Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin CryptoTax DeFAI Chain SAFU AGI Claude Me Claude Skill Claude Cowork
Independent Media
Not affiliated with any project
DeFi Protocol Mechanics, Decoded
defi-bible.com
LATEST
The WBTC in Your Wallet Is Actually Backed by a Two-of-Three Key: Breaking Down Wrapped Bitcoin's Complete Trust Structure  ·  A Protocol You Never Touched Got Hacked — Why Did Your Deposit Still Shrink: Breaking Down the Kelp-to-Aave Bad Debt Chain  ·  Before You Buy, Spend Five Minutes Checking One Thing: Is This Token About to Hit an Unlock Cliff  ·  SEC Commissioner Warns: Moving a Crypto Vault Onchain Doesn't Escape Securities Law — What This Means for the Yield Protocol You're Using  ·  The World's Largest Asset Manager Put an $18 Billion Fund on Uniswap — What Does That Actually Mean?  ·  Same Address, Same Block, In and Right Back Out: How to Catch a JIT Liquidity Attack Yourself With a Block Explorer
protocols

The WBTC in Your Wallet Is Actually Backed by a Two-of-Three Key: Breaking Down Wrapped Bitcoin's Complete Trust Structure

30-Second Version · For the impatient
'1:1 reserve' is a marketing line. 'Who holds the key that can deploy the reserve, and how many keys are needed to agree' is the actual risk disclosure — the former makes you feel reassured, the latter actually determines how reassured you should be.

Full Explanation +
01 · Why did this happen?

If one of the key holders within the 2-of-3 multi-signature acts maliciously, can the other two keys prevent them?

Yes, this is exactly the core defense mechanism of a 2-of-3 multi-signature design. Any transaction moving funds needs at least 2 keys' agreement and signature — a single key's holder, even genuinely wanting to act maliciously, technically cannot unilaterally move any funds — they'd need to convince at least one other key holder to sign along, and if the other two key holders refuse to cooperate, this malicious transaction simply cannot execute technically.

This is also why BitGo, when adjusting the key structure in 2024, specifically ensured it retained two of the three keys — meaning even if the newly joined partner BiT Global wanted to unilaterally deploy funds, they technically entirely couldn't, since they'd lack BitGo, the critical second signing party. This design, to some extent, demonstrates that a multi-signature mechanism's genuine defensive strength lies not in the number of keys itself, but in the concrete technical constraint of 'whether a single holder has the ability to bypass other holders and independently complete a transaction.'

02 · What is the mechanism?

During the 2024 key structure adjustment, what might have happened if BitGo hadn't responded to market concern promptly and insisted on the original adjustment plan?

This is a hypothetical scenario, but you can reference the redemption run mechanism covered in an earlier article to work through the possible trajectory. If BitGo hadn't responded promptly at the time and let market concern keep brewing, more holders might have continued choosing to redeem and exit — this kind of sustained redemption pressure could, to some extent, form the self-reinforcing loop covered in an earlier article — the more people redeem, the more noticeable the market's worry over this token's trust level becomes, prompting more originally-watching holders to also join the redemption ranks.

If this loop continued developing without being effectively interrupted, theoretically it could lead to WBTC's market confidence continuously deteriorating — even if the underlying Bitcoin reserve was actually still sufficient, a purely confidence-based problem could still cause this token's secondary-market trading price to deviate from the genuine 1:1 peg level, forming a depeg phenomenon similar to what's covered in an earlier article. BitGo's choice to respond quickly and adjust the key allocation structure, to some extent, was exactly aimed at proactively intervening to resolve concern before this potential vicious cycle genuinely took shape — also why communication speed and concrete response during a crisis is such a critical concrete case for maintaining market confidence.

03 · How does it affect me?

Besides WBTC, are there other Bitcoin wrapped token alternatives in the market, and how do their trust structures differ?

Yes, the market genuinely has a few different Bitcoin wrapped token designs with varying trust structures. Some newer alternatives adopt an entirely decentralized collateralized minting model, not relying on a single or a few centralized custodian institutions to hold the underlying Bitcoin — instead, a decentralized validator network jointly manages the minting and redemption process, theoretically further lowering dependency on trusting a specific institution, but potentially also bringing extra technical-level risk due to a more complex mechanism; there's also some exchange launching its own branded Bitcoin wrapped token, with that exchange itself serving as the custodian — this model's trust structure, to some extent, comes closer to directly trusting that exchange, noticeably different from WBTC's architecture relying on multi-party DAO governance and multi-signature to disperse risk.

When verifying any Bitcoin wrapped token alternative, it's worth specifically understanding which trust model it adopts — whether continuing WBTC's architecture of multi-signature plus DAO governance, an entirely decentralized collateralized minting mechanism, or a single institution directly serving as custodian. Different models each carry different trade-offs between 'trust concentration' and 'mechanism complexity' — no model is absolutely always safer, needing judgment based on your own preference across these different risk types.

04 · What should I do?

How can an everyday user specifically verify whether the WBTC in their hand genuinely has equivalent Bitcoin reserve backing it?

A few concrete verification steps: check the proof-of-reserve page WBTC's official or a third-party data platform provides — most mature wrapped tokens publicly disclose their underlying reserve address, letting anyone directly query through a blockchain explorer how much Bitcoin this address actually holds, and compare this figure against the currently externally circulating total WBTC amount, confirming whether the two genuinely maintain a 1:1 correspondence; verify whether this reserve address's public record is continuously, real-time updated, or only a one-time static disclosure at a specific point in time — the former usually offers higher transparency, letting you verify anytime, rather than only being able to trust a single snapshot at some point in time.

For an everyday user, walking through this entire verification process doesn't require professional blockchain analysis capability — most steps can be directly completed through a public blockchain explorer and third-party data platform. Periodically (doesn't need to be daily, but worth occasionally) verifying the reserve correspondence status once, especially when the market sees news of a major governance change similar to the 2024 key structure adjustment, is worth proactively verifying rather than purely relying on the protocol's verbal statement.

Full Content +

An earlier article covered Wrapped Bitcoin's (WBTC) basic operating logic — using genuine Bitcoin as 1:1 reserve, minting it into a token usable on Ethereum. But behind the phrase '1:1 reserve' actually sits an entire concrete governance and technical architecture, determining who can deploy this reserve and who can veto whom. This article completely breaks down this structure, letting you see clearly what you're actually trusting when holding WBTC.

Layer One: A Multi-Signature Wallet, Not a Single Person's Call

The underlying Bitcoin reserve is held in a 2-of-3 multi-signature wallet — meaning this wallet has a total of 3 private keys set up, and any transaction moving funds needs at least 2 of these keys' agreement and signature to execute, with a single key alone insufficient to unilaterally move funds. This design's core intent is avoiding a single institution or single individual from being able to independently control the entire batch of Bitcoin reserve.

Layer Two: The Key-Holding Structure, Which Genuinely Underwent an Adjustment in 2024

Before August 2024, WBTC's key structure was simply led by the single institution BitGo; in August 2024, BitGo announced bringing in a new co-custody partner, BiT Global, adjusting the key allocation structure — this news triggered market concern at the time. If key allocation becomes more dispersed, involving more institutions of different backgrounds, theoretically governance is more decentralized, but it could also bring new coordination risk and trust concern. The market's reaction at the time was fairly direct — within two weeks of the news breaking, WBTC's redemption volume reached roughly 60 times the new minting volume, showing a fairly substantial proportion of holders chose to redeem and exit before the concern got clarified. BitGo subsequently quickly responded, re-adjusting the key structure, ensuring it still held two of the three keys, retaining substantive veto power, with BiT Global holding only one, unable to unilaterally deploy funds — this adjustment, to some extent, eased market concern, but also left a precedent worth remembering: a key structure adjustment, even if the intent could be strengthening decentralization, can still genuinely trigger confidence wavering and capital movement in the short term.

Layer Three: DAO Governance, Deciding Who Can Join This System

WBTC's overall governance is overseen by a multi-signature DAO mechanism, and this DAO's members include the custodian, merchants, and other institutions closely related to the DeFi ecosystem. The concrete power this DAO holds includes deciding which new institutions can join as a merchant or custodian, plus protocol-level rule changes. This means WBTC's trust structure isn't as simple as 'you trust the single company BitGo' — it also includes the layer of 'you trust this entire DAO's governance decision quality.'

Layer Four: Merchants and KYC, an Intermediary Layer Everyday Users Never Touch

An everyday retail user usually doesn't directly interact with the custodian or the DAO, instead directly swapping other tokens for WBTC already circulating externally through a decentralized exchange. What genuinely needs to walk through the full minting or redemption process is an authorized 'Merchant,' who needs to complete identity verification and anti-money-laundering compliance review before directly interacting with the custodian. This means for most users holding WBTC, what you're actually trusting is an entire chain of 'merchant — custodian — DAO,' not a single link.

What This Means for Your Money

Understanding WBTC's complete trust structure helps you more accurately assess how concentrated or dispersed the counterparty risk you actually bear is when holding this token. The 2024 key structure adjustment incident provides a concrete reference case — even the largest-scale, longest-standing wrapped token can still see its governance structure change, and this kind of change, even if the final outcome is neutral or even positive for users, can still cause genuine short-term market volatility during the adjustment process. Assessing any wrapped token can't just look at whether it claims '1:1 reserve backing' — it also needs specifically understanding, behind this 1:1 reserve, how the key structure is distributed, how the governance mechanism operates, and whether this structure has ever genuinely been stress-tested by the market before.

Diagram
WBTC 的四層信任結構多重簽署錢包、金鑰持有結構、DAO 治理、商家與 KYC 四層,底部標註 2024 年金鑰調整事件與贖回量飆升。WBTC's Four Layers of Trust1. Multisig Wallet2-of-3 keys required2. Key HoldersBitGo + BiT Global3. WBTC DAOApproves merchants4. Merchants + KYCUser-facing layerAugust 2024: key structure change triggered 60x redemption spikeReserves were never the problem — governance structure change wasDeFi Bible · defi-bible.com
Feel free to share. Please credit the source.
Ask a Question
Please enter at least 10 characters
Related Articles
The World's Largest Asset Manager Put an $18 Billion Fund on Uniswap — What Does That Actually Mean?
protocols · Jul 29
'100% Fully Reserved' Isn't the Finish Line: How to Check If a Stablecoin Can Withstand a Redemption Run
risk · Jul 29
Why Do Bridges Keep Getting Hacked? Check These Three Things to Judge Bridge Safety
developers · Jul 25
How Do Stablecoins Actually Stay Stable? Three Fundamentally Different Designs
fundamentals · Jul 23
More Related Topics