"The Infinite Compute Layer for Everything" by Michael Dong // ECC#2 - Buenos Aires 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Michael Dong from Brevis showcases their infinite compute layer for web3 and what Brevis does and problems it faces. Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] Thank you everyone uh for coming to my talk this afternoon. I'm Michael. I'm co-founder and CEO of Brevis. And uh as Brevis, what we bu we're building is what we call the infinite compute layer for web3. And uh you know it's a smart verifiable computing platform that allows you to offload very complex and heavy data computation from a blockchain to an offchain environment where you can essentially generate a zk proof and verified onchain.
So, but before I dive into what exactly Brevis does, let me kind of try to describe the problem we're trying to solve a little bit more. And that's not the right clicker. Okay. So, you know, blockchains are often advertised as word computers, but if you think about it, they're actually some crappy water computers themselves because none of them can run faster than a single server and they're generally very very expensive to run. Now what is the fundamental reason for that?
Well, you know, you may say, you may say that, wait, wait, wait, wait a minute. You know, we have done so much in the last, you know, 10 years in blockchain scaling. We should be able to just run any kind of a computation on blockchain, especially layer one blockchains today. Well, unfortunately, that is not the case. Let me give you a very very simple example here.
That is why we don't even have VIP trader programs on DAXis. You know VIP trader programs, you see them on all your centralized exchanges. The concept is very simple. If you trade it allowed, you become a VIP of the exchange and then you get a trading fee discount. But the reason they don't have this in your smart contract based access is because building this in smart contract and running this kind of computation to calculate what is a user's historical trading volume turns out to be extremely expensive.
So you know that's that's kind of like the scalability constraint you're still facing in today's modern blockchain especially layer one blockchains but even if you're doing this on the cheapest layer two there is available you're still faced with a huge amount of transaction fee that is going to bankrupt the entire chain. So the fundamental reason behind this is that today's layer one and blockchain consensus are built on a very very simple form of computation. So let's say you know here we're trying to achieve a consensus between two nodes Alice and Bob. Alice is doing this computation and trying to convince Bob the same. So what we do here in the simplest form of computing is that Alice will do the computation herself and then you know uh tells Bob hey this is the result of the computation.
Now, how does Bob know the result is actually correct? Oh, what's going on? Okay, so how can Bob know this result is actually correct? Well, you know, the simplest thing Bob can do is to do the computation again. So you know Bob spend the same amount of computation power and do the same kind of computation and we use recmp computation as a way to do verification and the only way to achieve consensus in today's uh consensus protocols.
So what this means is that let's say you're trying to process this kind of a swap in your daxis with a one single node. But if you're trying to do this on Ethereum, for example, there are like 800,000 or close to a million nodes. What's going to happen eventually is that you're going to repeat the same piece of computation again and again again for a million times. Now this is a fundamental reason why blockchains and layer two block layer one blockchains are expensive today. So how do we solve that?
Well, we can solve this fundamental challenge with something called verifiable computing. So in verifiable computing, you have different roles in the entire computation process. You have something called a prover in which case is Alice. So for Alice, she's not only doing the computation itself, but also generates something called a zero knowledge proof. Now the this zero knowledge proof is a very magical thing that she can send it to Bob.
And for Bob, he doesn't actually need to do the competition again, but instead just verify the proof with extremely low cost and extremely low latency. Now the magical thing about you know ZK proof is that you can decouple the process of doing the computation with the verification of the computation itself. And also very importantly you know with ZK proof it doesn't actually matter what is the the complexity of their original computation once you generate a proof the cost of verification mostly stays constant. So this is like a very very powerful paradigm that you can use to build a faster you know blockchains and uh uh many other things. So you know privous is actually used in many different kind of scenarios but in blockchain specifically what you can do is instead of putting all the heavy and data complex combination onchain you can move them away from blockchain to an offchain environment and in that offchain environment we can do is you can generate the zk proof and send the proof back to the blockchain where the blockchain itself can only just verify the proof in the smart contract with extremely low cost and low latency and become only the glue point of very complex competition.
And with this kind of new paradigm, you essentially extend the capability of blockchain computation to infinity because whenever you encounter something that is too complex to do onchain, you can just offload it to this kind of verifiable offchain environment. So I want to highlight that this kind of computation is not theoretical anymore. So this is actually being used by numerous different kind applications and you know in various different kind of sectors you know like MetaMask you know pancake swap, unis swap, beefy, open eden, euro, linear and all these different kind of top tier applications actually uses a previous day to power a new generation of features that is uh oh available uh in their application. So some very quick examples. Well, you know, we talked about this and you can essentially just have the capability to now, you know, on pancake swap, you know, use uh the brevis to generate a proof that you have actually traded allowed on the uh exchange and then kind of get a trans transaction fee and trading discount.
And uh you know we're actually building something even more exciting in the intelligent DeFi space to essentially allow you to build a new generation of perpetual swap exchanges that have the same experience of a centralized exchange but at the same time gives you the same kind of a security of layer 1 because you settle all these kind of matching process using ZK to the layer 1 blockchain but and at the same time you get also get some additional privacy benefit because you can enable something like a darkpool And speaking of privacy and especially for this event, you know, we are enabling a variety of privacy preerving verification features for many different applications including Kaido. So on Kaido today user can essentially generate a test station of their wallet uh token holding amount without actually revealing the amount of tokens they hold and revealing the exact wallet address and associated that attestation with their social profile to say that okay look I'm giving some opinion about like D5 market and you know I can prove that I'm a power user for D5 but I don't need to show you what exactly is my wallet address and this is a kind of a feature that is can be achieved by brevis as well and um you know um we are also kind of doing a lot of things in the RWE and the stable token space to allow kind of a distribution and launch of stable token and real world asset ecosystem. So once you launch a stable token the next thing you need to do is to actually get them embedded in the entire D5 ecosystem. Well how do you do that? You need to design a reward program that can organically embed your stable token into all these kind of D5 protocols and allow user to kind of actually use them.
Well, how do you do that? You need a system that is actually trustless and secure and transparent so that the user knows that okay, I'm getting this reward not because you know I'm good friend with this project but also because but actually because I'm actually a power user for the protocol itself. So now you know with brevis what we can do is that is we built something called continuous protocol incentivization to allow user to generate zik proof of their interaction with the different protocols using the stable token and use that as a way to get user um you know protocol reward and similarly we recently launched with the linear for their linear ignation program to help distribute a 1 billion linear token using zik proof as well. So there are many different kind of application we're running but my prediction here is that as you can see you know verifiable computing is actually being adopted by all these kind of different top tier project and in 10 years I would say 99% of all competition for blockchain applications are going to happen offchain and hopefully verified by zk proof and brevis so you know okay so I've been talking about brevis but what is actually inside this magic box so the entire hardware stakeh stack is consists of three parts in the middle it's something called a pickle zk VM and then you know we have some co-processors and a prover network that support this whole thing so pickle is a risk five based zkm that you can use to prove really any kind of software combination it's a risk 5 ISA VM with a function level pre-o compiles so you know because it is a high level and general purpose zk VM um the developer experience is very drastically different from your traditional zero knowledge proof development experience. You can basically write a high level programming languages without actually relying on low-level understanding of the zero knowledge proof protocols.
So for example, this is like the kind of a program you run if you want to essentially prove the correct computation of Fibonacci uh numbers. And what this means is that once you have this, you can essentially run your entire Ethereum client like in Rust in a verifiable way. So with this, you totally change how Ethereum layer one of consensus work because now instead of having all 800,000 nodes repeat the same kind of computation, you only need to have one node does the competition itself and generate a proof. So the entire rest of the network can just verify the proof with extremely low cost. And this is what we're doing and this is what how we're helping to change the Ethereum layer one uh scaling landscape by essentially proving Ethereum blocks in real time in terms of execution.
Now what this means is that you can essentially have a pickle to essentially generate a zk proof and you know the rest of the network can just verify the proof and the entire processing cost fundamentally will decrease by orders of magnitude and we currently provide the fastest ZKVM for Ethereum proving uh you know uh in production and you can oh what happened you can refer to our ah You can to refer to east proofs which is like a layer two bits equivalent for ZKVMs for more detail about the performance of the our Pico ZKVM and you know Pico is very performant but the performance is not enough and in fact we know that because Pico is like very generalized ZKVM it definitely make some trade-offs in terms of the performance and generality. So you know the performance of Pico is not going to be as fast as a specialized circuit. But for PIV we want it to operate at the optimal point of the trade-off plane. So how do we do that? Well, no, this is actually thanks to you know this is like the modular modularity here is to the rescue where we build Pico in a very modular way where we have a very general glue in the middle and then you can add a bunch of plugin into this entire system to make a specialized use cases and the specific use case is much faster to run.
So you know instead of just relying on the general VM we have a bunch of application level co-processors. Some of them focus on onchain data co-processing, some of them focusing on ZKML and others. So specifically we have a onchain z co-processing zk co-processor that allows you to generate zik proof for any historical onchain data and run arbitrary computation on top of them and this gives you another two order from magnitude faster performance for these kind of use cases that you when you need actually onchain data uh processing and this is a precisely why with the brevis you can actually you know build a lot of different kind of use cases is that is production ready because we have this kind of a very unique modular and glue and co-processor architecture that is embedded in our entire architecture. So finally what we have here is that you know you have a very general ZKVM and then bunch of co-processors. What we also have is something called a brevis prover that allows you to generate proof in a transparent and a decentralized way and you know it really helps you to handle hogenous workload with a new kind of auction mechanism called truthful online double auction that allows you to actually cater to different and a very kind of a you know diverse set of workload that is possible and uh you know needed in the entire proving process and uh you know we're launching the prover network very soon and uh you know um hope you guys can follow us here and if you have any questions you can always find us after the talk.
Thank you. [applause]
Automatic transcript — names and jargon may be misspelled.