Optimism Bridge (OP Mainnet)
The scheduled date is the outside bound. Kill criteria are checked every day, and a trigger reopens the memo that week.
APPROVED WITH LIMITS, MATCHING BASE AND ARBITRUM AT THE SAME CAP. OP Mainnet’s canonical bridge is standard OP Stack: a seven-day optimistic challenge window on withdrawals, no exploit of the bridge contracts themselves identified. Optimism’s own current security-model documentation, verified directly rather than inferred from an older governance-charter reading, confirms the live structure: a 2-of-2 nested multisig — a 10-of-13 Security Council multisig and a 5-of-7 Optimism Foundation multisig, both required, either can veto — that can upgrade core contracts with no delay. That is the same zero-delay upgrade shape already priced into Base’s cap in this registry, not a materially different structure, so it earns the same 15% limit rather than a stronger or weaker one.
- Any confirmed exploit of OP Mainnet’s own OptimismPortal or L1StandardBridge contracts, as distinct from other OP Stack chains’ incidents
- The Security Council or Optimism Foundation multisig threshold or composition changes without public disclosure
- The nested 2-of-2 multisig upgrades a core contract without independently verifiable approval from both component multisigs
- The seven-day withdrawal challenge period is shortened or bypassed for a class of users without equivalent public availability
The research file
Mechanism
Standard OP Stack three-step withdrawal: initiate on OP Mainnet, prove on Ethereum roughly an hour after the relevant output root posts, then wait a seven-day challenge period before finalizing and claiming. Deposits are fast with no delay. This is the same lineage as Base and Arbitrum’s canonical bridges, both already reviewed in this registry.
Control and governance
Per Optimism’s own current security-model documentation: ”the security of OP Stack chains is currently dependent on a multisig managed jointly by the Optimism Security Council and the Optimism Foundation… a 2-of-2 nested multisig which is in turn governed by a 10-of-13 multisig managed by the Optimism Security Council and a 5-of-7 multisig managed by the Optimism Foundation. This multisig can be used to upgrade core OP Stack smart contracts without upgrade delays.” Both component multisigs must approve any upgrade and either can veto it, but neither imposes a waiting period once both agree — an earlier-dated Security Council charter describing a 14-day delay on all actions has been superseded by this current documentation. The Security Council also serves as Guardian for the fault-proof dispute-game system, providing a backstop against invalid withdrawal proposals during their challenge window and able to shift the system to a permissioned dispute game if the permissionless fault-proof process fails. The Optimism Foundation currently operates the sole sequencer, though users can bypass it by sending transactions directly to the OptimismPortal contract.
Incident record
No exploit of OP Mainnet’s own canonical bridge contracts was identified through this review’s 2026-08-17 search cutoff. Two incidents sometimes associated with Optimism’s bridge belong elsewhere and should not be conflated with it: a December 2023 exploit of the generic OP Stack bridge template hit Hypr Network, a different OP-Stack-based chain, for about $420K, and was fixed by Optimism’s developers in the shared template rather than reflecting a live OP Mainnet failure; and an April 2026 Hyperbridge exploit (an unrelated Polkadot protocol) executed transactions across several chains it operated on, including Optimism as a destination, without compromising OP Mainnet’s own bridge.
Exit under stress
Same seven-day challenge window as Base and Arbitrum, uniformly applied, with no officially expedited path outside third-party liquidity bridges, which carry a separate trust model and are out of scope for this canonical-bridge entry.
Comparison
Against Base (approved with limits at the same 15% cap): both run a zero-delay-once-approved upgrade multisig, Base’s being a nested 2-of-2 of a 6-member operator multisig and an 11-member independent council, Optimism’s being a 2-of-2 of a 13-member council and a 7-member foundation multisig — comparable in shape, with Optimism’s somewhat larger component sets. Against Arbitrum (also approved with limits at 15%): Arbitrum’s non-emergency path carries a real roughly-eleven-day delay that Optimism’s does not, making Arbitrum modestly more conservative on that specific axis, though Arbitrum’s emergency path is equally delay-free. None of these differences are large enough in either direction to justify a different cap for OP Mainnet than its two already-approved peers.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Optimism Docs — OP Stack security model · primary · accessed 2026-08-17
Supports: 2-of-2 nested multisig, no upgrade delay, Guardian role, sequencer decentralization status - Optimism Docs — using the Standard Bridge · primary · accessed 2026-08-17
Supports: mechanism, prove and finalize flow - Optimism Help — withdrawals from Optimism · primary · accessed 2026-08-17
Supports: seven-day challenge period - Security Council Charter v0.1 — ethereum-optimism/OPerating-manual · primary · accessed 2026-08-17
Supports: earlier charter version, superseded by current security-model documentation - Coinpaper — Hypr loses over $420,000 in OP Stack bridge exploit · secondary · accessed 2026-08-17
Supports: confirms incident hit a different OP Stack chain, not OP Mainnet
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |