0:30 and I'll have 30 minutes. So, we're going to do 15 minutes of this kind of background lead-up 0:37 to the problem, and about me and the context and the things that I think are important, 0:43 and then five minutes on this thing, and then I do think the Q&A is really where the magic 0:47 happens, so I think that Q&A is good. I'm going to say some pretty audacious things 0:51 in this talk, so it's only fair that people get to ask questions about them, but I do 0:56 have a kind of a long intro slide. So, I spoke at all three of the first scaling conferences. 1:02 I was on the program committee for the fourth. This conference is supposed to be continuing 1:06 in that vein, but what happened after the first three, or really even the first two, 1:12 is that the scaling conferences quickly became pretentious academic junk conferences, so 1:18 I stopped going, and I think this conference is also in danger of falling into that mold, 1:25 although there were some good talks, but the other thing is that in December 2013, see, 1:31 this is actually all important, because it's very difficult for you to understand why CUSF 1:36 is the solution to something unless you understand me and sort of where I'm coming from, so all 1:42 this is actually important, but back in December 2013, I had this peer-to-peer Oracle prediction 1:48 market blockchain technology that I called Truthcoin, which was supposed to be a side 1:53 chain L2, even back in 2013, which I quickly renamed to BitcoinHiveMind.com, and you can 1:59 actually go to that site, and you can still look at it if you want. I had to rename it 2:03 because people thought it was an altcoin, but this project basically became Polymarket. 2:08 In fact, Polymarket is a much worse version of what I produced in 2013, but although I 2:13 give them tons of credit for executing, but it just, this speaks a little bit to what 2:19 a lot of this talk is about, which is that we've had a little bit of slow developer action 2:26 that has translated to, you know, billions of dollars per month in lost volume, and so 2:34 that's part of what I'm trying to get at here. Then, so the reason why this never turned 2:40 on was because the company Blockstream that planned to deliver on peer-to-peer sidechains, 2:46 they sort of never actually delivered on that, and so that's, this next thing is that after 2:51 they failed to deliver that technology, I had to do it myself, which began as this essay 2:57 measuring decentralization from September 2015, and then it later became the StriveChain 3:02 blog post, and then it became BIP300 today, and that's part of what I'm going to talk 3:06 about in a little while. And then furthermore, I did this presentation in June 2016 called 3:13 sidechain Privatization, which basically anticipated not only MEV, but also the more 3:18 complicated cross-chain MEV, and this led to an invention called Blind Merged Mining 3:25 in January 2017, which later became BIP301, and which today would be known as Proposer-Builder 3:32 Separation, and what this does is it automatically converts all L2 block value, including the 3:38 transaction fees, any indirect value, DEX, arbitrage, whatever, it transforms all of 3:44 that value into L1 transaction fees, and miners don't even need to look at what is happening 3:50 on the L2, which is hence the name Blind, and then there's more stuff, but it's not 3:55 really important, so. Okay, I have a very different take, which I'm going to explain 4:00 now on this L2 situation, which is this is the endgame for Bitcoin as I see it. These 4:07 circles are to scale, which is why I used the monospace font here to get them to scale, 4:11 but the left circle is, you have to understand what I'm getting at here, which is a little 4:15 hard to explain, but the left circle is all the transaction fees paid to miners in the 4:20 year 2022, and the next one over is the fees in 2023, which was the ordinal's year, and 4:27 the third one is back in 2022, all of the fees collected by all altcoins that are not 4:33 Bitcoin, and then this gigantic circle all the way on the right is the value of all the 4:38 transaction fees paid on earth in 2022 if they were on Bitcoin, and so this is an estimation 4:45 that I made, so of course I have to admit that I sort of eyeballed it, but I did look 4:49 at quite a few things. I looked at the credit card company statistics, I looked at WeChat 4:54 pay, I looked at the Federal Reserve, there's a payments study, and I have a huge blog post 4:59 where I go into the details in writing, which I'm going to reference later in the talk, 5:05 so you'll be able to look it up if you're interested, but basically I came up, you know, 5:09 I looked at like population of the world that is over 14 years old, and all this other stuff, 5:13 so it's basically 6.4 trillion dollars in 2024, you know, trended back to 2022, and 5:21 then the 10 cents for transaction, because that's very low, and it's significantly lower 5:26 than basically everything else that exists, and it's so low, but you see once you get 5:31 to 10 cents, someone can only undercut you by around 9 cents per transaction, and I thought 5:36 that's probably not enough to get people to switch networks, so that's kind of, I just 5:40 eyeballed it as the equilibrium fee, but people are free to use whatever numbers, but the 5:44 point is it's a huge amount, and the other thing is it doubles in value, it grows at 5:49 6.2% a year, it probably goes faster than that, that's the lowest estimate, it's something 5:59 like, yeah, it's something like 3 per day per person above, yeah, it's per year, right, 6:06 so this doubles every 11 to 12 years, yes, okay, so why do I bring this up? Well, okay, 6:17 the first question is a very important one, which is, if Bitcoin took over the world, 6:22 who would get this giant pile of money? And the current intellectual climate is pushing 6:28 these non-mined L2s, which would include the Lightning Network, ARK, Rollups, Liquid, these 6:36 are not mined L2s, and by that I mean the transaction fees on the L2, they do not go 6:42 to the L1 Bitcoin miner, instead they go to someone else, they go to the Lightning Node 6:47 that routed the payment, or they go to the LSP, or they go to the ARK SP, or they go 6:54 to the sequencer, the Rollup sequencer, so the money goes to someone else, and of course 7:00 that's kind of rude to the miners, but that's not really why I bring it up, it's really 7:04 much worse than that, it's actually very, very interesting what will probably happen, 7:10 and my guess, this is a complete guess on my part, but I don't see how it can be any 7:14 other way other than to produce this horrendously unstable situation that will end in a conflict 7:21 between the L1 and L2 overall, and a huge incentive for miner centralization, and then 7:30 eventually vertical integration between the L2s and the L1 miners, and then this vertical 7:36 integration will utterly obliterate the entire L2 security model in the first place, the 7:42 L2 will end up fully custodial, possibly even miner custodial, and then the value will all 7:47 become MEV in fact, I have a little bit more to say about that later, so the reason that 7:55 I bring, let me explain a little bit more about this, which is to say, so the miners 7:58 get this tiny circle, and then there's this huge circle above going to like the ARK Super 8:02 Node or something, the reason why this is actually important is that the miners have an extreme 8:08 ability to affect the L2s, every L2 is vulnerable to 51% attack by L1 miners, for example, the 8:17 Lightning Network requires a L1 transaction to join the network, and it requires one to leave 8:21 the network, and the Lightning Network only works at all if you can broadcast justice transactions 8:27 to L1 whenever you want, and the 51% hashrate group can censor these transactions, and if you 8:33 don't believe me, here's Rene Picard, who wrote the book Mastering Lightning, he's saying 8:37 exactly what I'm saying here, and this is the same for BitVM, where BitVM has like a justice 8:43 transaction that is basically something like, if someone does something that they would not be 8:48 allowed to do in the L2, you pull this on L1 and you can slash their bond or whatever, the 8:55 different L2s are very different from each other, of course, but no matter what the L2 is, the 8:59 miners can block the entrance and the exit, if they can figure out what it is, so there's some 9:06 little bit of animosity would go a long way, so basically if we return to this example where you 9:12 have like something like a Foundry LSP, you know, or Antpool LSP, a Foundry Lightning on one hand, 9:18 versus the Lightning Nodes that are not backed by giant amounts of hashrate, then it would be 9:25 completely understandable for the actual end user to get nervous about using the non-mined 9:29 LSPs, because they would not be secure, and the HTLC would really do nothing, and eventually the 9:36 non-mined, you know, the non-miner associated LSPs would go out of business, and everyone would use 9:42 a minor LSP, all the HTLC stuff would be superfluous, and the Lightning security model wouldn't even 9:49 apply in this case anymore, and the interesting thing is that all of this, the whole L2 value of 9:53 a giant sphere, or a giant circle, that would all become MEVs, since it would now become mandatory 10:00 to become a Lightning service provider, it would now, every viable miner would have to become an 10:06 LSP, and they would have a monopoly as well, because it would be very difficult to start a 10:11 new Lightning company now, and on the flip side, it would be difficult to start a new mining pool, 10:16 so it would really be some kind of like super MEV, and so the bizarre thing, ironically, the only way 10:23 to undo the MEV at that point would be to create a mined L2, and then hope that everyone switches 10:29 to it, and so even if the ones on the left had succeeded, they would end up, we would end up 10:34 wishing that they had failed. In other words, the non-mined L2s are not going to work. They may 10:41 work in the superficial sense of the software not crashing, or the software being able to put 10:47 transactions through, for some people, but I think this means that they can never really be big, you 10:53 know, they can never really be a big success, because as soon as they're a big success, they'll 10:57 never really be this, you know, this huge circle. As soon as they are, miners will think, why am I 11:01 getting this tiny circle, and the LSP is getting this huge circle. We can talk about why the tiny 11:06 circle will probably stay tiny on L1, but it's a different question, and then people think, miners 11:12 will think, well, why don't we start our own, you know, mining LSP, foundry LSP, and then they get 11:18 into a fight, and it is a battle where one of the sides doesn't have any bullets. So instead, here's 11:25 my proposal for the mined L2s, which I'm now calling 1313, due to a math coincidence, but the 11:33 details are in two blog posts of mine that are very old. I mean, this one is from February 2021, 11:39 but basically it's a very small L1 block size that we have already, and then 13 separate L2s 11:47 distributed amongst users on the planet, more or less geographically, each released one at a time 11:53 as the previous ones fill up, and they start with what is the equivalent of 13 megabytes, a block 11:59 size that grows over time for each of them, and then this is the other one here. This is this post, 12:04 all the world's transactions, where I talked about the estimates for, you know, how many transactions 12:10 are actually in the world on a given year, and it has this table, and I have them, if they grow at 12:17 those rates, and then it converges to a planetary scale by the year 2030, which is a 9.8 trillion 12:24 transactions per year, and so that is this schedule, and this idea, from the end user's 12:31 point of view, is better than Lightning, which is, you know, the viable L2 today, in the following ways. 12:37 I'm not going to list them all, but I'll list a few, which is like, it has, there's no channels, there's no 12:41 interactivity requirements at all, there's no liquidity problems at all, there's no, like, fee for 12:47 liquidity, as with ORC, you can onboard people directly to L2 without using L1 bytes, and the payments 12:53 don't fail, and of course, 100% of the fees are passed down to miners instead of 0%. It actually has 13:04 more benefits also, it actually slightly improves miner centralization by allowing faster and smaller 13:10 cashouts to, from pools to the end hashers, and furthermore, it does not require any changes to 13:17 Bitcoin Core at all, but it does require this thing, CUSF, which I am going to get to eventually, pretty soon. 13:23 So, and on top of that, we just, I love the dev tooling talk, that's great, the software already 13:32 exists today, so here it is, we've built it, actually, and it even has a little GUI there, up in the top 13:39 right, so it has a wallet, it has interface, Bitcoin Core, the L1 is in the bottom left, and then the L2 13:47 thing is in the top right, you can't really see it right now, but this is the new CUSF version, in fact, so 13:54 now, I think I have a little bit to get through what this is, it's, I think it's going to be kind of 14:00 difficult to understand, you know, but I'm going to try to explain it anyway, so, because some people will 14:05 think this is such a small idea, it doesn't count as anything, and other people will think this is so drastic 14:09 an idea that it is, so I don't know what you'll find yourself in, but, CUSF stands for Core Untouched Soft 14:16 Fork, and it threads the needle between these two roadblocks, and one of them is this, which is that Bitcoin 14:25 Core cannot soft fork anymore, these numbers are from BitMEX research, they are not mine, but I put them in 14:33 this table, and this is a table of soft forks in Bitcoin's history, and you can see that we used to do one every 14:40 two years or so, and now we do basically zero, I also took the opportunity to look up the time it took to get from 14:49 the first, you know, concrete mailing list suggestion of the idea, to when it was coded, and then when it was 14:58 actually activated, and so you can see SegWit was 20 months, and Tapper was 46 months, and I think if you have been 15:06 paying attention today, you see that there's all these ideas, but everyone has this, for whatever, every single idea 15:12 that someone has put forward, that's like someone's least favorite idea, and so there is no actual consensus on 15:19 anything, and so that is why there's this logjam here. So this is the first roadblock. The second roadblock, though, is 15:27 that you really cannot just switch away from Bitcoin Core to something else, that's too drastic of a change for a 15:31 variety of reasons, like to leave the, for a completely different client, it might disconnect you from the network, 15:42 and it might, you might wonder, like, who is going to maintain this in the long run, so you can't do that type of thing, 15:49 there's no way to actually compete with Bitcoin Core with the second client. One reason is that they have these CVEs that 15:57 are only disclosed to them, they're the only ones who know about these security vulnerabilities, which they sort of must 16:02 keep secret, and so this is just one reason among many why you cannot write a competing client, basically. And so this solution 16:14 here is that you keep Bitcoin Core completely unchanged, and you just keep, it's almost like a dependency or something, you just 16:19 have it there, doing its thing, same thing it did before, and then you release a second piece of software that manages the 16:26 soft fork only, and that is called, you know, that would be the QCEV activator or something, so after Bitcoin Core scans the 16:33 block, it passes the block to, like, the OP_CAT activator, for example, it scans the block again, and then if there's any OP_CAT 16:42 rule-breaking over there, that's the only thing it's scanning for, second time, then it tells Bitcoin Core to reject the block, and 16:49 this makes the soft fork, you know, it's much faster, safer, easier to understand. It's safer in particular because it's a little bit 16:57 more reversible, you don't have to, like, restart the mining operation, you just add the second piece of software, and then if the 17:03 second piece of software is low quality, or if it crashes or something, then it's just, like, not there. The soft fork temporarily 17:09 deactivates in that situation, but it doesn't have, it doesn't affect any, doesn't have to affect anything that is currently running. I 17:17 mean, it's a nuanced question, but. Yeah, and so also, this is a paper here. I stashed it at this site. This is just a site that I 17:26 grabbed quickly, bit300qcev.com. There is a paper there, you can check it out. This thing, the ordinalization of soft forks, I don't 17:36 know if that will help people understand or make it more confusing, but, like, ordinals are, like, you have the existing thing and 17:41 then you run a second thing that helps you make more money, and this is similar in that way, so I don't know. It's not exactly the same, 17:48 but. And we have the software already. I did do it for BIP300/301, and I also did it for OP_CAT, the bit 347 version that we heard 18:01 about earlier today. So the software already exists, and you can fork this software, and you can make a CTV activator or whatever, if you 18:10 wish. Okay, let's see. Okay, good. I have almost 20 minutes exactly, so I think I'm going to, I think I will do this slide, though, which is 18:19 that, okay, this, in one sense, this is really no different than how any other soft fork would activate, but in another way, it's very, very 18:25 different, so. It has the same effect as a soft fork. I think one interesting thing about this idea is that most people don't understand what a 18:33 soft fork is or what it's doing, and as a result, this is like the best way of explaining to someone what a soft fork actually is and why it's, you 18:43 know, mostly harmless. But it has the same effect, but there's two different software, you know, demons, and there's, it is inefficient in the 18:54 sense that the computer basically has to do twice as much work as to scan all the blocks a second time, but it's more efficient in the sense of 19:02 humans because we don't have to get a pull request through Bitcoin Core because they do not want to do any controversial pull request ever, and as 19:10 you can see, it's very easy to just manufacture controversy even about things that are objectively harmless. So I guess I think I will sneak this 19:20 last one in here. So again, so just to get it into three bullet points, I think the idea is miners run this, to scale Bitcoin, you know, miners run 19:30 this BIP300 accusive activator, Bitcoin Core continues to do nothing, which they're very good at that, so, and then once 51% hashrate is running it, 19:40 then this will activate. It will only activate for as long as they are running it, and then of course regular people can run the activator with their own 19:45 node also to do that, to validate the rules, which would be the full node in that case. And then the miners activate these mined L2s and they collect money 19:57 from them, and then Bitcoin has scalability, privacy, etc. And I have to compare this to, the alternative plan is to take the same people who for years have 20:06 been overly optimistic about the viability of lightning, and then wait for them to finish ARK or whatever, or some other thing where there's not even dev tooling 20:14 for it yet, which is going to be way worse for the end user, and it's more complicated and more expensive, and it may not work at all, and then such that even if it did 20:24 work, the miners won't get any money, which will lead to this conflict that I mentioned before, and then that will lead to this total collapse of the original 20:33 security model anyway, and then all of that is even if we, if it takes too long for us to actually finish this, Bitcoin might be replaced by something else, 20:42 because we can go very slow for a long time, but until we actually have, if it's possible to get 8 billion users of a certain coin, and then other people are trying to do 20:51 that as quickly as possible, and we don't, then that doesn't look great for us. So I think, yeah, I have tons of extra slides, and I have even more stuff, but I would like, I think the 21:00 questions are far more important, so if you don't ask any questions, I will do random slides. 21:05 Or let them know about the issuers. 21:08 You can maybe just yell it out, I can repeat it. 21:10 Okay, so my question is with the CUSF implementation, what about the fragility of having an additional client working through the RPC, connecting to Bitcoin Core, 21:19 to then validate once, after they come in, to make sure that any rules are invalidated? 21:25 Couldn't that be three scenarios where essentially you as a miner are kind of switching your validation logic on and off, depending on if the program is working properly? 21:33 That's the point. 21:35 You don't have to restart the whole server. 21:37 You just have to restart the server here. 21:39 Yes, the question, if people didn't hear it. 21:41 You enforce the rule. 21:43 It goes down, right? 21:45 It's a very good question. 21:47 It's a very good question. 21:49 The question was, I think, if I heard it correctly, was, doesn't this, we have now a second P, instead of it all being in one Bitcoin Core, you have it in a few things, if one crashes, and the other people's done, 22:00 and once it was on, then won't there be inconsistently enforced rules, and then maybe there'll be like a fork or something. 22:06 Yeah, so the key thing to keep in mind about that is that that is accurate, but that is actually true of every soft fork. 22:14 It's just this implementation. 22:16 So I think, in a sense, you're right that how it is implemented may affect whether or not the implementation is reliable. 22:26 But I think that the bigger issue is like, okay, let's think about it a little bit more like this. 22:34 The new soft fork is just, this is not like something where you're going to keep releasing a new version every three months. 22:40 This activator will just do like the OP_CAT 15 lines of code, and so it will be like a finished product. 22:46 So it was kind of like, it will either crash at first, or it will be a finished project, I think. 22:54 I don't know if that answers the, I know, this is a very new kind of weird thing. 22:58 To rephrase that question as a comment, and then I'll make it a question, I guess. 23:04 This is a terrible idea to have a separate piece of software, especially if it's something like Python, 23:08 because if you do succeed in getting the soft fork activated, then that Python code with whatever subtle bugs it has 23:16 becomes consensus, and somebody like Bitcoin Core will have to then reimplement it in C++ and make it permanent. 23:22 But kind of what I would suggest here is if you want to activate a soft fork this way, 23:26 just make a patch of Bitcoin Core, and yes, your pull request might never get merged, 23:32 but you can always just release your own Bitcoin Core version that says like, 23:36 this is identical to Bitcoin Core version 3.29.0 with only this new opcode added. 23:42 The reason why that will not work is because of the rebasing. You have to constantly rebase. 23:46 Yeah, rebasing and opcode is not that hard. 23:48 I disagree. 23:51 We've been in here to ask. 23:53 I would say that if you can do that, you should not be doing soft forks. 23:57 I refuse to accept this critique. 23:59 The rebasing is like an endless vampiric draw on whoever wants to do something new. 24:07 See, this is the issue. 24:09 The issue is that the existing thing doesn't work. 24:11 And the other thing is, I had this in extra slides. 24:13 I know I'm like scamming people now with this, that I would do questions. 24:17 I read this paper, which is a very cool paper. 24:19 I read it on the train ride up here. 24:21 And this is what we've been hearing a lot today about like, 24:25 should we adopt the soft fork and like twiddling little, 24:27 it's like, I don't know, we're changing the temperature on the faucet or something a little bit. 24:32 But to me, this is a matter of life or death. 24:34 Either we aggressively pursue innovation and adoption as quickly as possible, 24:40 or we will probably eventually be replaced by something that does. 24:44 So this is like a cheap alarmist thing. 24:46 But I don't really see it this way of like, do this, do that, or whatever. 24:51 I just think like this is like a huge mistake and a huge risk for no reason. 24:55 And so we need something that actually works to draw in people who want, 24:58 people like Jeremy, he can't be up here making a slide that says, 25:01 I've been doing CTV for the last 800 years and nothing has happened. 25:04 And then now later on, we decide, oh, covenants are great. 25:08 No one was talking, Jeremy was talking about covenants like whatever, 25:11 like in 2016 or something. 25:13 And now everyone has decided, we can't wait. 25:16 We have to do something where there's the risk. 25:19 This is the whole point of this idea is it concentrates the risk in the new software 25:23 and it does not, it has no interaction with the existing software. 25:28 We cannot have people forced to explain it to Bitcoin Core 25:34 because people in Bitcoin Core, no offense, you know, they don't get it. 25:37 But you're describing two separate problems here, right? 25:39 One is to get a change through that you want 25:41 and maybe not everybody in Bitcoin Core wants it. 25:44 And the second is implementing that change. 25:47 So the first part, like if people don't want it, that's one discussion. 25:50 But if you implement it in Python, which it sounds like what you're doing. 25:54 No, it's not in Python at all, it's in Rust. 25:56 Fine, you can put it in Rust. 25:58 But the point is that that change is going to be there for eternity if it succeeds. 26:01 And so somebody will have to execute that Rust code for eternity. 26:04 I don't think that it necessarily should be. 26:06 I actually think we should be a little more experimental with the software 26:09 because they don't need to be there for eternity. 26:11 Because imagine if the software crashes and is abandoned, 26:14 then all it means is that the software deactivates 26:16 and anyone who tried to use it loses money. 26:18 But that's no different than the way the Lightning Network worked for like five, six years 26:22 where it was like in a state of being half-completed 26:24 and people would lose money all the time. 26:29 Okay, clearly very fruitful for discussion. 26:32 A lot of questions, but I'm sorry, we're going to have to move on to the next one. 26:36 So, sorry Marshall, sorry Trey, sorry anyone else who has any questions. 26:41 But if you do, grill Paul out in the hallway over there 26:45 or in the conference room on floor 14. 26:48 Also there's coffee out there now for anyone who needs a little bit of a pickup. 26:51 But with that, thank you Paul, appreciate your thoughts.