-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0182 ============================================================ Advisory-ID: 0xCERT-2026-0182 Severity: High Published: 2026-09-28T17:17:49.547Z Updated: 2026-10-08T22:46:38.986Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0182 Title: CVE-2026-48100: Payy Summary - ------- Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it never checks that the unused tail of the outer array is zero. A registered prover can build a valid agg_final proof for an approved rollup block while inserting an extra burn message after the real messages. RollupV1.verifyRollup() then parses that public input as a normal burn and transfers USDC from the rollup contract to the attacker. This is a severe cir… Details - ------- Summary Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it never checks that the unused tail of the outer array is zero. A registered prover can build a valid agg_final proof for an approved rollup block while inserting an extra burn message after the real messages. RollupV1.verifyRollup() then parses that public input as a normal burn and transfers USDC from the rollup contract to the attacker. This is a severe circuit soundness failure: the proof system accepts a public statement whose messages array is not fully derived from the verified inner proofs. On the current deployment, verifyRollup() is restricted to the existing allowlisted prover, so a fresh public caller cannot submit the invalid proof directly. That gate limits who can reach L1 today; it does not make the circuit statement sound. The issue becomes permissionless under the prover model described in the Payy whitepaper. Section 3.3.2 states: "To join as a prover, the prover is required to submit a small stake", and Section 3.3.1 states that if a prover fails to submit, "other nodes can submit the block proof instead." In that model, an attacker only needs to become a registered prover and use public validator approval data for an already approved block. This issue has been patched in version 1.3.0. Severity High (CVSS 8.7), as scored by NVD. Weakness - - CWE-349 Recommended actions - - Check whether you run or depend on the affected component and version - - Apply the vendor's fix or mitigation from the references below Source & attribution This 0xCERT advisory summarises CVE-2026-48100 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-48100. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://nvd.nist.gov/vuln/detail/CVE-2026-48100 - - https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr - - https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRloJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcKrh/GjIkMIub+5MibxUWJUxAl24Oo8Yoh0wNC erNPZxYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAAC8dwEAiVZvT+Avbn0nRl/9 pGM2HMRvboFxXppAH+3gwu451wcBAPbWGE/A2M1FIxoGGXSIlsPEvjWt2e4q 09mdkYYImrYI =42Dm -----END PGP SIGNATURE-----