fAmulet: Finding Finalization Failure Bugs in Polygon zkRollup
Zihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo, Ting Chen
摘要
Zero-knowledge layer 2 protocols emerge as a compelling approach to overcoming blockchain scalability issues by processing transactions through the transaction finalization process. During this process, transactions are efficiently processed off the main chain. Besides, both the transaction data and the zero-knowledge proofs of transaction executions are reserved on the main chain, ensuring the availability of transaction data as well as the correctness and verifiability of transaction executions. Hence, any bugs that cause the transaction finalization failure are crucial, as they impair the usability of these protocols and the scalability of blockchains. In this work, we conduct the first systematic study on finalization failure bugs in zero-knowledge layer 2 protocols, and define two kinds of such bugs. Besides, we design fAmulet, the first tool to detect finalization failure bugs in Polygon zkRollup, a prominent zero-knowledge layer 2 protocol, by leveraging fuzzing testing. To trigger finalization failure bugs effectively, we introduce a finalization behavior model to guide our transaction fuzzer to generate and mutate transactions for inducing diverse behaviors across each component (e.g., Sequencer) in the finalization process. Moreover, we define bug oracles according to the distinct bug definitions to accurately detect bugs. Through our evaluation, fAmulet can uncover twelve zero-day finalization failure bugs in Polygon zkRollup, and cover at least 20.8% more branches than baselines. Furthermore, we employ fAmulet to uncover zero-day bugs and reconfirm known bugs in Scroll zkRollup and Optimism Rollup, highlighting the generality of fAmulet to be extended to other layer 2 protocols. At the time of writing, all our uncovered zero-day bugs have been confirmed and fixed by the corresponding official teams.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo 等USENIX Security 2025
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue 等ICSE 2026
- Automated Soundness and Completeness Vetting of Polygon zkEVMXinghao Peng, Zhiyuan Sun, Kunsong Zhao, Zuchao Ma 等USENIX Security 2025
它引用的顶会 Paper25
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 等USENIX Security 2021 · 被引用 410 次
- Arbitrum: Scalable, private smart contractsHarry A. Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg 等USENIX Security 2018 · 被引用 353 次
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate 等NDSS 2019 · 被引用 305 次
相关 Paper
- Fuzzing Processing Pipelines for Zero-Knowledge CircuitsChristoph Hochrainer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisCCS 2025 · 被引用 1 次
- A Secure Sequencer and Data Availability Committee for RollupsMargarita Capretto, Martín Ceresa, Antonio Fernández Anta, Pedro Moreno-Sanchez 等CCS 2025
- Specular: Towards Secure, Trust-minimized Optimistic Blockchain ExecutionZhe Ye, Ujval Misra, Jiajun Cheng, Wenyang Zhou 等S&P 2024 · 被引用 9 次
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
- Arguzz: Testing zkVMs for Soundness and Completeness BugsChristoph Hochrainer, Valentin Wüstholz, Maria ChristakisUSENIX Security 2026 · 被引用 2 次
