0:00 Oh, here we go. Nice. And now here we all are. 0:05 Happy Friday to everyone. 0:10 There was some big, not sidechain news, but L2 news. 0:15 Just broke. Sort of. 0:19 I actually haven't really looked into it, but apparently this Lightning channel jamming thing is... 0:26 I remember seeing someone give a talk at MIT this year, but apparently it's worse. 0:35 I mean, I kind of always thought where Lightning really starts to run into problems is when you go through people. 0:43 The bidirectional payment channels are sort of fine enough, but when you have to route them through third parties, 0:52 that is when it really requires a lot of effort to keep it working. 0:58 And this is the new thing. I mentioned this many years ago about channel risk, 1:03 about if you open the channel with the wrong person, you may regret it. 1:08 But I don't know if we want to touch on this. It's so new. I haven't really had a chance to look into it at all. 1:14 We already have too many new things. The BitVM is already too new. 1:21 I haven't heard of it, so if you could link it. Happy Friday, by the way. Can you hear me? 1:26 Yes, I can hear you. Link it. Yes, let's put it. We'll put the link in. Let's get that link. 1:33 Yeah, I'm quoting this person. They made this public post. 1:39 The public post is from Antoni Riard, and they have a very salacious sentence. 1:47 They're very serious in their conviction, so I quoted it. 1:53 Hopefully, it's not too impolite, but anyway, there it is. 2:02 But you never know. 2:08 I'm not sure we should even go into it, because Lightning already has many unfixable problems, in my opinion. 2:17 And there's really nothing wrong with Lightning, per se. 2:20 If I can just maybe give a little bit of a take here. 2:25 It has nothing to do with the people working on Lightning, and it has nothing to do with the Lightning design. 2:29 It is the people in the audience, who are the Lightning fanboys, who basically have turned the idea into a weapon against Bitcoin success. 2:42 Because they turn it into Scaling Messiah, and then it's just like, the idea you can't criticize, and then it warps everything. 2:51 And then you have people who really don't, you know, the non-technical people just get fed a version that is completely false. 2:58 And then they make, they make, they form a worldview around that mistaken idea. 3:11 Well, there you go. 3:12 But that's hot news. 3:14 But maybe we'll return to it if no one, if people haven't looked, I haven't looked into it. 3:20 Willem hasn't looked into it, so. 3:23 No, I haven't. 3:24 I think in general, coming back to Lightning, I think the base protocol seems fairly easy. 3:31 But as with anything, the devil is always in the details and implementation. 3:37 And so I think that's something generally for any sidechain, really. 3:40 Like even an idea as Lightning, just some hash, time locks, and two out of two multisigs. 3:49 Like even an idea as simple as that eventually becomes very, very difficult and a lot of different effect factors. 3:54 So I think something generally we need to be aware of. 3:59 Indeed. 4:00 Okay, so what should we do here exactly? 4:02 My guess is that most people listening to this either now or with the recording later, they will probably like be, my guess is those people are all like pretty confused about BitVM and maybe Spiderchain. 4:19 Maybe they know Drivechain a little bit better because we do the space every Friday. 4:24 Maybe not, though. 4:26 I'm not sure. 4:28 So should we just do the song and dance where we explain our idea again? 4:35 I think what probably a lot of people would want to get out of this is if we compare and contrast the ideas somewhat. 4:42 I mean, BitVM is like you and I would sit down and we want to bet half a Bitcoin on a chess game. 4:51 I'm going to give you my take on it. 4:54 And we sit down and I compute all the possible moves that I could make as white right now. 5:02 And then if I do anything else or if I don't make one of those moves, I have constructed something where you can, you know, the chess opponent like Robin and I are going to play chess. 5:14 And if I either don't move at all within the amount of time or if I make some kind of illegal move, then the my money goes to my money is slashed from me and goes to Robin. 5:30 And so then I move pawn to E4 and then we recompute it again and we do it again. 5:36 Except with Robin has to reply in time. 5:40 And then at the end, it says if someone is in a checkmated state or whatever, then the other person wins. 5:47 And if there's a stalemate, I guess there's a refund or something. 5:50 Is that like a good way to think about it or what do you think? 5:56 Yeah, kind of. But you do the calculation only once at the end in the case of a game. 6:03 Like in the case of a game, you have two phases. 6:05 First phase is we do our moves. 6:09 And then we get to a stage where one party says, OK, the game is over. 6:15 And then we evaluate the circuit given the inputs, which are the moves that we made. 6:22 And then the circuit evaluates to either true or false. 6:26 And if it evaluates to true, then it means you won. 6:29 If it evaluates to false, then I won. 6:32 But isn't there a time right before the game starts where we have to both agree how much money is? 6:39 Don't we fund the transaction first? 6:44 Don't we have to do... 6:48 That's the part that I think I don't get, really. 6:52 On L1, I'm putting this into some kind of... 6:57 What is it being put into on L1? 6:59 The two of two. 7:01 We just create a joint output where both our money is in. 7:05 And then we do this challenge-response game. 7:10 We prepare the challenge-response game for that output. 7:15 And then at the end, one of us could run that challenge-response game with the other one. 7:25 Yeah, but surely you can't actually compute... 7:29 Isn't it has to be something the way I said? 7:31 We agree to play chess, but we can't possibly... 7:38 How do you know whether or not you've broken the rules on the first... 7:45 We sit down and we pay to do two of two. 7:49 And then it will leak the other person's key if the circuit... 8:00 I still don't really get... 8:02 What I'm confused is you can't pre-compute all the chess moves possible because there's far too many. 8:10 Yeah. 8:11 But we have to do something when we fund the transaction. 8:16 And then there has to be something... 8:18 So we fund the transaction and then the next step... 8:21 How do I know that we're playing chess and not checkers, basically? 8:25 Yeah, we do commit to a program that can evaluate a chess position and say if you won or if I won. 8:33 Yeah. 8:35 Okay. 8:38 But I think this is also the right way to just think about it in general, right? 8:43 Because people cannot really join or leave this, as I understand it. 8:50 So it is a lot like a bunch of people get together and play a game of some kind. 8:54 Yeah. 8:56 It's probably the most easy way for most people to understand it. 9:02 Yeah. 9:04 And you don't have a global state, like there's no blockchain. 9:07 There's no... 9:10 Right, because a blockchain is kind of like... 9:14 You can generate it in the privacy of your own home with all the blinds drawn and all the windows closed. 9:24 You can generate as many keys as you want and then start sending coins to those. 9:29 So it's like the blockchain has this ability to add new people in all the time. 9:36 But this does not, right? 9:38 This is like people already exist. 9:40 Well, I'm not sure. 9:42 Maybe it does. 9:44 I don't know. 9:46 Maybe there's some kind of CTV thing. 9:48 That is the main drawback of the BitVM that it is limited to this prover verifier setting. 9:54 What you can do is that you have multiple verifiers. 9:59 So that is interesting, for example, for a two-way pack. 10:02 You could have a prover that facilitates a two-way pack between two chains. 10:08 And then you could have many verifiers, let's say 100 verifiers. 10:14 And each of them can challenge them in parallel. 10:17 And if one of them gets to the end or disproves the prover, then they can punish the prover. 10:28 Hmm. 10:30 Maybe we can do an example with actual numbers. 10:38 You have 100. 10:40 Well, how does it work if there's 10? 10:43 So how would it work in the parallel case where someone wants to... 10:52 Here we all are. 10:55 Someone opens BitVM. 10:57 They want to make a new extension block or some kind of zone, like a roll-up zone or a payments zone. 11:06 And so we're going to do the two-way peg. 11:11 So what do they do next? 11:15 Yeah, there would be the prover that first has to put up some deposit to incentivize them to stay honest. 11:27 And then they could pack BTC to the other chain or people could just send money to the prover's address. 11:35 That's how they peg in. 11:37 And the peg out is just the prover sending the money to someone else. 11:42 And the verifiers, they would verify that this someone else is actually someone who pegged out in the sidechain. 11:52 With the prover address that you just mentioned, is that a separate address or is that the address where the BitVM is deployed? 12:02 That would be a separate address. 12:04 Separate address. 12:06 So you need introspection, basically. 12:08 Yes, exactly. 12:10 Essentially, it's introspection. 12:12 You use the BitVM to do introspection on the transactions that the prover does. 12:17 On the peg out transactions that the prover does. 12:20 Yeah, that works, I think. 12:24 The only limitation is then the size of the stake of the prover, so to speak. 12:30 Yes. 12:32 The prover probably has more money than is locked in the sidechain in that simple case. 12:39 Maybe you can optimize it, but in the simple idea, it would be just if there's one BTC in the sidechain, 12:45 then the prover would have to put up 1.5 BTC or something to hold him accountable. 12:56 That's pretty interesting. 13:01 Yeah, I don't know. 13:03 A lot of these have this interesting feature of people putting up the L1 coins or they put up some kind of coins that will be slashed later if they do the wrong thing. 13:12 It's interesting that the regular real world operates often in almost the reverse way. 13:20 Not saying that that's good or bad. 13:22 It's probably bad, in fact, but it's just noteworthy that the real world has credit, where it's like no one has anything up. 13:30 They just say, I will pay you. 13:33 We will do this the right way, and then if I don't, then I will pay you $10,000. 13:40 And often, no one puts up anything. 13:44 Although, of course, sometimes they do. 13:46 They put escrow, but often they don't. 13:50 So that's a neat idea. 13:52 Okay, cool. 13:54 We'll turn to a spider chain, but I think probably the best thing of all would be if the audience would ask questions. 14:04 Because I don't know if the three of us talk to each other. 14:08 I'm not sure if anyone will get anything out of that. 14:10 I mean, I hope they do. 14:12 We could each compare and contrast the three the way we see it, I suppose. 14:18 Okay, well, let's go to spider chain. 14:21 My understanding is spider chain is something where there's lots of multi-sig outputs, and then there's something on top. 14:28 Kind of reminds me of Counterparty, but it's not really like that at all. 14:33 There's things like Bitcoin Core, Bitcoin Core Plus, you know, spider version, into the spiderverse. 14:40 And it is keeping track of who has staked coins, kind of like a BitVM. 14:47 People have staked coins, and in return, they are allowed to spend away other coins that are in the multi-sig. 14:56 If either someone's following the rules, or in the case where someone is breaking rules and is doing the wrong thing, or if enough of them, each conspire to all break the rules. 15:09 But it's kind of a similar idea where you have to have lots of different people involved, and it's very easy for them to coordinate on the truth, because that's all just automatic. 15:19 But to get them all to steal, they would have to coordinate amongst themselves first, which is harder to do. 15:29 I'm not sure if that is how you would explain it, but I'm thinking of there's many, many UTXOs in the spider chain world. 15:37 Every time people are making new, when they deposit, they make new multi-sig UTXOs that are all partly controlled by this big group. 15:46 Hence the whole web thing. 15:50 Yeah, that's the way to see it. I don't really think that's going to be an issue, the amount of UTXO, because in the end, it's all on Bitcoin that you can see it as well. 16:03 The best way to explain the spider chain is, you basically have a bunch of decentralized multi-sigs that are controlled by the staker set. 16:16 For example, you have 10,000 different stakers, they all put a certain amount of Bitcoin in those decentralized multi-sigs, and that basically secures a second layer, or the EVM. 16:31 And then there's a second very interesting part of the spider chain is that it has forward security. 16:38 So basically, even if you have two thirds, you lose control of two thirds majority of the stakers that they can still not steal any Bitcoin. 16:50 I hope that explains it a little bit. 16:54 In the sense, in general, inside chains, I always think you have two big parts. 16:57 One part is how do you lock the assets? 17:01 And then the second part is the consensus. 17:04 Basically, how do you build the blocks in the second part of the chain? 17:08 Compare that to a Drivechain, you basically have BIP300, I think, for the asset locking mechanism, and then you have merge mining for the second part. 17:18 And then BitVM is actually, I think, it's more a lower level, basically, circuit that allows you to build different types of sidechains. 17:33 So for example, in the spider chain, when we say decentralized multi-sigs, what it actually is, it's like a small BitVM in the sense that we build a Boolean circuit in every multi-sig wallet. 17:47 That basically holds that Bitcoin. 17:50 That basically acts very similar to the model or the optimistic proof that we see in BitVM. 17:59 So I think it enables, BitVM kind of enables way more types of sidechains. 18:05 So I think it eventually becomes very compatible. 18:09 And then maybe the last thing I would say is in the spider chain, we actually optimized for fully decentralization and liveness. 18:18 Since everyone will be able to run a full node, the exit and entrance of new node runners becomes very easy. 18:26 So basically, you can have an unlimited amount of people running the sidechain and verifying the sidechain. 18:35 Well, that's a short summary. 18:38 Yeah, that's pretty interesting. 18:41 Could you go over again that part about even if you lose two thirds? 18:46 I guess maybe, should we all just say what would be the worst case scenario for our thing? 18:53 I don't know. Probably not. 18:55 But you said about if you lose control of two thirds, then you said still that's not enough. 19:01 I thought I was reading Jameson Lopp's summary of it. 19:04 And he was saying something like, if you have enough of the stake, you can start just emptying it and giving it to yourself. 19:13 I thought maybe. 19:15 Did you think he had a fair summary or no? 19:18 Usually, Jameson Lopp is pretty good. 19:20 He's got a very good summary. 19:23 He very quickly understood it. 19:25 But he doesn't say that exactly what the attack factor basically is. 19:30 Anyone with two thirds majority of the stake can hold the sidechain. 19:34 So basically, the sidechain will stop producing new blocks. 19:38 However, they will not be able to steal any Bitcoin. 19:43 And that's basically what we call forward security. 19:46 It comes from forward secrecy in encryption. 19:49 Basically, because we have sequential multisig generated over time. 19:54 That means that older multisig wallets are basically controlled by older established stakers. 20:04 So at a certain point in time, if you lose control of two thirds of the orchestrators, all the previous multisigs are actually still secure. 20:13 So only the future multisigs that are being created from that point onwards are insecure, so to speak. 20:24 So the older Bitcoin is still secure. 20:27 And yeah, the worst case scenario. 20:30 I'm happy to talk about that. 20:32 I think in our cases, that's very clear. 20:34 Basically, you lose two thirds majority of the staker set. 20:39 And then the chain halts. 20:42 That crowds out any people. 20:44 And then basically, the chain is dead. 20:47 And everyone will still be able to get their Bitcoin back. 20:53 But yeah, the chain is basically halted. 20:56 So it's no longer useful. 21:01 Well, that's not so bad. But I still don't understand what's happening on L1 when you say they get their coins back. Like, to me, it's like you deposit the coins into something else. Then something else is happening. Like I got was deposited into SpiderChain. Then I bet them on, you know, an NFL game. And now maybe I won, maybe I lost. It seems like it's not happening anymore. 21:26 Yeah, there's a difference between L1 and L2. You can basically L2 Bitcoin, which you can always trade to L1 Bitcoin. 21:57 Right. But I thought you were saying everyone can get their money back. You mean, so like, if the new owner who wins the bet on L2, they can always get their money back on L1, even if everything goes away. 22:09 Yeah, we'll have to be coordinated by the orchestrators. There's actually an opportunity to improve that part later on where you can unilaterally get Bitcoin back. 22:20 If you build like a Boolean circuit with a Bitfm, that's definitely possible. So I think longer term, there might be an opportunity to do that. In the short term, basically, once the chain is taken over, you can coordinate with the orchestrators to distribute everybody's L2 Bitcoin to L1 Bitcoin very easily. Just send out all the transactions. 22:51 But that's the worst case scenario for the spider chain, how it's designed at the moment. 22:57 Maybe you could go over again, like all the different groups, the orchestrators, the regular user deposits. So like if I want to deposit a spider chain, I go to like whatever spiderchain.com or something, right? 23:13 I download some software, and then I send BTC to multisig on L1. And the multisig is between me, I assume, me and someone from the orchestrator set. Right. So what's the L1 multisig? 23:33 Yeah. Very good question. So basically, how it looks like is very similar to Arbitrum, if people have used that. You just go to the Botanics Bridge website, you send, you connect your Ethereum address, your EVM address. 23:52 From that, we will generate a certain Bitcoin address that has this Deproot circuit or Deproot tree behind it that connects your EVM address to that specific Bitcoin address. And that is a multisig address that is shared between a random subset of all the orchestrators. 24:15 So for example, 100 orchestrators randomly chosen out of 10,000 stickers. And that basically, that transaction, once confirmed, will give you back Bitcoin on the second layer. Now the actual Bitcoin on the layer one is then secured in that single multisig with a Deproot tree in it. 24:39 Yeah. And the idea is those people could take the L1 coins, but if they do, I will get reimbursed or they will get punished by the other orchestrators, something like that. 24:53 Yeah, correct. It's similar to what we've discussed on the BitPM 2 way back, Robin talked about earlier. The moment that happens, all the orchestrators, their stakes get slashed. 25:07 Every orchestrator. 25:09 That is part of that maliciously signed a malicious transaction. 25:15 Yeah, it's only the ones who did the wrong thing. Yeah, of course. 25:18 And so they get slashed and their funds go to the other orchestrators or to miners or where do they go? 25:27 The slash goes to the one who reported it. 25:32 Oh, that's cool. But 100% of it or? 25:37 Yeah, the idea right now is 100% that makes the economics the most sense. Basically, if you remember Jameson Lopp's article, he talks about capital efficiency, and it's the same issue we basically discussed earlier with the BitPM. 25:53 If the orchestrator or the staker only has a stake of 1.5 Bitcoin, then basically you can only really secure one Bitcoin. 26:04 Now, if you suddenly have 100 stakers that, for example, stake one Bitcoin, then you can have at max stake 100 Bitcoin there, right? 26:14 Because now there's 100 different stakers that all stake one Bitcoin. 26:19 But now if actually there's an incentive for all the rest of the people to actually report malicious behavior, they can get all the staking rewards. 26:30 So anyone who reports could possibly get up to 99 Bitcoin of all the rest of the malicious stakers, so to speak. 26:38 I think Robin has had some similar ideas on that in the case of a one-to-N multiparty system. 26:47 It makes your capital efficiency of all the stakers way higher, basically. 26:53 Sure, but I want to use Spiderchain. They give me the address. 27:02 It turns out Flavor is the guy who's supposed to be watching my coins, and he will get slashed if he does the wrong thing. 27:13 But what if he does the wrong thing, and then he reports it also? 27:18 Then he gets the money just going from one pocket to another, it seems. 27:22 Yeah, exactly. But it depends if other malicious people join as well. 27:30 So if other stakers also maliciously sign that same transaction, then he lures some people in. 27:40 But of course, he'll always pay transaction fees, etc., and he'll have to exit. 27:49 So it's a game where there are zero things to win. It doesn't hurt the system, but yeah, it's possible. 27:56 Well, I thought it was something like if you have two-thirds of the staker set are all the same person, 28:03 then can't they just basically take all the, quote, deposits and then report themselves? 28:11 And then they collect the deposits, and they collect the slash from themselves. 28:17 And that would seem to be the losers would be the last third who weren't in on it. 28:24 So now you have to differentiate between the whole network and a single multisig, because it's a different game theory. 28:32 A single multisig versus the whole network where you could have two-thirds majority, and that's where the forward secure. 28:40 So for the whole network, let's say you have two-thirds majority of the whole network. 28:45 You don't have two-thirds majority of every single multisig. 28:50 Actually, you don't have any two-thirds majority of any previously generated multisig. 28:57 So basically, the only thing you can do is try to convince all the others to join you, but then basically... 29:06 Well, sure, but I mean, that's just a slightly different setup. 29:09 I'm the first. I put all of the money. The spider chain has started, and I put all of the money in. 29:15 I have 100% so far. I put 100 Bitcoin in, and then someone puts whatever it would take to make that number work out. 29:26 I guess they put 50 or they put 49 in. 29:30 The next person puts 49 in. I have two-thirds, and I have the oldest two-thirds. 29:36 I know it's kind of implausible, I suppose. 29:40 But in that scenario, I can take all the deposits and the... 29:46 Do I also take the 49 that are the latest? Probably not. I'm not sure. 29:52 Yeah. So now you're initially in the first phases. 29:57 When there's zero Bitcoin staked, yes, you're feeling very vulnerable to that. 30:02 But yeah, it becomes way more secure once you grow the system. 30:05 Because basically, you will start off as a federation as well. 30:09 Basically, a permissioned staking federation where people can stake with federation partners. 30:17 Until you have enough Bitcoin staked, and then you can become fully permissioned. 30:22 And then if you try it again, then it becomes very costly. 30:26 Cool. I think probably some people that I know, they will want to ask about 30:34 what happens if 51% L1 miners try to interfere with your thing? 30:41 Because of course, in Drivechain, it's not very good. 30:43 They can interfere by just taking everything, basically. 30:47 However, it seems also that this... I had a conjecture many years ago 30:51 that this is kind of always true for anything, which has been kind of borne out by the Lightning Network. 30:59 And so in BitVM, I think it also applies where if you're playing the game against 51% miners, 31:12 the game of chess or whatever, they also know what message to refuse to allow in. 31:19 And they can time it out, take the funds, which I think must be universal. 31:27 But maybe not. I don't know. 31:29 I don't know. Maybe it's not a very interesting question. I'm not sure. 31:34 So what would the 51% do exactly? 31:40 Because I think in the case of the SpiderChain, they can halt leg outs. 31:45 They can halt the finality. 31:47 Basically, you would only get finality after, I don't know, whenever you post a route back to Bitcoin. 31:56 But since we'll probably do a week delay for stakers to exit, 32:01 they would have to halt for a week in order to make the long-range attack possible. 32:06 So I don't think really there's an attack factor there. 32:10 Yeah, there probably isn't. I think you're right. 32:12 Since it's an L1, it's just a bunch of multisig. 32:19 So you can hold them hostage, of course. 32:22 I mean, 51% hashrate can always hold something hostage. 32:26 But anything with those timeouts, the hostage situation is much worse. 32:32 But there are none in SpiderChain. 32:35 There's no like, you must do this by this time or else. 32:41 You know, like an HTLC, right? 32:44 Is there any equivalent of an HTLC in SpiderChain? 32:49 No, not really. 32:51 And even if you lose 51% of the miners, 32:55 then whenever a transaction gets confirmed by the other 49%, you're still fine. 33:00 So yeah, I don't think the SpiderChain is really vulnerable to the 51% attack. 33:06 Yeah, probably not. 33:08 Robin had a weird connecting thing, and then he's dropped down. 33:13 He'll probably be back up soon. 33:17 This app is very buggy, honestly. 33:20 The spaces. 33:22 I mean, it is for me. Other people seem to have no problems with it. 33:25 Got a brand new phone, and it still doesn't work. 33:28 It's very buggy. 33:30 We also have a flavor. 33:32 I think it's good. We should get the audience people up here. 33:35 Breathe some more life into the conversation. 33:44 Can you hear me? 33:46 Yes. 33:48 So I wanted to ask questions that were a little moving away from the technical side 33:52 and just get more of a background on Willem and his kind of experience in Bitcoin 33:57 and the inspiration behind SpiderChain. 34:01 And as a bonus question, did Drivechains inspire SpiderChains at all? 34:08 I kind of had that question for both Willem and Robin. 34:15 I think I can go first. 34:18 So in background, I grew up in Belgium. 34:22 I lived most of my life there, actually. 34:25 I have a mathematics background. 34:27 Came 13th National Mathematics Competition. 34:30 And that's actually where the name Botanics comes from. 34:33 As a prize, I got this book about mathematics in nature. 34:38 Very big prize. 34:40 All about trees and basically all the fractals and et cetera in nature 34:48 where you see the Fibonacci sequence. 34:50 Then ended up doing electrical engineering. 34:52 Then in the master's, focused on cryptography. 34:54 So I broke some authenticated encryption algorithms 34:58 where I broke one of the algorithms by breaking the forward secrecy, 35:03 which is basically the forward security used in encryption. 35:07 So that came into play in the SpiderChain. 35:10 Then ended up doing something completely different. 35:12 Went into chemicals, moved to Saudi Arabia 35:15 and basically only really saw the Bitcoin macro picture. 35:20 When I went to Lebanon, saw hyperinflation happening, 35:24 put everything together very quickly. 35:27 And then basically became a very big Bitcoiner. 35:31 Then moved to the US, to Boston. 35:36 Now recently, last two weeks, moved to New York. 35:39 Missed you yesterday, Paul, unfortunately. 35:42 And basically like a year and a half ago, 35:45 tried to figure out how to basically build sidechains on Bitcoin. 35:51 Because I started to realize, okay, now you have Bitcoin. 35:54 It's going to take over the world. 35:56 How is the world looking that fully runs on Bitcoin? 36:01 Basically means our whole financial system needs to run on Bitcoin. 36:04 That means all the stock markets, trades, global, yeah, 36:09 insurance, whatsoever, supply chains will run on Bitcoin. 36:12 How does that look like and what you need for that? 36:14 And so at the same time, I saw a lot of applications 36:17 like Dexys and DeFi gain product market fits and gained adoption. 36:22 So I started to realize that the EVM is actually, 36:25 might be a very powerful virtual machine. 36:29 I think we all agree it's not the best, 36:31 but I think there's $200 billion of applications created on an EVM. 36:35 And basically when I started off trying to design the spider chain, 36:39 that boxed me in the sense that I wanted to be able to run an EVM 36:46 and I wanted it to be able to be decentralized. 36:49 I think one of the big issues that I typically always have with Optimistic 36:53 or other type of roll-ups or sovereign roll-ups is that it's always one party. 36:57 So I wanted it to be fully decentralized. 37:00 I wanted it to be able to run an EVM and I wanted it to be able to run 37:04 on current Bitcoin core. 37:06 And that's where Drivechains came in. 37:09 I realized that Bitcoin is falsifying more and more. 37:13 It's very hard to make changes. 37:15 And I did get some inspiration from DriveChains. 37:19 Basically, I think Drivechains showed me that you need two big things 37:23 in any sidechain. 37:25 You need an asset locking mechanism and you need a consensus 37:28 or a sequence for basically designing or deciding the blocks on your sidechain. 37:36 And that drove me like, hey, what if we don't do proof-of-work? 37:42 What happens if we change to proof-of-stake? 37:45 And how can we decentralize the multistakes or the asset locking mechanism? 37:50 That basically was the basis of the spider chain. 37:56 Thanks for answering. 37:59 I was wanting to hear the same answer from Robin, if he'll take that question. 38:06 Yeah, I'm working on ZeroSync, which is applying zero knowledge proofs to Bitcoin. 38:13 Essentially, we are building a validity proof of Bitcoin's chain state 38:19 that allows you to sync full nodes instantly and stuff like that 38:23 or to run a full node on your phone. 38:25 And in general, to make it way more accessible to sync the chain state. 38:31 And yeah, working on that, it became apparent that it would be super cool 38:35 to have a ZKP verifier on the main layer. 38:38 And as William already mentioned, it's hard to change Bitcoin. 38:41 So we didn't really hope for some kind of soft fork. 38:48 I mean, we did at some point or still, we hope for simplicity. 38:54 If there was simplicity, it would basically be a byproduct to implement a ZKP verifier. 39:00 But stuff like an Ops ZKP verifier, that will not happen anytime soon 39:09 because the proof systems are not mature yet. 39:12 And it will end essentially in endless bike-shedding to agree on some kind of Ops ZKP verifier. 39:19 So yeah, in Miami, in Bitcoin Miami this year, 39:25 I met SuperTestNet and also Sam Parker. 39:29 And we were hanging out at the Nostra Beach. 39:33 And we were talking about if there is not some way to hack a ZKP verifier 39:39 into Bitcoin script as it is right now. 39:41 And starting from there, we created the Telegram group 39:47 that was titled Hack a ZKP Verifier into Bitcoin. 39:50 And yeah, we have been bouncing off ideas of each other for like half a year now. 39:57 And yeah, shared all kinds of different approaches that might lead somewhere. 40:03 And then at some point, I read about MET, Merkleis, all the things. 40:09 And then it became kind of obvious that something like that should be somehow possible 40:15 by hacking it into tap roots. 40:16 And that's how the BitVM was created. 40:20 And yeah, was I inspired by drivetrains? 40:23 Yeah, well, to some degree, of course. 40:25 In general, like I've been working on ideas, 40:31 like in general, like on sidechain ideas since like I think I started 2019 to 2020. 40:38 I published my first paper where I wrote about like a Bitcoin-backed proof of stake, 40:41 which is essentially a consensus mechanism that allows you to stake Bitcoins 40:47 in the Bitcoin chain, and then you can vote on sidechain blocks. 40:50 And if you ever equivocate and vote on two conflicting blocks, 40:53 then you lose your Bitcoin in the Bitcoin chain. 40:56 And that is a way to leverage Bitcoin's proof of work to gain sidechain consensus. 41:04 And yeah, I think these consensus mechanisms, 41:07 there are quite a few interesting consensus mechanisms. 41:11 There's like the Bitcoin-backed proof of stake that I just mentioned. 41:14 There is BIP301. 41:16 There is Blind Merged Mining, as Ruben Thompson proposed it. 41:19 There is merge mining, of course. 41:21 So there are quite a few proposals, and some of them are already possible today, 41:27 even though like not ideally, or sorry, not in an ideal way, 41:32 but in some way it's already possible. 41:34 So what's really interesting is the pack. 41:37 And yeah, the two-way pack was the main reason to invent the BitVM. 41:43 And yeah, now we have that solution that is a bit better than what we had before, 41:49 because yeah, it's essentially like a federation, 41:53 but the trust model is reduced in the sense that you have to trust 41:57 that there's at least one honest party. 41:59 You don't have to trust that some majority is honest. 42:01 You only have to trust that there is one honest party in the federation, 42:06 and then the pack is secure. 42:12 Those are really insightful answers. Thank you. 42:16 Sorry, what was that? 42:18 Oh, those are really insightful answers. Thank you. 42:23 I guess I have more questions if nobody else wants to come up. 42:28 So I would say, again, this is a question kind of for both of you, 42:32 but I guess also for Paul, if he wants to answer. 42:37 After having discussed the worst-case scenario, 42:40 what does the best-case scenario look like for either of your ideas 42:45 in terms of adoption, use cases, 42:49 and what kind of roadblocks do you see moving forward for your ideas? 42:54 Shall I start? 42:57 Okay, if nobody else is starting. 43:01 Oh, I mean, hold on. 43:03 There we go. 43:05 For me, the ideal outcome is that we have a free market of sidechains. 43:10 So everybody can create their own sidechain 43:14 and compete with the other sidechains. 43:16 And Paul just said, 43:19 free market of sidechains. 43:22 Paul just changed his mind. 43:24 Thumbs down. 43:26 No free market of sidechains. 43:29 I hit the wrong button. 43:32 All right, thumbs up. 43:34 So, yeah, that would be great for Bitcoin 43:37 if we essentially get all the innovations together 43:42 and have everybody who has great ideas trying it out on Bitcoin 43:49 and no shitcoin thingy around it. 43:54 At least it would be great 43:56 if there would be no justification to create shitcoins. 43:58 And then investors won't buy it, hopefully, 44:01 if the market is as efficient as we would like it to be. 44:08 We would have a free market of sidechains 44:10 and people could just try out ideas for scalability, privacy, utility. 44:16 That would be my idea. 44:17 And the biggest roadblock that I see 44:19 is generalizing the BitVM bridge to more verifiers. 44:25 Because in the model as it is right now, 44:28 you could maybe have a hundred verifiers, 44:30 maybe even a thousand 44:32 if it's okay for you to do lots of setup. 44:36 Or if the setup ceremony is computationally expensive, 44:39 if you agree, if that's fine for you, 44:41 then you might have a thousand verifiers. 44:43 But it's hard to scale it to a million verifiers. 44:47 Or something in the current setting. 44:49 Solving that would be really awesome 44:53 if we could essentially have a million verifiers. 44:57 And if one of them is honest, then the bridge works. 45:00 That would be like the dream. 45:02 Currently, it is limited by the number of verifiers, 45:05 which is the biggest roadblock so far. 45:09 To add to that, maybe Robin, 45:11 I've been thinking about this a lot. 45:15 And you can basically, if you limit to a hundred, 45:18 but you create multiple exactly the same BitVMs, 45:22 then there's no real reason why you cannot go beyond that. 45:26 Like if you take the model of the spider chain, 45:29 you can have 10,000 stickers, 45:31 but every multi-stick is secured by a hundred people. 45:34 You could do the same thing 45:36 where every BitVM is basically 45:39 a different subset of a hundred people 45:42 out of 10,000. 45:44 And then basically you can keep creating new BitVMs 45:49 that run exactly the same circuit. 45:54 Yeah, I agree on that. But that requires more deposit, I think. Like, I think in general, there's that trade-off between how much setup do you, or like how computationally expensive can the setup be? That is one dimension. The next dimension is how much deposits shall the prover put up? And yeah, the more you accept setup costs, and the more you accept deposit costs, the more expensive the setup costs are. I think that's a really good point. 46:21 Yeah. But your provers can be different people as well. If you all run the same circuit, every prover can put in a new stick. 46:40 That's true. 46:41 And then basically you can scale and you have massive capital, the same capital efficiency that you have, that you see in the spider chain, basically. 46:49 But that might cost liveness again. If the pack is facilitated by, let's say, three people, then all three of them have to agree. Otherwise, it stops working. The funds get frozen. 47:06 And in the current setting, what we have is that we really have this one-off-N assumption. And if just one party is honest, then you have both liveness and safety, which is quite strong. 47:19 Wait, your prover always has to be online, right? 47:24 Yeah, of course. Like, you can slash them if they go offline. 47:27 Yeah, exactly. You don't need all parties. You just need some of the verifiers to be online. Same as in the spider chain, really. You only need one of the people to not collaborate and report any malicious behavior, which can be even more trustless. 47:51 I do see that you can get that one-off-N assumption if you have an N-of-N multisig. But that has the problem that you sacrifice liveness as soon as one person is offline. 48:12 Say again? Like an N-of-N BitVM? 48:15 BitVM is one-off-seven. And then we can be certain if one person is honest of that seven people, then nobody will ever steal that money. However, the problem is, if only one of these seven people is offline, then the money cannot be moved at all. So, we sacrifice liveness. 48:37 No, you can have like a threshold multisig, right? Or a threshold signature. 48:44 Then you weaken the other assumption. Let's say we have a five out of seven, then that means there have to be at least three honest people, right? 48:55 Correct. It's a trade-off. 48:59 Yeah, it's a trade-off. And the trade-off you don't have with BitVM in the simple setting where one honest verifier is sufficient for both liveness and safety. 49:11 Yep. No, I was more in general referencing to creating multiple bitvms with multiple provers that put in different stakes that basically can increase your capital efficiency and solve that problem, plus can solve the prover liveness problem. 49:35 Yeah, basically, I can see a spider chain world where basically every multisig is actually a BitVM instead of a multisig. 49:48 That would make sense to me. 49:50 Then you solve the capital efficiency, you solve the liveness. I still have to think more about what you actually put in the BitVM. But yeah, kind of way. 50:05 Also, there is another way that you could cascade the validators or the verifiers. So you could have 100 verifiers who verify the prover. 50:14 But if the prover does something and the verifiers don't act, like they just stay, they just do nothing, or they ask stupid questions, quote unquote, questions that don't reveal the fraud of the prover, 50:29 then other verifiers can slash the verifiers. So the first stage verifiers, the verifiers who are connected to the prover, they could set up circuits with other verifiers that verify themselves. 50:44 So you could have like this cascade of verifiers. And yeah, you could hold the verifiers accountable with other verifiers. 50:54 Yeah, exactly. And then like maybe your first one can have one out of an assumption where you only need one on a certifiers, but basically for the second layer of cascaded verifiers, you can do a threshold, so to speak. 51:10 That makes a lot of sense. And then once you have a threshold, you can probably use like a rose to swap in and out new or old participants if people want to change. 51:20 Yeah. Oh, and another important point is that in general about two-way packs, we have that thing, if that two-way pack just works somehow, even if it's very slow, and if it's cumbersome to use it, it still is of great value because then you can use it to pack BTC to the sidechain. 51:42 And regular users, they can just use atomic swaps between the sidechain and the mainchain. So they do not have to use the pack actually. Only like liquidity providers or like a very small subset of the sidechain users would actually use the two-way pack and all the other users, they just use atomic swaps. 52:05 So for them, it's instant. And only if you use the real bridge, then it's slower and more cumbersome and like you need a bigger amount to pack out and stuff like that. But yeah, it's a great trade off. 52:21 It's in general a great property of two-way packs that as long as they work somehow, they are good enough to work really well in practice because the atomic swaps for the win. 52:35 Yeah, exactly. I think Drivechains had the same idea. I think long-term pool. Yeah, atomic swaps are the best. 52:44 Yeah, so you don't really lose anything by delaying it because it's actually better honestly to split the groups up I think is my guess is that you have regular users who they understand that they want it now, right? They want to swap out quickly and they understand that they pay a fee for that. 53:03 That's what most regular people want. You hire a plumber or something. You pay, but you get what you want and you don't have to do anything. But you do Uber Eats. You get your food, you pay, but you get what you want. 53:17 And it's better to just split it into like an employees only section where the people swap. The people are swapping slowly and they're the ones that actually care about the minutia of each sidechain and whether or not it has ZK proofs or whether or not it's like Zcash where there might be hidden inflation bugs. 53:34 They all care about this and they make the market on the instant swap outs, but most regular people don't do it except in the case where someone is like handy around the house. They fix their own pipe. So they change the oil in their own car or something like that. It's just better to split them up. 53:55 Yeah. 54:00 Cool. We have Satoshi Indeliers here. He's now a wizard. So congratulations. 54:06 Thanks. 54:08 Thank you. Hey, what's up guys? I'm not as familiar with the flow yet for the approver and verifier of BitVM, but I have a question. Does the verifier have anything at stake? 54:21 Yes. 54:23 You want to disincentivize the verifier from starting baseless disputes. If the approver was honest. 54:33 Does it cost anything for the approver? If it's a baseless dispute, is it really that costly for them to just disprove it real quick? 54:40 Yeah. They have to participate in this challenge response protocol and they must do a few transactions back and forth and the loser should pay all the transaction fees. 54:55 I see. Because what I was thinking of is to solve the 100 verifier thing, maybe you would have a verifier where the public key is known for other people, but it seems like you can grief it. 55:08 Yeah. You can ask like, quote unquote, stupid questions. You can ask questions that don't reveal what... 55:16 Does it cost anything to ask? Is that an on-chain transaction? 55:19 Yes. In the worst case, yes. I mean, you can always do everything off-chain as long as both parties collaborate. But when one of the parties is lying, then they will try to drag it out as much as possible, of course. 55:39 Is there any way to have a verifier that cannot do on-chain, they can only do off-chain, this way you can make that known, that public key? And then if there is a dispute, some potential, then other verifiers would be like, oh, okay. And then they'll do it on-chain. 55:57 Not really. I mean, these hash commitments definitely allow you to do all the steps off-chain. But the problem here is that in the very worst case, the prover just stops responding, right? They don't answer anything. And then you have to force them to give you a response. 56:20 But then you'll still need somebody that's going to take it on-chain. 56:23 Yes. 56:25 Okay, thank you. 56:26 The best thing you can, you said you are not that familiar with the internals of the BitVM, and I have not explained them publicly that well. These ideas of having low-level circuits, but on the other hand, having actually a virtual machine, and then you can commit to state transitions of that virtual machine, and then you use the circuits only to disprove an incorrect state transition of that machine. 56:53 That is the current idea, how to build all that. And yeah, that search in that state transitions, that would be just like, state is just the Merkle root of the memory of the machine. So that's essentially a hash that you commit to. 57:13 And the verifier would have to do a binary search in the state commitments of the prover, like the prover just, he commits and says, yeah, state one led to state two, and state two led to state three, and so on, and so on, and so on. And then the verifier has to do binary search over these states to find the first faulty state to disprove it. 57:37 And in particular, the first thing that binary search, it's quite deterministic. So it is, at every step, it is clear what the verifier would have to ask. And that's why you could have a verifier. 57:51 Like, everybody could be the verifier in that case. And if they ask a stupid question, you can slash them for that. Like, you can prove that this question was not the most efficient question that they could have asked. And yeah, you can punish them for that. It adds more complexity, but it seems possible. 58:11 And the verifiers can be like a dynamic federation of newer ones coming in, previous ones being removed, and things like this. 58:19 The idea behind this is that everybody could be a verifier and that they don't have to sign up at all. In the first place, they could just like, come in later and say, Okay, I will do one step of the protocol now. And I put up this deposit. And I do my one step and then there's a timeout phase where other people could challenge them and be like, Hey, you know, the question that you asked is not the most efficient question that you could have asked. So you get punished for it. 58:45 This way, it might become open, like that might solve the main pain point and that might allow everybody to be a verifier, which is kind of like... 58:56 In that case, if a person does have enough funds, then they can ask their stupid question and then other verifiers that they control can say that it's fine as long as they have enough funds to attack it this way. 59:09 Yeah. 59:16 Okay, yeah. So making it all similar resistant is important, right? But maybe the funds might be enough of a detractor, but still, you know, it can get annoying if somebody really wants to attack. 59:30 Yeah. 59:31 Another basic question is, with these type of sidechains, I assume you can have merge mining and Blind Merged Mining as well, right? 59:38 Yes. 1:00:09 But in a proof of stake algorithm, you can have a huge asymmetry because the cost of producing the chain is just the time value of the Bitcoins that are at stake. But the cost of attacking the chain is like the actual value of the Bitcoins, which are... 1:00:26 But if it's not contributing to the base layer security, do you see that as an issue? 1:00:32 You mean like if they are not paying enough fees? 1:00:38 I'm saying if you have the sidechain running its own proof of stake consensus and... 1:00:43 No, no, no. This proof of stake consensus would be like Bitcoins staked in Bitcoin, in the Bitcoin blockchain. 1:00:50 Right, but who's earning the fees from this? 1:00:54 If it's open for anybody, then it's not the miners. And if it's not the miners, then it's not going to base layer security, right? 1:01:03 Yes, that's true. That's a drawback. Definitely. 1:01:08 So that being said, do you still think the proof of stake is better? Wouldn't it be better to add to layer one security instead? 1:01:18 Yeah, I mean, it would be definitely ideal if fees go to the Bitcoin miners and then you add to the base layer security. That would be ideal. Definitely. Yes. 1:01:31 I think I need to chime in here because I've had a lot of those discussions about like, if you have all layer two and all the fees end up being generated on layer two, like what does that leave to the miners on layer one? 1:01:47 And I actually don't think that will be an issue because there's a very big incentive for anyone who's running layer two protocols or sidechains to have sufficient security to go back to the layer one. 1:02:02 So there's multiple ways to basically accrue more of the fees generated on layer two to let that accrue back to layer one. And it's in the incentive of the layer one sidechain node runners to basically do that. 1:02:18 So I think that's trying to come up with a very interesting incentive model that's way down the line. I think generally that will not be an issue. 1:02:29 But what do you mean though about, can you give an example of a way that the L2 people would pay L1 that does not have some kind of like collective action problem, which I think is what usually kills that type of thing. It's like a volunteer, you know, you just like voluntarily giving up money. 1:02:49 I can think of a scenario. If you have this layer two that is proof of stake or whatever, if it needs to anchor to L1 anyways, the miners can say, well, if you want to anchor to L1, here's the fee, right, ultimately. 1:03:03 Exactly. 1:03:05 Oh, yeah, that could be a good idea. But of course, doesn't it give them an, you know, how many, the question is like, are the bytes fungible or not? And it seems like they sort of must be to some extent. 1:03:23 I mean, maybe not, because, I mean, what I'm getting at is they have this way of anchoring to L1. 1:03:30 The picture is something like this. The L2 is making $50 million a day in fees. It's collecting $50 million a day for fees. And then they decide, well, we want to give some of this to the L1 miners. 1:03:44 But there's a rival L2 that is also collecting $50 million a day in fees. And so then the miners, from the miners point of view, they're going to say something like, listen, we know that you guys anchor into L1, like here and here. 1:04:02 So if you want that block space, we're charging you, you know, $25 million a day or whatever it is. And then it seems like the L2 can just innovate, excuse me, a different way of anchoring, and it's kind of cat and mouse. 1:04:21 Or it seems that one of the L2s is at a disadvantage, because it will voluntarily be paying for L1. This is the collective action problem I mentioned before. It will voluntarily be paying an L1, and the benefit will go to both L2s. 1:04:35 So it's just kind of, you get the same amount, regardless of how much you, everyone gets the same amount, regardless of how much you individually pay, which probably won't work. 1:04:48 Well, in this case, if there's an infinite amount of ways that they can anchor, well, then you can't stop them, you can't force them to merge mine no matter what anyways. 1:04:58 Right. 1:04:59 Well, the idea being, the way 301 was designed was, imagine they wanted to like vertically integrate but specialize. 1:05:14 How would they accomplish that the best way for them all? Because the idea of 301, because what they could do is they could just try to say, we hold this hostage, we censor everything of this shape, or something like that, which may destroy a bunch of legitimate L1 use cases. 1:05:32 But I think it doesn't matter whether they can or they can't. 1:05:38 If they can't stop, if they can't hold L2 hostage, then you have the collective action problem, and the fees don't go to L1. 1:05:47 But if you can hold it hostage, then you have a conflict between L1 and L2, because L2 has all the money and L1 can hold it hostage. 1:05:57 So I think the problem kind of appears either way you go around that mountain. 1:06:08 I think in general, it's very hard to predict how this will play out. There is, though, a very big incentive. If the fees are too high on layer two, people will just go back to mainchain. I think that's one thing I think we'll see play out. 1:06:20 The second thing is something we have already seen play out, and that's what's been happening on Liquid. 1:06:26 So when you think about how Liquid is implemented, they put their transaction fees on Bitcoin main layer way higher than anyone else, just to make sure that it is confirmed. 1:06:40 One of the big risks of any two-way peg is that you have to calculate somehow the transaction fees for your peg out. 1:06:48 And if you calculate that too low, then basically your whole sidechain will get stuck. 1:06:56 So you need to put those transaction fees high enough, which will create automatically way higher fees for layer one. 1:07:04 We've already seen that play out because of Liquid, and we'll probably end up implementing it very similarly. 1:07:10 Because you don't want to have the risk that basically your sidechain has too low fees, and then that locks your peg outs, and then you end up in very niche scenarios that you don't want to end up in. 1:07:28 And since it's the end user that is bridging back, it's paying for fees, then basically you will calculate high enough base fees for the main layer either way. 1:07:39 And then I think the third point is, like Satoshi said, as a layer two, you want to have high enough fees on the base layer. 1:07:51 And it is a collective action problem. I see that, but there's also a collective incentive to really make sure the security of the layer two is guaranteed. 1:08:03 And one of the ways to do that is have high enough fees on the base layer. 1:08:09 Yeah, but the withdrawal fees are just, I think, I don't know why this is so common, but people often use the word fees to refer to two completely different things. 1:08:21 Which is obviously not good from the perspective of having a normal conversation about it. 1:08:27 Because I use fee rates for the dollar per transaction going rate, and then fees is like the total revenue of the block collected. 1:08:39 I don't know, that's just what I prefer to use, but I think that all the withdrawals, those are all going to be L1 transactions. 1:08:47 So they will pay the L1 rate. They may pay L1 plus a buffer, as you were saying. 1:08:54 And so that's certainly true. The idea that it's a collective action problem, but we don't want to suffer from the problem, that's true of every collective action problem. 1:09:10 The first thing you said, I don't remember what it was, but I remember thinking that that's not, oh, this is the fee versus fee rates. 1:09:17 Yeah, you're saying if L2 fee rates go up, that encourages people to go to L1, but that's not what I'm saying. 1:09:23 I'm saying it's quite possible that the L2 is collecting huge amounts of total fees, but the fee rates will be lower because of a higher quantity of transactions. 1:09:32 So they could have 10 million times more transactions, each pay half as much fees as on L1. 1:09:38 But then you still have this conflict between L1 and L2, where L1 is saying, listen, L1 is like whatever, Boromir from Lord of the Rings. 1:09:49 He's like, we're doing all the work over here, stopping the orcs from invading, and we don't get any credit. 1:09:58 And the L2 people can get 100x or 1,000x or 10,000x times more. 1:10:05 So I either say there will be a conflict between L1 and L2, or there'll be the collective action problem. 1:10:11 Or maybe nothing will happen because maybe it won't be a big deal. 1:10:15 But I guess I think it will be a big deal in the future, because we're talking about a ton of money. 1:10:24 And then people will start, and they won't say it overtly. 1:10:28 They won't be like, we are doing such and such because we want the fees. 1:10:35 They'll just start little nonsense Twitter psyops, and they'll say, whatever sucks, or miners will drop every fifth multisig or something. 1:10:45 I don't know. But I think it might be a rough seas. 1:10:54 Here's even more of an oddball. Alex Kravitz was talking about it last week, where in a 1:11:02 potential world that we have a trust-minimized or trust-less two-way peg, most likely one 1:11:09 of the first things will happen is a wrap on Ethereum for an actual trustless or trust-minimized 1:11:16 peg. And now Ethereum has a credible Bitcoin asset, and then it gives more credibility to 1:11:23 the Ethereum EVM. Their fees go up because they have the network effect, you know, that 1:11:29 continues to legitimize or solidify their network effect to continue to grow because of a 1:11:36 two-way peg now that works for Bitcoin to Ethereum. 1:11:41 What do you guys think about this? 1:11:42 I'm happy to go here because a lot of people always told me over the last months that I 1:11:51 should use the spider chain to build a bridge to Ethereum. Now, how I think about it is, 1:11:57 why would you ever use a bridge if you can just send Bitcoin to a centralized exchange by 1:12:06 Ethereum, send it to Ethereum mainnet, and then buy Wrapped Bitcoin? 1:12:12 Like, I have zero risks there and we've seen that 80% of the hacks are all breaches. 1:12:19 Well, Wrapped Bitcoin has that centralization risk of, you know, the custodial Bitco. 1:12:25 Yeah, but there is a big difference between security and centralization. 1:12:31 Like, Liquid is probably one of the most secure things out there. 1:12:35 So security, like centralized solutions, can be way more secure than decentralized solutions 1:12:40 because it's often trustless. 1:12:42 But the thing with Liquid is it doesn't have the network effect of, you know, all the DeFi 1:12:46 protocols that Ethereum has with their TVL and, you know, lock collateral in all of their 1:12:53 whatever contracts, right? 1:12:55 So the incentive will be for Ethereum to have, you know, sure, Wrapped Bitcoin works fine. 1:13:01 But if they can have a better Wrapped Bitcoin that is actually more trustless, right, that 1:13:06 would benefit them and their whole ecosystem. 1:13:11 If you can convince the market that it's more trustless, one, trustless, two, Wapex, we 1:13:16 haven't seen it yet, and two, all the hacks have always been happening on bridges. 1:13:22 I don't know. It's an interesting question. 1:13:26 I actually think the easiest way to maybe implement the bridge is go on a second layer 1:13:36 EVM on Bitcoin and then build an EVM bridge instead of a Bitcoin-Ethereum bridge. 1:13:44 But generally, I think I'm not really afraid of the case for the bridges taking the network 1:13:51 effects to Ethereum. 1:13:53 I think it's the opposite. 1:13:55 Like with an EVM on Bitcoin, I think Ethereum should be more scared that all the activity 1:14:02 will go back to Bitcoin. 1:14:07 I agree as well, because I think it still doesn't solve their whole consensus problems on 1:14:12 that side of like USDC centralization or things like that, if they had a fork or whatever. 1:14:19 So, yeah, I think as well, if you have a Bitcoin side EVM, eventually over time, the 1:14:26 liquidity would grow and then you're really just fighting the monetary asset of Bitcoin 1:14:31 versus Ethereum, where most likely Bitcoin will continue to win there. 1:14:38 That would be my hope too, but I think your concern is valid. 1:14:41 I would think if they all have equal features, it does just put so much of a premium on the 1:14:53 number one coin and it does stigmatize everything else, is my thought. 1:14:59 So I don't know, like anything that... 1:15:03 Because think about the story you have to tell if you want Ethereum to flip in BTC. 1:15:08 The story has to be something like, if we at Ethereum did such and such, we have turned 1:15:15 complete scripts, we have state, we have a freedom to develop and this turned out to be 1:15:20 more important than Bitcoin's conservatism. 1:15:25 That's like the story you have to tell, right? 1:15:26 Like, why did it, why did it flip and why should people join Ethereum as the number one 1:15:30 coin? Because, you know, if they flip, it could flip flop, you know, right? 1:15:34 Flip back and forth. 1:15:36 So people would say, hey, the number two coin sometimes becomes number one. 1:15:41 So the story they have to tell has to be something like, we have these features, these 1:15:45 properties that Bitcoin doesn't have and it's permanent. 1:15:49 But in a world where Bitcoin has just gained the ability to, like where they each gain each 1:15:55 other's features, then I think that's not good for the number two coin. 1:16:00 But it's about the network effects and I think like Ethereum is number one when it comes 1:16:07 to network effects of like casinos. 1:16:11 Yeah, we can see also a similar example that happened when AVAX was incentivizing and 1:16:16 bribing people to move over to them during last cycle and, you know, the fees were much 1:16:22 lower, arguably about, you know, their decentralization and their consensus is different. 1:16:27 But eventually, like there was a moment that, you know, there was a decent amount of 1:16:30 liquidity growing over there, but then eventually it evaporated. 1:16:33 And I assume it's because the network effect of Ethereum was just so much stronger and 1:16:37 greater that you might temporarily bribe people to move on to your, you know, whatever 1:16:42 faster, cheaper, better network. 1:16:43 But if it doesn't have that stickiness of the of the liquidity, then eventually a dry 1:16:49 out. But I don't think this will be a problem for Bitcoin because here the monetary 1:16:53 asset has more of a network effect, even if it's not in the casino aspect. 1:16:58 The fact that it's a better network effect for money might be enough for liquidity to 1:17:02 eventually grow and actually be sticky over the longer term. 1:17:08 Well, I mean, we all hope so, but it is true that, you know, Ethereum has a lot of users, 1:17:15 has a lot of fee paying users, has a lot of activity. 1:17:19 It has a lot going forward in terms of not like a top down intelligentsia, but it has a 1:17:26 lot of actual. 1:17:28 It just has a lot of actual people who are who are excited about it, and of course, 1:17:32 Bitcoin obviously does as well. 1:17:34 But the problem is in Bitcoin, we have, you know, sort of been lying to ourselves. 1:17:41 I mean, this is the BIP300 or Drivechain. 1:17:44 It really would have been a much better idea back in 2015 when I first proposed it. 1:17:49 When Ethereum was still a complete, complete pile of junk, that would have been much 1:17:54 better. We would have had all this stuff on Bitcoin, you know, a long time ago, and 1:17:58 there probably wouldn't have been a big Ethereum network effect. 1:18:02 And now as Ethereum gets better, we just have more sour grapes, I think, where we just 1:18:08 say, oh, we never wanted that anyway. 1:18:09 We have the Jocko Mazzucco slide or whatever. 1:18:13 We say. Every other idea is not good. 1:18:18 And and so. 1:18:21 I'm not sure I think our culture is much weaker, I think, actually, than the Ethereum 1:18:28 culture, believe it or not. 1:18:33 Yeah, but I'm not really I don't really believe that all these things will play out 1:18:40 long term. And you just have to look at the market cap numbers. 1:18:47 Bitcoin has 600 billion dollars of market cap and almost no utility in applications. 1:18:54 And so even though Ethereum has the strongest network effects, both in switching costs, 1:19:00 in culture, network effects and liquidity, longer term, there's a massive incentive to 1:19:07 move to Bitcoin because in Bitcoin, you have all the capital that is not being used in 1:19:14 any application. So if I'm a I'm a dev and I'm looking for customers, there's 600 1:19:21 billion dollars of potential customers. 1:19:22 Why wouldn't I move over? 1:19:24 And so it's a question of time before basically, yeah, the whole ecosystem, the 1:19:31 network effects start on Bitcoin. 1:19:33 If you build the argument around the market cap, though, then it's it's something of a 1:19:38 circular reasoning, really, because. 1:19:42 So, I mean, I've seen those market cap numbers change quite a bit. 1:19:45 I remember when Ethereum had, you know, one ten thousandth the market cap of BTC. 1:19:50 So I've seen those numbers change enormously over the last whatever, 10 years more. 1:19:56 So, you know, and once the day of the Dow hack or whatever, Ethereum felt like 66 percent 1:20:04 or something like that. So so I hope that everyone is right about all this and that none 1:20:09 of it matters. I gave you a little speech just a moment ago about how they'll have equal 1:20:15 features. I think that stigmatizes the number two coin, makes it really difficult for it to 1:20:19 succeed. So I certainly believe that. 1:20:22 Certainly hope it won't be an issue, but I wouldn't build it all on the market cap because 1:20:28 the market cap I have seen the Bitcoin market cap get cut in half in a day, several 1:20:35 times. I've seen Ethereum fall by two thirds in a day at one time. 1:20:41 I've seen quite a bit of stuff happen, and the market, the market cap is mostly it's 1:20:47 circular reasoning itself, because I think it's people speculating on future ability to 1:20:53 spend the coin, future utility of the coin. 1:20:56 So it's inherently very speculative. 1:20:58 And so people's expectations of the future can change like in an instant. 1:21:08 As far as like Bitcoin's culture being weaker than Ethereum's, I think that maybe in 1:21:15 utility and like casino wise, Ethereum might have like a stronger culture or utility and 1:21:20 whatever. But as far as like a base layer money, I think Bitcoin's culture is probably way 1:21:26 stronger. Like you said, who knows what the future will hold, but you know, I think 1:21:32 Ethereum's culture is terrible, but I think that Bitcoin's has gone from being OK to even 1:21:40 worse. We, I think we really, you know, what made Ethereum's culture bad was when it was 1:21:46 talking about being world computer and and blah, blah, blah, saving the planet and said all 1:21:52 this, this, this big stuff. 1:21:55 So it's the big talk and not being serious about getting things done. 1:21:59 But now we are the ones who do the big talk. 1:22:02 We have this grandiose nonsense that we're lying to ourselves about. 1:22:09 The details don't add up yet, but they're very close, but not yet. 1:22:14 Not until Bill 300 activates, then it'll all be, then it'll go back to being perfect. 1:22:25 It's about the self-deception, though, just to be clear, that's what it is. 1:22:30 It's just because once you have once people can't be honest, then there's no recovery. 1:22:38 So. And it was very different 2012, 2014, it was very different people, you know. 1:22:45 It was just go back and read BitcoinTalk.org and just read what it was like in 2012, 2014, 1:22:53 that type of a thing 10 years ago. 1:22:55 And it was. And I think the Twitter algorithm is also screwing us to some extent. 1:23:08 Anyway, we have some other people up here, they are. 1:23:11 Hello. Crypto Congress conversion. 1:23:16 Yeah, I just wanted to just on this discussion of the culture and market cap versus the 1:23:24 fees paid and things like that, I do think, you know, I just I agree that market cap isn't a good indicator 1:23:31 and that people aren't building again the culture of Bitcoin. 1:23:36 There's so I think so much of that market cap is people who are, you know, never going to spend any of their Bitcoin. 1:23:43 Right. That's that is the I maybe the predominant Bitcoin culture is, you know, hold your keys, hold your crypto or whatever. 1:23:51 Hold your Bitcoin cold storage, you know, save it for the rest of your life and then, you know, you'll be rich. 1:23:57 Right. And so I think we definitely need to see, you know, the start of a culture shift that we are willing to pay fees. 1:24:06 We are willing to use applications and then all those applications will be built and then we'll have, you know, we have to have that kind of culture shift before we can overtake a theory of whose culture is I'm using apps, 1:24:20 whether or not to make money or, you know, identity apps or things like that. 1:24:23 But, you know, I am I have a theorem so that I can use it. 1:24:31 I completely agree that if you had gone back in time to the 2012, 2014 era, I think this is all because of the scaling war split the medium of exchange and store value groups. 1:24:45 Previously, they were absolutely the same group and people imagined my guess is that people would have actually imagined something that is much more like BitVM. 1:24:55 If you went back to 2012, everyone would think, wow, this is going to be crazy. 1:24:59 I'm going to go online and I'm not going to I'm going to be in the anonymous Internet and I'm going to pay for like my VPN with Bitcoin and I'm going to pay for like my whatever, you know, my drugs or something with Bitcoin and my prostitutes and I'm going to have magic encrypted files on the Internet. 1:25:15 And I'm going to play against I'm going to play chess against someone. 1:25:19 And cryptography is going to guarantee that the winner of the chess game gets something we could have people will have people meet like the fast and the furious where they all meet on the one road to race. 1:25:32 And they were like, we have like cryptographic like chat rooms and stuff. 1:25:36 And like there'll be a spam resistant email. 1:25:39 People are talking a lot about using it a lot. 1:25:43 And we had BitPay, we're like, oh, BitPay, it's exactly like a credit card, except much cheaper. 1:25:49 It's a better deal for the merchant, the user, you know, the customer. 1:25:53 They get cash the next day. 1:25:54 BitPay was big. 1:25:56 It was a big idea. 1:25:57 And just to have this cool little logo and it was just like a visa. 1:26:00 You could like have a little sticker at your at your store. 1:26:05 And it was really about using it as much as it was about people talking about, hey, the properties of money are way better. 1:26:13 We have 21 million coins only. 1:26:15 There's no inflation. 1:26:15 It's totally predictable monetary policy. 1:26:18 There's no ambiguity. 1:26:20 You you always know exactly. 1:26:21 Unlike gold, you always know exactly how much Bitcoin you have. 1:26:25 So people talked about the store of value stuff, of course, but they also talked about the medium of exchange. 1:26:32 And this is why I I repeat this a lot, but I really believe it, that the scaling war screwed everything up in Bitcoin, because. 1:26:41 Now we get to a point where people would there are people who will say. 1:26:49 You know, they'll say we don't even want to use Bitcoin, using Bitcoin is bad, and in fact, if we if we use it too much, it might it might, you know, it might make it harder for BlackRock to get the ETF or something. 1:27:01 And if you had said that in in 2012, a person's head would have just exploded, they would have said. 1:27:09 Who fucking cares about that? 1:27:11 And so, I mean, yeah, it's important. 1:27:13 Adoption is good. 1:27:15 Investment is good. 1:27:16 High market cap is good. 1:27:18 BlackRock ETF, that's that's good. 1:27:21 But I just don't I just don't get it, you know, really, there would be, you know, the cypherpunk future has departed almost completely. 1:27:30 Because the cypherpunk future was like, you know, magic file storage and something like that. 1:27:37 So now it's considered very fashionable to reject all that. 1:27:42 And say we don't want. 1:27:44 Application that part of this is the sour grapes that I mentioned before, this is a really sad thing is that because other coins like Ethereum and other stuff, Filecoin or whatever, because they have moved into that territory. 1:27:57 Now, the Bitcoin culture has to say is forced to say we're holding a gun to ourselves and we say, well, we never really wanted that anyway. 1:28:07 That's just some. 1:28:08 That's just a scam. 1:28:11 And yeah, that's not good. 1:28:13 That's why it's a big problem. 1:28:15 Yeah, but I do think there's something in addition to just a medium of exchange that we have to get in people's mind right on Ethereum. 1:28:25 You know, it's not that people think ether is a good money or, you know, it's something that they want to maximize. 1:28:34 There are plenty of people on Ethereum who, you know, it's simply the gas. 1:28:38 It's simply the, you know, it's the means to get what they want. 1:28:43 They hold a little bit of ether, but they're, you know, they're in tokens or NFTs. 1:28:47 They're, you know, they're doing identity stuff with the ENS and they're, you know, more about that and building that out. 1:28:55 And then, you know, the ether, right. 1:28:57 I could imagine if lightning scaled perfectly and Bitcoin was used as, you know, a store of value and a medium of exchange. 1:29:05 It's still unless people can wrap their heads around it being, you know, gas and having. 1:29:12 I don't know if this makes sense, but maybe it is simply a medium of exchange and they're paying the fee to do these things. 1:29:19 But I don't know. 1:29:20 In my head, it seems like it's an additional property of this like utility in order to access these things. 1:29:27 I have to have and use Bitcoin to do so. 1:29:33 Yes, this is a very important point that people often claim that ordinals spam the blockchain. 1:29:40 I just want to say I don't own any ordinals at all, or inscriptions or whatever, but I'm going to defend them slightly because 1:29:48 they say that there's no, it takes up block space that should instead be used for transactions. 1:29:54 But that's not true because the ordinals inscription thing is a transaction. 1:29:59 It is, it pays a transaction fee to the miner. 1:30:03 And it is a, it is a transaction. 1:30:06 So it's not the transaction you want, but it is something. 1:30:11 And as a result, it, uh, they bid for the block space they pay the most. 1:30:18 So they're the rightful owner. 1:30:22 And yeah, it just goes to this, like, yeah, this, but I think this is the scaling thing about how, um, payments was de-emphasized. 1:30:29 It was originally a big emphasis was payments and now it's been de-emphasized. 1:30:35 So it used to be like removing it. 1:30:38 We thought, I can't believe we have to compete with Western union, which is like charges 15% or something and charges a fortune. 1:30:45 And we were just like, we're going to, this is going to be no problem. 1:30:49 And, you know, payment, we all make payments multiple times a day. 1:30:55 But yeah, this was, uh, the scaling war really threw a giant wrench in all this, not because, you know, the correct side one. 1:31:04 But that's not the point really both sides lost because the community split and then each side became obsessed with only it's one thing. 1:31:15 When both are, both are needed or really what's really needed is just the, the ability to be honest with yourself about things that you want. 1:31:24 So like in Bitcoin, we actually, we want payments, we want scalability, we want, uh, smart contracts, but we were often, often we lie to ourselves about, about that fact, you know, 1:31:35 I think, I think there was another thing, uh, as well that, that contributed, not just, uh, the scaling war. 1:31:41 Um, and from my experience early on, there was, it was a pro exploration and a pro innovation. 1:31:47 And like, it was a pro learn about the other protocols and try them out and, you know, understand them. 1:31:52 And if they are good, you know, Bitcoin will eventually adopt it. 1:31:55 I remember that, that culture early on. 1:31:57 Um, but then there was also the, the Hal Finney's that would say, you know, the base layer really doesn't scale on, you know, in its current form. 1:32:03 Right. 1:32:04 With his famous post saying that it's going to be as rare today, uh, in the future as, as a Bitcoin transaction today. 1:32:11 Right. 1:32:11 So he already saw that, um, the, the, the scaling limitations and, um, you know, other layers that would actually be doing the, the medium of exchange and things like that. 1:32:20 But I, I think that the, the, what really happened, what another thing that happened is during maybe, um, you know, old coin booms or ICO booms and things like this, there was, there was a defense mechanism where Bitcoiners would try to protect newcomers. 1:32:32 Because obviously during new cycles, there is an influx of new people and the new people, they don't really understand the actual inner workings of the protocols. 1:32:41 And they're very prone to getting scammed. 1:32:43 So it was a lot easier to protect them by just calling everything a scam outright. 1:32:47 Right. 1:32:48 And like, because, you know, obviously you're protecting them from 99.99% that are scams. 1:32:52 And I feel like it was because of this defense mechanism that was shunning everybody away from everything else to protect them rightfully so. 1:33:00 But at the same time, it eventually became too strong where, you know, it, it lost the idea of actually explore it. 1:33:06 You don't have to invest in it. 1:33:07 You don't have to buy it. 1:33:07 Don't fall for the marketing, but explore it and learn about it. 1:33:10 And I think that part kind of got lost, you know, over the years because of the defense mechanism. 1:33:19 I definitely agree with the history, you know, tracking where we lost this. 1:33:23 But then, Paul, I like that you mentioned ordinals. 1:33:27 I do think that is hopeful for the future that it seemed like when that came out, you know, even though whatever, you know, maybe they were inefficient and expensive. 1:33:37 Just the fact that so many of those things got minted, it pulled, you know, a number of people from Ethereum back into Bitcoin, you know, that they. 1:33:47 So definitely I am hopeful for one of these scaling solutions, one of these sidechain solutions. 1:33:55 I'm hopeful that one of them can, you know, lead us to, you know, take more of that, more of what Ethereum has right now. 1:34:05 And, you know, maybe one day make it obsolete. 1:34:08 And so anyway, that's it for me. 1:34:10 Just wanted to talk about that debate. 1:34:12 Thanks, guys. 1:34:14 Yeah, no, absolutely. 1:34:15 I agree. I think I'll be more optimistic. 1:34:19 I think what's next for Bitcoin is minimum of exchange. 1:34:24 I think I really believe in there was this one chart called the evolution of Bitcoin that said it would go from a digital collectible to store of value. 1:34:34 To a medium of exchange, to a unit of account. 1:34:38 I just posted on my Twitter as well, if you want to see which graph I'm talking about. 1:34:44 But I think during the scaling war, you've optimized for store of value. 1:34:49 I think last bull run, we've seen everyone in the world talk about digital gold, like it achieved that status in people's minds. 1:34:58 And I think what's going to happen next bull run, we'll have botanics with a sidechain. 1:35:05 There will be a bunch of different sidechains. 1:35:07 And I actually think we'll see a massive increase of adoption of dApps back on Bitcoin. 1:35:12 And that's, I think, where Bitcoin as a medium of exchange starts to play way more a role. 1:35:19 And that's, I think, in the dApp world of things, but also in the macroeconomic type of things. 1:35:26 Countries will start transacting way more in Bitcoin. 1:35:30 The more people get thrown off Swift, the more Bitcoin will be used. 1:35:37 And so I think the medium of exchange, we haven't seen it play out yet, 1:35:41 but I think it will come way faster than we all expect. 1:35:46 Just to give everyone an expectation here, once you have an EVM that's fully equivalent on Bitcoin, 1:35:54 it takes you a day to copy any application that you have on Ethereum and deploy it on Bitcoin. And so I think the changeover will be way faster than a lot of people expect. 1:36:07 Initially, it will go slow because you have the massive liquidity effects. But after that, I think a lot more people will come back and the battles will be between different sidechains. And basically, you'll see an explosion of sidechains. I think, as Robin mentioned, the tools are being laid out right now. And over the next years, I think, development on sidechains and on Bitcoin mainlayer and applications will be much, much faster than we would have expected. 1:36:37 Applications will just explode in the next world. 1:36:49 Paul, can I ask a question? 1:36:51 Yes, of course. 1:36:54 First, just a quick comment with respect to Ordinals. It reminds me a lot of, I don't know if you remember when Satoshi Dice was popular, people were making the same arguments that Satoshi Dice was spamming the blockchain. 1:37:07 My other question, I've been following you for a long, long time, like over a decade. And I sort of, I don't know, sort of checked out of the community for a while. And I just wanted to know what your thoughts are. You don't have to answer the question if you've covered it elsewhere, if you've covered it today. 1:37:33 But there seems to be like, you know, the small blocker argument, and then or the Hal Finney argument, or the Hal Finney position versus the Satoshi position where Satoshi said that, you know, Bitcoin never hit a scaling ceiling. 1:37:48 He mentioned that nodes and miners were the same thing and that there would be large server farms. So he or she or they or whatever, envision Bitcoin scaling on chain. And from what I'm hearing from you is you don't feel that way. Is that right? And if so, why not? Thank you. 1:38:13 Sure, yes, they said that about Satoshi Dice. But what they didn't say as loudly, but Eric Voorhees replied, Eric Voorhees was like the inventor of Satoshi Dice or whatever. And that was the place where we could, you would send a Bitcoin somewhere. And then if you based on the source of randomness, there was like the block cast or something, you could win money. 1:38:36 And they send the coins back to you, and it was all happening on chain. And it involved a lot of spam on the blockchain. But Satoshi Dice had actually paid more fees total, not only per each transaction, you know, not enough, not only enough to outbid, but Satoshi Dice, the entity had paid at one point, more transaction fees total than had been paid in the entire history of Bitcoin. 1:39:07 So that was a very interesting phenomenon. But yes, so this question has come up many, many, many times. So if you really want to know in depth, my view, I wrote in September 2015, this post measuring decentralization, where I say that it is problematic, the more expensive a full node is, but I have a giant essay about that. 1:39:33 And then I wrote an essay called Thunder, which is about scaling with sidechains. It's a little joke of mine. And I explained in detail why this is different from naive L1 large block ism. And it allows us to basically have our cake and eat it too, which is to say, you could get large blocks and use them for payments if you want. 1:39:59 But the entire network doesn't have to come along with you. You don't have to risk the entire L1 on that. And we don't. It's only optional to utilize the extra block space. 1:40:15 But yes, Satoshi seemed to really think that it didn't matter very much that the he thought that full node costs my he thought that every miner had to run a full node. This is I think where I would probably disagree with him. Really miners never run a full node. So I think that the irony though, is that there seems to be like, if you can draw like a grid, and there's like four different groups that all seem to believe different things. 1:40:43 So I think original Satoshi, he thought that miners always had to run nodes. And that's like the Bitcoin SV position now. And then there's other people who say that. I mean, I say miners never need to run nodes, but that running nodes is the important thing. 1:41:04 Other people will say that it doesn't matter. There is no such thing as running a node without being a miner. So that's where this, but it's kind of a bizarre little. It's a bizarre little grid of who thinks what, but my answer is, it doesn't really matter because we can have both of the two options. 1:41:26 Small block L1, large block L2 optional. Now anyone who wanted L2, they could do that. Anyone who wanted L1, they do that. And so it's a moot point really. 1:41:44 But clearly Satoshi began as a large blocker. And then it's like an infinite block size blocker. And then he was the one who himself inserted the one megabyte block size limit. I think it was in July 2010, something like that. 1:42:00 So he did that and then he left without, he described it, we could phase it out later. But even though he had things that phased out, like he had difficulty adjustment and he had the halving every four years, he didn't put any of that in. 1:42:22 He kind of knew that he had kind of left it that way. So he put that in. So he had become kind of a small blocker. 1:42:32 I think the original design, I think, was unlimited block size. I think, you know, like, I'm not sure, but he's because he seemed to be obsessed with like the Merkle tree and it had like log two and like log N. 1:42:45 It had like log N SPV properties. And he thought that if miners can't mine a block, they won't know whose block is valid or not, unless they run a node. So they cannot. So I don't know. Hopefully this is answering some of your question. 1:43:02 Just when you said that anyone who wants a large L1 can have that, do you mean by using L2? 1:43:10 Use large block L2 by using a sidechain, sidechain and Bitcoin. 1:43:14 And in terms of like, I find that people talk about decentralization a lot, but, you know, decentralization is merely a means to an end and the end is actually censorship, censorship resistance. 1:43:34 And to me, it becomes like an economic question as to how many nodes or how much decentralization do you need? 1:43:43 But it's not the quantity of nodes. I talk about this in the essay, measuring decentralization, and it's not the quantity of nodes. It is the how expensive it is to spin up a new node. 1:43:53 This is the cost of the cell dividing, basically. How easily can we get all the nodes back or start up a new node and look into the blockchain ourselves? 1:44:05 And so that cost must be low, but I mean, apparently like Tron is decentralized enough to support an enormous number of USDT payments or whatever. 1:44:17 So, apparently we don't really know where the line is and it's slightly different for each person. 1:44:23 It's an economic question of allocation of scarce resources. And the way I see it is that the block size cap is, you know, it's sort of like central planning. 1:44:37 It's devs or the community or whoever saying that we know that we need more decentralization. 1:44:45 Well, I don't think that's correct. 1:44:48 You're not allowing the market to discover the right block size to balance the medium of exchange utility of Bitcoin while maintaining censorship resistance. 1:45:00 And you're choosing or whoever is choosing to forego that medium of exchange utility, which is why you're seeing the things that you're seeing. 1:45:08 In terms of stagnation of development of BTC as a medium of exchange. 1:45:16 Well, I think it's not correct. I mean, well, there's a part of it. There's some truth to it, but not enough. 1:45:22 But what's true about the block size limit, the one megabyte static block size limit, is it's unclear exactly how we are supposed to recover from the limit not being correct. 1:45:38 So, you know, like if the limit is an error, how do we recover from it? 1:45:44 And similarly, as you say, if in the free market, you know, usually if there's someone who's opening a restaurant and they do something wrong every single time, people love the restaurant, but they think the prices are just too high. 1:46:00 Or the dishes aren't clean or something, then someone can open a new restaurant next to it, do the thing, do it the right way. 1:46:10 And it's just a question of barrier sentry and stuff like that. 1:46:14 So the free market usually has ways of correcting mistakes. 1:46:18 If someone's wage is wrong or the price or something is wrong or, you know, something's not being constructed the right way, technically. 1:46:27 And a static one megabyte block size limit, it doesn't really have that feature because it's sort of unclear how are we supposed to get out from under it? 1:46:36 You know, do we launch a different coin? Do we hard fork Bitcoin? 1:46:40 I think that's what a hard fork is. A hard fork is the market taking, you know, taking the issue into its own hands. 1:46:50 Why would you say that, though? 1:46:52 Because a group of people, some people wanted small blocks, some people wanted unbounded blocks. 1:47:01 And so the community forked and now, you know, we have an obvious split, though. 1:47:06 It doesn't split because 80% of people maybe were indifferent or something, but they all stay on BTC. 1:47:12 I wish the hard fork enabled competition. 1:47:15 The hard fork is kind of like the restaurant scenario where it's very, very, very, very difficult. 1:47:20 You have very high barriers to entry. 1:47:23 So the hard fork is feeble as a competitor, is not able to compete. 1:47:28 I wish that it would. 1:47:30 If it was, then it would be a moot point, right? 1:47:33 Because it would say, well, no one would complain because you would. 1:47:38 Let me explain to you what I mean when I say, like, if the hard fork was a good way of inspiring competition, 1:47:47 then what would always happen would be whenever anyone hard forked, 1:47:52 the market cap would be divided into two equal portions for some tiny amount of time. 1:47:59 And both of the new projects would get like a new name and like a new ticker symbol, completely new. 1:48:05 So it really would split from one thing into two different things. 1:48:10 But that's just not what the hard fork does. 1:48:13 The hard fork is too weak. 1:48:14 The hard fork is just a shit coin. 1:48:19 I mean, I wish it would. 1:48:21 Yeah, well, I think, you know, I think of the hard fork as sort of a vestigial organ almost. 1:48:30 And when the right economic conditions present themselves, 1:48:34 that it may, you know, have the right, quote unquote, genetic makeup so that it'll flourish in the future. 1:48:39 And I think with ordinals, you know, and fees, you know, going really high, 1:48:46 I think it woke some people up in terms of how, you know, 1:48:50 some people were stacking sats and had very small amounts of sats. 1:48:54 Maybe were priced out of ever accessing their on-chain sats because fees were too high. 1:49:00 And it may be in the future. 1:49:02 Look, hypothetically, if you think of some type of thought experiment 1:49:05 where BTC's fees rise up, you know, a hundredfold, a thousandfold, 1:49:13 then all of a sudden these shit coins start to have utility. 1:49:18 Well, I think also that what gives them utility is that we in Bitcoin, we don't have an answer. 1:49:24 When someone comes to us, when someone comes and says, 1:49:26 listen, I really want to do ring signatures for extra privacy. 1:49:29 We in Bitcoin, we have to turn them away. 1:49:32 We don't give them anything that they can use. 1:49:35 And as a result, they must launch Monero or whatever. 1:49:42 So what are we supposed to tell them? 1:49:44 You know, when the developers are going to make something, 1:49:46 yeah, what are we supposed to do? 1:49:48 Jeremy makes CTV and the community drags its feet for five years. 1:49:53 And so it's either, either you just do nothing. 1:49:57 You're supposed to do nothing with your idea or you have to launch an alt. 1:50:00 And then we don't, we don't, it's a similar concept to the, 1:50:05 what I was telling you about where I was explaining my point of view 1:50:08 about the one megabyte static block size, where it's kind of like, 1:50:11 it's unclear exactly how is it that we're supposed to get out from under this? 1:50:17 If it's a mistake, if we say no ring signatures on Bitcoin, 1:50:22 is that a mistake or not? 1:50:24 And we say, well, if it is, then how do we escape from it? 1:50:30 I think it takes a crisis. That's all. 1:50:37 Sorry to interrupt you guys, but I have to say goodbye here. 1:50:41 Unfortunately, I have another appointment now. 1:50:44 Um, yeah. 1:50:50 Yeah. Check out BitVM.org, read the white paper, give us feedback, 1:50:56 try to break it. And, uh, yeah. 1:51:00 Have a great day. Bye. 1:51:02 Cool. See you. 1:51:04 I'm also going to sort of, uh, turn off my mic. 1:51:08 Thanks Paul for everything you do. 1:51:10 Yeah. Paul is awesome. Activate BIP300. 1:51:15 Thank you. 1:51:18 Thanks guys. 1:51:21 Let's see if we want any more questions, um, 1:51:25 from the audience that are new or about anything. 1:51:31 Yeah. 1:51:34 In the meantime, I can maybe, uh, 1:51:36 chime in on what we just discussed on, uh, on Monero. 1:51:40 Yeah, do it. 1:51:42 I start to get this theory that how I see it is that any more or less 1:51:48 successful layer one that we've seen like Monero, um, 1:51:52 and others basically always should read some kind of, 1:51:56 or have some property that reach product market fit in the market and privacy 1:52:00 basically, uh, 1:52:02 it's one of those properties and it shows that there is demand or blockchain 1:52:06 demand for something and that's privacy. Um, same for Ethereum. 1:52:10 It shows that there's demand for a virtual machine in a blockchain. 1:52:14 Same for Solana. It shows that there's, 1:52:16 there's demand for a fast for high speed transactions for gaming, et cetera. 1:52:21 And, um, Bitcoin is of course, yeah, 1:52:24 the most secure decentralized money. Um, 1:52:27 and I think all of those will be true, but for money, 1:52:31 it matters most, uh, that what Bitcoin has, 1:52:36 but you can have all those properties, um, 1:52:40 on second layers or on sidechain. 1:52:42 So I fully believe at some point we'll see a Monero, uh, 1:52:46 fully running on Bitcoin as a sidechain or, uh, Solana, 1:52:50 there will be a very fast sidechain or, um, yeah, 1:52:54 the EVM of course makes so much sense, but that's basically what I've been 1:52:58 thinking. Yeah. I mean, I hope so, but I mean, like, 1:53:01 I've been waiting for like eight years. I mean, 1:53:06 not that I've only focused on this, but, but yeah, 1:53:09 I think that that's the idea is that eventually it would, but you know, 1:53:13 weirdly, this is why I mentioned the culture where the scenario with the 1:53:18 culture is, um, 1:53:21 like that people have decided that they don't really even want these things. 1:53:27 So there'll be hostility to this hostility to like one 19 or something. 1:53:31 So I don't know. I mean, I hope so, but I think, uh, 1:53:34 that is going to be kind of a, kind of a concerning development of like, 1:53:41 do we, do people even want there to be EVM on Bitcoin or something? 1:53:47 Yeah. It'd be an interesting thing to see it play out. I don't. 1:53:51 Well, I guess we'll, uh, we'll see very soon. Um, cause it's happening, but, 1:53:56 uh, yeah, I think there will definitely be a lot of hate, but in the end, 1:54:00 um, if it gains adoption, 1:54:03 then the market basically tells us them, uh, um, 1:54:07 they were wrong in that sense. 1:54:09 Cool. Great. Yeah, I agree. Yeah, I agree. You know, 1:54:14 if you're not going to be one of the ones using this, then, you know, 1:54:18 it's kind of annoying when people, 1:54:21 it should be a relationship between the software developer and their users and 1:54:26 not like random other people who don't know what to, you know, 1:54:31 the comment and they don't know what they're talking about. 1:54:33 Anyway, Flavor, did you have something? 1:54:36 Oh, I just want to ask, I guess a little more straightforward of a question. 1:54:41 Um, it kind of ties into the first question I asked, 1:54:44 which is that it does seem a little bit like, uh, too bad that Robin left, 1:54:49 but that, that BitVM and spider chain are almost answers to, 1:54:55 um, the issues that Drivechain has faced. 1:54:58 Um, with the bureaucracy and the idea that Drivechain needs permission, 1:55:03 whereas BitVM and spider chain don't. Um, 1:55:08 and so I guess that's kind of why I was asking that question. 1:55:11 And I wanted to hear, uh, Willem speak to that, I guess, and speak, 1:55:15 I guess a little bit, share your thoughts on, uh, 1:55:19 what you've seen Drivechain go through, uh, on a political level. 1:55:23 Well, you know, I've never actually released, you know, 1:55:25 I never had a pull request and I never released client software that miners 1:55:30 could run to activate. So, but yeah, I did. 1:55:36 So that's, it's possible, but, but, but yeah, 1:55:40 I do think that in general, 1:55:43 the soft fork idea kind of died in after SegWit because, 1:55:48 sure we had taproot, but that's all we've had. Uh, 1:55:52 and so that makes us going from like 2015 December until the present with only 1:55:58 those two. And people are just awkward. They don't want to, every time this, 1:56:03 this activation logic pops up, 1:56:08 people get annoyed. And that is because, 1:56:11 um, they're all of them have mistaken views. I think, honestly, 1:56:15 we could do a clean them all up by just saying, we, 1:56:19 we had this thing, bib nine and it required 95% hashing, 1:56:23 hash rate to activate soft forks, 1:56:25 but then miners use that to hold the soft fork hostage. 1:56:29 And, uh, that had nothing to do with the soft fork though, 1:56:33 that it was, it was, it was, uh, 1:56:37 and, uh, that had nothing to do with the soft fork though, 1:56:41 that everything to do with other things, 1:56:43 other mistakes that have been made by overlapping groups of people. 1:56:50 So it's true though. But yeah, I don't understand why the, 1:56:54 the bigger question is why aren't, 1:56:57 why didn't people work on Drivechain? 1:57:00 Like why didn't they just switch to working on Drivechain after problems with 1:57:04 the lightning network emerged in like 2017, 1:57:08 2018 and why didn't they pursue sidechains in general? 1:57:14 I think honestly, 1:57:15 a lot of it is just because of liquid where everyone thought Blockstream was 1:57:18 working on it. 1:57:19 And then people didn't really realize that they had abandoned it. Uh, 1:57:25 that's my guess. It's hard to say. I think now it's very weird because as I've 1:57:31 said, as the old coins have gotten stronger, 1:57:34 the prevailing attitude in Bitcoin is to just deny that there's anything good 1:57:39 happening over there. So that's not really constructive, 1:57:44 but I don't know. Uh, it's a very weird, um, situation. 1:57:50 I think the idea of like not, not needing a soft fork, 1:57:55 that is of course touted as an advantage of bid VM and spider chain over drive 1:58:00 chain. But in my view, this is just a symptom of a disease. 1:58:06 The there's no, 1:58:08 there's no reason to have a prejudice against the soft fork. 1:58:11 The reason why people failed with the soft fork was because the relationship 1:58:16 between developers and miners was one of distrust. 1:58:19 So that people had failed already to do the right thing, 1:58:24 which was communicate their ideas effectively and a ball on both sides. 1:58:31 So they had failed already and then they, 1:58:33 they doubled down on their failure by blaming the soft fork. 1:58:37 When all the soft fork did was hold up a mirror to their own lack of virtue and 1:58:42 lack of leadership and just overall, you know, 1:58:46 inability to achieve success. 1:58:50 So they blamed the mirror, which is a soft fork. And, 1:58:56 uh, and, but we make, I'll explain what I mean by that, 1:58:59 which is we make all kinds of code changes all the time in Bitcoin, 1:59:03 any of which could be like a assert zero bug that crashes the node or which 1:59:09 has some kind of key logger or do something else. That's terrible. 1:59:12 Matt Corral inadvertently, I don't really blame him, 1:59:16 but he was just trying to speed up something by like half a millisecond. 1:59:21 And he inadvertently introduced an inflation bug. 1:59:25 It has nothing to do with whether or not it's a hard or soft fork intended. 1:59:29 So none of that's even, 1:59:32 this is such a notable case because that one in particular was found by a 1:59:36 Bitcoin cash developer and then reported to BTC. 1:59:38 So I'm just saying weird stuff is totally possible when you are not, 1:59:42 it has nothing to do with hard soft fork, hard fork, no fork, whatever. 1:59:47 If we want to be pro ossification, we should just not change. 1:59:50 There should be no code changes at all. No refactoring, no nothing. 1:59:55 Just don't change the code. If we aren't, if we wisely say, well, 2:00:01 that idea is probably never going to work because you have things like 2:00:03 dependencies and CVE, right? Critical vulnerabilities. 2:00:12 Just anything about like the hardware changes, the software, 2:00:16 like the operating systems change. Like, do you have something on a phone? 2:00:20 Do you have something on a tablet? These things change over time, you know? 2:00:25 So the ossification is probably not happening just because of dependencies 2:00:29 alone. So, uh, 2:00:33 so what I'm getting at is why do we care so much about the soft fork? 2:00:36 What it does is again, is the soft fork is the mirror. It's, 2:00:39 we look into the mirror and we see something really ugly and we say, 2:00:44 and what it says is we can't soft fork, but the, but it's, you know, 2:00:49 it's not the mirror's fault. It's our fault. We are bad at doing. 2:00:53 We're bad at communicating the ideas to the community, the miners are bad at taking responsibility for both their past mistake and also they're bad at taking responsibility for the future of Bitcoin. 2:01:01 They say, I have invested all this money in mining equipment, we will do, you know, soft forks again. 2:01:10 And developers have decided that they, they, developers have decided to become spineless. 2:01:16 Basically, they've said, I don't want to take responsibility for a soft fork because as what happened with Jeremy Rubin and myself, you get blamed. 2:01:25 You get a lot of unwanted attention from, you know, people have no idea what they're talking about. 2:01:30 And, uh, the developers all look the other way, which makes them kind of complicit really. 2:01:36 They are the, uh, you know, first they came for the such and such, but, um, 2:01:44 the, so this is all what it is. 2:01:47 It's a very ugly situation. 2:01:49 And, uh, everyone is determined to just say, just evade the issue, which is on one sense is very rational because it would just evade the issue because we don't need a soft fork. 2:02:01 But I think that we make all these changes already. 2:02:05 Every single version, there's numerous, numerous changes that are, you know, they're not good. 2:02:11 Or, I mean, they're harmless. 2:02:12 That's not what I mean. 2:02:13 What I mean is we make all these changes, but they don't get treated with the same, um, like this might destroy Bitcoin attitude. 2:02:24 So it's just pointless, completely pointless. 2:02:27 And, uh, yeah, the, the reason why it's a symptom of something much worse is that it just speaks to how little any of these words mean anything. 2:02:39 You know what I mean? 2:02:40 Like you time travel a hundred years in the future and say, Oh, I use Bitcoin today. 2:02:43 And Bitcoin is something controlled by the, the, the fed in the United States. 2:02:49 And it has an unlimited supply and it has no privacy, but people call it Bitcoin. 2:02:53 A hundred years from now, because we've already started to do this with like custodial lightning, for example. 2:03:01 So if the words stop meaning anything, as soon as we lose, you know, the honesty and the self criticism, then it's all, it will all go away. 2:03:10 And so that's what I'm trying to say about this whole thing about needing a soft fork. 2:03:15 Like it's, it's ridiculous. 2:03:17 It's not anything. 2:03:18 It just shows how we, uh, no longer are able to think about ideas correctly. 2:03:27 I would say to, to add on here, Paul, I would say there is something that speaks for ossification. 2:03:35 And when you think about all technologies and even science and mathematics, you always form a certain basis. 2:03:42 Um, and as an example, you have the internet, uh, could there have been a better TCP IP? 2:03:49 Uh, could there have been better? 2:03:51 Um, I don't know, low level designs probably. 2:03:55 Um, but there is something that enables further development once the basis, uh, no longer changes a lot. 2:04:02 And I think, um, like, do I believe Bitcoin will ossify at some point? 2:04:08 Yes. 2:04:09 And I think it probably should because you can make development, um, of building on Bitcoin way more predictable. 2:04:18 Um, and so I would also argue a little bit because you talked about that we're constantly making changes to Bitcoin. 2:04:26 I think there's a dependent, there's a difference between fixing small issues and bugs and opening up new, uh, new possibilities. 2:04:35 Um, that's sad. 2:04:36 I'm playing the advocate of the devil here because I would love to see more, uh, uh, soft forks happening. 2:04:44 You're a hundred percent correct. 2:04:48 You're a hundred percent correct. 2:04:49 But the, but the soft fork already is the ossified. 2:04:53 You know what I mean? 2:04:54 Like this, the hard fork that breaks the ossification as the soft fork, if it's already backwards compatible. 2:04:59 So that's why I say it's no different than any other code change. 2:05:03 They say we changed the way some matrix is every code change is a soft fork. 2:05:09 Really? 2:05:11 Either it breaks compatibility and it's a hard fork or it's a soft fork. 2:05:14 So, you know what I mean? 2:05:15 If someone refactors, they change how a matrix is multiplied and they save half a second, that is a soft fork. 2:05:21 Really? 2:05:23 Version 25 is a soft fork of version 24 Bitcoin core. 2:05:31 So a soft fork really, I mean, I guess if you want it to really make the definition mean something, it would just be has 51% of the miners. 2:05:39 Run the latest version. 2:05:43 Are 51%. 2:05:44 But so, but you can do an awful lot with that. 2:05:46 I mean, TCP IP, of course. 2:05:49 It was general enough to have the whole internet built on top of it. 2:05:53 So if. 2:05:56 Is that true of Bitcoin today? 2:05:59 I certainly think we should have 119 300 and up vault. 2:06:06 I think. 2:06:08 I think up vault should be on L1 or something like it should be some kind of vaulting thing should be on L1. 2:06:14 I mean, if we don't. 2:06:16 The other thing, though, is that the TCP IP. 2:06:21 If you. 2:06:25 How am I going to put this? 2:06:26 What I'm trying to articulate is that. 2:06:30 They were really. 2:06:34 I'm trying to articulate the point that we all as you move up the stack. 2:06:40 The barriers to entry are lower, like it's very easy to launch an altcoin, right? 2:06:48 Relatively speaking, but then if you would have time traveled to the past, how easy would it have been to launch a different like. 2:06:56 You know, a different TCP IP that that would work. 2:07:00 And get people to adopt that. 2:07:03 We're in pretty difficult. 2:07:05 So there's more competition, so I think that speaks to more competition. 2:07:09 There is the more you have to worry about. 2:07:12 Being replaced. 2:07:14 And it's kind of like TCP IP. 2:07:17 I'm sure fortunes were made and lost, you know, and that was chosen. 2:07:21 So to speak. 2:07:23 But it won't be like this with Bitcoin, where you have a lot of people involved who don't know anything. 2:07:28 You know, TCP IP, probably most of the people involved were. 2:07:31 Had more direct knowledge of. 2:07:34 So it's whereas today you have a lot of people who just invest and they just think this is, you know, future money or something. 2:07:41 I'm not sure how. 2:07:43 It's a bigger, bigger topic, so I'm not sure, but I agree with you that it should also buy Bitcoin can and will also buy to some extent. 2:07:51 It's it can never ossify completely because of like dependencies and like hardware and things. 2:07:57 But it will just be removing the it'll be re emulating the same. 2:08:04 Exact same thing. 2:08:06 So I think that that's the case, but I just don't you know, I don't see it. 2:08:10 Well, you can only you should only do that when you actually have the ability to, first of all, meet the desire. 2:08:19 It's a minimum that we'll be able to meet the. 2:08:22 The planetary scale like TCP IP scales to eight billion people. 2:08:29 So if you can't do that, then you should just be crossed off the list. 2:08:32 So we'll see about, you know, what types of L2s work for that. 2:08:37 But, yeah, I don't know. 2:08:38 I think it's not quite the same, but I think, yeah, there's a lot of truth to what you're saying. 2:08:57 Cool. 2:08:58 Well, hey, this has been a fun. 2:08:59 I don't know if we should. 2:09:00 Please come up if you have questions. 2:09:03 Otherwise, we could have a relatively shorter one today at only two hours. 2:09:09 A little. 2:09:18 Doesn't seem like anyone wants to come up at the moment. 2:09:23 So. 2:09:25 So. 2:09:31 I think we can end it and people can listen to the recording. 2:09:33 I hope someone got. 2:09:36 Something useful out of all this. 2:09:41 Yeah, I can maybe end up on the last note. 2:09:44 I think a lot of what we've been talking about will change over the coming months. 2:09:53 Like we'll soon see. 2:09:57 So I've seen it. 2:09:58 That's not run a few times from botanic. 2:10:00 So first version of a centralized node with an IBM. 2:10:05 And so it becomes very easy to start deploying. 2:10:08 And I think it will be groundbreaking and mind blowing for a lot of people to read. 2:10:12 See it work. 2:10:14 So I think that will change a lot of perception over the coming months. 2:10:17 Once you see it. 2:10:18 Like people are visual people. 2:10:19 They love to see things. 2:10:21 So definitely stay in touch. 2:10:25 Make sure to follow. 2:10:27 Botanics again. 2:10:28 And very soon. 2:10:30 We'll see that. 2:10:31 We'll see that. 2:10:32 That's not. 2:10:33 And then. 2:10:34 Yeah, I can. 2:10:36 I've been every time I use it. 2:10:38 It's quite incredible to see. 2:10:39 So I think a lot of the discussions will soon very quickly. 2:10:44 Very quickly change. 2:10:46 Cool. 2:10:47 Yeah, that's always nice when people can run the software and actually experience it. 2:10:53 That's usually better for learning about things. 2:10:58 OK, great. 2:10:59 Well, hey, thanks, everyone. 2:11:02 Hope you enjoyed this. 2:11:03 So. 2:11:04 Had a good time. 2:11:06 We usually hang out every week, every Friday afternoon. 2:11:10 So thanks a lot. 2:11:12 Awesome. 2:11:13 Thank you, Paul. 2:11:14 Thank you. 2:11:17 Bye, everyone.