LibraryConsensus2017Design paperCorpus record
Bitcoin as a Transaction Ledger: A Composable Treatment
Bitcoin as a ledger. Christian Badertscher, Ueli Maurer, Daniel Tschudi and Vassilis Zikas.
The paper gives a composable ledger functionality and shows that a bitcoin-like protocol realises it under stated assumptions.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.
The five-minute read
The defect
The backbone papers analyse a chain of blocks. A wallet author needs a ledger of transactions and a way to compose it with other protocols.
The proposal
The paper gives a composable ledger functionality and shows that a bitcoin-like protocol realises it under stated assumptions.
Composition matters when the ledger is a subroutine of a payment or a co
The functionality is the specification of what an ideal ledger does.
The bound
Composable security is not a phrase a marketing page can invoke without the functionality.
One action, walked through
- Write down the ledger functionality: what an adversary can still reorder or delay.
- Show the protocol realises it.
- Do not export the theorem to a protocol with different timing or a different adversary.
- Which network model is assumed?
The argument, unpacked
What the paper is for
If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.
What happened after
Later composable treatments of stake chains cite this style of theorem.
What has to be true
- Composable security is not a phrase a marketing page can invoke without the functionality.
- The model is not a stake chain.
- It does not set confirmation policy for a merchant.
What happened after the paper
Later composable treatments of stake chains cite this style of theorem.
What to check before you use the idea
- What is the ideal ledger allowed to do?
- Which network model is assumed?
- Does the proof compose with the application, or only stand alone?
Terms
- Functionality
- An ideal description of the service the protocol claims to provide.
- Composition
- The protocol stays secure when other protocols call it.
The problem the paper names
The backbone papers analyse a chain of blocks. A wallet author needs a ledger of transactions and a way to compose it with other protocols.
What the design proposes
- Composition matters when the ledger is a subroutine of a payment or a contract.
- The functionality is the specification of what an ideal ledger does.
- Realisation is a proof in their model, not a production audit.
How the mechanism is specified
- Write down the ledger functionality: what an adversary can still reorder or delay.
- Show the protocol realises it.
- Do not export the theorem to a protocol with different timing or a different adversary.
What this page does not treat as proven
- Composable security is not a phrase a marketing page can invoke without the functionality.
- The model is not a stake chain.
- It does not set confirmation policy for a merchant.
Why a venture studio still reads it
If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
