Edge | Bitcoin EVMs: All about Zkrollups, sidechains, and other L2s - Paul Puey | ETHDam III 2025
CryptoCanal·Tue, Oct 7, 2025, 12:00 AM
Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ Edge | Bitcoin EVMs: All about Zkrollups, sidechains, and other L2s - Paul Puey | ETHDam III - 2025 🎤 About the Speaker: Paul is CEO and Co-Founder of Edge, a self-custody exchange and security platform for cryptocurrency. The Edge platform has been used by millions of users across several apps including Edge itself. Paul has professionally worked in crypto for 10 years and voluntarily organized local crypto meetups for 11 years. Prior to Edge, Paul held lead GPU engineering positions with Nvidia and Chromatic Research. 𝕏 Follow: https://x.com/paullinator https://edge.app/ https://x.com/EdgeWallet ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 0:00 Welcome & Introduction 0:54 Why Bitcoin Needs L2s 2:24 L2 Goals: Privacy & Programmability 3:38 Early Bitcoin L2s & Limitations 4:21 ZK Rollups on Bitcoin (Alpen) 6:20 Alpen Architecture Explained 8:00 Security Pros & Critiques 11:04 Spiderchain: Rotating MPC Model 14:25 Drivechains: Miner-Governed L2s 17:27 Chomian Ecash & Fedimint Analysis
Transcript
Welcome to East to E to E to E to E. Um, so next up, uh, we got uh Paul from the edge uh speaking about some uh yeah, again, nerdy stuff. ZK rollups, Bitcoin EVMS, all of this. And um then we're going to have a panel about uh wallets as well, which is the actually going to be one of the few panels I'm moderating this weekend. So I'm really excited for that.
So please give it up for Paul. Thank you everybody. Cool. Cool. All right.
Apologize here. I couldn't see the other screen and I'm not mirroring. So let's see how this looks. Okay. Cool.
All right. Well, thanks everybody. Um, I know it's a whole lot of privacy chat, but I'm going to pivot a little bit, you know, somewhat related and talk about L2s, um, especially on Bitcoin. And one of it, one of their purposes is actually to hopefully bring a bit more privacy to Bitcoin, but also pro programmability. Obviously, the the Ethereum space has really exploded the use case of programmable smart contracts, and we're going to see how that has been delivered into Bitcoin, what are the different options, and what's upcoming.
Quick introduction. My name is Paul Puy, CEO and co-founder of Edge. We're a self-custody privacy focused app that lets people buy, sell, and trade. Um, used to work over at NVIDIA many, many years ago. Still a developer, although I shouldn't be since I, you know, also the CEO of our company.
Um, and I've been speaking at conferences now since about 2014 on a myriad of different topics. So hopefully you guys get some good information about this. So, first thing about Bitcoin L2s, there's a, you know, the the term L2, what does it mean, a layer 2? People say, well, that's a side chain or it's not. I'm going to end this slide really quickly and say there's no agreed upon difference um on the definition.
You ask three people, you might get three different answers. So, let's just say that I'm talking about basically the combination of these two things over the course of this presentation. So, really, it's well, why? What's the purpose of having an L2 in Ethereum space? it was scalability.
But in the Bitcoin space, it's both scalability and functionality. Bitcoin is obviously very limited in what it can do. And so the two primary pieces of functionality that they're looking at adding L2s for is number one, privacy, um, and the number two, programmability, much like we get already in the Ethereum ecosystem. So what are some of the ways that L2s have already been trying to get built on Bitcoin as far back as gosh, 2015? Obviously, lightning, you know, the paper came out in 2015 and it is deployed.
Um, and a lot of people will hate me for saying this, but I don't think it's achieved its goal. Um, and so other types of L2s were also built. Most of them are bucketed in a technology that I would call like a federated multisig, you know, which lets people get Bitcoin in and out of the main Bitcoin chain and onto an L2 or side chain um via a giant multisig that is federated, meaning the participants of that multisig are chosen um by a group or entity. Rootstock um and liquid are both those types. But I'm going to talk more about some of the newer ways or stuff that's upcoming um that we haven't yet seen in the Bitcoin world.
So number one, ZK roll-ups. And we can thank the Ethereum world for this. They kind of had innovated on ZK roll-ups uh which are a way of having another chain, you know, an L2 and its transactions verified by the main chain, the L1. Um I'm going to talk a little bit about um Alpin and I learned actually just yesterday that very similar to Alpin is Citria which I think there's a presentation going on I think right now more detailed on ZK roll-ups if you're a developer and want a really technical talk. I've never said this before but leave this room and then actually go to the one on ZK roll-ups.
This is going to be a much more high level discussion of the different options and how they work. I'll also talk about MPC multisig options such as spider chain drive chains which has been a longtime proposal but hasn't seen the light of day and then show me an ecash which has gotten really popular. Um I'm going to share some of my sub subjective opinion on these uh types of protocols. So first um Alpin Labs is building a ZK rollup uh chain. It's not yet deployed for Bitcoin.
um used a protocol called BitVM, which is a way to do programmability on the Bitcoin layer 1, but it's incredibly complicated. It's incredibly expensive. It's not friendly to develop, but it's used to replace the lack of programmability on Bitcoin in comparison to ETH, right? To do these roll-ups, you need to execute some code on the main L1 that verifies the transactions on the L2. Um, and this is what BitVM is used for.
Some of the other notable bullet points of Alpin is it has a centralized sequencer. So what does that mean? When you create transactions on the layer 2, the EVM one company Alpin gets to choose what the order of those transactions are and which ones get in. Um the the bridge though is an N ofN basically a multisig, an MPC multic. And this is the bridge that locks up Bitcoin on one side and then chooses to mint a tokenized well not really tokenized but the main asset that is pegged to Bitcoin on the layer 2.
Um there's federated prover nodes. I'll talk a little bit about what that is a little bit later. Um and then decentralized challengers meaning anyone can challenge this network and say hey that proof isn't valid. All right so anyone can do that but it can cost a lot of money. So this is kind of like what the network look like looks like to peg in and peg out, right?
You've got these bridge operators. That's the term in Alpen which are part of the multisig. Um someone on the layer one wants to go and peg bitcoin in. They send it to this multisig of bridge operators. They come to consensus and say okay we're going to mint some bitcoins on the alpin um layer 2.
And then the same thing in the happy case where all of the bridge operators are operational. Once again, it's an N ofN multisig, meaning all if there's 20 of these operators, all 20 have to be alive and sign to get the funds out. What about the verification of transactions? How do you know that a transaction on the L2 is truly valid? Um, the transactions once again go through that centralized sequencer.
So, Alpin has control of that sequencer. Um and it then goes out to provers which are the feder some federated nodes that are chosen um and they then go and write the proofs onto the bitcoin L1 and these proofs aren't validated. You know they they can be challenged but that can be very costly. Um but they're written there so that if someone sees that a proof doesn't uh that a transaction on the L2 is invalid they can challenge that proof which could actually slash these nodes. And I had mentioned it's an n ofn multic.
So in this case, say there's three bridge operators. If any one goes down, then the multisig breaks, but then there's this backup, right? So this is the an important piece is that you're not fully relying on the multisig to be up. Obviously with n ofn one goes down, you don't want to lose all the money that's pegged onto this L2. And this is where BitVM using a very expensive series of transactions can actually recover the the funds.
And so someone that wanted to peg out at the time when one of these nodes are down can actually execute a transaction directly on the L1 that would unlock the funds. And this is that script that virtual machine script that's running on Bitcoin. But once again, it's a very costly um costly pro process and it happens if one node is down. Ideally on the happy case, you know, there aren't any. So for these ZK rolls, what are the pros?
Luckily, these nodes, they can't steal with without 100% of malicious nodes, right? So you need a huge compromise to the network to to lose any Bitcoin. It uses the Bitcoin L1 to provide security. And this is what many other quote unquote side chains or L2s don't do. They simply have a set of nodes that validate transactions on one side and then a bridge between the two.
Here you're actually using the mining effort of Bitcoin to provide security because these proofs are going on the L1 and they can actually be verified on the L1 as well. Big criticisms that centralized sequencer. So the centralized sequencer it can choose what transactions get in which means it can censor. However, you can actually bypass the sequencer. There's a thing called forced inclusion but it's insanely expensive.
So both challenging the the provers and bypassing the sequencer if there's a group of people that are being censored would cost about a 3 to 4 megabyte transaction in Bitcoin and so incredibly expensive but know that there is that possibility and so a second sequencer can get launched and just having that capability is what keeps the sequencer effectively in check. Um, as well it's it can be very slow to peg out. Like getting the Bitcoin out of the L2 and into the L1 could take weeks to months. Um, and as I had mentioned, it's very expensive to challenge the proofs if the provers put or put in invalid transaction. I'm sorry, the sequencer put in invalid transactions.
Challenging it is also about 3 to four megabyte transaction. Um, and can easily cost a ton of Bitcoin. I haven't done the math on the top of my head. Um but know that it's an expensive operation. The reason why it's okay that it's expensive to challenge is that there is stake that the um that the provers have to provide and they could lose that and that stake far exceeds the cost of this transaction.
And it's very easy to determine that yes the the provers and the sequencers have put in invalid data. And if they have anyone who wants a challenge will happily spend a gigantic transaction because there's so much to earn from that and that's what keeps them in check. So some other notes um there are some soft fork proposals that are being made for Bitcoin. Um one of them opcat which doesn't look like it's it's going to pass based on just consensus that would eliminate the need for this multi-IG of bridge operators. Um opcat or anything that enables a term called recursive covenants.
This is probably more technical than you know even I can go into but know that that would eliminate having trust in these 10 federated bridge operators and it would be entirely um programmable on the Bitcoin L1. So if we had that great without it just you know has a very long amount of time required to get Bitcoin out of the L2 and into the L1. Um but it it doesn't kill the uh idea as a whole. Okay. Okay.
And then uh another one is kind of an iteration on what we've seen before in um side chains and L2s, which is like that multi-IG idea without proofs. So there's no proofs that go onto the L1. And so uh I had brought up rootstock that's been around since I gosh 2017 if not earlier. Botanics Labs building a new chain called spider chain has a similar but kind of newish iteration of this this concept. So it's full EVM capable you know much like um Alpens's Alpen Labs project uh it uses multiple MPC multisig orchestrators so a lot of buzzwords there so MPC allows you to have more keys than a conventional Bitcoin multisig which in the early days was limited to 15 keys um and it uses multisig at the cryptography level not at the protocol level so and they also rotate these multisig vaults.
So it's not just a federation of fixed entities that are chosen by rootstock. Instead, it's anybody can join in and be a part of this multisig. And then each of the multisig has uh nodes or they call them orchestrators that stake Bitcoin. So here's a little depiction of what that the multisig looks like. every block in Bitcoin, a a an address is created that allows people to deposit into the multisig to mint on the L2.
So you deposit L1 Bitcoin, right? Your standard Bitcoin and then L2 um is L2 Bitcoin is then minted. But a new multi-IG address is picked randomly from the set of orchestrators. So, this looks like a bunch of gibberish lines across, but each block I picked, I think two to threeish orchestrators that come together, create a brand new vault and publish that address for people to deposit into new block, a new address, a new block, a new address. So, it effectively is rotating the orchestrators.
So, you don't have one fixed set, nor do you have a known target of who to target for all the funds in the network, right? It's it's it's much more distributed. So it's almost like it's a multiig of multiigs. So what's the pro of this model? You've got a more decentralized and rotating set of orchestrators versus a fixed federation that are chosen by a central entity.
Um much much harder if not cannot censor. You don't have that fixed um sequencer. Uh, and you also have faster pegouts. Um, since you're not using bitvm, which is a very slow way to challenge um challenge incorrect behavior of the uh of the bridge. Um, you generally can peg out in hours versus weeks.
But the criticisms, uh, you don't need 100% of the nodes to steal. You need about roughly 60%. If 60 are malicious, then you can steal some Bitcoin. Um, some of the criticisms I've heard, it's much more complex of code and uh, UTXO management becomes pretty complex and it doesn't leverage the layer one like all that hash power and mining power on Bitcoin isn't leveraged to secure the transactions that are on the L2. The thing that secures them is 100% just pure proof of stake by the uh, orchestrators.
Uh, drive chains or BIP 300 was introduced by Paul Stos years ago. Um, and really it's not a chain, it's not an L2, it's a method of building L2s that uses a different model than the previous two that I mentioned. You know, the MPC multisig or the ZK proofs. Instead, you can think of drive chains as a multi-IG of the miners on Bitcoin. The existing miners on Bitcoin are the ones that effectively get to vote on creating a transaction or validating a transaction that goes onto an L2, pegging in and pegging out the Bitcoin.
and they vote by hash rate. So, the nice thing about that, you don't have to go and deploy a whole new set of nodes, right? You've already got the the uh ecosystem of miners. Um the L2s though have to be approved by a minor. So, you can't just launch your own L2.
Miners actually vote to say yes, I approve of this L2 and we're going to support it or no, we don't. So, the pros, as I mentioned, no need to set up a federation. you don't need any additional nodes. Um and and this is probably one of the biggest um arguments for drive chains is it doesn't siphon the fees out to another set of nodes. The miners that already exist on on the L1 get compensated for the work that they do.
But there's a bunch of criticisms. Um number one, it needs this softwork BIP 300 which many people don't want to see happen. Um the withdrawal times are gigantic. getting the uh getting the peg bitcoin that's on another chain out to the layer 1 is currently looking like 3 to 6 months to do that. Now you might ask why does it take so long?
Well, when you have miners voting with their hash power and there's only one block every 10 minutes, you really need a lot of blocks to get a feel for all right, is this a majority vote across a lot of different miners? And so to get really good confidence that you've got that majority vote takes a really long amount of time. Um, another criticism is that it motivates miners to earn money not just securing the network but on all of these different side chains. And there's that, you know, philosophy in the Bitcoin world like, oh, it changes the purpose of Bitcoin. You know, it's supposed to be just store of value money.
And to me, that's me whatever, right? Like people can do with the chain what they want. Um, and so based on the criticisms, um, and mostly on what seems like the community consensus, drive chains doesn't look like it's going to get adopted with a soft fork. But I have heard from Paul Schwarz that there's a way to kind of jam it into the ecosystem by giving some software that can run on top of a full node, meaning you don't have to change like Bitcoin core. You can run Bitcoin Core as is and run this little piece of software on the side and then now you're contributing to the software.
And if enough miners do that, this can actually go live. Last thing I want to talk about is uh what's achieved quite a bit of of hype and um uh adoption especially within the Bitcoin community um that really likes to actually transact like wants to not just have Bitcoin as a store of value but wants to like move money around between each other. That's Chom and Ecash. Now this is actually a precursor to Bitcoin, right? This protocol or method of transacting way predates Bitcoin and you know is something that was used to build pieces of what Bitcoin is today.
Basically the hashing algorithm and ironically it's somehow coming back and it gives up some of the the benefits that Bitcoin brought to this uh like digital cash ecosystem. The three main, I think, bullet points to help describe this, I'll go into a bit more detail, are number one, you've got trusted community mters, people that mint tokens that represent Bitcoin that people can then bounce around to each other. Number two, it uses a cryptography technique called blind signatures. Just know that there are these signatures that have a interesting property to them. I'll go into a little bit more later.
And then these transactions are offchain. When people bounce the ecash transactions, they don't do it on any chain at all. They simply send each other a piece of data, right? Just like an email. So, what does this look like?
Here's a big graph. I'm going to try to walk through it. All right. You got our favorite Alice, Bob, and Charlie here trying to send money to each other. Alice has some Bitcoin, but she don't want to send she doesn't want to send expensive onchain Bitcoin back and forth between people.
So she chooses to mint some e-cash tokens which represent Bitcoin. So she generates a key and that's just a random number, right? A key and then using some cryptography blinds it. So blinding a key is the equivalent of putting a letter in uh a letter inside an envelope um with kind of like that carbon copy paper that you can write on top of and it goes to the paper underneath. So she blinds this key and then sends Bitcoin with a blinded key over to the mint.
So the mint cannot see the key that's inside of it, but they can sign it. And so they see the bitcoin, they, you know, say it's one bitcoin. The mint signs it and they sign it with a key that represents one bitcoin that publicly knows this key is signing one bitcoin and returns that blinded signed key back to Alice. So Alice now has this blinded signed key and she can take it out of the envelope, right? And that's I can't see my my cursor, but in the upper left to the left of Bob is that opened envelope and it has the signature in it and it has the unblinded key.
So the combination of that that signature and the original key is the token that can be bounced around to people. So Alice can send it to Bob, Bob can send it to Charlie, and then Charlie can redeem that by sending it back to the mint. And the mint can verify, oh, look, that's my signature. I signed it. But I don't quite know who gave who originally minted it because I didn't see the key.
It was blinded at the time that the mentor signed it. But they know that they were the ones that signed it and therefore there there was some money that they collected in order to mint that token. Charlie just proved that. So now the mint sends the Bitcoin back to Charlie. So that's the redemption process.
So what's so cool about Choming Ecash? Well, the pros, it's fast, right? As soon as you you've minted, it's very fast to to bounce the uh the token back and forth. It's decently private in the sense that there's no onchain transaction other than the minting and redemption. So, if you're not minting and you're not redeeming, there's no trace of the transaction.
But the criticisms, centralized custody, you should have caught that when I first said that, right? These mentors are fully trusted entities. You're giving them Bitcoin and trusting they won't just run away with it. And there have been some mentors in the ecash world that basically rug people. Um, there were two protocols I mentioned.
One is Fediment and one Cashew or these two different apps. fedment at least suggests that you create a federation of mentors that hold the keys suggests but there's no standard there's no guarantee you have no idea really you're fully trusting um whoever that custodian is so personally that's dead in the water for me I which I was like why do we just go backwards Bitcoin solved this problem and now we just brought the problem back so I yeah I'll admit I'm here on stage page telling you all about this and describing this protocol just to really on it and say don't use it. But I want you to understand why, not just on it for no reason. So there's there's your issue. Number two, this token is infinitely easy to double spend.
So going back to that description here, um Bob accepting the key, he actually isn't at risk if he knows that Alice is the one that minted it. Um, but as soon as Charlie gets it, Charlie's like, "Uh, actually, I'm sorry." Charlie in the attempt at at redeeming has to hope that neither Bob or Alice sent that same token to someone else, right? There's no guarantee that when you receive the token that it hasn't already been redeemed because it's just a payload of data. It's just a string of bits and that's it.
It's basically the equivalent of sending your private key to someone, right? putting it down on a piece of paper and then passing it around hoping no one redeems it and no one sweeps it. So, the only way around that is to every single time you go and receive a token, you have to try to redeem it or you could try to what's called called refresh it where you give it to the mint and the mint gives you back another token. Um, so there's no onchain transaction. We have to constantly refresh it.
That gives up some of the privacy that you know Chomine ecash was actually built for, but it at least alleviates the concern of getting double spent. But this isn't even part of most protocols and and not protocols, but apps that implement ecash. They don't do this refresh automatically. So you can get rugged by someone sending a token to multiple people. Um and as well it needs a separate secure side channel meaning it needs another way for someone to send funds from or send this token from one person to another.
If you look up the proposal say oh you could send it you know over your phone SMS or email one of the most sec insecure methods of communication. So highly not recommended but yet at the same time this is what um people are are using. That's a good summary. Hopefully you guys learned a little bit about, you know, the different L2s and what to look for in in this kind of land of uh scaling and adding functionality to Bitcoin. Real quick, I'll end with a little bit what we're doing at Edge app that lets you definitely hold, send, receive, buy, sell, and trade a lot of different privacy coins.
That's where we believe strongly is that uh the ecosystem of privacy is important. We want to make it as super simple as possible. Uh we just launched a feature that it really is important in the security and privacy space. We haven't talked about this enough, but physical privacy just launched the ability to have a duress pin in the app and or a different pin than usual and you show a sub account with a different set of funds. So in case there is that moment of duress where someone's forcing you to unlock your your device, you could unlock it and not show the funds that you normally would have.
And then we're open source. People can check it out github.comedge.app. I think it's important in any privacy focused tool is that it's open source so people can audit it.
That's it. Thanks everybody. Appreciate it. Cool. Thanks so much.
Uh we actually got one question for you and then uh going to take a seat. Uh let me just get it up. So investing on decentralized sequences is expensive given that uh the main source of revenue is I don't know if that makes sense to you. Give it a crack. would uh given that what is the main source of revenue for the one investing?
Oh, I see what they were saying. So, investing in the projects that build a decentralized sequencer is tough because there's no token, right? So, um admittedly that is an interesting challenge. I'm not sure what was the motivation in investing in spider chain. Like it could simply be that they will they will be some of the early sequencers on the network, right?
They're the main developers. They'll be the early sequencers on the network. But it's true. Being early doesn't mean that you're there when there's a lot of money. I'm not an investor, at least not in companies.
All right. Um, and I don't know the pitch other than investors trying to pump the bags they already have, such as Bitcoin. And I think a lot of Bitcoin investors really think think of it this way. They're not investing in the company success. They're investing in the ecosystem necessary to drive success of the protocol and the asset they already have.
Cool. Thanks for sharing. I hope that answered the question at least from your point of view. Uh the second question being tornado cache is arguably better chanian ecash. How hard is it to organize a similar tornado cache on bitv?
So I think you need less of a quote unquote tornado cache but instead you need a side chain that is kind of like a Zcash, right? And through that you can do an equivalent to a tornado cache transaction that just simply moves funds to another address through the kind of Zcashish network and then you've quote unquote kind of like mixture funds. Um and that is one of the talks and there was a paper that was written that I was that I was given um by the Alpen labs team that had a proposal to build a full ZK snark chain using the technology that Alpin had built to be able to bridge to and from the main L1 but not to an EVM L2 but to a fully private L2. Um and I think that's one of the grander visions. Personally, I think this is the only hope for Bitcoin is, you know, this L2 ecosystem.
Otherwise, it'll get taken over by a lot of the different functionality and privacy chains. Um, but having a programmable L2 plus a private L2 combined would be that that's the end all beall. You're you're done if it's fast and actually just kill the L1 at that point. There's actually not too much purpose because the L1 is contributing security today, but that security is only going down the more the L2s are used and then you don't really need it at at some point. Cool.
Thanks for sharing. Uh, please unplug your laptop and take a seat.
Automatic transcript — names and jargon may be misspelled.