The RISC Zero zkVM is a verifiable computer that works like a real embedded RISC-V micro-processor, enabling programmers to write ZK proofs like they write any other code.
| Target | Type | Severity |
|---|---|---|
https://github.com/risc0/risc0/tree/main/risc0 Copy | Other | Critical |
The list is not limited to the following submissions but it gives an overview of what issues we care about:
risc0/circuit/rv32im-sys directory contains pre-production code. Vulnerabilities in this system are not currently in scope, until closer to official release.risc0-zkvm versions 2.x and 3.x are the currently supported versions, along with dependencies published by risc0. The main branch contains code under development, and issues reported that exist only on main will be awarded at reduced or no severity.We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: