Agent skill

ZKsync Era Defense Study

by tradecatlabs in tradecatlabs/vibe-coding-cn

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.

MITAuto-check passedSecurity

Install ZKsync Era Defense Study

skills CLI
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .claude/skills/web3-hunt-zksync-era && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web3-hunt-zksync-era
GitHub stars
17k
Used in
2 other repos
Token cost
~2.2k tokens
SKILL.md length
872 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.

  • Works in 3 steps: L1ERC20Bridge (legacy wrapper →… → L1SharedBridge (previous → absorbed into… → L1AssetRouter + L1Nullifier (current)
  • Learning what a well-defended L1 bridge and rollup protocol looks like
  • SKILL.md covers TARGET PROFILE, ARCHITECTURE (What Makes It…, ALL 25 ATTACK VECTORS TESTED and WHY THIS PROTOCOL IS…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This file documents a finished bug bounty hunt on ZKsync Era through Immunefi that produced zero submittable findings across 25 tested attack vectors. It is kept as a defense study: what makes a protocol hard to hunt, which patterns block the ten bug classes, and when to stop. The target profile covers the L2 rollup, a codebase of about 750K lines of Solidity, Rust and Yul, and several prior audits including OpenZeppelin.

A pre-dive scorecard shows the target passing the TVL, payout and complexity checks while getting a warning on audit quality, and the lesson drawn is to weight the audit firm's tier more heavily for very large protocols. The file also sketches the architecture, including the L1 bridge stack, the L2 system and user-space contracts and the diamond proxy pattern with shared storage, and then tabulates the tested vectors with the reason each one failed.

When your agent uses it

  • Learning what a well-defended L1 bridge and rollup protocol looks like
  • Deciding when to abandon a bug bounty target after repeated dead ends
  • Refining pre-dive scoring for protocols with very large codebases
  • Reviewing a log of attack vectors that were tried and why each failed

Example prompts

  • “Use the ZKsync Era study to tell me whether a large, heavily audited bridge is worth hunting.”
  • “Summarize the attack vectors that failed against ZKsync Era and the reason for each.”
  • “Add an audit firm tier check to my pre-dive target scorecard, based on this study.”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. L1ERC20Bridge (legacy wrapper → delegates to AssetRouter)
  2. L1SharedBridge (previous → absorbed into AssetRouter/Nullifier)
  3. L1AssetRouter + L1Nullifier (current)

What it can do on your machine

Read from SKILL.md and the folder at commit 5b76a8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

ZKsync Era Defense Study loads about 2.2k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 872 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tradecatlabs/vibe-coding-cn at commit 5b76a8f, republished under its MIT licence (© tradecatlabs). 872 words, ~2,246 tokens.

Download SKILL.mdSave it as .claude/skills/web3-hunt-zksync-era/SKILL.md (or your agent's skills folder).
name
web3-hunt-zksync-era
description
ZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a target. Contains architecture breakdown, 25 tested attack vectors, and pre-dive scoring refinements for large L1 bridge protocols.

LIVE HUNT: ZKsync Era (Immunefi) — COMPLETED, 0 FINDINGS

Outcome: 0 submittable findings after 5+ sessions, 22+ agents, 25+ contracts, 25+ attack vectors Lesson: This file exists as a DEFENSE STUDY — what a hardened protocol looks like, and when to stop hunting.


TARGET PROFILE

FieldValue
ProtocolZKsync Era (L2 rollup)
PlatformImmunefi
TVL$322M (L2BEAT Total Value Secured)
Bounty$100K minimum Critical, $1.1M max
Codebase750K LOC (Solidity + Rust + Yul)
AuditsOpenZeppelin V29 (June 2025), multiple prior audits
VersionProtocol V29.4
Repogithub.com/matter-labs/era-contracts
PrimacyPrimacy of Impact — even out-of-scope assets qualify
Prior payouts$50K (ChainLight ZK circuit bug)
Pre-Dive Scorecard
CheckResultScore
TVL > $500K$322MPASS
Max payout > $10K$100K minimumPASS
Simple protocol?750K LOC, L1↔L2 bridge + ZK + governancePASS (complex)
< 500 lines?750K LOCPASS
Audit qualityOpenZeppelin (top-tier) on ALL critical pathsWARNING

REFINEMENT: Pre-dive should weight audit quality MORE for large protocols. A protocol passing TVL/LOC/payout checks can still be unhuntable if OZ/ToB audited the exact code you'd hunt. Add "audit firm tier" as a SOFT kill signal for 500K+ LOC protocols.


ARCHITECTURE (What Makes It Hardened)

L1 Bridge Stack
Bridgehub (router)
  ├── L1AssetRouter (token routing)
  │     ├── L1Nullifier (deposit/withdrawal state)
  │     └── L1NativeTokenVault (token custody)
  ├── ChainTypeManager (chain registration)
  └── ValidatorTimelock (RBAC execution delay)
L2 System Contracts (kernel space 0x8000-0xFFFF)
Bootloader (0x8001) → AccountCodeStorage, NonceHolder, KnownCodeStorage,
ImmutableSimulator, ContractDeployer, L1Messenger (0x8008),
MsgValueSimulator, L2BaseToken (0x800a), SystemContext (0x800b),
BootloaderUtilities, Compressor, ComplexUpgrader
L2 User Space Contracts (0x10000+)
Create2Factory, Bridgehub, AssetRouter, NativeTokenVault, MessageRoot
Diamond Proxy Pattern (EIP-2535)
  • All facets (Admin, Executor, Mailbox, Getters) share single ZKChainStorage struct
  • No storage collision possible between facets
  • Function selectors explicitly mapped in DiamondCut

ALL 25 ATTACK VECTORS TESTED

Critical Path (Vectors 1-8)
#VectorTargetWhy It Failed
1UnsafeBytes offset miscalculationL1Nullifier _parseL2WithdrawalMessageAll callers pre-validate message length before UnsafeBytes calls
2Legacy/new boundary double-withdrawalL1Nullifier_isLegacyTxDataHash try/catch returns false on decode failure; encoding prefix discriminator prevents collision
3secondBridgeAddress return value manipulationBridgehub requestL2TransactionTwoBridges>0xFFFF check blocks system contracts; L2-side msg.sender auth makes crafted returns useless
4Failed deposit claim wrong amount (legacy encoding)L1Nullifier claimFailedDepositLegacy hash uses try/catch; depositHappened correctly tracks per-encoding-version
5V29 interop root forgeryExecutoraddChainBatchRoot requires onlyChain + onlyL2; historical roots verified via Merkle
6Missing access control on sibling functionAll bridge contractsEvery external function has appropriate modifier; checked all 50+ external functions
7Fee-on-transfer token accounting desyncNativeTokenVaultL1ERC20Bridge: if (amount != _amount) revert TokensWithFeesNotSupported()
8Governance timelock bypassValidatorTimelock5-role RBAC via AccessControlEnumerable; block.timestamp >= commitTimestamp + delay
Extended Surface (Vectors 9-25)
#VectorWhy It Failed
9GatewayTransactionFilterer bypassEra mainnet: transactionFilterer == address(0), not used
10Precommitment sentinel collision_revertBatches properly resets precommitment; sentinel values don't collide
11L2→L1 message forgery via sendToL1Anyone can call sendToL1, but L1 verifies sender=0x8008 in log — can't forge system log sender
12Compressor state diff manipulationpublishCompressedBytecode called only from bootloader context
13Admin privilege escalationDiamond proxy admin is governance; no facet can self-modify
14Fee calculation overflowAll fee math uses SafeMath or checked arithmetic
15Free L2 transaction abusereservedDynamic field properly handled; bootloader validates gas
16DataEncoding L1/L2 mismatchAll 10 encode/decode pairs verified consistent across L1↔L2
17NTV token registration race_ensureTokenRegistered is idempotent; double registration returns same assetId
18Asset ID collisionkeccak256(chainId, ntvAddress, tokenAddress) — no collision possible
19Beacon proxy CREATE2 collisionStandard CREATE2; address determined by deployer+salt+bytecodeHash
20Cross-contract reentrancyEach contract has independent ReentrancyGuard AND follows CEI
21Address aliasing collisionBijective mapping (add/subtract offset mod 2^160)
22Diamond proxy selector clashExplicit selector mapping in DiamondCut; duplicates would revert
23Priority tree manipulationMerkle range proofs; unprocessedIndex only moves forward
24Chain migration state corruptionforwardedBridgeMint validates consistency; atomic revert on mismatch
25Cross-chain message replayisWithdrawalFinalized[chainId][batch][index] prevents replay

Show full SKILL.md (300 more words)Show less

WHY THIS PROTOCOL IS UNHUNTABLE (Solidity Surface)

Defense Pattern 1: CEI Everywhere
solidity
// L1Nullifier._finalizeDeposit (line 411)
isWithdrawalFinalized[chainId][l2BatchNumber][l2MessageIndex] = true; // EFFECT first
// ... then external call to NTV

Every single withdrawal/claim/deposit path follows Check-Effect-Interact.

Defense Pattern 2: Independent Access Control on L2

Each L2 system contract independently enforces access:

  • L2BaseToken.transferFromTo: checks msg.sender against 3 allowed callers
  • L1Messenger.sendToL1: open to anyone, but L1 verifies sender field in log
  • SystemContext: onlyCallFromBootloader on all state-changing functions
  • No single RBAC failure cascades
Defense Pattern 3: Encoding Collision Resistance
LEGACY_ENCODING_VERSION = 0x00  (first byte)
NEW_ENCODING_VERSION    = 0x01  (first byte)

Different first byte = impossible to confuse one format for another.

Defense Pattern 4: Mature Legacy Boundary Handling

Three bridge generations coexist cleanly:

  1. L1ERC20Bridge (legacy wrapper → delegates to AssetRouter)
  2. L1SharedBridge (previous → absorbed into AssetRouter/Nullifier)
  3. L1AssetRouter + L1Nullifier (current)

Each boundary has explicit version checks, try/catch decoding, and fallback paths.

Defense Pattern 5: Audit Fix Quality

V29 OZ audit found 3 HIGHs. All fixes were thorough — not just patches but architectural improvements. The "least audited code" assumption (that fixes are hastily applied) did NOT hold here.


STRATEGIC TAKEAWAYS

When to Abandon a Large L1 Bridge Target
  1. After systematically testing top 8 attack vectors (Days 1-2): if all blocked, ROI drops exponentially
  2. If OZ/ToB audited the EXACT codebase version you're reviewing (not an older version)
  3. If 22+ automated agents all return clean across all contracts
  4. If encoding, access control, and CEI are all consistently applied with zero exceptions
What Could Still Work on ZKsync
  1. ZK circuits (Rust/RISC-V) — different skillset, different attack surface, prior $50K payout proves bugs exist there
  2. Bootloader assembly (Yul) — 5000+ lines of hand-written Yul, complex gas accounting, less audited
  3. New code drops (V30+) — fresh code = fresh bugs. Monitor era-contracts releases
  4. EVM emulation edge cases — EvmGasManager, EVM opcode compatibility gaps
  5. Interop protocol (when launched) — L2InteropRootStorage is minimal now, but interop = massive new surface
Pre-Dive Scoring Refinement

Add to the scorecard:

SOFT KILL: If protocol has OZ/ToB/Cyfrin audit on current version AND codebase > 500K LOC
           → expect 40+ hours for MAYBE 1 finding
           → only proceed if bounty floor > $50K AND you have protocol-specific expertise

NEXT: 08-ai-tools.md

© tradecatlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era of tradecatlabs/vibe-coding-cn.

Open the folder on GitHubat commit 5b76a8f

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in tradecatlabs/vibe-coding-cn, which our catalogue first saw on October 7, 2026.

Compare with similar skills

ZKsync Era Defense Study next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

ZKsync Era Defense Study compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
ZKsync Era Defense Study this skilltradecatlabs/vibe-coding-cn17k2 repos~2.2kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Flounderadshao/flounder518—~9.2kAutomated safety check: PassAGPL-3.0
Smart Contract Entry Point Analyzertrailofbits/skills7.5k1 repos~2.4kAutomated safety check: NotesCC-BY-SA-4.0
Reentrancy Auditoralt-research2/SolidityGuard104—~1.8kAutomated safety check: PassCustom licence

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Flounder

    adshao/flounder

    Operates Flounder, an autonomous white-hat security auditor.

    518 GitHub stars~9.2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Official

    Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

    7.5k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Reentrancy Auditor

    alt-research2/SolidityGuard

    Deep reentrancy vulnerability analysis for Solidity contracts.

    104 GitHub stars~1.8k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed

More from tradecatlabs/vibe-coding-cn

All 17 skills in this repo
  • Auto Skill Builder

    tradecatlabs/vibe-coding-cn

    Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.

    17k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Web3 Smart Contract Grep Arsenal

    tradecatlabs/vibe-coding-cn

    A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

    17k GitHub starsUsed in 2 repos~3.3k tokens
    Auto-check passed
  • Auto tmux Operator

    tradecatlabs/vibe-coding-cn

    Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.

    17k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: warnings
  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    Auto-check passed
  • Math Computation

    tradecatlabs/vibe-coding-cn

    Runs reproducible math computations and counterexample searches with SymPy, NumPy and mpmath, logging evidence without presenting results as proofs.

    17k GitHub stars~881 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about ZKsync Era Defense Study

What does ZKsync Era Defense Study do?

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. This file documents a finished bug bounty hunt on ZKsync Era through Immunefi that produced zero submittable findings across 25 tested attack vectors. It is kept as a defense study: what makes a protocol hard to hunt, which patterns block the ten bug classes, and when to stop.

When should I use ZKsync Era Defense Study?

ZKsync Era Defense Study fits situations like: learning what a well-defended L1 bridge and rollup protocol looks like; deciding when to abandon a bug bounty target after repeated dead ends; refining pre-dive scoring for protocols with very large codebases; reviewing a log of attack vectors that were tried and why each failed.

How do I install ZKsync Era Defense Study in Claude Code?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a claude-code`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era in tradecatlabs/vibe-coding-cn) into .claude/skills/web3-hunt-zksync-era in your project. Claude Code loads it when a task matches its description.

How do I install ZKsync Era Defense Study in Codex?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a codex`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era in tradecatlabs/vibe-coding-cn) into .agents/skills/web3-hunt-zksync-era in your project. Codex loads it when a task matches its description.

Can I use ZKsync Era Defense Study in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web3-hunt-zksync-era, .gemini/skills/web3-hunt-zksync-era, .github/skills/web3-hunt-zksync-era and .opencode/skills/web3-hunt-zksync-era in your project.

What does ZKsync Era Defense Study need to run?

SKILL.md names no scripts, command-line tools or credentials: ZKsync Era Defense Study is instructions for the agent only.

Does ZKsync Era Defense Study access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is ZKsync Era Defense Study safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does ZKsync Era Defense Study use?

ZKsync Era Defense Study is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does ZKsync Era Defense Study use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to ZKsync Era Defense Study?

Skills that share tags, products or a category with ZKsync Era Defense Study: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Flounder (adshao/flounder, 518 stars) and Smart Contract Entry Point Analyzer (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains ZKsync Era Defense Study?

tradecatlabs (a GitHub user) maintains it in tradecatlabs/vibe-coding-cn, which has 17,386 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: tradecatlabs/vibe-coding-cn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.