diff --git a/src/content/docs/en/technology/security/audits-and-bug-bounty.mdx b/src/content/docs/en/technology/security/audits-and-bug-bounty.mdx index 10553b99..5964caec 100644 --- a/src/content/docs/en/technology/security/audits-and-bug-bounty.mdx +++ b/src/content/docs/en/technology/security/audits-and-bug-bounty.mdx @@ -40,46 +40,52 @@ Scroll has worked with several industry-leading security audit firms to review o ### zkEVM circuits - Trail of Bits - - [Wave 1](https://github.com/trailofbits/publications/blob/master/reviews/2023-04-scroll-zkEVM-wave1-securityreview.pdf) - - [Wave 2](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scroll-zkEVM-wave2-securityreview.pdf) - - [Wave 3](https://github.com/trailofbits/publications/blob/master/reviews/2023-09-scroll-zkEVM-wave3-securityreview.pdf) - - [EIP-4844 Blob Support](https://github.com/trailofbits/publications/blob/master/reviews/2024-04-scroll-4844-blob-securityreview.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-04-scroll-zkEVM-wave1-securityreview%20(1).pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-08-scroll-zkEVM-wave2-securityreview.pdf) + - [Wave 3](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-09-scroll-zkEVM-wave3-securityreview.pdf) + - [EIP-4844 Blob Support](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2024-04-scroll-4844-blob-securityreview.pdf) - Zellic and Kalos - - [Wave 1](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) - - [Wave 2](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) ### Node implementation - Trail of Bits - - [zkTrie](https://github.com/trailofbits/publications/blob/master/reviews/2023-07-scroll-zktrie-securityreview.pdf) - - [L2geth](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-initial-securityreview.pdf) - - [L2geth diff](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-securityreview.pdf) + - [zkTrie](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-07-scroll-zktrie-securityreview.pdf) + - [L2geth](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-initial-securityreview.pdf) + - [L2geth diff](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-securityreview.pdf) ### Bridge and rollup contract - OpenZeppelin - - [Phase 1](https://blog.openzeppelin.com/scroll-layer-1-audit-1) - - [Phase 2](https://blog.openzeppelin.com/scroll-phase-2-audit) - - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://blog.openzeppelin.com/scroll-gasswap-multiple-verifier-wrapped-ether-and-diff-audit) - - [ScrollOwner and Rate Limiter](https://blog.openzeppelin.com/scrollowner-and-rate-limiter-audit) - - [USDC Gateway](https://blog.openzeppelin.com/scroll-usdc-gateway-audit) - - [Contract diff](https://blog.openzeppelin.com/scroll-diff-audit-report) - - [Bridge Gas Optimizations](https://blog.openzeppelin.com/scroll-bridge-gas-optimizations-audit) + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%201%20Audit%20Report.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%202%20Audit%20Report.pdf) + - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202308%20Scroll%20GasSwap,%20Multiple%20Verifier,%20Wrapped%20Ether%20and%20Diff%20Final%20Audit%20Report.pdf) + - [ScrollOwner and Rate Limiter](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20ScrollOwner%20and%20Rate%20Limiter%20Audit.pdf) + - [USDC Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20USDC%20Gateway%20Audit%20Report.pdf) + - [Contract diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20Diff%20Audit%20Report.pdf) + - [Bridge Gas Optimizations](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%20Bridge%20Gas%20Optimizations%20Audit%20Report%20(Feb%202024).pdf) - [EIP-4844 Support](https://blog.openzeppelin.com/scroll-eip-4844-support-audit) - [Batch Token Bridge](https://blog.openzeppelin.com/scroll-batch-token-bridge-audit) - Zellic - - [Report 1](https://github.com/Zellic/publications/blob/master/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) - - [Report 2](https://github.com/Zellic/publications/blob/master/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) - - [Lido Gateway](https://github.com/Zellic/publications/blob/master/Scroll%20Lido%20Gateway%20-%20Zellic%20Audit%20Report.pdf) + - [Report 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) + - [Report 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Lido Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20Lido%20Gateway%20-%20Zellic%20Audit%20Report.pdf) ### Auxiliary contracts - ZkTrie Verifier - - [OpenZeppelin](https://blog.openzeppelin.com/scroll-zktrieverifier-audit#notes-additional-information) + - [OpenZeppelin](https://blog.openzeppelin.com/scroll-zktrieverifier-audit) ### Euclid Upgrade - Trail of Bits - - [Phase 1](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase1-securityreview.pdf) - - [Phase 2](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase2-securityreview.pdf) + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase1-securityreview.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase2-securityreview.pdf) + +### Feynman Upgrade +- Trail of Bits + - [Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Feynman-Upgrade-Trails-of-Bits.pdf) +- Internal + - [Internal Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Internal-Audit-Scroll-Final-Report.pdf) ## Bug Bounty Program diff --git a/src/content/docs/es/technology/security/audits-and-bug-bounty.mdx b/src/content/docs/es/technology/security/audits-and-bug-bounty.mdx index 02cc8ee0..b0489963 100644 --- a/src/content/docs/es/technology/security/audits-and-bug-bounty.mdx +++ b/src/content/docs/es/technology/security/audits-and-bug-bounty.mdx @@ -30,40 +30,55 @@ Scroll ha trabajado con varias firmas líderes en auditoría de seguridad de la con enlaces a medida que estén disponibles. -### Circuitos de la zkEVM +### zkEVM circuits - Trail of Bits - - Wave 1 - - Wave 2 - - Wave 3 -- Zellic y Kalos - - [Wave 1](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) - - [Wave 2](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-04-scroll-zkEVM-wave1-securityreview%20(1).pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-08-scroll-zkEVM-wave2-securityreview.pdf) + - [Wave 3](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-09-scroll-zkEVM-wave3-securityreview.pdf) + - [EIP-4844 Blob Support](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2024-04-scroll-4844-blob-securityreview.pdf) +- Zellic and Kalos + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) -### Implementación del Nodo +### Node implementation - Trail of Bits - - [zkTrie](https://github.com/trailofbits/publications/blob/master/reviews/2023-07-scroll-zktrie-securityreview.pdf) - - L2geth - - [L2geth diff](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-securityreview.pdf) + - [zkTrie](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-07-scroll-zktrie-securityreview.pdf) + - [L2geth](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-initial-securityreview.pdf) + - [L2geth diff](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-securityreview.pdf) -### Bridge y contrato de rollup +### Bridge and rollup contract - OpenZeppelin - - [Fase 1](https://blog.openzeppelin.com/scroll-layer-1-audit-1) - - [Fase 2](https://blog.openzeppelin.com/scroll-phase-2-audit) - - [GasSwap, Verificador Múltiple, Wrapped Ether y Diff](https://blog.openzeppelin.com/scroll-gasswap-multiple-verifier-wrapped-ether-and-diff-audit) - - [ScrollOwner y Limitador de Rate](https://blog.openzeppelin.com/scrollowner-and-rate-limiter-audit) - - [Gateway de USDC](https://blog.openzeppelin.com/scroll-usdc-gateway-audit) - - [Diff de Contrato](https://blog.openzeppelin.com/scroll-diff-audit-report) + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%201%20Audit%20Report.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%202%20Audit%20Report.pdf) + - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202308%20Scroll%20GasSwap,%20Multiple%20Verifier,%20Wrapped%20Ether%20and%20Diff%20Final%20Audit%20Report.pdf) + - [ScrollOwner and Rate Limiter](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20ScrollOwner%20and%20Rate%20Limiter%20Audit.pdf) + - [USDC Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20USDC%20Gateway%20Audit%20Report.pdf) + - [Contract diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20Diff%20Audit%20Report.pdf) + - [Bridge Gas Optimizations](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%20Bridge%20Gas%20Optimizations%20Audit%20Report%20(Feb%202024).pdf) + - [EIP-4844 Support](https://blog.openzeppelin.com/scroll-eip-4844-support-audit) + - [Batch Token Bridge](https://blog.openzeppelin.com/scroll-batch-token-bridge-audit) - Zellic - - [Reporte 1](https://github.com/Zellic/publications/blob/master/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) - - [Reporte 2](https://github.com/Zellic/publications/blob/master/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Report 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) + - [Report 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Lido Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20Lido%20Gateway%20-%20Zellic%20Audit%20Report.pdf) -### Actualización Euclid -- Trail of Bits - - [Fase 1](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase1-securityreview.pdf) - - [Fase 2](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase2-securityreview.pdf) +### Auxiliary contracts +- ZkTrie Verifier + - [OpenZeppelin](https://blog.openzeppelin.com/scroll-zktrieverifier-audit) + +### Euclid Upgrade +- Trail of Bits + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase1-securityreview.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase2-securityreview.pdf) + +### Feynman Upgrade +- Trail of Bits + - [Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Feynman-Upgrade-Trails-of-Bits.pdf) +- Internal + - [Internal Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Internal-Audit-Scroll-Final-Report.pdf) ## Programa de Cazarrecompensas de Bugs diff --git a/src/content/docs/tr/technology/security/audits-and-bug-bounty.mdx b/src/content/docs/tr/technology/security/audits-and-bug-bounty.mdx index 7f511ad9..a628727a 100644 --- a/src/content/docs/tr/technology/security/audits-and-bug-bounty.mdx +++ b/src/content/docs/tr/technology/security/audits-and-bug-bounty.mdx @@ -24,40 +24,55 @@ Scroll, kod tabanımızı incelemek için sektör lideri birkaç güvenlik denet - OpenZeppelin ve Zellic köprü ve rollup sözleşmelerimizde bağımsız denetimler gerçekleştirdi - Trail of Bits, düğüm uygulamamızı analiz etti -### zkEVM devreleri +### zkEVM circuits - Trail of Bits - - [1. Dalga](https://github.com/trailofbits/publications/blob/master/reviews/2023-04-scroll-zkEVM-wave1-securityreview.pdf) - - [2. Dalga](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scroll-zkEVM-wave2-securityreview.pdf) - - [3. Dalga](https://github.com/trailofbits/publications/blob/master/reviews/2023-09-scroll-zkEVM-wave3-securityreview.pdf) -- Zellic ve Kalos - - [1. Dalga](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) - - [2. Dalga](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-04-scroll-zkEVM-wave1-securityreview%20(1).pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-08-scroll-zkEVM-wave2-securityreview.pdf) + - [Wave 3](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-09-scroll-zkEVM-wave3-securityreview.pdf) + - [EIP-4844 Blob Support](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2024-04-scroll-4844-blob-securityreview.pdf) +- Zellic and Kalos + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) -### Düğüm uygulaması +### Node implementation - Trail of Bits - - [zkTrie](https://github.com/trailofbits/publications/blob/master/reviews/2023-07-scroll-zktrie-securityreview.pdf) - - [L2geth](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-initial-securityreview.pdf) - - [L2geth diff](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-securityreview.pdf) + - [zkTrie](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-07-scroll-zktrie-securityreview.pdf) + - [L2geth](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-initial-securityreview.pdf) + - [L2geth diff](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-securityreview.pdf) -### Köprü ve rollup sözleşmesi +### Bridge and rollup contract - OpenZeppelin - - [1. Aşama](https://blog.openzeppelin.com/scroll-layer-1-audit-1) - - [2. Aşama](https://blog.openzeppelin.com/scroll-phase-2-audit) - - [GasSwap, Multiple Verifier, Wrapped Ether ve Diff](https://blog.openzeppelin.com/scroll-gasswap-multiple-verifier-wrapped-ether-and-diff-audit) - - [ScrollOwner and Rate Limiter](https://blog.openzeppelin.com/scrollowner-and-rate-limiter-audit) - - [USDC Ağ Geçidi](https://blog.openzeppelin.com/scroll-usdc-gateway-audit) - - [Contract diff](https://blog.openzeppelin.com/scroll-diff-audit-report) + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%201%20Audit%20Report.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%202%20Audit%20Report.pdf) + - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202308%20Scroll%20GasSwap,%20Multiple%20Verifier,%20Wrapped%20Ether%20and%20Diff%20Final%20Audit%20Report.pdf) + - [ScrollOwner and Rate Limiter](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20ScrollOwner%20and%20Rate%20Limiter%20Audit.pdf) + - [USDC Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20USDC%20Gateway%20Audit%20Report.pdf) + - [Contract diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20Diff%20Audit%20Report.pdf) + - [Bridge Gas Optimizations](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%20Bridge%20Gas%20Optimizations%20Audit%20Report%20(Feb%202024).pdf) + - [EIP-4844 Support](https://blog.openzeppelin.com/scroll-eip-4844-support-audit) + - [Batch Token Bridge](https://blog.openzeppelin.com/scroll-batch-token-bridge-audit) - Zellic - - [Rapor 1](https://github.com/Zellic/publications/blob/master/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) - - [Rapor 2](https://github.com/Zellic/publications/blob/master/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Report 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) + - [Report 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Lido Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20Lido%20Gateway%20-%20Zellic%20Audit%20Report.pdf) -### Euclid Yükseltmesi -- Trail of Bits - - [1. Aşama](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase1-securityreview.pdf) - - [2. Aşama](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase2-securityreview.pdf) +### Auxiliary contracts +- ZkTrie Verifier + - [OpenZeppelin](https://blog.openzeppelin.com/scroll-zktrieverifier-audit) + +### Euclid Upgrade +- Trail of Bits + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase1-securityreview.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase2-securityreview.pdf) + +### Feynman Upgrade +- Trail of Bits + - [Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Feynman-Upgrade-Trails-of-Bits.pdf) +- Internal + - [Internal Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Internal-Audit-Scroll-Final-Report.pdf) ## Hata Ödül Programı diff --git a/src/content/docs/zh/technology/security/audits-and-bug-bounty.mdx b/src/content/docs/zh/technology/security/audits-and-bug-bounty.mdx index 37597738..4443dd98 100644 --- a/src/content/docs/zh/technology/security/audits-and-bug-bounty.mdx +++ b/src/content/docs/zh/technology/security/audits-and-bug-bounty.mdx @@ -31,41 +31,55 @@ Scroll 已经与多家业内领先的安全审计公司合作,来审查我们 我们仍在与合作伙伴合作,以发布所有报告。当链接可用时,我们将更新此页面。 -### zkEVM 电路 +### zkEVM circuits - Trail of Bits - - [Wave 1](https://github.com/trailofbits/publications/blob/master/reviews/2023-04-scroll-zkEVM-wave1-securityreview.pdf) - - [Wave 2](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scroll-zkEVM-wave2-securityreview.pdf) - - [Wave 3](https://github.com/trailofbits/publications/blob/master/reviews/2023-09-scroll-zkEVM-wave3-securityreview.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-04-scroll-zkEVM-wave1-securityreview%20(1).pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-08-scroll-zkEVM-wave2-securityreview.pdf) + - [Wave 3](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2023-09-scroll-zkEVM-wave3-securityreview.pdf) + - [EIP-4844 Blob Support](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/2024-04-scroll-4844-blob-securityreview.pdf) - Zellic and Kalos - - [Wave 1](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) - - [Wave 2](https://github.com/Zellic/publications/blob/master/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) + - [Wave 1](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%201%20-%20Audit%20Report.pdf) + - [Wave 2](https://github.com/scroll-tech/scroll-audits/blob/main/zkEVM%20circuits/Scroll%20zkEVM%20-%20Part%202%20-%20Audit%20Report.pdf) -### 节点实现 +### Node implementation - Trail of Bits - - [zkTrie](https://github.com/trailofbits/publications/blob/master/reviews/2023-07-scroll-zktrie-securityreview.pdf) - - [L2geth](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-initial-securityreview.pdf) - - [L2geth diff](https://github.com/trailofbits/publications/blob/master/reviews/2023-08-scrollL2geth-securityreview.pdf) + - [zkTrie](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-07-scroll-zktrie-securityreview.pdf) + - [L2geth](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-initial-securityreview.pdf) + - [L2geth diff](https://github.com/scroll-tech/scroll-audits/blob/main/Node%20implementation/2023-08-scrollL2geth-securityreview.pdf) -### 跨链桥和 Rollup 合约 +### Bridge and rollup contract - OpenZeppelin - - [Phase 1](https://blog.openzeppelin.com/scroll-layer-1-audit-1) - - [Phase 2](https://blog.openzeppelin.com/scroll-phase-2-audit) - - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://blog.openzeppelin.com/scroll-gasswap-multiple-verifier-wrapped-ether-and-diff-audit) - - [ScrollOwner and Rate Limiter](https://blog.openzeppelin.com/scrollowner-and-rate-limiter-audit) - - [USDC Gateway](https://blog.openzeppelin.com/scroll-usdc-gateway-audit) - - [Contract diff](https://blog.openzeppelin.com/scroll-diff-audit-report) - - [Bridge Gas Optimizations](https://blog.openzeppelin.com/scroll-bridge-gas-optimizations-audit) + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%201%20Audit%20Report.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202307%20Scroll%20Layer%202%20Audit%20Report.pdf) + - [GasSwap, Multiple Verifier, Wrapped Ether and Diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202308%20Scroll%20GasSwap,%20Multiple%20Verifier,%20Wrapped%20Ether%20and%20Diff%20Final%20Audit%20Report.pdf) + - [ScrollOwner and Rate Limiter](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20ScrollOwner%20and%20Rate%20Limiter%20Audit.pdf) + - [USDC Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20USDC%20Gateway%20Audit%20Report.pdf) + - [Contract diff](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/202309%20Scroll%20Diff%20Audit%20Report.pdf) + - [Bridge Gas Optimizations](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%20Bridge%20Gas%20Optimizations%20Audit%20Report%20(Feb%202024).pdf) + - [EIP-4844 Support](https://blog.openzeppelin.com/scroll-eip-4844-support-audit) + - [Batch Token Bridge](https://blog.openzeppelin.com/scroll-batch-token-bridge-audit) - Zellic - - [Report 1](https://github.com/Zellic/publications/blob/master/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) - - [Report 2](https://github.com/Zellic/publications/blob/master/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Report 1](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2005.26.23%20Zellic%20Audit%20Report.pdf) + - [Report 2](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20-%2009.27.23%20Zellic%20Audit%20Report.pdf) + - [Lido Gateway](https://github.com/scroll-tech/scroll-audits/blob/main/Bridge%20and%20rollup%20contract/Scroll%20Lido%20Gateway%20-%20Zellic%20Audit%20Report.pdf) -### Euclid 升级 -- Trail of Bits - - [第一阶段](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase1-securityreview.pdf) - - [第二阶段](https://github.com/trailofbits/publications/blob/master/reviews/2025-04-scroll-euclid-phase2-securityreview.pdf) +### Auxiliary contracts +- ZkTrie Verifier + - [OpenZeppelin](https://blog.openzeppelin.com/scroll-zktrieverifier-audit) + +### Euclid Upgrade +- Trail of Bits + - [Phase 1](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase1-securityreview.pdf) + - [Phase 2](https://github.com/scroll-tech/scroll-audits/blob/main/Euclid%20Upgrade/2025-04-scroll-euclid-phase2-securityreview.pdf) + +### Feynman Upgrade +- Trail of Bits + - [Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Feynman-Upgrade-Trails-of-Bits.pdf) +- Internal + - [Internal Report](https://github.com/scroll-tech/scroll-audits/blob/main/Feynman%20Upgrade/Internal-Audit-Scroll-Final-Report.pdf) ## 漏洞赏金计划