# Polygon Hermez Markdown version of https://l2beat.com/layer2s/projects/hermez ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $271.88 K (-0.27% compared to seven days ago; canonically bridged $271.88 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Type: ZK Rollup - Purpose: Payments - Host chain: Ethereum ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Validity proofs (SN) (sentiment: good) - Data availability: Onchain (sentiment: good) - Exit window: 7d (sentiment: warning) - Proposer failure: Self propose (sentiment: good) ### About Hermez is an open-source ZK Rollup that aims to be optimized for secure, low-cost and usable token transfers on the wings of Ethereum. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/hermez#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/hermez) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/hermez/breakdown) ## Risk summary **Warning:** Hermez and Polygon have recently merged. Hermez and Polygon Hermez are two names for the same rollup. ### Funds can be stolen if 1. the operators trigger a false alarm during withdrawal, (CRITICAL) 2. a contract receives a malicious code upgrade. There is a 7 days delay on code upgrades. ### Funds can be frozen if 3. the operator refuses to include their transactions and users lack resources to propose blocks themselves. ## Risk analysis **Warning:** Hermez and Polygon have recently merged. Hermez and Polygon Hermez are two names for the same rollup. ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for , users can use the exit hatch to withdraw their funds. ### State validation Validity proofs (SN) (sentiment: good) SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setup. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window 7d (sentiment: warning) Users have 7d to exit funds in case of an unwanted upgrade. There is a 7d delay before a upgrade is applied, and withdrawals can take up to 0s to be processed. ### Proposer failure Self propose (sentiment: good) If the Proposer fails, users can leverage the source available prover to submit proofs to the L1 bridge. ## Data availability ### All data required for proofs is published onchain All the data that is used to construct the system state is published onchain in the form of cheap calldata. This ensures that it will always be available when needed. **References** - [Data Availability - Hermez documentation](https://docs.hermez.io/#/developers/glossary?id=data-availability) ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. **References** - [ZK proofs - Hermez documentation](https://docs.hermez.io/#/about/security?id=zk-proofs) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/hermez#updates). ## Operator ### There is no central operator The system runs an auction in which anyone can bid to become the operator for a set number of blocks. The operator will be able to propose blocks and collect fees during this window. Hermez will also run an operator known as boot coordinator that will propose blocks in case no one bids in the auction. This operator can be removed by the governance. **References** - [Forging Consensus Protocol - Hermez documentation](https://docs.hermez.io/#/developers/protocol/consensus/consensus?id=forging-consensus-protocol) - [Boot Coordinator - Hermez documentation](https://docs.hermez.io/#/developers/protocol/consensus/consensus?id=boot-coordinator) ### Users can force any transaction Because the block production is open to anyone if users experience censorship from the operator they can propose their own blocks which would include their transactions. **Risks** - Funds can be frozen if the operator refuses to include their transactions and users lack resources to propose blocks themselves. **References** - [Can coordinators censor transactions? - Hermez documentation](https://docs.hermez.io/#/faq/end-users?id=can-coordinators-censor-transactions) ## Withdrawals ### Regular exit The user initiates the withdrawal by submitting a regular transaction on this chain. When the block containing that transaction is settled the funds become available for withdrawal on L1. ZK proofs are required to settle blocks. Finally the user submits an L1 transaction to claim the funds. This operation cannot be performed if the withdrawal exceeds certain threshold. **References** - [Withdrawing Funds from Hermez - Hermez documentation](https://docs.hermez.io/#/developers/sdk?id=withdrawing-funds-from-hermez) ### Forced withdraw The user submits the withdrawal request on L1. This forces the operators to pick up the request before other L2 transactions. A block still needs to be proved, the user still submits a merkle proof, and the funds threshold still cannot be exceeded. **References** - [Force Exit - Hermez documentation](https://docs.hermez.io/#/developers/sdk?id=force-exit) ### Delayed withdraw When the user does a regular or forced withdraw and their funds exceed a certain threshold a timer activates. After a specified time has passed and the emergency mode has not been activated the funds can be withdrawn. **References** - [Withdrawal Delayer Mechanism - Hermez documentation](https://docs.hermez.io/#/developers/protocol/withdrawal-delayer/withdrawal-delayer?id=mechanism) ### Emergency mode When the user does a regular or forced withdraw and their funds exceed a certain threshold a timer activates. The operators can now trigger emergency mode and transfer the user's funds to the governance. **Risks** - Funds can be stolen if the operators trigger a false alarm during withdrawal (CRITICAL). **References** - [Withdrawal Delayer Mechanism - Hermez documentation](https://docs.hermez.io/#/developers/protocol/withdrawal-delayer/withdrawal-delayer?id=mechanism) ## Smart contracts ### Ethereum #### HermezAuctionProtocol Addresses: [0x15468b45eD46C8383F5c0b1b6Cf2EcF403C2AeC2](https://etherscan.io/address/0x15468b45eD46C8383F5c0b1b6Cf2EcF403C2AeC2#code), [0x9D62Cdc389caaB35ada830A7C6Ae847D5E8512C6](https://etherscan.io/address/0x9D62Cdc389caaB35ada830A7C6Ae847D5E8512C6#code) (Implementation (Upgradable)), [0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3](https://etherscan.io/address/0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3#code) (Admin) #### Hermez Addresses: [0xA68D85dF56E733A06443306A095646317B5Fa633](https://etherscan.io/address/0xA68D85dF56E733A06443306A095646317B5Fa633#code), [0x6D85D79D69b7e190E671C16e8611997152bD3e95](https://etherscan.io/address/0x6D85D79D69b7e190E671C16e8611997152bD3e95#code) (Implementation (Upgradable)), [0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3](https://etherscan.io/address/0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3#code) (Admin) #### ProxyAdmin Addresses: [0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3](https://etherscan.io/address/0x07a00a617e1DaB02Aa31887Eb5d521d4529a32E3#code) Admin of HermezAuctionProtocol and Hermez, owned by the timelock. #### WithdrawalDelayer Addresses: [0x392361427Ef5e17b69cFDd1294F31ab555c86124](https://etherscan.io/address/0x392361427Ef5e17b69cFDd1294F31ab555c86124#code) #### Timelock Addresses: [0xf7b20368Fe3Da5CD40EA43d61F52B23145544Ec3](https://etherscan.io/address/0xf7b20368Fe3Da5CD40EA43d61F52B23145544Ec3#code) Enforces a 7 day delay on upgrades. The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is a 7 days delay on code upgrades.