zkSync Era Bridge
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON A NO-DELAY CENSORSHIP CAPABILITY LAYERED ON TOP OF AN EMERGENCY PATH THAT BYPASSES ALL STANDING DELAYS. zkSync Era, Matter Labs’ ZK rollup, uses real SNARK validity proofs and a three-hour post-execution delay before withdrawals become actionable — materially faster than an optimistic rollup’s seven-day window, a genuine mechanism strength. But L2Beat rates it Stage 0, and its own risk summary states plainly that funds can be stolen through a malicious upgrade because the standard 4-day-3-hour to 8-day-3-hour upgrade delay can be bypassed entirely if the EmergencyUpgradeBoard initiates it instead, with no delay at all. Separately, an operator-controlled TransactionFilterer can block user transactions, including withdrawals, with zero delay — the same censorship-filter pattern that already sank Robinhood Chain in this batch. A real, confirmed compromise of a privileged key inside this exact organization in April 2025 compounds rather than offsets the structural concern.
- The TransactionFilterer capability is removed, or is demonstrated to require the same delay and approval path as a standard upgrade
- The EmergencyUpgradeBoard’s ability to bypass the standard multi-day delay is removed or itself gated behind a minimum standing delay
- zkSync Era reaches at least Stage 1 per L2Beat’s published criteria
- Twelve consecutive months with no privileged-key compromise anywhere in the Matter Labs or ZK Foundation governance or operational infrastructure, counted from the April 2025 incident
The research file
Mechanism
zkSync Era is a general-purpose ZK rollup with full EVM compatibility, using SNARK validity proofs, the Boojum prover with PLONK and FFLONK verification, for a genuine cryptographic correctness guarantee. A ValidatorTimelock contract delays block execution, including withdrawals and other L2-to-L1 messages, by three hours before they are actionable on L1.
Control and governance
Confirmed directly from L2Beat: zkSync Era is rated Stage 0. Its risk summary states that funds can be stolen if a contract receives a malicious code upgrade; there is a four-day-three-hour to eight-day-three-hour delay on code upgrades unless the upgrade is initiated by the EmergencyUpgradeBoard, in which case there is no delay at all. It also states that users can be censored because the operator can implement a TransactionFilterer without delay — the same category of mechanism already documented for the already-rejected Robinhood Chain in this batch. Governance is structurally elaborate on paper: a Security Council (8 members, 4-of-8 to approve upgrades, 3-of-8 for a soft freeze, 6-of-8 for a hard freeze), Guardians (8 members, 5-of-8 for vetoes and approvals), and a ZK Foundation Multisig (3-of-6) jointly govern the standard path, with a fastest timeline of roughly 14 days and a Guardian-fallback path of roughly 44 days. But these three bodies also form the EmergencyUpgradeBoard, which bypasses every one of those delays and executes instantly — making the standing delay optional at the discretion of the same parties who would need to collude to abuse it.
Incident record
No exploit of the bridge or core Diamond contract itself was identified. But in April 2025 an attacker compromised the private key controlling zkSync’s own airdrop smart contracts and minted about 111 million ZK tokens, roughly $5M; Matter Labs stated the main network and user funds were unaffected, but this is a confirmed, realized instance of a privileged key being compromised inside this exact organization, not a hypothetical one. A separate incident in May 2025 saw zkSync’s official social accounts compromised to spread phishing links, an operational-security pattern worth noting alongside the governance structure above, though not itself a bridge-contract failure.
Exit under stress
L2Beat’s own exit-window rating is ”None” for the emergency-upgrade path and four days, three hours for the regular path — and even the regular path’s protection is undercut by the no-delay TransactionFilterer censorship capability described above. This is structurally the same profile that sank Linea and Robinhood Chain in this batch, not the Base, Arbitrum, or Optimism profile that cleared approval.
Comparison
Against Base, Arbitrum, and Optimism, all approved with limits in this registry, those chains have a standing seven-day withdrawal window that exists independent of the upgrade mechanism and no disclosed no-delay censorship filter; zkSync Era has neither guarantee intact. Against Linea, also rejected in this registry for a ”None” exit-window rating and a demonstrated unilateral halt, zkSync Era’s governance is nominally broader and more procedurally elaborate, but shares the same practical flaw of an emergency path that defeats the standing delay, plus a real recent admin-key compromise Linea does not carry.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- L2Beat — ZKsync Era · primary · accessed 2026-08-18
Supports: Stage 0 rating, EmergencyUpgradeBoard no-delay bypass, TransactionFilterer censorship risk, exit window ratings, Security Council and Guardian thresholds - Halborn — explained: the ZKsync hack, April 2025 · secondary · accessed 2026-08-18
Supports: admin-key compromise, loss figure, airdrop-contract scope - The Defiant — zkSync suffers $5M loss after admin wallet exploit · secondary · accessed 2026-08-18
Supports: secondary confirmation of April 2025 incident - ZKsync Docs — audits · primary · accessed 2026-08-18
Supports: audit listing - Mitosis University — April 2025 zkSync exploit: timeline, impact, and security lessons · secondary · accessed 2026-08-18
Supports: incident timeline, official response
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |