DeFi Daily News
Saturday, October 18, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Metaverse

rewrite this title White Hat Hacker Reveals Critical Flaw In Scroll, Co-Founder Defends Protocol Security

Alisa Davidson by Alisa Davidson
April 30, 2025
in Metaverse
0 0
0
rewrite this title White Hat Hacker Reveals Critical Flaw In Scroll, Co-Founder Defends Protocol Security
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

by
Alisa Davidson


Published: April 30, 2025 at 11:10 am Updated: April 30, 2025 at 10:50 am

by Ana


Edited and fact-checked:
April 30, 2025 at 11:10 am

To improve your local-language experience, sometimes we employ an auto-translation plugin. Please note auto-translation may not be accurate, so read original article for precise information.

In Brief

Pavel Shabarkin publicly disclosed a critical vulnerability on Scroll, claiming that the issue could have halted the blockchain, impacting over $100 million in TVL, but Scroll reportedly failed to resolve the problem effectively.

White Hat Hacker Reveals Critical Flaw In Scroll, Co-Founder Defends Protocol Security

White hat hacker Pavel Shabarkin publicly disclosed a critical vulnerability on the Ethereum Layer 2 network Scroll via social media platform X. He claimed that the issue could have halted the blockchain, impacting over $100 million in total value locked (TVL). Despite this, Scroll reportedly failed to resolve the problem effectively.

According to Pavel Shabarkin, “Anyone could force Scroll L2 into an indefinite re-org, halting the chain so that no user transactions would be included in blocks and the chain would not move forward. All funds on L2 would be frozen.”

The hacker also expressed frustration with Scroll’s response to the issue, noting that the project downplayed his report and failed to engage in meaningful communication, opting instead for silence. Additionally, he pointed out that Immunefi, the platform handling the vulnerability report, did not accurately classify the issue, even after he requested a re-evaluation. As a result, Pavel Shabarkin chose to go public with his findings to raise awareness about Scroll’s apparent lack of security expertise.

The issue reported by Pavel Shabarkin poses risks to the Scroll network, with the potential for the chain to be halted at no cost to the attacker. During the attack, withdrawals would remain blocked, potentially indefinitely, as the attacker can sustain the halt without any expense. This disruption in block production would prevent essential time-sensitive decentralized finance (DeFi) actions, such as adding funds to avoid liquidation or updating oracle prices, placing user funds at substantial risk. Additionally, the sequencer would stop collecting transaction fees because no Layer 2 user transactions could be included in blocks. The vulnerability is particularly concerning as anyone with internet access could trigger the attack, making it an easily accessible threat.

On Feb 17 2025 I reported a critical vulnerability to @Scroll_ZKP. $100m+ in TVL was at risk for more than 2 months.

Anyone could force Scroll L2 into an indefinite re-org, halting the chain so that no user transactions would be included in blocks and the chain would not move…

— Pavel Shabarkin (@shabarkin) April 30, 2025

In response, Ye Zhang, co-founder of Scroll, explained that the hacker’s claims stem from a fundamental misunderstanding of how the protocol operates. Specifically, the hacker overlooked the light CCC check that the sequencer conducted prior to the Euclid upgrade.

He highlighted that, “The PoC doesn’t hold up. Logs don’t seem to show reorgs. Light CCC already tracks precompile invocations and skips such transactions without triggering any reorg.”

Ye Zhang further emphasized that Scroll is committed to ensuring protocol security, having invested over $1 million in audits, and values the contributions of whitehat hackers. 

Scroll is an Ethereum Layer 2 scaling solution that leverages Zero-Knowledge (ZK) rollups to improve transaction throughput, lower gas fees, and preserve Ethereum’s security and decentralization. By incorporating a zkEVM (Zero-Knowledge Ethereum Virtual Machine), Scroll ensures full compatibility with Ethereum’s existing infrastructure, enabling developers to deploy decentralized applications (dApps) without needing to modify their code.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author


Alisa, a dedicated journalist at the MPost, specializes in cryptocurrency, zero-knowledge proofs, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles


Alisa Davidson










Alisa, a dedicated journalist at the MPost, specializes in cryptocurrency, zero-knowledge proofs, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.








More articles

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: CofoundercriticaldefendsflawHackerHatProtocolRevealsrewriteScrollsecuritytitlewhite
ShareTweetShare
Previous Post

rewrite this title Italy’s worried about crypto

Next Post

rewrite this title ‘The White Lotus’ Star Michelle Monaghan Shares Vacation Must-Haves

Next Post
rewrite this title ‘The White Lotus’ Star Michelle Monaghan Shares Vacation Must-Haves

rewrite this title 'The White Lotus’ Star Michelle Monaghan Shares Vacation Must-Haves

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
Why Outlet Malls Are Struggling In The U.S.

Why Outlet Malls Are Struggling In The U.S.

July 16, 2024
rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for .7 billion, in Buffett’s biggest deal in three years

rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for $9.7 billion, in Buffett’s biggest deal in three years

October 2, 2025
Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

July 31, 2024
rewrite this title Während BlackRock Geldanlagen tokenisiert, wird PepeNode das Mining revolutionieren! | Bitcoinist.com

rewrite this title Während BlackRock Geldanlagen tokenisiert, wird PepeNode das Mining revolutionieren! | Bitcoinist.com

October 14, 2025
Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

August 14, 2024
TopStep Discount Code

TopStep Discount Code

September 17, 2024
rewrite this title NASCAR Truck Series Playoff Picture 2025: Updated driver points standings after Love’s RV Stop 225 at Talladega Superspeedway

rewrite this title NASCAR Truck Series Playoff Picture 2025: Updated driver points standings after Love’s RV Stop 225 at Talladega Superspeedway

October 18, 2025
rewrite this title ‘Only 0K?’ Jack Dorsey Prods Tether Over Donation to Support Bitcoin Devs – Decrypt

rewrite this title ‘Only $250K?’ Jack Dorsey Prods Tether Over Donation to Support Bitcoin Devs – Decrypt

October 18, 2025
rewrite this title Beyond Politics And Sports: The New Frontiers Of Prediction Markets In 2025

rewrite this title Beyond Politics And Sports: The New Frontiers Of Prediction Markets In 2025

October 18, 2025
rewrite this title Altcoins Selling Pressure Persists As Exchange Inflow Hits 2025 High — Details

rewrite this title Altcoins Selling Pressure Persists As Exchange Inflow Hits 2025 High — Details

October 18, 2025
rewrite this title Buying a laptop? Wait! A mini PC may actually be better for you

rewrite this title Buying a laptop? Wait! A mini PC may actually be better for you

October 18, 2025
rewrite this title and make it good for SEOICICI Bank Q2 results: PAT rises 5% YoY to Rs 12,359 cr, NII grows 7%

rewrite this title and make it good for SEOICICI Bank Q2 results: PAT rises 5% YoY to Rs 12,359 cr, NII grows 7%

October 18, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.