Finance · Fintech · Crypto — explained

Bitfolio

An independent explainer desk · No ads · No affiliate links

TechExplainer

What are layer 2 rollups, and how do optimistic and ZK rollups differ?

Rollups move most of the work off Ethereum's main chain but still lean on it for security. Here is how the two main designs work and what each asks you to trust.

Aerial night view of an elevated expressway interchange with streams of traffic lights
Photo: “Bangkok Expressway” by Mark Fischer, CC BY-SA 2.0, via flickr.com · Edited: duotone, cropped.

The short answer

A rollup is a separate network that executes transactions off Ethereum, bundles them into batches and posts the data back to Ethereum. Optimistic rollups assume batches are valid unless challenged within a dispute window; zero-knowledge (ZK) rollups attach a cryptographic proof that each batch is correct.

Key takeaways

  1. Layer 2 networks handle transactions away from Ethereum's main chain (layer 1) while relying on it for security.
  2. Rollups execute transactions off-chain, then post compressed transaction data to Ethereum so anyone can check or rebuild the state.
  3. Optimistic rollups use fraud proofs and a challenge period, typically seven days, which delays withdrawals back to Ethereum.
  4. ZK rollups use validity proofs, so withdrawals do not wait for a challenge period, but generating proofs is computationally costly.
  5. Since the Dencun upgrade of March 2024, rollups can post data in cheaper temporary "blobs" introduced by EIP-4844.

Why does Ethereum need layer 2 networks?

Every transaction on Ethereum's main chain, called layer 1, is processed by every node on the network. That is what makes it secure, but it also limits how much it can handle. When demand rises, the network congests and fees climb2. ethereum.org describes the tension as a trilemma: a simple blockchain design can achieve only two of decentralisation, security and scalability2.

Ethereum's move to proof of stake did not fix this; ethereum.org notes The Merge was never intended to lower gas fees7. Instead, the main route to scale is now layer 21: networks that process transactions away from the main chain while taking advantage of its security1. Unlike changes to layer 1 itself, these need no change to the Ethereum protocol1.

Figure · Where a rollup sits

Where a rollup sitsUsers and appssend cheap, fast transactionsL3Rollup (layer 2)orders, executes and batches themL2Ethereum (layer 1)stores batch data, checks proofsL1
  1. L3Users and appssend cheap, fast transactions
  2. L2Rollup (layer 2)orders, executes and batches them
  3. L1Ethereum (layer 1)stores batch data, checks proofs

What is a rollup and how does it work?

A rollup performs transaction execution outside layer 1 and then posts the data to layer 1, where consensus is reached1. ethereum.org explains that rollups bundle hundreds of transactions into a single layer 1 transaction, spreading the main-chain fee across everyone in the batch2.

Figure · From your transaction to Ethereum

From your transaction to Ethereum01You transacton the rollup02Sequencerbatchesmanytransactionstogether03Data postedcompressed, toEthereum04State rootsavedin the rollupcontract05Checkedby fraud orvalidity proof
  1. 01You transacton the rollup
  2. 02Sequencer batchesmany transactions together
  3. 03Data postedcompressed, to Ethereum
  4. 04State root savedin the rollup contract
  5. 05Checkedby fraud or validity proof

The rollup's current state, every account and balance, is summarised in a Merkle tree whose root hash is stored in a contract on Ethereum; each new batch updates that root3. Because the batch data itself is published on Ethereum as calldata or in blobs, anyone can rebuild the rollup's state and check the operator's work34.

Worked example

Why batching cuts costs (illustrative numbers)

Imagine posting one batch to Ethereum costs 0.01 ETH and the batch holds 500 transactions. Split evenly, each user's share of that main-chain cost is 0.01 ÷ 500 = 0.00002 ETH. Real rollup fees also include the operator's own costs and change with demand on both layers.

How do optimistic rollups work?

Optimistic rollups are called that because they assume transactions are valid by default and only run a check if someone raises a challenge1. After a batch is posted, there is a challenge period during which anyone can dispute it by submitting a fraud proof3. This window typically lasts seven days3.

Operators must post a bond before producing blocks, and that bond can be slashed if they post an invalid one3. The security model needs just one honest party watching and willing to challenge3.

The catch is time. Users have to wait for the challenge period to end before withdrawing funds back to Ethereum3. In return, optimistic rollups are relatively easy for developers, because existing Ethereum contracts can be ported with full compatibility3.

How do zero-knowledge rollups work?

Zero-knowledge (ZK) rollups take the opposite approach: instead of waiting for someone to object, they prove each batch is correct up front. The operator submits a validity proof showing that the proposed state change really is the result of executing the batch, and a contract on Ethereum verifies it4. Our guide to zero-knowledge proofs explains the underlying cryptography.

Two families of proof are common. ZK-SNARKs produce small proofs that are quick to verify but depend on a trusted setup ceremony; ZK-STARKs avoid that setup by relying on publicly verifiable randomness4. Because funds can leave as soon as a proof is verified, there is no challenge-period delay on withdrawals to Ethereum4.

The costs show up elsewhere. ethereum.org notes that computing and verifying proofs is expensive, that producing them can require specialised hardware, which may encourage centralisation, and that compatibility with existing Ethereum software can be harder4.

Optimistic vs ZK rollups: which trade-offs matter?

The two main rollup designs compared

Optimistic rollupsZK rollups
How batches are trustedAssumed valid unless challenged1Proven valid with a cryptographic proof4
Withdrawal to EthereumWait for the challenge period, typically 7 days3No challenge wait once the proof is verified4
Main security assumptionAt least one honest party will challenge fraud3Soundness of the proof system (and setup, if any)4
Main costSlow finality and data posted on-chain3Heavy computation to generate proofs4
Running Ethereum appsFull compatibility3Can be harder to make compatible4

Figure · Innocent until proven guilty, or proven first

Innocent until proven guilty, or proven firstOptimisticPost batch, then allow challengesFraud proof only if disputedSeven-day exit is typicalZero-knowledgePost batch with a validity proofEthereum verifies every batchExit once the proof checks out

Optimistic

  • Post batch, then allow challenges
  • Fraud proof only if disputed
  • Seven-day exit is typical

Zero-knowledge

  • Post batch with a validity proof
  • Ethereum verifies every batch
  • Exit once the proof checks out

What did EIP-4844 and blobs change for rollups?

Posting data to Ethereum is one of a rollup's main costs, and easing it is the stated motivation of EIP-48445. The proposal introduced a new transaction type that carries blobs: large chunks of data that Ethereum's execution environment cannot read, though a commitment to them can be checked5. Each blob holds 4,096 elements of 32 bytes, or 128 KiB5, and blobs are pruned after about 18 days5 instead of being stored forever.

The change went live in the Dencun upgrade on 13 March 2024, which ethereum.org says significantly decreased the cost of data storage for layer 2 rollups6.

What mistakes do people make with layer 2 networks?

Common beginner mistakes

  1. Treating every layer 2 as equally secure

    ethereum.org warns that many layer 2 projects are young and somewhat experimental, and suggests checking independent risk assessments before using one2.

  2. Calling a sidechain a rollup

    A sidechain is an independent chain running in parallel to Ethereum, and a validium keeps its data off Ethereum1. Neither offers a rollup's guarantee that the data is on layer 1.

  3. Forgetting the withdrawal wait

    Withdrawing from an optimistic rollup straight back to Ethereum means waiting out the challenge period, typically seven days3. Plan for it.

  4. Ignoring who runs the sequencer

    A rollup that relies on a single, centralised sequencer gives that operator influence over the order of transactions3.

Risk warning

Bridging funds carries extra risk

Moving money onto or off a layer 2 relies on bridge contracts and on the rollup's own code, and some of that code can be changed by its operators. Bugs or failures can lead to losses. Start with small amounts, read our guide to cross-chain bridges and our risk disclosure.

Frequently asked questions

Is a layer 2 a separate blockchain?

Yes. ethereum.org describes a layer 2 as a separate blockchain that extends Ethereum and inherits its security guarantees2.

Why does withdrawing from some rollups take a week?

Optimistic rollups give everyone a challenge period, typically seven days, to dispute a batch with a fraud proof, and withdrawals wait until it ends3.

Are ZK rollups always better than optimistic rollups?

Not simply. They allow faster exits, but proofs are costly to produce, may need specialised hardware and can make Ethereum compatibility harder4.

Do rollups store data on Ethereum forever?

Data posted as calldata stays on-chain, while blob data is kept by nodes for about 18 days5. The rollup's state root remains in its Ethereum contract3.

What is a sequencer?

It is the operator that orders and batches a rollup's transactions before posting them to Ethereum3. If it is centralised, it can influence transaction ordering3.

The bottom line

Rollups make Ethereum cheaper to use by doing the work elsewhere and posting the evidence back to the main chain. Optimistic rollups trust first and allow challenges, which means a wait to exit; ZK rollups prove first, at the cost of heavy computation. Either way, the network you use, its sequencer and its bridge add risks on top of Ethereum's own.

Sources

  1. Scaling — ethereum.org developer documentation Primary source
  2. Layer 2: learn — ethereum.org Primary source
  3. Optimistic rollups — ethereum.org developer documentation Primary source
  4. Zero-knowledge rollups — ethereum.org developer documentation Primary source
  5. EIP-4844: Shard Blob Transactions — Ethereum Improvement Proposals (eips.ethereum.org), 2022 Primary source
  6. The history of Ethereum (network upgrades) — ethereum.org Primary source
  7. The Merge — ethereum.org Primary source

How we checked this page: every figure above links to the numbered source it came from. Spotted an error? Tell the desk — see our editorial policy.

Read next