Skip to content
TrackPodcasts
businessSep 8, 20261:27:27

Another Bitcoin Related Hack. WTF Is Going On?

About this episode

The Liquid Network just got hacked for over $300 million. 4,000 Bitcoin drained through a caching bug that let someone print liquid bitcoins out of thin air. Bitcoin itself wasn't hacked. Jack breaks down exactly what went wrong so you understand what happened.

Join the Revolution: https://strike.me/


Get every episode summarized

Each time The Jack Mallers Show publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

486 searchable segments. Every word is indexed and playable.

Another Bitcoin Related Hack. WTF Is Going On?

The Jack Mallers Show

0:00
1:27:27

Full transcript

The Jack Mallers ShowAnother Bitcoin Related Hack. WTF Is Going On?. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Yo, welcome back to another episode of the Jack Mallow show. I am your host Jack and you are listening to yet another edition of mail bag Monday. For those that don't know some unfortunate news in the Bitcoin world, there was another exploit, another hack. This one for over $300 million. Now, some of it has been returned. And before I get started, Bitcoin itself has not been hacked. The geography itself has not been hacked. Mathematics itself has not been hacked. But a sidechain known as liquid developed by block stream did suffer an exploit that saw what should have been an unauthorized withdrawal of over $300 million, $4,000 Bitcoin to be exact. So today, I will be covering first some macro updates. That's what you guys expect out of me. I'd never leave you hanging. And then we're going to deep dive. What is liquid? Why does it exist? How does it work?

What exactly went wrong? And then ultimately, what can we learn from this as a community, as a group of Bitcoiners, security, open source software, AI, all of it. So without further ado, let's get started snapshot. I'm talking to you all at a Bitcoin price of $79,130. That puts Bitcoin's market cap just below 1.6 trillion at 1.59 trillion. All time high remains. For $26,080, we are 37.2% down from that all time high. Don't look now. Objects in the mirror may be closer than they appear. We made that all time high in October 6, 2025. It's been 336 days since we made that all time high. And the last Bitcoin block, since I hit stream, was block height, 965,978. As I mentioned, we're going to do macro first. Brief, there's not a ton to go over, but there's enough. There always is. And then we're going to go big on the liquid.

Hack. I mean, I want Mondays of this show to be very relevant, very real time for you guys. I just want to do the best I can on Monday at 6 p.m. Eastern. It's like a news show, basically. And unfortunately, liquid hack is the news. And so we're going to go deep dive. And hopefully this is the episode for you to fully understand what's going on by the common man for the common man. Macro, first and foremost, we're getting back to my four questions before we waste anybody's time. Let's answer these questions first. One is the straight or hormones still closed. Two is the conflict still ongoing with the United States and Iran. Three are global supply chains still disrupted. And four can global debt survive this disruption. All these answers remain the same, which is a bit curious, obviously, because when this conflict started, it depends on when you technically count, but it could be the end and end of February, like the last day or the beginning of March.

It don't really matter. The point was, this is going to be a few weeks. We're coming off of kidnapping the president of a sovereign nation in Venezuela. And this was not going to be a conflict that was going to persist or be here to stay. It's going to be quick work. And obviously, it's Labor Day and the conflict is still ongoing, which I don't think was on anybody's mind when this started. So the straight is still closed. The conflict is still ongoing. Global supply chains are still disrupted and global debt is going to have a really tough time with this conflict. I mean, you couldn't ignore this quote from Scott Besson. Everybody knows Scotty Boy, our favorite, the CFO of the United States of America. He came out and said, and I quote, that the straight-of-hormose will be worthless in two years. Dependence of the straight-of-hormose is unlikely to end despite plans to build pipelines, says analysts, as the narrow channel will remain critical for container shipping and transporting

natural gas. US Treasury Secretary Scott Besson on Monday said the straight will quote, be a worthless piece of water in two years. Americans' new pipelines are built that will help Gulf countries bypass it to transport oil to the global market. So I actually got the clip of our boy, Scotty B, saying this really crazy quote. So let's see. Uh-oh. Do I have an issue here? Let's see if I can find a way to play it. Give me two seconds. I'm actually just going to, I got it from a tweet. I'm actually going to just pull up the tweet. All right. Here's our boy, Scotty B, talking about how the straight-of-hormose will soon be worthless. We have to de-risk. We have to de-risk everywhere in the world. We could see the Iranians are trying to use the straight-of-hormose as a choke point. It's not a choke point for the US, but it is a choke point for many other countries.

And, um, but, you know, that will be bypassed in two years. And two years, the straight-of-hormose will be like a worthless piece of water. Okay. In two years, the straight-of-hormose will be a worthless piece of water. Um, sure. I guess. Uh, listen, a few things to note here. Uh, one, I don't know what to believe anymore. Um, really, in pot. I doubt that. Okay. I doubt that. Whatever timeline government gives add a zero to it. Um, that's just been my experience. But what do I know? What else is worth noting here? Um, is that the United States and what it out, you guys can Google all of the things that I'm citing here. There's lots of articles. This was, oh boy. Did not mean to do that. Crud. Hold on one second.

How do I undo that? Not, not a, not a professional podcaster here. Ladies and gentlemen, not a great showing here. But we hang in. There we go. Okay. Um, what Bessent is talking about. This is at the G20 summit. And what he's talking about is really what we've been talking about on the show for quite some time. Being able to resure a lot of industry in the United States production, industrial equipment, industrial manufacturing. And he's talking about, and he goes to great lengths at what he calls de-risking relationships. There's geopolitical tension in relationships. And we've talked a lot about the United States reliance on China, the United States reliant on Russia. The reliance on Iran and the straight or hormones. And Bessent is talking about de-risking that and saying, well, we're going to build different trade flows, different pipelines, different channels, different trade partners.

Now listen, all of that is fine, but that's very inflationary. Globalism and this idea that everybody is the US is just going to print a lot of money and export inflation and export currency. And import really, really cheap labor and cheap products and services via China. That's very cheap. That's, that's, um, it helps make the American dream and the life that all these Americans are expecting affordable. Well, the iPhone is cheaper than it would be if it was produced in Manhattan. Why? Because it's made in Sichuan, China. That's why. Now, if what Bessent is saying is we need to de-risk ourselves from these relationships. So we're going to start making the iPhone here. We're going to start doing oil trade, not through the straight or hormones. Again, that's fine, but that implies inflation and higher prices, higher commodity prices, potentially higher iPhone prices.

You guys get my point is that it's a, it's reordering geopolitical relationships and reordering the way that things are made and consumed in the world is totally fine, but it has really grave implications. And we've been talking about this on the show for a very long time. So I just find it interesting and absolutely noteworthy that the US Secretary is telling us of the Treasury, excuse me, is telling us that we are in fact de-risking ourselves from certain geopolitical parties, certain trade partners. We're not going to be solely reliant to import everything and assume everybody's going to act in good faith. By the way, think of it in the reverse. We're de-risking from people. People are de-risking from us because what is our weapon of choice? It's not the straight or straight or hormones, it's not rare earths. What is it? It's the world reserve currency, it's the dollar. And so Iran, Russia, China, a lot of the companies that find themselves on the other side of us, which to be clear I'm an American, I'm not necessarily a fan of any of these countries, but they're de-risking similarly by adopting neutral reserve asset like gold.

And all of them, by the way, are mining Bitcoin by using different payment channels and payment networks. They're using the Chinese payment networks to settle global trade, settle oil trade and it's de facto backed by gold. And so all of this de-risking, all of what bests into saying, all of this de-risking, that's fine. You want the straight or hormones to be a worthless piece of water in two years? I would add a zero to that, I would say 20 years, but fine, two years fine. It doesn't matter, I don't care. What matters is this is all very inflationary, very inflationary, it means much higher Bitcoin price, much higher gold price, much higher commodity price. None of this is free. So that was absolutely worth noting, didn't want that to go by without you guys making or making sure you guys saw that headline. As it relates to the Iran war and how listen, driving prices higher, expectations of inflation continues to go up, which means bond yields will continue to go up. These treasure yields continue to go up. So this from Jim Bianco, the 10 year is now equal to a three year high. So it remains just under 4.8%.

And whenever the 10 year has gotten this high yields, that is, then there's been some form of central planning intervention, whether it's from the Federal Reserve or the US government and the Treasury themselves, it doesn't really matter. This has been historically a problem and I, we just saw a lesson talk about buybacks hinting at certain intervention, we know that. Him and Worsh, our buddies, we've talked on the show about potential outright yield curve control or some variation, distant cousin of it that effectively achieves the same thing. So we'll keep a close eye on it. Now this from Joseph is worth pointing out as long as we're on the topic of Iran, the straight of war moose in this conflict for those listening on the podcast waves, what is visualizes when the US started to attack Iran and then yields on the 10 year of just shot up into the right ever since. So when before the conflict started at the end of February, the 10 year yield was below 4%. Now it's almost 5%, which for yields the 10 year that staggering amounts of growth in a short amount of time.

Do I think that this is a coincidence? No, by the way, if they stopped the conflict, it would certainly ease pressure on yields, but yields ultimately have to go up because inflation is baked into the cake and if inflation is baked in the cake, we've talked about this time and time. Again, on this show, you should not lend money to anybody, especially the US government, especially over a long duration like 10 years, if you're not at the very least being compensated for inflation, if you're not getting paid at least the rate at which the things around you are rising in price, then what are you doing? I can't have a deal, you're the sucker at the table. And so as inflation expectations rise, so will this yield number and guess what is not good when it comes to inflation and inflation expectations and government spending war is not good. I mean, all of the debt that the private sector and arguably de facto the public sector is taking on to support AI, not good for inflation, all of this quote unquote de-risking, the straight-ahorn moose is going to be a worthless puddle of water and China de-risking from the US, the US de-risking from China.

All of that is not good when it comes to inflation expectations. So this is why I've arrived at a very consistent opinion that yield curve control is one of the more likely outcomes I see because I don't understand how they're going to get yields down without printing money and lending it to themselves. The very simplified version, guys, is who in their right mind would lend to the US government given all, I mean, it's just math. You just all you have to do is have half a brain and go on the internet for about five minutes and be like, yikes, I could buy Bitcoin, I could do so many other things besides lend money to the US government given all that's going on. I mean, why in the Lord's name would I do that? And that's what the market is telling us now I found this Wall Street Journal op-ed hilarious because so first of all, let me, before I start making jokes at the expense of other people, let me, let me first just say it is interesting that the public's opinion is getting closer to the opinion that we've had on this show that me and the listeners here have had on this show.

That obviously all of this is baked in the in the cake, inflation's baked into the cake, the currency is the escape valve, it's got to get crush, it's got to get to base, it's got to get made weaker, everything around who's going to get far more expensive in dollar terms, own hard assets, no man should work for what another man can print. That's been our opinion. Now, this Wall Street Journal op-ed is getting kind of close. So let me read this quote that is from the article itself, you guys should read it. On the right. Yeels on long dated government bonds are rising across the world and the reaction among the financial press and talking heads is a mini panic. Oh no, the debt crisis has finally arrived. The better view is hooray for the bomb market as investors awake at long last from nearly two decades of financial repression. Spendthrift governments might finally have to pay more to borrow and tighten their belts as a result. Now to me, fascinating. They're saying, I mean, guys, direct quote in the Wall Street Journal op-ed, the debt crisis has finally arrived.

Long dated government bonds are rising across the world. Governments are going to have to pay a lot to continue to borrow money. All of that is like, okay, so I'm not crazy. I'm not this crazy hooded psychopath in an empty closet speaking gibberish. Okay, we might be making a little bit of sense over here. Now, the implication here though is what is hilarious. Basically, if you read the article, the implication is basically, if politicians don't listen, so on the left, the screenshot for the listeners is a tweet from the Wall Street Journal supporting and promoting this op-ed and the tweet reads, higher yields aren't a crisis. It could be if politicians in Washington don't listen. So it's basically saying Congress and in Washington needs to start listening or else we're going to get to a crisis. And this is something that I've talked about on the show. So at least they're getting the core premise. The core premise is now being understood by the mainstream public.

We are in a sovereign debt crisis. This is a problem. The currency is the escape valve, the basement, inflation. All of these things. This is not a niche Bitcoin cult vocabulary anymore. This is like well understood, non-negotiable, non-debatable fact. And here's the thing too. I said this on lapse of episode. You can disagree with my delivery. You can disagree with the way I dress. You can disagree with the way I look. You can disagree with the way I talk. You can't disagree with math. Math is hard, really hard to sit across the table from and lay a cogent argument against. 2 plus 2 equals 4. Sorry that I like wearing t-shirts as opposed to button-ups. But 2 plus 2 equals 4. That's just fact. And so the world is starting to understand that fact. Now what they're struggling with is the second order of facts of these facts. So the notion that well, okay, it's not a crisis yet. Because all Washington has to do is just listen and change and act.

And I pose you guys the question here to all of the Wall Street Journal, op-ed authors and employees and colleagues and fans. What do you want them to act on? So here what I have on the screen is the largest outlays from the US government. I've shown you guys this slide time and time and time again. And for those listening that can't see, the biggest, I'll just voice over it. The biggest expense for the US government is health and human services. Which year over year all of these things have grown. Okay. So health and human services will now come in at over 1.5 trillion dollars. Social security is next will come in at over 1.2 trillion dollars. The treasury expense. So how much the US government is paying on its debt will come in almost tied with social security at over 1.2 trillion dollars. Defense has grown year over year and will come in over 600 billion dollars. Guys, this is on an annual so October to June, June full year. So there's full year, 2025, full year, 226. Okay. And I go on and on and on. So when people say, oh, the US government needs to cut back on education.

This education is a rounding error. We're not even talking about 100 billion dollars is spent. Health and human services, social security, treasury and defense. Okay, Wall Street Journal, you think that Washington and politicians just need to listen and act act on what? Seriously, you want them to take away health human services? Medical you, is that what you want? By the way, as this guy in New York City is promising free groceries, you think that that's going to solve this problem is to take away their health and human services or take away their social security? Oh, you think that what Washington needs to do right now is take our defense budget to zero? Seriously, this is the problem is they don't understand the second order effects. So yes, Bravo. Hopefully you've been listening to this show. You now understand we are in a sovereign debt crisis and there's only one way out. It is through inflation. It is through a weaker currency. Unless we magically stop spending all this money, but the problem is you didn't take a look at what it would take to stop spending all the money. It's very easy to sit there and say, what the heck Washington? Just pay attention. Stop spending so much. Okay, if it's so easy, what would you do?

You want to take away health and human services from the American people, social security, defense? You think that the president running and I've made this point so many times. You think that if I ran for president and I said, here's the plan. I'm going to take away health human services, everything medical related. I will take it away from you. I'm taking away all social security. I'm also sending our defense budget to zero. So if anyone fucks with us, we got to just take the punches to the chin. Do you think I win that election? Well, this guy in New York is promising that you could walk into a grocery store, take what you want off the shelves and not pay for it. So what do you want them to cut? Mind you, there is one line item that they can actually reduce the expense for. Take a guess. It's the one Donald Trump has been begging the Federal Reserve to reduce. The treasury expense, if they really need to cut expenses, there is one of them that they can cut and that's the interest rate or that's yield curve control.

You guys want to borrow a ton of money, but you don't want yields to go over 5%. There's a really simple way to do that. You'll the curve control, print the money and lend it to yourself or you guys want to reduce your treasury expense. There's a really simple way to do that. Cut interest rates to near zero again. But outside of that, yeah, yeah, genius. You're right. If the government can all of a sudden stop spending money. And by the way, this is just the second order effects. The third order effects of this, there's orders of orders of effects. Is that if the government stopped spending spending money, then you know that I think it's 25% of the workforce in the United States of America is in the medical industry. Like the United States cannot stop spending this money. It is the stimulus to the economy. I mean, it will default. I digress. This is supposed to be an episode about liquid. So let's get to that. But anyway, to close out the macro update.

So where does that leave us with the Fed's decision at September right now, prediction markets have it at about a coin toss. A 25 basis point increase to interest rates is at 52% no changes at 48%. So we're about a coin toss of whether the Fed is going to hike or not. But here's the problem. If the Fed hikes. We're in a sovereign debt crisis. The 10 years going to go higher. And all of these problems. There's only one way out. Inflation weaker currency. Some form of yield curve control. If the Fed cuts and starts sending rates towards zero, the 10 years going to go higher. So we're in a sovereign debt crisis. There's only one way out. Inflation. A much weaker currency. Some form of yield curve control. It doesn't matter. Again, you could say, ah, well, you know, I think that way is better than this way. I like up better than down. I look blue, better than red. Fine. I don't care. What about the fact that 2 plus 2 equals 4? How do you feel about that? Do you have any qualms with that? Can you possibly disagree with that? Because that's my point. The math is the math. Sorry. It is.

What it is. We've borrowed from our future and spent it with no production to pay it back. That loss has to be realized. And that loss will be realized by a weaker currency via inflation. That's it. You can you can say, well, no, well, I would prefer to realize the loss by hiking rates. Oh, no, no, no, no. Well, at Harvard, I learned that we should realize this loss via cutting rates. Well, guess what? As a bit, Quinter, I don't care. I know what to do with all this information. You guys can sit and debate through Wall Street Journal op-eds of what Congress should be listening to and what they should. It doesn't matter. Don't own any of these paper IOUs. Don't lend money to governments. They're all insolvent. They'll never be able to pay you back in purchasing power. Stay humble and stack sats. Okay. Next, let's talk about liquid. Listen, first and foremost, let's be clear about something because this show is ideally in a dream world. This is all signal, no noise, no fud, set in the record straight. So I do not want people to say, oh my gosh, Bitcoin's insecure. Bitcoin has all these problems. Bitcoin has no problems. Bitcoin is on average 10 minutes of block, tick tock, next block, Bitcoin and math and cryptography continue to work flawlessly. Despite.

This really complicated world that it was born into Bitcoin continues to march on. So Bitcoin itself was not hacked. Bitcoin remains secure. The cryptography that Bitcoin relies on and uses remains secure. Mathematics as a construct and a concept for us humans remains secure. Liquid was hacked and the actual news is that 4,000 Bitcoin was withdrawn from the liquid network. So what is liquid? Liquid is a side chain. It's what's called a side chain. So it is a separate blockchain connected to Bitcoin. So Bitcoin at the end of the day is a bunch of public information. And we call this public ledger, this public information, a blockchain. And I know that there are some newcomers and some folks that are not technical and not necessarily experts that do tune into the show. Just get these things dumbed down, humanism, have them relatable, explain to them in language they can understand. But everybody I think under the sun has heard the word blockchain. So everyone knows the Bitcoin blockchain liquid is a separate blockchain. So to be clear, it is not Bitcoin. It is what we call a side chain now.

Getting into side chains and stuff in my opinion, not totally worth our time. But it's like a separate layer. It's a separate layer, not Bitcoin itself. Why would you build another blockchain? Why does liquid exist? What was the point of building it? Well, the point was what if we want to bring something new to Bitcoin, new features, new capabilities without having to change Bitcoin itself. So this was the core idea in 2014 when the team at block streams, so you can see the names here on the right, Adam back, MacCarollo, Luke Dash, Jr., Gregory Maxwell's on here, Andrew Polsh was on here, Peter Willa. I mean, there's a lot of names that you'll recognize on here. And to be clear, let me just say, I'm a huge fan of all of these gentlemen. They've contributed immensely to Bitcoin. I mean, block stream as a company, I've been a fan of, I think they've contributed tremendously to Bitcoin over the years, lots of development. They've employed and supported lots of the greatest engineers in the history of Bitcoin. They've been forces of good for Bitcoin. So this is in no way just to make sure that my personal opinion on the parties involved is known and stated up front.

This is in no way like any form of judgment, moral, personal, any of that at all. This is just, you know, the people got it, the people got to have a source of truth and something, some new source they can rely on that doesn't have advertisers or incentives or whatever. And I'm trying to be that. So in 2014, these guys authored a white paper on side chains. So the title of this paper was enabling blockchain innovations with pegged side chains. And there's a direct quote in here that I think says the point that I'm trying to make implementation changes to the consensus critical parts of Bitcoin must necessarily be handled very conservatively. And this has been a highly debated topic throughout Bitcoin's history is, do we really want to change it? I mean, if we're going to update Bitcoin, add flashy new things to Bitcoin, you better be really, really careful. I remember Dylan and I, so everyone knows Dylan, my chief of staff, my best friend, Dylan and I were having a conversation and Dylan said, you know,

after all these years, isn't Bitcoin supposed to be a little bit faster or do a few more cool things or be a little bit more sexy and appealing? Like, what the hell? It's been over 15 years of this thing existing and like, where's the flashy new stuff? And I remember I love this analogy. I said, listen, man, we fly to Europe all the time from the United States. So we got across the pond as they say. We're going for business, we're going for conferences, whatever the case is. And I told Dylan, you know, airplanes have been flying for a long time, much longer than Bitcoin's been around. So what the hell? Why is a flight to Europe still at minimum six hours from Chicago? I mean, where's the sexy flashier, quicker flight to Europe? I mean, these things been flying nonstop. It's getting pretty boring. And I said, listen, I bet you somebody can I bet you someone can engineer a flight to Europe in half the time that it typically takes. However, there is a increased chance that the plane crashes and you die.

You want to get on that flight? Are you cool with the very safe and reliable six hour one? Or would you rather have a heightened chance of dying, but you might get there in three hours. And he goes, no, I mean, well, I don't want to die. I said, okay, that's the point. The point is we created perfect money, fixed supply money. Money that doesn't cost me anything to hold sovereignly of my own real property rights for all. And the point is that just we can get there safely, not that we could get there super quickly, not that we could get there super sexy. So safely, that's the level of engineering we're dealing with here. And so I'll read this quote again from the side chains white paper that was the precursor to liquid implementation changes to the consensus critical parts of Bitcoin must necessarily be handled very conservatively. And so what we've seen over the years is Bitcoin is very slow to make any changes because it's like engineering airplane.

You can't like get there safely if it takes a block 10 minutes fine, who cares? If we want instantaneous transactions will build that on another layer like the lightning network. If we want new features will build that on a peg side chain like liquid. Do not mess with Bitcoin, right? So innovation has happened at the layers, okay? This is where experimentation and a lot of these added feature sets come into Bitcoin and why we do not touch the core protocol. So Bitcoin itself can be thought of as money, consensus, and settlement. It's a very simple set of rules that everybody can verify. Anyone can run a node. So very simple things that allow Bitcoin to ultimately then be secure because you're not adding a lot of bells and whistles and complexity that leave opportunity for things to go wrong. Now, these side chains is where you can experiment. You can do things like enhance privacy. You can make new assets on top of Bitcoin, have all new sorts of features.

So the point is that you don't have to put every useful feature inside of Bitcoin itself. Bitcoin's about can I get my money from here to the other side of the world safely? Can I get my money from the year 2026 to the year 2126 safely without inflation, without debatement, without confiscation, without censorship? That's the core principles. Let the fancy things be teetered with on these other chains or these other layers, okay? So here's somewhat of a timeline. So Bitcoin is obviously introduced in 2009. That's the first block. This side chains paper came out in 2014. Now, this idea of confidential transactions in elements came out in 2015. Confidential transactions, as you could tell by the name, is privacy enhancing transactions. Now, liquid, which is an implementation of this paper that came out in 2014, launched in 2018. And this exploit now happened in 2026.

Okay, so now more technicals of liquid. So liquid is a separate blockchain. Again, separate network. So you have the Bitcoin network and the liquid network. So Bitcoin was not hacked. Liquid was hacked. Okay, how does it work? Well, you're going to see these concepts as you read the news of pegging in and pegging in. And there's pegs. What does it mean to have pegs? What is a liquid peg? Well, the idea is you deposit Bitcoin that's then locked. And that's what we call a peg in. So you deposit one Bitcoin in and that Bitcoin is locked. And then what's minted on the liquid blockchain, which again is a separate network, a separate blockchain, is a liquid Bitcoin, an LBTC. So one BTC equals one LBTC. And that way, the idea is that the side chains can then have Bitcoin pledged into them. The Bitcoin sits in his locked almost as if it's collateral one for one for them to then create their own token that's supposed to represent a Bitcoin that can do fans your features.

For example, if you wanted to have privacy enhancements in privacy at a at a crazy impressive level at the transaction layer, as we'll get into Bitcoin might not be able to give that to you out of the box. So you could deposit your Bitcoin and peg it in to this liquid network. And then you can use LBTC in a privacy way that traditional Bitcoin may not be able to give you. Does that make sense now? How does the Bitcoin get back out? Well, you burn if you want to withdraw and get out of the liquid network, you burn that LBTC that was given to you when you pegged in. And then you take the Bitcoin out of the locked vault and that's pegging out. So you basically got one Bitcoin for every one liquid Bitcoin and the liquid Bitcoin is operating on its own network with its own features that could give you some enhanced functionality, some new features, some sexiness, some flashiness, the equivalence of what I mentioned to Dylan of like you might be able to fly to Europe quicker than six hours.

But obviously you guys know where I'm going with this LBTC's not BTC. That's why at strike the only thing we sell is Bitcoin, the real Bitcoin, not the ETF Bitcoin, not the liquid Bitcoin, not the derivative Bitcoin, not the securitized Bitcoin. I mean, those are all I'm not going to make any moral judgments on them, but there's nothing like holding actual Bitcoin that must be one of the takeaways real Bitcoin, okay, real UTXOs, real, the real blockchain, not the derivative of the blockchain, not an abstraction of the blockchain, not the one traded on the New York Stock Exchange version, no real Bitcoin. And liquid Bitcoin is not real Bitcoin, okay, so back to liquid, the entire premise is wholly reliant on this one concept, all the Bitcoin that's pegged in and deposited represents all of the outstanding liquid Bitcoins. So for example, if there's been 4,000 real Bitcoins pegged into the liquid vault, let's say, that means that there are 4,000 liquid Bitcoins.

You can only have as many liquid Bitcoins as you can have real Bitcoins. You guys know where I'm going with this. If I can somehow create more liquid Bitcoins without putting more real Bitcoins in the deposited vault, then we'd have a problem. If I were to say, I'm going to create an extra 1,000 liquid Bitcoins without giving the vault 1,000 real Bitcoins, well then we would have a mismatch. There'd be 4,000 real Bitcoins in 5,000 liquid Bitcoins. And if there's a run on the bank and all everything is withdrawn, then someone's sitting with a balance of a liquid Bitcoin that isn't backed by a real Bitcoin. There's a mismatch. Make sense? So in the actual Bitcoin network, the real Bitcoin network, the one Satoshi invented and launched. Everyone can see everything. And that is a feature. So for example, in a 10 Bitcoin transaction, maybe you send 6 Bitcoin to somebody else and 4 Bitcoin gets returned back to you as a form of change.

The entire network can see that transaction. They can see that you once had 10, you then sent 6 to this other very specific person. And the other 4 was returned to you. And we can all verify that and do the math and verify the cryptography. That is a feature is that Bitcoin is public and auditable by all do not trust verify everyone can see the amounts. Everyone can verify that you did not invent anymore Bitcoin. This is a superpower. By the way, guys, because people have some qualms about Bitcoin's baked in privacy, and that's fine. And there's a separate episode, but there's ways that we can improve it responsibly. But keep in mind that if we could not see everything and audit everything, how would we ever be able to enforce the monetary policy? Because if I can't see if you're creating Bitcoins out of thin air, then how do I know you're not inflating past the 21 million limit? And so very core things like a fixed supply money has to be publicly auditable where everything is in the open for everyone to verify.

Now, this is not perfect for privacy, obviously. So everyone would be able to see that Jack pay Dylan 2.37 Bitcoin. Everyone on earth can see the amounts. And that has presented as a privacy problem for certain use cases. Now, again, I don't want this to be a privacy 101. If you guys want privacy episodes, we can do that. There's many ways to achieve privacy in Bitcoin. So I'm not making the case that liquid was the only way or that Bitcoin doesn't have privacy at all. Neither of those are true. The point is liquid and confidential transactions. We're trying to and still I don't know what's going to happen. Still are, I guess, if the network continues to go on still are trying to basically solve for some privacy use cases when it comes to Bitcoin transactions. And this slide is a little misleading too because obviously with the blockchain, the blockchain doesn't say Jack paid Dylan. It's a random string of letters and numbers. So it's not, you know, it's pseudonymous, not, you know, people don't necessarily know which public key is Jack.

But of course, I mean, you've got services like chanelis and people can see where have I KYC and pattern recognition and make fairly educated guesses. And the fact that everything is out in the open certainly makes it more difficult than not to be private when using Bitcoin out of the box. So the question is, well, can we have both? Can we hide the amount that people are sending and be able to prove the math and make it cryptographically sound? And that's what liquid tried to do. But again, tried to do it with confidential transactions on its own network. And it's not, not trying to do this with Bitcoin because as you can imagine, let's say we implemented into Bitcoin and there's an issue or it doesn't work out perfectly. Then all of a sudden, people can create Bitcoins out of thin air. There goes our 21 million fixed supply of the asset class and this whole experiment that we are shepherding into the future is totally ruined. What you can do is you know what? On second thought, I don't mind getting to Europe in six hours. Take your time. Honestly, it could be 60 hours as long as you don't kill me. And that's kind of what you end up realizing with Bitcoin. It's perfect money. We can experiment on layers, companies can experiment with products, but just leave the money alone. Let's just make sure that I can carry my money through time and through space safely.

So liquid and confidential transactions in one slide oversimplified, but not by a lot, basically tried to create a transaction where you can't see the actual amount, but making sure that it's still mathematically proving. So you can still verify important claims about this hidden number. So just because we can't see the number itself, we can still make cryptographic guarantees with the transaction. That was the point. Now, this is where I'm going to try to make very, very technical topics, very understandable to the public. But hold me accountable. Okay, but this is where this is an inflection points in the episode where you guys are going to have to lock in here. Now, because we don't know the number itself in the transaction and the whole point is allow people to be moving around this LBTC, these bitcoins on a new network design for privacy, allow them to move all these things around without people seeing who's sending what amounts to who got it.

Okay, first we have to be able to check do the inputs equal the outputs. Okay, meaning if we have 10 bit coin deposited, that means we can only have 10 bit coin in this network input output is 10 equal 10. Okay, that's obvious because obviously if 10 equal 50 someone created 40 out of thin air and that would be invalid and it doesn't matter how great the privacy benefits are, if you know, you could create money out of thin air and effectively steal from people will then this network is useless. Now this other check is very, very fascinating. We also have to make sure that every output is non negative is what it's called. It's not a negative number. Okay, and this cannot be enforced by a balance check. Now, let me carefully walk you guys through what I mean. As I said, let's say you start with the number 10. And the network has an output of six and an output of four. That's totally valid because 10 equals 10 6 plus 4 is 10. Nobody is spending money that they don't have.

Now, this is how you could potentially cheat. Let's say you start with the number 10 and I create an output that is plus 4,000 and 10 and another output that is negative 4,000. Okay, well, that balance is still 10 equals 10 because in the same way that 6 plus 4 equals 10, 4,000 and 10 plus negative 4,000 also equals 10. But the problem is I've then given myself plus 4,000 and 10 and this negative 4,000 is an unspendable. You can't spend a negative number. And so I've messed with the math by using negative numbers to make sure that 10 equals 10 still, but I'm giving myself 4,000 and 10 because I'm using a negative number to offset it, which is not spendable. It's like monopoly funny money. Does that make sense? So not only does 10 have to equal 10 that the inputs have to equal the outputs to make sure that no one's creating money.

But we also have to make sure that nobody is using negative numbers. Does that make sense? And I know you guys like, well, hold on a side chain separate blockchain. Now negative. I know it's not, I mean, listen, I'm not pitching you. You're going to get a PhD and all this stuff, but you're going to be able to understand how this hack went down and lessons to take away. So those are the two checks in this liquid network that must must must must happen. You cannot allow negative numbers because then someone can create a massive positive number for themselves and then offset the 10 equals 10 math by just placing a negative number that's totally invalid. So in this example, if I created 4,000 and 10 and then offset it by a negative 4,000, I control the 4,000 and 10 bitcoins now I can spend those and then what's sitting there is an unspendable negative 4,000 number.

Understand? So on net, if you offset everything, I just printed myself 4,000 bitcoins. I did not create those 4,000 bitcoins by depositing real bitcoins into the pegging to create actual liquid bitcoins for myself. As if I was a central bank, I just created them out of thin air. So back to bridging technical concepts for the Main Street public, there are two checks in the liquid network that must work and one is called the balance proof, which is does 10 equal 10 to the inputs equal the outputs. We have to make sure that nobody is inflating the amount of bitcoins and the way the bitcoin, the actual bitcoin network solves this is everything's public. We can see everything who's sending what amounts to everybody so we can account for where all of the bitcoins are. But if you want to have crazy privacy features, which is great, you introduce the opportunity for bitcoin inflation where people are creating bitcoins out of thin air because you can't see everything.

So that's why when people on Twitter are like, why don't we have this feature? Why don't we have this feature? Well, consider that really, really, really smart people have thought about all of this and we've as a community made very high quality decisions as to why not privacy is very hard because you might ruin bitcoin entirely by allowing anyone to create bitcoins out of thin air if we can't all audit and verify all of the information ourselves. So one is called a balance proof and the other, how do we ensure that no one's using negative numbers to get around this trick? It's called a range proof. And so when you're on Twitter or you're reading the news and you see balance proof, range proof, that's what this means. Range proof is to ensure that there's no negative numbers used and balance proof is to ensure that 10 equals 10, the input equals the output, et cetera, et cetera. Fair? Now, both of doing these things costs real work.

It's computationally expensive to do. That's another thing about having all sorts of very fancy features when it comes to bitcoin is there's no free lunch. Right, so the other thing in bitcoin is we want to make sure that anybody can run a node. What's the point of being able to audit and verify if it's only for a select few? Well, it's only for open AI and through op at Google Amazon and Microsoft. You know, I can't verify it, but they can. Well, then what would we solve? And so another thing in bitcoin that you guys will see as it's debated on the internet and stuff is well, even if a feature is cool and even if it's possible, what limitations does it place? On everyone else to be able to participate because in order for bitcoin to work, we all have to be able to apply checks and balances on everybody else. And if only some people can practically run and audit these things, well, then there's implicit trust in the system all over again, and we've achieved nothing. And so these things were very expensive to run. And so what the node software did is it implemented a technical concept called caching. Okay, so what the hell is caching?

Caching is effectively the software remembering just for convenience sake like, hey, I already checked your ID. You guys ever go to a bar and the bouncer checks your ID and then you go and you say, hold on, I got to make a phone call. You leave the bar and you come back in and the bouncer recognizes you said, I don't need to look at your ID again. I already looked at your ID. I know you're 21. I don't have to do it all over again. And so it's this idea and software of taking a very expensive check that you would have to do every single time. And basically checking it once, storing this specific check and saying, I already looked at that. So every single time it asked me to check it again, I'm just going to remember that I already checked it and let it pass. And this is caching is a very common place software engineering concept, by the way, this is not like caching itself is not insecure by any means or unscored by any means. But as I said, this is what we call a cache created this little animated visual is that you scan your ID, a bouncer checks your ID for the first time, totally valid.

And then 10 seconds later, he's not going to check it again. It's like, dude, I already checked it. You're good man. You're 21. Like for the rest of the night, you can walk in and out of the front door. Like you're good. Okay, perfect. Now, really important. If you're going to implement caching, how do you know that it's the same thing? Like, obviously a bouncer knows I'm the same person just by looking at my face and realizing, oh, that's that guy. I recognize that guy. But obviously if I had like a twin brother, then it'd be kind of hard. You would need like a unique identifier to understand the thing that you checked and then every single time it comes back up that it is the same thing that you checked you need like a label. And in the software, this is known as a cache key. It's like a fingerprint. It means this is the exact thing that I already checked. And so what happened is this is a little timeline for you guys. So in 2016, this range proof cache. So again, we had, let me go all the way back here.

We have balance proofs and range proofs balance proof is the 10 equals 10, the input equals the output. Okay, but the range proof is that there is no negative number, which is really, really important because then someone can use negative numbers to kind of cheat their way around the math. And so caching for these range proofs for this negative number check was introduced in 2016 in the summer of 2016. Okay. Now range proofs were extended to support assets. So on the liquid network, not only does it support Bitcoin, but you can create like tokenized equities. You can create all sorts of different assets on this network. Okay. Now in 2019, there was a cache key simplified bug that was created and needed to be fixed now is very difficult to exploit this bug was recently introduced and there was a very recent patch. So we call this bug a bug a was fixed by extending this key to include and this is where technically I'm going to lose you a bit. So I actually won't even voice over.

Bug a was fixed, but when bug a was fixed it created bug B and bug B was what was exploited today and I'm going to do my best here to try and walk you guys through what they were trying to fix and then what bug they accidentally created and how it was exploited. But basically they were trying to fix an older bug that was very difficult to exploit in doing that they created an even worse issue. So this is the timeline and that this tweet is from I don't know how to pronounce this guy's name. Mana not. I don't know he's great on this topic. Mana not. But basically I'll just read his tweet. The original bug a allows some limited cash poisoning because the cash key doesn't commit to the asset and script allowing a cash result for a range proof for one asset to be applied to a different asset.

Let me try and humanize this by the common man for the common man. I got you guys. So what this bug effectively is is it's remember if you're cashing something you have to be very specific about what you already checked and if you see it again making sure that you let it pass like the bouncer letting me back into the bar. It has to be positive that I don't have a twin brother right and obviously letting someone into a bar is not nearly as high stakes as a monetary network. We have to be very positive so you got to stamp these things be like I checked this this very specific thing and if I see this very specific thing again I could let it through. And what bug a allowed is what was being cashed wasn't associated with the asset that it was checking and the script that it was checking so it had left those two properties out and so the bug was well I can create something valid with one asset have that cash and then try and replicate it with a totally different asset. So let's say there's tokenized micro strategy and tokenized Amazon stock well when they cashed it they didn't necessarily associate it with micro strategy or Amazon they just cashed it as a valid asset without being specific of what the asset was and so that's a bug because I could technically do something valid with micro strategy and then try and do something invalid with Microsoft but the cash thing might say you're good to go because it still thinks it's micro strategy.

Hopefully that made sense so I digress exploiting this in practice looks quite difficult since the amount must match the primer and the proof must be genuine the 2026 fix so this recent fix added these missing fields to the cash key producing a format like the proof the amount the asset and the script so the fix is well let's be specific if the asset is micro strategy then that needs to be added to the cash key. So if we're caching this if we're saving it in our memory bank we got to be specific what's the asset what's the script what's the amount what's the proof now unfortunately this makes it even easier to manipulate and exploit and this is what happened basically so this is I mean for those that are watching on YouTube if you guys want to see this is the actual code that introduced the error so this was the commit so the update was the title fix range proof cash bind to asset and script so exactly what I just said so range proof that's the proof that ensures there's no negative numbers cash that's hey let's store it in the memory bank because checking these things is really expensive if we've already checked it let's not have to check it again and it's binding it to the asset so it's saying okay if this is tokenized micro strategy if this is LBTC if this is Amazon stock we need to make sure that when we cash it and we store it in the memory bank that we're clear

about what asset we're caching makes sense and now this created a even bigger problem like a disastrous problem as we now know so here's the problem okay and this is how I try and visualize it to dumb it down what it did is it's again it took let me go back it took the proof the amount the asset and the script and it combined it all together to give context for again make sense in theory the problem is this let's take the letters A B and C okay A B plus C becomes A B and C but so does A plus B and C do you understand there's a difference technically between A B plus C versus A plus B C A B plus C versus A plus B C different but if you can

catenate them together they both become A B C and this is effectively what happened cryptography didn't break mathematics didn't break this was a caching bug so the cash stamp was effectively A B C even if transaction one was A B plus C in transaction two was A plus B C the cash looked at it as oh they're both ABC they're good although that's a huge difference right A B plus C and A plus B C is not the same thing but if you add everything together and you treat it as oh they're both A B C they're good well that's a problem and so here's an actual technical slide from this guy or girl don't know him mononaut that actually shows what happened so if you take the proof the

amount the asset in the script and you take this is the new cash key format if you give one valid transaction that does everything the normal way and you create a cash key for the node so you walk into the bar and the bouncer checks your ID and they now cash it and they say this is good A B C is good but they implemented it wrong because they did not take into account for well was it A plus B C or was it A B plus C which one was it because then what the attacker did is created a brand new transaction that compiles to the same cash key but inputted a massive negative number and so they they created an invalid transaction but the problem is the bouncer the node already cashed it as you're good to go through the door because it's A B C I don't need to check it because in my memory it says A B C is good if they checked it they would have rejected it at the door that'll be like dude you're 15 years old you can't

come into the bar but the problem is the ID was already stamped is like you're good to go I don't even need to think twice about it and so actually I mean what happened is the hacker like actually cashed the word wrecked R E K T I mean the hacker I obviously knew what they were doing this was the exploit is to create a valid transaction that would then be cashed for this range proof so that they can create an invalid transaction with a massive negative number which as we described earlier effectively printed a ton of Bitcoin out of thin air sorry not real Bitcoin L B T C liquid bitcoins and there is your problem the bouncer the node that's supposed to enforce the rules had already cashed oh ABC again not delineating between a plus BC or AB plus C to very different things you know and I'm over simplifying but you can extrapolate you know one could be a totally valid transaction and the other could have a negative 4,000 number in it right and there's your problem and so here's kind of I mean I

hear the 4 steps to exploit liquid step 1 submit something valid so a primer transaction with a real range proof something that passes both input equals output and there's no negative numbers then step 2 is that the liquid network checks it and realizes oh man this is a very expensive thing to compute it's valid and we're going to cash it as valid so if we ever see it again just let it through the door. So then the step 3 after they've done that is to build a invalid transaction but build it in a way that results in the same cash key so that when it gets to the bouncer the bouncer says oh I've seen this before you're good man go go on and have all the shots you want don't worry about it. But again it's because the way that they are caching they're remembering they're storing things in their memory was wrong. And so then step 4 is it gets to the node and the node said I've already looked at this it's good go ahead you're good to go even though they were using a negative number even though the range proof was was invalid.

You see so the range proof was never actually verified when people say like how was this a valid transaction it wasn't a valid transaction the problem was it was never checked. But that also gives it should hopefully be very illuminating to like well what was the actual issue was. Did a cryptographic library fail with some math like you know nowadays you got people that get so like carried away with AI like did AI a break mathematics as we know it no there it I mean in implementation on caching was just if they had an error it was very poor implementation I mean unfortunately. But I mean not to say that's all like I don't want to undermine the severity of this I mean over 300 million dollars I hope everyone gets made whole there's a whole other side plot of the white hat and you know I chose to ignore that I hope everyone is made whole here and this sucks like let's not get cute about that like this sucks especially for those involved.

But the reality of the situation is like cryptography didn't break math didn't break Bitcoin didn't break this company that built a separate blockchain to try and give Bitcoin transactions some fancy features by basically building like a derivative of Bitcoin called LBTC like they just implemented caching incorrectly. Unfortunately so anyway you guys remember this math equation 10 equals 4,000 and 10 plus negative 4,000. And I know for the audio listeners those you lifting in the gym right now you're like to you're hurting my brain I know the number 10 equals 4,000 and 10 plus negative 4,000 so if you net out 4,000 and 10 and negative 4,000 you get 10. So yes 10 equals 10 and if you never check if there was a negative number in there because again cash key your stamped the bouncer already saw your ID I don't need to see it again you're good well then what happened. Well going back to this initial slide if there's 4,000 real bitcoins in the vaults and there's only then allowed to be 4,000 LBTC but if I created plus 4,000 then I basically just created 4,000 LBTC that are unbacked out of thin air.

So now there's 8,000 LBTC and only 4,000 real bitcoins backing them so then what do I do next well I initiate a 4,000 Bitcoin withdrawal. And of course the nodes are like yeah well you I mean there's now there's enough LBTC you you have them now because you were able to create that valid transaction well it was invalid but it passed you guys know what I mean. And so then they withdrew the 4,000 Bitcoin but then everyone was like well wait a second I have LBTC but there's no Bitcoin in the vault backing it so my LBTC is just is worthless all the actual bitcoins gone someone created LBTC out of thin air. And again to make the point crystal clear LBTC isn't Bitcoin and this is why people say ETF Bitcoin isn't Bitcoin a security equity in the capital markets isn't Bitcoin. There's only one Bitcoin and the world will have to very painfully learn this lesson over and over and over again and it sucks I hate watching it I really do it sucks.

But it's just not much color I can add outside of like Bitcoin is unbelievably scarce you can't create your own version on your own blockchain you can't create it in the stock market you can't create it in an ETF like yes the derivatives of Bitcoin have their time have their place they might be valuable given certain context and I'm not here to to cast moral judgment or or or make decisions based on other people's lives and other people's needs I mean people are going to be are you're going to do what they need. To do for their own self interest I mean who might tell you what's good for you okay all I'm saying is LBTC is not BTC black rock BTC is not BTC. A company's security or preferred stock is not BTC that's just again you don't need to like the way I look dress act whatever but that's that's that's two plus two equals four thing you know. And so anyway remember the whole peg out thing that's what happened the person found a way to create LBTC out of thin air by basically manipulating the whole cash key thing and then they pegged out they took the 4,000 BTC they printed to themselves and they withdrew the real BTC out of the vault with it.

It's like an IOU but the problem is there wasn't all real BTC backing all the LBTC so now everyone else that's still on the network still has their LBTC it's there but it's not backed by real BTC anymore so it's a fact worthless it's nothing right. So anyway hopefully that was like a very digestible way to kind of understand what happened liquid is a side chain that was built. To have different set of features and there was just an implementation error in something called caching and it allowed someone to print a bunch of Bitcoins out of thin air and in one of the takeaways guys is that's why we keep Bitcoin very simple at the protocol layer a lot of this fancy shmancy features and all this fun stuff like listen. Yeah you guys get it so anyways the actual status of this issue so 4,000 Bitcoin was withdrawn honestly if you're interested it's a crazy plot the hacker was conversing with block stream the company that runs this side chain.

In the Bitcoin blockchain itself they were embedding messages back and forth in the Bitcoin blockchain the hacker literally said like yeah I stole all your money or I guess your networks money I don't know how much of it was actually theirs but I stole your networks money and if you want it back you got to have this conversation with me in public on the Bitcoin blockchain hit me up here. And so there embedding messages in Bitcoin transactions published on the blockchain talking to each other back and forth and the hacker returned 3,400 Bitcoin so far and is continually talking to them in encrypted messages and it's unclear if they're going to return the full amount of funds if they're going to keep some to themselves because they started to encrypt the messages where not everyone can read them so the investigation and the recovery is ongoing but. As far as what happened I mean I was I'm hoping because this information is all very fresh like as of yesterday Sunday and so my hope is that.

This episode could be just like a very basic explainer of what actually went wrong and killing a lot of fun it's not a cryptography thing AI didn't crack mathematics I didn't crack anything I mean I don't know if I was helpful in the exploit or not I have no idea. But it was it was an implementation error in caching which is I mean that is nothing to do with Bitcoin. So yeah anyway back to first principles to wrap this episode up why does Bitcoin change so slowly I wanted to introduce. I mean you guys know I'm a huge fan of Bitcoin history and I've been around this industry for a very long time. So there's a infamous back and forth between Gavin Andrewson one of the early Bitcoin developers and Satoshi Nakamoto himself. And he said one of Satoshi's most famous quotes is from this Bitcoin talk dot org correspondence and from 2010 this is from June 17 2010. And I wanted to just read it to you guys because if there's opportunities to understand why Bitcoin engineering is slow why certain design choices were made why Bitcoin is.

So this is a very simple way to build a certain way this could be a cool opportunity to learn a little bit more about Bitcoin lore Bitcoin history Bitcoin design decisions so anyways. Gavin Andrewson on June 17 2010 at 1138 am posted the following to the Bitcoin talk forum. So I'm writing a little tool that dissect the Bitcoin wallet dot that mainly because I want to understand better exactly how Bitcoin works. And I see that the outputs of the transaction have value the number of bitcoins and a bunch of bytes that are run through the little fourth like scripting language built into Bitcoin first it makes me a little nervous that Bitcoin has a scripting language in it. Even though it is really simple scripting language it has no loops it has no pointers has nothing but math and crypto. It makes me nervous because it makes it more complicated and complication is the enemy of security. It also makes it harder to create a second compatible implementation of Bitcoin but I think I can get over that looking at the code new transactions are verified by pushing the signature and then public key on the interpreter stack and then running the transaction script.

Could I write code to create transactions with any valid script. And he goes on asking a few questions now this was Satoshi Nakamoto's response. The nature of Bitcoin is such that once version 0.1 was released the core design of Bitcoin was set in stone for the rest of its lifetime because of that I wanted to design it to support every possible transaction type I could think of. The problem was each thing required a special support code and data fields whether it was used or not and only covered one special case at a time. It would have been an explosion of special cases and again complexity is hard for security. The solution was script which is the name of Bitcoin's scripting language which generalizes the problem so that transacting parties can describe their transaction as a predicate that the node network evaluates. The nodes only need to understand the transaction to the extent of evaluating whether the senders conditions are met.

The script is actually a predicate. It's just an equation that evaluates to true or false. Again, guys, keep it simple. Bitcoin at the end of the day is just information and it's so simple all of the designs is to reduce complexity so that Bitcoin can be very simple which in turn makes it secure. The receiver of a payment does a template match for the script. I want to read this part. The design supports a tremendous variety of possible transaction types that I designed years ago. Eskro transactions, bonded contracts, third party arbitration, multi-party signatures, etc. If Bitcoin catches on in a big way, these are things that we want to explore in the future but they all had to be designed at the beginning to make sure that they would be possible later. I don't believe a second compatible implementation of Bitcoin will ever be a good idea. So much of the design depends on all the nodes getting exactly identical results in lockstep.

A second implementation would be a menace to the network. The MIT license is compatible with all other licenses and commercial uses so there's no need to rewrite it from a licensing standpoint. So much good stuff in here. So one, that complications is the enemy of security. Satoshi knew all of this, kept this in mind and he had a very difficult problem to solve which is once you implement Bitcoin you can't change it. And so he had to find a way to build something very simple, very secure but flexible enough that people in the year 2026 can still play with it and make their needs met. And then he's talking about how another implementation again is just you're adding more variables, adding more complexity. What if the implementation resolves of a function slightly different than Bitcoin core and then now you've got a chain split. And it's there's so much good stuff in here, so much we can learn from Bitcoin history.

So that one of the takeaways is every feature has a cost, guys. It's increased amounts of code, increased amounts of states, increased amount of interactions, increased amount of text testing, increased amount of review needed, and ultimately an increasing amount of ways that you could be wrong. And it's not that complexity is inherently insecure. It's that complexity expands the surface that has to be both understood and then kept secure and maintain secure. Security is not something that you can just achieve one day. Every single second you have to ensure security, the world around you changes. Like security is hard. And so the more surface area you create the harder it is to be secure. And what's fascinating is this is from the side chains white paper that Blockstream wrote in 2014. I pulled some quotes because again these guys are Bitcoiners. They understand all of this. I mean, unfortunately, their side chain and basically business logic implementation of this thing they wanted to build for their customers just had an issue in it.

But they understand all these things because this is from their white paper in 2014. One problem is infrastructure fragmentation because each alt chain uses its own technology stack. Effort is frequently duplicated and lost because of this and because implementers of alt chains may fail to clear the very high bearer. Security specific domain knowledge in Bitcoin security problems are often duplicated across alt chains while their fixes are not substantial resources must be spent finding or building the expertise to review novel distributed crypto systems. But when they are not security weaknesses are often invisible until they are exploited. Security weaknesses are often invisible until they are exploited. This is from the same paper. Script extensions have been proposed for Bitcoin but since such extensions are usable only by a small subset of users but all users would need to deal with the increased complexity and risk of these subtle interactions these extensions have not been accepted into Bitcoin.

So again, what this paper clearly lays out is that the increased complexity was rejected by the core Bitcoin protocol because us as a community were like, no, no, no, yes, one day we'll figure out privacy but unless we're absolutely sure of ourselves, we're not going to like, sorry about your business or what your customers want, like, sorry, you're going to have to build your own blockchain to sell for that. Like this is too risky. Any new complexity carries serious risk and in the analogy I told Dylan at the end of the day I just want to get to Europe safely sure takes six hours. I don't care. I really don't it's not that big of a deal. Oh, 10 minute blocks. What is nine minute blocks going to solve your problem. Visa transactions are instant. We're going to have to build something like the lightning network anyway. Let's just make it safe. Let's just like it say. And so what they write is they say one problem is infrastructure fragmentation. Well, I mean, and I'll get into this in a second.

Everybody's poured their blood, sweat and tears into Bitcoin core into the Bitcoin protocol itself and Satoshi's writing you shouldn't have multiple implementations. There's risk in that too. Just doing one thing well is incredibly difficult. So hard. Just keep it simple. That's why I talk about on the show all the time. Don't make life harder than it needs to be. Earn more than you spend. Save in something hard. Love others be selfless. Care health. Well, like just do the simple things well. So many people in life have all these problems and all these opinions. They're not taking care of their bodies. They're not saving and hard money. They're not earning more than they're spending. But they want to have opinions about local government and construction down the block and air travel. It's brother. My brother in Christ. First, earn more than you spend. Second, care what you put in your body.

Right. Third, save, save in something hard. Save and hard money. And I take this to this liquid example is guys, young hearted is to make sure in the world of AI that the Bitcoin protocol is secure. Joe, hard it is to have an open source project that has an incentive of $1.59 trillion. Why is Bitcoin core secure? Because the entire Bitcoin network relies on it. How many people care at the end of the day if liquid is a successful project or not? Not many. Not many. And so this is this fragmentation problem of like you create all these projects. Well, like where's all the open source community and all the researchers and all the developers and all of the university professors. They're going to make sure that all your caching implementation is correct. And the cryptography research is eventually your fragmenting resources. Right. That's infrastructure fragmentation and a security weakness will go invisible until it's exploited. That's what happened to cold card.

So what happened to liquid? This is what makes me very nervous. And when I, you know, when people say, well, Jack, I'm getting really scared. What can I use that secure? I say Bitcoin core. There's no hardware wallet that people care more about than Bitcoin core. There's no side chain that people care more about than Bitcoin core than the Bitcoin protocol itself. At the end of the day, Bitcoin is very simple, very simple. And there's $1.59 trillion worth of incentive for this one protocol to be secure and work well and get you there safely. And listen, with complexity with all these projects side chains, all these other things, it's going to be very difficult to get all of the resources and all of the attention. So the last thing I want to say is people say, yeah, but it's open source. And I've made this point before open source doesn't make it secure. It makes its source available. You can read the source code. So yes, you can read and inspect and contest and modify and criticize the code.

But just because everyone can doesn't mean that everyone does. Okay. Yes, it's possible to review. But how many people were actually reviewing? Because the real scarcity is attention. Attention is the real scarce resource, especially in the world of AI. What do people actually care about? Where are the incentives actually? And that's what I'm saying. Cold card was open source. Well, it turns out not that many people cared enough to review it because there was a bug for five years where people's money could just be taken out of thin air. Liquid is technically open source source available. But again, it's like, it's tough. Like, was it getting enough? Like we're talking about levels of security. I'm equating to airplanes, like putting human beings 40,000, and then fucking feet in the air. That you cannot fuck around. You need to make sure that everyone's on the same page. You're getting enough attention and scrutiny and review.

You can't put people 40, 50,000 feet in the air if nobody really cares about the plane. Is this plane safe? I don't really know. There's only been a few guys that have ever kind of tested it and taken a look. What? I'm not getting on that fucking plane. Are you nuts? If I said, hey, here's a flight to London. But I don't know. Supposedly, one or two guys have taken a look and made sure it worked. But it's open source. Are you getting on that plane? You're crazy. Come on. Come on. No way. No way. Anyway, I just think that this is a, it sucks because this is a lesson that the community's painfully learned. Yeah. Just because something's open source doesn't make it secure. I really think Bitcoin core is undersold as a tool to Bitcoiners. I mean, if you need to create a wallet and listen, I know that, you know, it's not the greatest user experience and stuff. But, and there's going to be a market for hardware wallets. There's going to be a market for side chains. I mean, you know, at the end of the day, it's a free market.

Bitcoin is the only free markets we have left. And people are going to experiment and try things and where there is demand, people will create supply and, you know, made the best man win. And some people are going to fail. Some people are going to succeed. The world's going to continue to spin and Bitcoin is going to continue to produce blocks no matter what. But man, so anyways, yeah, listen, security's not a check box, right. Liquid was open source, employment and multi-sig had formal cryptography, federations, range proofs, and still had an incident, right. And so security is a property of the whole system. And it's an ever lasting race. You have to be more secure than whoever's trying to attack you. That's what security really is at the end of the day. You're never secure for good. You're, you have been secure up until this point. But yeah, it's important. I think the open source thing, it's very difficult to create an open source project that has network facts, economies of scale, attention, and incentives. And I mean, looking back at some of this. And I hate, I hate the people that take Satoshi's words as gospel.

I mean, nobody knew what he meant. Also, he's a lot of be wrong. So I'm not saying like just because Satoshi said it, but I don't know history. I find, you know, a lot of this stuff fascinating. Good look back on. But the lesson for me, features aren't free. Open source is not magic. Multi-sig isn't magic. Cryptography isn't magic. Okay. Like, you know, understanding what is Bitcoin, what isn't Bitcoin, what to be considered secure, how these things work. So obviously important. And yeah, I mean, the other takeaway I just want to reiterate is that Bitcoin was not hacked and experiments around Bitcoin was, you know, a business implementing a side chain was unfortunately exploited. But this is why these experiments happen outside of Bitcoin and hopefully explains helps explain why Bitcoin is Bitcoin and we do not fuck with Bitcoin. Okay. Real quick, I've been talking about just doing more content and trying to expand the show a little bit. So here's what I got for the schedule this week. You guys will get new content out of me every day this week.

So no Q&A today because I'm doing dedicated Q&A. For those that don't know, I released ask.jackmallors.com where you can call in and basically leave not literally call in, but you can leave me a voicemail basically. Just just I've gotten like over 100 you guys are the best and these questions are awesome. I'm super excited. So no Q&A today and no Bitcoin 101 today. When trying to make these dedicated episodes on separate days so that because these shows end up being three hours long and I'm trying to squeeze in Q&A and I'm context switching between how did liquid get hacked and then like what is inflation 101. It's just too much. So I mean, I really appreciate that you guys like the content and enjoy trying to learn from me and I can make I think higher quality stuff for you. So today and always Monday will be macro and current events. So you got a little bit of macro and a lot of current events today of this hack tomorrow. We're going to try and do Bitcoin history.

So this is something you guys have been more and more interested in. So I'm going to try and come up with a history episode. See how it goes. It might not be a mainstay. We'll see Wednesdays will be Q&A where it's really this ask Jack where I play your audio recordings out loud for everybody to hear and I just respond to them in real time. So just I mean, it sounds really fun to me and like hearing your guys voice and being able to allow you guys to articulate questions is just it's fun. Trust me Wednesday is going to be a lot of fun. Thursday will get back to Bitcoin 101. So we've done an episode on inflation. We've done an episode on security and the cold card incident. So let me know we can do money value inflation mining custody monetary theory monetary history. Let me know what you guys are interested in and I'm going to come out with one episode of Bitcoin 101 a week and then Fridays will be strike. So everyone's like, hey, where are the strike updates you guys keep shipping stuff. I will make weekly how the company's improving what we're building feedback we're getting from you guys all of that good stuff that will be Friday episodes.

And so that's what you can expect for this week again, not all this will stay on a week over week, but we'll get to a schedule that you guys like and we're little short form animated stuff we're working on. So it should be really fun. So with that, I'll see you tomorrow. Man, I tried to make this episode short and I didn't stand a chance 90 minutes. Geez Louise. All right, guess I'll have to try again next week any comments questions feedback all of it. I mean, this show has come such a far away because of you guys. I love you guys even when you're critical. It's helpful and it's useful. So let me know where I can be better what you want to see and with that, I'll officially see you tomorrow. It'll be the first time we post on Tuesday ever. See you there. Peace. Love you.

More episodes

More from The Jack Mallers Show

View all episodes →