Professor at Stanford University (tselab.stanford.edu, davidtse.io) Co-founder of Babylon protocol, Information theorist.

Pinned Tweet
Today we release BABE, a new Groth16 proof verification protocol for Bitcoin. It improves the state-of-the-art by three orders of magnitude in setup and storage costs. eprint.iacr.org/2026/065.pdf BABE (BAbylon-BErkeley) is a synthesis of two key ideas: Witness encryption on linear pairing, and Argo MAC, a recently introduced garbling primitive. Witness encryption on linear pairing reduces the complex pairing operations in Groth16 verification to a single scalar multiplication on the BN254 elliptic curve. The single scalar multiplication can further be transformed into a vector homomorphic MAC, which can be efficiently computed by Argo MAC. BABE will be launched as part of Babylon's alpha-testnet for the Trustless Bitcoin Vault in February. We thank: - our Berkeley collaborators @SanjamGarg and Dimitris Kolonelos for teaching us so much about witness encryption - @liameagen and @therealyingtong for sharing their amazing work on Argo MAC - the Babylon engineering team, for turning our theoretical ideas into a real system with demonstrable performance gains Check out the paper and give us feedback!
BitVM2 suffers from a huge on-chain fee of > $15,000. BitVM3 dramatically reduces this to be less than $100, but the off-chain costs are very significant: terabytes to store the garbled circuits and hours of compute and communication to set things up. Bulky. Three months ago we embarked on a totally different approach based on witness encryption. Happy to report today that we got a 3 orders of magnitude reduction in storage and in the setup time while keeping the transaction fees as BitVM3. More details later.
16
41
223
35,888
AI disruption in research will not be evenly distributed. Theory-heavy fields like cryptography, blockchain, and information theory are exposed earlier because much of the work is abstract, computational, and machine-verifiable.
4
6
34
2,197
Glamsterdam is coming. In the worst case, handling a hard fork means: → Pause the system → Ask users to withdraw → Restart under new rules Technically viable. Practically terrible UX. So the real problem is avoiding this outcome.
4
3
14
1,099
It takes me at least five years to train a new graduate student to the PhD level. Yet AI can produce a new generation of models every few months. Our knowledge cycle is measured in years, while AI's is measured in months.
2
8
43
3,073
AI can solve hard research *problems*. Can AI solve entire research *areas*? We want to find out. So we start with an area we are familiar with: Bitcoin.
Solving Bitcoin is an auto-research project aimed at advancing the state of the art in Bitcoin protocols. We’re starting by optimizing common cryptographic primitives, including Lamport signatures and arithmetic. Join us: let your clankers optimize scripts, implement new primitives, and submit PRs. github.com/solving-bitcoin/b…
2
2
18
1,801
A cell phone cannot build a better cell phone. AI can build a better AI. A previous model's reasoning data can become training data for the next generation. That feedback loop gives AI a speed of improvement earlier technologies did not have.
3
3
27
1,770
I had no interaction with Berkeley for 13 years. The first invitation back in September 2025 helped produce BABE. That return led to a meeting with @Sanjamgarg. We named BABE after Babylon and Berkeley.
3
18
1,927
We did not solve witness encryption. BABE is a relaxation of witness encryption to allow interaction. A solution to (non interactive) would have a big impact on theory and practice.
2
2
28
2,041
David Tse retweeted
We’ll be in Hong Kong for @Bitcoinconfasia from this week🇭🇰 Meet @baby_fisherman, @yijihoon5, and @rngesus_95 to talk native Bitcoin collateral, integrations, and Babylon Trustless Bitcoin Vaults (TBV). See you in Hong Kong.
15
15
52
9,993
SBC is the least academic of the academic conferences. Crypto trade shows sit at one extreme. Closed academic conferences sit at the other. SBC occupies the middle ground. Having no formal proceedings gives technical researchers the freedom to tell the story behind the work.
2
3
30
3,167
At SBC 2025, I crossed out witness encryption as a dead end. Our garbled circuit solution required 42 gigabytes of data and an on-chain cost of $15,000. Dan Boneh sat in the front row and said "not yet."
3
5
49
7,256
One year later, we found a way. Combining garbled circuits with witness encryption ideas producing a concrete improvement in cryptographic proof efficiency.
1
28
779
Congratulations on solving a beautiful problem. This is bringing back old memories ; I still remember first discussing this problem with Sergio Verdu when he was on sabbatical at Berkeley in the late 1990's . With a wink of an eye it's now 25 years later. Some perspective on this problem from someone who has been around. This problem belongs to the class of problems called "multiuser or MIMO detection", pioneered by Sergio Verdu and received a lot of attention in the late 80's and early 90's, In the late 90's and early 2000's, there was a resurgence of interest in this problem via connections with random matrix theory. I myself have worked on a bunch of these problems, evaluating performance of different MIMO detectors. The problem that AI and @DimitrisPapai have solved is the ultimate of these problems because the optimal MIMO detector is the joint ML detector. I am very happy to see it solved. That being said, I have to say that MIMO detection as a whole has made little impact on how actual wireless communication systems are built. Because wireless communication systems, like all communication systems, use coding, while MIMO detection only talks about uncoded systems; the N information bits here in this problem are uncoded. It turns out that much lower SNR can be achieved with coding. Take this problem as an example, with coding, a constant SNR* = 1.32 is sufficient to support an information rate of 1 bit per antenna, in contrast to the growing SNR = 2 log N result just proved. That's one reason why although this problem is beautiful as a mathematical problem, it has not received the full attention of the information theory community even in those days of peak activity. Claude Shannon has already told us in his 1948 information theory paper: to achieve the ultimate limit of communication, one needs to do coding. Uncoded systems are sub-optimal. So SNR = 2 log N is only optimal among uncoded communication systems, but SNR* = 1.32 is optimal among all communication systems. The problem that Claude Shannon solved in his 1948 paper was the capacity of point to point communication, The problem here is one example (so called point to point MIMO channel), and hence the optimal SNR* = 1.32 can already be computed by Shannon's 1948 theory (no AI needed). Most of the information theorists' attention in the hey days of wireless communications research has been to extend Shannon's theory to network information theory problems, such as the broadcast channel, the relay channel and the interference channels. In those problems , one ask what is the best information rate (or equivalently, the minimum SNR needed) that a network of users can communicate with each other. These problems have been proposed since the 60's and the 70's and to this day none have been solved in their full generality. I'd love to see AI take a crack at some of those open problems.
7
14
152
54,841
Doesn't this guy look good?
Deposit native Bitcoin as collateral, not so difficult! @VladDegen, Babylon's DeFi Product Lead, walks us through how to deposit your native Bitcoin on our Public Testnet for native Bitcoin-backed borrowing. Join the Public Testnet with @aave v4:
3
3
18
4,078
I'm a big believer in a principle from @danboneh: "The best crypto is always developed in public." If you're building, make it public as soon as it's ready so the community can attack it. This is how you build security that holds up under real-world scrutiny.
7
6
52
3,335
We've raised four funding rounds. The difficulty of each round depended almost solely on market timing, not our technology. Exception: A16Z invested during a bad market because they believed in long-term trustless infrastructure. Most VCs are "long-term investors" until sentiment shifts.
12
8
178
22,684
Without BABE and witness encryption, the BitVM2 option is roughly $15,000 and for BitVM3 40GB per garbled circuit, and a couple days for a basic action. That is why cryptographic proof efficiency is key for trustless Bitcoin collateral.
5
7
37
4,856
Last year at SBC, I presented the slide below on verifying ZK proofs for Bitcoin and said that witness encryption didn't seem like a viable path. @danboneh said from the audience "right, not yet" (you can hear it in the recording). He is quite prescient. It's now a year later and tomorrow at SBC I'll be presenting (925am PT) on how we discovered a witness-encryption-based solution to reduce costs by 1000x.
11
11
91
7,481
As a researcher, the instinct is to share only after things are fully thought through. But the most interesting ideas are the least worked out. So “thinking in public” becomes a tradeoff: frequency vs correctness. I don’t think I’ve fully resolved that yet.
4
1
14
1,438
Can Claude trained only on 1938 knowledge invent information theory ?
Demis Hassabis, CEO of Google DeepMind and Nobel laureate, says the AGI definition the industry uses is too low a bar. His Einstein test: train a system on a 1901 knowledge cutoff and ask it to invent special relativity. "The human brain is the only existence proof we have that general intelligence is even possible." "That's a pretty high bar, and it means that it's probably higher bar than just being able to do some useful economic work." "The type of test I would have is like an Einstein test of, you know, let's train one of these systems with a 1901 knowledge cutoff. Can it invent special relativity like Einstein did in 1905?" "What you'd actually want is something a future version of AlphaGo to be able to invent Go, right? Invent a game as deep and as complex and elegant and as beautiful as Go, not just come up with a strategy within the game." "I don't think today's systems are yet capable of doing that, but I think they will be able to in the future." - Demis Hassabis (@demishassabis), CEO of Google DeepMind, on The Next Big Thing.
4
3
20
4,958