TFTC: A Bitcoin Podcast - #207: Tom Trevethan

Episode Date: November 6, 2020

Join Marty and Matt as they sit down with Tom Trevethan, CTO of CommerceBlock, to discuss: - Statechains - Mercury Wallet - Trust tradeoffs - Privacy gains - Fee structure - Custodial tradeoff - Use c...ases - much more Follow Tom on Twitter Checkout Mercury Wallet Shoutout to this week's sponsors. Cash App. Start #stackingsats today. Use the promo code: "stackingsats" to receive $10 and contribute $10 to OWLS Lacrosse when you download the app.

Transcript
Discussion (0)
Starting point is 00:00:00 What's up, freaks? It's your boy Marty here to introduce this episode of Tales from the Crypt. Matt O'Dell and I sat down with the CTO from Commerce Block, Tom Trevison, to talk about Mercury Wallet, the software they're building to implement state chains so that we can get another second layer scaling solution and privacy solution built on top of Bitcoin. It's a very interesting episode. If you guys are interested in state chains, I highly recommend you pay attention to this one. We dive in, talk about the trade-offs, the security benefits, the privacy benefits, everything that's going on. I'm really excited to see state chains in the wild, and I think Tom does an incredible job of explaining them, and I'm very happy that him and the team at Commerce Block are building out Mercury Wallets so that we can get them to market.
Starting point is 00:00:51 This episode of Tales from the Crypt Is brought to you by our good friends At the motherfucking Cash App You freaks already know all about them But if you don't know about them If you already know about them Then you shouldn't not know about them
Starting point is 00:01:07 But if any of you are out there And you don't know about them Cash App's helping you stack sats Send sats Sell sats Receive sats And you can make sats the standard We're saying sats sats sats sats sats
Starting point is 00:01:17 Because we're no longer Buying fractions of Bitcoin We're buying whole sats, tens of sats, hundreds of sats, thousands of sats, tens of thousands, millions, tens of millions, hundreds of millions if you're balling out. You can make sats a sender. You can DCA into sats too. If you want to buy daily, weekly, or biweekly, you can set it and forget it. We've got to figure out when we need to front run Matt O'Dell. He admitted it last night in a rabbit hole recap that he changed his daily buy.
Starting point is 00:01:46 so we need freaks to get out there and start their daily buys at random hours just so we have confidence that at least one of you is front running matt odell uh on top of the sat stacking stacks liver's stonks if you're into the stonk market you can invest in stocks okay i know all of you aren't into the stonks you're not big stonk fans the option's there right if your favorite stock's a little too expensive you can buy as low as one dollar via the cash app because all this is connected to your bank account there's no four to five day waiting periods cash app may even be your bank account they're offering account number and routing numbers so that you can direct deposit your
Starting point is 00:02:22 paychecks into the cash app bank of the future check it out use the code stacking stats when you do it's s-t-a-c-k-i-n-g-s-a-t-s you're gonna get ten dollars and ten dollars gonna go to our good friends at owls lacrosse that's owls lacrosse enjoy this rip i learned a lot i hope you do too okay you've had a dynamic where money's become freer than free if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting like safe haven i believe that in a world where central bankers are tripping over themselves to
Starting point is 00:03:19 devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean that's part of the bull case for bitcoin if you're not paying attention you probably should be what is up freaks welcome back to tales from the crypt it's your boy marty bent here uh first podcast recording in my uh my three-week uh getaway from the united states uh in the islands i've got i've got a new uh studio here i think it's much better than the one i have been recording out of uh but matt and i are very excited for this conversation we're sitting down with tom uh god we were going over your last name trevathan trevathan uh trevathan uh from commerce block the cto commerce block uh a company that launched the uh mercury wild
Starting point is 00:04:14 on bitcoin's test net a couple of weeks ago we wrote about it it's an implementation of state change which is a second layer solution that we have been writing about and talking about but wondering whether or not it would ever get implemented so it seems like mercury wallet has launched an implementation of state change and we're just excited to learn about it and to talk with you tom to learn about why you guys built this to learn about state change in general so i think to start just learn a little bit about you and what you do at commerce block I guess, how did you find yourself in this position, particularly working on state chains? Yeah, so my background is I was a physicist. I worked at university doing research,
Starting point is 00:04:58 mainly in theory and computation, so computation modeling. And then a few years ago, I made the decision to kind of leave academia and haven't looked back since then. I'm kind of enjoying startup life, which I think is more exciting, more kind of dynamic. So yeah, so I joined Commerce Block, must be about two and a half years ago. And they were just starting out. And at Commerce Block, we've essentially, what we were previously doing was creating uh kind of blockchain solutions for clients um who wanted to um uh tokenize things so we had this this big client uh called dgld they wanted to tokenize gold um and uh so we um created a uh a platform for them to do this based on elements which liquid is based on um and uh
Starting point is 00:06:03 So they wanted a, their own, you know, they wanted to have, you know, permission control over this. So they wanted like KYC integration and stuff. And so we forked elements and created basically a platform for them to use tokenized as gold. And the idea was that this is all backed up by Bitcoin's immutability and proof of work. So we developed this protocol to basically utilize Bitcoin's immutability, which goes a bit beyond just simple timestamping that use this kind of idea of Peter Todd's of like a single use seal so that you can prove uniqueness of this secondary chain. So it's basically an asset backed side chain. And so this is what we've been working on for the past couple of years. But we've struggled really to get kind of traction. Our big argument is this is a great way to scale. And the whole idea of issuing tokens on Ethereum is there's
Starting point is 00:07:10 huge scalability problems in that if you wanted to verify the ownership of something, verify the token on Ethereum, you have to verify the whole Ethereum blockchain, which is growing bigger and bigger all the time. So basically our motivation for this kind of approach was a scalability one, but really we've struggled to find attraction and issues with exchange integrations and competing against the kind of big players, you know, EOS and all these people that are essentially funding people to use their platforms. So, yeah, kind of went on from this. We did get interest from a few people doing privacy-based sidechains
Starting point is 00:08:03 kind of separate from Liquid that would be... Excuse me, Matt. Matt, there's something going on with your computer or something. It's like putting in this loud noise. I think it's going to mess up the audio. Is it really? Is it coming from my side? Yeah, it's definitely coming from you.
Starting point is 00:08:22 It happens on RHR too, but since you record the audio, it doesn't mess that up i think it would mess this up though you just mute while you're not talking yeah there we go perfect sorry tom um yeah so essentially we've we've kind of started to well yeah we got some interest in doing privacy-based sidechains but then the the real kind of thing uh that kind of pivoted us is that we got interest from someone to work with us to develop like a discreet law contract based system and one of the so what we they want they wanted to provide some kind of derivative based platform and we've suggested discreet law contracts on Bitcoin but one of the big
Starting point is 00:09:06 problems that we have with discreet law contracts I guess you're familiar with with the idea of DLCs and how they work, that you have basically a kind of blinded Oracle, which provides the, you know, a signature, which can be used to settle this contract one way or the other. But the real big problem with DLCs was the problem of like capital lockup. So obviously if you enter a DLC with someone
Starting point is 00:09:38 and it's supposed to, you know, mature at a certain date, say with some Oracle providing some price you know your your capital is locked up in that contract for that time and so one of the things we'd we'd we'd been aware of this state chain idea from from Ruben Samsung you know kind of last year and we thought this would be a really great way of being able to to actually change the ownership of one position of a discrete law contract without having to do any on-chain transaction. So this was our original motivation for looking at this,
Starting point is 00:10:17 was that we wanted to have a system where we could enable, say, discrete law contracts to be freely traded or the positions to be freely traded without having to necessarily do an on-chain transaction. So that kind of sparked our interest in that. And then I guess when we start to think about actually how we're going to implement this, it grew from there and we're thinking, basically all the advantages that this gives us
Starting point is 00:10:41 in terms of privacy. And privacy seems to be a kind of quite profitable kind of business at the moment. And yeah, and we looked at the market and seeing that, we've seen privacy wallets, privacy um you know wasabi samurai you know having a creating quite a lot of mind share and and you know and also earning quite a lot of money so so this seemed to be an interesting way to to pivot and also from a kind of you know a uh personal point of view it's more interesting working on
Starting point is 00:11:20 bitcoin and everyone loves that's what everyone really wants to do is do get companies um so so So, yeah, so we got excited about this and we're going ahead and creating an implementation. We've pretty much finished the kind of back end of this. Now we're kind of working on a wallet which can use this. Yes, it's incredible. Actually, using state chains as a solution to solve the capital lockup in DLCs is extremely novel.
Starting point is 00:11:55 It makes a lot of sense because you can just, trade out of that position if you want to again without touching the train without actually having to make an on-chain transaction just pass that along so i think using that as an example is probably good jumping in point to explain stay chains how they maybe compare to something like a lightning network as a second layer solution what are the differences what are what are the trade-offs and how and why you think they're important okay yeah so um so really i guess getting down to the the simplest kind of explanation analogy i mean it comes down what was the simplest way you could uh do an off-chain transfer of ownership of
Starting point is 00:12:41 say in the first instance just say a bitcoin utxo and the very naive thing you could say well just give someone the private key um which could work but it's not secure because the previous owner uh obviously you know has to be trusted to delete their private key and not use it to then steal the output so we no one would ever trust uh someone just uh you know giving them a private key uh to a bitcoin output um unless you unless you hold a ballet wallet yeah yeah of course yeah and and well well this is this is the kind of a good way of looking at it it's like a virtual open dime so that's okay obviously open dime solved it with a contrasted hardware where you you know you trust the uh the the the the stick they've produced
Starting point is 00:13:34 and that it's not been tampered with um and that therefore the um uh you know the key is is no one one can know the key. So essentially the basic idea of state chains is that you're basically passing around ownership of a single UTXO. And that's the first important thing to understand about it, which is a disadvantage, is that you can only transfer whole UTXOs. So comparing So obviously, say, you know, a federated side chain where you peg in a certain amount of Bitcoin and then you can trade it around with whoever you want and then peg out an arbitrary amount. In a state chain, you're essentially, you're locking up a fixed amount, which you can then pass around and then you draw that exact same UTXO. um so the the way i guess yeah the way in which it works really is that you you have a a trusted entity so this uh it's clear i guess it's good to be clear from the outset this is it requires trust
Starting point is 00:14:45 um not the same kind of trust as like you would have with a custodian um however there is there is trust involved um the uh the main advantages i think are which maybe we're going to discuss the subtleties of uh that there is a a type of it's it's non-custodial um uh the yeah there's been kind of arguments about whether it is really not custodial uh ruben came up with this nice description called it's i'd say like preemptively non-custodial um and censorship resistant so in principle the whole idea of it well the whole um advantage is that even if the if using a money on a state chain so using a state chain entity or this trusted party that they your your money can never be seized or frozen um and in order for the state chain
Starting point is 00:15:43 entity to steal from you that they would have to kind of plan an attack in advance and a fraud in advance um uh so really the two real advantages uh over a fully custodial solution is the fact that yeah you your funds can't be frozen or seized um and also that the uh the state chain entity can't arbitrarily decide to steal from you um but i guess yeah i'll go into exactly where the trust is but so essentially yeah so on a kind of lower level exactly what happens is that someone so deposit uh bitcoin into uh the state chain or we call it yeah the state chain entity is the operator of the state chain who must be trusted um and in reuben's original design this is goes into a two of two multi-sig um and that one key belongs to the station entity and the
Starting point is 00:16:37 the other key belongs to the depositor. And in Ruben's original concept, you'd use some kind of secure way of transferring the key using like adapter signatures. But essentially what would happen is that then the owner would then transfer ownership of that UTXO to a new person. They would just hand over the key to the new owner. And then the state entity is basically going to promise only to cooperate with a new owner to co-sign the transaction. But in addition to this, the first owner and the new owner, the state chain entity will co-sign what's called a backup transaction, which enables the current owner and only the current owner to redeem the Bitcoin if the state chain entity disappears or doesn't
Starting point is 00:17:32 incorporate. Is that similar to green wallet? Yes, in a way, yeah. But the issue with state chaining services, just like in Lightning, the new owner's backup transaction has to supersede the previous owner's backup transaction and has to become valid. And so in Ruben's original idea, the plan was to use like L2 kind of update mechanism so the new owner would get a transaction which could always claim the output the if the if the previous owner tried to submit a invalid state just like in lightning then the true owner has it has a
Starting point is 00:18:15 transaction which can then take the output so I need to kind of watch watch the chain make sure that the previous owner doesn't submit the expired backup transaction um so we don't have l2 at the moment and we may not for a long time uh and i think it's uh um yeah i think it's a it's a dangerous game to play to wait for these kind of protocol upgrades um yes because l2 free freaks you don't understand we're not saying l2 like the letter l to layer two we're saying l2 e l t o o this is something that many second layer solutions have been waiting for, but it requires a change at the protocol level, correct? Yeah. This is kind of a SIGHASH no input. So, it's basically a new SIGHASH type. So,
Starting point is 00:19:06 yeah. But there are alternatives to this. And one of them is to use like time locks, incrementing time locks so that you can essentially say the new owner basically can claim, use their backup transaction earlier than the previous owner um so this does have some unfortunately i mean with with uh l2 you could essentially have kind of billions and billions of updates uh but with the kind of a time lock based solution you do limit um the uh the kind of number of transfers you can have and also the amount of time people are going to have to wait in a kind of a backup situation which is is you know it should be clear that the backup situation is kind of only if everything goes wrong in the station and shut down or blown up so yeah so so
Starting point is 00:19:56 using this this kind of decremented time lock solution in addition we we have a slightly different approach to to Rubens original specification is is that we have this key recycling mechanism which increases the basically the the security that relies upon this multi-party computation way of doing basically a two-of-two signing so instead of using a 2-2 multisig we have single split between the state chain and actually what, um, uh, I'm here. I just shut my video off. This is exactly, this is exactly what, um, uh, say, uh, Chris Belcher is doing for his point swap implementation. So, I mean, we have to use this two-party ECDSA because
Starting point is 00:21:04 of our key update mechanism, but it does have other really great advantages in that you have a much bigger anonymity set. You have a smaller on-chain kind of transaction size which saves in fees. And to anyone, you know, on the blockchain, it just looks like any other single you know to pay paid to public key hash output so yes it's a bit about this this key update mechanism which gives one of the one of the crucial properties of the fact that the it makes the whole thing kind of hack-proof so the what happens is that when you you basically when you when you someone deposits uh funds onto the the state chain uh they uh generate a shared public key
Starting point is 00:21:58 shared two two private key shares but shared publicly um money's paid to that um uh bitcoin's paid to that public key um and then when the ownership is transferred to a new owner what happens is that the new owner generates their own private key um and then we do a multi-party computation between the state chain entity the old owner and the new owner and we actually update the private key of the state chain entity such that it now can only be used to sign the UTXO with the new owner and so so long as the state chain entity deletes that the previous private key share, then the old owner, there's no way that the old owner can co-sign to spend the Bitcoin.
Starting point is 00:22:52 How could you prove that you're deleting those keys? This is the key thing. It's where there's an element of trust. So if the state chain entity does what it claims to do and actually deletes that key, so you're trusting them to delete that key. If they delete that key, then the thing is completely secure. An old owner can never collude with a station entity to steal money. Obviously, the station entity can't be hacked by an old owner to steal the money because the key is gone.
Starting point is 00:23:24 But that's the critical thing, is that you need to trust the station entity to actually delete that key for the whole thing to be secure. So there's several ways you can go about that. I mean, essentially, it is always going to be, to a certain extent, reliant on some kind of trust. We're currently implementing a kind of hardware trusted execution environment solution where we use a trusted enclave that's capable of doing, like, remote attestation. I don't know if you know, like, Intel SGX,
Starting point is 00:23:58 um uh which uh enables you to well to to basically do to obviously you're kind of preventing kind of uh you know people to hackers who had had like physical access to the machine or um from from basically watching the the system and had root access and could kind of you know record old key shares um also you can do some remote attestation so you can you can actually prove to your well give you know given the assumptions of the the trusted hardware um that you're actually performing the deletion that you claim to be but it's an unsolvable aspect of the of the implementation and that's fine it just is what it is right because like you could always be the old owner and if you're the old owner exactly yeah right then that whole you have to
Starting point is 00:24:51 trust the coordinator no matter what yeah yeah yeah you have to um and there's things you can Obviously, that's what it's going to boil down to is the trust and reputation of the coordinator. So there are other options is further splitting the key and becoming more of a federation so that then you can, say, split the key, say, of the state chain entity three ways, maybe have three different kind of organizations. And if any one of those deletes the key, then the whole thing is secure. um but yeah so so it but fundamentally yeah it is you are trusting the state chain entity to delete the key um and but i'm a big fan of economic incentives basically disincentivizing any collusion from a state chain entity or coordinator yeah yeah moving against their their clients so what are the economic incentives for you guys not to collude yeah so i think that
Starting point is 00:25:53 this whole thing doesn't protect you against a malicious state chain entity a malicious state chain entity could decide to conduct a fraud against a user and steal from them but an honest state chain entity who is hacked uh who has been operating honestly or a state chain entity who is say taken over by the authorities or subpoenaed or something has no power to actually sees funds unlike say a custodian um so uh so yeah the the that's the the fundamental kind of trust trade-off but another thing that another feature that we've added um is well it's the state chain itself i mean it's called a state chain because you actually have a chain of signatures, which determines ownership of the UTXO. And that this actually is a proof of your
Starting point is 00:26:51 ownership. And so any user who's stolen from has evidence that they've been stolen from. So that, yeah, you essentially have a proof of fraud. And this proof of ownership is kind of of attested to bitcoin so that you have this kind of uh proof that nothing's been double spent um everything is uniquely owned um yeah and then you're basically you're relying upon the state entity being trustworthy um but in a way i think as a as a business that there is some there is some virtue in that because you know the the trust element And it enables you to create a brand and a reputation. I think the problem with, well, from a business point of view,
Starting point is 00:27:46 the problem with completely trustless kind of protocols is that there's no money to be made from a business point of view, you know, because there's no requirement for any kind of reputation. So, yeah, you can always kind of, it's a race to the bottom if you're providing kind of you know uh completely trustless services because obviously anybody can do it anybody can be anonymous and uh and and do that so so yeah so i guess that's an overview of the the the basic underlying uh kind of mechanism by how this works um but then yeah i can go on to talk if you want about the the kind of privacy applications we're thinking about and doing
Starting point is 00:28:34 doing essentially off-chain coin swaps yes so so i definitely i want to jump more into that and then because i want to jump into that and how limited is the scope of the applications of a state chain layer due to the fact that you need uh equal size utxs Yeah, so the equal size UTXOs thing is, I guess, a big problem for some applications. So I mean, I really like the idea of doing some kind of, you know, you could do some kind of, you know, non-custodial, proactively non-custodial exchange. But the thing that the fixed size UTXOs hampers there is the, um, the fact that, yeah, you can't really make up arbitrary amounts. Um,
Starting point is 00:29:35 so, uh, I guess in the, using it for payments is an issue because you, you, you can have a wallet with say, you know, certain fixed amounts, just like you do, you know, you pay for, um, you, you pay with, with cash. I mean, you can obviously, you know, you have certain fixed denomination notes or coins, and in a transaction, you can obviously receive, you know, some other change. And there's ways to do this that you can kind of minimize the number of coins you need. um uh so so that is one limitation but i think i think uh if you know with the right kind of user interface uh this can be kind of overcome uh quite quite easily um if people don't have to do
Starting point is 00:30:26 that uh kind of coin selection you know um manually and if the the swapping the change swapping is kind of made kind of seamless um so fixed amounts though can help for for kind of privacy um applications so um the doing doing coin swap so obviously choosing certain fixed amounts you can maximize the uh the number of potential yeah the anonymity set and the number of potential other people you can swap coins with um so yeah the the uh what the service that we're planning to kind of when when we have our full implementation um is essentially a coin swapping service um so this uh essentially would mean you know users come along with a fixed denomination UTXO so 0.1 Bitcoin say and then join a basically register that coin
Starting point is 00:31:33 with a swapping service like a coordinator and then that this would be swapped with other users coins so what we've done is we've implemented a scheme to do this which is kind of quite similar to the zero link protocol that say wasabi uses to blind the to blind the the basically the the swap matching from the coordinator itself so I mean so it's doing these kind of off-chain coin swaps I guess there's well you're getting two layers of privacy one is privacy from the blockchain itself so that you're not publishing uh the the swap on chain and so that that the the on-chain transaction graph is not telling you you know who's swapped with who um but then the coordinator itself obviously can record information
Starting point is 00:32:41 about uh you know which which coin has swapped with which coin um however with this protocol which is a bit like the zero link protocol using blinded signatures. Essentially, if you have a group of, say, users, say there's four of them, they each register that they want to swap 0.1 Bitcoin coin for someone else's 0.1 Bitcoin coin. This coordinator essentially takes those four coins and then randomly assigns each one of those coins to another random individual in the group um and then with a blinded token and using a new tool connection um you then are able to basically receive a a coin a new coin uh which wasn't yours um and although you know which coin you swapped it with the coordinator doesn't know who swapped
Starting point is 00:33:40 with who um so the yeah the real aim with this is that we're hoping to make this kind of very quick and easy so it's a training like i said it's a trade-off between obviously you have to trust the station entity and this coordinator um although they never have custody of your funds um but this can happen very quickly these are kind of almost instant transactions um so that we're hoping that this will enable much higher frequency of swaps so people can join
Starting point is 00:34:13 the system and then do these very fast rounds of swaps with lots of individuals and when they're ready, go back on chain and that we've removed a lot of that
Starting point is 00:34:29 transaction graph information away from the chain and hidden it from the coordinator as well. So, I mean, the key here is that you need to do multiple swaps so that you don't have to trust the person you're swapping with because they know what their previous swap was, right? So what's the fee structure? What's the planned fee structure here?
Starting point is 00:34:50 How does that work? So, yeah, I mean, we thought about this, and the trouble is it's almost impossible to charge a fee for swaps or transfers because of this fixed amount restriction, this fixed UTXO. um so we think the best way of doing it is just charging a a fee say on withdrawal so um yeah entry and entry and withdrawal um the the issue we had with with thinking about charging the fee on uh deposit was just from a user experience point of view is that um if you're going to pay in from a a third-party wallet you would have to explicitly include a a fee
Starting point is 00:35:39 payment as well um which uh uh maybe an issue well you could do it the way whirlpool did it right where the only way to come in is through your wallet through mercury wallet yeah yeah yeah when that's one thing that we we can add we originally were going to make the wallet kind of uh in you know both a bitcoin and state chain wallet so you'd have a bitcoin balance and a state coin balance and you could transfer between the two and that's where the fee would get taken in my mind so how does the fee get taken on the withdrawal side how does that look uh so you you basically would have to do a uh yeah to withdraw you have to get the section entity to co-sign and the section would just say i'm only going to co-sign if this withdrawal transaction
Starting point is 00:36:24 contains an output paying me you know the the the fee um so but then within the uh state chain every every transfer would be then fearless and free uh so that's awesome so so swaps infinite swaps for free for no additional cost yeah i mean obviously that that's kind of a you could think that that potentially is a like a dos risk because people can just spam uh but the the thing is with the the time locking of the backup transactions is that you only have a finite amount of uh swaps you can do um so you can do like 500 swaps um so obviously people i think i think will be incentivized not to run down that number um because otherwise then the closer you get to that number you're then going to have to do
Starting point is 00:37:20 withdrawal and uh an on-chain transaction so yeah and it's i mean having uh entry for the stay chain b through the mercury while it makes a lot of sense you see block stream coming out with aqua that new wallet that allows people to go between on-chain and liquid pretty easily it seems like that's becoming a more uh or i don't want to say standard but the precedence being set for that type of interaction with the second layer just to be baked into waltz software inherently the infinite rounds with no added fees seems like a huge improvement so what i'm trying to get out of here is like how does this compare to coin join specifically and is it like inherent uh upgrade matt i think i assume what your answer will be
Starting point is 00:38:12 is that you use both or a combination of the two but i think just like from a from a cost of attaining a sufficient privacy perspective like how competitive is this with with a coin joint implementation like wasabi or samurai well i mean i was gonna say but before tom jumps in here i mean the way because it i think it seems like really dense topic but from like a high level point of view the way I'm looking at it right now is this is basically zero link which is what we see for Whirlpool that's that's what Whirlpool and Wasabi is based off of with slight differences this seems closer to Whirlpool this model in terms of like the fee structure
Starting point is 00:39:02 and the incentives I think it's you know all else equal it seems like a privacy improvement in terms of effectiveness with additional trust you add trust yeah the system to accomplish that improvement in privacy and that trust being if the coordinator wants to be malicious they can take your funds if a malicious coordinator in in traditional zero-link schemes don't can't can't take your funds they can they can just degrade your privacy yeah that's right yeah so i guess it's about that trade-off i mean i guess it sits somewhere between a fully centralized mixer and uh the you know the the well-called wasabi uh coin joins where yeah you always retain full
Starting point is 00:39:52 custody always you know no one can steal your money uh in those protocols um so yeah it's a trade-off uh that you get this potentially uh increased kind of anonymity set um uh also uh yeah but you're not you're not giving your money directly to a custodian like you do with a centralized mixer so it sits somewhere yeah i'd say sits somewhere in between those and the beauty there is the beauty there is historically even though a custodial mixer provides great on-chain privacy if you can trust the custodian they've been a massive regulatory target so i think what ruben has been saying is legal custodial ship which is this idea that if you're acting in good faith a regulator shouldn't consider you a custodian because you can't take
Starting point is 00:40:48 funds or seize funds in that situation yeah which is a massive improvement in terms of regulatory protection and then i just wanted to say in terms of i really like the idea that you basically leaned into this issue with state chains that it's single denomination because on privacy that's desirable you don't really have a choice anyway that's not even a state limitation there so you're kind of yeah if you're just getting if people kind of standardize the the value of the coins they use and you massively increase yeah the privacy for all of those if if suddenly you know you've got thousands and thousands of 0.01 Bitcoin UTXOs, that does, yeah, just increase a lot. The ability of, you know, the ability of people to kind of mix and swap. But yeah,
Starting point is 00:41:37 you're right about the regulatory thing. I mean, that's a key, that's a big thing for a business as well that you, yeah, I mean, it is a kind of, it's a bit of a regulatory hack really to do this that you can you're running a centralized trusted service but no one can come and say to you please seize this you know it's non-custodial because we haven't we haven't recorded these keys we haven't colluded in with everyone therefore we're completely powerless yeah and you you can't move the coins by yourself unless you're the counterparty and in the state chain transaction as well um that's fascinating this is and again this is something that's ruben wrote about it last year we've been
Starting point is 00:42:35 talking about it but not until your announcement uh a week or two ago that you were launching mercury wallet on uh testnet or bitcoin's testnet like i haven't heard anybody even attempting to to create an implementation so i'm just like extremely excited that i'm sure you guys have been vocal about it for a while and i just missed it but yeah well we started we started kind of working on it i guess back in kind of april may this this year um so the first step is obviously get it all working properly kind of protocol wise command line wise um and so the current when we say micro wallet at the moment it's a very simple kind of command line uh client um but we're now working on a you know a uh the full kind of final uh gui
Starting point is 00:43:30 um wallet which hopefully will be ready in a month or two awesome what is how's the uh reception on testing it been? How has the software been? Yeah, everything's working. I don't know if many people have actually tested it. I mean, yeah, it's quite technically involved. We should probably do another launch with maybe an easier to use client. You know, at the moment, anybody would have to download the Rust and compile the Rust themselves. So a few people tried it though. if any of you rust devs who listen to this podcast are out there get on it i'd love to see this tested out and so what are what are the plans so you won't have a gui within a month
Starting point is 00:44:18 hopefully yeah um what where do we go from there is there something or an amount of data you're looking to observe on testnet before you guys launch product or we'll keep doing we'll keep doing testing um and you know we want it's a new thing i mean i guess we kind of do like a soft launch where you know we would tell people to uh maybe not put serious amounts of money in it to start with a bit like when lightning uh was launched uh don't be reckless um and uh yeah and essentially build up confidence make sure because it's a new it's a new protocol it's a new model we need to make sure it's very robust and secure
Starting point is 00:45:03 and yeah hopefully this will basically start happening kind of over the over into the new year yeah and then I mean moving on to other kind of applications is very interesting as well
Starting point is 00:45:20 and we still have this you know discrete like contract use case in mind uh and so it'd be yeah that'd be a really cool thing to do as well yeah we're we're big fans of dlcs here yeah yeah this is kind of it there seems a lot of promise there to create um you know to create kind of uh yeah derivatives derivatives that can be traded i think could be very powerful like synthetic dollars and things that can be yes so you're working on
Starting point is 00:45:56 all this very interesting tech i'm interested to learn about more about you the person tom like are you interested in this stuff because of the tech the liberating nature of the technology and do you like the sound money aspect it's yeah i mean originally i was drawn to the the technology um and then i think there's there's something about this i know quite a lot of uh people who've but he's studied physics, really into Bitcoin. There's something very alluring about this, this kind of a proof of work and the fact that you have this, you know,
Starting point is 00:46:36 this global state, which is kind of, there's an objectivity to it, which is very, very fascinating that you have this single global state, which is completely kind of, you know, no one can control it. And that you have this kind of this huge amount of energy that goes into securing it. It's a really, really fascinating kind of machine when you kind of look at it. And so I think that was originally the big draw for me.
Starting point is 00:47:12 I mean, I've always been I've always really been into cryptography as kind of a hobby and really fascinated by kind of modern cryptography and all the magical things that can do zero knowledge proofs and and uh all this kind of stuff um but yeah the more i've got the more i've got into bitcoin the more kind of convinced i've become about how kind of um revolutionary it is going to be um in terms of yeah kind of undermining all kinds of established kind of power structures um and this the it's really weird that you know when you try and explain it to people people can't even it's difficult to even communicate to people that you have this thing that basically is incorrect no one can no one can control this no one can um uh corrupt this um and so that's
Starting point is 00:48:01 i think is its biggest kind of um uh appeal is this yeah this this this yeah this this way of of storing value transacting value that that is impossible for anybody to stop or yeah these and yeah the more the more kind of you start to think about the the consequences of how this is going to change the world yeah it's and i don't i don't know the answer to that um i don't you know i'm not sure about kind of hyper bitcoinization all these things but i think it's going to be a big a big deal in the future not i uh i actually recently reread misha trubitsky's piece on proof of work essentially just being a decentralized clock like you mentioned proof of work creating uh just a state at any given point in time of the ledger and it's crazy to think uh so i originally
Starting point is 00:48:59 came to bitcoin fascinated by the sound monetary properties and its effect on economics and finance but as i get further down the rabbit hole i just become more drawn and uh more focused on the proof work aspect just turning energy uh into these hashes that could potentially produce bitcoin and it's fascinating when you have the aha moment over proof of work of how it really melds the physical and digital worlds together in a way that's never been done before yeah i mean it's this this kind of like what it's called thermodynamic immutability you know it's uh uh that yeah you you you have this this way of now you have this kind of source of truth now which didn't exist before nothing like it has existed before um and yeah the consequence of
Starting point is 00:49:50 this is is yeah difficult to really uh predict um yeah and it's funny watching people particularly in the the altcoin world sort of gloss over proof of work and run right to what i would argue I think there's fundamental misunderstandings and you see a lot the I think people would be involved in in these kind of like you know kind of Byzantine fault tolerance protocols and things it's I think yeah there's a misunderstanding that proof of work is just a kind of a way of nodes to agree but it's a lot more than that and and yeah that the that has so many kind of specific properties and I think it's the only
Starting point is 00:50:37 kind of permissionless way to have any kind of consensus but yeah it's kind of yeah it's a really incredible thing that you you have this yeah it's basically impossible
Starting point is 00:50:53 no it doesn't matter who colludes it doesn't matter who kind of subjective opinions of the rest of the world there's this one objective source of truth that anybody can can independently verify um so yeah it's kind of yeah i think there's this there's so many unexplored use cases for this as well um uh for for well yeah for for proving things um yeah yeah in a trustless way no i love having conversations with physicists on this podcast
Starting point is 00:51:29 Dhruv Bansal being one of my favorite because he just naturally takes it to the nth degree talking about Bitcoin in space and how this can help us interact with intergalactic communities if they exist and Dyson spheres
Starting point is 00:51:45 if you try to play this out if it's successful will Bitcoin mining eat up all the energy in our solar system that might eat up all the spare energy right Yeah. And that's, I guess, another thing that people that kind of is slightly annoying about
Starting point is 00:52:05 criticisms of Bitcoin's energy use is, again, a failure to understand what it's actually achieving. And the energy isn't wasted. This is replacing trust, essentially. And trust is usually very, very energy inefficient in the real world. yeah people don't know how to calculate and define the opportunity cost of not using that waste energy to produce bitcoins yeah yeah it's uh yeah it's a learning process it's a huge learning curve too yeah coming to these like wrapping your head around proof of work wrapping your head around money to begin with and then everything you can't do with a utxo So that's one thing. I have a theory that you could apply Jevons paradox to a Bitcoin UTXO and seeing you create a state chain implementation sort of feeds into the narrative behind that theory, which is if you can make UTXOs more useful, give them more utility, they will be used more and therefore driving a sufficient fee market to sustain mining with a hard supply chain.
Starting point is 00:53:18 cap into the future yeah yeah yeah yeah i can see where that's going um so why mercury well what's any any reason behind the name no i don't know i don't know if it came from yeah i can't remember the exact reasoning for it uh it just sounded uh good i think we've used a mercury name before uh for some kind of elements stroke liquid kind of uh thing but yeah no i can't remember the uh the exact uh name but i think it's one of these things that just stuck um and uh and yeah seems to seems to sound quite nice so yeah um no again thank you for for putting in the work to get this implementation market it's again something we've been talking about um i know it's only on testnet now but the fact that somebody's
Starting point is 00:54:16 working on it is incredibly bullish in my mind yeah it's been a lot of fun it's been it's been a really fascinating thing to work on um and again this is it's my uh first kind of uh um use of of rust uh in in uh kind of in something real um so that's been quite interesting challenging but yeah it's been a lot of it's been very interesting and a lot of fun
Starting point is 00:54:45 to build this and yeah everyone's very enthusiastic about it on the team so yeah and it's one of these things yeah I've just got a good feeling about it
Starting point is 00:54:55 I think it might yeah be in the right place at the right time and yeah hopefully be be
Starting point is 00:55:05 useful I mean if it helps with privacy i think it will certainly be useful we think that's one of the most needed areas of improvement in the bitcoin stack is his privacy tools so yeah another one another option is just incredible um i just wanted to jump in here real quick uh first of all um appreciate the work you know i've been very focused we've been very focused on privacy here for a while now and we think it is one of bitcoin's major uh you know ux issues uh mostly
Starting point is 00:55:43 uh in terms of direct directly right in the face of user and i i think it's it's a it's a major vulnerability to mostly on the user side yeah the number one thing for all these systems is the amount of people we get using them so yeah do not do not diminish do not um underestimate the importance of the importance of ux here like it needs to be uh straightforward for the user where they can conceptualize it and and there can't be that many foot gun things because if if there's a way for the user to shoot themselves in their foot they probably will and yeah but these systems it usually hurts other people's privacy as well because it diminishes the overall uh the the the overall anonymity set um i have a question the has there been any thought into using this
Starting point is 00:56:34 type of implementation as like a private way to do like swaps between lightning and liquid and on-chain um well i guess there's two two there's been people lots of people mentioned doing uh using this on kind of uh lightning channels being able to swap ownership of uh lighting channels in the same way that you swap ownership of a you know position in dlc right um but yeah the the you could do swaps again you the current model is the yeah that you trust you're basically trusting the coordinator to do the swap atomically um but there's no reason you you couldn't swap anything like i feel like specifically with liquid it'd be like really easy to implement into something like this am i mistaken to do a kind of what an lbtc btc swap
Starting point is 00:57:28 where we're like any the people who enter the state chain for the swap the swapping of this in the state chain could be either liquid or on chain and they could come out either liquid or on chain yeah yeah yeah that's that's an interesting idea actually which would be easy because obviously it's the same that obviously swapping with a different currency is you have the problem of the fixed amounts but i guess on on this would be exactly the same it's already packed anyway yeah that's yeah that's quite an interesting idea like people would i guess like that because there's more privacy yeah because it'd be it would it'd be interesting that you could come in or out with liquid or on chain it would make an interesting privacy heuristic breaker there
Starting point is 00:58:09 yeah yeah that's interesting idea and it's the major shortfall of liquid right now is coming in and out yeah yeah because uh to do a peg out is so it could benefit both you know yeah yeah yeah matt with the hot product tips here on tftc um tom i know we have a hard stop because you have to pick up your children is there anything uh we should wrap up with particularly that's on your mind anything to focus on anything um I don't think so. And in particular, hopefully I've been able to, you know, get across everything we're, we're, we're doing. But yeah, I mean, if, if it would be great if people were, would want to, you know,
Starting point is 00:58:52 help us test it out. Also, you know, everything we do is completely open source. And yeah, I mean, if, if, if people wanted to go ahead and, and you know, set up their own state chain entities they're kind of, you know, welcome to do that and yeah basically we appreciate any kind of feedback people can give us but yeah
Starting point is 00:59:16 but it's been yeah we're getting a lot of good we're getting a lot of good kind of feedback on yeah that this is something that people would use and people would find valuable oh yeah no I think
Starting point is 00:59:32 I'm very excited to see see a proper implementation of state chains come to market. It seems like you guys are on the right path and very much looking forward to the GUI and the main net product when it launches. I'm sure we'll definitely be testing it out and letting the freaks know how it went. So definitely keep us updated on everything that's going on. Yeah, sure. Matt, do you have anything to wrap up with?
Starting point is 00:59:57 Thanks for coming on, Tom. Really appreciated this conversation. Yeah, no, thanks for having me. I appreciate it well I hope you enjoy the rest of your night thank you again for taking an hour to come explain this to us again very bullish
Starting point is 01:00:14 and excited to see what we have in store moving forward so that's all we got this week freaks cheers peace and love tiki

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.