1h ago
Rootstock Cofounder Urges Mandatory Withdrawal Delays for Bitcoin Bridges After Liquid Exploit
Rootstock cofounder and chief scientist Sergio Lerner is urging Bitcoin cross-chain bridges to make "delayed withdrawals" a required safeguard, arguing that bridges should not release funds immediately after software checks.
Speaking to crypto.news after an unauthorized withdrawal incident involving the Liquid Network, Lerner said that without a time lock, a single verification flaw can translate into an instant, near-total loss, leaving bridge operators little time to react. A built-in delay, he said, could create a monitoring and intervention window of several hours to spot anomalies and stop withdrawals before real BTC moves.
The remarks follow an unusual outflow from the Liquid Federation wallet. Reports say an attacker minted LBTC without sufficient collateral and then used SideSwap's pegout service to initiate a withdrawal, resulting in a transfer of nearly 4,000 BTC from the federation wallet. Liquid has described the parties involved as so-called "whitehat hackers." SideSwap said it processed the request through normal procedures because the LBTC appeared indistinguishable from properly collateralized tokens.
About 23 minutes after the request, the federation wallet sent 3,996 BTC to the designated Bitcoin address. Roughly 3,400 BTC have been returned to date. Blockstream said affected bridge nodes have been patched, but about 598 BTC remains unrecovered. As of Sept. 10, Liquid has resumed block production, though transaction recovery and peg operations have not restarted.
Lerner said the incident underscores the dangers of immediate release and argued that a mandatory waiting period between the creation of uncollateralized LBTC and the release of underlying BTC could have materially reduced losses. Under such a design, withdrawals would pass software verification but enter a waiting phase, during which automated monitoring can confirm pegout requests match the BTC reserves backing LBTC. If token supply and collateral diverge, operators could pause withdrawals before hardware signatures are applied, preventing rapid BTC outflows from the federation wallet.
Rootstock already uses a delay: a 36-hour waiting period. Lerner said Rootstock's two-way peg relies on dedicated hardware security modules called PowHSMs, which independently verify that 4,000 Rootstock blocks—about 36 hours of cumulative proof-of-work—have elapsed before signing BTC withdrawals. He added that the private key never leaves the device, and function nodes cannot compel the hardware to bypass the waiting period. Even if most signature participants colluded, they could at most delay withdrawals, not force an early transfer of the underlying BTC.
Lerner also pointed to longer-term protocol-level approaches. BIP443 remains in draft form, and Rootstock's current protections still depend on HSMs and a federated model rather than Bitcoin mainnet consensus. He said a future native Bitcoin vault solution could encode similar controls directly at the protocol layer. BIP443 proposes an opcode, OP_CCV, that would allow Bitcoin outputs to carry constraints limiting how funds can be moved later, with envisioned use cases including sidechains, stateful outputs, and revocable two-step withdrawal structures.