tBTC
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED. tBTC is one of the better disclosed decentralized Bitcoin bridges, with rotating threshold wallets, governance delays, audits, a redemption watchtower, and a coverage pool. It is still rejected for the current advisor perimeter because it replaces native Bitcoin with an upgradeable Ethereum claim secured by an honest-majority operator assumption and bridge-governance parameters. The product is useful infrastructure, but no approved client use currently requires adding those risks instead of holding native BTC.
- A separately approved client position requires tBTC and no native-Bitcoin implementation satisfies the same purpose
- Independent operator concentration and wallet-member selection remain within a documented honest-majority stress limit
- A proposed-size native redemption completes within the stated service level and the coverage pool can absorb the modeled wallet loss
- Any bridge, wallet-registry, DKG, watchtower, or governance exploit opens an immediate review
The research file
Mechanism and client claim
A depositor sends BTC to a threshold-ECDSA wallet selected from Threshold Network operators, reveals the deposit to the Ethereum Bridge, and receives tBTC after the wallet sweeps the UTXO and a proof is accepted. Redemption burns or debits the Ethereum-side claim, queues a Bitcoin output script, and relies on the active wallet to build and sign a Bitcoin transaction. Wallets rotate on a scheduled lifecycle and moving-funds transactions transfer reserves between them. The bridge therefore avoids one centralized custodian but does not make the Ethereum token native Bitcoin.
Control, governance, and legal perimeter
BridgeGovernance owns the upgradeable Bridge and can change deposit, redemption, wallet, fraud, treasury, and trusted-vault parameters subject to parameter-specific delays. Threshold token governance and timelock controllers sit above those contracts. Operator selection is random and threshold signing requires an honest majority, but stake and operator independence determine whether that assumption is meaningful. Trusted vaults and cross-chain integrations can add separate contracts. The published mainnet list, audits, redemption watchtower and coverage pool are positive controls, not elimination of governance or quorum risk.
Incident and operating record
Threshold publishes core bridge, wallet-registry, DKG, cross-chain integration, and staking audit reports through 2025. No current tBTC-v2 reserve-loss exploit was identified in the reviewed sources as of the cutoff. That record distinguishes tBTC from opaque wrappers, but the protocol documentation itself frames security as an honest-majority probability rather than a trustless equivalence to Bitcoin. A clean period cannot prove future DKG independence, bridge-governance restraint, Bitcoin proof correctness, or sufficient coverage after a correlated operator failure.
Exit, liquidity, and failure path
Native redemption requires a valid request, an available active wallet, sufficient main UTXO, Bitcoin transaction construction, operator signatures, proof submission, and confirmations. Fees include a governance-adjustable redemption charge and Bitcoin miner cost. A timed-out redemption can be reported and penalized, but delay is still borne by the holder. Secondary tBTC liquidity may be faster but introduces market discount and DEX depth. During a threshold-signing, governance, Ethereum, or Bitcoin disruption, quoted TVL does not create an alternate guaranteed one-for-one exit.
Comparison and decision
Native BTC has no bridge contract, Ethereum upgrade path, token-governance layer, or rotating custody quorum. Wrapped Bitcoin can be necessary collateral for a separately approved Ethereum strategy, and tBTC would compare favorably with a single custodian on censorship resistance, but that is a dependency decision attached to the exact strategy—not a reason to approve the wrapper in isolation. Reopen if a client-approved position specifically requires tBTC and measured redemption, operator concentration, coverage, and contract delays beat every available wrapper alternative.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Threshold Docs — tBTC bridge · primary · accessed 2026-08-19
Supports: threshold wallets, honest-majority assumption, fees - Threshold Docs — Bridge contract API · primary · accessed 2026-08-19
Supports: deposit, sweep, redemption, wallet lifecycle - Threshold Docs — BridgeGovernance · primary · accessed 2026-08-19
Supports: governable parameters, delays, trusted vaults - Threshold Docs — security audits · primary · accessed 2026-08-19
Supports: bridge audits, DKG audits, integration audits - Threshold Docs — mainnet contracts · primary · accessed 2026-08-19
Supports: Bridge, timelock, watchtower, coverage pool - DefiLlama — tBTC protocol data · secondary · accessed 2026-08-19
Supports: protocol category, chain perimeter, current TVL
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Bitcoin | Approved | sovereign | no issuer, sequencer, or upgrade key controls native Bitcoin; the standing control risk is mining-pool concentration, not an administrative backdoor. |
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |