# Citrea | Building rollups on Bitcoin - Omer Talip Akalin | ETHDam III - 2025

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2025-10-07
- Duration: 17:07
- Watch: https://streameth.org/watch/yt-E7xIXZajlZ8
- YouTube: https://www.youtube.com/watch?v=E7xIXZajlZ8

## Description

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo.
🌷 https://www.ethdam.com// 🌷

------------------

Citrea | Building rollups on Bitcoin: ideas, tradeoffs, and the future - Omer Talip Akalin | ETHDam III - 2025     

🎤 About the speaker:
Talip is a DevRel Engineer at Citrea - as an ex-protocol engineer with lots of spicy takes and ideas, he’s now helping all developers across the globe to accelerate Hyperbitcoinization.

𝕏 Follow:
https://twitter.com/otaliptus https://citrea.xyz/ https://x.com/citrea_xyz 

------------------

About ETHDam & CryptoCanal
ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich.

Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance.

------------------

🎥 Credits:
Intro / outro by babyPRO -  https://babypro.art/
ETHDam Photography by Paulus – https://concretestate.eu/ 
MC of ETHDam - Laura Brown - Cofounder at JobStash & Veri, and your resident crypto ginger. https://linktr.ee/laurabxyz

------------------

Special thanks to our partners who made ETHDam possible: 
🌹 Hackathon – Bouquet:
Oasis Network https://oasisprotocol.org/ 

🌷 Hackathon – Petal:
Circles https://aboutcircles.com 

💛 Conference – Gold:
Zano https://zano.org/ 
Dash https://www.dash.org/ 
Bitvavo https://bitvavo.com/en 

🩶 Conference – Silver:
Igra Labs https://igralabs.com/hero

💛 Conference – Copper:
Lido https://lido.fi/ 
DeTrip https://detrip.travel/
Cake Wallet https://cakewallet.com/ 
The Grid https://thegrid.id/ 
Calimero Network https://calimero.network/ 
0xbow https://0xbow.io/ 
Mina https://minaprotocol.com/
JobStash https://jobstash.xyz/ 
Cyber Capital https://www.cyber.capital/  
POAP https://poap.xyz/ 
Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 

🌱 Sponsor:
EF Ecosystem Support Program https://esp.ethereum.foundation

------------------
0:00 Intro
1:05 State of Ethereum
2:38 Programmability of Bitcoin
4:00 Bitcoin Scaling Challenges
5:02 Sidechains & Lightning Issues
6:22 ZK Rollups on Bitcoin
8:00 Citrea Architecture
9:56 Bridge Design with BitVM
11:48 Trust-Minimized Bridge (Clementine)
14:48 Bitcoin Drama & Core Dev Reactions

## Transcript

Welcome to Eth Dog. To Eth Dog. To Eth Dog. Um yeah, I think the last two presentations were very interesting. So, I'll try my best to go into some another crazy world of Bitcoin and what the hell is going on on that end because it's a whole another mania. Um yeah, I mean I hope it's going to be nice and I hope we get rollups in the future, but we will see. We will get them. So, oops, just to briefly talk about where am I? I'm Talip. I'm the DevRel at Citrea. We're building a ZK rollup on Bitcoin. And yeah, before that I was a protocol engineer and then we grew a lot and we became smarter, so I basically didn't need to code anymore. Team handles everything for me. I now talk with developers who wants to build on us. Yeah, I will do a speedrun. This will be extremely fast and I hope extremely funny as well. I don't know, we will see. If you have any other questions, let's catch up later or in the Q&amp;A. Um yeah, today I will first start about like the state of Ethereum basically just to have a baseline and then go through the state of Bitcoin which is very cool, I hope. And then we will get rollups and bridges and then some interesting stuff at the end, politics of Bitcoin. Yeah, before start I have a very important announcement. This is super important like everything depends on this. Rollups are not bridges. They're not the same thing. You can have rollups or chains without bridges which is not ideal obviously, but this is very important for the context because actually we're building two things. First one is a rollup and the second one is a bridge. So, just keep that in mind. We will visit that later. Um yeah, so on the Ethereum scaling, I guess we're doing fine especially based on the last presentation. That was nice. Yeah, L1 is doing okay. It's doing even better. Sidechains are now not calling themselves L2 which is a win. And now rollups are also doing fine, I guess. If you check the L2Beat the numbers are very good. They earned a lot of money even though they don't care about stages at all. Like it's going nice and we have some more and more and more. Um Yeah, I guess they earn money, so it works for them. Unfortunately, some of them are oops oops oops a bit like I don't know why it moves fast, but yeah. Unfortunately, some of them are a bit shady in these like I don't want to name names, but be careful on what rollup you're using because I don't really trust all of them still. We should do better. Um yeah, so it's good. People are using it. Everything's fine on the Ethereum world. So, what about the other world? What about Bitcoin? Well, first let's check on the programmability of Bitcoin. So, on the left you have some Solidity code. I guess it was from the Uniswap. I don't remember where where I took it from. And you see like if you're kind of have some familiarity with programming, it's kind of readable, understandable, kind of useful. And here we have the scripting language of Bitcoin on UTXOs which is quite an assembly like language which is very primitive in terms of opcodes and not only the opcodes, but also the limitations of the your stack. You can only have, you know, some number of bytes and some number of elements on it and you need to fit it into very interesting stuff, so you cannot really build anything extremely practical with it other than moving your money around. And even worse, like if you manage to do things, then if the chain gets used because the chain is not used at all. Now everyone is doing paper BTC or centralized exchange BTC. But if you really try to use Bitcoin, then you also cannot use it because if when everyone tries to use it, the fees will jump. You pay more than $100 per transaction sometimes. And if everyone in the world may try to use Bitcoin, it just wouldn't work with eight transactions per second or whatever. Like it just doesn't scale at the moment. So, now seeing this, then there should be solutions, right? Okay, like yeah, this is the reaction of many people. So, there should be solutions. What can we do? I mean Ethereum people are scaling L1, right? So, let's scale L1 then. It doesn't work like that. So, because there are different camps and different politics. So, the Bitcoin block sizes are 4 megabytes and when you ask people, some people think it should be even smaller. Some people think nothing should be done other than holding. And there are people demanding things that cannot get things. Oops, this is kind of frustrating at the moment. Yeah, and there are people kind of trying to do useful stuff like us as well, but also they cannot get what they want. Sergio is from Rootstock. They're doing some cool research, but yeah. I get extra time for this. Um yeah, so we cannot get much. So, you don't scale L1. It's just stuck. Latest upgrade was four years ago. Before that it was eight years ago and still we suffer from some of the implementation problems of these upgrades as well. So, scaling L1 is a problem. Okay, what else you can do then? It doesn't work. Then let's try sidechains, right? People can do sidechains. And they did actually. Like there are a bunch of sidechains on the Bitcoin world. If you check bitcoinlayers.org which is an open source very solid project. They just compare every tradeoff. Well, sidechains kind of work just like the Ethereum ones, but the problem is we have even more shady ones. Like here I see at least six scams here. So, I don't want to name names, but again be careful on what you're doing. Yeah, sidechains they function, but they don't really function and they're not as secure as we want. So, people did pay payment channels which is kind of lightning. They're great because they're trustless. You can exit whenever you want almost all the time. Um but the problem is they're useful until they're not useful and they work until they don't work. Most of the time they work. Most of the time lightning works fine, but you can also only send money and stuff like that. And the amount as get it's bigger as it gets bigger, stuff doesn't work. So, it's kind of also in a problematic shape. So, then yeah, sidechains, channels and bunch of other stuff like drive chains which I don't really talk about it here and then merge mine chains which is another idea and meta protocols of shitcoins and whatever. Yeah, so everything is going fine. So, another idea then Ethereum people build rollups. So, what if you build a rollup on Bitcoin, right? Then you get some functionality and people can do whatever they want with some security tradeoffs. Well, okay, let's build an optimistic rollup on Bitcoin. Let's make a layer. Let's execute transactions and then submit our data into Bitcoin and then the thing is in the previous presentation Julian, right? Julian showed like 128 blobs and each blob is I don't know some many bytes and kilobytes. And the problem is you cannot fit it all into Bitcoin. So, if you try to build an optimistic rollup on Bitcoin, you can't because you have 4 megabytes of blocks that are coming in 10 minutes in the average. You need to publish full transaction data which will cost you arguably at least $50,000 per L1 block. I don't know. Just making numbers, but it's maybe more, maybe less, but whatever. And then you cannot how how are you going to do a fraud proof if you're doing an optimistic rollup? That's also another thing because Bitcoin script is hideous. You cannot challenge anything. So, it's just arbitrary data you dump and then you can't do anything at all. And yeah, it's expensive. So, you cannot do optimistic rollups. We crossed this one. So, what if you do then something better which is ZK rollup option? Can you do it maybe? So, let's check if it's possible. So, to make a ZK rollup, you need to have a chain, execute transactions, batch them, submit them into Bitcoin. And then there is a sequencer that produces blocks, orders transactions and then there's a prover prove things and posts or like generates the proof. So, and actually you can do it. So, because on the ZK rollups you have a proof that is Stark or Snark. Like size size is still small. And if you use Merkle tree differences rather than a full state data, then it fits. So, on the on the average is like what we get is on a couple of Bitcoin blocks, the amount of data we need to publish in the Merkle tree diff form which is also something ZK rollups on Ethereum world use right now is around several hundred kilobytes which is still expensive, but much better than 4 megabytes of or like 40 megabytes of data. And the tradeoff you get is you need to prove. So, you cannot just instantly post and finalize your data. By the way, finalization also sucks because you need to wait six Bitcoin blocks which is 60 minutes to get everything finalized, but still. And then you get more TPS at least. So, it's it's worth. And then yeah, you send these data along with the proof to Bitcoin DA so that anyone running a Bitcoin node can read Bitcoin itself and sync with you and continue living which is a net win. Like people don't depend on your RPCs to read data and stuff like that typical rollup. And then yeah, if you post state diffs, it works nicely in the current form. We hope. Um yeah, so we also use Stark. Like you can also use Stark to Snarks because Snarks are much less on the size. Starks are unbounded computation. And now congratulations. You made a ZK rollup on Bitcoin. But so, okay, we did this one by the way. It is live on Bitcoin testnet 4. It's called Citrea, my company. It's a bit of a shill time now. So, the architecture currently is sequencer publishes like generates the blocks and then sends to prover. Prover proves them and then with state difference to Merkle tree publish to Bitcoin. And if you're running a full node, you can just use Bitcoin as the source of truth. And this system is also EVM compatible. So, whatever you use on the EVM, it also works here. 7702 account abstraction, all of it. And then, yeah, 2-second blocks times, whatever. So, now you have an independent chain. But then, the problem also Also, like we website called c2a.usage.com if you want to check how much data in what form we post to Bitcoin, you can check it out. Um it's a lot of money, but still it works. Users will pay for it, we hope. Um And on the demand side of things, so you cannot have multiple of them. You can have multiple rollups, but probably not more than two or three because the rollup post data and block is size is limited. And once you post more data, the fees will increase. Bitcoin becomes kind of unusable. And uh so, this is our transaction among other Bitcoin transactions in one block. So, it's kind of like a bit huge. And there can be multiple of them. So, it's another problem. Yeah, and there is a demand for Bitcoin rollups, actually, because holding Bitcoin works, but doing some other stuff may also work. So, people want it. And uh yeah, so this is a huge bomb on what's going on on the Bitcoin. So, it will be fun if you have two rollups. If three, I think it will become unusable. We will see. And uh this happened. So, we were talking with some core devs. I told them like we're going to bomb the DA, and they were like, "What?" It is what it is. Yeah, it will be up. We will see. In 3 months, we will have some fun because we're going mainnet. But yeah, I didn't know Thank you. Um So far, I did the rollup stuff. I have 5 minutes. So, let's do something extremely faster even. Rollup is in the bridge. I have the rollup, but where is the money, and how do I move my money out of Bitcoin? So yeah, current solutions, just give your money into a 3 of 5 multisig, and then beg that Justin Sun doesn't steal your money, which is a great idea if you want. You can use MPCs, which is arguably the same thing with multisigs, but whatever. And then, what if there is a better way? Yeah, like is there a better way? So, what's all the catch? Yes, there is a better way. Plot twist. Um so, you cannot verify a proof directly on Bitcoin script due to the reasons that I talked in terms of Bitcoin script capabilities and stuff like that. If anyone's saying trustless bridges, you can show them this image. They're just lying flat out. There's no trustless bridge you can do without OP_CAT. With OP_CAT, you can do it. But yeah, also like the we can still write a growth 16 verifier in Bitcoin script, which is 800 MB. So, you if you can fit it in the 4 MB, then you can do trustless bridge. Um but still, there are some ideas. One of them called BitVM. So, with the BitVM idea, what you do is you split this 800 MB, and then make a Merkle tree out of them, and then put it onto UTXOs. And then, you can reveal if someone is dishonest by providing a valid proof on a UTXO. So, this is kind of technical, but I will go over it. So, this is the paper. It's a very solid, groundbreaking idea came around almost 2 years ago. And then, there's BitVM 1 and 2. And anyone in the world can challenge uh people on UTXOs. So, we also implemented this one. It's also getting ready in 3 weeks 3 months so that uh you don't need to use C2A without a bridge. So, it will be a fully functional ZK rollup with a trust-minimized bridge. And uh yeah, it's called Clementine, our bridge design. We have a white paper released 2 weeks ago. And uh the way it works is this is 800 MB text file, and then you split into chunks. And then, if someone does something wrong on the bridge, what you do is you run the code on your computer, find out which section failed, and then reveal it on Bitcoin script, and then kick malicious people out of N and of M multisig. And uh this is our transactions, which is again very well-sized. And uh this is the kicking out transaction stuff, which is also very fun. Increase the fees and stuff like that. This is our bridge design, which I don't really want to talk about at the moment on this level. There's bunch of these. A more simplified version is um how it works in 10 seconds. You give your money into an N of N. You can get out from N of N, and you only need one out of N to be functional and honest for everything to work. So, now you don't trust 3 of 5 multisig of Justin Sun. You only need one out of N for everything in the world to work and continue functioning. And uh yeah, some more ideas. If we can get more opcodes, it is much better. Will we get more opcodes? No one knows the answer. Um rollups will be be useful, I think. Miners will get rich. Fees will increase. And uh we also incubate some EVM applications products on our own internally so that people can use Bitcoin with account abstraction stuff, which is much better, we believe. We have uh some very cool stuff coming on, especially some solid stablecoin designs, Bitcoin-backed. And uh this is some of the project names. And then lastly, in 30 seconds, let's go over the recent stuff. So, after white paper release, some Bitcoin core devs realized Just give me 1 more minute. I had problems with After white paper release, some Bitcoin core devs realized in the bridge construction, there are some weird limitations and transaction choices we did. So then, we they asked us, and then we gave them answers, and then they were like, "Okay, this is an easy fix. It doesn't affect anyone. So, let's change some stuff on Bitcoin. Let's change OP_RETURN opcode a bit." And then, the drama unfolded. So, this is a technical discussion. I think it now has around 200 mails or something because some camps really doesn't want these to be unleashed, they say, on Bitcoin. And uh this was the GitHub discussion, which is now locked. Over 200 comments with 375 magic, and then 100 people approving. Um Yeah, so it became a lot of controversy in the last 2 weeks to the point that there are some technical people trying to tell people that this is not a huge deal because it's very minimal. It's already possible today. And then, there are people who hates us, basically, tries to filter us from Bitcoin, which they cannot because we're not doing anything against consensus rules. And then, there are people who says we're trying to destroy Bitcoin by some other people's support because some of our investors are apparently big blockers or stuff like that. And then, there is more more and more drama like "The new EVM is the old enemy." Oh, we raised 40 million, by the way. And then, like shitcoiners, go away from my coins, whatever. And then, there's also good people who agrees with us. Like appreciate all the appreciation. Uh we're doing fine, I believe. Also, there are one, two companies that are also doing fine, like Aligned Stackware guys, hopefully. And then, this is the last image. I saw this yesterday. This was very fun. These are the BTC core devs. These are the people against the minimal minimal change, and this is us, apparently. So, I'm really happy with this. They believe we bribe core devs or something, which is ridiculous, but anyways. Yeah, all of these will be fun until the quantum computers come and Satoshi's coins will be moved. Then we will have another discussion because it's possible. Um yeah, this is this what we have every day. So, thank you. [Applause]
