Lombard Security Model
Lombard secures bitcoin through a 14-member Security Consortium (OKX, Galaxy, Kraken, Wintermute, and 10 others) where every transaction requires a two-thirds majority to authorize. No single institution controls anything. This is backed by hardware-level key protection via CubeSigner, independent verification via Bascule Drawbridge, and 10 third-party audits. Zero incidents. Zero downtime since launch.

Security Consortium
The Security Consortium distributes trust across multiple independent digital asset institutions. These members possess public reputations, legal accountability, professional security teams, and geographic/organizational diversity.
Members include OKX, Galaxy, DCG, Wintermute, Amber Group, Figment, P2P, Kiln, Kraken, Antpool, and F2Pool. See the full Consortium roster and member roles.
Key operational requirements:
- Two-thirds majority (10 of 14 members) must sign off on critical operations
- A single or even four compromised members cannot authorize actions independently
- Membership requires infrastructure deployment, KYB review, network voting, and smart contract updates
CubeSigner: Hardware-Level Protection
CubeSigner, built by Cubist, manages cryptographic operations through Hardware Security Modules. Private keys are generated inside HSMs and never leave secure hardware, ensuring keys remain inaccessible to Consortium members, Lombard, or Cubist.
Implementation mechanisms:
- Fine-grained signing sessions with expiration and revocation capabilities
- Transaction restrictions limiting key usage to specific transaction types
- Multi-party authorization requirements for high-risk operations
- Timelocks preventing immediate credential utilization
- Hardware-enforced signing policies that prevent unauthorized transaction types
Bascule Drawbridge: Independent Verification
Operating as an independent verification layer, Bascule provides cross-checks preventing a compromised Consortium from minting unbacked LBTC. The system monitors Bitcoin independently, awaits six confirmations, and requires dual authorization from both the Consortium and Bascule.
For deposits: Before any mint, Bascule independently verifies that the BTC deposit exists on the Bitcoin network with 6 confirmations. Minting requires valid signatures from both the Consortium and Bascule.
For withdrawals (Reverse Bascule): Bascule monitors redemption events on supported chains. Before CubeSigner authorizes a BTC payout, the Reverse Bascule verifies that the corresponding LBTC was actually burned.
Smart Contract Security
Lombard contracts undergo rigorous third-party audits from six firms, OpenZeppelin, Halborn, Veridise, Sherlock, ABDK, and Cantina. The protocol maintains an Immunefi bug bounty program offering rewards up to $250,000 and employs Hexagate for real-time behavioral monitoring.
Safety mechanisms include:
- Pausable critical functions
- Two-step upgrades with timelocks
- Rate limiting on unusual patterns
Operational Security
Infrastructure protection includes:
- Documented incident response procedures
- Formal key ceremonies with multiple witnesses
- Regular penetration testing
- Continuous ecosystem threat monitoring
Transparency Measures
Chainlink Proof of Reserve feeds verify Bitcoin backing every 10 minutes. On-chain audit trails, publicly available audit reports, and comprehensive documentation support user verification of security measures.
How LBTC Compares to Other Wrapped Bitcoin
LBTC, WBTC, and cbBTC all represent Bitcoin onchain, but they differ in how that Bitcoin is secured and whether it earns yield.
| Property | LBTC | WBTC | cbBTC |
|---|---|---|---|
| Type | Wrapped bitcoin | Wrapped bitcoin | Wrapped bitcoin |
| Native yield | Yes | No | No |
| Custody / trust model | Hybrid: 14-member consortium with HSM keys for the liquidity buffer, segregated qualified custody under a tri-party agreement for the active allocation | Custodial (BitGo 2-of-3 multisig) | Custodial (Coinbase) |
| Backing | Fully backed by BTC | 1:1 BTC | 1:1 BTC |
| Reserve verification | Chainlink Proof of Reserve + Bascule Drawbridge | Chainlink Proof of Reserve | Chainlink Proof of Reserve |
| Redeemable for native BTC | Yes | Yes | Yes |
| Multi-chain | Yes | Yes | Yes |
The main differences are yield and the custody model. WBTC and cbBTC pay no yield and rely on a single custodian. LBTC pays yield and splits its backing: the liquidity buffer is signed for by a 14-member consortium, and the active allocation sits in segregated, Lombard-owned accounts at qualified custodians under a tri-party agreement.
Known Risks
The protocol acknowledges inherent limitations:
- Strategy risk: The covered-call strategy behind LBTC’s yield can see temporary mark-to-market drawdowns during sharp Bitcoin rallies, and yield falls below target in low-volatility periods
- Custody and counterparty risk: The active allocation relies on qualified custodians and OTC options counterparties, bounded by the tri-party agreement and financial settlement. See Risks
- Smart contract vulnerabilities: Despite audits, no code is guaranteed bug-free
- Bridge infrastructure dependencies: Cross-chain transfers rely on external validators
- Permissioned Consortium coordination: Requires trust in institutional members
- Regulatory uncertainties: Evolving legal landscape for crypto assets
Frequently Asked Questions
Next Steps
- Consortium Members, Full list of the 14 Security Consortium members
- Audits, Complete audit history and security review details
- Bug Bounty, Immunefi program details and reward tiers
- Transparency, Proof of Reserve, oracles, and on-chain verification