Search

Search for projects by name or address

Ink logo
Ink

There are impactful changes and part of the information might be outdated.

Badges

About

Ink is an Optimistic Rollup built with the OP Stack by Kraken exchange.



Badges

About

Ink is an Optimistic Rollup built with the OP Stack by Kraken exchange.


Total
Canonically BridgedCanonically Bridged ValueCanonical
Natively MintedNatively Minted TokensNative
Externally BridgedExternally Bridged ValueExternal

ETH & derivatives
Stablecoins
BTC & derivatives
Other
Compare with other projects
Chain stats
Transfer size
Under $100
$100-$1K
$1K-$10K
$10K-$100K
Over $100K
Transfer type distribution

Past Day UOPS
Past Day Ops count
Max. UOPS
Past day UOPS/TPS Ratio
Compare with other projects

The section shows the operating costs that L2s pay to Ethereum.



Total cost
Avg cost per L2 UOP
Avg cost per day

Compare with other projects

This section shows how much data the project publishes to its data-availability (DA) layer over time. The project currently posts data to; previously it posted toEthereumEthereum.



Data posted
Avg size per day
Avg size per L2 UOP

Compare with other projects

This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule.

No ongoing anomalies detected

Avg. tx data subs. interval
Avg. state updates interval
Past 30 days anomalies
100% normal uptime

Ink becomes Stage 1

2025 Jan 22nd

Learn more
Sequencer failureState validationData availabilityExit windowProposer failure
Sequencer failure
Self sequence

In the event of a sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. failure, users can force transactions to be included in the project’s chain by sending them to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. There can be up to a 12h delay on this operation.

State validation
Fraud proofs (INT)

Fraud proofs allow actors watching the chain to prove that the state is incorrect. Interactive proofs (INT) require multiple transactions over time to resolve.

Data availability
Onchain

All of the data needed for proof construction is published on Ethereum L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

Exit window
None

There is no exit windowThe amount of time that users have to exit a system before an unwanted upgrade. It takes into account upgrade delays, forced transaction delays and other time factors. To be considered Stage 1, a rollup needs to have an exit window of at least 7d if upgrades are initiated by a permissioned actor less decentralized than a Security Council. For Stage 2, a rollup needs at least 30d in all cases outside of onchain provable bugs. for users to exit in case of unwanted upgrades as they are initiated by the Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. with instant upgrade power and without proper notice.

Proposer failure
Self propose

Anyone can be a ProposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. and propose new roots to the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge..

Ink
Ink is a
Stage 1
Optimistic Rollup.
The project passes the walkaway test: users can exit in the presence of malicious operators even if the Security Council disappears.

Learn more about Stages
Please keep in mind that these stages do not reflect project security, this is an opinionated assessment of project maturity based on subjective criteria, created with a goal of incentivizing projects to push toward better decentralization. Each team may have taken different paths to achieve this goal.

All data required for proofs is published on chain

All the data that is used to construct the system state is published on chain in the form of cheap blobsThe data that a rollup publishes to its L1/data availability (DA) layer. They consist of the L2 transactions that are rolled up, along with some metadata. Blobs are introduced as a new transaction type within Ethereum with EIP-4844, and has rollup scaling specifically in mind. Blobs persist on Ethereum’s Beacon Chain ephemerally. or calldata. This ensures that it will be available for enough time.

  1. Derivation: Batch submission - OP Mainnet specs
  2. BatchInbox - address
  3. OptimismPortal2.sol - source code, depositTransaction function
Learn more about the DA layer here: Ethereum logoEthereum
Node software

The rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. nodeA software client that participates in the network. is composed of two software components: op-node, implementing consensusAn agreement on the latest and correct state of a blockchain. Unlike L1 blockchains which coordinate participating nodes with consensus rules, rollups rely on L1s for reaching consensus by checking the state of the rollup smart contract deployed thereon. related logic, and op-geth, implementing execution logic. The configuration file can be found here.

Compression scheme

Data batches are compressed using the zlib algorithm with best compression level.

Genesis state

The genesis file can be found here.

Data format

The format specification of SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs.’s data batches can be found here.

A diagram of the state validation
A diagram of the state validation

Updates to the system state can be proposed and challenged by anyone who has sufficient funds. If a state rootA cryptographic hash succinctly representing a state using a Merkle tree. passes the challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled., it is optimistically considered correct and made actionable for withdrawals.


State root proposals

Proposers submit state rootsA cryptographic hash succinctly representing a state using a Merkle tree. as children of the latest confirmed state root (called anchor state), by calling the create function in the DisputeGameFactory. A state root can have multiple conflicting children. Each proposal requires a stake, currently set to 0.08 ETH, that can be slashed if the proposal is proven incorrect via a fraud proofAlso referred to as a fault proof, it is the construction of an assertion that fraud was perpetrated on an optimistic rollup. More concretely, that an invalid state transition took place according to the protocol rules. The submitter of a fraud proof would expect a reward from the optimistic rollup protocol for helping maintain the integrity of the system.. Stakes can be withdrawn only after the proposal has been confirmed. A state root gets confirmed if the challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled. has passed and it is not countered.

  1. OP stack specification: Fault Dispute Game
Challenges

Challenges are opened to disprove invalid state rootsA cryptographic hash succinctly representing a state using a Merkle tree. using bisection games. Each bisection move requires a stake that increases expontentially with the depth of the bisection, with a factor of 1.09493. The maximum depth is 73, and reaching it therefore requires a cumulative stake of 691.23 ETH from depth 0. Actors can participate in any challenge by calling the defend or attack functions, depending whether they agree or disagree with the latest claim and want to move the bisection game forward. Actors that disagree with the top-level claim are called challengers, and actors that agree are called defenders. Each actor might be involved in multiple (sub-)challenges at the same time, meaning that the protocol operates with full concurrency. Challengers and defenders alternate in the bisection game, and they pass each other a clock that starts with 3d 12h. If a clock expires, the claim is considered defeated if it was countered, or it gets confirmed if uncountered. Since honest parties can inherit clocks from malicious parties that play both as challengers and defenders (see freeloader claims), an inherited clock with too little time remaining is generally extended by 3h. The extension is 6h when the next claim is immediately before split depth 30, and 1d 3h (the standard extension plus the 1d oracle challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled.) immediately before the last depth. Along a full-depth path, cumulative extensions can therefore add up to 10d 3h. Since unconfirmed state roots are independent of one another, users can decide to exit with a subsequent confirmed state root if the previous one is delayed. Winners get the entire losers’ stake, meaning that sybils can potentially play against each other at no cost. The final instruction found via the bisection game is then executed onchain in the MIPS one step proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract. contract who determines the winner. The protocol does not enforce valid bisections, meaning that actors can propose correct initial claims and then provide incorrect midpoints. The protocol can be subject to resource exhaustion attacks (Spearbit 5.1.3).

  1. Fraud Proof Wars: OPFP

Program Hashes

Name
Hash
Repository
Verification
Used in
0x0337...9025
OP Mainnet logoInk logo

Past upgrades

The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included.

Count of upgrades
71
Last upgrade
2mo 23d ago
Avg upgrade interval
2mo 23d
2026 September 10, 12:59 UTC
1change

Optimism Security Council: Member rotated.

contract Optimism Security Council (eth:0xc2819DC788505Aac350142A7A707BF9D03E3Bd03) [GnosisSafe] {
+++ description: None
values.$members.9:
- "eth:0x0aA384EB2fedD2741277A0f72909A0d7275575D7"
+ "eth:0xd91530dB01c60C6B3b824707D33fb0771aB85930"
}
2026 August 27, 12:36 UTC
4changes

SystemConfig: ownership transferred from OpFoundationOperationsSafe to OpFoundationUpgradeSafe.

contract SystemConfig (eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364) [opstack/SystemConfig] {
+++ description: Contains configuration parameters such as the Sequencer address, gas limit on this chain and the unsafe block signer address.
values.owner:
- "eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A"
+ "eth:0x847B5c174615B1B7fDF770882256e2D3E95b9D92"
}
contract OpFoundationUpgradeSafe (eth:0x847B5c174615B1B7fDF770882256e2D3E95b9D92) [GnosisSafe] {
+++ description: None
receivedPermissions.0:
+ {"permission":"interact","from":"eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364","description":"it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system.","role":".owner"}
}
contract OpFoundationOperationsSafe (eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A) [GnosisSafe] {
+++ description: None
receivedPermissions:
- [{"permission":"interact","from":"eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364","description":"it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system.","role":".owner"}]
}
contract SaferSafes (eth:0xA8447329e52F64AED2bFc9E7a2506F7D369f483a) [gnosisSafeModules/SaferSafes] {
+++ description: A Gnosis Safe module combining LivenessModule and TimelockGuard. Provides liveness checks where a fallback owner can challenge and take over if Safe owners are unresponsive, plus optional timelock delays for transaction scheduling.
receivedPermissions.0.via.0.address:
- "eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A"
+ "eth:0x847B5c174615B1B7fDF770882256e2D3E95b9D92"
}
2026 August 10, 11:02 UTC
5changes

DisputeGameFactory: the proposer key was rotated. L1FeeVault: the recipient changed to a new address and the minimum withdrawal dropped from 2 ETH to 0.15 ETH. This vault collects only the L1 data-fee component of L2 transaction fees; the BaseFeeVault and SequencerFeeVault still pay out to the previous recipient at the 2 ETH threshold.

contract DisputeGameFactory (eth:0x10d7B35078d3baabB96Dd45a9143B94be65b12CD) [opstack/DisputeGameFactory_v2] {
+++ description: The dispute game factory allows the creation of dispute games, used to propose state roots and eventually challenge them. This variant exposes per-type reads only; the legacy array views (gameImpls[], initBonds[]) were removed in the new implementation.
values.proposerFromDGF:
- "eth:0x65436ddCbc026F34118954F229f7F132b696b3B4"
+ "eth:0x3832bfbeF03173E4C49a00ec0DD178817A02D177"
}
contract L1FeeVault (ink:0x420000000000000000000000000000000000001A) [opstack/Layer2/L1FeeVault_karst] {
+++ description: Collects the L1 portion of the L2 transaction fees, which are withdrawable to the FeesCollector on L1.
values.MIN_WITHDRAWAL_AMOUNT:
- "2000000000000000000"
+ "150000000000000000"
values.minWithdrawalAmount:
- "2000000000000000000"
+ "150000000000000000"
values.recipient:
- "ink:0xa6f0F94C13C4255231958079E7331694205F6c93"
+ "ink:0x1eB630b2e7409597D462dd5f3D21E305FC56B8C9"
values.RECIPIENT:
- "ink:0xa6f0F94C13C4255231958079E7331694205F6c93"
+ "ink:0x1eB630b2e7409597D462dd5f3D21E305FC56B8C9"
}
2026 July 30, 11:04 UTC
3changes

SystemConfig batch submitter and unsafe block signer rotated. L1Block now mirrors the new batcher hash on L2.

contract SystemConfig (eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364) [opstack/SystemConfig] {
+++ description: Contains configuration parameters such as the Sequencer address, gas limit on this chain and the unsafe block signer address.
values.batcherHash:
- "eth:0x500d7Ea63CF2E501dadaA5feeC1FC19FE2Aa72Ac"
+ "eth:0x6db6161fC5662450E801398Bad62dD9921216B98"
values.unsafeBlockSigner:
- "eth:0x7D056B99AA2021864c42E25B4F8cE3BdEAc9463C"
+ "eth:0x7b322282DF45E537E5de76D60E1432Db3cF3F8E1"
}
contract L1Block (ink:0x4200000000000000000000000000000000000015) [opstack/Layer2/L1Block] {
+++ description: Simple contract that returns information about the latest L1 block, which is derived permissionlessly from the L1 chain.
values.batcherHash:
- "0x000000000000000000000000500d7ea63cf2e501dadaa5feec1fc19fe2aa72ac"
+ "0x0000000000000000000000006db6161fc5662450e801398bad62dd9921216b98"
}
2026 July 20, 15:34 UTC
5changes

SystemConfig owner transferred from the Gelato Multisig to the OpFoundationOperationsSafe ( 0x9BA6…6b3A ). Ink's sequencer address, batch-submitter address, and gas config are now controlled by OP Foundation instead of Gelato.

contract SystemConfig (eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364) [opstack/SystemConfig] {
+++ description: Contains configuration parameters such as the Sequencer address, gas limit on this chain and the unsafe block signer address.
values.owner:
- "eth:0xBeA2Bc852a160B8547273660E22F4F08C2fa9Bbb"
+ "eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A"
}
- Status: DELETED
EOA (eth:0x6a0A93Cd6d6FB7a36bF6234ef4650Bf9474e7682)
+++ description: None
contract OpFoundationOperationsSafe (eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A) [GnosisSafe] {
+++ description: None
receivedPermissions:
+ [{"permission":"interact","from":"eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364","description":"it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system.","role":".owner"}]
}
contract SaferSafes (eth:0xA8447329e52F64AED2bFc9E7a2506F7D369f483a) [gnosisSafeModules/SaferSafes] {
+++ description: A Gnosis Safe module combining LivenessModule and TimelockGuard. Provides liveness checks where a fallback owner can challenge and take over if Safe owners are unresponsive, plus optional timelock delays for transaction scheduling.
receivedPermissions.0:
+ {"permission":"interact","from":"eth:0x62C0a111929fA32ceC2F76aDba54C16aFb6E8364","description":"it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system.","role":".owner","via":[{"address":"eth:0x9BA6e03D8B90dE867373Db8cF1A58d2F7F006b3A"}]}
}
- Status: DELETED
contract Gelato Multisig (eth:0xBeA2Bc852a160B8547273660E22F4F08C2fa9Bbb) [GnosisSafe]
+++ description: None

The system has a centralized operator

The operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. is the only entity that can propose blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over.. A live and trustworthy operator is vital to the health of the system.

  • MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.

Users can force any transaction

Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly.

  1. Sequencing Window - OP Mainnet Specs
  2. OptimismPortal2.sol - source code, depositTransaction function

Regular exits

The user initiates the withdrawal by submitting a regular transaction on this chain. When a state rootA cryptographic hash succinctly representing a state using a Merkle tree. containing such transaction is settled, the funds become available for withdrawal on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. after 3d 12h. Withdrawal inclusion can be proven before state root settlementThe mechanism with which the execution of rollup blocks and the resultant state is verified and possible disputes are resolved. In the context of rollups or other modular blockchains, it often refers to the proof system used--validity (ZK) or fraud proofs, or a combination thereof. Sometimes it will refer to this mechanism along with where the mechanism's outputs are ultimately published and verified, as in Ethereum being a settlement layer by verifying the proofs and allowing for withdrawals., but a 7d period has to pass before it becomes actionable. The process of state root settlement takes a challenge periodIn optimistic rollups, the window of time wherein network participants can assert that some fraud was included in a prior block. Most optimistic rollups currently specify a challenge window of 7 days. By extending the period, there is more time for participants to guard against fraud (invalid state transitions), but also more time until withdrawals gets enabled. of at least 3d 12h to complete. Finally the user submits an L1 transaction to claim the funds. This transaction requires a merkle proof.

  1. OptimismPortal2.sol - Etherscan source code, proveWithdrawalTransaction function
  2. OptimismPortal2.sol - Etherscan source code, finalizeWithdrawalTransaction function

Forced messaging

If the user experiences censorship from the operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. with regular L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.->L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. messaging they can submit their messages directly on L1. The system is then obliged to service this request or halt all messages, including forced withdrawals from L1 and regular messages initiated on L2. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular message.

  1. Forced withdrawal from an OP Stack blockchain

EVM compatible smart contracts are supported

OP stack chains are pursuing the EVM EquivalenceA perfect degree of compatibility; where one system or concept is indistinguishable from another in the domain being compared. In the context of rollups, it generally refers to the proximity to the EVM and to Ethereum architecture. model. No changes to smart contracts are required regardless of the language they are written in, i.e. anything deployed on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. can be deployed on L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  1. Introducing EVM Equivalence
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner

Ethereum

Actors:

SuperchainProxyAdminOwner0x5a0A…3d2A

A Multisig with 2/2 threshold.

  • Can upgrade with no delay
    • DisputeGameFactory
    • DelayedWETH
    • OptimismPortal2
    • SystemConfig
    • L1ERC721Bridge
    • L1CrossDomainMessenger
    • L1StandardBridge
    • SuperchainConfig
    • OptimismMintableERC20Factory
    • ETHLockbox
    • AnchorStateRegistry
  • Can interact with AddressManager
    • set and change address mappings
  • Can interact with AddressManager
    • set and change address mappings
Used in:
OpFoundationUpgradeSafe0x847B…9D92

A Multisig with 5/7 threshold. It uses the following modules: SaferSafes (A Gnosis Safe module combining LivenessModule and TimelockGuard. Provides livenessLiveness refers to the ability of a system to respond to requests and to process them in a timely manner. In the context of L2s, it refers to the ability of settling transactions, proofs and state roots to the base layer. checks where a fallback owner can challenge and take over if Safe owners are unresponsive, plus optional timelock delays for transaction scheduling). Member of SuperchainProxyAdminOwner.

  • Can interact with SystemConfig
    • it can update the preconfer address, the batch submitter (SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs.) address and the gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. configuration of the system
  • Can interact with SuperchainConfig
    • Allowed to pause withdrawals. In op stack systems with a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system., the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants.)
Used in:
SaferSafes0xA844…483a

A Gnosis Safe module combining LivenessModule and TimelockGuard. Provides livenessLiveness refers to the ability of a system to respond to requests and to process them in a timely manner. In the context of L2s, it refers to the ability of settling transactions, proofs and state roots to the base layer. checks where a fallback owner can challenge and take over if Safe owners are unresponsive, plus optional timelock delays for transaction scheduling.

  • Can interact with SystemConfig
    • it can update the preconfer address, the batch submitter (SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs.) address and the gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. configuration of the system
  • Can interact with SuperchainConfig
    • Allowed to pause withdrawals. In op stack systems with a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system., the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants.)
Used in:
Optimism Security Council0xc281…Bd03

A Multisig with 10/13 threshold. It uses the following modules: LivenessModule (used to remove members inactive for 3mo 8d while making sure that the threshold remains above 75%. If the number of members falls below 8, the OpFoundationUpgradeSafe takes ownership of the multisig). Member of Optimism Guardian Multisig, SuperchainProxyAdminOwner.

  • Can interact with SuperchainConfig
    • Allowed to pause withdrawals. In op stack systems with a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system., the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants.)
Used in:
LivenessGuard0x2442…4a25

Modular contract to be used together with the LivenessModule. Tracks livenessLiveness refers to the ability of a system to respond to requests and to process them in a timely manner. In the context of L2s, it refers to the ability of settling transactions, proofs and state roots to the base layer. / activity of Safe owners.

  • Can interact with LivenessModule
    • can remove members of Optimism Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. inactive for 3mo 8d
Used in:
Optimism Guardian Multisig0x09f7…dAf2

A Multisig with 1/1 threshold. It uses the following modules: DeputyPauseModule (Allows 0x2fA150379bF32b6d79Eeb4ff9bD280E76049a87c, called the deputy pauser, to act on behalf of the OpFoundationUpgradeSafe if set as its Safe module).

Participants (1):

Optimism Security Council
Used in:
OpFoundationOperationsSafe0x9BA6…6b3A

A Multisig with 5/7 threshold. It uses the following modules: SaferSafes (A Gnosis Safe module combining LivenessModule and TimelockGuard. Provides livenessLiveness refers to the ability of a system to respond to requests and to process them in a timely manner. In the context of L2s, it refers to the ability of settling transactions, proofs and state roots to the base layer. checks where a fallback owner can challenge and take over if Safe owners are unresponsive, plus optional timelock delays for transaction scheduling).

Used in:
  • Can interact with SystemConfig
    • Allowed to commit transactions from the current layer to the host chain
Optimism EOA 10x2fA1…a87c
  • Can interact with SuperchainConfig
    • Allowed to pause withdrawals. In op stack systems with a proof systemThe infrastructure that allows projects to verify their state transitions. It is composed by onchain verifiers and offchain provers. The main two flavors are optimistic and ZK proof systems, but they can be combined in a hybrid model. In general though, if a system is able to accept state roots optimistically, even if it has a ZK component, it is considered an optimistic proof system., the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants.)
Used in:

Ink

Actors:

SuperchainProxyAdminOwner_L2Alias0x6B1B…4E3b
  • Can upgrade with no delay
    • L2CrossDomainMessenger
    • GasPriceOracle
    • L2StandardBridge
    • SequencerFeeVault
    • OptimismMintableERC20Factory
    • L1BlockNumber
    • L2ERC721Bridge
    • L1Block
    • L2ToL1MessagePasser
    • OptimismMintableERC721Factory
    • L2ProxyAdmin
    • BaseFeeVault
    • L1FeeVault
    • SchemaRegistry
    • EAS
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner
Note: Contracts presented in this section had their implementations updated since the last time our team looked at this project. The information presented may be inaccurate.
A diagram of the smart contract architecture
A diagram of the smart contract architecture

Ethereum

The main entry point to deposit ERC20 tokens from host chain to this chain.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner

All supported tokens in this escrow are included in the value secured calculation.

Implementation used in:
LivenessModule0x0454…a748

used to remove members inactive for 3mo 8d while making sure that the threshold remains above 75%. If the number of members falls below 8, the OpFoundationUpgradeSafe takes ownership of the multisig

  • Roles:
    • fallbackOwner: OpFoundationUpgradeSafe if the number of Optimism Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. members falls below 8
    • livenessGuard: LivenessGuard
Implementation used in:
PreimageOracle0x1E1d…b1E0

The PreimageOracle contract is used to load the required data from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. for a dispute game.

Implementation used in:
FaultDisputeGame0x2DDA…4AeC

Logic of the dispute game. When a state rootA cryptographic hash succinctly representing a state using a Merkle tree. is proposed, a dispute game contract is deployed. Challengers can use such contracts to challenge the proposed state root.

Implementation used in:
SuperchainProxyAdmin0x543b…fB04
  • Roles:
    • owner: SuperchainProxyAdminOwner
Implementation used in:
DeputyPauseModule0x76fC…1754

Allows 0x2fA150379bF32b6d79Eeb4ff9bD280E76049a87c, called the deputy pauser, to act on behalf of the OpFoundationUpgradeSafe if set as its Safe module.

  • Roles:
    • deputy: Optimism EOA 1 though restricted to the SuperchainConfig’s pause() function
Implementation used in:

The MIPS contract is used to execute the final step of the dispute game which objectively determines the winner of the dispute.

Implementation used in:
ProxyAdmin0xd560…1f79
  • Roles:
    • owner: SuperchainProxyAdminOwner
PermissionedDisputeGame0xe1dF…b87e

Same as FaultDisputeGame, but only two permissioned addresses are designated as proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. and challenger.

Implementation used in:
There are impactful changes to the following contracts, and part of the information might be outdated.

The dispute game factory allows the creation of dispute games, used to propose state rootsA cryptographic hash succinctly representing a state using a Merkle tree. and eventually challenge them. This variant exposes per-type reads only; the legacy array views (gameImpls[], initBonds[]) were removed in the new implementation.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

The OptimismPortal contract is the main entry point to deposit funds from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. It also allows to prove and finalize withdrawals. It specifies which game type can be used for withdrawals, which currently is the FaultDisputeGame.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

Contains configuration parameters such as the SequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. address, gas limitThe maximum amount of gas a transaction or block may consume. on this chain and the unsafe blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. signer address.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
    • batcherHash: EOA 1
    • owner: OpFoundationUpgradeSafe; ultimately SaferSafes
Implementation used in:

Used to manage global configuration values for multiple OP Chains within a single Superchain networkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes.. The SuperchainConfig contract manages individual pause states for each chain connected to it, as well as a global pause state for all chains. The guardian role can pause either separately, but each pause expires after 3 months if left untouched.

  • Roles:
    • admin: SuperchainProxyAdmin; ultimately SuperchainProxyAdminOwner
    • guardian: Optimism Guardian Multisig; ultimately OpFoundationUpgradeSafe, Optimism EOA 1, Optimism Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups., SaferSafes
Proxy used in:
Implementation used in:

Used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC-721 tokens from host chain to this chain.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

Sends messages from host chain to this chain, and relays messages back onto host chain. In the event that a message sent from host chain to this chain is rejected for exceeding this chain’s epoch gas limitThe maximum amount of gas a transaction or block may consume., it can be resubmitted via this contract’s replay function.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

Contract designed to hold the bonded ETH for each game. It is designed as a wrapper around WETH to allow an owner to function as a backstop if a game would incorrectly distribute funds.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

A helper contract that generates OptimismMintableERC20 contracts on the networkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. it’s deployed to. OptimismMintableERC20 is a standard extension of the base ERC20 token contract designed to allow the L1StandardBridge contracts to mint and burn tokens. This makes it possible to use an OptimismMintableERC20 as this chain’s representation of a token on the host chain, or vice-versa.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

A simple escrow contract storing ETH for the canonical bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge..

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
The following tokens are included in the value secured calculation:
ETH token logo
Implementation used in:

Contains the latest confirmed state rootA cryptographic hash succinctly representing a state using a Merkle tree. that can be used as a starting point in a dispute game. This variant stores respectedGameType, retirementTimestamp, and disputeGameFinalityDelaySeconds locally and drops the legacy *FromGame fields, since the AggregateVerifier model does not expose vm()/weth()/absolutePrestate() on its game implementation.

  • Roles:
    • admin: ProxyAdmin; ultimately SuperchainProxyAdminOwner
Implementation used in:

Ink

The L2CrossDomainMessenger (L2xDM) contract sends messages from L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., and relays messages from L1 onto L2 with a system tx. In the event that a message sent from L2 to L1 is rejected for exceeding the L1 gas limitThe maximum amount of gas a transaction or block may consume., it can be resubmitted via this contract’s replay function.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Provides the current gas pricePrice of one unit of gas specified in a transaction. The token used to pay for gas is usually Ether, but rollups can use other custom tokens. for L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. transactions.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

The L2StandardBridge contract is the main entry point to deposit or withdraw ERC20 tokens from L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. This contract can store any token.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Collects the sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. fees, which are withdrawable to the FeesCollector on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

A helper contract that generates OptimismMintableERC20 contracts on the networkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. it’s deployed to. OptimismMintableERC20 is a standard extension of the base ERC20 token contract designed to allow the L1StandardBridge contracts to mint and burn tokens. This makes it possible to use an OptimismMintableERC20 as this chain’s representation of a token on the host chain, or vice-versa.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Simple contract that returns the latest L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. number.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

The L2ERC721Bridge contract is the main entry point to deposit or withdraw ERC721 tokens from L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. This contract can store any token.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Simple contract that returns information about the latest L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over., which is derived permissionlessly from the L1 chain.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Contract used internally by the L2CrossDomainMessenger to send messages to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development., including withdrawals. It can also be used directly as a low-level interface.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Factory contract to create bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. compliant ERC721 IOU token representations of bridged L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. ERC721 tokens.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Administration contract for the L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. predeploy proxies. Adds upgradePredeploys(address), which can only be called by the system depositor account and delegatecalls an L2ContractsManager to upgrade every predeploy in a single networkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. upgrade transaction.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias
    • owner: SuperchainProxyAdminOwner_L2Alias

Collects EIP-1559 base fees, which are withdrawable to the FeesCollector on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Collects the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. portion of the L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. transaction fees, which are withdrawable to the FeesCollector on L1.

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Contracts to register schemas for the Ethereum Attestation Service (EAS).

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

Contract containing the main logic for the Ethereum Attestation Service (EAS).

  • Roles:
    • admin: L2ProxyAdmin; ultimately SuperchainProxyAdminOwner_L2Alias

The current deployment carries some associated risks:

  • Funds can be stolen if a contract receives a malicious code upgrade. Both regular and emergency upgrades must be approved by both the Security Council and the Foundation. There is no delay on regular upgrades.

Program Hashes

Name
Hash
Repository
Verification
Used in
0x0337...9025
OP Mainnet logoInk logo