Optimism / Base canonical bridges (OP Stack): cross-chain bridges rating breakdown
The same structure as Arbitrum and the same verdict: withdrawals are proven to Ethereum and subject to a seven-day challenge window, with no external committee attesting on your behalf. Telling detail — after losing $625m, Ronin itself migrated to an OP Stack L2 in May 2026, explicitly to improve its security.
The same structure as Arbitrum and the same verdict: withdrawals are proven to Ethereum and subject to a seven-day challenge window, with no external committee attesting on your behalf. Telling detail — after losing $625m, Ronin itself migrated to an OP Stack L2 in May 2026, explicitly to improve its security.
How the score is built
Each criterion is scored 0–10 and weighted. The median column is the middle score across every entry in this ranking, so a row reads as a position rather than a number.
| Criterion | What we measured | Weight | Score | Category median | Rank | Weighted gap |
|---|---|---|---|---|---|---|
| Trust assumption | — | 40% | 10 | 4 | 1 of 16 | +2.40 |
| The upgrade key | null emergency upgrade threshold · sourced · 2026-07-15 | 15% | 6 | 3 | 2 of 16 | +0.45 |
| Incidents — and did users get paid | — | 25% | 10 | 9 | 1 of 16 | +0.25 |
| Audits and transparency | — | 10% | 8 | 5.5 | 1 of 16 | +0.25 |
| Cost and speed | — | 10% | 9 | 6 | 1 of 16 | +0.30 |
Measured 15 July 2026 · weights and method · decided by trust assumption, worth +2.40 points against the median
Trust assumption: 10/10
Not a label — a number. Who, exactly, can move the money if they collude or are compromised? A canonical rollup bridge answers "nobody: Ethereum itself verifies the withdrawal, and the seven-day window is the period in which fraud can be proven". An external committee answers with a threshold, and that threshold IS the rating: Ronin was 5-of-9 and four of those keys sat on one company's servers. Harmony was 2-of-5. We publish the signer count and the threshold wherever they exist, and where a project will not state them, that silence is scored as the risk it is.
Scored 10 of 10 against a category median of 4, which places it 1st of 16 among cross-chain bridges on this criterion. At a 40% weight that is 2.40 points above the median contribution of the weighted total. The best score in the category is 10, the worst 2.
The upgrade key: 6/10
The assumption that quietly overrides the whitepaper. A bridge whose contracts can be upgraded by a small multisig HAS that multisig as its real trust model, whatever the architecture diagram says — and Nomad proves it: the bug that lost $186m was introduced BY an upgrade. So we ask who holds upgrade authority, and we score the answer rather than the design.
Scored 6 of 10 against a category median of 3, which places it 2nd of 16 among cross-chain bridges on this criterion. At a 15% weight that is 0.45 points above the median contribution of the weighted total. The best score in the category is 7, the worst 1.
Incidents — and did users get paid: 10/10
Every exploit with its root cause, and then the column nobody else publishes: were users made whole, and is that INDEPENDENTLY confirmed or merely claimed? Read the results carefully, because they do not mean what people think. Reimbursement in this category has tracked the sponsor’s balance sheet, not the bridge’s security. That makes "they paid people back last time" close to worthless as a safety signal, and we score it accordingly.
Scored 10 of 10 against a category median of 9, which places it 1st of 16 among cross-chain bridges on this criterion. At a 25% weight that is 0.25 points above the median contribution of the weighted total. The best score in the category is 10, the worst 3.
Audits and transparency: 8/10
Named firms, dated reports, published. An unnamed audit is not an audit. Undisclosed validator counts are scored as undisclosed, not assumed benign.
Scored 8 of 10 against a category median of 5.5, which places it 1st of 16 among cross-chain bridges on this criterion. At a 10% weight that is 0.25 points above the median contribution of the weighted total. The best score in the category is 8, the worst 4.
Cost and speed: 9/10
Deliberately the smallest weight, and one qualification matters more than the number: we refuse to treat the canonical bridge’s seven-day withdrawal window as a defect. It is not a delay that clever engineering removed — it is the exact period during which Ethereum can be used to prove a withdrawal fraudulent. A fast bridge is fast for one reason: it substituted somebody’s signature for that proof.
Scored 9 of 10 against a category median of 6, which places it 1st of 16 among cross-chain bridges on this criterion. At a 10% weight that is 0.30 points above the median contribution of the weighted total. The best score in the category is 9, the worst 5.
Other measurements
Its nearest neighbours in this ranking
| # | Entry | Trust assumption | How it differs |
|---|---|---|---|
| 1 | Arbitrum canonical bridge | 10 | Level on trust assumption; the gap is elsewhere. |
| 3 | Circle CCTP | 8 | Behind by 2 on trust assumption. |
| 4 | Across | 8 | Behind by 2 on trust assumption. |
Questions about this score
Can I withdraw from an OP Stack chain faster than seven days?
+
Only by using a third party that fronts you the money and waits out the window itself, which is a real service with a real price. What you cannot do is remove the window — it is the mechanism by which Ethereum verifies the withdrawal, and anything that skips it has substituted trust in someone for a proof.