Cointime

Download App
iOS & Android

The Endgame for Decentralization in the OP Ecosystem is Stage 2

A critical discussion on the path to blockchain maturity is how to decentralize, how much, and when. This blog post shares a bit more about how we are thinking about this process at OP Labs as we support the ecosystem engineers building out a fault proof system for the OP Stack and the Optimism Collective as it establishes its first security council.

In an insightful article on the Ethereum Magicians forum, Vitalik Buterin lays out the roadmap for achieving Stage 2 Decentralization, a critical milestone for any layer 2 network looking to decentralize. This post has informed much of the conversation around technical decentralization in the Optimism Collective over the last two years. We firmly believe all Layer 2 blockchains should prioritize reaching this stage of decentralization as swiftly (and safely!) as possible, to ensure a more robust, secure, and truly decentralized ecosystem.

To remind everyone what is required for rollups to reach Stage 2, here are the criteria outlined in Vitalik Buterin’s original post:

Requirements:- In the event that code does not have bugs, there must not be any group of actors that can, even unanimously, post a state root other than the output of the code.This somewhat awkward phrasing (“IF the code does not have bugs, THEN no one can override it”) is meant to permit use of security councils in ways that are clearly limited to adjudicating undeniable bugs, such as the following:- The rollup uses two or more independent implementations of its state transition function (eg. two distinct fraud provers, two distinct validity provers, or one of each), and the security council can adjudicate only if they disagree - which would only happen if there is a bug.- If someone submits a transaction or series of transactions that contains two valid proofs for two distinct state roots after processing the same data (ie. “the prover disagrees with itself”), control temporarily turns over to the security council.- If no valid proof is submitted for >= 7 days (ie. “the prover is stuck”), control temporarily turns over to the security council.- Upgrades are allowed, but must have a delay of >= 30 days

In summary, to take off their “training wheels” and achieve Stage 2 decentralization, rollups must have a trustless fault proof system, multiple functioning proving mechanisms, and rollups that have a security council or a similar entity must meet specific criteria.

Why is it so important to reach Stage 2?

What Stage 2 does that Stage 1 does not is ensure there’s no one group of actors that can “even unanimously, post a state root other than the output of the code.” Stage 1 L2s still have some version of a multisig or security council that could hypothetically (although not without costs) alter a chain’s state root to censor or initiate invalid withdrawals. It’s not entirely trustless. Removing this ability further decentralizes networks and ensures users possess an unalienable ability to exit the system.

This type of flexibility is critical to the Superchain because it balances interoperability—everyone using the same fault proof will be on the same protocol version—without sacrificing user freedom and protections. The right to exit should always be preserved, and not impact the way a Chain or an app functions.

Why is it taking so long for Optimism to reach Stage 1 decentralization?

Projects might take a “depth first” approach while moving towards Stage 2: get to Stage 1 with a single fault proof as fast as possible, and then work out how to make a multiproof fault proof system to reach Stage 2 status. Optimism, by contrast, took a “breadth first” approach that aims to make a functional, fast-growing multiproof network. Ecosystem engineers are building the first implementation of the fault proof system in a way that enables that approach. Meanwhile, because this is all being built in the open, with an open source stack, other developers in the ecosystem were able to start building many other implementations in parallel with the work on the first fault proof implementation.

We know how important it is to get this right on the first try. Today, OP Stack engineers have laid the groundwork for rapid multiproof expansion, and they are working towards achieving Stage 1 status according to L2Beat’s risk analysis metrics, a respected standard in the industry. But Bedrock was built from the ground up with Stage 2 decentralization in mind. We are uninterested in reaching Stage 1 simply for the sake of saying we did so. From day one, it has been just one part of our pragmatic plan to reach Stage 2 as quickly and safely as possible.

Stage 2 is endgame. Here’s what that looks like in practice:

First came Bedrock and the OP Stack

In order to prioritize achieving Stage 2, we knew we needed to design a codebase that would make it easier to get there. We needed the modularity introduced by the Bedrock upgrade to make sure that once a functioning, trustless fault proof system was designed for the OP Stack, ecosystem developers could leverage its modular superpowers to help us design not just one or two, but many, alternate proving mechanisms.

At the same time we needed to make sure that even unforeseeable technological developments would not make the OP Stack obsolete. The current design of the OP Stack ensures that developers can swap proving components to include ZK technology, something that once threatened the growth of Optimistic rollups. Chains in the Optimism ecosystem are not forever bound to using optimistic proving mechanisms. We expect they will be able to leverage advancements in ZK technology and the resurgence of plasma, or a combination of all three mechanisms, in their Chain’s fault proof system.

It took time to design the OP Stack and execute the Bedrock upgrade, but the result of this investment has put the entire ecosystem in a position to rapidly accelerate our development progress in the coming months and beyond. This means it was time well and strategically spent.

Next comes a multiproof ecosystem

So far this approach has paid off tremendously. The evidence is in how quickly alternative clients have taken off since the Bedrock launch, and how many teams in the ecosystem are currently working on alternative fault proof implementations as well. In addition to OP Labs and all of the alternative client maintainers (Test in Prod, the reth team and Base, Nethermind, a16z crypto, and Kai Chen and the Hildr team), which are used as critical dependencies in the OP Stack, teams currently working on alternative fault proofs include the State Channels team, RISCZero, O(1) Labs, AltLayer, Protolambda (at OP Labs), and engineers Willem Olding and Eric Tu, along with geohotz and his initial work on Cannon.

Here’s what this is shaping up to look like:

The OP Stack is a triple threat. It is modular and open source, which means that the full power of the Stack can find its way into the hands of the third “threat,” its tremendously creative and brilliant developer community. It would take years for OP Labs engineers to develop, test, and implement the multiple proof schemes required for Stage 2 decentralization. By putting the best tools in the hands of the superstar core developers and engineers in our ecosystem, anyone with an interest in Optimism’s success can design the components that will help reach our goal.

Security council

To reach Stage 1 decentralization and progress to Stage 2, networks need something akin to a security council—a multisig with which to manage protocol upgrades that is maintained by a minimum of 8 independent individuals with a signing threshold of 75% or greater.

In the fall of 2023, rollout began in earnest to establish the Optimism ecosystem’s first security council, comprised of individuals outside of the Foundation. The first 14 members of the Optimism ecosystem’s security council were ratified by a governance vote in December 2023, and another governance vote on whether or not to share upgrade keys with the security council in an interim ‘Phase 0’ was also successful.

One of Optimism’s prized values is open source technology. Just as ecosystem engineers are building the MIT licensed open source OP Stack in the open, the security council will be built in the open, such as the public charter, an open source implementation, and transparent operations. This is in keeping with the two of the three guiding principles that have inspired the structure of the security council: transparency, and community.

The third principle, safety over liveness, informs the design the security council, and of security in the Optimism ecosystem overall. Prioritizing safety over liveness means it’s more important for the system to avoid errors and invalid states, especially ones that would result in a loss of funds, even if it results in temporarily halting operations.

All L2s should aim for Stage 2.

That’s it. That’s the meme.

It’s not enough for L2s to reach Stage 1 and limit the use of training wheels, while still relying on a single proving mechanism to secure a nascent fault proof system. Further, a single fault proof system is only as good as the strength of the security council that can steward it. For the first phase, a 14-person security council has been ratified by Optimism Governance to govern the security of the Superchain, and a key goal in 2024 is to have this security council managing the upgrade keys of the ecosystem at the direction of Optimism Governance, and independently from the Optimism Foundation.

Comments

All Comments

Recommended for you

  • ETH Trading Volume on Hyperliquid Exceeds BTC, Reaching Approximately $1.1 Billion in 24 Hours

    On October 11, the trading volume of ETH on the Hyperliquid platform reached approximately $1.1 billion in the last 24 hours, surpassing BTC's $805 million. Market analysts believe that the increase in ETH trading volume is related to suspected exploitation of the PaperTrade mechanism. Earlier today, reports indicated that PaperTrade was allegedly manipulated by two addresses, revealing a significant vulnerability in the protocol: the two wallet addresses executed trades on Hyperliquid with a single transaction size of about $20 million, causing ETH prices to fluctuate by approximately 10 to 20 basis points, and establishing long positions with a notional value of several hundred million dollars on PaperTrade.

  • Ledger Confirms Unauthorized Hardware Implant in Devices, Losses May Exceed $86 Million

    On October 11, Cointelegraph reported that hardware wallet manufacturer Ledger confirmed the presence of unauthorized hardware implants in the devices of an affected user. The incident involves losses related to devices purchased from its Southeast Asian distributor, CryptoBilis. Investigator Specter estimates that the losses may exceed $86 million, involving Bitcoin, Ethereum, and Tron. Ledger stated that it is in contact with the affected users; CryptoBilis has confirmed the suspension of all hardware wallet inventory sales until the investigation is complete. Ledger claims that the incident appears to be limited to this single distributor and its market, and that its own infrastructure, systems, and services have not been compromised. The company has not yet confirmed the number of affected customers or the total amount of losses. Ledger advises users who have not initialized their devices to refrain from doing so, while those who have already initialized their devices may consider transferring their assets to a new signer using a new mnemonic.

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.