Skip to content

ZKsync Adds EraVM Safeguards Before Planned Retirement

Matter Labs has outlined five security measures for ZKsync chains that still run EraVM, an execution environment whose chains are expected to begin a retirement transition within six months of the September 4 announcement. New protocol development is moving to Atlas, while EraVM chains continue to settle value during the transition.

Longer delays and a second node

The EraVM security update recommends increasing the execution delay for public chains from three hours to 24 hours. The extra time is meant to give operators a larger window to identify an exploit and intervene before a malicious batch reaches finalization.

Matter Labs is also working with each active EraVM chain to operate an independently hosted second node that confirms executed batches. Separate infrastructure raises the difficulty of compromising the full verification path, although it does not remove software defects shared by both nodes.

Code disclosure and emergency changes

Covered Era protocol code will be published three months after an upgrade ships rather than immediately. Independent auditors will retain continuous access. Matter Labs said delayed public disclosure reduces the advantage attackers could gain from studying newly frozen code while funds remain on EraVM.

GAP-5, approved by the Token Assembly on August 24, changes the name “Emergency Upgrades” to “Instant Upgrades.” It also requires a notice on the ZK Nation forum after an instant upgrade. The terminology does not change the underlying authority, so users should continue to track when and why such changes occur.

A second proving system

The fifth measure is EraBender, an Airbender-based prover intended to run beside Boojum. Using independently developed proving systems aims to avoid relying on one implementation. A safety benefit depends on the systems failing differently rather than sharing the same specification or integration flaw.

Matter Labs also said it will add monitoring, internal reviews and tools that assert security properties. Some technical details may remain private temporarily when disclosure would create a material risk.

Why EraVM is being retired

ZKsync introduced EraVM in 2023 as a production zkEVM. Atlas runs the EVM natively and will receive future protocol capabilities. The transition concentrates development on the newer architecture rather than maintaining two execution paths indefinitely.

The retirement does not apply to chains already running Atlas. Permissioned chains, including GRVT, are expected to provide their own instructions. Matter Labs said ordinary externally owned accounts do not need to act, while smart-contract assets will require guidance and dates that had not yet been published.

What users need to verify

Owners should first determine whether funds sit in a normal account or inside an EraVM contract. They should then wait for chain-specific notices and verify links through official channels before signing a migration. A retirement deadline is a predictable opening for phishing messages that manufacture urgency.

Operators have a different checklist: the execution-delay proposal, independent-node deployment, upgrade notices and final migration dates. The safeguards reduce exposure during the transition, but the move is complete only when contract assets have a tested path and affected chains publish their schedules.

Sources & further reading