Trail of Bits

Scroll Euclid Phase 2

Type

Security review

Client

Scroll

Date

2025-04

Domain

Blockchain

Effort

4 wks

Section

Scroll

Trail of Bits's security review of Scroll (Apr 2025) identified 5 issues: 1 low, and 4 informational.

Findings · 5

  1. 1 Polynomial evaluation does not consider roots of unity edge case Informational
  2. 2 Transaction data length missing from the ChunkInfo PI hash Informational
  3. 3 Risky use of GITHUB_ENV in GitHub action Informational
  4. 4 Unpinned external GitHub CI/CD action versions Low
  5. 5 Potential credential persistence in artifacts Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related