Published: May 2, 2025
8
11
108

1/ Last week, Scroll performed an emergency mainnet upgrade to fix two critical bugs - one in our zk proving system and one in our bridge contract. Here's a breakdown of what happened, how we acted to protect users, and what we plan to strengthen security moving forward. 🧵

2/ Issue 1: OpenVM Circuit Soundness A bug in the OpenVM circuit (reported by @axiom_xyz) could have allowed a colluding sequencer and prover to generate invalid zk proofs that still pass onchain verification.

3/ Issue 2: Bridge Message Spoofing A separate bug (reported by @WhiteHatMage via @immunefi) could have allowed attackers to mint ETH or ERC20 tokens on Scroll by spoofing messages across L1 and L2. This vulnerability came from a change introduced during the Euclid upgrade.

4/ Actions We immediately paused the affected EnforcedTxGateway contract after receiving the report to protect user assets. Scroll engineers quickly developed and tested fixes for both bugs in collaboration with Axiom.

5/ Emergency Upgrade Execution After rigorous internal and external reviews, the Security Council signed off on an emergency upgrade transaction. The patches were deployed on April 25, and Scroll mainnet was safely upgraded without user impact.

6/Massive Shoutouts @axiom_xyz for their responsible disclosure and collaboration on fixing the OpenVM circuit issue. @WhiteHatMage for spotting the bridge vulnerability and responsibly reporting it via @immunefi, who's been awarded a $1M USD bounty.

7/ What's Next? We are taking several steps to improve security further: • Working with @trailofbits to implement more protections • Adding more static analysis and fuzzing tests • Exploring the formal verification for the bridge • Improving the internal review and external

8/ Security is a continuous journey and will always be a key focus for Scroll. This incident shows how strong community collaboration, fast actions, and a robust Security Council model keep users safe. Check out the full post-mortem report: https://forum.scroll.io/t/repo...

Image in tweet by Scroll

@Scroll_ZKP Author of one of reports here šŸ™‹. Big shout-out to the team truly for their immediate response and mitigation. Proof of their commitment to security. šŸ§™ā€ā™‚ļøšŸ“œ

@Scroll_ZKP Impressed by the transparency here. Quick bug fixes and clear comms are what separate good projects from great ones. This kind of proactive approach is exactly what builds long-term trust in the zk ecosystem.

@Scroll_ZKP Mainnet should not be shipped unless full-proof. But Web3 teams are in a hurry. Even at the cost of security.

@Scroll_ZKP scroll always on their toes, respect

Share this thread

Read on Twitter

View original thread

Navigate thread

1/16