Paper 2024/1768

Programmable Bitcoin Verification via Synthesis-Aided Lifting

Hanzhi Liu, Nubit, University of California, Santa Barbara
Jingyu Ke, Nubit
Hongbo Wen, Nubit, University of California, Santa Barbara
Luke Pearson, Polychain Capital
Robin Linus, ZeroSync, Stanford University
Lukas George, ZeroSync
Manish Bista, Alpen Labs
Hakan Karakuş, Chainway Labs
Domo, Layer 1 Foundation
Junrui Liu, University of California, Santa Barbara
Yanju Chen, University of California, Santa Barbara
Yu Feng, Nubit, University of California, Santa Barbara
Abstract

A new wave of proposals, such as covenants (OP_CHECKTEMPLATEVERIFY), the reactivation of OP_CAT, and BitVM-style fraud proofs, promises to turn Bitcoin into a settlement layer for decentralised finance. These projects must be expressed in Bitcoin script, a stack language with no loops or recursion; practical applications therefore expand into megabytes of unrolled opcodes whose slightest error can freeze or steal funds. Existing verification tools collapse under the resulting explosion of constraints. We present bitguard, the first scalable verifier for programmable-Bitcoin artifacts. Inspired by recent advances in program lifting and synthesis, bitguard automatically (i) lifts raw script into a semantics-preserving, register-based DSL and (ii) detects repetitive slices that mimic batch operations (map, fold, filter, Merkle-proof checks). Each slice is replaced with a single higher-order combinator whose behavior is captured by an axiom, shrinking downstream SMT constraints by orders of magnitude. A counter-example-guided inductive synthesis loop ensures every transformed fragment remains equivalent to its original script. Evaluated on 104 real-world benchmarks, including full BitVM2 prover–verifier pairs, bitguard automatically verifies 88% of the cases in an average of 23.57s, outperforms direct SMT encodings by up to two orders of magnitude, and uncovers 5 previously unknown vulnerabilities. These results demonstrate that synthesis-aided lifting with axiomatized batch combinators delivers practical, rigorous assurance for the emerging ecosystem of programmable Bitcoin.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
BitVMBitcoin ScriptFormal VerificationProgram Synthesis
Contact author(s)
hanzhi @ ucsb edu
windocotber @ riema xyz
hongbowen @ ucsb edu
luke @ polychain capital
roblinus @ stanford edu
lukas @ zerosync org
manish @ alpenlabs io
hakan @ chainway xyz
domodata @ proton me
junrui @ ucsb edu
yanju @ ucsb edu
yufeng @ ucsb edu
History
2025-07-22: last of 4 revisions
2024-10-30: received
See all versions
Short URL
https://ia.cr/2024/1768
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/1768,
      author = {Hanzhi Liu and Jingyu Ke and Hongbo Wen and Luke Pearson and Robin Linus and Lukas George and Manish Bista and Hakan Karakuş and Domo and Junrui Liu and Yanju Chen and Yu Feng},
      title = {Programmable Bitcoin Verification via Synthesis-Aided Lifting},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1768},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1768}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.