"Non-custodial" is the most overused word in peer-to-peer crypto trading. Every platform claims it. But the platforms that genuinely earn it do so in very different ways, and the mechanism decides what can go wrong, who can stall a trade, and what happens if the platform disappears.
This post compares the four escrow designs you will run into when looking at HODL HODL and the platforms people compare it with: a 2-of-3 multisig, Lightning hold invoices, security deposits with mediation, and smart contracts.
The test for "non-custodial"
A useful one-line test: if a support employee could move the funds on their own, it is custodial. Real non-custodial escrow means the money sits under rules that no single party, including the platform, can override. Trades settle to your own wallet, not to an internal balance.
Everything below passes that test. They just pass it differently.
1. A 2-of-3 multisig (HODL HODL)
HODL HODL locks each Bitcoin trade in a 2-of-3 multisig address. Three keys exist; any two can move the coins:
OP_2 <buyer> <seller> <escrow_agent> OP_3 OP_CHECKMULTISIG
- Buyer and seller agree: two signatures, the coins move, nobody else is involved.
- They disagree: the third key signs with whichever side the dispute process favours.
Strengths: plain Bitcoin script, nothing exotic, and the coins sit on-chain where anyone can see them.
Trade-offs: on-chain fees and confirmation times, Bitcoin only, and no built-in clock. If one side goes silent, someone still has to act on the dispute.
2. Lightning hold invoices (RoboSats)
RoboSats does escrow without an on-chain address at all. The seller pays a Lightning hold invoice: the payment is locked in-flight, not settled. The preimage that would settle it is only revealed once the buyer confirms the fiat payment, and if the trade fails, the invoice is cancelled and the sats return to the seller.
Strengths: fast, cheap, private (it runs over Tor with no registration), and nothing ever lands in a long-lived escrow address.
Trade-offs: hold invoices tie up liquidity along the route while they are open, so trade sizes are modest by design, and you need a Lightning wallet ready.
3. Security deposits and mediation (Bisq)
Bisq is desktop software rather than a website, with trades negotiated peer-to-peer over Tor and no central order book server. Both traders post security deposits alongside the trade amount, so each side has something to lose by misbehaving, and a mediation process handles disputes.
Strengths: no company acting as coordinator, strong privacy, and a deposit that makes stalling expensive.
Trade-offs: a heavier setup than a web signup, thinner liquidity, and deposits that raise the capital you need to trade.
4. Smart contracts
The fourth design moves the rules into a contract. Funds are locked in a contract that releases them on explicit conditions:
// simplified
function release() external onlyBuyer { _pay(seller); }
function claimAfterTimeout() external onlySeller {
require(block.timestamp >= deadline, "review window open");
_pay(seller);
}
function rule(uint8 ruling) external onlyArbitrator {
ruling == 1 ? _pay(seller) : _pay(buyer);
}
Strengths: timeouts are part of the contract, so a silent counterparty cannot block the other side forever. It works with stablecoins, which removes the incentive to stall a dispute while the price moves. And the arbitrator can be a decentralized court such as Kleros instead of a single person.
Trade-offs: you are trusting the contract code, so it needs to be open source and verified on a block explorer. And a contract on its own is not a marketplace: it settles a deal, it does not find you a counterparty.
Side by side
| Multisig (HODL HODL) | Hold invoice (RoboSats) | Deposits (Bisq) | Smart contract | |
|---|---|---|---|---|
| Where funds sit | On-chain 2-of-3 address | In-flight Lightning payment | On-chain, with deposits | Contract you can inspect |
| Silent counterparty | Needs the dispute key | Invoice expires or is cancelled | Mediation | Built-in timeout |
| Assets | BTC | BTC (Lightning) | BTC and others | Stablecoins and tokens |
| Finds you a trader | Yes | Yes | Yes | No |
The question to ask first
The most useful question is not "which is best" but "do I need a marketplace, or do I need escrow?" If you want to be matched with strangers to buy or sell Bitcoin for fiat, you need a marketplace, and the first three designs are built for that. If you have already agreed a deal with one specific person (an OTC trade, a freelance milestone, a domain sale), the order book is overhead and a plain escrow contract is the narrower tool.
For a fuller comparison of the platforms themselves, including which ones have shut down and which fake "revived" versions to avoid, see our write-up of Hodl Hodl alternatives, which covers Bisq, RoboSats, Peach and LocalCoinSwap in more depth.
Disclosure: I work on Vaultion, a non-custodial smart-contract escrow, which is the fourth design above. Platform details change, so check current rules on any service before trading. This post was drafted with AI assistance.
Top comments (0)