Alba: The Dawn of Scalable Bridges for Blockchains

Giulia Scaffino

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Blockchain Security 2

Overview

In this insightful talk from the NDSS Symposium, Giulia Scaffino introduced Alba, a groundbreaking protocol designed to overcome two of the most significant limitations plaguing modern blockchain ecosystems: scalability and interoperability. While Layer 2 solutions have made strides in off-chain transaction processing, they traditionally remain tethered to their native Layer 1 blockchains. Similarly, existing bridge protocols, though enabling some cross-chain communication, often require transactions to be posted on-chain, inherently hindering their scalability and preventing seamless interoperability between different Layer 2 protocols or between a Layer 2 and a non-native Layer 1.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: Blockchain scalability and interoperability challenges
  2. 2:00 Current bridge limitations: lack of scalability and off-chain support
  3. 2:20 Alba's new paradigm: scalable, off-chain, L2-to-L2 interoperability
  4. 4:40 How Alba works: proving off-chain payments to smart contracts
  5. 6:00 Alba's technical design for efficiency and enhanced security
  6. 7:00 Alba's performance: efficient gas costs and security analysis
  7. 8:30 Alba's advantages: consensus agnostic, instant finality, liveliness security

Alba: The Dawn of Scalable Bridges for Blockchains

Speakers: Giulia Scaffino

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=n_o6E-IVljA

Overview

In this insightful talk from the NDSS Symposium, Giulia Scaffino introduced Alba, a groundbreaking protocol designed to overcome two of the most significant limitations plaguing modern blockchain ecosystems: scalability and interoperability. While Layer 2 solutions have made strides in off-chain transaction processing, they traditionally remain tethered to their native Layer 1 blockchains. Similarly, existing bridge protocols, though enabling some cross-chain communication, often require transactions to be posted on-chain, inherently hindering their scalability and preventing seamless interoperability between different Layer 2 protocols or between a Layer 2 and a non-native Layer 1.

Alba proposes a novel paradigm: scalable bridges. By supporting off-chain transactions, Alba dramatically enhances the scalability of decentralized applications and, crucially, enables true interoperability across diverse Layer 2 networks, or between a Layer 2 and any Layer 1, regardless of its native affiliation. The protocol is presented with a specific focus on payment channels as the underlying Layer 2 technology, chosen for their maturity, decentralization, broad compatibility, and effective scaling of both storage and computation. This work not only defines a new category of blockchain infrastructure but also delivers a concrete, evaluated solution that promises to unlock a new era of interconnected and high-throughput decentralized applications.

The importance of Alba lies in its potential to fundamentally alter how decentralized applications are built and interact. By enabling efficient, secure, and truly off-chain communication between disparate blockchain systems, Alba addresses a critical bottleneck that has limited the widespread adoption and utility of blockchain technology. Its design principles, rooted in augmenting existing Layer 2 mechanisms with robust on-chain dispute resolution, offer a practical path toward a more integrated and scalable blockchain future.

Background

▶ Watch: Introduction: Blockchain scalability and interoperability challenges (0:00)

Despite significant advancements, blockchains continue to grapple with fundamental limitations that impede their mainstream adoption. The first is scalability. Prominent blockchains like Bitcoin and Ethereum exhibit remarkably low transaction throughput, processing only about 8 and 15 transactions per second, respectively. This pales in comparison to traditional payment networks like Visa, which can handle tens of thousands of transactions per second. Such low throughput restricts the types of applications that can realistically operate on these networks.

The second major limitation is interoperability. By their very design, blockchains are isolated systems, lacking native mechanisms for information or asset exchange between them. This fragmentation creates silos, hindering the development of complex, multi-chain applications. The research community has dedicated substantial effort to addressing these challenges, leading to various solutions.

For scalability, Layer 2 protocols have emerged as a primary strategy. These protocols, including payment channels, state channels, commit chains, sidechains, and rollups, allow users to execute transactions off-chain, leveraging the underlying Layer 1 blockchain for security, dispute resolution, or finality. However, a crucial characteristic of existing Layer 2 protocols is their inherent dependency: they are designed to interact only with their respective Layer 1. This means a payment channel on Bitcoin cannot directly interact with a smart contract on Ethereum without an intermediary.

For interoperability, bridge protocols have been developed, encompassing various approaches such as trusted protocols, atomic swaps, oracles, and chain relays. While these bridges facilitate some form of cross-chain communication, they share a critical flaw that undermines true scalability: most existing bridges require transactions to be posted on-chain on one or both sides of the bridge. This on-chain requirement reintroduces the very scalability bottlenecks that Layer 2 solutions aim to solve, making it impractical for high-volume applications and, more importantly, preventing direct interoperability between two different Layer 2 protocols, or between a Layer 2 and a Layer 1 that is not its native host.

Alba specifically targets payment channels as its initial Layer 2 focus. Payment channels are a mature and decentralized Layer 2 solution, exemplified by the Lightning Network on Bitcoin. They offer virtual compatibility with all existing blockchains and effectively scale both storage and computation. A payment channel operates in three phases:

  1. Opening Phase: Two users (e.g., Alice and Bob) lock coins in a funding transaction on-chain, creating a shared output and an initial state reflecting their contributions.
  2. Update Phase: After the funding transaction is published, the parties can update the channel state off-chain as many times as they wish, performing numerous transactions without touching the Layer 1.
  3. Closing Phase: When done, the final state of the channel is published on-chain.
  4. Dispute Phase: A critical component ensuring security. In a rational setting, this phase guarantees that only the latest valid state of the channel is finalized on-chain. Any attempt to publish an old, invalid state results in the cheating party losing their locked funds.

This existing landscape highlights the gap Alba aims to fill: enabling efficient, off-chain interoperability that scales beyond the limitations of current Layer 2s and bridges, leveraging the proven security model of payment channels.

Key Findings

▶ Watch: Alba's new paradigm: scalable, off-chain, L2-to-L2 interoperability (2:20)

Alba introduces a transformative approach to blockchain interoperability, yielding several key findings and contributions:

  1. Definition of Scalable Bridges: The talk formally defines the concept of a scalable bridge, a new paradigm that supports off-chain transactions for cross-chain communication, thereby enhancing application scalability and enabling interoperability between diverse Layer 2 protocols or between a Layer 2 and a non-native Layer 1.
  2. First Scalable Bridge Design: Alba is presented as the first concrete design and implementation of such a scalable bridge. It specifically targets payment channels as the underlying Layer 2 mechanism, leveraging their inherent off-chain capabilities.
  3. Efficiency Metrics: Alba demonstrates remarkable efficiency in its optimistic execution path. When deployed on Ethereum, an Alba contract costs only 48,000 gas for a successful proof of an off-chain payment. This is highly efficient, especially when compared to a simple Ethereum transfer, which costs 21,000 gas. In pessimistic scenarios (e.g., involving disputes), Alba's costs are comparable to those of other standard bridge solutions, positioning it favorably within the existing ecosystem.
  4. Rigorous Security Analysis: The security of Alba is established through a dual-pronged approach:
  • Universal Composability (UC) Framework: This robust cryptographic framework is used to formally define security by comparing the protocol's behavior in a "real world" setting to an "ideal world" functionality, ensuring that no adversary in the real world can achieve more than in the ideal world.
  • Game Theoretical Approach: A game-theoretic analysis models the interactions between rational participants (e.g., Alice and Bob) who aim to maximize their profit. This analysis demonstrates that Alba achieves a subgame perfect Nash equilibrium when parties submit valid proofs, meaning rational actors are incentivized to behave honestly and follow the protocol rules, preventing cheating.
  1. Unique Protocol Properties: Alba inherits and enhances several desirable properties, distinguishing it from other bridge solutions:
  • Consensus Agnostic: Alba's design is not tied to a specific consensus mechanism, allowing it to bridge different types of blockchains.
  • Instant Finality: In the rational setting, transactions facilitated by Alba achieve instant finality, similar to off-chain Layer 2 transactions, without waiting for Layer 1 block confirmations on both chains.
  • Security Against Liveness Attacks on Source Chain: Unlike some light-client-based bridges that can be vulnerable if the source chain experiences liveness issues, Alba maintains security.
  • Constant Resource Consumption: Alba allows for relaying communication and storage that is constant in the length of the source chain. This is a significant advantage over many other bridge types that require resource consumption proportional to the history or complexity of the source chain.
  1. Enabling New Applications: Beyond basic payment transfers, Alba opens the door to a range of sophisticated decentralized applications:
  • Multi-asset Payment Channels: Enabling channels that can handle various types of digital assets.
  • Optimistic Stateful Computation: Facilitating complex, multi-step computations off-chain within payment channels, with on-chain dispute resolution. An example discussed in the paper is playing chess on a payment channel.

These findings collectively demonstrate that Alba is not merely an incremental improvement but a foundational shift in how cross-chain interoperability can be achieved, offering a highly efficient and secure mechanism for scaling decentralized applications.

Technical Deep Dive

▶ Watch: How Alba works: proving off-chain payments to smart contracts (4:40)

The core innovation of Alba lies in its ability to securely prove that an off-chain transaction, specifically a payment within a Layer 2 payment channel, has occurred to a smart contract on a different, potentially non-native, Layer 1 blockchain. This is achieved through a clever augmentation of both the Layer 2 channel state and the Layer 1 smart contract.

Let's illustrate Alba's mechanism using a lending protocol as a running example, involving Alice, Bob, a Lightning Network payment channel (Layer 2 on Bitcoin), and an Alba smart contract on Ethereum (a non-native Layer 1).

  1. Initial Setup and Atomic Actions:
  • Alice wishes to borrow coins from Bob.
  • Alice first locks a certain amount of collateral into the Alba smart contract on Ethereum. This collateral acts as a guarantee for the loan.
  • Concurrently, Bob grants the loan to Alice on the Lightning Network payment channel.
  • Crucially, these two actions – Alice locking collateral on Ethereum and Bob granting the loan on the Lightning Network – must happen atomically. This ensures that if one action fails, the other is also reverted, preventing either party from being disadvantaged. The atomic swap mechanism could be used here, although not explicitly detailed in the transcript, it's implied by the requirement for atomicity.
  1. Off-chain Payment and State Augmentation:
  • After receiving the loan, Alice can use the borrowed funds.
  • When Alice is ready to repay the loan, she performs a payment back to Bob within the existing Lightning Network payment channel. This is a standard off-chain transaction within the Layer 2.
  • The innovation comes here: Alba requires the state of the payment channel to be augmented to include additional, application-specific data. In this lending example, the channel state would be updated to explicitly record that "Ellis has returned the loan to Bob." This augmentation is vital for efficiency, as it allows the on-chain contract to verify relevant information directly.
  1. On-chain Proof and Contract Execution:
  • Once Alice has paid back the loan off-chain, Alba allows her to prove this payback transaction to the Ethereum smart contract. This proof is not the entire off-chain transaction history, but rather a concise cryptographic proof derived from the augmented channel state.
  • Upon receiving and validating this proof, the Alba smart contract on Ethereum executes a corresponding on-chain transaction. In this case, it would release Alice's locked collateral back to her, completing the lending cycle across two disparate blockchain networks.
  1. Dispute Mechanism for Security:
  • To ensure full security, the Alba smart contract on Ethereum is augmented with a dispute mechanism. This mechanism is analogous to the dispute phase in a standard payment channel protocol.
  • It ensures that in a rational setting, where users seek to maximize their profit, they are incentivized to behave correctly and submit only valid proofs. If a party attempts to submit an old or fraudulent proof of an off-chain payment (e.g., Alice claiming she paid back the loan when she didn't, or Bob claiming she didn't when she did), the dispute mechanism allows the honest party to challenge this claim.
  • The rational analysis, using a game theoretical approach, demonstrates that Alba achieves a subgame perfect Nash equilibrium. This means that no player can improve their outcome by unilaterally changing their strategy, given the strategies of others, and this holds true for every subgame of the overall interaction. This provides strong guarantees against cheating.

Comparison with Zero-Knowledge (ZK) Bridges:

During the Q&A, a comparison with ZK-proof based bridges was raised. While ZK bridges are indeed very efficient on-chain (due to the compact nature of ZK proofs), they impose a significant computational burden on the prover off-chain. Generating ZK proofs often requires heavy computational resources. Furthermore, ZK bridges, in their current common implementations, still often require transactions to be posted on-chain, limiting their scalability. Alba, in contrast, aims for constant resource consumption for bandwidth, computation, and storage for the proof generation and verification, making it more scalable in terms of overall system resources.

Applicability to Rollups:

The speaker noted that applying Alba directly to rollups would require an "entirely different design." Rollups operate on fundamentally different principles, often involving a sequencer and using the underlying chain as a "lazy ledger" to check transaction ordering and compute state. Alba's current design is tightly coupled with the state update and dispute mechanisms of payment channels, which are distinct from rollup architectures. However, the concept of off-chain interoperability could certainly be explored for rollups in future research.

Security in Multiple Blockchains:

The security model for Alba assumes that the underlying blockchains (specifically the target blockchain where the Alba contract resides, e.g., Ethereum) are both safe and live. It also assumes that the standard security assumptions of the underlying Layer 2 payment channel are fulfilled. Building on these assumptions, the Universal Composability (UC) framework is employed. The UC framework allows defining an "ideal world" where the desired functionality is perfectly achieved and then proving that Alba in the "real world" (with its cryptographic primitives and protocol steps) is as secure as this ideal world. The game-theoretic analysis further strengthens this by analyzing the entire set of possible actions for all players and, based on their utility functions, identifying the dominant strategies that lead to honest behavior.

In essence, Alba's technical elegance lies in its minimal yet effective augmentation of existing Layer 2 and Layer 1 mechanisms, creating a secure and efficient pathway for off-chain cross-chain communication.

Demo / Proof of Concept

▶ Watch: Alba's performance: efficient gas costs and security analysis (7:00)

While the talk did not feature a live, interactive demonstration in the traditional sense, the speaker presented a concrete proof of concept and an evaluation of the Alba protocol's efficiency when deployed on a real blockchain.

The core of the demonstration involved:

  1. Deployment of an Alba Contract on Ethereum: The researchers implemented and deployed an Alba smart contract onto the Ethereum blockchain. This contract embodies the on-chain logic required for verifying off-chain payment channel proofs and managing the associated dispute mechanism and collateral.
  2. Efficiency Evaluation: The team rigorously evaluated the gas costs associated with Alba's operations on Ethereum.
  • In the optimistic case, where all parties behave honestly and no disputes arise, proving an off-chain payment channel update to the Alba contract costs a mere 48,000 gas. This figure is highly competitive, especially when considering that a simple Ether transfer on Ethereum costs 21,000 gas. This low cost validates Alba's claim of efficiency for its primary function.
  • In the pessimistic case, which would involve a dispute being raised and resolved on-chain, the gas costs are similar to those incurred by other standard bridge protocols. This indicates that while the optimistic path is exceptionally efficient, the security guarantees provided by the dispute mechanism do not come at an exorbitant premium compared to existing solutions.

The running example of a lending protocol (Alice borrowing from Bob via a Lightning Network channel and repaying via an Alba contract on Ethereum) served as a practical illustration of how Alba would function in a real-world decentralized application. This concrete evaluation and the clear cost metrics provide strong evidence for Alba's practicality and its potential to deliver on its promise of scalable and efficient cross-chain interoperability.

Defensive Implications

▶ Watch: Alba's advantages: consensus agnostic, instant finality, liveliness security (8:30)

Alba presents a significant advancement for the blockchain ecosystem, offering crucial defensive implications for developers, users, and the broader community:

  1. Enabling Scalable and Secure Cross-Chain Applications: For application developers, Alba provides a robust framework to build genuinely scalable and interoperable decentralized applications (dApps) that leverage the efficiency of Layer 2 solutions across different Layer 1s. Developers can now design dApps that integrate services or assets from multiple chains without being bottlenecked by on-chain transaction costs or the limitations of single-chain Layer 2s. This means less reliance on centralized intermediaries or less secure trusted bridges.
  2. Mitigating Interoperability Risks: By offering a secure, decentralized, and off-chain-first approach to bridging, Alba helps mitigate risks associated with many existing bridge designs, which have frequently been targets for exploits due to their complexity, reliance on multisig wallets, or centralized components. Alba's reliance on augmented payment channel states and a smart contract dispute mechanism provides a higher degree of security and decentralization.
  3. Understanding Dispute Mechanisms: Defenders should recognize the critical role of the dispute mechanism within the Alba smart contract. This mechanism is the ultimate arbiter of truth for off-chain actions. Developers implementing Alba-like protocols must ensure their dispute mechanisms are correctly designed, thoroughly audited, and resilient to attack, as any vulnerability here could compromise the entire system. Users interacting with Alba-enabled dApps should understand the dispute process and their rights/responsibilities within it.
  4. Efficiency and Cost Analysis: The demonstrated 48,000 gas cost for optimistic operations on Ethereum is a key metric for defenders to consider. This low cost means that even frequent cross-chain interactions can be economically viable, reducing the attack surface that often arises from users trying to bypass high fees. However, defenders should also be aware of the "pessimistic case" costs, which are comparable to standard bridges, and plan for potential dispute costs.
  5. Rational Actor Model and Game Theory: The security analysis based on a game theoretical approach and subgame perfect Nash equilibrium is vital. It implies that as long as participants are rational and seek to maximize their profit, the system is secure against cheating. Defenders should understand the assumptions underpinning this rationality and consider edge cases where actors might behave irrationally (e.g., state-sponsored attacks, griefing attacks) and how the protocol might respond.
  6. Constant Resource Consumption: Alba's property of constant resource consumption for relaying communication and storage, independent of the source chain's length, is a significant defensive advantage. It means the bridge's operational costs and complexity do not grow indefinitely with the activity or age of the source chain, leading to more predictable and sustainable operations.
  7. Future-Proofing for Diverse L2s: While Alba initially focuses on payment channels, its paradigm of scalable bridges sets a precedent for how other Layer 2 solutions (like future rollup designs) could achieve similar off-chain interoperability. Defenders should monitor how these principles evolve and adapt to new Layer 2 architectures.

In summary, Alba provides a robust, efficient, and well-analyzed framework for cross-chain interoperability. Defenders can leverage its design principles to build more secure and scalable dApps, but must also remain vigilant in understanding and implementing its core security mechanisms, particularly the dispute resolution process.

Key Takeaways

  • Blockchains are inherently limited by scalability and interoperability issues. Current Layer 2 solutions are tied to native Layer 1s, and existing bridges often require on-chain transactions, hindering true scalability.
  • Alba introduces the concept of "scalable bridges" to enable off-chain interoperability. This paradigm allows Layer 2 protocols to interact with other Layer 2s or non-native Layer 1s efficiently and securely.
  • Alba leverages augmented payment channel states and a smart contract dispute mechanism. It proves off-chain payments to an on-chain contract, with security guaranteed by a dispute system similar to Layer 2 channels, ensuring rational actors behave honestly.
  • The protocol is highly efficient and rigorously secure. Optimistic operations on Ethereum cost only 48,000 gas, and its security is proven via Universal Composability (UC) framework and game theoretical analysis, demonstrating a subgame perfect Nash equilibrium.
  • Alba offers unique advantages over other bridge solutions. It is consensus agnostic, provides instant finality (in rational settings), is secure against liveness attacks on the source chain, and consumes constant resources for communication and storage relay.
  • Alba unlocks new application possibilities. It enables complex cross-chain dApps such as multi-asset payment channels and optimistic stateful computation, exemplified by playing chess off-chain.

About the Speaker(s)

The talk on Alba, "The Dawn of Scalable Bridges for Blockchains," was presented by Giulia Scaffino. While specific titles or affiliations were not detailed in the provided transcript, she is the lead presenter of this significant research, which is described as a joint work with Lucaser Masabastic and Mat Maf. Her presentation at the NDSS Symposium highlights her expertise and contributions to the field of blockchain security and decentralized systems research.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate academic research on a real problem — cross-chain interoperability without on-chain bottlenecks — with a concrete protocol design, formal security proofs, and actual gas benchmarks. Solid NDSS-tier work, but this is a blockchain/distributed systems paper, not security research in the adversarial sense, and the write-up summary reads more like a conference brochure than a technical briefing.

Heather Calloway (CISO) — PASS

Technically credible academic work on blockchain bridge protocol design — but this is outside my lane entirely. No governance angle, no institutional risk, no enterprise security relevance. Routing accordingly.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025