Up next
All episodesPREMIUM: Taiko & The Future of Rollups | Justin Drake, Brecht Devos, & Jeff Walsh
The Trillion Dollar ETH Pitch | RSA+DH
ROLLUP: ETFs Back? | Robinhood Acquires Bitstamp | Biden SAB-121 Veto
DEBRIEF: The Luke Gromen Interview
The End of the Petrodollar | Luke Gromen
PREMIUM: AggLayer & Espresso | Brendan Farmer & Ben Fisch
When Will We Go Parabolic This Cycle? | RSA+DH
DEBRIEF: The Justin Drake vs. Anatoly Yakovenko Interview
Inside the episode
🎬 DEBRIEF | Ryan & David unpacking the episode
Today on the show, we’re exploring the frontier of ZK Rollups on Bitcoin!
The Bitcoin L2 landscape is standing on the shoulders of this technical implementation called BitVM. We brought Robin Linus, one of the author’s of the BitVM White Paper, to not only dive into how BitVM got started, but more importantly, what it means for the future of Bitcoin.
TIMESTAMPS
0:00 Intro
5:03 Who is Robin Linus?
10:20 Why Bitcoin?
16:19 Bitcoin Needs to Scale
22:15 BitVM Eureka Moment
24:31 The State of BitVM
27:19 BitVM vs Ethereum Rollups
33:45 How Does BitVM Work?
46:07 BitVM Critiques
55:07 The Bitcoin L2 Space
59:33 The BitVM Endgame
1:03:07 The Future of Bitcoin
1:07:09 Closing & Disclaimers
RESOURCES
Transcript
In general, there is that thing in
the crypto industry that um when there is a hot topic, uh there is hype, and when there is hype, then there is easy money. Like people want to invest, people think there is that opportunity to like make a quick hundred X or something.
And then there are always
projects who are exploiting that, who are selling
stupid ideas to to greedy investors.
Welcome to Bakelist, where we explore the frontier of internet money and internet finance. And today on the show, we are exploring the frontier of ZK rollups on Bitcoin through the lens of the BitVM. You might be familiar with the Bitcoin Layer 2 landscape. This has been a thing that has been very hyped in development in the Bitcoin world over the last year or so. All of that technical innovation is standing on the shoulders of this uh technical implementation called the BitVM, which promises to enable true, uncompromised, trustless Bitcoin layer twos. We are bringing one of the authors of the BitVM white paper, Robin Linus, on the show today to talk about how he got into the world of building the BitVM and exactly how it works and what it strictly enables under the hood, and how it is the same or also different from the Ethereum roll ups that you may be familiar with.
This, at least to me, I don't know, David, if you agree is, is uh one of the most exciting projects I've ever heard of on um Bitcoin because it promises to create a um just a ton of innovation and scale on top, including kind of a robust roll-up type ecosystem and all sorts of things can be built on top of BitVM to sort of scale this. So some have described this uh to us as the holy grail for Bitcoin scalability. So it's very exciting to hear Robin describe that here today. Guys, we will get right to the episode with Robin Linus about BitVM. But before we do, we want to thank the sponsors that made this possible.
Bankless Nation, super excited to introduce you to Robin Linus, a Bitcoin developer and one of the primary authors of the BitVM white paper. BitVM is a proposal that aims to bring Turing complete smart contracts to Bitcoin, similar to those that we would find on a dedicated smart contract chain. Robin, welcome to Bankless.
Hi, thanks for having me.
So, Robin, I know you primarily as uh the BitVM guy. Uh, so I'd actually like to get to know you uh a little bit more. What's your background with Bitcoin? How did you come to become uh put working on the BitVM? Just tell us a little bit about yourself.
Yeah, together with my co-founder Lukas, we founded a nonprofit company called ZeroSync.
And the goal of ZeroSync was just broadly to uh apply zero knowledge proofs to Bitcoin.
Because yeah, obviously zero knowledge proofs are
the future, and um we kind of saw a lag in in Bitcoin. Like nobody was really applying them.
And yeah, that's why we founded that nonprofit company, and we started out building.
A chain state proof, which is essentially a way to compress the chain and sync faster, so that you essentially can sync on a phone or something.
And um yeah, while playing with these zero-knowledge proofs, it became apparent that it would be awesome to have some kind of CKP verifier on the main layer as well.
But um back then Bitcoin was like
trending towards ossification a lot. Like
Jeremy, Jeremy Rubin just tried to activate CTV and
well he failed with that, and uh the sentiment in the entire community was.
Uh pretty much against any kinds of forks back then. And um
yeah, so
then the idea came up if there is some way to hack a ZKP verifier into Bitcoin as it is.
Because Bitcoin has that scripting language, which is very limited,
but hardly anyone can tell what it can do and what it cannot do.
And so it was a very interesting research question what we can do with it, and can we build a ZKP verifier with that?
And yeah, for the better part of 2023,
me and a couple of friends just
bounce off ideas off each other. Uh, what could be possible? We researched different CKP schemes.
And um yeah, it seemed like nothing really works because yeah, there is that script size limit. You can have at most four megabytes of script
because the block size is four megabytes, so your script can be at most four megabytes.
And that sounds a lot, but it's actually very little because script is so limited. For example, there is no multiplication. Like the most simple thing, multiplying two numbers is not possible natively in Bitcoin script.
What you can do though is stuff like addition. And then when you can do addition, you can compose multiplication, but then you need a lot of opcodes, and then your your the script size blows up very quickly.
And um yeah, so we figured out that it's not really possible to just
build a ZKP verifier directly in script.
And um
then I thought it's just not possible. But two of my friends, namely uh Super Testnet,
yeah, a couple other guys, we founded a group,
um, a Telegram group, and um
they keep pushing. They they were totally convinced that there must be some way to activate uh to implement a ZKP verifier in Bitcoin script.
And I thought actually it's nuts, but uh I I like reading what they were saying.
And then at some point, um
Somebody came into the group who
talked about optimistic verification.
The MAT proposal, maybe you've heard of that. Probably Ethereum people are not that familiar with it. Merkalize all the things it's called.
And um
when I dug more deeply into that, uh it became apparent that something like that should be possible
in Bitcoin script as it is right now.
And then I started playing around, and then uh
I built like a first version that was very limited and didn't really solve the problem.
But after a week or two it just suddenly became obvious how to do it. And then uh
Supertestnet started building prototypes and uh he he he actually started telling everyone about it and everybody got excited so I just wrote very quickly a white paper and pumped it out and uh yeah suddenly BitVM was a thing.
Where would you say you get your like engineering chops from? Were you a cryptographer by trade before discovering crypto, or did you or uh did you learn cryptography through Bitcoin? Like where is some of your like technical competency come from?
Yeah, I studied computer science. Um I was always very interested in math as well,
but like I s I started out more like
Building apps, uh web apps, and uh
more like on the user interface side of things. I also like design a lot.
And uh when I started to work on Bitcoin, it
became obvious that it doesn't really scale. It doesn't really work as money because it's just too expensive and too clunky.