# Illium│Zero Knowledge Blockchain - Chris Pacia│ETHDam 2024

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 23:21
- Watch: https://streameth.org/watch/yt-qJPMbx9QS2M
- YouTube: https://www.youtube.com/watch?v=qJPMbx9QS2M

## Description

Join Chris Pacia, Founder of Illium for a talk: “Illium: Zero Knowledge Blockchain”. Learn how they build a blockchain with full zero knowledge coin transfers and smart contracts using recursive snarks.
https://x.com/ChrisPacia https://x.com/illiumcrypto https://illium.org/ 

Sterling Schuyler - MC of ETHDam, copy and content writer for emerging fund managers & crypto enthusiasts.

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 
ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/

Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

## Transcript

[Music] all right thank you everyone for being here next up we have Chris all right thank you guys um I can give you a little introduction of me um my name is Chris paccia I've probably been around in this space for quite a while now it feels like I think I got into Bitcoin like 2011 um I worked on early on I worked on um open Bazar I was lead developer for open Bazar I don't know if you guys remember that project um I know Amir mentioned it last night on stage it's a little bit of a throwback um and then I was also pretty kind of heavily involved in the scaling Wars on on the the wrong side of that um back in like 2014 through 17 and I was one of the handful of developers um who kind of got Bitcoin cash off the ground um so I want to talk about a project I've been working on for a couple years at this point called iliam um it's a new cryptocurrency the way I'm kind of thinking of it is it's sort of like you know if we had to design Bitcoin or really any cryptocurrency from the groundup using 2024 technology what would that look like and so kind of going to walk you through what that looks like in illiam and um you know why I think that this is uh at least interesting to say the least so um you ever since you know I got into Bitcoin there were probably I we we all knew there were shortcomings early on right and I would say at least these that you could probably add to this list I would say these are at least the big ones um extensibility you know if if I were designing Bitcoin in 20 2009 I wouldn't have thought to add a scripting language at all I think that was pretty amazing that Satoshi had the foresight to do that um but you know of course unfortunately it wasn't um as flexible as you would like it to be there wasn't like a whole lot that you could do with it um you know privacy of course being a big one um with all of our transactions being public then we have the UN you know the zeroc comp issue with the transactions not really being secure and then even after they receive a confirmation um you know you have to wait to receive a certain level of uh confidence before you can really accept it and then of course we have the scalability problem so you know extensibility was sort of the first nut to be cracked with you know ethereum came out you know not that long after um and so you know that's you know pretty much a solve problem um privacy um I'd say it's I have a little shoulder shrug here um you know we had coins early on some coins incorporating like mixing into the protocol in fact you know I worked uh when we worked on bitcoin cash we worked on some really Advanced mixing protocols like cash Shuffle and cash fusion and stuff like this you have Monero um added like probabilistic privacy into it and then of course zcash kind of did it when I consider sort of be the right way by using ZK snarks to kind of you know fully encrypt all the transactions um but zcash and most other cryptocurrencies to follow that have had that type of privacy historically have not been able to extend that to Smart contracts or any kind of scripting language or anything like this so you know the Privacy is usually just for basic transfers and nothing else and then the speed of the transactions um we've gotten better at that with a lot of proof of stake uh coins are somewhat fast to finalization although depending on your use case like if you're trying to buy something in person um you know it still might not be sufficient um um and then you have I'm I'm kind of a bit of a fan of the Avalanche consensus algorithm we'll talk about how we use that inum here in a little bit but um you know I'd say Avalanche is probably the one cryptocurrency that has that level of like almost instant finalization to it but there's trade-offs with that and you know so I have the shoulder shrug here because it's not fully solved in terms of like can you achieve that level of fast finalization with without having to have any of the negatives or any of the drawbacks to it and then you know scalability we're still here um so this is kind of the landscape of at least kind of where I see cryptocurrency has been and so I mean we're in 2024 Bitcoin came out in 209 and we still don't have any cryptocurrencies at all that are able to do all of these things okay which is pretty amazing because these were the things that we kind of all identified very early on we could improve upon and we're kind of still not there at at least not there in terms of you know it all being done in in a single cryptocurrency so um I want to talk a bit uh here about primarily the privacy and extensibility kind of how we're going to do sort of smart contracts and scripting in a um in zero knowledge in ilam and we're going to give you kind of a little bit of an overview hopefully you guys will be able to follow along so um ZK snarks um hopefully you know how you know what the is we're talking this is a kind of a programmatic zero knowledge proof where um we're essentially going to create a function and you're the prover and verifier are going to have prior agreement about what that function is could be anything we want it to be um and then the prover is going to prove that he knows some inputs to that function that make the function produce a certain output without revealing what those inputs are okay the function in our example here would be fubar and if the interface was just this simple it would be really nice and easy to use ZK snarks but unfortunately it isn't um yeah um so we have we have issues with ZK snarks um that have really kind of prevented us at least up until very very recently from kind of deploying them very widely um so when you're writing these functions like that Fubar in the previous example you're not writing in Boolean logic like you would in a normal computer program instead you're having to write in arithmetic logic in basically trying to formulate your statements in terms of like you know mathematical Expressions which is kind of like worse than trying to program an assembly okay like much much worse um we have uh an issue with loops so normally in normal programming you have a loop you can break out of that loop at any time you don't have to the loop doesn't have to continue going um you know after you're done with your computation but in ZK snars um you can't really break out of a loop so what you need to do is you know let's say you're doing something like trying to verify a a miracle proof you might need to you know sometimes that proof might be very small if your set is very small and then other times it might be very big if your set's very big but in the cases where your set is very small you can't just skip all the other iterations of the loop that you don't need instead you have to calculate what is the maximum number of Loops that I might need what's the maximum size of my set for example then every single time you need to do that maximum number of Loops so your computation can blow out pretty quickly along those same lines if you have IFL statements um they you have to execute both sides of the block right so if one side is a very small amount of computation and the other one's a large amount of computation you're going to be executing both of them and you're going to have to bear that expensive cost so um it's definitely not like normal programming and it kind of limits what we can do with it so in recent years and this is like very recent stuff like the last year or two years people have been putting in a lot of effort to try to make systems where we can use ZK snarks more like regular programming and so the one that I use here in iliam that I'm going to talk about is called um lurk um lurk is a turn complete programming language it was developed by protocol Labs I don't know if you guys they're the same ones who make ipfs and filecoin the lead developer for lurk his name is um chimed Kang I believe if I pronounce that right and um he wrote the uh ZK snark implementation for filecoin which um sounds like it was a nightmare to create and um so he kind of took those lessons that he learned from writing that in filecoin and applied it to lurk so the the basic idea here what we're looking to do is we have in in computer science we have this concept of like a universal turing machine something that can uh kind of execute any sort of computation that we want what we would kind of like to have is a universal circuit where we can uh create a proof for any kind of computation that we want and so part of the solution to this um has been with some advances in cryptography in recent years with the recursive snarks and the uh incrementally verifiable computation uh the the basic idea here is we're going to have a um a circuit that we're able to kind of sort of Step through our program and go through that circuit multiple times in order to execute our program so it it then does sort of beg the question like what should that circuit look like because we do have these still have these underlying issues with the the performance of the ZK snarks and the optimizations so we want our circuit to be kind of as minimalist as we can make it um you know for performance reason so what is kind of the minimalist type circuit that we can come up with for this like universal circuit concept then we have this real big throwback to 1960 here recursive functions of symbolic expressions in their computation by Machine by McCarthy at MIT where he's introducing lisp right the Lis programming language so lisp is a very very minimalist programming language that I it creates a um you have a cek machine where basically there's a you take an input and you have a like very minimal State transition it produces an output and you can kind of recursively step through your program that way until you can you know execute the full program and so something like this is this where this is basically what lurk is implementing inside the circuit as kind of a very minimalist form of a programming language so I asked chat GPT to give me an diagram for a cek machine and and this is what it came up with which is not even remotely closed but um but I mean you can think of it as we're going to have a program we're going to break our program up into multiple steps and for each step it become you have the input into to our circuit we perform some computation we get an output that output then becomes the input to the next iteration of the circuit so when we create a program this is a little program um creating a um calculating a Fibonacci Sequence um we can this in this example we've got 89 iterations through the circuit so we're going to step through our program that iterate through our program this way and at the end result we're going to get a single succinct ZK snark proof Pro that proves the correct um output that the the inputs that we have to this program produce a particular output um the nice thing about this is we're we're back to using Boolean logic again um we're not using um you know arithmetic logic loops work the way you think they would if you you can break out of a loop you don't have to calculate what is the maximum number of Loops that I need to make if statements work like you think they would if you have a expensive computation you can just skip that um you know in the like else block you know or whatever you only execute one side of that block rather than all of them so basically we're back to normal computation again so how do we use lurk and ilium uh all transactions have a ZK snark proof attached to it uh the proof uh this is utxo model by the way the uh we prove that the inputs that we're spending in our transaction exist in the set of all outputs in the chain we prove that the inputs have not been previously spent we prove that the output amounts do not exceed the input amounts and we prove that the spender is authorized to spend the coins and we do all of this in uh zero knowledge so basically what this is is we've just recreated zcash essentially right this is very similar to how zcash Works albeit we're using a little different cryptography under the hood but same concept but can we go a little further so in lurk we have um there there's this kind of built-in concept called functional commitments where any expression you can basically get a hash of it for all intents and purposes so here we've got a function f ofx we can call that commit function to get the hash of it and then later on we can you know open it up and execute that function um just by calling this open command and in this case you know we have an output of 122 and we could prove that we know some input which is the number five in this case that makes the output um that produces that particular output without revealing our input so with this concept of functional commitments if you think about it I don't know if your brain goes the same place that mine does but it's reminds me quite a bit of the pay to script hash in Bitcoin so in Bitcoin uh some address types um have this their pay to script hash address you create a script in Bitcoin and you take the hash of it this hash becomes your uh payment address essentially so your payment address that you send coins to is just the serialization of this hash and then when you want to spend the coins in Bitcoin the spender has to provide the script to as part of the transaction and the full nodes on the network will verify that the script uh the hash of that script matches the hash that you committed to in your address if it doesn't it's an invalid transaction so basically we do the exact same thing in illiam where all addresses are pay to script hash addresses where the script hash in this case is a lurk functional commitment where the user is committing to any kind of custom uh locking script if you will unlike Bitcoin however this is a turn complete language and you can do any kind of computation with it that you want and just like with Bitcoin when you go to spend your transaction the spend has to provide the um the script and we verify that the hash of the script matches the hash that was committed to in the address but all of this is done in zero knowledge so we're you unlike Bitcoin we're not revealing this script to the network okay so all of this kind of remains hidden um this example here is particularly interesting this is a multisig script on illiam um privacy coins have typically had an issue with multisig um they can do basic transfers pretty easy but then you start trying to say well how do I do multisig and it starts to become a mess like some of them have to do uh like like a schnore aggregate signature we have many rounds of communication and the user experience really just breaks down but with this we can because we can create any script we want we're kind of back to multisig kind of the way we're all familiar with it which is pretty great but can we do more um so when the script executes we have these um two parameters private and public we pass into the script as it's executing these arguments here that allow the script to inspect all the private and public data that's part of the transaction and then make decisions whether to lock or remain locked based on what this data is and the the private data and public data it contains all the data not just about the current input being spent but all the other inputs and outputs on the transaction so you have basically full covenants that you can do things like this script is pretty much saying like these coins can't be spent unless they're being sent to this particular address okay so we're just putting a restriction on where the coins can be spent we can one up that and take it just a little bit further um and we can make what I would call a recursive script and um now this isn't a recursive function because we can put a recursive function just inside here and just iterate over that as much as we want a recursive script in this context is um every time is what this is doing is it's saying in order to spin from this script it has to go back into the exact same script okay uh can't go to any other script so you can think of this as sort of every spend of this utxo is an iteration of a loop essentially and in every iteration I can decide which one of these methods I want to call so this is starting to look very much like a smart contract where we have methods it's deployed on the network and we have methods that we can call and from there you know we can just add state to it so outputs can have state attached to it they can read the state they can mutate it they can manipulate it you can in in this little example I have a method called increment counter which just reads the state and increments an integer so basically we have all the components of a smart contract we have a script that's deployed on the network that has methods associated with it that has State associated with it that you can make repeated calls to it you can manipulate that state contracts can interact with other contracts they can um they can make function calls on other contracts other contracts can call their functions or read their state so we've got everything and all the components of a smart contract but all in zero knowledge and all without revealing any of this information to the network so when we look at a transaction Over The Wire this is really all you see and there's really no identifying information here so you don't know is this a basic transfer is this a smart contract was this a token right we could be sending tokens around the network instead of you know iliam coins we don't know because it all just looks like an encrypted blob to anyone looking at this um another nice thing we see there's a fee attached to this this fee is just um similar to bitcoin it's just there to prevent spam it's not a gas fee so there's no we don't have a need for gas because all these transactions are going to verify in constant time so it doesn't matter if this is a basic transfer or whether it's the world's most complex smart contract that they all take the same amount of time to verify and because they're taking the same amount of time to verify we don't have to do what like ethereum does and start charging fees per op code and things like this where the more uh complex your smart contract is the bigger the fees you have to pay okay it's all constant okay so there's more to iliam than this but that's just kind of an overview of how we sort of achieve this zero knowledge property and uh build a completely private blockchain so what do we have extensibility yes pretty much anything that you could do on a traditional smart Contracting platform you could do in this model privacy right all transactions look the same um you can't tell one from another there's no private data being leaked on any of these transactions fast I did mention um briefly mentioned Avalanche doesn't have any um relation to the Avalanche Network the avax uh who's the sponsor of this event uh except that I do use a custom version of the consensus algorithm that I wrote with some tweaks to it to address some of the kind of perceived um you know maybe some security trade-offs that they make so I could elaborate more on that later if you ask me about it and then scalability haven't really done anything new with scalability but a lot of The cryptographic Primitives that are in place could potentially be used as a foundation for things like proofs of consensus and succinct blockchain because all the tools to do that are still there so um we have an alpha Network live right now if you want to test it out there's a a faucet where you can get some coins hoping to move to a more formal test net middle of this year or so and depending on how all of that goes maybe uh you know main net launch later this year early next year okay thank you awesome thank you so much Chris and uh now if we can have the lights up so we can see everyone's beautiful faces lovely do we have any questions what cryptographic backend do you use for zero knowledge Nova Nova yeah oh very cool yeah uh we should talk yeah it's not um I should say lur um lurk is using Nova and um so I'm using lyric so by extension it's it's Nova um other than kind of you know following the development and the pull requests and everything it's uh I'm not like super deep in my knowledge of of how it works but yeah but I can talk about it yeah yeah um what's what's the catch uh no solidity compiler probably yeah yeah I mean if you someone could probably make a compiler that could compile solidity in into this um you know it's just the the model's a little bit different so that I mean I don't know if it would be like it's not going to be like a one to one one to one port of a contract directly over to this but yeah awesome do we have any other questions no awesome well thank you again so much [Music]
