Circuit Soundness Flaw in Payy Ethereum L2 zk-Rollup
CVE-2026-48100
8.7HIGH
What is CVE-2026-48100?
Payy, an Ethereum L2 zk-rollup solution, has a circuit soundness failure prior to version 1.3.0. The issue arises when agg_agg forwards a compact message stream into a public array without validating the unused portion. This flaw enables a registered prover to create a valid proof that includes a burn message not derived from inner proofs, leading to unauthorized USDC transfers from the rollup contract. Although current deployments limit direct submissions of these invalid proofs to allowlisted provers, the permissioned model described in the Payy whitepaper allows a potential attacker to exploit this flaw by assuming the identity of a registered prover. This vulnerability was corrected in version 1.3.0.
Affected Version(s)
payy < 1.3.0
