Lighter Bridge (zkLighter)
This review reaches an adverse assessment based on operational concentration and recent liveness failures, not on the architecture. Lighter (zkLighter) is a custom application-specific ZK rollup for perpetual futures. It uses genuine SNARK validity proofs to verify every state transition, a stronger cryptographic guarantee against invalid state than Hyperliquid Bridge’s custom validator consensus, already rejected in this registry. But only three externally-owned accounts control sequencing and batch commitment, and they do not even form a multisig. A separate emergency multisig can also cut the standard 21-day upgrade timelock to zero. This is the same ”no meaningful delay once an emergency path is invoked” pattern already priced into Base’s cap, but here it comes with genuinely thin operational protection rather than a disclosed council. Multiple proof-submission and state-update outages in July and August 2026, including one a week before this review, add a live reliability concern to the governance gap. The proof system is a real strength and should make this a faster reopen than Hyperliquid or Unit once operational maturity catches up.
- Sequencer or batch-commitment control moves from three externally-owned accounts to a disclosed multisig of at least 4-of-7 with named or institutionally-accountable operators
- The emergency multisig’s ability to zero out the 21-day upgrade timelock is removed or itself gated behind a minimum delay
- Ninety consecutive days with no proof-submission or state-update outage exceeding one hour
- A proposed-size withdrawal is demonstrated to clear under normal operation within a documented maximum time
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
Users deposit and withdraw through Ethereum, with a footprint that also touches Arbitrum. A Batch Prover uses Plonky2 circuits to generate SNARK proofs of the matching engine’s state transitions, and contracts verify those proofs on-chain. The sequencer therefore cannot steal funds through an invalid state transition alone, since it cannot prove that an incorrect state is valid. This is a strictly stronger default guarantee than an optimistic or BFT-consensus design.
Control and governance
L2Beat’s discovery data shows that only three externally-owned accounts control batch commitment and execution. They do not form a multisig, making this a thinner operational trust set than even Unit’s three-guardian MPC setup, though the accounts control sequencing rather than custody. Standard contract upgrades pass through a 3-of-5 multisig with a 21-day timelock, but a separate 4-of-7 emergency multisig can cut that delay to zero seconds. A forced-inclusion backstop exists. If operators fail to process forced L1 transactions within 14 days, the system enters ”desert mode,” and users must exit by proving their balance via ZK proof against the last-settled state. This is a real escape hatch, but users can remain stuck much longer than under Arbitrum’s or Base’s hours-scale force-inclusion window.
Incident record
This review found no fund-loss exploit. But it found real, recent liveness problems: a 4.5-hour downtime on 2025-10-10 caused by database growth issues, and multiple proof-submission delays in July and August 2026. These included a three-hour-38-minute state-update outage on 2026-08-09, roughly a week before this review. This is a current, recurring operational problem, not a resolved historical one.
Exit
Under normal operation, users take the standard bridge withdrawal path back through Ethereum. The ZK-proof desert-mode exit is the backstop under stress, and users cannot invoke it until the 14-day forced-inclusion deadline described above. This review could not show that a proposed-size withdrawal would clear within a documented maximum time under current operating conditions.
Comparison
Hyperliquid Bridge is already rejected in this registry for its 27-validator custom consensus and closed-source client. Lighter’s validity-proof design gives stronger cryptographic protection against invalid state. Base and Arbitrum’s canonical bridges, both approved with limits, have broader validator or council sets and faster forced-inclusion windows. Lighter’s three-EOA sequencer and emergency path that can erase the 21-day upgrade delay leave it weaker on concentrated governance, even though its proof system is stronger on correctness. Its recent outages also create a live reliability concern that neither approved peer currently carries.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- L2Beat — Lighter · secondary · accessed 2026-08-17
Supports: multisig thresholds, sequencer EOA count, forced-inclusion timing, incident log - Lighter — official site · primary · accessed 2026-08-17
Supports: mechanism overview - Lighter Docs — security audits · primary · accessed 2026-08-17
Supports: audit listing, content not independently retrieved - CoinDesk — a new Hyperliquid rival raises funds at $1.5B valuation · secondary · accessed 2026-08-17
Supports: scale and funding context - DefiLlama — Lighter Bridge protocol record · secondary · accessed 2026-08-17
Supports: tracked TVL
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |