Arbitrum is an Optimistic Rollup that aims to feel exactly like interacting with Ethereum, but with transactions costing a fraction of what they do on L1.
Funds can be stolen if…
Funds can be lost if…
Funds can be frozen if…
MEV can be extracted if…
After some period of time, the published state root is assumed to be correct. For a certain time period, usually one week one of the whitelisted actors can submit a fraud proof that shows that the state was incorrect.
- Funds can be stolen if none of the whitelisted verifiers checks the published state. Fraud proofs assume at least one honest and able validator (CRITICAL).
- MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.
The user initiates the withdrawal by submitting a transaction on L2. When the block containing that transaction is finalized the funds become available for withdrawal on L1. The process of block finalization usually takes several days to complete. Finally the user submits an L1 transaction to claim the funds. This transaction requires a merkle proof.
- Funds can be frozen if the centralized validator goes down. Users cannot produce blocks themselves and exiting the system requires new block production (CRITICAL).
When a user initiates a regular withdrawal a third party verifying the chain can offer to buy this withdrawal by paying the user on L1. The user will get the funds immediately, however the third party has to wait for the block to be finalized. This is implemented as a first party functionality inside Arbitrum's token bridge.
Arbitrum uses the Arbitrum Virtual Machine (AVM) to execute transactions. This is similar to the EVM, but is independent from it and allows fraud proofs to be executed.
- Funds can be lost if there are mistakes in the highly complex AVM implementation.
The system uses the following set of permissioned addresses:
- Arbitrum MultiSig 0xC234…0941 (MultiSig)The admin of all contracts in the system, capable of issuing upgrades without notice and delay. This allows it to censor transactions, upgrade bridge implementation potentially gaining access to all funds stored in a bridge and change the sequencer or any other system component (unlimited upgrade power). It is also the admin of the special purpose smart contracts used by validators.
- MultiSig participants 0x0C88…CE1e (EOA), 0x68aF…6e12 (EOA), 0x8042…951B (EOA), 0xf7FA…59c6 (EOA), 0xc19A…e972 (EOA), 0xc73b…5075 (EOA)These addresses are the participants of the 4/6 Arbitrum MultiSig.
- Sequencer 0xcCe5…0513 (EOA)Central actor allowed to set the order in which L2 transactions are executed.
- They can submit new state roots and challenge state roots. Some of the validators perform their duties through special purpose smart contracts.
The system consists of the following smart contracts:
- ProxyAdmin 0x171a…d7c4This contract is an admin of most other contracts allowed to upgrade their implementations. It is owned by a 4-of-6 multisig.
- Main contract implementing Arbitrum One Rollup. Manages other Rollup components, list of Stakers and Validators. Entry point for Validators creating new Rollup Nodes (state commits) and Challengers submitting fraud proofs.
- Main entry point for the Sequencer submitting transaction batches to a Rollup.
- Entry point for users depositing ETH and sending L1 --> L2 messages. Deposited ETH is escowed in a Bridge contract.
- Contract managing Inboxes and Outboxes. It escrows ETH sent to L2. This contract stores the following tokens: ETH.
- ProxyAdmin (2) 0x9aD4…0aDaThis is a different proxy admin for the three gateway contracts below. It is also owned by a 4-of-6 multisig..
- Router managing token <--> gateway mapping.
- Main entry point for users depositing ERC20 tokens. Upon depositing, on L2 a generic, "wrapped" token will be minted. This contract can store any token
- Main entry point for users depositing ERC20 tokens that require minting custom token on L2. This contract can store any token
- L1DaiGateway 0xD3B5…3011Custom DAI Gateway, main entry point for users depositing DAI to L2 where "canonical" L2 DAI token managed by MakerDAO will be minted. Managed by MakerDAO.
- L1Escrow 0xA10c…9400DAI Vault for custom DAI Gateway managed by MakerDAO. This contract stores the following tokens: DAI.
The current deployment carries some associated risks:
- Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).
- Executing and Securing the Chain - Arbitrum documentation
- Note: onlyValidator modifier
- Submitting Transactions - Arbitrum documentation
- Validators - Arbitrum documentation
- If the sequencer is malicious - Arbitrum documentation
- Mainnet for everyone - Arbitrum Blog
- L2 to L1 Messages Lifecycle - Arbitrum documentation
- Rules for Confirming or Rejecting Rollup Blocks - Arbitrum documentation
- Tradeable Bridge Exits - Arbitrum documentation
- AVM - Arbitrum documentation