April 5, 2023

Polygon zkEVM: Results of Spearbit’s Security Audit

Leading up to last week’s launch of Polygon zkEVM Mainnet Beta, the network was comprehensively audited. For more than four months, twenty-six researchers, from two independent security teams, tested all 35 components of Polygon zkEVM, setting a rigorous standard for future and existing ZK rollups. 

Making these reports public is how open-source protocols allow users to DYOR—there are no black boxes with the open-source Polygon zkEVM Mainnet Beta. 

Scope, Classifications, and Findings

Spearbit’s audit covered every component of Polygon zkEVM, including the prover. The following is a summary of those findings, organized by component. 

The security firm classifies vulnerabilities based on severity and likelihood. 

In total, the security researchers documented ten critical, one high, and four medium-level vulnerabilities in their review of the code for Polygon zkEVM Mainnet Beta. All of these vulnerabilities were fixed before the launch and an additional audit to verify those fixes was just carried out.

Polygon zkEVM Prover + Cryptography

In a ZK rollup–or any rollup—the network generates a state transition. The prover is where the proof for making a valid state transition is generated. For that reason, it’s the most complex part of the tech stack. The performance of the prover also, to an extent, dictates the performance of the network.

Twitter/X

This is content from Twitter/X. It only loads after you allow social networking cookies.

View on Twitter/X

Spearbit’s security team reviewed this codebase, completely or partially, during three discrete audits. (Repo here.) Following their review of the cryptography of Polygon zkEVM’s prover, Spearbit wrote: “no major soundness issues were discovered in either the cryptography or implementation review.” 

In two separate reviews of Polygon zkEVM’s prover, Spearbit found two critical and two low-level vulnerabilities. All four vulnerabilities were fixed before the launch of Mainnet Beta.   

Smart Contracts

Because Polygon zkEVM uses validity proofs to generate state transitions, the bridge between the network and Ethereum will have no intermediaries or third parties. Currently, there are security mechanisms in place to protect users at this early stage. But, once the network is mature, the only thing governing the bridge will be two smart contracts: one on Ethereum and one on Polygon zkEVM. (There is also a third smart contract for the consensus mechanism, once the network is progressively decentralized.) 

Spearbit’s audit of these smart contracts found no critical or high-severity vulnerabilities. There were three medium-risk vulnerabilities, which were all fixed by Polygon Labs and verified by Spearbit prior to the launch of Mainnet Beta. 

There were also 16 low-risk vulnerabilities discovered. Based on Spearbit’s classification, low risk applies to a wide range of vulnerabilities, from “attacks that can be easily repaired or even gas inefficiencies.” The devs for Polygon zkEVM have responded to each in the linked report and have prioritized the limited outstanding issues in the next development sprints. Here are some examples of those low-risk vulnerabilities:

  • One relied on there being multiple ZK rollups in a single network
  • Another is for users who input an invalid address when bridging funds out of the network

ROM

The ROM in Polygon zkEVM stores the instructions for interpreting transaction data. Spearbit’s security review of the ROM covered two reports, which documented five critical vulnerabilities. All five were fixed before the launch of Mainnet Beta, and those fixes were verified by Spearbit’s researchers.

The ROM also contains zkASM, the assembly language that allows Polygon zkEVM to execute the EVM’s opcodes. One critical vulnerability was documented and fixed before the launch of Mainnet Beta.

Tune into the Polygon Blog and social channels to stay up to date on the latest from the Polygon ecosystem.

Together, we can build an equitable future for all through the mass adoption of Web3!

Website | Twitter | Developer Twitter | Telegram | Reddit | Discord | Instagram | Facebook | LinkedIn

More Blogs

August 4, 2026

WalletsOpen Money Stack

Custodial vs. Non-Custodial Wallets: Which One Should Your Platform Build?

August 3, 2026

Open Money StackPayments

Move Money Between Solana and Polygon, Ethereum, Base + more EVM Chains with Polygon OMS

July 30, 2026

Polygon ChainOpen Money StackPayments

Ithaca Upgrade Is Live: Payments on Polygon Chain Are More Reliable Than Ever

July 30, 2026

PaymentsPolygon ChainOpen Money Stack

Kansai Electric Power's Rewards Arm Turns Loyalty Points Into Real Stablecoin Payments on Polygon Chain

July 27, 2026

Polygon Chain

Mento Protocol Launches on Polygon for Local Currency Stablecoin Payments

July 9, 2026

PaymentsInstitutionalPolygon Chain

PayPal USD Lands on Polygon Chain, Enabling Regulated Onchain Dollars to Move Across Borders in One Integration

July 2, 2026

Open Money StackPaymentsPolygon Chain

Credible Races Past $152M Total Payments Volume on Polygon

June 26, 2026

PaymentsPolygon Chain

We Built the Best Blockchain for Payments. Now We’re Bringing the World’s Enterprises Onchain

June 22, 2026

InstitutionalOpen Money StackPayments

Uquid Integrates Polygon's Open Money Stack for 1-Click Crypto Checkout Across 178M+ Products

June 19, 2026

Open Money StackPolygon ChainPayments

How to Integrate Stablecoins into Your Payment Product