The security agency ChainLight received a $50,000 bounty from Matter Labs for reporting a vulnerability in ZK-circuits
ChainCatcher news, the blockchain security organization ChainLight stated that its researchers discovered a soundness vulnerability in the ZK-circuits of the zkSync Era mainnet on September 15, and immediately reported the issue on the 19th. This vulnerability allows malicious provers to generate "proofs" for invalid executed blocks, which would be accepted by the validator smart contracts on L1. zkSync developers Matter Labs have since deployed a fix and provided ChainLight with a reward of 50,000 USDC, marking the first bounty awarded for a ZK-circuits vulnerability in zkSync Era.