zkSync Era Bridge
We reject zkSync Era because it has a no-delay censorship tool layered on an emergency path that bypasses all standing delays. Matter Labs’ ZK rollup uses real SNARK validity proofs and a three-hour post-execution delay before withdrawals become actionable, materially faster than an optimistic rollup’s seven-day window and a genuine strength in the mechanism. But L2Beat rates it Stage 0, and its own risk summary says funds can be stolen through a malicious upgrade because the standard 4-day-3-hour to 8-day-3-hour upgrade delay can be bypassed entirely if the EmergencyUpgradeBoard initiates it, with no delay at all. Separately, an operator-controlled TransactionFilterer can block user transactions, including withdrawals, with zero delay. The same censorship-filter pattern already sank Robinhood Chain in this batch. A real, confirmed compromise of a privileged key inside this organization in April 2025 adds to the structural concern.
- The TransactionFilterer capability is removed, or is demonstrated to require the same delay and approval path as a standard upgrade
- The EmergencyUpgradeBoard’s ability to bypass the standard multi-day delay is removed or itself gated behind a minimum standing delay
- zkSync Era reaches at least Stage 1 per L2Beat’s published criteria
- Twelve consecutive months with no privileged-key compromise anywhere in the Matter Labs or ZK Foundation governance or operational infrastructure, counted from the April 2025 incident
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
zkSync Era is a general-purpose ZK rollup with full EVM compatibility. It uses SNARK validity proofs and the Boojum prover with PLONK and FFLONK verification, which provide a real cryptographic correctness guarantee. A ValidatorTimelock contract delays block execution, including withdrawals and other L2-to-L1 messages, by three hours before users can act on them on L1.
Control and governance
L2Beat confirms that zkSync Era is rated Stage 0. Its risk summary says funds can be stolen if a contract receives a malicious code upgrade. Code upgrades face a four-day-three-hour to eight-day-three-hour delay unless the EmergencyUpgradeBoard initiates the upgrade, in which case there is no delay at all. It also says the operator can censor users by implementing a TransactionFilterer without delay. This is the same type of mechanism already documented for the already-rejected Robinhood Chain in this batch. The formal governance structure is complex: a Security Council (8 members, 4-of-8 to approve upgrades, 3-of-8 for a soft freeze, 6-of-8 for a hard freeze), Guardians (8 members, 5-of-8 for vetoes and approvals), and a ZK Foundation Multisig (3-of-6) jointly govern the standard path, with a fastest timeline of roughly 14 days and a Guardian-fallback path of roughly 44 days. But these three bodies also form the EmergencyUpgradeBoard, which can bypass every delay and act at once. This makes the standing delay optional for the same parties who would need to collude to abuse it.
Incident record
We found no exploit of the bridge or core Diamond contract itself. But in April 2025, an attacker compromised the private key controlling zkSync’s own airdrop smart contracts and minted about 111 million ZK tokens, roughly $5M. Matter Labs said the main network and user funds were unaffected, but this was a real compromise of a privileged key inside this organization, not a hypothetical case. In a separate incident in May 2025, attackers compromised zkSync’s official social accounts to spread phishing links. That event shows an operational-security pattern worth noting beside the governance structure above, though it was not itself a bridge-contract failure.
Exit under stress
L2Beat gives the emergency-upgrade path an exit-window rating of ”None” and the regular path a window of four days, three hours. Even the regular path offers less protection because the no-delay TransactionFilterer described above can censor users. This is the same basic profile that sank Linea and Robinhood Chain in this batch, not the Base, Arbitrum, or Optimism profile that cleared approval.
Comparison
Base, Arbitrum, and Optimism are all approved with limits in this registry. Those chains have a standing seven-day withdrawal window that exists apart from the upgrade mechanism, and they disclose no no-delay censorship filter. zkSync Era keeps neither guarantee intact. Linea is also rejected in this registry for a ”None” exit-window rating and a demonstrated unilateral halt. zkSync Era has broader governance and more formal procedures on paper, but it shares the same practical flaw: an emergency path defeats the standing delay. It also carries a real recent admin-key compromise that Linea does not.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- L2Beat — ZKsync Era · primary · accessed 2026-08-18
Supports: Stage 0 rating, EmergencyUpgradeBoard no-delay bypass, TransactionFilterer censorship risk, exit window ratings, Security Council and Guardian thresholds - Halborn — explained: the ZKsync hack, April 2025 · secondary · accessed 2026-08-18
Supports: admin-key compromise, loss figure, airdrop-contract scope - The Defiant — zkSync suffers $5M loss after admin wallet exploit · secondary · accessed 2026-08-18
Supports: secondary confirmation of April 2025 incident - ZKsync Docs — audits · primary · accessed 2026-08-18
Supports: audit listing - Mitosis University — April 2025 zkSync exploit: timeline, impact, and security lessons · secondary · accessed 2026-08-18
Supports: incident timeline, official response
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |