Sequencer Failure and Forced Exit
A rollup relies on one operator to order transactions, so if that operator stops or censors, users need a working escape hatch to the settlement layer.
运作方式
Most rollups today run a single sequencer that receives transactions, orders them, and gives users a fast soft confirmation before the batch is posted to the settlement chain. If the sequencer halts, the chain stops accepting new transactions even though funds remain safe on the layer below, and if it censors, a specific user stops being served. The designed remedy is forced inclusion: submitting the transaction directly to the settlement layer's inbox, after which the rollup must include it within a fixed window. That path only helps if it is actually implemented, exercised, and usable in the conditions where it is needed, which are exactly the conditions where settlement-layer fees tend to be high, and optimistic designs add a challenge period before withdrawals complete.
实际可观测的内容
Check whether the sequencer is permissioned and who runs it, whether a forced-inclusion mechanism exists in the deployed contracts, what its delay window is, and whether anyone has demonstrably used it. Read who can upgrade the bridge and the proof system, whether those upgrades pass a timelock, and whether a security council can bypass the timelock. Published uptime records and incident post-mortems show how often the sequencer has stopped and for how long.
先例
Major rollups have experienced sequencer outages lasting hours during which no new transactions were processed, while balances remained recoverable on the settlement layer.
哪些因素使其更重要或更不重要
Consider whether forced inclusion is implemented and tested, the length of the delay and challenge windows, who holds upgrade keys over the bridge, and whether the proof system is live or still permissioned.
相关因素
适用资产范围
本因素适用类别中规模最大的资产。出现在此处,意味着该因素与此类资产相关,而非表示相关情况已经发生。