Lune

CCS2026Top-tier venue

BitVM3: Efficient Bitcoin Bridges via Garbled Circuits

Robin Linus Woll, Ioannis Alexopoulos, Lukas Aumayr, Zeta Avarikioti, Matteo Maffei, David Tse

2026Year
1Top-tier citations

Abstract

Bitcoin bridges, protocols that lock BTC on Bitcoin and represent it on a secondary system, underpin much of Bitcoin's application layer, yet remain poorly secured. Deployed bridges rely on federated custody with honest-majority assumptions, while BitVM2, the state of the art in trust-minimized bridging, incurs worst-case dispute costs of approximately $16,000, requiring large operator bonds and deposits that restrict participation to well-capitalized parties.

We present BitVM3-bridge, a trust-minimized bridge architecture from Bitcoin to (i) chains with finality certificates, such as Ethereum, and (ii) Bitcoin rollups. Our main contribution is an end-to-end bridge construction that makes trust-minimized Bitcoin bridging practical at scale. The bridge is powered by BitVM3-core, a modular abstraction for permissionless off-chain computation on Bitcoin using garbled circuits. In BitVM3-core, a challenger evaluates a garbled circuit entirely off-chain and obtains a fraud-proof witness if and only if the operator's claim is incorrect. This paradigm reduces total on-chain costs to approximately 9,withthechallengetransactionitselfcostingjust9, with the challenge transaction itself costing just 0.20. This nearly 1000× cost reduction enables smaller bonds, broader operator participation, and smaller deposit sizes.

Beyond the bridge itself, we make two additional contributions. First, we formalize BitVM3-core as a sound and complete on-chain proof system under standard cryptographic assumptions. Prior GCbased proposals typically provide either informal security arguments or construction-specific formalizations; by contrast, our framework captures existing constructions within a uniform model and gives a generic treatment based on axiomatized security and functional assumptions. Second, we introduce an on-chain Bitcoin light client secure in the variable-difficulty setting, enabling permissionless chain introspection on Bitcoin and thereby the rollup variant of BitVM3-bridge. BitVM3: Efficient Bitcoin Bridges via Garbled Circuits Checkpoint i 0 BTC Burn KickOff 1 Checkpoint i+1 0 BTC Burn KickOff 1 Op.

Commit to H(B i ), T i Commit to H(B i+1 ), T i+1 Operator ∧ LampVerify Ci ∧ AbsTimelock(Ti -2 hours) Operator ∧ LampVerify Ci+1 ∧ AbsTimelock(Ti+1 -2 hours) Challenger Challenger Challenger Challenger Asserti,j (or Payout) Asserti+1,j (or Payout) AbsTimelock(i • 2016 + k + k6/11) or DisproveCheckpointi (i.e., H(si-1)) AbsTimelock(i • 2016 + k + k6/11) or DisproveCheckpointi (i.e., H(si-1)) Operator ∧ RelTimelock(Δ) AbsTimelock((i + 1) • 2016 + k + k6/11) or DisproveCheckpointi+1 (i.e., H(si)) AbsTimelock((i + 1) • 2016 + k + k6/11) or DisproveCheckpointi+1 (i.e., H(si)) Operator ∧ RelTimelock(Δ)

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext e1196917-cc7d-4e58-8420-ffaad2546af8

Cited by top-tier papers1

Ask how each one uses it

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines