Cointime

Download App
iOS & Android

Polygon zkEVM: Results of Hexens' Security Audit

Validated Project

A comprehensive security audit of Polygon zkEVM began in December. Two security teams have been independently stress-testing all components, including the prover and smart contracts for Polygon zkEVM.

The result of the audit by one of those security teams, Hexens, is now available. (You can view the full report here.) In keeping with Polygon zkEVM’s built-in-public ethos, we wanted to outline the findings.

‍In total, Hexens found nine vulnerabilities, ranging in severity from critical to low—and seven additional recommendations related to informational gaps in Polygon zkEVM’s documentation.

‍As of this writing, all 16 issues have been fixed.

Those fixes related to the network were made available on the audit-upgraded testnet that went live earlier this month.

Polygon zkEVM: Setting the Standard

The security audit for Polygon zkEVM has been thorough, rigorous, and is not even finished. In addition to Hexens, another security team, Spearbit, conducted a parallel audit of Polygon zkEVM’s smart contracts. The Polygon Hermez team also conducted its own internal audit. Last week, Spearbit began yet another audit, focused on the ZK circuits and cryptography.

‍No technology, especially novel technology like Polygon zkEVM, can be entirely de-risked. However, Polygon Labs is establishing best practices for securing zkEVMs. When Mainnet Beta for Polygon zkEVM launches, all 35 components will have been audited three times, by 26 researchers, over the course of nearly four months. ‍

In the coming weeks, we will share the findings of the remaining audits as the reports are finalized.

Audit Scope

Hexens’ security review focused on the client stack. This includes the RPC node, sequencer, and aggregator, where proofs are generated. Hexens also reviewed PIL, the language for creating polynomial identities, and the smart contract for bridging assets to Ethereum.

Audit Findings

In total, four critical vulnerabilities were found in Hexens’ audit. One relied on an exploitation of the mechanism that makes Polygon zkEVM censorship resistant. Another used the extended features of ERC-777 tokens to launch a re-entrancy attack on the bridge smart contract. The other two critical vulnerabilities relied on manipulation of missing binary constraints: one in the Storage state machine and one in the ROM.

The remaining vulnerabilities were non-critical. Two in particular are worth highlighting because they illustrate the technical complexity of designing a rollup that increases Ethereum’s throughput without sacrificing EVM-equivalence.

In the EVM, the ecrecover function is used to recover the public key of a transaction sender from the transaction signature. This is an important function for verifying the authenticity of a transaction. A discrepancy with how ecrecover is implemented in zkASM, the assembly language used to implement the EVM in Polygon zkEVM, could have allowed a dishonest user to generate a proof for a transaction that is not compliant with the EVM.

Another non-critical vulnerability would have relied on a difference in the maximum size allowed for gas limits and chain IDs between Polygon zkEVM and EVM implementations, allowing a dishonest user to spam the sequencer and potentially interrupt the network’s availability.

For a comprehensive resource on Polygon zkEVM, check out the documentation wiki. And if you’re interested in (or perplexed by) Zero Knowledge, follow Polygon Labs’ dedicated ZK handle, @0xPolygonZK, and head over to our ZK forum.

Read more: https://polygon.technology/blog/polygon-zkevm-results-of-hexens-security-audit

Comments

All Comments

Recommended for you

  • Yi Lihua: The market cycle remains valid, and we remain optimistic about the next bull market opportunity in the industry.

    Liquid Capital founder Yi Lihua stated in an article that first, he acknowledges that the market cycle is still valid. With the US stock market holding strong and the new phase of DAT/ETF, the consensus in the crypto circle has not been broken, coupled with the market being easily manipulated. But on the other hand, thinking in reverse, entering a bear market in the crypto space is also the best time to lay out plans, just like in the last cycle when we benefited from positioning during the bear market. The future is bright, still optimistic about the next bull market opportunity in the industry, will continue to work hard building, pessimists are correct, optimists win.

  • Trend Research sold another 20,770 ETH in the past 20 minutes, equivalent to approximately $43.57 million.

    according to Lookonchain monitoring, Trend Research sold another 20,770 ETH (approximately 43.57 million USD) in the past 20 minutes, currently holding only 10,303 ETH (approximately 21.5 million USD).

  • BTC breaks through $69,000

     market shows BTC breaking through $69,000, currently at $69,039, with a 24-hour increase of 3.96%. The market is highly volatile, please manage your risk accordingly.

  • The "BTC OG Insider Whale" deposited another 69.08 million USDT into a Binance deposit address associated with Yi Lihua.

    according to on-chain analyst Ai Yi (@ai_9684xtpa), the "BTC OG insider whale" has deposited 69.08 million USDT into a Binance deposit address associated with Yili Hua. In the past 11 hours, a total of 10,000 ETH and 69.08 million USDT have been transferred in, with a total value of 89.47 million USD.

  • BTC falls below $69,000

    the market shows BTC falling below $69,000, currently at $68,957.16, with a 24-hour increase of 5.84%. The market is highly volatile, please manage your risk accordingly.

  • ETH breaks $2,000

    the market shows ETH breaking through $2000, currently at $2000.7, with a 24-hour decline of 3.93%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks through $68,000

    the market shows BTC breaking through $68,000, currently at $68,000.01, with a 24-hour decline of 3.33%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks through $67,000

    the market shows BTC breaking through $67,000, currently at $67,006.7, with a 24-hour decline of 3.83%. The market is highly volatile, please manage risk accordingly.

  • COINMY Named Title Sponsor of “The Silent Rise” Summit in Hong Kong on February 9

    According to CoinTime, COINMY has been confirmed as the title sponsor of “The Silent Rise” summit, taking place in Hong Kong on February 9. COINMY (CMY) is a globally compliant digital asset exchange focused on bridging traditional payment systems with the crypto ecosystem, with an emphasis on transparency, security, and efficient global trading infrastructure. “The Silent Rise” is a themed summit co-hosted by RWAX, METASTONE, ChainTimes, and other ecosystem partners, with sponsorship support from CoinMy, Nexus Chain, and several more Web3 projects. The event will be held from 14:00 to 22:00 on February 9 at the 28th floor of Crowne Plaza Hong Kong Causeway Bay, and is positioned as one of the most anticipated side events during Consensus Hong Kong 2026. The summit will feature multiple roundtable discussions covering key themes such as AI, Real-World Assets (RWA), and next-generation financial systems. The summit brings more than 20 prominent speakers to explore emerging trends, system design, and the evolving architecture of Web3.

  • Cardano founder: Over $3 billion lost in the crypto space

    On February 6, Cardano founder Charles Hoskinson revealed in a live broadcast that despite losing more than 3 billion US dollars in the crypto field, he still chooses to stay in the industry rather than quit. In response to external comments that he can afford the losses because he is wealthy, he said: "If you think I am in this business for the money, you are completely wrong — even if I lose everything, I will not stop."