Optimism Bridge (OP Mainnet)
Approved for: positions on Ethereum. The limits are in the memo below.
Review open since 2026-09-28: A published event names Optimism Bridge (OP Mainnet): Optimism Upgrade 20 changes fault proofs to super roots while retaining output-root withdrawal proofs. The verdict stands until the review closes.
Our assessment is favorable with conditions. OP Mainnet’s canonical bridge uses the standard OP Stack: a seven-day optimistic challenge window on withdrawals, with no identified exploit of the bridge contracts themselves. Optimism’s own current security-model documentation, checked directly rather than inferred from an older governance-charter reading, confirms the live structure. A 2-of-2 nested multisig consists of a 10-of-13 Security Council multisig and a 5-of-7 Optimism Foundation multisig. Both must approve, either can veto, and together they can upgrade core contracts with no delay. That is the same zero-delay upgrade structure already observed on Base, not a materially different structure. Client selection and sizing remain advisor decisions.
- Any confirmed exploit of OP Mainnet’s own OptimismPortal or L1StandardBridge contracts, as distinct from other OP Stack chains’ incidents
- The Security Council or Optimism Foundation multisig threshold or composition changes without public disclosure
- The nested 2-of-2 multisig upgrades a core contract without independently verifiable approval from both component multisigs
- The seven-day withdrawal challenge period is shortened or bypassed for a class of users without equivalent public availability
Watched nightly. The review opened 2026-09-28 is shown under the verdict above; the memo stands as issued until it closes.
The research file
Mechanism
The standard OP Stack withdrawal has three steps: initiate on OP Mainnet, prove on Ethereum roughly an hour after the relevant output root posts, then wait a seven-day challenge period before finalizing and claiming. Deposits are fast, with no delay. This bridge shares the same lineage as Base and Arbitrum’s canonical bridges, both already reviewed in this registry.
Control and governance
Optimism’s own current security-model documentation states: “the security of OP Stack chains is currently dependent on a multisig managed jointly by the Optimism Security Council and the Optimism Foundation… a 2-of-2 nested multisig which is in turn governed by a 10-of-13 multisig managed by the Optimism Security Council and a 5-of-7 multisig managed by the Optimism Foundation. This multisig can be used to upgrade core OP Stack smart contracts without upgrade delays.” Both component multisigs must approve any upgrade, and either can veto it. Neither requires a waiting period once both agree. This current documentation replaces an earlier Security Council charter that described a 14-day delay on all actions. The Security Council also serves as Guardian for the fault-proof dispute-game system. It protects against invalid withdrawal proposals during their challenge window and can shift the system to a permissioned dispute game if the permissionless fault-proof process fails. The Optimism Foundation currently operates the sole sequencer, though users can bypass it by sending transactions directly to the OptimismPortal contract.
Incident record
This review identified no exploit of OP Mainnet’s own canonical bridge contracts through its 2026-08-17 search cutoff. Two incidents sometimes linked to Optimism’s bridge belong elsewhere and should not be confused with it. A December 2023 exploit of the generic OP Stack bridge template hit Hypr Network, a different OP-Stack-based chain, for about $420K. Optimism’s developers fixed it in the shared template, and it did not reflect a live OP Mainnet failure. An April 2026 Hyperbridge exploit, involving an unrelated Polkadot protocol, executed transactions across several chains where it operated, including Optimism as a destination, without compromising OP Mainnet’s own bridge.
Exit under stress
The bridge uses the same seven-day challenge window as Base and Arbitrum, applied in all cases. There is no officially expedited path outside third-party liquidity bridges, which have a separate trust model and fall outside the scope of this canonical-bridge entry.
Comparison
Base and Optimism both use an upgrade multisig with zero delay once approved. Base uses a nested 2-of-2 made up of a 6-member operator multisig and an 11-member independent council. Optimism uses a 2-of-2 made up of a 13-member council and a 7-member foundation multisig. The structure is comparable, with somewhat larger component sets at Optimism. Arbitrum is also approved with limits at 15%. Its non-emergency path has a real roughly-eleven-day delay that Optimism’s lacks, making Arbitrum modestly more conservative on that specific point, though Arbitrum’s emergency path is equally delay-free. None of these differences are large enough in either direction to change the relative research assessment among these peers.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Optimism Docs — OP Stack security model · primary · accessed 2026-08-17
Supports: 2-of-2 nested multisig, no upgrade delay, Guardian role, sequencer decentralization status - Optimism Docs — using the Standard Bridge · primary · accessed 2026-08-17
Supports: mechanism, prove and finalize flow - Optimism Help — withdrawals from Optimism · primary · accessed 2026-08-17
Supports: seven-day challenge period - Security Council Charter v0.1 — ethereum-optimism/OPerating-manual · primary · accessed 2026-08-17
Supports: earlier charter version, superseded by current security-model documentation - Coinpaper — Hypr loses over $420,000 in OP Stack bridge exploit · secondary · accessed 2026-08-17
Supports: confirms incident hit a different OP Stack chain, not OP Mainnet
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |