# ZKFair Markdown version of https://l2beat.com/layer2s/projects/zkfair ## Summary **Warning:** The canonical bridge escrow was upgraded to an unverified implementation and user funds were moved to [an EOA, then deposited to AAVE](https://etherscan.io/tx/0x0f1ca15e92757dc08e1ac62ef5cfc45a37735c589c655f521f0fd99fb0d5a5d2). They were subsequently withdrawn and [moved to a new contract](https://etherscan.io/tx/0x59304b6420a556c303b4fbcc0608c14d57d06b7aa13366f3851b3be3d6e167ed). Related [tweet by the ZKFair team](https://x.com/ZKFCommunity/status/1910329561105252694). - Total Value Secured: $63.94 K (-0.30% compared to seven days ago; canonically bridged $14.99 K, natively minted $48.95 K, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - **Warning:** The ZKF token associated with ZKFair accounts for 76.5% of the TVS! (sentiment: warning) - Past day UOPS: <0.01 (-28.5% compared to seven days ago) - Type: Other - Purpose: Universal - Host chain: Ethereum - Chain ID: 42766 ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: Validity proofs (SN) (sentiment: good) - Data availability: External (DAC) (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Self propose (sentiment: good) ### About ZKFair is a Validium based on Polygon CDK and Celestia DA. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/zkfair#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/zkfair) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/zkfair/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/zkfair#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/zkfair) ## Milestones & Incidents - 2023-12-20: [ZKFair Mainnet is Live](https://twitter.com/ZKFCommunity/status/1737307444181869017). ZKFair launched. ## Risk summary **Warning:** 2 addresses have unverified source code (CRITICAL). - Bridge: 0xb10f60B4Ea978CA02aFBAC57fa84907e8439766e - OldBridge: 0x9cb4706e20A18E59a48ffa7616d700A3891e1861 **Warning:** The forced transaction mechanism is currently disabled. The project claims to use CelestiaDA but smart contracts on L1 use DAC. Arbitrary messaging passing is removed from the bridge. ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is a 1d delay on code upgrades, 2. the source code of unverified contracts contains malicious code (CRITICAL). ### Funds can be lost if 3. the external data becomes unavailable (CRITICAL). ### Funds can be frozen if 4. the sequencer refuses to include an exit transaction (CRITICAL). ### Users can be censored if 5. the operator refuses to include their transactions. ### MEV can be extracted if 6. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis **Warning:** The canonical bridge escrow was upgraded to an unverified implementation and user funds were moved to [an EOA, then deposited to AAVE](https://etherscan.io/tx/0x0f1ca15e92757dc08e1ac62ef5cfc45a37735c589c655f521f0fd99fb0d5a5d2). They were subsequently withdrawn and [moved to a new contract](https://etherscan.io/tx/0x59304b6420a556c303b4fbcc0608c14d57d06b7aa13366f3851b3be3d6e167ed). Related [tweet by the ZKFair team](https://x.com/ZKFCommunity/status/1910329561105252694). **Warning:** The forced transaction mechanism is currently disabled. The project claims to use CelestiaDA but smart contracts on L1 use DAC. Arbitrary messaging passing is removed from the bridge. ### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. Although the functionality exists in the code, it is currently disabled. ### State validation Validity proofs (SN) (sentiment: good) SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setup. ### Data availability External (DAC) (sentiment: bad) Proof construction relies fully on data that is NOT published onchain. There exists a Data Availability Committee (DAC) with a threshold of 3/5 that is tasked with protecting and supplying the data. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Self propose (sentiment: good) If the Proposer fails, users can leverage the source available prover to submit proofs to the L1 bridge. There is a 5d delay for proving and a 5d delay for finalizing state proven in this way. These delays can only be lowered except during the emergency state. ## Data availability Set of parties responsible for signing and attesting to the availability of data. ### Risk analysis #### Economic security None (sentiment: bad) There are no onchain assets at risk of being slashed in case of a data withholding attack, and the committee members are not publicly known. #### Fraud detection None (sentiment: bad) There is no fraud detection mechanism in place. A data withholding attack can only be detected by nodes downloading the full data from the DA layer. #### Committee security 3/5 (sentiment: bad) The committee does not meet basic security standards, either due to insufficient size, lack of member diversity, or poorly defined threshold parameters. The system lacks an effective DA bridge and it is reliant on the assumption of an honest sequencer, creating significant risks to data integrity and availability. #### Upgradeability No delay (sentiment: bad) There is no delay in the upgradeability of the bridge. Users have no time to exit the system before the bridge implementation update is completed. #### Relayer failure No mechanism (sentiment: bad) The relayer role is permissioned, and the DA bridge does not have a Security Council or a governance mechanism to propose new relayers. In case of relayer failure, the DA bridge will halt and be unable to recover without the intervention of a centralized entity. ### Technology #### Architecture ![polygoncdk architecture](https://l2beat.com/images/da-layer-technology/polygoncdk/architecture.png#center) Polygon CDK validiums utilize a data availability solution that relies on a Data Availability Committee (DAC) to ensure data integrity and manage off-chain transaction data. This architecture comprises the following components: - **Operator**: A trusted entity that collects transactions, computes hash values for the transaction batch, and then requests and collects signatures from Committee members. - **Data Availability Committee (DAC)**: A group of nodes responsible for validating batch data against the hash values provided by the operator (sequencer), ensuring the data accurately represents the transactions. - **PolygonCommittee Contract**: Contract responsible for managing the data committee members list. Each DAC node independently validates the batch data, ensuring it matches the received hash values. Upon successful validation, DAC members store the hash values locally and generate signatures endorsing the batch's integrity. The sequencer collects these signatures and submits the transactions batch hash together with the aggregated signature on Ethereum. The PolygonCommittee contract is used during batch sequencing to verify that the signature posted by the sequencer was signed off by the DAC members stored in the contract. #### DA Bridge Architecture ![polygoncdk bridge architecture](https://l2beat.com/images/da-bridge-technology/polygoncdk/architectureL2.png#center) The DA commitments are posted to the destination chain through the sequencer inbox, using the inbox as a DA bridge. The DA commitment consists of a data availability message provided as transaction input, made up of a byte array containing the signatures and all the addresses of the committee in ascending order. The sequencer distributes the data and collects signatures from Committee members offchain. Only the DA message is posted by the sequencer to the destination chain inbox (the DA bridge). A separate contract, the PolygonCommittee contract, is used to manage the committee members list and verify the signatures before accepting the DA commitment. **Risks** - Funds can be lost if a malicious committee signs a data availability attestation for an unavailable transaction batch. - Funds can be lost if the bridge contract or its dependencies receive a malicious code upgrade. There is no delay on code upgrades. **References** - [Polygon CDK Validium Documentation](https://docs.polygon.technology/cdk/architecture/cdk-validium/#data-availability-committee-dac) ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. **References** - [ZKFairValidium.sol#L758 - Etherscan source code, _verifyAndRewardBatches function](https://etherscan.io/address/0x668965757127549f8755D2eEd10494B06420213b#code#F8#L758) ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/zkfair#updates). ## Operator ### The system has a centralized sequencer Only a trusted sequencer is allowed to submit transaction batches. A mechanism for users to submit their own batches is currently disabled. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. - Funds can be frozen if the sequencer refuses to include an exit transaction (CRITICAL). **References** - [ZKFairValidium.sol#L61 - Etherscan source code, onlyTrustedSequencer modifier](https://etherscan.io/address/0x668965757127549f8755D2eEd10494B06420213b#code#F8#L461) ### Users can't force any transaction The mechanism for allowing users to submit their own transactions is currently disabled. **Risks** - Users can be censored if the operator refuses to include their transactions. **References** - [ZKFairValidium.sol#L475 - Etherscan source code, isForceBatchAllowed modifier](https://etherscan.io/address/0x668965757127549f8755D2eEd10494B06420213b#code#F8#L475) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks. ## Permissions ### Ethereum #### Actors ##### Sequencer Addresses: [0x9eed06d1566F0cAfdA3df624E2376864cA84Db6c](https://etherscan.io/address/0x9eed06d1566F0cAfdA3df624E2376864cA84Db6c) Its sole purpose and ability is to submit transaction batches. In case they are unavailable users cannot rely on the force batch mechanism because it is currently disabled. ##### Proposer Addresses: [0xd6888c41EeAcc94f4A1CEe7A99E1557aa41FA027](https://etherscan.io/address/0xd6888c41EeAcc94f4A1CEe7A99E1557aa41FA027) The trusted proposer (called Aggregator) provides the ZKFairValidium contract with ZK proofs of the new system state. In case they are unavailable a mechanism for users to submit proofs on their own exists, but is behind a 5d delay for proving and a 5d delay for finalizing state proven in this way. These delays can only be lowered except during the emergency state. ##### ZKFairAdmin Addresses: [0x0110B1B231aA3b96a94c900eb3056297526AB725](https://etherscan.io/address/0x0110B1B231aA3b96a94c900eb3056297526AB725) A Multisig with 3/4 threshold. Admin of the ZKFairValidium, can set core system parameters like timeouts, sequencer and aggregator as well as deactivate emergency state. ##### ZKFairOwner Addresses: [0x8933Fa0A97f39cd38f56b1887d5cc56cF04F3A88](https://etherscan.io/address/0x8933Fa0A97f39cd38f56b1887d5cc56cF04F3A88) A Multisig with 3/4 threshold. The ZkFair Owner is a multisig that can be used to trigger the emergency state which pauses bridge functionality, restricts advancing system state and removes the upgradeability delay. ##### 5 EOAs Addresses: [0x033A75B6B0fc26eDf60e99c4172eB5f87E733ca2](https://etherscan.io/address/0x033A75B6B0fc26eDf60e99c4172eB5f87E733ca2), [0x061D273bEf947BD0ef2B828526e710eEa0f297ae](https://etherscan.io/address/0x061D273bEf947BD0ef2B828526e710eEa0f297ae), [0x9231622437bD57349cC9a15CDEc5383627DEbA17](https://etherscan.io/address/0x9231622437bD57349cC9a15CDEc5383627DEbA17), [0x9d8616545C9941138832EebC58Cb498E0ef21a13](https://etherscan.io/address/0x9d8616545C9941138832EebC58Cb498E0ef21a13), [0xFe1da7CAd939805d4A889822357c348177a5118d](https://etherscan.io/address/0xFe1da7CAd939805d4A889822357c348177a5118d) Members of the Data Availability Committee. The setup is equivalent to a 3/5 multisig. ##### DAC Owner Addresses: [0xa57c2B747193fe3F9CC8bea89103B7d76B8A0c70](https://etherscan.io/address/0xa57c2B747193fe3F9CC8bea89103B7d76B8A0c70) The owner of the Data Availability Committee, can update the member set at any time. ##### 2 EOAs Addresses: [0x75575Dc1adD71eA794A52D83f836a13F7891C527](https://etherscan.io/address/0x75575Dc1adD71eA794A52D83f836a13F7891C527), [0x9412eCbEE1e8dd25F347D6d8002f62eF540ddDAa](https://etherscan.io/address/0x9412eCbEE1e8dd25F347D6d8002f62eF540ddDAa) Controls the upgrades to the ZKFairValidiumDAC and ZKFairValidium contracts through the Timelock. ## Smart contracts ### Ethereum #### ZKFairValidium Addresses: [0x1CbC08bf0D48b18F9f97796c61352b192d1850A5](https://etherscan.io/address/0x1CbC08bf0D48b18F9f97796c61352b192d1850A5#code), [0x668965757127549f8755D2eEd10494B06420213b](https://etherscan.io/address/0x668965757127549f8755D2eEd10494B06420213b#code) (Implementation (Upgradable)), [0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3](https://etherscan.io/address/0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3#code) (Admin) The main contract of the Polygon CDK Validium. It defines the rules of the system including core system parameters, permissioned actors as well as emergency procedures. The emergency state can be activated either by the ZkFair Owner, by proving a soundness error or by presenting a sequenced batch that has not been aggregated before a 7d timeout. This contract receives transaction roots, L2 state roots as well as ZK proofs. It also holds the address of ZKFairValidiumDAC. Can be upgraded by: ZKFairAdmin with None delay **References** - [State injections - stateRoot and exitRoot are part of the validity proof input.](https://etherscan.io/address/0x668965757127549f8755D2eEd10494B06420213b#code#F8#L809) #### Bridge Addresses: [0xb10f60B4Ea978CA02aFBAC57fa84907e8439766e](https://etherscan.io/address/0xb10f60B4Ea978CA02aFBAC57fa84907e8439766e#code) (unverified) The current escrow contract for user funds. The source code of this contract is not verified on Etherscan. #### OldBridge Addresses: [0x9cb4706e20A18E59a48ffa7616d700A3891e1861](https://etherscan.io/address/0x9cb4706e20A18E59a48ffa7616d700A3891e1861#code) (unverified), [0x58371687dc997A7A11154bBcA72aEb15e4Db8F46](https://etherscan.io/address/0x58371687dc997A7A11154bBcA72aEb15e4Db8F46#code) (Implementation (Upgradable), unverified), [0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3](https://etherscan.io/address/0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3#code) (Admin, unverified) Deprecated! Was the escrow contract for user funds. It is mirrored on the L2 side and can be used to transfer ERC20 assets. To transfer funds a user initiated transaction on both sides is required. The source code of this contract is not verified on Etherscan. Can be upgraded by: ZKFairAdmin with None delay #### GlobalExitRoot Addresses: [0x72abD6416Ea2d99ad30C86B90e7409Dc2d1ba40b](https://etherscan.io/address/0x72abD6416Ea2d99ad30C86B90e7409Dc2d1ba40b#code), [0xC4CD3D0b31904969a397A98AcE8bDF2A94ba8615](https://etherscan.io/address/0xC4CD3D0b31904969a397A98AcE8bDF2A94ba8615#code) (Implementation (Upgradable)), [0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3](https://etherscan.io/address/0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3#code) (Admin) Synchronizes deposit and withdraw merkle trees across L1 and L2. The global root from this contract is injected into the L2 contract. Can be upgraded by: ZKFairAdmin with None delay #### FflonkVerifier Addresses: [0x769E285d2120472c3400A09684B82A842012F46d](https://etherscan.io/address/0x769E285d2120472c3400A09684B82A842012F46d#code) An autogenerated contract that verifies ZK proofs in the ZKFairValidium system. #### ZKFairValidiumDAC Addresses: [0x997CfB0838544f68E59f877EDc905001456F125b](https://etherscan.io/address/0x997CfB0838544f68E59f877EDc905001456F125b#code), [0x63150fA72c1c9fF8Fe4438f8355927D3415b0FDc](https://etherscan.io/address/0x63150fA72c1c9fF8Fe4438f8355927D3415b0FDc#code) (Implementation (Upgradable)), [0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3](https://etherscan.io/address/0xb57b9101dEc7dC1635B576fFf71F2f522C970EF3#code) (Admin) Committee attesting that data for a given dataRoot has been published. The DAC Owner can update the member set at any time. Can be upgraded by: ZKFairAdmin with None delay #### Timelock Addresses: [0x52882c7564fAca480549145fAc4d0b09eD0D9c17](https://etherscan.io/address/0x52882c7564fAca480549145fAc4d0b09eD0D9c17#code) Contract upgrades have to go through a 1d timelock unless the Emergency State is activated. It is controlled by the TimelockExecutor. The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is a 1d delay on code upgrades. - Funds can be stolen if the source code of unverified contracts contains malicious code (CRITICAL).