There has been a lot of excitement around BitVM the last couple of days.
We all believed arbitrary computation on #Bitcoin needed a script upgrade, so how can BitVM achieve this without a consensus change? 🧵👇
Oct 11, 2023 · 11:02 AM UTC
3
20
81
26,188
💻 Running arbitrary computation off-chain and efficiently doing dispute resolution on-chain has been a paradigm I and many others have been excited about for a while:
⚙️I just recently posted a regtest demo of something I'm very excited about to the #bitcoin dev mailinglist:
1
7
1,170
Since MATT and its accompanying opcode OP_CHECKCONTRACTVERIFY (CCV) is what I have most hands-on experience with, I will use it to explain BitVM.
1
7
819
In both BitVM and MATT, what you do is having a prover break up the computation into a long series of steps, where each step takes the state of the computation to a new state 📜
1
10
856
If a verifier disagrees with the outcome of the computation, it can challenge the prover by finding a single state step that is not according to the pre-agreed upon rules ❌
1
7
831
The reason we haven't been able to do this in Bitcoin script is that there has been no trustless way of bringing "state" from one transaction to the next 💾
This is essentially what (among other things) covenant proposals like CCV enables.
So how does BitVM do it? 🤔
1
11
912
The novel building block that makes this possible is the “bit value commitment” construction 🤓
This is a very clever way of getting around the limitation that you cannot easily pass state trustlessly from one bitcoin transaction to the next.
1
2
20
14,734
Bit commitment is an incentive based scheme, where the prover has to choose whether a data bit in the computation is 0 or 1.
💰 During setup the prover deposits some amount of BTC that is guarded by two secrets.
🔎 If the verifier learns both secrets they can take the money.
1
1
10
1,428
The trick is to force the prover to reveal one of these secrets in order to set the value of one bit - so if they try to cheat by changing a bit from one step to the next they risk losing their deposit! 💸
1
2
10
1,346
Bit commitments magically incentives the prover to transition the correct state from one step of the computation to the next - achieving what a covenant would do! 🤯
1
11
949
In other words, the BitVM prover is incentivised both to not "change its mind" about the state of the computation AND to perform every step of the computation according to the rules. If they don't, they will lose their deposit 🤝
1
1
9
1,611
There are still a few unanswered questions to make BitVM practical, but all in all this is a *very* exciting development.
Very much looking forward to the ideas emerging over the next weeks/months to bridge the gap! My guess is that it will always involve some tradeoffs, which may or may not be practical in the real world.
1
9
1,461
I look forward to the prototypes and demos popping up - and hopefully answering some of the lingering questions. Hats off to script wiz @robin_linus 🧙♂️
1
1
13
951




