# MegaETH Markdown version of https://l2beat.com/layer2s/projects/megaeth ## Summary **Warning:** There are impactful changes and part of the information might be outdated. - Total Value Secured: $84.36 M (-3.06% compared to seven days ago; canonically bridged $10.08 M, natively minted $48.52 M, externally bridged $25.76 M; 30.5% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Past day UOPS: 24.28 (+0.87% compared to seven days ago) - Gas token: ETH - Type: Other - Purpose: Universal - Host chain: Ethereum - Chain ID: 4326 ### Risks - Sequencer failure: Self sequence (sentiment: good) - State validation: Fraud proofs (1R, ZK) (sentiment: bad) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About MegaETH is a real-time blockchain based on the OP Stack architecture and the hybrid Kailua proof system, targeting sub-millisecond latency and over 100,000 transactions per second. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/megaeth) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/megaeth/breakdown) ## Volume and flows Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#interop-flows). ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/megaeth) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#onchain-costs). ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#liveness). ## Risk summary **Warning:** The project relies on program hashes that could not be successfully reproduced from their published sources (CRITICAL). ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. the validity proof cryptography is broken or implemented incorrectly, 3. no challenger checks the published state, 4. the proposer routes proof verification through a malicious or faulty verifier by specifying an unsafe route selector. ### Funds can be lost if 5. the sequencer posts an unavailable transaction root, (CRITICAL) 6. the data is not available on the external provider (CRITICAL). ### Funds can be frozen if 7. the vanguard exploits their vanguard advantage (36558901084y 8mo), halting the chain until they propose, 8. a verifier needed for a given proof is paused by its permissioned owner. ### MEV can be extracted if 9. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Self sequence (sentiment: good) In the event of a sequencer failure, users can force transactions to be included in the project's chain by sending them to L1. There can be up to a 12h delay on this operation. ### State validation Fraud proofs (1R, ZK) (sentiment: bad) Fraud proofs allow actors watching the chain to prove that the state is incorrect. Single round proofs (1R) prove the validity of a state proposal, only requiring a single transaction to resolve. A fault proof eliminates a state proposal by proving that any intermediate state transition in the proposal results in a different state root. For either, a ZK proof is used. Since the node source is not available, challengers cannot watch the chain independently. `vanguardAdvantage` applies to every proposal and is set to 36558901084y 8mo, so only the Vanguard can submit state proposals; faulty proposals can be flagged but not replaced, halting the chain until the Vanguard proposes a correct state root. ### Data availability External (sentiment: bad) Proof construction and state derivation fully rely on data that is posted on EigenDA. The sequencer is publishing data to EigenDA v2. Sequencer transaction data roots are not checked against the DACert Verifier onchain. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## Stage MegaETH is not even a Stage 0 project. **Warning:** The requirement for available node software is under review. ### Stage 0 - [x] The project self-identifies as a Validium or Optimium. - [x] State roots are posted to Ethereum L1. - [x] A complete and functional proof system (fraud or validity proofs) is deployed. - [ ] (under review) A source-available node exists that can reconstruct the L2 state when DA is accessible. Please note that the L2BEAT team has not verified the validity of the node source code. - [x] There are at least 5 external actors who can submit fraud proofs. ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council to push a malicious upgrade, or sequencer+DA-committee collusion to withhold data and finalize invalid state roots, should be the only ways (other than bugs) to steal funds or block withdrawals indefinitely. - [x] Users are able to exit without the help of the permissioned operators, provided DA is accessible. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. - [x] The proof system meets the minimum trusted setup requirements defined in the L2BEAT [trusted setup assessment framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). - [ ] Not all program sources are public or not all program hashes can be independently regenerated. ### Stage 2 - [x] Fraud proof submission is open to everyone. - [ ] Upgrades unrelated to onchain provable bugs, including upgrades to the DA verifier, provide less than 30d to exit. - [ ] The Security Council's actions are not confined to onchain provable bugs. ## Data availability ### Data is posted to EigenDA Transactions roots are posted onchain and the full data is posted on EigenDA. The sequencer is publishing data to EigenDA v2. Since the DACert Verifier is not used, availability of the data is not verified against EigenDA operators, meaning that the Sequencer can single-handedly publish unavailable commitments. If EigenDA becomes unavailable, the sequencer falls back to Ethereum. **Risks** - Funds can be lost if the sequencer posts an unavailable transaction root (CRITICAL). - Funds can be lost if the data is not available on the external provider (CRITICAL). **References** - [EigenDA Docs - Overview](https://docs.eigenda.xyz/overview) - [Derivation: Batch submission - OP Mainnet specs](https://github.com/ethereum-optimism/specs/blob/main/specs/protocol/derivation.md#batch-submission) - [BatchInbox - address](https://etherscan.io/address/0x00656C604FC470e6a566A695B74455e18a6D75D3#code) - [OptimismPortal2.sol - source code, depositTransaction function](https://etherscan.io/address/0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9#code) ## State validation ### State root proposals Proposers submit state roots as children of any (possibly unresolved) previous state root proposal, by calling the `propose()` function in the KailuaTreasury. A parent state root can have multiple conflicting children, composing a tournament. Each proposer requires to lock a bond, currently set to 0.00001 ETH, that can be slashed if any proposal made by them is proven incorrect via a fault proof or a conflicting validity proof. The bond can be withdrawn once the proposer has no more pending proposals that need to be resolved and was not eliminated. Proposals consist of a state root and a reference to their parent and implicitly challenge any sibling proposals who have the same parent. A proposal asserts that the proposed state root constitutes a valid state transition from the parent's state root. To offer efficient zk fault proofs, each proposal must include 3600 intermediate state commitments, each spanning 1 L2 blocks. Proposals target sequential tournament epochs of currently 3600 * 1 L2 blocks. A tournament with a resolved parent tournament, a single child- and no conflicting sibling proposals can be resolved after 7d. The **Vanguard** is the only address that can submit any proposal (first child or conflicting sibling) on a parent state root during the `vanguardAdvantage` window of 36558901084y 8mo. Faulty Vanguard proposals can be flagged via ZK fault proofs (`proveOutputFault`) but cannot be replaced by an honest sibling, so the chain stalls at that tournament until the Vanguard submits a correct state root. **Risks** - Funds can be frozen if the vanguard exploits their vanguard advantage (36558901084y 8mo), halting the chain until they propose. **References** - [Sequencing - Kailua Docs](https://boundless-xyz.github.io/kailua/design.html#sequencing) - [Vanguard - Kailua Docs](https://boundless-xyz.github.io/kailua/parameters.html#vanguard-advantage) ### Challenges Any actor can submit a ZK fault proof against an existing child proposal via `proveOutputFault` to mark it faulty during the 7d challenge period; this blocks the wrong proposal from resolving but does not, by itself, advance the chain. Conflicting sibling proposals (which would survive the tournament and resolve in place of a faulty proposal) can only be submitted by the Vanguard during the `vanguardAdvantage` window. In the tree of proposed state roots, each parent node can have multiple children. These children are indirectly challenging each other in a tournament, which can only be resolved if but a single child survives. A state root can be resolved if it is **the only remaining proposal** due to any combination of the following elimination methods: 1. the proposal's challenge period of 7d has ended before a conflicting proposal was made 2. the proposal is proven correct with a full validity proof (invalidates all conflicting proposals) 3. a conflicting sibling proposal is proven faulty Proving any of the 3600 intermediate state commitments in a proposal faulty invalidates the entire proposal. Proving a proposal valid invalidates all conflicting siblings. Pruning of a tournament's children happens strictly chronologically, which guarantees that the first faulty proposal of a given proposer is always pruned first. When pruned, an invalid proposal leads to the elimination of its proposer, which invalidates all their subsequent proposals, slashes their bond, and disallows future proposals by the same address. A slashed bond is transferred to an address chosen by the prover who caused the slashing. A single remaining child in a tournament can be 'resolved' and will be finalized and usable for withdrawals after an execution delay of 3d 12h (time for the Guardian to manually blacklist malicious state roots). **References** - [How to run a challenger - Boundless Docs](https://boundless-xyz.github.io/kailua/operate.html) - [Disputes - Kailua Book](https://boundless-xyz.github.io/kailua/dispute.html) ### Validity proofs Validity proofs and fault proofs both must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. The Kailua state validation system is primarily optimistically resolved, so no validity proofs are required in the happy case. But two different zk proofs on unresolved state roots are possible and permissionless: The proveValidity() function proves a state root proposal's full validity, automatically invalidating all conflicting sibling proposals. proveOutputFault() allows any actor to eliminate a state root proposal for which they can prove that any of the 3600 intermediate state transitions in the proposal are not correct. Both are zk proofs of validity, although one is used as an efficient fault proof to invalidate a single conflicting state transition. **Risks** - Funds can be stolen if the validity proof cryptography is broken or implemented incorrectly. - Funds can be stolen if no challenger checks the published state. - Funds can be stolen if the proposer routes proof verification through a malicious or faulty verifier by specifying an unsafe route selector. - Funds can be frozen if a verifier needed for a given proof is paused by its permissioned owner. **References** - [Kailua Proof System - Boundless Docs](https://boundless-xyz.github.io/kailua/introduction.html) - [Verifier upgrade and deprecation - Kailua Docs](https://github.com/risc0/risc0-ethereum/blob/main/contracts/version-management-design.md) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/megaeth#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can force any transaction Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly. **References** - [Sequencing Window - OP Mainnet Specs](https://github.com/ethereum-optimism/optimism/blob/51eeb76efeb32b3df3e978f311188aa29f5e3e94/specs/glossary.md#sequencing-window) - [OptimismPortal2.sol - source code, depositTransaction function](https://etherscan.io/address/0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9#code) ## Withdrawals ### Regular exits The user initiates the withdrawal by submitting a regular transaction on this chain. When a state root containing such transaction is settled, the funds become available for withdrawal on L1 after 3d 12h. Withdrawal inclusion can be proven before state root settlement, but a 7d period has to pass before it becomes actionable. The process of state root settlement takes a challenge period of at least 7d to complete. Finally the user submits an L1 transaction to claim the funds. This transaction requires a merkle proof. **References** - [OptimismPortal2.sol - Etherscan source code, proveWithdrawalTransaction function](https://etherscan.io/address/0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9#code) - [OptimismPortal2.sol - Etherscan source code, finalizeWithdrawalTransaction function](https://etherscan.io/address/0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9#code) ### Forced messaging If the user experiences censorship from the operator with regular L2->L1 messaging they can submit their messages directly on L1. The system is then obliged to service this request or halt all messages, including forced withdrawals from L1 and regular messages initiated on L2. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular message. **References** - [Forced withdrawal from an OP Stack blockchain](https://docs.optimism.io/stack/transactions/forced-transaction) ## Other considerations ### EVM compatible smart contracts are supported OP stack chains are pursuing the EVM Equivalence model. No changes to smart contracts are required regardless of the language they are written in, i.e. anything deployed on L1 can be deployed on L2. **References** - [Introducing EVM Equivalence](https://medium.com/ethereum-optimism/introducing-evm-equivalence-5c2021deb306) ## Permissions ### Ethereum #### Actors ##### EigenLayerOperationsMultisig Addresses: [0xBE1685C81aA44FF9FB319dD389addd9374383e90](https://etherscan.io/address/0xBE1685C81aA44FF9FB319dD389addd9374383e90) A Multisig with 3/6 threshold. * Can upgrade **with 10d delay** * AVSDirectory [via: TimelockControllerOwning with 10d delay → EigenLayerOwningMultisig → EigenLayerProxyAdmin] * DelegationManager [via: TimelockControllerOwning with 10d delay → EigenLayerOwningMultisig → EigenLayerProxyAdmin] * Can interact with EigenDAServiceManager * can pause the DA bridge **with no delay or with 10d delay** [via: PauserRegistry - or TimelockControllerOwning with 10d delay → EigenLayerOwningMultisig → PauserRegistry] ##### EigenDAOperationsMultisig Addresses: [0x002721B4790d97dC140a049936aA710152Ba92D5](https://etherscan.io/address/0x002721B4790d97dC140a049936aA710152Ba92D5) A Multisig with 2/4 threshold. * Can upgrade **with no delay** * StakeRegistry [via: ProxyAdmin] * BLSApkRegistry [via: ProxyAdmin] * RegistryCoordinator [via: ProxyAdmin] * EjectionManager [via: ProxyAdmin] * SocketRegistry [via: ProxyAdmin] * EigenDADisperserRegistry [via: ProxyAdmin] * EigenDAServiceManager [via: ProxyAdmin] * PaymentVault [via: ProxyAdmin] * IndexRegistry [via: ProxyAdmin] * EigenDARelayRegistry [via: ProxyAdmin] * EigenDAThresholdRegistry [via: ProxyAdmin] * Can interact with RegistryCoordinator * can add and remove strategies * Can interact with EigenDAServiceManager * can transfer ownership of the contract, update the metadata URI, set reward initiator and set batch confirmer ##### Safe Addresses: [0x92e0E0B15e3e99b32c9ED9AD284F939553C7b7d6](https://etherscan.io/address/0x92e0E0B15e3e99b32c9ED9AD284F939553C7b7d6) A Multisig with 6/10 threshold. * Can upgrade **with no delay** * BunnyInbox * L1StandardBridge [via: ProxyAdmin] * SystemConfig [via: ProxyAdmin] * L1ERC721Bridge [via: ProxyAdmin] * SuperchainConfig [via: ProxyAdmin] * L1CrossDomainMessenger [via: ProxyAdmin] * OptimismPortal2 [via: ProxyAdmin] * DisputeGameFactory [via: ProxyAdmin] * DelayedWETH [via: ProxyAdmin] * AnchorStateRegistry [via: ProxyAdmin] * OptimismMintableERC20Factory [via: ProxyAdmin] * Can interact with SystemConfig * it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system * Can interact with DelayedWETH * can pull funds from the contract in case of emergency * Can interact with AddressManager * set and change address mappings [via: ProxyAdmin] ##### EigenLayerRewardsInitiatorMultisig Addresses: [0x178eeeA9E0928dA2153A1d7951FBe30CF8371b8A](https://etherscan.io/address/0x178eeeA9E0928dA2153A1d7951FBe30CF8371b8A) A Multisig with 3/4 threshold. * Can interact with EigenDAServiceManager * can create rewards submissions ##### EigenDA Multisig Addresses: [0x338477FfaF63c04AC06048787f910671eC914B34](https://etherscan.io/address/0x338477FfaF63c04AC06048787f910671eC914B34) A Multisig with 3/8 threshold. * Can interact with EjectionManager * can eject DA operators from a quorum ##### Safe Addresses: [0xe8344867AB6387e17b7cAE2dE52C63BCf501BD98](https://etherscan.io/address/0xe8344867AB6387e17b7cAE2dE52C63BCf501BD98) A Multisig with 4/6 threshold. * Can interact with MegaPreDepositVaultRefund * manage all access control roles * service (execute) refunds from this contract ##### Safe Addresses: [0x63eCafD27E0B86B37903c8aA64beD47244Ad909A](https://etherscan.io/address/0x63eCafD27E0B86B37903c8aA64beD47244Ad909A) A Multisig with 1/5 threshold. Member of Safe. ##### Safe Addresses: [0xB2A9EB0c7b729c3EC704e843eF260084B3caE67F](https://etherscan.io/address/0xB2A9EB0c7b729c3EC704e843eF260084B3caE67F) A Multisig with 1/1 threshold. ##### Megaeth Multisig Addresses: [0xCB264DEf50D166d4aE7cF60188eC0038819fb719](https://etherscan.io/address/0xCB264DEf50D166d4aE7cF60188eC0038819fb719) A Multisig with 4/6 threshold. ##### EigenLayerOwningMultisig Addresses: [0x369e6F597e22EaB55fFb173C6d9cD234BD699111](https://etherscan.io/address/0x369e6F597e22EaB55fFb173C6d9cD234BD699111) A Multisig with 1/2 threshold. ##### EigenLayerPauserMultisig Addresses: [0x5050389572f2d220ad927CcbeA0D406831012390](https://etherscan.io/address/0x5050389572f2d220ad927CcbeA0D406831012390) A Multisig with 1/7 threshold. ##### EOA 1 Addresses: [0xB98c6b1A805b96707A43e1F1ACFa163B68098FA6](https://etherscan.io/address/0xB98c6b1A805b96707A43e1F1ACFa163B68098FA6) * Can interact with SystemConfig * Allowed to commit transactions from the current layer to the host chain ##### 3 EOAs Addresses: [0x454Ef2f69f91527856E06659f92a66f464C1ca4e](https://etherscan.io/address/0x454Ef2f69f91527856E06659f92a66f464C1ca4e) (EOA 2), [0x5A49Bf6c5690E22dFff3eB37F7dd18254eC361ED](https://etherscan.io/address/0x5A49Bf6c5690E22dFff3eB37F7dd18254eC361ED) (EOA 3), [0x8ED83c6Bb12E441Ca2C3a544F525d4a3Fb6484D8](https://etherscan.io/address/0x8ED83c6Bb12E441Ca2C3a544F525d4a3Fb6484D8) (EOA 5) * Can interact with EigenDAServiceManager * can confirm batches to the DA bridge ##### 2 EOAs Addresses: [0x8642473a123FE33b0aaE90bD8604eA1029417236](https://etherscan.io/address/0x8642473a123FE33b0aaE90bD8604eA1029417236) (EOA 4), [0xD2Ee81Cf07B12140C793FcE5B26313CDd9d78eA8](https://etherscan.io/address/0xD2Ee81Cf07B12140C793FcE5B26313CDd9d78eA8) (EOA 6) * Can interact with EjectionManager * can eject DA operators from a quorum ##### EOA 7 Addresses: [0xe0550117Cb066D3b330eBd764B0d75D3BA378734](https://etherscan.io/address/0xe0550117Cb066D3b330eBd764B0d75D3BA378734) * Can interact with RegistryCoordinator * can approve the replacement of churned operators from a quorum ##### EOA 8 Addresses: [0xe8437B66E834B7CdC90cC5D98B8DD6e636b37D7a](https://etherscan.io/address/0xe8437B66E834B7CdC90cC5D98B8DD6e636b37D7a) * Can interact with EigenDARelayRegistry * Can store and serve both unencoded blobs as well as encoded chunks ##### EOA 9 Addresses: [0xF3d7C0D52fF8f4CF74A3CD9C53778516f4235bE9](https://etherscan.io/address/0xF3d7C0D52fF8f4CF74A3CD9C53778516f4235bE9) * Can interact with EigenDADisperserRegistry * Can disperse EigenDA blobs to the EigenDA node operators ##### EOA 10 Addresses: [0x0A383fF8387CF07315f476D1686E95b1a97adc97](https://etherscan.io/address/0x0A383fF8387CF07315f476D1686E95b1a97adc97) Member of Safe, Safe, Megaeth Multisig, Safe. * Can interact with SuperchainConfig * Allowed to pause withdrawals. In op stack systems with a proof system, the Guardian can also blacklist dispute games and set the respected game type (permissioned / permissionless) [via: Safe] * Can interact with RiscZeroVerifierRouter * add/remove verifiers and the selectors they are mapped to ## Smart contracts ### Ethereum #### KailuaTreasury Addresses: [0x01853F268B170D4A15D0c3AE905757b5Ec8375f3](https://etherscan.io/address/0x01853F268B170D4A15D0c3AE905757b5Ec8375f3#code) Entrypoint for state root proposals. Manages bonds (currently 0.00001 ETH) and tournaments for the OP Kailua state validation system, wrapping the OP stack native DisputeGameFactory. #### BunnyInbox Addresses: [0x02B8d1329B653d6f53A8420C8DDbBbb5518F51b2](https://etherscan.io/address/0x02B8d1329B653d6f53A8420C8DDbBbb5518F51b2#code), [0x59888ea06a54bdC7d495c24513ed5b7A58ed7804](https://etherscan.io/address/0x59888ea06a54bdC7d495c24513ed5b7A58ed7804#code) (Implementation (Upgradable)), [0x92e0E0B15e3e99b32c9ED9AD284F939553C7b7d6](https://etherscan.io/address/0x92e0E0B15e3e99b32c9ED9AD284F939553C7b7d6#code) (Admin) Onchain EigenDA certificate verification inbox. Receives batch data, strips 4-byte prefix, RLP-decodes EigenDACertV3 and calls the EigenDACertVerifier to validate the certificate. Used as the batch inbox for EigenDA-based data availability. * Roles: * **admin**: Safe Can be upgraded by: Safe with no delay #### SystemConfig Addresses: [0x1ED92E1bc9A2735216540EDdD0191144681cb77E](https://etherscan.io/address/0x1ED92E1bc9A2735216540EDdD0191144681cb77E#code), [0x7f84fEb1cEb9C91844ee80C63d153d9128Fb40e9](https://etherscan.io/address/0x7f84fEb1cEb9C91844ee80C63d153d9128Fb40e9#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) Contains configuration parameters such as the Sequencer address, gas limit on this chain and the unsafe block signer address. * Roles: * **admin**: ProxyAdmin; ultimately Safe * **batcherHash**: EOA 1 * **owner**: Safe Can be upgraded by: Safe with no delay #### RiscZeroGroth16Verifier Addresses: [0x411e56a890c5fe0712f6F345977815Ba8E7785C3](https://etherscan.io/address/0x411e56a890c5fe0712f6F345977815Ba8E7785C3#code) Verifier contract for RISC Zero Groth16 proofs (version 2.0.0-rc.3). #### OptimismPortal2 Addresses: [0x7f82f57F0Dd546519324392e408b01fcC7D709e8](https://etherscan.io/address/0x7f82f57F0Dd546519324392e408b01fcC7D709e8#code), [0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9](https://etherscan.io/address/0x55400445e384393f9c1BE23e7E734e8d44Ed9fd9#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) The OptimismPortal contract is the main entry point to deposit funds from L1 to L2. It also allows to prove and finalize withdrawals. It specifies which game type can be used for withdrawals, which currently is the KailuaGame. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### DisputeGameFactory Addresses: [0x8546840adF796875cD9AAcc5B3B048f6B2c9D563](https://etherscan.io/address/0x8546840adF796875cD9AAcc5B3B048f6B2c9D563#code), [0x4bbA758F006Ef09402eF31724203F316ab74e4a0](https://etherscan.io/address/0x4bbA758F006Ef09402eF31724203F316ab74e4a0#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) The dispute game factory allows the creation of dispute games, used to propose state roots and eventually challenge them. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### StakeRegistry Addresses: [0x006124Ae7976137266feeBFb3F4D2BE4C073139D](https://etherscan.io/address/0x006124Ae7976137266feeBFb3F4D2BE4C073139D#code), [0x1C468cf7089D263c2f53e2579b329B16aBc4dd96](https://etherscan.io/address/0x1C468cf7089D263c2f53e2579b329B16aBc4dd96#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Keeps track of the total stake of each operator. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### BLSApkRegistry Addresses: [0x00A5Fd09F6CeE6AE9C8b0E5e33287F7c82880505](https://etherscan.io/address/0x00A5Fd09F6CeE6AE9C8b0E5e33287F7c82880505#code), [0x5d0B9cE2e277Daf508528E9f6Bf6314E79e4eD2b](https://etherscan.io/address/0x5d0B9cE2e277Daf508528E9f6Bf6314E79e4eD2b#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Keeps track of the BLS public keys of each operator and the quorum aggregated keys. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### RegistryCoordinator Addresses: [0x0BAAc79acD45A023E19345c352d8a7a83C4e5656](https://etherscan.io/address/0x0BAAc79acD45A023E19345c352d8a7a83C4e5656#code), [0x2088435ABcB1234A9427B755931C9064C93a2595](https://etherscan.io/address/0x2088435ABcB1234A9427B755931C9064C93a2595#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Operators register here with an AVS: The coordinator has three registries: 1) a `StakeRegistry` that keeps track of operators' stakes, 2) a `BLSApkRegistry` that keeps track of operators' BLS public keys and aggregate BLS public keys for each quorum, 3) an `IndexRegistry` that keeps track of an ordered list of operators for each quorum. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig * **churnApprover**: EOA 7 * **owner**: EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### PauserRegistry Addresses: [0x0c431C66F4dE941d089625E5B423D00707977060](https://etherscan.io/address/0x0c431C66F4dE941d089625E5B423D00707977060#code) Defines and stores pauser and unpauser roles for EigenDA contracts. * Roles: * **pausers**: EigenLayerOperationsMultisig, EigenLayerOwningMultisig, EigenLayerPauserMultisig #### EjectionManager Addresses: [0x130d8EA0052B45554e4C99079B84df292149Bd5E](https://etherscan.io/address/0x130d8EA0052B45554e4C99079B84df292149Bd5E#code), [0xC125fECDDabFe13f29EB287Bb8551892AEE7C98A](https://etherscan.io/address/0xC125fECDDabFe13f29EB287Bb8551892AEE7C98A#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Contract used for ejection of operators from the RegistryCoordinator for violating the Service Legal Agreement (SLA). * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig * **ejectors**: EOA 4, EOA 6, EigenDA Multisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### SocketRegistry Addresses: [0x5a3eD432f2De9645940333e4474bBAAB8cf64cf2](https://etherscan.io/address/0x5a3eD432f2De9645940333e4474bBAAB8cf64cf2#code), [0x5b60105ceD5207D6ad217BF2d426e133454eCFB4](https://etherscan.io/address/0x5b60105ceD5207D6ad217BF2d426e133454eCFB4#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### EigenDADisperserRegistry Addresses: [0x78cb05379a3b66E5227f2C1496432D7FFE794Fad](https://etherscan.io/address/0x78cb05379a3b66E5227f2C1496432D7FFE794Fad#code), [0x7DECf99BE82Ea4Cf72F381a5fCBc04228955FBE5](https://etherscan.io/address/0x7DECf99BE82Ea4Cf72F381a5fCBc04228955FBE5#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Registry for EigenDA disperser info such as disperser key to address mapping. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig * **dispersers**: EOA 9 Can be upgraded by: EigenDAOperationsMultisig with no delay #### EigenDAServiceManager Addresses: [0x870679E138bCdf293b7Ff14dD44b70FC97e12fc0](https://etherscan.io/address/0x870679E138bCdf293b7Ff14dD44b70FC97e12fc0#code), [0xae448D008B6F69033AfdA361b46b36C472B6FEE0](https://etherscan.io/address/0xae448D008B6F69033AfdA361b46b36C472B6FEE0#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Bridge contract that accepts blob batches data availability attestations. Batches availability is attested by EigenDA operators signatures and relayed to the service manager contract by the EigenDA disperser. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig * **batchConfirmers**: EOA 2, EOA 3, EOA 5 * **owner**: EigenDAOperationsMultisig * **pauserRegistry**: PauserRegistry; ultimately EOA 11, EOA 12, EOA 13, EOA 14, EOA 15, EOA 16, EigenLayerCommunityMultisig, EigenLayerOperationsMultisig, EigenLayerOperationsMultisig2, Safe * **rewardsInitiator**: EigenLayerRewardsInitiatorMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### PaymentVault Addresses: [0xb2e7ef419a2A399472ae22ef5cFcCb8bE97A4B05](https://etherscan.io/address/0xb2e7ef419a2A399472ae22ef5cFcCb8bE97A4B05#code), [0x62242213E6FA34E943844f9B3124150EFb9CB0dD](https://etherscan.io/address/0x62242213E6FA34E943844f9B3124150EFb9CB0dD#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Entrypoint for making reservations and on demand payments for EigenDA. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### IndexRegistry Addresses: [0xBd35a7a1CDeF403a6a99e4E8BA0974D198455030](https://etherscan.io/address/0xBd35a7a1CDeF403a6a99e4E8BA0974D198455030#code), [0x1ae0b73118906f39D5ED30Ae4A484ce2F479a14c](https://etherscan.io/address/0x1ae0b73118906f39D5ED30Ae4A484ce2F479a14c#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) A registry contract that keeps track of an ordered list of operators for each quorum. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### EigenDARelayRegistry Addresses: [0xD160e6C1543f562fc2B0A5bf090aED32640Ec55B](https://etherscan.io/address/0xD160e6C1543f562fc2B0A5bf090aED32640Ec55B#code), [0xF6D82FBBdf700c086389e72C3023812e956ECa9e](https://etherscan.io/address/0xF6D82FBBdf700c086389e72C3023812e956ECa9e#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Registry for EigenDA relay keys, maps key to address. * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig * **relayers**: EOA 8 Can be upgraded by: EigenDAOperationsMultisig with no delay #### EigenDAThresholdRegistry Addresses: [0xdb4c89956eEa6F606135E7d366322F2bDE609F15](https://etherscan.io/address/0xdb4c89956eEa6F606135E7d366322F2bDE609F15#code), [0x92104977f16dAe423966caa5cD9C115F2D25a8D6](https://etherscan.io/address/0x92104977f16dAe423966caa5cD9C115F2D25a8D6#code) (Implementation (Upgradable)), [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) (Admin) Registry of EigenDA threshold (i.e, adversary and confirmation threshold percentage for a quorum) * Roles: * **admin**: ProxyAdmin; ultimately EigenDAOperationsMultisig Can be upgraded by: EigenDAOperationsMultisig with no delay #### AVSDirectory Addresses: [0x135DDa560e946695d6f155dACaFC6f1F25C1F5AF](https://etherscan.io/address/0x135DDa560e946695d6f155dACaFC6f1F25C1F5AF#code), [0xcD35Cef328b496fA9d70a8d7C34EF3434614862b](https://etherscan.io/address/0xcD35Cef328b496fA9d70a8d7C34EF3434614862b#code) (Implementation (Upgradable)), [0x8b9566AdA63B64d1E1dcF1418b43fd1433b72444](https://etherscan.io/address/0x8b9566AdA63B64d1E1dcF1418b43fd1433b72444#code) (Admin) * Roles: * **admin**: EigenLayerProxyAdmin; ultimately EigenLayerCommunityMultisig, EigenLayerOperationsMultisig, EigenLayerOperationsMultisig2 Can be upgraded by: EigenLayerOperationsMultisig2 with 10d delay, EigenLayerOperationsMultisig with 10d delay, EigenLayerCommunityMultisig with no delay #### DelegationManager Addresses: [0x39053D51B77DC0d36036Fc1fCc8Cb819df8Ef37A](https://etherscan.io/address/0x39053D51B77DC0d36036Fc1fCc8Cb819df8Ef37A#code), [0x6a8BEd4062C895130E2d09bA442D3eCEAd5Df6c2](https://etherscan.io/address/0x6a8BEd4062C895130E2d09bA442D3eCEAd5Df6c2#code) (Implementation (Upgradable)), [0x8b9566AdA63B64d1E1dcF1418b43fd1433b72444](https://etherscan.io/address/0x8b9566AdA63B64d1E1dcF1418b43fd1433b72444#code) (Admin) The DelegationManager contract is responsible for registering EigenLayer operators and managing the EigenLayer strategies delegations. The EigenDA StakeRegistry contract reads from the DelegationManager to track the total stake of each EigenDA operator. * Roles: * **admin**: EigenLayerProxyAdmin; ultimately EigenLayerCommunityMultisig, EigenLayerOperationsMultisig, EigenLayerOperationsMultisig2 Can be upgraded by: EigenLayerOperationsMultisig2 with 10d delay, EigenLayerOperationsMultisig with 10d delay, EigenLayerCommunityMultisig with no delay #### SuperchainConfig Addresses: [0x5d0Ff601BC8580D8682c0462df55343Cb0b99285](https://etherscan.io/address/0x5d0Ff601BC8580D8682c0462df55343Cb0b99285#code), [0x2F64d234f1Ec6bA2eA6914d943c99b45fFF14E89](https://etherscan.io/address/0x2F64d234f1Ec6bA2eA6914d943c99b45fFF14E89#code) (Implementation (Upgradable)), [0xab48b73a9e59aF01AfE91e18cA0774295581d07A](https://etherscan.io/address/0xab48b73a9e59aF01AfE91e18cA0774295581d07A#code) (Admin) This is NOT the shared SuperchainConfig contract of the OP stack Superchain but rather a local fork. It manages the `PAUSED_SLOT`, a boolean value indicating whether the local chain is paused, and `GUARDIAN_SLOT`, the address of the guardian which can pause and unpause the system. * Roles: * **admin**: ProxyAdmin; ultimately Safe * **guardian**: Safe; ultimately EOA 10 Can be upgraded by: Safe with no delay #### L1StandardBridge Addresses: [0x0CA3A2FBC3D770b578223FBB6b062fa875a2eE75](https://etherscan.io/address/0x0CA3A2FBC3D770b578223FBB6b062fa875a2eE75#code), [0x0b09ba359A106C9ea3b181CBc5F394570c7d2a7A](https://etherscan.io/address/0x0b09ba359A106C9ea3b181CBc5F394570c7d2a7A#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) The main entry point to deposit ERC20 tokens from host chain to this chain. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### L1ERC721Bridge Addresses: [0x3D8ee269F87A7f3F0590c5C0d825FFF06212A242](https://etherscan.io/address/0x3D8ee269F87A7f3F0590c5C0d825FFF06212A242#code), [0x7aE1d3BD877a4C5CA257404ce26BE93A02C98013](https://etherscan.io/address/0x7aE1d3BD877a4C5CA257404ce26BE93A02C98013#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) Used to bridge ERC-721 tokens from host chain to this chain. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### L1CrossDomainMessenger Addresses: [0x6C7198250087B29A8040eC63903Bc130f4831Cc9](https://etherscan.io/address/0x6C7198250087B29A8040eC63903Bc130f4831Cc9#code), [0x5D5a095665886119693F0B41d8DFeE78da033e8B](https://etherscan.io/address/0x5D5a095665886119693F0B41d8DFeE78da033e8B#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) Sends messages from host chain to this chain, and relays messages back onto host chain. In the event that a message sent from host chain to this chain is rejected for exceeding this chain's epoch gas limit, it can be resubmitted via this contract's replay function. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### MegaPreDepositVaultRefund Addresses: [0x22cfa62eD71922781984aA2AcffEfA9a82593071](https://etherscan.io/address/0x22cfa62eD71922781984aA2AcffEfA9a82593071#code) Refund escrow designed to hold the funds extracted from the predeposit vault and send them back to the users listed in the vault. * Roles: * **defaultAdmin**: Safe * **executor**: Safe #### MegaUSDmPreDeposit Addresses: [0x46D6Eba3AECD215a3e703cdA963820d4520b45D6](https://etherscan.io/address/0x46D6Eba3AECD215a3e703cdA963820d4520b45D6#code) Predeposit Escrow, not connected to an L2: Users can deposit USDC. The system uses off-chain permit signatures to ensure only KYC'd users can deposit. Withdrawals can only be made by Megaeth Multisig to MegaPreDepositVaultRefund. * Roles: * **owner**: Megaeth Multisig * **permitSigner**: EOA 17 #### ProxyAdmin Addresses: [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code), [0xab48b73a9e59aF01AfE91e18cA0774295581d07A](https://etherscan.io/address/0xab48b73a9e59aF01AfE91e18cA0774295581d07A#code) * Roles: * **owner**: Safe #### PreimageOracle Addresses: [0x1fb8cdFc6831fc866Ed9C51aF8817Da5c287aDD3](https://etherscan.io/address/0x1fb8cdFc6831fc866Ed9C51aF8817Da5c287aDD3#code) The PreimageOracle contract is used to load the required data from L1 for a dispute game. #### ProxyAdmin Addresses: [0x8247EF5705d3345516286B72bFE6D690197C2E99](https://etherscan.io/address/0x8247EF5705d3345516286B72bFE6D690197C2E99#code) * Roles: * **owner**: EigenDAOperationsMultisig #### DelayedWETH Addresses: [0x86183e7b1D908D9A5C3Bc59cC2232F2ffE4E7145](https://etherscan.io/address/0x86183e7b1D908D9A5C3Bc59cC2232F2ffE4E7145#code), [0x5e40B9231B86984b5150507046e354dbFbeD3d9e](https://etherscan.io/address/0x5e40B9231B86984b5150507046e354dbFbeD3d9e#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) Contract designed to hold the bonded ETH for each game. It is designed as a wrapper around WETH to allow an owner to function as a backstop if a game would incorrectly distribute funds. * Roles: * **admin**: ProxyAdmin; ultimately Safe * **owner**: Safe Can be upgraded by: Safe with no delay #### KailuaGame Addresses: [0x8c0Ed8Dd0CcF6d596e321d81eD895ad51fE30B84](https://etherscan.io/address/0x8c0Ed8Dd0CcF6d596e321d81eD895ad51fE30B84#code) Implementation of the KailuaGame with type 1337. Based on this implementation, new KailuaGames are created with every new state root proposal. #### RiscZeroVerifierRouter Addresses: [0x910b159F79288DD706789ec7768E979d4D88C057](https://etherscan.io/address/0x910b159F79288DD706789ec7768E979d4D88C057#code) A router proxy that routes to verifiers based on selectors. The mapping can be changed by a permissioned owner (0x0A383fF8387CF07315f476D1686E95b1a97adc97). * Roles: * **owner**: EOA 10 #### EigenDACertVerifier Addresses: [0xa4F38615e6a1846ccD7ff08E8179CBdAC8F5ff3B](https://etherscan.io/address/0xa4F38615e6a1846ccD7ff08E8179CBdAC8F5ff3B#code) A DA verifier contract for EigenDA V2 certificates. The verifier is used to verify the certificate against operator signatures and stake thresholds. #### PermissionedDisputeGame Addresses: [0xB2E4D20ECF58f2cE6a8d3bf0c982c2c77BE42152](https://etherscan.io/address/0xB2E4D20ECF58f2cE6a8d3bf0c982c2c77BE42152#code) Same as FaultDisputeGame, but only two permissioned addresses are designated as proposer and challenger. #### AnchorStateRegistry Addresses: [0xEEd67E139CC7721EC656B449F01B7b4D7dCFD671](https://etherscan.io/address/0xEEd67E139CC7721EC656B449F01B7b4D7dCFD671#code), [0x7b465370BB7A333f99edd19599EB7Fb1c2D3F8D2](https://etherscan.io/address/0x7b465370BB7A333f99edd19599EB7Fb1c2D3F8D2#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) Contains the latest confirmed state root that can be used as a starting point in a dispute game. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### MIPS Addresses: [0xF027F4A985560fb13324e943edf55ad6F1d15Dc1](https://etherscan.io/address/0xF027F4A985560fb13324e943edf55ad6F1d15Dc1#code) The MIPS contract is used to execute the final step of the dispute game which objectively determines the winner of the dispute. #### OptimismMintableERC20Factory Addresses: [0xF875030B9464001fC0f964E47546b0AFEEbD7C61](https://etherscan.io/address/0xF875030B9464001fC0f964E47546b0AFEEbD7C61#code), [0x5493f4677A186f64805fe7317D6993ba4863988F](https://etherscan.io/address/0x5493f4677A186f64805fe7317D6993ba4863988F#code) (Implementation (Upgradable)), [0x15fCB0120D414f246ead019cA4BdF97447cd8d90](https://etherscan.io/address/0x15fCB0120D414f246ead019cA4BdF97447cd8d90#code) (Admin) A helper contract that generates OptimismMintableERC20 contracts on the network it's deployed to. OptimismMintableERC20 is a standard extension of the base ERC20 token contract designed to allow the L1StandardBridge contracts to mint and burn tokens. This makes it possible to use an OptimismMintableERC20 as this chain's representation of a token on the host chain, or vice-versa. * Roles: * **admin**: ProxyAdmin; ultimately Safe Can be upgraded by: Safe with no delay #### Escrow for USDC Addresses: [0xCB264DEf50D166d4aE7cF60188eC0038819fb719](https://etherscan.io/address/0xCB264DEf50D166d4aE7cF60188eC0038819fb719#code), [0x41675C099F32341bf84BFc5382aF534df5C7461a](https://etherscan.io/address/0x41675C099F32341bf84BFc5382aF534df5C7461a#code) (Implementation (Upgradable)) Multisig currently designated as the 'Treasury'. The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).