Lighter Bridge (zkLighter)
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON OPERATIONAL CONCENTRATION AND RECENT LIVENESS FAILURES, NOT ON THE ARCHITECTURE. Lighter (zkLighter) is a custom application-specific ZK rollup for perpetual futures, using genuine SNARK validity proofs to verify every state transition — a stronger cryptographic guarantee against invalid state than Hyperliquid Bridge’s custom validator consensus, already rejected in this registry. But sequencing and batch commitment are controlled by only three externally-owned accounts, not even a multisig, and a separate emergency multisig can collapse the standard 21-day upgrade timelock to zero — the same ”no meaningful delay once an emergency path is invoked” pattern already priced into Base’s cap, but here paired with genuinely thin operational protection rather than a disclosed council. Multiple proof-submission and state-update outages in July and August 2026, including one a week before this review, compound a live reliability concern on top of the governance gap. The proof system is a real strength that should make this a faster reopen than Hyperliquid or Unit once operational maturity catches up.
- Sequencer or batch-commitment control moves from three externally-owned accounts to a disclosed multisig of at least 4-of-7 with named or institutionally-accountable operators
- The emergency multisig’s ability to zero out the 21-day upgrade timelock is removed or itself gated behind a minimum delay
- Ninety consecutive days with no proof-submission or state-update outage exceeding one hour
- A proposed-size withdrawal is demonstrated to clear under normal operation within a documented maximum time
The research file
Mechanism
Users deposit and withdraw through Ethereum, with a footprint also touching Arbitrum. A Batch Prover generates SNARK proofs, using Plonky2 circuits, of the matching engine’s state transitions, which are verified on-chain. This means the sequencer cannot steal funds through an invalid state transition alone, since incorrect state cannot be proven valid — a strictly stronger default guarantee than an optimistic or BFT-consensus design.
Control and governance
Per L2Beat’s discovery data, batch commitment and execution are controlled by only three externally-owned accounts — not a multisig, a thinner operational trust set than even Unit’s three-guardian MPC setup, though functionally a different kind of control (sequencing versus custody). Standard contract upgrades route through a 3-of-5 multisig with a 21-day timelock, but a separate 4-of-7 emergency multisig can reduce that delay to zero seconds. A forced-inclusion backstop exists: if operators fail to process forced L1 transactions within 14 days, the system enters ”desert mode” and users must exit by proving their balance via ZK proof against the last-settled state — a real escape hatch, but with a much longer stuck-period than Arbitrum’s or Base’s hours-scale force-inclusion window.
Incident record
No fund-loss exploit was identified. But real, recent liveness fragility was: a 4.5-hour downtime on 2025-10-10 from database growth issues, and multiple proof-submission delays in July and August 2026, including a three-hour-38-minute state-update outage on 2026-08-09, roughly a week before this review. This is a current, recurring operational problem, not a resolved historical one.
Exit
The standard path is bridge withdrawal back through Ethereum under normal operation; the ZK-proof desert-mode exit is the stress-case backstop, gated behind the 14-day forced-inclusion deadline described above. This review could not demonstrate a proposed-size withdrawal clearing within a documented maximum time under current operating conditions.
Comparison
Against Hyperliquid Bridge, already rejected in this registry for a 27-validator custom consensus and closed-source client, Lighter’s validity-proof design is a stronger cryptographic guarantee against invalid state. Against Base and Arbitrum’s canonical bridges, both approved with limits, those have broader validator or council sets and faster forced-inclusion windows; Lighter’s three-EOA sequencer and emergency-collapsible 21-day upgrade delay are weaker on the governance-concentration axis even though the underlying proof system is stronger on the correctness axis, and the recent outages are a live reliability concern neither approved peer currently carries.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- L2Beat — Lighter · secondary · accessed 2026-08-17
Supports: multisig thresholds, sequencer EOA count, forced-inclusion timing, incident log - Lighter — official site · primary · accessed 2026-08-17
Supports: mechanism overview - Lighter Docs — security audits · primary · accessed 2026-08-17
Supports: audit listing, content not independently retrieved - CoinDesk — a new Hyperliquid rival raises funds at $1.5B valuation · secondary · accessed 2026-08-17
Supports: scale and funding context - DefiLlama — Lighter Bridge protocol record · secondary · accessed 2026-08-17
Supports: tracked TVL
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |