0:00 Let's get a closer look at this at this tweet here, although I know I have two 0:03 laptops up here so I have to do the right one. There we go. 0:07 Okay, so this is why merged mining and Drivechains are such a nasty attack. 0:16 Paul is a really awful person to push this. And then we have here, we have even 0:24 more intrigue. Merged mine sidechains was Greg Maxwell's biggest mistake. In 0:31 fact, the biggest mistake of a lot of people. So there's just so much intrigue 0:35 here. My name is Paul Sztorc. I have a background in economics and statistics 0:41 particularly. For two and a half years I worked at the Yale economics department 0:45 for Bill Nordhaus directly. He won the Nobel Prize a few months ago. While I was 0:51 working there, I invented this Bitcoin technology called Truthcoin, which is 0:55 later split up into several projects. Augur and Gnosis are Ethereum versions. 1:00 There's one called M of AO by Zach Hess. That's its own blockchain. And then 1:05 there's a Bitcoin core fork that is called Bitcoin Hivemind. I also started a 1:11 cool Bitcoin blog called Truthcoin.info and have a bunch of famous posts up 1:15 here that a lot of people seem to enjoy reading. There's one about nothing is 1:20 cheaper than proof of work. Cycles back every now and then and we'll get like 1:23 seven, ten thousand views in a day when someone links to it. And I presented at 1:30 the first three scaling conferences and I was on the program committee for the 1:33 fourth one. More succinctly, I'm a really awful person, I suppose. So I was going 1:39 to originally give this talk on something kind of really specific and 1:42 esoteric, but instead this like thing happened like last week. So I thought 1:48 I'd kind of rearrange the talk and it will still be about what I wanted it to 1:51 be about, but it will just be in kind of a different order than you're thinking. 1:54 So first I'm going to talk about what sidechains are and how they work and 1:58 then I'm going to talk right and go right into these critiques because why 2:02 should you have to, you know, fight personally through all this technical 2:07 specialization when there's already people who will critique the project for 2:10 you. And then I'm going to try to maybe at the end sneak in this point that I was 2:15 going to make as the entire sidechains presentation before. So, two laptops at 2:24 once. Okay, I'm going to use a mouse like an idiot on this one. Okay, here we go. So 2:42 what are sidechains? Surprisingly the definition has become quite contentious. 2:47 The definition that I use is a little old-fashioned. It's this original 2:51 definition about basically saying that hard forks are bad because implementation 2:56 changes to the consensus critical parts of Bitcoin must necessarily be handled 3:01 very conservatively. But you can do something else instead where you can 3:06 kind of build a little compartment that people can opt into and this is a really 3:10 good sentence here I think. We propose a new technology peg sidechains which 3:15 enables bitcoins and other ledger assets to be transferred between multiple 3:19 blockchains. This gives users access to new and innovative cryptocurrency 3:24 systems using the assets they already own. So that's great. These are some 3:30 slides from Adam back from 2016. He's talking about the things that you can 3:35 use sidechains for a little bit more concretely. Basically though the idea is 3:40 that Bitcoin will, you can send Bitcoin to a different piece of software and the 3:44 Bitcoin money can kind of pretend that it's an altcoin. So it can pretend to be 3:49 like Ethereum or Zcash or Bitcoin Cash. This is a meme that I made on my 3:58 website when the price of Bitcoin was $6,800 and now I just scroll down. It's a 4:07 screenshot of CoinMarketCap and with sidechains there's no real need for 4:12 altcoins to exist because you can replicate their features perfectly. So 4:16 the least popular altcoin will be on the chopping block. It will probably 4:21 collapse and die out. And then the second least popular one will be the new least 4:25 popular living one and that one will die out and then they probably just be all 4:29 destroyed and something that I call iterative deletion. And so instead in the 4:36 sidechain world the different quantities of Bitcoin will be in different pieces 4:41 of software on different chains. And so you can see at the bottom here I have 4:44 this grand total 21 million coin limit and I have these 4.3 million coins that 4:51 have not yet been mined and we have the 16 or so 17 million that are in 4:55 circulation and they would be broken up. Not all of them would be on Bitcoin core. 4:59 Some of them would be hanging out on other projects and those projects are 5:03 free to take risks or be very dumb ideas. So that's the idea and this is a 5:10 it's kind of a restatement of this multiple blockchains hard fork 5:14 alternative concept. So I actually built this. Actually Cryptex basically did 5:21 all the work and he's also at this conference although I don't know. I don't 5:25 see him in the room so I guess he's taking advantage. Oh he's over there. So 5:28 Cryptex and I we built this and here's three screenshots. You can see this one 5:36 is Bitcoin core with a different color scheme but also with a tab that's called 5:40 sidechains in the top right. And then you here this is how you add a new sidechain. 5:46 You first you write the software and then you paste, excuse me, you paste the 5:51 hash of the software here and click this button. These are a little outdated. We've 5:55 actually made this a lot better but this is a will give you a basic idea. So 6:00 you just kind of click a button and then this sidechain. It's a little more 6:04 complicated than that but this is basically it. And then you have this 6:08 sidechain that exists in a list and you can send Bitcoin to this piece of 6:13 software and it will receive it. And then you can also send Bitcoin away from that 6:18 piece of software and get it back from this. This is called Grin but that's a 6:23 joke. This isn't actually Grin. It's just an example that we titled Grin which is 6:27 a MimboWimbo project of course but that's like an idea. It's an example of 6:31 stealing the altcoin technology. Okay. So how does it work? There is a, there's 6:39 these two components to Drivechain which is the sidechain technology that 6:44 Cryptex and I developed. One is this idea of the hashrate escrow which is like a 6:49 container output. It compresses three to six months of sidechain data into a 6:55 fixed 32 bytes and I'm going to explain that because it's pretty important. But 7:00 then there's this other thing called Blind Merged Mining which replaces the 7:03 act of running a sidechain node with the act of just including a single high fee 7:08 transaction. So what does all that mean? Well here I have a diagram in the main 7:14 chain is in orange and the sidechain is in green below. And the thing is the main 7:21 chain full nodes do not and cannot validate the sidechain rules or data. So 7:27 because that would, well I'll get to that in a second, but the whole point here is 7:32 that these are like optional plugins. So the main chain full node needs to be 7:35 able to see perfectly accurate picture of the network regardless of what 7:39 happens on the sidechain. But as there's a problem with that which is that to 7:44 below to the main chain full node these two histories will look the same. And I 7:51 have one where A sends money to B and then B sends money to themselves in the 7:56 sidechain. And then it changes owners to E and F. There's a different history where A 8:01 sends money to B, sends money to C, sends money to D, and then sends money to a 8:06 completely different person, H. And to the main chain these have to look the same. 8:11 You just see that A and B went in and E and F came out or that H came out. And you 8:16 don't know which one of them is legitimate. But since you are only tracking this net 8:25 effect, you can in fact compress it down to one transaction ID which is just 32 8:30 bytes. And we basically just cheat and we say these 32 bytes will probably be 8:34 correct although there's more to it than that as I'm going to explain. And the thing 8:39 is you've compressed it down to 32 bytes and the sidechain full nodes and the 8:43 sidechain SPV nodes will be yelling these 32 bytes constantly every block for the 8:48 32 months. So they'll be trying to warn everyone which of the 32 bytes are right. 8:54 But the only way to know for sure if they're right is to run the sidechain full node and 8:57 that is the illegal thing because that cannot be mandatory for our main chain users. And I 9:04 have this metaphor that people think is very funny but it's basically like you're trying to 9:09 cross this finish line. The 32 bytes are inserted into the main chain and then they 9:14 march very slowly across a kind of finish line. And the finish line is very, very, very 9:19 far away. It's 13,150 steps away and you can only take one step per block. So this is 9:26 very, very rare. 32 bytes, three to six months. And the thing is only one, per sidechain 9:33 only one 32 byte train car can advance at a time. So I have a funny video here. It's not 9:40 really a video but it's pretty simple and you can just see that only one of these things 9:44 will be able to take a step forward at a time because if you try multiple ones at once then 9:48 it's a mutual exclusivity. So if one advances the others go backwards. So you don't want to 9:54 watch this second from the bottom one. This one will go up a little bit first so I'll go back. 10:00 It's time equals ten and then one goes up and another one goes up and the other ones are 10:04 forced to go back to the finish line. Miners can also just abstain from moving any of these 10:10 or they can just say they don't know what's going on and set them all back. Ultimately you 10:14 can only get one to move forward. And I'm going to explain line merge mining in a second 10:19 because it's best explained. All this is best explained in the context of the critiques 10:23 because again what does it matter what I think, how I think it works. Let's hear from the 10:31 skeptics. So the two big critiques are this idea that miners can steal and also this extremely 10:38 esoteric Peter Todd point about an increased likelihood of main chain transaction censorship. 10:44 So I'm going to refute both of these or try to. Both of them are completely false and they're 10:54 both so weird and they have so many weird errors mixed in and just general confusion that I 11:00 actually often trip myself up by trying to articulate all of them at once which is why I wrote 11:04 this down. And you'll see it's like there's like five things wrong simultaneously with both of 11:09 them. So here we go. Now the idea here is that of course I just assume that these 32 bytes will 11:16 be right but there's nothing, absolutely no way of demonstrating that. And so why would I do 11:22 that? Why wouldn't the 32 bytes just be bytes that immediately reassign all of the Bitcoin to 11:27 like Jihan Wu or something. And the act of moving a train car forward, it only costs the 11:33 opportunity of moving some other train car forward so that that's not, you know, people are 11:38 not really convinced by this and they say, well miners will just take the money. So now I'm 11:45 going to respond to that which is that first in five parts and I'm going to read the reason and 11:51 then I'm going to put up a little summary. So first it's admittedly true that all SPV proofs, 11:58 whether or not they're Drivechain or something else, they have to allow miners to forge a 12:03 withdrawal of the funds because SPV proofs are only gated by proof of work. But that's 12:09 completely intentional because that's exactly what allows the sidechain to be optional in the 12:13 first place. So if we wanted to, we could easily prevent miner theft 100%. We could just force 12:18 all main chain full nodes to validate all the sidechain blocks. But that would be the so-called 12:24 evil fork or the soft hard fork and it would be a de facto unlimited block size increase for all 12:30 users and an unlimited, theoretically unlimited loss of decentralization. So it's like 12:35 intentionally we're avoiding this bleak outcome. The only, we have to choose one of three 12:40 options. One is mandatory sidechains and evil forks and unlimited loss of 12:45 decentralization. And the second one is alt coins whose mere existence violates the 21 million 12:52 coin limit through a kind of inflation tax. And then the third one is this sidechains whose 12:57 withdrawals only rely on SPV proofs where even miners can steal sort of applies. And so the 13:01 people who criticize Drivechain on this basis for its use of SPV security, they probably don't 13:07 realize that they're necessarily instead supporting either unlimited loss of full node 13:12 decentralization, mandatory sidechains, or else they're supporting an unlimited inflation tax on 13:18 bitcoiners via alt coins. So that is the first. Would you prefer that it were mandatory, in 13:23 which case it would be perfectly safe, or would you prefer these alt coins hang around and drain 13:30 resources from, and attention from bitcoin? Now the second thing is while all SPV proofs are 13:38 vulnerable to miner tampering, Drivechain has extra features as I just explained. So the thing 13:46 is compressed super low and you have these 32 bytes and they're announced and then forced to 13:50 march very slowly, one step per block, across the finish line that is very far away. So even 13:55 with 100% hash rate participation in the attack, this takes three months. So new contestants 14:00 begin the race at any time. Only one racer can step forward at a time. And whoever crossed the 14:07 32 byte finish line first will win. But these sidechain SPV nodes are going to be yelling as 14:14 loud as possible what the correct 32 bytes are. So even if there's constant maximum scale 14:23 professional tampering, it will all be very, very easy for the user to observe and demonstrate to 14:28 others. And investors and users have plenty of time to react to this. And one reaction could be 14:34 the UASF to block the tamper 32 byte transaction from ever crossing the finish line when it 14:39 finally gets there. And that's much easier than, for example, to SegWit UASF because it 14:44 requires no software development, no real life coordination on actions and timing. And if the 14:50 UASF fails and if the sidechain was objectively valuable, then the Bitcoin's total transaction 14:56 fees and exchange rate should fall, which would punish the very miners who instigated the 15:01 tampering. So it's transparent and it harms the miners. There are all these other rules that are 15:08 enforced by main chain nodes that make it much harder to steal from the sidechain. Third is 15:15 that some sidechains are bad and you actually want to get rid of them. So it's a good thing if 15:19 miners have an incentive to evict these people. It's kind of like a city with a large criminal 15:23 homeless population or something. Some of the sidechains, if they work correctly, they can 15:27 leach off of other sidechains, which is something that I hope to explain. We probably won't have 15:31 anywhere near enough time. But the point is you actually want to get rid of these people. And how 15:36 can you make sure that only the best sidechains are let in and only the worst ones are kept out? 15:39 You give the decision to the people who have the most skin in the game, who get the transaction 15:46 fees or who suffer when the Bitcoin price declines. Fourth, the very idea of can and the whole 15:53 miners can steal schtick is a complete misrepresentation of the way Bitcoin works. In a 16:00 naive sense, the miners can always steal Bitcoin, whether or not it's on Drivechain or main chain 16:06 or even in lightning channels. This is because miners just control the contents of the 16:09 blockchain. And so the true question has always been, will miners steal anything? And in 16:13 answering it, we always rely on these theories about miners' choices and motivations and 16:18 behavior. And then we apply those theories to a given design. So I think the purport of this 16:26 can language is to imply falsely that Drivechain design puts users' Bitcoins into immediate 16:32 risk of just being taken by the miners in the very next block and therefore that I'm assuming 16:37 some kind of miner altruism or something. But the truth is that there are features in drive 16:42 chain, especially the slow, transparent, high-effort withdrawal process that I assume will 16:47 convince the profit-maximizing selfish miners that harvesting the sidechains for their 16:53 transaction fees, the ongoing transaction fees and their value-boosting properties, is more 16:58 lucrative than just devouring them in one shot. It's like killing the goose that laid the 17:02 golden egg. So use of the word can equals does not understand the way Bitcoin works. And 17:10 fifth and most importantly, you can only steal funds that the user has deposited to a side 17:16 chain. So it's completely, non-sidechain funds are completely unaffected by sidechains, 17:21 obviously. And consumer sovereignty is a basic principle of Bitcoin. So users are allowed to 17:25 handle their own funds however they like and they're even allowed to destroy them or delete 17:29 them. And so you should really just let people make their own mistakes. Now, the second one is 17:36 extremely bizarre. And now I see that I'm not going to have a little bit of time to explain how 17:40 weird it is. So I'll run through this very quickly. But basically, the argument says that drive 17:48 chain increases the risk of transaction censorship on the main chain by giving economic 17:53 advantages to large pools, which makes them inevitable in equilibrium. And it simultaneously 17:59 makes these large pools less anonymous somehow and more susceptible to coercion, which 18:05 eventually affects the main chain users. Now, of course, this is why I invented blind merge 18:10 mining, which completely solves this problem. In regular merge mining, a miner needs to run a 18:15 full node of everything they collect transaction fees on. But with Blind Merged Mining, this 18:20 thing that I invented, you do not need to do that. So the problem is just solved. The full nodes 18:26 don't need to run the sidechain software. Instead of exchanging 100% of the fixed network, 100% 18:35 of the data that would go across the sidechain full node, they just need a tiny, tiny amount of 18:43 data, that mempool data, that's fixed. And let me explain. Let's see, I have a good way of 18:48 explaining how this works. Somewhere. Yeah. But I think I just won't, so, because I don't have 18:56 time. But even though I solved this with Blind Merged Mining, the complaint is actually complete 19:01 nonsense. And I would like to explain why in a lot of detail, but I think I'd rather have the time 19:05 for questions. But one reason is that there is a ridiculous magnitude of the argument. So I see at 19:13 the top, I'm saying this argument basically says that if Bitmain sells T-shirts on the side, 19:18 then eventually all miners will need to sell T-shirts and anyone who can control T-shirts will 19:23 control Bitcoin and then Peter Todd admits that that is in fact what he's saying, which is 19:27 ridiculous. And the thing is, I have a long couple paragraphs here that I'm not going to get to 19:32 read, but the argument ends up contradicting itself because he's saying that every 10 cents of 19:37 profit eventually becomes mandatory. But this is a, you know, an inducement of 10 cents is 19:42 different from something that's really mandatory. But there's more to it than that, which is that 19:46 the argument ends up contradicting itself because it says there'll be main chain transaction 19:49 censorship and those main chain transactions pay transaction fees. So including every single 19:56 main chain transaction, mining pools are going to end up fighting for that just as hard as they 20:03 would fight to, you know, get any other source of profits, the T-shirts for example. So, and 20:10 again, I don't have a lot of time for this, but there's a conflation between mining 20:13 centralization and node centralization in the hopes that by using the word centralization, 20:19 you'll be tricked into thinking they're the same thing even though they're completely different. 20:23 And in fact, miners are suppliers and users are customers. So what's good for one will 20:29 eventually be something that's bad for the other. So it's actually, I would like to explain a lot 20:33 of this more, but I don't have enough time. The other thing is transaction censorship is a 20:37 privacy issue. So if you just solve privacy, then you don't have to worry about this at all. 20:41 It's really, that's the main focus for anyone who's worried about transaction censorship 20:44 should be focused on that. The other thing I do want to mention before I just sprint 20:48 through directly to the end is that we probably need the merge mining fees. I don't have time to 20:53 explain what this is, but basically it's a security budget over 40 years of fees are zero. 20:58 And I've compared it to the USA defense budget and it's on billions per year. And what I would 21:03 have explained is that the block subsidy and the transaction fees are completely different 21:06 things. And in fact, people have now learned to use altcoins as a medium of exchange and the 21:12 fees are low, which means that we currently get about $10 million per year in fees. We get like 21:18 $200 a block. And without merge mining, we might, the fee, the total amount of fees might 21:24 plausibly never be higher than that. And so it just adds 0.01 cents when priced in billions to 21:29 this and then that's not enough. So far from being a threat to Bitcoin, it's possibly the only 21:35 savior. And vanilla merge mining can't be stopped. So I don't know exactly what Peter Todd's 21:40 argument is because this is like inevitable. And not the Blind Merged Mining part, the vanilla part 21:46 is less difficult, even harder to stop. So actually I was going to talk about another thing and then 21:51 relate this to my original point, but I kind of basically don't really have time for that. So 21:55 oh well. And there we go. So yes, questions. And I'll be here all day. So sorry about that. Yes, 22:00 Andreas. Did I start five minutes early? I thought I was, no, I think I was moved to 10 22:13 recently. I was. It's okay, Andreas. I can give it to you personally afterwards. Yes. 22:24 Yeah, WinMainNet. I don't know. Maybe there's a soft fork this summer. Maybe. I don't know. 22:28 I have no idea. You never know. That's a cursed question. Didn't you see Dan Anderson's talk 22:32 yesterday? You're not supposed to ask those kind of questions. Those are cursed questions. Okay, 22:38 yeah. Sorry that was kind of all rushed and everything, but yes. 22:41 Ah, but what are they speculating on? The features, right? Or the properties, the lower fees? 23:00 A lot of people, you know, log coins really had a basically nothing market share until Bitcoin 23:05 fees went up. So a popular view is that the Bitcoin fees inspired people to switch. 23:10 Just for people who do the round trips, you know, a person who buys $20 worth of... 23:22 We had Ethereum. I think it's similar, though. I think it's a similar story where people noticed 23:26 something about Bitcoin that made them uncomfortable and then they sort of left. So with 23:30 Ethereum, they were like, this is like a Turing complete thing. Or there was like concerns about 23:36 how the scalability debate would be resolved one way or the other. Some people thought 23:40 this is too easy to change. Some people thought this is too hard to change. So I think it's still 23:44 a... I guess I would almost flip the question around and say, what else would explain it? I 23:52 mean, a lot of people want to make money, right? But so many things don't... There are lots of 23:58 things that don't... That could be scams but just don't work. So I could try to sell you monopoly 24:03 money and I could say this is all for greed or for speculative value, but it doesn't work, right? 24:09 So you need... Somehow you need to like close the loop. I need to convince you to actually buy my 24:12 monopoly money. You see what I mean? It's not like... Yes, thanks. That's two minutes, right? 24:18 Thank you. Does that answer your question or no? Okay, good. 24:33 Yeah, but I have to clarify that I think they just won't steal any money in lightning channels 24:38 or mainnet or anything. I just... That's why I think it's just a... Yes, you were saying? 24:41 I think it is... Well, I don't know about fundamental, but there are all these assumptions 25:10 about... You'd have to say... I would say something like the amount of money if you actually... 25:17 It's hard to explain quickly, but we're talking here about this large magnet. I think you're 25:22 right that it is, but that's why there's a 13,000 block thing instead of just... The way in Bitcoin 25:27 it works is it's just one block and then you're considered on the track to be valid. But this 25:32 thing isn't even considered to be valid until after 13,000 blocks. So the magnitudes are different. 25:37 That's why one is so difficult, such a difficult trial to try to offset that type of thing. And I 25:42 do think that there's... At some point, it jumps a category where it's not just like the longer, 25:46 the better. At some point, it's just so long that you just think like, wow, if something like this 25:51 is going to happen, it just must be because everyone wants it to happen and that kind of... 25:59 Well, there are a couple of things also to say. The reorg, if you do the reorg the right way, 26:02 you can steal a ton of money. And if you're going to reorg on that scale, 26:07 you can steal on that scale for like 13,000 blocks. That's like the amount of Bitcoin 26:12 to turn over per day. It's like a huge amount of money. So it's more than could even... 26:22 Yes. No, you're right. The compartments are a weakness here because you want everyone to be 26:28 in the same boat and you do not want some people to be stigmatized. But one counterpoint to that 26:34 though is that all the sidechains should at least be in the same boat. So if you got one 26:37 or two popular sidechains and one kind of stupid sidechain that's like marginally stupid and so 26:42 like barely not stupid and just kind of no one knows what they feel about it, you still think 26:48 that maybe miners would not want to steal from that one because they'd be like, this will just 26:51 cause theft, this will cause fear in the whole sidechain's infrastructure. And I had something 27:00 else I was going to say but I can't remember what it was. But you want that to blend together 27:05 and then you'd want... I have another great point but I can't remember it. Sorry. All right. So I 27:09 think we're almost out of time, I guess. Yep. Okay. So that's the talk. Thank you very much. 27:16 I'll be here all day.