Skip to content
Private, independent platform.Private, independent platform: free for clients, funded by a commission paid by vendors.Funding
smart-contract.com

Directory by blockchain

ZKsync smart contract audit and development

Building and auditing on ZKsync, a zero-knowledge rollup: its own compilers and VM, native account abstraction, EVM differences and how to prepare.

ZKsync is a zero-knowledge rollup on Ethereum: it executes transactions off Ethereum and proves their validity with cryptographic proofs verified on Ethereum. It supports Solidity and Vyper, but runs them on its own virtual machine rather than a byte-for-byte copy of the EVM. For a project, this means familiar languages with a set of behavioral differences that must be tested and reviewed explicitly.

Building on ZKsync

Solidity and Vyper sources are compiled with dedicated ZKsync compilers to the network's virtual machine. Most application code works as written, but some low-level behaviors differ from Ethereum. ZKsync has native account abstraction: every account can be a smart contract with custom validation, which enables features such as sponsored fees but changes assumptions about who initiates a transaction.

  • Languages: Solidity, Vyper
  • Tooling: ZKsync plugins for Hardhat and a ZKsync-adapted version of Foundry
  • Differences to check: contract deployment and address derivation, some opcodes and precompiles, gas and data costs

What auditors look at

  • EVM differences: code relying on CREATE or CREATE2 address prediction, inline assembly, or specific opcodes that behave differently
  • Account abstraction: assumptions that the caller is a simple externally owned account, signature validation, paymaster logic
  • L1 to L2 messaging and bridged assets, including authentication of messages coming from Ethereum
  • Gas and data cost assumptions copied from Ethereum
  • Classic EVM application risks: reentrancy, oracle manipulation, access control

Before requesting quotes

  • Confirm the code compiles with the ZKsync toolchain and that tests run against it, not only on a standard EVM
  • Flag any inline assembly, factory contracts or address precomputation
  • Describe custom accounts or paymasters if your project uses them
  • List deployment targets if the same code also runs on other EVM chains

ZKsync smart contract auditors

  • Coinspect

    Public information

    Web3 security firm: smart contract, L1/L2 protocol and source code audits, penetration testing

    • Audit
    • Penetration testing

    Ethereum · BNB Chain · Polygon · Optimism · ZKsync · +2 more

  • Cyfrin

    Public information

    Smart contract audits, penetration testing and security education, maker of Aderyn and Solodit

    • Audit
    • Penetration testing

    Ethereum · ZKsync · Arbitrum · Avalanche · BNB Chain · +8 more

  • Hexens

    Public informationUnited Kingdom

    Offensive security firm auditing smart contracts, L1/L2 protocols, ZK and cryptography

    • Audit
    • Penetration testing

    Ethereum · Polygon · ZKsync · Aptos

  • Nethermind

    Public informationUnited Kingdom

    London blockchain engineering and research firm; its Nethermind Security arm audits smart contracts

    • Development
    • Audit

    Ethereum · Starknet · ZKsync · Solana

  • Omniscia

    Public informationBulgaria

    Blockchain security firm auditing Solidity smart contracts, with web-based public reports

    • Audit

    Ethereum · Polygon · Arbitrum · Base · BNB Chain · +3 more

  • OpenZeppelin

    Public informationUnited Kingdom

    Smart contract security audits and the open-source OpenZeppelin Contracts library

    • Audit

    Ethereum · Arbitrum · Optimism · Base · ZKsync · +2 more

  • QuillAudits

    Public information

    Smart contract audit firm also offering dApp penetration testing, wallet audits and monitoring

    • Audit
    • Penetration testing

    Ethereum · NEAR · BNB Chain · Polygon · Optimism · +8 more

  • ScaleBit

    Public information

    Web3 security team auditing smart contracts, dApps and blockchains, with a Bitcoin layer 2 focus

    • Audit

    Ethereum · Arbitrum · BNB Chain · Solana · Polygon · +3 more

  • Shieldify

    Public informationBulgaria

    Bulgarian Web3 security company offering smart contract audits by review or by subscription

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · ZKsync · Avalanche · BNB Chain · +1 more

ZKsync smart contract developers

  • BootNode

    Public information

    Web3 development consultancy building smart contracts, dApps and infrastructure for Ethereum teams

    • Development

    Ethereum · Optimism · ZKsync

  • Moonsong Labs

    Public informationUnited States

    Blockchain engineering firm for institutional protocols, tokenization and payment infrastructure

    • Development

    Ethereum · ZKsync · Solana · Polkadot

  • Nethermind

    Public informationUnited Kingdom

    London blockchain engineering and research firm; its Nethermind Security arm audits smart contracts

    • Development
    • Audit

    Ethereum · Starknet · ZKsync · Solana

  • RedDuck

    Public informationUkraine

    Web3 engineering partner writing audit-ready smart contracts on EVM chains, Solana and Bitcoin

    • Development

    Ethereum · Polygon · BNB Chain · Arbitrum · Base · +6 more

  • Shieldify

    Public informationBulgaria

    Bulgarian Web3 security company offering smart contract audits by review or by subscription

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · ZKsync · Avalanche · BNB Chain · +1 more

  • Zpoken

    Public informationEstonia

    Senior crypto engineering team for L1 consensus, zero-knowledge, DeFi mechanisms and stablecoins

    • Development

    Ethereum · Solana · NEAR · Arbitrum · Base · +1 more

Describe your project once. Compare with confidence.

Get comparable quotes from vetted developers, then secure your code with an independent auditor.

Get quotes

Free for clients. No commitment.