# Sophon Markdown version of https://l2beat.com/layer2s/projects/sophon ## Summary **Warning:** Sophon will be sunsetting in late 2026. See the [announcement](https://x.com/sophon/status/2070192257295335800) and the [migration guide](https://sophon.com/content/) for details. - Total Value Secured: $5.66 M (-0.49% compared to seven days ago; canonically bridged $5.66 M, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - **Warning:** The SOPH token associated with Sophon accounts for 26.2% of the TVS! (sentiment: warning) - Past day UOPS: <0.01 (+40.2% compared to seven days ago) - Stage: Stage 0 - Gas token: SOPH - Type: Validium - Purposes: Gaming, Social, AI - Host chain: Ethereum - Chain ID: 50104 ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: Validity proofs (ST, SN) (sentiment: good) - Data availability: External (sentiment: warning) - Exit window: None (sentiment: bad) - Proposer failure: Replace proposer (sentiment: warning) ### About Sophon is a consumer-centric ecosystem on a ZK Stack Validium L2, designed to bring onchain benefits to everyday lifestyle and entertainment applications. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/sophon) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/sophon/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/sophon) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#onchain-costs). ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#liveness). ## Milestones & Incidents - 2026-06-25 (incident): [Sophon initiates L2 sunset](https://x.com/sophon/status/2070192257295335800). Sophon announces sunsetting the L2 and stops new deposits. - 2025-05-28: [SOPH TGE](https://x.com/sophon/status/1927697463655219692). SOPH, the gas token of Sophon, is officially live. - 2025-04-23: [Avail Vector DA Bridge](https://blog.availproject.org/avail-to-power-consumer-entertainment-onchain-with-sophon/). Sophon is the first validium to integrate with the Vector data availability bridge to Avail. - 2024-12-18: [Mainnet public launch](https://x.com/sophon/status/1861771965284896996). Sophon Mainnet is now open for all users. - 2024-09-22: [Mainnet private launch](https://blog.sophon.xyz/the-road-to-mainnet/). Sophon launches their mainnet privately. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is a 4d 3h - 8d 3h delay on code upgrades unless upgrade is initiated by the EmergencyUpgradeBoard in which case there is no delay. ### Funds can be lost if 2. the sequencer posts an unavailable transaction root, (CRITICAL) 3. the data is not available on the external provider, (CRITICAL) 4. the proof system is implemented incorrectly. ### Users can be censored if 5. the operator refuses to include their transactions, 6. the Operator does not specifically whitelist them in the TransactionFilterer. ### MEV can be extracted if 7. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. The Operator actively uses a TransactionFilterer contract, which requires accounts that enqueue or force transactions from L1 to be whitelisted. ### State validation Validity proofs (ST, SN) (sentiment: good) STARKs and SNARKs are zero knowledge proofs that ensure state correctness. STARKs proofs are wrapped in SNARKs proofs for efficiency. SNARKs require a trusted setup. ### Data availability External (sentiment: warning) Proof construction and state derivation fully rely on data that is posted on Avail. Transaction data is checked against the Vector bridge data roots, signed off by Avail validators. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Replace proposer (sentiment: warning) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. There is a decentralized Governance system that can attempt changing Proposers with an upgrade. ## Stage Sophon is a Stage 0 Validium. ### Stage 0 - [x] The project self-identifies as a Validium or Optimium. - [x] State roots are posted to Ethereum L1. - [x] A complete and functional proof system (fraud or validity proofs) is deployed. - [x] DA is attested by a committee or external DA layer, not solely by the sequencer. - [x] A source-available node exists that can reconstruct the L2 state when DA is accessible. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/matter-labs/zksync-era) ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council to push a malicious upgrade, or sequencer+DA-committee collusion to withhold data and finalize invalid state roots, should be the only ways (other than bugs) to steal funds or block withdrawals indefinitely. - [ ] Users' withdrawals can be censored by the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. - [ ] The Security Council is not properly set up. - [x] The DA verifier is non-upgradeable, or upgrades to it provide at least a 7d independent exit window. - [x] The DA layer meets minimum decentralization: a DAC with ≥5 external members under an honest-minority assumption, or an external DA chain with an attestation verifier. - [x] The proof system meets the minimum trusted setup requirements defined in the L2BEAT [trusted setup assessment framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). - [x] Prover source code is published. - [x] The sources of all programs used are public and program hashes can be independently regenerated. ### Stage 2 - [ ] Upgrades unrelated to onchain provable bugs, including upgrades to the DA verifier, provide less than 30d to exit. - [ ] The DA verifier (and related contracts) is upgradeable with less than 30d independent exit window. - [ ] The DA mechanism relies on reputational security alone; no staked assets are at risk for DA misbehavior or slashable < TVS. ## Data availability ### Data is posted to Avail Transactions roots are posted onchain and the full data is posted on Avail. The vector bridge is used to verify attestations from the Avail validator set that the data is indeed available. **Risks** - Funds can be lost if the sequencer posts an unavailable transaction root (CRITICAL). - Funds can be lost if the data is not available on the external provider (CRITICAL). **References** - [AvailL1DAValidator - checkDA() function](https://etherscan.io/address/0x8f50d93B9955B285f787043B30B5F51D09bE0120#code#F1#L16) ## State validation Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. ### Prover Architecture ZKsync Era proof system Boojum can be found [here](https://github.com/matter-labs/era-boojum/tree/main) and contains essential tools like the Prover, the Verifier, and other backend components. The specs of the system can be found [here](https://github.com/matter-labs/zksync-era/tree/main/prover). ### ZK Circuits ZKsync Era circuits are built from Boojum and are designed to replicate the behavior of the EVM. The source code can be found [here](https://github.com/matter-labs/era-zkevm_circuits/tree/main). The circuits are checked against tests that can be found [here](https://github.com/matter-labs/era-zkevm_test_harness/tree/main). **Risks** - Funds can be lost if the proof system is implemented incorrectly. ### Verification Keys Generation SNARK verification keys can be generated and checked against the Ethereum verifier contract using [this tool](https://github.com/matter-labs/zksync-era/tree/main/prover/crates/bin/vk_setup_data_generator_server_fri). The system requires a trusted setup. ## Upgrades & Governance There are two main paths for contract upgrades in the shared ZK stack ecosystem - standard and emergency - both converging on the shared upgrade management contract ProtocolUpgradeHandler. The standard path involves a governance proposal and voting through the DAO, multiple timelock delays and finally approval by the Guardians or 4 SecurityCouncil participants. The emergency path allows for contract upgrades without any delay by the EmergencyUpgradeBoard, which acts as a 3/3 Multisig between SecurityCouncil, Guardians and the FoundationMultisig. ### Standard path #### On ZKsync Era Delegates can start new proposals by reaching a threshold of 21M ZK tokens on the ZKsync Era Rollup's ZkProtocolGovernor contract. This launches a 3d 'voting delay' after which the 7d voting period starts. During these first two periods, the proposal can be canceled by the proposer or if it falls below the proposing threshold. A proposal is only successful if it reaches both quorum (630M ZK tokens) and simple majority. When it reaches quorum, a remaining voting period of 3d is guaranteed by a potential late quorum vote extension. In the successful case, it can be queued in the 0s timelock which forwards it via the Gateway to Ethereum as an L2->L1 log. #### On Ethereum After the execution of the proposal-containing batch (3h delay), the proposal is now picked up by the ProtocolUpgradeHandler and enters the 3d 'legal veto period'. This serves as a window in which a veto could be coordinated offchain, to be then enforced by non-approval of Guardians and SecurityCouncil. A threshold of 2 Guardians can extend the veto period to 7d. After this a proposal enters a *waiting* state of 1mo, from which it can be immediately approved (cancelling the delay) by 4 participants of the SecurityCouncil. For the unlikely case that the Security Council does not approve here, the Guardians can instead approve the proposal, or nobody. In the two latter cases, the waiting period is enforced in full. A proposal cannot be actively cancelled in the ProtocolUpgradeHandler, but will expire if not approved within the waiting period. An approved proposal now enters the *pendingExecution* state for a final delay of 1d and can then be executed. #### Other governance tracks There are two other tracks of Governance also starting with DAO Delegate proposals the ZKsync Era rollup: 1) Token Program Proposals that add new minters, allocations or upgrade the ZK token and 2) Governance Advisory Proposals that e.g. change the ZK Credo or other offchain Governance Procedures without onchain targets. The protocol for these two other tracks is similar to the first part of the standard path described above (albeit having different quorum and timelock values), and not passing over to the Ethereum L1. Further customizations are that the ZkFoundationMultisig can propose to the ZkTokenGovernor without a threshold and that the Guardians' L2 alias can cancel proposals in the ZkTokenGovernor and the ZkGovOpsGovernor. ### Emergency path SecurityCouncil (6/8), Guardians (5/8) and ZkFoundationMultisig (3/6) form a de-facto 3/3 Multisig by pushing an immediate upgrade proposal through the EmergencyUpgradeBoard, which circumvents all delays and executes immediately via the ProtocolUpgradeHandler. ### Upgrade Delays The cumulative duration of the upgrade paths from the moment of a voted 'successful' proposal is 4d 3h or 8d 3h (depending on Guardians extending the LegalVetoPeriod) for Standard, 0 for Emergency and 1mo 4d for the path in which the SecurityCouncil is not approving the proposal. ### Freezing The SecurityCouncil can freeze (pause withdrawals and settlement) all chains connected to the current ChainTypeManager. Either for a softFreeze of 12h or a hardFreeze of 7d. After a softFreeze and / or a hardFreeze, a proposal from the EmergencyUpgradeBoard has to be passed before subsequent freezes are possible. Only the SecurityCouncil can unfreeze an active freeze. ### ZK cluster Admin and Chain Admin Apart from the paths that can upgrade all shared implementations, the ZK stack governance system defines other roles that can modify the system: A single *ZK cluster Admin* role who governs parameters in the shared contracts and a *Chain Admin* role (defined in each chain-specific diamond contract) for managing parameters of each individual ZK chain that builds on the stack. These chain-specific actions include critical operations like setting a transaction filterer that can censor L1 -> L2 messages, changing the DA mode, migrating the chain to a different settlement layer and standard operations like setting fee parameters and adding / removing Validators in the ValidatorTimelock. For rollups, data availability on Ethereum is validated by a RollupL1DAValidator contract (or a RelayedSLDAValidator on the Gateway). Each rollup can become a permanent rollup (through their Chain Admin) which disallows DA changes to non-whitelisted sources or settlement layers in the future. The source of truth for rollup-compliant DA validator contracts is the RollupDAManager contract, which is administered via the ProtocolUpgradeHandler. ZKsync Era's Chain Admin differs from the others as it also has the above *ZK cluster Admin* role in the shared ZK stack contracts. ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/sophon#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can't force all transactions If a user is censored by the L2 Sequencer, they cannot by default force their transaction via the L1 queue. The active TransactionFilterer only allows whitelisted accounts to enqueue L1 to L2 transactions. Even if a user were specifically whitelisted, there is no mechanism that forces the L2 Sequencer to include transactions from the queue in an L2 block, as they have the choice to process the queue in order or not at all. **Risks** - Users can be censored if the operator refuses to include their transactions. - Users can be censored if the Operator does not specifically whitelist them in the TransactionFilterer. **References** - [L1 - L2 interoperability - Developer's documentation](https://docs.zksync.io/zksync-protocol/rollup/l1_l2_communication#priority-operations-1) - [Mailbox facet](https://etherscan.io/address/0x1e34aB39a9682149165ddeCc0583d238A5448B45#code#F1#L405) - [TransactionFilterer](https://etherscan.io/address/0x006ea4836b5C3EB8694AE6D1e08207610E1d5e41#code#F1#L26) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks. **References** - [Withdrawing funds - ZKsync documentation](https://docs.zksync.io/zksync-protocol/rollup/bridging-assets) ### Forced messaging If the user experiences censorship from the operator with regular L2->L1 messaging they can submit their messages directly on L1. The system is then obliged to service this request or halt all messages from L1, including all forced withdrawals and deposits. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular message. ## Permissions ### Ethereum #### Actors ##### EmergencyUpgradeBoard Addresses: [0xF73a7dCfa68E52030ec39E41a23DCA51F3aAa111](https://etherscan.io/address/0xF73a7dCfa68E52030ec39E41a23DCA51F3aAa111) A custom contract allowing a 3/3 of SecurityCouncil, ZK Foundation Multisig and Guardians to `executeEmergencyUpgrade()` via the ProtocolUpgradeHandler. * Can upgrade **with no delay** * ValidatorTimelock [via: ProtocolUpgradeHandler → ProxyAdmin] * BridgeHub [via: ProtocolUpgradeHandler → ProxyAdmin] * MessageRoot [via: ProtocolUpgradeHandler → ProxyAdmin] * CTMDeploymentTracker [via: ProtocolUpgradeHandler → ProxyAdmin] * L1AssetRouter [via: ProtocolUpgradeHandler → ProxyAdmin] * L1NativeTokenVault [via: ProtocolUpgradeHandler → ProxyAdmin] * ChainTypeManager [via: ProtocolUpgradeHandler → ProxyAdmin] * L1Nullifier [via: ProtocolUpgradeHandler → ProxyAdmin] * ChainAssetHandler [via: ProtocolUpgradeHandler → ProxyAdmin] * ProtocolUpgradeHandler [via: ProtocolUpgradeHandler → ProxyAdmin] * L1USDCBridge [via: ProtocolUpgradeHandler → ProxyAdmin] * Can interact with SophonTransactionFilterer * call requestL2Transaction() with any target/calldata (whitelisted superuser sender) [via: ProtocolUpgradeHandler] * Can interact with BridgeHub * set critical contract addresses for the shared cluster, register settlement layers, pause and unpause migrations and the bridge and manage zk chain registration [via: ProtocolUpgradeHandler] * Can interact with L1NativeTokenVault * pause / unpause the bridge [via: ProtocolUpgradeHandler] * Can interact with ChainTypeManager * manage the shared ValidatorTimelock contract address and the admin role, register and execute upgrades (and set their deadlines), freeze, revert batches and set permissioned validators and fee params for all connected chains [via: ProtocolUpgradeHandler] * Can interact with L1Nullifier * pause, unpause and set critical escrow address references [via: ProtocolUpgradeHandler] * Can interact with ChainAssetHandler * pause, resume chain migrations [via: ProtocolUpgradeHandler] * Can interact with RollupDAManager * manage allowed rollup DA pairs (allowed to be used by rollups in permanent rollup mode) [via: ProtocolUpgradeHandler] ##### Matter Labs Multisig Addresses: [0x4e4943346848c4867F81dFb37c4cA9C5715A7828](https://etherscan.io/address/0x4e4943346848c4867F81dFb37c4cA9C5715A7828) A Multisig with 4/7 threshold. * Can upgrade **with no delay** * ServerNotifier [via: EraChainAdminProxy → ProxyAdmin] * Can interact with BridgeHub * create new zk chains (based on the current version), register tokens (ZK cluster Admin role) [via: EraChainAdminProxy] * Can interact with ChainTypeManager * set the pending admin of this contract and the ServerNotifier contract address (ZK cluster Admin role) [via: EraChainAdminProxy] ##### Avail Multisig 1 Addresses: [0x7F2f87B0Efc66Fea0b7c30C61654E53C37993666](https://etherscan.io/address/0x7F2f87B0Efc66Fea0b7c30C61654E53C37993666) A Multisig with 4/7 threshold. * Can upgrade **with no delay** * Vector * Can upgrade **with 1d delay** * AvailBridgeV1 [via: TimelockController with 1d delay → ProxyAdmin] * Can interact with Vector * can freeze the Vector contract and update the list of authorized relayers * Can interact with AvailBridgeV1 * manage the pauser role and all other access control configurations, set the address of the target contract for DA verification, manage fees **with 1d delay** [via: TimelockController with 1d delay] * Can interact with TimelockController * cancel queued transactions * execute transactions that are ready * manage all access control roles **with 1d delay or with no delay** [via: TimelockController with 1d delay - or - acting directly] * propose transactions ##### SecurityCouncil Addresses: [0x59195219d1176E42f8e607e9AC114926D47f9035](https://etherscan.io/address/0x59195219d1176E42f8e607e9AC114926D47f9035) A Multisig with 6/8 threshold. Custom Multisig implementation that has a general threshold of 6 but also specific thresholds for upgrade approvals (4) or soft freezes (3). * Can interact with ProtocolUpgradeHandler * soft freeze, hard freeze, approve a protocol upgrade * Can interact with EmergencyUpgradeBoard * one of its 3/3 signers **References** - [Security Council members - ZK Nation docs](https://docs.zknation.io/zksync-governance/schedule-3-zksync-security-council) ##### Guardians Addresses: [0x600dA620Ab29F41ABC6596a15981e14cE58c86b8](https://etherscan.io/address/0x600dA620Ab29F41ABC6596a15981e14cE58c86b8) A Multisig with 5/8 threshold. Custom Multisig implementation that has a general threshold of 5 and a specific threshold for extending the legal voting period of 2. * Can interact with ProtocolUpgradeHandler * extend the legal veto period, approve a protocol upgrade * Can interact with EmergencyUpgradeBoard * one of its 3/3 signers **References** - [Guardians - ZK Nation docs](https://docs.zknation.io/zksync-governance/schedule-4-zksync-guardians) ##### SophonTransactionFilterer Addresses: [0x006ea4836b5C3EB8694AE6D1e08207610E1d5e41](https://etherscan.io/address/0x006ea4836b5C3EB8694AE6D1e08207610E1d5e41) A contract implementing the ITransactionFilterer interface, allows only trxs from whitelisted superusers. The whitelist is defined in AccessControl roles. * Can interact with Diamond * define addresses that can send transactions from L1 to L2 (e.g. for deposits, withdrawals, queued transactions). This is enforced in the Mailbox Facet ##### ValidatorTimelock Addresses: [0x2e5110cF18678Ec99818bFAa849B8C881744b776](https://etherscan.io/address/0x2e5110cF18678Ec99818bFAa849B8C881744b776) Intermediary contract between the *Validators* and the central diamond contract that delays block execution (ie withdrawals and other L2 --> L1 messages) by 3h. * Can interact with Diamond * commit, prove, execute, revert batches directly in the main Diamond contract. This role is typically held by a proxying ValidatorTimelock ##### SophonChainAdminMultisig Addresses: [0xe4644b6d106A18062344c0A853666bc0B8f052d1](https://etherscan.io/address/0xe4644b6d106A18062344c0A853666bc0B8f052d1) A Multisig with 3/5 threshold. * Can interact with SophonTransactionFilterer * call requestL2Transaction() with any target/calldata (whitelisted superuser sender) [via: SophonZkEvmAdmin] * Can interact with Diamond * administrate operator roles for this chain in the ValidatorTimelock, manage fees, apply predefined upgrades, manage censorship through a TransactionFilterer, set DA mode, migrate the chain to whitelisted settlement layers (Chain Admin role) [via: SophonZkEvmAdmin] ##### Avail Multisig 2 Addresses: [0x1a5BA9447D02Ddaf7bcB5594Fc27dE2Daf588930](https://etherscan.io/address/0x1a5BA9447D02Ddaf7bcB5594Fc27dE2Daf588930) A Multisig with 3/5 threshold. * Can interact with AvailBridgeV1 * pause the bridge ##### ZK Foundation Multisig Addresses: [0xbC1653bd3829dfEc575AfC3816D4899cd103B51c](https://etherscan.io/address/0xbC1653bd3829dfEc575AfC3816D4899cd103B51c) A Multisig with 3/6 threshold. * Can interact with EmergencyUpgradeBoard * one of its 3/3 signers ##### SP1VerifierGatewayMultisig Addresses: [0xCafEf00d348Adbd57c37d1B77e0619C6244C6878](https://etherscan.io/address/0xCafEf00d348Adbd57c37d1B77e0619C6244C6878) A Multisig with 2/3 threshold. * Can interact with SP1VerifierGateway * affect the liveness and safety of the gateway - can transfer ownership, add and freeze verifier routes ##### 2 EOAs Addresses: [0xa7Fc7e6CF378523aF8C159Cb55073D258e32A13B](https://etherscan.io/address/0xa7Fc7e6CF378523aF8C159Cb55073D258e32A13B) (EOA 1), [0xE2DDB84786aff975FE7B511acCc3AF5a1657AbF3](https://etherscan.io/address/0xE2DDB84786aff975FE7B511acCc3AF5a1657AbF3) (EOA 2) * Can interact with ValidatorTimelock * Permissioned to call the functions to commit, prove, execute and revert L2 batches through the ValidatorTimelock in the main Diamond contract ##### EOA 3 Addresses: [0xB1e2974E81922c1d5923dB4580292fB9954E9E05](https://etherscan.io/address/0xB1e2974E81922c1d5923dB4580292fB9954E9E05) * Can interact with SophonZkEvmAdmin * set the conversion factor for gas token deposits ##### EOA 4 Addresses: [0x50B238788747B26c408681283D148659F9da7Cf9](https://etherscan.io/address/0x50B238788747B26c408681283D148659F9da7Cf9) * Can interact with SophonTransactionFilterer * call requestL2Transaction() with any target/calldata (whitelisted superuser sender) * manage the whitelist ##### 2 EOAs Addresses: [0x5afeCA1153D94750e170e6021B95416A68c60f4E](https://etherscan.io/address/0x5afeCA1153D94750e170e6021B95416A68c60f4E) (EOA 5), [0xBaEb92889696217A3A6be2175E5a95dC4cFFC9f7](https://etherscan.io/address/0xBaEb92889696217A3A6be2175E5a95dC4cFFC9f7) (EOA 6) * Can interact with SophonTransactionFilterer * call requestL2Transaction() with any target/calldata (whitelisted superuser sender) ##### EOA 7 Addresses: [0x7EBe0bf025ca5993551cE6CEe3f541B24FDF7c35](https://etherscan.io/address/0x7EBe0bf025ca5993551cE6CEe3f541B24FDF7c35) * Can interact with Vector * it is a ‘Relayer’ and can call commitHeaderRange() to commit block ranges to the Vector contract. Since adding and removing Relayers emits no events, there can be more relayers than are presented here ### ZKsync Era #### Actors ##### ZkProtocolGovernor Addresses: [0x76705327e682F2d96943280D99464Ab61219e34f](https://explorer.zksync.io/address/0x76705327e682F2d96943280D99464Ab61219e34f) Main Governance contract allowing for token voting (simple majority) with the ZK token through delegates. This contract is used for protocol upgrade proposals (ZIPs) that start on ZKsync Era, go through Ethereum Layer 1 and can - from there - target all L1 and L2 contracts. At least 21M ZK tokens are necessary to start a proposal and a 630M quorum of voted tokens must be met to succeed. * Can interact with ProtocolUpgradeHandler * start (queue) upgrades [via: ProtocolTimelockController] * Can interact with ProtocolTimelockController * cancel queued transactions * execute transactions that are ready * manage all access control roles and change the minimum delay [via: ProtocolTimelockController] * propose transactions ##### ZkTokenGovernor Addresses: [0xb83FF6501214ddF40C91C9565d095400f3F45746](https://explorer.zksync.io/address/0xb83FF6501214ddF40C91C9565d095400f3F45746) Governance contract allowing for token voting (simple majority) with the ZK token through delegates. This contract is used for Token Program Proposals (TPPs) usually targeting the ZK token on ZKsync Era. At least 21M ZK tokens are necessary to start a proposal (for delegates) and a 630M quorum of voted tokens must be met to succeed. * Can interact with ZkToken * grant the MINTER_ROLE to arbitrary addresses, thus controlling the minting of the ZK token **with 3d delay** [via: ZkTokenTimelockController with 3d delay] * Can interact with ZkTokenTimelockController * manage all access control roles and change the minimum delay **with 6d delay** [via: ZkTokenTimelockController with 3d delay with 3d delay] * cancel queued transactions * execute transactions that are ready * propose transactions ##### Guardians_l2Alias Addresses: [0x711ea620AB29f41AbC6596a15981e14ce58C97c9](https://explorer.zksync.io/address/0x711ea620AB29f41AbC6596a15981e14ce58C97c9) * Can interact with ZkTokenGovernor * cancel proposals while they are pending (after having been proposed) or active (during the voting period) ##### ZKFoundationMultisig_l2Alias Addresses: [0xcd2753Bd3829dfeC575AFC3816d4899CD103C62D](https://explorer.zksync.io/address/0xcd2753Bd3829dfeC575AFC3816d4899CD103C62D) * Can interact with ZkTokenGovernor * make direct proposals without owning ZK tokens. In propose-guarded mode, this address is the ONLY allowed proposer. Propose-guarded mode is currently set to false ##### ProtocolUpgradeHandler_l2Alias Addresses: [0xF41EcA3047B37dc7d88849de4a4dc07937Ad6bc4](https://explorer.zksync.io/address/0xF41EcA3047B37dc7d88849de4a4dc07937Ad6bc4) * Can upgrade **with no delay** * ZkToken [via: ZkTokenProxyAdmin] * Can interact with ZkToken * control all roles in the ZkToken access control, including the minter roles ## Smart contracts ### Ethereum #### Diamond Addresses: [0x05eDE6aD1f39B7A16C949d5C33a0658c9C7241e3](https://etherscan.io/address/0x05eDE6aD1f39B7A16C949d5C33a0658c9C7241e3#code), [0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253](https://etherscan.io/address/0x37CefD5b44c131FEf27e9Bc542e5B77A177A7253#code) (Implementation #1 (Upgradable)), [0x1666124221622eb6154306Ea9BA87043e8be88B2](https://etherscan.io/address/0x1666124221622eb6154306Ea9BA87043e8be88B2#code) (Implementation #2 (Upgradable)), [0x1e34aB39a9682149165ddeCc0583d238A5448B45](https://etherscan.io/address/0x1e34aB39a9682149165ddeCc0583d238A5448B45#code) (Implementation #3 (Upgradable)), [0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691](https://etherscan.io/address/0x0597CaA8A823A699d7CD9E62B5E5d4153FF82691#code) (Implementation #4 (Upgradable)) The main contract defining the Layer 2. Operator actions like commiting blocks, providing ZK proofs and executing batches ultimately target this contract which then processes transactions. During batch execution it processes L1 --> L2 and L2 --> L1 transactions. * Roles: * **getAdmin**: SophonZkEvmAdmin; ultimately SophonChainAdminMultisig * **getTransactionFilterer**: SophonTransactionFilterer * **validators**: ValidatorTimelock #### AvailL1DAValidator Addresses: [0x8f50d93B9955B285f787043B30B5F51D09bE0120](https://etherscan.io/address/0x8f50d93B9955B285f787043B30B5F51D09bE0120#code) Contract that verifies that the validiums data was made available on Avail by querying the AvailBridgeV1 on Ethereum for a merkle proof of inclusion. #### BridgeHub Addresses: [0x303a465B659cBB0ab36eE643eA362c509EEb5213](https://etherscan.io/address/0x303a465B659cBB0ab36eE643eA362c509EEb5213#code), [0xc89423b4909080fB8F8A43dF5E1C27001e55C24B](https://etherscan.io/address/0xc89423b4909080fB8F8A43dF5E1C27001e55C24B#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) The main registry (hub) for all the contracts in the ZK stack cluster and central entrypoint for bridge transactions. Stores important mappings like from chainId to diamond address, from chainId to parent CTM, from chainId to base token etc. A clone of Bridgehub is also deployed on each L2 chain, but this clone is only used on settlement layers. * Roles: * **admin**: EraChainAdminProxy, ProxyAdmin; ultimately EmergencyUpgradeBoard, Matter Labs Multisig * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### MessageRoot Addresses: [0x5Ce9257755391D1509cD4eC1899d3F88A57BB4aD](https://etherscan.io/address/0x5Ce9257755391D1509cD4eC1899d3F88A57BB4aD#code), [0x669ed5BB1377C917333e7d4223ce3419EE4099fD](https://etherscan.io/address/0x669ed5BB1377C917333e7d4223ce3419EE4099fD#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Aggregates remote bridge message roots from all ZK stack chains. To be used with the Gateway when deployed. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### CTMDeploymentTracker Addresses: [0x6078F6B379f103de1Aa912dc46bb8Df0c8809860](https://etherscan.io/address/0x6078F6B379f103de1Aa912dc46bb8Df0c8809860#code), [0x00e9d8A4b35C32880A10Feb391aDEDA0D3F90991](https://etherscan.io/address/0x00e9d8A4b35C32880A10Feb391aDEDA0D3F90991#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Asset deployment tracker where the 'asset' is a ChainTypeManager. The registering of asset IDs for ChainTypeManagers is necessary to be able to migrate them to a given settlement layer, for example the Gateway. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### RollupL1DAValidator Addresses: [0x72213dfe8CA61B0A782970dCFebFb877778f9119](https://etherscan.io/address/0x72213dfe8CA61B0A782970dCFebFb877778f9119#code) Contract that verifies the data availability of ethereum calldata and blobs. Can be used by ZK stack rollups as the L1 part of a DAValidator pair. #### L1AssetRouter Addresses: [0x8829AD80E425C646DAB305381ff105169FeEcE56](https://etherscan.io/address/0x8829AD80E425C646DAB305381ff105169FeEcE56#code), [0x2386Bc2E26f39b72f0D4FDE0c07D68e4eEFfC725](https://etherscan.io/address/0x2386Bc2E26f39b72f0D4FDE0c07D68e4eEFfC725#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Canonical central asset router for all ZK stack chains. Routes deposits and withdrawals to the respective asset handlers (like the L1NativeTokenVault); does not escrow funds itself. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### ChainTypeManager Addresses: [0xc2eE6b6af7d616f6e27ce7F4A451Aedc2b0F5f5C](https://etherscan.io/address/0xc2eE6b6af7d616f6e27ce7F4A451Aedc2b0F5f5C#code), [0x4aB7204e4205c96C32E23ADa9191720976dC084f](https://etherscan.io/address/0x4aB7204e4205c96C32E23ADa9191720976dC084f#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Defines L2 diamond contract versions, creation and upgrade data and the proof system for all ZK stack chains connected to it. ZK chains are children of this central contract and can only upgrade to versions that were previously registered here. The current protocol version is 0,30,1. * Roles: * **admin**: EraChainAdminProxy, ProxyAdmin; ultimately EmergencyUpgradeBoard, Matter Labs Multisig * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### L1Nullifier Addresses: [0xD7f9f54194C633F36CCD5F3da84ad4a1c38cB2cB](https://etherscan.io/address/0xD7f9f54194C633F36CCD5F3da84ad4a1c38cB2cB#code), [0x71759C4eA628293F5a99aAB1585dF1c8dA4718e0](https://etherscan.io/address/0x71759C4eA628293F5a99aAB1585dF1c8dA4718e0#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Contract responsible for bookkeeping L1 bridging transactions. Used to finalize withdrawals and reclaim failed deposits. Does not escrow funds. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### ProtocolUpgradeHandler Addresses: [0xE30Dca3047B37dc7d88849dE4A4Dc07937ad5Ab3](https://etherscan.io/address/0xE30Dca3047B37dc7d88849dE4A4Dc07937ad5Ab3#code), [0x36625Bd3dDB469377C6e9893712158cA3c0cC14B](https://etherscan.io/address/0x36625Bd3dDB469377C6e9893712158cA3c0cC14B#code) (Implementation (Upgradable)), [0x1e4c534e7ce1FF5621Ea506D99b367D7d8EFbE3e](https://etherscan.io/address/0x1e4c534e7ce1FF5621Ea506D99b367D7d8EFbE3e#code) (Admin) The central upgrade contract and Governance proxy for all ZK stack contracts. Accepts successful DAO proposals from L2 and emergency proposals from the EmergencyUpgradeBoard. The three members of the EmergencyUpgradeBoard also have special roles and permissions in this contract. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard * **emergencyUpgradeBoard**: EmergencyUpgradeBoard * **guardians**: Guardians * **l2_protocol_governor**: ProtocolTimelockController; ultimately ZkProtocolGovernor * **securityCouncil**: SecurityCouncil Can be upgraded by: EmergencyUpgradeBoard with no delay #### RollupDAManager Addresses: [0xE689e79a06D3D09f99C21E534cCF6a8b7C9b3C45](https://etherscan.io/address/0xE689e79a06D3D09f99C21E534cCF6a8b7C9b3C45#code) Simple registry for allowed DA address pairs for the 'rollup' data availability mode (can be permanently enforced with isPermanentRollup=true). Rollup DA address pairs (especially the L1 part) usually point to contracts that validate if data was made available on Ethereum. * Roles: * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard #### AvailBridgeV1 Addresses: [0x054fd961708D8E2B9c10a63F6157c74458889F0a](https://etherscan.io/address/0x054fd961708D8E2B9c10a63F6157c74458889F0a#code), [0x737539737b44493F65c17eAfE165197b6410d254](https://etherscan.io/address/0x737539737b44493F65c17eAfE165197b6410d254#code) (Implementation (Upgradable)), [0x36194271a00dBBBae314E83dA56d0FF75fDa367B](https://etherscan.io/address/0x36194271a00dBBBae314E83dA56d0FF75fDa367B#code) (Admin) Bridge contract that verifies merkle proofs of inclusion in the proven data of the Vector DA- and arbitrary message bridge. Also used for token- and arbitrary message transfers between Avail and Ethereum. * Roles: * **admin**: ProxyAdmin; ultimately Avail Multisig 1 * **defaultAdmin**: TimelockController; ultimately Avail Multisig 1 * **pauser**: Avail Multisig 2 Can be upgraded by: Avail Multisig 1 with 1d delay #### SophonZkEvmAdmin Addresses: [0xE1eeA4D6443b19D373Fe99De838b930Ef0ac2Ad3](https://etherscan.io/address/0xE1eeA4D6443b19D373Fe99De838b930Ef0ac2Ad3#code) A governance proxy that lets SophonChainAdminMultisig act through it. * Roles: * **owner**: SophonChainAdminMultisig * **tokenMultiplierSetter**: EOA 3 #### EraChainAdminProxy Addresses: [0x2cf3bD6a9056b39999F3883955E183F655345063](https://etherscan.io/address/0x2cf3bD6a9056b39999F3883955E183F655345063#code) A governance proxy that lets Matter Labs Multisig act through it. * Roles: * **owner**: Matter Labs Multisig #### L1USDCBridge Addresses: [0xf553E6D903AA43420ED7e3bc2313bE9286A8F987](https://etherscan.io/address/0xf553E6D903AA43420ED7e3bc2313bE9286A8F987#code), [0x2ccD5486Ea1b2A52dcD387c01314F6A328f66cbB](https://etherscan.io/address/0x2ccD5486Ea1b2A52dcD387c01314F6A328f66cbB#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### EraVerifierPlonk Addresses: [0x0DAAB2B7b38ab48712996E760152c569FA356DbF](https://etherscan.io/address/0x0DAAB2B7b38ab48712996E760152c569FA356DbF#code) Verifies a zk-SNARK proof using an implementation of the PlonK proof system. #### EraVerifierFflonk Addresses: [0x8470d6B3fd71B5fE3906B4ea04498d18F721eDe9](https://etherscan.io/address/0x8470d6B3fd71B5fE3906B4ea04498d18F721eDe9#code) Verifies a zk-SNARK proof using an implementation of the fflonk proof system. #### EraDualVerifier Addresses: [0xCeF0218c0C6dB0768e48debeE26E41B8DAdE7081](https://etherscan.io/address/0xCeF0218c0C6dB0768e48debeE26E41B8DAdE7081#code) A router contract for verifiers. Routes verification requests to EraVerifierFflonk or EraVerifierPlonk depending on the supplied proof type. #### ProxyAdmin Addresses: [0x1e4c534e7ce1FF5621Ea506D99b367D7d8EFbE3e](https://etherscan.io/address/0x1e4c534e7ce1FF5621Ea506D99b367D7d8EFbE3e#code), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) * Roles: * **owner**: ProtocolUpgradeHandler #### ProxyAdmin Addresses: [0x257FC0c3EB02F7ba8C0fd3eD57692A9c1ee6D29B](https://etherscan.io/address/0x257FC0c3EB02F7ba8C0fd3eD57692A9c1ee6D29B#code) * Roles: * **owner**: EraChainAdminProxy #### L1NativeTokenVault Addresses: [0xbeD1EB542f9a5aA6419Ff3deb921A372681111f6](https://etherscan.io/address/0xbeD1EB542f9a5aA6419Ff3deb921A372681111f6#code), [0x8E1C5A8c5d8C33ed0eC756d6f4006f2D875bA083](https://etherscan.io/address/0x8E1C5A8c5d8C33ed0eC756d6f4006f2D875bA083#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Canonical central asset escrow for all ZK stack chains. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### ChainAssetHandler Addresses: [0xDd5CB8B9037357B4cD37391A073798f8aaB61076](https://etherscan.io/address/0xDd5CB8B9037357B4cD37391A073798f8aaB61076#code), [0xaa180C70126f751C164465638770B865965A744B](https://etherscan.io/address/0xaa180C70126f751C164465638770B865965A744B#code) (Implementation (Upgradable)), [0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1](https://etherscan.io/address/0xC2a36181fB524a6bEfE639aFEd37A67e77d62cf1#code) (Admin) Specialized contract for managing chain assets, i.e. chain migrations. * Roles: * **admin**: ProxyAdmin; ultimately EmergencyUpgradeBoard * **owner**: ProtocolUpgradeHandler; ultimately EmergencyUpgradeBoard Can be upgraded by: EmergencyUpgradeBoard with no delay #### ServerNotifier Addresses: [0xfca808A744735D9919EEBe4660B8Fd897456Ce31](https://etherscan.io/address/0xfca808A744735D9919EEBe4660B8Fd897456Ce31#code), [0x260813B0DAf35dda95c41F39c6Cc3F24dc87028A](https://etherscan.io/address/0x260813B0DAf35dda95c41F39c6Cc3F24dc87028A#code) (Implementation (Upgradable)), [0x257FC0c3EB02F7ba8C0fd3eD57692A9c1ee6D29B](https://etherscan.io/address/0x257FC0c3EB02F7ba8C0fd3eD57692A9c1ee6D29B#code) (Admin) A simple contract that can be called by the ChainAdmin to emit notifications about chain migrations. * Roles: * **admin**: ProxyAdmin; ultimately Matter Labs Multisig Can be upgraded by: Matter Labs Multisig with no delay #### Vector Addresses: [0x02993cdC11213985b9B13224f3aF289F03bf298d](https://etherscan.io/address/0x02993cdC11213985b9B13224f3aF289F03bf298d#code), [0xc6217f1549Cab6f22ac4AC56d42e6C248731a33D](https://etherscan.io/address/0xc6217f1549Cab6f22ac4AC56d42e6C248731a33D#code) (Implementation (Upgradable)), [0x0000000000000000000000000000000000000000](https://etherscan.io/address/0x0000000000000000000000000000000000000000#code) (Admin) The Vector bridge contract that accepts and stores Avail data availability commitments on Ethereum. * Roles: * **guardians**: Avail Multisig 1 * **relayers**: EOA 7 * **timelocks**: Avail Multisig 1 Can be upgraded by: Avail Multisig 1 with no delay #### ProxyAdmin Addresses: [0x36194271a00dBBBae314E83dA56d0FF75fDa367B](https://etherscan.io/address/0x36194271a00dBBBae314E83dA56d0FF75fDa367B#code) * Roles: * **owner**: TimelockController #### TimelockController Addresses: [0x45828180bbE489350D621d002968A0585406d487](https://etherscan.io/address/0x45828180bbE489350D621d002968A0585406d487#code) A timelock with access control. The current minimum delay is 1d. * Roles: * **canceller**: Avail Multisig 1 * **defaultAdmin**: Avail Multisig 1, TimelockController; ultimately Avail Multisig 1 * **executor**: Avail Multisig 1 * **proposer**: Avail Multisig 1 #### SP1Verifier Addresses: [0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459](https://etherscan.io/address/0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459#code) Verifier contract for SP1 proofs (v5.0.0). #### SP1VerifierGateway Addresses: [0x3B6041173B80E77f038f3F2C0f9744f04837185e](https://etherscan.io/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e#code) This contract is the router for zk proof verification. It stores the mapping between identifiers and the address of onchain verifier contracts, routing each identifier to the corresponding verifier contract. * Roles: * **owner**: SP1VerifierGatewayMultisig #### SP1Verifier Addresses: [0x8a0fd5e825D14368d90Fe68F31fceAe3E17AFc5C](https://etherscan.io/address/0x8a0fd5e825D14368d90Fe68F31fceAe3E17AFc5C#code) Verifier contract for SP1 proofs (v6.0.0). #### SP1Verifier Addresses: [0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A](https://etherscan.io/address/0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A#code) Verifier contract for SP1 proofs (v6.1.0). ### ZKsync Era #### ProtocolTimelockController Addresses: [0x085b8B6407f150D62adB1EF926F7f304600ec714](https://explorer.zksync.io/address/0x085b8B6407f150D62adB1EF926F7f304600ec714#code) Timelock contract allowing the queueing of transactions with a minimum delay of 0s. * Roles: * **canceller**: ZkProtocolGovernor * **executor**: ZkProtocolGovernor * **proposer**: ZkProtocolGovernor * **timelockAdmin**: ProtocolTimelockController; ultimately ZkProtocolGovernor #### ZkToken Addresses: [0x5A7d6b2F92C77FAD6CCaBd7EE0624E64907Eaf3E](https://explorer.zksync.io/address/0x5A7d6b2F92C77FAD6CCaBd7EE0624E64907Eaf3E#code), [0x4fcd824D304e9b1584CdBb582c104BDcbFb11274](https://explorer.zksync.io/address/0x4fcd824D304e9b1584CdBb582c104BDcbFb11274#code) (Implementation (Upgradable)), [0xdB1E46B448e68a5E35CB693a99D59f784aD115CC](https://explorer.zksync.io/address/0xdB1E46B448e68a5E35CB693a99D59f784aD115CC#code) (Admin) The ZK token contract on ZKsync Era. Mintable through access control roles. Used for voting in the ZK stack governance system. * Roles: * **admin**: ZkTokenProxyAdmin; ultimately ProtocolUpgradeHandler_l2Alias * **defaultAdmin**: ProtocolUpgradeHandler_l2Alias * **minterAdmin**: ZkTokenTimelockController; ultimately ZkTokenGovernor Can be upgraded by: ProtocolUpgradeHandler_l2Alias with no delay #### ZkTokenProxyAdmin Addresses: [0xdB1E46B448e68a5E35CB693a99D59f784aD115CC](https://explorer.zksync.io/address/0xdB1E46B448e68a5E35CB693a99D59f784aD115CC#code) * Roles: * **owner**: ProtocolUpgradeHandler_l2Alias #### ZkTokenTimelockController Addresses: [0xe5d21A9179CA2E1F0F327d598D464CcF60d89c3d](https://explorer.zksync.io/address/0xe5d21A9179CA2E1F0F327d598D464CcF60d89c3d#code) Timelock contract allowing the queueing of transactions with a minimum delay of 3d. * Roles: * **canceller**: ZkTokenGovernor * **executor**: ZkTokenGovernor * **proposer**: ZkTokenGovernor * **timelockAdmin**: ZkTokenTimelockController; ultimately ZkTokenGovernor The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is a 4d 3h - 8d 3h delay on code upgrades unless upgrade is initiated by the EmergencyUpgradeBoard in which case there is no delay.