BitVM3: Efficient Bitcoin Bridges via Garbled Circuits
Robin Linus Woll, Ioannis Alexopoulos, Lukas Aumayr, Zeta Avarikioti, Matteo Maffei, David Tse
Abstract
Bitcoin bridges, protocols that lock BTC on Bitcoin and represent it on a secondary system, underpin much of Bitcoin's application layer, yet remain poorly secured. Deployed bridges rely on federated custody with honest-majority assumptions, while BitVM2, the state of the art in trust-minimized bridging, incurs worst-case dispute costs of approximately $16,000, requiring large operator bonds and deposits that restrict participation to well-capitalized parties.
We present BitVM3-bridge, a trust-minimized bridge architecture from Bitcoin to (i) chains with finality certificates, such as Ethereum, and (ii) Bitcoin rollups. Our main contribution is an end-to-end bridge construction that makes trust-minimized Bitcoin bridging practical at scale. The bridge is powered by BitVM3-core, a modular abstraction for permissionless off-chain computation on Bitcoin using garbled circuits. In BitVM3-core, a challenger evaluates a garbled circuit entirely off-chain and obtains a fraud-proof witness if and only if the operator's claim is incorrect. This paradigm reduces total on-chain costs to approximately 0.20. This nearly 1000× cost reduction enables smaller bonds, broader operator participation, and smaller deposit sizes.
Beyond the bridge itself, we make two additional contributions. First, we formalize BitVM3-core as a sound and complete on-chain proof system under standard cryptographic assumptions. Prior GCbased proposals typically provide either informal security arguments or construction-specific formalizations; by contrast, our framework captures existing constructions within a uniform model and gives a generic treatment based on axiomatized security and functional assumptions. Second, we introduce an on-chain Bitcoin light client secure in the variable-difficulty setting, enabling permissionless chain introspection on Bitcoin and thereby the rollup variant of BitVM3-bridge. BitVM3: Efficient Bitcoin Bridges via Garbled Circuits Checkpoint i 0 BTC Burn KickOff 1 Checkpoint i+1 0 BTC Burn KickOff 1 Op.
Commit to H(B i ), T i Commit to H(B i+1 ), T i+1 Operator ∧ LampVerify Ci ∧ AbsTimelock(Ti -2 hours) Operator ∧ LampVerify Ci+1 ∧ AbsTimelock(Ti+1 -2 hours) Challenger Challenger Challenger Challenger Asserti,j (or Payout) Asserti+1,j (or Payout) AbsTimelock(i • 2016 + k + k6/11) or DisproveCheckpointi (i.e., H(si-1)) AbsTimelock(i • 2016 + k + k6/11) or DisproveCheckpointi (i.e., H(si-1)) Operator ∧ RelTimelock(Δ) AbsTimelock((i + 1) • 2016 + k + k6/11) or DisproveCheckpointi+1 (i.e., H(si)) AbsTimelock((i + 1) • 2016 + k + k6/11) or DisproveCheckpointi+1 (i.e., H(si)) Operator ∧ RelTimelock(Δ)
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e1196917-cc7d-4e58-8420-ffaad2546af8Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Proof-of-Stake SidechainsPeter Gazi, Aggelos Kiayias, Dionysis ZindrosS&P 2019 · 222 citations
- FlyClient: Super-Light Clients for CryptocurrenciesBenedikt Bünz, Lucianna Kiffer, Loi Luu, Mahdi ZamaniS&P 2020 · 151 citations
- zkBridge: Trustless Cross-chain Bridges Made PracticalTiancheng Xie, Jiaheng Zhang, Zerui Cheng, Fan Zhang et al.CCS 2022 · 131 citations
- Duty-Free Bits: Projectivizing Garbling SchemesNakul Khambhati, Anwesh Bhattacharya, David HeathCCS 2026
- BABE: Verifying Proofs on Bitcoin Made 1000x CheaperSanjam Garg, Dimitris Kolonelos, Mikhail Sergeevitch, Srivatsan Sridhar et al.CCS 2026
Related papers
- Bridging Bitcoin to Second Layers via BitVM2Robin Linus Woll, Lukas Aumayr, Zeta Avarikioti, Matteo Maffei et al.USENIX Security 2026 · 6 citations
- Glimpse: On-Demand PoW Light Client with Constant-Size Storage for DeFiGiulia Scaffino, Lukas Aumayr, Zeta Avarikioti, Matteo MaffeiUSENIX Security 2023
- Bitcontracts: Supporting Smart Contracts in Legacy BlockchainsKarl Wüst, Loris Diana, Kari Kostiainen, Ghassan Karame et al.NDSS 2021
- Alba: The Dawn of Scalable Bridges for BlockchainsGiulia Scaffino, Lukas Aumayr, Mahsa Bastankhah, Zeta Avarikioti et al.NDSS 2025
- Arbitrum: Scalable, private smart contractsHarry A. Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg et al.USENIX Security 2018 · 353 citations
