Ethereum rollups explained: optimistic vs zero-knowledge
Both kinds of rollup report to Ethereum. The difference is how they convince it they told the truth — and how long you wait to leave.
Logos are trademarks of their respective owners, shown for identification only. Their use does not imply endorsement. Licences.

On this page
- A rollup executes transactions off Ethereum's main chain, bundles them into batches and posts the data back to Ethereum.
- Optimistic rollups assume batches are correct and allow a challenge period, so withdrawals to Ethereum take roughly seven days.
- Zero-knowledge rollups send a cryptographic validity proof with each batch; once Ethereum verifies it, withdrawals need no challenge wait.
- Ethereum's March 2024 Dencun upgrade introduced blobs, a cheaper temporary data space for rollups that is pruned after about 18 days.
- Rollups use an operator called a sequencer to order transactions, so users depend on it staying online and on the rollup's escape routes.
A rollup is a layer 2 network that executes transactions away from Ethereum, then posts compressed transaction data back to it. Optimistic rollups assume batches are valid unless someone proves fraud during a challenge window; zero-knowledge rollups attach a validity proof that Ethereum checks before accepting the batch.
What is a rollup, in plain terms?
Think of Ethereum as a court that is expensive to use. A rollup is like a busy local office that handles thousands of routine cases, then files a compact summary with the court. The court does not redo each case, but it keeps the files and can rule on any dispute.
Technically, ethereum.org describes rollups as layer 2 systems that execute transactions off-chain and post the transaction data to layer 1, where it is secured by Ethereum's consensus. A smart contract on Ethereum holds the rollup's deposits and records its latest state. Because the data sits on Ethereum, anyone can rebuild the rollup's state from it — which is why rollups are described as inheriting Ethereum's security, unlike sidechains.
The hard question is how Ethereum knows the summary is honest. There are two answers, and they give the two families their names.
How do optimistic rollups work?
Optimistic rollups are “innocent until proven guilty”. The operator posts a batch and a claimed new state, and Ethereum accepts it provisionally. A challenge period follows during which anyone watching can dispute the result by submitting a fraud proof.
ethereum.org explains that disputes are narrowed down through a back-and-forth (bisection) game until only a single disputed computation step remains, which Ethereum then executes itself to decide who was right. If fraud is proven, the bad batch is reverted.
The cost of this approach is time. Users withdrawing from an optimistic rollup to Ethereum must wait until the challenge period — roughly seven days — has passed, because until then a batch could still be overturned.

How do zero-knowledge rollups work?
Zero-knowledge (ZK) rollups take the opposite approach: prove first, then accept. With each batch, the operator submits a validity proof — a short piece of cryptography showing that the new state follows correctly from the old state and the transactions. A verifier contract on Ethereum checks the proof. If it fails, the batch is rejected.
ethereum.org describes two main proof families. SNARKs produce small proofs that are cheap to verify but need a trusted setup and rely on elliptic-curve cryptography. STARKs need no trusted setup and are considered resistant to quantum computers, but their proofs are larger and cost more to verify on Ethereum.
Because correctness is proven up front, there is no challenge window: once the proof is verified, funds can be withdrawn to Ethereum. The catch is that generating proofs is computationally heavy, and building a ZK system that faithfully reproduces the Ethereum Virtual Machine (a zkEVM) has proven difficult.
How do optimistic and zero-knowledge rollups compare?
| Question | Optimistic rollup | Zero-knowledge rollup |
|---|---|---|
| How is correctness shown? | Assumed; fraud proofs during a challenge period | Validity proof checked by Ethereum for every batch |
| Withdrawal to Ethereum | About seven days | Once the proof is verified |
| Main cost | Watchers must monitor; capital waits during exits | Expensive proof generation, often on specialised hardware |
| Ethereum compatibility | Generally close to the EVM | Harder; zkEVM projects aim to close the gap |
| Examples named by ethereum.org | Arbitrum One, Base | ZKsync Era; zkEVM projects such as Scroll, Linea, Polygon zkEVM |
Neither design changes what you see in a wallet day to day. The differences show up when something goes wrong or when you move money back to Ethereum. For contract compatibility, see what EVM-compatible means.
Why did blobs make rollups cheaper?
A rollup's biggest bill is usually publishing data on Ethereum. Originally that data went into calldata, which every Ethereum node keeps permanently — an expensive place to store something only needed for a while.
EIP-4844, known as proto-danksharding, created a new kind of space called a blob. It went live with the Dencun upgrade in March 2024. Each blob holds 4,096 field elements of 32 bytes, or 131,072 bytes (128 KB). Blob data is deleted by nodes after 4096 epochs, about 18 days — long enough for anyone to check or challenge it, but without burdening nodes forever.
Rollups also pass a share of this data cost to users. Arbitrum's documentation explains its fees combine execution costs with a charge for posting data to the parent chain, and the OP Stack documentation describes a separate L1 data fee on top of execution gas.

What risks do rollup users still carry?
- Sequencer power. A sequencer has priority in ordering transactions. ethereum.org notes that users can submit transactions directly on Ethereum, and the sequencer must then include them within a time limit — an escape route, but a slow one. OP Stack chains have no public mempool; only the sequencer sees pending transactions.
- Young code. ethereum.org says layer 2 safety depends on the technology, smart-contract security and the network's maturity.
- Bridges. Moving assets in and out relies on contracts that hold large pools of funds; read cross-chain bridges explained.
What mistakes do people make with rollups?
- Expecting instant exits from an optimistic rollup. The native route to Ethereum takes about a week by design.
- Assuming ZK means private. In a ZK rollup, the proof shows a batch is correct; it does not by itself hide your transactions.
- Treating every “layer 2” label as a rollup. If a network does not post its data to Ethereum, it does not inherit Ethereum's security.
- Ignoring which network an exchange supports. Deposits must arrive on the exact rollup the recipient accepts; see crypto addresses.
Questions readers ask
Are rollups the same as sharding?
No. Sharding would split Ethereum's own data capacity; rollups are separate systems that use that capacity. Proto-danksharding (blobs) was a first step that gives rollups cheaper data space.
Which is better, optimistic or ZK?
Neither is simply better. Optimistic rollups are simpler and closer to the EVM but have a week-long exit; ZK rollups exit faster but need heavy proving. The right comparison is the specific network's track record and design.
Do I pay rollup fees in ETH?
Fees cover the rollup's own processing plus a share of Ethereum data costs. Check the network's documentation for the coin it charges in before you bridge.
What happens if a rollup's sequencer goes offline?
Rollups are designed with ways to submit transactions through Ethereum directly. ethereum.org describes this forced-inclusion route for optimistic rollups; how well it works depends on each network.
Rollups let Ethereum handle more activity by doing the work elsewhere and keeping the evidence on the main chain. Optimistic rollups trust first and allow challenges; zero-knowledge rollups prove first. Either way, you are also trusting the rollup's code, its sequencer and its bridge — so learn how to exit before you deposit.
Sources
- ethereum.org (Ethereum Foundation), Scaling (2026)Primary source
- ethereum.org (Ethereum Foundation), Optimistic rollups (2026)Primary source
- ethereum.org (Ethereum Foundation), Zero-knowledge rollups (2026)Primary source
- ethereum.org (Ethereum Foundation), Danksharding (2026)Primary source
- Ethereum Improvement Proposals, EIP-4844: Shard Blob Transactions (2022)Primary source
- ethereum.org (Ethereum Foundation), Layer 2 (2026)Primary source
- Offchain Labs (Arbitrum documentation), Arbitrum vs Ethereum: comparison overview (2026)Primary source
- Optimism documentation, Differences between Ethereum and OP Stack chains (2026)Primary source
Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.



