Notice of 2026 Instant Upgrades: Security Patches

Following the introduction of the proposed Instant Upgrade terminology and classification framework with GAP-5, the ZKsync Security Council is publishing a consolidated record of the Instant Upgrades executed during 2026 to date.

Under the proposed framework, an Instant Upgrade is a protocol upgrade executed with the approval of the Emergency Upgrade Board rather than through the standard Token Assembly governance process. Each Instant Upgrade is classified as either:

  • Category 1: Security Patch — a preventative or precautionary security update deployed rapidly to remediate a vulnerability before exploitation or public disclosure; or
  • Category 2: Emergency Response — an Instant Upgrade responding to an active security event.

All five Instant Upgrades executed in 2026 to date are classified as Category 1: Security Patch.

2026 Security Patches

Signing date Upgrade / purpose Details
23 Jan 2026 v0.29.3 circuit patch Addressed three reported ZKsync Era ZK circuit vulnerabilities, including one soundness issue.
5 Feb 2026 v0.29.4 circuit patch Addressed multiple reported circuit vulnerabilities involving over- and under-constraints.
24 Jul 2026 v0.29.5 circuit patch Fixed a circuit overconstraint that could prevent proofs from being generated for valid batches.
8 Aug 2026 v0.30.0 circuit patch A circuit patch preventing miscomputation in certain EraVM operations.
15 Aug 2026 v0.30.1 circuit patch Fixed a cryptographic weakness in the proof system and made additional corrections to VM behavior.

Instant Upgrade Decision

The Instant Upgrade process was used so these issues could be patched before they were publicly disclosed. Following the standard Token Assembly governance process would have required the relevant upgrades and their purpose to be disclosed before deployment, potentially increasing protocol security risk.

The issues addressed by each of the five Security Patches have been remediated through the respective upgrades listed above.

At the time each Instant Upgrade was approved, there was no evidence of active exploitation. These upgrades were preventative security actions and were not undertaken in response to an active exploit or ongoing attack.

User funds were not believed to be actively at risk in connection with any of these Security Patches.

The Security Patches did not require any action from users or ecosystem participants. No user action is required in response to these Notices.

The Security Council is not aware of any material effect on transactions, deposits, withdrawals, finalization or other protocol operations arising from the issues addressed by these patches.

Further disclosure

The information above represents the level of technical detail that the Security Council considers appropriate to disclose publicly regarding these Security Patches.

The Security Council has determined that further technical disclosure in relation to these Security Patches would create additional security risk. Accordingly, no Security Patch Reports will be published at this time.

1 Like