Search for projects by name or address
There are impactful changes and part of the information might be outdated.
Cartesi PRT Honeypot v2 is an application-specific Stage-2 rollup that stress-tests Cartesi Rollups’ security. Protected solely by Cartesi’s PRT (Permissionless Refereed Tournaments) fraud-proof algorithm, it turns its locked funds into an open bounty for... anyone who can break the system. Users should not deposit unless they are willing to donate their funds to the Honeypot.
Cartesi PRT Honeypot v2 is an application-specific Stage-2 rollup that stress-tests Cartesi Rollups’ security. Protected solely by Cartesi’s PRT (Permissionless Refereed Tournaments) fraud-proof algorithm, it turns its locked funds into an open bounty for... anyone who can break the system. Users should not deposit unless they are willing to donate their funds to the Honeypot.
The section shows the operating costs that L2s pay to Ethereum.
Cartesi PRT Honeypot v2 deployed on Ethereum
2025 Nov 8th
Cartesi PRT Honeypot v2 deployed to Ethereum mainnet.
Dave: decentralized, secure, lively fraud-proofs
2025 May 9th
Dave paper published on ACM DLT, a peer-reviewed journal.
Users can self sequence transactions by sending them on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. There is no privileged operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades..
Fraud proofs allow actors watching the chain to prove that the state is incorrect. Interactive proofs (INT) require multiple transactions over time to resolve.
All of the data needed for proof construction is published on Ethereum L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..
Users cannot exit their funds as all deposits are considered donations.
Anyone can be a ProposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. and propose new roots to the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge..
Rollup operators cannot compromise the system, but being application-specific might bring additional risk.
Users can deposit (donate) CTSI tokens to the Honeypot. The funds can only be withdrawn by the Cartesi Multisig to its own address. The appchain has the very specific purpose of a bug bounty on the proof system, incentivizing security researchers to break it and claim the deposited funds.
All executed transactions are submitted to an on chain smart contract. The execution of the rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. is based entirely on the submitted transactions, so anyone monitoring the contract can know the correct state of the rollup chain.
The genesis state comes from the Honeypot Cartesi Machine template included in the Honeypot v3 release. Alternatively, you can recreate it by following the build steps in the Honeypot GitHub Repository.
The information in the section might be incomplete or outdated.
The L2BEAT Team is working to research & validate the content before publishing.
After some period of time, the published state rootA cryptographic hash succinctly representing a state using a Merkle tree. is assumed to be correct. For a certain time period, usually one week, anyone can submit a fraud proofAlso referred to as a fault proof, it is the construction of an assertion that fraud was perpetrated on an optimistic rollup. More concretely, that an invalid state transition took place according to the protocol rules. The submitter of a fraud proof would expect a reward from the optimistic rollup protocol for helping maintain the integrity of the system. that shows that the state was incorrect.The initial bond for joining the tournament is set to 0.23219805 ETH.
Funds can be stolen if there is no one that checks the published state. Fraud proofs assume at least one honest and able validator.
Name | Hash | Repository | Verification | Used in | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0x144d...e609 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
The example tournament has concluded. Nothing to see.
The example tournament has concluded. Nothing to see.
| contract TopTournament_example (eth:0xA2835312696Afa86c969e40831857dbB1412627f) { | |
| +++ description: Represents the entry point and highest level of a dispute in PRT. Disagreeing validators join this tournament to resolve conflicts over the entire computation trace through a bisection game. The required bond amount for joining the Tournament is calculated from worst case gas estimates and currently is 0.23219805 ETH. | |
| values.arbitrationResult.0: | |
| - | false |
| + | true |
| values.arbitrationResult.1: | |
| - | "0x0000000000000000000000000000000000000000000000000000000000000000" |
| + | "0xb24767473a260dd656044e7302fc47c52e2d93ce0f3ffb58668b6dcc95e11880" |
| values.arbitrationResult.2: | |
| - | "0x0000000000000000000000000000000000000000000000000000000000000000" |
| + | "0x144d45af1181b35f2b11c4b1150d6cb16934c28093707fb97c911ff16b3fe609" |
| values.isClosed: | |
| - | false |
| + | true |
| values.isFinished: | |
| - | false |
| + | true |
| values.timeFinished.0: | |
| - | false |
| + | true |
| values.timeFinished.1: | |
| - | 0 |
| + | 23801750 |
| } | |
Diff against honeypot v1: - Application: minimal changes, mainly formatting and casing, and a new field is added to track the number of "executed outputs". The template hash is different. - DaveConsensus: new constants, new interface. The biggest change comes from the imported interface but very little of it is actually used. - InputBox: aesthetic changes. - ERC20Portal: aesthetic changes. - MultiLevelTournamentFactory: main change i notice is the additional of a height value in many functions. - BottomTournament - MiddleTournament - TopTournament: obligatory bondValue added (gas dependent) that must be paid on joinTournament(), can be used for gas refunds and be claimed by tournament winner - No significant changes in the Top/Middle/Bottom tournament factories.
Diff against honeypot v1:
height value in many functions.| + | Status: CREATED |
| contract MiddleTournament (eth:0x0a88360f41D0f643ea63ade00c0A1a795395d2D9) | |
| +++ description: Handles the intermediate stages of a dispute following the TopTournament targeting a more granular bisection game. | |
| + | Status: CREATED |
| contract InputBox (eth:0x1b51e2992A2755Ba4D6F7094032DF91991a0Cfac) | |
| +++ description: Serves as both the canonical log for arbitrary dApp inputs and a portal for depositing assets (one possible type of input). It ensures data availability and that all off-chain participants process the same inputs in the same order. | |
| + | Status: CREATED |
| contract CartesiStateTransition (eth:0x31EEaeC2A8d855B13B376b72C172F0c20A2910F6) | |
| +++ description: Onchain verifier that can execute a single, disputed instruction of the Cartesi machine. It is the ultimate arbiter that BottomTournament calls to determine which party's claimed state transition is correct. | |
| + | Status: CREATED |
| contract TopTournament (eth:0x367Ff3c21E189645aaf17bDD41D4C186686CfE53) | |
| +++ description: Represents the entry point and highest level of a dispute in PRT. Disagreeing validators join this tournament to resolve conflicts over the entire computation trace through a bisection game. | |
| + | Status: CREATED |
| contract MiddleTournamentFactory (eth:0x47c7f40841F842f7691cB9Fd6Cd63673B79dCe79) | |
| +++ description: None | |
| + | Status: CREATED |
| contract Cartesi Multisig (eth:0x60247492F1538Ed4520e61aE41ca2A8447592Ff5) | |
| +++ description: None | |
| + | Status: CREATED |
| contract BottomTournamentFactory (eth:0x6ccb8955afFA2aE4A88a4fC30916b41074d1F2B6) | |
| +++ description: None | |
| + | Status: CREATED |
| contract MultiLevelTournamentFactory (eth:0xa02997f69Dc5F1A727abE12ee36f87E28BBdEa6b) | |
| +++ description: Responsible for creating and orchestrating the multi-stage dispute process. It instantiates the correct tournament contract (Top, Middle, or Bottom) depending on the current stage of the dispute game. | |
| + | Status: CREATED |
| contract TopTournament_example (eth:0xA2835312696Afa86c969e40831857dbB1412627f) | |
| +++ description: Represents the entry point and highest level of a dispute in PRT. Disagreeing validators join this tournament to resolve conflicts over the entire computation trace through a bisection game. The required bond amount for joining the Tournament is calculated from worst case gas estimates and currently is 0.23219805 ETH. | |
| + | Status: CREATED |
| contract ERC20Portal (eth:0xACA6586A0Cf05bD831f2501E7B4aea550dA6562D) | |
| +++ description: Contract that allows anyone to perform transfers of ERC-20 tokens to Cartesi DApps. | |
| + | Status: CREATED |
| contract CanonicalTournamentParametersProvider (eth:0xc8d8639C3ec8925A00d4F262299807DC632c3113) | |
| +++ description: Provides constant configuration data for the tournament system. It defines parameters like the number of levels (3), the minimum challenge period of ~7d, and the size of computation segments at each stage of a dispute. | |
| + | Status: CREATED |
| contract BottomTournament (eth:0xe6B4444d324E0B403c9C43C5d7c8B2C3d5d02962) | |
| +++ description: Referees the dispute over a single contested Cartesi machine step as the final stage of arbitration in a dispute. It calls the CartesiStateTransition contract to get a definitive on-chain ruling and identify the winner. | |
| + | Status: CREATED |
| contract DaveConsensus (eth:0xF0D8374F8446E87e013Ec1435C7245E05f439259) | |
| +++ description: Contract managing PRT fraud-proof tournaments, application epochs and input validation, as well as settlement and challenge periods. Dispute tournaments are started here and the final, verified computation result (as an `outputsMerkleRoot`) is recorded when they are resolved. | |
| + | Status: CREATED |
| contract Application (eth:0xfDDF68726a28e418fA0c2a52c3134904a8c3e998) | |
| +++ description: Main dApp contract that escrows assets and executes the verified results (outputs) from off-chain computation. It relies on the eth:0xF0D8374F8446E87e013Ec1435C7245E05f439259 contract to validate outputs before releasing assets or triggering on-chain actions. The immutable template hash of the dApp is `0x144d45af1181b35f2b11c4b1150d6cb16934c28093707fb97c911ff16b3fe609`. | |
| + | Status: CREATED |
| contract TopTournamentFactory (eth:0xfdF16a7D9143f5E3B7B056b761a7eF8Ce18dc6eF) | |
| +++ description: None | |
There is no privileged entity that sequences transactions or produces blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over.. This activity is permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants. and open to anyone.
Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly.
No address apart from the Cartesi Multisig can trigger a withdrawal and deposits are considered donations to the Honeypot. If a withdrawal is requested by them, all funds in the escrow are withdrawable to the permissioned address as soon as the next settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. occurs (min. every 7d 1h).

A Multisig with 3/6 threshold.


Serves as both the canonical log for arbitrary dApp inputs and a portal for depositing assets (one possible type of input). It ensures data availabilityThe property of a rollup's data being reachable by any node retrieving the data that were rolled up and executed to reach the proposed state. Data availability (DA), specifically decoupling it from the rollup nodes themselves, is one of the preeminent factors which allows a rollup to scale securely. A rollup is faced with a decision of what to use as a DA layer to guarantee that any node can retrieve this data--permissionlessly under any circumstance. For this reason, using Ethereum for DA currently provides the strongest security guarantees. If data is stored somewhere other than a permissionless L1, then the project is not a rollup, but rather a validium or an optimium. and that all off-chain participants process the same inputs in the same order.
Contract managing PRT fraud-proof tournaments, application epochs and input validation, as well as settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. and challenge periods. Dispute tournaments are started here and the final, verified computation result (as an outputsMerkleRoot) is recorded when they are resolved.
Main dApp contract that escrows assets and executes the verified results (outputs) from off-chain computation. It relies on the DaveConsensus contract to validate outputs before releasing assets or triggering on-chain actions. The immutable template hashA fixed-length fingerprint of variable-size input, produced by a hash function. of the dApp is 0x144d45af1181b35f2b11c4b1150d6cb16934c28093707fb97c911ff16b3fe609.

Handles the intermediate stages of a dispute following the TopTournament targeting a more granular bisection game.
Onchain verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover. that can execute a single, disputed instruction of the Cartesi machine. It is the ultimate arbiter that BottomTournament calls to determine which party’s claimed state transition is correct.
Responsible for creating and orchestrating the multi-stage dispute process. It instantiates the correct tournament contract (Top, Middle, or Bottom) depending on the current stage of the dispute game.
Represents the entry point and highest level of a dispute in PRT. Disagreeing validatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier join this tournament to resolve conflicts over the entire computation trace through a bisection game. The required bond amount for joining the Tournament is calculated from worst case gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. estimates and currently is 0.23219805 ETH.
Contract that allows anyone to perform transfers of ERC-20 tokens to Cartesi DApps.
Provides constant configuration data for the tournament system. It defines parameters like the number of levels (3), the minimum challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled. of ~7d, and the size of computation segments at each stage of a dispute.
Referees the dispute over a single contested Cartesi machine step as the final stage of arbitration in a dispute. It calls the CartesiStateTransition contract to get a definitive on-chain ruling and identify the winner.
Name | Hash | Repository | Verification | Used in | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0x144d...e609 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||