# Building a future-proof L2

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-07
- Duration: 25:31
- Watch: https://streameth.org/watch/yt-BZWoxKAfU2A
- YouTube: https://www.youtube.com/watch?v=BZWoxKAfU2A

## Description

I will present some of the considerations, mechanisms, technical and algorithmic breakthroughs that are required to build a future-proof L2, with Post-quantum cryptography (PQC) in mind, to enable mass adoption of blockchain technology. E.g.: Full L2 that runs atop multiple L1s, next-generation proving, innovative use cases, and more.

## Transcript

[Music] uh hello uh so I'm Orin I'm uh from starkware and starkware is one of the main teams building Stark net which is a public general purpose zarola built on top of ethereum and what I want to do here is share some of our do I need to yeah it share some of our things around how to build like a rollup which is a uh indeed future proof and we're building it using proof so there is some double meaning here uh now another angle of this is if you're building an app and you're thinking of which chain you should Deploy on uh this should also tell you some of the things you probably should be thinking about not working okay so this is what I'm going to cover uh briefly how we see web 3 today uh touch some types of networks that are there you probably heard layer ones layer twos validity rollups optimistic rollups public chains app chains I'm going to touch that a bit and then uh I'll mention the few aspects that we think at least are important in the chain some of them are like the harder uh technology and infrastructure stuff some which are not less important are more around Vision Values and Community the softer aspects okay so we probably know this uh uh graph uh what I would like to claim is that blockchain today is still in one of these leftmost phases it still has not made it to mainstream uh and why aren't we mainstream yet well a large part of it is that the infrastructure is not there or it at least wasn't there until recently especially in terms of scale cost and ux and the thing that's greatly needed is some killer apps like there there really aren't that many kill or probably aren't any killer apps right now in crypto that has made it main mainstream okay so we have layer ones and layer twos uh generally speaking ethereum and and also Bitcoin are really great layer ones vitalic mentioned it his opening yesterday layer one is really the trust machine uh they're secure they're decentralized permissionless censorship resistant credibly neutral all those nice words uh but they also have strong networks they have lots of users lots of operators lots of liquidity writing on top of them they're usually field proven lots of apps writing on top of them but uh they're severely limited and mainly from these aspects in terms of scale in terms of cost and also in terms of ux so you have then you have some other lay ones that apparently solve this but if you look closely they usually do that by compromising the trust so they're either not decentralized or less decentralized or less secure uh so you give something out for for uh for scale and cost what layer twos try to do is solve these limitation on a second layer the the scale cost and ux issues and but still keep the trust machine on those layer ones so the trust machine is still ethereum or or Bitcoin I'll mention that later uh but we can provide scale and and and cost in ux better scale cost in ux on a on a different layer you probably know of this as well this is the blockchain trilemma it basically states that you have to choose two out of these three decentralization scalability of security you can't have all three why so from first principles in order to secure to ensure security you have to have all nodes run all the transactions just to verify that they're indeed valid on the other hand to be decentralized you need to be able to run a node on a weak machine so everybody could run it so the natural conclusion is that you have to limit the throughput so you could run all these transactions even on a week machine the only thing uh wrong with this blockchain trilemma is that it isn't really true and why isn't it true uh and here we have uh I mean the people who actually phrased it didn't take into account this neographic algorithm that that we use and others use as well that's called validity proofs uh so what's validity proofs it came from Academia long before blockchain it's not specifically related just to blockchain it tries to solve the following problem let's say I'm I'm aover and you're the verifier I want to uh I want to convince you that I have done uh a complex computation correctly so what I do is in addition to doing the actual computation I I do some additional work and I generate a proof the format of of the proof is defined by the protocol I send you the proof you're the verifier the verifier looks at the proof and decides whether it accepts it or not and there are three things we want here one is that if the computation is indeed correct I should be able to generate a proof that you the verifier will accept two is if the computation is not correct I should not be able to to uh generate a proof that the verifier will accept which basically means that I I am not able to cheat I can't convince you of something that's not true and the third is that we want the verification cost to be small so verifications should be should be a lot faster and a lot less resource intensive than the original computation the one that I'm doing so there are a bunch of protocols that do that star which is the one that we're using has some very good properties uh but this is basically a solve problem again not necessarily in blockchain so how can how do we use it here so validity rollups uh which is what we're doing as well basically says the following okay I'll start with the with the the issue that I mentioned before without proofs there are two aspects here you have the sequencers or miners or validators whatever you call those uh entities that generate the blocks they have to execute all transactions but in blockchain such as ethereum and and Bitcoin that's not enough you have to have all full nod so you're full node you want to know what's happening with the network the only way you could be certain that this is indeed valid is you have to execute all the transactions yourselves and there are a lot more nodes than than sequencers or validators in ethereum you have maybe millions of them right now with proofs you actually break this uh connection uh because all the nodes in order to know that the transactions are correct they don't need to reexecute them they only need to verify the proof and like I said before verifying a proof is a lot less work than than running the transactions and this is the only way that I know of that actually solves this trilemma all other ways typically if you look at it closely you probably sacrifice either security and or decentralization to get the scale okay another thing you probably heard of there are public chains like ethereum Bitcoin Stark net a public chain there are also app chains so app specific chains that you could spin your own and just run whatever you want on that and there are both are probably needed for different use cases so we try to categorize It generally uh when in general would you opt to run on a public chain typically when you either when you care a lot about composability you want to connect to other apps that are already there or you want to leverage the network effects of that chain the users that are already there other apps liquidity or uh or often this is the simplest thing to do because it's it's lower touch you just build an app you throw it for instance on ethereum and it runs by itself you throw it on Stark knet it runs by itself when would you opt for an app chain so one major category is when you want more control what's more control you may want to customize the network in a different manner than a public chain is running you may not want to be affected by congestion due to other apps uh you may want privacy that on public chains you typically don't get that's one aspect another is uh maybe you want to capture the network Revenue yourself or at least part of it in the public chain typically the miners the verifier sequencers they get the network fees they get the the block rewards maybe you want to uh capture that yourself if you have a good app the third main thing is branding and distribution you want you may want your own network because you want it to be called by your name or maybe you have a good distribution Channel you want to bring them to your own network and not to a public chain okay so what's important in the chain this plays different uh a different role whether it's an app chain or a main chain but all these aspects are somewhat import important in both and when you choose you should probably think like where you fall on these continues so I'm going to touch briefly touch some of them uh I'll start with security uh I'm often told and I think reality shows it in many cases that nobody cares about security uh or at least they don't care about security until they get hacked uh so I claim that you should think about security especially in blockchain uh so I I do agree that different block like different use cases call for different levels of security and then you can make concessions in some cases but I think these are a few things you should at least ask yourself uh so like how strong is the cryptography uh and yesterday's opening remarks ralic mentioned as well do you want it to be Quantum post Quantum secure does that matter to you uh is it field proving is it is it been running for a while is a lot of economic value writing on what's been running up until now which is some evidence that it's probably field proven it's probably more sound uh what damage can the operator do now now here again sometimes it's a single operator which makes it very very uh uh important but also if it's uh it's some decentralized network if you have like a malicious majority for a certain period of time what's the what's the worst thing they could do could they steal tokens could they just stop the network could they censor there are different levels of of damage that they could do and different networks fall differently in these categories uh if somebody wants to attack the network how expensive is that uh so this this is from vitalic talk yesterday he actually gave us a shout out for for this thing that we've actually done three years ago uh this was dydx V3 which was built on uh a product that we've built uh was an earlier rollup it was an app chain in this case with a single operator but now came the time where dydx start decided they want to wind it down and they stopped operating network but the users can still uh pull their funds off because we designed this uh mechanism we called an escaped hash that was back in 2021 but this is something that if you don't think about beforehand you may end up having a problem afterwards okay one of the major things people use uh layer Twos for is because they solve the the throughput issue the scalability issue so what are uh uh what are the main things that limit the throughput so if you look at layer ones uh they have to execute all the transactions all nodes execute all transactions like I said before there subset of the nodes that take part in consensus but a large subset so this is also quite expensive uh and all the data is there for everybody right so you have all these things are things that potentially limit the throughput because you want everybody to be able to run it now the secret sauce that we have I mentioned it before is proofs and proofs affect scale in two main aspects the main one is the one I mentioned before we don't need all the nodes to run the transactions we just need the consensus nodes to run all the actions these there are a lot less of them and this means that you can do a lot a lot more execution orders of magnitude more execution the other aspect is that it actually enables submitting a lot less data to layer one because we could just submit the state diffs for every bunch of transactions you don't need to have each and every transaction with all its data uh optimistic rollups for instance which don't use proofs uh either sacrifice decentralization or they sacrifice security because at the end of the day if you want to make sure that the transactions are indeed secure you still need each and every full node to to uh execute all the transactions and you also need to submit all the transaction data to layer one because you need that for the optimistic for the fraud proof mechanism uh so when you compare uh validity rollups in terms of throughput looking towards the future the main thing you should look at is like the execution times like how efficient is the sequencing of that network if you look at optimistic scoll up you you you need to look even more strongly at that it's going to be much more limited but also on the data so for instance with Stark net uh here you could see things that these are actual measurements from the live Network as you could see this is greatly increasing uh mainly since we're putting an an extended effort on that on this and this will continue and this will also continue when the network is very decentralized because as I said we don't need all full nod to execute so this is just the the efficiency of the sequencers themselves so that's throughput cost is quite similar but not exactly the same I mean the main difference here is that at least with validity RS you have an additional aspect here which is the prover right because we need to generate proofs indeed it's always a single node that needs to generate a proof for a block but it's still it's still expensive so if you look at if you compare validity rollups to to one another you need to look both on the sequencer cost and also on the on the prover cost optimistic rollups and L uh L ones typically don't have that so this is the this is a similar graph from uh the cost of storet uh as much as I would like to take credit for this the big drop that you see here uh didn't have that much to do with us it was actually due to 4844 from ethereum uh when ethereum moved to blobs uh like the data cost submitted to layer one effectively went down to zero uh and that's the big drop you see over here uh but and that's important to realize this is not going to stay this way I mean it's already on the verge of congesting now once it starts congesting it's it's a market data prices are going to go go up how much up we don't know probably a lot uh and once that happens you're going to start seeing the differences between validity rollups and optimistic rollups because valid rollups have an advantage the one that I've just described uh this is a zoom in on on specifically on the proving uh technology uh We've recently announced well over six months ago the our next Generation prover which is called St uh it rides on an improved start protocol which is a collaboration between us starware and uh uh polygon zero and uh it enables the pro to be a lot less a lot more efficient how much more efficient two to three orders of magnitude more efficient so what you see here stone is our current Pro that's what's running in in Stark net production today so the numbers I showed you before our running Stone Su who's coming out in q1 next year is going to be 100 to 1,000x more uh efficient than Stone what that does first it reduces proven cost like I said proven cost is important for validity rollups uh but on top of that it opens new possibilities such as client side proving maybe I'll touch that in a second another thing that uh you could sometimes do with the with Layer Two so ethereum and evm have their own set of limitations some of which no longer have to exist when you move to proofs and and to layer tws uh so these are some examples from Stark for instance dark you have native account abstraction so all accounts are smart contracts this allows very uh great flexibility I'll show you in a second some of the things people do with it today uh for instance it allows you to use different cryptography for for signing for user signing transaction other things that you could you could provide some some more privacy than uh using proofs you have a wider variety of data availability options specifically our language is rlike so it's easier to develop in so these are some some of the things that used dat and are alive on on Stark net today so Argent that's one of the leading Wallets on starnet uh they have two Factor authentication you can have a gaming session so if you play you don't have to sign anything during the session uh you could approve in advance up to a certain spending limit uh braavos that's another major wallet they have face ID so this really gives you a a web to look and feel when you're using it you could have multi owners for an account you could have spending limits iubu is a one of the main amm on stet check it out it it provides very good Capital efficiency with uh the capabilities that Stark enables you today to do uh Avenue run a pay Master pay Master meaning the user could send a transaction but somebody else pays for that transaction so you could use that oh sorry so that could be used to provide like you could go in we just did a a few weeks ago we did a a stress test like a real stress test on production with users playing a game that did lots of transactions they didn't have to sign in they didn't have to install a wallet no seed phrases they could go in with uh uh fingerprints and just play okay I'm um other things you could do Dojo they provided U this game engine that enables you to run a lot of uh game logic on chain a lot more than you could do on ethereum uh their longer term vision is to use what I mentioned before when I talked about St a client side proving which basically says that you could run most of the game logic offchain on the client Des device generate a proof and submit that to the chain just to be verified so this is a real GameChanger sorry the pun uh you don't have to run all the game logic onchain to be able to trust it uh Giza have a similar uh infrastructure for machine learning same it's the same IDE similar idea you could run a bunch of thing offchain but then just verify onchain that you've run them correctly and this year if you like uh mmps try this one out it's it's pretty amazing uh so these are the hardware aspects related to infrastructure or technology uh what's also important is a bunch of software aspects related to community to the people and to the values of that community so when you choose a chain I think it's also important to look like who are the people there what's the community like uh what's the vision what are the values what energy do you feel from the team there are very big differences between the different uh chains in that aspect uh so for instance look at the team behind behind it this specifically is our starkware uh track record uh with lots of innovation I think we're the first ones who put uh who who productize provs uh we're the first one who put Layer Two rollups in production uh Circle star I mentioned before these things typically continue if you have a team that's Innovative they're going to continue to innovate and Innovation on the infrastructure level also affects Innovation on the application Level as I showed you before um in terms of vision again this is starware Vision we want to fuel the integrity web what's the Integrity web so blockchains often we talk about technical stuff we talk about cryptography computers all these nice little things uh I want to claim that blockchains are primarily not about that but they're actually much more about these things about Community about about Freedom about human rights about social functions that they enable people to do so we want to focus technology enables that but we focus a lot more about making sure that these things uh are embodied in in whatever we do uh another main thing we're working on right now uh is actually making Stark net air to on top of not just ethereum but also Bitcoin which is something that until recently we thought was not possible either but uh with some uh major advances in research there it seems that once opcat is enabled this will be possible and this is an an article that came out last last week or maybe even this week that actually shows that you could even do it without opcat it's just going to be a lot more expensive uh these for example these are actually from the Stark net Foundation they're not Stark net they're not starkware but again check these things out if you want to join a chain a community like what what does the community stand for what's important to the people there uh and finally it's it's still at the end of the day a matter of people uh so it's worthwhile like talking to the people seeing what they're like feeling the energy uh see what they value uh that's often a lot more important than technical stuff so that's it uh for my part all right thank you thank you yes let's give him a big round of applause all right let's do Q&amp;A uh yeah when stage two okay I start with first question about Bitcoin okay Bitcoin is weaker than ethereum no no no the the the first one when stage two ah when stage two rollups uh so we are working on on decentralization as we speak uh it's coming out in phases so we have started uh uh Gathering people to start staking at First St they still don't play a part in consensus uh and we're basically rebuilding our code it was initially uh built for a different system than we've used it for stet the next phase is coming out in q1 our Target is towards the end of next year to start uh having a a decentralized operation of the network so basically anybody wants to will be able to sequence and prove so to prove star net blocks and take part in this it's it's a major effort but uh it's coming all right it's coming let's keep watching okay next one uh with so many altoos it's too much fragmentation which one we win what are the characteristic of the winning and possibility of unifying okay so a lot of what I said is around that uh I don't think it's going to be a one- winner take all uh I think there are a bunch of use cases that do allow different things and even prefer different things so even the public network versus app chain uh aspect that I touched before in some cases people will want to run app chains and not run on the main chain so I don't think it's going to be just one chain that rules them all um I do think that validity rups have uh some inherent uh benefits over the other options so I think they're M much better poised longer term to to give scale and and better cost and and better us next uh but there are lots of them as well uh and and definitely there's going to be some it's not just unification it's going to be there's going to be some uh like better coordination or uh uh bridging or aggregation between uh different layer toos a lot of teams are working on it right now it's still not working well but I believe that will happen all right and I encourage you all to stay for the next session because we are about to talking about this topic exactly all right next one why Kyo not rust why Cairo and not rust okay so Cairo is very much like rust uh not that many differences uh it is a smart contract language so rust is wider in its scope you could write a lot of things in Rust that you can't really prove because they use some other stuff uh it's not very far from it uh we are always considering whether we want to support additional VMS and some like the next one might be rust itself uh but again if you like rust uh I don't think you'll find CYO major difference how hard is it if I know rust like how hard is it to it's pretty easy it's uh like for people who come from rust typically Cairo is a very natural example uh if they go to Solana it's like rust but it's not exactly rust either so it's it's similar okay thanks all right next one I heard State offer two seconds finality but eum itself cannot finalize block that fast what do you mean by okay so always in Layer Two you have two levels of finality you have Layer Two finality and they're in layer one finality layer one finality you only get once the proofs reach ethereum and ethereum very verifies it which is definitely lot more than 10 than two seconds but you also have earlier fin finality in Layer Two right now Stark net is centralized so this basically rides on a centralized sequencer uh ensuring that transactions have been included but once this is decentralized there's going to be consensus protocol in Layer Two and you're going to get much quicker Layer Two finality before layer one and that could be in the order of magnitude of two seconds probably even less all right thank you okay next one uh let's talk about Bitcoin eum that you mentioned that you will post on the two chains uh Wier board and yeah what if they okay so I I wouldn't say Bitcoin is weaker than ethereum I think in terms of security it's probably actually stronger than ethereum uh in terms of uh uh programmability it offers a lot less options than ethereum uh but it is actually very secure and it is a very strong Network there are lots of people there and there's lots of of uh hardware and capital actually securing that network uh and today for the people on Bitcoin they can't do that much with their tokens because because of the pro uh uh programmability issue that I just mentioned so if you have Stark net r on top of Bitcoin as well all of a sudden you could take your Bitcoin move it to to a layer two which is as secure as Bitcoin and do stuff with it and have Smart contracts that you could run uh ethereum allows it today but for the ethereum community so I think unifying the two will have uh great benefits definitely for the Bitcoin Community but also for the ethereum community because now you could run the same applications and and Target both audiences
