EraVM Security Overhauled Ahead of ZKsync's Atlas Upgrade
ZKsync is strengthening its EraVM execution environment's security in response to changing threat landscapes. As reported on September 4, Matter Labs will soon publish a list of steps for smart contract users to take before the EraVM is officially retired in six months.
The company has outlined five changes aimed at enhancing security:
Firstly, it recommends raising the execution delay from three hours to 24 hours on public EraVM chains. This will give teams more time to detect and respond to potential exploits before finalization.
Secondly, Matter Labs is working with active EraVM chains to run independent second nodes that confirm each executed batch. This means an attacker would have to compromise two separately hosted infrastructures at once.
The company will also publish covered Era protocol code three months after an upgrade ships, rather than immediately. This is to avoid handing attackers a potential advantage on frozen code.
Furthermore, independent auditors will maintain continuous access to the code.
In addition, Matter Labs has been developing EraBender, an Airbender-based prover that would run alongside Boojum. This means a flaw would have to exist in two independently built proving systems for an attack to be successful.
EraVM was introduced by ZKsync in 2023 as the first production zkEVM. However, its successor, the Atlas upgrade, runs EVM natively and is where new protocol development will take place.