
The ADI Foundation is an Abu Dhabi-based organization building sovereign-grade blockchain infrastructure to help modernize public systems across emerging markets. Founded by Sirius International, the digital arm of IHC, ADI is focused on powering national-scale services that work at the policy level. The program rewards for bugs that break the soundness of the Airbender prover and its on-chain verifier(s) used by ADI’s zkEVM stack—i.e., any issue that makes an invalid state transition (or forged/incorrect proof) be accepted as valid, either in native (Rust) verification or on L1 smart contracts.
| Target | Type | Severity |
|---|---|---|
https://github.com/ADI-Foundation-Labs/ADI-Stack-Airbender-Prover/tree/4f0cf4cd1a0d7cf48d366135e53da7960b936932 Copy | Protocol | Critical |
https://github.com/ADI-Foundation-Labs/ADI-Stack-Airbender-System/tree/357b836552d72550b20a341e1b45b730bef87806 Copy | Protocol | Critical |
https://github.com/ADI-Foundation-Labs/ADI-Stack-Contracts/tree/04346d566e7625ae42ec74861da409329f9f4a3d/l1-contracts/contracts/state-transition Copy | Smart Contract | Critical |
https://github.com/ADI-Foundation-Labs/ADI-Stack-Protocol/tree/767759541cd018e4271f9774f0d760ce727c905d Copy | Protocol | Critical |
https://github.com/ADI-Foundation-Labs/ADI-Stack-zkOS-Wrapper/tree/eb75ad8ee972c63a30ef1121a1b9dc79a2942569 Copy | Smart Contract | Critical |
We are looking for evidence of attack that causes invalid proofs or state transitions to be accepted by either native or on-chain verification, including:
Please use the following tags for the source code:
Reports from any other source code version would be rejected.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: