# Hyperliquid Markdown version of https://l2beat.com/layer2s/projects/hyperliquid ## Summary **Warning:** Critical contracts can be upgraded by an EOA which could result in the loss of all funds. **Warning:** Why is the project listed in others? The proof system isn't fully functional. Consequence: projects without a proper proof system fully rely on single entities to safely update the state. A malicious proposer can finalize an invalid state, which can cause loss of funds. There is no data availability bridge. Consequence: projects without a data availability bridge fully rely on single entities (the sequencer) to honestly rely available data roots on Ethereum. A malicious sequencer can collude with the proposer to finalize an unavailable state, which can cause loss of funds. Learn more about the [recategorisation](https://medium.com/l2beat/framework-update-l2-projects-recategorisation-5d43b0d1fe50). - Total Value Secured: $7.16 B (-1.38% compared to seven days ago; canonically bridged $7.16 B, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - TVS by asset: Stablecoins $7.16 B (100%) - Past day UOPS: No data - Type: Other - Purpose: Exchange - Host chain: Arbitrum One - Last 24h cross-chain volume: $190.65 M - Last 24h cross-chain transfers: 17.48 K - Interop protocols used (last 24h volume): [Hyperliquid](https://l2beat.com/interop/protocols/hyperliquid) ($149.58 M), [CCTP v2](https://l2beat.com/interop/protocols/cctpv2) ($38.07 M), [Relay](https://l2beat.com/interop/protocols/relay) ($2.99 M) - Tokens by volume (last 24h): [USDC](https://l2beat.com/interop/tokens/9HN5PN/usdc) ($189.29 M), [ETH](https://l2beat.com/interop/tokens/C0Hmkq/eth) ($758.97 K), [USDT](https://l2beat.com/interop/tokens/xxeNQv/usdt) ($281.42 K), and 119 more - Risks shown: combined with host chain Arbitrum One; Risk analysis also lists each separately ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: None (sentiment: bad) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Hyperliquid is a performant exchange with its main bridge on Arbitrum. It uses a custom consensus algorithm called HyperBFT. ### Links - Website: https://hyperfoundation.org/ - Bridge: https://app.hyperliquid.xyz/trade - Docs: https://hyperliquid.gitbook.io/hyperliquid-docs - Explorer: https://app.hyperliquid.xyz/explorer - Repository: https://github.com/hyperliquid-dex - Social: https://x.com/HyperliquidX, https://discord.gg/hyperliquid, https://t.me/hyperliquid_dex - Contracts explorer (Disco): https://disco.l2beat.com/ui/p/hyperliquid ### Badges - Application-specific chain: This project is built to operate a specific application - Custom DA solution: This project is using a custom DA solution - Built on top of Arbitrum: The project has Arbitrum as its host chain ## Value Secured The interactive TVS charts are shown on [the HTML page](https://l2beat.com/layer2s/projects/hyperliquid#tvs). Token by token: [TVS breakdown](https://l2beat.com/layer2s/projects/hyperliquid/tvs-breakdown). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/hyperliquid) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/hyperliquid/breakdown) ## Volume and flows The interactive flows chart is shown on [the HTML page](https://l2beat.com/layer2s/projects/hyperliquid#interop-flows). ## Risk summary There are 3 additional risks coming from the host chain [Arbitrum One](https://l2beat.com/layer2s/projects/arbitrum) ### Funds can be stolen if 1. the permissioned validator majority signs an invalid withdrawal request (CRITICAL), 2. the permissioned finalizers don't finalize withdrawals. ### Funds can be frozen if 3. the permissioned validator set stops processing withdrawals (CRITICAL), 4. the permissioned lockers maliciously pause the bridge. ### MEV can be extracted if 5. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis The L3 risks depend on the individual properties of L3 and those of the host chain combined. **Warning:** Critical contracts can be upgraded by an EOA which could result in the loss of all funds. | | Sequencer failure | State validation | Data availability | Exit window | Proposer failure | | --- | --- | --- | --- | --- | --- | | Arbitrum One (L2) | Self sequence (sentiment: good) | Fraud proofs (INT) (sentiment: good) | Onchain (sentiment: good) | None (sentiment: bad) | Self propose (sentiment: good) | | Hyperliquid (L3, individual) | No mechanism (sentiment: bad) | None (sentiment: bad) | External (sentiment: bad) | None (sentiment: bad) | Cannot withdraw (sentiment: bad) | | Hyperliquid (L3, combined) | No mechanism (sentiment: bad) | None (sentiment: bad) | External (sentiment: bad) | None (sentiment: bad) | Cannot withdraw (sentiment: bad) | ### L3 combined risks The information below reflects combined L2 & L3 risks. #### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. #### State validation None (sentiment: bad) Currently the system permits invalid state roots. More details in project overview. #### Data availability External (sentiment: bad) Proof construction and state derivation rely fully on data that is ultimately NOT published on Ethereum. #### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. #### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## State validation ### No state validation Hyperliquid does not use a proof system to validate state transitions on Arbitrum. Withdrawals are externally verified by the permissioned validator set. **Risks** - Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL). - Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL). ## Upgrades & Governance ### Past upgrades The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included. - Count of upgrades: No upgrades - Last upgrade: N/A - Avg upgrade interval: N/A - 2025-11-18 16:23 UTC, deployment of [CoreDepositWallet](https://hyperevmscan.io/address/0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24#code): transaction [0x920aa47c6b5f9939fbe7f791b96283e063b4256f6994356a2ad03bc6eac26518](https://hyperevmscan.io/tx/0x920aa47c6b5f9939fbe7f791b96283e063b4256f6994356a2ad03bc6eac26518), implementations: [0x7537af00779cc053a696e47ebd451b5bc4790DA3](https://hyperevmscan.io/address/0x7537af00779cc053a696e47ebd451b5bc4790DA3#code) ## Updates Each date links the update on the HTML page, which also shows its contract diffs. ### [2026-06-11 09:48 UTC](https://l2beat.com/layer2s/projects/hyperliquid?update=2329222d) (2 changes) add hyperevm locking USDC escrow. ### [2026-04-24 13:19 UTC](https://l2beat.com/layer2s/projects/hyperliquid?update=bd305647) (1 change) revive hl. ## Operator The section considers only the L3 properties. For more details please refer to [Arbitrum One](https://l2beat.com/layer2s/projects/arbitrum) ### The system has a centralized operator Hyperliquid is composed of two sets of permissioned validators: a "hot" validator set and a "cold" validator set. The hot validator set is responsible for initiating withdrawals upon user requests, while cold validators can invalidate them during the 200s challenge period and rotate validator sets after an emergency pause. Both sets are currently composed of 4 validators with equal power. The system accepts a request if signed by 2/3+1 of validator power. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. - Funds can be stolen if the permissioned validator majority signs an invalid withdrawal request (CRITICAL). - Funds can be frozen if the permissioned validator set stops processing withdrawals (CRITICAL). - Funds can be frozen if the permissioned lockers maliciously pause the bridge. - Funds can be stolen if the permissioned finalizers don't finalize withdrawals. **References** - [Bridge2 - Hyperliquid docs](https://hyperliquid.gitbook.io/hyperliquid-docs/for-developers/api/bridge2) - [Bridge2 contract: function checkValidatorSignatures()](https://arbiscan.io/address/0x2Df1c51E09aECF9cacB7bc98cB1742757f163dF7#code#L2190) ## Permissions Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/hyperliquid ### Arbitrum One #### Actors ##### 4 EOAs (0x2632…1504) Addresses: [0x263294039413B96D25E4173a5F7599F8b3801504](https://arbiscan.io/address/0x263294039413B96D25E4173a5F7599F8b3801504) (EOA 1), [0x58E1b0E63C905D5982324FCd9108582623b8132e](https://arbiscan.io/address/0x58E1b0E63C905D5982324FCd9108582623b8132e) (EOA 2), [0xda6816df552c3f9e0FB64979fb357800d690d79B](https://arbiscan.io/address/0xda6816df552c3f9e0FB64979fb357800d690d79B) (EOA 6), [0xEF2364dB5db6F5539Aa0bC111771a94Ee47637Fc](https://arbiscan.io/address/0xEF2364dB5db6F5539Aa0bC111771a94Ee47637Fc) (EOA 8) - Can interact with HyperliquidBridge - Can request withdrawals, start a validator set change, add lockers and finalizers (Can also change cold validators by adding a finalizer and proposing/finalizing a new validator set) - finalize withdrawals, finalize validator set updates - vote for locking the bridge contract ##### 4 EOAs (0x5a92…5ede) Addresses: [0x5a92b4A6a525445c9B4FFf61C0db71dCfE305ede](https://arbiscan.io/address/0x5a92b4A6a525445c9B4FFf61C0db71dCfE305ede) (EOA 3), [0x8003FD297a7Aa477B746825E7A506675bF590E91](https://arbiscan.io/address/0x8003FD297a7Aa477B746825E7A506675bF590E91) (EOA 4), [0x86d6AE3032732F27239075D77a1317989B52F628](https://arbiscan.io/address/0x86d6AE3032732F27239075D77a1317989B52F628) (EOA 5), [0xE346B41B47296153A21E64D6bFc857C27874C6e7](https://arbiscan.io/address/0xE346B41B47296153A21E64D6bFc857C27874C6e7) (EOA 7) - Can interact with HyperliquidBridge - Can change the dispute period, block duration and locker threshold. Can also invalidate withdrawals, emergencyUnlock (unpause and change the validator set), remove lockers and finalizers ##### EOA 9 Addresses: [0xf9d2282A4A4C216f624717C0747D23146FC048c5](https://arbiscan.io/address/0xf9d2282A4A4C216f624717C0747D23146FC048c5) - Can interact with HyperliquidBridge - finalize withdrawals, finalize validator set updates - vote for locking the bridge contract ### HyperEVM #### Actors ##### EOA 10 Addresses: [0x8E66c6AC847f06b9502fA2512435a62005f5Fb92](https://hyperevmscan.io/address/0x8E66c6AC847f06b9502fA2512435a62005f5Fb92) - Can upgrade **with no delay** - CoreDepositWallet ## Smart contracts ![A diagram of the smart contract architecture](https://l2beat.com/static/images/architecture/hyperliquid.311669ee.png) Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/hyperliquid ### Arbitrum One #### HyperliquidBridge (escrow) Addresses: [0x2Df1c51E09aECF9cacB7bc98cB1742757f163dF7](https://arbiscan.io/address/0x2Df1c51E09aECF9cacB7bc98cB1742757f163dF7#code) Single contract containing the logic for the Hyperliquid bridge. It manages deposits, withdrawals, the hot and cold validator sets, as well as the lockers, finalizers, and all the permissioned functions. The current locker threshold is 2 and the minimum validator threshold is 2/3*4. - Roles: - **coldAddresses**: EOA 3, EOA 4, EOA 5, EOA 7 - **finalizers**: EOA 1, EOA 2, EOA 6, EOA 8, EOA 9 - **hotAddresses**: EOA 1, EOA 2, EOA 6, EOA 8 - **lockers**: EOA 1, EOA 2, EOA 6, EOA 8, EOA 9 The following tokens are included in the value secured calculation: USDC ### HyperEVM #### CoreWriter Addresses: [0x3333333333333333333333333333333333333333](https://hyperevmscan.io/address/0x3333333333333333333333333333333333333333#code) #### CoreDepositWallet (escrow) Addresses: [0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24](https://hyperevmscan.io/address/0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24#code), [0x7537af00779cc053a696e47ebd451b5bc4790DA3](https://hyperevmscan.io/address/0x7537af00779cc053a696e47ebd451b5bc4790DA3#code) (Implementation (Upgradable)), [0x8E66c6AC847f06b9502fA2512435a62005f5Fb92](https://hyperevmscan.io/address/0x8E66c6AC847f06b9502fA2512435a62005f5Fb92#code) (Admin) **Past upgrades** (Count of upgrades: No upgrades, Last upgrade: N/A, Avg upgrade interval: N/A) - 2025-11-18 16:23 UTC, deployment of [CoreDepositWallet](https://hyperevmscan.io/address/0x6B9E773128f453f5c2C60935Ee2DE2CBc5390A24#code): transaction [0x920aa47c6b5f9939fbe7f791b96283e063b4256f6994356a2ad03bc6eac26518](https://hyperevmscan.io/tx/0x920aa47c6b5f9939fbe7f791b96283e063b4256f6994356a2ad03bc6eac26518), implementations: [0x7537af00779cc053a696e47ebd451b5bc4790DA3](https://hyperevmscan.io/address/0x7537af00779cc053a696e47ebd451b5bc4790DA3#code) Manages USDC transfers between HyperEVM and HyperCore. It handles user deposits, optionally deducts a fee for new HyperCore accounts, and routes assets to specific DEXs. It also processes cross-chain withdrawals from HyperCore to external chains via Circle CCTP. - Roles: - **admin**: EOA 10 The following tokens are included in the value secured calculation: USDC Can be upgraded by: EOA 10 with no delay