Search

Search for projects by name or address

Cronos zkEVM logo
Cronos zkEVM

Cronos zkEVM is sunsetting. See the announcement - withdrawals via the official bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. are open until June 3, 2027.

Badges

About

Cronos zkEVM is a general-purpose Validium on Ethereum built on the ZK Stack, scaling the existing portfolio of Cronos apps and chains.


  • Total Value SecuredTVS
    $30.13 M4.16%
  • Past day UOPSDaily UOPS
    <0.016.74%
  • Gas token
    ETH
  • Type
    Other

  • Purpose
    Universal
  • Chain ID
    388

  • Tokens breakdown

    Sequencer failureState validationData availabilityExit windowProposer failure

    Badges

    About

    Cronos zkEVM is a general-purpose Validium on Ethereum built on the ZK Stack, scaling the existing portfolio of Cronos apps and chains.

    Why is the project listed in others?

    There is no data availability bridge

    Consequence: projects without a data availability bridge fully rely on single entities (the sequencer) to honestly rely available data roots on Ethereum. A malicious sequencer can collude with the proposer to finalize an unavailable state, which can cause loss of funds.

    Learn more about the recategorisation here.


    Total
    Canonically BridgedCanonically Bridged ValueCanonical
    Natively MintedNatively Minted TokensNative
    Externally BridgedExternally Bridged ValueExternal

    ETH & derivatives
    Stablecoins
    BTC & derivatives
    Other
    Compare with other projects
    Past Day UOPS
    Past Day Ops count
    Max. UOPS
    Past day UOPS/TPS Ratio
    Compare with other projects

    The section shows the operating costs that L2s pay to Ethereum.



    Total cost
    Avg cost per L2 UOP
    Avg cost per day

    Compare with other projects

    This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule.

    No ongoing anomalies detected

    Avg. proof subs. interval
    Avg. state updates interval
    Past 30 days anomalies
    100% normal uptime

    Mainnet Launch

    2024 Aug 15th

    Cronos zkEVM Launches Its Alpha Mainnet powered by ZKsync.

    Learn more
    Sequencer failureState validationData availabilityExit windowProposer failure
    Sequencer failure
    Enqueue via L1

    Users can submit transactions to an L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. queue, but can’t force them. The sequencers cannot selectively skip transactions but can stop processing the queue entirely. In other words, if the sequencers censor or are down, they are so for everyone.

    State validation
    Validity proofs (ST, SN)

    STARKs and SNARKs are zero knowledge proofs that ensure state correctness. STARKs proofs are wrapped in SNARKs proofs for efficiency. SNARKs require a trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits..

    Data availability
    External

    Proof construction and state derivation rely fully on data that is NOT published onchain.

    Exit window
    None (emergency upgrade path)
    4d 3h (regular upgrade path)

    Non-emergency upgrades go through a 4d 3h delay, but the central operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. can still censor withdrawal transactions by implementing a TransactionFilterer with no delay.

    There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable.

    Proposer failure
    Replace proposer

    Only the whitelisted proposers can publish state rootsA cryptographic hash succinctly representing a state using a Merkle tree. on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., so in the event of failure the withdrawals are frozen. There is a decentralized Governance system that can attempt changing Proposers with an upgrade.

    Cronos zkEVM
    Cronos zkEVM is not even a
    Stage 0
    project.

    Learn more about Stages
    Please keep in mind that these stages do not reflect project security, this is an opinionated assessment of project maturity based on subjective criteria, created with a goal of incentivizing projects to push toward better decentralization. Each team may have taken different paths to achieve this goal.

    Data is not stored on chain

    The transaction data is not recorded on the Ethereum main chain. Transaction data is stored off-chain and only the hashes are posted onchain by the centralized SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs..

    • Funds can be lost if the external data becomes unavailable (CRITICAL).

    1. ExecutorFacet - _commitOneBatch() function

    Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract.


    Prover Architecture

    ZKsync Era proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system. Boojum can be found here and contains essential tools like the ProverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract., the VerifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover., and other backend components. The specs of the system can be found here.

    ZK Circuits

    ZKsync Era circuits are built from Boojum and are designed to replicate the behavior of the EVM. The source code can be found here. The circuits are checked against tests that can be found here.

    • Funds can be lost if the proof system is implemented incorrectly.

    Verification Keys Generation

    SNARKShort for "succinct non-interactive argument of knowledge", a SNARK is a widely used type of zero-knowledge proof that is short and fast to verify. Different kinds of SNARKs are usually systematized by proof size, verification time, and type of setup. The most famous SNARKs are Groth16, PLONK/Marlin, Bulletproofs, and STARKs. verification keys can be generated and checked against the Ethereum verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover. contract using this tool. The system requires a trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits..

    PROVER

    Trusted Setups

    Onchain verifier

    Used in

    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in

    Onchain verifier

    Used in

    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in

    Onchain verifier

    Used in

    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in

    Onchain verifier

    Used in

    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in

    Program Hashes

    Name
    Hash
    Repository
    Verification
    Used in
    0x0100...51e6
    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in

    A diagram of the upgrades and governance
    A diagram of the upgrades and governance

    There are two main paths for contract upgrades in the shared ZK stack ecosystem - standard and emergency - both converging on the shared upgrade management contract ProtocolUpgradeHandler. The standard path involves a governance proposal and voting through the DAO, multiple timelock delays and finally approval by the Guardians or 4 SecurityCouncil participants. The emergency path allows for contract upgrades without any delay by the EmergencyUpgradeBoard, which acts as a 3/3 Multisig between SecurityCouncil, Guardians and the FoundationMultisig.

    Standard path

    On ZKsync Era

    Delegates can start new proposals by reaching a threshold of 21M ZK tokens on the ZKsync Era RollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup.’s ZkProtocolGovernor contract. This launches a 3d ‘voting delay’ after which the 7d voting period starts. During these first two periods, the proposal can be canceled by the proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. or if it falls below the proposing threshold. A proposal is only successful if it reaches both quorum (630M ZK tokens) and simple majority. When it reaches quorum, a remaining voting period of 3d is guaranteed by a potential late quorum vote extension. In the successful case, it can be queued in the 0s timelock which forwards it via the Gateway to Ethereum as an L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.->L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. log.

    On Ethereum

    After the execution of the proposal-containing batch (3h delay), the proposal is now picked up by the ProtocolUpgradeHandler and enters the 3d ‘legal veto period’. This serves as a window in which a veto could be coordinated offchain, to be then enforced by non-approval of Guardians and SecurityCouncil. A threshold of 2 Guardians can extend the veto period to 7d. After this a proposal enters a waiting state of 1mo, from which it can be immediately approved (cancelling the delay) by 4 participants of the SecurityCouncil. For the unlikely case that the Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. does not approve here, the Guardians can instead approve the proposal, or nobody. In the two latter cases, the waiting period is enforced in full. A proposal cannot be actively cancelled in the ProtocolUpgradeHandler, but will expire if not approved within the waiting period. An approved proposal now enters the pendingExecution state for a final delay of 1d and can then be executed.

    Other governance tracks

    There are two other tracks of Governance also starting with DAO Delegate proposals the ZKsync Era rollup: 1) Token Program Proposals that add new minters, allocations or upgrade the ZK token and 2) Governance Advisory Proposals that e.g. change the ZK Credo or other offchain Governance Procedures without onchain targets. The protocol for these two other tracks is similar to the first part of the standard path described above (albeit having different quorum and timelock values), and not passing over to the Ethereum L1. Further customizations are that the ZkFoundationMultisig can propose to the ZkTokenGovernor without a threshold and that the Guardians’ L2 alias can cancel proposals in the ZkTokenGovernor and the ZkGovOpsGovernor.

    Emergency path

    SecurityCouncil (6/8), Guardians (5/8) and ZkFoundationMultisig (3/6) form a de-facto 3/3 Multisig by pushing an immediate upgrade proposal through the EmergencyUpgradeBoard, which circumvents all delays and executes immediately via the ProtocolUpgradeHandler.

    Upgrade Delays

    The cumulative duration of the upgrade paths from the moment of a voted ‘successful’ proposal is 4d 3h or 8d 3h (depending on Guardians extending the LegalVetoPeriod) for Standard, 0 for Emergency and 1mo 4d for the path in which the SecurityCouncil is not approving the proposal.

    Freezing

    The SecurityCouncil can freeze (pause withdrawals and settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals.) all chains connected to the current ChainTypeManager. Either for a softFreeze of 12h or a hardFreeze of 7d. After a softFreeze and / or a hardFreeze, a proposal from the EmergencyUpgradeBoard has to be passed before subsequent freezes are possible. Only the SecurityCouncil can unfreeze an active freeze.

    ZK cluster Admin and Chain Admin

    Apart from the paths that can upgrade all shared implementations, the ZK stack governance system defines other roles that can modify the system: A single ZK cluster Admin role who governs parameters in the shared contracts and a Chain Admin role (defined in each chain-specific diamond contract) for managing parameters of each individual ZK chain that builds on the stack. These chain-specific actions include critical operations like setting a transaction filterer that can censor L1 -> L2 messages, changing the DA mode, migrating the chain to a different settlement layer and standard operations like setting fee parameters and adding / removing ValidatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier in the ValidatorTimelock. For rollups, data availabilityThe property of a rollup's data being reachable by any node retrieving the data that were rolled up and executed to reach the proposed state. Data availability (DA), specifically decoupling it from the rollup nodes themselves, is one of the preeminent factors which allows a rollup to scale securely. A rollup is faced with a decision of what to use as a DA layer to guarantee that any node can retrieve this data--permissionlessly under any circumstance. For this reason, using Ethereum for DA currently provides the strongest security guarantees. If data is stored somewhere other than a permissionless L1, then the project is not a rollup, but rather a validium or an optimium. on Ethereum is validated by a RollupL1DAValidator contract (or a RelayedSLDAValidator on the Gateway). Each rollup can become a permanent rollup (through their Chain Admin) which disallows DA changes to non-whitelisted sources or settlement layers in the future. The source of truth for rollup-compliant DA validator contracts is the RollupDAManager contract, which is administered via the ProtocolUpgradeHandler. ZKsync Era’s Chain Admin differs from the others as it also has the above ZK cluster Admin role in the shared ZK stack contracts.

    Past upgrades

    The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included.

    Count of upgrades
    44
    Last upgrade
    1mo 9d ago
    Avg upgrade interval
    4mo 19d
    2026 August 21, 11:14 UTC
    High severity
    11changes

    CronosZkEVMAdmin upgraded the boojum verifiers to version v0.30.1 (the same version as zksync era). The new verifiers are not yet reproduced.

    - Status: DELETED
    contract L1VerifierPlonk (eth:0x35CD3865199F2D9c574f34DD72520B19842d440c) [shared-zk-stack/L1VerifierPlonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    - Status: DELETED
    contract L1VerifierFflonk (eth:0x4A34cE730052cb195d8a95e730623eEcc1CB8B66) [shared-zk-stack/L1VerifierFflonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    contract Diamond (eth:0x7b2DA4e77BAE0e0d23c53C3BE6650497d0576CFc) [shared-zk-stack/Diamond] {
    +++ description: The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions.
    values.$pastUpgrades.13:
    + ["2026-08-21T08:26:11.000Z","0xb77459936506ff9df19c5fd6fa15538dfd94241e02c616217a8c66d474e27754",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$upgradeCount:
    - 13
    + 14
    +++ description: Protocol version, increments with each protocol upgrade.
    +++ severity: HIGH
    values.getProtocolVersion:
    - 128849018880
    + 128849018881
    values.getSemverProtocolVersion.2:
    - 0
    + 1
    values.getVerifier:
    - "eth:0xC47D355402E78b886B628914B3b129F236fEe3cc"
    + "eth:0xCeF0218c0C6dB0768e48debeE26E41B8DAdE7081"
    }
    - Status: DELETED
    contract DualVerifier (eth:0xC47D355402E78b886B628914B3b129F236fEe3cc) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0x4A34cE730052cb195d8a95e730623eEcc1CB8B66 or eth:0x35CD3865199F2D9c574f34DD72520B19842d440c depending on the supplied proof type.
    + Status: CREATED
    contract EraVerifierPlonk (eth:0x0DAAB2B7b38ab48712996E760152c569FA356DbF) [shared-zk-stack/L1VerifierPlonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    + Status: CREATED
    contract EraVerifierFflonk (eth:0x8470d6B3fd71B5fE3906B4ea04498d18F721eDe9) [shared-zk-stack/L1VerifierFflonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    + Status: CREATED
    contract EraDualVerifier (eth:0xCeF0218c0C6dB0768e48debeE26E41B8DAdE7081) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0x8470d6B3fd71B5fE3906B4ea04498d18F721eDe9 or eth:0x0DAAB2B7b38ab48712996E760152c569FA356DbF depending on the supplied proof type.
    2026 August 10, 10:28 UTC
    High severity
    13changes

    Cronos zkevm admin upgraded boojum verifier to v29.5 (same as zksync era, was registered on chain type manager before). Verifier is not yet reproduced.

    contract Diamond (eth:0x7b2DA4e77BAE0e0d23c53C3BE6650497d0576CFc) [shared-zk-stack/Diamond] {
    +++ description: The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions.
    values.$pastUpgrades.11:
    + ["2026-08-08T09:36:47.000Z","0xce0ea2790b5b12033089168685da6c016111f209c0a4e870c9de7956035a956d",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$pastUpgrades.12:
    + ["2026-08-10T08:37:11.000Z","0xfeca0b076fcaff4a944b72952fab789eded3f96f34417b0d0cdbee0012c27a64",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$upgradeCount:
    - 11
    + 13
    +++ description: Protocol version, increments with each protocol upgrade.
    +++ severity: HIGH
    values.getProtocolVersion:
    - 124554051588
    + 128849018880
    values.getSemverProtocolVersion.1:
    - 29
    + 30
    values.getSemverProtocolVersion.2:
    - 4
    + 0
    values.getVerifier:
    - "eth:0xCD279BD537c8e1A1acC46aC2205bebD8902F7A45"
    + "eth:0xC47D355402E78b886B628914B3b129F236fEe3cc"
    }
    - Status: DELETED
    contract L1VerifierPlonk (eth:0x7f33D100f482093182111d69a4a457289e99f4ec) [shared-zk-stack/L1VerifierPlonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    - Status: DELETED
    contract L1VerifierFflonk (eth:0xa38a0Df579F9eCA29fbA560b9885B1113b1Df442) [shared-zk-stack/L1VerifierFflonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    - Status: DELETED
    contract DualVerifier (eth:0xCD279BD537c8e1A1acC46aC2205bebD8902F7A45) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0xa38a0Df579F9eCA29fbA560b9885B1113b1Df442 or eth:0x7f33D100f482093182111d69a4a457289e99f4ec depending on the supplied proof type.
    + Status: CREATED
    contract L1VerifierPlonk (eth:0x35CD3865199F2D9c574f34DD72520B19842d440c) [N/A]
    +++ description: None
    + Status: CREATED
    contract L1VerifierFflonk (eth:0x4A34cE730052cb195d8a95e730623eEcc1CB8B66) [N/A]
    +++ description: None
    + Status: CREATED
    contract DualVerifier (eth:0xC47D355402E78b886B628914B3b129F236fEe3cc) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0x4A34cE730052cb195d8a95e730623eEcc1CB8B66 or eth:0x35CD3865199F2D9c574f34DD72520B19842d440c depending on the supplied proof type.
    2026 June 09, 09:36 UTC
    High severity
    12changes

    Upgraded boojum verifier to use the same version as zksync era.

    - Status: DELETED
    contract DualVerifier (eth:0x4d335C5C08FEc91a39965351AbB6E315ad2e9ff3) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0xD324a7c8556A059371B207fB96FD77bE24E2042c or eth:0xe201837d151E5aC33Af3305f287Ad6F6a7Dfccd7 depending on the supplied proof type.
    contract Diamond (eth:0x7b2DA4e77BAE0e0d23c53C3BE6650497d0576CFc) [shared-zk-stack/Diamond] {
    +++ description: The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions.
    values.$pastUpgrades.9:
    + ["2026-06-08T09:28:23.000Z","0x7d96630296efe03df04817a3a8c321f7676edd22f4a387632c018ae7f83f152c",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$pastUpgrades.10:
    + ["2026-06-09T09:27:47.000Z","0x2cf6ba0dc95e4d5160f6146838f8cbac0ca887cc0617d898020b1fff8c343204",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$upgradeCount:
    - 9
    + 11
    +++ description: Protocol version, increments with each protocol upgrade.
    +++ severity: HIGH
    values.getProtocolVersion:
    - 124554051586
    + 124554051588
    values.getSemverProtocolVersion.2:
    - 2
    + 4
    values.getVerifier:
    - "eth:0x4d335C5C08FEc91a39965351AbB6E315ad2e9ff3"
    + "eth:0xCD279BD537c8e1A1acC46aC2205bebD8902F7A45"
    }
    - Status: DELETED
    contract L1VerifierFflonk (eth:0xD324a7c8556A059371B207fB96FD77bE24E2042c) [shared-zk-stack/L1VerifierFflonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    - Status: DELETED
    contract L1VerifierPlonk (eth:0xe201837d151E5aC33Af3305f287Ad6F6a7Dfccd7) [shared-zk-stack/L1VerifierPlonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    + Status: CREATED
    contract L1VerifierPlonk (eth:0x7f33D100f482093182111d69a4a457289e99f4ec) [shared-zk-stack/L1VerifierPlonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    + Status: CREATED
    contract L1VerifierFflonk (eth:0xa38a0Df579F9eCA29fbA560b9885B1113b1Df442) [shared-zk-stack/L1VerifierFflonk]
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    + Status: CREATED
    contract DualVerifier (eth:0xCD279BD537c8e1A1acC46aC2205bebD8902F7A45) [shared-zk-stack/DualVerifier]
    +++ description: A router contract for verifiers. Routes verification requests to eth:0xa38a0Df579F9eCA29fbA560b9885B1113b1Df442 or eth:0x7f33D100f482093182111d69a4a457289e99f4ec depending on the supplied proof type.
    2025 December 11, 14:34 UTC
    High severity
    48changes

    v29.2 standard upgrade.

    - Status: DELETED
    contract L1VerifierFflonk (eth:0x1AC4F629Fdc77A7700B68d03bF8D1A53f2210911)
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    - Status: DELETED
    contract L1VerifierPlonk (eth:0x2db2ffdecb7446aaab01FAc3f4D55863db3C5bd6)
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    - Status: DELETED
    contract ValidatorTimelock2 (eth:0x5D8ba173Dc6C3c90C8f7C04C9288BeF5FDbAd06E)
    +++ description: Intermediary contract between the *Validators* and the central diamond contract that delays block execution (ie withdrawals and other L2 --> L1 messages) by 3h.
    contract CronosZkEvm (eth:0x7b2DA4e77BAE0e0d23c53C3BE6650497d0576CFc) {
    +++ description: The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions.
    sourceHashes.1:
    - "0xbc2380479529743c27e6ab96cdf08210319fadcbca0856cf50c6b1b54bf8437f"
    + "0xc7513302e4e09efc907df5e645d9f8037b1d02409f9a9089f61061c8951ef1ff"
    values.$implementation.0:
    - "eth:0x431449e2a28A69122860A4956A3f7191eE15aFBC"
    + "eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253"
    values.$implementation.1:
    - "eth:0xae5cbB5f70e134668a13d7C8EcEF5e9E6FffCF22"
    + "eth:0x1666124221622eb6154306Ea9BA87043e8be88B2"
    values.$implementation.2:
    - "eth:0x365D0ae3ECA13004daf2A4ba1501c01AaEbb4fec"
    + "eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45"
    values.$implementation.3:
    - "eth:0x2f116b9033d88Bb3Cf64C371AE5458fbA22BA39A"
    + "eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"
    values.$pastUpgrades.8:
    + ["2025-12-11T09:24:35.000Z","0xef33b2d54a34da1a1d04bc1929f239f104751f6c1a5776760df176520283c73b",["eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253","eth:0x1666124221622eb6154306Ea9BA87043e8be88B2","eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45","eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"]]
    values.$upgradeCount:
    - 8
    + 9
    values.facetAddresses.0:
    - "eth:0x431449e2a28A69122860A4956A3f7191eE15aFBC"
    + "eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253"
    values.facetAddresses.1:
    - "eth:0xae5cbB5f70e134668a13d7C8EcEF5e9E6FffCF22"
    + "eth:0x1666124221622eb6154306Ea9BA87043e8be88B2"
    values.facetAddresses.2:
    - "eth:0x365D0ae3ECA13004daf2A4ba1501c01AaEbb4fec"
    + "eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45"
    values.facetAddresses.3:
    - "eth:0x2f116b9033d88Bb3Cf64C371AE5458fbA22BA39A"
    + "eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691"
    values.facets.eth:0x431449e2a28A69122860A4956A3f7191eE15aFBC:
    - ["acceptAdmin()","unfreezeDiamond()","upgradeChainFromVersion(uint256,((address,uint8,bool,bytes4[])[],address,bytes))","setPorterAvailability(bool)","setTransactionFilterer(address)","setTokenMultiplier(uint128,uint128)","freezeDiamond()","genesisUpgrade(address,address,bytes,bytes[])","forwardedBridgeMint(bytes,bool)","prepareChainCommitment()","setValidator(address,bool)","setPendingAdmin(address)","allowEvmEmulation()","setDAValidatorPair(address,address)","forwardedBridgeBurn(address,address,bytes)","changeFeeParams((uint8,uint32,uint32,uint32,uint32,uint64))","makePermanentRollup()","executeUpgrade(((address,uint8,bool,bytes4[])[],address,bytes))","forwardedBridgeRecoverFailedTransfer(uint256,bytes32,address,bytes)","setPriorityTxMaxGasLimit(uint256)","setPubdataPricingMode(uint8)"]
    values.facets.eth:0xae5cbB5f70e134668a13d7C8EcEF5e9E6FffCF22:
    - ["getPubdataPricingMode()","getPriorityTxMaxGasLimit()","getTotalBlocksCommitted()","getVerifierParams()","baseTokenGasPriceMultiplierDenominator()","getTransactionFilterer()","isDiamondStorageFrozen()","getProtocolVersion()","getChainId()","getBridgehub()","getTotalBlocksExecuted()","getPriorityTreeRoot()","getVerifier()","facetAddresses()","getDAValidatorPair()","getPriorityQueueSize()","getSettlementLayer()","getAdmin()","storedBlockHash(uint256)","getFirstUnprocessedPriorityTx()","facets()","getL2SystemContractsUpgradeTxHash()","isPriorityQueueActive()","getChainTypeManager()","getBaseTokenAssetId()","getBaseToken()","l2LogsRootHash(uint256)","getL2SystemContractsUpgradeBlockNumber()","getTotalPriorityTxs()","facetFunctionSelectors(address)","getTotalBlocksVerified()","storedBatchHash(uint256)","getTotalBatchesExecuted()","isEthWithdrawalFinalized(uint256,uint256)","isFacetFreezable(address)","facetAddress(bytes4)","getPendingAdmin()","getL2BootloaderBytecodeHash()","getTotalBatchesCommitted()","getL2EvmEmulatorBytecodeHash()","getL2SystemContractsUpgradeBatchNumber()","isFunctionFreezable(bytes4)","baseTokenGasPriceMultiplierNominator()","getTotalBatchesVerified()","getPriorityTreeStartIndex()","getSemverProtocolVersion()","isValidator(address)","getL2DefaultAccountBytecodeHash()"]
    values.facets.eth:0x365D0ae3ECA13004daf2A4ba1501c01AaEbb4fec:
    - ["proveL1ToL2TransactionStatus(bytes32,uint256,uint256,uint16,bytes32[],uint8)","bridgehubRequestL2Transaction((address,address,uint256,uint256,bytes,uint256,uint256,bytes[],address))","requestL2Transaction(address,uint256,bytes,uint256,uint256,bytes[],address)","proveL2LogInclusion(uint256,uint256,(uint8,bool,uint16,address,bytes32,bytes32),bytes32[])","finalizeEthWithdrawal(uint256,uint256,uint16,bytes,bytes32[])","proveL2LeafInclusion(uint256,uint256,bytes32,bytes32[])","l2TransactionBaseCost(uint256,uint256,uint256)","requestL2TransactionToGatewayMailbox(uint256,bytes32,uint64)","requestL2ServiceTransaction(address,bytes)","bridgehubRequestL2TransactionOnGateway(bytes32,uint64)","proveL2MessageInclusion(uint256,uint256,(uint16,address,bytes),bytes32[])"]
    values.facets.eth:0x2f116b9033d88Bb3Cf64C371AE5458fbA22BA39A:
    - ["revertBatchesSharedBridge(uint256,uint256)","proveBatchesSharedBridge(uint256,uint256,uint256,bytes)","commitBatchesSharedBridge(uint256,uint256,uint256,bytes)","executeBatchesSharedBridge(uint256,uint256,uint256,bytes)"]
    values.facets.eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253:
    + ["acceptAdmin()","unfreezeDiamond()","upgradeChainFromVersion(uint256,((address,uint8,bool,bytes4[])[],address,bytes))","setPorterAvailability(bool)","setTransactionFilterer(address)","setTokenMultiplier(uint128,uint128)","freezeDiamond()","genesisUpgrade(address,address,bytes,bytes[])","forwardedBridgeMint(bytes,bool)","prepareChainCommitment()","setValidator(address,bool)","setPendingAdmin(address)","allowEvmEmulation()","setDAValidatorPair(address,address)","forwardedBridgeBurn(address,address,bytes)","changeFeeParams((uint8,uint32,uint32,uint32,uint32,uint64))","makePermanentRollup()","executeUpgrade(((address,uint8,bool,bytes4[])[],address,bytes))","getRollupDAManager()","forwardedBridgeRecoverFailedTransfer(uint256,bytes32,address,bytes)","setPriorityTxMaxGasLimit(uint256)","setPubdataPricingMode(uint8)"]
    values.facets.eth:0x1666124221622eb6154306Ea9BA87043e8be88B2:
    + ["getPubdataPricingMode()","getPriorityTxMaxGasLimit()","getTotalBlocksCommitted()","getVerifierParams()","baseTokenGasPriceMultiplierDenominator()","getTransactionFilterer()","isDiamondStorageFrozen()","getProtocolVersion()","getChainId()","getBridgehub()","getTotalBlocksExecuted()","getPriorityTreeRoot()","getVerifier()","facetAddresses()","getDAValidatorPair()","getPriorityQueueSize()","getSettlementLayer()","getAdmin()","storedBlockHash(uint256)","getFirstUnprocessedPriorityTx()","facets()","getL2SystemContractsUpgradeTxHash()","isPriorityQueueActive()","getChainTypeManager()","getBaseTokenAssetId()","getBaseToken()","l2LogsRootHash(uint256)","getL2SystemContractsUpgradeBlockNumber()","getTotalPriorityTxs()","facetFunctionSelectors(address)","getTotalBlocksVerified()","storedBatchHash(uint256)","getTotalBatchesExecuted()","isEthWithdrawalFinalized(uint256,uint256)","isFacetFreezable(address)","facetAddress(bytes4)","getPendingAdmin()","getL2BootloaderBytecodeHash()","getTotalBatchesCommitted()","getL2EvmEmulatorBytecodeHash()","getL2SystemContractsUpgradeBatchNumber()","isFunctionFreezable(bytes4)","baseTokenGasPriceMultiplierNominator()","getTotalBatchesVerified()","getPriorityTreeStartIndex()","getSemverProtocolVersion()","isValidator(address)","getL2DefaultAccountBytecodeHash()"]
    values.facets.eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45:
    + ["proveL1ToL2TransactionStatus(bytes32,uint256,uint256,uint16,bytes32[],uint8)","bridgehubRequestL2Transaction((address,address,uint256,uint256,bytes,uint256,uint256,bytes[],address))","requestL2Transaction(address,uint256,bytes,uint256,uint256,bytes[],address)","proveL2MessageInclusionShared(uint256,uint256,uint256,(uint16,address,bytes),bytes32[])","proveL2LogInclusion(uint256,uint256,(uint8,bool,uint16,address,bytes32,bytes32),bytes32[])","finalizeEthWithdrawal(uint256,uint256,uint16,bytes,bytes32[])","proveL2LeafInclusionShared(uint256,uint256,uint256,bytes32,bytes32[])","proveL2LeafInclusion(uint256,uint256,bytes32,bytes32[])","l2TransactionBaseCost(uint256,uint256,uint256)","requestL2TransactionToGatewayMailbox(uint256,bytes32,uint64)","requestL2ServiceTransaction(address,bytes)","bridgehubRequestL2TransactionOnGateway(bytes32,uint64)","proveL2MessageInclusion(uint256,uint256,(uint16,address,bytes),bytes32[])","proveL2LogInclusionShared(uint256,uint256,uint256,(uint8,bool,uint16,address,bytes32,bytes32),bytes32[])"]
    values.facets.eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691:
    + ["precommitSharedBridge(address,uint256,bytes)","commitBatchesSharedBridge(address,uint256,uint256,bytes)","executeBatchesSharedBridge(address,uint256,uint256,bytes)","revertBatchesSharedBridge(address,uint256)","proveBatchesSharedBridge(address,uint256,uint256,bytes)"]
    values.getL2BootloaderBytecodeHash:
    - "0x0100085f9382a7928dd83bfc529121827b5f29f18b9aa10d18aa68e1be7ddc35"
    + "0x01000911c4db4fe62c98e180cfa7e9b3a22fb15f505905d4bf36192f481551e6"
    values.getL2DefaultAccountBytecodeHash:
    - "0x010005f72e443c94460f4583fb38ef5d0c5cd9897021c41df840f91465c0392e"
    + "0x010005f73e7c299ed73db937843643bdc276cbc2cc8596287e1e0cf3afc60252"
    values.getL2EvmEmulatorBytecodeHash:
    - "0x01000d83e0329d9144ad041430fafcbc2b388e5434db8cb8a96e80157738a1da"
    + "0x01000d8bae37b82f311186426184866498b357f41d7a02ced11f3e3fbfbacd63"
    +++ description: Protocol version, increments with each protocol upgrade.
    +++ severity: HIGH
    values.getProtocolVersion:
    - 120259084289
    + 124554051586
    values.getSemverProtocolVersion.1:
    - 28
    + 29
    values.getSemverProtocolVersion.2:
    - 1
    + 2
    values.getVerifier:
    - "eth:0xD71DDC9956781bf07DbFb9fCa891f971dbE9868A"
    + "eth:0x4d335C5C08FEc91a39965351AbB6E315ad2e9ff3"
    values.validators.0:
    - "eth:0x5D8ba173Dc6C3c90C8f7C04C9288BeF5FDbAd06E"
    values.validators.1:
    - "eth:0x8c0Bfc04AdA21fd496c55B8C50331f904306F564"
    + "eth:0x2e5110cF18678Ec99818bFAa849B8C881744b776"
    values.getRollupDAManager:
    + "eth:0xE689e79a06D3D09f99C21E534cCF6a8b7C9b3C45"
    implementationNames.eth:0x431449e2a28A69122860A4956A3f7191eE15aFBC:
    - "AdminFacet"
    implementationNames.eth:0xae5cbB5f70e134668a13d7C8EcEF5e9E6FffCF22:
    - "GettersFacet"
    implementationNames.eth:0x365D0ae3ECA13004daf2A4ba1501c01AaEbb4fec:
    - "MailboxFacet"
    implementationNames.eth:0x2f116b9033d88Bb3Cf64C371AE5458fbA22BA39A:
    - "ExecutorFacet"
    implementationNames.eth:0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253:
    + "AdminFacet"
    implementationNames.eth:0x1666124221622eb6154306Ea9BA87043e8be88B2:
    + "GettersFacet"
    implementationNames.eth:0x1e34aB39a9682149165ddeCc0583d238A5448B45:
    + "MailboxFacet"
    implementationNames.eth:0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691:
    + "ExecutorFacet"
    }
    - Status: DELETED
    contract ValidatorTimelock (eth:0x8c0Bfc04AdA21fd496c55B8C50331f904306F564)
    +++ description: Intermediary contract between the *Validators* and the central diamond contract that delays block execution (ie withdrawals and other L2 --> L1 messages) by 3h.
    - Status: DELETED
    contract DualVerifier (eth:0xD71DDC9956781bf07DbFb9fCa891f971dbE9868A)
    +++ description: A router contract for verifiers. Routes verification requests to eth:0x1AC4F629Fdc77A7700B68d03bF8D1A53f2210911 or eth:0x2db2ffdecb7446aaab01FAc3f4D55863db3C5bd6 depending on the supplied proof type.
    + Status: CREATED
    contract ValidatorTimelock (eth:0x2e5110cF18678Ec99818bFAa849B8C881744b776)
    +++ description: Intermediary contract between the *Validators* and the central diamond contract that delays block execution (ie withdrawals and other L2 --> L1 messages) by 3h.
    + Status: CREATED
    contract DualVerifier (eth:0x4d335C5C08FEc91a39965351AbB6E315ad2e9ff3)
    +++ description: A router contract for verifiers. Routes verification requests to eth:0xD324a7c8556A059371B207fB96FD77bE24E2042c or eth:0xe201837d151E5aC33Af3305f287Ad6F6a7Dfccd7 depending on the supplied proof type.
    + Status: CREATED
    reference ProxyAdmin (eth:0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1)
    +++ description: None
    + Status: CREATED
    contract L1VerifierFflonk (eth:0xD324a7c8556A059371B207fB96FD77bE24E2042c)
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    + Status: CREATED
    contract L1VerifierPlonk (eth:0xe201837d151E5aC33Af3305f287Ad6F6a7Dfccd7)
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    + Status: CREATED
    reference RollupDAManager (eth:0xE689e79a06D3D09f99C21E534cCF6a8b7C9b3C45)
    +++ description: None
    2025 August 21, 14:48 UTC
    High severity
    11changes

    Upgraded verifeirs to version 28.1.

    - Status: DELETED
    contract DualVerifier (0x53F5DE9De3B2DA90633a2c74BEb3b9912cdd1579)
    +++ description: A router contract for verifiers. Routes verification requests to eth:0xD5dBE903F5382B052317D326FA1a7B63710C6a5b or eth:0x5BAfEF6729228add8775aF4Cecd2E68a51424Ee1 depending on the supplied proof type.
    - Status: DELETED
    contract L1VerifierPlonk (0x5BAfEF6729228add8775aF4Cecd2E68a51424Ee1)
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    contract CronosZkEvm (0x7b2DA4e77BAE0e0d23c53C3BE6650497d0576CFc) {
    +++ description: The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions.
    values.$pastUpgrades.7:
    + ["2025-08-21T06:13:47.000Z","0x7fb079169799d3618fdbbde9815e5e1b0afeb2191b301dfb80c9811b67b38489",["eth:0x431449e2a28A69122860A4956A3f7191eE15aFBC","eth:0xae5cbB5f70e134668a13d7C8EcEF5e9E6FffCF22","eth:0x365D0ae3ECA13004daf2A4ba1501c01AaEbb4fec","eth:0x2f116b9033d88Bb3Cf64C371AE5458fbA22BA39A"]]
    values.$upgradeCount:
    - 7
    + 8
    +++ description: Protocol version, increments with each protocol upgrade.
    +++ severity: HIGH
    values.getProtocolVersion:
    - 120259084288
    + 120259084289
    values.getSemverProtocolVersion.2:
    - 0
    + 1
    values.getVerifier:
    - "eth:0x53F5DE9De3B2DA90633a2c74BEb3b9912cdd1579"
    + "eth:0xD71DDC9956781bf07DbFb9fCa891f971dbE9868A"
    }
    - Status: DELETED
    contract L1VerifierFflonk (0xD5dBE903F5382B052317D326FA1a7B63710C6a5b)
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    + Status: CREATED
    contract L1VerifierFflonk (0x1AC4F629Fdc77A7700B68d03bF8D1A53f2210911)
    +++ description: Verifies a zk-SNARK proof using an implementation of the fflonk proof system.
    + Status: CREATED
    contract L1VerifierPlonk (0x2db2ffdecb7446aaab01FAc3f4D55863db3C5bd6)
    +++ description: Verifies a zk-SNARK proof using an implementation of the PlonK proof system.
    + Status: CREATED
    contract DualVerifier (0xD71DDC9956781bf07DbFb9fCa891f971dbE9868A)
    +++ description: A router contract for verifiers. Routes verification requests to eth:0x1AC4F629Fdc77A7700B68d03bF8D1A53f2210911 or eth:0x2db2ffdecb7446aaab01FAc3f4D55863db3C5bd6 depending on the supplied proof type.

    The system has a centralized operator

    The operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. is the only entity that can propose blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over.. A live and trustworthy operator is vital to the health of the system.

    • MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.

    Users can force any transaction via L1

    If a user is censored by the L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs., they can try to force their transaction via an L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. queue. Right now there is no mechanism that forces L2 Sequencer to include transactions from the queue in an L2 blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over.. The operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. can implement a TransactionFilterer that censors forced transactions.

    • Users can be censored if the operator refuses to include their transactions.

    • Users can be censored if the operator implements a TransactionFilterer, which is possible without delay.

    1. L1 - L2 interoperability - Developer's documentation

    Regular messaging

    The user initiates L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.->L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. messages by submitting a regular transaction on this chain. When the blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks.

    1. Withdrawing funds - ZKsync documentation

    Forced messaging

    If the user experiences censorship from the operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. with regular L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.->L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. messaging they can submit their messages directly on L1. The system is then obliged to service this request or halt all messages from L1, including all forced withdrawals and deposits. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular message.

    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner

    Ethereum

    Actors:

    EmergencyUpgradeBoard0xF73a…a111

    A custom contract allowing a 3/3 of SecurityCouncil, ZK Foundation Multisig and Guardians to executeEmergencyUpgrade() via the ProtocolUpgradeHandler.

    • Can upgrade with no delay
      • ValidatorTimelock
      • BridgeHub
      • MessageRoot
      • CTMDeploymentTracker
      • L1AssetRouter
      • L1NativeTokenVault
      • ChainTypeManager
      • L1Nullifier
      • ChainAssetHandler
      • ProtocolUpgradeHandler
    • Can interact with BridgeHub
      • set critical contract addresses for the shared cluster, register settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layers, pause and unpause migrations and the bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. and manage zk chain registration
    • Can interact with L1NativeTokenVault
      • pause / unpause the bridge
    • Can interact with ChainTypeManager
      • manage the shared ValidatorTimelock contract address and the admin role, register and execute upgrades (and set their deadlines), freeze, revert batches and set permissioned validatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier and fee params for all connected chains
    • Can interact with L1Nullifier
      • pause, unpause and set critical escrow address references
    • Can interact with ChainAssetHandler
      • pause, resume chain migrations
    • Can interact with RollupDAManager
      • manage allowed rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. DA pairs (allowed to be used by rollups in permanent rollup mode)
    Used in:
    Matter Labs Multisig0x4e49…7828

    A Multisig with 4/7 threshold.

    • Can upgrade with no delay
      • ServerNotifier
    • Can interact with BridgeHub
      • create new zk chains (based on the current version), register tokens (ZK cluster Admin role)
    • Can interact with ChainTypeManager
      • set the pending admin of this contract and the ServerNotifier contract address (ZK cluster Admin role)
    Used in:
    SecurityCouncil0x5919…9035

    A Multisig with 6/8 threshold. Custom Multisig implementation that has a general threshold of 6 but also specific thresholds for upgrade approvals (4) or soft freezes (3).

    • Can interact with ProtocolUpgradeHandler
      • soft freeze, hard freeze, approve a protocol upgrade
    • Can interact with EmergencyUpgradeBoard
      • one of its 3/3 signers
    Used in:
    1. Security Council members - ZK Nation docs
    Guardians0x600d…86b8

    A Multisig with 5/8 threshold. Custom Multisig implementation that has a general threshold of 5 and a specific threshold for extending the legal voting period of 2.

    • Can interact with ProtocolUpgradeHandler
      • extend the legal veto period, approve a protocol upgrade
    • Can interact with EmergencyUpgradeBoard
      • one of its 3/3 signers
    Used in:
    1. Guardians - ZK Nation docs
    ValidatorTimelock0x2e51…b776

    Intermediary contract between the ValidatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier and the central diamond contract that delays blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. execution (ie withdrawals and other L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. --> L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. messages) by 3h.

    • Can interact with Diamond
      • commit, prove, execute, revert batches directly in the main Diamond contract. This role is typically held by a proxying ValidatorTimelock
    Used in:
    CronosChainAdminMultisig0x4c57…dFce

    A Multisig with 2/3 threshold.

    • Can interact with Diamond
      • administrate operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. roles for this chain in the ValidatorTimelock, manage fees, apply predefined upgrades, manage censorship through a TransactionFilterer, set DA mode, migrate the chain to whitelisted settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layers (Chain Admin role)
    TransactionFiltererDenyList0xA899…9139
    • Can interact with Diamond
      • define addresses that can send transactions from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. (e.g. for deposits, withdrawals, queued transactions). This is enforced in the Mailbox Facet
    TxFiltererOwnerMultisig0xC774…ab8b

    A Multisig with 2/5 threshold.

    • Can interact with Diamond
      • administrate operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. roles for this chain in the ValidatorTimelock, manage fees, apply predefined upgrades, manage censorship through a TransactionFilterer, set DA mode, migrate the chain to whitelisted settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layers (Chain Admin role)
    • Can interact with TransactionFiltererDenyList
      • manage the blacklist of addresses in the TransactionFilterer
    ZK Foundation Multisig0xbC16…B51c

    A Multisig with 3/6 threshold.

    • Can interact with EmergencyUpgradeBoard
      • one of its 3/3 signers
    Used in:
    • Can interact with Diamond
      • administrate operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. roles for this chain in the ValidatorTimelock, manage fees, apply predefined upgrades, manage censorship through a TransactionFilterer, set DA mode, migrate the chain to whitelisted settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layers (Chain Admin role)

    ZKsync Era

    Actors:

    ZkProtocolGovernor0x7670…e34f

    Main Governance contract allowing for token voting (simple majority) with the ZK token through delegates. This contract is used for protocol upgrade proposals (ZIPs) that start on ZKsync Era, go through Ethereum Layer 1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. and can - from there - target all L1 and L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. contracts. At least 21M ZK tokens are necessary to start a proposal and a 630M quorum of voted tokens must be met to succeed.

    • Can interact with ProtocolUpgradeHandler
      • start (queue) upgrades
    • Can interact with ProtocolTimelockController
      • cancel queued transactions
      • execute transactions that are ready
      • manage all access control roles and change the minimum delay
      • propose transactions
    Used in:
    ZkTokenGovernor0xb83F…5746

    Governance contract allowing for token voting (simple majority) with the ZK token through delegates. This contract is used for Token Program Proposals (TPPs) usually targeting the ZK token on ZKsync Era. At least 21M ZK tokens are necessary to start a proposal (for delegates) and a 630M quorum of voted tokens must be met to succeed.

    • Can interact with ZkToken
      • grant the MINTER_ROLE to arbitrary addresses, thus controlling the minting of the ZK token with 3d delay
    • Can interact with ZkTokenTimelockController
      • manage all access control roles and change the minimum delay with 6d delay
      • cancel queued transactions
      • execute transactions that are ready
      • propose transactions
    Used in:
    Guardians_l2Alias0x711e…97c9
    • Can interact with ZkTokenGovernor
      • cancel proposals while they are pending (after having been proposed) or active (during the voting period)
    Used in:
    ZKFoundationMultisig_l2Alias0xcd27…C62D
    • Can interact with ZkTokenGovernor
      • make direct proposals without owning ZK tokens. In propose-guarded mode, this address is the ONLY allowed proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.. Propose-guarded mode is currently set to false
    Used in:
    ProtocolUpgradeHandler_l2Alias0xF41E…6bc4
    • Can upgrade with no delay
      • ZkToken
    • Can interact with ZkToken
      • control all roles in the ZkToken access control, including the minter roles
    Used in:
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner
    A diagram of the smart contract architecture
    A diagram of the smart contract architecture

    Ethereum

    The main contract defining the Layer 2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. OperatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. actions like commiting blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over., providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. --> L2 and L2 --> L1 transactions.

    • Roles:
      • getAdmin: CronosZkEVMAdmin; ultimately CronosChainAdminMultisig, EOA 1, TxFiltererOwnerMultisig
      • getTransactionFilterer: TransactionFiltererDenyList
      • validatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier: ValidatorTimelock
    Implementation used in:
    ValidiumL1DAValidator0x907b…146A

    Contract that ‘verifies’ the data availabilityThe property of a rollup's data being reachable by any node retrieving the data that were rolled up and executed to reach the proposed state. Data availability (DA), specifically decoupling it from the rollup nodes themselves, is one of the preeminent factors which allows a rollup to scale securely. A rollup is faced with a decision of what to use as a DA layer to guarantee that any node can retrieve this data--permissionlessly under any circumstance. For this reason, using Ethereum for DA currently provides the strongest security guarantees. If data is stored somewhere other than a permissionless L1, then the project is not a rollup, but rather a validium or an optimium. for validiums. This implementation only checks the correct formatting and does not serve as a DA oracle. Can be used by ZK stack validiums as the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. part of a DAValidator pair.

    Implementation used in:

    The main registry (hub) for all the contracts in the ZK stack cluster and central entrypoint for bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. transactions. Stores important mappings like from chainId to diamond address, from chainId to parent CTM, from chainId to base token etc. A clone of Bridgehub is also deployed on each L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. chain, but this clone is only used on settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layers.

    • Roles:
      • admin: EraChainAdminProxy, ProxyAdmin; ultimately EmergencyUpgradeBoard, Matter Labs Multisig
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    Proxy used in:

    Aggregates remote bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. message roots from all ZK stack chains. To be used with the Gateway when deployed.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
    Proxy used in:

    Asset deployment tracker where the ‘asset’ is a ChainTypeManager. The registering of asset IDs for ChainTypeManagers is necessary to be able to migrate them to a given settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals. layer, for example the Gateway.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
    Proxy used in:
    RollupL1DAValidator0x7221…9119

    Contract that verifies the data availabilityThe property of a rollup's data being reachable by any node retrieving the data that were rolled up and executed to reach the proposed state. Data availability (DA), specifically decoupling it from the rollup nodes themselves, is one of the preeminent factors which allows a rollup to scale securely. A rollup is faced with a decision of what to use as a DA layer to guarantee that any node can retrieve this data--permissionlessly under any circumstance. For this reason, using Ethereum for DA currently provides the strongest security guarantees. If data is stored somewhere other than a permissionless L1, then the project is not a rollup, but rather a validium or an optimium. of ethereum calldata and blobsThe data that a rollup publishes to its L1/data availability (DA) layer. They consist of the L2 transactions that are rolled up, along with some metadata. Blobs are introduced as a new transaction type within Ethereum with EIP-4844, and has rollup scaling specifically in mind. Blobs persist on Ethereum’s Beacon Chain ephemerally.. Can be used by ZK stack rollups as the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. part of a DAValidator pair.

    Implementation used in:

    Canonical central asset router for all ZK stack chains. Routes deposits and withdrawals to the respective asset handlers (like the L1NativeTokenVault); does not escrow funds itself.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
    Proxy used in:
    Used in:

    Defines L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. diamond contract versions, creation and upgrade data and the proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system. for all ZK stack chains connected to it. ZK chains are children of this central contract and can only upgrade to versions that were previously registered here. The current protocol version is 0,30,1.

    • Roles:
      • admin: EraChainAdminProxy, ProxyAdmin; ultimately EmergencyUpgradeBoard, Matter Labs Multisig
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    Proxy used in:

    Contract responsible for bookkeeping L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. bridging transactions. Used to finalize withdrawals and reclaim failed deposits. Does not escrow funds.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    Proxy used in:
    Used in:

    The central upgrade contract and Governance proxy for all ZK stack contracts. Accepts successful DAO proposals from L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. and emergency proposals from the EmergencyUpgradeBoard. The three members of the EmergencyUpgradeBoard also have special roles and permissions in this contract.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
      • emergencyUpgradeBoard: EmergencyUpgradeBoard
      • guardians: Guardians
      • l2_protocol_governor: ProtocolTimelockController; ultimately ZkProtocolGovernor
      • securityCouncil: SecurityCouncil
    Proxy used in:
    RollupDAManager0xE689…3C45

    Simple registry for allowed DA address pairs for the ‘rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup.’ data availabilityThe property of a rollup's data being reachable by any node retrieving the data that were rolled up and executed to reach the proposed state. Data availability (DA), specifically decoupling it from the rollup nodes themselves, is one of the preeminent factors which allows a rollup to scale securely. A rollup is faced with a decision of what to use as a DA layer to guarantee that any node can retrieve this data--permissionlessly under any circumstance. For this reason, using Ethereum for DA currently provides the strongest security guarantees. If data is stored somewhere other than a permissionless L1, then the project is not a rollup, but rather a validium or an optimium. mode (can be permanently enforced with isPermanentRollup=true). Rollup DA address pairs (especially the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. part) usually point to contracts that validate if data was made available on Ethereum.

    • Roles:
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    Implementation used in:
    EraChainAdminProxy0x2cf3…5063

    A governance proxy that lets Matter Labs Multisig act through it.

    • Roles:
      • owner: Matter Labs Multisig
    Implementation used in:
    EraVerifierPlonk0x0DAA…6DbF

    Verifies a zk-SNARKShort for "succinct non-interactive argument of knowledge", a SNARK is a widely used type of zero-knowledge proof that is short and fast to verify. Different kinds of SNARKs are usually systematized by proof size, verification time, and type of setup. The most famous SNARKs are Groth16, PLONK/Marlin, Bulletproofs, and STARKs. proof using an implementation of the PlonKA zk-SNARK proving system introduced by Gabizon, Williamson and Ciobotaru in 2019 that allows proving custom circuits. Plonk is based on KZG polynomial commitments and thus requires a universal trusted setup. proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system..

    Implementation used in:
    CronosZkEVMAdmin0x6a88…8Dd4
    • Roles:
      • admins: CronosChainAdminMultisig, EOA 1, TxFiltererOwnerMultisig
    EraVerifierFflonk0x8470…eDe9

    Verifies a zk-SNARKShort for "succinct non-interactive argument of knowledge", a SNARK is a widely used type of zero-knowledge proof that is short and fast to verify. Different kinds of SNARKs are usually systematized by proof size, verification time, and type of setup. The most famous SNARKs are Groth16, PLONK/Marlin, Bulletproofs, and STARKs. proof using an implementation of the fflonk proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system..

    Implementation used in:
    EraDualVerifier0xCeF0…7081

    A router contract for verifiers. Routes verification requests to EraVerifierFflonk or EraVerifierPlonk depending on the supplied proof type.

    Implementation used in:
    ProxyAdmin
    2 instances
    0x1e4c…bE3e0xC2a3…2cf1
    • Roles:
      • owner: ProtocolUpgradeHandler
    Implementation used in:
    ProxyAdmin0x257F…D29B
    • Roles:
      • owner: EraChainAdminProxy
    Implementation used in:

    Canonical central asset escrow for all ZK stack chains.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    The following tokens are included in the value secured calculation:
    CRO token logoUSDC token logoWBTC token logozkCRO token logoFUL token logoFRTN token logoMOON token logo
    Proxy used in:

    Specialized contract for managing chain assets, i.e. chain migrations.

    • Roles:
      • admin: ProxyAdmin; ultimately EmergencyUpgradeBoard
      • owner: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard
    Proxy used in:

    A simple contract that can be called by the ChainAdmin to emit notifications about chain migrations.

    • Roles:
      • admin: ProxyAdmin; ultimately Matter Labs Multisig
    Proxy used in:

    ZKsync Era

    ProtocolTimelockController0x085b…c714

    Timelock contract allowing the queueing of transactions with a minimum delay of 0s.

    • Roles:
      • canceller: ZkProtocolGovernor
      • executor: ZkProtocolGovernor
      • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: ZkProtocolGovernor
      • timelockAdmin: ProtocolTimelockController; ultimately ZkProtocolGovernor
    Implementation used in:

    The ZK token contract on ZKsync Era. Mintable through access control roles. Used for voting in the ZK stack governance system.

    • Roles:
      • admin: ZkTokenProxyAdmin; ultimately ProtocolUpgradeHandler_l2Alias
      • defaultAdmin: ProtocolUpgradeHandler_l2Alias
      • minterAdmin: ZkTokenTimelockController; ultimately ZkTokenGovernor
    Proxy used in:
    ZkTokenProxyAdmin0xdB1E…15CC
    • Roles:
      • owner: ProtocolUpgradeHandler_l2Alias
    Implementation used in:
    ZkTokenTimelockController0xe5d2…9c3d

    Timelock contract allowing the queueing of transactions with a minimum delay of 3d.

    • Roles:
      • canceller: ZkTokenGovernor
      • executor: ZkTokenGovernor
      • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: ZkTokenGovernor
      • timelockAdmin: ZkTokenTimelockController; ultimately ZkTokenGovernor
    Implementation used in:

    The current deployment carries some associated risks:

    • Funds can be stolen if a contract receives a malicious code upgrade. There is a 4d 3h - 8d 3h delay on code upgrades unless upgrade is initiated by the EmergencyUpgradeBoard in which case there is no delay.

    Program Hashes

    Name
    Hash
    Repository
    Verification
    Used in
    0x0100...51e6
    ZKsync Era logoAbstract logoCronos zkEVM logoSophon logoLens logo

    Projects used in

    Search for projects used in