# Rollups on Bitcoin - Omer Talip Akalin | Citrea

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2025-10-07
- Duration: 26:08
- Topics: People & Blogs
- Watch: https://streameth.org/watch/yt-lYhtMY75bSM
- YouTube: https://www.youtube.com/watch?v=lYhtMY75bSM

## Description

Rollups on Bitcoin - Omer Talip Akalin | Citrea

## Transcript

Um yeah, hi everyone. Uh before we start, I want to ask a very important question. How many people holds Bitcoin today in this room? Like some amount of Bitcoin. Okay, more than what I expected. That's cool. We are not all ETH maxis. That's cool. Um how many people use Bitcoin on the Bitcoin L1 itself? Okay, the number is much less which is very normal to be honest and uh yeah um we try to do fun things on Bitcoin. I hope this talk will be interesting for you. Um before we start I want to give some background on myself. My name is Talip. I'm a de engineer at Citra. It's a roll up on Bitcoin that I will talk about a bit today in terms of the also with the other constructions too. Um this is going to be a fast like rather fast presentation. So um you know if you have any questions in mind after even after Q&amp;A just find me and then like we can talk about it and um yeah like most of the things are also my personal opinions which I find very true but you know you may disagree with me it's a very personal presentation to be honest apart from the technical facts um yeah today we will first start with the state of Ethereum because this is ETH Belgrad you know kind of a good baseline to set what we're doing and what's possible today and and we will go over the state of Bitcoin which is very interesting and uh frustrating and then uh we will go over what's today possible and you know what's going to be possible with what we're building and what the other cool people are building too and uh at the end I will have some angry um takes about you know what's going on overall the whole presentation is a bit angry too so be prepared for it um yeah so to start with I have a very important distinction uh rollups are not the same things as bridges. Um, roll-ups are blockchains essentially, but bridges are bridges and a rollup itself can function without a bridge too. This is a very common misconception in the ETH world. So, just to let you know um on Ethereum scaling um today. So, we built bunch of stuff on Ethereum today. It's the world of DeFi essentially. Um L1 is doing good and gas prices are kind of reasonable and um you know it's like essentially rollups are doing fine. There is also ideas towards L1 scaling. Side chains are not named naming themselves L2s anymore. And uh it's at the end of the day it's money like you can use it as money whether uh compared to you know when when you check the all the existing L2 solutions they're also enabling you to use them as money and uh they have a bunch of TVL on them people are using them everything is good you know we enjoy life even though in terms of the security assumptions I think we have some problems I would accept uh this kind of moves on its own by the way just to double check um I would expect this table and this piece of diagram to be better. Maybe it's because hard to do. Maybe it's some skill issues. Maybe people don't want to really improve the security of the systems we have today. But anyways, like overall Ethereum itself is doing fine and uh everything is working nicely. So I guess like we can give a thumbs up on it. So now we said Ethereum is good, but what about Bitcoin then? So it depends on how you define Bitcoin, right? So if you define Bitcoin as a gold to buy and hold, then you're doing great because the price is 100K. You know, no one is richer than you and life is good. But if you believe that it's the best asset in the world with arguably the most uh you know, the securest asset in the world with most decentralization and most nostalgia even, I don't know how you want to name it, then uh Bitcoin itself may not be doing very well. If you want to think about it as the combination of these two, then you know, you're in maybe a better shape. And if you just want to, you know, buy some ETFs, paper BTC, then you're in a good shape. But I definitely disagree with you. I don't think it is the future that you want it to be. So assuming peer-to-peer cash idea and the money idea makes sense. Then uh then we have some problems because so this is the picture of Bitcoin Meold and um this is from the times where it's cheap. I think today is also cheap. But uh if Bitcoin starts to get used then you get enormous fees and everything starts to kind of shittier. Unfortunately the fees increase the chain becomes unusable. Bitcoin maxes get angry on Twitter. They yell at you and all the fights happen. So it's kind of like if you try to use Bitcoin other than holding today for most of the times you may get frustrated if you try to do it at the same time with all the people too. Um and and if you try to do more with your Bitcoin like in Ethereum world we have bunch of stuff like we have lending borrowing platforms on Ethereum and uh we have vaults on Ethereum world with the EVMs on the L2s we have privacy with tornado cash rail gun and all the other stuff we have we like you know if you want to buy and sell Bitcoin even you need a custodian and this is I I really find this really ironic like because we like this whole system was built to get around of custodians, get around of people who can control your money, get around of you spending it. And now it's not practical to use for these senses. Now to do any kind of these in the list, you need a custodian like you use, I don't know, coinbase or stuff like that. I don't think this was the intended purpose. I think this should be changed. And uh there's actually many people thinking like me too. So I'm not alone on this. Um you know, in this alone, you may believe again you should just buy and hold. Maybe this is your opinion but to my opinion I think I should be able to do all of these in the best asset in the world and I think it's Bitcoin. Um and even not only these but also the Bitcoin execution environment itself like the code on the right is um the code on the right is Bitcoin script and the code on the this side to me left is uh on the on the from smart smart contract of I think unis swap or something. So as you can see the difference I mean the code on the right the code on the left the Ethereum code also gets compiled into assembly but still um the language is very primitive on Bitcoin scripting and the stack which is the execution environment limits of Bitcoin script is also very very limited. Um the number of operations you can do the things you can do are very very limited and u again if you still try to do things then this is the things that you see on your mental explorer like it just becomes unusable kind of. So yeah what do you do then are you just getting angry and then do nothing of course not like you know after flipping the table you go and try to do things right and people also had some ideas and they started to work on it. One particular idea is changing the album itself. Well, there is a dilemma on this because not everyone agrees with you. I believe that Bitcoin L1 should change. There should be improvements, but not everyone thinks like me. Like, you know, some Bitcoin cord says no, Bitcoin is perfect or like it should be even smaller block sizes and stuff like that. Some people say it looks terrible and then some people say no, this is the beauty of it, it is perfect. And then there's also a bunch of researchers that agrees with me that it sucks. But at the end of the day, everyone has a different opinion and no one not everyone thinks about scaling it. Okay. So yeah, you you're just stuck on that. You cannot change Bitcoin L1. The latest upgrade was four years ago even. So it takes years to do things. So yeah, because of this, people tried things. People tried side chains, which if you check bitcoin layers.org, which is a great website, you can check their security assumptions. But the problem with side chains is most of like some of them are very shady. I am not going to name names here due to respect to all the industry but I hope that some of the companies here essentially die because they lie on whatever they do all the time. Um but there are credible names as well but at the end of the day there are side chains. So it's like you have a different security assumption you have a different breed security assumption as well other than the chain. So it kind of like works to some degree. People try to do payment challenge. If how many people here heard about lightning network? Okay. Yeah. So, people tried lightning. People tried alternative constructions. It's great that they're trustless. Like you can exit the system whenever you want, which is I think really underestimated um property. But then on on the other hand, it works most of the times, but it doesn't work when you sometimes need it or if the amounts increase, it doesn't work. Like there are a bunch of problems with lightning. Even though people disagree, I don't think it's a like extremely great shape let's say and then uh people also tried bunch of stuff but uh at the end of the day it didn't work. So you know Ethereum has bunch of roll-ups. Can you have rollups on Bitcoin too? This is the idea and this is the title of the presentation too. So what is a rollup then? You know let's let's go with an optimistic rollup. How many people here knows what's rollup is? Okay. Um so rollups are the blockchains that publishes its data on another blockchain. That means the other blockchain as long as the other blockchain is alive and functioning then your data is secure and always accessible. It never gets loed even when people plug off their computers or stuff like that. Whole idea is securing a blockchain with another blockchain. So there's this one construction called optimistic rollup where you publish all of your transaction data into another blockchain and then uh you know as long as that blockchain is alive then everything is secure. But the problem is you cannot do this on bitcoin because you have bunch of problems. The blocks of bitcoin are 4 megabytes and if you try to post more or if you even try to come near to it like a couple of hundreds of kilobytes then the amount of fees you pay becomes catastrophic. like you will end up paying I don't know thousands of dollars probably and um even if you do this one property that I'm going to mention is some constructions have the ability to challenges towards malicious people and uh you don't have these and if you try to do it on bitcoin so it's kind of like you cannot do the ethereumistic optimistic rollup construction on bitcoin it doesn't work so what else you can do like you need to do something better and the idea is called ZK rollups which is uh which uses zero knowledge proofs. It's like you have bunch of transactions on your chain and then you batch them together and then you prove them that they're right. It's like a magic box and then you also post all these data into the bitcoin. So as long as bitcoin is secure and as long as bitcoin is functional then all the data will remain there and it's always accessible and usable. And uh the trade-off here is because you post a lot of data and because you need to prove it as well, you kind of sacrifice your speed, but uh you know it's more secure because as long as Bitcoin is alive and functional, which I believe it will happen maybe forever, I don't know, at least until I die. Um you will have it and then you post it in the state form which is if you have Merkel trees, you publish the differences of it and as long as this Merkel tree differences are there, everything is secured. Um, is there any other clicker that moves automatically? Yes or no? Okay, I will try my best. Um, yeah, like ZK rollups today on Ethereum. They're live. They're functional and uh everything is good with this ideal construction. You can have a ZK rollup now. And actually, we did this one. So, it's called Citra. Obviously, it's live on a Bitcoin test net 4 today. And um it's actually much more practical. And actually this is kind of the diagram that I want to show. Um the whole point is as long as Bitcoin is alive the data that gets posted in the system will be always there and uh you can always run your own node to verify things. So um yeah this is a really cool construction because compared to side chains if your full nodes die or if something happens in side chains you cannot get this property of being always able to sync and you know kind of use your social consensus force to do things but on rollups you inherit the full security of it. So this is on theory very good like right you have this rollup everything is functioning but we we have a problem actually and uh yeah again this is the construction of side chains and roll-ups. So on the side chains you only have the hash on rollups you have the full data of the chain and if something goes wrong on the side chains then you panic and uh it's kind of like you kind of maybe screwed on rollups you have this opportunity to always be able to check things and then verify on your own. they're a better construction. And um this is also another website we've made. It's called c3ausage.com. It's the amount of transaction data that we post on Bitcoin. You can check it out. Like uh there's we also publish the transactions themselves too. And um why do we do this is also another question. One reason is there's a demand for it. Um and also we needed to to do the analysis of it too. But at the end of the day there is a demand for it. Um because the current Bitcoin on the existing chains are not secure enough. Um if you try to use Bitcoin on Ethereum today, what you do is go to your custodian and use it which is a three or five multisig or something. So you trust three people out of five to not to steal your money and this is kind of a challenge. And um all these rollups also helps Bitcoin budget itself too because today Bitcoin fees are low and miners of Bitcoin are also kind of struggling with the budget too. So, it's kind of like we need to help it and we help it by posting these huge bombs into Bitcoin and we pay a lot of money for it too. So, it's kind of like uh we help miners, we help Bitcoin to be more sustainable as well. And um yeah, but the thing is if so, we're one rollup. If you get one more roll up and then another roll up, if you have three rollups live at the same time on Bitcoin, then uh this is the kind of memple space you get per transaction. you pay I don't know 2550 $50 maybe $100. So it's going to be some fun times once everything goes to main network. We're live on test net now by the way. Um yeah and uh this was kind of the reaction. I will I sometimes talk with some core developers of Bitcoin and then say like we're doing this and this is what's happening and then uh you know everyone is shocked but uh it will be okay. We will have some fun times. We're bringing some new construction. Um yeah I did this announcement of rollup is not the bridge right and um then the question is what is a bridge on one end and also how do you move your bitcoin so a common problem is if you hold bitcoin on bitcoin it's just on bitcoin if you hold ethereum for example on ethereum it's just on ethereum but if I want to move my money into a blockchain into another one if I want to move an equivalent bitcoin asset if I want to have Bitcoin equivalent asset on Ethereum, how am I going to do this? Right? If if I have Bitcoin on Bitcoin L1, how am I going to move my money into this construction called Citria and how am I going to use it? And uh today's ways what you do is you give your money to I don't know like five people and then the construction is you trust three people to not steal or you give your money to Coinbase which is I don't know I don't really trust them and uh or like overall the whole constructions today we have is kind of honest majority assumptions. You give the money to an honest majority and then you hope that everything goes right which for now goes right but we see also al also the hacks like in in a two of three multiscults hacked and then you know we got $1.5 billion stolen. So this is a big problem. We need better constructions than trusting some people or majority of people. So what what are the solutions then you know um so the ZK idea is mostly used on Ethereum world today. Oops you got a nice spoiler. The ZK ID is used nicely on Ethereum world today to do bridges. Uh but the problem is you cannot do them on Bitcoin very easily because the Bitcoin itself is kind of problematic. And today some people claim that they have made these ZK trustless bridges. Trustless means you can exit whenever you want type of bridges. If someone tells you they do a trust bridge on Bitcoin, you can now finally show them this image because they're a bunch of clouds. On theory, you cannot do trust bridges between Bitcoin and the other assets. This is crucially important. This is what hurts the image of the industry today actually. So, it's kind of important for me. That's why I mention it twice. Again, you cannot do trustless bridges between Bitcoin and other chains today. But there are other things you can do. So even if you cannot do true ZK verification bridges on Bitcoin script today, you can still do some alternative constructions even in this environment like this is the code to multiply a number by 256 on Bitcoin which is uh a very horrendous way to do it. It's clever but horrendous. And then uh this is some bunch of mathematical stuff with ZK for you to do it as well. So it's kind of like you need very interesting workarounds to do things but still you can do things and one of the things that you can also do is optimistically verifying zk proofs. It's uh a bit tough to explain but I will try to do my best. Um the way to do it is the zk proofs are kind of magical numbers. It's like your um it's you can think of them as keys and then you can build one of them bridges with these zk bridges. It's like you only need one out of n people to be honest whereas on the other chains or on the other systems you need three or five to be honest and functioning all the time. And the idea results from a construction called bitvm. It's like verifying proofs on bitcoin script. This is a very new idea. I think it was started from almost two years ago and uh we and some other teams have been working on this for a very like for the introduction of the idea essentially and uh using this verification idea we can do much secure bridges and uh with this much secure bridges you can move your funds from bitcoin to other chains and it's been built by a collaboration of some companies in the space too and uh what does that mean even okay so this is the problem what does one of What does trust minimize mean? What does best mean? Okay, so here's the thing. Let's say you have some money. Okay, this is uh your money and then you put it into here in the system and then here there's another construction of P3M and you put it here. So if you want to move your money around or if you want to exit in the ideal scenarios what happens is you trust three people out of five in the current constructions and in here in our bridge design you trust only one out of 10. So if you check it here, if let's say three people here dies, then your money is stuck because the money cannot be moved. And uh this is a big what if because you know three people dead or three people got hacked by North Koreans, your money is stolen essentially and you're done. We need something better than this and this can happen. And with the B3M based ZK bridges, we can do this one. As long as one is honest, then the funds are secure. They cannot be stolen. This is a massive improvement because the militia actors are going crazy. The bugs are going crazy. We're trying to limit the damage. And for the first time in the Bitcoin history, this is now possible. We can do constructions like this. And again, no matter what happens to the remaining n minus one, you only need this honest guy. And yeah, we did this one too. So it's also functional on Bitcoin test net 4. It's called Clementine, our bridge design. Um these are our cryptographers in the team. I'm not that smart so my name is is not here. Um and the way it works is the code on the left is a snark verifier and then you divide it into chunk chunks and then if something goes wrong you basically prove or disprove it on Bitcoin. Um and this is the end end result that you get which is nice blocks with bunch of fees that you pay but it is the trade-off for the security. you now get a more secure asset on Bitcoin. Um this is how it looks like on the diagram which even I get confused. So I will do a better version of this explanation. It's this one. So to use these kind of constructions what happens is if you have 10 BTC let's say you give your money into 10 BTC and of multisc and then when you want to get out one of these end again pays you and then they get it back later with CK proofs. This is the construction and this is the best one we could do until now but I think uh very soon we will announce maybe a better version. I don't know we will see it. Um but the whole idea is again the whole idea is to improve this one. This sucks. And the people here also get bored too. Like there are some shady actors in Asia which again I will not name names but uh they have influence here and this actually is the in danger in some setups. We try to do a much better version and uh this is the best theoretical construction we could do and people can do for now. Um yeah so and uh all of these are now possible on Bitcoin today. But what about the future right? I I told you like in the beginning of the presentation changing Bitcoin is very problematic but uh there are some discussions going on what to do. There are some new upgrade ideas to Bitcoin. I think we may get the first one not the second and third one because it's very hard to convince people. Everyone's fighting and shouting each other which uh you know sucks kind of. I I say to people like this is a great idea. OPK is super cool. OPCKP is super cool. And then what Bitcoiner says oh you shitcoiners you you go away. I don't want you. I don't know. It's a permissionless chain. I don't need to ask you what I want to do and uh I do something very technical for the future. So I don't care about it. Um yeah. So my guesses are I think the rollups will be very useful. We will we try to go to mainet hopefully within this year and much sooner than what you expect maybe in a couple of months and uh when we go live the miners will get richer and the fees will increase. So it will be funies to see the amount of reaction we see going to bitcoiners and um it we are trying to make it even more fun through our incubation program called origins. It's um so we can do all this crazy rude goldberg machines that I showed you here. But if no one uses it and if it's not useful then it's literally not useful. We're just going to implement things and then it will die on its own. So we don't want this. We want users as everyone. So the construction we have because of this is um we try to do this through the origins. It's like we incubate visionary founders and developers. We help them pretty much what they do in terms of you know strategies, ideas, constructions, implementations. We try to do one-on-one with them but they need to be as visionary and as ambitious as we are. We have some examples of it today. Uh, one of them is Tanari which you will see them the founder Philip in the next presentation after me. I also wear their t-shirt because why not? It's a, you know, kind of cool feature. Tar is our like a very cool self-custodial platform. It's like today's Bitcoin US sucks. And with Tari, we aim to improve this by at least 10x. You will be able to use Bitcoin in any way you want including sending receiving payments, integrated lending borrowing protocols, Bitcoin back stable coins even which is Nectra uh our one of our primary projects as well and uh we also incubate a DEX which is called Satsuma and you can check them. It's like I kind of put them as examples. We have more coming up. We also have Crest for example and but the whole point is without these applications without these Bitcoin first applications all of this innovation cannot be succeed you know cannot be successful. So the idea is we we were lucky to have people as ambitious as us and uh we try to support them and we try to work together on that end and um yeah all of these discussions will be fun until the quantum computers come because the moment quantum computers come then Satoshi's coins will be vulnerable and then they will be spendable and uh it will bring some fun discussions among everywhere because if someone spends them what are you going to Yeah, it's the every day looks like this for me and uh I hope the presentation didn't look like this for you. If it did, please catch up with me on the exit like we can talk after Philip's presentation obviously. Thank you. Yeah, if anyone has any questions, one question I can take. I hope I hope it was that you know like informative and fun that there's no questions but it's also possibly it was too boring or complex. I don't know but I did my best also feedback this one is broken a bit. &gt;&gt; Yeah. Yeah. &gt;&gt; Yeah. Thank you very much then and I hope you enjoy for the rest of the event.
