Security

Built for Confidence.
Proven On-Chain.

Four independent layers of security. No single points of failure. Every satoshi secured and independently verifiable.

$3B+
Bitcoin Secured
500k+
Transactions
14
Consortium Members
10+
Independent Audits
Architecture

Four Layers. No Single Points of Failure.

Multiple parties must agree before any Bitcoin moves. Each transaction is independently verified, and every satoshi secured.

01
Security Consortium

14 Institutions. No Unilateral Control.

An alliance of the industry's leading digital asset institutions, including Galaxy Digital, Wintermute, and Kraken. Members authorize every transaction, ensuring that no single entity can move funds alone. 10-of-14 consensus is always enforced.

02
Key Isolation

Private Keys That Never Leave Hardware.

All signing operations are conducted inside FIPS-140 certified HSMs and Trusted Execution Environments. Even fully compromised servers cannot access the underlying keys.

03
Secondary Verification

Independent Verification Of Every Transaction.

All operational actions are verified by a second independent system. Bascule Drawbridge, by Cubist, verifies every deposit and redemption. Chainlink verifies every bridge transaction. Layered defense blocks unbacked issuance.

04
Governed Smart Contracts

Enforced Rules. Active Defense.

Onchain timelocks for protocol upgrades provide additional review time. Real-time anomaly detection within the mempool can detect potential malicious actions before they happen, and pause the protocol.

Security Consortium

14 Industry Leading Institutions.

Fourteen independent digital asset institutions collectively validate every mint, redemption, and cross-chain transfer. No single member can act alone, even nine compromised members cannot authorize a transaction.

10-of-14
Consensus Required
Zero
Security Incidents
Always
Independently Verified
Galaxy
DCG
Kiln
Figment
P2P
Chorus One
Nansen
Wintermute
Amber
Cubist
Antpool
F2Pool
OKX
Kraken

Examine the Architecture.
Under the Hood.

Select view
Simulate a transaction
BITCOIN NETWORKSECURITY CONSORTIUMBLOCKCHAIN NETWORKSCRYPTOGRAPHICVAULTSECURITYLEDGEREthereum, BaseSolanaSui+6 more networksBascule DrawbridgeSECONDARY VERIFICATIONChainlink OraclesSECONDARY VERIFICATION
Scroll to explore →

Showing the Mint transaction flow.

How It Works

Deposit. Consensus. Mint.

01

Deposit

Your BTC deposit is monitored independently and relayed to all involved parties. After six confirmations, cryptographic attestations are produced.

02

Consensus

A supermajority of Security Consortium members must sign to authorize any action. Keys are protected inside hardware enclaves. No member can ever access the raw private keys.

03

Mint

Minting requires valid signatures from both the Security Consortium and Bascule Drawbridge independently. Proof of Reserve oracles attest full Bitcoin backing on-chain.

Security Principles

Security You Can Verify and Trust.

No single entity can act alone

Every operation requires 10-of-14 independent institutions to reach consensus before a single satoshi moves. Lombard is one actor, not the operator. Nine compromised members still cannot authorize any transaction.

Enforced verification

Deposit validation, consensus checks, and Bascule Drawbridge attestation all execute before tokenized assets are issued. There is no window where minted tokens exist without fully backed Bitcoin. The system prevents discrepancies by design rather than detecting them after the fact.

Every layer provides independent security

CubeSigner, Bascule, the Security Consortium, and onchain Proof of Reserves each operate as if they are the last line of defense. Defense-in-depth in practice: independent systems, each alone sufficient to secure the protocol.

Enhanced governance and leading security practices

10+ audits from the top blockchain and cryptography experts. Real-time monitoring and threat detection. Protocol governance with two-step upgrades and timelocks. A $250,000 bug bounty keeps accountability continuous.

Transparency

Verified by Experts.
Transparent to Everyone.

Audit Reports

Verified by 10+ Independent Firms

OpenZeppelin, Veridise, Sherlock, Halborn, Spearbit, Cantina and more. Over ten independent firms have audited Lombard's smart contracts and architecture. Every report is publicly accessible.

OpenZeppelinVeridiseSherlockHalbornSpearbitCantina
All Audit Reports →
Bug Bounty
Active

$250,000 Bug Bounty

Found a potential security vulnerability? Report exclusively through Immunefi as the official disclosure channel.

Immunefi
Report a Bug →
Proof of Reserves
Live

Real-Time Onchain Verification

Real-time, onchain verification that every Lombard tokenized asset (LBTC and BTC.b) is fully backed by Bitcoin. Updated continuously. Independently verifiable.

ChainlinkRedstone
Live Dashboard →
For Institutions

Put clients' BTC to work with Bitcoin Smart Accounts.

Offer BTC yield, lending, and collateral management as a new product line. Your clients' Bitcoin stays in existing custody with no additional risk.

For Developers

Build on Bitcoin's most trusted infrastructure.

Integrate LBTC, BTC.b, and Bitcoin Smart Accounts into any DeFi application with a single SDK. BTC yield, staking, lending, and cross-chain liquidity across 10+ networks.