Trail of Bits

Scroll ZkEVM 4844 Blob

Type

Security review

Client

Scroll

Date

2024-04

Domain

Blockchain

Effort

6 wks

Section

Scroll

Trail of Bits's security review of Scroll (Apr 2024) identified 7 issues: 1 high, and 6 informational.

Findings · 7

  1. 1 BarycentricEvaluationConfig circuit does not constrain the size of blob values Informational
  2. 2 Public statement not included in the challenge preimage High
  3. 3 Challenges are not uniformly random due to modulo bias Informational
  4. 4 Initial oset is ignored in assign_data_bytes Informational
  5. 5 Witness generation and constraint generation are not separated Informational
  6. 6 Constraints are not suciently documented Informational
  7. 7 BarycentricEvaluationConfig circuit returns zero on roots of unity Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related