Circle Launches Wrapped Bitcoin on Ethereum and Arc: cirBTC
The company behind USDC wants to hold your Bitcoin. In May 2026, Circle announced wrapped Bitcoin on Ethereum and Arc: a token called cirBTC, backed 1:1 by native BTC and issued through the same Circle Mint infrastructure that handles USDC and EURC, according to Eco's cirBTC explainer. At announcement it was not yet live. The headline is simple. The plumbing underneath is not.
Most coverage stops at "institutions get another option" and skips what developers care about. Who holds the mint key? What does a cross-chain transfer between Ethereum and Arc actually verify? Can the token be frozen? What does "on-chain proof of reserves" prove, and what does it leave out?
This deep-dive takes cirBTC apart layer by layer. Where Circle hasn't published contract details yet, we reason from the architecture it already runs in production for USDC and say clearly which parts are inference.
Key Takeaways:cirBTC is a custodial wrapped Bitcoin token: Circle announced it in May 2026 as a 1:1 BTC-backed token launching first on Ethereum and Arc, with access starting through Circle Mint for institutional clients, and was listed as "coming soon, subject to regulatory approvals" with no firm mainnet date.Security depends entirely on Circle's custody and controls: The token's integrity relies on Circle's mint, burn, and redemption controls and its custodian's key management, not on Bitcoin's proof-of-work.CCTP burn-and-mint transport avoids the lock-and-mint honeypot: If cirBTC uses Circle's Cross-Chain Transfer Protocol to move between chains, it avoids locking collateral in a bridge contract (the target of the largest bridge hacks), but cross-chain transfers depend on Circle's off-chain attestation signer.On-chain proof of reserves shows disclosed BTC but has limits: Verifiable reserve addresses prove only that a disclosed set holds BTC; they cannot prove completeness, that coins are unencumbered, or that total liabilities match across all chains.Redemption and peg are separate risks: Only authorized institutions can redeem cirBTC for native BTC directly; retail holders depend on DEX arbitrage to maintain the peg, and if arbitrage breaks (low liquidity, high fees, or paused redemptions), the token can degrade despite adequate reserves.
Table of Contents
- What Did Circle Actually Announce?
- How Would cirBTC Minting Work at the Contract Level?
- How Does Redemption Work, and Who Holds the Exit Rights?
- How Would cirBTC Move Between Ethereum and Arc?
- What Does "On-Chain Proof of Reserves" Actually Prove?
- How Does cirBTC Compare to cbBTC, WBTC, tBTC and TeleBTC?
- Where Do Light-Client Bridges Fit?
- What Should Developers Check Before Integrating cirBTC?
- Frequently Asked Questions
- Conclusion
What Did Circle Actually Announce?
cirBTC is a wrapped Bitcoin token: an ERC-20-style asset on non-Bitcoin chains, where each unit is a claim on one BTC held in Circle-controlled custody. Here is what was announced in May 2026, drawn from Bitcoin Foundation's coverage and Eco's documentation:
- Launch chains: Ethereum and Arc, Circle's own Layer-1. More chains (possibly Base, Solana, Avalanche) are expected later but unconfirmed.
- Backing: 1:1 native BTC, with proof of reserves described as verifiable on-chain.
- Access: institutions go first. That means OTC desks, exchanges, treasuries, market makers, and lending protocols, with existing Circle Mint customers at the front of the queue.
- Retail: retail users get access indirectly, through secondary listings on exchanges and DEXs.
- Status: a waitlist at circle.com/cirbtc, "subject to regulatory approvals." Mint and redemption fees were not disclosed.
Note the date. It is now October 2026, and Eco's launch timeline listed no mainnet date at announcement. Check Circle's official channels for current status before you build against a live contract address.
Circle is entering a market with established players. WBTC has run since January 2019 under BitGo custody. Coinbase's cbBTC launched in September 2024 and had roughly $2–3B in supply by May 2026, according to Eco, citing DefiLlama data. The landscape also includes proof-based options such as TeleBTC, which uses SPV light-client verification instead of attestations (for background on Bitcoin scaling and interoperability designs, see our guide to Layer-2 solutions for Bitcoin), and BTC to WBTC bridges show the range of fee and speed tradeoffs across wrapped Bitcoin routes. Circle isn't selling a new kind of asset. It's selling its compliance reputation and its distribution.
How Would cirBTC Minting Work at the Contract Level?
Minting cirBTC will most likely follow a permissioned-minter pattern: only addresses Circle authorizes can create tokens, and only up to a set allowance. Circle hasn't published the cirBTC contract. Its USDC and EURC contracts, though, share one open-source codebase, circlefin/stablecoin-evm, and Circle frames cirBTC's trust model as identical to USDC's. Reusing that codebase is the reasonable expectation, but confirm it once the cirBTC contracts are published.

The FiatToken role model
Circle's production token contract splits privileges into separate roles, each held by a different key:
- Owner: assigns every other role.
- masterMinter: calls
configureMinter(minter, allowance)to authorize a minting address with a hard cap, andremoveMinterto revoke it. - Minter: calls
mint(to, amount). The function reverts ifamountexceeds the remainingminterAllowance. Minters can alsoburntokens they hold. - Pauser: calls
pause(), which stops every transfer, mint, and burn. - Blacklister: calls
blacklist(account). A blacklisted address can't send or receive tokens. - Proxy admin: upgrades the implementation behind an upgradeable proxy, which can change any of the logic above.
The allowance mechanism is the most interesting control. A compromised minter key can't mint unlimited tokens, only up to its configured allowance. That caps how much damage one hot key can do, at the cost of trusting whoever holds the masterMinter key.
Step-by-step mint flow (inferred)
- An authorized participant (AP), such as an OTC desk with a Circle Mint account, asks to mint.
- Circle Mint gives the AP a Bitcoin deposit address controlled by Circle's custodian. The custodian hadn't been named at announcement.
- The AP broadcasts a BTC transaction. It enters the mempool, then gets included in a block.
- The custodian waits for a confirmation threshold before crediting the deposit. Six confirmations (about 60 minutes at Bitcoin's ~10-minute block target) is a common industry convention; Circle hasn't published its threshold.
- Circle Mint credits the AP's account, and a Circle minter address calls
mint(apAddress, amount)on Ethereum or Arc. - The ERC-20
Transfer(0x0, apAddress, amount)event fires, and total supply goes up.
Notice what is missing. No contract on Ethereum checks that the BTC deposit happened. The link between step 3 and step 5 is an off-chain record at Circle. That is the defining property of every custodial wrapped Bitcoin, and it is exactly where cirBTC differs from light-client designs (more on those below). This gap is central when evaluating Bitcoin bridge risks.
How Does Redemption Work, and Who Holds the Exit Rights?
Only authorized participants can redeem cirBTC for native BTC directly. Everyone else exits by selling on a secondary market. Per Eco's breakdown, minting and redemption run through Circle Mint for authorized participants. If cirBTC copies USDC's flow, it looks like this:
- The AP sends cirBTC to its Circle Mint deposit address on Ethereum or Arc.
- Circle burns the tokens, which reduces
totalSupply. - The custodian builds a Bitcoin transaction spending reserve UTXOs (typically through MPC or multisig signing) to the AP's BTC address.
- The transaction confirms on Bitcoin, and the AP holds native BTC again.
Here is the nuance most write-ups miss. For a DeFi user, cirBTC's peg is held up by arbitrage, not by a redemption right. If cirBTC trades at 0.995 BTC on a DEX, an AP buys it there, redeems at par, and pockets the spread. That loop works only while three things hold: the AP set is deep, redemptions aren't paused, and fees are lower than the spread. If any one fails, holders of a supposedly 1:1 asset can see a persistent discount and have no direct way to fix it.
Custodial wrappers have shown this pattern before. When WBTC moved to a new multi-jurisdiction custody arrangement in August 2024, several DeFi protocols and exchanges reassessed their WBTC exposure over governance concerns, even though no reserves were reported missing. Peg and confidence risk are different from reserve risk, and they usually show up first. This is why understanding decentralized versus centralized exchange models matters for wrapped Bitcoin liquidity.
How Would cirBTC Move Between Ethereum and Arc?
cirBTC is expected to move between chains by burning on the source chain and minting on the destination chain, through Circle's Cross-Chain Transfer Protocol (CCTP), instead of locking tokens in a bridge contract. Eco lists CCTP as the transport layer in its cirBTC vs cbBTC comparison, and Eco Routes is set to orchestrate cirBTC across 15+ chains where USDC already runs. Confirm CCTP support for cirBTC when it goes live.

The CCTP message lifecycle
Circle's CCTP documentation describes this flow for USDC:
- Burn: the user calls
depositForBurn(amount, destinationDomain, mintRecipient, burnToken)on the source chain'sTokenMessenger. The tokens are burned. - Emit: the
MessageTransmitteremits aMessageSentevent carrying a nonce, the source and destination domain IDs, the recipient, and the amount. - Attest: Circle's off-chain Attestation Service watches the source chain. Once it considers the burn final, it signs the message hash with Circle's attester key or keys.
- Mint: anyone calls
receiveMessage(message, attestation)on the destinationMessageTransmitter. The contract recovers the signer, checks it against the registered attester set, marks the nonce as used (which blocks replays), and tellsTokenMinterto mint.
Contrarian take: for a custodial asset, burn-and-mint is the right design, and it is better than how most wrapped tokens reach new chains. Lock-and-mint bridges leave a growing pile of locked collateral in a contract, and that pile has been the target of the largest bridge exploits in crypto history. CCTP leaves nothing locked. It adds no new trust assumption only because it reuses the one you already accepted: Circle's key controls issuance on every chain. Moving cirBTC across chains is exactly as trustworthy as Circle, no more and no less.
What Arc adds
Arc is Circle's EVM-compatible Layer-1, introduced by Circle in 2025. Circle describes it as using USDC as its native gas token and the Malachite BFT consensus engine for deterministic, sub-second finality, along with opt-in privacy features; check Arc's current mainnet status before building on it. Deterministic finality matters for cirBTC. On Arc, a CCTP attestation can be issued as soon as a block is committed, with no probabilistic waiting period. That makes Arc a natural venue for institutional BTC-collateralized lending, where the collateral (cirBTC) and the debt (USDC) live on the same chain under the same issuer's compliance tools. Trustless designs take a different route; see intent-based security for one alternative approach to cross-chain settlement.
What Does "On-Chain Proof of Reserves" Actually Prove?
On-chain proof of reserves proves that a disclosed set of Bitcoin addresses holds at least X BTC at a given block height. It doesn't prove the set is complete, that the coins are unencumbered, or that liabilities match. Circle positions verifiable on-chain reserves as a difference from cbBTC's attested off-chain model, per Eco. That is an improvement. Developers should still understand what it covers.
A rigorous BTC proof of reserves has three parts:
- Asset side: the custodian publishes reserve addresses. Anyone can add up their UTXO set from a full node and check that the total is at least the claimed BTC.
- Control proof: a signed message from each address (or a spend to a known address) shows the custodian holds the private keys, not just an address that belongs to someone else.
- Liability side: cirBTC
totalSupplyadded up across every chain, plus any tokens in flight (burned on a source chain through CCTP but not yet minted on the destination).
Part 3 gets harder with every chain Circle adds. With cirBTC on Ethereum and Arc, and potentially 15+ chains through Eco Routes, a full liability check means reading supply on every domain at roughly the same moment. Oracle feeds, such as the Chainlink proof-of-reserve feed used for WBTC, exist to automate this; Circle hasn't named a PoR oracle provider for cirBTC. When you evaluate cirBTC, ask whether a contract can consume the PoR feed (for example, a lending market that halts borrows when reserves fall below supply) or whether it's only a dashboard. For how reserve and verification failures play out in practice, see our bridge security exploit analysis.
How Does cirBTC Compare to cbBTC, WBTC, tBTC and TeleBTC?
Wrapped Bitcoin designs differ along five trust surfaces: custody, issuance, transport, redemption, and censorship. The useful question isn't "is it safe?" but "which party has to behave honestly at each layer?"

- Custody: who holds the native BTC, and what happens if they disappear?
- Issuance: what has to be true before a token is minted, and who checks it?
- Transport: how does the token reach other chains?
- Redemption: who can turn the token back into BTC?
- Censorship: can one entity freeze, blacklist, or pause holders?
| Token | Launched | Custody | Mint verification | Redemption access | Freeze / pause |
|---|---|---|---|---|---|
| cirBTC (Circle) | Announced May 2026 | Circle custody partner (unnamed at announcement) | Off-chain: Circle Mint ledger | Authorized Circle Mint participants | Expected (USDC pattern); confirm on deployment |
| cbBTC (Coinbase) | Sept 2024 | Coinbase Prime | Off-chain: Coinbase ledger | Coinbase customers | Yes |
| WBTC | Jan 2019 | BitGo-led multi-custodian model | Off-chain: merchant/custodian process | Whitelisted merchants | Pausable |
| tBTC (Threshold) | Live (v2) | Threshold signer set (t-of-n, no single custodian) | Bitcoin SPV proofs checked on-chain (optimistic minting can precede the proof) | Permissionless | Protocol governance |
| TeleBTC | Live | Lockers backed by slashable collateral | Bitcoin SPV light-client proof checked on-chain | Any holder, by bridging back to BTC | No single custodian; see TeleSwap docs |
Sources: Eco, Threshold Network docs, issuer documentation.
The table shows a clear split. cirBTC, cbBTC, and WBTC are attestation-based: the destination chain takes an operator's word that BTC arrived. tBTC and TeleBTC are proof-based: they anchor issuance in Bitcoin's own consensus data, verified on-chain. Within the custodial group, cirBTC's pitch is regulatory polish and Circle Mint distribution. Its security model is not new.
Where Do Light-Client Bridges Fit?
A light-client bridge mints wrapped BTC only after a smart contract checks, using Bitcoin's own proof-of-work, that the deposit transaction is buried in the heaviest chain. The method is Simplified Payment Verification (SPV), described in section 8 of the Bitcoin whitepaper:
- Header relay: Relayers submit 80-byte Bitcoin block headers to a light-client contract on the destination chain.
- PoW check: the contract double-SHA-256 hashes each header, checks the result is below the target encoded in the
nBitsfield, checks thatprevBlockHashlinks to a header it already stored, and applies difficulty-adjustment rules at 2,016-block boundaries. - Inclusion proof: the user (or a Teleporter) submits the raw deposit transaction plus a Merkle branch. The contract hashes up the branch and checks the result against the
merkleRootin a stored header. - Depth check: the contract requires a set number of headers on top of the including block before minting.
Forging a deposit would mean producing valid proof-of-work at real Bitcoin difficulty. No signer, custodian, or attestation service can approve a mint that didn't happen on Bitcoin.
TeleSwap is a trust-minimized Bitcoin bridge built on this model. Its token, TeleBTC, is minted 1:1 only against a Bitcoin transaction verified by SPV light-client proofs, and the BTC is held by Lockers whose collateral can be slashed if they misbehave. TeleSwap supports 12 networks and has processed $501.5M in bridged volume over 532,851 transactions, including $42.6M in the 30 days to October 4, 2026, according to TeleSwap network stats. For developers comparing routes, it also connects native BTC directly to existing wrappers. You can go BTC to cbBTC on Ethereum or BTC to WBTC on Ethereum in one step, with fees paid in Bitcoin assets. Our explainer on DEX routing mechanics covers how to compare paths on slippage.
Light-client and custodial wrappers aren't really rivals for the same user. An institution that needs a regulated counterparty and legal recourse will reasonably choose cirBTC. A DeFi protocol that wants collateral without a single issuer able to freeze it will look to the proof-based options. The mistake is treating them as interchangeable because both are worth "1 BTC."
What Should Developers Check Before Integrating cirBTC?
Treat cirBTC as a privileged-role token and audit those roles before listing it as collateral. Once Circle publishes addresses, run through this list:
- Read the proxy admin and implementation. Confirm it is FiatToken-derived, or find out what changed. Record who can upgrade it and whether there is a timelock.
- Handle blacklist reverts. If
transfercan revert for blacklisted addresses, a liquidation that sends seized collateral to a blacklisted liquidator, or from a blacklisted borrower, can fail. Design fallback paths, as lending markets that list USDC already must. - Use the right decimals. BTC uses 8 decimals (satoshis). Check cirBTC's
decimals()on each chain and never hard-code 18 or 6. - Price it carefully. Don't price cirBTC at BTC/USD by assumption. Use a cirBTC-specific market feed or a PoR-gated price, so a depeg doesn't become bad debt.
- Verify CCTP domains. If you bridge cirBTC programmatically, confirm the token is registered in
TokenMinteron both domains and that you're tracking nonces forreceiveMessageidempotency, per Circle's developer docs. - Size the exit. Model the slippage of unwinding your protocol's cirBTC exposure on DEXs, because your users can't redeem through Circle Mint. Our BTC token swap speed guide covers how routes differ across venues.
Frequently Asked Questions
What is cirBTC?
cirBTC is Circle's wrapped Bitcoin token, backed 1:1 by native BTC in custody and launching first on Ethereum and Circle's Arc blockchain. Circle announced it in May 2026 as a custodial wrapped Bitcoin product minted and redeemed through Circle Mint, the same institutional infrastructure that issues USDC and EURC, aimed at OTC desks, treasuries, and lending protocols.
Is cirBTC live yet?
At its May 2026 announcement, cirBTC was not live and was described as "coming soon, subject to regulatory approvals." Circle opened a waitlist at circle.com/cirbtc but gave no firm mainnet date at announcement. As of October 2026, confirm the current status and official contract addresses directly with Circle before integrating against live contracts.
How is cirBTC different from cbBTC?
Both cirBTC and cbBTC are custodial 1:1 BTC-backed tokens, but they differ by issuer, launch chains, and how reserves are disclosed. cbBTC is issued by Coinbase, has been live since September 2024 on Base, Ethereum, and Solana, and uses attested off-chain Coinbase Prime custody. cirBTC is issued through Circle Mint, launches on Ethereum and Arc, and promises on-chain verifiable proof of reserves, which Circle positions as more transparent than cbBTC's off-chain attestation model.
Can cirBTC be frozen or blacklisted?
Probably yes, if cirBTC uses the same contract pattern as USDC, which includes both blacklist and pause functions controlled by Circle. Circle's open-source FiatToken contracts give a blacklister role the power to block addresses from sending or receiving tokens, and a pauser role can halt all transfers. Circle hadn't published the cirBTC contract at announcement, so verify the deployed code when it goes live.
How will cirBTC move between Ethereum and Arc?
cirBTC is expected to use Circle's Cross-Chain Transfer Protocol (CCTP), which burns tokens on the source chain and mints them on the destination chain after Circle's attestation service cryptographically signs the burn message. This architecture avoids keeping locked collateral in a bridge contract (a major exploit vector), but cross-chain transfers depend on Circle's attester keys remaining secure and responsive.
Can retail users mint or redeem cirBTC directly?
No, not at launch; direct minting and redemption are limited to authorized institutional participants on Circle Mint. Retail users will get cirBTC through exchange and DEX secondary listings, and the token's peg to 1 BTC depends on institutional arbitrageurs buying cirBTC at discounts and redeeming at par—meaning peg stability is not guaranteed if redemption access is paused or institutional liquidity dries up.
Is cirBTC trustless?
No, cirBTC is not trustless; it is a custodial asset, so every holder trusts Circle and its unnamed custodian to hold BTC and honor redemptions. Trust-minimized alternatives such as tBTC and TeleBTC anchor issuance in Bitcoin's own proof-of-work through SPV proofs checked on-chain, so they don't rely on a single issuer's key management or off-chain attestation.
What does "on-chain proof of reserves" for cirBTC actually prove?
On-chain proof of reserves for cirBTC proves that a disclosed set of Bitcoin addresses holds at least a stated amount of BTC at a given block height, but it does not prove that the address set is complete, that the coins are unencumbered (not committed to other obligations), or that liabilities across all chains match those reserves. It is a transparency improvement over attested off-chain custody, but it is not a substitute for direct on-chain verification of Bitcoin deposits the way light-client bridges provide.
Conclusion
Circle's wrapped Bitcoin on Ethereum and Arc is best understood as USDC's architecture with a BTC reserve: permissioned minters with allowances, issuer-controlled freeze and pause powers, burn-and-mint transport through CCTP, and redemption limited to institutions. That is a coherent product for regulated capital, and on-chain proof of reserves is a real step up in transparency compared with attestation-only models.
It doesn't change the basic tradeoff. Every cirBTC is exactly as trustworthy as Circle's off-chain ledger. If you want BTC on other chains where minting depends on Bitcoin's proof-of-work rather than an operator's signature, compare the proof-based routes before you commit. You can see live volume and supported networks on the network stats page at teleswap.xyz, or bridge native BTC directly at teleswap.xyz. For how TeleSwap compares with an aggregator route, see Rango Exchange vs TeleSwap: Bitcoin Swaps Compared.