Search

Search for projects by name or address

Scroll logo
Scroll

Badges

About

Scroll is ZK Rollup that extends Ethereum’s capabilities through ZK tech and EVM compatibility.



Badges

About

Scroll is ZK Rollup that extends Ethereum’s capabilities through ZK tech and EVM compatibility.


Total
Canonically BridgedCanonically Bridged ValueCanonical
Natively MintedNatively Minted TokensNative
Externally BridgedExternally Bridged ValueExternal

ETH & derivatives
Stablecoins
BTC & derivatives
Other
Compare with other projects
Past Day UOPS
Past Day Ops count
Max. UOPS
Past day UOPS/TPS Ratio
Compare with other projects

The section shows the operating costs that L2s pay to Ethereum.



Total cost
Avg cost per L2 UOP
Avg cost per day

Compare with other projects

This section shows how much data the project publishes to its data-availability (DA) layer over time. The project currently posts data toEthereumEthereum.



Data posted
Avg size per day
Avg size per L2 UOP

Compare with other projects

This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule.

No ongoing anomalies detected

Avg. tx data subs. interval
Avg. proof subs. interval
Avg. state updates interval
Past 30 days anomalies
100% normal uptime

Security Council removal

2026 Jun 1st

Independent 9-of-12 Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. replaced by a 3-of-4 team admin multisig; drops to Stage 0.

Learn more

Emergency verifier upgrade

2026 Feb 23rd

Emergency verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover. replacement due to a bug in the guest proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract. program.

Learn more
Sequencer failureState validationData availabilityExit windowProposer failure
Sequencer failure
Self sequence

In the event of a sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. failure, users can force transactions to be included in the project’s chain by sending them to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. There can be up to a 7d delay on this operation. Proposing new blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. requires creating ZK proofs.

State validation
Validity proofs (ST, SN)

STARKs and SNARKs are zero knowledge proofs that ensure state correctness. STARKs proofs are wrapped in SNARKs proofs for efficiency. SNARKs require a trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits..

Data availability
Onchain

All of the data needed for proof construction is published on Ethereum L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

Exit window
None

There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable.

Proposer failure
Self propose

If the ProposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. fails, users can leverage the source available proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract. to submit proofs to the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge..

Scroll
Scroll is a
Stage 0
ZK Rollup.

Learn more about Stages
Please keep in mind that these stages do not reflect project security, this is an opinionated assessment of project maturity based on subjective criteria, created with a goal of incentivizing projects to push toward better decentralization. Each team may have taken different paths to achieve this goal.

All data required for proofs is published on chain

All the data that is used to construct the system state is published on chain in the form of cheap blobsThe data that a rollup publishes to its L1/data availability (DA) layer. They consist of the L2 transactions that are rolled up, along with some metadata. Blobs are introduced as a new transaction type within Ethereum with EIP-4844, and has rollup scaling specifically in mind. Blobs persist on Ethereum’s Beacon Chain ephemerally. or calldata. This ensures that it will be available for enough time.

  1. ScrollChain.sol - Etherscan source code commitBatches() function
Learn more about the DA layer here: Ethereum logoEthereum
Node software

The nodeA software client that participates in the network. software to reconstruct the state is available here. Note that it uses the L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. p2p networkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. to fetch blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over., and not the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. network. The consistency with L1 data can be checked by running the scroll-geth node with the --rollup.verify flag.

Compression scheme

Data batches are compressed using the zstd algorithm.

Genesis state

The genesis file can be found here, which contains two prefunded addresses and five predeployed contracts.

Data format

BlocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. are grouped into chunks, chunks are grouped into batches, and batches are grouped into bundles. Chunk encoding format can be found here, and batch encoding format can be found here.

Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract.


Prover Architecture

The proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract. code can be found here.

ZK Circuits

Scroll circuits are OpenVM-based Guest Programs that use the OpenVM proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract.. The source code of the base circuits can be found here.

Verification Keys Generation

SNARKShort for "succinct non-interactive argument of knowledge", a SNARK is a widely used type of zero-knowledge proof that is short and fast to verify. Different kinds of SNARKs are usually systematized by proof size, verification time, and type of setup. The most famous SNARKs are Groth16, PLONK/Marlin, Bulletproofs, and STARKs. verification keys can be generated and checked against Ethereum verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover. contract using this guide. The system requires a trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits..

Validity proofs

Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract.

  1. ScrollChain.sol - Etherscan source code, verifyAggregateProof() and verifyBundleProof() calls
PROVER

Trusted Setups

Program Hashes

Name
Hash
Repository
Verification
Used in
0x003a...bf72
Scroll logo
0x0093...7909
Scroll logo
0x0062...d297
Scroll logo
0x0039...9269
Scroll logo
0x0021...3d67
Scroll logo

All core contracts in the Scroll protocol are upgradable by the ProxyAdmin, which is controlled by the ScrollAdminMultisig through the ScrollOwner contract. The ScrollOwner is a central governance contract controlled by four distinct Timelocks: two governed by the ScrollAdminMultisig and two by the Scroll team multisigs. Each multisig can initiate specific types of changes with differing delay guarantees. On 2026-06-01, Scroll removed its independent 9-of-12 Security CouncilA Security Council is a sufficiently decentralized set of members that is able to upgrade a system. A properly set up Security Council consists of at least 8 members with a threshold greater than 75%. What 'sufficiently decentralized' means is fundamentally subjective and L2BEAT evaluates each case individually. A Security Council is allowed to instantly upgrade Stage 1 rollups. and transferred its roles on the TimelockSCSlow (3d execution delay) and TimelockSCEmergency (No execution delay) on both chains to the ScrollAdminMultisig, along with admin of the L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. AgoraGovernor. Emergency pause of core contracts is managed through the PauseController, which allows the team to pause batch commitment and finalization in permissioned mode, as well as L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.->L2 messaging. Each pause is subject to a cooldown period of 1mo execution delay, during which the ScrollAdminMultisig can unpause. SCR token holders perform onchain voting on governance proposals through the AgoraGovernor contract on L2. However, onchain governance proposals do not contain transaction payloads, so onchain voting only acts as an onchain temperature check.

Past upgrades

The metrics include upgrades on the currently used proxy contracts. Historical proxy contracts and changes of such are not included.

Count of upgrades
42
Last upgrade
7mo 25d ago
Avg upgrade interval
12mo 3d
2026 September 18, 09:30 UTC
14changes

Review active Scroll v10 verifier at the main-branch block.

New and verified contracts

+ Status: CREATED
contract GnosisSafeL2 (eth:0x11cd09a0c5B1dc674615783b0772a9bFD53e3A8F) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Safe (eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Scroll Security Council Minority (eth:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Safe (eth:0x69C2eD64171bF5737c2B78bdF722e68a032B2825) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Safe (eth:0x8edC4EADEE120d4C51923c515e7C3241c815C2BC) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Safe (eth:0x9479ABfebefEea3c846163012a472b44F305b3d7) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Safe (eth:0xC3eA7C657884BB380B66D79C36aDCb5658b01896) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract GnosisSafeL2 (scr:0x11cd09a0c5B1dc674615783b0772a9bFD53e3A8F) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract SafeL2 (scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract Scroll Security Council Minority (scr:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract SafeL2 (scr:0x69C2eD64171bF5737c2B78bdF722e68a032B2825) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract SafeL2 (scr:0x8edC4EADEE120d4C51923c515e7C3241c815C2BC) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract SafeL2 (scr:0x9479ABfebefEea3c846163012a472b44F305b3d7) [GnosisSafe]
+++ description: None
+ Status: CREATED
contract SafeL2 (scr:0xC3eA7C657884BB380B66D79C36aDCb5658b01896) [GnosisSafe]
+++ description: None
2026 June 26, 10:26 UTC
3changes

Marked verifier contract as source-verified since its bytecode was successfully reproduced in zk catalog.

New and verified contracts

contract PlonkVerifierFeynmanV2 (eth:0x96cbcC4333E172927fDa8B631C716d43E2FBA01C) [N/A] {
+++ description: None
unverified:
- true
sourceHashes:
+ ["0x0ffd802e46395eb0f9e68316cd3afa259549980515f4922777333fc64f675834"]
references:
+ [{"text":"Source Code","href":"https://l2beat.com/zk-catalog/openvmprover#verifiers"}]
}
2026 June 26, 10:26 UTC
4changes

OpenVM upgraded to 1.6.0: https://forum.scroll.io/t/announcement-openvm-v1-6-0-upgrade-on-scroll/1482. Programs are reproduced, the verifier is not yet regenerated.

- Status: DELETED
contract ZkEvmVerifierPostFeynman (eth:0x0dE180164Dc571522457101F5c47B2eaB36d0A82) [N/A]
+++ description: None
contract MultipleVersionRollupVerifier (eth:0x4CEA3E866e7c57fD75CB0CA3E9F5f1151D4Ead3F) [scroll/MultipleVersionRollupVerifier] {
+++ description: Contract used to update the verifier and keep track of current and old versions.
values.latestVerifier.9.verifier:
- "eth:0x0dE180164Dc571522457101F5c47B2eaB36d0A82"
+ "eth:0x808297224e86b1a6055B5F790a2cE07Ed611f955"
}
+ Status: CREATED
contract ZkEvmVerifierPostFeynman (eth:0x808297224e86b1a6055B5F790a2cE07Ed611f955) [N/A]
+++ description: None
+ Status: CREATED
contract PlonkVerifierFeynmanV2 (eth:0x96cbcC4333E172927fDa8B631C716d43E2FBA01C) [N/A]
+++ description: None
2026 June 16, 12:32 UTC
17changes

Final Security Council removal transaction. ScrollAdminMultisig now controls the scMinorityNoDelay path (used to unpause core contracts via the PauseController), completing the Security Council removal.

- Status: DELETED
contract GnosisSafeL2 (eth:0x11cd09a0c5B1dc674615783b0772a9bFD53e3A8F) [GnosisSafe]
+++ description: None
- Status: DELETED
contract Scroll Security Council Minority (eth:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE) [GnosisSafe]
+++ description: None
- Status: DELETED
EOA (eth:0x498C0c17e26EEEC63375A4A20Ba8A91Aa357CbcD)
+++ description: None
- Status: DELETED
contract Safe (eth:0x69C2eD64171bF5737c2B78bdF722e68a032B2825) [GnosisSafe]
+++ description: None
contract ScrollOwner (eth:0x798576400F7D662961BA15C6b3F3d813447a26a6) [scroll/ScrollOwner] {
+++ description: Owner of all contracts in the system. It implements an extension of AccessControl that manages roles and functions allowed to be called by each role.
values.accessControl.roles.SECURITY_COUNCIL_MINORITY_NO_DELAY_ROLE.members.0:
- "eth:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.scMinorityNoDelay.0:
- "eth:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
- Status: DELETED
contract Safe (eth:0x8edC4EADEE120d4C51923c515e7C3241c815C2BC) [GnosisSafe]
+++ description: None
- Status: DELETED
contract Safe (eth:0x9479ABfebefEea3c846163012a472b44F305b3d7) [GnosisSafe]
+++ description: None
- Status: DELETED
contract Safe (eth:0xC3eA7C657884BB380B66D79C36aDCb5658b01896) [GnosisSafe]
+++ description: None
contract ScrollAdminMultisig (eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761) [GnosisSafe] {
+++ description: Multisig of Scroll team operators that controls the rollup's upgrade and proof-system parameter paths.
receivedPermissions.11:
+ {"permission":"interact","from":"eth:0x798576400F7D662961BA15C6b3F3d813447a26a6","description":"unpause core contracts via the PauseController.","role":".scMinorityNoDelay"}
}
- Status: DELETED
contract GnosisSafeL2 (scr:0x11cd09a0c5B1dc674615783b0772a9bFD53e3A8F) [GnosisSafe]
+++ description: None
contract ScrollOwner (scr:0x13D24a7Ff6F5ec5ff0e9C40Fc3B8C9c01c65437B) [scroll/ScrollOwnerL2] {
+++ description: Owner of all contracts in the system. It implements an extension of AccessControl that manages roles and functions allowed to be called by each role.
values.accessControl.roles.SECURITY_COUNCIL_MINORITY_NO_DELAY_ROLE.members.0:
- "scr:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
- Status: DELETED
contract Scroll Security Council Minority (scr:0x40bD67b02EBf1CFB4AdA7F60CabAc94d6aafc6eE) [GnosisSafe]
+++ description: None
- Status: DELETED
contract SafeL2 (scr:0x69C2eD64171bF5737c2B78bdF722e68a032B2825) [GnosisSafe]
+++ description: None
- Status: DELETED
contract SafeL2 (scr:0x8edC4EADEE120d4C51923c515e7C3241c815C2BC) [GnosisSafe]
+++ description: None
- Status: DELETED
contract SafeL2 (scr:0x9479ABfebefEea3c846163012a472b44F305b3d7) [GnosisSafe]
+++ description: None
- Status: DELETED
contract SafeL2 (scr:0xC3eA7C657884BB380B66D79C36aDCb5658b01896) [GnosisSafe]
+++ description: None
2026 June 05, 10:11 UTC
High severity
51changes

Security Council removal. On 2026-06-01, Scroll executed a multiSend transaction replacing its independent 9-of-12 Security Council ( eth:0x1a37bF… / scr:0x1a37bF… ) with the 3-of-4 ScrollAdminMultisig ( 0xcca54B0916Cee2186b47E9709BEdcb7041A8F761 ). This upgrade moves the chain to Stage 0. - L1 execution tx: 0xbc6079d5…b373765 (2026-06-01T12:36:23Z) - L2 execution tx: 0x7278f818…14b62bd (2026-06-01T12:42:30Z) - Forum announcement (2026-04-13): Governance Update: Security Council Transition All Security Council permissions ( TIMELOCK ADMIN ROLE , PROPOSER ROLE , EXECUTOR ROLE , CANCELLER ROLE on TimelockSCSlow and TimelockSCEmergency on both chains, plus L2 AgoraGovernor.admin ) transferred to ScrollAdminMultisig . Pre-existing co-holders ( Scroll Multisig 1 , AgoraGovernor on L2 slow) are unchanged. Still pending (queued in TimelockSCSlow, 3-day). A batch was scheduled to transfer SECURITY COUNCIL MINORITY NO DELAY ROLE on ScrollOwner away from the independent 3/12 Scroll Security Council Minority to ScrollAdminMultisig . Not yet executed in this discovery snapshot.

contract TimelockSCEmergency (eth:0x0CD4c0F24a0A9f3E2Fe80ed385D8AD5a2FfECA44) [scroll/L1Timelock] {
+++ description: A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.
values.accessControl.TIMELOCK_ADMIN_ROLE.members.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.PROPOSER_ROLE.members.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.EXECUTOR_ROLE.members.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.CANCELLER_ROLE.members.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Canceller.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Proposer.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.timelockAdminAC.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
contract GnosisSafeL2 (eth:0x11cd09a0c5B1dc674615783b0772a9bFD53e3A8F) [GnosisSafe] {
+++ description: None
values.$members.1:
- "eth:0x7742637569CE1dd9AA9F4F91EaAc7c028C5e1f4d"
values.$members.2:
- "eth:0xbB2491beFBd46CF26F7e9B9Dec16E0c31f9c5ae3"
values.$members.6:
- "eth:0x9106372987a14400F283bc1AfC122A57130c18a3"
values.$members.7:
- "eth:0xDD659911EcBD4458db07Ee7cDdeC79bf8F859AbC"
values.$members.9:
- "eth:0xa28b7D23e9F8D8d5346A7901ecC9eC8ea48bAEcD"
values.$members.11:
- "eth:0x32E8B0B9783d65170fd37f79079d5707107cCc62"
values.multisigThreshold:
- "2 of 12 (17%)"
+ "2 of 6 (33%)"
}
- Status: DELETED
contract Safe (eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD) [GnosisSafe]
+++ description: None
contract TimelockSCSlow (eth:0x3f9041350B661c74C6CbE440c8Bd6BC4C168a9fd) [scroll/L1Timelock] {
+++ description: A timelock with access control. The current minimum delay is 3d. Proposals that passed their minimum delay can be executed by anyone.
values.accessControl.TIMELOCK_ADMIN_ROLE.members.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.PROPOSER_ROLE.members.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.EXECUTOR_ROLE.members.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
values.accessControl.EXECUTOR_ROLE.members.1:
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.CANCELLER_ROLE.members.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Canceller.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.1:
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Proposer.0:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.timelockAdminAC.1:
- "eth:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
EOA (eth:0x498C0c17e26EEEC63375A4A20Ba8A91Aa357CbcD) {
+++ description: None
proxyType:
- "EOA"
+ "EIP7702 EOA"
sourceHashes:
+ ["0x1f44812af62d28f019e30e8eb2af596fb36c7db9d34576972c0405e110a6ef45"]
values:
+ {"$implementation":"eth:0x63c0c19a282a1B52b07dD5a65b58948A07DAE32B","delegationManager":"eth:0xdb9B1e94B5b69Df7e401DDbedE43491141047dB3","DOMAIN_VERSION":"1","eip712Domain":{"fields":"0x0f","name":"EIP7702StatelessDeleGator","version":"1","chainId":1,"verifyingContract":"eth:0x498C0c17e26EEEC63375A4A20Ba8A91Aa357CbcD","salt":"0x0000000000000000000000000000000000000000000000000000000000000000","extensions":[]},"entryPoint":"eth:0x0000000071727De22E5E9d8BAf0edAc6f37da032","getDeposit":0,"getDomainHash":"0xe8c593be46a5ed8888fb0c3e5e73bf758d388267b7f243139256b041295bf293","getNonce":0,"NAME":"EIP7702StatelessDeleGator","PACKED_USER_OP_TYPEHASH":"0xbc37962d8bd1d319c95199bdfda6d3f92baa8903a61b32d5f4ec1f4b36a3bc18","VERSION":"1.3.0"}
}
- Status: DELETED
contract SafeL2 (scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD) [GnosisSafe]
+++ description: None
contract TimelockSCEmergencyScroll (scr:0x1f807E2E8ab2e61230a0A9C271F90242831278b4) [scroll/L1Timelock] {
+++ description: A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.
values.accessControl.TIMELOCK_ADMIN_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.PROPOSER_ROLE.members.0:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.EXECUTOR_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.CANCELLER_ROLE.members.0:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Canceller.0:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Proposer.0:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.timelockAdminAC.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
contract AgoraGovernor (scr:0x2f3F2054776bd3C2fc30d750734A8F539Bb214f0) [N/A] {
+++ description: Used to propose and manage onchain governance proposals.
values.admin:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
contract TimelockSCSlow (scr:0x79D83D1518e2eAA64cdc0631df01b06e2762CC14) [scroll/L1Timelock] {
+++ description: A timelock with access control. The current minimum delay is 3d. Proposals that passed their minimum delay can be executed by anyone.
values.accessControl.TIMELOCK_ADMIN_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.PROPOSER_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.EXECUTOR_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
values.accessControl.EXECUTOR_ROLE.members.2:
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.accessControl.CANCELLER_ROLE.members.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Canceller.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+++ description: Executing proposals is only open to all addresses if this resolves to the 0x0 address
+++ severity: HIGH
values.Executor.2:
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.Proposer.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
values.timelockAdminAC.1:
- "scr:0x1a37bF1Ccbf570C92FE2239FefaaAF861c2924DD"
+ "scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761"
}
+ Status: CREATED
contract ScrollAdminMultisig (eth:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761) [GnosisSafe]
+++ description: Multisig of Scroll team operators that controls the rollup's upgrade and proof-system parameter paths.
+ Status: CREATED
contract ScrollAdminMultisig (scr:0xcca54B0916Cee2186b47E9709BEdcb7041A8F761) [GnosisSafe]
+++ description: L2 counterpart of ScrollAdminMultisig.

The system has a centralized sequencer

While forcing transaction is open to anyone the system employs a privileged sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. that has priority for submitting transaction batches and ordering transactions.

  • MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.

  1. ScrollChain.sol - Etherscan source code, finalizeBundlePostEuclidV2() function modifier

Users can force any transaction

Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly. The enforced livenessLiveness refers to the ability of a system to respond to requests and to process them in a timely manner. In the context of L2s, it refers to the ability of settling transactions, proofs and state roots to the base layer. mechanism is activated if either an L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. message has not been finalized for more than 7d or a batch has not been finalized for more than 7d. When activated, transactions that were directly posted to the smart contract can be forcefully included by anyone on the host chain, which finalizes their ordering.

  1. EnforcedTxGateway.sol - Etherscan source code
  2. L1MessageQueueV2 - Etherscan proxy contract

Regular messaging

The user initiates L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.->L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. messages by submitting a regular transaction on this chain. When the blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks.

  1. L1ETHGateway.sol - Etherscan source code, finalizeWithdrawETH function
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner

Ethereum

Actors:

ScrollAdminMultisig0xcca5…F761

A Multisig with 3/4 threshold. Multisig of Scroll team operators that controls the rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup.’s upgrade and proof-system parameter paths.

  • Can interact with TimelockSCEmergency
    • cancel queued transactions
    • execute transactions that are ready
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock
  • Can interact with TimelockSCSlow
    • cancel queued transactions
    • execute transactions that are ready
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock with 3d delay or with no delay
  • Can interact with ScrollOwner
    • disable enforced batch mode
    • unpause core contracts via the PauseController
    • update and reset the PauseController cooldown period
    • update ScrollChain zk proof verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover.
    • update the L1ScrollMessenger fee vault address
    • update the minimum delay message queue parameters and enforced mode parameters
    • upgrade all core contracts of the system
  1. Governance Update: Security Council Transition, Contributor Roles & Operational Adjustments (Scroll forum, 2026-04-13)
  2. L1 execution tx
Scroll Multisig 20xbdA1…0cBc

A Multisig with 2/4 threshold.

  • Can interact with ScrollOwner
    • pause the ScrollChain in permissioned mode and the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. -> L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. message queue
    • remove permissioned batchers and provers to the whitelist, and update the sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. address
    • revert unfinalized batches
  • Can interact with TimelockEmergency
    • cancel queued transactions
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock

Participants (4):

EOA 1EOA 3EOA 4EOA 2
Scroll Multisig 30xEfc9…4dbe

A Multisig with 2/4 threshold.

  • Can interact with TimelockFast
    • cancel queued transactions
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock with 1d delay or with no delay
  • Can interact with ScrollOwner
    • add permissioned batchers and provers to the whitelist with 1d delay
    • set ERC20 gateways in the L1GatewayRouter with 1d delay
Scroll Multisig 10x1FF1…236f

A Multisig with 1/4 threshold.

Participants (4):

EOA 3EOA 4EOA 1EOA 2

Member of Scroll Multisig 1, Scroll Multisig 4, Scroll Multisig 2.

  • Can interact with TimelockSCEmergency
    • execute transactions that are ready
  • Can interact with TimelockFast
    • execute transactions that are ready
  • Can interact with TimelockSCSlow
    • execute transactions that are ready
  • Can interact with TimelockEmergency
    • execute transactions that are ready

Member of Scroll Multisig 1, Scroll Multisig 4, Scroll Multisig 2, ScrollAdminMultisig, Scroll Multisig 3.

  • Can interact with TimelockSCEmergency
    • execute transactions that are ready
  • Can interact with TimelockFast
    • execute transactions that are ready
  • Can interact with TimelockSCSlow
    • execute transactions that are ready
  • Can interact with TimelockEmergency
    • execute transactions that are ready

Member of Scroll Multisig 1, Scroll Multisig 2, ScrollAdminMultisig, Scroll Multisig 3.

  • Can interact with TimelockSCEmergency
    • execute transactions that are ready
  • Can interact with TimelockFast
    • execute transactions that are ready
  • Can interact with TimelockSCSlow
    • execute transactions that are ready
  • Can interact with TimelockEmergency
    • execute transactions that are ready

Scroll

Actors:

ScrollAdminMultisig0xcca5…F761

A Multisig with 3/4 threshold. L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. counterpart of ScrollAdminMultisig.

  • Can interact with ScrollOwner
    • disable enforced batch mode
    • update ScrollChain zk proof verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover.
    • upgrade all core contracts of the system
  • Can interact with TimelockSCEmergencyScroll
    • cancel queued transactions
    • execute transactions that are ready
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock
  • Can interact with AgoraGovernor
    • can configure contract settings such as voting delay, quorum, contract manager with no delay or with 3d delay
  • Can interact with TimelockSCSlow
    • cancel queued transactions
    • execute transactions that are ready
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock with 3d delay or with no delay
  1. L2 execution tx
AgoraGovernor0x2f3F…14f0

Used to propose and manage onchain governance proposals.

  • Can interact with AgoraGovernor
    • can configure contract settings such as voting delay, quorum, contract manager with 3d delay
  • Can interact with TimelockSCSlow
    • cancel queued transactions
    • execute transactions that are ready
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock with 3d delay
Scroll Multisig 20xbdA1…0cBc

A Multisig with 2/4 threshold.

  • Can interact with TimelockEmergency
    • cancel queued transactions
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock

Participants (4):

EOA 5EOA 7EOA 8EOA 6
Scroll Multisig 30xEfc9…4dbe

A Multisig with 2/4 threshold.

  • Can interact with TimelockFast
    • cancel queued transactions
    • propose transactions
    • update the minimum delay and manage all access control roles of the timelock with 1d delay or with no delay
GnosisSafeL20x2B2A…4351

A Multisig with 2/2 threshold.

  • Can interact with AgoraGovernor
    • can propose new onchain governance proposals without the required threshold of votes

Participants (2):

0x1Da4…8f500x5585…1320
ProxyAdmin0x8e34…cE45
  • Can upgrade with no delay
    • L2LidoGateway
Scroll Multisig 10x1FF1…236f

A Multisig with 1/4 threshold.

Participants (4):

EOA 7EOA 8EOA 5EOA 6

Member of Scroll Multisig 1, Scroll Multisig 2.

  • Can interact with TimelockSCEmergencyScroll
    • execute transactions that are ready
  • Can interact with TimelockFast
    • execute transactions that are ready
  • Can interact with TimelockSCSlow
    • execute transactions that are ready
  • Can interact with TimelockEmergency
    • execute transactions that are ready

Member of Scroll Multisig 1, Scroll Multisig 2, ScrollAdminMultisig, Scroll Multisig 3.

  • Can interact with TimelockSCEmergencyScroll
    • execute transactions that are ready
  • Can interact with TimelockFast
    • execute transactions that are ready
  • Can interact with TimelockSCSlow
    • execute transactions that are ready
  • Can interact with TimelockEmergency
    • execute transactions that are ready
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner
A diagram of the smart contract architecture
A diagram of the smart contract architecture

Ethereum

MultipleVersionRollupVerifier0x4CEA…ad3F

Contract used to update the verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover. and keep track of current and old versions.

Contains the array of queued L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. -> L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. messages, either appended using the L1ScrollMessenger or the EnforcedTxGateway.

  • Roles:
    • admin: ProxyAdmin

Contract used to send L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. -> L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. and relay messages from L2. It allows to replay failed messages and to drop skipped messages. L1 -> L2 messages sent using this contract pay for L2 gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. on L1 and will have the aliased address of this contract as the sender.

  • Roles:
    • admin: ProxyAdmin
The following tokens are included in the value secured calculation:
ETH token logo

Contracts to force L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. -> L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. messages with the proper sender.

  • Roles:
    • admin: ProxyAdmin
ScrollOwner0x7985…26a6

Owner of all contracts in the system. It implements an extension of AccessControl that manages roles and functions allowed to be called by each role.

  • Roles:
    • opsFast: TimelockFast; ultimately Scroll Multisig 3
    • opsNoDelay: TimelockEmergency; ultimately Scroll Multisig 2
    • scMinorityNoDelay: ScrollAdminMultisig
    • scNoDelay: TimelockSCEmergency; ultimately ScrollAdminMultisig

System configuration contract for Scroll, contains enforcedBatchParameters and messageQueueParameters determining permissionlessAnyone willing should be able to join and leave the network at any time, without causing significant disturbance to the network or being detrimental to the party in question. No single entity should have the power to allowlist or blocklist participants. mode.

  • Roles:
    • admin: ProxyAdmin
    • owner: ScrollOwner

The main contract of the Scroll chain. Allows to post transaction data and state rootsA cryptographic hash succinctly representing a state using a Merkle tree., along with proofs. Sequencing and proposing are behind a whitelist unless enforcedBatchMode is activated.

  • Roles:
    • admin: ProxyAdmin
TimelockSCEmergency0x0CD4…CA44

A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: ScrollAdminMultisig
    • executor: Scroll Multisig 1, ScrollAdminMultisig; ultimately EOA 1, EOA 2, EOA 3, EOA 4
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: ScrollAdminMultisig
    • timelockAdmin: ScrollAdminMultisig, TimelockSCEmergency; ultimately ScrollAdminMultisig
TimelockFast0x0e58…C4F4

A timelock with access control. The current minimum delay is 1d. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: Scroll Multisig 3
    • executor: Scroll Multisig 1; ultimately EOA 1, EOA 2, EOA 3, EOA 4
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: Scroll Multisig 3
    • timelockAdmin: Scroll Multisig 3, TimelockFast; ultimately Scroll Multisig 3
TimelockSCSlow0x3f90…a9fd

A timelock with access control. The current minimum delay is 3d. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: ScrollAdminMultisig
    • executor: Scroll Multisig 1, ScrollAdminMultisig; ultimately EOA 1, EOA 2, EOA 3, EOA 4
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: ScrollAdminMultisig
    • timelockAdmin: ScrollAdminMultisig, TimelockSCSlow; ultimately ScrollAdminMultisig
TimelockEmergency0x8267…216b

A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: Scroll Multisig 2
    • executor: Scroll Multisig 1; ultimately EOA 1, EOA 2, EOA 3, EOA 4
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: Scroll Multisig 2
    • timelockAdmin: Scroll Multisig 2, TimelockEmergency; ultimately Scroll Multisig 2

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC721 tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  • Roles:
    • admin: ProxyAdmin
  • Roles:
    • admin: ProxyAdmin
The following tokens are included in the value secured calculation:
DAI token logo

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ETH from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  • Roles:
    • admin: ProxyAdmin

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC20 tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. It allows to change the token mappings.

  • Roles:
    • admin: ProxyAdmin

All supported tokens in this escrow are included in the value secured calculation.

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC1155 tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  • Roles:
    • admin: ProxyAdmin

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC20 tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. It uses a fixed token list.

  • Roles:
    • admin: ProxyAdmin

All supported tokens in this escrow are included in the value secured calculation.

Main entry point for depositing ETH and ERC20 tokens, which are then forwarded to the correct gateway.

  • Roles:
    • admin: ProxyAdmin
The following tokens are included in the value secured calculation:
wstETH token logo

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. WETH from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  • Roles:
    • admin: ProxyAdmin

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. ERC20 tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. It allows to change the token mappings.

The following tokens are included in the value secured calculation:
pufETH token logo

Contract used to bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge. USDC tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. to L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups..

  • Roles:
    • admin: ProxyAdmin
The following tokens are included in the value secured calculation:
USDC token logo
PlonkVerifierV1-10x03a7…0110
  1. Source Code
PlonkVerifierPostEuclid-20x3985…6eA4
  1. Source Code
ZkEvmVerifierPostFeynman
3 instances
0x4AF7…DDb50x8082…f9550xa8d4…F485
PlonkVerifierGalileo0x749f…C75e
  1. Source Code
PlonkVerifierV2-10x8c1b…30f7
  1. Source Code
PlonkVerifierFeynmanV20x96cb…A01C
  1. Source Code
  • Roles:
    • admin: ProxyAdmin
  • Roles:
    • admin: ProxyAdmin
ZkEvmVerifierPostEuclid-20xc084…29bA
ProxyAdmin0xEB80…d072
  • Roles:
    • owner: ScrollOwner

Scroll

ScrollOwner0x13D2…437B

Owner of all contracts in the system. It implements an extension of AccessControl that manages roles and functions allowed to be called by each role.

  • Roles:
    • scNoDelay: TimelockSCEmergencyScroll; ultimately ScrollAdminMultisig

Contract used to withdraw ERC20 tokens on L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups. and finalize deposit the tokens from L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

  • Roles:
    • admin: ProxyAdmin
TimelockSCEmergencyScroll0x1f80…78b4

A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: ScrollAdminMultisig
    • executor: Scroll Multisig 1, ScrollAdminMultisig; ultimately EOA 5, EOA 6, EOA 7, EOA 8
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: ScrollAdminMultisig
    • timelockAdmin: ScrollAdminMultisig, TimelockSCEmergencyScroll; ultimately ScrollAdminMultisig
TimelockFast0x2b14…d376

A timelock with access control. The current minimum delay is 1d. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: Scroll Multisig 3
    • executor: Scroll Multisig 1; ultimately EOA 5, EOA 6, EOA 7, EOA 8
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: Scroll Multisig 3
    • timelockAdmin: Scroll Multisig 3, TimelockFast; ultimately Scroll Multisig 3
TimelockSCSlow0x79D8…CC14

A timelock with access control. The current minimum delay is 3d. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: AgoraGovernor, ScrollAdminMultisig
    • executor: AgoraGovernor, Scroll Multisig 1, ScrollAdminMultisig; ultimately EOA 5, EOA 6, EOA 7, EOA 8
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: AgoraGovernor, ScrollAdminMultisig
    • timelockAdmin: ScrollAdminMultisig, TimelockSCSlow; ultimately AgoraGovernor, ScrollAdminMultisig
TimelockEmergency0xA77D…734f

A timelock with access control. The current minimum delay is 0s. Proposals that passed their minimum delay can be executed by anyone.

  • Roles:
    • canceller: Scroll Multisig 2
    • executor: Scroll Multisig 1; ultimately EOA 5, EOA 6, EOA 7, EOA 8
    • proposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block.: Scroll Multisig 2
    • timelockAdmin: Scroll Multisig 2, TimelockEmergency; ultimately Scroll Multisig 2
ProposalTypesConfigurator0xfDa7…640E

Contract of the USDC token on Scroll.

  • Roles:
    • admin: ProxyAdmin
  • Roles:
    • admin: ProxyAdmin

Counterpart to the L1GatewayRouter contract.

  • Roles:
    • admin: ProxyAdmin
L2MessageQueue0x5300…0000

Used to append messages to the L2MessageQueue from the L2ScrollMessenger.

Counterpart to the L1ERC1155Gateway contract.

  • Roles:
    • admin: ProxyAdmin

Counterpart to the L1CustomERC20Gateway contract.

  • Roles:
    • admin: ProxyAdmin
ScrollStandardERC20Factory0x66e5…1484

Contract used to deploy ScrollStandardERC20 tokens for L2StandardERC20Gateway.

Contract of the L2ScrollMessenger contract.

  • Roles:
    • admin: ProxyAdmin
  • Roles:
    • admin: ProxyAdmin

ETH is pre-minted to this contract in the genesis blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. and released on Scroll whenever corresponding deposits are made on Ethereum.

  • Roles:
    • admin: ProxyAdmin

Counterpart to the L1ERC721Gateway contract.

  • Roles:
    • admin: ProxyAdmin
  • Roles:
    • owner: ScrollOwner
  • Roles:
    • admin: ProxyAdmin
Can be upgraded by:
  • Roles:
    • admin: ProxyAdmin
MasterMinter0xb5cE…e4BE

Contract that uses controllers to manage minters for USDC on Scroll.

ScrollStandardERC200xC7d8…3f69

Contract of the ERC20 standard token used by the ERC20 factory.

  • Roles:
    • admin: ProxyAdmin

The current deployment carries some associated risks:

  • Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).

Program Hashes

Name
Hash
Repository
Verification
Used in
0x003a...bf72
Scroll logo
0x0093...7909
Scroll logo
0x0062...d297
Scroll logo
0x0039...9269
Scroll logo
0x0021...3d67
Scroll logo