# Morph Markdown version of https://l2beat.com/layer2s/projects/morph ## Summary - Total Value Secured: $162.58 M (-1.32% compared to seven days ago; canonically bridged $16.18 M, natively minted $0.00, externally bridged $146.40 M; 90.0% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Past day UOPS: 0.22 (-32.3% compared to seven days ago) - Stage: Stage 0 - Gas token: ETH - Type: Optimistic Rollup - Purpose: Universal - Host chain: Ethereum - Chain ID: 2818 ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Fraud proofs (1R, ZK) (sentiment: warning) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Self propose (sentiment: good) ### About Morph is an EVM compatible rollup. It operates as an optimistic rollup with ZK fault proofs and has plans for decentralizing the Sequencer. Their mission is to build the first blockchain for consumers, where user-friendly applications integrate seamlessly into everyday life, becoming indispensable utilities. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/morph#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/morph) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/morph/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/morph#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/morph) ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/morph#data-posted). ## Milestones & Incidents - 2026-09-22: [Fully centralized sequencing](https://etherscan.io/tx/0xdeb5268cbec1b47c77ad46cb8dd29491833e45ae374d2905f94f4e0499e8110e). Only submitters staked in the new Submitter contract can commit batches. BLS input removed. ## Risk summary **Warning:** The current rollup version loses liveness if bad/random data is posted to blobs using `commitBatch()` ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. no whitelisted challenger posts a challenge for an incorrect state root. ### MEV can be extracted if 3. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis **Warning:** The current rollup version loses liveness if bad/random data is posted to blobs using `commitBatch()` ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for 7d, new L1 batches must include at least 1 transaction from the queue. ### State validation Fraud proofs (1R, ZK) (sentiment: warning) Fraud proofs allow actors watching the chain to prove that the state is incorrect. Single round proofs (1R) only require a single transaction to resolve. ZK proofs are used to prove the correctness of the state transition. The system currently operates with at least 5 whitelisted challengers external to the team. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Self propose (sentiment: good) Anyone can become a Proposer after 7d of inactivity from the currently whitelisted Proposers. This requires using the source-available prover to submit a zk proof of validity for the proposal. ## Stage Morph is a Stage 0 Optimistic Rollup. ### Stage 0 - [x] A complete and functional proof system is deployed. - [x] There are at least 5 external actors who can submit fraud proofs. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [x] A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/morph-l2/run-morph-node) ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [ ] Users' withdrawals can be censored by the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. - [ ] The Security Council is not properly set up. - [x] The proof system meets the minimum trusted setup requirements defined in the L2BEAT [trusted setup assessment framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). - [x] Prover source code is published. - [ ] Not all onchain verifiers' smart contracts can be independently regenerated from the verifier source code. - [x] The sources of all programs used are public and program hashes can be independently regenerated. ### Stage 2 - [ ] Fraud proof submission is open only to whitelisted actors. - [ ] Upgrades unrelated to onchain provable bugs provide less than 30d to exit. - [ ] The Security Council's actions are not confined to onchain provable bugs. ## Data availability ### All data required for proofs is published on chain All the data that is used to construct the system state is published on chain in the form of cheap blobs or calldata. This ensures that it will be available for enough time. **References** - [Rollup.sol - Etherscan source code commitBatch() and commitBatchWithBlobProof() functions](https://etherscan.io/address/0x759894Ced0e6af42c26668076Ffa84d02E3CeF60#code) ## State validation ### Fraud proofs Morph uses a one round fault proof system where whitelisted Challengers, if they find a faulty state root within the 2d challenge window, can post a 1 WEI bond and request a ZK proof of the state transition. At least 5 Challengers are operated by entities external to the team. After the challenge, during a 3d proving window, a ZK proof must be delivered, otherwise the state root is considered invalid and the submitter's whole stake in the Submitter contract (at least 1 ETH) is slashed, with 30% of it forwarded as challenger reward and the rest accruing to the Submitter owner. The zkVM used is SP1 by Succinct. If a valid proof is delivered, the Challenger loses the challenge bond. The Morph Multisig can revert unfinalized batches. **Risks** - Funds can be stolen if no whitelisted challenger posts a challenge for an incorrect state root. **References** - [Whitelisted Challengers - Morph Docs](https://docs.morphl2.io/docs/how-morph-works/optimistic-zkevm/#challenger-address-list) - [Rollup.sol - Etherscan source code, commitBatch(), challengeState(), proveState() functions](https://etherscan.io/address/0x213CE22b487B71Ac68a1B5b12d2b93D1AF30Ea1d#code) - [Submitter.sol - Etherscan source code, isActive(), stake(), slash() functions](https://etherscan.io/address/0x3c5C88F69B190a1c497996AfEDb1a6591b0dF576#code) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/morph#updates). ## Operator ### The system has a centralized operator Batches and state roots can only be committed to L1 by submitters whitelisted by the Morph multisig in the Submitter contract, each staking at least 1 ETH. No sequencer signatures are verified onchain, and the L2 block-producing sequencer set is managed separately through the L1Staking contract. Sequencing is centralized and permissioned to the listed submitters in practice. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. **References** - [Rollup.sol - Etherscan source code, onlyActiveSubmitter modifier](https://etherscan.io/address/0x213CE22b487B71Ac68a1B5b12d2b93D1AF30Ea1d#code) - [Submitter.sol - Etherscan source code, addSubmitter()](https://etherscan.io/address/0x3c5C88F69B190a1c497996AfEDb1a6591b0dF576#code) ### Users can force transactions Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors such a request or is down for 7d, any new proposal must include at least 1 transaction from the queue. Proposing is permissionless under these conditions if proven immediately. **References** - [EnforcedTxGateway proxy - PAUSED - Etherscan source code](https://etherscan.io/address//0xc5Fa3b8968c7FAbEeA2B530a20b88d0C2eD8abb7#readProxyContract#F7) - [EnforcedTxGateway.sol implementation - Etherscan source code](https://etherscan.io/address/0xCb13746Fc891fC2e7D824870D00a26F43fE6123e#code) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. The process of block finalization takes a challenge period of 2d to complete. **References** - [L1ETHGateway.sol - Etherscan source code, finalizeWithdrawETH function](https://etherscan.io/address/0x63eeCb6bE6087B094c2CBAA34f2902593eAE979c#code) ## Permissions ### Ethereum #### Actors ##### L1Staking Addresses: [0x0Dc417F8AF88388737c5053FF73f345f080543F7](https://etherscan.io/address/0x0Dc417F8AF88388737c5053FF73f345f080543F7) Staking registry of the L2 sequencer set. It relays staker additions and removals to the L2 Staking contract through the messenger, which determines the L2 block-producing sequencer set. The Rollup does not reference it: L1 batch submission and slashing are authorized through the Submitter contract, so the stake, challenge-deposit and reward parameters here are not enforced by the Rollup. * Can interact with Whitelist * can send gasless transactions to L2 (L2 gas fee waived) ##### Morph Multisig 2 Addresses: [0xB822319ab7848b7cC4537c8409e50f85BFb04377](https://etherscan.io/address/0xB822319ab7848b7cC4537c8409e50f85BFb04377) A Multisig with 3/5 threshold. * Can interact with L1Staking * whitelist and remove stakers (the L2 sequencer set relayed to L2) and manage the staking, slashing and reward config of this contract * Can interact with L1MessageQueueWithGasPriceOracle * manage L2 base fee, max gas limit and set the whitelist checker contract * Can interact with TimelockController * cancel queued transactions * propose transactions * Can interact with Rollup * Allowed to challenge or delete state roots proposed by a Proposer * Can interact with EnforcedTxGateway * pause and unpause, update the fee vault * Can interact with Whitelist * manage the whitelist ##### Morph Multisig 1 Addresses: [0xF101f7f59A348c1F971A2BC64fdBdA58c7bBD887](https://etherscan.io/address/0xF101f7f59A348c1F971A2BC64fdBdA58c7bBD887) A Multisig with 4/6 threshold. * Can upgrade **with no delay** * L1Staking [via: TimelockController → ProxyAdmin] * L1ETHGateway [via: TimelockController → ProxyAdmin] * L1USDCGateway [via: TimelockController → ProxyAdmin] * L1MessageQueueWithGasPriceOracle [via: TimelockController → ProxyAdmin] * L1StandardERC20Gateway [via: TimelockController → ProxyAdmin] * TimelockController [via: ProxyAdmin] * L1GatewayRouter [via: TimelockController → ProxyAdmin] * Rollup [via: TimelockController → ProxyAdmin] * L1CustomERC20Gateway [via: TimelockController → ProxyAdmin] * EnforcedTxGateway [via: TimelockController → ProxyAdmin] * L1USDCGatewayLegacy [via: TimelockController → ProxyAdmin] * L1CrossDomainMessenger [via: TimelockController → ProxyAdmin] * Submitter [via: TimelockController → ProxyAdmin] * Can interact with TimelockController * execute transactions that are ready * manage all access control roles [via: TimelockController - or - acting directly] * Can interact with MultipleVersionRollupVerifier * register new verifiers to be used starting from a given L2 batch index * Can interact with L1GatewayRouter * manage token to escrow mapping and (un-)register escrows * Can interact with Rollup * can pause and unpause, revert unfinalized batches, update proof window and finalization period, manage challengers, modify the verifier address * Can interact with L1CrossDomainMessenger * set critical configs and contract references and pause/unpause * Can interact with Submitter * add and remove submitters (batch committers/proposers), set the minimum stake, the challenge deposit and the slashing reward share, and withdraw the non-rewarded remainder of slashed stakes ##### 37 EOAs Addresses: [0x0092bC49078f130D27e70dBeee441E227280B97D](https://etherscan.io/address/0x0092bC49078f130D27e70dBeee441E227280B97D) (EOA 1), [0x03FD36AEd3b2597aA79bb5f543f3a0eAf9DEB0FA](https://etherscan.io/address/0x03FD36AEd3b2597aA79bb5f543f3a0eAf9DEB0FA) (EOA 2), [0x111BC31F5cfE920004FD17449BDb5e476C02AEC5](https://etherscan.io/address/0x111BC31F5cfE920004FD17449BDb5e476C02AEC5) (EOA 3), [0x1721D3Ae2d68E3Dd32525400Ed2a29060F1300c6](https://etherscan.io/address/0x1721D3Ae2d68E3Dd32525400Ed2a29060F1300c6) (EOA 4), [0x234aCb24b1DeeA7f6c7530b8c29a6378bA21e1D0](https://etherscan.io/address/0x234aCb24b1DeeA7f6c7530b8c29a6378bA21e1D0) (EOA 5), [0x323a78C1c910b282dE98a557d735628A02E00983](https://etherscan.io/address/0x323a78C1c910b282dE98a557d735628A02E00983) (EOA 6), [0x3b065B18EdFFC7cf3D751E33d45C1FB4fD78d57b](https://etherscan.io/address/0x3b065B18EdFFC7cf3D751E33d45C1FB4fD78d57b) (EOA 8), [0x4Ee3690901157bE86A33371bEc1e5021A10Ba47C](https://etherscan.io/address/0x4Ee3690901157bE86A33371bEc1e5021A10Ba47C) (EOA 9), [0x5c6E1011cd3b5d7D2937c098b8F61d6B3d1aee7e](https://etherscan.io/address/0x5c6E1011cd3b5d7D2937c098b8F61d6B3d1aee7e) (EOA 10), [0x611e4B24e89bC524Fc06f73b6FD02bE3Ec73d6Db](https://etherscan.io/address/0x611e4B24e89bC524Fc06f73b6FD02bE3Ec73d6Db) (EOA 11), [0x6D7cC6C62CD6CcdaC482E82aA7A3763926e93854](https://etherscan.io/address/0x6D7cC6C62CD6CcdaC482E82aA7A3763926e93854) (EOA 13), [0x71C10870dC38E54d987C22e96aB32b46cc08564F](https://etherscan.io/address/0x71C10870dC38E54d987C22e96aB32b46cc08564F) (EOA 14), [0x731a89035F88Bde8fB7357AaAD6620F4716aC1be](https://etherscan.io/address/0x731a89035F88Bde8fB7357AaAD6620F4716aC1be) (EOA 15), [0x74204e3801E9394848AbDBAd6f378d0b11e9a091](https://etherscan.io/address/0x74204e3801E9394848AbDBAd6f378d0b11e9a091) (EOA 16), [0x77B29534738E3F0F297d36635d7884965C7c8cE1](https://etherscan.io/address/0x77B29534738E3F0F297d36635d7884965C7c8cE1) (EOA 18), [0x8b8bc0EB904fDD2862a6433d020F15bBc8a7b13e](https://etherscan.io/address/0x8b8bc0EB904fDD2862a6433d020F15bBc8a7b13e) (EOA 19), [0x8C0cFFcBAb44c7aB6e96EB607c49188dE99a17Cd](https://etherscan.io/address/0x8C0cFFcBAb44c7aB6e96EB607c49188dE99a17Cd) (EOA 20), [0x92C4d5d9CaDD1aF74080DE7aa078434007F710Bb](https://etherscan.io/address/0x92C4d5d9CaDD1aF74080DE7aa078434007F710Bb) (EOA 21), [0x95417708f67f4a5dF1A447efe40c6C74e38Ab832](https://etherscan.io/address/0x95417708f67f4a5dF1A447efe40c6C74e38Ab832) (EOA 22), [0x95C373754C66feF1Eb2dbb6934aF821C551D9738](https://etherscan.io/address/0x95C373754C66feF1Eb2dbb6934aF821C551D9738) (EOA 23), [0x9Ac29D4f41A139D9b7be32C2906Df9f86FA51b2b](https://etherscan.io/address/0x9Ac29D4f41A139D9b7be32C2906Df9f86FA51b2b) (EOA 24), [0xa609285fF6F2a0Dfdeb03cc33d78d8a47A691497](https://etherscan.io/address/0xa609285fF6F2a0Dfdeb03cc33d78d8a47A691497) (EOA 25), [0xAa54d89A2B420F286Db0C19732D07abe08E6b442](https://etherscan.io/address/0xAa54d89A2B420F286Db0C19732D07abe08E6b442) (EOA 26), [0xB2e53dcb84dc869E3bA61911a170B53eE1326184](https://etherscan.io/address/0xB2e53dcb84dc869E3bA61911a170B53eE1326184) (EOA 27), [0xb4A20D473e8C378aE742a8017DD67756a358eAB6](https://etherscan.io/address/0xb4A20D473e8C378aE742a8017DD67756a358eAB6) (EOA 28), [0xbD9f4fdC48a9A8c7eA1075CFDf4F3bd365d50Bab](https://etherscan.io/address/0xbD9f4fdC48a9A8c7eA1075CFDf4F3bd365d50Bab) (EOA 30), [0xbfd62b7915da8c19C701FD13237b555Ad38C4b4C](https://etherscan.io/address/0xbfd62b7915da8c19C701FD13237b555Ad38C4b4C) (EOA 31), [0xC412B4e6399F694CfF21D038d225373Fd6596811](https://etherscan.io/address/0xC412B4e6399F694CfF21D038d225373Fd6596811) (EOA 32), [0xC4db900F76293042349448D1Ba30F71518325Bb3](https://etherscan.io/address/0xC4db900F76293042349448D1Ba30F71518325Bb3) (EOA 33), [0xc8F7DaeF4b49c1593cC3996aB2afa8B56e00fcF8](https://etherscan.io/address/0xc8F7DaeF4b49c1593cC3996aB2afa8B56e00fcF8) (EOA 34), [0xcA00091a35d0b546A15d000F8bCeDA56255EE4D0](https://etherscan.io/address/0xcA00091a35d0b546A15d000F8bCeDA56255EE4D0) (EOA 35), [0xd11f9c4F5d9b1feC2d14581d3674066442B68772](https://etherscan.io/address/0xd11f9c4F5d9b1feC2d14581d3674066442B68772) (EOA 36), [0xDF063FAEb46de1b4336bC70Da7175f16aB4A7272](https://etherscan.io/address/0xDF063FAEb46de1b4336bC70Da7175f16aB4A7272) (EOA 37), [0xE48eA86dCdE15E28624E5De9d6D3738fc52B6bFe](https://etherscan.io/address/0xE48eA86dCdE15E28624E5De9d6D3738fc52B6bFe) (EOA 38), [0xF2FF0509520fAf35B511074466A509e00d73C307](https://etherscan.io/address/0xF2FF0509520fAf35B511074466A509e00d73C307) (EOA 40), [0xf50A81C771AD3237aeA2FD18E4ee8055CC4Cd2B9](https://etherscan.io/address/0xf50A81C771AD3237aeA2FD18E4ee8055CC4Cd2B9) (EOA 41), [0xF6Ee30269dB1854987cA6812E1ff66c3A5F660Fd](https://etherscan.io/address/0xF6Ee30269dB1854987cA6812E1ff66c3A5F660Fd) (EOA 42) * Can interact with Rollup * Allowed to challenge or delete state roots proposed by a Proposer ##### 3 EOAs Addresses: [0x34E387B37d3ADEAa6D5B92cE30dE3af3DCa39796](https://etherscan.io/address/0x34E387B37d3ADEAa6D5B92cE30dE3af3DCa39796) (EOA 7), [0x6aB0E960911b50f6d14f249782ac12EC3E7584A0](https://etherscan.io/address/0x6aB0E960911b50f6d14f249782ac12EC3E7584A0) (EOA 12), [0xBBA36CdF020788f0D08D5688c0Bee3fb30ce1C80](https://etherscan.io/address/0xBBA36CdF020788f0D08D5688c0Bee3fb30ce1C80) (EOA 29) * Can interact with L1Staking * Stakers relayed to the L2 Staking contract as the L2 sequencer set. This does not authorize committing batches or proposing state roots on L1, which the Submitter contract controls * Can interact with Submitter * Actors allowed to commit transaction batches and propose and prove state roots while staked at or above the minimum ##### 2 EOAs Addresses: [0x76F91869161dC4348230D5F60883Dd17462035f4](https://etherscan.io/address/0x76F91869161dC4348230D5F60883Dd17462035f4) (EOA 17), [0xf0e11a8EA095Cc915f5a7e420928d396ed1Bb7e4](https://etherscan.io/address/0xf0e11a8EA095Cc915f5a7e420928d396ed1Bb7e4) (EOA 39) * Can interact with L1Staking * Stakers relayed to the L2 Staking contract as the L2 sequencer set. This does not authorize committing batches or proposing state roots on L1, which the Submitter contract controls ## Smart contracts ### Ethereum #### L1ETHGateway Addresses: [0x1C1Ffb5828c3A48B54E8910F1c75256a498aDE68](https://etherscan.io/address/0x1C1Ffb5828c3A48B54E8910F1c75256a498aDE68#code), [0x63eeCb6bE6087B094c2CBAA34f2902593eAE979c](https://etherscan.io/address/0x63eeCb6bE6087B094c2CBAA34f2902593eAE979c#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to bridge ETH from L1 to L2. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### L1USDCGateway Addresses: [0x2C8314f5AADa5D7a9D32eeFebFc43aCCAbe1b289](https://etherscan.io/address/0x2C8314f5AADa5D7a9D32eeFebFc43aCCAbe1b289#code), [0xB409E42e8284244F56edf9cB24b2A1f227DC3cE0](https://etherscan.io/address/0xB409E42e8284244F56edf9cB24b2A1f227DC3cE0#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to bridge USDC tokens from L1 to L2. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### ProxyAdmin Addresses: [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) * Roles: * **owner**: TimelockController #### L1MessageQueueWithGasPriceOracle Addresses: [0x3931Ade842F5BB8763164bDd81E5361DcE6cC1EF](https://etherscan.io/address/0x3931Ade842F5BB8763164bDd81E5361DcE6cC1EF#code), [0xf3b7724334cb0aDBC49CAC90e166Af99C07Be6aa](https://etherscan.io/address/0xf3b7724334cb0aDBC49CAC90e166Af99C07Be6aa#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contains the array of queued L1 -> L2 messages, either appended using the L1Messenger or the EnforcedTxGateway. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **owner**: Morph Multisig 2 Can be upgraded by: Morph Multisig 1 with no delay #### L1StandardERC20Gateway Addresses: [0x44c28f61A5C2Dd24Fc71D7Df8E85e18af4ab2Bd8](https://etherscan.io/address/0x44c28f61A5C2Dd24Fc71D7Df8E85e18af4ab2Bd8#code), [0x75BC012fA81DF052baFc4EF9255Af29B6C4e5301](https://etherscan.io/address/0x75BC012fA81DF052baFc4EF9255Af29B6C4e5301#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to bridge ERC20 tokens from L1 to L2. It uses a fixed token list. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### TimelockController Addresses: [0x542675E90E269F20ecbb9e0095d4751ac155B530](https://etherscan.io/address/0x542675E90E269F20ecbb9e0095d4751ac155B530#code), [0x5F0CAaf0d3b8dd8eA9f80CDbb0021930d3c17353](https://etherscan.io/address/0x5F0CAaf0d3b8dd8eA9f80CDbb0021930d3c17353#code) (Implementation (Upgradable)), [0x8654061457582c867B77A3a9f4ca714dFc84Ec17](https://etherscan.io/address/0x8654061457582c867B77A3a9f4ca714dFc84Ec17#code) (Admin) A timelock with access control. The current minimum delay is 0s. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **canceller**: Morph Multisig 2 * **defaultAdmin**: Morph Multisig 1, TimelockController; ultimately Morph Multisig 1 * **executor**: Morph Multisig 1 * **proposer**: Morph Multisig 2 Can be upgraded by: Morph Multisig 1 with no delay #### MultipleVersionRollupVerifier Addresses: [0x5d1584c27b4aD233283c6da1ca1B825d6f220EC1](https://etherscan.io/address/0x5d1584c27b4aD233283c6da1ca1B825d6f220EC1#code) Used to update the verifier and keep track of current and old versions. Routes to a registered verifier by batch index, so that every batch is verified by the latest verifier that is enabled for this batch. * Roles: * **owner**: Morph Multisig 1 #### ZkEvmVerifierV1 Addresses: [0x651cA600813fC0126225b727EDbA617949b1d1c9](https://etherscan.io/address/0x651cA600813fC0126225b727EDbA617949b1d1c9#code), [0x9774CE99E8Ab3f13582bC6c2Bd2832e5A25C4624](https://etherscan.io/address/0x9774CE99E8Ab3f13582bC6c2Bd2832e5A25C4624#code) A snark verifier based on SP1 by Succinct. It verifies RISC-V execution in a PLONK proof. Used to verify the validity of L2 state transitions for single round fraud proofs. #### L1GatewayRouter Addresses: [0x7497756ADA7e656aE9f00781aF49Fc0fD08f8A8a](https://etherscan.io/address/0x7497756ADA7e656aE9f00781aF49Fc0fD08f8A8a#code), [0x6D9623d44C4A1629815D9d6236FF25C4f82Cc819](https://etherscan.io/address/0x6D9623d44C4A1629815D9d6236FF25C4f82Cc819#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Main entrypoint for depositing ETH and ERC20 tokens, which are then forwarded to the correct escrow. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **owner**: Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### Rollup Addresses: [0x759894Ced0e6af42c26668076Ffa84d02E3CeF60](https://etherscan.io/address/0x759894Ced0e6af42c26668076Ffa84d02E3CeF60#code), [0x213CE22b487B71Ac68a1B5b12d2b93D1AF30Ea1d](https://etherscan.io/address/0x213CE22b487B71Ac68a1B5b12d2b93D1AF30Ea1d#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) The main contract of the Morph rollup. Allows to post transaction data and state roots and implements the proof system. Sequencing and proposing are permissioned to the active submitters registered and staked in the Submitter contract. If the EnforcedTxGateway is not paused, any submitter must include at least one L1 -> L2 message in their proposal if the oldest message is > 7d old. If the submitters are censoring or down for more than 7d, users can permissionlessly propose and prove via `commitBatchWithProof()`. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **challengers**: EOA 1, EOA 10, EOA 11, EOA 13, EOA 14, EOA 15, EOA 16, EOA 18, EOA 19, EOA 2, EOA 20, EOA 21, EOA 22, EOA 23, EOA 24, EOA 25, EOA 26, EOA 27, EOA 28, EOA 3, EOA 30, EOA 31, EOA 32, EOA 33, EOA 34, EOA 35, EOA 36, EOA 37, EOA 38, EOA 4, EOA 40, EOA 41, EOA 42, EOA 5, EOA 6, EOA 8, EOA 9, Morph Multisig 2 * **owner**: Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### ProxyAdmin Addresses: [0x8654061457582c867B77A3a9f4ca714dFc84Ec17](https://etherscan.io/address/0x8654061457582c867B77A3a9f4ca714dFc84Ec17#code) * Roles: * **owner**: Morph Multisig 1 #### L1CustomERC20Gateway Addresses: [0xA534BAdd09b4C62B7B1C32C41dF310AA17b52ef1](https://etherscan.io/address/0xA534BAdd09b4C62B7B1C32C41dF310AA17b52ef1#code), [0x833cfC8cFbc77365bD184025AdFD2fe01112b0Dc](https://etherscan.io/address/0x833cfC8cFbc77365bD184025AdFD2fe01112b0Dc#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to bridge ERC20 tokens with custom L2 representations from L1 to L2. It allows to change the token mappings. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### EnforcedTxGateway Addresses: [0xc5Fa3b8968c7FAbEeA2B530a20b88d0C2eD8abb7](https://etherscan.io/address/0xc5Fa3b8968c7FAbEeA2B530a20b88d0C2eD8abb7#code), [0xCb13746Fc891fC2e7D824870D00a26F43fE6123e](https://etherscan.io/address/0xCb13746Fc891fC2e7D824870D00a26F43fE6123e#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contracts to force L1 -> L2 messages with the L1 sender. Currently paused: false. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **owner**: Morph Multisig 2 Can be upgraded by: Morph Multisig 1 with no delay #### L1USDCGatewayLegacy Addresses: [0xc9045350712A1DCC3A74Eca18Bc985424Bbe7535](https://etherscan.io/address/0xc9045350712A1DCC3A74Eca18Bc985424Bbe7535#code), [0xe11DeE885e5D38e4dc477219F50a6B1cF5DC298a](https://etherscan.io/address/0xe11DeE885e5D38e4dc477219F50a6B1cF5DC298a#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to bridge USDC tokens from L1 to L2. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### L1CrossDomainMessenger Addresses: [0xDc71366EFFA760804DCFC3EDF87fa2A6f1623304](https://etherscan.io/address/0xDc71366EFFA760804DCFC3EDF87fa2A6f1623304#code), [0x0cC37d5239F9027A1269f53D83c73084D538f3a9](https://etherscan.io/address/0x0cC37d5239F9027A1269f53D83c73084D538f3a9#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Contract used to send L1 -> L2 and relay messages from L2. It allows to replay failed messages and to drop skipped messages. L1 -> L2 messages sent using this contract pay for L2 gas on L1 and will have the aliased address of this contract as the sender. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **owner**: Morph Multisig 1 Can be upgraded by: Morph Multisig 1 with no delay #### Submitter Addresses: [0xf2d50000C994565A4742059802fdbb0BEE1CBef6](https://etherscan.io/address/0xf2d50000C994565A4742059802fdbb0BEE1CBef6#code), [0x3c5C88F69B190a1c497996AfEDb1a6591b0dF576](https://etherscan.io/address/0x3c5C88F69B190a1c497996AfEDb1a6591b0dF576#code) (Implementation (Upgradable)), [0x31110622D6CA24c9FF307d6ae1715F16E47F16A0](https://etherscan.io/address/0x31110622D6CA24c9FF307d6ae1715F16E47F16A0#code) (Admin) Registry and ETH staking contract for the accounts allowed to commit transaction batches and propose state roots to the Rollup. The owner whitelists submitters, who are active only while registered, not withdrawing and staked at or above the minimum. When a submitter's batch is successfully challenged, the Rollup slashes the submitter's whole stake through this contract: the configured reward share is forwarded to the Rollup for the challenger and the remainder accrues to the owner. Stake withdrawals are claimable only once the batch committed at withdrawal time is finalized. * Roles: * **admin**: ProxyAdmin; ultimately Morph Multisig 1 * **owner**: Morph Multisig 1 * **submitters**: EOA 12, EOA 29, EOA 7 Can be upgraded by: Morph Multisig 1 with no delay #### Whitelist Addresses: [0xFFafDd9167777C0e5421e0B6789D6d7A5E386984](https://etherscan.io/address/0xFFafDd9167777C0e5421e0B6789D6d7A5E386984#code) Generic whitelist. Currently used to whitelist addresses that can send or relay messages to/from L2 without paying for L2 gas. * Roles: * **owner**: Morph Multisig 2 * **whitelisted**: L1Staking The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).