TFTC: A Bitcoin Podcast - #207: Tom Trevethan
Episode Date: November 6, 2020Join Marty and Matt as they sit down with Tom Trevethan, CTO of CommerceBlock, to discuss: - Statechains - Mercury Wallet - Trust tradeoffs - Privacy gains - Fee structure - Custodial tradeoff - Use c...ases - much more Follow Tom on Twitter Checkout Mercury Wallet Shoutout to this week's sponsors. Cash App. Start #stackingsats today. Use the promo code: "stackingsats" to receive $10 and contribute $10 to OWLS Lacrosse when you download the app.
Transcript
Discussion (0)
What's up, freaks? It's your boy Marty here to introduce this episode of Tales from the Crypt.
Matt O'Dell and I sat down with the CTO from Commerce Block, Tom Trevison, to talk about Mercury Wallet,
the software they're building to implement state chains so that we can get another second layer scaling solution
and privacy solution built on top of Bitcoin. It's a very interesting episode.
If you guys are interested in state chains, I highly recommend you pay attention to this one.
We dive in, talk about the trade-offs, the security benefits, the privacy benefits, everything that's going on.
I'm really excited to see state chains in the wild, and I think Tom does an incredible job of explaining them,
and I'm very happy that him and the team at Commerce Block are building out Mercury Wallets so that we can get them to market.
This episode of Tales from the Crypt
Is brought to you by our good friends
At the motherfucking
Cash App
You freaks already know all about them
But if you don't know about them
If you already know about them
Then you shouldn't not know about them
But if any of you are out there
And you don't know about them
Cash App's helping you stack sats
Send sats
Sell sats
Receive sats
And you can make sats the standard
We're saying sats sats sats sats sats
Because we're no longer
Buying fractions of Bitcoin
We're buying whole sats, tens of sats, hundreds of sats, thousands of sats, tens of thousands, millions, tens of millions, hundreds of millions if you're balling out.
You can make sats a sender.
You can DCA into sats too.
If you want to buy daily, weekly, or biweekly, you can set it and forget it.
We've got to figure out when we need to front run Matt O'Dell.
He admitted it last night in a rabbit hole recap that he changed his daily buy.
so we need freaks to get out there and start their daily buys at random hours just so we
have confidence that at least one of you is front running matt odell uh on top of the
sat stacking stacks liver's stonks if you're into the stonk market
you can invest in stocks okay i know all of you aren't into the stonks you're not big
stonk fans the option's there right if your favorite stock's a little too expensive you
can buy as low as one dollar via the cash app because all this is connected to your bank
account there's no four to five day waiting periods cash app may even be your bank account
they're offering account number and routing numbers so that you can direct deposit your
paychecks into the cash app bank of the future check it out use the code stacking stats when
you do it's s-t-a-c-k-i-n-g-s-a-t-s you're gonna get ten dollars and ten dollars gonna go to our
good friends at owls lacrosse that's owls lacrosse
enjoy this rip i learned a lot i hope you do too
okay
you've had a dynamic where money's become freer than free
if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting
like safe haven i believe that in a world where central bankers are tripping over themselves to
devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean
that's part of the bull case for bitcoin if you're not paying attention you probably should be
what is up freaks welcome back to tales from the crypt it's your boy marty bent here
uh first podcast recording in my uh my three-week uh getaway from the united states uh in the
islands i've got i've got a new uh studio here i think it's much better than the one i have been
recording out of uh but matt and i are very excited for this conversation we're sitting down
with tom uh god we were going over your last name trevathan trevathan uh trevathan uh from
commerce block the cto commerce block uh a company that launched the uh mercury wild
on bitcoin's test net a couple of weeks ago we wrote about it it's an implementation of state
change which is a second layer solution that we have been writing about and talking about but
wondering whether or not it would ever get implemented so it seems like mercury wallet
has launched an implementation of state change and we're just excited to learn about it and to
talk with you tom to learn about why you guys built this to learn about state change in general
so i think to start just learn a little bit about you and what you do at commerce block
I guess, how did you find yourself in this position, particularly working on state chains?
Yeah, so my background is I was a physicist. I worked at university doing research,
mainly in theory and computation, so computation modeling. And then a few years ago, I made the
decision to kind of leave academia and haven't looked back since then. I'm kind of enjoying
startup life, which I think is more exciting, more kind of dynamic. So yeah, so I joined
Commerce Block, must be about two and a half years ago. And they were just starting out.
And at Commerce Block, we've essentially, what we were previously doing was creating
uh kind of blockchain solutions for clients um who wanted to um uh tokenize things so we had this
this big client uh called dgld they wanted to tokenize gold um and uh so we um created a
uh a platform for them to do this based on elements which liquid is based on um and uh
So they wanted a, their own, you know, they wanted to have, you know, permission control over this.
So they wanted like KYC integration and stuff.
And so we forked elements and created basically a platform for them to use tokenized as gold.
And the idea was that this is all backed up by Bitcoin's immutability and proof of work.
So we developed this protocol to basically utilize Bitcoin's immutability, which goes a bit beyond just simple timestamping that use this kind of idea of Peter Todd's of like a single use seal so that you can prove uniqueness of this secondary chain.
So it's basically an asset backed side chain. And so this is what we've been working on
for the past couple of years. But we've struggled really to get kind of traction. Our big argument
is this is a great way to scale. And the whole idea of issuing tokens on Ethereum is there's
huge scalability problems in that if you wanted to verify the ownership of something, verify
the token on Ethereum, you have to verify the whole Ethereum blockchain, which is growing
bigger and bigger all the time. So basically our motivation for this kind of approach was
a scalability one, but really we've struggled to find attraction and issues with exchange
integrations and competing against the kind of big players, you know, EOS and all these
people that are essentially funding people to use their platforms.
So, yeah, kind of went on from this.
We did get interest from a few people doing privacy-based sidechains
kind of separate from Liquid that would be...
Excuse me, Matt.
Matt, there's something going on with your computer or something.
It's like putting in this loud noise.
I think it's going to mess up the audio.
Is it really?
Is it coming from my side?
Yeah, it's definitely coming from you.
It happens on RHR too, but since you record the audio,
it doesn't mess that up i think it would mess this up though you just mute while you're
not talking yeah there we go perfect sorry tom um yeah so essentially we've we've kind of
started to well yeah we got some interest in doing privacy-based sidechains but then
the the real kind of thing uh that kind of pivoted us is that we got interest from someone to work
with us to develop like a discreet law contract based system and one of the so
what we they want they wanted to provide some kind of derivative based platform
and we've suggested discreet law contracts on Bitcoin but one of the big
problems that we have with discreet law contracts I guess you're familiar with
with the idea of DLCs and how they work,
that you have basically a kind of blinded Oracle,
which provides the, you know, a signature,
which can be used to settle this contract one way or the other.
But the real big problem with DLCs
was the problem of like capital lockup.
So obviously if you enter a DLC with someone
and it's supposed to, you know, mature at a certain date,
say with some Oracle providing some price you know your your capital is
locked up in that contract for that time and so one of the things we'd we'd we'd
been aware of this state chain idea from from Ruben Samsung you know kind of last
year and we thought this would be a really great way of being able to
to actually change the ownership of one position of a discrete law contract
without having to do any on-chain transaction.
So this was our original motivation for looking at this,
was that we wanted to have a system where we could enable, say,
discrete law contracts to be freely traded or the positions to be freely traded
without having to necessarily do an on-chain transaction.
So that kind of sparked our interest in that.
And then I guess when we start to think about actually
how we're going to implement this,
it grew from there and we're thinking,
basically all the advantages that this gives us
in terms of privacy.
And privacy seems to be a kind of quite profitable
kind of business at the moment.
And yeah, and we looked at the market
and seeing that, we've seen privacy wallets,
privacy um you know wasabi samurai you know having a creating quite a lot of mind share and and you
know and also earning quite a lot of money so so this seemed to be an interesting way to to pivot
and also from a kind of you know a uh personal point of view it's more interesting working on
bitcoin and everyone loves that's what everyone really wants to do is do get companies um so so
So, yeah, so we got excited about this
and we're going ahead and creating an implementation.
We've pretty much finished the kind of back end of this.
Now we're kind of working on a wallet which can use this.
Yes, it's incredible.
Actually, using state chains as a solution
to solve the capital lockup in DLCs is extremely novel.
It makes a lot of sense because you can just,
trade out of that position if you want to again without touching the train without actually
having to make an on-chain transaction just pass that along so i think using that as an example is
probably good jumping in point to explain stay chains how they maybe compare to something like
a lightning network as a second layer solution what are the differences what are what are the
trade-offs and how and why you think they're important okay yeah so um so really i guess
getting down to the the simplest kind of explanation analogy i mean it comes down
what was the simplest way you could uh do an off-chain transfer of ownership of
say in the first instance just say a bitcoin utxo and the very naive thing you could say
well just give someone the private key um which could work but it's not secure because the
previous owner uh obviously you know has to be trusted to delete their private key and not use
it to then steal the output so we no one would ever trust uh someone just uh you know giving
them a private key uh to a bitcoin output um unless you unless you hold a ballet wallet
yeah yeah of course yeah and and well well this is this is the kind of a good way of looking at
it it's like a virtual open dime so that's okay obviously open dime solved it with a
contrasted hardware where you you know you trust the uh the the the the stick they've produced
and that it's not been tampered with um and that therefore the um uh you know the key is is no one
one can know the key. So essentially the basic idea of state chains is that you're basically
passing around ownership of a single UTXO. And that's the first important thing to understand
about it, which is a disadvantage, is that you can only transfer whole UTXOs. So comparing
So obviously, say, you know, a federated side chain where you peg in a certain amount of Bitcoin and then you can trade it around with whoever you want and then peg out an arbitrary amount.
In a state chain, you're essentially, you're locking up a fixed amount, which you can then pass around and then you draw that exact same UTXO.
um so the the way i guess yeah the way in which it works really is that you you have a a trusted
entity so this uh it's clear i guess it's good to be clear from the outset this is it requires trust
um not the same kind of trust as like you would have with a custodian um however there is there
is trust involved um the uh the main advantages i think are which maybe we're going to discuss
the subtleties of uh that there is a a type of it's it's non-custodial um uh the yeah there's
been kind of arguments about whether it is really not custodial uh ruben came up with this nice
description called it's i'd say like preemptively non-custodial um and censorship resistant so
in principle the whole idea of it well the whole um advantage is that even if the if using a
money on a state chain so using a state chain entity or this trusted party
that they your your money can never be seized or frozen um and in order for the state chain
entity to steal from you that they would have to kind of plan an attack in advance and a fraud in
advance um uh so really the two real advantages uh over a fully custodial solution is the fact
that yeah you your funds can't be frozen or seized um and also that the uh the state chain
entity can't arbitrarily decide to steal from you um but i guess yeah i'll go into exactly where
the trust is but so essentially yeah so on a kind of lower level exactly what happens is that
someone so deposit uh bitcoin into uh the state chain or we call it yeah the state chain entity
is the operator of the state chain who must be trusted um and in reuben's original design this
is goes into a two of two multi-sig um and that one key belongs to the station entity and the
the other key belongs to the depositor. And in Ruben's original concept, you'd use some
kind of secure way of transferring the key using like adapter signatures. But essentially
what would happen is that then the owner would then transfer ownership of that UTXO to a
new person. They would just hand over the key to the new owner. And then the state
entity is basically going to promise only to cooperate with a new owner to co-sign the
transaction. But in addition to this, the first owner and the new owner, the state chain
entity will co-sign what's called a backup transaction, which enables the current owner
and only the current owner to redeem the Bitcoin if the state chain entity disappears or doesn't
incorporate.
Is that similar to green wallet?
Yes, in a way, yeah. But the issue with state chaining services, just like in Lightning,
the new owner's backup transaction has to supersede the previous owner's backup transaction
and has to become valid. And so in Ruben's original idea, the plan was to use like L2
kind of update mechanism so the new owner would get a transaction which
could always claim the output the if the if the previous owner tried to submit a
invalid state just like in lightning then the true owner has it has a
transaction which can then take the output so I need to kind of watch watch
the chain make sure that the previous owner doesn't submit the expired backup
transaction um so we don't have l2 at the moment and we may not for a long time uh and i think it's
uh um yeah i think it's a it's a dangerous game to play to wait for these kind of protocol
upgrades um yes because l2 free freaks you don't understand we're not saying l2 like the letter l
to layer two we're saying l2 e l t o o this is something that many second layer solutions have
been waiting for, but it requires a change at the protocol level, correct?
Yeah. This is kind of a SIGHASH no input. So, it's basically a new SIGHASH type. So,
yeah. But there are alternatives to this. And one of them is to use like time locks,
incrementing time locks so that you can essentially say the new owner basically can claim, use
their backup transaction earlier than the previous owner um so this does have some unfortunately i
mean with with uh l2 you could essentially have kind of billions and billions of updates uh but
with the kind of a time lock based solution you do limit um the uh the kind of number of transfers
you can have and also the amount of time people are going to have to wait in a kind of a backup
situation which is is you know it should be clear that the backup situation is kind of only if
everything goes wrong in the station and shut down or blown up so yeah so so
using this this kind of decremented time lock solution in addition we we have a
slightly different approach to to Rubens original specification is is that we
have this key recycling mechanism which increases the basically the the
security that relies upon this multi-party computation way of doing
basically a two-of-two signing so instead of using a 2-2 multisig we have
single split between the state chain and actually what, um, uh, I'm here. I just shut my video
off. This is exactly, this is exactly what, um, uh, say, uh, Chris Belcher is doing for
his point swap implementation. So, I mean, we have to use this two-party ECDSA because
of our key update mechanism, but it does have other really great advantages in that you
have a much bigger anonymity set. You have a smaller on-chain kind of transaction size
which saves in fees. And to anyone, you know, on the blockchain, it just looks like any
other single you know to pay paid to public key hash output so yes it's a bit
about this this key update mechanism which gives one of the one of the
crucial properties of the fact that the it makes the whole thing kind of
hack-proof so the what happens is that when you you basically when you when you
someone deposits uh funds onto the the state chain uh they uh generate a shared public key
shared two two private key shares but shared publicly um money's paid to that um uh bitcoin's
paid to that public key um and then when the ownership is transferred to a new owner what
happens is that the new owner generates their own private key um and then we do a multi-party
computation between the state chain entity the old owner and the new owner and we actually update
the private key of the state chain entity such that it now can only be used to sign the UTXO
with the new owner and so so long as the state chain entity deletes that the previous private
key share, then the old owner, there's no way that the old owner can co-sign to spend
the Bitcoin.
How could you prove that you're deleting those keys?
This is the key thing.
It's where there's an element of trust.
So if the state chain entity does what it claims to do and actually deletes that key,
so you're trusting them to delete that key.
If they delete that key, then the thing is completely secure.
An old owner can never collude with a station entity to steal money.
Obviously, the station entity can't be hacked by an old owner to steal the money because the key is gone.
But that's the critical thing, is that you need to trust the station entity to actually delete that key for the whole thing to be secure.
So there's several ways you can go about that.
I mean, essentially, it is always going to be, to a certain extent,
reliant on some kind of trust.
We're currently implementing a kind of hardware trusted execution environment
solution where we use a trusted enclave that's capable of doing, like,
remote attestation.
I don't know if you know, like, Intel SGX,
um uh which uh enables you to well to to basically do to obviously you're kind of
preventing kind of uh you know people to hackers who had had like physical access to the machine or
um from from basically watching the the system and had root access and could kind of you know
record old key shares um also you can do some remote attestation so you can you can actually
prove to your well give you know given the assumptions of the the trusted hardware um
that you're actually performing the deletion that you claim to be but it's an unsolvable aspect of
the of the implementation and that's fine it just is what it is right because like you could always
be the old owner and if you're the old owner exactly yeah right then that whole you have to
trust the coordinator no matter what yeah yeah yeah you have to um and there's things you can
Obviously, that's what it's going to boil down to is the trust and reputation of the coordinator.
So there are other options is further splitting the key and becoming more of a federation so that then you can, say, split the key, say, of the state chain entity three ways, maybe have three different kind of organizations.
And if any one of those deletes the key, then the whole thing is secure.
um but yeah so so it but fundamentally yeah it is you are trusting the state chain entity
to delete the key um and but i'm a big fan of economic incentives basically disincentivizing
any collusion from a state chain entity or coordinator yeah yeah moving against their
their clients so what are the economic incentives for you guys not to collude yeah so i think that
this whole thing doesn't protect you against a malicious state chain entity a malicious state
chain entity could decide to conduct a fraud against a user and steal from them but an honest
state chain entity who is hacked uh who has been operating honestly or a state chain entity who is
say taken over by the authorities or subpoenaed or something has no power to actually
sees funds unlike say a custodian um so uh so yeah the the that's the the fundamental kind of
trust trade-off but another thing that another feature that we've added um is well it's the
state chain itself i mean it's called a state chain because you actually have a chain of
signatures, which determines ownership of the UTXO. And that this actually is a proof of your
ownership. And so any user who's stolen from has evidence that they've been stolen from.
So that, yeah, you essentially have a proof of fraud. And this proof of ownership is kind of
of attested to bitcoin so that you have this kind of uh proof that nothing's been double spent
um everything is uniquely owned um yeah and then you're basically you're relying upon the
state entity being trustworthy um but in a way i think as a as a business
that there is some there is some virtue in that because you know the the trust element
And it enables you to create a brand and a reputation.
I think the problem with, well, from a business point of view,
the problem with completely trustless kind of protocols
is that there's no money to be made from a business point of view,
you know, because there's no requirement for any kind of reputation.
So, yeah, you can always kind of, it's a race to the bottom
if you're providing kind of you know uh completely trustless services because obviously anybody can
do it anybody can be anonymous and uh and and do that so so yeah so i guess that's an overview of
the the the basic underlying uh kind of mechanism by how this works um but then yeah i can go on to
talk if you want about the the kind of privacy applications we're thinking about and doing
doing essentially off-chain coin swaps yes so so i definitely i want to jump more into that
and then because i want to jump into that and how limited is the scope of the applications
of a state chain layer due to the fact that you need uh equal size utxs
Yeah, so the equal size UTXOs thing is, I guess, a big problem for some applications.
So I mean, I really like the idea of doing some kind of, you know, you could do some
kind of, you know, non-custodial, proactively non-custodial exchange. But the thing that
the fixed size UTXOs hampers there is the, um, the fact that, yeah,
you can't really make up arbitrary amounts. Um,
so, uh, I guess in the,
using it for payments is an issue because you, you,
you can have a wallet with say, you know, certain fixed amounts,
just like you do, you know, you pay for, um, you, you pay with, with cash.
I mean, you can obviously, you know, you have certain fixed denomination notes or coins, and in a transaction, you can obviously receive, you know, some other change.
And there's ways to do this that you can kind of minimize the number of coins you need.
um uh so so that is one limitation but i think i think uh if you know with the right kind of
user interface uh this can be kind of overcome uh quite quite easily um if people don't have to do
that uh kind of coin selection you know um manually and if the the swapping the change
swapping is kind of made kind of seamless um so fixed amounts though can help for for kind of
privacy um applications so um the doing doing coin swap so obviously choosing certain fixed amounts
you can maximize the uh the number of potential yeah the anonymity set and the number of potential
other people you can swap coins with um so yeah the the uh what the service that we're planning
to kind of when when we have our full implementation um is essentially a coin swapping
service um so this uh essentially would mean you know users come along with a fixed
denomination UTXO so 0.1 Bitcoin say and then join a basically register that coin
with a swapping service like a coordinator and then that this would be
swapped with other users coins so what we've done is we've implemented a scheme
to do this which is kind of quite similar to the zero link protocol that say wasabi uses
to blind the to blind the the basically the the swap matching from the coordinator itself
so I mean so it's doing these kind of off-chain coin swaps I guess there's well you're getting
two layers of privacy one is privacy from the blockchain itself so that you're not publishing
uh the the swap on chain and so that that the the on-chain transaction graph is not telling you you
know who's swapped with who um but then the coordinator itself obviously can record information
about uh you know which which coin has swapped with which coin um however with this protocol
which is a bit like the zero link protocol using blinded signatures.
Essentially, if you have a group of, say, users, say there's four of them,
they each register that they want to swap 0.1 Bitcoin coin for someone else's 0.1 Bitcoin coin.
This coordinator essentially takes those four coins and then randomly assigns each one of those
coins to another random individual in the group um and then with a blinded token and using a new
tool connection um you then are able to basically receive a a coin a new coin uh which wasn't yours
um and although you know which coin you swapped it with the coordinator doesn't know who swapped
with who um so the yeah the real aim with this is that we're hoping to make this kind of very
quick and easy so it's a training like i said it's a trade-off between obviously you have to
trust the station entity and this coordinator um although they never have custody of your funds
um but this can happen very quickly these are kind of almost instant transactions um so that
we're hoping that this will
enable much
higher frequency of
swaps so people can join
the system and then
do these very
fast rounds of swaps with lots
of individuals
and
when they're ready, go back on chain
and that we've removed
a lot of that
transaction graph
information away from the chain and
hidden it from the coordinator as well.
So, I mean, the key here is that you need to do multiple swaps
so that you don't have to trust the person you're swapping with
because they know what their previous swap was, right?
So what's the fee structure?
What's the planned fee structure here?
How does that work?
So, yeah, I mean, we thought about this,
and the trouble is it's almost impossible to charge a fee for swaps or transfers
because of this fixed amount restriction, this fixed UTXO.
um so we think the best way of doing it is just charging a a fee say on withdrawal so um
yeah entry and entry and withdrawal um the the issue we had with with thinking about charging
the fee on uh deposit was just from a user experience point of view is that um if you're
going to pay in from a a third-party wallet you would have to explicitly include a a fee
payment as well um which uh uh maybe an issue well you could do it the way whirlpool did it
right where the only way to come in is through your wallet through mercury wallet
yeah yeah yeah when that's one thing that we we can add we originally were going to make the
wallet kind of uh in you know both a bitcoin and state chain wallet so you'd have a bitcoin balance
and a state coin balance and you could transfer between the two and that's where the fee would
get taken in my mind so how does the fee get taken on the withdrawal side how does that look
uh so you you basically would have to do a uh yeah to withdraw you have to get the section entity to
co-sign and the section would just say i'm only going to co-sign if this withdrawal transaction
contains an output paying me you know the the the fee um so but then within the uh
state chain every every transfer would be then fearless and free uh so that's awesome
so so swaps infinite swaps for free for no additional cost yeah i mean obviously that
that's kind of a you could think that that potentially is a like a dos risk because
people can just spam uh but the the thing is with the the time locking of the backup transactions
is that you only have a finite amount of uh swaps you can do um so you can do like 500 swaps
um so obviously people i think i think will be incentivized not to run down that number
um because otherwise then the closer you get to that number you're then going to have to do
withdrawal and uh an on-chain transaction so yeah and it's i mean having
uh entry for the stay chain b through the mercury while it makes a lot of sense you see
block stream coming out with aqua that new wallet that allows people to go between on-chain and
liquid pretty easily it seems like that's becoming a more uh or i don't want to say standard but
the precedence being set for that type of interaction with the second layer just to be
baked into waltz software inherently the infinite rounds with no added fees seems like a huge
improvement so what i'm trying to get out of here is like how does this compare to coin join
specifically and is it like inherent uh upgrade matt i think i assume what your answer will be
is that you use both or a combination of the two but i think just like from a from a cost of
attaining a sufficient privacy perspective like how competitive is this with with a
coin joint implementation like wasabi or samurai well i mean i was gonna say
but before tom jumps in here i mean the way because it i think it seems like really dense
topic but from like a high level point of view the way I'm looking at it right
now is this is basically zero link which is what we see for Whirlpool that's
that's what Whirlpool and Wasabi is based off of with slight differences
this seems closer to Whirlpool this model in terms of like the fee structure
and the incentives I think it's you know all else equal it seems like a privacy
improvement in terms of effectiveness with additional trust you add trust yeah
the system to accomplish that improvement in privacy and that trust
being if the coordinator wants to be malicious they can take your funds if a
malicious coordinator in in traditional zero-link schemes don't can't can't take
your funds they can they can just degrade your privacy yeah that's right yeah so i guess it's
about that trade-off i mean i guess it sits somewhere between a fully centralized mixer
and uh the you know the the well-called wasabi uh coin joins where yeah you always retain full
custody always you know no one can steal your money uh in those protocols um so yeah it's a
trade-off uh that you get this potentially uh increased kind of anonymity set um uh also uh
yeah but you're not you're not giving your money directly to a custodian like you do with a
centralized mixer so it sits somewhere yeah i'd say sits somewhere in between those
and the beauty there is the beauty there is historically even though a custodial mixer
provides great on-chain privacy if you can trust the custodian they've been a massive regulatory
target so i think what ruben has been saying is legal custodial ship which is this idea that if
you're acting in good faith a regulator shouldn't consider you a custodian because you can't take
funds or seize funds in that situation yeah which is a massive improvement in terms of regulatory
protection and then i just wanted to say in terms of i really like the idea that you basically
leaned into this issue with state chains that it's single denomination because on privacy that's
desirable you don't really have a choice anyway that's not even a state limitation there so you're
kind of yeah if you're just getting if people kind of standardize the the value of the coins
they use and you massively increase yeah the privacy for all of those if if suddenly you know
you've got thousands and thousands of 0.01 Bitcoin UTXOs, that does, yeah, just increase
a lot. The ability of, you know, the ability of people to kind of mix and swap. But yeah,
you're right about the regulatory thing. I mean, that's a key, that's a big thing for
a business as well that you, yeah, I mean, it is a kind of, it's a bit of a regulatory
hack really to do this that you can you're running a centralized trusted
service but no one can come and say to you please seize this you know it's
non-custodial because we haven't we haven't recorded these keys we haven't
colluded in with everyone therefore we're completely powerless yeah and you you can't move the coins by
yourself unless you're the counterparty and in the state chain transaction as well um that's
fascinating this is and again this is something that's ruben wrote about it last year we've been
talking about it but not until your announcement uh a week or two ago that you were launching
mercury wallet on uh testnet or bitcoin's testnet like i haven't heard anybody even attempting to
to create an implementation so i'm just like extremely excited that i'm sure you guys have
been vocal about it for a while and i just missed it but yeah well we started we started kind of
working on it i guess back in kind of april may this this year um so the first step is obviously
get it all working properly kind of protocol wise command line wise um and so the current
when we say micro wallet at the moment it's a very simple kind of command line uh client um
but we're now working on a you know a uh the full kind of final uh gui
um wallet which hopefully will be ready in a month or two awesome what is how's the uh reception on
testing it been? How has the software been? Yeah, everything's working. I don't know
if many people have actually tested it. I mean, yeah, it's quite technically involved.
We should probably do another launch with maybe an easier to use client. You know,
at the moment, anybody would have to download the Rust and compile the Rust themselves.
So a few people tried it though.
if any of you rust devs who listen to this podcast are out there get on it i'd love to
see this tested out and so what are what are the plans so you won't have a gui within a month
hopefully yeah um what where do we go from there is there something or an amount of data you're
looking to observe on testnet before you guys launch product or we'll keep doing we'll keep
doing testing um and you know we want it's a new thing i mean i guess we kind of do like a soft
launch where you know we would tell people to uh maybe not put serious amounts of money in it to
start with a bit like when lightning uh was launched uh don't be reckless um and uh yeah and
essentially build up confidence make sure because it's a new it's a new protocol it's a new model
we need to make sure it's very robust
and secure
and yeah hopefully this will
basically start happening kind of over the
over into the new year
yeah
and then I mean
moving on to
other kind of applications
is very interesting as well
and we still have
this you know discrete like contract
use case
in mind
uh and so it'd be yeah that'd be a really cool thing to do as well yeah we're we're big fans
of dlcs here yeah yeah this is kind of it there seems a lot of promise there to create um you
know to create kind of uh yeah derivatives derivatives that can be traded i think could
be very powerful like synthetic dollars and things that can be yes so you're working on
all this very interesting tech i'm interested to learn about more about you the person tom like
are you interested in this stuff because of the tech the liberating nature of the technology
and do you like the sound money aspect it's yeah i mean originally i was drawn to the the technology
um and then i think there's there's something about this i know quite a lot of uh people who've
but he's studied physics, really into Bitcoin.
There's something very alluring about this,
this kind of a proof of work
and the fact that you have this, you know,
this global state, which is kind of,
there's an objectivity to it,
which is very, very fascinating
that you have this single global state,
which is completely kind of, you know, no one can control it.
And that you have this kind of this huge amount of energy that goes into securing it.
It's a really, really fascinating kind of machine when you kind of look at it.
And so I think that was originally the big draw for me.
I mean, I've always been I've always really been into cryptography as kind of a hobby
and really fascinated by kind of modern cryptography and all the magical things that can do zero
knowledge proofs and and uh all this kind of stuff um but yeah the more i've got the more i've got
into bitcoin the more kind of convinced i've become about how kind of um revolutionary it is
going to be um in terms of yeah kind of undermining all kinds of established kind of power structures
um and this the it's really weird that you know when you try and explain it to people people
can't even it's difficult to even communicate to people that you have this thing that basically
is incorrect no one can no one can control this no one can um uh corrupt this um and so that's
i think is its biggest kind of um uh appeal is this yeah this this this yeah this this way of
of storing value transacting value that that is impossible for anybody to stop or yeah these and
yeah the more the more kind of you start to think about the the consequences of how this is going
to change the world yeah it's and i don't i don't know the answer to that um i don't you know i'm
not sure about kind of hyper bitcoinization all these things but i think it's going to be a big
a big deal in the future not i uh i actually recently reread misha trubitsky's piece on
proof of work essentially just being a decentralized clock like you mentioned proof of work creating
uh just a state at any given point in time of the ledger and it's crazy to think uh so i originally
came to bitcoin fascinated by the sound monetary properties and its effect on economics and finance
but as i get further down the rabbit hole i just become more drawn and uh more focused on the proof
work aspect just turning energy uh into these hashes that could potentially produce bitcoin
and it's fascinating when you have the aha moment over proof of work of how it really melds the
physical and digital worlds together in a way that's never been done before yeah i mean it's
this this kind of like what it's called thermodynamic immutability you know it's uh
uh that yeah you you you have this this way of now you have this kind of source of truth now
which didn't exist before nothing like it has existed before um and yeah the consequence of
this is is yeah difficult to really uh predict um yeah and it's funny watching people particularly
in the the altcoin world sort of gloss over proof of work and run right to what i would argue
I think there's fundamental misunderstandings and you see a lot the I think people would be
involved in in these kind of like you know kind of Byzantine fault tolerance protocols and things
it's I think yeah there's a misunderstanding that proof of work is just a kind of a way of
nodes to agree but it's a lot more than that and and yeah that the that has so many kind of
specific properties
and I think it's the only
kind of permissionless way to
have any kind of
consensus
but yeah
it's kind of yeah it's a really
incredible thing that you
you have this
yeah it's basically impossible
no it doesn't matter who
colludes it doesn't matter
who kind of
subjective opinions of the rest of the world
there's this one objective source of truth that anybody can can independently verify
um so yeah it's kind of yeah i think there's this there's so many unexplored use cases for this as
well um uh for for well yeah for for proving things um yeah yeah in a trustless way
no i love having conversations with physicists on this podcast
Dhruv Bansal being one of my favorite
because he just
naturally takes it to
the nth degree talking about
Bitcoin in space and how this can help us
interact with intergalactic
communities if they exist
and Dyson spheres
if you try to play this out
if it's successful
will Bitcoin mining
eat up all the energy in our solar system
that might
eat up all the spare energy
right
Yeah. And that's, I guess, another thing that people that kind of is slightly annoying about
criticisms of Bitcoin's energy use is, again, a failure to understand what it's actually achieving.
And the energy isn't wasted. This is replacing trust, essentially. And trust is
usually very, very energy inefficient in the real world.
yeah people don't know how to calculate and define the opportunity cost of
not using that waste energy to produce bitcoins yeah yeah it's uh yeah it's a learning process
it's a huge learning curve too yeah coming to these like wrapping your head around proof of work
wrapping your head around money to begin with and then everything you can't do with a utxo
So that's one thing. I have a theory that you could apply Jevons paradox to a Bitcoin UTXO and seeing you create a state chain implementation sort of feeds into the narrative behind that theory, which is if you can make UTXOs more useful, give them more utility, they will be used more and therefore driving a sufficient fee market to sustain mining with a hard supply chain.
cap into the future yeah yeah yeah yeah i can see where that's going
um so why mercury well what's any any reason behind the name no i don't know i don't know
if it came from yeah i can't remember the exact reasoning for it uh it just sounded uh
good i think we've used a mercury name before uh for some kind of elements stroke liquid
kind of uh thing but yeah no i can't remember the uh the exact uh name but i think it's one
of these things that just stuck um and uh and yeah seems to seems to sound quite nice so yeah
um no again thank you for for putting in the work to get this implementation market it's again
something we've been talking about um i know it's only on testnet now but the fact that somebody's
working on it is incredibly bullish in my mind yeah it's been a lot of fun it's been it's been
a really fascinating thing to work on um and again this is it's my uh first kind of uh um
use of of rust uh in in uh kind of in something real um so that's been quite interesting
challenging
but yeah
it's been a lot of
it's been very interesting
and a lot of fun
to build this
and yeah
everyone's very enthusiastic
about it on the team
so yeah
and it's one of these things
yeah I've just got
a good feeling about it
I think it might
yeah
be in the right place
at the right time
and
yeah hopefully
be
be
useful
I mean if it helps
with privacy
i think it will certainly be useful we think that's one of the most needed areas of improvement
in the bitcoin stack is his privacy tools so yeah another one another option is just incredible
um i just wanted to jump in here real quick uh first of all
um appreciate the work you know i've been very focused we've been very focused on privacy here
for a while now and we think it is one of bitcoin's major uh you know ux issues uh mostly
uh in terms of direct directly right in the face of user and i i think it's it's a it's a major
vulnerability to mostly on the user side yeah the number one thing for all these systems is the
amount of people we get using them so yeah do not do not diminish do not um underestimate the
importance of the importance of ux here like it needs to be uh straightforward for the user where
they can conceptualize it and and there can't be that many foot gun things because if if there's a
way for the user to shoot themselves in their foot they probably will and yeah but these systems it
usually hurts other people's privacy as well because it diminishes the overall uh the the
the overall anonymity set um i have a question the has there been any thought into using this
type of implementation as like a private way to do like swaps between lightning and liquid and
on-chain um well i guess there's two two there's been people lots of people mentioned doing uh
using this on kind of uh lightning channels being able to swap ownership of uh
lighting channels in the same way that you swap ownership of a you know position in dlc right um
but yeah the the you could do swaps again you the current model is the yeah that you trust
you're basically trusting the coordinator to do the swap atomically um but there's no reason you
you couldn't swap anything like i feel like specifically with liquid it'd be like really
easy to implement into something like this am i mistaken to do a kind of what an lbtc btc swap
where we're like any the people who enter the state chain for the swap the swapping of this
in the state chain could be either liquid or on chain and they could come out either liquid or
on chain yeah yeah yeah that's that's an interesting idea actually which would be easy because obviously
it's the same that obviously swapping with a different currency is you have the problem of
the fixed amounts but i guess on on this would be exactly the same it's already packed anyway
yeah that's yeah that's quite an interesting idea like people would i guess like that because
there's more privacy yeah because it'd be it would it'd be interesting that you could come
in or out with liquid or on chain it would make an interesting privacy heuristic breaker there
yeah yeah that's interesting idea and it's the major shortfall of liquid right now is coming
in and out yeah yeah because uh to do a peg out is so it could benefit both you know yeah yeah
yeah matt with the hot product tips here on tftc
um tom i know we have a hard stop because you have to pick up your children is there anything
uh we should wrap up with particularly that's on your mind anything to focus on anything um
I don't think so. And in particular, hopefully I've been able to, you know,
get across everything we're, we're, we're doing. But yeah, I mean, if,
if it would be great if people were, would want to, you know,
help us test it out. Also, you know,
everything we do is completely open source. And yeah, I mean, if, if,
if people wanted to go ahead and, and you know,
set up their own state chain entities they're kind of, you know,
welcome to do that
and yeah basically we appreciate
any kind of feedback people can give us
but yeah
but it's been yeah we're getting a lot of good
we're getting a lot of good
kind of
feedback on
yeah that this is something that people would
use and people would find
valuable
oh yeah no I think
I'm very excited
to see
see a proper implementation of state chains come to market.
It seems like you guys are on the right path and very much looking forward to
the GUI and the main net product when it launches.
I'm sure we'll definitely be testing it out and letting the freaks know how it
went. So definitely keep us updated on everything that's going on.
Yeah, sure. Matt, do you have anything to wrap up with?
Thanks for coming on, Tom. Really appreciated this conversation.
Yeah, no, thanks for having me.
I appreciate it
well I hope you enjoy the rest of your
night
thank you again for taking an hour
to come explain this to
us again very bullish
and excited to see what we
have in store moving forward so
that's all we got this week freaks cheers
peace and love
tiki
