pull down to refresh

tl;dr - a p2p exchange (bitcoin <-> stablecoins) that is built on a statechain (mercury layer) and that uses nostr for identities and offer data. There's a video at the end of the tweet.

we built a bitcoin dark pools prototype 🪄

tl;dr - we built a privacy-preserving, bitcoin exchange using @mercurylayer, nostr, and a zk-execution network. the bitcoin transfer is completed offchain via a blind co-signer. the stablecoin network only reveals hashes of inputs and outputs, no amounts or user addresses. orders are matched peer-to-peer using nostr identities. exchange is atomic & privacy-preserving. deets:

this protocol is built on the following:
  • statechains, a way to transfer ownership for bitcoin utxos offchain by reassigning spending keys
  • private stablecoin network with flexible zk-circuits/contracts that lock funds to a specific sha256 hash
  • a blind co-signer that facilitates ownership transfer for bitcoin utxos offchain per a specific order
the exchange builds upon mercury layers’ latch protocol. the seller locks their offchain "utxo" into an order that they create. the order specifies that an offchain transfer to the buyer’s offchain address should occur after buyer & seller commit to it. an order with a hash is created.

the order hash is then used to lock stablecoins on the zk network. meaning, the buyer must lock their funds into an escrow contract where the funds are only claimable by revealing the preimage for the order’s sha256 hash (or they refund the buyer after a timelock).

after these stables (or any other shitcoin, tbh) are locked on the zk side, the buyer submits the tx hash to the seller. after verifying that stables are locked in escrow, the seller calls the co-signer to unlock the transfer to the buyer. after verifying that the seller has committed this, the buyer also calls the co-signer to unlock the transfer. the co-signer reassigns the statechain multisig spending key to the buyer and tweaks their keyshare. the co-signer then deletes their key with the seller.

after the statechain transfer, the co-signer then reveals the preimage for the order to the seller. the seller uses that to claim the stables on the zk network out of the escrow contract. swap completed. buyer trusts signer deleted their keyshare up until the point the exit the statechain back to bitcoin.

we’ve taken this swap protocol and developed an RFQ protocol using nostr identities. in the exchange application, users create a nostr identity and submit buy and sell orders. only their npub, and the amount of their respective order, is revealed. no bitcoin addresses or other pii is exposed. when a user finds an suitable offer in the orderbook, they submit an encrypted firm quote with exact amounts and prices. only the counterparty in the trade can decrypt this message.

from an onchain perspective, there is no onchain bitcoin transaction. on the stablecoin side, zk magic only see hashes of inputs and outputs publicly available. you can’t even discern which token was involved in the trade.

the co-signer is blind and dumb. validation is done peer-to-peer between countparties. co-signer only signs when its told to.

this is a demo and opinionated design. in our view, it’s extremely privacy-preserving and makes nice tradeoffs wrt user self-custody.

we’ll building more optimized versions that make different tradeoffs, but wanted to share this example. all code will be open-sourced in the future.

YAY!!! 🥳 big fan of mercury layer!! But I guess they are just using their technology.

Got too excited

reply

Why would I want to exchange my clean, pure sats for dirty stablecoins? Can I spend them more easily on rent, groceries and insurance?

reply

i hear tell that stablecoins are easy to spend in places like Venezuela and Argentina, perhaps even easier than bitcoin?

I was thinking of it from the perspective of a user who wants to buy bitcoin more privately. You could buy stablecoins on a kyc'd exchange and then potentially use this (whenever it is actually launched) to turn them into more private bitcoin. Would it have less risk than using Bisq? Or be easier than finding an employer willing to pay in sats? Not sure.

reply

I don't think that switching to another coin adds any privacy. Sure you can do a robosats USDT trade... but you still have the same fiat amount to your name with the CEX you bought stables on, so you leave a similar trail?

Good point about the hyperinflationary places though - I guess it's a solution to use premium slavery money instead of the low-end ones.

reply
108 sats \ 1 reply \ @brink 21 Jul

If it's privacy preserving, how can I trust that it's not manipulating the prices? The order book is hidden?

reply

I don't think the oracle problem and the privacy problem overlap.

reply

We need to make Bitcoin accessible for everyone so they use it as money and easy to understand and interact with for everyday people

Bitcoiners:

we built a privacy-preserving, bitcoin exchange using @mercurylayer, nostr, and a zk-execution network. the bitcoin transfer is completed offchain via a blind co-signer. the stablecoin network only reveals hashes of inputs and outputs, no amounts or user addresses. orders are matched peer-to-peer using nostr identities. exchange is atomic & privacy-preserving. deets:
this protocol is built on the following:
statechains, a way to transfer ownership for bitcoin utxos offchain by reassigning spending keys
private stablecoin network with flexible zk-circuits/contracts that lock funds to a specific sha256 hash
a blind co-signer that facilitates ownership transfer for bitcoin utxos offchain per a specific order

Everyday people:

yeah fuck that

reply

hahahaha... another sat in the Justin was right jar #1509782

Stablecoins that trace back to your Bitcoin stack after you sell on a "DEX"... coordinators everywhere conducting surveillance...

"Blind" co-signer = Centralized server you must trust to delete key shares

"private ZK network" = stablecoin issuer sees the flow, colludes with the DCEX operator to trace your swap

Trial balloon so they can start pushing covenants to paper over UX a bit

reply
6 sats \ 0 replies \ @Troser 21 Jul -47 sats

If they can keep the UX simple, something like this could get real attention.

Real question: Would countries HODL the prize money or instantly dump it?

If France holds BTC for 4 years and it 3x's, every other FA looks dumb holding fiat.