TechNewsReel
Live

Rootstock Co-Founder Urges Bitcoin Bridges to Adopt Mandatory Withdrawal Delays

Sergio Lerner argues that time-delay locks can transform catastrophic software bugs into manageable security incidents.

TechNewsReel Newsroom · September 10, 2026

Rootstock co-founder Sergio Lerner is calling for the adoption of mandatory withdrawal delays in Bitcoin bridges to prevent total fund losses caused by software bugs. The proposal aims to eliminate the systemic risk inherent in immediate settlement models, where a single validation error can lead to an instantaneous drain of assets.

Lerner's advocacy follows a security breach on the Liquid Network, where 3,996 BTC were unauthorizedly withdrawn from the federation wallet. The incident occurred after unbacked L-BTC was minted through an Elements cache vulnerability and processed via SideSwap. While the attacker eventually returned 3,400 BTC, approximately 596 BTC remained outstanding. Lerner noted that if Liquid had utilized a time-delay lock, the bug would have been a manageable incident rather than a full-scale catastrophe.

The Mechanics of Time-Delay Locks

Many cross-chain bridges currently rely on immediate settlement, meaning funds move the moment the software validates a request. Rootstock addresses this vulnerability through its PowHSMs (Hardware Security Modules), which implement a 4,000-block delay—roughly 36 hours—before signing a peg-out. This window allows operators to detect and halt fraudulent transactions before they are finalized on the blockchain.

According to Lerner, the absence of such a lock means that a validation bug and a total loss of funds become the same event. By decoupling the validation of a request from the actual movement of funds, bridges can create a critical buffer for human or automated intervention.

Industry Implications and Future Outlook

As Bitcoin bridges handle increasingly large sums of collateral, the reliance on immediate settlement creates a fragile ecosystem. Implementing time-delay locks shifts the security paradigm from total reliance on bug-free code to a model of active monitoring and recovery. This transition is seen as essential for the long-term stability of the Bitcoin scaling ecosystem.

To further decentralize this security, there is a push to move these controls from proprietary hardware, like Rootstock's HSMs, directly into Bitcoin's native consensus rules. BIP-443 is a draft proposal that introduces the OP_CHECKCONTRACTVERIFY (OP_CCV) opcode. This would enable native Bitcoin vaults with dynamic output restrictions, allowing withdrawal controls to be enforced by the network itself rather than trusted bridge operators.

What Remains to be Seen

While the technical benefits of time-delay locks are clear, their adoption depends on the industry's willingness to trade immediate liquidity for enhanced security. The progression of BIP-443 will be a key indicator of whether the Bitcoin community prefers native, consensus-level vault controls over the current reliance on third-party hardware and federation-based security models.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.