# Immutable zkEVM Markdown version of https://l2beat.com/layer2s/projects/immutablezkevm ## Summary - Total Value Secured: $27.81 M (+2.73% compared to seven days ago; canonically bridged $27.80 M, natively minted $11.43 K, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - **Warning:** The IMX token associated with Immutable zkEVM accounts for 47.0% of the TVS! (sentiment: warning) - Past day UOPS: 0.50 (-6.39% compared to seven days ago) - Type: Other - Purpose: Universal - Host chain: Ethereum - Chain ID: 13371 ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: None (sentiment: bad) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Immutable zkEVM is a sidechain focused on gaming and powered by Polygon stack. It plans to eventually transition to a ZK Rollup. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/immutablezkevm#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/immutablezkevm) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/immutablezkevm/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/immutablezkevm#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/immutablezkevm) ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. validators decide to mint more tokens than there are locked on Ethereum thus preventing some existing holders from being able to bring their funds back to Ethereum, 3. validators relay a withdraw request that wasn't originated on the source chain. ### Users can be censored if 4. validators on Axelar decide to not mint tokens after observing an event on Ethereum. ## Risk analysis ### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. ### State validation None (sentiment: bad) Currently the system permits invalid state roots. More details in project overview. ### Data availability External (sentiment: bad) Proof construction and state derivation rely fully on data that is NOT published onchain. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## State validation ### No state validation Immutable zkEVM bridge makes use of Axelar network (a Cosmos chain) to transfer assets between Ethereum and Immutable zkEVM. As in any standard Cosmos chain, validators are bonded by staking tokens and can be slashed by social consensus for misbehaviour. A deposit starts by a user depositing tokens on the Bridge contract and then the tokens are minted on the destination chain. Withdrawals to Ethereum can be delayed by a predefined time with a flow rate mechanism that controls outflows of the bridge escrow. The ProxyAdmin or an address with the rate_control role can define so-called buckets for each token: Each bucket has a capacity and a refill rate. All withdrawals that exceed the tokens bucket capacity trigger the withdrawal queue, which delays subsequent withdrawals of *any* of the bridges' assets for a time defined in withdrawalDelay (currently 1d). **Risks** - Users can be censored if validators on Axelar decide to not mint tokens after observing an event on Ethereum. - Funds can be stolen if validators decide to mint more tokens than there are locked on Ethereum thus preventing some existing holders from being able to bring their funds back to Ethereum. - Funds can be stolen if validators relay a withdraw request that wasn't originated on the source chain. ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/immutablezkevm#updates). ## Permissions ### Ethereum #### Actors ##### OwnerMultisig Addresses: [0xD2C37fC6fD89563187f3679304975655e448D192](https://etherscan.io/address/0xD2C37fC6fD89563187f3679304975655e448D192) A Multisig with 4/6 threshold. Multisig controlling the ProxyAdmin, potentially stealing all locked funds. ##### ProxyAdmin Addresses: [0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8](https://etherscan.io/address/0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8) Contract allowed to upgrade the Bridge, its flow rate control and the Axelar adaptor. ## Smart contracts ### Ethereum #### Bridge Addresses: [0xBa5E35E26Ae59c7aea6F029B68c6460De2d13eB6](https://etherscan.io/address/0xBa5E35E26Ae59c7aea6F029B68c6460De2d13eB6#code), [0x177EaFe0f1F3359375B1728dae0530a75C83E154](https://etherscan.io/address/0x177EaFe0f1F3359375B1728dae0530a75C83E154#code) (Implementation (Upgradable)), [0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8](https://etherscan.io/address/0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8#code) (Admin) Main escrow for tokens. Can be upgraded by: ProxyAdmin with no delay #### RootAxelarBridgeAdaptor Addresses: [0x4f49B53928A71E553bB1B0F66a5BcB54Fd4E8932](https://etherscan.io/address/0x4f49B53928A71E553bB1B0F66a5BcB54Fd4E8932#code), [0xE2E91C1Ae2873720C3b975a8034e887A35323345](https://etherscan.io/address/0xE2E91C1Ae2873720C3b975a8034e887A35323345#code) (Implementation (Upgradable)), [0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8](https://etherscan.io/address/0xdE2BCd3F0297d29c25e83228E5A33C0b43b51Ec8#code) (Admin) Axelar adaptor contract used by the bridge. Can be upgraded by: ProxyAdmin with no delay The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).