zkQUORUMv0.8.4

zkQUORUM0.8.4 · commit 8e41bc2

Two lenses,then proof.

zkQUORUM runs five independent analyzers against the same source and keeps only what at least two of them flag.

Each survivor is compiled into a forked-chain harness and executed. If the exploit does not move value, the finding is dropped.

  • callorder
  • authority
  • statewrite
  • guard
  • valueflow
toggles saved notes from earlier runs

1 source → 5 lenses → proof

REGISTRY · run 0x17

2verified

Reproduced by executing the exploit on a forked chain. 1 more corroborated, not yet reproduced.

  • VaultCorewithdraw()reentrancy

    CF-0117 · drained in 3 calls, block 19 402 117

    0.0072 ETH
    verified
  • FeeRoutersetRate()unguarded-state-write

    CF-0121 · harness reused setup from run 0x0e

    712 USDC
    verified
  • BridgeLedgersettle()unchecked-call

    CF-0124 · pattern recalled from run 0x09, not yet reproduced

    —
    corroborated

EXPERIMENT 01 · exp-01

The amnesia run

Same 24 targets, same lenses, same seed. With recall on, zkQUORUM reads its own notes from ten earlier runs: harness setups that worked, patterns that were confirmed, paths that were dead ends.

STATE
recall:on
RUN
0x17
PRIOR RUNS
10
TARGETS
24
SEED
4471
~/targets/bench-24run 0x17
$ zkquorum scan contracts/ --recall --seed 4471zkQUORUM 0.8.4 (8e41bc2) · run 0x17 · 2026-09-28 14:02:11Znotes     10 prior runs loaded from .zkquorum/notes (212 entries)lenses    callorder authority statewrite guard valueflowSCAN      contracts/VaultCore.sol:withdrawCLASS     reentrancyMATCH     callorder-lens          guard-lens          valueflow-lensSTATUS    verifiedIMPACT    0.0072 ETH · drained in 3 calls, block 19 402 117SCAN      contracts/FeeRouter.sol:setRateCLASS     unguarded-state-writeMATCH     authority-lens          statewrite-lensSTATUS    verifiedIMPACT    712 USDC · harness reused setup from run 0x0eSCAN      contracts/BridgeLedger.sol:settleCLASS     unchecked-callMATCH     valueflow-lens          callorder-lensRECALL    similar pattern confirmed in run 0x09STATUS    corroboratedNOTE      pattern recalled from run 0x09, not yet reproduced--------------------------------------------------------------targets       24lens-units    120signals       7corroborated  3verified      2recalled      1elapsed       6m 41s$ 

THE NUMBERS

Every run is on disk.

Each of the eleven runs writes its prompts, lens outputs, harness scripts, chain forks and verdicts to a dated directory. Nothing is filtered before publishing: false positives, timeouts and lens disagreements stay in the record. The target set is 24 contracts with 31 known vulnerabilities from past audits, frozen at commit 8e41bc2. Any number below can be recomputed with one command from the files it came from.

11
runs
24
targets
31
known bugs
4 812
files kept

PRECISION

Right when it flags

A single lens is wrong more often than it is right. Requiring a second, independent lens to reach the same function removes most of the noise without losing confirmed bugs.

class: reentrancy

74%

  • one lens alone29%
  • two lenses agree74%
raw results →results/precision/reentrancy.csv

RECALL

Found across runs

Share of the 31 known bugs found and reproduced, measured after each run with recall on. Most of the gain comes from reused harness setups, not from new detection.

11 RUNS

3%→61%

run 01run 03run 06run 11
per-run data →results/recall/by-run.json

BENCHMARK

Against a baseline

The baseline is a widely used single-pass static analyzer, run with default detectors on the same 24 targets. It is faster and better on access control. Both columns are reproducible from the same directory.

MetriczkQUORUMbaseline
Reentrancy precision74%62%
Access-control precision41%58%
Verified findings19n/a
False positives (24 targets)1137
Median runtime per target6m 40s14s
Independent agreement2 of 5 lensessingle pass

● highlighted value = better on that row · bench/baseline-0927/

ARCHITECTURE

How a claim becomes evidence

  1. 01

    SOURCE

    solidity, pinned compiler

  2. 02

    LENSES

    5 independent passes

    • callorder
    • authority
    • statewrite
    • guard
    • valueflow
  3. 03

    AGREEMENT

    ≥ 2 lenses, same function

  4. 04

    CANDIDATE

    hypothesis + entry point

  5. 05

    EXECUTION

    forked chain, fixed block

  6. 06

    VERIFIED

    value moved or dropped

NOTE 03

Known limits

  1. 01

    Agreement is not independence. All five lenses share a model family, and two of them share a prompt template, so they can be wrong together. We count this as the main open problem.

  2. 02

    Execution is slow and incomplete. 6 of 31 known bugs need off-chain state or governance timing the harness cannot reproduce; they are reported as corroborated, never as verified.

  3. 03

    24 targets is a small set. Numbers will move as it grows.

Run it yourself.

$ git clone https://github.com/zkquorum/zkquorum
$ zkquorum scan contracts/ --recall

requires foundry ≥ 1.2 and an RPC endpoint for forking