Search

Search for projects by name or address

Hyperliquid logo
Hyperliquid

Critical contracts can be upgraded by an EOA which could result in the loss of all funds.

Badges

About

Hyperliquid is a performant exchange with its main bridge on Arbitrum. It uses a custom consensus algorithm called HyperBFT.


  • Total Value SecuredTVS
    $7.26 B1.20%
  • Past day UOPSDaily UOPS
    No data
  • Type
    Other
  • Purpose
    Exchange

  • Host chain
    Arbitrum One

  • Tokens breakdown


    Sequencer failureState validationData availabilityExit windowProposer failure

    Badges

    About

    Hyperliquid is a performant exchange with its main bridge on Arbitrum. It uses a custom consensus algorithm called HyperBFT.

    Why is the project listed in others?

    The proof system isn't fully functional

    Consequence: projects without a proper proof system fully rely on single entities to safely update the state. A malicious proposer can finalize an invalid state, which can cause loss of funds.

    There is no data availability bridge

    Consequence: projects without a data availability bridge fully rely on single entities (the sequencer) to honestly rely available data roots on Ethereum. A malicious sequencer can collude with the proposer to finalize an unavailable state, which can cause loss of funds.

    Learn more about the recategorisation here.


    Total
    Canonically BridgedCanonically Bridged ValueCanonical
    Natively MintedNatively Minted TokensNative
    Externally BridgedExternally Bridged ValueExternal

    ETH & derivatives
    Stablecoins
    BTC & derivatives
    Other
    Compare with other projects
    Chain stats
    Transfer size
    Under $100
    $100-$1K
    $1K-$10K
    $10K-$100K
    Over $100K
    Transfer type distribution

    The L3 risks depend on the individual properties of L3 and those of the host chain combined.
    Critical contracts can be upgraded by an EOA which could result in the loss of all funds.
    SEQUENCER
    FAILURE
    STATE
    VALIDATION
    DATA
    AVAILABILITY
    EXIT WINDOWPROPOSER
    FAILURE
    Arbitrum One
    L2
    Self sequenceFraud proofs (INT)OnchainNoneSelf propose
    Hyperliquid
    L3 • Individual
    No mechanismNoneExternalNoneCannot withdraw
    Hyperliquid
    L3 • Combined
    No mechanismNoneExternalNoneCannot withdraw
    L2 & L3 individual risks
    Sequencer failureState validationData availabilityExit windowProposer failure
    L3 combined risks
    Sequencer failureState validationData availabilityExit windowProposer failure

    L3 combined risks
    The information below reflects combined L2 & L3 risks.
    Sequencer failure
    No mechanism

    There is no mechanism to have transactions be included if the sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. is down or censoring.

    State validation
    None

    Currently the system permits invalid state rootsA cryptographic hash succinctly representing a state using a Merkle tree.. More details in project overview.

    Data availability
    External

    Proof construction and state derivation rely fully on data that is ultimately NOT published on Ethereum.

    Exit window
    None

    There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable.

    Proposer failure
    Cannot withdraw

    Only the whitelisted proposers can publish state rootsA cryptographic hash succinctly representing a state using a Merkle tree. on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., so in the event of failure the withdrawals are frozen.

    No state validation

    Hyperliquid does not use a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system. to validate state transitions on Arbitrum. Withdrawals are externally verified by the permissioned validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier set.

    • Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL).

    • Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL).

    Past upgrades

    The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included.

    Count of upgrades
    No upgrades
    Last upgrade
    N/A
    Avg upgrade interval
    N/A
    2026 June 11, 09:48 UTC
    2changes

    add hyperevm locking USDC escrow.

    New and verified contracts

    + Status: CREATED
    contract CoreWriter (hyperevm:0x3333333333333333333333333333333333333333) [N/A]
    +++ description: None
    + Status: CREATED
    contract CoreDepositWallet (hyperevm:0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24) [hyperliquid/CoreDepositWallet]
    +++ description: Manages USDC transfers between HyperEVM and HyperCore. It handles user deposits, optionally deducts a fee for new HyperCore accounts, and routes assets to specific DEXs. It also processes cross-chain withdrawals from HyperCore to external chains via Circle CCTP.
    2026 April 24, 13:19 UTC
    1change

    revive hl.

    Initial discovery

    + Status: CREATED
    contract HyperliquidBridge (arb1:0x2Df1c51E09aECF9cacB7bc98cB1742757f163dF7)
    +++ description: Single contract containing the logic for the Hyperliquid bridge. It manages deposits, withdrawals, the hot and cold validator sets, as well as the lockers, finalizers, and all the permissioned functions. The current locker threshold is 2 and the minimum validator threshold is 2/3*4.
    The section considers only the L3 properties. For more details please refer to Arbitrum One logoArbitrum One

    The system has a centralized operator

    Hyperliquid is composed of two sets of permissioned validatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier: a “hot” validator set and a “cold” validator set. The hot validator set is responsible for initiating withdrawals upon user requests, while cold validators can invalidate them during the 200s challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled. and rotate validator sets after an emergency pause. Both sets are currently composed of 4 validators with equal power. The system accepts a request if signed by 2/3+1 of validator power.

    • MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.

    • Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL).

    • Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL).

    • Funds can be frozen if the permissioned lockers maliciously pause the bridge.

    • Funds can be stolen if the permissioned finalizers don't finalize withdrawals.

    1. Bridge2 - Hyperliquid docs
    2. Bridge2 contract: function checkValidatorSignatures()
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner

    Arbitrum One

    Actors:

    • Can interact with HyperliquidBridge
      • Can request withdrawals, start a validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier set change, add lockers and finalizers (Can also change cold validators by adding a finalizer and proposing/finalizing a new validator set)
      • finalize withdrawals, finalize validator set updates
      • vote for locking the bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. contract
    • Can interact with HyperliquidBridge
      • Can change the dispute period, blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. duration and locker threshold. Can also invalidate withdrawals, emergencyUnlock (unpause and change the validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier set), remove lockers and finalizers
    • Can interact with HyperliquidBridge
      • finalize withdrawals, finalize validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier set updates
      • vote for locking the bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. contract

    HyperEVM

    Actors:

    • Can upgrade with no delay
      • CoreDepositWallet
    A dashboard to explore contracts and permissions
    Go to Disco
    Disco UI Banner
    A diagram of the smart contract architecture
    A diagram of the smart contract architecture

    Arbitrum One

    HyperliquidBridge
    Escrow
    0x2Df1…3dF7

    Single contract containing the logic for the Hyperliquid bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge.. It manages deposits, withdrawals, the hot and cold validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier sets, as well as the lockers, finalizers, and all the permissioned functions. The current locker threshold is 2 and the minimum validator threshold is 2/3*4.

    • Roles:
      • coldAddresses: EOA 3, EOA 4, EOA 5, EOA 7
      • finalizers: EOA 1, EOA 2, EOA 6, EOA 8, EOA 9
      • hotAddresses: EOA 1, EOA 2, EOA 6, EOA 8
      • lockers: EOA 1, EOA 2, EOA 6, EOA 8, EOA 9
    The following tokens are included in the value secured calculation:
    USDC token logo

    HyperEVM

    CoreWriter0x3333…3333

    Manages USDC transfers between HyperEVM and HyperCore. It handles user deposits, optionally deducts a fee for new HyperCore accounts, and routes assets to specific DEXs. It also processes cross-chain withdrawals from HyperCore to external chains via Circle CCTP.

    • Roles:
      • admin: EOA 10
    The following tokens are included in the value secured calculation:
    USDC token logo
    Can be upgraded by: