Following the introduction of the proposed Instant Upgrade terminology and classification framework with GAP-5, the ZKsync Security Council is publishing a consolidated record of the Instant Upgrades executed during 2026 to date.
Under the proposed framework, an Instant Upgrade is a protocol upgrade executed with the approval of the Emergency Upgrade Board rather than through the standard Token Assembly governance process. Each Instant Upgrade is classified as either:
- Category 1: Security Patch — a preventative or precautionary security update deployed rapidly to remediate a vulnerability before exploitation or public disclosure; or
- Category 2: Emergency Response — an Instant Upgrade responding to an active security event.
All five Instant Upgrades executed in 2026 to date are classified as Category 1: Security Patch.
2026 Security Patches
| Signing date | Upgrade / purpose | Details |
|---|---|---|
| 23 Jan 2026 | v0.29.3 circuit patch | Addressed three reported ZKsync Era ZK circuit vulnerabilities, including one soundness issue. |
| 5 Feb 2026 | v0.29.4 circuit patch | Addressed multiple reported circuit vulnerabilities involving over- and under-constraints. |
| 24 Jul 2026 | v0.29.5 circuit patch | Fixed a circuit overconstraint that could prevent proofs from being generated for valid batches. |
| 8 Aug 2026 | v0.30.0 circuit patch | A circuit patch preventing miscomputation in certain EraVM operations. |
| 15 Aug 2026 | v0.30.1 circuit patch | Fixed a cryptographic weakness in the proof system and made additional corrections to VM behavior. |
Instant Upgrade Decision
The Instant Upgrade process was used so these issues could be patched before they were publicly disclosed. Following the standard Token Assembly governance process would have required the relevant upgrades and their purpose to be disclosed before deployment, potentially increasing protocol security risk.
The issues addressed by each of the five Security Patches have been remediated through the respective upgrades listed above.
At the time each Instant Upgrade was approved, there was no evidence of active exploitation. These upgrades were preventative security actions and were not undertaken in response to an active exploit or ongoing attack.
User funds were not believed to be actively at risk in connection with any of these Security Patches.
The Security Patches did not require any action from users or ecosystem participants. No user action is required in response to these Notices.
The Security Council is not aware of any material effect on transactions, deposits, withdrawals, finalization or other protocol operations arising from the issues addressed by these patches.
Further disclosure
The information above represents the level of technical detail that the Security Council considers appropriate to disclose publicly regarding these Security Patches.
The Security Council has determined that further technical disclosure in relation to these Security Patches would create additional security risk. Accordingly, no Security Patch Reports will be published at this time.