# Term Structure Markdown version of https://l2beat.com/layer2s/projects/termstructure ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $2.23 K (-2.74% compared to seven days ago; canonically bridged $2.23 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Stage: Stage 0 - Type: ZK Rollup - Purposes: Payments, Exchange, Lending - Host chain: Ethereum ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Validity proofs (SN) (sentiment: good) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Use escape hatch (sentiment: good) ### About Term Structure introduces a distinct ZK Rollup solution democratizing fixed-rate and fixed-term borrowing and lending as well as fixed income trading by offering low transaction fees and enabling forced withdrawals. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/termstructure#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/termstructure) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/termstructure/breakdown) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/termstructure#onchain-costs). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/termstructure#liveness). ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL). ### Funds can be lost if 2. the user is unable to generate the non-trivial ZK proof for exodus withdraw, 3. the flashloan mechanism is implemented incorrectly. ### Users can be censored if 4. the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ### MEV can be extracted if 5. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for for more than 14d, users can use the exit hatch to withdraw their funds. ### State validation Validity proofs (SN) (sentiment: good) SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setup. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Use escape hatch (sentiment: good) Users are able to trustlessly exit by submitting a zero knowledge proof of funds. ## Stage Term Structure is a Stage 0 ZK Rollup. Term Structure provides the infrastructure for fixed-rate leverage, lending and borrowing. Arbitrary contracts are not supported. **Warning:** The requirement for available node software is under review ### Stage 0 - [x] A complete and functional proof system is deployed. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [ ] (under review) A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. ### Stage 1 - [ ] Principle: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [x] Users are able to exit without the help of the permissioned operators. - [ ] Upgrades executed by actors with more centralized control than a Security Council provide less than 7d for users to exit if the permissioned operator is down or censoring. ### Stage 2 - [ ] Upgrades unrelated to onchain provable bugs provide less than 30d to exit. ## Data availability ### All data required for proofs is published onchain All the data that is used to construct the system state is published onchain in the form of cheap calldata. This ensures that it will always be available when needed. **References** - [RollupFacet.sol - Etherscan source code, _commitOneBlock function](https://etherscan.io/address/0x955cdD2E56Ca2776a101a552A318d28fe311398D#code) ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. **References** - [RollupFacet.sol - Etherscan source code, verifyOneBlock function](https://etherscan.io/address/0x955cdD2E56Ca2776a101a552A318d28fe311398D#code) ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/termstructure#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. **References** - [RollupFacet.sol - Etherscan source code, onlyRole in commit, verify, execute functions](https://etherscan.io/address/0x955cdD2E56Ca2776a101a552A318d28fe311398D#code) ### Users can force exit the system Force exit allows the users to escape censorship by withdrawing their funds. The system allows users to force the withdrawal of funds by submitting a request directly to the contract onchain. The request must be served within a defined time period. If this does not happen, the system will halt regular operation and permit trustless withdrawal of funds. **Risks** - Users can be censored if the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. **References** - [AccountFacet.sol - Etherscan source code, forceWithdraw function](https://etherscan.io/address/0x8D0fc76595E42f38c771ecEE627DA5654Ca2E75A#code) - [Force Withdrawal and Evacuation Mode - Term Structure documentation](https://tutorials.ts.finance/how-to-use-term-structure/onboarding-guide/withdraw#forced-withdraw-and-evacuation-mode) ## Withdrawals ### Regular exit The user initiates the withdrawal by submitting a regular transaction on this chain. When the block containing that transaction is settled the funds become available for withdrawal on L1. ZK proofs are required to settle blocks. Finally the user submits an L1 transaction to claim the funds. **References** - [AccountFacet.sol - Etherscan source code, withdraw function](https://etherscan.io/address/0x8D0fc76595E42f38c771ecEE627DA5654Ca2E75A#code) - [Withdraw - Term Structure documentation](https://docs.institutional.ts.finance/features/withdrawal) ### Forced exit If the user experiences censorship from the operator with regular exit they can submit their withdrawal requests directly on L1. The system is then obliged to service this request. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular exit. **References** - [AccountFacet.sol - Etherscan source code, forceWithdraw function](https://etherscan.io/address/0x8D0fc76595E42f38c771ecEE627DA5654Ca2E75A#code) - [Forced Withdrawal - Term Structure documentation](https://tutorials.ts.finance/how-to-use-term-structure/onboarding-guide/withdraw?utm_source=chatgpt.com#forced-withdraw-and-evacuation-mode) ### Emergency exit If the enough time deadline passes and the forced exit is still ignored the user can put the system into Evacuation Mode, disallowing further state updates. In that case everybody can withdraw by submitting a zero knowledge proof of their funds with their L1 transaction. **Risks** - Funds can be lost if the user is unable to generate the non-trivial ZK proof for exodus withdraw. **References** - [Evacuation Mode - Term Structure documentation](https://tutorials.ts.finance/how-to-use-term-structure/onboarding-guide/withdraw?utm_source=chatgpt.com#forced-withdraw-and-evacuation-mode) ## Other considerations ### Flashloans on escrowed funds **Note:** This section requires more research and might not present accurate information. The protocol allows flashloans with the funds locked with the bridge, for a fee. **Risks** - Funds can be lost if the flashloan mechanism is implemented incorrectly. **References** - [FlashloanFacet.sol - Etherscan source code, flashLoan function](https://etherscan.io/address/0xbb629c830a4d153CDE43Cb127b5aff60d1185B8c#code) ## Permissions ### Ethereum #### Actors ##### Admins Addresses: [0xa00d50A40B1635D293c87BA36503bD2504b5D818](https://etherscan.io/address/0xa00d50A40B1635D293c87BA36503bD2504b5D818) Can update the main verifier, the evacuation verifier, can set the flash loan premium, set the half liquidation threshold, the liquidation factor, the borrow rate, the rollover fee, the withdraw protocol fee, the price feed, the stablecoin used, the minimum deposit amount and it can pause the system. ##### TermStructure Multisig 1 Addresses: [0xa00d50A40B1635D293c87BA36503bD2504b5D818](https://etherscan.io/address/0xa00d50A40B1635D293c87BA36503bD2504b5D818) A Multisig with 4/6 threshold. Owner of the protocol, meaning it can upgrade the project implementation potentially gaining access to all funds. ##### Operators Addresses: [0xeBec1D162f8467C0070C190A347Bbc3bFf6d14F8](https://etherscan.io/address/0xeBec1D162f8467C0070C190A347Bbc3bFf6d14F8) Can add tokens to the system. ##### Committers Addresses: [0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12](https://etherscan.io/address/0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12) Can commit blocks on L1 and revert pending (i.e. not yet executed) blocks. ##### Verifiers Addresses: [0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12](https://etherscan.io/address/0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12) Can verify blocks on L1. ##### Executers Addresses: [0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12](https://etherscan.io/address/0x0A4aB40Cc78D34052e1A8F5Bb5BaEb0174aBDe12) Can execute blocks on L1. ##### TermStructure Multisig 2 Addresses: [0x23bCad9BFB1378cd45b32525B835F037b673f529](https://etherscan.io/address/0x23bCad9BFB1378cd45b32525B835F037b673f529) A Multisig with 4/6 threshold. Address collecting a portion of protocol fees. Currently set to 100% of the fees. ##### TermStructure Multisig 3 Addresses: [0x2df3e912aeDe36ea5EaB06232ca3b239a40A8165](https://etherscan.io/address/0x2df3e912aeDe36ea5EaB06232ca3b239a40A8165) A Multisig with 4/6 threshold. Address collecting a portion of protocol fees. Currently set to 0% of the fees. ##### TermStructure Multisig 4 Addresses: [0xB7ef7117FfCa1956249B666D9fdBe182cFbbF5ca](https://etherscan.io/address/0xB7ef7117FfCa1956249B666D9fdBe182cFbbF5ca) A Multisig with 4/6 threshold. Address collecting a portion of protocol fees. Currently set to 0% of the fees. ## Smart contracts ### Ethereum #### ZkTrueUp Addresses: [0x09E01425780094a9754B2bd8A3298f73ce837CF9](https://etherscan.io/address/0x09E01425780094a9754B2bd8A3298f73ce837CF9#code), [0x09E01425780094a9754B2bd8A3298f73ce837CF9](https://etherscan.io/address/0x09E01425780094a9754B2bd8A3298f73ce837CF9#code) (Implementation #1 (Upgradable)), [0x8D0fc76595E42f38c771ecEE627DA5654Ca2E75A](https://etherscan.io/address/0x8D0fc76595E42f38c771ecEE627DA5654Ca2E75A#code) (Implementation #2 (Upgradable)), [0x5d8A9DDA649524D1Ce31C204551a93560617D1D3](https://etherscan.io/address/0x5d8A9DDA649524D1Ce31C204551a93560617D1D3#code) (Implementation #3 (Upgradable)), [0xbb629c830a4d153CDE43Cb127b5aff60d1185B8c](https://etherscan.io/address/0xbb629c830a4d153CDE43Cb127b5aff60d1185B8c#code) (Implementation #4 (Upgradable)), [0x84283289D7E57a2f5b80ddA065AC99450eB44cb6](https://etherscan.io/address/0x84283289D7E57a2f5b80ddA065AC99450eB44cb6#code) (Implementation #5 (Upgradable)), [0xf1E357A2645dad05FbfbC34ddF6c2D24B9f332B9](https://etherscan.io/address/0xf1E357A2645dad05FbfbC34ddF6c2D24B9f332B9#code) (Implementation #6 (Upgradable)), [0x955cdD2E56Ca2776a101a552A318d28fe311398D](https://etherscan.io/address/0x955cdD2E56Ca2776a101a552A318d28fe311398D#code) (Implementation #7 (Upgradable)), [0x0d7598cE7Cd1fA07C2a26c49876F850b0AD66bbC](https://etherscan.io/address/0x0d7598cE7Cd1fA07C2a26c49876F850b0AD66bbC#code) (Implementation #8 (Upgradable)), [0x10a73b16f6CD03931484b4Ae69fEDc55E868D295](https://etherscan.io/address/0x10a73b16f6CD03931484b4Ae69fEDc55E868D295#code) (Implementation #9 (Upgradable)), [0x882aBFb2F6A67d36350499991638044e8Bd83a72](https://etherscan.io/address/0x882aBFb2F6A67d36350499991638044e8Bd83a72#code) (Implementation #10 (Upgradable)) Main contract of the system. It manages deposits, withdrawals, verification, permissions and DeFi operations. Can be upgraded by: TermStructure Multisig 1 with no delay #### Verifier Addresses: [0x23369A60E5A8f422E38d799eD55e7AD8Ed4A86cE](https://etherscan.io/address/0x23369A60E5A8f422E38d799eD55e7AD8Ed4A86cE#code) Verifier contract used to verify the SNARK proofs. Can be upgraded by: TermStructure Multisig 1 with no delay The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).