Elevated risk — instantly upgradeable contracts, no forced-inclusion mechanism, and off-chain data availability create significant trust assumptions, partially offset by a clean track record and strong gaming partnership pipeline.
Risk Breakdown
Top Risks
Immutable zkEVM contracts are instantly upgradeable with no exit window for users, meaning the admin can modify core system contracts — including the bridge — at any time without a timelock delay. This creates a significant centralization risk where users must trust the Immutable team not to make harmful changes.
The system runs in validium mode with off-chain data availability, meaning transaction data is NOT posted on Ethereum. If the off-chain DA provider fails or withholds data, users cannot independently reconstruct the state or prove their balances for withdrawal.
Only whitelisted proposers can publish state roots on L1, and there is no mechanism for forced transaction inclusion if the sequencer censors or goes offline. In the event of sequencer failure, withdrawals are frozen with no user-accessible fallback.
The gaming/NFT-focused ecosystem has relatively low DeFi TVL compared to general-purpose L2s, creating concentration risk around gaming adoption which has shown volatile engagement patterns across Web3.
Frequently Asked Questions
Is Immutable X safe to use?
What are the main risks of using Immutable X?
What is Immutable X's risk score breakdown?
How does Immutable X compare to other L2 protocols?
Has Immutable X ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.