Control profile
- Transaction ordering
- Centralised — >99% of transactions through a single sequencer
- Escape hatch
- Forced inclusion via the L1 delayed inbox. forceInclusion threshold is 24 hours; in practice a full self-service exit is slow and costly.
- Upgrade authority
- DAO plus a security council. Admin keys can upgrade bridge contracts on roughly a 7-day timeline — as at every other top-5 L2.
- Liveness record
- Sequencer outages have occurred; user funds were never at risk, but access was.
Ketju assessment
Stage 1 with live permissionless fraud proofs, which is the current state of the art — as of mid-2026 there are still NO Stage 2 rollups. So this is as good as an L2 gets, and it is still not Ethereum. Appropriate for yield-first and tokenised-income mandates where cheap transactions matter more than censorship resistance. NOT appropriate for a sovereignty-first mandate: a client who is paying us to make them un-freezable should not sit behind a single sequencer and a 7-day upgrade key.
Observable review triggers
- Fraud proof system disabled or made permissioned
- Force-inclusion delay extended beyond 24 hours
- Security council threshold lowered, or upgrade timelock shortened below 7 days
- Sequencer outage exceeding 6 hours
These triggers make the judgment monitorable. They are not predictions; each identifies a fact that would revoke or force review of the current assessment.
Advisor implementation questions
- Does the client’s thesis require censorship resistance, or primarily low-cost settlement?
- Can the client exit without cooperation from the normal transaction-ordering party?
- Who can upgrade bridges or contracts, and what delay applies?
- Does the asset introduce an issuer weaker than the chain grade?
- What evidence will show a halt, censorship event, or governance change?