New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

ZKPs on Bitcoin | Ying, David, Volokh, Keagan

Ethereum DenverMon, Mar 9, 2026, 12:00 AM

🚀 Get Ready for ETHDenver 2026! 🚀 We're already hard at work preparing for next year's biggest Web3 event! Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

Transcript

six months old.

What's his resting pose? He must be like 10.

I think they gave thumbs up to us.

All right. Hello. Um, my name is Keegan Mcclullen. I'll be moderating this panel which is titled Zero Knowledge Proofs on Bitcoin. Um, I've worked on and around Bitcoin for a number of years and uh am very interested in the topic and I will let the rest of the panelists introduce themselves.

Uh, yeah, I'm David Croy. Uh, I'm with Alpen Labs and we're building ZK rollups on Bitcoin.

I'm Millia. I do product at Starkware. I can also swim and drive.

My name is Ing Tong and I'm one of the co-founders of Ideal. Uh, ideal is also building trust reduced bitcoin bridges and I do mostly applied cryptography zero knowledge proofs.

Okay. So the question I want to start off with is that given that this panel is titled zero knowledge proofs on Bitcoin, I am very interested in like the zero knowledge proof primitive. But one of the observations that I have is that every single panelist up here is building Bitcoin bridges. And so the question that I have is what is it about the Bitcoin bridge that makes it kind of ground like patient zero for zero knowledge proofs on Bitcoin? I mean the idea of creating like some sort of trustless bridge has been the holy grail in in in Bitcoin and our industry forever.

Uh you know like back in 2014 Blockstream you know some of the major Bitcoin OGs they had this vision that we could create these side chains or these bridges that go from the layer one into a different layer two and we can get you know privacy or big blocks or you know DeFi or you know all of these different concepts. And so the idea of being able to create a a trustless bridge has always been the holy grail, but it was never actually possible until we had these kind of this notion or these concepts of of zero knowledge proofs. So that to me is kind of why it's like patient zero. Like this is the holy grail that I think our industry has always been building towards and we're kind of on the brink of being able to build practical implementations of it.

And really uh the superpower of the zk snark primitive that we're exploiting here is succyncness. So being able to compact the state of the site system and still check that it's valid and still check that its state transitions are wellformed. Uh we can do this very efficiently using zero knowledge proofs. Uh there's best-in-class proof systems like groth 16 and parry that are constant size uh in the relation being proven. And so this allows us to verify state arbitrary state transitions in a very limited compute uh such as bitcoin.

Nothing to add.

Very succinct of you.

So kind of a followup to that then what is it exactly that zero or in what ways do zero knowledge pro proofs play a role in each of the designs that uh your teams are putting together? want to go.

Uh I guess uh the key um property of zero knowledge proofs that is used is uh the fact that there's six sync to verify. So it's a primitive that allows you to compress basically infinite computation into one block. That's one aspect. The other aspect is that it's a the verifier program is a fixed program. So setting it up for the bridge is much easier than constantly having to import execution of arbitrary VM code.

That's my take. And um uh verifying a zk snark directly in Bitcoin script is really not very straightforward. Bitcoin script is missing big arithmetic and opcat and lots of op codes we might want. Um and therefore I think all of us are sort of interested in a bit VM3 style constructions in which the snark verifier is actually taken offchain uh into a garbled circuit and then uh optimistically verified onchain and we can go into details if if we want. Yeah, let's go ahead and talk about the basic overall design of like the I believe you know garbled circuits are something that at least two if not all three of you are pursuing in somewhere.

No. Uh Ilia, do you want to talk a little bit more about the design that you guys are putting together?

Yes, our design is whatever the people around me will build.

So what are the what are the people around you willing to build? That's the essential question.

Let's ask them.

Well, I I I think for context, right? So, so just to be clear, it's like Bitcoin can't natively verify zero knowledge proofs. For a layman like myself, that means that it struggles to do something like multiplication. So, we have to kind of hack in some sort of ability for Bitcoin to reason about zero knowledge proofs. And we do this through something called like an optimistic ZK verification.

And the family of products that have kind of allowed us to do this is something called BitVM uh yeah, called BitVM. There was a trade-off to all these different bitms. Like I think you heard Ilia mention BitVM 3. So BitVM one kind of says we can have Bitcoin reason about zero knowledge proofs but it takes a long amount of time. It could take you know 6 to 12 months to verify a zero knowledge proof.

So then we kind of squeezed that constraint and said well okay we can get that down to maybe we can verify these zero knowledge proofs in 1 to two weeks but the cost onchain on bitcoin is very high. And then we kind of squeezed that and then we said okay uh you know it's not going to take a long amount of time with bitvm one. It won't be high onchain costs like BitVM 2, but it will uh you know be larger off-chain storage requirements. So each kind of iteration has been a superior trade-off that allows Bitcoin to uh verify these zero knowledge proofs and that's kind of at the bleeding edge is this concept within BitVM that we call garbled circuits which is kind of the most efficient and optimized way uh with the lowest amount of overhead that Bitcoin can reason about these zero knowledge proofs. By the way, since this is an Ethereum conference, I assume most people are uh familiar with the design of optimistic rollup.

So, BitVM one and two are ve very very similar to that. The challenger basically asks the uh the person who asserted that they deserve funds to seek and destroy any faults in their execution. And the major breakthrough with BitVM which uh leverages garbled circuits is that the fact that you don't need this game anymore and you can defer any computation and most of the interaction offchain. So it's a very substantial breakthrough. BitVM3 is still optimistic but as he said it moves more of the work offchain and um so at the highest level the API we want is that uh if some operator posts an invalid zk snark onchain then anyone can learn the secret pre-image of some hash and having learned this secret pre-image they can then slash the operator that's the top level API primitive that we're trying to achieve.

So because uh there is no way to natively verify a zk snark what we do is we put the verifier in a garbled circuit as such that uh when evaluated on an invalid proof the garbled circuit reveals uh this pre-image offchain. So the process of challenging of evaluating the garbled circuit is completely permissionless and anyone who evaluates an invalid proof um using the operator's garbled circuit is able to slash the operator onchain. So high level this is how zk proofs fit into the architecture of bitvm3 bridges. So it's still it's still optimistic because we have to wait for some challenger and some evaluator to actually uh slash the operator.

Yeah.

Okay. So it seems reasonable to uh categorize all of this as like the the zero knowledge proofs and really the succinctness is the key property that you guys are after is really just a means to an end to build these sort of trustless two-way pegs. So maybe one of the questions I want to start with uh in that direction is why should people be interested or excited about this ability to create two-way pegs in Bitcoin?

I mean I am a Bitcoiner and there are special properties that Bitcoin has that other assets in our industry do not. Many people have just kind of, you know, begrudgingly just admitted that Bitcoin is a a special snowflake. And so even if we build these things like, you know, Snarks and DeFi and, you know, whatever other stuff in the Ethereum conference, there is a a missing component there that it it is more important to have this stuff on Bitcoin. Like it is the largest, it is the most important. It's the most untapped market.

It has because of its properties, its monetary properties, it it probably has the best chance of actually disrupting, you know, the monetary order. Like it's just frankly more important that Bitcoin has access to these things, these trustless bridges than the rest of our industry. Uh that may be a hot take at an Ethereum conference, but you know, that's what I feel.

Is there a second best?

There is no second best.

Um yeah. Um, why these trustless or trust reduced two-way pegs are interesting is because they're just strictly better than any alternative that exists today. The most widely used kind of Bitcoin defy construction is rep Bitcoin, which is just a multi-IG bridge. Uh, and there's a threshold assumption there, KFN honesty, meaning that KFN signers could just steal your funds. Uh these bitv constructions improve the trust assumptions greatly.

Um for deposit safety and deposit livveness we only have a one of for deposit livveness we have an n ofn livveness assumption on our signers. For deposit safety we have just a one of n honesty assumption. And then for withdrawals, so getting your money out of the bridge, uh, all we have is a one of n honesty assumption on the operators. So BitVM3 is a way to gain a strict improvement on the security assumptions over any other existing solution today. So, I want to actually So, I I heard an argument for why Bitcoin is important and I heard an argument for why this trustless two-way peg is better than like maybe some sort of wrapped ethere wrapped Bitcoin on Ethereum type of bridge.

But like, let's motivate even deeper than that. Why do we want bridges at all? Forget how good the design is. Forget bridges to where like like bridges from Bitcoin versus bridges from Ethereum. Like, what is it about the bridge?

What does it unlock for us as users of Bitcoin?

I mean, the Bitcoin ecosystem is extremely conservative and they're very hesitant to perform any protocol changes. So, it really narrows the functionality of Bitcoin to digital gold to a store of value. Uh, but it turns out that some people want to do more with their Bitcoin. They might want to borrow stables against it. Maybe they want to transact privately.

Uh, maybe they want to employ other DeFi protocols. So, bridges uh they just let you do that in another environment. And uh you really need to optimize the security of the bridge so people are comfortable and they don't feel that they're uh foregoing their Bitcoin in order to have these extra extra abilities.

For me um you know there are certain values that are ingrained into the ethos of Bitcoin and at its core I would say one is Bitcoin as a monetary revolution and then also this more cipher punk revolution of privacy. And as Ilia kind of alluded to, like there are certain things that may be required to necessitate these monetary revolutions and these cypher punk revolutions. And if we cannot change the base layer of Bitcoin because we don't want to or it's too risky or for whatever reason, the only kind of seemingly plausible way to to kind of like further perpetuate these ideals that I think everyone in Bitcoin is aligned with is through some sort of bridge. And it has to be a bridge with the absolute most trust minimized properties possible. So for me, I want to see privacy extended.

I want to see Bitcoin is money extended. And I think a reality is that, you know, finance is kind of the anchor that must be carried if money is to be succeeded. And so simply just having the attributes of sound money is not good enough if you want to undermine, you know, the entire global monetary order. And I do. So

yeah, I think a really sort of accurate signal is just how popular wrapped Bitcoin is. Even though it's just a multi-c even though the security assumptions are re really strong um people are using it to get loans people are using it to trade on DeFi AMMs and um I think just switching to a strictly better and more secure option has really real um sort of implications on which users this bridge is accessible to so institutions, custodians who need to fulfill certain legal requirements might find a trust reduced bridge just might might find the multisig just impossible to use and a trust reduced bridge as a viable option. Um and yeah, I really echo David and Alia's point on bringing privacy to Bitcoin. I think yeah whatever we do on Bitcoin has a huge impact on the rest of the ecosystem. Um, yeah.

So, what I one of the things that I'm hearing right now is that, you know, the goal is to try to maximize people's like financial like sovereignty, maybe their their agency. And Bitcoin allows this through some of its other uh like principles and values as do like you know maybe some other cryptocurrencies with just different trust assumptions and Bitcoin has the lowest set of trust assumptions. has the highest amount of like uh like it has cemented these values most strongly. But it sounds like also that if we want to undermine the global monetary order as it were that finance is a key in innovation in the sort of money stack or the economic stack that needs to be you know brought forward and that in order to bring that about we need these bridges presumably because the side systems that these are that we're building bridges to is in some way enabling these decentralized financial interactions. My next question really is maybe if you could each describe sort of like your idealized version of a side system uh that you might build a bridge to uh and kind of tie it back into that fi those financial goals that you might have.

Maybe give specific examples something that users could get excited about. Not necessarily like this. I mean not no timelines. I'm not asking you to promise anything, but like paint a very concrete picture of like what users will be able to do should one of these bridges be able to be uh correctly and uh like stood up in production.

I'm happy to go, but you guys want to go reverse order?

Yeah, I think really the possibilities are endless. You can verify arbitrary state transitions using um BitVM bridges. Um at Ideal one site system that we're very interested in is shielded CSV uh shielded client side validation and this is a protocol that shifts um the bulk of the responsibilities of validation to the client side and only uses consensus for um enforcing um double spend prevention. So, this protocol is really lightweight, high throughput payments, and fully private um and almost fully client side. So, we're excited for protocols like this that maximize user agency and privacy.

Uh, and this would be one of the first site systems we want to bridge to from Bitcoin. Uh for me in addition to what Ying Tong said I think the site system should have a consensus protocol that is DAG based and the DAG should be very wide because I think that's the best way to counteract me uh which I think is going to be very important in finance and I think it's sort of an uh understated uh understated development in blockchain that you you can have consensus protocols that really uh mediate uh moderate the effect of uh of like the the the classical model of sequential monopolies. in in current blockchains. I think it will be a major breakthrough.

Could you define for the audience what MEV is and why we should like want less of it?

Um yeah, I don't know if we want less of it. In a nutshell, what it is is the people who produce the blocks, they have an unfair advantage because they get to decide what goes into a block. And this uh advantage is exacerbated if uh if at every point in time there is one person with a monopoly on what happens next. So in a world where no such uh there is no such one entity it's uh it's more fair and uh a lot of the value that this monopolist can generate can be kicked back to users or just annihilated which uh I think is very important for high frequency trading and generally financial systems.

Um so my kind of ideal setup for a bridge is one that is radically unopinionated where you could have a bridge that goes from the Bitcoin layer 1 into any sort of expressive ecosystem that you prefer. If you like the EVM, great. If you like shielded CSV, amazing. You know, if you like Cairo and Starkware, great. And everybody can kind of be sovereign and choose, you know, which sort of set of trade-offs that they want, yet they can all share a unified bridge.

Uh you can kind of cross compose with each other. That is like kind of the grand vision and the ideal vision. In the short term, you're probably going to see these more just like here's a bridge, it goes into an EVM environment. But the long term is one where you have kind of, you know, you're radically unopinionated in the in uh kind of which environment that you want to go into. Uh and none of them would be a secondass citizen to to to the other.

In terms of concrete use cases, like people have been talking about DeFi for years, but I think really if you're like on the bleeding edge of seeing what's happening, we're really on the brink of these things structurally out competing Trady without any sort of random tokens and shenanigans. I think within the next, you know, even 6 months, I think that you're going to see things like, you know, Bitcoin back loans in like the low to single uh digit interest rates, not variable, but fixed interest rate maturity. I think that you're going to see DEX's and spot markets for BTC actually be able to out compete, you know, things like Coinbase and Binance, you know, without incentives, without like impermanent loss. There are some radically cool things that are happening where it's no longer cope where we say use DeFi, it's sovereign, it's decentralized, but you're actually just like hemorrhaging money and it's a worse solution. Like I think that these solutions are actually on the brink of of again out competing the alternatives.

The last thing I'll say on this is account abstraction is an insanely powerful concept for actually abstracting away the painful UX of things like seed phrases and ledgers and hardware wallets and having like the high security in non-custodial with like a Venmo or Cash App like experience and that is just a game changer. I think it's a great point by David that um lots of new DeFi primitives and protocols can be enabled using Bitcoin bridges and in particular using more secure Bitcoin bridges. So if the participant in this uh loan or this trading protocol can be their own operator and can contribute to the security of their own deposit and withdraw then they will be way more likely to participate and that's why better underlying primitives such as Argo um that shrinking the cost uh of these protocols and making them more efficient on chain has such a huge difference in the range of use cases that are enabled. And in Argo, our garbled circuit is 15.5 megabytes.

Uh anyone can be their own operator. And with this design, we're fundamentally qualitatively changing the types of bridges that are possible and the types of applications that people will feel secure using. I want to follow up on something that David just said where that you think that within six months that we will see uh changes where sort of DeFi will be able to essentially out compete tradfi in terms of just the the actual product without having to appeal to any sort of idealism about decentralization or privacy. What in the landscape has actually changed that makes DeFi actually legitimately more competitive on the grounds of pure finance as opposed to it being as opposed to appealing to the more cipher punk roots? I think one thing um with like say pool based models like like a uh or what compound pioneered this idea of what I call like permissionless capital formation like you are actually able to see in these pools that they're being able to borrow it you know I think it's like 3.

75% right now and part of that is there really is this idea where if you just create this open permissionless pool where yeah sure big institutions could come in or you know small people that have $10 or $1 and it could be all around the world like this idea that that people actually demand things like stable coins. They want to stay on chain. They're not using stable coins because uh you know they're they're forced to. They prefer to. And because they have this open access to these markets like a like there really is this idea that this permissionless open ability to just attract in deposits has been extremely successful at at driving liquidity.

There's also kind of more maybe I'll pause there because I don't want to get too into the weeds.

Well, unfortunately we are actually at time. So uh I you know I hope that this discussion was like interesting for people. I know that it was you know maybe titled zero knowledge proofs but I think at least with the speakers that we had in the room um I wanted them to at least speak on the things that they were you know interested in and actually like building uh and while zero knowledge proofs were a a key ingredient to that um I think that the implications of it are a little bit more interesting for for the audience. So hope that was the the right direction. Um yeah and we'll see you guys around the conference.

Thank you.

Automatic transcript — names and jargon may be misspelled.