Quick Answer
Arbitrum's EVM equivalence means Ethereum security patterns apply directly — the additional audit surface is Arbitrum's optimistic rollup assumptions, sequencer trust model, and L2-specific precompile behavior.
Arbitrum's sequencer is a single centralized entity. It can frontrun, censor, or halt. Contracts that require sequencer liveness guarantees or assume fair transaction ordering are exposed to sequencer failure or manipulation.
L2-to-L1 withdrawals take 7 days to finalize. Contracts that need immediate Ethereum-side asset availability after an Arbitrum withdrawal must use bridging protocols — introducing additional bridge security risk.
block.number on Arbitrum returns Arbitrum block numbers, not Ethereum block numbers. Arbitrum produces blocks much faster than Ethereum — time-dependent contracts using block.number behave differently than intended.
Cross-chain messages from Ethereum to Arbitrum have a processing delay. Contracts that depend on immediate L1-to-L2 message execution can face race conditions during the delay window.
| Vulnerability | Severity | Description | Example |
|---|---|---|---|
| Sequencer Centralization Risk | High | Arbitrum's sequencer is operated by Offchain Labs — a single centralized entity that orders transactions before they are submitted to Ethereum. A sequencer can frontrun user transactions, censor specific addresses, or go offline and halt L2 operations. Contracts that depend on transaction ordering guarantees or liveness are exposed to sequencer failure. | A liquidation protocol that depends on liquidators being able to submit transactions within a specific time window — a sequencer outage (Arbitrum experienced a 7-hour outage in 2022) prevents liquidators from acting, creating bad debt. |
| Fraud Proof Window Attack | High | Arbitrum One uses a 7-day optimistic rollup challenge period. During these 7 days, L2-to-L1 withdrawals are not final — a fraud proof can revert them. Contracts that depend on receiving Ethereum-side assets immediately after an L2 withdrawal transaction fail if a fraud proof challenge is submitted during the window. | A protocol that atomically processes an L2 withdrawal and subsequent Ethereum-side operation — a fraud proof during the 7-day window reverts the L2 withdrawal, leaving the Ethereum-side operation completed without the corresponding L2 state change. |
| Arbitrum-Specific Precompile Differences | Medium | Arbitrum implements several Ethereum precompiles differently or adds Arbitrum-specific precompiles (ArbSys, ArbGasInfo). Contracts that interact with these precompiles or assume Ethereum L1 precompile behavior may behave unexpectedly on Arbitrum. ArbSys.arbBlockNumber() returns Arbitrum block numbers, not Ethereum block numbers — a significant difference for time-dependent logic. | A contract using block.number for time-based vesting — on Arbitrum, block.number returns the Arbitrum block (which advances much faster than Ethereum), causing vesting schedules to complete far earlier than intended. |
| L1-to-L2 Message Delay Exploitation | Medium | Arbitrum's inbox mechanism introduces a delay between L1 message submission and L2 execution. Contracts that depend on immediate cross-chain message processing can be exploited if an attacker can submit a conflicting L2 transaction during the delay window — settling a dispute differently than the L1 message intended. | A cross-chain governance contract that accepts votes via L1 messages — a 10-minute delay in L1-to-L2 message processing allows a different on-chain state to be established during the delay window. |
| Gas Estimation Inaccuracy | Low | Arbitrum's two-dimensional gas model (L2 execution gas + L1 data posting gas) makes gas estimation more complex than Ethereum. Contracts that perform gas checks or provide gas estimates to users may produce incorrect values if they don't account for both gas dimensions, leading to failed transactions or user confusion. | A meta-transaction relayer that estimates gas for users and fronts the cost — the relayer underestimates L1 data posting fees, pays more than it charges, and becomes unprofitable over time. |