Skip to content

LibraryConsensus2017Design paperCorpus record

Bitcoin as a Transaction Ledger: A Composable Treatment

Bitcoin as a ledger. Christian Badertscher, Ueli Maurer, Daniel Tschudi and Vassilis Zikas.

The paper gives a composable ledger functionality and shows that a bitcoin-like protocol realises it under stated assumptions.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.

The five-minute read

The defect

The backbone papers analyse a chain of blocks. A wallet author needs a ledger of transactions and a way to compose it with other protocols.

The proposal

The paper gives a composable ledger functionality and shows that a bitcoin-like protocol realises it under stated assumptions.

Composition matters when the ledger is a subroutine of a payment or a co

The functionality is the specification of what an ideal ledger does.

The bound

Composable security is not a phrase a marketing page can invoke without the functionality.

One action, walked through

  1. Write down the ledger functionality: what an adversary can still reorder or delay.
  2. Show the protocol realises it.
  3. Do not export the theorem to a protocol with different timing or a different adversary.
  4. Which network model is assumed?

The argument, unpacked

What the paper is for

If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.

What happened after

Later composable treatments of stake chains cite this style of theorem.

What has to be true

  • Composable security is not a phrase a marketing page can invoke without the functionality.
  • The model is not a stake chain.
  • It does not set confirmation policy for a merchant.

What happened after the paper

Later composable treatments of stake chains cite this style of theorem.

What to check before you use the idea

  • What is the ideal ledger allowed to do?
  • Which network model is assumed?
  • Does the proof compose with the application, or only stand alone?

Terms

Functionality
An ideal description of the service the protocol claims to provide.
Composition
The protocol stays secure when other protocols call it.

The problem the paper names

The backbone papers analyse a chain of blocks. A wallet author needs a ledger of transactions and a way to compose it with other protocols.

What the design proposes

  • Composition matters when the ledger is a subroutine of a payment or a contract.
  • The functionality is the specification of what an ideal ledger does.
  • Realisation is a proof in their model, not a production audit.

How the mechanism is specified

  • Write down the ledger functionality: what an adversary can still reorder or delay.
  • Show the protocol realises it.
  • Do not export the theorem to a protocol with different timing or a different adversary.

What this page does not treat as proven

  • Composable security is not a phrase a marketing page can invoke without the functionality.
  • The model is not a stake chain.
  • It does not set confirmation policy for a merchant.

Why a venture studio still reads it

If a paper says 'secure under composition', ask which functionality and which model. This is one of the few that answers for a bitcoin-like ledger.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.