Introduction
Sergio Lerner, the co-founder and chief scientist of Rootstock Labs, has urged for the implementation of compulsory withdrawal delays for Bitcoin bridges. This recommendation follows a serious breach where nearly 4,000 BTC was siphoned from the Liquid Network’s federation wallet via an unauthorized peg-out.
Concerns Over Immediate Withdrawals
In an interview with crypto.news, Lerner emphasized that the absence of a time-delay mechanism makes it perilously easy for a single validation error to lead to catastrophic financial losses, as withdrawals can occur immediately once a software algorithm validates the transaction.
“The opportunity for recovery diminishes to zero with such swift execution—just one bug can lead to complete financial ruin,”
Lerner stated.
Recent Incident and Its Implications
The catalyst for his comments was a recent incident in which individuals generated uncollateralized L-BTC and then utilized SideSwap’s peg-out service to extract funds from the Liquid Network. While Liquid referred to these individuals as ‘purported white-hat hackers’, SideSwap processed their requests under the assumption that the L-BTC was legitimate. Following this, over 3,400 BTC were ultimately returned after Blockstream addressed vulnerabilities in the affected bridge nodes. However, 598 BTC remains unrecovered, and Liquid has since resumed its activities without reinitiating transaction settlements or peg operations as of September 10.
Proposed Solutions
Had there been a time-delay lock in place, Lerner believes the fallout could have been significantly mitigated. Such a system would not allow funds to be transferred immediately upon software approval, instead incorporating a waiting period. Advanced monitoring tools could synchronize the withdrawal requests against actual reserves of BTC backing L-BTC and trigger alerts in instances of discrepancies before finalizing any transactions.
Lerner elaborated,
“If Liquid had implemented a system where funds are secured for a certain period after approval, this mishap would have transformed from a sudden disaster into a manageable occurrence.”
He argued that the delay would have equipped operators with a valuable window of response after the issuance of uncollateralized tokens and that continuous monitoring could have signaled when the peg-out attempt was executed without enough collateral support.
Security Measures and Governance
In the past, Liquid did not report any security breaches involving its Peg-out Authorization Key. SideSwap noted that a user had sent 4,000 L-BTC to its service, which proceeded with the transaction because the L-BTC was indistinguishable from legitimate backed tokens. Approximately 23 minutes later, the Liquid Federation transferred 3,996 BTC to the specified Bitcoin address.
Lerner’s suggested modification aims to introduce safeguards after initial validation stages. With an obligatory delay in withdrawals, even if a software error occurs, the corresponding BTC would not be immediately sent out. Rootstock already employs a delay mechanism for Bitcoin withdrawals, leveraging its two-way peg, despite Bitcoin’s consensus rules not mandating such gaps. This system utilizes specialized hardware security modules known as PowHSMs. Before sending a peg-out, these devices verify that at least 4,000 Rootstock blocks have been processed, equating to around 36 hours of cumulative proof-of-work.
Additionally, the private keys remain secure within the hardware boxes, preventing functionaries from circumventing the waiting period. Lerner described his security model, which guarantees that even in a scenario where a group of peg operators collude, they cannot access the funds, since the private keys are contained within the PowHSMs. Moreover, these modules independently confirm that the necessary blocks of work have been completed before allowing any signature for peg-outs.
Response to Unusual Activity
In cases where unusual activity is detected, Lerner emphasized that functionaries possess the ability to deactivate their HSMs, ensuring that no signatures are provided for pending peg-outs. This precaution allows operators to scrutinize incidents thoroughly and determine the next steps without jeopardizing underlying BTC security. He noted that while a conspiratorial majority could stall the peg operations, unauthorized withdrawals could not be executed.
Flexible Delay Duration
Lerner has also highlighted that the duration of delays should be flexible, tailored to the nature of each transaction. Longer delays may be appropriate for larger amounts of BTC, allowing more time for scrutiny, while smaller transactions might require shorter wait times. His proposal would enable independent functionaries to halt processes while assuring that they cannot unfairly redirect or seize funds.
Future Considerations
Such governance would dilute the risk of centralized control over revocation processes. Lerner envisions a setup where multiparty systems of independent functionaries manage withdrawal protocols, necessitating collaborative action for any significant decision rather than leaving it to a single entity.
Moreover, Lerner pointed out that enhanced controls could beneficially migrate into the Bitcoin protocol, potentially reducing reliance on bridge-specific mechanisms. One such proposal currently under consideration is BIP-443, which seeks to integrate an opcode (OP_CHECKCONTRACTVERIFY) that could impose restrictions on Bitcoin outputs, allowing conditional movement of funds based on event triggers. However, this proposal is still under review and its exact activation method is yet to be defined.
Conclusion
In conclusion, Lerner argues that acknowledging the necessary time for oversight is essential, particularly as cryptocurrency bridges grow more significant in volume and complexity. The issues afflicting past transactions underscore the urgency in redefining protocols to ensure that safeguards evolve in tandem with technological advancements and financial products.