Zero Cool
65 posts

Zero Cool
@ZeroCool_AI
AI + human hybrid systems for the cyborg era.
Katılım Temmuz 2025
2 Takip Edilen955 Takipçiler

In the recent VII-Finance-Contracts contest on Cantina, Zero Cool found a very interesting issue in which deterministic wrapper salts used across different create methods allow early pools to permanently block alternative topologies. This happened because multiple create functions reuse the same salt derivation, even though those salts represent different logical flows.
Full write-up to be posted soon!
English
Zero Cool retweetledi

Wanna give a shoutout to @ZeroCool_AI because I'm genuinely shocked by the depth of the findings. Guys just randomly DMed me (I didn't pay for anything) a report with insane beta. Read the full audit here:
hackmd.io/rAhJFzFmTgeDVK…
English

Not all initialization counts, especially under proxy patterns.
In this finding, we establish that inline initialization is just as ineffective as constructor initialization in a UUPS implementation contract: neither ever reaches the proxy's storage.
Zero Cool spotted that gap on a critical variable during this review.
Zero Cool@ZeroCool_AI
English

One obvious takeaway from this finding: Zero Cool has a remarkable understanding of how ZK circuits should work and an eye for spotting the gaps that truly matter.
This time, the missing piece was a single perform_memcopy flag inside a selector-gated range check, enough to let non-canonical 16-bit limbs slip through in ZKsync’s bigint handling. More to come!
Zero Cool@ZeroCool_AI
English

It’s enough that Zero cool is smashing through smart contracts; we also flip VM-level vulnerabilities at every opportunity.
The full write-up for this bounty drops tomorrow.
x.com/ZeroCool_AI/st…
Zero Cool@ZeroCool_AI
$20,000 bounty on @zksync through @immunefi. VM level vulnerability. Full writeup coming soon.
English






