# Mantle Markdown version of https://l2beat.com/layer2s/projects/mantle ## Summary - Total Value Secured: $1.49 B (-2.03% compared to seven days ago; canonically bridged $789.69 M, natively minted $41.94 M, externally bridged $663.58 M; 44.3% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Past day UOPS: 0.23 (-4.50% compared to seven days ago) - Stage: Stage 0 - Gas token: MNT - Type: ZK Rollup - Purpose: Universal - Host chain: Ethereum - Chain ID: 5000 ### Risks - Sequencer failure: Self sequence (sentiment: good) - State validation: Validity proofs (ST, SN) (sentiment: good) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Mantle is a modular general-purpose Ethereum rollup. Transaction data is posted to Ethereum blobs and state transitions are validated onchain via OP Succinct ZK validity proofs (SP1). Its design philosophy aims to offer users a less costly and more user-friendly experience, provide developers with a simpler and more flexible development environment, and deliver a comprehensive set of infrastructure for the next wave of mass-adopted dApps. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/mantle) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/mantle/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/mantle) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#onchain-costs). ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#liveness). ## Milestones & Incidents - 2026-04-16: [Arsia upgrade: full Ethereum DA](https://etherscan.io/tx/0xa9f65671c6b80206db6f058626a8702cf9171dc5d5ab7e382bf124d2b0e1e55a). EigenDA code path removed; DA is Ethereum only. Mantle reclassified as a rollup. - 2025-09-16: [Upgrade to OP Succinct](https://x.com/Mantle_Official/status/1967936628678430965). Mantle upgrades to OP Succinct, integrating ZK proofs for state validation. - 2025-03-19: [Move to EigenDA](https://github.com/mantlenetworkio/mantle-v2/releases/tag/v1.1.1). Mantle deactivates MantleDA and data availability migrates to EigenDA. - 2024-03-15: [Mainnet v2 Tectonic Upgrade](https://www.mantle.xyz/blog/announcements/mantle-completes-mainnet-v2-tectonic-upgrade). Mantle completes Mainnet v2 Tectonic Upgrade. - 2023-07-14: [Mainnet Launch](https://www.mantle.xyz/blog/announcements/mantle-network-mainnet-alpha). Mantle is live on mainnet. - 2023-07-11: [MNT token migration begins](https://www.mantle.xyz/blog/announcements/bit-to-mnt-user-guide). Users can exchange their BIT tokens to MNT tokens. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. in non-optimistic mode, the validity proof cryptography is broken or implemented incorrectly, 3. optimistic mode is enabled and no challenger checks the published state, 4. the proposer routes proof verification through a malicious or faulty verifier by specifying an unsafe route id. ### Funds can be frozen if 5. the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production, (CRITICAL) 6. the permissioned proposer fails to publish state roots to the L1, 7. in non-optimistic mode, the SP1VerifierGateway is unable to route proof verification to a valid verifier. ### MEV can be extracted if 8. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Self sequence (sentiment: good) In the event of a sequencer failure, users can force transactions to be included in the project's chain by sending them to L1. There can be up to a 12h delay on this operation. ### State validation Validity proofs (ST, SN) (sentiment: good) STARKs and SNARKs are zero knowledge proofs that ensure state correctness. STARKs proofs are wrapped in SNARKs proofs for efficiency. SNARKs require a trusted setup. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## Stage Mantle is a Stage 0 ZK Rollup. ### Stage 0 - [x] A complete and functional proof system is deployed. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [x] A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/succinctlabs/op-succinct/) ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [ ] Users' withdrawals can be censored by the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. - [x] Prover source code is published. - [x] The sources of all programs used are public and program hashes can be independently regenerated. ### Stage 2 - [ ] Upgrades unrelated to onchain provable bugs provide less than 30d to exit. - [ ] The Security Council's actions are not confined to onchain provable bugs. ## Data availability ### All data required for proofs is published on chain All the data that is used to construct the system state is published on chain in the form of cheap blobs or calldata. This ensures that it will be available for enough time. **References** - [Derivation: Batch submission - OP Mainnet specs](https://github.com/ethereum-optimism/specs/blob/main/specs/protocol/derivation.md#batch-submission) - [BatchInbox - address](https://etherscan.io/address/0xFFEEDDCcBbAA0000000000000000000000000000#code) - [OptimismPortal.sol - source code, depositTransaction function](https://etherscan.io/address/0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7#code) ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. Through the SuccinctL2OutputOracle, the system also allows to switch to an optimistic mode, in which no proofs are required and a challenger can challenge the proposed output state root within the finalization period. **Risks** - Funds can be stolen if in non-optimistic mode, the validity proof cryptography is broken or implemented incorrectly. - Funds can be stolen if optimistic mode is enabled and no challenger checks the published state. - Funds can be stolen if the proposer routes proof verification through a malicious or faulty verifier by specifying an unsafe route id. - Funds can be frozen if the permissioned proposer fails to publish state roots to the L1. - Funds can be frozen if in non-optimistic mode, the SP1VerifierGateway is unable to route proof verification to a valid verifier. **References** - [Op-Succinct architecture](https://succinctlabs.github.io/op-succinct/architecture.html) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/mantle#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can force any transaction Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly. **References** - [Sequencing Window - OP Mainnet Specs](https://github.com/ethereum-optimism/optimism/blob/51eeb76efeb32b3df3e978f311188aa29f5e3e94/specs/glossary.md#sequencing-window) - [OptimismPortal.sol - source code, depositTransaction function](https://etherscan.io/address/0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7#code) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks. **Risks** - Funds can be frozen if the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL). **References** - [OptimismPortal.sol - source code, proveWithdrawalTransaction function](https://etherscan.io/address/0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7#code) - [OptimismPortal.sol - source code, finalizeWithdrawalTransaction function](https://etherscan.io/address/0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7#code) ### Forced messaging If the user experiences censorship from the operator with regular L2->L1 messaging they can submit their messages directly on L1. The system is then obliged to service this request or halt all messages, including forced withdrawals from L1 and regular messages initiated on L2. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular message. **References** - [Forced withdrawal from an OP Stack blockchain](https://docs.optimism.io/stack/transactions/forced-transaction) ## Other considerations ### EVM compatible smart contracts are supported OP stack chains are pursuing the EVM Equivalence model. No changes to smart contracts are required regardless of the language they are written in, i.e. anything deployed on L1 can be deployed on L2. **References** - [Introducing EVM Equivalence](https://medium.com/ethereum-optimism/introducing-evm-equivalence-5c2021deb306) ## Permissions ### Ethereum #### Actors ##### MantleSecurityMultisig Addresses: [0x4e59e778a0fb77fBb305637435C62FaeD9aED40f](https://etherscan.io/address/0x4e59e778a0fb77fBb305637435C62FaeD9aED40f) A Multisig with 6/14 threshold. * Can upgrade **with no delay** * OPSuccinctL2OutputOracle [via: ProxyAdmin] * SystemConfig [via: ProxyAdmin] * L1CrossDomainMessenger [via: ProxyAdmin] * L1StandardBridge [via: ProxyAdmin] * OptimismPortal [via: ProxyAdmin] * Can upgrade **with 1d delay** * L1MantleToken [via: TimelockController with 1d delay → MantleTokenProxyAdmin] * Can interact with OPSuccinctL2OutputOracle * can toggle between the optimistic mode and not optimistic (ZK) mode, update the SP1 verification keys, the verifier address, the rollup config hash, the submission interval and manage the approved proposer set * Can interact with L1MantleToken * can mint new MNT (up to 2% of supply per year as set by mintCapNumerator) and transfer token ownership * Can interact with SystemConfig * it can update the batch submitter (Sequencer) address, the unsafe block signer, the L2 gas limit (bounded by `maximumGasLimit()`), the resource metering config, and all fee/gas parameters: legacy `setGasConfig(overhead, scalar)`, Arsia `setGasConfigArsia(basefeeScalar, blobbasefeeScalar)`, `setBaseFee`, `setEIP1559Params`, `setMinBaseFee`, `setDAFootprintGasScalar` and `setOperatorFeeScalars` * Can interact with TimelockController * cancel queued transactions * execute transactions that are ready * manage all access control roles **with 1d delay or with no delay** [via: TimelockController with 1d delay - or - acting directly] * propose transactions * Can interact with AddressManager * set and change address mappings [via: ProxyAdmin] ##### MantleEngineeringMultisig Addresses: [0x2F44BD2a54aC3fB20cd7783cF94334069641daC9](https://etherscan.io/address/0x2F44BD2a54aC3fB20cd7783cF94334069641daC9) A Multisig with 3/7 threshold. * Can interact with OPSuccinctL2OutputOracle * can delete proposed state roots, enable/disable the optimistic (proof-less) mode and change the finalization period * Can interact with OptimismPortal * Allowed to pause withdrawals. In op stack systems with a proof system, the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionless) ##### SP1VerifierGatewayMultisig Addresses: [0xCafEf00d348Adbd57c37d1B77e0619C6244C6878](https://etherscan.io/address/0xCafEf00d348Adbd57c37d1B77e0619C6244C6878) A Multisig with 2/3 threshold. * Can interact with SP1VerifierGateway * affect the liveness and safety of the gateway - can transfer ownership, add and freeze verifier routes ##### EOA 1 Addresses: [0x2f40D796917ffB642bD2e2bdD2C762A5e40fd749](https://etherscan.io/address/0x2f40D796917ffB642bD2e2bdD2C762A5e40fd749) * Can interact with SystemConfig * Allowed to commit transactions from the current layer to the host chain ##### EOA 2 Addresses: [0x6667961f5e9C98A76a48767522150889703Ed77D](https://etherscan.io/address/0x6667961f5e9C98A76a48767522150889703Ed77D) * Can interact with OPSuccinctL2OutputOracle * Allowed to post new state roots of the current layer to the host chain ## Smart contracts ### Ethereum #### SystemConfig Addresses: [0x427Ea0710FA5252057F0D88274f7aeb308386cAf](https://etherscan.io/address/0x427Ea0710FA5252057F0D88274f7aeb308386cAf#code), [0x9CA047689261E35c9e507b1BB0B7443C2A436310](https://etherscan.io/address/0x9CA047689261E35c9e507b1BB0B7443C2A436310#code) (Implementation (Upgradable)), [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) (Admin) Contains configuration parameters such as the batch submitter (Sequencer) address, the L2 gas limit, the unsafe block signer address and the Arsia fee/gas mechanics (base/blob scalars, EIP-1559 params, minimum base fee, DA footprint gas scalar and EIP-7706-style operator fee). * Roles: * **admin**: ProxyAdmin; ultimately MantleSecurityMultisig * **batcherHash**: EOA 1 * **owner**: MantleSecurityMultisig Can be upgraded by: MantleSecurityMultisig with no delay #### OptimismPortal Addresses: [0xc54cb22944F2bE476E02dECfCD7e3E7d3e15A8Fb](https://etherscan.io/address/0xc54cb22944F2bE476E02dECfCD7e3E7d3e15A8Fb#code), [0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7](https://etherscan.io/address/0xe1399f54ba2597b4EaDA9E3450c34D393fb131A7#code) (Implementation (Upgradable)), [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) (Admin) The main entry point to deposit funds from host chain to this chain. It also allows to prove and finalize withdrawals. * Roles: * **admin**: ProxyAdmin; ultimately MantleSecurityMultisig * **guardian**: MantleEngineeringMultisig Can be upgraded by: MantleSecurityMultisig with no delay #### L1CrossDomainMessenger Addresses: [0x676A795fe6E43C17c668de16730c3F690FEB7120](https://etherscan.io/address/0x676A795fe6E43C17c668de16730c3F690FEB7120#code), [0xb8DE82551fA4BA3bE4B3d9097763EDBeED541308](https://etherscan.io/address/0xb8DE82551fA4BA3bE4B3d9097763EDBeED541308#code) (Implementation (Upgradable)), [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) (Admin) Sends messages from host chain to this chain, and relays messages back onto host chain. In the event that a message sent from host chain to this chain is rejected for exceeding this chain's epoch gas limit, it can be resubmitted via this contract's replay function. * Roles: * **admin**: ProxyAdmin; ultimately MantleSecurityMultisig Can be upgraded by: MantleSecurityMultisig with no delay #### L1StandardBridge Addresses: [0x95fC37A27a2f68e3A647CDc081F0A89bb47c3012](https://etherscan.io/address/0x95fC37A27a2f68e3A647CDc081F0A89bb47c3012#code), [0xb4133552BA49dFb60DA6eb5cA0102d0f94ce071f](https://etherscan.io/address/0xb4133552BA49dFb60DA6eb5cA0102d0f94ce071f#code) (Implementation (Upgradable)), [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) (Admin) The main entry point to deposit ERC20 tokens from host chain to this chain. * Roles: * **admin**: ProxyAdmin; ultimately MantleSecurityMultisig Can be upgraded by: MantleSecurityMultisig with no delay #### MantleTokenProxyAdmin Addresses: [0x0cac2B1a172ac24012621101634DD5ABD6399ADd](https://etherscan.io/address/0x0cac2B1a172ac24012621101634DD5ABD6399ADd#code) * Roles: * **owner**: TimelockController #### OPSuccinctL2OutputOracle Addresses: [0x31d543e7BE1dA6eFDc2206Ef7822879045B9f481](https://etherscan.io/address/0x31d543e7BE1dA6eFDc2206Ef7822879045B9f481#code), [0x4059509fFb703B048D1e9Ce3118F90E759076f50](https://etherscan.io/address/0x4059509fFb703B048D1e9Ce3118F90E759076f50#code) (Implementation (Upgradable)), [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) (Admin) Contains a list of proposed state roots which Proposers assert to be a result of block execution. The SuccinctL2OutputOracle modifies the L2OutputOracle to support whenNotOptimistic mode, in which a validity proof can be passed as input argument to the proposeL2Output function. * Roles: * **admin**: ProxyAdmin; ultimately MantleSecurityMultisig * **challenger**: MantleEngineeringMultisig * **initialProposer**: EOA 2 * **owner**: MantleSecurityMultisig Can be upgraded by: MantleSecurityMultisig with no delay #### L1MantleToken Addresses: [0x3c3a81e81dc49A522A592e7622A7E711c06bf354](https://etherscan.io/address/0x3c3a81e81dc49A522A592e7622A7E711c06bf354#code), [0xCd368c1d80120b0Dd92447c87eB570154f8e685c](https://etherscan.io/address/0xCd368c1d80120b0Dd92447c87eB570154f8e685c#code) (Implementation (Upgradable)), [0x0cac2B1a172ac24012621101634DD5ABD6399ADd](https://etherscan.io/address/0x0cac2B1a172ac24012621101634DD5ABD6399ADd#code) (Admin) MNT token contract: Mantle uses Mantle (MNT) as the designated gas token, allowing users pay for gas in MNT. * Roles: * **admin**: MantleTokenProxyAdmin; ultimately MantleSecurityMultisig * **owner**: MantleSecurityMultisig Can be upgraded by: MantleSecurityMultisig with 1d delay #### TimelockController Addresses: [0x65331ff6F8B0fc2612F2a0deBD9d04Fce60a447F](https://etherscan.io/address/0x65331ff6F8B0fc2612F2a0deBD9d04Fce60a447F#code) A timelock with access control. The current minimum delay is 1d. * Roles: * **canceller**: MantleSecurityMultisig * **defaultAdmin**: MantleSecurityMultisig, TimelockController; ultimately MantleSecurityMultisig * **executor**: MantleSecurityMultisig * **proposer**: MantleSecurityMultisig #### ProxyAdmin Addresses: [0xca35F8338054739D138884685e08b39EE2217794](https://etherscan.io/address/0xca35F8338054739D138884685e08b39EE2217794#code) * Roles: * **owner**: MantleSecurityMultisig #### SP1Verifier Addresses: [0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459](https://etherscan.io/address/0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459#code) Verifier contract for SP1 proofs (v5.0.0). #### SP1VerifierGateway Addresses: [0x3B6041173B80E77f038f3F2C0f9744f04837185e](https://etherscan.io/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e#code) This contract is the router for zk proof verification. It stores the mapping between identifiers and the address of onchain verifier contracts, routing each identifier to the corresponding verifier contract. * Roles: * **owner**: SP1VerifierGatewayMultisig #### SP1Verifier Addresses: [0x8a0fd5e825D14368d90Fe68F31fceAe3E17AFc5C](https://etherscan.io/address/0x8a0fd5e825D14368d90Fe68F31fceAe3E17AFc5C#code) Verifier contract for SP1 proofs (v6.0.0). #### SP1Verifier Addresses: [0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A](https://etherscan.io/address/0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A#code) Verifier contract for SP1 proofs (v6.1.0). The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).