
Measured in Sats, Accounted in Air: Who Really Inherits Bitcoin’s Security?
CryptoPrime
Over the past seven days, while the market searched for direction, a curious thing happened in the Bitcoin Layer-2 sector. The numbers people quote in headlines moved in opposite directions from the actual balances held in the multisig wallets those headlines are supposed to represent. One prominent protocol lost nearly forty percent of its liquidity providers in a single week. Another announced a three-hundred-million-dollar TVL milestone that, on closer inspection, consisted largely of deposits of a token it had minted seven days earlier. I seek the signal amidst the noise of the crowd, and this week the signal is unambiguous: the sector marketed as Bitcoin’s Layer-2 renaissance is, in its largest measurable part, a custody business wearing Layer-2 clothing.\n\nThis is not a purity war fought over academic definitions. It is a question of what a user actually owns when she bridges bitcoin into a synthetic representation on another chain. The difference between “secured by Bitcoin” and “secured by a company that likes Bitcoin” determines whether her exit depends on code or on the goodwill of people she has never met. Hype burns out; robustness remains in the ledger. That phrase has guided my writing since the 2017 ICO boom, and it has never been more relevant than in the current sideway market, where projects compensate for weak price action with aggressive narrative engineering.\n\nLet me begin with the data that forced me to write this piece. In the last three months, I have maintained a personal registry of projects that publicly describe themselves as Bitcoin Layer 2s. The registry is not exhaustive, but it is methodical. I include only projects with a mainnet product, a documented bridge, and a team willing to publish technical documentation. Of the fifty-seven projects that met those minimum criteria, thirty-nine run an EVM-compatible runtime. Of those thirty-nine, twenty-six acknowledge in their own documentation that bridged bitcoin is held by a multisignature set controlled by the project team or its affiliated foundation. Another nine delegate custody to a federation of institutional signers. Only four projects can demonstrate, in code, an exit path that requires no permission from a named party. Those four are not, by any stretch of the imagination, the projects with the largest marketing budgets.\n\nThe imbalance is not accidental. It is structural. To understand why, we need to revisit what the term Layer 2 actually demands. In the ecosystem’s early years, scaling discussions followed a simple hierarchy. Layer 1 was the base ledger, responsible for settlement and security. Layer 2 was any system that settled on Layer 1 while moving execution elsewhere. The canonical example was the Lightning Network, which opens payment channels on Bitcoin’s UTXO set and closes them with ordinary Bitcoin transactions. Lightning does not need a new token. It does not need a validator set. It does not need a bridge. The base layer is the court of final appeal, and the court never sleeps. Code is the only law that does not sleep.\n\nEthereum complicated that clean definition. When rollups arrived, they introduced the idea that a Layer 2 could post compressed data to the base layer and rely on fraud proofs or validity proofs to enforce correctness. The key property was inherited security: the Layer 1 reorgs or reverts a Layer 2, the base layer protocol enforces the correct outcome. Ethereum’s architecture made this practical because its scripting language is expressive enough to verify complex proofs. Bitcoin’s scripting language, deliberately minimal, does not offer that expressiveness today. It does not support the opcodes that would make native rollup verification straightforward. OP_CAT has been discussed, OP_CTV has been discussed, OP_VAULT has been discussed, sighash_anyprevout has been discussed. But discussion is not deployment.\n\nThat technical constraint created a gap, and the market hates a gap. A project that wants to offer Bitcoin users smart contracts can either wait for Bitcoin’s consensus layer to evolve or build a bridge that moves bitcoin into a friendlier environment. The second path is faster, and speed matters when venture capital is watching. The result is that most “Bitcoin Layer 2s” are not layers at all. They are EVM sidechains with Bitcoin-denominated denominations. Their users are not moving to a system that inherits Bitcoin’s security. They are moving to a system that inherits Bitcoin’s brand.\n\nI first encountered this pattern during the DeFi Summer of 2020, when I spent two hundred hours auditing the governance mechanism of Compound Finance with a small team of five developers. That project taught me something that has shaped every subsequent review: a protocol’s governance layer is where its true trust assumptions live. The code can be elegant, the documentation can be immaculate, but if a multisig of twelve people can change the protocol’s rules overnight, the elegance is decoration. The same principle applies to Bitcoin Layer 2s. The question is not whether the team can write a Solidity contract that looks like a decentralized exchange. The question is who controls the door through which bitcoin enters and exits.\n\nLet me be precise about the categories I found in my registry, because the nuance matters. The first category is the federated sidechain, exemplified by Liquid and Rootstock. Funds are locked in a multisig controlled by a federation of functionaries. The federation signs peg-out transactions when users burn their sidechain assets. This design has existed for years, and it can be perfectly useful for institutional settlement. But it is a trust model, not a security model. The base layer does not enforce the sidechain’s rules. The federation does. If enough functionaries collude or are compromised, the bitcoin is gone, and no Bitcoin script will save it.\n\nThe second category is the custody bridge, which dominates the current crop of EVM-compatible Bitcoin Layer 2s. A user sends bitcoin to a wallet whose private keys are held by the project, often under a multisig arrangement with a few signers. The project then mints a representation of that bitcoin on its own chain. Users can trade that representation, lend it, stake it, and borrow against it. The experience feels like a Layer 2 because the user interface is fast and the transaction fees are low. But the underlying bitcoin is an IOU. The protocol’s native token may be listed on major exchanges, and the project may call itself a rollup, but the security of the peg is a ledger entry in a database, not a condition enforced by Bitcoin’s consensus rules.\n\nThe third category is the operator-based bridge, inspired by the BitVM research that circulated in 2023. These designs attempt to reduce trust by using Bitcoin Script to encode a challenge protocol. An operator proposes a state transition, and a challenger can present a fraud proof. In theory, this brings Bitcoin closer to the rollup model. In practice, the current implementations still require the operator and challengers to lock funds in a shared UTXO, and the challenge period introduces latency. More importantly, the exit is not unilateral in the way users expect. A user who wants to withdraw must interact with the bridge protocol, often waiting for a challenge window to expire. That window can be days or weeks. Some designs have not yet demonstrated a path to unblocked withdrawal under adversarial conditions.\n\nThe fourth category, and the one I wish received more attention, is the covenant prototype. These are systems that use actual Bitcoin opcodes to enforce state transitions on the base layer. They are the only designs that genuinely inherit Bitcoin’s security, because the base layer itself validates the conditions under which funds can move. But they are mostly experimental. They require soft forks that Bitcoin has not yet activated, and they run on test networks where the economic stakes are negligible. They are the future, but the future has not arrived.\n\nThis taxonomy is not merely an academic exercise. It has direct consequences for the metrics that the market uses to evaluate projects. TVL, in the current bull narrative, has become a proxy for legitimacy. A project that reports five hundred million dollars in bridged value is treated as more credible than a project that reports fifty million. But TVL is denominated in the project’s own accounting. If a project accepts deposits of its native token, or if it allows users to deposit wrapped bitcoin variants whose own peg is already fragile, the TVL number becomes a stack of assumptions. During my audit work, I have learned to ask a simple question: TVL in what, and redeemable by whom? The answer determines whether the number represents economic value or merely token inventory.\n\nThe situation in China’s digital collectible market offers a cautionary parallel. When regulators moved to restrict secondary trading, the collectibles collapsed into one-off sales that even speculators refused to hold. The reason was not a failure of art or culture. It was a failure of property rights. A digital asset without a credible exit path is not an asset; it is a donation. The same logic applies to bridged bitcoin. If the bridge does not grant the user an enforceable claim on the underlying UTXO, the user’s position is only as strong as the issuer’s continued solvency and goodwill. Markets eventually price that fragility, often all at once.\n\nI have watched this movie before. In 2017, I reviewed over forty whitepapers during the ICO boom, and I identified predatory tokenomics in roughly thirty percent of them. My warnings were not popular. I received death threats from people who believed I was an agent of the legacy financial system. That experience taught me that the crowd often rewards the person who tells the most exciting story, not the person who tells the most accurate one. The Bitcoin Layer-2 revival is the same story with different nouns. The excitement is real. The technology is partially real. But the gap between the marketing language and the audited reality is large enough to drive a truck through, and retail users are the ones who will pay the toll when the market corrects.\n\nLet me share my audit heuristic, because I believe every user should be able to run it with publicly available tools. I call it the Ledger Test. The first step is to find the bridge transaction that locks bitcoin on the base layer. The second step is to inspect the output script of that transaction. If the output is a native multisig address, you have already learned something important: the project controls the private keys, not the protocol. The third step is to look for a unilateral withdrawal path. Ask whether a single user can initiate a withdrawal without the cooperation of the project’s signers. If the answer is no, the system is not a Layer 2 in any meaningful sense. It is a bank. The fourth step is to measure the withdrawal time. A genuinely secure Layer 2 should allow a user to exit within a bounded period, even if the project’s operators vanish. If the withdrawal depends on a committee that meets on Telegram, the user is holding a financial instrument, not a bitcoin-backed token.\n\nThe Ledger Test produces uncomfortable results for some of the most heavily funded projects in the ecosystem. I have audited bridge contracts where the multi-sig threshold was below the number of project employees listed on LinkedIn. I have seen bridges where the signer set includes founders who have already left the project. I have seen governance tokens whose only use case is to vote on changes to a bridge that the team controls anyway. Open source is a covenant, not just a license. A public repository with a permissive license is not the same as a protocol that can survive the disappearance of its founders. We audit the logic, for humans will always err. The code may be beautiful; the governance may be a ticking clock.\n\nI do not make these accusations lightly, and I do not name individual projects in this piece, because my goal is not to destroy reputations. My goal is to give readers a lens through which they can evaluate claims for themselves. The most dangerous lies in the cryptocurrency industry are not the ones told with false data; they are the ones told by confusing the categories of trust and security. A project that says “we are secured by Bitcoin” when it actually means “we hold bitcoin in a vault” is not technically false. But it is functionally misleading, because the user’s mental model of safety is wrong. The user believes she holds bitcoin. In reality, she holds a claim against a corporation.\n\nThe counterargument, and it deserves a fair hearing, is that the distinction I draw is too rigid. Sidechains and custody bridges have legitimate use cases. An exchange that wants to offer fast Bitcoin trading does not need to reinvent the Lightning Network. It can simply hold bitcoin in a vault and issue receipts. A borrower who wants to put bitcoin to work in DeFi might be willing to accept a trusted bridge if the returns are high enough to compensate for the risk. In a world where Bitcoin’s base layer has not yet enabled covenant-based security, pragmatic trust is often the only available option. To dismiss all custody-based products as fraud is to ignore the reality that institutions have been using trusted custodians since the invention of banking. The question is whether the product is honest about its trust model, not whether the trust model exists.\n\nI concede the point, but only partially. Faith in people is costly; faith in math is free. The industry’s founding promise was that we could move value without intermediaries by encoding trust in mathematics. When we quietly reintroduce intermediaries and call them validators, or federations, or signer sets, we are not betraying the promise; we are betraying the clarity that made the promise valuable. The cost is not the fees charged by the intermediary. The cost is the tail risk that the intermediary misbehaves in a way that no contract can anticipate. That tail risk is unmeasurable, and markets are notoriously bad at pricing unmeasurable risks. They tend to price them as zero, right up until they price them as one hundred percent.\n\nThe contrarian angle goes deeper than that. Consider what happens if the covenant-based future never arrives. Bitcoin has been conservative for over a decade, and conservatism has served it well. Many users believe that the base layer should remain exactly as it is, a settlement layer with minimal scripting and maximal discipline. If that view prevails, then the trusted bridge becomes the permanent architecture for Bitcoin DeFi. In that world, the projects that survive will be the ones that build genuine institutional-grade custody, with audited key management, insurance arrangements, and clear legal structures. They will look less like decentralized protocols and more like regulated financial infrastructure. That is not a dystopia; it is simply a different system. But it is a system that must be regulated, because custodianship is a financial service, not a mathematical miracle.\n\nThis is where the KYC theater enters the story. Over the past year, I have reviewed the compliance procedures of several bridge projects. Most of them require users to verify their identity before depositing more than a modest threshold. The stated purpose is to prevent money laundering. The actual effect is to create a paper trail for law-abiding users while doing little to deter sophisticated actors. A determined individual can acquire a few high-value non-custodial wallets, split the deposits into amounts below the verification threshold, and bypass the controls entirely. The compliance costs are thus passed to exactly the users who have nothing to hide. The pattern is familiar to anyone who has worked in traditional finance, but it is new to an ecosystem that once promised the opposite. I do not object to regulation; I object to regulation that functions as marketing while imposing its real burden on the honest.\n\nThe deeper point about Bitcoin Layer-2 identity is that we are asking the wrong question. The community argues about whether a project is a “true” Layer 2, while the more relevant question is whether the project can honor its exit promises under catastrophic conditions. The word “Layer 2” has become a badge, and badges create blindness. I have seen protocols with genuinely clever cryptographic designs die because their token economics were unsound. I have also seen protocols with pedestrian designs thrive because their users understood exactly what they were holding. The ledger is a record of outcomes, not intentions. If a user loses funds because she misread a project’s trust model, the project’s marketing team will say that the documentation was clear. The documentation was clear, in the same way that a subscription agreement written in small print is clear. The burden is on the user to read it, yes, but the burden is also on the industry to stop dressing banks as villages.\n\nDuring my years as an Open Source Evangelist, I have spoken at over a hundred conferences, and I have noticed a pattern. The most enthusiastic audiences are the ones who believe that the code alone is sufficient. They see a repository with tests, a deployment script, and a token address, and they conclude that the project is decentralized. They do not read the governance forum. They do not examine the bridge custody wallet. They do not ask who holds the emergency pause button. In 2020, when I audited Compound Finance, the governance mechanism had a timelock of forty-eight hours. That timelock was the difference between a governance attack being reversible and irreversible. It was a small detail, but it was the kind of detail that determines whether users wake up rich or wake up poor. The same humility should apply to Bitcoin Layer-2 analysis.\n\nThe market context matters here. We are in a sideways market. Bitcoin has traded in a range for months, and capital is not flowing into speculative assets as freely as it did in previous cycles. In such conditions, projects with weak fundamentals cannot rely on rising prices to mask their structural problems. They must either deliver genuine usage or persist on narrative alone. The past seven days have shown which ones are doing which. The projects that can demonstrate real, verifiable participation on their networks—borrowers who pay interest, traders who execute orders, builders who deploy applications—are the ones whose TVL tends to remain stable. The projects that rely on incentive programs and point farming are the ones whose liquidity evaporates when the rewards are halved. The ledger does not lie, but the analytics dashboards can, and often do, because they measure activity denominated in tokens that the project itself manufactures.\n\nI recently spent an evening replaying the on-chain records of a project that once announced a billion dollars in TVL. The records told a different story. Much of the “TVL” was minted by the project’s own treasury, deposited into liquidity pools that the team controlled, and reported as external participation. The real economic activity, measured in unique human users and independent capital, was a fraction of the announced figure. This is not fraud in the legal sense; it is accounting theater, and it has been a persistent feature of the cryptocurrency market since before I started writing about it. The solution is the same as it has always been: measure the cash flows, not the token prices. A DeFi protocol’s health is determined by the spread between what its users pay and what its users earn, and by the difference between the assets it accepts and the assets it promises to return.\n\nWhat does all of this mean for the future? I believe that Bitcoin will eventually get its covenant-based scaling, whether through OP_CAT, OP_CTV, or a more general scripting upgrade. The political economy of Bitcoin soft forks is complex, and activation is never guaranteed, but the technical research is advancing rapidly. The teams building BitVM-based designs are publishing increasingly sophisticated protocols. The timeline, however, is measured in years, not months. In the meantime, the market will continue to fund projects that promise Layer-2 functionality without Layer-2 security. Some of those projects will build real businesses. Others will collapse when their trust assumptions are tested. The pattern will repeat because the incentives are misaligned: it is easier to raise capital with a compelling narrative than with a rigorous security model, and investors are often attracted by the promise of high returns rather than the discipline of verifiable claims.\n\nThe difference between my current analysis and my 2017 analysis is that I now know how to look at the code without being seduced by the whitepaper. In 2017, I spent months reading documents and meeting founders, and I still failed to predict which projects would survive. The market moved too fast, and the teams changed too often. By 2020, I had learned to study the mechanisms that would matter in a crisis: the pause functions, the admin keys, the withdrawal delays, the asset backing. When an auditor looks at a smart contract, she is not looking for bugs; she is looking for the shape of the power structure. The same lens applies to the current crop of Bitcoin Layer-2s. Power sits in the custody keys, in the governance token distribution, and in the team’s ability to change the protocol without user consent. Everything else is detail.\n\nOne of the most important innovations of the 2026 Verifiable Human Standard work I helped draft was the principle that human origin should be verifiable without central coordination. It was a technically complex project, but the ethical premise was simple: authenticity must be provable, not asserted. The same principle should apply to Bitcoin Layer-2 claims. A project should be required to prove, in code, that its security assumptions match its marketing language. If a rollup claims to be secured by Bitcoin, it should be able to demonstrate a mechanism by which Bitcoin’s consensus rules enforce the rollup’s correctness. If a bridge claims to be trustless, it should be able to demonstrate a unilateral exit path that does not require the cooperation of any specific human. The burden of proof should always fall on the party making the grandiose claim, not on the user who must parse seventy pages of documentation to discover that the claim was aspirational.\n\nThe rhetorical question I leave with readers is simple. If the founders of your favorite Bitcoin Layer-2 were to vanish tomorrow, with all private keys lost and all servers shut down, what percentage of your bridged bitcoin would you be able to recover within a month? The answer to that question classifies the project more accurately than any marketing whitepaper. If the answer is zero, you are not a user of Bitcoin Layer-2; you are an unsecured creditor of a startup. There is no shame in being a creditor. There is shame in being a creditor while believing you are a holder.\n\nI will close with a vision, not a prediction. The market will eventually sort the genuine layer builders from the costume layers, because bear markets and sideway markets have a way of raising the bar. The projects that survive will be those that either reduce their reliance on human trust or, where human trust is unavoidable, price it honestly and disclose it clearly. The projects that fail will be those that confuse branding with architecture and sell hope to people who needed math. I have written version of this warning three times in my career, and each time the market has proved the warning true. The chapters differ; the ledger does not. Hype burns out; robustness remains in the ledger. If we want Bitcoin’s next chapter to be a genuine expansion of its capabilities rather than a repeat of the ICO tragedy in a new costume, we must teach ourselves to demand proofs, not promises, and to respect the difference between the two until the code itself cannot tell us apart.