Compartir este artículo

Team Behind Bitcoin-Backed Ethereum Token tBTC Explains Shutdown

A bug in tBTC meant the dapp couldn't tell different bitcoin addresses apart, the team has disclosed.

Actualizado 14 sept 2021, 8:43 a. .m.. Publicado 20 may 2020, 8:51 a. .m.. Traducido por IA
Credit: Shutterstock
Credit: Shutterstock

Keep Network says a flawed code addition forced the shutdown of its bitcoin-backed Ethereum token, tBTC, just two days after it launched.

STORY CONTINUES BELOW
No te pierdas otra historia.Suscríbete al boletín de Crypto Daybook Americas hoy. Ver todos los boletines

On May 18, deposits of bitcoin into tBTC were paused for 10 days – a move prompted by a bug that was supposedly missed by a security audit and was later found by two of the network's contributors.

That bug, Keep Network revealed in a Medium blog post Wednesday, related to a flaw in the processing of deposit redemptions (when users try and pull bitcoin back out of the system), essentially due to the code's inability to tell different types of bitcoin addresses apart.

"The team triggered this pause after finding a significant issue in the redemption flow of deposit contracts that put signer bonds for open deposits at risk of liquidation when certain types of bitcoin addresses were used in redemption," Keep Network, which is behind the Thesis project that launched the token, said in the post.

The team noted that redemptions had originally been restricted to p2wpkh address outputs, but were later widened to include "any other output scripts." The issue arose if a user tried to redeem pay-to-scripthash (p2sh) addresses. This changed code had not been specifically tested, bar more generally on testnets at a later stage, the post concedes.

"[D]ue to a bug in the redemption dApp in use at the time, the proof step of the redemption flow never occurred," Keep Network wrote. "These p2sh addresses would have failed validation had the proof step occurred, but reliance on the dApp’s display of a completed state meant the team assumed the redemption had completed successfully, when it in fact had not."

Also read: Blockfolio Quietly Patches Years-Old Security Hole That Exposed Source Code

A second bug was also found meaning that, even if the proof code had been free of issues, a "malicious redeemer" could have specified an output script that resulted in an invalid bitcoin transaction.

Community manager at Blockstream, Daniel Williams, who has an interest in bitcoin and goes by the handle, @Grubles, critically summed up the primary bug in a May 20 tweet, saying:

grubles-on-tbtc

While the bug and subsequent pause have been a setback for the Thesis team, a new call out has been made to solicit help from code auditors to help track down any further issues.

"We're also in the market for BTC-focused auditors for round 3," the team said a Tweet on Wednesday.

See also: Makers of Keep Protocol Raise $7.7M to Bring Trustless BTC to DeFi

In addition to technical and process changes, the Thesis team will be announcing how it plans on approaching a "redeploy of the tBTC system" and how that will impact existing plans around the KEEP token distribution.

"We’re looking forward to showing the world a stronger, more secure Bitcoin on Ethereum," the team said

Más para ti

Protocol Research: GoPlus Security

GP Basic Image

Lo que debes saber:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

Más para ti

Bitcoin Rebounds to $93K From Post-Fed Lows, but Altcoins Remain Under Pressure

Bitcoin (BTC) price (CoinDesk)

Downward pressure on bitcoin is losing steam, with the market stabilizing but not yet out of the woods, said one analyst.

Lo que debes saber:

  • Bitcoin rebounded from a sharp early selloff on Thursday to trade above $93,000 shortly after the close of U.S. stocks.
  • The late-day gain in bitcoin came alongside a rebound in the Nasdaq from big morning losses; the tech index closed with just a 0.25% loss.
  • Downward pressure on bitcoin is losing steam, said one analyst, but the market is not yet out of the woods.