Skip to content

LibraryInteroperability2018Design paperCorpus record

Atomic Cross-Chain Swaps

Atomic swaps. Maurice Herlihy.

A swap across ledgers where either every transfer completes or none does, using hash locks and time locks. There is no custodian in the paper. A party can still walk away and leave the other waiting.

Herlihy's atomic swaps lock assets on several chains under the same hash and release them with one preimage, or return them after a timeout. There is no custodian. There is also no guarantee the other party will finish.

The five-minute read

One secret, many chains

Whoever knows the preimage can claim. Publishing the preimage to take the asset on one chain reveals it to the counterparty, who takes the asset on the other. That coupling is the atomicity.

Timeouts are mandatory

If the secret is never published, every escrow must be able to refund. A swap with no timeout is a donation. The order of timeouts matters, because the party who moves second needs time to react.

Not every graph works

The paper's result is about which sets of pairwise swaps can be made atomic. A product that draws an arbitrary mesh of trades and calls it Herlihy has not checked the condition.

Price is out of scope

The protocol completes a pre-agreed exchange or reverts. It does not discover a fair price, route liquidity, or insure anyone against moving the market.

One action, walked through

  1. Parties agree the amounts and a hash of a secret one of them chose.
  2. Each locks funds in a contract that pays the counterparty if shown the preimage before a deadline, and refunds otherwise.
  3. Deadlines are staggered so the party who must react still has time after the secret appears.
  4. The secret-holder publishes the preimage on the chain where they want to claim.
  5. The other party sees it and claims on their chain. If the secret never appears, refunds fire.

The argument, unpacked

Atomic is not fair in the informal sense

A party can lock, wait, and refund, having used the other side's time and information. The paper stops them taking the asset without paying. It does not stop them wasting the counterparty's timeout. Calling that trustless requires saying what was actually guaranteed.

A committee that can complete the swap early is a custodian

The moment a third set of keys can release the escrow, the construction has left the paper and become a bridge. That may be a product choice. It is not an atomic swap.

What has to be true

  • Every chain in the swap can hash the same way and can enforce a timeout refund.
  • Timeouts are long enough for an honest party to observe the preimage and claim, and ordered so the leader cannot claim at the last moment and leave the other stranded.
  • The hash is preimage-resistant. A guessable secret breaks the lock.
  • Contracts cannot be upgraded mid-swap by an admin the paper does not include.

What happened after the paper

Lightning uses the same hash-lock idea inside channels rather than as a one-shot exchange of on-chain assets. Bridge products usually replaced the preimage with a committee. Herlihy's 2018 paper is the citation for custodian-free atomicity and for the graph condition. It is not a citation for wrapped assets.

What to check before you use the idea

  • What is the hash, and who knows the preimage at the start?
  • What are the timeouts, and who must react last?
  • Can anyone other than the preimage holder release the funds?
  • Does the swap graph match a pattern the protocol actually supports?

Terms

Hash lock
A condition that pays whoever presents the preimage of a committed hash.
Timelock
A deadline after which the original holder can take the funds back.

The problem the paper names

Two chains cannot read each other's state. Herlihy asks when a group of parties can still exchange assets so that no coalition gets paid without paying.

What the design proposes

  • A secret preimage. Publishing it on one chain lets the counterparty claim on the other.
  • Timeouts so a locked asset returns if the secret never appears.
  • A graph of who swaps with whom. Not every directed graph has an atomic protocol under the paper's rules.

How the mechanism is specified

  • The hash has to be the same primitive on every chain involved. A chain that cannot escrow and hash does not fit.
  • Atomicity is about completion, not about price. The paper does not discover a fair exchange rate.
  • The leader of the protocol learns the secret first in some positions. The timeout has to cover that advantage.

What this page does not treat as proven

  • This is not a bridge, not wrapped bitcoin, and not a liquidity network.
  • A timeout that is too short fails honest users. A timeout that is too long freezes funds. That choice is operational.
  • Herlihy's graph condition is part of the result. A product that ignores it is not this protocol.

Why a venture studio still reads it

If a swap claims to be atomic, name the hash, the timeout, and what an abort costs each side. If a committee can release the funds early, it is custody.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.