Additionally, note that the probability of the proof system breaking can be reduced greatly by making the proof system itself a multisig of multiple independent systems (this is what I advocate in https://ethereum-magicians.org/t/a-simple-l2-security-and-finalization-roadmap/23309 ). I suspect all stage 2 deployments for the first years will be like this.