# Metis Andromeda Markdown version of https://l2beat.com/layer2s/projects/metis ## Summary - Total Value Secured: $29.39 M (-3.84% compared to seven days ago; canonically bridged $29.39 M, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - **Warning:** The Metis token associated with Metis Andromeda accounts for 75.0% of the TVS! (sentiment: warning) - Past day UOPS: 0.12 (+19.9% compared to seven days ago) - Gas token: METIS - Type: Other - Purpose: Universal - Host chain: Ethereum - Chain ID: 1088 ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: Fraud proofs (INT) (sentiment: bad) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Security Council minority (sentiment: warning) ### About Metis Andromeda is an EVM-equivalent solution originally forked from Optimism OVM. It uses a decentralized Sequencer pool running Tendermint consensus and MPC module to sign transaction batches. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/metis) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/metis/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/metis) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#onchain-costs). ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#liveness). ## Milestones & Incidents - 2025-05-13: [Metis starts using blobs](https://etherscan.io/tx/0x1c28c8e7b89c5da880a52c3e4e4ca6da332816e72c0600d55c18479be897c8b7). Permissioned batcher is posting blobs to the inbox. - 2023-03-15: [Data hashes posted to EOA](https://etherscan.io/tx/0x4dbb3a65f411b2319dc5c824804a6593d6bf6b482a76493e9089e1e055267123). Hashes to data blobs are now posted to EOA address instead of CanonicalTransactionChain contract. - 2022-04-12: [Data availability change](https://metisdao.medium.com/decentralized-storage-goes-live-da876dc6eb70). Update moving data to an off-chain committee. - 2021-11-19: [Mainnet Launch](https://metisdao.medium.com/metis-to-launch-andromeda-honoring-our-commitment-to-decentralization-fa2d03394398). Public launch of Metis Layer 2 Andromeda, based on the Optimism codebase. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. the GameCreator colludes with the StateDeleter to block Challenges in the proof system (CRITICAL). ### Funds can be lost if 3. there are mistakes in the highly complex OVM implementation. ### Funds can be frozen if 4. the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production, (CRITICAL) 5. an invalid state root is successfully disputed but it is not deleted by the permissioned MVM_Fraud_Verifier (Metis Security Council minority). ### Users can be censored if 6. the operator refuses to include their transactions. ### MEV can be extracted if 7. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. The single address acting as a sequencer on L1 is not trustlessly linkable to the claim of multiple decentralized sequencers being used. ### State validation Fraud proofs (INT) (sentiment: bad) Fraud proofs allow actors watching the chain to prove that the state is incorrect. Interactive proofs (INT) require multiple transactions over time to resolve.Anyone can submit challenge requests. However, permissioned actors are needed to create the challenge and to delete successfully disputed state roots. Additionally, the current permissioned actors (GameCreator and Security Council minority) can collude and finalize malicious state roots. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Security Council minority (sentiment: warning) Only the whitelisted proposer can update state roots on L1, so in the event of failure the withdrawals are frozen. The Security Council minority can be alerted to enforce censorship resistance because they own the proposer registry, controlling the active whitelisted proposer. ## Stage Metis Andromeda is not even a Stage 0 project. **Warning:** The requirement for available node software is under review ### Stage 0 - [x] A complete and functional proof system is deployed. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [ ] (under review) A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/MetisProtocol/mvm) ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [ ] Users' withdrawals can be censored by the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. - [x] The Security Council is properly set up [(List of members)](https://docs.metis.io/andromeda/network/council). ### Stage 2 - [ ] Upgrades unrelated to onchain provable bugs provide less than 30d to exit. - [ ] The Security Council's actions are not confined to onchain provable bugs. ## Data availability ### All data required for proofs is published on chain Transaction data is posted to Ethereum using blobs. Initially, data was posted to the CanonicalTransactionChain contract, then it moved to just posting hashes to an EOA address, and as of May 2025, the system uses blobs for data availability. **References** - [Blobs batcher - Metis source code](https://github.com/MetisProtocol/mvm/blob/e816c6c461a8e91db3a9ccaa33d2d0f6a60633d5/go/op-program/chainconfig/rollupcfg.go#L85) ## State validation ### State root proposals Dispute game contracts for state validation are deployed but not used to propose state roots as in standard OP Stack chains. Instead, the permissioned proposer submits state roots through the appendStateBatch function in the `StateCommitmentChain` contract. A state root gets confirmed if the challenge period has passed and the state batch is not disputed. **References** - [StateCommitmentChain - Etherscan source code](https://etherscan.io/address/0xA738573Ec0FD7959BfA60Aaa8a23Fe7BEC6c4Bd7#code) ### Challenges Games can only be created on demand by the permissioned GameCreator should a dispute be requested. Users can signal the need for a dispute by bonding 4.0 METIS and calling the dispute() function of the `DisputeGameFactory`. If a game is not created by the `GameCreator` within the dispute timeout period of 2d, anyone can call `disputeTimeout()`. This function calls `saveDisputedBatchTimeout()` on the `StateCommitmentChain`, which marks the batch as disputed. This blocks L2->L1 messaging and withdrawals for the disputed batch and any subsequent batches until the dispute is deleted. Should a game be created and resolved, disputed state batches can be marked as such in the `StateCommitmentChain`. Then, these flagged batches can be deleted (within the fraud proof window). Batches can only be deleted by the MVM_Fraud_Verifier contract address, which currently corresponds to the `Metis Security Council` minority. **Risks** - Funds can be frozen if an invalid state root is successfully disputed but it is not deleted by the permissioned MVM_Fraud_Verifier (Metis Security Council minority). - Funds can be stolen if the GameCreator colludes with the StateDeleter to block Challenges in the proof system (CRITICAL). **References** - [DisputeGameFactory - No games are created to propose state roots](https://etherscan.io/address/0x1C2f0A08762f0aD4598fB5de8f9D6626a4e4aeE3) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/metis#updates). ## Operator ### The system has a decentralized sequencer set As of April 2024 Metis uses a permissioned sequencer pool running a Tendermint consensus. Once consensus is reached on a block, an MPC address is used to submit a block hash to Ethereum. The infrastructure to manage the MPC is offchain and not trustless because Ethereum does not verify the validity of MPC address. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. **References** - [Decentralized Sequencer - Metis documentation](https://docs.metis.io/andromeda/sequencer/architecture/mpc) ### Users can't force any transaction There is no general mechanism to force the sequencer to include the transaction. **Risks** - Users can be censored if the operator refuses to include their transactions. **References** - [CanonicalTransactionChain - Etherscan source code](https://etherscan.io/address/0x56a76bcC92361f6DF8D75476feD8843EdC70e1C9#code) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. The process of block finalization usually takes several days to complete. **Risks** - Funds can be frozen if the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL). **References** - [Transaction finality - Metis documentation](https://docs.metis.io/andromeda/sequencer/architecture/transaction) ## Other considerations ### EVM compatible smart contracts are supported Metis uses the Optimistic Virtual Machine (OVM) 2.0 to execute transactions. **Risks** - Funds can be lost if there are mistakes in the highly complex OVM implementation. **References** - [MVM repository - Metis source code](https://github.com/MetisProtocol/mvm) ## Permissions ### Ethereum #### Actors ##### Metis Security Council Addresses: [0xbf1752DE62d825aF0634F514226F881a449874b6](https://etherscan.io/address/0xbf1752DE62d825aF0634F514226F881a449874b6) A Multisig with 6/8 threshold. * Can upgrade **with no delay** * L1CrossDomainMessenger * LockingInfo [via: ProxyAdmin] * DisputeGameFactory [via: ProxyAdmin] * FaultProofLockingPool [via: ProxyAdmin] * L1StandardBridge * MVM_InboxSenderManager * StateCommitmentChain * LockingPool [via: ProxyAdmin] * DelayedWMetis [via: ProxyAdmin] **References** - [Security Council members - Metis Docs](https://docs.metis.io/andromeda/network/council) ##### Metis Multisig Addresses: [0x48fE1f85ff8Ad9D088863A42Af54d06a1328cF21](https://etherscan.io/address/0x48fE1f85ff8Ad9D088863A42Af54d06a1328cF21) A Multisig with 4/9 threshold. Can pause, censor, instantly upgrade the bridge and upgrade other critical contracts in the system. * Can interact with DisputeGameFactory * Can create new dispute games ##### Metis Security Council Minority Addresses: [0xAd07701EE9348d2B9e7De061883C10574c543279](https://etherscan.io/address/0xAd07701EE9348d2B9e7De061883C10574c543279) A Multisig with 2/8 threshold. * Can interact with Lib_AddressManager * Can delete batches from the StateCommitmentChain ##### RewardEscrowerMultisig Addresses: [0x62478E4eeb4070fE399866aB05e821AB97200947](https://etherscan.io/address/0x62478E4eeb4070fE399866aB05e821AB97200947) A Multisig with 2/4 threshold. Escrows staking rewards for Sequencers. ##### EOA 1 Addresses: [0xAaaAA9A2e72753cE09915fee7c0AFa6f34745799](https://etherscan.io/address/0xAaaAA9A2e72753cE09915fee7c0AFa6f34745799) * Can interact with DisputeGameFactory * Can create new dispute games ##### EOA 2 Addresses: [0xaE4d46bD9117Cb017C5185844699c51107cB28a9](https://etherscan.io/address/0xaE4d46bD9117Cb017C5185844699c51107cB28a9) * Can interact with MVM_InboxSenderManager * Allowed to commit transactions from the current layer to the host chain ##### EOA 3 Addresses: [0xf3CEB4C2ef996CdBc95C4E18c6D0CA988CC09040](https://etherscan.io/address/0xf3CEB4C2ef996CdBc95C4E18c6D0CA988CC09040) * Can interact with MVM_ProposerRegistry * Allowed to post new state roots of the current layer to the host chain * Can interact with Lib_AddressManager * Allowed to post new state roots of the current layer to the host chain ## Smart contracts ### Ethereum #### L1CrossDomainMessenger Addresses: [0x081D1101855bD523bA69A9794e0217F0DB6323ff](https://etherscan.io/address/0x081D1101855bD523bA69A9794e0217F0DB6323ff#code), [0xc1Ce5240B42AB158027095f658d530F9989b414F](https://etherscan.io/address/0xc1Ce5240B42AB158027095f658d530F9989b414F#code) (Implementation (Upgradable)), [0xbf1752DE62d825aF0634F514226F881a449874b6](https://etherscan.io/address/0xbf1752DE62d825aF0634F514226F881a449874b6#code) (Admin) The L1 Cross Domain Messenger (L1xDM) contract sends messages from L1 to Metis, and relays messages from Metis onto L1. In the event that a message sent from L1 to Metis is rejected for exceeding the Metis epoch gas limit, it can be resubmitted via this contract's replay function. * Roles: * **admin**: Metis Security Council Can be upgraded by: Metis Security Council with no delay #### CanonicalTransactionChain Addresses: [0x56a76bcC92361f6DF8D75476feD8843EdC70e1C9](https://etherscan.io/address/0x56a76bcC92361f6DF8D75476feD8843EdC70e1C9#code) The Canonical Transaction Chain (CTC) contract is an append-only log of transactions which must be applied to the OVM state. Given that transactions batch hashes are sent to an EOA address, it allows any account to enqueue() a transaction, which the Sequencer must eventually append to the rollup state. #### StateCommitmentChain Addresses: [0xA2FaAAC9120c1Ff75814F0c6DdB119496a12eEA6](https://etherscan.io/address/0xA2FaAAC9120c1Ff75814F0c6DdB119496a12eEA6#code), [0xA738573Ec0FD7959BfA60Aaa8a23Fe7BEC6c4Bd7](https://etherscan.io/address/0xA738573Ec0FD7959BfA60Aaa8a23Fe7BEC6c4Bd7#code) (Implementation (Upgradable)), [0xbf1752DE62d825aF0634F514226F881a449874b6](https://etherscan.io/address/0xbf1752DE62d825aF0634F514226F881a449874b6#code) (Admin) The State Commitment Chain (SCC) stores a list of proposed state roots in a linked ChainStorageContainer contract. Only a permissioned state root proposer (MVM_Proposer) can submit new state roots. * Roles: * **admin**: Metis Security Council Can be upgraded by: Metis Security Council with no delay #### LockingInfo Addresses: [0x0fe382b74C3894B65c10E5C12ae60Bbd8FAf5b48](https://etherscan.io/address/0x0fe382b74C3894B65c10E5C12ae60Bbd8FAf5b48#code), [0x0D30F0d7934f53aaF6a1630A4c109AF4513a65cC](https://etherscan.io/address/0x0D30F0d7934f53aaF6a1630A4c109AF4513a65cC#code) (Implementation (Upgradable)), [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) (Admin) Contract acting as an escrow for METIS tokens managed by LockingPool. * Roles: * **admin**: ProxyAdmin; ultimately Metis Security Council Can be upgraded by: Metis Security Council with no delay #### ChainStorageContainer-SCC-batches Addresses: [0x10739F09f6e62689c0aA8A1878816de9e166d6f9](https://etherscan.io/address/0x10739F09f6e62689c0aA8A1878816de9e166d6f9#code) Storage container for SCC batches. #### DisputeGameFactory Addresses: [0x1C2f0A08762f0aD4598fB5de8f9D6626a4e4aeE3](https://etherscan.io/address/0x1C2f0A08762f0aD4598fB5de8f9D6626a4e4aeE3#code), [0x61B220bbfeF9A94163764928B039d85e94A509d9](https://etherscan.io/address/0x61B220bbfeF9A94163764928B039d85e94A509d9#code) (Implementation (Upgradable)), [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) (Admin) Factory contract for creating dispute games. Unlike in standard OP Stack chains, games are not created to propose state roots. Instead, games are created on demand by the permissioned `GameCreator` only should a dispute arise. * Roles: * **admin**: ProxyAdmin; ultimately Metis Security Council * **gameCreator**: EOA 1, Metis Multisig Can be upgraded by: Metis Security Council with no delay #### MetisConfig Addresses: [0x2aA4E192994757c5fAB87Ba13812B89564EA57Ff](https://etherscan.io/address/0x2aA4E192994757c5fAB87Ba13812B89564EA57Ff#code) Contract used to manage configuration of global Metis values. #### FaultProofLockingPool Addresses: [0x2CA48fF3bBC59Bff859543E63233116ecdA3DCBb](https://etherscan.io/address/0x2CA48fF3bBC59Bff859543E63233116ecdA3DCBb#code), [0x1061528C33b8034952fb7355cC481e193b29FCa6](https://etherscan.io/address/0x1061528C33b8034952fb7355cC481e193b29FCa6#code) (Implementation (Upgradable)), [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) (Admin) The FaultProofLockingPool is a contract that allows sequencers to lock their funds for a certain period of time. The contract is used in the Metis protocol to ensure that sequencers have enough funds to cover the potential losses from disputes. It currently has a balance of 0 METIS. * Roles: * **admin**: ProxyAdmin; ultimately Metis Security Council Can be upgraded by: Metis Security Council with no delay #### ChainStorageContainer-CTC-batches Addresses: [0x38473Feb3A6366757A249dB2cA4fBB2C663416B7](https://etherscan.io/address/0x38473Feb3A6366757A249dB2cA4fBB2C663416B7#code) Storage container for CTC batches. #### FaultDisputeGame Addresses: [0x388DEfE576077257074F77c727aA5F2e3B815E21](https://etherscan.io/address/0x388DEfE576077257074F77c727aA5F2e3B815E21#code) Contract for handling fault disputes (should games be created). Successfully disputed batches are marked as disputed to the StateCommitmentChain. #### L1StandardBridge Addresses: [0x3980c9ed79d2c191A89E02Fa3529C60eD6e9c04b](https://etherscan.io/address/0x3980c9ed79d2c191A89E02Fa3529C60eD6e9c04b#code), [0xa0cfE8Af2AB5C9232714647702DbACf862EA4798](https://etherscan.io/address/0xa0cfE8Af2AB5C9232714647702DbACf862EA4798#code) (Implementation (Upgradable)), [0xbf1752DE62d825aF0634F514226F881a449874b6](https://etherscan.io/address/0xbf1752DE62d825aF0634F514226F881a449874b6#code) (Admin) Main entry point for users depositing ERC20 tokens and ETH that do not require custom gateway. * Roles: * **admin**: Metis Security Council Can be upgraded by: Metis Security Council with no delay #### MVM_ProposerRegistry Addresses: [0x5669d0C8C28B7E2c3d10eD246bEb042bDdd12E18](https://etherscan.io/address/0x5669d0C8C28B7E2c3d10eD246bEb042bDdd12E18#code) The Proposer Registry contains the addresses of the current active proposers for the chain. * Roles: * **proposer**: EOA 3 #### BondManager Addresses: [0x595801b85628ec6979C420988b8843A40F850528](https://etherscan.io/address/0x595801b85628ec6979C420988b8843A40F850528#code) The Bond Manager contract will handle deposits in the form of an ERC20 token from bonded Proposers. It will also handle the accounting of gas costs spent by a Verifier during the course of a challenge. In the event of a successful challenge, the faulty Proposer's bond will be slashed, and the Verifier's gas costs will be refunded. Current mock implementation allows only OVM_Proposer to propose new state roots. No slashing is implemented. #### PreimageOracle Addresses: [0x789a64284e29d2225430606D3D89a9336870BBbC](https://etherscan.io/address/0x789a64284e29d2225430606D3D89a9336870BBbC#code) Oracle for providing preimages. #### MVM_DiscountOracle Addresses: [0x7f6B0b7589febc40419a8646EFf9801b87397063](https://etherscan.io/address/0x7f6B0b7589febc40419a8646EFf9801b87397063#code) Oracle specifying user fees for sending L1 -> Metis messages and other parameters for cross-chain communication. #### MVM_InboxSenderManager Addresses: [0x8b0d1D3557aF524351FCd09eE8E7a48adcB712e0](https://etherscan.io/address/0x8b0d1D3557aF524351FCd09eE8E7a48adcB712e0#code), [0x10ACFD506472F6Cb0602dF880172935cEE9AC7B0](https://etherscan.io/address/0x10ACFD506472F6Cb0602dF880172935cEE9AC7B0#code) (Implementation (Upgradable)), [0xbf1752DE62d825aF0634F514226F881a449874b6](https://etherscan.io/address/0xbf1752DE62d825aF0634F514226F881a449874b6#code) (Admin) Container contract for designated sequencer addresses. * Roles: * **admin**: Metis Security Council * **blobBatcher**: EOA 2 Can be upgraded by: Metis Security Council with no delay #### ProxyAdmin Addresses: [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) * Roles: * **owner**: Metis Security Council #### Lib_AddressManager Addresses: [0x918778e825747a892b17C66fe7D24C618262867d](https://etherscan.io/address/0x918778e825747a892b17C66fe7D24C618262867d#code) Contract used to manage a mapping of string names to addresses. Modern OP stack uses a different standard proxy system instead, but this contract is still necessary for backwards compatibility with several older contracts. * Roles: * **1088_MVM_FraudVerifier**: Metis Security Council Minority * **_1088_MVM_Proposer**: EOA 3 #### Metis Token Addresses: [0x9E32b13ce7f2E80A01932B42553652E053D6ed8e](https://etherscan.io/address/0x9E32b13ce7f2E80A01932B42553652E053D6ed8e#code) Metis token contract. #### ChainStorageContainer-CTC-queue Addresses: [0xA91Ea6F5d1EDA8e6686639d6C88b309cF35D2E57](https://etherscan.io/address/0xA91Ea6F5d1EDA8e6686639d6C88b309cF35D2E57#code) Storage container for CTC queue. #### MIPS Addresses: [0xAFD640204D73B02C3521eA8ea3771182527Ff057](https://etherscan.io/address/0xAFD640204D73B02C3521eA8ea3771182527Ff057#code) #### LockingPool Addresses: [0xD54c868362C2098E0E46F12E7D924C6A332952Dd](https://etherscan.io/address/0xD54c868362C2098E0E46F12E7D924C6A332952Dd#code), [0xD8f38c831E5032d23065Eaaee8c0620e17c04D60](https://etherscan.io/address/0xD8f38c831E5032d23065Eaaee8c0620e17c04D60#code) (Implementation (Upgradable)), [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) (Admin) Contract allowing users to lock tokens to apply to become a sequencer, receive rewards, unlock tokens to exit the sequencer, reward distribution. * Roles: * **admin**: ProxyAdmin; ultimately Metis Security Council Can be upgraded by: Metis Security Council with no delay #### DelayedWMetis Addresses: [0xfA947f70c3509d5b70A606e871aE0C85397D0738](https://etherscan.io/address/0xfA947f70c3509d5b70A606e871aE0C85397D0738#code), [0xa2033fbb6213B2233a6998391ccc8E070BcC1B51](https://etherscan.io/address/0xa2033fbb6213B2233a6998391ccc8E070BcC1B51#code) (Implementation (Upgradable)), [0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8](https://etherscan.io/address/0x8FbB8D00f7621B68F219B0B18738F07aF513D5C8#code) (Admin) Delayed wrapped Metis token contract. * Roles: * **admin**: ProxyAdmin; ultimately Metis Security Council Can be upgraded by: Metis Security Council with no delay ### Metis Andromeda #### OVM_L2ToL1MessagePasser Addresses: [0x4200000000000000000000000000000000000000](https://explorer.metis.io/address/0x4200000000000000000000000000000000000000#code) #### OVM_DeployerWhitelist Addresses: [0x4200000000000000000000000000000000000002](https://explorer.metis.io/address/0x4200000000000000000000000000000000000002#code) #### MVM_ChainConfig Addresses: [0x4200000000000000000000000000000000000005](https://explorer.metis.io/address/0x4200000000000000000000000000000000000005#code) #### L2CrossDomainMessenger Addresses: [0x4200000000000000000000000000000000000007](https://explorer.metis.io/address/0x4200000000000000000000000000000000000007#code) The L2CrossDomainMessenger (L2xDM) contract sends messages from L2 to L1, and relays messages from L1 onto L2 with a system tx. In the event that a message sent from L2 to L1 is rejected for exceeding the L1 gas limit, it can be resubmitted via this contract’s replay function. #### Ether Token Addresses: [0x420000000000000000000000000000000000000A](https://explorer.metis.io/address/0x420000000000000000000000000000000000000A#code) #### OVM_GasPriceOracle Addresses: [0x420000000000000000000000000000000000000F](https://explorer.metis.io/address/0x420000000000000000000000000000000000000F#code) #### L2StandardBridge Addresses: [0x4200000000000000000000000000000000000010](https://explorer.metis.io/address/0x4200000000000000000000000000000000000010#code) The L2StandardBridge contract is the main entry point to deposit or withdraw ERC20 tokens from L2 to L1. This contract can store any token. #### OVM_SequencerFeeVault Addresses: [0x4200000000000000000000000000000000000011](https://explorer.metis.io/address/0x4200000000000000000000000000000000000011#code) #### L2StandardTokenFactory Addresses: [0x4200000000000000000000000000000000000012](https://explorer.metis.io/address/0x4200000000000000000000000000000000000012#code) #### MVM_Coinbase Addresses: [0xDeadDeAddeAddEAddeadDEaDDEAdDeaDDeAD0000](https://explorer.metis.io/address/0xDeadDeAddeAddEAddeadDEaDDEAdDeaDDeAD0000#code) The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).