# X Layer Markdown version of https://l2beat.com/layer2s/projects/xlayer ## Summary - Total Value Secured: $133.54 M (+5.53% compared to seven days ago; canonically bridged $4.19 M, natively minted $0.00, externally bridged $129.34 M; 96.8% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Past day UOPS: 19.43 (+0.88% compared to seven days ago) - Gas token: OKB - Type: Other - Purpose: Universal - Host chain: Ethereum - Chain ID: 196 ### Risks - Sequencer failure: Self sequence (sentiment: good) - State validation: Fraud proofs (1R, ZK) (sentiment: bad) - Data availability: Onchain (sentiment: good) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About X Layer is an OP Stack Layer 2 by OKX with seamless integration with OKX products. It is connected to the Agglayer shared bridge. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/xlayer) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/xlayer/breakdown) ## Volume and flows Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#interop-flows). ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/xlayer) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#onchain-costs). ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#liveness). ## Milestones & Incidents - 2026-06-30: [OP Succinct Lite dispute game activated](https://etherscan.io/address/0x8841FA06099FEdfE7DB6962926C6A281e9E1e607). X Layer activates OP Succinct Lite to resolve challenged OP Stack state proposals with ZK proofs. - 2025-08-05: [Migration to Pessimistic Proofs](https://etherscan.io/tx/0xab579dbf426db0badfaef925504105088f3300b51f1362a4084c57d7e13c0fb1#eventlog). X Layer stops validating the full L2 state and moves to bridge accounting proofs. - 2024-04-16: [X Layer Public Launch](https://x.com/XLayerOfficial/status/1780056275898048562). X Layer is live on mainnet, integrated with Agglayer. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades, (CRITICAL) 2. the validity proof cryptography is broken or implemented incorrectly, 3. no whitelisted challenger disputes an invalid state root before the challenge window expires, 4. the SP1 verifier gateway owner routes proof verification through a malicious or faulty verifier. ### Funds can be lost if 5. the Agglayer pessimistic proof system for shared bridge accounting is implemented incorrectly. ### Funds can be frozen if 6. the OP Succinct Lite proof system or verifier gateway cannot accept valid proofs during a challenge, 7. the permissioned proposer fails to publish state roots to L1. ## Risk analysis ### Sequencer failure Self sequence (sentiment: good) In the event of a sequencer failure, users can force transactions to be included in the project's chain by sending them to L1. There can be up to a 12h delay on this operation. ### State validation Fraud proofs (1R, ZK) (sentiment: bad) Fraud proofs allow actors watching the chain to prove that the state is incorrect. Single round proofs (1R) only require a single transaction to resolve. ZK proofs are used to prove the correctness of the state transition. Challenges are currently restricted to 1 whitelisted challenger and proposals are restricted to 1 whitelisted proposer. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only whitelisted proposers can publish state roots. Permissionless proposing becomes available only after 1000y of proposer inactivity, which is not a practical recovery path. ## Data availability ### Data is posted on Ethereum Transaction data is posted to Ethereum L1 as compressed calldata or blobs through the OP Stack batch inbox. ## State validation ### Fraud proofs State roots are proposed by whitelisted proposers who create dispute games via the DisputeGameFactory by posting a bond of 0.00000001 ETH. Once created, the game enters a challenge period of 1h during which whitelisted challengers can dispute the proposal by posting a bond of 0.00000001 ETH. If challenged, anyone can submit a ZK proof to prove the correct state within the proving period of 7d. After the challenge period passes without a successful challenge, or after a valid proof is submitted, anyone can resolve the game and finalize the state root. **Risks** - Funds can be stolen if the validity proof cryptography is broken or implemented incorrectly. - Funds can be stolen if no whitelisted challenger disputes an invalid state root before the challenge window expires. - Funds can be stolen if the SP1 verifier gateway owner routes proof verification through a malicious or faulty verifier. - Funds can be frozen if the permissioned proposer fails to publish state roots to L1. **References** - [OP Succinct Lite architecture](https://succinctlabs.github.io/op-succinct/fault_proofs/fault_proof_architecture.html) - [OPSuccinctFaultDisputeGame.sol - Etherscan source code](https://etherscan.io/address/0x8841FA06099FEdfE7DB6962926C6A281e9E1e607#code) - [SP1VerifierGateway.sol - Etherscan source code](https://etherscan.io/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e#code) ## Upgrades & Governance The regular upgrade process for shared system contracts and L2-specific validium contracts starts at the PolygonAdminMultisig. For the shared contracts, they schedule a transaction that targets the ProxyAdmin via the Timelock, wait for 3d and then execute the upgrade. An upgrade of the Layer 2 specific validium contract requires first adding a new rollupType through the Timelock and the AgglayerManager (defining the new implementation and verifier contracts). Now that the rollupType is created, either the local admin or the PolygonAdminMultisig can immediately upgrade the local system contracts to it. Chains using pessimistic proofs often have completely sovereign upgrade paths from the ones described here, but the shared contracts still remain relevant to them because they use them as escrow. The PolygonSecurityCouncil can expedite the upgrade process by declaring an emergency state. This state pauses both the shared bridge and the AgglayerManager and allows for instant upgrades through the timelock. Accordingly, instant upgrades for all system contracts are possible with the cooperation of the SecurityCouncil. The emergency state has been activated 1 time(s) since inception. Furthermore, the PolygonAdminMultisig is permissioned to manage the shared trusted aggregator (proposer and prover) for all participating Layer 2s, deactivate the emergency state, obsolete rollupTypes and manage operational parameters and fees in the AgglayerManager directly. The local admin of a specific Aggchain can manage their chain by choosing the trusted sequencer, manage forced batches and set the data availability config. For sovereign chains using pessimistic proofs they can manage any proof logic that might be used on top of the minimal pessimistic one. Creating new Layer 2s (of existing rollupType) is outsourced to the PolygonCreateRollupMultisig but can also be done by the PolygonAdminMultisig. Custom non-shared bridge escrows have their custom upgrade admins listed in the permissions section. ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/xlayer#updates). ## Operator ### Users can force any transaction Because the state of the system is based on transactions submitted on the underlying host chain and anyone can submit their transactions there it allows the users to circumvent censorship by interacting with the smart contract on the host chain directly. ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks. **References** - [AgglayerBridge.sol - source code, claimAsset function](https://etherscan.io/address/0x66E0120e3c965552a89AcC37b03f762624baC5Ad#code) ## Other considerations ### Agglayer shared bridge and OP Stack state validation X Layer uses OP Stack dispute games for state validation and withdrawal finalization. Separately, the Agglayer shared bridge uses pessimistic proofs to constrain cross-chain bridge accounting for assets in the shared bridge. **Risks** - Funds can be lost if the Agglayer pessimistic proof system for shared bridge accounting is implemented incorrectly. - Funds can be frozen if the OP Succinct Lite proof system or verifier gateway cannot accept valid proofs during a challenge. **References** - [Pessimistic Proof - Polygon Knowledge Layer](https://docs.polygon.technology/cdk/concepts/pessimistic-proofs) ## Permissions ### Ethereum #### Actors ##### PolygonAdminMultisig Addresses: [0x242daE44F5d8fb54B198D03a94dA45B5a4413e21](https://etherscan.io/address/0x242daE44F5d8fb54B198D03a94dA45B5a4413e21) A Multisig with 5/9 threshold. * Can upgrade **with 3d delay** * AgglayerGateway [via: Timelock with 3d delay (no delay if in emergency state) → SharedProxyAdmin] * AgglayerBridge [via: Timelock with 3d delay (no delay if in emergency state) → SharedProxyAdmin] * AgglayerManager [via: Timelock with 3d delay (no delay if in emergency state) → SharedProxyAdmin] * AgglayerGER [via: Timelock with 3d delay (no delay if in emergency state) → SharedProxyAdmin] * Can interact with AgglayerGateway * add new routes from proof selector to verifier / pessimisticVkey for pessimistic proofs **with 3d delay** [via: Timelock with 3d delay (no delay if in emergency state)] * add or update default aggchain verification keys (aggchainVkey) for any given selectors * change the aggchainSigners and threshold (a multisig used for permissioned state transitions) * freeze routes from proof selector to verifier / pessimisticVkey for pessimistic proofs * Can interact with AgglayerBridge * upgrade the implementation of wrapped tokens deployed by the bridge **with 3d delay** [via: Timelock with 3d delay (no delay if in emergency state)] * Can interact with AgglayerManager * deploy new projects that use predefined rollup types (implementations) and connect them or other Agglayer chains to the PolygonRollupManager * manage all access control roles, add new rollup types (which are implementation contracts that can then be upgraded to by connected projects), update any connected projects to new rollup types, migrate to pessimistic proofs and rollback batches, connect existing rollups to the PolygonRollupManager **with 3d delay** [via: Timelock with 3d delay (no delay if in emergency state)] * manage parameters like fees for all connected projects, set the trusted aggregator, stop the emergency state, update projects and obsolete rollup types * Can interact with Timelock * propose, cancel and execute transactions in the timelock, manage all access control roles and change the minimum delay **with 6d delay or with 3d delay** [via: Timelock with 3d delay (no delay if in emergency state) with 3d delay (no delay if in emergency state) - or - acting directly with 3d delay (no delay if in emergency state)] ##### Xlayer Multisig Addresses: [0xC290bE56089BCC83c6993583ce2cF51a7951D45A](https://etherscan.io/address/0xC290bE56089BCC83c6993583ce2cF51a7951D45A) A Multisig with 2/3 threshold. * Can upgrade **with no delay** * AnchorStateRegistry [via: ProxyAdmin] * DelayedWETH [via: ProxyAdmin] * SystemConfig [via: ProxyAdmin] * OptimismMintableERC20Factory [via: ProxyAdmin] * OptimismPortal2 [via: ProxyAdmin] * L1ERC721Bridge_neutered [via: ProxyAdmin] * L1StandardBridge_neutered [via: ProxyAdmin] * L1CrossDomainMessenger [via: ProxyAdmin] * Can upgrade **with 1h delay** * DisputeGameFactory [via: TimelockController with 1h delay → ProxyAdmin] * Can interact with DisputeGameFactory * set the dispute game implementation and initial bond for any game type **with 1h delay** [via: TimelockController with 1h delay] * Can interact with AddressManager * set and change address mappings [via: ProxyAdmin] * Can interact with TimelockController * cancel queued transactions * manage all access control roles **with 1h delay** [via: TimelockController with 1h delay] * propose transactions ##### AgglayerManager Addresses: [0x5132A183E9F3CB7C848b0AAC5Ae0c4f0491B7aB2](https://etherscan.io/address/0x5132A183E9F3CB7C848b0AAC5Ae0c4f0491B7aB2) The central shared managing contract for Polygon Agglayer chains. This contract coordinates chain deployments and proof validation. All connected Layer 2s can be globally paused by activating the 'Emergency State'. This can be done by the PolygonSecurityCouncil or by anyone after 1 week of inactive verifiers. * Can upgrade **with no delay** * AggchainECDSAMultisig ##### PolygonSecurityCouncil Addresses: [0x37c58Dfa7BF0A165C5AAEdDf3e2EdB475ac6Dcb6](https://etherscan.io/address/0x37c58Dfa7BF0A165C5AAEdDf3e2EdB475ac6Dcb6) A Multisig with 6/8 threshold. * Can interact with AgglayerManager * activate the emergency state in the PolygonRollupManager and in the shared bridge immediately, effectively pausing all projects connected to them and making system contracts instantly upgradable ##### PolygonCreateRollupMultisig Addresses: [0xC74eFc7fdb3BeC9c6930E91FFDF761b160dF79dB](https://etherscan.io/address/0xC74eFc7fdb3BeC9c6930E91FFDF761b160dF79dB) A Multisig with 3/5 threshold. * Can interact with AgglayerManager * deploy new projects that use predefined rollup types (implementations) and connect them or other Agglayer chains to the PolygonRollupManager ##### SP1VerifierGatewayMultisig Addresses: [0xCafEf00d348Adbd57c37d1B77e0619C6244C6878](https://etherscan.io/address/0xCafEf00d348Adbd57c37d1B77e0619C6244C6878) A Multisig with 2/3 threshold. * Can interact with SP1VerifierGatewayOlder * affect the liveness and safety of the gateway - can transfer ownership, add and freeze verifier routes ##### EOA 1 Addresses: [0x491619874b866c3cDB7C8553877da223525ead01](https://etherscan.io/address/0x491619874b866c3cDB7C8553877da223525ead01) * Can interact with AggchainECDSAMultisig * sole address that can force batches ##### EOA 2 Addresses: [0x610DE9141a2c51A9A9624278AA97fbE54b27c102](https://etherscan.io/address/0x610DE9141a2c51A9A9624278AA97fbE54b27c102) * Can interact with AggchainECDSAMultisig * sign state transitions (replaces state validation for this aggchain) ##### EOA 3 Addresses: [0x98245d0ADF4595C66F0a9Db8E13c44CBFF6be459](https://etherscan.io/address/0x98245d0ADF4595C66F0a9Db8E13c44CBFF6be459) * Can interact with SystemConfig * Allowed to commit transactions from the current layer to the host chain ##### EOA 4 Addresses: [0xa90B4C8B8807569980F6cC958c8905383136B5eA](https://etherscan.io/address/0xa90B4C8B8807569980F6cC958c8905383136B5eA) * Can interact with AggchainECDSAMultisig * set the trusted sequencer address ##### EOA 5 Addresses: [0x6eE7BDa7AF04F61ccf93aB4b8DB2289aBe76C6aA](https://etherscan.io/address/0x6eE7BDa7AF04F61ccf93aB4b8DB2289aBe76C6aA) Member of Xlayer Multisig. * Can upgrade **with no delay** * SuperchainConfig [via: OwnerContract → ProxyAdmin] * Can interact with SystemConfig * it can update the preconfer address, the batch submitter (Sequencer) address and the gas configuration of the system * Can interact with AccessManager * Allowed to add or remove proposers and challengers, and transfer ownership of the AccessManager ##### EOA 6 Addresses: [0x20A53dCb196cD2bcc14Ece01F358f1C849aA51dE](https://etherscan.io/address/0x20A53dCb196cD2bcc14Ece01F358f1C849aA51dE) * Can interact with AgglayerManager * Permissioned to post new state roots and global exit roots accompanied by ZK proofs ##### EOA 7 Addresses: [0x736E68Af2CbF2aB0E46E4310fE5Ae568b3642FF6](https://etherscan.io/address/0x736E68Af2CbF2aB0E46E4310fE5Ae568b3642FF6) * Can interact with AccessManager * Allowed to challenge or delete state roots proposed by a Proposer * Can interact with PermissionedDisputeGame * Allowed to challenge or delete state roots proposed by a Proposer ##### EOA 8 Addresses: [0xE43944421681170648E10007f73816e04F74394F](https://etherscan.io/address/0xE43944421681170648E10007f73816e04F74394F) * Can interact with AccessManager * Allowed to post new state roots of the current layer to the host chain * Can interact with PermissionedDisputeGame * Allowed to post new state roots of the current layer to the host chain ## Smart contracts ### Ethereum #### AggchainECDSAMultisig Addresses: [0x2B0ee28D4D51bC9aDde5E58E295873F61F4a0507](https://etherscan.io/address/0x2B0ee28D4D51bC9aDde5E58E295873F61F4a0507#code), [0x0D49fD0d79723e4D24AaC83f604ED2D3d5fC0f21](https://etherscan.io/address/0x0D49fD0d79723e4D24AaC83f604ED2D3d5fC0f21#code) (Implementation (Upgradable)), [0x5132A183E9F3CB7C848b0AAC5Ae0c4f0491B7aB2](https://etherscan.io/address/0x5132A183E9F3CB7C848b0AAC5Ae0c4f0491B7aB2#code) (Admin) System contract defining the X Layer Aggchain logic. It only enforces bridge accounting (pessimistic) proofs to protect the shared bridge while the Aggchain state transitions are not proven. They must instead be signed by 1 aggchainSigner(s). * Roles: * **admin**: AgglayerManager, EOA 4 * **aggchainSigners**: EOA 2 * **forceBatchAddress**: EOA 1 Can be upgraded by: AgglayerManager with no delay #### SystemConfig Addresses: [0x5065809Af286321a05fBF85713B5D5De7C8f0433](https://etherscan.io/address/0x5065809Af286321a05fBF85713B5D5De7C8f0433#code), [0xfCA51bf5bDc5aC16B86F859d6BEe90cfdF6fEb72](https://etherscan.io/address/0xfCA51bf5bDc5aC16B86F859d6BEe90cfdF6fEb72#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Contains configuration parameters such as the Sequencer address, gas limit on this chain and the unsafe block signer address. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig * **batcherHash**: EOA 3 * **owner**: EOA 5 Can be upgraded by: Xlayer Multisig with no delay #### OptimismPortal2 Addresses: [0x64057ad1DdAc804d0D26A7275b193D9DACa19993](https://etherscan.io/address/0x64057ad1DdAc804d0D26A7275b193D9DACa19993#code), [0xa0fEfC3A457F6A1aE2d81FC172D6dE090a9F4033](https://etherscan.io/address/0xa0fEfC3A457F6A1aE2d81FC172D6dE090a9F4033#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Central message and gas token (dOKB) bridge of the OP stack part of this deployment. It finalizes withdrawals against the currently respected OP Succinct Lite dispute game and allows forced transactions. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### DisputeGameFactory Addresses: [0x9D4c8FAEadDdDeeE1Ed0c92dAbAD815c2484f675](https://etherscan.io/address/0x9D4c8FAEadDdDeeE1Ed0c92dAbAD815c2484f675#code), [0x74Fac1D45B98bae058F8F566201c9A81B85C7D50](https://etherscan.io/address/0x74Fac1D45B98bae058F8F566201c9A81B85C7D50#code) (Implementation (Upgradable)), [0xE8b516B3Bf9A6593696462953d98991202f890Ee](https://etherscan.io/address/0xE8b516B3Bf9A6593696462953d98991202f890Ee#code) (Admin) The dispute game factory allows the creation of dispute games, used to propose state roots and eventually challenge them. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig * **owner**: TimelockController; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with 1h delay #### AgglayerGateway Addresses: [0x046Bb8bb98Db4ceCbB2929542686B74b516274b3](https://etherscan.io/address/0x046Bb8bb98Db4ceCbB2929542686B74b516274b3#code), [0xD062B7f9fbB89bdA59262E77015C34a27Dc9aB49](https://etherscan.io/address/0xD062B7f9fbB89bdA59262E77015C34a27Dc9aB49#code) (Implementation (Upgradable)), [0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A](https://etherscan.io/address/0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A#code) (Admin) A verifier gateway for pessimistic proofs. Manages a map of chains and their verifier keys and is used to route proofs based on the first 4 bytes of proofBytes data in a proof submission. The SP1 verifier is used for all proofs. * Roles: * **addPpRoute**: Timelock; ultimately PolygonAdminMultisig * **admin**: SharedProxyAdmin; ultimately PolygonAdminMultisig * **aggchainDefaultVKey**: PolygonAdminMultisig * **alMultisig**: PolygonAdminMultisig * **freezePpRoute**: PolygonAdminMultisig Can be upgraded by: PolygonAdminMultisig with 3d delay #### AgglayerBridge Addresses: [0x2a3DD3EB832aF982ec71669E178424b10Dca2EDe](https://etherscan.io/address/0x2a3DD3EB832aF982ec71669E178424b10Dca2EDe#code), [0x66E0120e3c965552a89AcC37b03f762624baC5Ad](https://etherscan.io/address/0x66E0120e3c965552a89AcC37b03f762624baC5Ad#code) (Implementation (Upgradable)), [0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A](https://etherscan.io/address/0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A#code) (Admin) The shared bridge contract, escrowing user funds sent to Agglayer chains. It is usually mirrored on each chain and can be used to transfer both ERC20 assets and arbitrary messages. * Roles: * **admin**: SharedProxyAdmin; ultimately PolygonAdminMultisig * **proxiedTokensManager**: Timelock; ultimately PolygonAdminMultisig Can be upgraded by: PolygonAdminMultisig with 3d delay #### AgglayerGER Addresses: [0x580bda1e7A0CFAe92Fa7F6c20A3794F169CE3CFb](https://etherscan.io/address/0x580bda1e7A0CFAe92Fa7F6c20A3794F169CE3CFb#code), [0x7F1655d9d570167B2a3FfD1Ef809D3Fdd74427C5](https://etherscan.io/address/0x7F1655d9d570167B2a3FfD1Ef809D3Fdd74427C5#code) (Implementation (Upgradable)), [0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A](https://etherscan.io/address/0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A#code) (Admin) A merkle tree storage contract aggregating state roots of each participating Layer 2, thus creating a single global merkle root representing the global state of the Agglayer, the 'global exit root'. The global exit root is synchronized to all connected Layer 2s to help with their interoperability. * Roles: * **admin**: SharedProxyAdmin; ultimately PolygonAdminMultisig Can be upgraded by: PolygonAdminMultisig with 3d delay #### Timelock Addresses: [0xEf1462451C30Ea7aD8555386226059Fe837CA4EF](https://etherscan.io/address/0xEf1462451C30Ea7aD8555386226059Fe837CA4EF#code) A timelock with access control. In the case of an activated emergency state in the AgglayerManager, all transactions through this timelock are immediately executable. The current minimum delay is 3d. * Roles: * **timelockAdmin**: PolygonAdminMultisig (no delay if in emergency state), Timelock (no delay if in emergency state); ultimately PolygonAdminMultisig (no delay if in emergency state) #### L1CrossDomainMessenger Addresses: [0xF94B553F3602a03931e5D10CaB343C0968D793e3](https://etherscan.io/address/0xF94B553F3602a03931e5D10CaB343C0968D793e3#code), [0xb686F13AfF1e427a1f993F29ab0F2E7383729FE0](https://etherscan.io/address/0xb686F13AfF1e427a1f993F29ab0F2E7383729FE0#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Sends messages from host chain to this chain, and relays messages back onto host chain. In the event that a message sent from host chain to this chain is rejected for exceeding this chain's epoch gas limit, it can be resubmitted via this contract's replay function. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### AnchorStateRegistry Addresses: [0x000590BB65ab1864a7AD46d6B957cC9a4F2C149d](https://etherscan.io/address/0x000590BB65ab1864a7AD46d6B957cC9a4F2C149d#code), [0xeb69cC681E8D4a557b30DFFBAd85aFfD47a2CF2E](https://etherscan.io/address/0xeb69cC681E8D4a557b30DFFBAd85aFfD47a2CF2E#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Contains the latest confirmed state root that can be used as a starting point in a dispute game. It specifies which game type can be used for withdrawals, which currently is the OPSuccinctFaultDisputeGame. Variant for chains using OPSuccinct (SP1) games instead of Cannon, which omits Cannon-specific cross-contract fields (vm, oracle, weth, challengePeriod, absolutePrestate from game). * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### DelayedWETH Addresses: [0x1B8A252A71bC8997d3871aF420895B5845212fC6](https://etherscan.io/address/0x1B8A252A71bC8997d3871aF420895B5845212fC6#code), [0x33Dadc2d1aA9BB613A7AE6B28425eA00D44c6998](https://etherscan.io/address/0x33Dadc2d1aA9BB613A7AE6B28425eA00D44c6998#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Contract designed to hold the bonded ETH for each game. It is designed as a wrapper around WETH to allow an owner to function as a backstop if a game would incorrectly distribute funds. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### PreimageOracle Addresses: [0x1fb8cdFc6831fc866Ed9C51aF8817Da5c287aDD3](https://etherscan.io/address/0x1fb8cdFc6831fc866Ed9C51aF8817Da5c287aDD3#code) The PreimageOracle contract is used to load the required data from L1 for a dispute game. #### MIPS Addresses: [0x305D1C0EED9a0291686f3BfDf1F5E54aaeeF80e4](https://etherscan.io/address/0x305D1C0EED9a0291686f3BfDf1F5E54aaeeF80e4#code) The MIPS contract is used to execute the final step of the dispute game which objectively determines the winner of the dispute. #### ProxyAdmin Addresses: [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) * Roles: * **owner**: Xlayer Multisig #### OptimismMintableERC20Factory Addresses: [0x62e1Aaeba9A8AA4654980653dB4B21FC82C61c15](https://etherscan.io/address/0x62e1Aaeba9A8AA4654980653dB4B21FC82C61c15#code), [0x8ee6fB13c6c9a7e401531168E196Fbf8b05cEabB](https://etherscan.io/address/0x8ee6fB13c6c9a7e401531168E196Fbf8b05cEabB#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) A helper contract that generates OptimismMintableERC20 contracts on the network it's deployed to. OptimismMintableERC20 is a standard extension of the base ERC20 token contract designed to allow the L1StandardBridge contracts to mint and burn tokens. This makes it possible to use an OptimismMintableERC20 as this chain's representation of a token on the host chain, or vice-versa. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### L1ERC721Bridge_neutered Addresses: [0x85d37236f063C687d056b3604CBEe4B60d124858](https://etherscan.io/address/0x85d37236f063C687d056b3604CBEe4B60d124858#code), [0xFbd06fCb2a023d89a7ae9BeE89d157C5264cf42b](https://etherscan.io/address/0xFbd06fCb2a023d89a7ae9BeE89d157C5264cf42b#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) Used to bridge ERC-721 tokens from host chain to this chain. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### OPSuccinctFaultDisputeGame Addresses: [0x8841FA06099FEdfE7DB6962926C6A281e9E1e607](https://etherscan.io/address/0x8841FA06099FEdfE7DB6962926C6A281e9E1e607#code) Logic of the dispute game. When a state root is proposed, a dispute game contract is deployed. Challengers can use such contracts to challenge the proposed state root. #### AccessManager Addresses: [0x98BA64d8c8Dd33bD75F2154214BFd849d0D5c17B](https://etherscan.io/address/0x98BA64d8c8Dd33bD75F2154214BFd849d0D5c17B#code) Contract managing access control for proposers and challengers in OPSuccinct. * Roles: * **challengers**: EOA 7 * **owner**: EOA 5 * **proposers**: EOA 8 #### L1StandardBridge_neutered Addresses: [0xAecF995ABf9E7eDE7ae0CE65E60622C9eD84823a](https://etherscan.io/address/0xAecF995ABf9E7eDE7ae0CE65E60622C9eD84823a#code), [0x2978527d5D1372C32fEdC182FDE7559c0471d051](https://etherscan.io/address/0x2978527d5D1372C32fEdC182FDE7559c0471d051#code) (Implementation (Upgradable)), [0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6](https://etherscan.io/address/0x313ce9Cec2070B519f13BDaFe07eabb4f215FEE6#code) (Admin) This OP stack bridge contract has been modified to disallow ETH and ERC-20 bridging. * Roles: * **admin**: ProxyAdmin; ultimately Xlayer Multisig Can be upgraded by: Xlayer Multisig with no delay #### ProxyAdmin Addresses: [0xC6901aBf8D39079d6b028dA550BB643f10840552](https://etherscan.io/address/0xC6901aBf8D39079d6b028dA550BB643f10840552#code) * Roles: * **owner**: OwnerContract #### OwnerContract Addresses: [0xe58C365Da30c746204022e61482bBE828cAA9091](https://etherscan.io/address/0xe58C365Da30c746204022e61482bBE828cAA9091#code) A minimal contract that lets its owner send arbitrary calls and delegatecalls. * Roles: * **owner**: EOA 5 #### ProxyAdmin Addresses: [0xE8b516B3Bf9A6593696462953d98991202f890Ee](https://etherscan.io/address/0xE8b516B3Bf9A6593696462953d98991202f890Ee#code) * Roles: * **owner**: TimelockController #### PermissionedDisputeGame Addresses: [0xEeDa796a23bc98726e47934ca9B54fDDa5a608e8](https://etherscan.io/address/0xEeDa796a23bc98726e47934ca9B54fDDa5a608e8#code) Same as FaultDisputeGame, but only two permissioned addresses are designated as proposer and challenger. * Roles: * **challenger**: EOA 7 * **proposer**: EOA 8 #### TimelockController Addresses: [0xFa3A5834D9990B94045C7b3229547FF101D552d6](https://etherscan.io/address/0xFa3A5834D9990B94045C7b3229547FF101D552d6#code) A timelock with access control. The current minimum delay is 1h. * Roles: * **canceller**: Xlayer Multisig * **defaultAdmin**: TimelockController; ultimately Xlayer Multisig * **proposer**: Xlayer Multisig #### SP1Verifier Addresses: [0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459](https://etherscan.io/address/0x0459d576A6223fEeA177Fb3DF53C9c77BF84C459#code) Verifier contract for SP1 proofs (v5.0.0). #### SharedProxyAdmin Addresses: [0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A](https://etherscan.io/address/0x0F99738B2Fc14D77308337f3e2596b63aE7BCC4A#code) * Roles: * **owner**: Timelock #### BridgeLib Addresses: [0x3622Fcf450ca40a340b7492Ae5F60E7c7Ea68aB3](https://etherscan.io/address/0x3622Fcf450ca40a340b7492Ae5F60E7c7Ea68aB3#code) Extension contract of the AgglayerBridge for asset metadata.. #### SP1Verifier Addresses: [0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A](https://etherscan.io/address/0xc3c6dDDAc8829b233Dc6536Ec024775a57b0AF2A#code) Verifier contract for SP1 proofs (v6.1.0). #### SP1VerifierGatewayOlder Addresses: [0x397A5f7f3dBd538f23DE225B51f532c34448dA9B](https://etherscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B#code) This contract is the router for zk proof verification. It stores the mapping between identifiers and the address of onchain verifier contracts, routing each identifier to the corresponding verifier contract. * Roles: * **owner**: SP1VerifierGatewayMultisig #### SP1Verifier Addresses: [0x50ACFBEdecf4cbe350E1a86fC6f03a821772f1e5](https://etherscan.io/address/0x50ACFBEdecf4cbe350E1a86fC6f03a821772f1e5#code) Verifier contract for SP1 proofs (v5.0.0). #### SP1Verifier Addresses: [0x99A74A05a0FaBEB217C1A329b0dac59a1FA52508](https://etherscan.io/address/0x99A74A05a0FaBEB217C1A329b0dac59a1FA52508#code) Verifier contract for SP1 proofs (v6.0.0). #### SP1Verifier Addresses: [0xb69f2584CBcFf99a58C4e7002E8b89Af54a6f4e2](https://etherscan.io/address/0xb69f2584CBcFf99a58C4e7002E8b89Af54a6f4e2#code) Verifier contract for SP1 proofs (v6.1.0). The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).