Abstract, the Ethereum layer 2 built by Pudgy Penguins parent Igloo Inc., announced on 6 October that it shuts down on 15 December. The migration page is blunt about what happens to anyone who misses it: “Any users that do not migrate their assets by this date will lose access to their funds.” Sixty-nine days of notice, which sounds generous, and a date, which sounds precise. This morning I pointed a script at Abstract’s RPC and measured what the chain actually does with a withdrawal. The median time from a batch being committed on Ethereum to that batch being executed on Ethereum was three hours and eighteen minutes. The notice mentions neither that number nor a time of day. Somebody has published a deadline without subtracting the deadline’s own latency from it, and the people most exposed are the ones who chose the honest exit.
TL;DR
- Abstract shuts on 15 December 2026 and says unmigrated funds will be inaccessible. Blast, four days earlier, announced a 26 October deadline and said the opposite: recovery stays possible afterwards via its L1 contracts.
- I sampled 60 consecutive Abstract L1 batches on 7 October. Commit to execute ran a median of 198.4 minutes, minimum 198.1, maximum 211.2. Twenty of the sixty were committed and not yet executed.
- On a ZK Stack chain the execute step is the gate. L2Beat’s own risk row for Abstract: “Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen.”
- So the last safe native-bridge moment is the shutdown instant minus roughly three and a half hours, and neither the shutdown instant nor the subtraction has been published. Four figures are in circulation for how much is at stake: 8.7m dollars, 38.7m, 48m and 76m.
- Provable fairness proves the draw. It has never said a word about whether the chain will still be executing batches when the prize moves.
What the notice actually says
Igloo launched Abstract in January 2025 as a home for consumer crypto, betting that the Pudgy Penguins brand could drag ordinary people on-chain. By its own count it processed over 325 million transactions, saw six billion dollars of DEX volume and touched four million wallets, across roughly 144 applications. The games were real games: Pudgy World, Gigaverse, Onchain Heroes, Dogami, ChronoForge, 77-Bit, and D20 Labs brought its Sugartown platform across, poker club included. Somebody even shipped an on-chain coin flip on it, which is the genre this blog lives in.
Luca Netz, Igloo’s chief executive, was candid in the wind-down note: “Even after losing 8 figures, we could have launched a token or pursued an ICO. Ultimately we decided against this.” Shutting something down cleanly, in public, with ten weeks of warning and without printing a token to cover the hole, is better behaviour than most of this industry manages.
The instruction to users is simple. Bridge out through the Migration Hub at migrate.abs.xyz, or the native bridge at native-bridge.abs.xyz, or via Stargate, Relay or Jumper, before 15 December. The page warns that the native route carries a delay of about three hours.
That last clause is the entire subject of this post, and it is the only part of the notice written in the passive voice of an inconvenience. Three hours is presented as a wait. It is not a wait. It is a dependency on the operator still being there when the wait ends.
Sixty batches, measured this morning
Abstract is a ZK Stack chain, chain ID 2741, settling to Ethereum. Transactions execute on the layer 2 almost instantly. Then they are gathered into a batch, the batch is committed to Ethereum, a validity proof is generated and submitted, and finally the batch is executed, at which point its state root is settled and the L2-to-L1 messages inside it, which is what a withdrawal is, become actionable on Ethereum.
ZKsync’s own documentation puts complete finality at “around 3 hours”, including a deliberate delay of “approximately 3 hours as a security measure”. That is the advertised figure. I wanted the observed one, so at 08:29 UTC on 7 October I pulled details for the sixty most recent L1 batches, numbers 93,062 to 93,121, spanning eleven hours of commits from 21:30 the previous evening.
| Measurement | Value |
|---|---|
| Commit to execute, median | 198.4 minutes (3h 18m) |
| Commit to execute, min / max | 198.1 min / 211.2 min |
| Commit to prove, median | 102.3 minutes |
| Prove to execute, median | 99.1 minutes |
| Batches committed, not yet executed | 20 of 60 |
| Batches not yet proven | 17 of 60 |
| L2 transactions per batch, median | 1,989 (min 1,356, max 2,724) |
| L2 transactions across the 60 batches | 119,043 |
Two things stand out. The first is how tight the distribution is: across forty completed batches, the spread from fastest to slowest is thirteen minutes on a three-and-a-quarter hour journey. This is not a flaky pipeline. It is a metronomic one, which is exactly why nobody thinks about it.
The second is the queue. Twenty batches sat committed on Ethereum and not yet executed, seventeen of them without a proof yet. At a median of 1,989 transactions each, that is roughly forty thousand transactions’ worth of Abstract state published to Ethereum, cryptographically destined to be correct, and not yet settled. That queue is not an anomaly, it is the steady state. A forty-thousand-transaction tail has hung off this chain every second of its life, and the same is true of every rollup you use.
Meanwhile the chain itself looks perfectly healthy and says nothing. Blocks arrive every 0.644 seconds on average across the last thousand, carrying one to three transactions each, at a base fee pinned to the floor of 45,250,000 wei on every block I sampled from 29 September onwards. A chain with sixty-nine days to live looks identical, through an RPC, to one with sixty-nine years.
A lag is not a delay when the operator is leaving
Here is the part the notice leaves out. On a ZK Stack chain, the execute step is performed by a whitelisted proposer. Not by you, not by a permissionless market of provers, not by anyone who feels like paying the gas. L2Beat’s risk assessment for Abstract states it plainly: “Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen.” The sequencer row is no kinder: “Users can submit transactions to an L1 queue, but can’t force them.” Abstract sits at Stage 0.
Read those rows next to the shutdown notice and “funds will be inaccessible” stops being a policy and becomes a specification. It is not that Igloo intends to confiscate anything. It is that a chain whose withdrawals require a whitelisted party to keep publishing state roots has, by construction, no exit that survives that party going home. The notice and the risk row are the same fact, written by two people who did not know they were describing the same thing.
Which gives you the arithmetic nobody has done. If you use the native bridge, your withdrawal is not out when you sign it. It is out when the batch containing it is executed on Ethereum, a median of three hours and eighteen minutes after that batch is committed, and the commit happens some minutes after your transaction lands. Call it three and a half hours, generously. The real last safe moment for a trust-minimised exit is the instant the proposer stops, minus three and a half hours.
Nobody has published the instant the proposer stops. The notice gives a date, not a time. If “by 15 December” means the end of that day, the cliff is somewhere around 20:30 UTC on the 15th. If it means the start, it is 20:30 UTC on the 14th. That is a twenty-four hour ambiguity stacked on top of an unstated three-and-a-half hour latency, and the whole stack lands on the one group of users who did the responsible thing and refused to trust a third-party liquidity bridge.
That is the perversity worth sitting with. Stargate, Relay and Jumper settle you out in minutes, because a liquidity provider fronts you the funds on the other side and takes the Abstract-side risk themselves. The native bridge, the one that needs no counterparty, the one a self-custody maximalist would insist on, is the only route with a three-hour exposure to the operator’s continued existence. On 14 December, trustlessness will be the riskier option, and nothing in the notice tells you so.
Blast, four days earlier, said the opposite
Abstract is the second layer 2 to announce its own end in a week. Blast got there on 2 October, citing operating costs that had overtaken revenue, with a withdrawal deadline of 26 October. Twenty-four days, against Abstract’s seventy. But the shorter notice came with a materially better promise: Blast said that after the deadline, recovery remains possible through direct interaction with its bridge contracts on Ethereum, with instructions to follow. It also warned that withdrawals would pause for about a week while staked positions were unwound from Lido, after which the withdrawal delay would drop to 24 hours.
Put the two announcements side by side and the user-facing language is nearly identical. A date, an instruction, a tone of mild urgency. The consequences are not identical at all. For Blast the date is an operational convenience and the L1 contracts remain a backstop. For Abstract the date is a forfeiture. Nothing in either notice teaches you which kind you are reading. You would have to know that one is an OP Stack chain and the other a ZK Stack chain, read L2Beat’s proposer-failure row for each, and work it out yourself.
And Blast has its own unsubtracted lag in the open: a 24-hour withdrawal delay against a 26 October deadline means the last safe moment is the 25th. When two independent organisations make the same omission four days apart, it is not an oversight. It is a convention.
Nobody agrees how much is on the chain
I wanted to know how much money this applies to. It depends who you ask, by a factor of nine.
| Source | Figure | What it counts |
|---|---|---|
| DefiLlama | 8.73m dollars | Value in DeFi protocols on the chain |
| L2Beat | 38.74m dollars | Total value secured, down 33.3% in 7 days |
| Unchained | ~48m dollars | Assets, cited just before the announcement |
| CoinDesk | ~76m dollars | Assets, as of 7 October |
L2Beat breaks its figure down as 20.13m canonically bridged, 18.50m externally bridged and 106.87k natively minted, falling by a third in seven days, which tells you people are already leaving. None of these numbers is wrong, and none of them answers the only question an individual has: whether their balance is in the at-risk pile. A raffle contract holding escrowed ticket money is not in DefiLlama’s DeFi TVL. It is somewhere in L2Beat’s canonically bridged total, unlabelled, indistinguishable from an idle wallet.
Why this lands hardest on games
A game contract cannot read a blog post. This sounds trivial and is not. Everything about Abstract’s death is off-chain: the date lives on a web page and an X post, the time of day does not exist anywhere, and the proposer’s intentions are in someone’s head. There is no field in a block, no precompile, no registry contract, no RPC method that encodes “this chain stops on 15 December”. I went looking. eth_chainId answers the same today as it will on the 14th. The block timestamp does not know either.
Which means a raffle on Abstract that closes on 20 December is, right now, selling tickets with perfect integrity for a draw that cannot be paid. The contract is not buggy. Its randomness could be impeccable, its escrow accounting flawless and publicly verifiable. It will take your money today because every check it is capable of performing passes. The only check that would have stopped it is one no contract can perform, because the fact it needs is not on the chain it lives on.
This is a different failure from the ones this series has catalogued. It is not the Harmony sunset, where nobody ever promised to keep the chain running but balances survived by default through an airdrop to identical addresses; Abstract’s preservation is conditional on a user action inside a window. It is not the who-stores-the-proof problem, which asks whether you can still verify a past draw. You will be able to verify Abstract draws forever, because the data is on Ethereum. You simply will not be able to move the prize. And it is not the solvent-shutdown problem, where an operator closes with the money intact and no clock on the claims. Here there is a clock, published, set to the wrong time.
It is closest to yesterday’s post on finality having three different answers depending on which head you ask for. That was about a healthy chain, where the gap between confirmed and final is a risk window you can measure and wait out. This is the same gap on a chain where the thing that closes it is scheduled to stop. A finality lag you can wait out and a finality lag that expires are not the same object.
What this means for Satoshie
Satoshie runs raffles and coinflips on Base, with Chainlink VRF supplying the randomness. The fairness claim we make is narrow and I want to keep it narrow: the number that picks your winner is generated by a verifiable random function, the request and the fulfilment are both on-chain, and nobody including us can see or steer the outcome in between. That claim is about one step in the process. It has never been a claim about the chain underneath.
What Abstract teaches is that the claim needs a neighbour. If a platform ever winds down, the honest disclosure is not “we will give you plenty of notice”. It is the arithmetic: here is our commit-to-execute lag, measured not quoted, here is the exact instant our last batch goes in, and therefore here is your last safe moment, which is earlier than the date on the poster. A wind-down notice that states a date without subtracting its own settlement latency has given you a number that is wrong in the direction that costs you money.
There is a second commitment buried in this, about open draws rather than idle balances. A deadline is survivable for a wallet, because a wallet can leave whenever it likes. It is not survivable for a raffle that is mid-flight, because the entries are escrowed and the draw has not happened. Any platform shutting down owes its users a rule for that case stated in advance: no draw may close after the last safe moment, and any that would have must be refunded before it. That rule has to be written while the chain is healthy, because the day you need it is the day you can no longer deploy a contract to enforce it. We publish our VRF fulfilment latency and our gas costs because measured numbers beat adjectives. Settlement lag belongs in the same list.
Honest limits
Five, and the first is the biggest.
I measured a healthy chain, not a dying one. Nothing in my data says Igloo will halt the proposer at the stroke of the deadline. A competent team almost certainly intends to keep proving and executing for some period after the sequencer stops, precisely to drain the queue. My complaint is not that they will behave badly. It is that the notice does not say, and “trust them to do the sensible thing” is the exact posture a rollup exists to make unnecessary.
Most people will not be exposed to this. Stargate, Relay and Jumper are offered first and will handle the overwhelming majority of exits, instantly, with none of the above applying. The lag bites the minority who chose the native route: small, disproportionately self-custodial, and the group least likely to be told anything they do not read for themselves.
I did not perform a withdrawal. My claim that the execute step gates L2-to-L1 messages comes from how ZK Stack settlement is documented and from L2Beat’s proposer-failure row. I measured the batch pipeline directly and read the architecture; I did not test the exit end to end.
The four dollar figures are other people’s. I reconciled them by reasoning about what each counts, which is plausible rather than proven. I computed none of them independently.
Base is Stage 0 too. Satoshie runs on a chain with a centralised sequencer and the same general shape of dependency. This is not an argument that our ground is solid and Abstract’s was soft. It is an argument that the lag is a number everyone should publish, including us, and that none of us did.
Three questions worth asking
- Does the platform’s wind-down deadline have a time of day attached to it? A date without a time has a twenty-four hour error bar, and the error bar points at you.
- Has anyone subtracted the settlement lag from that deadline? If the published figure is the headline date rather than the headline date minus the measured commit-to-execute time, nobody has done the arithmetic and you will have to.
- What happens to a game that is still open when the chain closes? Escrowed entries with no draw and no refund rule is the worst cell in this table, and it is the one nobody writes a policy for.
The eighty-eighth unasked half of fairness
The half we ask is whether the draw was fair. Abstract’s games, as far as I know, drew fairly for twenty-one months. Four million wallets, 325 million transactions, a proof system that has never once failed to produce a correct state root, and a batch pipeline so regular that sixty consecutive samples varied by thirteen minutes.
The half we do not ask is whether the result is reachable, and for how long, and by whom. Reachability is not a cryptographic property. It is a budget decision, expressed on-chain as a whitelisted address that either keeps publishing state roots or does not, and every provably fair outcome on that chain is downstream of it.
Abstract did the hard and honourable thing: announced the end early, in public, without a token. Then it published a date that is wrong by about three and a half hours, in the direction that costs its most careful users the most money, because subtracting the lag from the deadline is not yet something anyone thinks to do. Blast made the same omission four days earlier at a different scale.
Barriers at a level crossing come down before the train arrives. Not when. Before, by a margin someone calculated, because the people who built it understood that a warning issued at the moment of impact is not a warning. Two layer 2 networks announced their closing times this month. Neither of them dropped the barrier early.
Satoshie runs provably fair raffles and coinflips on Base, with Chainlink VRF. Our draws, our latency and our costs are all on-chain and all measurable. Come and check our arithmetic.


