ToG is peak fiction

Joined February 2018
30 Photos and videos
25th Bam retweeted
4
22
688
お金持ち目指して頑張ります! #FX戦士くるみちゃん
1
61
436
10,380
25th Bam retweeted
Btc?? Hello???
1
1
18
433
1億円あれば… 働かなくても年間で 300万円ぐらい稼げる…! #FX戦士くるみちゃん
37
317
2,151
251,429
2000万取り返してみせるから…! #FX戦士くるみちゃん
5
123
666
34,428
(くるみちゃんの放送に合わせて相場大荒れして欲しいなぁ…)
12
36
238
17,012
25th Bam retweeted
Which way, western man?
13
5
133
17,137
25th Bam retweeted
Replying to @rasmr_eth
1
1
43
3,024
大切なことはくるみちゃんで学びました。
17
142
770
50,633
25th Bam retweeted
Kurumi
Good Morning 💙
3
1
14
1,438
25th Bam retweeted
Now, the quantum resistance roadmap. Today, four things in Ethereum are quantum-vulnerable: * consensus-layer BLS signatures * data availability (KZG commitments proofs) * EOA signatures (ECDSA) * Application-layer ZK proofs (KZG or groth16) We can tackle these step by step: ## Consensus-layer signatures Lean consensus includes fully replacing BLS signatures with hash-based signatures (some variant of Winternitz), and using STARKs to do aggregation. Before lean finality, we stand a good chance of getting the Lean available chain. This also involves hash-based signatures, but there are much fewer signatures (eg. 256-1024 per slot), so we do not need STARKs for aggregation. One important thing upstream of this is choosing the hash function. This may be "Ethereum's last hash function", so it's important to choose wisely. Conventional hashes are too slow, and the most aggressive forms of Poseidon have taken hits on their security analysis recently. Likely options are: * Poseidon2 plus extra rounds, potentially non-arithmetic layers (eg. Monolith) mixed in * Poseidon1 (the older version of Poseidon, not vulnerable to any of the recent attacks on Poseidon2, but 2x slower) * BLAKE3 or similar (take the most efficient conventional hash we know) ## Data availability Today, we rely pretty heavily on KZG for erasure coding. We could move to STARKs, but this has two problems: 1. If we want to do 2D DAS, then our current setup for this relies on the "linearity" property of KZG commitments; with STARKs we don't have that. However, our current thinking is that it should be sufficient given our scale targets to just max out 1D DAS (ie. PeerDAS). Ethereum is taking a more conservative posture, it's not trying to be a high-scale data layer for the world. 2. We need proofs that erasure coded blobs are correctly constructed. KZG does this "for free". STARKs can substitute, but a STARK is ... bigger than a blob. So you need recursive starks (though there's also alternative techniques, that have their own tradeoffs). This is okay, but the logistics of this get harder if you want to support distributed blob selection. Summary: it's manageable, but there's a lot of engineering work to do. ## EOA signatures Here, the answer is clear: we add native AA (see eips.ethereum.org/EIPS/eip-8… ), so that we get first-class accounts that can use any signature algorithm. However, to make this work, we also need quantum-resistant signature algorithms to actually be viable. ECDSA signature verification costs 3000 gas. Quantum-resistant signatures are ... much much larger and heavier to verify. We know of quantum-resistant hash-based signatures that are in the ~200k gas range to verify. We also know of lattice-based quantum-resistant signatures. Today, these are extremely inefficient to verify. However, there is work on vectorized math precompiles, that let you perform operations ( , *, %, dot product, also NTT / butterfly permutations) that are at the core of lattice math, and also STARKs. This could greatly reduce the gas cost of lattice-based signatures to a similar range, and potentially go even lower. The long-term fix is protocol-layer recursive signature and proof aggregation, which could reduce these gas overheads to near-zero. ## Proofs Today, a ZK-SNARK costs ~300-500k gas. A quantum-resistant STARK is more like 10m gas. The latter is unacceptable for privacy protocols, L2s, and other users of proofs. The solution again is protocol-layer recursive signature and proof aggregation. So let's talk about what this is. In EIP-8141, transactions have the ability to include a "validation frame", during which signature verifications and similar operations are supposed to happen. Validation frames cannot access the outside world, they can only look at their calldata and return a value, and nothing else can look at their calldata. This is designed so that it's possible to replace any validation frame (and its calldata) with a STARK that verifies it (potentially a single STARK for all the validation frames in a block). This way, a block could "contain" a thousand validation frames, each of which contains either a 3 kB signature or even a 256 kB proof, but that 3-256 MB (and the computation needed to verify it) would never come onchain. Instead, it would all get replaced by a proof verifying that the computation is correct. Potentially, this proving does not even need to be done by the block builder. Instead, I envision that it happens at mempool layer: every 500ms, each node could pass along the new valid transactions that it has seen, along with a proof verifying that they are all valid (including having validation frames that match their stated effects). The overhead is static: only one proof per 500ms. Here's a post where I talk about this: ethresear.ch/t/recursive-sta… firefly.social/post/farcaste…
797
1,135
5,698
931,594
25th Bam retweeted
════════════ Pokémon FireRed and Pokémon LeafGreen confirmed for Nintendo Switch! ═══════════ These download-exclusive titles will be available after the #PokemonDay Presents presentation which begins Friday, February 27, 2026, at 6AM PST. #PokemonFRLG
2,491
12,864
89,707
14,582,087
25th Bam retweeted
Bitcoin up or down? 5 minute up/down crypto polymarkets are now live. Powered & secured by Chainlink 🤝
3,022
2,731
47,370
689,242,819
25th Bam retweeted
Serious business.
591
377
4,382
1,217,412
25th Bam retweeted
HyperCore will support outcome trading (HIP-4). Outcomes are fully collateralized contracts that settle within a fixed range. They are a general-purpose primitive that are useful for applications such as prediction markets and bounded options-like instruments. There has been extensive user demand in both of these areas, and builders will likely think of novel applications as well. Outcomes bring non-linearity, dated contracts, and an alternative form of derivative trading that does not involve leverage or liquidations. The outcome primitive expands the expressivity of HyperCore, while composing with other primitives such as portfolio margin and the HyperEVM. Outcomes are a work in progress and currently only being tested on testnet. Canonical markets based on objective settlement sources will be deployed once technical development is complete. Canonical markets will be denominated in USDH. Pending user feedback, the infrastructure will be extended to permissionless deployment.
886
908
5,866
1,778,952
25th Bam retweeted
Base is for traders.
330
89
1,162
67,499
25th Bam retweeted
Markets, powered by USDH. Only on Hyperliquid.
Markets is your new home for trading global assets, 24/7. A new era for finance has just begun. Now live.
3
5
116
6,947
25th Bam retweeted
Markets by Kinetiq is now live. The first user-owned, decentralized exchange for global markets. kmHYPE stakers make history by being the collective powering our HIP-3 DEX, @markets_xyz. The universal frontend for capital markets. We've created the most state-of-the-art experience for serious and casual traders alike. We're starting with US500: The U.S. large-cap equity market benchmark. More listings are imminent. Hyperliquid x.com/markets_xyz/status/201…

Markets is your new home for trading global assets, 24/7. A new era for finance has just begun. Now live.
7
12
163
13,477
25th Bam retweeted
Markets by @kinetiq_xyz will launch on Monday, January 12th. Global trading will change forever.
42
47
392
57,117