Research/Bitcoin

Wrapped Bitcoin Security Models: wBTC, cbBTC, tBTC, and the Trust Spectrum

Comparing the security models of wrapped Bitcoin variants: custodial (wBTC, cbBTC), threshold (tBTC), and decentralized bridge approaches.

bcTanjiJul 9, 2026

Over $15 billion worth of Bitcoin now exists as wrapped tokens on other blockchains, primarily Ethereum. These wrapped Bitcoin variants let holders access DeFi lending, liquidity pools, and yield strategies without selling their BTC. But each wrapping mechanism introduces a trust assumption that does not exist when holding native Bitcoin. Understanding the security model behind each wrapped Bitcoin variant is essential before depositing funds into any of them.

This article maps the wrapped Bitcoin landscape across a trust spectrum: from fully custodial models like wBTC and cbBTC, to threshold-secured approaches like tBTC and sBTC, to consortium-based designs like LBTC. For each, we examine the custody architecture, minting and burning process, attestation mechanisms, and historical security record.

Why Wrapped Bitcoin Exists

Bitcoin's scripting language is intentionally limited. It secures over $1 trillion in value precisely because it avoids the complexity that enables smart contract exploits on other chains. But this conservatism means Bitcoin cannot natively participate in DeFi protocols, lending markets, or liquidity pools built on Ethereum, Solana, or other programmable chains.

Wrapped Bitcoin solves this by creating a representation of BTC on another chain. A user deposits real BTC with some entity (a custodian, a smart contract, a signer set), and receives an equivalent token on the destination chain. The core question is always the same: who holds the keys to the deposited Bitcoin, and what stops them from running off with it?

The bridge problem: Every wrapped Bitcoin variant is fundamentally a bridge. Bridges have been the single largest source of DeFi losses: over $2 billion was stolen from bridge exploits in 2022 alone, accounting for 69% of all DeFi hacks that year according to Chainalysis. Bridge exploits have continued into 2026, with $328 million in cross-chain losses reported through May.

wBTC: The Original Custodial Wrapper

Wrapped Bitcoin (wBTC) launched in January 2019 as the first widely adopted Bitcoin wrapper on Ethereum. It uses a three-party model: custodians hold the BTC, merchants handle minting and burning, and users interact with the ERC-20 token.

BitGo originally served as the sole custodian, holding all backing BTC in cold storage. The model was straightforward: trust BitGo not to steal the Bitcoin, and trust that the mint and burn process accurately tracks deposits and redemptions.

The BitGo Custody Controversy

In August 2024, BitGo announced a joint venture with BiT Global, a Hong Kong-based entity, to create a "multi-jurisdictional custody" structure. Under the new arrangement, BiT Global would receive two of three keys in the multisig wallet controlling wBTC reserves. Corporate filings revealed that BiT Global had connections to Justin Sun and the TRON ecosystem, raising immediate concerns about the concentration of key control.

The transition completed on October 8, 2024. Control is now shared across the United States (BitGo), Singapore, and Hong Kong (BiT Global) using a multi-signature protocol requiring two of three signatures to approve any transaction.

The fallout was significant. MakerDAO (now Sky) voted 88% in favor of offboarding wBTC as collateral in September 2024, though they later reversed course after conversations with BitGo's CEO. Coinbase delisted wBTC entirely on December 19, 2024, citing listing standards. BiT Global sued Coinbase for anti-competitive behavior, but the lawsuit was dropped in June 2025.

wBTC Minting and Attestation

Minting wBTC requires going through an authorized merchant who performs KYC/AML checks. The user sends BTC to the custodian, and after sufficient Bitcoin confirmations, an equivalent amount of wBTC is minted on Ethereum. Burning reverses this: wBTC is destroyed and the custodian releases BTC. Arbitrageurs keep the peg tight by minting when wBTC trades above BTC spot and redeeming when it trades below.

For proof of reserves, wBTC uses Chainlink Proof of Reserve for automated on-chain verification. DeFi protocols can query collateralization before executing lending or borrowing actions. The wbtc.network dashboard publishes live reserve data, and BitGo initiates proof-of-reserve transactions on the Bitcoin blockchain for independent verification.

cbBTC: Coinbase's Institutional Alternative

Coinbase launched cbBTC on September 12, 2024, positioning it as a simpler, more trusted alternative to wBTC. The timing was notable: it arrived weeks after the BitGo/BiT Global controversy eroded confidence in wBTC's custody structure. cbBTC is available on Ethereum, Base, Solana, and Arbitrum.

The custody model is maximally simple: Coinbase is the sole custodian. There is no multisig, no signer set, no threshold scheme. You are trusting a single regulated U.S. company. By mid-2026, cbBTC holds roughly 24-25% of the wrapped BTC market with approximately 80,000-90,000 tokens in circulation.

cbBTC Trust Concerns

cbBTC's service agreement is with Coinbase, Inc., not Coinbase Trust Company. Under the terms of service, BTC deposited to mint cbBTC legally becomes Coinbase's asset. The token also includes a freeze function: Coinbase can unilaterally freeze and blacklist any address holding cbBTC.

At launch, cbBTC had no proof of reserves at all. DeFiLlama developer 0xngmi publicly criticized this, noting that "almost every single bridge provides a Proof of Reserves, but Coinbase doesn't." Coinbase added proof of reserves in February 2025, showing 26,627 BTC backing 26,616 cbBTC tokens at that time.

Custodial Wrapped Bitcoin Compared

PropertywBTCcbBTC
CustodianBitGo + BiT Global (2-of-3 multisig)Coinbase, Inc. (sole custodian)
Launch dateJanuary 2019September 2024
ChainsEthereum + multiple L2sEthereum, Base, Solana, Arbitrum
KYC required to mintYes (via merchants)Yes (Coinbase account)
Proof of reservesChainlink on-chain PoR (since 2019)Added February 2025
Freeze functionNoYes (Coinbase can freeze addresses)
Approximate market share~43-45%~24-25%
Key riskBiT Global key control concentrationSingle-entity counterparty risk

tBTC: Threshold-Secured Wrapping

tBTC takes a fundamentally different approach. Instead of a corporate custodian, BTC deposits are secured by a distributed network of signers using threshold ECDSA cryptography. A group of signers collectively generates a single public key from private key shares, and no individual signer ever possesses the full private key.

The system operates with a pool of 100 signers and a 51-of-100 threshold to approve Bitcoin movements. For each individual deposit, a signer group of three nodes is randomly selected from the pool. These signers post 150% of the deposit value in ETH as collateral, creating an economic incentive against misbehavior.

How tBTC Minting Works

When a user wants to mint tBTC, a signer group forms and generates a Bitcoin wallet via threshold ECDSA. The user sends BTC to this wallet. After Bitcoin confirmations, the signers provide cryptographic proof to the Ethereum smart contract, which verifies the deposit and mints tBTC. The process takes one to two hours. Redemption reverses this: tBTC is burned and the signers release BTC from the deposit wallet.

Anyone meeting the technical and collateral requirements can run a signer node, making the system permissionless. Random selection of signer groups prevents coordinated collusion. If a signer group misbehaves (attempts to steal the deposited BTC), their ETH collateral is slashed and used to compensate affected users.

tBTC Security Track Record

tBTC v1 launched in 2021 and immediately identified two cryptography vulnerabilities that were patched without any fund losses. In 2023, two bugs were discovered through an FTX-associated address that temporarily blocked redemptions but resulted in no losses. A whitehat researcher discovered a transaction malleability vulnerability in August 2023, which was also fixed without incident.

In May 2026, a third-party bridge exploit (the Verus-Ethereum bridge) drained 103.6 tBTC along with other assets, totaling approximately $11.58 million. This was a vulnerability in the Verus bridge, not in tBTC's own threshold signing infrastructure. Over four years of operation and $3.5 billion in cumulative volume, tBTC has had zero direct security incidents resulting in user fund losses from its core custody mechanism.

sBTC: Signer-Secured on Stacks

sBTC went live on mainnet in December 2024 with Bitcoin deposits, followed by withdrawal activation in late April 2025. It represents a middle ground between fully custodial and fully decentralized models. Users send BTC to a multisig wallet controlled by sBTC signers, and an equivalent 1:1 backed sBTC token is minted on the Stacks layer.

The system launched with 15 community-elected signers, including institutional operators like Blockdaemon and Kiln. A 70% consensus threshold (11 of 15) is required for signing operations. The safety guarantee is that as long as 30% of signers (5 of 15) behave honestly, all deposited funds remain safe. Signers must stake assets and face economic penalties for malicious behavior.

sBTC demand was intense: the initial 1,000 BTC deposit cap filled in four days, the second cap filled in under 24 hours, and the third in just 2.5 hours. By the end of Q4 2025, the peg was uncapped entirely. TVL peaked at $545 million before settling around $437 million by end of Q1 2026.

LBTC: Consortium-Based Liquid Staking

LBTC from Lombard Finance introduces yet another trust model. It is a yield-bearing, cross-chain Bitcoin token backed 1:1 by BTC that is restaked through the Babylon Protocol to provide economic security for other chains. Users receive LBTC and earn staking rewards, making it distinct from pure wrapped tokens: it combines wrapping with liquid restaking.

LBTC grew to over $1 billion in TVL in just 92 days after launch and currently commands roughly 70% market share among yield-bearing BTC variants. The underlying BTC is held by a set of regulated, institutional-grade custodians using threshold cryptography. A quorum of independent custodians must coordinate to sign any transaction, and no custodian has unilateral authority to issue, burn, or move LBTC.

Governance is managed by a 15-firm Institutional Consortium (including OKX and Wintermute) that acts as a root of trust, verifying every deposit and mint. Every action requires signatures from two-thirds of consortium members. The Lombard Ledger, a Cosmos-based appchain running CometBFT consensus, serves as the coordination layer. Keys are protected in hardware security modules via CubeSigner, and Chainlink oracles provide real-time proof of reserves.

The Wrapped Bitcoin Trust Spectrum

These five variants span a spectrum from maximal trust in a single entity to distributed trust across many independent participants. The following table maps where each model sits:

PropertycbBTCwBTCLBTCsBTCtBTC
Trust modelSingle custodian2-of-3 multisigInstitutional consortiumElected signers (15)Permissionless threshold (100)
Key holders1 (Coinbase)2 entities (BitGo, BiT Global)15 institutional members15 elected signers100 permissionless nodes
Signing thresholdN/A (sole custodian)2-of-32/3 of consortium11-of-15 (70%)51-of-100
Permissionless participationNoNoNoElected (up to 150 seats)Yes (anyone can run a node)
Economic securityCoinbase balance sheetBitGo insuranceInstitutional reputationStaked assets + slashing150% ETH overcollateralization
Censorship resistanceLow (freeze function)MediumMediumMedium-highHigh
Yield-bearingNoNoYes (restaking)No (but Stacks stacking)No
The tradeoff is real: Moving left on this spectrum gets you simplicity, regulatory clarity, and institutional familiarity. Moving right gets you censorship resistance, permissionless access, and reduced counterparty risk. No wrapped Bitcoin variant eliminates trust entirely: every one requires trusting that some set of key holders will not collude or be compromised.

Historical Bridge Exploits and What They Teach

The security models above do not exist in a vacuum. The history of cross-chain bridges is littered with catastrophic failures that illustrate exactly what can go wrong when trust assumptions break down.

Largest Bridge Exploits

  • Ronin Bridge (March 2022): North Korea's Lazarus Group compromised five of nine validator keys through social engineering, draining $625 million in wETH and USDC. The attack exploited a key management weakness: too few validators with insufficient operational separation.
  • Wormhole Bridge (February 2022): An attacker exploited a smart contract bug on Solana to forge guardian signature verification, stealing 120,000 wETH (roughly $320 million). The vulnerability was in the verification logic, not the custody model itself.
  • Nomad Bridge (August 2022): A smart contract upgrade introduced a bug that allowed anyone to fake a valid transaction proof. Over $190 million was drained in a chaotic free-for-all where hundreds of addresses copied the exploit.

The common thread across these incidents is not a single failure mode. Ronin was a key management failure. Wormhole was a verification logic bug. Nomad was a smart contract upgrade error. This diversity of attack vectors underscores the fundamental challenge: bridges introduce multiple layers of software and operational complexity, and each layer is a potential failure point. Read more about these risks in our analysis of stablecoin cross-chain bridging risks.

The Philosophical Tension: Sovereignty vs. Composability

Bitcoin was designed to be a bearer asset: possession of the private key is full ownership, with no counterparty required. Every wrapped Bitcoin variant compromises this property. When you deposit BTC to receive wBTC, you have traded self-custody for DeFi composability. The BTC is no longer yours in the Bitcoin-native sense: it is held by someone else, and you hold an IOU on a different blockchain.

This tradeoff is not inherently wrong. Billions of dollars in wrapped BTC exist because the DeFi use cases (lending, liquidity provision, yield farming) create genuine economic value. But users should be clear-eyed about what they are giving up. The original cypherpunk vision of Bitcoin was sovereignty without intermediaries. Wrapped Bitcoin reintroduces intermediaries, just different ones than traditional finance.

The progression from wBTC's single-custodian model to tBTC's permissionless threshold network represents an attempt to reduce this tradeoff: keeping DeFi composability while distributing trust across enough independent parties that no single failure can compromise user funds. But distribution is not elimination. Even tBTC requires trusting that a majority of randomly selected signers will behave honestly and that the smart contract code is correct.

How Spark Approaches the Problem Differently

All of the wrapped Bitcoin variants above share a common design decision: they bridge Bitcoin to another blockchain. The BTC leaves Bitcoin's security model and enters the security model of the destination chain, plus the security model of the bridge itself. This is two layers of additional trust on top of Bitcoin's base layer.

Spark takes a fundamentally different approach. Rather than bridging Bitcoin to another chain, Spark keeps Bitcoin native while enabling programmability through off-chain statechains. The BTC never leaves Bitcoin's UTXO set. What changes is who can authorize spending it, using FROST threshold signatures shared between the user and a set of operators.

This eliminates bridge risk entirely. There is no wrapped token, no destination chain smart contract, no bridge verification logic to exploit. Users maintain self-custody with unilateral exit to Bitcoin L1 at any time, using pre-signed exit transactions that do not require operator cooperation. The worst case scenario is operator unavailability (you cannot make new Spark transfers), not fund theft.

For users who want Bitcoin programmability without the trust overhead of bridges, Spark represents a different point on the design space: native Bitcoin that stays native.

Choosing a Wrapped Bitcoin Variant

The right choice depends on what you are optimizing for. There is no universally superior option, only different tradeoff profiles:

  • Institutional DeFi users who prioritize regulatory clarity and counterparty familiarity may prefer cbBTC, accepting the single-custodian risk for the convenience of Coinbase integration.
  • Users who want established liquidity and broad DeFi integration may choose wBTC, acknowledging the custody structure changes while benefiting from the deepest liquidity pools.
  • Users prioritizing censorship resistance and minimal trust may choose tBTC, accepting slower minting times and lower liquidity in exchange for permissionless, overcollateralized custody.
  • Users interested in Bitcoin-native yield may choose LBTC for its restaking rewards, understanding the consortium-based trust model.
  • Stacks ecosystem participants may choose sBTC for its tight integration with Clarity smart contracts and the Stacks consensus mechanism.
Due diligence checklist: Before depositing BTC into any wrapping protocol, verify: who holds the keys, what the signing threshold is, whether proof of reserves exists, whether the token has a freeze or blacklist function, and what the historical security track record looks like. The comparison tables above provide a starting point.

The Market Is Fragmenting

The wrapped Bitcoin market is no longer dominated by a single player. wBTC's market share has declined from near-monopoly to roughly 43-45%. cbBTC rapidly captured 24-25% within two years of launching. BTCB (Binance-wrapped BTC) holds approximately 22%. The remaining share is split among LBTC, tBTC, sBTC, FBTC, and emerging entrants.

Circle announced cirBTC in 2026, targeting institutional flows with "stablecoin-grade" compliance and reserve transparency. This fragmentation reflects a healthy market response to the concentration risks that the wBTC controversy highlighted. Different users have different trust preferences, and the market is now serving each segment.

But fragmentation also introduces liquidity fragmentation. Splitting wrapped BTC across five or six variants means thinner liquidity pools, wider spreads, and more complex DeFi routing for each. The market will likely consolidate around two or three winners per trust category: one custodial leader, one threshold leader, and one yield-bearing leader.

What Comes Next

The wrapped Bitcoin landscape is evolving in several directions simultaneously. Custodial models are adding more transparency through proof of reserves and multi-jurisdictional custody. Threshold models are expanding their signer sets and reducing collateral requirements. Yield-bearing variants are creating new incentive structures through restaking.

But the most fundamental shift may be away from wrapping entirely. Layer 2 protocols like Spark and other Bitcoin L2s are demonstrating that Bitcoin programmability does not require leaving Bitcoin's security model. If you can get instant transfers, stablecoin support, and DeFi functionality while keeping your BTC native, the case for wrapped Bitcoin weakens significantly.

For developers building on Bitcoin, the Spark SDK and documentation provide a starting point for integrating native Bitcoin programmability without bridge dependencies. For users who want to experience what native Bitcoin payments feel like in practice, wallets like General Bread offer a Spark-powered interface for instant Bitcoin and stablecoin transfers. Explore how different Bitcoin L2 trust models compare to understand the full design space beyond wrapped tokens.

This article is for educational purposes only. It does not constitute financial or investment advice. Bitcoin and Layer 2 protocols involve technical and financial risk. Always do your own research and understand the tradeoffs before using any protocol.