Layer 2s: what actually moves off-chain
The execution moves; the settlement guarantee does not. That split is the entire idea.
At a glance
- A layer 2 executes many transactions itself, then posts a compressed summary back to layer 1.
- Security still comes from layer 1 — the rollup only inherits it if it can prove its batch was computed correctly.
- Optimistic and zero-knowledge rollups differ in how they prove that: a challenge window, or a mathematical proof, respectively.
A base chain like Ethereum can only process so many transactions per block before fees rise and confirmation slows. A layer 2 is a separate system that executes transactions itself, off the base chain, and only periodically reports a compressed summary back to it.
The word doing the work here is “rollup.” Thousands of individual transfers are batched, compressed, and submitted to layer 1 as a single piece of data alongside a claim about the resulting state. Layer 1 does not re-run each transaction; it only has to be convinced the claim is correct.
How it gets convinced splits rollups into two families. An optimistic rollup assumes the claim is correct and gives anyone a window — typically seven days — to submit proof that it wasn't, which is why withdrawing back to layer 1 from one takes that long. A zero-knowledge rollup submits a cryptographic proof of correctness alongside the claim itself, so there is no challenge period and no assumption of good faith required.
The security you get is inherited, not independent. A layer 2's guarantee is only as strong as the base chain it settles to and the correctness of the bridge contract holding funds on that base chain — which is why bridge contracts, not the rollups themselves, have been the site of the largest losses in the space.
Key terms
- Rollup
- A layer 2 that batches many transactions and posts a compressed summary and proof back to layer 1.
- Optimistic rollup
- A rollup that assumes correctness and allows a challenge window before finalising a batch.
- Zero-knowledge proof
- A cryptographic proof that a computation was done correctly, without re-executing it.
Frequently asked
If a rollup is hacked, is my base-chain balance safe?
It depends what was compromised — funds bridged into the rollup rely on the bridge contract's security, which has historically been the more common point of failure than the rollup's execution itself.
Why does withdrawing from an optimistic rollup take so long?
The challenge window — often seven days — gives anyone time to dispute a fraudulent batch before it finalises; withdrawing early would defeat that guarantee.
Are zero-knowledge rollups always faster to withdraw from?
Typically yes for cryptographic finality itself, though practical withdrawal times still depend on proof generation time and the specific implementation.