# Cartesi Authority Honeypot Markdown version of https://l2beat.com/layer2s/projects/cartesi-honeypot ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $0.03 (0.00% compared to seven days ago; canonically bridged $0.03, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Type: Other - Purpose: Bug bounty - Host chain: Ethereum ### Risks - Sequencer failure: Self sequence (sentiment: good) - State validation: None (sentiment: bad) - Data availability: Onchain (sentiment: good) - Exit window: ∞ (sentiment: good) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Honeypot is an application-specific rollup designed to challenge the security of Cartesi Rollups. It provides a gamified battlefield to incentivize bug hunters to hack the application to obtain the funds locked in the rollup contract. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/cartesi-honeypot#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/cartesi-honeypot) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/cartesi-honeypot/breakdown) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/cartesi-honeypot#onchain-costs). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/cartesi-honeypot#liveness). ## Milestones & Incidents - 2025-07-08: [Honeypot archived](https://x.com/cartesiproject/status/1940757477844455765). Honeypot funds withdrawn, and validator turned off. - 2023-09-26: [Honeypot launch](https://x.com/cartesiproject/status/1706685141421047982). Honeypot launched on mainnet. - 2023-04-11: [Honeypot announcement](https://medium.com/cartesi/cartesi-ecosystem-update-2023-124b384401cc#:~:text=Honeypot%20DApp%20on%20Mainnet). Honeypot first announced to the community. ## Risk summary ### Funds can be stolen if 1. an invalid state root is submitted to the system by the configured Authority (CRITICAL). ### Funds can be frozen if 2. the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL). ### MEV can be extracted if 3. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Self sequence (sentiment: good) In the event of a sequencer failure, users can force transactions to be included in the project's chain by sending them to L1. There is no delay on this operation. ### State validation None (sentiment: bad) Currently the system permits invalid state roots. More details in project overview. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window ∞ (sentiment: good) Users can exit funds at any time because contracts are not upgradeable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## Stage Cartesi Authority Honeypot is not even a Stage 0 project. ### Stage 0 - [ ] There is no onchain fraud proof system. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [x] A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/cartesi/rollups/tree/v1.0.2/offchain) ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [ ] Users' withdrawals can be censored by the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. ### Stage 2 - [ ] Upgrades unrelated to onchain provable bugs provide less than 30d to exit. ## Data availability ### All transaction data is recorded on chain All executed transactions are submitted to an on chain smart contract. The execution of the rollup is based entirely on the submitted transactions, so anyone monitoring the contract can know the correct state of the rollup chain. **References** - [InputBox.sol#30 - Etherscan source code, addInput function](https://etherscan.io/address/0x59b22D57D4f067708AB0c00552767405926dc768#code#F1#L30) ## State derivation ### Node software The Cartesi node software source code can be found [here](https://github.com/cartesi/rollups/tree/v1.0.2/offchain). ### Compression scheme No compression is used. ### Genesis state The genesis state is derived from the Honeypot Cartesi Machine template, which can be found within the [Honeypot server Docker image](https://hub.docker.com/layers/cartesi/honeypot/main-server-mainnet/images/sha256-9067ebcf3d915e8091aba45bd231a328a7ac260924d85387137ed133f3e240ac) at `/var/opt/cartesi/machine-snapshots/0_0`. Alternatively, it is possible to recreate it by following the build procedure outlined in the [Honeypot GitHub Repository](https://github.com/cartesi/honeypot#building-machine-to-deploy). ### Data format The reference implementation for ERC20 deposits can be found [here](https://github.com/cartesi/rollups/blob/v1.0.2/onchain/rollups/contracts/common/InputEncoding.sol#L40). To learn about the withdrawal request format, please refer to the documentation [here](https://github.com/cartesi/honeypot#withdrawing-the-pot). ## State validation ### No state validation Ultimately, Cartesi DApps will use interactive fraud proofs to enforce state correctness. This feature is currently in development and the Honeypot DApp permits invalid state roots. Since Honeypot is immutable, this feature will not be added to the DApp. **Risks** - Funds can be stolen if an invalid state root is submitted to the system by the configured Authority (CRITICAL). **References** - [Authority.sol#L148 - Etherscan source code, submitClaim function](https://etherscan.io/address/0x9DB17B9426E6d3d517a969994E7ADDadbCa9C45f#code#F1#L48) ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/cartesi-honeypot#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can force any transaction Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly. ## Withdrawals ### Regular exit The user initiates the withdrawal by submitting a regular transaction on this chain. When the block containing that transaction is settled the funds become available for withdrawal on L1. The process of settling a block usually takes several days to complete. Finally the user submits an L1 transaction to claim the funds. **Risks** - Funds can be frozen if the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL). ## Permissions ### Ethereum #### Actors ##### Authority owner Addresses: [0x79Ec6ba3352216E496FCfEd1d2e86Ee15eed3861](https://etherscan.io/address/0x79Ec6ba3352216E496FCfEd1d2e86Ee15eed3861) The Authority owner can submit claims to the Honeypot DApp. ## Smart contracts ### Ethereum #### Honeypot Addresses: [0x0974CC873dF893B302f6be7ecf4F9D4b1A15C366](https://etherscan.io/address/0x0974CC873dF893B302f6be7ecf4F9D4b1A15C366#code) CartesiDApp instance for the Honeypot DApp, responsible for holding assets and allowing the DApp to interact with other smart contracts. #### InputBox Addresses: [0x59b22D57D4f067708AB0c00552767405926dc768](https://etherscan.io/address/0x59b22D57D4f067708AB0c00552767405926dc768#code) Contract that receives arbitrary blobs as inputs to Cartesi DApps. #### ERC20Portal Addresses: [0x9C21AEb2093C32DDbC53eEF24B873BDCd1aDa1DB](https://etherscan.io/address/0x9C21AEb2093C32DDbC53eEF24B873BDCd1aDa1DB#code) Contract that allows anyone to perform transfers of ERC-20 tokens to Cartesi DApps. #### Authority Addresses: [0x9DB17B9426E6d3d517a969994E7ADDadbCa9C45f](https://etherscan.io/address/0x9DB17B9426E6d3d517a969994E7ADDadbCa9C45f#code) Simple consensus model controlled by a single address, the owner. #### History Addresses: [0x385485FcaCD8AdB70C8A5a6B07155C907e78FAd9](https://etherscan.io/address/0x385485FcaCD8AdB70C8A5a6B07155C907e78FAd9#code) Contract that stores claims for Cartesi DApps.