A practical breakdown of Layer 2 scaling mechanics, comparing optimistic and zero-knowledge rollups, transaction execution fees, and EVM compatibility.

Layer 2 (L2) is a separate chain that runs on top of Ethereum. It executes transactions off chain, then posts the data back to Ethereum. Ethereum checks the data and holds the final state, so the L2 inherits Ethereum security while offering higher throughput and lower fees.
This is different from an alt L1 like Solana or Avalanche, which secures itself with its own validators, and from a sidechain, which runs its own consensus and does not post data to Ethereum.
If you use only Ethereum mainnet today, this guide helps you decide when to move and which type of rollup fits your use case.
Ethereum prioritizes decentralization and security, which limits base layer throughput. The trilemma, described by Vitalik Buterin, states that a simple chain design can only maximize two of three properties: decentralization, security, and scalability. Ethereum chose to keep blocks small enough that regular hardware can verify them, to preserve decentralization.
On mainnet this means roughly 15 transactions per second and variable gas fees that spike with demand. The community chose a rollup-centric roadmap instead of simply raising the gas limit. Rollups keep the base layer focused on settlement and data availability, and move execution to L2s where it can scale.
Other scaling designs exist, but they do not inherit the same guarantees. Sidechains and validiums keep data off Ethereum. They can be cheaper but require you to trust their own data holders and consensus. A rollup posts batch data to Ethereum so anyone can reconstruct the chain and check correctness.
All rollups share the same basic flow. The difference is how Ethereum decides a state update is valid.
After this step, Ethereum considers the state update settled. Bridges use that settled root to complete deposits and withdrawals.
The Fusaka upgrade in December 2025 added PeerDAS, a more efficient way for validators to sample blob availability without downloading full blobs. Ethereum.org notes this as part of scaling to support many more rollups without requiring larger home validators.
Ethereum provides two guarantees for rollups:
The bridge and proof contracts live on Ethereum. Final withdrawals and cross-chain messages are only safe once Ethereum accepts the rollup block that contains them.
EIP-4844 is Proto-Danksharding. Before it, more than 90 percent of rollup cost came from posting data permanently as calldata. By moving rollup data to temporary blobs, Proto-Danksharding reduced the cost of data posting. Rollups have moved batch submission to blobs since March 2024, which lowered user fees on major L2s. Full Danksharding, with proposer-builder separation and data availability sampling across many more blobs, is the next step toward another 100 to 1000x of scale. Work on it continues.
Optimistic rollups assume a batch is valid unless someone proves it is not. This is often called innocent until proven guilty.
Live examples: Arbitrum One, OP Mainnet, and Base. Base is built on the OP Stack, the same open framework that powers OP Mainnet.
During the window, later blocks can build on an unconfirmed root, but they can be reverted if their parent is found invalid.
Ethereum.org tracks current costs as about 5 to 20 times cheaper than L1 for rollups in general, with fees composed of L1 data publication (blob or calldata) plus L2 execution fees. Check a live fee tracker for the chain you plan to use, since blob base fees change per block.
A single sequencer orders transactions today on most optimistic rollups. If it censors or goes offline, you can submit through an L1 delayed inbox so the L2 must include your transaction or stop finalizing. On OP Stack chains this is typically enforced within hours, on Arbitrum One the force inclusion delay is up to 24 hours with additional timeout buffers. This gives you an escape hatch, but it costs time and L1 gas.
ZK-rollups prove validity up front with cryptography. This is often called guilty until proven valid.
Live examples: zkSync Era by Matter Labs, Starknet by StarkWare, Polygon zkEVM, Scroll, Taiko, and Linea by Consensys. They sit at different points on the zkEVM spectrum. Taiko aims for full Ethereum equivalence, others trade exact equivalence for easier proving.
Both let the L1 verifier confirm correctness without re-running every transaction. Many teams also use recursion, where a proof verifies other proofs, to finalize multiple blocks with one submission.
Proving simple transfers is straightforward. Proving arbitrary EVM execution is hard. The EVM has many opcodes and state touches in memory, stack, and storage. A zkEVM must recreate that logic inside a circuit and prove each step. That is why full EVM support came later for ZK rollups than for optimistic rollups, and why prover costs remain the main trade-off.
Ethereum.org summarizes the current picture as:
Your actual fee has three parts: the L1 data cost (blob or calldata), the L2 execution fee, and for ZK the amortized cost to generate and verify the proof across the batch. Large batches spread cost, but posting small batches often raises per-transaction cost. Blob base fees rise when many rollups compete for the 3 to 6 blobs per block, and some ZK operators fall back to calldata when blobs are expensive.
For recent network-level fees, Ethereum.org points to its networks page. As of late August 2026 it lists average fees like $0.054 on Ethereum mainnet, $0.002 on Base, $0.005 on Arbitrum One, $0.004 on Starknet, with wide variance by operation and congestion. Use a live L2 fee tracker and the rollup explorer to confirm batch posting status for the transaction you care about.
| Feature | Optimistic rollups | ZK-rollups |
|---|---|---|
| Validation method | Fraud proofs during a challenge window. State accepted unless a valid challenge proves fraud. | Validity proofs verified on L1 before state is accepted. |
| Challenge period | Yes. Typically about 7 days on OP Stack chains, 6.4 days on Arbitrum One. | No challenge period. Finality follows proof verification and L1 confirmation. |
| Withdrawal through the canonical bridge | About 7 days. Fast liquidity bridges exist but charge a fee and add their own trust assumptions. | No 7 day wait. You still wait for batch inclusion, proof generation, and L1 confirmation, often minutes to a few hours. |
| Security model | Cryptoeconomic. Needs at least one honest watcher and bonded sequencer. Misbehavior is penalized by slashing. | Cryptographic. Math guarantees the transition is valid if the verifier contract accepts the proof. |
| EVM compatibility | High today. Most contracts deploy with little or no change. | Improving fast. zkEVMs now support most Solidity, but edge cases and gas differences remain. Starknet uses Cairo, not Solidity. |
| Proving cost | Low. Fraud proof work is done by ordinary nodes. | High. Provers need specialized hardware, often GPUs, and the work is done by a small set of operators today. |
| Data posted to L1 | Full batch data must be on L1 for challengers to check. | Also posts data for reconstruction, but can use stronger compression since validity does not depend on re-execution. |
| Examples | Arbitrum One, OP Mainnet, Base | zkSync Era, Starknet, Polygon zkEVM, Scroll, Linea, Taiko |
A sidechain runs its own consensus and does not post data to Ethereum. A validium posts validity proofs to Ethereum but keeps data off chain. Both can be fast and cheap, but they do not inherit Ethereum data availability. That means you must trust their operators and data holders to stay available and honest. Ethereum.org classifies only rollups, which post data to Ethereum and derive security from Ethereum consensus, as Layer 2 in the strict sense. The others are separate scaling approaches with different trust assumptions.
Keep custody logic on Ethereum when possible. Use the canonical bridge for large exits. Third party bridges that front funds on L1 are useful but add counterparty risk and fees.
Use L2Beat and the project docs. For general DeFi and NFTs, Arbitrum One, OP Mainnet, or Base are common choices. For apps that need fast canonical withdrawals, look at zkSync Era or Starknet. 2. **Add the network to your wallet.
All of these L2s use Ethereum addresses. Add the RPC from the official docs or via a chain list. Fund it with a bridge. Start with a small test amount. 3. **Track finality.
A fast confirmation from the sequencer is not L1 finality. For optimistic rollups, check the explorer for the batch posting time and the remaining challenge window. For ZK, check when the validity proof is verified. 4. **Choose your bridge deliberately.
Canonical bridges are secured by the L2 contracts on Ethereum. Third party bridges and aggregators are faster for optimistic withdrawals but add fees and separate risk. Do not put more through them than you can afford to wait on if they pause. 5. **Watch blob fees.
After Dencun, blob base fees are the key cost lever. Explorers show pending blobs per block. High demand can raise fees.
On Arbitrum and OP Stack chains you can usually deploy compiled Solidity with Hardhat or Foundry unchanged. Test gas and calldata use specifically, since the L2 charges an L1 data fee that reflects what you publish. 2. **Adapt for ZK constraints.
On zkSync, Scroll, Linea, or Taiko, run the project compiler and test suite. On Starknet you write in Cairo. Measure proof-related limits like maximum batch size and pubdata overhead. 3. **Handle cross chain timing.
L1 to L2 messages take minutes. L2 to L1 messages from optimistic rollups take about a week via the canonical path. Do not build logic that assumes a synchronous call back. 4. **Plan for sequencer downtime.
Add a UI path that submits through L1 if the sequencer does not include a transaction. Test force inclusion on testnet. 5. **Audit bridge assumptions.
Keep high value exits on the canonical bridge. If you use a liquidity provider, bound your exposure.
Bigger blocks need larger nodes and more specialized hardware. That reduces the number of people who can run a node and hurts decentralization. Rollups keep the base layer small and secure while adding throughput in a separate layer that still settles on Ethereum.
A rollup publishes batch data to Ethereum and Ethereum enforces validity through fraud or validity proofs. A sidechain runs its own consensus and does not publish data to Ethereum, so it has separate security. A validium publishes proofs to Ethereum but keeps data off Ethereum, so you must trust its data holders.
To give any watcher time to post a fraud proof and get it included on Ethereum, even if an attacker tries to censor challenges. Seven days, or 6.4 days under Arbitrum Bounded Delay, balances user wait time against censorship risk. Shorter exits exist via third party bridges that front the funds, but they move the trust elsewhere.
No. They skip the 7 day window, but you still wait for your transaction to be included in a batch, for the prover to generate the proof, for the proof to be verified on Ethereum, and for the bridge message to be relayed. That is usually minutes to a few hours, depending on batch cadence and L1 load.
A rollup that posts data to Ethereum and enforces fraud or validity proofs is stronger than a sidechain, but it is not identical to using L1 directly. You add dependence on sequencer liveness, proof correctness, and bridge contracts. Check the rollup stage, audits, and upgrade mechanism before you deposit.
Blobs are binary fields carried in type 3 transactions. They are not kept in Ethereum execution state. Consensus nodes hold them for about 18 days, then prune. Operators and indexers that need longer history must store it themselves.Which rollup should I pick today? Pick by your constraint. If you need the fewest code changes and broad tooling, use an optimistic rollup like Arbitrum One or an OP Stack chain. If you need faster canonical exits and can handle zk tooling or Cairo, use a ZK rollup like zkSync Era or Starknet. Check current fees on a fee tracker and confirm data availability is on Ethereum.
Sources: ethereum.org - Scaling, Optimistic Rollups, Zero-Knowledge Rollups, Layer 2, Roadmap Scaling, Roadmap Danksharding, Layer 2 Networks (pages last updated June-August 2026). Specific figures for calldata costs, proof verification, blob lifetimes, Dencun date, and fee multiples are taken from those pages.
Explore more guides and career playbooks