New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

ETHWarsaw Meetup 0x02 (31.05.2022)

ETH Warsaw — 2022ETH WarsawFri, Oct 7, 2022, 12:00 AM

The second event in the ETHWarsaw Meetup series leading up to the ETHWarsaw Hackathon in September 2022! Hosted at: The Faculty of Electronics and Information Technology, Warsaw University of Technology. Supported by: @EthereumFoundation & @LivepeerProject Music by: @BensoundMusic

Transcript

okay guys let's start so gm warsaw my name is susan abrachevska and i would like to welcome you to the second meetup and let's start [Applause] thank you let's start from like uh i will remind you just simple uh quickly our rules that apply here so first of all be kind and respect others and the second of all we want to tolerate cheating or sales pitches so be aware and our goals as a if warsaw foundation are as you can see is educate about web free help other discover new web free talents and we would like to put warsaw on the map of great web free events and by that contribute to the global ethereum community and how we want to do that here you can see our roadmap we started with our first meetup today is the second meetup and the first part of this roadmap will finish in september on a conference in hackathon so i would like to invite you all to this hackathon and conference and see you there hopefully this is all possible by our team and be countless for them they're somewhere there if you want to talk to them ask them about what we are doing just reach them and here is our sponsor so we are actually part of the ethereum foundation's road to depth devcons so yeah thanks to ethereum foundation we are all here today without further adieu let me present you agenda for today we'll start with piotr schlechtjack's presentation about scaling ethereum with rollups and then we'll go to presentation of jakob wojciechowski and he will tell us why our oracle is crucial for defy and after presentations i would like to invite you to to grab pizza drinks and to just networking so please enjoy the second meetup you can reach us on i don't know twitter our um web page so please welcome piotr and peter the stage is yours i'll use this mic but i need to set up my gear hey fantastic welcome everyone so today we're gonna talk about scaling ethereum with rollups and uh i've structured my presentation a bit like an investigation i'm gonna figure out why we're gonna figure out how and then we're gonna figure out some more spicy stuff about what's actually going on but first we're gonna start at the end at the big diagnosis blockchains are ill unfortunately they've fallen ill because we are all using them we're all using them and they can't handle it the blockchain cannot scale on its own right even if we try to you know increase its parameters make it process more transactions make it do more things more bigger gas limit lower block times it actually won't solve the problem it will just decrease decentralization and the um increase in performance that we are going to get is really not enough to handle what we actually need to scale so what's the solution roll-ups okay end of presentation no um blockchain is like a train and you probably haven't heard this metaphor before because i invented it while i was making the presentation the main idea is that the train cars are like blockchain blocks so each time a new block is added right a new train car is added and the locomotive is the node and the reason this metaphor works is because the locomotive the node has to handle all of the weight of all of the blocks it has to actually carry it it has to process all of the data it has to store all of the state it has to do all of the work and the more we put onto its back the more blocks the heavier it gets and the harder it gets and this is why it actually increasing the load on the nodes reduces decentralization because you just need to have a better locomotive which is to say a better node and in fact the metaphor goes even further because the the train cars as blocks actually allow us to visually represent what's really going on when we stack transactions into blocks because you can imagine transactions actually as you know some packets of goods that are being transported and the train car the block actually only has you know a limited space and we as discussed cannot increase that space because the decentralization will suffer so we need to figure out how to stuff it the best we can to figure out to fit the most we can and we need a mechanism to actually decide how much cargo can we put in so here we have an abstract way to visualize that each uh each rectangle here is a single transaction and the block can fit i don't know it's i think eight transactions here some of them are larger some of them are smaller we still haven't talked about how do we measure it and it turns out the way we measure transactions is actually crucial for enabling rollups to work because i don't know if you know but in bitcoin the transactions are just measured by size the bigger your transaction is in terms of bytes this is a bit of a simplicity simplification but let's say the bigger your transaction is in terms of bytes um the more the more it's going to cost the more it's going to weigh the more it's going to take up block space but in ethereum your transaction can be actually very small it can be just you know i want to trade this token for this token on uni swap but then when you actually execute it it does all of the things it transfers the token it calculates the different pool values it transfers the token back all of this all of this calculation is going on so we need a different measure and um here is another metaphor that i came up with while doing the presentation actually the the way we measure the uh transaction cost in ethereum is a bit like going to a beauty salon right you go there and you want to do i don't know your hair or something and then you go through the list and it's like okay i want to do long hair but i'm a man but i also want to do the beard but not nails and you sum it sum it all up right and you get and you get a total and an ethereum is actually a bit of the same so i've summed up some of the more common operations so if you want to do just a simple transaction just a value transfer you're going to pay 21 000 gas by the way gas it might sound weird it's i think the name is very bad to me it should be named as computation units and then nobody would be confused what it is it's just computation units it's just a unit of measure so the transaction costs 21 000 gas each byte of call data which is uh the call data is basically what the transaction is composed of so if you wanna call uh for example the uni swap contract to swap tokens you're going to give the contract some instructions to say hey swap this token for this token and these instructions are what is call data so for each byte of call data it's actually only 16 gas that you pay for reading values from storage which is each contract on ethereum has its own like database structure where it can save some values so for example each token has its own little database where it stores how many tokens each user has now to read how many tokens a user has you have to pay around it depends but around 2 000 gas to actually write uh some to actually give some tokens to a new new user you have to write the value to storage which costs about 20 000 and then if you want to create a new contract it costs 32 000 so all in all to sum up all of those values if you do some operations on the main net you probably want to change some state you want to change some storage maybe you want to deploy a smart contract you definitely want to send a transaction all of this adds up and as you can see to do anything it costs a lot of money the verdict the verdict how to deal with this is to do as little as possible on chain but you know if we don't do things on chain where do we even do it does it even happen anywhere if the chain doesn't know what's how can it even work and so the the first part to understanding rollups is the pricing and keep in mind that the call data is very very cheap this is going to come in handy later the second part to understanding rollups is the state transition so you know blockchains are hard there are many moving parts but if you think about it what happens on the blockchain is actually really really simple is this formula the next state of the blockchain of every contract of every account of everything that happens is just whatever was there before plus whatever transactions users made so a simple example would be you know before i had one eath um and my friend had no eath and then so this was the previous state now the transaction would be i transfer half eth to my friend and then the next state is of course i have half a neith and my friend has half an eighth so the same thing applies to basically anything that you do on the blockchain and here comes the ingenious part about rollups if you know the initial state which most probably is nobody has anything and then you add up all of the transactions that happened right so someone deposited money someone transferred money someone swapped money then you just actually need all of the transaction data to figure out what's the final state you don't actually need the state you just need the data and so why while you execute on the main ethereum chain you pay for both the data and the execution you can actually not pay for the execution you can just have the data and then you can calculate the state yourself in the background somewhere else and then you have a very very cheap way to do transactions so here is where the metaphor of the trains and cars of trains goes too far here is a block with roll-up transactions and each roll-up transaction is just the data no execution and then the execution is kind of like tagged along like this balloon attached to this transaction because what the balloon represents here is that we can do all of the computation of chain right we know the previous state we know the transaction data and we can compute everything off chain so the balloons don't actually weigh the train down and make it possible to have even more done with the chain and we have just one issue with this entire approach right so so far we've discussed the following we have transactions but we only use the data to describe everything that's happening we then use those transactions to construct the state so if we want to for example deposit money we'll just say okay a transaction on the one layer one i mean the base ethereum blockchain so here the small definition of terms l1 layer 1 the main theorem blockchain l2 layer to the roll-up the chain that's you know constructed from all of this data if you want to deposit money there it's easy because all we do is we have some data on l1 that says we deposited money and then we can actually you know apply it just as any transaction data to calculate the state where i now have more money but what if i want to take the money out so far we've assumed that we can calculate so on the all of the state ourselves so you know we can do it off-chain we cannot worry about anything but there comes a point where we actually would like some money back right and all of this optimization if it doesn't allow us to do anything with the state it's kind of pointless you know it's like oh let's have some data i calculate some state i need to get it back and here another thing another nice thing from the blockchain space is going to help us out is the tree and of course in it trees go grow upside down and this is actually a merkle tree and the merkle tree is a very simple data structure it just uses hashes it's like hashes all the way up and at the very bottom of the tree is the state so this is where you can see that okay i have some eth or you know i have some tokens or the the unit swap smart contract has some pool balance something like this then you take this state you hash it and you take a state of another account right you have two hashes you hash them together and now you have a hash representing a state of two accounts you take the hash of the next two accounts you hash it together you have the state for four accounts you hash it however many times you need and then you have one root hash right one single small value that represents the entire state of the entire system okay so we have this value you know it looks random but how do we actually you know now get the stuff out of this tree well here is where the hashes are very important because with hashes you can construct merkle proofs and you know all of these terms are super fancy miracle proofs are just the hashes along the way so if you want to prove that the user balance is in the tree you just need all of the hashes that are used alongside so if if i have some balance i need to know the balance of the neighbor in the tree so that i can compute the hash on the next level and then i need to know the neighbor hush on that level to compute the next hash and then if i know all of the hashes and the original value then someone else can recalculate all of the hashes up to this point and compare the hash that they got with the hash that the state act the the hash of the entire state and this is what miracle proof is if the hashes are correct then it means that the value had to be in the tree so let's say i wanted to cheat i wanted to say that oh i actually have more ether than i have in this tree well i wouldn't be able to do it because if i posted the proof that i have more if then the actual hash value at the end of the proof when someone recomputes it would be different from the correct state hush so then to withdraw money from this roll-up construction all we need is to put the resulting state route of the entire roll-up chain on the main blockchain and then we can just say okay i have some money there i can prove it to everyone because i have the miracle proof and i want that money out this means that we have now established a way to have a cheap chain right because we only pay for the data it's running completely in parallel it doesn't disturb the main chain and we can go in because we can have a deposit transaction that you know is counted like any other transaction just data and we can go out because we have the state route and we can do a miracle proof that we have the money and that's the end of our worries right no so it turns out that someone has to compute the state route someone has to put the state route on chain and we need to have a mechanism to figure out if it's correct normally when you have a blockchain you don't worry about such things because every node in the system actually runs all of the transaction actually computes all of the state so everybody knows the state and if someone would try to you know state an incorrect state then nobody would accept it but with a rollup we have a different situation we have a situation where someone says the new state is this right the new state is like i know a hush of one two three four five six seven okay and then we need a way to figure out if he's lying or not and there are two approaches and we're going to start uh to talk uh with optimistic roll-ups and then we're gonna move to zk rollups the optimistic approach is actually really simple when you think about it it's you know we're gonna assume the hash is correct someone someone has posted the hash it's going to be fine but but we're going to give a window of around let's say seven days where we assume that there is at least one person in the entire world actually has computed the state has checked that it is the same state hush that someone has posted on chain and if the hashes are different that this one person will post a transaction on chain claiming i challenge you i want to go to court i want the blockchain to decide and this is the idea of fraud proofs so with optimistic roll-ups as i said we assume that the state route is correct but if it isn't anyone can challenge it and to make sure that the everyone is sufficiently incentivized we require anyone who wants to propose a new state route to put up a bond if you want to have your state be the new state you need to actually put some eth as collateral and then if someone would say oh you actually you know did something wrong maybe you cheated maybe you have an error maybe maybe you know maybe i don't like you then then they can challenge right and they also have to put up a bond and then it's time for the final showdown the blockchain has to decide and you know here comes the tricky part because the blockchain cannot just execute all of the transactions because that would defeat the entire purpose of the scaling solution if we anytime we find something is slightly incorrect we have to re-execute everything then we just pay the same cost so we need a smarter solution and the current state of the art is we actually do sort of an interactive game between the block producer who claims that this is a new state and the validator who claims that actually the state was incorrect and they together figure out through i don't know the name of the algorithm where you split into twos and then you figure out something in the middle it's like bisection by binary search exactly through binary search they figure out the exact moment in the calculation where something has gone wrong and then the blockchain has to only execute this single step in the entire execution and this is how you save money on validating everything instead of validating all of the execution you first require the block producer and the validator to figure out where they actually disagree a single execution step and then you execute just that step and the blockchain just decides because it now knows either the block producer is correct or the validator is correct and then one of them loses the money oops and actually you know it happened and it happened to us so um chris who's somewhere among you i don't know where uh oh this is chris um who's also the co-founder of l2 beat has done a hack the idea was to steal real money and the real money in question was nothing short of eight dollars now why was it eight dollars and why do we even think that stealing them was possible well there is this optimistic roll-up called fuel and fuel is amazing it has like nice technology it allows you to as as i just described transfer money between people deposit withdrawal it's like optimistic it has all of the execution of chain all of this good stuff it has just one problem nobody uses it like literally no one so the eight dollars that was there was sitting there for over a year no activity nada right and we thought to ourselves well it's gonna be a good pr stunt right we're gonna steal the money and we're gonna say to everyone you know what optimistic roll-ups are great but what about optimistic roll-ups where nobody watches the chain and we thought to ourselves we are so smart so we created the master plan the master plan was to become a block producer we posted a bond point five eth to steal eight dollars we posted the bond now we posted a fraudulent state transition a state transition that assigns the eight dollars to us the final part was about to begin a two-week wait where in the constant anticipation of the impending reward we would sit and wait for the time where we could send the deposit transaction but actually the instant that we sent the fraudulent state transition it turns out that the chain was not abandoned and the validators for the fuel optimistic roll-up were actually there all along and so instead of getting eight dollars in the sweet sweet hacky payback money we lost 0.25 eth and uh you know i had to put off buying new clothes i had to eat less this month but the story is nice i think so uh anyway it it turns out that actually even though a chain can have like zero activity on the main ethereum chain it can look completely dead because of the way optimistic roll-ups are constructed the construction is still secure if there is at least one person anywhere somewhere willing and able to check the state and the qr code is if you want to read a more technical description of what happened and uh so this was the first thing right optimistic roll-ups we put the we put the state we we assume it's correct then we thought proof now comes the zk roll ups and this is uh you know an unfunny joke two roll ups walk into a bar the barman asks can i see your ideas optimistic roll-up says if nobody can prove i'm underage in seven days that means i'm over 18. and uh zk rolap says i can prove to you i'm over 18 but i won't show you my id and this is the main idea uh behind optimistic roll-ups sorry behind zk roll ups is that the main way we actually save on uh on computation is that instead of doing all of the computation we just have a proof of correctness and the proof of correctness is zero knowledge because it doesn't contain all of the information about what was actually executed so the real fun part of zero knowledge is that it actually alleviates a problem with optimistic rollups because when we have the optimistic pull up it has this uh small issue that because there is a window in which everybody and anybody can challenge the state that means that we cannot assume actually that the state has been like fully checked fully correct until the window closes and only after the window for checking the state closes we can allow someone to withdraw money from this construction so usually if you just want to withdraw money from an optimistic rollup you have to wait seven days it sucks for zero knowledge rollups because every time you post a new state update you actually have to create a zero knowledge proof that every execution that you did was correct that means that as long as the blockchain can check the proof you don't have to wait to withdraw the state is immediately considered valid so it's absolutely great and it's also super complex um here is an accurate depiction of what happens when you create the zk proof it uh it requires a lot of math and a lot of things that i can't explain and this is why i think it's magic and this all sounds great right you have optimistic roll-ups that are simpler to build but you require some weighting you have zero knowledge roll-ups more complex to build but you have some nice properties and now you're thinking to yourself why am i paying the l1 ethereum fees what am i doing wrong with my life i just want to use the roll-ups where can i find the roll-ups and uh you know not always great it turns out and uh this is a screenshot and the screenshot is made to look like part of the page but it's a screenshot from l to beat where it actually shows the risks of using the different solutions because there are many solutions out there that we could potentially call rollups but they're not finished the technology i described to you is not done it's not fully researched it's not completed as in you know you can just deploy it as any smart contract and you have a rollup there are many challenges that have yet to be overcome and uh some of them are because the rod proofs and the zk proofs are actually quite complex to build you know i did some hand waving or the fault proofs that you can you know bisect all of the execution to find the single execution step and then execute it it turns out it's not that easy right and then for uh you know zero knowledge the proofs are actually also quite complex the mathematics behind it is complex but also trying to mimic what the blockchain does in the first place with all of the intricacies of the evm like reverts or i don't know a message calls between contracts or you know having different account types for externally on the account and contracts there are all different considerations that you have to take into account where building those proof systems so it's not that easy and so here come the challenges first challenge first challenge is that if you are an operator that uh sorry operator if you're a developer that you know has built your own rollup and you know as you all know now that it's not finished you have to you know constantly develop it you have to potentially fix bugs add new features all of the good stuff so you add a way for yourself to change the code and i mean it's justified in a way as i said you have to fix bugs and you have to add new features because it's not finished on the other hand as dua lipa says i've got new rules right if you are using the rollup the operator can just come out of the know of sorry out of nowhere and say that all of the rules that you assumed were the rules of the game up to this point are now changed the upgradeability mechanism doesn't really differentiate between an update that finally does the fraud proofs correctly and an update that says all of the money that users deposited is now mine to the smart contract all of them just look like updates and so there is inherent risk even if we assume that the developers are completely benevolent if their keys are stolen if they are manipulated for example through external coercion governments i don't know kidnappings stuff like this then you have an issue of what happens to the money in the rollup and what happens to the smart contract and the rules inside it moving past this moving past this if your systems for proving are kinda like unfinished maybe a bit proprietary you know you don't want to open it up to anyone to use or abuse right because if you have a system that's kinda ready maybe ready you don't really know you have a lot of tests but you know you would like more then what do you do well you say okay we're gonna do it live but with a check only a group of trusted friends is gonna be able to use that system because you know as a developer you have some confidence that they are not going to steal the money so if you are an external participant and you figure out something's wrong right and you want to submit a fraud proof for example where you're well you're like one of those ladies trying to get into this club no you need permission and you don't have one so this is also you know in a way justified because if there wasn't those permissions then someone could abuse vulnerabilities in the system and potentially also steal money but it's another thing to consider and the last part as i said is um the proofs are actually complex and the reason the the proofs are complex is mostly due to the evm because if really if all you wanted to do is transfer some tokens around it's not that complex it's not that complex you just need to you know subtract the value there and add the value elsewhere but if you want to do arbitrary during complete execution of smart contracts well it's another story indeed and if you really want the l1 to be able to re-execute some parts of the execution l2 you really have to implement the evm in the evm which is not fun let me tell you and so uh but this guy likes it uh and with uh with zero knowledge proofs it's kind of the same although you're not implementing the evm and evm you're implementing evm with cutting edge maths and i don't know it's not fun also maybe some people like it i i think it can be fun but it definitely isn't easy and you know so we have the nice technology the nice vision but we also have the issues right with the ecosystem and now for the finale it's up to you right to do something about it to contribute to this space and i think you know there are many ways to contribute one of the ways is just to learn about it more there are many resources that i'm going to talk about in a second the other way is to you know once you've learned something you can become a researcher in this space to either figure out the different solutions that are there or try to push some of the research either in the zero knowledge space or in the front through space or there are even more areas for example resource pricing that i completely uh you know haven't mentioned you can also if you know some devops skills right use that because there is a lot of infrastructure that needs to be run and you know this might be useful and then if you just want to develop smart contracts then you now have an entire new domain that you can use for your applications that has a bit of a different trade-off maybe at this point less security but also a lot cheaper transaction fees which means that the opportunity for what you can do with the smart contracts is bigger and then if you're like uh you know really into building low-level stuff and you like languages like go rust you can build the l2 infrastructure itself now for the resources is actually where you want to learn this stuff and uh you know i have this blouse and together with chris and many other people here we've created l2 beat and this is a resource that's uh you know mainly focused on education and research and so we recently did the conference in amsterdam we have a website we have a twitter and we are also looking for you know people eager to be more in this space and with that i thank you very much for being here and i don't know yesterday if we have some time for questions or anything but yes okay so we can have some questions if anybody has some [Applause] oh we have a question there i don't know if we should run around with a mic or anyone can use the microphones on the tables so just feel free press the button and peek hello what will be the price of optimism token thank you so it will be between zero and infinity thank you although with recent developments you know saying it will be between zero i know it's hard it's hard to say that there are different things happening in the blockchain space sometimes tokens are worth zero actually so maybe between zero inclusive and infinity any other questions um yeah hey uh how does progress a computation fee in the kerala labs uh how does gas work in the kerala yeah so i mean computations is it lineary progression or maybe some another no so it's actually very different and it depends on the roll-up that you use some roll-ups try to actually mimic the evm so they'll try to be as close to what ethereum actually does as possible so when you develop on them you would be just writing a regular solidity smart contract and the resource pricing would be basically no similar because it would be just a different table for the different op codes in evm and some are actually completely different like for example starknet where you have their own different language their own different pricing and it really varies depending on the roll-up so there is not one easy answer you need to press the button what are the so l2 solutions you're most excited about that's a good question i think uh that i'm most excited about the upcoming one at once so um there i think are four that i'm really watching to see what they're gonna do which is one of them is starknet from starkware one of them is zk sync 2.0 the other one is actually arbitrary optimism because they are about to run some big upgrades and i'm really keen to see how they turn out but it doesn't mean that they are the only ones i think for example there is going to be fuel v2 there are going to be some other chains like arbitrary many trust chains and there is even some rollup sorry reddit chain in the works and you know loopring as always has some updates to their exchange role there are many many different solutions and i think at this point and it's you know a meme in blockchain but we're early in the you know layer two space and i think uh you know that means that there are no clear winners yet go ahead yeah one more question is it any actually a reason that optimistic relapse should exist i mean the only cons of zakir labs in comparison with optimistic ones is only the complexity as you've been saying right but i believe can sort out it in a few years so any real reason so the the real reason is the timeline and the timeline is such that the zika roll-ups are not fully ready yet and of course sorry so when they get ready when the mr lab's gonna die well that's that's one way the the actually the it's not as obvious because the uh optimistic roll-ups can get really really optimized and the seven-day withdrawal window is actually only if you want to do it through the main bridge but there are many ways to circumvent that and so i think that it's not as clear-cut of course as you said zk roll ups have clear advantages but the advantages are not as pronounced and if optimistic roll ups get optimized enough they i think will still be able to compete of course in the very long term we would probably expect that zika roll-ups are the let's say winners or will have process majority of transactions but i think it's not settled yet and i don't think it will be for a long time can i add something does it work okay so uh i think this is much more nuanced that uh you know zika roll ups are gonna be like the real once they are ready right it's it's not like this like people are underestimating the fact that optimistic roll-ups can be extremely efficient when things go well like you don't do anything with zika relapse you always need to verify the proof right you need to do it always even though things are perfectly fine right and um there's this uh thing that zika wraps can scale better because they just can prove the state diffs that were uh broadcasted on the chain instead of like all transactions and this is the the sk one one of the skyability benefits but this also means that they lose accountability of the blockchains of l1 because you don't post all transaction data on chain you just post uh state divs and uh this is different than what optimistic apps are trying to do so uh it's much more nuanced then you know zktec is better other questions yeah let's let's do one last question so as we all know the only way to really scale blockchain is for roll-ups as as you have explained in your presentation but do you see any other projects on working on the roll-ups on other blockchains and one blockchains definitely i'm gonna strongly recommend you also learn about the lightning network because i think it's a completely different and really interesting approach to scaling a blockchain it at this moment i know there are some works doesn't really do smart contracts but it's great for payments and i think that it's really worthwhile to read up about it uh what do you think will happen with other l1 blockchains when roll-ups will roll out on ethereum well um it depends but the future is hard to predict but most other l1 blockchains are not really innovative because they're like okay let's do ethereum but let's switch one thing to have a different trade-off and in if if you really want something to be successful you're gonna do like 10x that not as not really in terms of you know uh this 10x transactions it's just 10x better in every aspect developer tooling you know the the speed the the the possibilities so if you just have a blockchain that does more transactions it's you know it's it's not innovation in my opinion so this is why i don't really see a reason even right now for other ones okay thank you so much and uh give it up for usteda [Applause] yeah thank you piotr and now please welcome cuba because for him [Applause] hi guys thanks for coming thanks for having me congrats to amazing talk not only super interesting but as i'm intimidated by the number of funny memes and pants that he used this is going to be more boring but i try my best so let me tell you something about oracles what's the purpose of arakas what are the common development patterns and how do we try to innovate the space so let's start with the oracle problem let's let us imagine a defy without oracles so a metaphor would be like having buying a new laptop without an access to internet so solutions like um stable coins something like die without the knowledge that was your true collateral won't be possible solution like other when you are taking a loan against your collateral also won't work also stuff like option settlements won't be impossible because you do not know what's the strike price it's very similar to leverage investing and trading it's really hard to close your position if you do not know what's the actual value of your assets and what's the value of your margin so the whole blockchain will be pretty useless at least in the area of defy so we i hope i convince you that in the defense space we need oracles but why do we need a dedicated service why cannot every smart contract simply directly call an external api and query for a price of ethereum or bitcoin so let's imagine we got a few thousands of nodes and every of the node is calling an external api and trying to get a price it will be a total cause so far some of the api will give an answer as a given time some will give a bit earlier some a bit later also some of the queries will time out and it will be extremely hard almost impossible to achieve a consensus around the answers also calling an external api from a blockchain node which is supposed to be fully deterministic and secure it's asking for troubles so we need something better we need a dedicated service that will provide us price in a secure way and how it all started so when people realize that we need a solution to inject external data to blockchain it started with a very simple pattern with a two-phase approach when you get a request and a response so first the construct is requesting a piece of data then a dedicated service is listening for that request prepares an answer and put it on chain it works quite fine if there's still a solution like that in production but there's one really big problem so the experience of using a protocol that is implemented that way it's not very pleasant it's like going on on the train with with beard and when you order a meal on one station you need to wait on another station to get part of the meal then you order another meal you wait to get to another station and then you can have let's say a supper or a drink so the journey wouldn't be so nice and definitely it breaks the the user experience but also it affects the compassibility because you get delays and asynchronous calls in the smart contract execution so there was another attempt so let's assume that we got all of the prices in place on chain delivered and fully persisted yeah life is super easy you simply query for the price you get it from a blockchain state and that's it fully synchronous execution super convenient for developers let's see one tiny problem who actually delivers all of the price data and who pays for the gas it's it's like super heavy it's like yeah it's it's really hard to to put all of the information in the train the train won't be able to run and the bill for putting all of that data will be super huge but it happened for the most popular tokens as you probably know that the current market leaders are syndicating the cost but still the the bill is extremely heavy on a time when the gas price is really high the the bill can is the extent one or two million dollars daily so we tried to to mix the both solution and have a convenience of the synchronous calls but without paying for the storage so that's our approach and what's the magic how can we avoid putting all of the data to the storage and actually simulate a situation when the data is already there so we use a very hacky way of passing the price information so as you may remember from the period presentation there's one structure in the in the menu that you've seen that's actually very cheap it's called call data so our approach is to put all of the pricing information in the call data so when you start to execute a transaction there is no price data but executing a transaction you can foresee what kind of information will be needed and then of time we prove append your transaction in a hacky way adding some extra information to the message data to the call data with the price information and forward delegate further the user transaction then on chain we verify the data that it comes from a trusted source checking the signature and actually make it available for consumption for any blockchain protocol so from the point of view of a developer it looks as the data was unchained for the point of user it also is very convenient because there is almost like no delay and the transaction can be processed synchronously and that's the screenshot on how actually we are calling the external services getting the the signed data and we we append the the message and also as a as a side effect of this pattern as i mentioned we do not touch the the storage of a target chain therefore the same the exactly same architecture could be applied to various blockchain and as you know we got at the moment dozens of layer two solutions and also we got quite a lot l1 solutions and blockchains that are longing for the price information but it's impossible to put all of the data on all of the trends that's why having this lightweight approach in our view could be more scalable in the current blockchain landscape so as you can see on the picture we we got nodes that take the data from external apis then we deliver them to the target chains obviously there might be a question what's in the middle how can we securely pass the information so this is kind of a reliable problem and we wanted to to focus on that to protect it against different kind of attacks so it cannot be ddos it cannot be spammed etc so we use different layers of transmission some of them are based on simple caching we also leverage decentralized protocols for um data transmission like like streamer very interesting pops up protocol and what's the point of doing that as i mentioned putting data directly on chain is extremely expensive so we compared the cost to the most popular solutions available and if you look at the storage cost there is a huge difference it's not an order of magnitude actually the the price is million times cheaper because we leverage for the storage not only our relay and network for the short-term storage but also r-wave which is a chain dedicated for storing data for the permanent storage so have a full accountability of the price feeds very similar to what's happening on chain but at the fraction of the cost so the difference is around 1 million and actually i think that the chart is corrupted but that's that's how close i can get to to 1 millionth with a single picture excel and let me show you some code so let's imagine that we are building a marketplace for nfts probably a quite common use case in in blockchains recently thousands of people are spinning of their own protocols for trading nfts and that's very simplistic one you you simply post an order you cancel an order you get orders and you get a price for an lfd or you can simply buy an lft using for convenience and native currency like on openc that you pay in ether which got a lot of advantages for example transactions are really cheap and it's easy to implement and let us take this solution and try to make it to upgrade it in a way that you can buy an nft which price whose price is denominated in usd's so it will be better for sellers to to post as nft and not to realize that in in a week time they are getting like one third of the price they intended to get so in order to do that you need to implement a price aware interface which actually is some fancy logic in assembly code that i'm not going to describe but every all of our code is open source so please take a look that's verifies the signatures and extract the price data and also you are responsible for the validation of data provider so the simplest way to do it is just to trust one of the provider but obviously the logic can be much more complex you can trust one of among many providers or you can randomly pick a provider and use any logic that you intend for your protocol and when you do these two magic steps then you can simply query a price as convenient as their price was already on chain also there is one additional step on the client side so whenever you are interacting with a contract that implements that interface you need to append the the transaction with the price data because in our case the users are the one responsible for passing the message to their is paying for the data transmission which is a very low cost and they are smuggling this oracle data so for that we we extended the iters js library and you simply wrap your own contract and specify what kind of price provider we are going to use uh so what kind of data can you already access so at the moment we got more than thousand assets we integrated with more than 60 sources and we persisted permanently more than two billion data points so everyone can check the history the accuracy the reliability of the service so that's one of the example the price of ethereum when we merge across more than 30 sources and deliver the median price on china other watch is really interesting recently we provided a way to specify our own custom oracle and do it using a web interface so we prepared that for for the hack money hackathon that happened recently there were like few projects using that solution there are various use cases like maybe sorry so some of them were about uh okay customers over we're about the weather data if you are going to build an interesting protocol utilizing that but what i also found funny one of the protocol was implementing a life insurance and then getting a point that we're saying when a person is alive or dead that was a pretty scary but actually very interesting use case so maybe that's the future of the blockchain and to give you an example of let's try to create a lightweight oracle maybe let me use an openc api okay what's interesting let's get some collection stats let's work in there's something there i'm passing the url try to evaluate yeah you get some answer and then you specify a json path to get the data okay and what can we get maybe a floor plan okay so we got a full price then you get the specify the name what kind of collection could it be let's see i get that okay dude that's official is anyone in there this is the good collection i don't know that's let me subscribe to that and then we deployed a service that every minute will query the api sign the data and make it available to use in your contract so if you are building a derivative on the price of nfts that's the way to go also what's interesting so apart from these funny use cases there is one protocol that's already is using the the solution to protect real money with funds and it's a prime brokerage trading protocol on the avalanche network which also is compatible with our solution because it's evm compatible blockchain so simply you can borrow some money with a collateral up to five times the amount of your collateral and you can use it for trading for staking etc so you can leverage your your yield farming if if you want to and they're using [Music] our oracles to constantly value the the total assets owned by user so even the stake tokens could be valued in the real time and if the value of the assets to the value of the collateral drops below a safe level then a liquidation bot can close a position and protect the solvency of the whole protocol so actually the the usage is really simple they just derive from our contract and they call a get price for message methods and yes so far so good touching the root obviously but that the protocol is live since two months and we we haven't experienced any hacks i hope that chris is not hearing that so also how do we store the configuration of the data providers and still a lot of data because we need to specify what kind of assets a data provider should deliver what's the probing interval what kind of data sources etc so there's a lot of data and we like to have this solution fully decentralized so all of that is managed through smart contracts but putting that directly on a network like it to you would be very expensive that's why as i mentioned we use rwef network which is amazing for storage in regard of the actual storage cost per data item and we build an extension on top of that that allows to execute any arbitrary logic so it's kind of a roll-up solution built on top of the storage network and our view makes like a total sense because for the base chain you definitely and basically need very efficient storage and the execution can happen often so that's also like a super interesting product that we are working on i'm not going to tell you that the full story is a fascinating research like how actually can you execute arbitrary code when only the inputs and the the code of the contract is persisted on chain so the code is executed often in a lazy way and then delivered on demand so i'm just putting this as a preview maybe if you are lucky to be invited for the next time we'd love to tell you more about it but it's based on the awesome execution layer and we we built a lot of tools like a transaction browser way to put randomness for the contracts etc and actually this price is like super early apart from us using that for oracles there are a few other projects that are using that already in production prominent projects on the r with network so i think that's all so thanks for the attention there are the links if you're interested in the the oracle problem and how we tackle that if you'd like to learn more or work with us we we're more than happy to to tell you more about the project and the company so thanks we have time for a few questions if you want any questions yeah what's the main killer feature of redstone the difference from machine learning for instance uh definitely as i mentioned there are these operating costs like with training you need to put all of the data on the target chain and the most popular chain at the moment is obviously ethereum as i mentioned the bill for daily gas costs could go up to a million or two millions and definitely at such a high price you can only support the subset of the tokens so the blue chip tokens like f btc so up to probably 100 tokens and the less popular one are refresh with much larger periods and with our solution if you are interested in the price of any arbitrary coin the long tail or simply put it simply the coins if you want to build a solution based on that you can do it because it's much more affordable as i said the the difference in cost is probably one to a million uh hi uh i want to understand a little bit more uh so as i understand there is no way to get uh oracle data if we are for example the introduction between contracts or we are not doing the transaction from the external owner account or like front end where you off chain wrap the data in the transaction uh is that correct yeah that's correct so you you need to also amend the entry point it doesn't need to be a front end it could be a script it could be any solution so at the point when you are submitting a transaction you need to also integrate with us so that's the cost as as a benefit you got this scalability that's that's yeah was but that cost thank you i'm interested to know uh you said that uh you said that the data comes from a trusted source i believe uh and uh i would like to ask what the trusted sources can anyone become provided for redstone finance or uh do you only run your own nodes that call the apis sure so so everyone is invited to become a provider but the duty of a provider is to publish a manifesto so what sources are you using what's your methodology what's your interval period etc and that's persisted that's that's a public knowledge in our contracts and then you are being kept accountable so if you deliver a incorrect price you can be punished for that so in order to become a provider you need to stake some tokens as a collateral and there is a dispute mechanism very similar to how the rollups are resolved so you prove that the data was wrong and then the dishonest provider could be punished just to follow up i'm interested in how you prove it is it a voting based system yeah so at the moment is token based voting system but we are exploring the the common solutions in the space so there are like two paths one is to use the trust execution environment which is quite heavy to to implement another one is to have a notary proofs of the tls communication so that's another approach and we are working to automate that but at the moment the dispute resolution is a manual uh dispute process that could be escalated with a rather cryptoeconomic mechanism involved than the purely technical verification overproof so it's more on the optimistic layer compared to the roll-ups rather than the zero-knowledge proof okay thank you very much if there are no more questions i would like to thank thank the speakers and before i let you go to the wonderful food and beverages that we have i would like to thank the warsaw university of technologies faculty of electronics and information technology my own also uh for letting us use this space which is wonderful and also i'd like to thank the many hopefully uh um viewers on online because we are actually streaming this uh as an experiment and seems to work fine so thank you we are using live peer if anyone uh wanna try that it's really fun uh but that was not an advertisement and uh thank you very much and i'm really glad to see more and more people here and hope to see you next time so enjoy thank you much

Automatic transcript — names and jargon may be misspelled.