TL;DR
LBTC is a claim on Bitcoin staked through Babylon, and the usual description of what you are trusting is a 14-member consortium signing at a two-thirds threshold. That description is accurate for mints, redemptions and cross-chain transfers. It is not accurate for contract upgrades, and this refresh established that on-chain rather than repeating it. The LBTC proxy's admin, and the token's own owner(), both resolve to a timelock whose proposer and executor rights are held by a 3-of-5 Gnosis Safe made up of five unlabeled externally owned accounts, alongside the original deployer address which still holds proposer rights. The consortium governance contract holds no role on that timelock at all. The delay is 24 hours today; the constructor set it to one hour. Three other things got measured rather than repeated: the peg held to within 0.49% at its worst across a year, the audit program ran through July 2026, and nothing broke. Caution, with the admin dimension now red.
Checklist
Audits & contracts. The audit directory in the protocol's own contracts repo holds 19 reports across Halborn, OpenZeppelin, Veridise, Sherlock and ABDK. Six are dated 2026: multi-pauser reviews by OpenZeppelin and Sherlock in April, mint-limit reviews by Sherlock in June and OpenZeppelin in July, and strategies reviews by OpenZeppelin and Veridise in June. That is a live program, not a launch-era snapshot, and the April and June work lands on mint authorization and bridge pausing, which is the surface that matters here. Three caveats. The contracts are upgradeable proxies, not immutable. The public audits page on the docs site stops at October 2025, so a user who checks only the website will understate the coverage by about ten months. And this report previously said the directory held 20 reports; the twentieth entry is a README, which is the kind of error that comes from counting a listing instead of reading it. Immunefi pays up to $250,000 for critical. Filenames, firms and dates were read from the repo; the PDFs were not.
Admin control. This dimension sets the verdict, and it is the one that changed. Follow the control path on-chain rather than through the marketing. The LBTC proxy's EIP-1967 admin slot points to a ProxyAdmin contract. That ProxyAdmin's owner() is the published Proxy Upgrade Timelock. The LBTC token's own owner() is that same timelock. So far this matches what the docs imply. The next step is the one nobody had taken: who can move the timelock. Its constructor named two proposers and one executor, and both named addresses still hold their roles today. One is a plain externally owned account, the address that deployed the contracts in May 2024, and it still holds proposer rights more than two years later. The other is a Gnosis Safe version 1.3.0 with five owners and a threshold of three, holding proposer, executor and canceller rights. All five Safe owners are externally owned accounts with no on-chain labels. The consortium governance contract was tested directly against the proposer and executor roles and holds neither. So the power to replace the implementation behind roughly 11,500 BTC of backing is three signatures out of five unidentified keys, not two thirds of fourteen named institutions. The delay before that lands is 24 hours, confirmed against two independent RPC nodes, and the constructor value was 3,600 seconds, which is where the "roughly one hour" figure in the July edition of this report came from. It was true once. It is not true now, and last month's report also contradicted itself, saying one hour in one paragraph and 24 hours in the next. What the consortium genuinely does control is real and worth keeping in view: the docs state that every mint, redemption and cross-chain transfer is validated by the 14-member Security Consortium at a two-thirds threshold, with keys generated in Cubist CubeSigner HSMs that "never leave secure hardware", and that "no single party can move your funds". Nine of the fourteen are named across Lombard's own posts. But the docs list the timelock address on their transparency page without saying a word about who controls it, and a five-key Safe is a materially narrower trust base than the consortium framing suggests. Red. One honesty note: the timelock does not implement enumerable access control and archive log queries are paywalled on free nodes, so this run confirmed that these two addresses hold these roles, not that no other address does.
Oracle. There is no lending-style price oracle in the mint or redeem path, so oracle manipulation is not the failure mode here. What Lombard runs instead is verification of the backing: Chainlink Proof of Reserve on Ethereum, plus a RedStone real-time reserve feed added in March 2026, both publishing the ratio of BTC held against LBTC circulating. Bascule independently confirms a Bitcoin deposit at 6 confirmations before a mint is authorized, and the docs state a mint "requires valid signatures from both" the consortium and Bascule. That is the right shape for this design. Green.
Liquidity & exit. Two doors, two speeds. Native redemption returns real Bitcoin and takes up to 10 days, which the docs attribute to Babylon's 7-day unbonding period plus Lombard's daily rebalancing cycle. Minimum redemption is 0.00013300 LBTC, including a 0.0001 LBTC network security fee. The fast door is selling LBTC on the secondary market, and this refresh measured how well that door has worked: across 360 daily observations from 2025-08-12 to 2026-08-06, pairing LBTC and BTC at matching timestamps, the ratio ranged from 0.99515 to 1.00986, with zero days below 0.995. The worst discount in a year was 0.49%, on 2025-08-20. Spot today is 1.0035. Note that the dates and extremes published in the draft of this refresh did not survive checking: 2025-11-13 measures 0.99981, not 0.99552, and 2026-07-31 measures 1.00071, not 1.0081. The conclusion holds, the specific numbers did not, and the corrected ones are above. A tight history is not a guarantee, and 10 days is a long time to hold a position you wanted out of.
Yield: real vs emission. The base is genuine Babylon staking yield, which is real and thin. The rest of what drew capital was points and then BARD emissions. BARD now trades at $0.1095, so emission-funded APR buys considerably less than it did at launch, which cuts both ways: less mercenary capital, and less headline yield. Treat any advertised APR as a mix and check the split before sizing. The current split is unverified this run.
Holder concentration. Both holder-distribution sources refused this run, Etherscan and Nansen each returning a paid-tier error, so per-wallet concentration is unverified. What is measurable: Ethereum's LBTC supply reads 8,443.38 tokens on-chain, against roughly 11,500 BTC of backing implied by the verified TVL and the spot BTC price, so about 73% of all LBTC lives on one chain. That is chain concentration, not whale concentration, and it is the ordinary consequence of Ethereum being where the integrations are. Unknown is not the same as fine, so this stays yellow.
Track record. No LBTC exploit and no depeg since launch in mid-2024. A scan of X posts and web sources covering 2026-07-01 through 2026-08-12 turned up no incident, no paused redemptions, no consortium change and no challenge to the reserves. LBTC is not paused on-chain, and neither is Bascule. The February 2025 Ionic loss of roughly $8.6M was an impersonation attack: attackers posing as the Lombard team got a counterfeit LBTC contract listed on a third-party lending market and borrowed against it. It was not a Lombard failure, and the distinction matters because the token name is the only thing the two events share. The May 2026 move of over $1B of bridging from LayerZero to Chainlink CCIP followed the April 2026 Kelp exploit and was industry-driven de-risking. One thing worth watching: measured in Bitcoin rather than dollars, the protocol backed about 13,326 BTC 90 days ago and about 11,500 today, down 13.7%, and down 42.5% from roughly 20,000 BTC at the May 2025 dollar peak. The dollar drop looks far worse, down 66.5% from the peak, because Bitcoin itself fell hard over the same window. This is steady bleed, not a run, but the direction is out.
Worst case
Three of the five keys on the upgrade Safe are compromised or coerced, and a malicious implementation is proposed and executed 24 hours later. That is now the cheapest path to harming LBTC holders, and it is considerably cheaper than the ten-of-fourteen consortium compromise this report previously described as the worst case. Twenty-four hours is enough warning to matter only if somebody is watching the timelock queue, and nothing in the product surfaces that to a holder. Separately, the custody path still has to fail for the Bitcoin itself to move: ten of the fourteen consortium members, plus Bascule as a second lock, and after April 2026 the cross-chain path requires Chainlink CCIP and the consortium to approve independently, so the single-verifier failure that cost Kelp roughly $292M is not the shape of this system. A softer bad day is more likely than either: Babylon slashing, or a stress window where you want out and the choice is a 10-day native redemption or selling at whatever the market offers. There is no insurance fund covering a custody or upgrade failure. Position sizing is the mitigation.
Bottom line
Caution, and for a different reason than last month. The peg measured tight, the audit cadence continued through July 2026 on exactly the mint and bridge controls that matter, and nothing broke. But the admin story this report has been telling was incomplete in the direction that flatters the protocol. Your mints and redemptions are validated by fourteen named institutions. The code those mints run through can be replaced by three signatures out of five anonymous keys after a 24-hour wait, and Lombard publishes the timelock address without publishing who holds it. That is a normal industry arrangement, and it is also the thing most likely to hurt you here. This remains one of the more carefully built BTC liquid staking designs. It is not a place to park a position you cannot afford to have locked or lost.
Data appendix
- TVL: $737.06M (DeFiLlama, "lombard", 2026-08-12, verified by orchestrator; the live
/tvl/lombardendpoint read $738.05M during this run). 90d ago: $1,056.31M on 2026-05-14, so down 30.2% in dollars. ATH $2,199.49M on 2025-05-23, so down 66.5% in dollars. In Bitcoin terms, using DeFiLlama BTC prices for each date ($64,083.61 today, $79,264.06 on 2026-05-14, $109,957 on 2025-05-23): about 11,500 BTC today, 13,326 BTC 90 days ago (down 13.7%), 20,003 BTC at the May 2025 dollar peak (down 42.5%). Most of the dollar decline is the BTC price; the rest is real outflow. - On-chain control path (measured this run, the correction that matters): LBTC token 0x8236a87084f8B84306f72007F36F2618A5634494 (name() returns "Lombard Staked Bitcoin"). Its EIP-1967 admin slot points to ProxyAdmin 0xbAE061c73876952aA2C5E483b74dFA785425F879; that contract's owner() is the Proxy Upgrade Timelock 0x055E84e7FE8955E2781010B866f10Ef6E1E77e59; LBTC's own owner() is that same timelock. The timelock's getMinDelay() returns 0x15180 = 86,400 seconds = 24 hours, confirmed on two independent public RPC nodes. Its constructor arguments, decoded from the creation bytecode, set minDelay to 3,600 seconds (1 hour) and named two proposers and one executor. Checked live via hasRole: 0x3f6bf1c36ccbb59eaf8415301a0cec73c344a079 (an EOA, the deployer of LBTC, the ProxyAdmin and the timelock) holds PROPOSER; 0x251a604e8e8f6906d60f8dedc5aaeb8cd38f4892 holds PROPOSER, EXECUTOR and CANCELLER. That second address is a Gnosis Safe version 1.3.0 with getThreshold() = 3 and five owners, all externally owned accounts with no on-chain labels: 0xd7b78bf124eb327f23f75f5c49de0c3fa5d2265a, 0x116744098070508c080b120a555b5453422b66ef, 0x70b9b04b19d9015efbe1db37bbe30dd304737950, 0xd775959eb15f6dff24a267f988f6c2e2f769deda, 0xdd48b7cfd0c2256e008b7c690fbe47ca77cd6071. The Consortium Governance contract 0xdAD58DfA5c1a7a34419AFdBE1f0d610efeea95E4 was tested against PROPOSER and EXECUTOR and holds neither. Caveat: the timelock does not expose enumerable access control and archive log queries were refused by every free RPC tried, so this confirms these addresses hold these roles, not that the role sets contain nothing else. This corrects the "roughly one-hour timelock" and the "consortium authorizes every contract upgrade" claims in the 2026-07-04 edition of this report.
- Pause state: LBTC paused() is false. Bascule Drawbridge 0xc750eCAC7250E0D18ecE2C7a5F130E3A765dc260 paused() is false. Both read on-chain 2026-08-12.
- Custody / consortium: 14-member Security Consortium, two-thirds threshold. Docs state "Every Lombard transaction (every mint, redemption, and cross-chain transfer) is validated by a 14-member Security Consortium", "Every action requires signatures from two-thirds of Consortium members", "Keys are generated and stored in Hardware Security Modules (HSMs), they never leave secure hardware", and "no single party can move your funds". The consortium page names no members. Lombard's own blog posts name nine: OKX, Galaxy, DCG, Wintermute, Figment, Kiln, Antpool, F2pool and Kraken. Some secondary coverage says 15 members rather than 14. Full roster and exact count: refresh. Note the scope: the docs describe consortium authority over mints, redemptions, staking, unstaking and cross-chain transfers, and do not claim it over contract upgrades.
- Cross-chain mint authorization: dual verification. Docs state that "both the bridge infrastructure (Chainlink CCIP) and the Security Consortium must independently approve a transfer before it completes", that a mint "requires valid signatures from both" the consortium and Bascule, and that "before any mint, Bascule independently verifies that the BTC deposit exists on the Bitcoin network with 6 confirmations". Contrast with the April 2026 Kelp exploit, which turned on a single cross-chain verifier.
- Audits: the contracts repo audit directory (github.com/lombard-finance/evm-smart-contracts, docs/audit) returns 20 entries, one of which is README.md, so 19 reports. Halborn V1, V1.5, V2. OpenZeppelin V2, YB, 2025-10, multipauser 04/26, strategies 06/26, mintlimit 07/26. Veridise V1, V2, strategies 06/26. Sherlock YB, GMP/Bascule 12/25, Wrapper 12/25, multipauser-bridge 04/26, mintlimit 06/26. ABDK SAB 202509, SaB NativeToken 25/11. Newest is July 2026. Filenames and dates read from the repo listing; PDF contents not read this run. The docs website audit page lists ten audits and nothing after 2025-10-24, so the site understates coverage. Immunefi bounty "up to $250,000 for critical vulnerabilities". The 8 High findings (2 partially resolved) in the Nov to Dec 2024 OpenZeppelin V2 audit are carried from the 2026-07-04 verification and were not re-read this run.
- Oracle / proof of reserve: Chainlink Proof of Reserve on Ethereum, plus RedStone real-time reserve verification announced 2026-03-23 ("real-time cryptographic proof that reserves match the circulating supply"). The feeds are readable on-chain; the underlying list of Bitcoin custody addresses was not confirmed published this run. Independent address-level verification: refresh.
- Redemption: docs state "Wait up to 10 days for BTC arrival", covering "Babylon's 7-day unbonding period plus Lombard's daily rebalancing cycle". Minimum "0.00013300 LBTC (includes 0.0001 LBTC network security fee)". Whether redemptions can be administratively paused is not addressed in that FAQ: refresh.
- Peg: 360 daily observations from 2025-08-12 to 2026-08-06 via the DeFiLlama coins chart API, pairing each LBTC point with the nearest BTC point within 15 minutes (the two series are stamped seconds apart, so exact-key matching yields nothing). Range 0.99515 (2025-08-20) to 1.00986 (2026-07-06). Zero days below 0.995, zero below 0.99. Spot 2026-08-12: LBTC $64,308.11 against BTC $64,083.61, ratio 1.0035. Two named extremes from the draft of this refresh were checked individually against the historical price endpoint and did not hold: 2025-11-13 measures 0.99981 and 2026-07-31 measures 1.00071. Note for anyone re-running this: CoinGecko's market_chart endpoint with vs_currency=btc returns a daily series with far wider extremes for the same period. Those are timestamp-misalignment artifacts. Do not report them as depegs.
- Supply: LBTC totalSupply on Ethereum reads 844,337,929,865 raw, 8 decimals, so 8,443.38 LBTC (read on-chain 2026-08-12), about 73% of the roughly 11,500 BTC of backing.
- Token: BARD $0.1095 (DeFiLlama price API, 2026-08-12). Launched 2025-09-18, 1B supply, 22.5% at TGE, roughly four-year vest with a one-year cliff for investors and contributors, per the 2026-07-04 verification. Unlock schedule status and next cliff: refresh.
- Holder concentration: refresh. Etherscan tokenTopHolders and Nansen top-holders both returned paid-tier errors this run.
- Babylon dependency: slashing exposure stated at roughly 0.1% of staked BTC with delegations across four finality providers, carried from the 2026-07-04 verification and not re-checked: refresh.
- Recent news scan (2026-07-01 to 2026-08-12): no exploit, depeg, paused redemption, consortium change or reserve challenge found. Sources: X search across the window, plus web search. Prior events unchanged: Feb 2025 Ionic loss (~$8.6M, attackers impersonated the Lombard team to get a counterfeit LBTC contract listed on Ionic and borrowed against it; not a Lombard exploit), May 2026 migration of $1B+ of bridging from LayerZero to Chainlink CCIP. Maintained monthly. Methodology: DeFi Research Instruction v2.