WORDS is a monthly journal of Bitcoin commentary. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. Thatâs why we made this journal, to preserve and further the understanding of Bitcoin.
Donate & Download the February 2018 Journal PDF
Remember, if you see something, say something. Send us your favorite Bitcoin commentary.
Satoshi. Give Us Your bcash!
By Beautyon
Posted February 1, 2018


Satoshi Nakamoto, the creator of Bitcoin, left us with a fantastic tool to change how everything is done in finance. When he created Bitcoin, a large number of them were kept by him. Its easy to understand how this happened. Would Bitcoin take off? Would the Bitcoin ever be worth anything? There was no way of knowing in advance. Others had tried in the past to solve the problem of how to make an electronic money and failed. In all probability, this attempt would have fail also, and the bitcoin in his wallet end up being worthless.
But it Bitcoin didnât fail. Bitcoin succeeded. Spectacularly.

Now we know for certain that Bitcoin, both as a novel and stable form of programmable money, and a programmable contract system, is worth literally trillions of dollars. Getting this new money and platform into the hands of as many people as possible as quickly as possible has to be the goal; the more Bitcoin users there are, the bigger the ecosystem becomes, the more platforms and uses are developed, and the faster The Transformation happens. The faster The Transformation happens, the more likely it is that we get to set the rules and standards by which this new economy is governed.

With our project Azteco, weâve created the easiest way of getting Bitcoin, using a simple and familiar 16 digit redeemable code system. These codes can be printed by any device, from generic computer hardware to the most modern POS systems. A vendor could even choose not to print them at all, and dictate them to the customer. The Azteco Vendor System can run anywhere, just like the MPESA vendors in Kenya run from wooden shacks, but unlike MPESA, which is a country specific locked in fiat system, Azteco sells access to Bitcoin, giving everyone a door to global e-commerce and its fluid, unrestricted facilities. Azteco users donât need to own a smartphone or a computer. All they need is an Azteco Voucher.

Weâve been hard at work on our roll out, and will soon be opening of our first vendors. Bearing this in mind, we have a bold proposition for you Mr. Nakamoto.
Give us your bcash⊠For great justice!
You have a huge store of Bitcoin. Now, there is a way to help our launch and seed the world with Bitcoin that doesnât involve using your Bitcoin. You can give us the bcash that was automatically created when the transaction record was cloned and the bcash alt-coin was launched.
All you would need to do is move your hoard of Bitcoin to a new address, and then give us the private keys to your old Bitcoin address. We then use Electrum Cash to import that public key and move your bcash coins to an exchange and sell them for Bitcoin, that we will use to fuel Azteco, distributing that bcash converted to Bitcoin to the market through our vouchers. We can disburse and diffuse the âfreeâ bcash converted to Bitcoin to the demographic that need it most in a fine grained way, so that a large number of different groups get to own Bitcoin.

Releasing your converted bcash into the market will also send a signal that bcash is explicitly rejected by you. The bcash fork will be effectively killed, along with the nauseating White Paper Cult, whilst simultaneously putting Bitcoin into the hands of people who need it. Our use of your bcash in this way will remove the risk of market shocks and a backlash against Bitcoin, which may have been the case had you afforded us the luxury of using your Bitcoin. Everyone will know that your Bitcoin will not suddenly flood the market, crashing the price.
Spreading your bcash converted to Bitcoin will increase the demand for Bitcoin services and encourage more retailers to accept it. It will widen the Bitcoin user demographic; when a new group of different users with real life needs comes on board who actually use Bitcoin rather than store it as a speculation vehicle, the dynamic will change. Bitcoin will start to behave even more like money, and will begin to fulfil its global potential.

Stills from âThe Tale Of Zatoichiâ 1962. Zaitoichi is a blind Yakuza, wandering masseur, gambler, and a lightning fast swordsman with incredible control over his blade. He can see objects with his hearing like a bat can. Click here to see the complete scene these stills were grabbed from. By pretending to be a bumbler, dropping the dice outside of the cup, he takes advantage of the dishonesty of gamblers, who only have themselves to blame for losing money by betting on the dice that are not in play. Sounds a bit like bcash, doesnât it? This theme is repeated throughout all the films in the âZatoichiâ series.
That is our proposal in a nutshell, Satoshi. Allow us to Johnny Appleseed your bcash converted to Bitcoin into the un-banked world. Sitting on an enormous cache of bcash can serve no purpose. That bcash converted to Bitcoin would be far more useful were it in motion, circulating in the hands of everyone with even the smallest need for it, whilst signalling to everyone that bcash is not Bitcoin.
You can encrypt a message to us containing your private key using our public key and then leave the encrypted ascii armoured reply on a public forum or other place where it will be spotted, for us to collect.
ââBEGIN PGP PUBLIC KEY BLOCKââVersion: PGPfreeware 6.5.8 for non-commercial use
mQGiBDiZoE8RBADO4RVs3eXTVQdT5vmgvbdYgIjjlxD4FUxR71m00arosyfeZkNyXWKaksFUJa2CLxKMTU3l+NzKqTtzd/1M33xsbbiuqPDj38DvyYRARw/3ShI4I6dKx2PJ/4FprBbH64K5kZlMJJUsFpYmsS5xD8VEQF2gxyLec4X0USvLqquYqwCg/6o/AG2HGKwEQLXVJH7z2TgF5DUEAKi/vuAIq7AVOVZj0Dhd5w8DVWL+QPBy5NU6nLeKWyD+Yn7yE0QgphbNg/eFJlfGzVZt5CNQ1TW0sZ/d6RvaF4ICn65auLpTL4CPAHSqQXZ70dMcmHeWtcSHI5h40BEnAi144r43qL/q5rNG6+o0I6FXV5V609P08pOl9l+h749MA/98yV+fkcb0VCEESFufZivuK702fCus4dKlBo6BJS2GE/rmd8CNBCTvAXfB+kN2aj4bePWC2dhx2EF+9T1JqiPQYtT3qYdCqkUiZadWPO6vvvomRHy8rDxCXpkpVReho3BR5awGn5NWMJHcVE1vxtg25M6mJVN3XY0gifsLeqTvkrQgSXJkaWFsLURpc2NzIDxpcmRpYWxAaXJkaWFsLmNvbT6JAE4EEBECAA4FAj4bE6IECwMCAQIZAQAKCRBeFtNu2zJA+R1tAJ4760uXcf3RGnLoB9IObLl9R8zBhQCg3GWVxz/o/2qLgstNFGBfFWDzhleJAEYEEBECAAYFAj4bnowACgkQJXr31HAfn1vfcwCbBk3fTaJy1Cg3/hQNEyHTnIbBE3UAmgNL66RGpzahpEHrtEOL5cxul9jhiQBGBBARAgAGBQI+HATEAAoJEO3SeV9eWbNIQcEAoOjrXQGf6qbsYz71/BcG3BNtRn+IAJ4tUFhzAgNxlI/OedrB6iLfQ/UorYkARgQSEQIABgUCPh136wAKCRBrH5us9CslP5KmAJ9Zf1ESgFdX8D3lldOhgz/qhQl8/ACfSxo8HXZM7IEQeRj+TeZlxXszAbeJAEYEMBECAAYFAj4jiLcACgkQ6qzefeIO66pzpACg9UF38/XHyLTiKFIz61bsmwMNbdwAn33q+vSyIwQJVjJt6nNl7nv/54CEiQBGBBARAgAGBQI+I4tPAAoJEOqs3n3iDuuqCKYAoJauRiOXDSjqjCgW4g+FR+1Z+RqtAKDCjpD+SHG3lDMXMzgCjeXBHuPhCbQqSXJkaWFsLURpc2NzIDxpcmRpYWxAaXJkaWFsc3lzLndpbi11ay5uZXQ+iQBOBBARAgAOBQI+GxOiBAsDAgECGQAACgkQXhbTbtsyQPmmEACfdeXERBB5jnqCWreGGpiJvjt4w+8AoNA/UcVWMqru/ZdG2G/a1yMYGXoJiQBOBBARAgAOBQI4maBPBAsDAgECGQEACgkQXhbTbtsyQPnWowCfb70O9Azg0rFgw0nIkgGfPFlUwBMAoLF4A+e+tXTxAC+Mpjo86SqGvQSliQCcBBABAQAGBQI4maCWAAoJEIBwiB5FzDvpC5wD/0P9OyIuKbRj3g1kDcxaj4t7ZxnrNE7EmrxZ5UjOuS8geijSUZjHMwqzNLx+AR9ves/fF8x7fiKi+FvkkwZAg8B/YAKosdMh+uztQRAR2a/OkK170FzM41ZyFx3aF0uEVqyOqU7QRxTQ7pNtF6+/hpyvLA4boqTH0v8QYd+Vt12IiQBGBBARAgAGBQI5gVEtAAoJENeaelcUR+zq1HsAoJrMlIxNCt/ClRBEwkQeh57pxTHfAKDQ1QfU5OHxl5PCkFtx2ZKObof++IkARgQQEQIABgUCO1wtLwAKCRBrH5us9CslPz67AJ95c1ZAVhkId3YHcFkF8xUPrX2Y6gCgoKjttcToxiuYCs6j+aOcyXxyIImJAEYEEBECAAYFAjvDfPQACgkQs4sqk0OK3fXk+ACfeP3Af7OThSi5TVblle3pkN9U0koAoKm8rtQ3jze1tHQQ4Z5fieY9a51HiQBGBBARAgAGBQI7zNjWAAoJEBRrtvt/wJrqtLIAoIBuxBbqh1vjI/qYhwraVcPMBpAxAJ9izxviic0azEVChwLObIwQQGpMFYkARgQQEQIABgUCO9AKVwAKCRAw5GZODMbydxJQAKCFxH1blSYUsEFvn5je9WNQooCGmwCgo2mdT78k0pQl9ZyANGOuxbocGPKJAEYEEBECAAYFAjvTLDkACgkQ7dJ5X15Zs0hpzQCgpLwFUiAF6qNGA1yxF5/LGC0IsxIAnRocTutZh8bm2D9YhG2u5bYRMW+/iQBGBBARAgAGBQI8xC4LAAoJECV699RwH59b1GwAmwdQuO2AyRt0bZi6fh1ykzpPADe6AJ9kSWuvLzP4bwCkyvZXVzKlo7Qun7QgUDJQUSBJbmZvcm1hdGlvbiA8aW5mb0BwMnBxLm5ldD6JAEsEEBECAAsFAj4bFDQECwMCAQAKCRBeFtNu2zJA+b77AKDVtNSznj3XhvGyJC2xR8Fs0XSF0ACgs56k1RT61ow8gfia1fdOtx4mjviJAEYEEBECAAYFAj4bnr0ACgkQJXr31HAfn1sKSgCg99t+iKGcGocG0VtePGEQ3Nih0BIAnR9Wy91PrFFzdbsX0pbaQI/EKB4YiQBGBBIRAgAGBQI+HXfuAAoJEGsfm6z0KyU/cz8AoM/hlinNBKMDHa71ugXyX/4fOAlzAJ9SiITeFMMahLRLPXJE7BkCB/PJ67kCDQQ4maBPEAgA9kJXtwh/CBdyorrWqULzBej5UxE5T7bxbrlLOCDaAadWoxTpj0BV89AHxstDqZSt90xkhkn4DIO9ZekX1KHTUPj1WV/cdlJPPT2N286Z4VeSWc39uK50T8X8dryDxUcwYc58yWb/Ffm7/ZFexwGq01uejaClcjrUGvC/RgBYK+X0iP1YTknbzSC0neSRBzZrM2w4DUUdD3yIsxx8Wy2O9vPJI8BD8KVbGI2Ou1WMuF040zT9fBdXQ6MdGGzeMyEstSr/POGxKUAYEY18hKcKctaGxAMZyAcpesqVDNmWn6vQClCbAkbTCD1mpF1Bn5x8vYlLIhkmuquiXsNV6TILOwACAgf/UrPbchMwOFLp0nX3j83nb0hirv0CJidehezXSAQz8Htk9Il8C/F4rDZlTZ4TpJdhBzSoAwu+SzUjQ4hOGoHsy9d88+gYw6+zamss4W+lrAiwulWBX+5sZqt47K3Wfry6+q6mS7QcmEXp0+cF897II2Y8BmHGaQLrxVIPz8JRtJZG7pquq8/CVBAM8dBTyr7trHykcRTmeUIolow6lEg34KvDkXac6eVOC0xrxR1OF7eXFRZ0DkULhGOrRX2wuMkmidC/GannB7pJ22G6H2oLy2IQVYkYV9gAKj8pB1VlO+j5goIWaJfW0xqY0caWgDSmdzdeBuVmvZASBHhEMRAd3okARgQYEQIABgUCOJmgTwAKCRBeFtNu2zJA+cFhAKCxCDbbunBppjgUS73htJ0hHq0rZwCfaHKTgbj7E8eMFmhotgaFm4/Gj1c==mfEpââEND PGP PUBLIC KEY BLOCKââ
Once news that this message is sitting somewhere to be collected, someone will scream at us that itâs waiting. We will find it, decrypt it, and use Electrum Cash to convert the bcash into Bitcoin through an exchange. We will distribute that bcash converted to Bitcoin through Azteco, with a discretionary maximum single voucher amount at whatever the real time rate is on the exchanges, to spread it widely.
According to this tweet you have about 1,000,000 bcash lying dormant. That is $1,329,289,987.67 at todayâs price, which is 143,563.32BTC. If we sell 1000 Bitcoin a month through our Azteco vouchers, it will take 11.96 years to sell them all. This would be a clean, slow and steady dispersal of this large hoard of bcash, over many years, with no chance of disrupting the market.
What say you? LETS DO IT!
âSatoshiâ promo code gets 3 free job postings on Hacker Noonâs job board.
Excited for Schnorr signatures
By Murch
Posted February 3, 2018
If youâre keeping a finger on the pulse of Bitcoin development, youâve probably already heard about Schnorr signatures and you probably wonât find much new here. You might rather want to check out Pieter Wuilleâs recent talk at BPASE18, or Bryan Bishopâs compilation of transcripts of Schnorr signature talks whom this article heavily leans on.
Bitcoin signatures are created using the Elliptic Curve Digital Signing Algorithm (ECDSA). Schnorr signatures are another form of digital signatures. The signatures are based on the same security assumptions as ECDSA and are compatible with the elliptic curve Bitcoin already uses (secp256k1). This means that Schnorr signatures can be created with the same private keys and are compatible with currently used key derivation schemes.
Schnorr signatures are smaller
ECDSA signatures vary in size, but almost all come in at a length of 72 or 71 bytes. A small portion will turn out smaller with a theoretical minimum of 8 bytes. [h/t Greg Maxwell]
Schnorr signatures are more efficient and compact than ECDSA signatures. The maximum length of each signature is 64 bytes. [via Harding] Bitcoin blocks include thousands of signatures, and I estimate from the top of my head that signatures make up more than a third of the blockchain data. Simply by being more compact, Schnorr signatures would reduce the blockchain data footprint by a few percent.
Schnorr signatures allow for compact multi-signatureâŠ
The multi-signature scheme in Bitcoin is straightforward but naĂŻve. You first list the set of public keys of the authorized signers, and then provide a sufficient count of signatures by the former. E.g., in a 2-of-3 multi-signature transaction input, three public keys and two signatures are provided.
Schnorr signatures have a neat mathematical property that allows multiple signatures to be combined into a single signature. The combined signature has the size of a single signature, but provides the authorization of the original separate signatures.
This allows for a more compact multi-signature scheme, where you only list the authorized public keys and provide a single signature. This is even more efficient for bigger multi-signature transactions. For example, a 3-of-15 and a 10-of-15 transaction input could now have the same weight (if you donât care who signed).
âŠand aggregated signatures across a whole transaction!
While multi-signature transactions make up a solid portion of the blockspace, the real breakthrough is that signatures can be aggregated across multiple inputs of a transaction. Instead of providing one (or multiple signatures) for each input, a transaction with Schnorr signatures can have a single signature for all inputs.
For example at BitGo, we use 2-of-3 multi-signature transactions. Every transaction input therefore has two signatures. As weâre seeing low fee rates on the network, some of our customers have started consolidating funds from low-value UTXO. With the current signature scheme, a 2-of-3 multi-sig transaction with 200 inputs would need 400 signatures or about 28.5 kB of signature data. With Schnorr signatures the same transaction could be signed with a single 64-byte Schnorr signature.
In his talk at BPASE18, Pieter Wuille estimated that purely from aggregating signatures for each transaction and leaving everything else the same, the Bitcoin blockchain would be between 25% and 30% smaller.
Scriptless Scripts, and⊠various black crypto magic
There is some interesting work by Andrew Poelstra lately which he calls âScriptless Scriptsâ (see e.g. his talk at Real World Crypto 2018). The idea is that you can express conditions in a smart contract by requiring certain signatures to be provided for the payout. By means of the above mentioned signature aggregation, this could be used to compactly encode smart contracts. The terms of the contract would be hidden from other users and only transparent to its participants, yet enforced by the whole Bitcoin network.
You may have heard about the recent cross-chain atomic swaps. The basic idea is that two payments on two different blockchains are linked in a way that they either both go through or neither. This can be used to decentrally trade cryptocurrencies. Hereby, the traders first lock up funds in shared addresses on both chains, and then create two interdependent transactions. The second transaction depends on a hash preimage that is revealed by the first transaction. Either party can back out and wait for the lock to expire to reclaim their funds, but when the first transaction is executed, the other transaction becomes immediately valid.
By means of the same property that allows for the signature aggregation, all of the above cross-chain atomic swap can be expressed in a single Schnorr signature indistinguishable from a regular spending transaction.
A BIP for Schnorr signatures is in the works
The introduction of Schnorr signatures into Bitcoin requires a new OP_CODE for signature verification. Luckily, Segwit gave us versioning for Bitcoin script, so support for Schnorr signatures can be activated with a soft fork. I hear that multiple Bitcoin Improvement Proposals are in the works and forthcoming shortly. Thanks to Pieter Wuille for review. Edit: Corrected the length of ECDSA DER-encoded signatures.
Rethinking Network Value to Transactions (NVT) Ratio
Dmitry Kalichkin
Posted February 3, 2018
This is the first post in our series on cryptoasset valuation. Second one is â Rethinking Metcalfeâs Law applications to cryptoasset valuation â.
Cryptoasset prices have been quite turbulent in the past few weeks. At times like this itâs especially important to look at the fundamental foundations of cryptoasset prices, and quantitative metrics. Today I will share with you one of the main metrics we use in our investing decisions at Cryptolab Capital.
Emerging field of cryptoeconomic ratio analysis
In traditional finance, ratio analysis is one of the most widely used valuation methods. Lacking the detail of other valuation approaches, such as DCF analysis, ratio-based valuation is much faster and is still a good proxy of fair value. It also allows one to easily track asset price dynamic over long periods of time as well as compare different assets to each other.
Over the course of the last year, a new study of cryptoeconomic ratio analysis emerged. The main idea behind this new field is to study the relationship between price of a cryptoasset and its fundamentals. One of the most widely known ratios is Network Value to Transactions, or NVT. Introduced and popularized by Chris Burniske, Willy Woo, and the team behind Coinmetrics, NVT is often called âcrypto PE ratio.â Hereâs the definition of the ratio:

In a traditional PE ratio, the earnings metric in the denominator is used as a proxy for the underlying utility of the company created for the shareholders. While cryptoassets donât have earnings, one can argue that the total value of transactions flowing through the network is a proxy for how much utility users derive from the chain. It is worth highlighting that Daily Transaction Volume in NVT takes into account only on-chain transactions. All the trading activity that happens on exchanges and is, for the most part, speculative is not included in this volume.
This Forbes article argues that NVT can be successfully used to detect bitcoin price bubbles when valuation is not supported by fundamentals and differentiate them from consolidations. The chart below concisely illustrates this argument.

This chart also greatly illustrates what we at Cryptolab Capital donât like about NVT in its current form. The spike in NVT follows the bubble with a considerable lag of a few months.Peak NVT coincides with the middle of a correction period. NVT is neither predictive (doesnât precede the overvaluation), nor descriptive (doesnât coincide with it). You can only detect the bubble a few months after it bursts.
Rethinking NVT ratio
Trying to dissect this issue and improve this ratio, we started by looking at the ratio definition:
âRatio has been smoothed using moving averages, 14 day forward and 14 day backward facingâŠâ
Mathematically speaking, this means the following:

Hereinafter:
- NVT_Classic stands for âClassic definition of NVTâ
- 28 MA_is â _28-day Moving Averageâ
- NV is â Network Value in USDâ
- TV is â Transaction Volume in USDâ
Letâs pause here and look back at the conceptual meaning of NVT. In this ratio, Transaction Volume is used as a proxy for fundamental network utility value. When you look at Transaction Volume on a daily basis, there is a lot of noise, so I completely agree with the decision to smooth it by using a 28-day Moving Average. But we asked ourselves a few questions:
- Why 28 days, and not 10, 30, 90, or 180? A 28-day average might be not enough for a truly fundamental metric.
- Why 14 days forward and backward? If we are trying to develop a predictive, or at least descriptive, indicator we shouldnât rely on future data.
- Do we need to smooth both parametersâââratio as a wholeâââor just the denominator?
We then experimented with different Moving Average periods, and came to an empiric conclusion that the optimal solution is to divide daily Network Value by 90 days Moving Average of Transaction Volume. So hereâs a definition of our new NVT ratio:

Comparing old and new NVT for bitcoin
Source: authorâs calculations
As can be seen from the chart above, when we move from a 28-day Moving Average to a 90-day Moving Average NVT definition, we get rid of the time lag issue described above. We can also see that every time NVT went to the Yellow or Red zone (autumn 2013, spring 2014, December 2017), a price correction followed.
We claim that this refined NVT ratio is a better descriptive metric of bitcoin bubbles. Conceptually, this makes sense. Given that Transaction Volume in NVT is a proxy for fundamental utility value of the network, a 90-day Moving Average is a better proxy for long-term fundamental value than a 28-day Moving Average.
Letâs now look at the recent bitcoin price performance using the refined NVT ratio in more detail. From January until mid-December 2017, bitcoin has appreciated almost 20x. For the most part of this rally, though, NVT ratio has stayed in the Green Zone. However, in December when price reached almost $20,000, NVT went into the Yellow for a few days. This rapid appreciation was shortly followed by a 30% price correction, and another even steeper price correction in the last weeks. After the correction, NVT has returned to the Green zone. This is another empiric evidence in support of 90 MA NVT.
Looking at the chart below, it is much harder (if at all possible) to foresee the December 2017 correction. Quite the opposite, during late 2017 price rally, NVT went down! How can it be?
Source: authorâs calculations
There is a non-static non-linear relationship between the numerator and denominator of NVT. Every time thereâs a sharp increase in price, thereâs growth in trading activity (off-chain transactions) that is shortly followed by on-chain transaction volume growth as investors liquidate their positions. Exchanges and wallets trade with each other to provide liquidity to their users. All this activity increases on-chain transaction volume, even though it is fully speculative.
In other words, the cryptoassets exhibit reflexivity. In the short run, the price changes the fundamentals. In this case, transaction volume follows price. I donât want to go into much detail on this, but I can refer you to an excellent article on the topic by the Coinmetrics team: â Mean-reversion and reflexivity: a Litecoin case study â.
So why does a longer period average result in a better indicator? Intuitively it makes sense. By definition, the role of Transaction Volume in the NVT denominator is to be a proxy for fundamental utility that users get from using the network. A longer smoothing period helps to get rid of the reflexivity effects described aboveâââspikes in transaction volume that follow sharp price increase. These irregularities are speculation-driven and are bad descriptors of fundamental intrinsic utility of the network. When we remove these irregularities, we end up with a better proxy for fundamental value in NVT denominator, and, as a result, the new NVT ratio becomes a better descriptor of price level.
Analyzing Litecoin using the refined NVT
Source: authorâs calculations
Looking at the chart, we can see that there were at least 3 cases since 2013 when the same logic applied: price spikes coincided with, or in some cases were even preceded by, spikes in 90-day NVT
- Autumn 2013
- Summer 2015
- Autumn 2015
- Late 2017
However, in a few cases it didnât work as well. Those cases are usually explained by a strong trend or some big external news:
- In late 2014, an NVT spike happened during a one-year-long price correction, and the price just kept going down. A similar dynamic can be seen on the BTC graph above during the correction of the second half of 2014. NVT spiked a couple of times while BTC price was steadily declining.
- Most interestingly, in April 2017 NVT spiked really high, but price actually went up! Here there were a couple of strong external factors: (1) SegWit adoption speculation, and more importantly, (2) listing on Coinbase in May that propelled asset price to a whole new level and moved LTC to another league. The price did increase significantly, but the fundamentals shortly followed.
Despite these exceptions, the descriptive power of the refined NVT for detection of overvaluation is still quite strong. It is definitely stronger than that of the currently used NVT.
Using new NVT for BCash
Source: authorâs calculations
BCash is quite new, and its history has been full of breaking news, hostile attacks on bitcoin, and other exogenous events. Given this, it is hard for us to define the limits of the Green, Yellow, and Red zones for this currency. If we were forced to state Cryptolab Capitalâs opinion, we would likely say it is rather overvalued at the moment, the NVT might still be in the Red zone, and the fundamentals have to catch up for the price to make sense.
But one thing that can be seen from the chart above is the sharp NVT spikes coincide perfectly with local price maxima. Yet another win for redefined NVT.
Summary
For every investor it is of crucial importance to understand what is going on in the market right now. As a result of Cryptolab Capital research, we have designed a metric that describes price bubbles well and without a time lag across different time periods and assets.
There is, however, another more fundamental weakness of NVT. It only takes into account total value of on-chain transactions, but it doesnât factor in the number of transactions or the number of addresses (wallets) participating in these transactions. Letâs call this metric Daily Active Addresses (DAA).
For internet companies, especially marketplaces, social networks, and other businesses with strong network effects, the analogous Daily Active Users (DAU) indicator is one of the most important performance and valuation metrics. This and other metrics that now make up the language of valuing internet companies didnât exist in the 1990s. It has been developed by technology investors over the last 20+ years. Similar valuation framework for cryptoassets is yet to be developed and is only starting to form.
In our next post, we will try to contribute to this framework and propose a way to use Daily Active Addresses (DAA) in cryptoasset network valuation.
Acknowledgements
I wanted to thank a few people who contributed to my understanding of cryptoasset investing, and gave valuable feedback in the process of this research:
- Professor Susan Athey from Stanford
- Professor Christian Catalini at MIT
- Chris Burniske from Placeholder.vc
- Willy Woo
ELI5: What do we mean by âblockchains are trustlessâ?
By Preethi Kasireddy
Posted February 3, 2018

Source: https://libcom.org/library/consensus-its-discontents
Intro
Many of us are guilty of describing blockchains as âtrustlessâ systems. However, Iâve come to realize that the term âtrustlessâ is ambiguous, confusing, and most importantly, inaccurate.
Blockchains donât actually eliminate trust. What they do is minimize the amount of trust required from any single actor in the system. They do this by distributing trust among different actors in the system via an economic game that incentivizes actors to cooperate with the rules defined by the protocol.
Let me explain in more detail.
A truly trustless transactional system would look something like this:

Two people who are interested in transacting with one another change hands directly. They are physically present, and therefore can easily verify
- Authenticity: the actual sender is handing over the money, and
- No double spending:the money is not fake, itâs a real $10 bill
While theoretically flawless, this transactional system is limited. Consider: two individuals may trade with one another only when they are in close physical proximity. For economies to function at scale, a transactional system should enable transfers with anyone in the world, regardless of distance.
So, what we really want is this:

As you can see from the diagram above, the way we achieve this aim is by having an intermediary who can facilitate the transfer of value to make sure that the actual sender is sending the money and the money is real.
This begs the question: who serves as the wholly trustworthy intermediary?
In modern day transactional systems, the intermediary can be a bank (e.g. Chase Bank); a payment provider (e.g. Paypal); a remittance company (e.g. Western Union); a credit card (e.g. Visa), and so on.

In this centralized model, the bank authenticates you, and guarantees the recipient that they are getting real money.
In other words, unless there is a direct physical transfer of value from one individual to the other, there must be some intermediary that exists that we âtrustâ.
Blockchains are no different.
Blockchains define a protocol that allows two individuals to transact with one another in a âpeer-to-peerâ manner over the Internet. When you digitally transfer value from one account to another on the blockchain, youâre trusting the underlying blockchain system to both enable that transfer and ensure sender authenticity and currency validity.

In a âcentralizedâ system, we trust a single third party (e.g. Chase Bank) to act as the intermediary who guarantees those two properties; in a âdecentralizedâ system, our trust is placed elsewhere, namely in public-key cryptography and a âconsensus mechanismâthat allows us to determine the truth.
Public-Key Cryptography
Public key cryptography (or asymmetrical cryptography) uses:
- a set of public keys visible to anyone, and
- a set of private keys visible only to the owner
The private key generates a âdigital signatureâ for each blockchain transaction that a user sends out. The signature ensures authenticity by:
- confirming that the transaction is coming from the user, and
- preventing the transaction from being altered by anyone once it has been issued
Changing the transaction message in any way will cause verification to fail.

Okay, so weâve figured out that public-key cryptography helps us authenticate users in a peer-to-peer system. But to ensure no double spending, we need to keep track of who has what so that we can know whether someone is sending real digital money or fake digital money.

This is where the âconsensus systemâ â which allows us to preserve a digitally shared truth â must come into play.
Machine Consensus (The Cryptoeconomic Protocol)
Blockchains have a shared ledger that gives us the absolute truth of the state of the system. It use mathematics, economics, and game theory to incentivize all parties in the system to reach a âconsensusâ, or coming to an agreement on a single state of this ledger.
Letâs take Bitcoin, for example. The Bitcoin protocol has a consensus algorithm called âProof of Workâ that holds the system together. For a transaction to be settled between two consumers, the algorithm requires that a set of nodes (called âminersâ) compete to validate transactions by solving a complex algorithmic problem. In other words, Bitcoin âeconomically incentivizesâ miners to purchase and use compute power to solve complex problems. These economic incentives include:
- miners earning a transaction fee that users pay for carrying out a transaction, and
- miners earning new Bitcoins for successfully solving the puzzle
Because of these economic incentives, miners are constantly watching the network so that they can gather a new set of transactions to fit into a new âblock.â Then they use their computing resources to solve the complex algorithm in order to âproveâ that they did some work.
The first miner to solve the algorithm adds the proof and the new block (and all the transactions in it) to the blockchain and broadcasts it to the network. At that point, everyone else in the network syncs the latest blockchain because itâs a âtruthâ everyone believes in.

Since miners are competing to run computations, there are times when multiple blocks get solved at the same time. This then creates a âforkâ of multiple chains:

When there are forks like this, the networkâs âcanonicalâ chain is the one which is the âlongestâ â the one which the most amount of miners trusted and continued to work on.

Every new block thatâs added to the blockchain in this manner adds more security to the system because an attacker who wants to create new blocks that overwrite a party of history would need to consistently solve for the puzzle faster than anyone else in the network. This is practically impossible to do, making itâs impossible to reverse engineer or alter the data inside these blocks. This is why users trust continue to trust the system.
So when we transact with one another on the blockchain, we areanchoring our trustin the miners who are giving up their resources to do some work to ensure no double spending.
Social Consensus (Governance)
Of course, even if the machine consensus works perfectly, we can never guarantee a 100% probability of reaching consensus on other important aspects required to maintain trust in the network. For example, when the underlying network needs to be upgraded, improved, or repaired, we need some way to trust that the network and all its constituents can appropriately handle the changes. In such cases, itâs very much a coordination effort amongst constituents, or what I would call a âsocial consensusâ (e.g. governance).
For example, if the blockchain requires an improvement (e.g. better transaction logs), we need a governance mechanism that coordinates the interests of all parties involved (users, developers, investors, etc.) in coming up with the best solution. Or if thereâs a controversy on the best path forward (e.g. a contentious fork), then a community needs to form a consensus on what to do next. If an agreement canât be reached, the network forks, and people are forced to choose one side over another instead of everyone believing in a shared truth. Users would lose trust in the system because they would be unable to reasonably determine which chain was the âvalidâ chain.
As I described in a previous post (bullet #6), there are many different models for blockchain governance and it remains an area of active research in the community. Blockchain governance is an incredibly tricky problem and finding a balance between centralized and distributed control will be essential to maintaining everyoneâs trust in the system.
Conclusion
When we say blockchains are âtrustless,â what we mean is that there are mechanisms in place by which all parties in the system can reach a consensus on what the canonical truth is. Power and trust is distributed (or shared) among the networkâs stakeholders (e.g. developers, miners, and consumers), rather than concentrated in a single individual or entity (e.g. banks, governments, and financial institutions).
Perhaps a more accurate way to describe blockchains is not as âtrustless,â but as built on the basis of distributed trust: We are trusting everyone in aggregate.
Of course, this assumes that we trust that a majority of the power held in the system belongs to stakeholders who share similar values. Unfortunately, I donât think we can claim â at least, not yet â to have figured out exactly what those shared values consist of. Hence the proliferation of blockchains and contentious forks in the past year ⊠but thatâs a long-winded topic for another day! đ
Bitcoin turning into a multi layered system is the most interesting thing in crypto in 2018
By BĂšr Kessels
Posted February 2, 2018
When you use Tinder, and you swipe someone, you probably donât sit there thinking âLetâs create some TCP packages and send them over IP, hoping they reach the phone of that nice looking fellow thereâ. You probably just think in terms of âlets swipe this nice fellow, Leoâ
Iâm bringing Tinder into this story to show the power of a layered architecture. You can swipe Leo because the Internet is made out of layers that You, Tinder, your phone, apps, your browser, can use for âfreeâ. Disclaimer: I donât actually have a Tinder, so I actually donât know if âswipingâ is the right term. But, well, this is a story about Bitcoin.
So, TCP/IP is made up out of four layers: Link layer, Internet Layer, Transport Layer and Application Layer. For this story, only the last two are interesting. On the internet, data is transported in the transport layer. Applications such as your browser, Tinder, your email-client or even the security camera at your front-door, use the transport layer to transport data. The power of this design becomes apparent if you turn it around: Applications donât need to invent, maintain or run their own network, cables, or protocols. They can just tell the Transport layer âHey, Iâve got a swipe, for Leo, can you deliver it to the Tinder servers? (so they can send it along to Leo)â.
Now, back to Bitcoin. The Bitcoin community is rolling out this thing called âLightning Network â. It is a layer on top of Bitcoin, in which value can be transported between people (aka âmake paymentsâ). It is one of the possible layers that can run on top of Bitcoin, but it is the first, and an important one: making payments is one of the most important features of Bitcoin today, so logically that this is the first thing to be moved into an application layer.
This Lightning Network can be used today. Sure, Leo needs to have a Lightning Network enabled client as do you, you might need to compile some stuff, might need to run your own server and so on, but it is possible. Today.
Essentially Lightning Network is the birth of an application layer on top of Bitcoin. This might seem uneventful, but the birth of this second layer gives Bitcoin a new purpose: it âdegradesâ Bitcoin to a mere transport layer for value. This is not some âPop! And weâre doneâ event, but a long process. Right now, Bitcoin is that transport layer, but is also, still an application layer: you can buy pizza, or buy beekeeping-gear through this transport layer, just fine. So it isnât very layered yet.
| This new layer is going to be so much better at this âpayingâ thing, that it will take an important feature âawayâ from Bitcoin: payments. But, before you get all angry: like with TCP/IP, one can use a layer directly, if you wish. You can just skip the transport layer, and deliver data directly over one of the lower layers, if you insist. You application can skip all the application layer stuff and interact with the transport layer directly, which happens a lot, actually. Youâve probably seen these âUse TCP/IP | use UDPâ-toggles in some settings of some app. Here an app can bypass, say, HTTP, TCP and so on, and use a much more raw way of delivering. You can still interact with Bitcoin, in order to transfer or manage funds, just fine. Itâs just that with this new Application layer, it will become much easier to just use that instead. |
If you want to buy takeway, or beekeeping gear, today, both you and the recieving party interact with the Transport layer directly. Tomorrow, we both will interact with an application layer; probably the Lightning Network, to settle that payment instead.
There will be more layers on top of Bitcoin, there will be layers on top of layers on top of layers, but deep down below, Bitcoin is the Layer that ensures value is transferred from you to Leo.
To me, this proves, again, that Bitcoin, as a project, âGets Itâ. Bitcoin does not need to be everything: it only needs to be a system to store and transfer value. Nothing more!
It does not need to invent, develop and maintain all the layers, just like Tinder does not need to maintain and invent everything from cables to how-to-get-a-swipe-to-Leo-protocols. Bitcoin needs to be a very secure, very solid, very stable layer to maintain these funds for all the layers on top of it. And Bitcoin is just that.
We should note, though, that a layered architecture was not envisioned by the inventor and early adopters of Bitcoin. They envisioned it more as a monolith: a single piece of software that handles all the possible use-cases and features in itself. At least, that is how I read the whitepaper: no-where was there a mention of âApplication layersâ or even âlayersâ.
Second layers can choose different models, use-cases, or different parameters. Lightning Network is complex but also (very) secure. It is decentralised, albeit maybe (time will tell) less so than Bitcoin itself. Other networks might opt for less security. Or even more centralisation. Or tweak other parameters.
If, for example, all you need to register is âI still owe you a beerâ, there could very well be a layer that maintains âall the beers owed by everyoneâ in a central database (or itâs own blockchain) and which registers a daily âstate of the beerâ on the Bitcoin layer. The possibilities are endless.
A lot of altcoins (or their advocates) did not design a layered system either. So many of these altcoins offer some âfeatureâ, like âspeedâ, or âprogrammabilityâ, or âthe ability to track bananasâ in their core. They often present those built-in features as âthe Bitcoin killerâ, but frankly, most of them have implemented these feature in the wrong place: as core part of their entire system, rather than as additional layers on top of standard value-transport-layers.
When you start looking at Bitcoin as âmerelyâ a the transport-layer for value, you might start to see the opportunities for other layers on top. And you might see a missing feature as good design, rather than as a missed opportunity, or as a sign that Bitcoin is doomed.
You donât need âinstant transactions, zero-feeâ in your transport-layer, you need that in your application layer. So saying that âRipple is better because it can scale up to Visa-Scaleâ is nonsense, because you should also mention the trade-off: Ripple has chosen to give away a lot of security maybe even all of it, in order to gain speed. And yes, Iâm picking out Ripple because I consider that the biggest scam of the 21st century (closely followed by the Roger Ver Coin, by the way). Also, Iâm not saying that it is a zero-sum game: that you can choose either speed or security. But making trade-offs is part of the game. Bitcoin does not make trade-offs if that hurts the decentralisation-property, or if it hurts security.
TCP/IP is not a very efficient system. A lot of resources are spent to ensure your âswipe for Leoâ ends up at Leoâs phone and not at Marksâ phone, or even your current boyfriends phone. In some cases this overhead can be âridiculousâ: sometimes far more data is sent around ensuring that your swipe arrives at the right place, than the actual content of, say, the swipe itself. I mean: TCP/IP is brilliant, but it needs a lot of trade-offs to be fault-tolerant, decentralised, secure and stable. Sometimes systems choose different protocols because TCP/IP is just not fast enough: you donât connect your computer-screen over the network to your computer, you use HDMI, or VGA: some other protocol that is much better at delivering pixels to your screen.
Bitcoinâs function is similar: it needs to be solid and secure. It must be slow and clunky, if that is what is needed to be solid and secure. Itâs sole function is to guarantee that your funds are secure, that transactions are valid and that there is no single party that can take over the network or your funds.
As such, Bitcoin does not include a âprogramming languageâ, like Ethereum does (Note: I actually do like Ethereum but for different reasons), because Bitcoin chooses security over âfancyâ new features like programming languages. It leaves things like âsmart contractsâ or âprogrammabilityâ to another layer. Instead of including it in the base layer. Note, though that such a smart-contract-layer does not (really) exist yet, but nothing fundamental stops it from being rolled out.
Nor does Bitcoin offer very good privacy (compared to e.g. Monero or Dash). But there could very well be an application layer, some alternative to Lightning Network that enhances privacy. So, rather than building it into the base layer, it leaves increased privacy to the application layer.
Bitcoin does not offer an exchange in itâs base-layer either (Like e.g. Stellar does). Nor does it offer file-storage, computing power or tracking of Bananaâs in itâs base layer.
By not implementing features, by choosing to be conservative, Bitcoin remains the most secure, most solid, and most predictable Transport Layer for transporting value. Ever. Exactly the features you want from such a basic layer.
As a closing note, Iâd like to stress that there certainly are altcoin-projects that are completely layered by design. Quite some âcryptocurrency projectsâ are actually an application layer on top of another transport layer: a vast majority of altcoins are basically tokens on Ethereum: they are the Application layer on top of Ethereum! So: Iâm not saying that all altcoins are wrong and only Bitcoin getâs it right: Iâm only offering an alternative way to view Bitcoin: not as a polished, finished, fancy project to be downloaded from the iTunes store, but as a single, technical layer. An important component in a vast and rapidly changing new field: managing value online.
Positive feedback, as well as images of cats, calling me literally hitler for hating on your beloved altcoins, or other comments are very welcome at my twitter or on reddit.
The Anatomy of Proof-of-Work
By Hugo Nguyen
February 10, 2018
This is Part 1 of a 5 part series
- Part 1 - The Anatomy of Proof-of-Work
- Part 2 - Bitcoin, Chance and Randomness
- Part 3 - How Cryptography Redefines Private Property
- Part 4 - Bitcoinâs Incentive Scheme and the Rational Individual
- Part 5 - Bitcoin: Two Parts Math, One Part Biology
Proof-of-Work (PoW) was originally invented as a measure against email spams. Only later it was adapted to be used in digital cash [1].
What PoW mining actually does under the hood, is that it converts kinetic energy (electricity) into a ledger block. A mining machine repeatedly performs hash operations until it solves a cryptographic puzzle. All hash operations are thrown away except for the one hash that solves it.
This one tiny hash, which itself takes very little energy to compute, is a direct representation of the huge ball of energy that was required to produce it. The âproofâ that the block was minted. In order to rewrite the block, an attacker later will have to spend a roughly equivalent number of hash operations that was originally required.
Letâs say that again: reverting takes an equivalent number of hash operations, not an equivalent amount of energy. That is because the hash is only a representation of the energy used, not the energy itself.
Over time, this representation of energy becomes less & less accurateâââas improved hardware becomes more efficient. Energy itself doesnât change, but its old representations âleakâ.
Another way to visualize this process, is to think of PoW mining as attaching physical weights to virtual blocks. Over time the older blocks get damaged and get lighter & lighter. This also reduces the total weight of the chain, all else being equal.
Bitcoin combats this attrition process by constantly creating new blocks with fresh weights. This ensures that the tip of the chain is always heavy in the present, protecting the integrity of the entire chain. Heavy chain == secure chain.
(Some have suggested that âheaviest chainâ is a better terminology than Satoshiâs âlongest chain.â Longest chain can be very misleading when we donât really mean length in the literal sense.)
SHA256 is the hash function that backs Bitcoin PoW mining. SHA256 protects the ledger from being rewritten. One hash in (to mine), one hash out (to revert). This is what gives Bitcoin its immutability property [2].
Itâs amazing when you think about it. Hash operations dedicate their entire existence to the purpose of securing the ledger! Rarely anything in the real world has 100% dedication & efficiency. (e.g.: contrast that with gasoline & the combustion engine).
In reality, it is probably not 100% but something close to it. Because irreversibility relies on the hashed results being uniformly random (just like when you roll a fair dice), and algorithms canât truly simulate real-world randomness.
Luckily for us, hash functions such as SHA256 have shown to be sufficiently random, aka âpseudorandomâ. SHA256 has been reviewed & stress-tested for years, and has a rich research literature behind it. So itâs not something we have to be too concerned about (yet).
Fundamentally, I believe the idea of âattaching energyâ to blocks is the right one & probably the only way to simulate immutability virtually.
Using energy burnt to back a block allows us to view immutability objectively. Whereas any non-energy-based method ultimately requires someoneâs subjective interpretation of immutability . [3]
By attaching energy to a block, we give it âformâ, allowing it to have real weight & consequences in the physical world. We can also think of PoW as the magic that brings a bunch of 0s & 1s into life.
In other words, PoW is the bridge between the digital & the physical.
Compare that to some cryptokitties that someone creates, modifies & removes as they see fit. Their uniqueness & existence are neither guaranteed nor reliable.
Even if the current variant of PoW fails, Iâm confident that there will be other ways of attaching energy to a block.
In conclusion, PoWâs application in blockchains might prove to be far more significant & wide reaching than what it was originally invented for. PoW gives us immutability, which gives us uncensorable money, which could potentially change how society organizes itself. (Read Nick Szaboâs wonderful essay on social scalability for more on that.)
*This is part 1 of the Bitcoin Fundamentals series. Check out the full series here: part 1 , part 2 , part 3 , part 4 , and part 5 .
[1]: The idea of using PoW in digital cash might have originated from Wei Daiâs b-money & Nick Szaboâs bitgold proposals in the late 90âs. Hal Finney created the first implementation of PoW in digital cash (RPOW) in 2004.
[2]: Immutability is a relative concept. When we say âimmutabilityâ we usually mean itâs practically immutable, not absolutely immutable. Even Gold can be synthesized given enough energy.
[3]: One such method is Proof-of-Stake. Read my article on Proof-of-Stake to understand its pitfalls & why it might be inferior to Proof-of-Work.
Crypto Innovation Spotlight: Schnorr Signatures
By Spencer Bogart
Posted February 22, 2018
Amid the commotion and flurry of excitement as crypto surged into mainstream, the significant implications of many real fundamental innovations being developed have been drowned out by the din of hand-wavy, hyperbolic claims. In this_ **_âCrypto Innovation Spotlightâ_ _series, I hope to shine a light on fundamental innovations that are driving our industry forward.**
Schnorr â What is it?
Schnorr is a digital signature algorithm. A digital signature algorithm, among other things, determines the relationship between public keys and private keys (âaddressâ and âpasswordâ) â which means the choice has significant implications for security.
In addition, because digital signatures are a significant portion of all the data that comprises a transaction, the choice of digital signature algorithm has significant implications for privacy and efficiency.
If adopted, Schnorr would be an alternative to Bitcoinâs current ECDSA (Elliptic Curve Digital Signature Algorithm).
What does it do?
To start, Schnorr signatures are appealing because theyâre easy to compute and considered highly secure. However, the main benefits of Schnorr signatures actually derive from their aggregation capabilities.
What does âaggregation capabilitiesâ actually mean? What are we aggregating?
To put it simply, Schnorr signatures can aggregate multiple distinct signature into a single signature. This signature aggregation capability is particularly valuable in light of the amount of space that is consumed by signature data in a Bitcoin transaction â this is depicted visually in Figures 1 & 2, below:
Figure 1: A standard Bitcoin transaction. Note how much space is consumed by signature data (highlighted in yellow) Source: Class materials from Jimmy Songâs Programming Blockchain Seminar
Even worse, this signature data grows in size linearly with the number of signers in a multi-signature transaction. For example, the yellow signature area in the figure above nearly doubles when we go from a standard transaction (1-of-1) to a 2-of-2 multi-signature transaction, as illustrated in Figure 2 below.
Figure 2: A multi-signature Bitcoin transaction â signature data highlighted in yellow. Source: Class materials from Jimmy Songâs Programming Blockchain Seminar
Schnorr signature aggregation is potentially helpful in a few different ways that each has derivative benefits for the Bitcoin network and its users.
First, the ability to aggregate multiple signatures into a single signature is particularly valuable for âmulti-signature transactionsâ â that is, Bitcoin transactions that require multiple signatures in order to be considered valid by the network. In Bitcoinâs current structure, these âmulti-signatureâ transactions are much larger than standard single-signature transactions â which has negative implications for efficiency and privacy (more on that later).

Second, it appears itâs also possible to extend to concept of Schnorr signature aggregation â with a scheme known as MuSig â to aggregate the signatures pertaining to multiple UTXOs into a single signature. Conceptually, itâs the same process as the example above but instead of just aggregating multiple-signatures that are required to spend a single UTXO, we extend the concept to also consolidate signatures across multiple UTXOs.
The end result is that while the former example enables us to achieve 1 signature per UTXO (even if the UTXO is technically constrained by multiple signatures), the latter example helps us to achieve 1 signature per transaction (which in itself could consume multiple UTXOs as inputs). This would mean a drastic reduction in the amount of data that needs to be processed and stored across the Bitcoin network (the benefits of which are discussed in more detail below).
Why do we care? What are the advantages and economic implications?
In short, these aggregation capabilities improve Bitcoinâs efficiency and privacy.
In terms of efficiency, the big benefit is smaller transactions â which means lower storage and computation costs. Indeed, Schnorr multi-signature transactions are even more compact and efficient than single-signature transactions in Bitcoin today. Thatâs important because it lowers transaction fees for users and minimizes resource requirements for network participants (e.g. full nodes, mining).
Also, because Schnorr multi-signature transactions are the same size and cost as non-multi-signature transactions, the adoption of Schnorr signatures should encourage an increasing variety â and perhaps complexity â of multi-signature transactions on the network. Itâs a win-win: Users can create more complex transaction arrangements without burdening the network or incurring additional costs.
In terms of privacy, the advantages of a Schnorr signatures (or a Schnorr-based scheme like MuSig) are two-fold. The first is that multi-signature transactions are indistinguishable from single-signature transactions. Second, an aggregated Schnorr multi-sig does not reveal the individual public key inputs (participants of the multi-sig contract).
Said differently, Schnorr signatures help us avoid leaking info about the public-key identities that are party to a multi-sig contract and even help us avoid revealing whether or not a transaction is multi-sig or not.
Lastly, Schnorr-based MuSig could also offer an indirect privacy advantage by improving the economics of multi-sig contracts: if we can aggregate signatures across multiple UTXOs, MuSig could incentivize the usage of privacy-enhancing functions such as âcoinjoinâ. That is, with MuSig, users could realize lower transaction costs by aggregating their transactions with others (effectively sharing the cost of your transactions space with others) â which would improve network privacy as a whole.
Ultimately, Iâm excited about the potential for Schnorr signatures in Bitcoin because they reduce the size of transactions (lower cost, less network overhead), minimize network resource demands (easier for people to verify transactions), and improve privacy.
Key People & Resources
· Research paper âSimple Schnorr Multi-Signatures with Applications to Bitcoinâ authored by Gregory Maxwell, Andrew Poelstra, Yannick Seurin, Pieter Wuille, Jan 1018
· Bitcoin.org blog post summarizing the benefits of Schnorr signatures.
Acknowledgements
Thank you to Andrew Poelstra and Jimmy Song for generously reviewing earlier drafts and offering corrections.
Bitcoin as a Display of Wealth
By Elaine Ou
Posted February 25, 2018
I just spent three weeks in bed with the flu from hell, which means I not only missed Bitcoinâs untimely death, but also its subsequent resurrection. Did everyone remember to buy the dip?
Gold is actually useful for some things, like filling teeth and making pretty jewelry; thatâs not most of its value, but it does provide a tether to reality, along with a 5000-year history 9/
â Paul Krugman (@paulkrugman) January 21, 2018
Had I been alert and conscious, I might have worried for a bit. Paul Krugman doesnât know anything about anything, but Iâll grant him this one: Thereâs nothing to backstop a cryptocurrencyâs value! If people come to believe that Bitcoin is worthless, itâs worthless. Thereâs no tether to reality đź. If only Bitcoin could be used to make pretty jewelry!
One of the greatest tragedies of modern money is the decoupling between a store and display of wealth. Or, more accurately, the societal decoupling between wealth and status. For most of human history, the functions of display and storage were condensed. Even before people wore clothing, they wore piercings and tattoos. A full-body ink job isnât transferable, but itâs a sort of proof of work.

Tribal tattoos on a mummified Scythian chieftain, 500 BC.
As societies increased in wealth, both people and objects became specialized in their functions. Stores of value were selected for their resistance to corrosion and theft. Displays of status optimize for just the opposite. The more unwieldy and vulnerable the display, the greater the power it conveys.

Thereâs no reliable way to physically project a bank account balance, so we use costly signals as a proxy. Designer shoes indicate disposable income. A diamond ring reveals your spouseâs bimonthly salary. An American Express Centurion card communicates the ability to spend half a million dollars a year.

Abundance signaling is wasteful, and often relies on a trusted third party to maintain the integrity of the signal. Bitcoin is regarded as a decentralized store of value, but still underappreciated as a way to disintermediate our displays of wealth.
Crypto-Bling

Cryptokitties, ugh. Why would anyone waste a perfectly good blockchain on a centrally controlled collectible? The only way to generate a cat image is to rely on the Cryptokitties website. And the only way to prove ownership of that image is to reveal your account address. Thereâs a better way to flaunt crypto wealth.
âWould you like to buy a provably scarce digital kitty?â pic.twitter.com/V6ukOCYguI
â Jameson Lopp (@lopp) December 4, 2017
Secure multi-party computations were first introduced in 1982 as a solution to the Millionairesâ Problem: Multiple millionaires want to know their relative wealth standing, but no one wants to reveal their actual net worth.
One solution is to distribute shares of a secret to each participant. Each person combines the secret with the value of their net worth, broadcasts the result, and a blinded function processes the values to arrive at the final rankings. This function evaluation forms the basis for a zero-knowledge proof.
This can be done with any cryptocurrency. Instead of self-reporting a net worth, each participant signs a message to prove ownership of an account. The message is combined with a secret share, resulting in an output that indicates the userâs balance relative to everyone else. Turn the output into crypto-bling by mapping it to a unique identicon. Bitcoin can now be used as a visual display of wealth.

The identicons can even be made unforgeable. If each viewer distributes a different secret, then the set of identicons will look different to every observer while still communicating the same information about relative status. A display of wealth, then, is in the eye of the beholder.

WordPress identicons
But an identicon isnât prettyâŠ
Paul Krugman is wrong about the pretty jewelry, cuz thatâs not what gold is about. Objectively speaking, silver is the most light-reflective element that exists. If you wanted to bedeck yourself in bling bling, youâd get the most bang for your buck with silver. But pound for pound, gold is more valuable because itâs harder to obtain.
Gold isnât valuable because itâs used for jewelry, jewelry is valuable because itâs made of gold. âNick Szabo
A display of wealth isnât about being pretty, itâs about having stuff that others donât. Roman emperors knew that wealth displays were a wasteful arms race, so they created sumptuary laws to prohibit conspicuous consumption.
Bitcoin bling removes the costly signaling by re-condensing the functions of a store and display of value, and does so without the need for a trusted third party. Someday, crypto-bling will be the prettiest bling around.
The Bullish Case for Bitcoin (part 1 of 4)
By Vijay Boyapati
Posted February 26, 2018
The Bullish Case for Bitcoin (part 1 of 4)
Genesis and the origins of money
With the price of a bitcoin surging to new highs in 2017, the bullish case for investors might seem so obvious it does not need stating. Alternatively it may seem foolish to invest in a digital asset that isnât backed by any commodity or government and whose price rise has prompted some to compare it to the tulip mania or the dot-com bubble. Neither is true; the bullish case for Bitcoin is compelling but far from obvious. There are significant risks to investing in Bitcoin, but, as I will argue, there is still an immense opportunity.
Genesis
Never in the history of the world had it been possible to transfer value between distant peoples without relying on a trusted intermediary, such as a bank or government. In 2008 Satoshi Nakamoto, whose identity is still unknown, published a 9 page solution to a long-standing problem of computer science known as the Byzantine Generalâs Problem. Nakamotoâs solution and the system he built from it â Bitcoin â allowed, for the first time ever, value to be quickly transferred, at great distance, in a completely trustless way. The ramifications of the creation of Bitcoin are so profound for both economics and computer science that Nakamoto should rightly be the first person to qualify for both a Nobel prize in Economics and the Turing award.
For an investor the salient fact of the invention of Bitcoin is the creation of a new scarce digital good â bitcoins. Bitcoins are transferable digital tokens that are created on the Bitcoin network in a process known as âminingâ. Bitcoin mining is roughly analogous to gold mining except that production follows a designed, predictable schedule. By design, only 21 million bitcoins will ever be mined and most of these already have been â approximately 16.8 million bitcoins have been mined at the time of writing. Every four years the number of bitcoins produced by mining halves and the production of new bitcoins will end completely by the year 2140.

Bitcoins are not backed by any physical commodity, nor are they guaranteed by any government or company, which raises the obvious question for a new bitcoin investor: why do they have any value at all? Unlike stocks, bonds, real-estate or even commodities such as oil and wheat, bitcoins cannot be valued using standard discounted cash flow analysis or by demand for their use in the production of higher order goods. Bitcoins fall into an entirely different category of goods, known as monetary goods, whose value is set game theoretically. I.e., each market participant values the good based on their appraisal of whether and how much other participants will value it. To understand the game theoretic nature of monetary goods we need to explore the origins of money.
The Origins of Money
In the earliest human societies, trade between groups of people occurred through barter. The incredible inefficiencies inherent to barter trade drastically limited the scale and geographical scope at which trade could occur. A major disadvantage with barter based trade is the double coincidence of wants problem. An apple grower may desire trade with a fisherman, for example, but if the fisherman does not desire apples at the same moment, the trade will not take place. Over time humans evolved a desire to hold certain collectible items for their rarity and symbolic value (examples include shells, animal teeth and flint). Indeed, as Nick Szabo argues in his brilliant essay on the origins of money, the human desire for collectibles provided a distinct evolutionary advantage for early man over his nearest biological competitors, homo neanderthalis.
The primary and ultimate evolutionary function of collectibles was as a medium for storing and transferring wealth.
Collectibles served as a sort of âproto-moneyâ by making trade possible between otherwise antagonistic tribes and by allowing wealth to be transferred between generations. Trade and transfer of collectibles were quite infrequent in paleolithic societies and these goods served more as a âstore of valueâ rather than the âmedium of exchangeâ role that we largely recognize modern money to play. Szabo explains:
Compared to modern money, primitive money had a very low velocity â it might be transferred only a handful of times in an average individualâs lifetime. Nevertheless, a durable collectible, what today we would call an heirloom, could persist for many generations and added substantial value at each transfer â often making the transfer even possible at all.
Early man faced an important game theoretic dilemma when deciding which collectibles to gather or create: which objects would be desired by other humans? By correctly anticipating which objects might be demanded for their collectible value, a tremendous benefit was conferred to the possessor in their ability to complete trade and to acquire wealth. Some Native American tribes such as the Narragansetts, specialized in the manufacture of otherwise useless collectibles simply for their value in trade. It is worth noting that the earlier the anticipation of future demand for a collectible good, the greater the advantage conferred to its possessor; it can be acquired more cheaply than when it is widely demanded and its trade value appreciates as the population which demands it expands. Furthermore, acquiring a good in hopes that it will be demanded as a future store of value hastens its adoption for that very purpose. This seeming circularity is actually a feedback loop that drives societies to quickly converge on a single store of value. In game theoretic terms this is known as a âNash Equilibriumâ. Achieving a Nash Equilibrium for a store of value is a major boon to any society as it greatly facilitates trade and the division of labor, paving the way for the advent of civilization.

Over the millennia, as human societies grew and trade routes developed, the stores of value that had emerged in individual societies came to compete against each other. Merchants and traders would face a choice of whether to save the proceeds of their trade in the store of value of their own society or the store of value of the society they were trading with, or some balance of both. The benefit of maintaining savings in a foreign store of value was the enhanced ability to complete trade in the associated foreign society. Merchants holding savings in a foreign store of value also had an incentive to encourage its adoption within their own society, as this would increase the purchasing power of their savings. The benefits of an imported store of value accrued not only to the merchants doing the importing, but also to the societies themselves. Two societies converging on a single store of value would see a substantial decrease in the cost of completing trade with each other and an attendant increase in trade based wealth. Indeed, the 19th century was the first time when most of the world converged on a single store of value â gold â and this period saw the greatest explosion of trade in the history of the world. Of this halcyon period, Lord Keynes wrote:
What an extraordinary episode in the economic progress of man that age was ⊠for any man of capacity or character at all exceeding the average, into the middle and upper classes, for whom life offered, at a low cost and with the least trouble, conveniences, comforts, and amenities beyond the compass of the richest and most powerful monarchs of other ages. The inhabitant of London could order by telephone, sipping his morning tea in bed, the various products of the whole earth, in such quantity as he might see fit, and reasonably expect their early delivery upon his doorstep
Part 2âŠ
Part 2 of this article will be published tomorrow and linked from Twitter (follow me). In part 2, I will cover the attributes that make a good store of value and how Bitcoin compares to other monetary goods, such as gold and fiat currencies, across these attributes.
Translations
This article has been translated into:
- Traditional Chinese by Flora Sun
- Simplified Chinese by Flora Sun
- Español by Iñigo with editing by Carlos Beltrån.
- Nederlandse by Wim.
- Française by Greg Guittard.
- Italiano by Ryan DeLongpre.
- PortuguĂȘs by Allex Fer.
- ŃŃŃŃĐșĐžĐč/Russian by CoinSpot.
The Bullish Case for Bitcoin (part 2 of 4)
By Vijay Boyapati
Posted February 27, 2018
The Bullish Case for Bitcoin (part 2 of 4)
The attributes of a good store of value
When stores of value compete against each other, it is the specific attributes that make a good store of value that allows one to out-compete another at the margin and increase demand for it over time. While many goods have been used as stores of value or âproto-moneyâ, certain attributes emerged that were particularly demanded and allowed goods with these attributes to out-compete others. An ideal store of value will be:
- Durable: the good must not be perishable or easily destroyed. Thus wheat is not an ideal store of value
- Portable: the good must be easy to transport and store, making it possible to secure it against loss or theft and allowing it to facilitate long distance trade. A cow is thus less ideal than a gold bracelet.
- Fungible: one specimen of the good should be interchangeable for another of equal quantity. Without fungibility the double coincidence of wants problem remains unsolved. Thus gold is more ideal than diamonds which are irregular in shape and quality.
- Verifiable: the good must be easy to quickly identify and verify as authentic. Easy verification increases the confidence of its recipient in trade and increases the likelihood a trade will be consummated.
- Divisible: the good must be easy to subdivide. While this attribute was less important in early societies where trade was infrequent, it became more important as trade flourished and the quantities exchanged became smaller and more precise.
- Scarce: As Nick Szabo termed it, a monetary good must have âunforgeable costlinessâ. In other words, the good must not be abundant or easy to either obtain or produce in quantity. Scarcity is perhaps the most important attribute of a store of value as it taps into the innate human desire to collect that which is rare. It is the source of the original value of the store of value.
- Established history: the longer the good is perceived to have been valuable by society, the greater its appeal as a store of value. A long established store of value will be hard to displace by a new upstart except by force of conquest or if the arriviste is endowed with a significant advantage among the other attributes listed above.
- Censorship resistant: a new attribute that has become increasingly important in our modern, digital society with pervasive surveillance is censorship resistance. That is, how difficult is it for an external party such as a corporation or state to prevent the owner of the good from keeping and using it. Goods that are censorship resistant are ideal to those living under regimes that are trying to enforce capital controls or to outlaw various forms of peaceful trade.
The table below grades Bitcoin, gold and fiat money (such as dollars) against the attributes listed above and is followed by an explanation of each grade:

Durability:
Gold is the undisputed King of durability. The vast majority of gold that has ever been mined or minted, including the gold of the Pharaohs, remains extant today and will likely be available a thousand years hence. Gold coins that were used as money in antiquity still maintain significant value today. Fiat currencies and bitcoin are fundamentally digital records that may take physical form (such as paper bills). Thus it is not their physical manifestation whose durability should be considered (since a tattered dollar bill may be exchanged for a new one), but the durability of the institution that issues them. In the case of fiat currencies, many governments have come and gone over the centuries and their currencies disappeared with them. The Papiermark, Rentenmark and Reichsmark of the Weimar Republic no longer have value because the institution that issued them no longer exists. If history is a guide, it would be folly to consider fiat currencies durable in the long term â the US dollar and British Pound are relative anomalies in this regard. Bitcoins, having no issuing authority, may be considered durable so long as the network that secures them remains in place. Given that Bitcoin is still in its infancy, it is too early to draw strong conclusions about its durability. However, there are encouraging signs that despite prominent instances of nation states attempting to regulate Bitcoin and years of attacks by hackers, the network has continued to function, displaying a remarkable degree of âanti-fragilityâ.
Portability:
Bitcoins are the most portable store of value ever used by man. Private keys representing hundreds of millions of dollars can be stored on a tiny USB drive and easily carried anywhere. Furthermore, equally valuable sums can be transmitted between people on opposite ends of the earth near instantly. Fiat currencies, being fundamentally digital are also highly portable. However, government regulations and capital controls mean that large transfers of value usually take days or may not be possible at all. Cash can be used to avoid capital controls, but then the risk of storage and cost of transportation become significant. Gold, being physical in form and incredibly dense, is by far the least portable. It is no wonder that the majority of bullion is never transported. When bullion is transferred between a buyer and a seller it is typically only the title to the gold that is transferred, not the physical bullion itself. Transmitting physical gold across large distances is costly, risky and time consuming.
Fungibility:
Gold provides the standard for fungibility. When melted down an ounce of gold is essentially indistinguishable from any other ounce, and gold has always traded this way on the market. Fiat currencies on the other hand are only as fungible as the issuing institutions allow them to be. While it may be the case that a fiat banknote is usually treated like any other by merchants accepting them, there are instances where large denomination notes have been treated differently to small ones. For instance, Indiaâs government, in an attempt to stamp out Indiaâs untaxed grey market, completely demonetized their 500 and 1000 rupee banknotes. The demonetization caused 500 and 1000 rupee notes to trade at a discount to their face value, making them no longer truly fungible with their lower denomination sibling notes. Bitcoins are fungible at the network level, meaning that every bitcoin, when transmitted, is treated the same on the Bitcoin network. However, because bitcoins are traceable on the blockchain, a particular bitcoin may become tainted by its use in illicit trade and merchants or exchanges may be compelled to not accept such tainted bitcoins. Without improvements to the privacy and anonymity of Bitcoinâs network protocol, bitcoins cannot be considered as fungible as gold.
Verifiability:
For most intents and purposes both fiat currencies and gold are fairly easy to verify for authenticity. However, despite providing features on their banknotes to prevent counterfeiting, nation states and their citizens still face the potential to be duped by counterfeit bills. Gold is also not immune from being counterfeited. Sophisticated criminals have used gold plated tungsten as a way of fooling gold investors into paying for false gold. Bitcoins on the other hand can be verified with mathematical certainty. Using cryptographic signatures, the owner of a bitcoin can publicly prove she owns the bitcoins she says she does.
Divisibility:
Bitcoins can be divided down to a hundred millionth of a bitcoin and transmitted at such infinitesimal amounts (network fees can, however, make transmission of tiny amounts uneconomic). Fiat currencies are typically divisible down to pocket change which has little purchasing power, making fiat divisible enough in practice. Gold, while physically divisible, becomes difficult to use when divided into small enough quantities that it could be useful for lower value day-to-day trade.
Scarcity:
The attribute that most clearly distinguishes Bitcoin from fiat currencies and gold is its predetermined scarcity. By design at most 21 million bitcoins can ever be created. This gives the owner of bitcoins a known percentage of the total possible supply. For instance, an owner of 10 bitcoins would know that at most 2.1 million people on earth (less than 0.03% of the worldâs population) could ever have as many bitcoins as they had. Gold, while remaining quite scarce through history, is not immune to increases in supply. If it were ever the case that a new method of mining or acquiring gold became economic, the supply of gold could rise dramatically (examples include sea-floor or asteroid mining). Finally, fiat currencies, while only a relatively recent invention of history, have proven to be prone to constant increases in supply. Nations states have shown a persistent proclivity to inflate their money supply to solve short term political problems. The inflationary tendencies of governments across the world leaves the owner of a fiat currency with a certainty that their savings will likely diminish in value over time.
Established history:
No monetary good has a history as long and storied as gold, which has been valued for as long as human civilization has existed. Coins minted in the distant days of antiquity still maintain significant value today. The same cannot be said of fiat currencies which are a relatively recent anomaly of history. From their inception, fiat currencies have had a near universal tendency toward eventual worthlessness. The use of inflation as an insidious means of invisibly taxing a citizenry has been a temptation that few states in history have been able to resist. If the 20th century, in which fiat monies came to dominate the global monetary order, established any economic truth, it is that fiat money cannot be trusted to maintain its value over the long or even medium term. Bitcoin, despite its short existence, has weathered enough trials in the market that there is a high likelihood it will not vanish as a valued asset any time soon. Furthermore, the Lindy effect suggests that the longer Bitcoin remains in existence the greater societyâs confidence that it will continue to exist long into the future. In other words, the societal trust of a new monetary good is asymptotic in nature, as is illustrated in the graph below:

If Bitcoin exists for 20 years there will be near universal confidence that it will be available forever, much as people believe the Internet is a permanent feature of the modern world.
Censorship resistance:
One of the most significant sources of early demand for bitcoin was its use in the illicit drug trade. Many subsequently surmised, mistakenly, that the primary demand for bitcoin was due to its ostensible anonymity. Bitcoin, however, is far from an anonymous currency; every transaction transmitted on the Bitcoin network is forever recorded on a public blockchain. The historical record of transactions allows for later forensic analysis to identify the source of a flow of funds. It was such an analysis that led to the apprehending of a perpetrator of the famous MtGox heist. While it is true that a sufficiently careful and diligent person can conceal their identity when using Bitcoin, this is not why Bitcoin was so popular for trading drugs. The key attribute that makes Bitcoin valuable for proscribed activities is that it is âpermissionlessâ at the network level. When bitcoins are transmitted on the Bitcoin network there is no human intervention deciding whether the transaction should be allowed. As a distributed peer-to-peer network, Bitcoin is, by its very nature, designed to be censorship resistant. This is in stark contrast to the fiat banking system where states regulate banks and the other gatekeepers of money transmission to report and prevent outlawed uses of monetary goods. A classic example of regulated money transmission is capital controls. A wealthy millionaire, for instance, may find it very hard to transfer their wealth to a new domicile if they wish to flee an oppressive regime. Although gold is not issued by states, its physical nature makes it difficult to transmit at distance, making it far more susceptible to state regulation than Bitcoin. Indiaâs Gold Control Act is an example of such regulation.
Bitcoin excels across the majority of attributes listed above, allowing it to outcompete modern and ancient monetary goods at the margin and providing a strong incentive for its increasing adoption. In particular, the potent combination of censorship resistance and absolute scarcity has been a very powerful motivator for many wealthy investors to allocate a portion of their wealth to the nascent asset.
Part 3âŠ
Part 3 of this article will be published tomorrow and linked from Twitter (follow me). In part 3, I will cover the evolution of money, how a monetary good transitions from a store of value to a medium of exchange and where Bitcoin is in its evolution to a fully fledged global money.
Go back to part 1.
Translations
This article has been translated into:
- Traditional Chinese by Flora Sun
- Simplified Chinese by Flora Sun
- Español by Carlos Beltrån with editing by Iñigo.
- Nederlandse by Wim.
- Française by Greg Guittard.
- PortuguĂȘs by Allex Fer.
- ŃŃŃŃĐșĐžĐč/Russian by CoinSpot.
The Bullish Case for Bitcoin (part 3 of 4)
By Vijay Boyapati
Posted February 28, 2018
The Bullish Case for Bitcoin (part 3 of 4)
The Evolution of Money
There is an obsession in modern monetary economics with the medium of exchange role of money. In the 20th century, states have monopolized the issuance of money and continually undermined its use as a store of value, creating a false belief that money is primarily defined as medium of exchange. Many have criticized Bitcoin as being an unsuitable money because its price has been too volatile to be suitable as a medium of exchange. This puts the cart before the horse, however. Money has always evolved in stages, with the store of value role preceding the medium of exchange role. One of the fathers of marginalist economics, Stanley Jevons, explained that:
Historically speaking ⊠gold seems to have served, firstly, as a commodity valuable for ornamental purposes; secondly, as stored wealth; thirdly, as a medium of exchange; and, lastly, as a measure of value.
Using modern terminology, money always evolves in the following four stages:
- Collectible. In the very first stage of its evolution, money will be demanded solely based on its peculiar properties, usually becoming a whimsy of its possessor. Shells, beads and gold were all collectibles before later transitioning to the more familiar roles of money.
- Store of value: Once it is demanded by enough people for its peculiarities, money will be recognized as a means of keeping and storing value over time. As a good becomes more widely recognized as a suitable store of value its purchasing power will rise as more people demand it for this purpose. The purchasing power of a store of value will eventually plateau when it is widely held and the influx of new people desiring it as a store of value dwindles.
- Medium of exchange: When money is fully established as a store of value its purchasing power will stabilize. Having stabilized in purchasing power, the opportunity cost of using money to complete trades will diminish to a level where it is suitable for use as a medium of exchange. In the earliest days of Bitcoin, many people did not appreciate the huge opportunity cost of using bitcoins as a medium of exchange, rather than as an incipient store of value. The famous story of a man trading 10,000 bitcoins (worth approximately $94 million at the time of this articleâs writing) for two pizzas illustrates this confusion.
- Unit of account. When money is widely used as a medium of exchange goods will be priced in terms of it. I.e., the exchange ratio against money will be available for most goods. It is a common misconception that bitcoin prices are available for many goods today. For example, while a cup of coffee might be available for purchase using bitcoins, the price listed is not a true bitcoin price; rather it is the dollar price desired by the merchant translated into bitcoin terms at the current USD/BTC market exchange rate. If the price of bitcoin were to drop in dollar terms, the number of bitcoins requested by the merchant would increase commensurately. Only when merchants are willing to accept bitcoins for payment without regard to the bitcoin exchange rate against fiat currencies can we truly think of Bitcoin having become a unit of account.
Monetary goods that are not yet a unit of account may be thought of as being âpartly monetizedâ. Today gold fills such a role, being a store of value but having been stripped of its medium of exchange and unit of account roles by government intervention. It is also possible that one good fills the medium of exchange role of money while another good fills the other roles. This is typically true in countries with dysfunctional states such as Argentina or Zimbabwe. In his book Digital Gold, Nathaniel Popper writes:
In America, the dollar seamlessly serves the three functions of money: providing a medium of exchange, a unit for measuring the cost of goods, and an asset where value can be stored. In Argentina, on the other hand, while the peso was used as a medium of exchange â for daily purchases â no one used it as a store of value. Keeping savings in the peso was equivalent to throwing away money. So people exchanged any pesos they wanted to save for dollars, which kept their value better than the peso. Because the peso was so volatile, people usually remembered prices in dollars, which provided a more reliable unit of measure over time.
Bitcoin is currently transitioning from the first stage of monetization to the second stage. It will likely be several years before Bitcoin transitions from being an incipient store of value to being a true medium of exchange and the path it takes to get there is still fraught with risk and uncertainty. It is striking to note that the same transition took many centuries for gold. No one alive has seen the real-time monetization of a good, as is taking place with Bitcoin, so there is precious little experience of the path this monetization will take.
Path dependence
In the process of being monetized a monetary good will soar in purchasing power. Many have commented that the increase in purchasing power of Bitcoin creates the appearance of a âbubbleâ. While this term is often using disparagingly, to suggest that Bitcoin is grossly overvalued, it is unintentionally apt. A characteristic that is common to all monetary goods is that their purchasing power is higher than can be justified by their use value alone. Indeed, many historical monies had no use value at all. The difference between the purchasing power of a monetary good and the exchange value it could command for its inherent usefulness can be thought of as a âmonetary premiumâ. As a monetary good transitions through the stages of monetization (listed in the section above) the monetary premium will increase. The premium does not, however, move in a straight, predictable line. A good X that was in the process of being monetized may be outcompeted by another Y that is more suitable as money and the monetary premium of X may drop or vanish entirely. The monetary premium of silver disappeared almost entirely in the late 19th century when governments across the world largely abandoned it as money in favor of gold.

Even in the absence of exogenous factors such as government intervention or competition from other monetary goods, the monetary premium for a new money will not follow a predictable path. Economist Larry White observed that:
the trouble with [the] bubble story, of course, is that is consistent with any price path, and thus gives no explanation for a particular price path
The process of monetization is game theoretic; every market participant attempts to anticipate the aggregate demand of other participants and thereby the future monetary premium. Because the monetary premium is unanchored to any inherent usefulness, market participants tend to default to past prices when determining whether a monetary good is cheap or expensive and whether to buy or sell it. The connection of current demand to past prices is known as âpath dependenceâ and is perhaps the greatest source of confusion in understanding the price movements of monetary goods.
When the purchasing power of a monetary good increases with increasing adoption, market expectations of what constitutes âcheapâ and âexpensiveâ shift accordingly. Similarly, when the price of a monetary good crashes, expectations can switch to a general belief that prior prices were âirrationalâ or overly inflated. The path dependence of money is illustrated by the words of well known Wall Street fund manager, Josh Brown:
I bought [bitcoins] at like $2300 and had an immediate double on my hands. Then I started saying âI canât buy more of it,â as it rose, even though thatâs an anchored opinion based on nothing other than the price where I originally got it. Then, as it fell over the last week because of a Chinese crackdown on the exchanges, I started saying to myself, âOh good, I hope it gets killed so I can buy more.â
The truth is that the notions of âcheapâ and âexpensiveâ are essentially meaningless in reference to monetary goods. The price of a monetary good is not a reflection of its cash flow or how useful it is but, rather, is a measure of how widely adopted is has become for the various roles of money.
Further complicating the path dependent nature of money is the fact that market participants do not merely act as dispassionate observers, trying to buy or sell in anticipation of future movements of the monetary premium, but also act as active evangelizers. Since there is no objectively correct monetary premium, proselytizing the superior attributes of a monetary good is more effective than for a regular goods, whose value is ultimately anchored to cash flow or use demand. The religious fervor of participants in the Bitcoin market can be observed in various online forums where owners actively promote the benefits of Bitcoin and the wealth that can be made by investing in it. In observing the Bitcoin market Leigh Drogen comments:
You recognize this as a religion â a story we all tell each other and agree upon. Religion is the adoption curve we ought to be thinking about. Itâs almost perfect â as soon as someone gets in, they tell everyone and go out evangelizing. Then their friends get in and they start evangelizing.
While the comparison to religion may give Bitcoin an aura of irrational faith, it is entirely rational for the individual owner to evangelize for a superior monetary good and for society as a whole to standardize on it. Money acts as the foundation for all trade and savings, so the adoption of a superior form of money has tremendous multiplicative benefits to wealth creation for all members of a society.
The shape of monetization
While there are no a priori rules about the path a monetary good will take as it is monetized, a curious pattern has emerged during the relatively brief history of Bitcoinâs monetization. Bitcoinâs price appears to follow a fractal pattern of increasing magnitude, where each iteration of the fractal matches the classic shape of a Gartner hype cycle.

In his article on the Speculative Bitcoin Adoption/Price Theory, Michael Casey posits that the expanding Gartner hype cycles represent phases of a standard S-curve of adoption that was followed by many transformative technologies as they become commonly used in society.

Each Gartner hype cycle begins with a burst of enthusiasm for the new technology and the price is bid up by the market participants who are âreachableâ in that iteration. The earliest buyers in a Gartner hype cycle typically have a strong conviction about the transformative nature of the technology they are investing in. Eventually the market reaches a crescendo of enthusiasm as the supply of new participants who can be reached in the cycle is exhausted and the buying becomes dominated by speculators more interested in quick profits than the underlying technology.
Following the peak of the hype cycle, prices rapidly drop and the speculative fervor is replaced by despair, public derision and a sense that the technology was not transformative at all. Eventually the price bottoms and forms a plateau where the original investors who had strong conviction are joined by a new cohort who were able to withstand the pain of the crash and who appreciated the importance of the technology.
The plateau persists for a prolonged period of time and forms, as Casey calls it, a âstable, boring lowâ. During the plateau, public interest in the technology will dwindle but it will continue to be developed and the collection of strong believers will slowly grow. A new base is then set for the next iteration of the hype cycle as external observers recognize the technology is not going away and that investing in it may not be as risky as it seemed during the crash phase of the cycle. The next iteration of the hype cycle will bring in a much larger set of adopters and be far greater in magnitude.
Very few people participating in an iteration of a Gartner hype cycle will correctly anticipate how high prices will go in that cycle. Prices usually reach levels that would seem absurd to most investors at the earliest stages of the cycle. When the cycle ends, a popular cause it typically attributed to the crash by the media. While the stated cause (such as an exchange failure) may be a precipitating event, it is not the fundamental reason for the cycle to end. Gartner hype cycles end because of an exhaustion of market participants reachable in the cycle.
It is telling that gold followed the classic pattern of a Gartner hype cycle from the late 1970s to the early 2000s. One might speculate that the hype cycle is an inherent social dynamic to the process of monetization.

Gartner cohorts
Since the inception of the first exchange traded price in 2010, the Bitcoin market has witnessed four major Gartner hype cycles. With hindsight we can precisely identify the price ranges of previous hype cycles in the Bitcoin market. We can also qualitatively identify the cohort of investors that were associated with each iteration of prior cycles.
$0â$30 (2009âJuly 2011): The first hype cycle in the Bitcoin market was dominated by cryptographers, computer scientists and cypherpunks who were already primed to understand the importance of Satoshi Nakamotoâs groundbreaking invention and who were pioneers in establishing that the Bitcoin protocol was free of technical flaws.
$30â$250 (July 2011âApril 2013): The second cycle attracted both early adopters of new technology and a steady stream of ideologically motivated investors who were dazzled by the potential of a stateless money. Libertarians such as Roger Ver were attracted to Bitcoin for the anti-establishment activities that would become possible if the nascent technology became widely adopted. Wences Casares, a brilliant and well-connected serial entrepreneur, was also part of the second Bitcoin hype cycle and is known to have evangelized Bitcoin to some of the most prominent technologists and investors in Silicon Valley.
$250â$1100 (April 2013âDecember 2013): The third hype cycle saw the entrance of early retail and institutional investors who were willing to brave the horrendously complicated and risky liquidity channels from which bitcoin could be bought. The primary source of liquidity in the market during this period was the Japan-based MtGox exchange that was run by the notoriously incompetent and malfeasant Mark Karpeles, who later saw prison time for his role in the collapse of the exchange.
It is worth observing that the rise in Bitcoinâs price during the aforementioned hype cycles was largely correlated with an increase in liquidity and the ease with which investors could purchase bitcoins. In the first hype cycle there were no exchanges available and acquisition of bitcoins was primarily through mining or by direct exchange with someone who had already mined bitcoins. In the second hype cycle, rudimentary exchanges became available but obtaining and securing bitcoins from these exchanges remained too complex for all but the most technologically savvy investors. Even in the third hype cycle, significant hurdles remained for investors transferring money to MtGox to acquire bitcoins. Banks were reluctant to deal with the exchange and third party vendors who facilitated transfers were often incompetent, criminal, or both. Further, many who did manage to transfer money to MtGox ultimately faced loss of funds when the exchange was hacked and later closed.
It was only after the collapse of the MtGox exchange and a two year lull in the market price of Bitcoin that mature and deep sources of liquidity were developed; examples include regulated exchanges such as GDAX and OTC brokers such as Cumberland mining. By the time the fourth hype cycle began in 2016 it was relatively easy for retail investors to buy bitcoin and secure them.
$1100â$19600? (2014â?):
At the time of writing, the Bitcoin market is undergoing its fourth major hype cycle. Participation in the current hype cycle has been dominated by what Michael Casey described as the âearly majorityâ of retail and institutional investors.

As sources of liquidity have deepened and matured, major institutional investors now have the opportunity to participate through regulated futures markets. The availability of a regulated futures market paves the way for the creation of a Bitcoin ETF which will then usher in the âlate majorityâ and âlaggardsâ in subsequent hype cycles.
Although it is impossible to predict the exact magnitude of the current hype cycle, it would be reasonable to conjecture that the cycle reaches its zenith in the range of $20,000 to $50,000. Much higher than this range and Bitcoin would command a significant fraction of goldâs entire market capitalization (gold and Bitcoin would have equivalent market capitalizations at a bitcoin price of approximately $380,000 at the time of writing). A significant fraction of goldâs market capitalization comes from central bank demand and itâs unlikely that central banks or nation states will participate in this particular hype cycle.
The entrance of nation states
Bitcoinâs final Gartner hype cycle will begin when nation states start accumulating it as a part of their foreign currency reserves. The market capitalization of Bitcoin is currently too small for it to be considered a viable addition to reserves for most countries. However, as private sector interest increases and the capitalization of Bitcoin approaches 1 trillion dollars it will become liquid enough for most states to enter the market. The entrance of the first state to officially add bitcoins to their reserves will likely trigger a stampede for others to do so. The states that are the earliest in adopting Bitcoin would see the largest benefit to their balance sheets if Bitcoin ultimately became a global reserve currency. Unfortunately it will probably be the states with the strongest executive powers â dictatorships such as North Korea â that will move the fastest in accumulating bitcoins. The unwillingness to see such states improve their financial position and the inherently weak executive branches of the Western Democracies will cause them to dither and be laggards in accumulating bitcoins for their reserves.
There is a great irony that the US is currently one of the nations most open in its regulatory position toward Bitcoin, while China and Russia are the most hostile. The US risks the greatest downside to its geopolitical position if Bitcoin were to supplant the dollar as the worldâs reserve currency. In the 1960s Charle de Gaulle criticized the âexorbitant privilegeâ the US enjoyed from the international monetary order it crafted with the Bretton Woods agreement of 1944. The Russian and Chinese governments have not yet awoken to the geo-strategic benefits of Bitcoin as a reserve currency and are currently preoccupied with the effects it may have on their internal markets. Like de Gaulle in the 1960s, who threatened to reestablish the classical gold standard in response to the USâs exorbitant privilege, the Chinese and Russians will, in time, come to see the benefits of a large reserve position in a non sovereign store of value. With the largest concentration of Bitcoin mining power residing in China, the Chinese state already has a distinct advantage in its potential to add bitcoins to its reserves.
The US prides itself as a nation of innovators with Silicon Valley being a crown jewel of the US economy. Thus far, Silicon Valley has largely dominated the conversation toward regulators on the position they should take vis-Ă -vis Bitcoin. However, the banking industry and the US Federal Reserve are finally having their first inkling of the existential threat Bitcoin poses to US monetary policy if it were to become a global reserve currency. The Wall Street Journal, known to be a mouth-piece for the Federal Reserve, published a commentary on the threat Bitcoin poses to US monetary policy:
There is another danger, perhaps even more serious from the point of view of the central banks and regulators: bitcoin might not crash. If the speculative fervor in the cryptocurrency is merely the precursor to it being widely used as an alternative to the dollar, it will threaten the central banksâ monopoly on money.
In the coming years there will be a great struggle between entrepreneurs and innovators in Silicon Valley, who will attempt to keep Bitcoin free of state control, and the banking industry and central banks who will do everything in their power to regulate Bitcoin to prevent their industry and money issuing powers from being disrupted.
The transition to a medium of exchange
A monetary good cannot transition to being a generally accepted medium of exchange (the standard economic definition of âmoneyâ) before it is widely valued, for the tautological reason that a good that is not valued will not be accepted in exchange. In the process of becoming widely valued, and hence a store of value, a monetary good will soar in purchasing power, creating an opportunity cost to relinquishing it for use in exchange. Only when the opportunity cost of relinquishing a store of value drops to a suitably low level can it transition to becoming a generally accepted medium of exchange.
More precisely, a monetary good will only be suitable as a medium of exchange when the sum of the opportunity cost and the transactional cost of using it in exchange drops below the cost of completing a trade without it.
In a barter based society, the transition of a store of value to a medium of exchange can occur even when the monetary good is increasing in purchasing power because the transactional costs of barter trade are extremely high. In a developed economy, where transactional costs are low, it is possible for a nascent and rapidly appreciating store of value, such as Bitcoin, to be used as a medium of exchange, albeit in a very limited scope. An example is the illicit drug market where buyers are willing to sacrifice the opportunity of holding bitcoins to minimize the substantial risk of purchasing the drugs using fiat currency.
There are, however, major institutional barriers to a nascent store of value becoming a generally accepted medium of exchange in a developed society. States use taxation as a powerful means to protect their sovereign money from being displaced by competing monetary goods. Not only does a sovereign money enjoy the advantage of a constant source of demand, by way of taxes being remittable only in it, but competing monetary goods are taxed whenever they are exchanged at an appreciated value. This latter kind of taxation creates significant friction to using a store of value as a medium of exchange.
The handicapping of market based monetary goods is not an insurmountable barrier to their adoption as a generally accepted medium of exchange, however. If faith is lost in a sovereign money its value can collapse in a process known as hyperinflation. When a sovereign money hyperinflates, its value will first collapse against the most liquid goods in the society, such as gold or a foreign money like the US dollar, if they are available. When no liquid goods are available or their supply is limited, a hyperinflating money will collapse against real goods such as real-estate and commodities. The archetypal image of a hyperinflation is a grocery store emptied of all its produce as consumers flee the rapidly diminishing value of their nationâs money.

Eventually, when faith is completely lost during a hyperinflation, a sovereign money will no longer be accepted by anyone and the society will devolve to barter or the monetary unit will have been completely replaced as a medium of exchange by another. An example of this process was the replacement of the Zimbabwe dollar with the US dollar. The replacement of a sovereign money with a foreign one is made more difficult by the scarcity of the foreign money and the absence of foreign banking institutions to provide liquidity.
The ability to easily transmit bitcoins across borders and absence of a need for a banking system makes Bitcoin an ideal monetary good to acquire for those afflicted by hyperinflation. In the coming years, as fiat monies continue to follow their historical trend toward eventual worthlessness, Bitcoin will become an increasingly popular choice for global savings to flee to. When a nationâs money is abandoned and replaced by Bitcoin, Bitcoin will have transitioned from being a store of value in that society to a generally accepted medium of exchange. Daniel Krawisz coined the term âhyperbitcoinizationâ to describe this process.
Part 4âŠ
Part 4 of this article will be published tomorrow and linked from Twitter (follow me). In part 4, I will tackle some of the major arguments against Bitcoin and why they are incorrect when understood in terms of the economic framework that has been discussed in parts 1, 2 and 3 of this article. I will also consider some of the genuine risks that face Bitcoin on its path toward full monetization.
Go back to part 2.
Translations
This article has been translated into:
- Traditional Chinese by Flora Sun
- Simplified Chinese by Flora Sun
- Español by Carlos Beltrån and Iñigo.
- Française by Greg Guittard.
- PortuguĂȘsby Allex Fer.