Thunderbolt: Fast Asynchronous Off-Chain Bitcoin Transfers
Hongbo Wen, Hanzhi Liu, Yanju Chen, Jingyu Ke, Dahlia Malkhi, Yu Feng
Abstract
We present Thunderbolt, an off-chain protocol that transfers Bitcoin UTXO ownership with seconds-scale latency, requires no channel graph, no routing, and no liquidity rebalancing, and lets the recipient be offline at the time of transfer. A single UTXO is locked once on-chain under a fixed public key jointly held by the current owner and a threshold committee; ownership then passes through an unbounded sequence of holders; each transfer is a purely off-chain, asynchronous operation whose on-chain cost is zero. The chain sees exactly two transactions regardless of how many transfers occur.
The core invariant is an algebraic cancellation: at each transfer the recipient's fresh secret is added to the holder's share and subtracted from the committee's share, so both shares rotate while the on-chain key stays fixed. To enforce this, the recipient publishes an invoice to a shared append-only ledger (the Thunderbolt Ledger): a public commitment, an encrypted copy for himself, and an encrypted copy for the committee, together with a zero-knowledge proof that all three encode the same fresh secret. The sender fetches the invoice, verifies the proof, homomorphically folds her secret into the recipient's ciphertext to produce a new ownership credential, and publishes the result with a second zero-knowledge proof. Both proofs use a single Sigma-protocol response to force the same witness across elliptic-curve and Paillier verification equations, requiring no trusted setup. The committee operates under a standard -threshold honest-majority assumption: at most of members may be corrupted. The recipient decrypts at any later time; the committee subtracts the fresh secret from its share. By binding each transfer to a distinct fresh secret and context identifier, multiple UTXOs can be transferred independently in parallel.
On our benchmark machine, a complete off-chain transfer finishes in 1022ms with a combined proof size of 3.8KB. General-purpose SNARK (Succinct Non-interactive Argument of Knowledge) backends are orders of magnitude slower on the same relations: even a reduced-parameter instantiation already exceeds our native proving time by two orders of magnitude, and a faithful realization at the deployed 3072-bit Paillier modulus exceeds the memory budget of consumer hardware.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 572cb6be-7620-4757-b0bd-def49431ebe3Related papers
- TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment HubEthan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro et al.NDSS 2017 · 322 citations
- Thora: Atomic and Privacy-Preserving Multi-Channel UpdatesLukas Aumayr, Kasra Abbaszadeh, Matteo MaffeiCCS 2022 · 20 citations
- Ark: Offchain Transaction Batching in BitcoinPim Keer, Matteo Maffei, Marco Argentieri, Andrew Camilleri et al.CCS 2026
- Securing Lightning Channels against Rational MinersLukas Aumayr, Zeta Avarikioti, Matteo Maffei, Subhra MazumdarCCS 2024 · 4 citations
- Fast Batched Asynchronous Distributed Key GenerationJens Groth, Victor ShoupEUROCRYPT 2024 · 19 citations
