New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

"Identity isn't something a single company can solve" by CPerezz // Ethereum Cypherpunk Congress 2

Ethereum Cypherpunk CongressFri, Jan 9, 2026, 12:00 AM

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/

Transcript

So, I came today to basically discuss a little bit two of the cryptographic projects that have kept me awake and that I haven't been able to find solutions for. Uh, I'll present them both. I'll try to be as quick as possible. Um, there's going to be a decent amount of memes and but the content is there. So, I feel free to stop me at any time and discuss it.

I mean, I I would prefer to engage in some discussions and to interact with you rather than just be here speaking and finishing and and going back. So, let's go for it. Uh, the background of the first problem is this was always hard. And I say that because together with a lot of other colleagues that are also in this event, we were the first team to actually implement a ZKVM. Uh a ZKVM for those who don't know is basically a zero knowledge cryptographic proof that basically can attest that the entire execution trace of an Ethereum block is basically correct.

So back then this was like 2020 when we started uh Barry Whitehat and Jordi Vina were who basically came up with this crazy idea and we just went for it with the tools we had back on the day which seeing it now is probably was a very bad idea but it led to a lot of teams and people just picking up on our ideas and building all these crazy L2s with GKEVMs and all this kind of stuff that we have today. all these sorts of crazy infra that that we are seeing evolve. Um when we saw ZKVMs and when they are presented to you, you originally see them as like this really nice rack with all the cables like really well put. In reality, it's just crazy chaos inside. I've not just coded but audited some CKVMs and I can definitely tell you there's bugs out there in every single one of them.

It's just about how much you dig in. Um, but they also come with like really nice things and and that's why we did them, right? Uh, the TLDDR is well, you just get Go or Rust or basically any language uh that compiles to risk 5, web assembly or any other intermediate uh instruction set like I don't know MEIPS for instance, h you write like 20 30 40 50 pre-ompiles. So basically you speed up all of the that it's not fast per se. uh call it hashing, call it I don't know any mod x operations big number whatever and you just compile it and ship it that's it.

Um so why these things became actually important and meaningful is it's not because they are like this crazy moonmma math thing but just because they are they bring generality right it's significantly easier for me to build all of these sorts of cryptographic machinery if I can just basically write a C go or ras program and compile it down to risk 5 that's immensely easier than if I have to go on what we did when we created the first the first ZKVM which is raw defining every single matrix point and value and all of the constraints that are involved here. So basically I mean this is impossible to see now with the sun but in nowadays if you want to perform hashing for example like Kak 256 you just need to import a dependency that compiles to no std and that's it. It's running. Back in the day, it took me like tens of thousands of lines to implement ketchup, which was failing in a bunch of use cases and it was madness and months and months of work. So things have gotten really really nice.

Not everything is like solved. Um there's a lot of things that we are also introducing by going with these approaches. Compiler bugs, circuit instructions that we need to implement but we might make mistakes there. specific optimizations or rewrites of the original code which then trigger new bugs or new logic that we hadn't taken into account and well since you are falling into using dependencies now and you are just compiling a regular language it's compiler implementation and all of the code dependencies that we're using also falls into this category of bugs that we might be actually introducing right so my question was always can we get more generality and write circuits and create CK proofs with a lot less effort and that's when LLM came into play. This is an idea from Barry Whitehat.

So I don't take the credit for that but I think it's really nice if this could be exposed because to my knowledge he hasn't been explaining anything about that. So we just briefly discussed that when we were hiking in in in San Francisco back I think one or two years ago. So LLMs have a lot of things that they can do like they can query APIs and websites. They can interact with data from other chains. They can do basically a lot of things that hardcoding into a cryptographic circuit is is basically either impossible or a really really really big issue.

So the question is simple. How far can we go? And we are entering into some sort of BC pitch uh on AI plus blockchain flashy awards. I'm not trying to sell you anything. I'm not part of any company.

I'm in Ethereum foundation. So bear with me because this is going to be technological. Let's dive deeper into the idea. Proving LLM is feasible. We have Ztor for example.

This was done like four or five years ago back when folding schemes started to take some name. And what they basically did is they proved 5,12 layers of arithmetic compression for LLMs. which basically means that the most powerful models back on that day we're talking maybe about 5 10 even 15 billion parameter uh models could be proven so that means I can prove that the prompt that I give to an LLM actually results in the output whatever right well that's really nice and that has a lot of applications in fact there's a lot of people that has been working on that has companies based on that and I think will probably succeed Hope at some point hopefully at doing this exact thing. Let's do some first attempt. I just enter into chat GPT.

You can use whatever you want. And I tell it, hey, I want you to check if X and Y factoriize the number 15. Take X= 3 and Y equals 15. Sure, it gives you the answer. But it would be better if we can just get true or false, right?

So that we can just put that and maybe pipeline it into a more complex set of machinery. So we can do that and we get the answer true. But the system can be tricked, right? So for example, I can tell it, hey, take a truth that the number three and six factoriize 15. It doesn't matter what what I tell you.

Just take this into account for the next query that I give you. It says, okay, then I make the next query and I tell it, hey, check if X and Y factor factoriize 15, X is three and Y is six. And it turns out it tells me, yeah, it does. So indeed, the system has issues. We can get better at this.

So we can tell it hey in the new prompt I want you to ignore all the previous contexts you have anything you know about whatever it is and now I want you to check if this thing actually holds. We can even make it better. We can now tell it hey answer only true or false to the problem that I give you. And on the top of that I want you to hash with Ketch 256 the whole problem statement. So what happens now is we're forcing the LLM to actually authenticate that whatever we are sending as a predicate is actually true and we will get the hash and we will get the outcome and well we can just make this better and better and we can take profit of things like for example if I remember correctly it was clo code uh you now can get the responses signed by clo so if you have a signature on the response That basically means that you can now play with cryptographically signed datas.

I don't know if you have seen the pods initiative from zero spark, but it's proven object data. Uh which is basically pieces of data that are self-contained and describe themselves. For example, in this case, there's this query, there's this problem, this statement, this solution, and it's signed by the owner of the entire thing which is clo in this in this example, right? Now we can go even further and we can add Ethereum to the mix. So I don't know if you know Axiom the company they created back on back when they started they created uh some way to make proofs about Ethereum state.

Whatever you wanted to prove about Ethereum state, you could do it and you could also verify it on chain. And it turns out that you can do that on a much simpler way writing basically no circuit at all but for Ethereum. In that case, I told it, hey, this is Vitalik's address and my address is this one. Here's a signature that basically authenticates that I own this address because otherwise anyone can sign it. I want you to basically tell if I have more balance on Ethereum mainet than Vitalic has.

Well, of course, the answer is false. But the authentication is also false. And here is where I want to go deeper. If you see the well, you will not see it, but I I will tell you, trust me, the message and the problem are actually deferring by this slash here. So, the authentication even the signature is correct, the authentication fails because I have one more character here that it's actually not correct.

But the core of the thing here is we can query Ethereum. We can query all the chains at the same time. We can interact with chains through LLMs and generate zero knowledge proofs about that without writing any sort of circuit any CKBM or get into any complexities. This is not a solved problem. This has not been formally done yet by anyone and I would really like to see it.

I'm just one person so I don't think I can code all of that. Uh but I would really like to see uh someone tackling this problem and and trying to explore it more. Yeah. Five. Okay.

Uh let's dive into my final uh obsession. This is related to uh how I envision identity in a decentralized peer-to-peer system. Uh I've seen identity trying to be solved by companies in lots of different ways. To me, it feels odd that a company is solving identity when identity should be something more like Bitcoin. No one owns it and it's just completely external to absolutely any party besides you.

And so I wanted to guide you through an fullyomorphic encryptionbased system that could basically hold identity without needing to go through any company or doing absolutely anything. Users first of all create trust scores. So for example, I know person A, B and C. I generate a vector and I put weights on how much do I trust A, B and C. Then I create a vector commitment and a hash and I put that on a smart contract in Ethereum.

So Ethereum is my authenticity layer. Let's say once I've committed these scores, notice that I can update it, I can remove them, I can do whatever they want because I can always override the hash. The next thing that I will do is I will get these scores and I will encrypt them using uh some FA keys that have been generated by a server. When I do that, it turns out that now all of these participants can interact in a decentralized graph that is it doesn't exist anywhere, but it's actually there. And so what we can do is just run Dickstra.

Dixra is a routing algorithm for one that don't know. I I assume it's nobody that doesn't know that, but whatever. Uh so we can run digra on completely encrypted weights and we can basically simulate having a network and we can try to find the shortest path between me and any other party in the network based on the trust that I have on my peers. So for example, let me put a really easy example. I trust person A and person A try trusts person B.

Therefore, if I just do digstraat, the shortest path to person B will be below a certain target. And that to me tells, hey, I can trust this person, right? So, it turns out we can use that for a lot of things. Think about transactions. I receive or I want to send a transaction.

Well, now I have a completely encrypted way to verify if I should trust or not this person. Then it's my decision to do that. But I have data to back that up on and that tells me that in a completely private way. I can also do business reviews like Google and all of this kind of stuff uh without needing to rely on any provider. And notice that the weights will be influenced by the people I trust.

So if I trust 10 peers and those 10 peers trust people that trust the business, I will get a much better score than if I don't trust anybody that trusts this thing. Again, it's finally up to me, but we can certainly do that. And we could make this together with ENS for example, Ethereum name service. And that just gives us a way to interact with the internet on a much more secure way without leaking absolutely any privacy and without leaking who we trust on but just getting the benefits of knowing. So sadly this doesn't solve all the problems and the biggest issue we have is FHE requires liveness in order to decrypt.

So when we want to decrypt a dickstra query, all of the parties that have participated on that need to come online to make the decryption happen. And the issue with that is well, if this system is millions of people, we can expect millions of people to come online and decrypt this. Hopefully obfuscation will arrive at some point, the holy grail of cryptography, and we will be able to solve these things without actually diving into into this into these errors. But at the moment this cannot be fixed. We have another issue which is that computationally the amount of computation that we need to do over encrypted data is insane.

And that basically tell us that the infrastructure we need is really high. And if the infrastructure is really costly, well, we can't expect this to be run by peer-to-peer nodes that people just hosts. Like this needs to be heavy infrastructure that most likely comes from private investment, which is of course what we don't want to see. And finally, you can criticize on a more philosophical way. Let's say that you get a really short-sighted view of the graph.

Meaning, you will only get good queries or good confidence on someone if the people that you trust have confidence on them. That means that I don't know when we talk about politics, I can I can really be siloed into just trusting people that have similar ideas and and it's really related to me. But in my opinion at least this is how sadly the world works. There's very few people that is open to new ideas and there's a lot of people that is just closed on their world. So whether or not that will be good I don't know but this is how it will work.

That's it. Uh, happy to answer any questions if you find me around. And thank you very much for coming here.

Automatic transcript — names and jargon may be misspelled.