Security Blindspots Beyond L2s | Luca Donno - L2BEAT
Ethereum DenverΒ·Mon, Mar 9, 2026, 12:00 AM
Speaker
π Get Ready for ETHDenver 2026! π We're already hard at work preparing for next year's biggest Web3 event! Keep your eyes peeled for more info on ETHDenver 2026βitβs going to be epic! π
Transcript
Hey everyone. Uh I'm Luca. I'm head of research at uh L2B and today I will talk about uh security blind spots outside of the L2s. So I'm going to talk about you know uh we mainly focus on L2s but today I will talk about what is going on outside of the L2s. So if you're not familiar with L2 beat uh the thing that we do is risk assessments and metrics for um all the L2s.
We have over uh 100 projects that we track and monitor on the website and we've been live for uh four years uh maybe more. And you know over time I think we did quite a good job to raise awareness of the risk of using uh diesel tools. Uh people are kind of familiar with the fact that uh there are centralized sequencers that can censor you um that you know the need of force transactions the fact that there might be a proof system or not that this proof system might be permissioned. Uh but you know in general people are kind of well aware of the risks uh with twos. What is less obvious today is the risk of the bridges outside of Elus.
Uh so for example when you see announcements like this one that you can bridge the Stark token to Salana like I'm pretty confident that very few people have idea of actually what's going on uh behind this like what bridge is being used and what is the security of this bridge. Another example is this one you know you want to bridge uh Zora is now live on Salana. Zora is like an Ethereum L2. The token is on Ethereum. So like how uh trading and holding the Zoro token on Solana for example compares to holding and trading the same token on Ethereum which is the original chain right?
What are the additional risks? Uh a lot of people have no idea. Another example is you know B that launched this B Solana bridge. How is this different from uh the Ethereum base bridge which is a canon kal to bridge. uh I saw this announcement where you can now bridge stake diff uh to binance chain and there are many examples uh of this.
So what we do today at alto bits is we track the L2s uh but the L2s are a subset uh of a larger class of bridges which is which are the lock and mint bridges. So a locker mint bridge is a bridge that locks assets in an escrow on one chain and mints assets on the other chain. Um all the L2s do this. Uh but there are lock main bridges outside of the L2 conical bridges. Some example are the one that I show here.
This is there are chain link with CCIP. There is layer zero D bridge wormhole XLR hyperlane. Um then there are another class of of bridges which are the burn and mint bridges. uh these are sometimes called omni chain bridges and this includes again layer zero uh CCIP with chain link warm hack hyperlane or CCTP for USDC and as you can see some of these uh projects appear both in lock mint and burnint and the security properties of a bridge if it's lockint or burn a mint are different um and usually those projects you know do a good job at obstructing the UX uh which you know sometimes also implies obstructing the risk which is which is not great. Um the other type of bridges that exist are the noming bridges uh or something called intent protocols or intent bridges.
These are bridges that make use of liquidity providers or intent solvers uh where tokens are not minted. The liquidity is already there. Um and these include stuff like Stargate relay across Gaza zip squid and near intense. And I want to explain a little bit more what all of these means. So when you see a lock and mint bridge, the thing that you should uh get used to do is to ask yourself a few questions to understand the risks.
So for example, uh there is a locking mechanism which means that there is an escro somewhere, right? And you should ask yourself who controls the locking escrow? Is this as upgradable? Um who can release the tokens, right? Um, you should ask yourself who can mint the tokens.
Once you lock the token, who has the permission to mint the token on the other side? Because this actor that can mint the tokens are also the potential to rug you by minting tokens out of thin air that don't correspond to the funds that you locked. Uh, what are the properties of these minted tokens? Because it could be that maybe the amounts are respected. Uh, there's no overmint, but the minted token is, for example, upgradeable.
it's a proxy that is upgradable but so by some actor that is outside of the original token um and who can unlock the tokens right so if I'm on a chain um if I want to go back I need to burn and unlock so once I burn the token what guarantees I have that those tokens will actually be unlocked um and one very important thing that is not obvious at all I think today is that you know we have stages for L2s that assess the security of of canonical bridges that are lock and mint. And one u realization is that for example all lock mint bridges that are third party validated cannot get above stage zero. Like we have this classification in three stages. Stage zero, stage one and stage two. We say stage zero is fully centralized.
Stage two is fully decentralized. Stage one is kind of in the middle. Again I'm simplifying. There are a lot of projects in autobe that are stage one. And one thing that you know people need to realize is stage one bridges are already much more secure than any other third party bridges uh that they listed here for example uh at least theoretically u theoretical guarantees.
So what about burner mint uh tokens? Again you should ask yourself who has the permission to m those tokens is the just the issuer itself. So for example I list CCTP here. CCTP is the bridge that is used by USDC to move token around. CCTP the bridge is controlled by uh circle itself.
So the risk of using CCTP over just holding circle uh sorry USDC um there's no additional risk because the entity is the same right uh but it might be that this is not the case um so who can mean the tokens who can burn the token um and then another thing that can happen is that the burn and mint token uh that is bridged by burning and minting is created out of a token that is locked in an escro. So one example of this is USDT0. You might be familiar with that. This is a token that is um that uses layer zero to move across chains. But this tokens is minted like before uh becoming burnt.
It is minted out of a locking escro that contains USDT. And this is cool because if you don't trust layer zero to move USDT zero around um you have an escrow where you can unlock the original USDT tokens. Um so you can get away from the risk of layer zero if you don't trust it. Some tokens don't do this. So it's important to know whether you have an escape opportunity.
And another thing that is important to know is where are all the uh what are all the token instances where they are because if some of if one of them is compromised then uh all the tokens on all the chains can be compromised. Um and then there are the non-minting protocols or again the intent protocols. Um in like what what happens in in protocols is that you send tokens to someone and someone else on the other chain or like the same actor uh most of the time on the other chain is supposed to uh give you some tokens. So first you should know who I'm giving the tokens to. Is this a like a contract with some guarantees or am I giving token to a new with no guarantees?
One example is relay. If you use if you ever use relay which has which has amazing UX it's super cheap and super fast. You're sending tokens to a new way. You're trusting fully a new way to give you tokens on the other side. Um can I get my tokens back if I don't get the tokens on the other side?
Uh so if I send the tokens and I don't get them back can I can I withdraw? How are solvers reimbured? So if uh I I send my token and I receive my token without the guarantees of the solvers. Uh this is important because uh they might account for risks and the price might be different. But one important thing is if I'm using a minting a non-minting protocol to get a token on another chain, this token on the other chain has been minted by someone.
So it's not true that with a non-minting protocol you get away with this issue. is just someone else is minting this token and you might not be aware of who this actor is. Um one example is this that I presented before right um Stark token is live on Solana. Stark token is the token of Starknet like an ethereum 2. This token lives on Ethereum.
It's originally minted on Ethereum and they say you can bridge the Stark token on Solana using near intense and you should already like feel a red flag because near intense is a non-minting protocol. So who is minting the Stark token on Solana? Like they're not saying this, right? It's not obvious. Uh near intense cannot mint.
So who is minting? And if you investigate a little bit, you will figure out that this entity is wormhole. Uh so wormhole has the power to mint tokens. you need to trust Wormhole. Uh wormhole has some guardians.
Uh I don't have time to go into the details, but like it is a third party actor outside of this darknet team that minted the original token that can potentially rug you. Uh so again once you see this the next time uh you should raise a red flag uh in your mind. Another example is this uh this is wrapped etherfy e which is a st token and they use layer zero and what I'm showing here is a visualization on all the chains where this token is available. Uh it's present in a lot of chains and the red arrows are configurations of who can mint the token on this chain depending on where the message is coming from originally. And you can have different configurations based on the source chain.
So again if like I'm here uh like there is BNB I have and there are like let's say 20 chains in total I I will have 20 configurations on BNB that I need to check to be able to know who is be who is able to mint my token. And if the uh layer zero token um supports 20 chains, I need to check 20 time 20 configuration, 400 configurations to just know what is the counterparty risk when holding this token, which is insane uh if you think about it. One funny thing is that for example uh these validators that verify messages are called devian. There is this one project which is called Canary which does devian inside tees. You may think that this is more secure because it's running in a TE.
But the thing is if this is only used in one of the paths and here there are two paths that are used by Canary uh and all the others don't use this you don't get the security of this because if one of these uh arrows fail the token is fully rugged right so either caner is used everywhere or it's useless and this is something that is not obvious um and we want to have more um awareness of this. So what we're launching next week uh on Alto is this um interrop dashboard. You will be able to select two chains and you will be able to see all the crosschain bridges that are used to bridge between these two chains. What is the volume of these bridges? What is the transfer time?
What are the tokens? Um and we will support also chains outside of the Ethereum ecosystem uh like Solana, Tron, Binance chain or whatever because we want to have visibility on how users bridge from the Ethereum ecosystem to the outside or vice versa. Um next week we're launching with um just the metrics we will do the risk assessments. So you will be able to know exactly what is the risk the counterpart to risk that you get when using these uh bridges and tokens. Uh that's all I have.
Thank you.
Automatic transcript β names and jargon may be misspelled.