# OMG Network Markdown version of https://l2beat.com/layer2s/projects/omgnetwork ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $57.21 K (-3.15% compared to seven days ago; canonically bridged $57.21 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Type: Plasma - Purpose: Payments - Host chain: Ethereum ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Exits only (sentiment: bad) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Use escape hatch (sentiment: good) ### About OMG Network claims to be the leading value transfer network for ETH and ERC20 tokens. The Network scales by centralizing transaction processing and remains safe by decentralizing security. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/omgnetwork#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/omgnetwork) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/omgnetwork/breakdown) ## Risk summary **Warning:** 2 addresses have unverified source code (CRITICAL). - ETHDepositVerifier: 0x649f37203c365DE759c8fc8CA35beBF5448F70Be - ERC20DepositVerifier: 0xD876aeb3a443FBC03B7349AAc115E9054563CD82 ### Funds can be stolen if 1. users are unable to withdraw in a mass exit event, 2. the source code of unverified contracts contains malicious code, (CRITICAL) 3. there are fraudulent exits which nobody reported. Fraud proofs assume that every exit is checked by at least one honest and able party (CRITICAL). ### Funds can be lost if 4. the external data becomes unavailable (CRITICAL). ### Users can be censored if 5. the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ### MEV can be extracted if 6. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for , users can use the exit hatch to withdraw their funds. ### State validation Exits only (sentiment: bad) Exits from the network are subject to a period when they can be challenged. The internal network state is left unchecked. ### Data availability External (sentiment: bad) Proof construction and state derivation rely fully on data that is NOT published onchain. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Use escape hatch (sentiment: good) Users are able to trustlessly exit by submitting a Merkle proof of funds. The details are unknown. ## Data availability ### Data is not stored on chain **Note:** This section requires more research and might not present accurate information. The transaction data is stored on a plasma chain and is not recorded on the Ethereum main chain. **Risks** - Funds can be lost if the external data becomes unavailable (CRITICAL). ## State validation ### Fraud proofs The internal system state is not subject to any checks. Only exits from the system can be challenged. This places a much higher burden on potential validators, as they have to monitor all user activity and not only the single state. **Risks** - Funds can be stolen if there are fraudulent exits which nobody reported. Fraud proofs assume that every exit is checked by at least one honest and able party (CRITICAL). ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/omgnetwork#updates). ## Operator ### The system has a centralized operator **Note:** This section requires more research and might not present accurate information. The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can independently exit the system **Note:** This section requires more research and might not present accurate information. Independent exit allows the users to escape censorship by withdrawing their funds. The system allows users to withdraw their funds by submitting a transaction directly to the contract onchain. **Risks** - Users can be censored if the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ## Withdrawals ### Regular exit **Note:** This section requires more research and might not present accurate information. The user executes the withdrawal by submitting a transaction on L1 that requires a merkle proof of funds. ### The mass exit problem is unsolved **Note:** This section requires more research and might not present accurate information. In case the operator is malicious all users need to exit within a predetermined time frame. Users that do not manage to do this will lose their funds. **Risks** - Funds can be stolen if users are unable to withdraw in a mass exit event. ## Smart contracts ### Ethereum #### EthVault Addresses: [0x3Eed23eA148D356a72CA695DBCe2fceb40a32ce0](https://etherscan.io/address/0x3Eed23eA148D356a72CA695DBCe2fceb40a32ce0#code) #### Erc20Vault Addresses: [0x070cB1270A4B2bA53c81CeF89d0FD584Ed4F430B](https://etherscan.io/address/0x070cB1270A4B2bA53c81CeF89d0FD584Ed4F430B#code) #### ETHDepositVerifier Addresses: [0x649f37203c365DE759c8fc8CA35beBF5448F70Be](https://etherscan.io/address/0x649f37203c365DE759c8fc8CA35beBF5448F70Be#code) (unverified) The source code of this contract is not verified on Etherscan. #### ERC20DepositVerifier Addresses: [0xD876aeb3a443FBC03B7349AAc115E9054563CD82](https://etherscan.io/address/0xD876aeb3a443FBC03B7349AAc115E9054563CD82#code) (unverified) The source code of this contract is not verified on Etherscan. #### PlasmaFramework Addresses: [0x0D4C1222f5e839a911e2053860e45F18921D72ac](https://etherscan.io/address/0x0D4C1222f5e839a911e2053860e45F18921D72ac#code) #### PaymentExitGame Addresses: [0x48d7A6bbc428bca019A560cF3e8EA5364395Aad3](https://etherscan.io/address/0x48d7A6bbc428bca019A560cF3e8EA5364395Aad3#code) The source code of the PaymentStartStandardExit library used by this contract is not verified on Etherscan. The current deployment carries some associated risks: - Funds can be stolen if the source code of unverified contracts contains malicious code (CRITICAL).