KETJU Research

← The Register

other

Lighter Bridge (zkLighter)

Rejected
Max sleeve
Reviewed
2026-08-17 · v1
Next review
2026-11-17
Research basis
Individual research
Chains
Ethereum · sovereign

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED ON OPERATIONAL CONCENTRATION AND RECENT LIVENESS FAILURES, NOT ON THE ARCHITECTURE. Lighter (zkLighter) is a custom application-specific ZK rollup for perpetual futures, using genuine SNARK validity proofs to verify every state transition — a stronger cryptographic guarantee against invalid state than Hyperliquid Bridge’s custom validator consensus, already rejected in this registry. But sequencing and batch commitment are controlled by only three externally-owned accounts, not even a multisig, and a separate emergency multisig can collapse the standard 21-day upgrade timelock to zero — the same ”no meaningful delay once an emergency path is invoked” pattern already priced into Base’s cap, but here paired with genuinely thin operational protection rather than a disclosed council. Multiple proof-submission and state-update outages in July and August 2026, including one a week before this review, compound a live reliability concern on top of the governance gap. The proof system is a real strength that should make this a faster reopen than Hyperliquid or Unit once operational maturity catches up.

The research file

Mechanism

Users deposit and withdraw through Ethereum, with a footprint also touching Arbitrum. A Batch Prover generates SNARK proofs, using Plonky2 circuits, of the matching engine’s state transitions, which are verified on-chain. This means the sequencer cannot steal funds through an invalid state transition alone, since incorrect state cannot be proven valid — a strictly stronger default guarantee than an optimistic or BFT-consensus design.

Control and governance

Per L2Beat’s discovery data, batch commitment and execution are controlled by only three externally-owned accounts — not a multisig, a thinner operational trust set than even Unit’s three-guardian MPC setup, though functionally a different kind of control (sequencing versus custody). Standard contract upgrades route through a 3-of-5 multisig with a 21-day timelock, but a separate 4-of-7 emergency multisig can reduce that delay to zero seconds. A forced-inclusion backstop exists: if operators fail to process forced L1 transactions within 14 days, the system enters ”desert mode” and users must exit by proving their balance via ZK proof against the last-settled state — a real escape hatch, but with a much longer stuck-period than Arbitrum’s or Base’s hours-scale force-inclusion window.

Incident record

No fund-loss exploit was identified. But real, recent liveness fragility was: a 4.5-hour downtime on 2025-10-10 from database growth issues, and multiple proof-submission delays in July and August 2026, including a three-hour-38-minute state-update outage on 2026-08-09, roughly a week before this review. This is a current, recurring operational problem, not a resolved historical one.

Exit

The standard path is bridge withdrawal back through Ethereum under normal operation; the ZK-proof desert-mode exit is the stress-case backstop, gated behind the 14-day forced-inclusion deadline described above. This review could not demonstrate a proposed-size withdrawal clearing within a documented maximum time under current operating conditions.

Comparison

Against Hyperliquid Bridge, already rejected in this registry for a 27-validator custom consensus and closed-source client, Lighter’s validity-proof design is a stronger cryptographic guarantee against invalid state. Against Base and Arbitrum’s canonical bridges, both approved with limits, those have broader validator or council sets and faster forced-inclusion windows; Lighter’s three-EOA sequencer and emergency-collapsible 21-day upgrade delay are weaker on the governance-concentration axis even though the underlying proof system is stronger on the correctness axis, and the recent outages are a live reliability concern neither approved peer currently carries.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.