This is a massive breakthrough for post quantum blockchains. Threshold signatures are a fundamental building block for the secure use of a blockchain and until now, there was no solution for how to make them with a post quantum scheme.
Ethereum will be post-quantum secure and it won’t have to give up application and consensus level security to achieve it.
Post quantum distributed validators when?
Show more
Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens?
In this new lecture, Stanford cryptographer
@danboneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing.
The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired.
00:00 Why blockchains need to prepare for quantum computers
03:05 Why Bitcoin may bet on hash-based signatures
06:25 The “big footgun” in stateful signatures
08:58 A quantum-safe signature that takes one billion hashes
14:13 Inside SLH-DSA’s virtual tree
20:30 How Bitcoin and Ethereum could make the switch
23:48 What happens when a wallet loses its state?
32:47 Can threshold signing survive the quantum transition?
36:39 How to hide lattice cryptography from the blockchain
38:49 Why threshold one-time signatures seem impossible
45:36 How context prevents forged signatures
49:37 The forgotten idea behind Winternitz signatures
54:50 Turning one-time signatures into threshold signatures
1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks?
1:06:26 Abandoned bitcoin and Satoshi’s recovery problem
Show more
This inaugural CFTC innovation advisory committee meeting is amazing to listen to. Kudos to
@MichaelSelig and team for the openness and approachability. Going on two hours of founders and leaders expressing their gratitude to the commission for the newfound approachability and willingness to regulate sensibly contrasted against their lived experience of persecution under previous admins. Super encouraging to hear and I look forward to seeing what comes from it.
Show more
Pluto, the DVT client written in Rust and developed by
@Nethermind, is in the final stretch of becoming production-ready.
Thanks,
@OisinKyne,
@Obol_Collective, for working together on this!
Institutions care about risk management. Ensuring that their customers' funds are not at risk to any one single anticipated failure, nor to one software provider is a requirement for adoption.
@BitcoinSuisse_ are one of the OG custodians and staking providers. They have over a decade of experience to prove that they understand risks in Ethereum, and what they mean for their customers, auditors, and regulators. They went all-in on Distributed Validators, and before long all other institutional staking offerings will too.
Show more
Awesome news! As one of the first institutional staking providers fully switching to Obol, having an alternative client eases many technology risk discussions with regulators and auditors... 💪
Can't wait to try it out!!
Show more
I don’t think we should be sacrificing censorship resistance for the staking ratio
CROPS > Ultrasound money
"We don't really have 100 billion dollars of security, we really have 5 million a day"
EIP-8363 critic Oisin Kyne on the censorship risk he says the proposal underrates
"The main reason I'm not happy with the current proposed curve is this idea of it going to zero. There's more than one metric that matters for Ethereum security. The one put up front is finality, we have this amount of ETH that will be guaranteed burned if a transaction ever becomes undone, and I agree the research says tens of billions of dollars getting destroyed is probably enough disincentive"
"Where we diverge is that's not the only thing that can go wrong. We also have this risk where the people staking their ETH decide to be particular about what they include in a block, saying we're only going to attest to blocks that do what we want, that don't have people we don't like in them. If they do that there's no penalty, so long as there's 51% of them or more doing it, it costs them nothing"
"The plan we have is, oh no, maybe we'll coordinate as a group and destroy all their ether for doing so, but I think that's a very big risk to hedge all of Ethereum security on. I don't think we should be sacrificing censorship resistance for the staking ratio"
"The fancy word is the Nakamoto coefficient, which comes from Bitcoin, this idea of how few orgs make up 50% of hash power or stake weight. We don't really have 100 billion dollars of security, we really have 5 million a day at the current curve, and depending on where the equilibrium lands it might be a million dollars a day or less. I don't know if that's enough to protect a trillion dollar computer"
Show more
Catch me,
@owocki, and
@jdetychey on
@laurashin's Unchained Pod to hash out Ethereum issuance in the coming minutes!
Six researchers proposed burning Ethereum's staking issuance to zero. Aave, Lido, Ether[.]fi and SharpLink lined up against it within 48 hours.
@jdetychey co-wrote it.
@OisinKyne runs a staking company that opposes it.
@owocki wonders how the community builds consensus
They all join me on the show today at 1pm ET
DON'T MISS IT! Tune in 🎧
Show more
There's a lot of bluster about sockpuppets and deleting comments in the issuance debate. Lets not lose sight of the actual outstanding questions about the proposal and ensure they get researched and addressed such that the community can have an informed debate about Ethereum's security.
- None of the issuance analysis includes costs, when you do, this proposal is not good for solo stakers, it makes them worse off both nominally and relatively versus other types of stakers.
- None of the issuance analysis accounts for the fact that ~97% of the network makes a real rate of return on the existing curve no matter the equilibrium because they are not staking only their own eth. This happens on both ends of the spectrum, the extremely large professionals, and the extremely small homestakers. Only the ~1% of solo stakers are focused on in the analysis so far (without their costs being accounted for which significantly alters the analysis).
- No other large PoS chain has runaway staking. These chains all have far larger dilution, and far less penalties for PoS failures. It tracks that Ethereum's equilibrium on this curve is likely lower than them (so <60% imo). I am not aware of a reason why in Ethereum, delegators will take more risks, for less rewards, while there are also better alternative uses for their capital (including simply protecting it in a cold wallet for the lowest dilution in the ecosystem).
- Ethereum does not have $100b in economic security, its likely under a million dollars per day. This proposal could drive it down 5-10x from there. There is no analysis as to whether this is likely enough of a security budget to protect Ethereum from a concerted attack.
- We have no agreed upon tracking of the network's Nakamoto (nor gini), these are measures of how easy it is to take over the chain, or how disastrous a failure of a particular multi-sig, smart contract, or custody platform might be. We should first be tracking them, and secondly we should be consensus-seeking on what is a sufficient number for them. I believe a Nakamoto of 10 should be the minimum tolerable floor. (and that gini needs to go down not up as it has been)
- Ethereum's security (Nakamoto) has been falling for ~2 years as the chain centralises. This isn't only due to the current curve, the delegation rate has been pushed far lower in this time, and the illiquidity penalty of native staking is forcing delegators to choose the most liquid staked eth offerings. We should be trying to improve the security posture of the chain rather than exacerbating the problems it faces by making the majority of delegation options non-viable. Correlated downtime penalties, a burn2exit feature, and boosted whistleblower rewards on key compromise, could all push the mean preference to solo stake or delegate stake to the long tail of operators, which would improve the chain's security (nakamoto) rather than hurting it.
- Stake quality is more important for Ethereum's security than stake quantity. The amount of operators it takes to control the chain is what we should care about, not the viability of a finality reversion event. We should not be damaging the chain's security to push a ratio by likely less than 20%.
- Without a cost model of stake, we haven't a good understanding of where equilibrium might be under the proposal (nor the existing curve). Backing into it from costs, I think 60m eth could be staked for as little as $5m per year by the biggest operators (0.002% issuance per year). If you account for MEV, non-ETH perks given to delegators to stake, and the value in controlling Ethereum, I think its very feasible for equilibrium under the new curve to be 45% or higher. An issuance that low would make all but the largest orgs non-viable.
- Making Ethereum more centralised is more likely to re-value Ethereum in line with other centralised chains than it is to be rewarded with an increased valuation. Ethereum's value comes from its credible neutrality and its decentralisation. Changing issuance in the proposed manner hurts both.
- We are a couple hard forks away from Real Time Proving, and a switch to Post Quantum Ethereum. The cost model for this chain is vastly different than the one we have today. Proposing blocks will take a server rack worth of expensive GPUs, and attesting with a Post Quantum signature scheme is also more costly than the existing scheme. We should be forward looking in this regard, and make sure we're making a change that allows block building to be at least modestly decentralised. Taking issuance to near zero and not making any allocation to the costs of proposing will lead to a world where as few as two entities can afford to eat the costs of producing blocks on Ethereum. We should not be re-doing the issuance model every couple years. Lets plan for the moment validation changes markedly, and lets build consensus for a change that best suits that future architecture. Forcing through a fast tracked change for a risk of dubious downside and dubious probability is not good for the network's reputation.
- Cutting the security budget and losing a large amount of the operator set makes Ethereum less CROPS. Ethereum's scaling roadmap depends on having large amounts of independent operators on the network, to ensure its Data Layer remains available, and to ensure fork choice is not compromised. We have to decide should Ethereum's roadmap take decisions that favour its CROPS nature, or one that favours ETH's disinflation. I don't believe we should jeopardise the former for the latter. A maximum of 1.5% dilution is lower than almost every asset in the world, it is not so high as to cause CROPS issues imo, sub 0.3% is a bigger concern.
These are not all of the concerns raised about this proposal, and some of these have been more addressed than others by proponents. The impact on DeFi and the Ethereum economy is also notable. I'm just flagging 10+ issues that are getting drowned out by infighting over the legitimacy of how we moderate this contentious debate. Lets focus on facts over feelings, and make a concerted effort to gather first-hand data and develop believable models, so that we can make informed decisions around what we think 'enough security' might look like for the chain on a multi-decade horizon. Thank you.
Show more
When we look back, securing your customer’s stake on multi-sigs instead of single hot private keys will look obvious in retrospect.
Take your staking security seriously before you wish you did. Adopt distributed validators.
Show more
Blockdaemon is migrating its Lido staking operations to
@Obol_Collective Distributed Validators, operated on geographically distributed nodes across multiple Ethereum clients, furthering a more secure, decentralized, and institutional-ready staking ecosystem.
Show more
It was a very obviously human written comment. It was a very intelligent comment. In fact, I would say one of the best comments on the entire proposal and it is hardly surprising that people are going to spin up accounts specifically to comment on this proposal for the first time because it is a highly highly contentious proposal, so people are very shocked by it and of course, they're creating accounts to comment on this forum because they've been told this is the only place where feedback will be considered, and they've simply never had occasion to comment on something before, because nothing else has been this contentious before.
Show more
Solo staker's taxes are a supposed reason for capping issuance. Proponents argue that solo stakers would be better off under the cap than a high staking ratio where their rewards come with higher dilution.
I think this argument falls apart when you model how much it costs to solo stake, which is unfortunately a lot. Electricity, hardware, internet, downtime, and the headaches of DIY are not free.
At a 70% staking ratio on today's curve (higher than I believe we can reach for the sake of argument). A 32 eth solo staker makes ~1.9% APR, ~$1167 gross. Operating costs are $537 (calculator here: taxes
@30% are $350. You make $280 per year net. (0.46% APR).
At a 40% ratio under a cap (lower than I believe we will reach for the sake of argument). You make ~0.8% APR, ~$491.50 gross. Operating costs are still $537, taxes are $147.50. You net to a $-193 loss. (-0.31% APR)
This effect applies even if you pump your eth stake way up to minimise the fixed operating costs. You have to argue about eth dilution and what that might do to the eth price because of stock to flow models, or make generous assumptions about why delegators making 0.72% APR for no effort will unstake, to try and make the math make sense.
What am I missing?
P.S. You make $1050 (1.71% APR) and $442 (0.72% APR) under these options if you delegate instead of solo staking. We definitely need to solve the disparity in taxation, and to make solo staking more economical, but this EIP does not seem to be beneficial for solo stakers as it claims to be.
Show more
The proposed issuance cap is designed to price out the lowest revenue, highest marginal cost stakers. Not only does it lower the revenue from staking to near 0, it especially penalises the weakest stakers most because it burns eth equivalent to perfect participation, not what you actually achieve. The 98% uptime solo validator gets even less rewards than the 99.5% professional, on top of their higher relative costs.
It is a bottom up filter for stakers, and will lower Ethereum's security budget until it fails and Ethereum gets compromised.
Ethereum should be focusing on becoming CROPS not ultrasound money.
Show more
@sheffieldreport > Positive nominal yields, managed but positive inflation (we are sub 1% already, basically on par with BTC) and positive real yields are how you create sound money.
This is the “Eth is money” argument I can get behind.
I agree with the whole post and subthread!
Show more
This is the most measured and fair explanation of the failings of the issuance debate to date. If you want to see what's yet to be addressed, see how this thread evolves (and ask the cap authors to address them asap).
These concerns have been raised consistently for 2+ years, and they are still yet to be addressed, we are not ready to move forward with a proposal to change issuance without a proper data driven deep dive into these challenges. Forcing a change through without measuring the problem and discerning whether its real or theoretic, and without ensuring the cure isn't worse than the disease is a recipe for disaster.
Minimum viable security that doesn't mean 'anti-fragile as fuck' won't cut it. Social slashing is not a realistic threat right now and won't protect us from a centralised validator set. Ethereum is valuable because its a permissionless, decentralised, world computer, not because of its issuance rate. Sacrificing the former for the latter, will dramatically devalue its value proposition in my eyes.
I also don't believe the current curve is sacrosanct, but I think a constrictive curve is more dangerous and worse than the status quo. I think the burden of proof to say otherwise is high, and I don't believe that work is yet done, nor will it get done in time for a decision on H-star. I'm happy to share what I know about costs and staking economics, to help us pathfind to a future with a long term resilient and secure Ethereum, and right now I think that means choosing CROPS over hard money for the network.
Show more
I think that EIP 8361 tries to do too many things (increasing the moneyness of ETH, pre-empting remotely possible future decreases security due to overstake, protecting solo stakers, etc) at once and in my estimation will mostly do the opposite. I honestly believe that issuance change is too complicated to treat with this urgency, that the far-future concerns are drastically overblown, and it's very bad timing to introduce such a divisive proposal, especially in such a way. It has also been pushed last minute in an attempt to squeeze into Hegota (still subject to the EIP Inclusion process), even though potential issuance changes had been communicated as per the current strawmap to be slated for I* at the earliest. IMO, this proposal lays Ethereum's hard-fought uniqueness (real decentralization and neutrality) at the sacrificial altar of ETH as money, camouflaged against an insufficiently scrutinized concept of "minimally viable" security spend. Unfortunately, it also doesn't come to terms with the fact the moral hazard of a "too big to fail" event is not necessarily mitigated by limiting staking adoption, only displaced, as ETH seeking yield will mostly just go to more risky and likely custodial solutions, in my estimation thereby increasing the likelihood of such an event.
Apart from misgivings around the governance and consensus (or lack thereof, given its wide-reaching scope and implications) process around this proposal, I find that the selective supporting research is too theoretical and is lacking from a macro, micro and behavioral economic modeling perspective, especially with regards to 2nd and 3rd order effects. This applies to especially to two aspects:
1) one of the central theses around the urgent concern about the stake rate (which is lower than most other PoS networks which are mostly fine) that also hinges on the idea that just because issuance is positive at 100% stake then there's necessarily incentive to do so (ignoring years of economic history and literature which illustrate that demand is actually expressed as a complex function of utility, and not merely purely theoretic expected value, and strong contra examples such as USD as cash/savings vs T-Bills); and
2) on the effect of drastically reduced issuance (and real validator rewards) on the resulting validator set, and the negative externalities that will be born out of this material change in monetary policy (and possible further changes which might be required for correction).
Due to the new proposed curve a very real possibility of a sustained equilibrium at or near 50% of Ethereum staked with 0 nominal (nevermind real) yield is now possible, which would essentially be a death-knell for the security of the network, as node operators and staking protocols which prioritize expertise, decentralization, and expensive know-how are priced out and large, centralized, minimal-cost parties take over the operation of the overwhelming majority of the network's validators. Unfortunately, at current ETH/USD prices, such a scenario isn't even necessary for this proposed issuance change to lead to a large consolidation of the operator set, which would drastically lower the network's Nakamoto coefficient and thus its resilience.
In an eventuality where few actors are allowed to control one of the fundamental levers of the network -- determining its security (i.e. control of fork choice) -- by simply being able to offer staking at break-even or at a loss for long enough to price most other actors out of the market, what will be left of Ethereum's neutrality when the only recourse (now made ever-more necessary) will be a substantial and messy social slashing? Not much.
I'm not against an issuance reduction in general; I am against an issuance reduction without centering on the core questions, and giving the community adequate time, tools, and analysis to be able to consider the bevy of implications. To me these core questions are:
* What is the right amount of economic security given that we want Ethereum to be the centerpiece of onchain finance? A minimum viable security approach here doesn't cut it -- nation states don't think this way and the largest financial network in the world shouldn't either
* What is the effect of the market structures generated by any issuance curve, the relevant expected prices of operation (eg in ETH/fiat terms), and the effect of issuance changes -- and their consequences -- on demand for the asset, especially on the underlying validator and node operator set?
* How does the network retain its neutrality, utility, and demand, if social slashing is utilized not in the same way that nuclear arms are (as a last-measure deterrent) but rather as as the go-to solution for problems created by the network's own security paradigm?
* Why do we honestly believe that the terminal staking rate is in the high double digits? What practical economic modelling or historical indicators are there to point towards this?
* Are we okay with a hyper-centralized validator set just because if they misbehave we will socially slash them? Why have PoS at all then and not just go to PoA or PoG?
Show more
Ethereum's security is not how much eth is staked, its how hard it is to control fork choice. A curve that goes to 0 at a reachable level will allow the biggest and most price insensitive orgs in the space to price out the vast majority of rational actors, such that they can control who gets to use Ethereum going forward.
The original curve deliberately prevents this, by increasing issuance as staking ratio goes up, making it impossible to price people out. Cappers will tell you this was a bug and mistake, it was not.
Ethereum should focus on CROPS, not wanting to have a security budget crisis faster than bitcoin does.
I'll share more about this in the coming days and weeks, but tl;dr: decentralisation > hard money.
Show more
Three locations, 5 different client types, no-downtime upgrades; this is what a professional staking setup looks like. With correlated downtime penalties coming in 2027 (🤞), high availability setups with client diversity and chain split protection will be a must for institutional stakers going forward.
Show more
Some detail on the setup, now live with the first deposits in: six Charon nodes across three sites, two per site. Duties need four, so a full site can go offline and the cluster keeps signing.
The same margin makes updates rolling instead of scheduled downtime.
Show more
Correlated downtime penalties got their first update in ~2 years as they're considered for inclusion in Hegota! Tl;dr:
- This EIP increases downtime penalties temporarily if a large amount of the network goes offline together. The goal is to penalise all stake piling onto the same few operators and datacenters, which has become a significant issue over the last 5 years.
- The original design was a tiny blip of penalties, not enough to change behaviour, nor enough to justify the dev effort. Now the penalties can scale up to 128x from the baseline penalty.
- This is still pretty small in terms of your principal, but can set you back weeks or more of rewards if you stake in a centralised manner that has an extended outage. (Worst case is ~0.38% of principal per day if you and a third of the network are offline, which is more than a month of lost rewards)
- Focusing on the source + target vote ensures short term failures in block production won't trigger this penalty.
- This penalty caps at 33% of stake offline, after that, its the existing inactivity leak that punishes you further, (which has a lot more teeth!).
Check out some example payback times, and a new vs old graph to show why the update is needed.
Hopefully the Core Devs will include EIP-7716 in Hegota, and Ethereum can start to value its decentralisation rather than taking it for granted before its all gone. Ask your local core dev to SFI EIP-7716!
Show more