We are hiring!Join L2BEAT

Layer2.Finance logoLayer2.Finance




Currently the TVL is calculated incorrectly, because it does not take assets locked in DeFi into account.

Layer2.Finance aims to democratize access to DeFi protocols for everyone. Users can aggregate their DeFi usage and save on Ethereum fees.

If you find something wrong on this page you can submit an issue or edit the information.

Risk summary


Fraud proofs ensure state correctness

After some period of time, the published state root is assumed to be correct. For a certain time period, usually one week anyone can submit a fraud proof that shows that the state was incorrect. Unfortunately in case of Layer2.Finance only some fraud proofs revert blocks and every successful fraud proof pauses the contract requiring the owner to unpause.

  • Funds can be stolen if there is no one that checks the published state. Fraud proofs assume at least one honest and able validator.

  • Funds can be frozen if the problematic fraud proof mechanism is exploited (CRITICAL).

  1. Which L2 scaling paradigm is Layer2.Finance using - Layer2.Finance FAQ
  2. RollupChain.sol#L441 - Layer2.Finance source code
  3. RollupChain.sol#L605 - Layer2.Finance source code

All data required for proofs is published on chain

All the data that is used to construct the system state is published on chain in the form of cheap calldata. This ensures that it will always be available when needed.

  1. RollupChain.sol#L191 - Layer2.Finance source code


The system has a centralized operator

The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system.

  • MEV can be extracted if the operator exploits their centralized position and frontruns user transactions.

  • Funds can be frozen if the sequencer halts its operations (CRITICAL).

  1. RollupChain.sol#L191 - Layer2.Finance source code
  2. Layer2.finance - Celer Network blog

There is no force transaction mechanism

If the users find themselves censored they can do nothing to force the inclusion of their transactions.

  • Users can be censored if the sequencer refuses to include their transactions (CRITICAL).

  1. RollupChain.sol#L191 - Layer2.Finance source code


Regular exit

The user initiates the withdrawal by submitting a transaction on L2. When the block containing that transaction is finalized the funds become available for withdrawal on L1. The process of block finalization usually takes several days to complete. Finally the user submits an L1 transaction to claim the funds. This transaction does not require a merkle proof.

  • Funds can be stolen if the operator does not include user's L2 withdrawal transactions (CRITICAL).

  1. RollupChain.sol#L191 - Layer2.Finance source code

Smart Contracts

The system consists of the following smart contracts:

RollupChain 0xf86F…1A05

This contract stores the following tokens: BUSD, DAI, USDC, USDT, WETH.

TransitionDisputer 0x5D3c…007f
Registry 0xFe81…14a8

The current deployment carries some associated risks:

  • Funds can be stolen if the owner calls owner-only functions that pause the contract and drain funds (CRITICAL).

  1. RollupChain.sol#L460-L496 - Layer2.Finance source code