KETJU Research

← The Register

other

zkSync Era Bridge

Rejected
Max sleeve
Reviewed
2026-08-17 · v1
Next review
2026-11-17
Research basis
Individual research
Chains
Ethereum · sovereign

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED ON A NO-DELAY CENSORSHIP CAPABILITY LAYERED ON TOP OF AN EMERGENCY PATH THAT BYPASSES ALL STANDING DELAYS. zkSync Era, Matter Labs’ ZK rollup, uses real SNARK validity proofs and a three-hour post-execution delay before withdrawals become actionable — materially faster than an optimistic rollup’s seven-day window, a genuine mechanism strength. But L2Beat rates it Stage 0, and its own risk summary states plainly that funds can be stolen through a malicious upgrade because the standard 4-day-3-hour to 8-day-3-hour upgrade delay can be bypassed entirely if the EmergencyUpgradeBoard initiates it instead, with no delay at all. Separately, an operator-controlled TransactionFilterer can block user transactions, including withdrawals, with zero delay — the same censorship-filter pattern that already sank Robinhood Chain in this batch. A real, confirmed compromise of a privileged key inside this exact organization in April 2025 compounds rather than offsets the structural concern.

The research file

Mechanism

zkSync Era is a general-purpose ZK rollup with full EVM compatibility, using SNARK validity proofs, the Boojum prover with PLONK and FFLONK verification, for a genuine cryptographic correctness guarantee. A ValidatorTimelock contract delays block execution, including withdrawals and other L2-to-L1 messages, by three hours before they are actionable on L1.

Control and governance

Confirmed directly from L2Beat: zkSync Era is rated Stage 0. Its risk summary states that funds can be stolen if a contract receives a malicious code upgrade; there is a four-day-three-hour to eight-day-three-hour delay on code upgrades unless the upgrade is initiated by the EmergencyUpgradeBoard, in which case there is no delay at all. It also states that users can be censored because the operator can implement a TransactionFilterer without delay — the same category of mechanism already documented for the already-rejected Robinhood Chain in this batch. Governance is structurally elaborate on paper: a Security Council (8 members, 4-of-8 to approve upgrades, 3-of-8 for a soft freeze, 6-of-8 for a hard freeze), Guardians (8 members, 5-of-8 for vetoes and approvals), and a ZK Foundation Multisig (3-of-6) jointly govern the standard path, with a fastest timeline of roughly 14 days and a Guardian-fallback path of roughly 44 days. But these three bodies also form the EmergencyUpgradeBoard, which bypasses every one of those delays and executes instantly — making the standing delay optional at the discretion of the same parties who would need to collude to abuse it.

Incident record

No exploit of the bridge or core Diamond contract itself was identified. But in April 2025 an attacker compromised the private key controlling zkSync’s own airdrop smart contracts and minted about 111 million ZK tokens, roughly $5M; Matter Labs stated the main network and user funds were unaffected, but this is a confirmed, realized instance of a privileged key being compromised inside this exact organization, not a hypothetical one. A separate incident in May 2025 saw zkSync’s official social accounts compromised to spread phishing links, an operational-security pattern worth noting alongside the governance structure above, though not itself a bridge-contract failure.

Exit under stress

L2Beat’s own exit-window rating is ”None” for the emergency-upgrade path and four days, three hours for the regular path — and even the regular path’s protection is undercut by the no-delay TransactionFilterer censorship capability described above. This is structurally the same profile that sank Linea and Robinhood Chain in this batch, not the Base, Arbitrum, or Optimism profile that cleared approval.

Comparison

Against Base, Arbitrum, and Optimism, all approved with limits in this registry, those chains have a standing seven-day withdrawal window that exists independent of the upgrade mechanism and no disclosed no-delay censorship filter; zkSync Era has neither guarantee intact. Against Linea, also rejected in this registry for a ”None” exit-window rating and a demonstrated unilateral halt, zkSync Era’s governance is nominally broader and more procedurally elaborate, but shares the same practical flaw of an emergency path that defeats the standing delay, plus a real recent admin-key compromise Linea does not carry.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.