Sui’s Hashi Explained: Native Bitcoin Collateral, and Why It Is Not Just Another Wrapped BTC

Sui's Hashi keeps your Bitcoin on Bitcoin and mints a receipt on Sui — but it is not trustless, it is trust redistributed. The launch is not the test; how much native BTC actually enters lending markets by year-end is.

There are two ways to put Bitcoin to work in DeFi. The old way hands your keys to a custodian and gives you a receipt. The new way — announced today at Sui Basecamp in Singapore — keeps your BTC on the Bitcoin network and mints a receipt on Sui. Same goal. Opposite custody model.

On October 8, 2026, Mysten Labs launched Hashi to mainnet. Co-founder and CPO Adeniyi Abiodun announced it with more than $500 million in capital commitments from 20+ partners, and Anchorage Digital — the first US federally chartered crypto bank — signed on as a day-one institutional partner through its Atlas settlement infrastructure and Porto self-custody wallet.

The pitch is simple and seductive: put your idle Bitcoin to work without selling it. Whether the pitch survives contact with reality is a different question. Let me hold the two models side by side.

Sui's Hashi Explained: Native Bitcoin Collateral, and Why It Is Not Just Another Wrapped BTC
A bank vault door — the old model asks you to hand over the keys; Hashi asks you to keep them. Aldo Moisio, Public domain, via Wikimedia Commons.

The Old Way — WBTC and the Custody IOU

Wrapped Bitcoin is not complicated. You send BTC to a custodian — historically BitGo for WBTC — and that custodian holds it while a wrapped token is issued on some other chain. That token is an IOU. It tracks the price of Bitcoin because someone, somewhere, promises to redeem it.

Where does the risk sit? With the custodian. One institution, or one consortium, holds the actual coins. If that custodian is compromised, insolvent, or frozen, your wrapped token is worth whatever the market decides an unbacked IOU is worth. You did not remove trust from the equation. You moved all of it onto a single counter-party.

To be fair, this model won because it was simple. A custodial wrapper is easy to audit, easy to redeem, and easy for exchanges to list. It is also the exact counterparty risk Bitcoin was built to eliminate.

The New Way — How Hashi Keeps Bitcoin on Bitcoin

Hashi inverts the custody question. Instead of moving BTC off the Bitcoin network, it builds a bridge that watches Bitcoin and issues a receipt on Sui. Every Sui address gets a unique P2TR (Pay-to-Taproot) deposit address on Bitcoin. Inside that Taproot tree sit two leaves:

Leaf one · 2-of-2 multisig

A multisig between the Hashi MPC key and a Guardian key. Normal spends need both signatures — validator collusion alone is not enough.

Leaf two · the 60-day recovery

A recovery script that lets the Hashi key alone spend — but only after a 60-day timelock (OP_CHECKSEQUENCEVERIFY). The escape hatch if the Guardian key is ever lost.

The internal key is a NUMS point — a number with no known private key. That is the clever part. It means every single spend is forced through the script path. There is no hidden shortcut, no single private key that can quietly move the coins.

The deposit flow runs like this:

  • 1) Deposit. You send native BTC to your Hashi deposit address.
  • 2) Confirm. Validators watch the Bitcoin network and confirm the deposit after enough block confirmations.
  • 3) Mint. hBTC is minted on Sui, and you use it as collateral — borrow stablecoins, lend, whatever the Sui DeFi market will take.
  • 4) Withdraw. Repay the loan, burn the hBTC, and MPC threshold signatures release the native BTC to any Bitcoin address you choose.

Now the signing. Withdrawals are signed by threshold Schnorr signatures among participating Sui validators. No single committee member ever holds the full key. The system is designed to stay secure as long as colluding stake stays below roughly one-third to one-half of committee voting power. More than 90% of Sui validators are expected to opt in. On top sits a Guardian Layer — a second, independent signer for normal withdrawals. And the pause switch is deliberately asymmetric: an emergency pause needs only 5% of committee voting weight to trigger, but resuming needs a two-thirds supermajority.

Read that asymmetry carefully. The design assumes failure is more likely than malice, so it makes freezing easy and unfreezing hard.

Same Goal, Opposite Custody

QuestionWBTC (old way)Hashi (new way)
Where does the BTC sit?With a custodian (BitGo)On the Bitcoin network, at your deposit address
What token do you get?Wrapped BTC (custodial IOU)hBTC (a receipt minted on deposit)
Who signs redemptions?The custodianThreshold Schnorr among validators + Guardian
Who do you trust?One custodian/consortiumAn MPC committee + Guardian + validator governance + software
What if the signer fails?Your IOU depends on one partyRecovery script after a 60-day timelock
Tax treatment (US)Generally a taxable eventFenwick opinion: deposits/redemptions may not be taxable

The bold judgment I want to leave here: It is not that Hashi removed trust. It is that it spread one custodian’s key across a committee and a guardian.

That is not a small thing. A single point of failure and a distributed threshold are different failure modes. But it is a distinction in how you trust, not whether you trust. Anyone who tells you Hashi is “trustless Bitcoin” is selling you something.

What hBTC Is, and What It Is Not

It is still a representation token. hBTC is the only coin Hashi creates, minted on deposit. You are not holding Bitcoin on Sui — you are holding a receipt. The difference from WBTC is custody architecture, not the existence of a receipt.
It creates no native Bitcoin yield. Any return comes from borrower interest and credit spreads in Sui lending markets — and brings liquidation risk and smart-contract risk. You exchanged custody risk for DeFi risk.
The $500M is commitments, not collateral. Commitments are promises to participate. Promises are not deposits. Until 20+ partners put real BTC in, it is a headline.
Testnet activity is not mainnet demand. 1.1M testnet deposits and 165k withdrawals prove the software works — not that institutions will trust it with billions.

Real adoption is measurable only after mainnet deployment. The clock started today.

Why Institutions Care About Idle Bitcoin

Here is the number that drives the whole thing: Bitcoin’s market cap exceeds $1 trillion, and roughly 0.22% of it is deployed in DeFi. Twenty-two basis points. Put that little of any other trillion-dollar asset class to work and you would be fired.

That is the gap Hashi is aimed at. Not retail users chasing yield, but institutions sitting on cold BTC that earns nothing. Anchorage’s involvement matters precisely because it brings the rails — Atlas for settlement, Porto for self-custody — that let a federally chartered bank custody native Bitcoin and interact with Hashi without selling it. The Fenwick law-firm opinion is the quiet signal worth watching: if deposits and redemptions may not be taxable events in the US, wrapping BTC stops being a taxable disposition — and that alone could move institutional capital frozen by tax friction for years.

The partner roster reads like a who’s-who of crypto plumbing: BitGo, Ledger, Blockdaemon, Cobo, and Fordefi on custody; Cumberland, FalconX, and Bullish on liquidity; AlphaLend, Navi, Scallop, Suilend, Fluid, Aftermath, and Concrete on lending; Soter Insure on Bitcoin-denominated insurance; CF Benchmarks on pricing. Audits and formal verification from Asymptotic, Certora, and OtterSec. A serious stack — but a serious stack is still just a launch.

The Real Test Is Not Today

Hashi is a clean idea, well-engineered, launched with a credible partner list. The mechanism is real: a Taproot tree with no hidden key, a threshold signature scheme with a guardian, an asymmetric pause switch that betrays a sober design philosophy.

But let me not pretend the outcome is settled. The launch is not the test. The test is how much native BTC actually enters live lending markets by year-end. Commitments are not collateral. Testnet volume is not mainnet demand. And hBTC is not Bitcoin — it is a better-architected receipt, and the difference matters.

It is not a trustless Bitcoin bridge. It is a reallocation of trust from one custodian to a committee plus a guardian plus code. Whether that is safer, cheaper, or more durable is an empirical question — and it starts being answered today, not at a keynote in Singapore.

(The End)

Blockchain

Chainlink Fulcrum Explained: Unbolting the Repo Market's Venue From Its Rails

2026-10-8 0:31:32

Analysis

Zcash at $1,600: What NU7 Really Buys, and What the Rally Doesn't Prove

2026-10-6 19:59:25

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search