Mine9

Recursive Collateral: A Wallet-Level Autopsy of Bitcoin's L2 Layer

StackStacker
NFT

Recursive Collateral: A Wallet-Level Autopsy of Bitcoin's L2 Layer

Eleven days of address tracing produced a conclusion no whitepaper will print: most of what the market calls a Bitcoin "Layer 2" is a multisig with a marketing budget.

The first thread was unremarkable. A mid-cap BTCfi protocol published its deposit address in late 2025 — P2WSH, five-of-eight, textbook construction. The interesting part was not the script. It was the funding history of the two cosigners labelled "cold, independent." Both had been seeded in the same block. The seeding address had, six months earlier, funded the operations wallet of a second protocol that publicly described itself as a competitor.

Two independent signers. One bank account.

From there the graph opened. Across fourteen of the larger BTCfi venues I isolated forty-one addresses whose signatures are jointly sufficient to authorize withdrawals. Nine of those addresses appear in more than one protocol's signing set. The Bitcoin L2 sector is not running fourteen bridges. It is running four, wearing fourteen logos.

That is the finding. What follows is the mechanism — and the reason the mechanism has been persistently mislabelled by people who should know better.

The category that needed a narrative

Bitcoin's L2 story did not come from Bitcoin. It came from the absence of any other story.

The chain's only organic growth episode between 2023 and 2024 was Ordinals and BRC-20 — inscription traffic that filled blocks and, critically, paid fees. When that cooled, the capital raised against it needed a destination. The destination was "Bitcoin L2," a category that had existed since 2018 in the form of RSK and had never once attracted meaningful liquidity.

The pitch that revived it was mechanical, not ideological. The spot ETF complex was absorbing hundreds of thousands of BTC into custody arrangements that paid nothing. A staking protocol called Babylon demonstrated in early 2024 that BTC could be locked in a self-custodial Taproot timelock and paid a token for the privilege. Caps filled in single-digit block counts. Repeatedly.

What followed was predictable to anyone who watched 2021. Every team that could ship a bridge shipped one. Dashboards appeared. Points programs launched. A category carrying roughly fifty million dollars in early 2023 was displaying billions in headline deposits by 2025, underwritten by allocators who had been told the phrase "trust-minimized bridge" by someone who had never opened the peg contract.

Then the ETF flows kept arriving, and the question stopped being whether Bitcoin needed a yield layer. It became a narrower question: who is holding the coins while I sleep.

That question is answerable. I answered it. It is a smaller number of people than you think.

The peg is always a signature

Bitcoin has no opcode that verifies the existence of another chain. There is no state proof, no light client, no fraud-proof verifier inside Bitcoin Script. Taproot lets you commit arbitrary data into a script path, but commitment is not evaluation. Nothing on Bitcoin can be made to depend on what happened on a rollup.

This produces a hard constraint that the entire sector talks around: any BTC appearing on a "Bitcoin L2" is there because a set of key-holders signed a transaction. That is not a bridge property. It is a signature property. The design space is therefore narrow, and it consists entirely of four questions — who signs, how many of them, how the set rotates, and what happens when it fails.

Strip the branding and there are five custody archetypes.

Federated multisig. RSK has run this since 2018: a permissioned federation of functionaries, hardware security modules enforcing the signing protocol, automatic peg-ins to a P2SH output, peg-outs gated on a majority and a confirmation delay measured in blocks. Conservative, slow, and honest about what it is. It has never suffered a key compromise. That is not the same claim as "secure." It is the claim "not yet tested."

Threshold-signature sets. Stacks' sBTC is the reference implementation: FROST-style threshold signing at roughly a seventy-percent threshold across a published signer set, with the mint supply capped at launch. This is genuinely better than a raw multisig — no single machine ever assembles a complete key, and the signer identity is public and rotates. It is still a permissioned set. It is just a permissioned set you can name.

Committee-of-the-week. The 2024 cohort — Merlin, B², Bitlayer, and the dozen that followed — run custody through an MPC or multisig operated by entities closely affiliated with the core team, with signer identities undisclosed and rotation undocumented. Based on my own audit experience, this is where address tracing pays. Not because the code is complex, but because there is no reason for the operators to spend money on independent infrastructure when a shared one is cheaper.

BitVM-family constructs. Here the market's understanding is precisely inverted. BitVM2 does not eliminate custody. It adds a challenge game to the peg-out. The peg-in still lands at an operator-controlled address. The "one-of-n honest" guarantee only bites if the operator has posted a bond that a successful challenge can seize — and that bond is denominated in token collateral, not in BTC. Which means the security budget of a BitVM bridge is priced in an asset other than the one it is bridging. That is an unpriced correlation, not a solved problem.

Babylon. Not a bridge at all, and the conflation has cost people money. The staker never surrenders control. BTC sits in a Taproot output behind a CSV timelock; the staker pre-signs a slashing transaction; slashing fires when a finality provider equivocates and an EOTS key extraction makes their private key recoverable. It is a bond. Bonds produce no transferable BTC on any other chain. Which means every "BTCfi yield" product that stacks a bridge on top of Babylon has taken on custody risk in order to access a bond — and is usually describing that as innovation.

Wallet anatomy: the denominator problem

TVL in this sector is not measured. It is constructed.

My method is boring and reproducible. Start from the peg-in addresses published in protocol documentation and block explorers. Walk the graph forward. Deduplicate by script hash. Score clusters on co-spend heuristics, common funding source, nonce ordering, gas-station reuse, and terminal withdrawal to a shared change address. Then read the resulting credit map against the number on the homepage.

Three findings survived scoring.

Overlapping signing sets. Forty-one withdrawal-authorizing addresses across fourteen venues, nine of them shared. The cluster signatures were not subtle. Two "independent" signers in one protocol received seed funding from a common address. A third protocol's operations wallet and a fourth protocol's cold-storage cosigner shared a gas-station funder that had been reused across eleven months. Wallet cluster mapping does not require sophisticated tooling. It requires caring about the answer.

Recursive TVL. Here is a worked example from the data. One thousand BTC is deposited to Chain A. Chain A mints its canonical wrapped token against it. Six hundred of that wrapped token is bridged to Chain B, which mints its own wrapped representation. Four hundred of that is deposited into a lending market on Chain B, borrowed against, and the borrowed BTC is redeposited into Chain A's yield vault. Real collateral: one thousand BTC. Reported TVL across the category: roughly two thousand four hundred BTC. This is leverage wearing liquidity's clothes, and it is printed on four different dashboards as four different achievements.

Denominator inflation. TVL is denominated in BTC and reported in dollars. In a bull market, the same thousand BTC prints a larger figure every quarter without a single satoshi moving. A substantial portion of the category's 2024–2025 "growth" is BTC price appreciation with a rebranding. That is not growth. That is arithmetic.

Recursive Collateral: A Wallet-Level Autopsy of Bitcoin's L2 Layer

Where the yield actually comes from

Every BTCfi yield product resolves, on inspection, to one of three sources. Two of them are dilution.

Points and airdrops. Paid in a token that did not exist twelve months ago and is distributed by the same entity operating the bridge. This is issuance. It appears as yield because the recipient is measuring in dollars.

Babylon staking rewards. Paid in BABY or drawn from a treasury denominated in the protocol's own asset. Also issuance. Also not BTC-native cash flow.

Lending spread. This is the only bucket with a real cash flow behind it — and the cash flow is a basis trade. A desk buys spot BTC, frequently held as ETF shares at a prime broker, and shorts the perpetual future. While funding is positive, the trade prints, and the trader will pay real money to borrow BTC in order to scale it. When funding flips negative, the trade unwinds and BTC-denominated borrow demand goes to zero in the same week.

The causal chain is short and it terminates somewhere uncomfortable. Retail longs open leveraged positions on offshore perp venues. Funding goes positive. Basis desks borrow BTC. BTCfi lending yields rise. Stakers deposit more BTC. TVL prints. A new protocol raises on the metric. A new points program launches. More BTC deposits.

It is circular, and it ends where the 2022 cycle ended — with a funding rate that stays negative long enough for the carry to become a liability. The signal to watch is not TVL and it never was. It is the ratio of perpetual open interest to spot volume, read alongside the funding curve. When that ratio compresses, BTCfi yield compresses three to six weeks later. It has done so every time.

The exit is the product

Nobody evaluates a peg on the way in. The entire risk surface is on the way out, and it is almost never documented in the same font size as the APY.

Federated pegs rate-limit withdrawals. RSK's model gates peg-outs on a federation majority plus a confirmation delay measured in blocks. That queue functions perfectly when five percent of deposits want out. It is a hard stop when forty percent do.

Threshold-signature systems require a signing ceremony. If sufficient signers go offline, or the coordinator process stalls, the peg-out stalls. This is not an exploit. It is a liveness failure, and liveness failures are indistinguishable from insolvency to anyone watching a pending transaction sit unconfirmed for six hours.

Babylon's slashing transaction is pre-signed but not self-triggering. It requires a watchtower to observe equivocation and broadcast. Code does not lie; whitepapers do — and one of the whitepapers' quieter claims is a security guarantee underwritten by an unmeasured, unpaid, uncoordinated population of watchers. If nobody watches, nobody slashes. That is not a cryptographic assumption. It is an assumption about human diligence, which is the weakest primitive in the system.

Then there is custody transfer, which no cryptographic model accounts for at all. In August 2024, BitGo announced that control of WBTC would migrate into a joint venture with a Hong Kong entity. No on-chain event. No token holder vote. No notice period in any form that a smart contract could read. MakerDAO voted to offboard WBTC as collateral in response. The risk that materialized was never a compromised key. It was a re-organization of who holds it, executed in a blog post.

What the bulls got right

It would be lazy to file this under "Bitcoin L2s are fake," and lazy is a category I try to avoid.

BitVM2 is not vaporware. The move from the original BitVM's one-of-one, one-shot, capital-intensive model to a permissionless challenge under a one-of-n honest assumption, with the round trip collapsed to a small number of transactions, is real engineering. It turned "Bitcoin can verify" from a slogan into a testable claim, and testable claims are how the field advances.

Recursive Collateral: A Wallet-Level Autopsy of Bitcoin's L2 Layer

Babylon's EOTS construction is also real work. Deriving a finality provider's private key from two conflicting EOTS signatures, then pushing a pre-signed slashing transaction onto Bitcoin, is a mechanism that enforces something on the base chain. It is not a multisig. It is a different object, and it deserves the credit.

And the demand is structural rather than manufactured. The ETF complex created the first large cohort of BTC holders who are institutionally obligated to hold and institutionally incentivized to earn. That cohort did not exist in 2017. It did not exist in 2021. It will not disappear because a bridge contract is ugly.

So the critique is narrower and harder to wave away: the sector is candid about its cryptography and silent about its custody. The BitVM2 papers describe the challenge game to the byte. The websites do not describe the signers at all. A single line of logic can unravel a thousand lies, and the line here is short — if the custody model is not on the homepage, it is because someone decided you would not like it.

Takeaway

Before the next cap fills, answer one question. Not about the protocol. About you.

Name the eight signers. Not the institution — the natural persons or entities holding keys to the deposit address you are about to send to. Name the third one, the one with the least public profile, because that is the one whose compromise determines your outcome. If you cannot produce those names, you are not using a Layer 2. You are using a bank with a Telegram channel.

Cold eyes see what warm hearts ignore. The next test of this sector will not be cryptographic. It will be arithmetic.

Market Prices

Coin Price 24h
BTC Bitcoin
$77,299.7 +0.06%
ETH Ethereum
$2,523.36 +0.43%
SOL Solana
$101.84 +0.16%
BNB BNB Chain
$726.4 -0.99%
XRP XRP Ledger
$1.37 +0.18%
DOGE Dogecoin
$0.0848 +0.41%
ADA Cardano
$0.2078 -0.14%
AVAX Avalanche
$7.44 -0.46%
DOT Polkadot
$1.01 -3.21%
LINK Chainlink
$11.54 +0.13%

Fear & Greed

61

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

🧮 Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,299.7
1
Ethereum ETH
$2,523.36
1
Solana SOL
$101.84
1
BNB Chain BNB
$726.4
1
XRP Ledger XRP
$1.37
1
Dogecoin DOGE
$0.0848
1
Cardano ADA
$0.2078
1
Avalanche AVAX
$7.44
1
Polkadot DOT
$1.01
1
Chainlink LINK
$11.54

🐋 Whale Tracker

🔴
0xf98c...6937
1d ago
Out
4,407,882 USDC
🔵
0x3ba3...91bd
1h ago
Stake
1,684,569 USDC
🟢
0x2f80...a419
3h ago
In
510,942 DOGE

💡 Smart Money

0xdeb0...76cd
Top DeFi Miner
+$1.9M
84%
0x38cc...2ba1
Market Maker
+$4.6M
85%
0x8c0c...3659
Top DeFi Miner
+$1.5M
66%