Rootstock co-founder called on the Bitcoin Cross-Chain Bridge to introduce a mandatory withdrawal delay to deal with the illegal withdrawal of approximately 4,000 BTC.
Rootstock co-founder Sergio Lerner proposed that the Bitcoin Cross-Chain Bridge should adopt a mandatory withdrawal delay mechanism. The recommendation came after nearly 4,000 BTC were extracted from the Liquid Network Alliance Wallet through unauthorized means. The time-lock mechanism provides bridge operators with a window of hours to identify and block unauthorized withdrawals.
Risks of instant settlement and background to L-BTC anomalies
Sergio Lerner, chief scientist and co-founder of Rootstock Labs, pointed out in an interview that instant settlement could cause a single verification error to cause financial losses before the bridging operator responds.
"Without a time-delay lock, a single verification flaw and total capital loss would become the same thing, because once the software issued an 'agree' command, funds would be transferred immediately," Lerner said.
His comments followed a security incident: the attacker created L-BTC without corresponding collateral and used SideSwap's withdrawal service to withdraw nearly 4,000 BTC from the Liquid Joint Wallet. Liquid called the attackers so-called "white-hat hackers," while SideSwap said its service passed L-BTC when processing requests because it appeared to be effective. Later, after Blockstream confirmed that the affected bridge nodes had been repaired, the attacker returned 3,400 BTC. As of September 10, there were still approximately 598 BTC items that had not been recovered, and Liquid continued to produce blocks without resuming trading or pledge operations.
How time delay locks create intervention windows
Lerner believes that if a mandatory delay was set between creating unsecured L-BTC and actually releasing BTC, the damage could have been reduced. Under this system, software approval does not immediately complete the withdrawal, but initiates a waiting period. Automated monitoring tools can compare the requested withdrawal amount with the BTC collateral supporting L-BTC before settlement, flag any imbalance.
"If Liquid has a time-delay lock-meaning that funds cannot be moved for a specified period of time regardless of what the software or carrier says-then the vulnerability will only cause a manageable incident rather than an immediate full-scale disaster."
According to Lerner, this delay would provide operators with a multi-hour response window after coins are minted. A 24/7 monitoring system can detect that withdrawal requests have passed preliminary software checks despite the lack of corresponding collateral. He added that operators can then suspend pledge operations until the hardware signs the transaction or releases BTC from the joint wallet.
This time, the Liquid system did not report the stolen "Peg-out Authorization Key". SideSwap stated that a customer sent 4,000 L-BTC to its withdrawal service, and since it could not be distinguished from supported L-BTC, the service processed the request in accordance with normal procedures. About 23 minutes later, United Wallet paid 3,996 BTC to the provided Bitcoin address.
Rootstock's 4,000 block Bitcoin withdrawal delay mechanism
Rootstock currently uses a delay mechanism to withdraw BTC in its two-way pledge channel, although Bitcoin consensus rules do not enforce waiting periods. The system relies on professional hardware called PowHSMs (Proof-of-Work Hardware Security Modules). Before signing withdrawal transactions, these devices independently verify that 4,000 Rootstock blocks have passed, which represents a cumulative workload of approximately 36 hours.
Lerner pointed out that the private key remains inside these devices, and operators cannot indicate the period required for hardware to bypass. Rootstock combines HSM rules with merge mining, and Bitcoin miners contribute proof of work to this sidechain.
"Even most pledged nodes with collusion cannot steal funds because the private key never leaves PowHSMs, and HSMs independently verify that 4,000 Rootstock blocks have passed before signing," Lerner said.
Rootstock's model assumes that most Bitcoin hashes and federal operators participating through merged mining will not join forces to stop the network. Lerner said compromised operators can interrupt pledge operations, causing activity issues, but HSM rules prevent them from enforcing unauthorized early withdrawals. When monitoring tools identify suspicious activity, operations personnel can shut down their HSMs, making pending withdrawals unable to be signed. Lerner described the suspension as a way to protect the underlying BTC for operations personnel to use when reviewing issues and deciding next steps.
"The majority who commit collusion can only stop the pledge at most, but cannot force unauthorized withdrawals," he said.
Distributed revocation controls restrict freezing powers
Stopping pending withdrawals introduces another risk, as the same powers may be used to delay legitimate users. Lerner said revocation mechanisms should not be controlled by a single company, operator or administrator. Instead, independent operators should share rights through a multi-party structure, with hardware rules restricting their behavior. In the model he proposed, operators could suspend processing but not redirect BTC to another address or confiscate it.
"To prevent single points of failure or centralized review, revocation of control should be distributed among independent, multiple operators, using hardware enforcement rules rather than centralized management keys."
Such controls still allow a group of operators to interrupt withdrawals when enough participants act together. Lerner's difference lies in the scope of his powers: Operations personnel can temporarily withhold signatures when reviewing exceptions, but cannot create valid transactions that transfer collateral to themselves.
Time delays need to be adjusted based on transaction value
Time delays also need to consider the amount and purpose of each transaction. A 36-hour wait may not be suitable for daily payments, while bridges holding large amounts of BTC have different risk characteristics. Lerner said high-value settlement systems should view time as a security control, similar to the delay mechanism used by physical bank vaults. Withdrawal periods can vary depending on the transaction amount, or different cumulative proof of work thresholds can be required based on the collateral at risk.
Shorter terms can be used for smaller transfers, while longer delays can provide more time for automated systems and human responders to review abnormally large requests. Lerner did not specify a uniform delay time for each bridge, but he cited Rootstock's 4,000 block requirement as an effective period for protecting large BTC balances.
Native Bitcoin vault can incorporate safeguards into consensus
Rootstock's current protection relies on its HSMs and syndicates rather than having the Bitcoin network enforce rules. Lerner said the native Bitcoin vault and revocation keys could move similar controls into the underlying protocol. One possible building block is BIP-443, a draft proposal for an opcode called OP_CHECKCONTRACTVERIFY (OP_CCV for short). The proposal would allow Bitcoin exports to carry data and limit the way its funds can be moved through future transactions.
BIP-443 describes OP_CCV as a consensus change that requires a soft fork. Its listed uses include state-portable bitcoin exports, sidechains, and a two-step withdrawal structure that allows responsive security. The proposal is still in draft status and its activation process has not yet been determined.
Lerner cited OP_CCV and BIP-443 as examples of how native vaults give users or designated parties time to cancel withdrawals when stolen credentials, software tampering, or other anomalies are detected. Lerner said moving the mechanism into Bitcoin Consensus would reduce reliance on specific bridging HSM strategies. Miners, operators or administrators must comply with spending conditions attached to Bitcoin exports, rather than applying a suspension of discretion after funds have been transferred.
For large bridge withdrawals, Lerner said the delay should be long enough so that automated alerts and human operators can identify the problem, stop processing, and check the affected software before BTC becomes permanently expendable to the recipient.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC