# ZKsync Lite Markdown version of https://l2beat.com/layer2s/projects/zksync-lite ## Summary **Warning:** This project is archived and no longer maintained. **Warning:** [ZKsync Lite enters sunset phase](https://x.com/zksync/status/2051210912141295768). - Total Value Secured: $32.33 K (-8.84% compared to seven days ago; canonically bridged $32.33 K, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - TVS by asset: ETH & derivatives $32.33 K (99.9%), Stablecoins $0.04 (0.00%), Other $0.15 (0.00%) - Past day UOPS: No data - Stage: Stage 0 (Appchain: ZKsync Lite provides the infrastructure for token transfer, swaps and NFT minting. Arbitrary contracts are not supported.) - Type: ZK Rollup - Purposes: Payments, Exchange, NFT - Host chain: Ethereum ### Risks - Sequencer failure: Force via L1 (sentiment: good) - State validation: Validity proofs (SN) (No execution delay; sentiment: good) - Data availability: Onchain (sentiment: good) - Exit window: None (emergency upgrade path; sentiment: bad); 7d (regular upgrade path; sentiment: warning) - Proposer failure: Use escape hatch (sentiment: good) ### About ZKsync Lite (formerly ZKsync) is a ZK Rollup platform that supports payments, token swaps and NFT minting. ### Links - Website: https://zksync.io/ - Bridge: https://lite.zksync.io/ - Docs: https://docs.lite.zksync.io/dev/ - Explorer: https://zkscan.io/ - Repository: https://github.com/matter-labs/zksync - Social: https://zksync.mirror.xyz/, https://join.zksync.dev/, https://t.me/zksync, https://twitter.com/zksync, https://twitter.com/zkSyncDevs - Contracts explorer (Disco): https://disco.l2beat.com/ui/p/zksync ### Badges - Application-specific chain: This project is built to operate a specific application - Ethereum with calldata: This project is posting its data to Ethereum as calldata ## Value Secured The interactive TVS charts are shown on [the HTML page](https://l2beat.com/layer2s/projects/zksync-lite#tvs). Token by token: [TVS breakdown](https://l2beat.com/layer2s/projects/zksync-lite/tvs-breakdown). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/zksync-lite?range=max) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/zksync-lite/breakdown) ## Activity The interactive activity chart is shown on [the HTML page](https://l2beat.com/layer2s/projects/zksync-lite#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/zksync-lite?range=max) ## Onchain costs The section shows the operating costs that L2s pay to Ethereum. The interactive costs chart is shown on [the HTML page](https://l2beat.com/layer2s/projects/zksync-lite#onchain-costs). ### Tracked transactions #### Batch submissions - functionCall: 2021-02-09 15:45 UTC - now; currently used; address: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF); selector: 0x45269298; signature: `function commitBlocks((uint32,uint64,bytes32,uint256,bytes32,bytes32), (bytes32,bytes,uint256,(bytes,uint32)[],uint32,uint32)[])` #### Proof submissions - functionCall: 2020-06-15 10:58 UTC - now; currently used; address: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF); selector: 0x83981808; signature: `function proveBlocks((uint32,uint64,bytes32,uint256,bytes32,bytes32)[] calldata _committedBlocks, (uint256[],uint256[],uint256[],uint8[],uint256[16]) memory _proof)` #### State updates - functionCall: 2020-06-15 10:58 UTC - now; currently used; address: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF); selector: 0xb0705b42; signature: `function executeBlocks(((uint32,uint64,bytes32,uint256,bytes32,bytes32),bytes[])[] calldata _blocksData)` ## Liveness This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule. The interactive liveness chart is shown on [the HTML page](https://l2beat.com/layer2s/projects/zksync-lite#liveness). ### Tracked transactions #### Proof submissions - functionCall: 2020-06-15 10:58 UTC - now; currently used; address: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF); selector: 0x83981808; signature: `function proveBlocks((uint32,uint64,bytes32,uint256,bytes32,bytes32)[] calldata _committedBlocks, (uint256[],uint256[],uint256[],uint8[],uint256[16]) memory _proof)` #### State updates - functionCall: 2020-06-15 10:58 UTC - now; currently used; address: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF); selector: 0xb0705b42; signature: `function executeBlocks(((uint32,uint64,bytes32,uint256,bytes32,bytes32),bytes[])[] calldata _blocksData)` ## Milestones & Incidents - 2026-05-04: [ZKsync Lite sunsets](https://x.com/zksync/status/2051210912141295768). Block production halts for ZKsync Lite, and the orderly sunset process begins. - 2023-02-16: [Rebranding](https://blog.matter-labs.io/all-aboard-zksync-era-mainnet-8b8964ba7c59#:~:text=ZKsync%201.0%20is%20now%20zkSync%20Lite). ZKsync becomes ZKsync Lite. - 2020-06-18: [ZKsync 1.0 launch](https://blog.matter-labs.io/zksync-is-live-bringing-trustless-scalable-payments-to-ethereum-9c634b3e6823). ZKsync is live, bringing scalable payments to Ethereum using ZK Rollup technology. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL). ### Funds can be lost if 2. the user is unable to generate the non-trivial ZK proof for exodus withdraw. ### Users can be censored if 3. the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. ### MEV can be extracted if 4. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure Force via L1 (sentiment: good) Users can force the sequencer to include a transaction by submitting a request through L1. If the sequencer censors or is down for for more than 14d, users can use the exit hatch to withdraw their funds. ### State validation Validity proofs (SN) (No execution delay; sentiment: good) SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setup. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window None (emergency upgrade path; sentiment: bad); 7d (regular upgrade path; sentiment: warning) Users have 7d to exit funds in case of an unwanted non-emergency upgrade. There is a 21d delay before a non-emergency upgrade is applied, and withdrawals can take up to 14d to be processed. There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Use escape hatch (sentiment: good) Users are able to trustlessly exit by submitting a zero knowledge proof of funds. ## Stage ZKsync Lite is a Stage 0 Appchain ZK Rollup. Rollup operators cannot compromise the system, but being **application-specific** might bring additional risk. ZKsync Lite provides the infrastructure for token transfer, swaps and NFT minting. Arbitrary contracts are not supported. **Note:** We're still in the process of formalizing how to properly integrate appchains in the Stages framework. ### Stage 0 5 requirements met. - Met: A complete and functional proof system is deployed. - Met: The project calls itself a rollup. - Met: State roots are posted to Ethereum L1. - Met: Inputs for the state transition function are posted to Ethereum L1. - Met: A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://github.com/matter-labs/zksync) ### Stage 1 2 issues need fixing. **Principle** - Issue: Compromising ≥75% of the Security Council should be the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. **Guidelines** - Met: Users are able to exit without the help of the permissioned operators. - Met: In case of an unwanted upgrade by actors more centralized than a Security Council, users have at least 7d to exit. - Met: The proof system meets the minimum trusted setup requirements defined in the L2BEAT [trusted setup assessment framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). - Met: Prover source code is published. - Issue: The Security Council is not properly set up. ### Stage 2 2 issues need fixing. - Issue: Upgrades unrelated to onchain provable bugs provide less than 30d to exit. - Issue: The Security Council's actions are not confined to onchain provable bugs. [Learn more about Stages](https://l2beat.com/stages). Please keep in mind that these stages do not reflect project security, this is an opinionated assessment of project maturity based on subjective criteria, created with a goal of incentivizing projects to push toward better decentralization. Each team may have taken different paths to achieve this goal. ## Data availability ### All data required for proofs is published onchain All the data that is used to construct the system state is published onchain in the form of cheap calldata. This ensures that it will always be available when needed. **References** - [Overview - ZKsync documentation](https://docs.lite.zksync.io/dev/#overview) - [ZkSync.sol - Etherscan source code, commitBlockInfo struct](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L44) Learn more about the DA layer here: [Ethereum](https://l2beat.com/data-availability/projects/ethereum/ethereum) ## State derivation ### Node software The node software is open-sourced and the source can be found [here](https://github.com/matter-labs/zksync). ### Compression scheme No compression, transactions are always the same size. ### Genesis state There is no genesis file nor regenesis for ZKsync Lite. By default, all accounts were empty at the beginning. ### Data format The data format documentations can be found [here](https://github.com/matter-labs/zksync/blob/master/docs/protocol.md#data-format). ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. **References** - [Validity proofs - ZKsync FAQ](https://docs.lite.zksync.io/userdocs/security/#validity-proofs) - [ZkSync.sol - Etherscan source code, proveBlocks function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L568) ## Updates Each date links the update on the HTML page, which also shows its contract diffs. ### [2026-07-23 11:36 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=102b27a0) (1 change) Rotated one Matter Labs ms member. ### [2026-07-22 10:12 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=6987b76e) (11 changes) Downgraded 5/8 owner multisig to 1/1. Note that the project is already sunset and entered the shutdown phase. ### [2026-05-12 10:07 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=720d80b5) (15 changes) Paused deposits to zksync. Upgraded zksync contract by adding token migration to claim distributor: https://disco.l2beat.com/diff/eth:0x8e972b354E6933275513C355Ee14D44A832aD2d9/eth:0x803B96fA3cE086A722CB6C1e2C79D304c8a263Ff. More precisely, added: - `l1ClaimDistributor`. It's supposed to store Merkle root of all toknes `claimRoot` and let users permissionlessly claim their funds agains the root - `pauseDeposits` function that permanently halts deposits into zksync L2 - `setClaimRoot` function that sets withdrawal smart contracts and activates exodus mode - `migrateToken` function that transfers given token to the registered claim distributor contract. Deposits to L2 were halted, claim distributor contract was set to 0x0a14B696350546110a0D8acDb86226983af9D2a0, exodus mode activated and several tokens were migrated to the claim contract. In the exodus mode, tokens could not be deposited and withdrawn, new blocks could not be committed, proven or executed. Config: use the new flattener implementation. ### [2026-03-20 15:22 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=12ac79ff) (1 change) Rotated ms member. ### [2025-12-29 11:33 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=7eca3027) (high severity, 10 changes) Upgraded Safe multisig to version 1.4.1. Also rotated one multisig member, added a new one and increased the threshold. ### [2025-10-07 14:23 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=b4de6ebe) (1 change) Removed old zksync validator. ### [2025-10-06 13:58 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=838b75c8) (high severity, 7 changes) Updated Verifier (diff https://disco.l2beat.com/diff/eth:0x6e95812C432F293b8045811F4B1758285EBDB206/eth:0x57B09100e6160503aBDEBC76012b6c358eA4e462): changed verifier key tree root; two constants not used in verifier aligned with the values used in the rollup contract. See this tweet: https://x.com/zkSyncDevs/status/1968062194832249336. Also added a new validator and changed one multisig member. ### [2025-07-14 12:46 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=fcbbb22a) (11 changes) Discovery rerun on the same block number with only config-related changes. ### [2025-07-01 12:11 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=c40511df) (1 change) ms signer change. ### [2025-03-19 15:45 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=edf80712) (7 changes) MS signer change. ### [2024-12-09 14:41 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=9cde90e1) (1 change) ZkSync Multisig signer replaced. ### [2024-08-15 07:40 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=1481cf0b) (2 changes) Two members of the ZkSync Multisig were replaced. ### [2024-08-14 07:30 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=c25b30d3) (1 change) One ZKsync Multisig member address is replaced with another. ### [2024-08-01 09:21 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=b88659e0) (7 changes) ZKsync lite add one signer (`0xD804aB3355a634aEBd45e1252d6208807defD554`) to their MS2, who is itself just one signer of the SC. ### [2023-11-21 15:45 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=44ba4866) (1 change) Change in the zkSync Era Multisig owners - one address is removed, which makes it a 4/7 Multisig. ### [2023-10-13 12:28 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=ddd3822e) (high severity, 2 changes) Updated verification keys. There are also some other changes in Config.sol, but they are an artefact of Etherscan verification and they are not used in practice. ### [2023-10-02 13:57 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=be487bb6) (1 change) ### [2023-09-26 13:05 UTC](https://l2beat.com/layer2s/projects/zksync-lite?update=bf75b803) (1 change) ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. **References** - [How decentralized is ZKsync - ZKsync FAQ](https://docs.lite.zksync.io/userdocs/decentralization/#how-decentralized-is-zksync) - [ZkSync.sol - Etherscan source code, requireActiveValidator in commitBlock function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L446) ### Users can force exit the system Force exit allows the users to escape censorship by withdrawing their funds. The system allows users to force the withdrawal of funds by submitting a request directly to the contract onchain. The request must be served within a defined time period. If this does not happen, the system will halt regular operation and permit trustless withdrawal of funds. **Risks** - Users can be censored if the operator refuses to include their transactions. However, there exists a mechanism to independently exit the system. **References** - [Priority queue - ZKsync FAQ](https://docs.lite.zksync.io/userdocs/security/#priority-queue) - [ZkSync.sol - Etherscan source code, addPriorityRequest function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L951) - [ZkSync.sol - Etherscan source code, setClaimRoot function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L183) ## Withdrawals ### Regular exit The user initiates the withdrawal by submitting a regular transaction on this chain. When the block containing that transaction is settled the funds become available for withdrawal on L1. ZK proofs are required to settle blocks. Finally the user submits an L1 transaction to claim the funds. **References** - [Withdrawing funds - ZKsync documentation](https://docs.lite.zksync.io/dev/payments/basic/#withdrawing-funds) ### Forced exit If the user experiences censorship from the operator with regular exit they can submit their withdrawal requests directly on L1. The system is then obliged to service this request. Once the force operation is submitted and if the request is serviced, the operation follows the flow of a regular exit. **References** - [Withdrawing funds - ZKsync documentation](https://docs.lite.zksync.io/dev/payments/basic/#withdrawing-funds) - [ZkSync.sol - Etherscan source code, requestFullExit function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L344) - [ZkSync.sol - Etherscan source code, requestFullExitNFT function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F22#L379) ### Emergency exit If the enough time deadline passes and the forced exit is still ignored the user can put the system into Exodus Mode, disallowing further state updates. In that case everybody can withdraw by submitting a zero knowledge proof of their funds with their L1 transaction. **Risks** - Funds can be lost if the user is unable to generate the non-trivial ZK proof for exodus withdraw. **References** - [Withdrawing funds - ZKsync documentation](https://docs.lite.zksync.io/dev/payments/basic/#withdrawing-funds) - [README.md - ZKsync Exit Tool](https://github.com/matter-labs/zksync/tree/master/infrastructure/exit-tool) - [AdditionalZkSync.sol - Etherscan source code, migrateToken function](https://etherscan.io/address/0x803b96fa3ce086a722cb6c1e2c79d304c8a263ff#code#F1#L41) ## Permissions Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/zksync ### Ethereum #### Actors ##### ZkSync Multisig Addresses: [0xE24f4870Ab85DE8E356C5fC56138587206c70d99](https://etherscan.io/address/0xE24f4870Ab85DE8E356C5fC56138587206c70d99) A Multisig with 1/1 threshold. This Multisig is the owner of Upgrade Gatekeeper contract and therefore is allowed to perform upgrades for Governance, Verifier and ZkSync contracts. It can also change the list of active validators and appoint the security council (by upgrading the ZkSync contract). Participants (1): [0x4e4943346848c4867F81dFb37c4cA9C5715A7828](https://etherscan.io/address/0x4e4943346848c4867F81dFb37c4cA9C5715A7828) ##### 15 actors Addresses: [0xa2602ea835E03fb39CeD30B43d6b6EAf6aDe1769](https://etherscan.io/address/0xa2602ea835E03fb39CeD30B43d6b6EAf6aDe1769), [0x9D5d6D4BaCCEDf6ECE1883456AA785dc996df607](https://etherscan.io/address/0x9D5d6D4BaCCEDf6ECE1883456AA785dc996df607), [0x002A5dc50bbB8d5808e418Aeeb9F060a2Ca17346](https://etherscan.io/address/0x002A5dc50bbB8d5808e418Aeeb9F060a2Ca17346), [0x71E805aB236c945165b9Cd0bf95B9f2F0A0488c3](https://etherscan.io/address/0x71E805aB236c945165b9Cd0bf95B9f2F0A0488c3), [0x76C6cE74EAb57254E785d1DcC3f812D274bCcB11](https://etherscan.io/address/0x76C6cE74EAb57254E785d1DcC3f812D274bCcB11), [0xFBfF3FF69D65A9103Bf4fdBf988f5271D12B3190](https://etherscan.io/address/0xFBfF3FF69D65A9103Bf4fdBf988f5271D12B3190), [0xAfC2F2D803479A2AF3A72022D54cc0901a0ec0d6](https://etherscan.io/address/0xAfC2F2D803479A2AF3A72022D54cc0901a0ec0d6), [0x4d1E3089042Ab3A93E03CA88B566b99Bd22438C6](https://etherscan.io/address/0x4d1E3089042Ab3A93E03CA88B566b99Bd22438C6), [0x19eD6cc20D44e5cF4Bb4894F50162F72402d8567](https://etherscan.io/address/0x19eD6cc20D44e5cF4Bb4894F50162F72402d8567), [0x39415255619783A2E71fcF7d8f708A951d92e1b6](https://etherscan.io/address/0x39415255619783A2E71fcF7d8f708A951d92e1b6), [0x399a6a13D298CF3F41a562966C1a450136Ea52C2](https://etherscan.io/address/0x399a6a13D298CF3F41a562966C1a450136Ea52C2), [0xee8AE1F1B4B1E1956C8Bda27eeBCE54Cf0bb5eaB](https://etherscan.io/address/0xee8AE1F1B4B1E1956C8Bda27eeBCE54Cf0bb5eaB), [0xe7CCD4F3feA7df88Cf9B59B30f738ec1E049231f](https://etherscan.io/address/0xe7CCD4F3feA7df88Cf9B59B30f738ec1E049231f), [0xA093284c707e207C36E3FEf9e0B6325fd9d0e33B](https://etherscan.io/address/0xA093284c707e207C36E3FEf9e0B6325fd9d0e33B), [0x225d3822De44E58eE935440E0c0B829C4232086e](https://etherscan.io/address/0x225d3822De44E58eE935440E0c0B829C4232086e) The Security Council's only role is to reduce the upgrade delay to zero if 9 of its members decide to do so. The council has 15 members which are hardcoded into the ZkSync contract. Changing the council requires a ZkSync contract upgrade. **References** - [Security Council Members - Etherscan source code](https://etherscan.io/address/0xBF8ee0141203A7986142000B85f7afaBeee1279d#code#F1#L75) - [Security Council 2.0 - Matter Labs blog post](https://blog.matter-labs.io/security-council-2-0-2337a555f17a) ##### Active validators Addresses: [0x0C6E6F8bb16846a0E9E866F3B9b8ec071f885Df5](https://etherscan.io/address/0x0C6E6F8bb16846a0E9E866F3B9b8ec071f885Df5) Those actors are allowed to propose, revert and execute L2 blocks on L1. ##### Token listing beneficiary Addresses: [0x2A0a81e257a2f5D6eD4F07b81DbDa09F107bd027](https://etherscan.io/address/0x2A0a81e257a2f5D6eD4F07b81DbDa09F107bd027) Account receiving fees for listing tokens. Can be updated by ZkSync Multisig. ## Smart contracts ![A diagram of the smart contract architecture](https://l2beat.com/static/images/architecture/zksync-lite.611ff8d3.png) Explore these contracts and permissions in Disco, L2BEAT's contract explorer: https://disco.l2beat.com/ui/p/zksync ### Ethereum #### ZkSync (escrow) Addresses: [0xaBEA9132b05A70803a4E85094fD0e1800777fBEF](https://etherscan.io/address/0xaBEA9132b05A70803a4E85094fD0e1800777fBEF#code), [0x803B96fA3cE086A722CB6C1e2C79D304c8a263Ff](https://etherscan.io/address/0x803B96fA3cE086A722CB6C1e2C79D304c8a263Ff#code) (Implementation #1 (Upgradable)), [0xBF8ee0141203A7986142000B85f7afaBeee1279d](https://etherscan.io/address/0xBF8ee0141203A7986142000B85f7afaBeee1279d#code) (Implementation #2 (Upgradable)), [0x38A43F4330f24fe920F943409709fc9A6084C939](https://etherscan.io/address/0x38A43F4330f24fe920F943409709fc9A6084C939#code) (Admin) The main Rollup contract. Allows the operator to commit blocks, provide ZK proofs (validated by the Verifier) and processes withdrawals by executing blocks. Users can deposit ETH and ERC20 tokens. This contract also defines the upgrade process for all the other contracts by enforcing an upgrade delay and employing the Security Council which can shorten upgrade times. All supported tokens in this escrow are included in the value secured calculation. Can be upgraded by: ZkSync Multisig with 21d or 0 if overridden by 9 of 15 Security Council delay **Upgrade details** When the upgrade process starts only the address of the new implementation is given. The actual upgrade also requires implementation specific calldata which is only provided after the delay has elapsed. Changing the default upgrade delay or the Security Council requires a ZkSync contract upgrade. #### Verifier Addresses: [0x5290E9582B4FB706EaDf87BB1c129e897e04d06D](https://etherscan.io/address/0x5290E9582B4FB706EaDf87BB1c129e897e04d06D#code), [0x57B09100e6160503aBDEBC76012b6c358eA4e462](https://etherscan.io/address/0x57B09100e6160503aBDEBC76012b6c358eA4e462#code) (Implementation (Upgradable)), [0x38A43F4330f24fe920F943409709fc9A6084C939](https://etherscan.io/address/0x38A43F4330f24fe920F943409709fc9A6084C939#code) (Admin) Implements ZK proof verification logic. Can be upgraded by: ZkSync Multisig with 21d or 0 if overridden by 9 of 15 Security Council delay **Upgrade details** When the upgrade process starts only the address of the new implementation is given. The actual upgrade also requires implementation specific calldata which is only provided after the delay has elapsed. Changing the default upgrade delay or the Security Council requires a ZkSync contract upgrade. #### Governance Addresses: [0x34460C0EB5074C29A9F6FE13b8e7E23A0D08aF01](https://etherscan.io/address/0x34460C0EB5074C29A9F6FE13b8e7E23A0D08aF01#code), [0x3FBc7C6c2437dE24F91b2Ca61Fc7AD3D2D62F4c8](https://etherscan.io/address/0x3FBc7C6c2437dE24F91b2Ca61Fc7AD3D2D62F4c8#code) (Implementation (Upgradable)), [0x38A43F4330f24fe920F943409709fc9A6084C939](https://etherscan.io/address/0x38A43F4330f24fe920F943409709fc9A6084C939#code) (Admin) Keeps a list of block producers, NFT factories and whitelisted tokens. Can be upgraded by: ZkSync Multisig with 21d or 0 if overridden by 9 of 15 Security Council delay **Upgrade details** When the upgrade process starts only the address of the new implementation is given. The actual upgrade also requires implementation specific calldata which is only provided after the delay has elapsed. Changing the default upgrade delay or the Security Council requires a ZkSync contract upgrade. #### UpgradeGatekeeper Addresses: [0x38A43F4330f24fe920F943409709fc9A6084C939](https://etherscan.io/address/0x38A43F4330f24fe920F943409709fc9A6084C939#code) This is the contract that owns Governance, Verifier and ZkSync and facilitates their upgrades. The upgrade constraints are defined by the ZkSync contract. #### TokenGovernance Addresses: [0x35cc31f63deef017c38d51B038891bAE7d614e86](https://etherscan.io/address/0x35cc31f63deef017c38d51B038891bAE7d614e86#code) Allows anyone to add new ERC20 tokens to ZKsync Lite given sufficient payment. Can be upgraded by: ZkSync Multisig with no delay **References** - [Governance.sol#L93 - Etherscan source code](https://etherscan.io/address/0x3FBc7C6c2437dE24F91b2Ca61Fc7AD3D2D62F4c8#code#F1#L93) #### NftFactory Addresses: [0x7C770595a2Be9A87CF49B35eA9bC534f1a59552D](https://etherscan.io/address/0x7C770595a2Be9A87CF49B35eA9bC534f1a59552D#code) Allows for withdrawing NFTs minted on L2 to L1. Can be upgraded by: ZkSync Multisig with no delay **References** - [Governance.sol#L205 - Etherscan source code](https://etherscan.io/address/0x3FBc7C6c2437dE24F91b2Ca61Fc7AD3D2D62F4c8#code#F1#L) The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).