Sidechain · settles to Bitcoin
Merlin Chain ticker MERL
Summary
Merlin runs a Polygon CDK zkEVM chain: an EVM whose execution can be proven with zero-knowledge proofs. One Merlin-operated sequencer orders transactions, aiming for a block every 3 seconds and sealing batches every 10 seconds. Batches and proofs go to a separate EVM parent chain that Merlin hosts (chain ID 202401), not to Bitcoin or Ethereum. Merlin's docs say an oracle network writes state roots and compressed data to Bitcoin Taproot outputs and that Bitcoin-based fraud proofs and a two-step proof submission scheme will come later; this review could not verify either, and Bitcoin itself cannot check Merlin's state. BTC arrives through an operator-run bridge and becomes the chain's gas coin. 47141617272931
Design
- System
- SidechainMerlin markets itself as a ZK-rollup Bitcoin layer 2, but its own docs describe it as fundamentally a sidechain that links to Bitcoin through an official bridge. It is filed here as a sidechain: blocks come from one Merlin-run sequencer, batches and proofs go to a separate Merlin-hosted EVM parent chain rather than to Bitcoin, Bitcoin cannot check Merlin's state or force withdrawals, and BTC moves in and out through an operator-run bridge. BTC, with 18 decimals on Merlin, is the gas coin; MERL is the governance and staking token.
- Settles to
- BitcoinBTC, several BRC-20 tokens and many Ordinals collections enter from Bitcoin through the operator-run official bridge, and Runes through the third-party UniCross bridge; Merlin's docs say state roots are written to Bitcoin. Bitcoin does not validate Merlin blocks or enforce withdrawals, and the rollup contracts that receive Merlin's batches run on a separate Merlin-hosted EVM chain, not on Bitcoin.
- Settlement family
- Bitcoin family
- Scarce resource
- Other
- State model
- Accounts
- Finality
- Other
- Who makes blocks
- A single sequencer run by the Merlin team. Follower nodes are configured to trust the sequencer's RPC and data stream. All 50 blocks in a sample read from the explorer's block list on 27 September 2026 listed the same producer address. Merlin's validator documentation pages are empty, one of them marked coming soon.
- Fork choice
- There is no open fork choice: the sequencer's ordering is canonical and follower nodes sync what the trusted sequencer publishes. No documented rule lets Bitcoin block data, stakers or anyone other than the operator override the sequencer's chain.
Qualifications
- System class · Contested. Merlin's marketing says ZK-rollup Bitcoin layer 2; its own concept page says it is fundamentally a sidechain; the Bitcoin Layers review calls it an alternative rollup whose parent chain is a private network. All three agree Bitcoin does not verify Merlin's state. This profile uses sidechain.
- Scarce resource · Not applicable. No open resource decides who produces blocks: the operator assigns the sequencer. MERL and BTC staking programs exist, but no reviewed document shows stakers choosing or checking blocks.
- Finality · Partial. A sequencer block is the operator's promise. Batches then go to the Merlin-hosted parent chain, where proofs may be checked but outsiders cannot easily audit the contracts. Merlin publishes no reorg limit, and there is no stage at which Bitcoin finality applies to Merlin transactions.
- Data availability · Unknown. Merlin's docs say raw data is held by its oracle network and that an upgraded data availability setup with Celestia and Nubit is coming. The Bitcoin Layers review says data is made available by a permissioned off-chain group. Neither description was independently verified.
- Bitcoin fraud proofs · Not applicable. Merlin's docs describe, in future tense, a challenge game with pre-signed Bitcoin transactions and a circuit of logic gates committed to a Taproot address. No live deployment was found, so there is nothing yet to assess.
- Staking role · Contested. Merlin describes its MERL and BTC staking programs as proof of stake that secures the network, and its tokenomics mention slashing and delegating MERL to consensus nodes, but its validator documentation pages are empty and every block in a 50-block sample came from one producer address.
- Upgrade authority · Applies. Merlin's bridge page says the official bridge uses upgradeable proxy contracts owned by a multisig with no timelock; the Bitcoin Layers review says Merlin's contracts are upgradeable by an admin.
Tradeoffs
- Emphasizes
- Scalability Contested
- Gives up
- Decentralized operation and trust-minimized custody: one operator-run sequencer orders every transaction, follower nodes trust its data stream, proofs are checked on a private Merlin-hosted chain, bridge deposits are credited by admin-approved addresses, and the bridge contracts can be upgraded by a multisig with no timelock.Merlin's docs say the design inherits Bitcoin's security because data is anchored in Bitcoin. The Bitcoin Layers review says Merlin currently inherits no security from Bitcoin, and this review found no Bitcoin-enforced check of Merlin's state or withdrawals, so the security corner is not listed and the reading is marked contested. Scalability here means cheap, fast EVM execution kept off Bitcoin, not a measured throughput.
- Full node at home
- Demanding 141516Merlin's current guide for its Erigon-based RPC node (the version 2.0.3 software, same hardware as the June 2025 upgrade guide) recommends 4 vCPU, 32 GB RAM and a 1 TB NVMe SSD with about 250,000 IOPS; the older node guide asked for 64 vCPU and 128 GB RAM per server. Either way the node syncs from Merlin-hosted endpoints (the sequencer data stream and the parent chain), so running one does not give independent verification of the operator.
- Throughput claims
- No classified figure recorded
Scaling layers
No scaling layer recorded in this profile.
Capabilities
| Capability | How it is provided | Notes and sources |
|---|---|---|
| Account abstraction | Structured assessment pending | Not yet assessed for any chain. |
| Atomic swaps | Unknown | No protocol-level trust-minimized swap was found. EVM contracts could implement hash-locked swaps, but none was reviewed, and any swap with BTC on Bitcoin still depends on the operator-run bridge. |
| Authenticated data publication | Unknown | Not yet assessed under this row's current definition. |
| Light clients | Unknown | Not yet assessed under the current definitions; no light client for Merlin was found. The design produces zero-knowledge proofs, but they are checked on a Merlin-hosted parent chain whose contracts outsiders cannot easily verify, so they do not give users a documented light-verification path. 2729 |
| Native staking or delegation | Structured assessment pending | Not yet assessed for any chain. |
| On-chain governance | Structured assessment pending | Not yet assessed for any chain. |
| Parallel execution | Structured assessment pending | Not yet assessed for any chain. |
| Payment or state channels | Unknown | No payment or state channel layer anchored to Merlin was found. |
| Programmable spending | Native (protocol or core-team software) Earlier definition | Contracts run on a Polygon CDK zkEVM whose documented instruction set has no Cancun-era opcodes and no BASEFEE, returns zero for PREVRANDAO, and has no RIPEMD-160 or blake2f precompiles. Bitcoin wallet users act through ERC-4337 smart accounts. 132223 |
| Protocol-verified messaging | Structured assessment pending | Not yet assessed for any chain. |
| Reversible transfers or recovery | Unknown | Not yet assessed under the current definitions; the earlier review found no protocol feature for cancelling, delaying or recovering payments. Merlin's smart-account page lists social recovery as a general feature of ERC-4337 accounts, but no cited source shows a recovery module live in the Particle accounts used on Merlin. 22 |
| Rollups | Unknown | Merlin's tokenomics mention prospective layer 3 networks that would use MERL for fees, but none was verified as live. Merlin itself is not a rollup on Bitcoin; see the class note. 8 |
| Shielded transfers | Structured assessment pending | Not yet assessed for any chain. |
| Signed partial offers | Unknown | Not yet assessed under this row's current definition. |
Reading these values
- How this feature is provided
- Built into the protocol, core-team software or independent software says where a feature lives and who can change it. These are implementation layers, not quality: core-team software is not closer to the protocol than independent software.
- Structured assessment pending
- The shared review has not assessed this feature for any chain yet (Account abstraction, Native staking or delegation, On-chain governance, Parallel execution, Protocol-verified messaging and Shielded transfers). That does not mean it is absent, and a chain’s profile may already describe it.
- Unknown
- The review has not established this for this chain under the current definition; the note beside it says why. Unknown is not absent and not a low score. A feature reads “Not present” only when a source shows it is absent.
- Earlier definition
- Payment or state channels, Programmable spending and Rollups keep the earlier definition until the next fact-check. There, “Native” does not separate the protocol from core-team software, “Ecosystem software” does not say who publishes it, and “Partial” does not say which layer.
- Reading across rows
- The list of capabilities is incomplete. Do not read these rows as a chain leading or lagging overall.
Ecosystem & custody
| Product type | Status | Notes and sources |
|---|---|---|
| Automated market makers | Established in the ecosystemMerlinSwap | MerlinSwap describes itself as a DEX built on Merlin around an AMM design it calls DL-AMM, with limit orders and liquidity mining, and Merlin's own gas guide uses it as the example swap venue. DefiLlama's data read on 27 September 2026 showed it holding more tracked liquidity than any other DEX on Merlin; the figure is not reproduced here. Its operator and audits were not reviewed. 25323334 |
| Issuer-native stablecoins | None found | Neither Circle's USDC address list nor Tether's supported-protocols page lists Merlin. Dollar tokens on Merlin are bridged: M-USDT and M-USDC are Merlin's Seal receipts for USDT and USDC staked elsewhere, and Meson moves USDT and USDC in, per Merlin's docs. 19203536 |
| Algorithmic stablecoins | Unknown | No algorithmic stablecoin with material usage was verified. Merlin's third-party bridge list names dollar-style tokens such as BBUSD and iUSD whose design was not reviewed. 19 |
| Bridges | First-partyMerlin official bridge (Bitcoin and Merlin), Meson, UniCross, FreeLayer2, Orbiter Finance, Owlto Finance, Chaineye | The official bridge moves BTC, several BRC-20 tokens and many Ordinals collections between Bitcoin and Merlin in both directions; its supported-token list does not include Runes. Merlin's docs list third-party routes: UniCross (Runes, BRC-20), Meson (USDT, USDC, WBTC, ETH), FreeLayer2 (several BTC and dollar tokens), and Orbiter, Owlto and Chaineye (BTC). Third-party bridges were not reviewed. Risk: Bitcoin cannot enforce this bridge. Admin-approved addresses credit deposits on Merlin by citing a Bitcoin transaction hash; the contract checks no Bitcoin proof. Withdrawals are requests an off-chain operator must pay out. The contracts are upgradeable by a multisig with no timelock. Bitcoin Layers says bridge deposits likely go to custodian addresses managed by Cobo, and that the BTC behind M-BTC sits in a Cobo-managed MPC wallet with an undisclosed signer count. 418192629 |
| Block explorers | First-partyMerlin Chain explorer (Blockscout) | The explorer named in Merlin's network settings runs Blockscout software and reads Merlin's own chain data; it is not an independent check of the operator. Other explorers were not reviewed. 1030 |
| Hardware wallets | ThinTrezor Safe 3, 5 and 7 through MetaMask or Rabby | See custody rows: Trezor's MERL page lists the Merlin Chain network with MetaMask and Rabby, and Trezor Suite itself does not include Merlin; Ledger's crypto-asset service has no Merlin network entry, and Merlin's own wallet guide does not mention hardware wallets. 24373839 |
Hardware-wallet custody
| Device maker | Status | What users can and cannot do |
|---|---|---|
| Ledger | UnknownSame as native: Unknown | Cannot: Find Merlin Chain among the networks in Ledger's crypto-asset service or manage a Ledger-listed Merlin accountLedger has not said it does not support Merlin, and no Ledger or Merlin page documents a way to sign Merlin transactions with a Ledger, for example through a general EVM wallet; that path was not tested. Ledger's asset service lists tokens named MERL only on Ethereum and BNB Smart Chain, and their contract link to Merlin's MERL was not checked. Ledger coin pages tried for Merlin returned 404. 3940 |
| Trezor | Through an intermediaryMetaMask or Rabby, listed on Trezor's Merlin Chain pageSame as native: Unknown | Can: Keep the key for a Merlin Chain address on a Trezor Safe 3, Safe 5 or Safe 7 and sign Merlin transactions through MetaMask or Rabby, which Trezor's MERL page lists beside the Merlin Chain network Cannot: Open Merlin Chain accounts in Trezor Suite: Merlin is not among Suite's networks in current code Cannot: Secure the BTC behind Merlin's gas coin: a hardware wallet protects the user's Merlin keys, while the bridged BTC stays with the bridge's custodiansTrezor's page is a token page for MERL that names Trezor Suite, MetaMask and Rabby beside Ethereum, BNB Smart Chain and Merlin Chain without saying which app handles which network; its generic text says Merlin Chain can be sent and received with Trezor Suite, but Suite's network code has no Merlin network. MERL on Ethereum or BNB Smart Chain, both Suite networks, is a token copy on another chain, not custody on Merlin. The page does not mention the BTC used as gas on Merlin, and older Trezor models were not listed. 293738 |
Public data
iKnow Blockchain has no public-data lookups for Merlin Chain yet. This is a limit of the service, not a statement about the network.
| Lookup | Status | What it covers and its limits |
|---|---|---|
| Address or account | Not available yet | Public-data lookups for this chain are not built yet. |
| Tokens and assets | Not available yet | Public-data lookups for this chain are not built yet. |
| NFTs | Not available yet | Public-data lookups for this chain are not built yet. |
| Transactions | Not available yet | Public-data lookups for this chain are not built yet. |
Sourced developments
Developments: Review overdue Reviewed Sep 27, 2026; next review was due Oct 7, 2026, 12:00 UTC.
Publication date · newest first
-
Merlin schedules a mainnet RPC upgrade to cdk-erigon v2.0.3
Merlin scheduled a mainnet service upgrade starting 20 January 2026 at 15:00 UTC to move its Erigon-based RPC component to v2.0.3, with an estimated 48 to 72 hours of intermittent RPC availability. Exchanges were asked to pause Merlin deposits and withdrawals beforehand. The release notes list crash fixes for batch lookups and block receipts.
- Implementation:Released
- Release:cdk-erigon v2.0.3 published
- Activation:maintenance scheduled to start 2026-01-20 15:00 UTC; no follow-up notice confirming its completion was found, though Merlin's current mainnet node guide now specifies v2.0.3
Sources: Merlin Chain Documentation — erigon-rpc: v2.0.2 to v2.0.3 (external site) · Merlin Chain (GitHub) — cdk-erigon v2.0.3 (external site) · Merlin Chain Documentation — Maintenance & Upgrade Guidelines (external site) · Merlin Chain Documentation — Deploy an erigon rpc for mainnet (external site)
-
Merlin closes legacy Merlin's Seal unstaking and MERL airdrop claims
Merlin announced that, as of 2026, it no longer accepts new Merlin's Seal unstaking requests or MERL airdrop claims, nearly two years after the 2024 staking event. Requests already submitted continue to be processed, and the related channels are closed permanently.
- Implementation:Announced
- Release:not a software release
- Activation:closed to new requests as of the announcement
Sources: Merlin Chain — Merlin Chain on Medium (RSS feed) (external site) · Merlin Chain Documentation — What is M-Token? (external site)
Topics your AI can explain
Your AI can explain these topics for Merlin Chain through the connection, with sources.
Known gaps
What this profile's review did not establish:
- No throughput figure is listed; no primary-source rate was classified for this profile.
- Whether Merlin is a Bitcoin layer 2, a sidechain or an alternative rollup on a private parent chain is contested; this profile files it as a sidechain for the reasons in its class note.
- Merlin's claim that an oracle network writes state roots and data to Bitcoin Taproot outputs was not verified; no Bitcoin transactions were traced.
- The operators, membership and contract code of the Merlin-hosted parent chain (chain ID 202401) could not be reviewed; the contracts repository lists it at a bare IP address.
- Who holds the BTC behind the official bridge rests on the Bitcoin Layers review, which says deposits likely go to custodian addresses managed by Cobo and that the BTC behind M-BTC sits in a Cobo-managed MPC wallet with an undisclosed signer count; Merlin's own docs mention only multisig and cold storage without naming signers.
- Current data availability arrangements are unverified: Merlin says an upgrade with Celestia and Nubit is coming, while Bitcoin Layers describes a permissioned off-chain group.
- The Bitcoin fraud-proof and two-step proof submission designs are described in future tense; no live deployment or schedule was found.
- Whether MERL or BTC staking has any role in block production could not be confirmed; the validator page is empty.
- Ledger's crypto-asset service has no Merlin network, and whether its MERL-named tokens on Ethereum and BNB Smart Chain are Merlin's MERL was not checked; no Ledger signing path for Merlin is documented. Trezor Suite's current network list does not include Merlin, so Trezor use rests on MetaMask or Rabby, which was not tested.
- Third-party bridges and MerlinSwap's operator and audits were not reviewed; MerlinSwap's standing among Merlin DEXs rests on DefiLlama's tracked data.
- The 50-block single-producer sample came from the explorer's own block list, which reads Merlin's own chain data.
- The designs of dollar-style tokens such as BBUSD and iUSD listed on Merlin's bridge page were not reviewed.
- No light client, payment or state channel, or live layer 3 anchored to Merlin was found.
- Audit reports in Merlin's audits repository were not read for this profile.
Sources
Oldest dated source check: Source checked Sep 27, 2026 Next check due Oct 27, 2026.
- About Merlin (external site)
- BTC Layer2 (external site)
- ZK-Rollup Network (external site)
- Decentralized Oracle Network (external site)
- Data Availability (external site)
- Two-Step ZKP Submission Mechanism (external site)
- Fraud Proofs Based on Bitcoin (external site)
- Tokenomics (external site)
- Milestone (external site)
- Mainnet (external site)
- Gas (external site)
- Fee Model (external site)
- Ethereum & Merlin Differences (external site)
- Deploy a rpc only node (external site)
- Mainnet fork12 upgrade guideline (external site)
- Deploy an erigon rpc for mainnet (external site)
- Validator (Coming Soon) (external site)
- Official Bridge (external site)
- Third-party Bridge (external site)
- Bridged Tokens (external site)
- Contract Addresses (Mainnet) (external site)
- AA Wallet (external site)
- Connecting to Merlin via BTC wallet (external site)
- Wallet (external site)
- MERL as Gas (external site)
- BTCLayer2Bridge.sol (external site)
- merlin-cdk-validium-contracts (external site)
- Merlin Chain on Medium (RSS feed) (external site)
- Merlin (external site)
- MerlinChain blockchain explorer (external site)
- Merlin explorer block list (Blockscout API) (external site)
- MerlinSwap Protocol (external site)
- Product Features (external site)
- MerlinSwap protocol data (API) (external site)
- USDC contract addresses (external site)
- Supported Protocols (external site)
- Merlin Chain wallet (external site)
- Trezor Suite network configuration (networksConfig.ts, develop branch) (external site)
- Ledger crypto-assets service, network list (external site)
- Ledger crypto-assets service, token search for MERL (external site)
Report an error
Found something wrong or out of date? Reporting is free, and every chain goes through the same process. Published corrections appear in the public log.
Funding disclosure
Funding disclosures appear here when an upkeep arrangement exists, in the form “Upkeep funded by [name]; verdicts unaffected.” The funder ledger has not been published yet. Neutrality & funding