and @HalbornSecurity, covering the full scope of the system
• Public contests with @code4rena featuring $345k in prizes

(cont'd)

2/
(cont'd)

• A public bug bounty with @immunefi, featuring a $100k expansion in scope and rewards
• Audits with independent researchers for specific parts of the system

3/
Building a secure network requires a multi-dimensional approach to protect users against all threats. Combining methods such as audits, contests, bug bounties & independent reviews is valuable because each delivers unique strengths & helps us catch even the most subtle bugs.

4/
Audit Contests

Contests like @code4rena’s are ideal for finding unique bugs. Auditors aim to find the most unusual bugs because the reward increases as a function of the uniqueness of the bug.

View our latest contest: code4rena.com/contests/2023-…

5/
Traditional Audits

Tier-1 auditors like @OpenZeppelin & @HalbornSecurity provide independent insights from their experience with issues in other codebases. Audits are about the quality of the auditors, which is why we chose the best.

View our reports:era.zksync.io/docs/dev/troub…

6/
Bug Bounties

Responsible disclosure and community contributions to security are very important for zkSync Era. Bug bounties like @immunefi incentivize whitehats to search for bugs and report them directly to us for a bounty.

Check out our bug bounty: immunefi.com/bounty/zksynce…

7/
Independent Experts

We work with independent security experts for more specialized topics, like identifying critical bugs in bridges, and ZK circuits. If you’re an independent researcher with a record of public disclosure looking to do work on zkSync Era, get in touch.

8/
User Education

We do our best to warn the community about potential scams, but there are many out there. Always check our official Twitter page or Discord for updates. Tips on how to spot a scam ⬇️



9/
Beyond these measures, we constantly invest in security through automated tooling, code reviews, and internal audits to ensure zkSync Era is a future-proof zkEVM. Security is not about checking boxes; it’s a continuous state of mind.

10/

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with zkSync ∎

zkSync ∎ Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @zksync

Mar 20
The mission continues. The wave of projects joining zkSync Era shows no signs of slowing down, and we’re excited to share another five updates from our fast-growing ecosystem. #jointhemission

🧵(1/7)
Immersive gaming project @HorizonLandMeta announced their collaboration with zkSync Era to build a decentralized platform for builders constructing their own open and accessible metaverse solutions.



🧵(2/7)
On-chain data services solution @OKLink announced their zkSync explorer, providing multi-dimensional on-chain data for zkSync Era ahead of our Full Launch Alpha milestone.



🧵(3/7)
Read 7 tweets
Feb 27
The mission continues. More projects are joining the new zkSync Era every week, and we’re excited to share another five updates from our fast-growing ecosystem. #jointhemission

🧵(1/7)
Secure interchain communication is coming to zkSync Era with @axelarcore, who just announced their interoperable virtual machine. Read about what it will bring to the zkSync ecosystem, and how it aims to unlock widespread web3 adoption, below.



🧵(2/7)
Game-Fi project @MetaMechaverse announced that their game MechaGacha is coming to zkSync Era, and all their digital assets will also be integrated with the protocol.



🧵(3/7)
Read 7 tweets
Feb 23
Security is a function of (time) x (money at stake).

Here is our 4-phase plan of gradually removing the training wheels while keeping the @zkSync Era∎ secure:

1/10
PHASE 1: Ignition

👉 you are here 👈

- Initial audits are complete
- Code 4rena contest for L1 is done
- Code is open sourced
- Bug bounties are open
- Team can instantly upgrade contracts
- Whitelisted users can deposit up to 10 ETH
- 2FA via whitelisted sequencer is on 2/10
PHASE 2: Ascent

Will begin with the Full Launch Alpha.

- Code 4rena contest for L2 is done
- Team can still instantly upgrade contracts
- Withdrawals is capped at 10% of the total token value per day; more requires manual approval 3/10
Read 9 tweets
Feb 21
Let’s BUIDL together at @EthereumDenver 2023.

Visit our workshops, keynotes, panel talks, and registration booth so we can swag you out with freebies and free BUIDLBux Food Truck tokens to refuel between #BUIDLing.👇🏼

1/11
🙌 zkSync Era #BUIDLWeek Booth (Feb 24 - March 1)

Kick off the week by collecting your ETHDenver x zkSync Era POAP, grabbing free swag, and winning game prizes. Find our booth by registration.

2/11
💻 Dev Workshop — Introduction to L2s: BUIDL apps on the zkEVM (Feb 25 | 1pm MST)

Learn to BUIDL apps on the zkEVM with zkSync Era’s developer relations engineer @uF4No.

Registration: eventbrite.com/e/ethdenver-zk…

3/11
Read 11 tweets
Feb 20
The mission continues. There was some big news for zkSync last week, and the wave of projects joining zkSync Era shows no signs of slowing down. We’re excited to share another five updates from our fast-growing ecosystem. #jointhemission

🧵(1/7)
Web3 browser @trycarbonio announced they will be bringing light speed browsing to zkSync Era, and explained why they’re excited to create the best possible ZK-rollup user experience.



🧵(2/7)
On-chain and off-chain analytics solution @aki_protocol announced their support for zkSync. Stay tuned for more details on our collaboration.



🧵(3/7)
Read 7 tweets
Feb 16
The wait is over.

All aboard zkSync Era∎ Mainnet!

Today, Ethereum's first zkEVM is:

• Opening mainnet to builders 🥳
• Adopting a brand new name 🎈
• Open-sourcing its entire codebase 🎆

blog.matter-labs.io/8b8964ba7c59

1/8
Community = <3

We want to take a moment to thank our community for their unwavering support in helping us make it to this milestone.

We’re proud and humbled that you’ve been with us every step of the journey.

2/8
zkSync 2.0 → zkSync Era∎

zkEVM is the endgame for scaling Ethereum. It's the beginning of universal blockchain adoption by millions.

zkSync is built to bring about a new era of freedom, individual sovereignty, and the power of network communities.

3/8
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(