Search for projects by name or address
Critical contracts can be upgraded by an EOA which could result in the loss of all funds.
Hyperliquid is a performant exchange with its main bridge on Arbitrum. It uses a custom consensus algorithm called HyperBFT.
Hyperliquid is a performant exchange with its main bridge on Arbitrum. It uses a custom consensus algorithm called HyperBFT.
Consequence: projects without a proper proof system fully rely on single entities to safely update the state. A malicious proposer can finalize an invalid state, which can cause loss of funds.
Consequence: projects without a data availability bridge fully rely on single entities (the sequencer) to honestly rely available data roots on Ethereum. A malicious sequencer can collude with the proposer to finalize an unavailable state, which can cause loss of funds.
Learn more about the recategorisation here.
| SEQUENCER FAILURE | STATE VALIDATION | DATA AVAILABILITY | EXIT WINDOW | PROPOSER FAILURE | |
| Arbitrum One L2 | Self sequence | Fraud proofs (INT) | Onchain | None | Self propose |
| Hyperliquid L3 • Individual | No mechanism | None | External | None | Cannot withdraw |
| Hyperliquid L3 • Combined | No mechanism | None | External | None | Cannot withdraw |
There is no mechanism to have transactions be included if the sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. is down or censoring.
Currently the system permits invalid state rootsA cryptographic hash succinctly representing a state using a Merkle tree.. More details in project overview.
Proof construction and state derivation rely fully on data that is ultimately NOT published on Ethereum.
There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable.
Only the whitelisted proposers can publish state rootsA cryptographic hash succinctly representing a state using a Merkle tree. on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., so in the event of failure the withdrawals are frozen.
Hyperliquid does not use a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system. to validate state transitions on Arbitrum. Withdrawals are externally verified by the permissioned validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier set.
Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL).
Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL).
The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included.
add hyperevm locking USDC escrow.
add hyperevm locking USDC escrow.
| + | Status: CREATED |
| contract CoreWriter (hyperevm:0x3333333333333333333333333333333333333333) [N/A] | |
| +++ description: None | |
| + | Status: CREATED |
| contract CoreDepositWallet (hyperevm:0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24) [hyperliquid/CoreDepositWallet] | |
| +++ description: Manages USDC transfers between HyperEVM and HyperCore. It handles user deposits, optionally deducts a fee for new HyperCore accounts, and routes assets to specific DEXs. It also processes cross-chain withdrawals from HyperCore to external chains via Circle CCTP. | |
revive hl.
revive hl.
| + | Status: CREATED |
| contract HyperliquidBridge (arb1:0x2Df1c51E09aECF9cacB7bc98cB1742757f163dF7) | |
| +++ description: Single contract containing the logic for the Hyperliquid bridge. It manages deposits, withdrawals, the hot and cold validator sets, as well as the lockers, finalizers, and all the permissioned functions. The current locker threshold is 2 and the minimum validator threshold is 2/3*4. | |
Hyperliquid is composed of two sets of permissioned validatorsIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier: a “hot” validator set and a “cold” validator set. The hot validator set is responsible for initiating withdrawals upon user requests, while cold validators can invalidate them during the 200s challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled. and rotate validator sets after an emergency pause. Both sets are currently composed of 4 validators with equal power. The system accepts a request if signed by 2/3+1 of validator power.
MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.
Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL).
Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL).
Funds can be frozen if the permissioned lockers maliciously pause the bridge.
Funds can be stolen if the permissioned finalizers don't finalize withdrawals.



Single contract containing the logic for the Hyperliquid bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge.. It manages deposits, withdrawals, the hot and cold validatorIn the context of L2s, a Validator is an actor that validates the correctness of state transitions. For optimistic rollups this corresponds to challengers, and for ZK rollups this corresponds to the onchain verifier sets, as well as the lockers, finalizers, and all the permissioned functions. The current locker threshold is 2 and the minimum validator threshold is 2/3*4.

Manages USDC transfers between HyperEVM and HyperCore. It handles user deposits, optionally deducts a fee for new HyperCore accounts, and routes assets to specific DEXs. It also processes cross-chain withdrawals from HyperCore to external chains via Circle CCTP.
