# Gluon Markdown version of https://l2beat.com/layer2s/projects/gluon ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $30.67 K (+0.75% compared to seven days ago; canonically bridged $30.67 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Type: Plasma - Purpose: Exchange - Host chain: Ethereum ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Fraud proofs (!) (sentiment: warning) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Use escape hatch (sentiment: good) ### About Gluon aims to be a Layer 2 scalable trading engine built on top of Ethereum, unlocking low fees and high frequency trading. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/gluon#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/gluon) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/gluon/breakdown) ## Risk summary **Warning:** LeverJ trading platform appears to be in a maintenance mode as the team moved to build NFT trading platform. Social medias associated with the project are silent since mid 2021. ### Funds can be stolen if 1. users are unable to withdraw in a mass exit event, 2. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 3. there is no one that checks the published state. Fraud proofs assume at least one honest and able validator. ### Funds can be lost if 4. the external data becomes unavailable (CRITICAL). ### Users can be censored if 5. the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ### MEV can be extracted if 6. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis **Warning:** LeverJ trading platform appears to be in a maintenance mode as the team moved to build NFT trading platform. Social medias associated with the project are silent since mid 2021. ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for , users can use the exit hatch to withdraw their funds. ### State validation Fraud proofs (!) (sentiment: warning) Fraud proofs allow actors watching the chain to prove that the state is incorrect. Because the data is not present on chain the security of fraud proofs is severely weakened. ### Data availability External (sentiment: bad) Proof construction and state derivation rely fully on data that is NOT published onchain. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Use escape hatch (sentiment: good) Users are able to trustlessly exit by submitting a Merkle proof of funds. ## Data availability ### Data is not stored on chain **Note:** This section requires more research and might not present accurate information. The transaction data is stored on a plasma chain and is not recorded on the Ethereum main chain. **Risks** - Funds can be lost if the external data becomes unavailable (CRITICAL). ## State validation ### Fraud proofs After some period of time, the published state root is assumed to be correct. For a certain time period, usually one week, anyone can submit a fraud proof that shows that the state was incorrect. **Risks** - Funds can be stolen if there is no one that checks the published state. Fraud proofs assume at least one honest and able validator. ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/gluon#updates). ## Operator ### The system has a centralized operator **Note:** This section requires more research and might not present accurate information. The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can independently exit the system **Note:** This section requires more research and might not present accurate information. Independent exit allows the users to escape censorship by withdrawing their funds. The system allows users to withdraw their funds by submitting a transaction directly to the contract onchain. **Risks** - Users can be censored if the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ## Withdrawals ### Regular exit **Note:** This section requires more research and might not present accurate information. The user executes the withdrawal by submitting a transaction on L1 that requires a merkle proof of funds. ### The mass exit problem is unsolved **Note:** This section requires more research and might not present accurate information. In case the operator is malicious all users need to exit within a predetermined time frame. Users that do not manage to do this will lose their funds. **Risks** - Funds can be stolen if users are unable to withdraw in a mass exit event. ## Smart contracts ### Ethereum #### Gluon Addresses: [0x75ACe7a086eA0FB1a79e43Cc6331Ad053d8C67cB](https://etherscan.io/address/0x75ACe7a086eA0FB1a79e43Cc6331Ad053d8C67cB#code) #### RegistryLogic Addresses: [0x385827aC8d1AC7B2960D4aBc303c843D9f87Bb0C](https://etherscan.io/address/0x385827aC8d1AC7B2960D4aBc303c843D9f87Bb0C#code) #### RegistryData Addresses: [0x0fC25C7931679B838209c484d49Df0Cb9E633C41](https://etherscan.io/address/0x0fC25C7931679B838209c484d49Df0Cb9E633C41#code) #### StakeLogic Addresses: [0x84e34fD82FC368F1a072075114AdC4b552a7a1F4](https://etherscan.io/address/0x84e34fD82FC368F1a072075114AdC4b552a7a1F4#code) #### StakeData Addresses: [0xaB3AC436D66CBEeDc734ed2c1562c3a213c9bc77](https://etherscan.io/address/0xaB3AC436D66CBEeDc734ed2c1562c3a213c9bc77#code) #### SpotLogic Addresses: [0x2D627FF93d32f5FEBb04d68409A889895B4aef2D](https://etherscan.io/address/0x2D627FF93d32f5FEBb04d68409A889895B4aef2D#code) #### SpotData Addresses: [0x0d283D685F0A741C463846176e4c8EFF90D3F9EC](https://etherscan.io/address/0x0d283D685F0A741C463846176e4c8EFF90D3F9EC#code) #### DerivativesLogic Addresses: [0xDfBFe895e07e5115773Cb9631CB2148114589caC](https://etherscan.io/address/0xDfBFe895e07e5115773Cb9631CB2148114589caC#code) #### DerivativesData Addresses: [0x563052914Fd973a2305763269A106a7B0B6D50Cc](https://etherscan.io/address/0x563052914Fd973a2305763269A106a7B0B6D50Cc#code) #### LegacyTokensExtension Addresses: [0xDA88EfA53c85Afa30564bb651A2E76b99a232082](https://etherscan.io/address/0xDA88EfA53c85Afa30564bb651A2E76b99a232082#code) The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).