# Jovay Markdown version of https://l2beat.com/layer2s/projects/jovay ## Summary **Warning:** This project is archived and no longer maintained. **Warning:** There are impactful changes and part of the information might be outdated. - Total Value Secured: $17.66 K (+0.32% compared to seven days ago; canonically bridged $17.66 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Gas token: ETH - Type: Other - Purposes: Universal, RWA - Host chain: Ethereum - Chain ID: 5734951 ### Risks - Sequencer failure: Enqueue via L1 (sentiment: warning) - State validation: TEE attestations (sentiment: bad) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Jovay, by Ant Digital Technologies, is an Ethereum Layer 2 blockchain built for real-world assets and users. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/jovay#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/jovay) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/jovay/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/jovay#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/jovay) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/jovay#onchain-costs). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/jovay#liveness). ## Risk summary **Warning:** 4 addresses have unverified source code (CRITICAL). - TEEVerifierProxyOwner: 0x79241BbE3646d8405849Cbe8608e77b82c402892 - 0x4815b8773E6686d0b6Ee16191Aef1ae6c50d6B77 - 0x83088c8Dd196a83f43140ddBD7B4727bD1d43AD4 - 0xf2A2Bee383C2e4d75d9aE5953b3A6cFABb661a47 ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. the source code of unverified contracts contains malicious code (CRITICAL). ### Users can be censored if 3. the operator is offline or refuses to process the queue. ### MEV can be extracted if 4. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Enqueue via L1 (sentiment: warning) Users can submit transactions to an L1 queue, but can't force them. The sequencers cannot selectively skip transactions but can stop processing the queue entirely. In other words, if the sequencers censor or are down, they are so for everyone. ### State validation TEE attestations (sentiment: bad) State roots are accepted when attested by a permissioned TEE through the TEEVerifierProxy. There is no challenge mechanism and no validity proofs can be submitted. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## Data availability ### All data required for proofs is published on chain All the data that is used to construct the system state is published on chain in the form of cheap blobs or calldata. This ensures that it will be available for enough time. **References** - [Rollup.sol - commitBatch stores calldata hashes for each batch](https://etherscan.io/address/0xe0a28B8918a62edB825055221a1dF12c7C81Bac1#code) - [L1Mailbox.sol - sendMsg enqueues transactions on Ethereum](https://etherscan.io/address/0x9869A90FDAc287519E48aff4cCE329907a995162#code) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/jovay#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. **References** - [Rollup.sol - addRelayer is restricted to the owner](https://etherscan.io/address/0xe0a28B8918a62edB825055221a1dF12c7C81Bac1#code) ### Users can enqueue transactions Users can submit transactions to an L1 queue, but can't force them. The sequencer cannot selectively skip transactions but can stop processing the queue entirely. In other words, if the sequencer censors or is down, it is so for everyone. **Risks** - Users can be censored if the operator is offline or refuses to process the queue. **References** - [L1Mailbox.sol - sendMsg enqueues deposit transactions](https://etherscan.io/address/0x9869A90FDAc287519E48aff4cCE329907a995162#code) - [Rollup.sol - commitBatch function passes the totalL1MessagePopped as input parameter](https://etherscan.io/address/0xe0a28B8918a62edB825055221a1dF12c7C81Bac1#code) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. **References** - [L1ETHBridge.sol - finalizeWithdraw executes ETH withdrawals](https://etherscan.io/address/0x922248Db4A99bB542539ae7165FB9D7A546FB9F1#code) - [L1Mailbox.sol - relayMsgWithProof verifies withdrawal proofs](https://etherscan.io/address/0x9869A90FDAc287519E48aff4cCE329907a995162#code) ## Permissions ### Ethereum #### Actors ##### Addresses: [0x4815b8773E6686d0b6Ee16191Aef1ae6c50d6B77](https://etherscan.io/address/0x4815b8773E6686d0b6Ee16191Aef1ae6c50d6B77) (unverified) * Can upgrade **with no delay** * L1ETHBridge [via: ProxyAdmin] * L1Mailbox [via: ProxyAdmin] * Rollup [via: ProxyAdmin] ##### Addresses: [0x83088c8Dd196a83f43140ddBD7B4727bD1d43AD4](https://etherscan.io/address/0x83088c8Dd196a83f43140ddBD7B4727bD1d43AD4) (unverified) * Can upgrade **with no delay** * ##### Addresses: [0xf2A2Bee383C2e4d75d9aE5953b3A6cFABb661a47](https://etherscan.io/address/0xf2A2Bee383C2e4d75d9aE5953b3A6cFABb661a47) (unverified) * Can upgrade **with no delay** * TEEVerifierProxyOwner ##### 2 EOAs Addresses: [0xA217ee134CB95B1ab56eF83a33956E5A979bf6e7](https://etherscan.io/address/0xA217ee134CB95B1ab56eF83a33956E5A979bf6e7) (EOA 1), [0xAe13Ce4Cd416cb4598865aa5aC8d13532bd3Cd99](https://etherscan.io/address/0xAe13Ce4Cd416cb4598865aa5aC8d13532bd3Cd99) (EOA 2) * Can interact with Rollup * Allowed to commit transactions from the current layer to the host chain * Allowed to post new state roots of the current layer to the host chain ## Smart contracts ### Ethereum #### L1Mailbox Addresses: [0x9869A90FDAc287519E48aff4cCE329907a995162](https://etherscan.io/address/0x9869A90FDAc287519E48aff4cCE329907a995162#code), [0x8327820B007Ee6dc6fF24A8798096C9961A0aB80](https://etherscan.io/address/0x8327820B007Ee6dc6fF24A8798096C9961A0aB80#code) (Implementation (Upgradable)), [0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b](https://etherscan.io/address/0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b#code) (Admin) The L1Mailbox contract is used to send messages to the L2. * Roles: * **admin**: ProxyAdmin Can be upgraded by: with no delay #### Rollup Addresses: [0xe0a28B8918a62edB825055221a1dF12c7C81Bac1](https://etherscan.io/address/0xe0a28B8918a62edB825055221a1dF12c7C81Bac1#code), [0xc8eEDE7229CcAd4a14f006845d05Fd51B28eE973](https://etherscan.io/address/0xc8eEDE7229CcAd4a14f006845d05Fd51B28eE973#code) (Implementation (Upgradable)), [0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b](https://etherscan.io/address/0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b#code) (Admin) The Rollup contract is used to submit and verify L2 batches. * Roles: * **admin**: ProxyAdmin * **relayer**: EOA 1, EOA 2 Can be upgraded by: with no delay #### L1ETHBridge Addresses: [0x922248Db4A99bB542539ae7165FB9D7A546FB9F1](https://etherscan.io/address/0x922248Db4A99bB542539ae7165FB9D7A546FB9F1#code), [0x376df788aFc6E801b24fC6C0fa6b53637A947ae7](https://etherscan.io/address/0x376df788aFc6E801b24fC6C0fa6b53637A947ae7#code) (Implementation (Upgradable)), [0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b](https://etherscan.io/address/0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b#code) (Admin) The L1ETHBridge contract is used to bridge ETH between the L1 and L2. * Roles: * **admin**: ProxyAdmin Can be upgraded by: with no delay #### DcapAttestationRouter Addresses: [0x238f4DaFC22013a864f85a54E276aC99975566fA](https://etherscan.io/address/0x238f4DaFC22013a864f85a54E276aC99975566fA#code) The DcapAttestationRouter contract is used for routing and verifying Intel SGX/TDX DCAP attestation proofs. The contract sends each quote to the corresponding verification path (cache verifier vs. Automata DCAP contract, and SGX vs. TDX measurement checks). #### MeasurementDao Addresses: [0x359437E2763e9622DD4324D7904BbF7516332D4F](https://etherscan.io/address/0x359437E2763e9622DD4324D7904BbF7516332D4F#code) The MeasurementDao contract is an onchain registry that allowlists SGX MR_ENCLAVE<->MR_SIGNER pairs and TDX RTMR3/MRTD values, and verifies DCAP quotes by matching quote fields to the stored measurements. #### TEEVerifierProxy Addresses: [0x371a8bda9a34d641B546883D6B5895d0A44AD46A](https://etherscan.io/address/0x371a8bda9a34d641B546883D6B5895d0A44AD46A#code) The TEEVerifierProxy contract is used to verify L2 batches using TEE attestations. It delegates proof verification to the dcapAttestationRouter contract. #### DaimoP256Verifier Addresses: [0x783377992FCA09009eaD952D4fBa6519e25726b4](https://etherscan.io/address/0x783377992FCA09009eaD952D4fBa6519e25726b4#code) #### TEEVerifierProxyOwner Addresses: [0x79241BbE3646d8405849Cbe8608e77b82c402892](https://etherscan.io/address/0x79241BbE3646d8405849Cbe8608e77b82c402892#code) (unverified), [0x621Dd8d71526D7Df51Fa1AA8D098f5eAEc81C573](https://etherscan.io/address/0x621Dd8d71526D7Df51Fa1AA8D098f5eAEc81C573#code) (Implementation (Upgradable), unverified), [0xf2A2Bee383C2e4d75d9aE5953b3A6cFABb661a47](https://etherscan.io/address/0xf2A2Bee383C2e4d75d9aE5953b3A6cFABb661a47#code) (Admin, unverified) * Roles: * **admin**: The source code of this contract is not verified on Etherscan. Can be upgraded by: with no delay #### TEECacheVerifier Addresses: [0x9734CcA9304A4c7a5a27bCFac9eDa23e09cBAaF2](https://etherscan.io/address/0x9734CcA9304A4c7a5a27bCFac9eDa23e09cBAaF2#code) A cache-enabled P-256 ECDSA verifier for Intel SGX/TDX DCAP quotes (v3/v4/v5) that authenticates local attestation data, extracts the 32-byte commitment, and lets the owner/authorized callers initialize, manage, and reuse cached attestation keys to skip repeat verifications. #### AutomataDcapAttestationFee Addresses: [0xb3a96165caf30F8F7cE9BCfdaaAe99BA93C1A6F9](https://etherscan.io/address/0xb3a96165caf30F8F7cE9BCfdaaAe99BA93C1A6F9#code) Contract used to charge a configurable basis-point fee to verify Intel DCAP quotes. Currently set to 0 basis points. #### ProxyAdmin Addresses: [0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b](https://etherscan.io/address/0xe2f33Bd70B301F53f61CB7b22D852bC8e3D95E2b#code) * Roles: * **owner**: The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL). - Funds can be stolen if the source code of unverified contracts contains malicious code (CRITICAL).