Ah, my recollection was that only a fixed (large) set of parties could challenge the withdraw with the fraud proof, so it was also a security assumption, but maybe that was BitVM v1? The nice thing about the BitVM machinery even in that model is you get 1-of-N liveness *and* 1-of-N security which is...