Skip to content

Instantly share code, notes, and snippets.

@vnprc
Last active November 19, 2024 02:13
Show Gist options
  • Select an option

  • Save vnprc/a50ecfaf6a55cb3bf52d6ee62d55876a to your computer and use it in GitHub Desktop.

Select an option

Save vnprc/a50ecfaf6a55cb3bf52d6ee62d55876a to your computer and use it in GitHub Desktop.
Hashpool

Hashpool

Hashpool is a new kind of mining pool that combines two big ideas: layered mining pools and accountless mining. In combination, I think these concepts can enable a new kind of self-hosted mining pool that will usher in a new era of bitcoin mining. It will decentralize hashrate, taking market share away from large KYC'd mining pools and delivering it to small scale miners. It accomplishes this by turning the mining pool into a borderless and private bitcoin onramp. My thesis is that large regulated mining operations will be prevented from doing business in a privacy-preserving manner, which creates the perfect opportunity for small miners if they have the right tools for the job. I want to build those tools.

Layered Architecture

A layered pool architecture is simply a mining pool that sends hashrate upstream to a larger mining pool and receives payouts from that pool to distribute to downstream miners. Layered pools are possible today, but I believe they are not a reality due to two factors: a lack of high-quality open source mining pool software and a lack of PPLNS pools to build on. The software is coming: the stratum v2 SRI implementation is almost production ready. The PPLNS pools are also coming. Ocean has been running for over a year on a modified PPLNS algorithm, and DEMAND is getting ready to launch as a PPLNS pool running SRI.

I believe PPLNS payouts are crucial to making the economics of layered pools pan out. FPPS exists to enable the pool to assume the "luck risk" of not finding a block for an extended period. The problem with this model is that it introduces moral hazard by enabling the same party to capture miners on their platform and price hashrate. This arrangement creates centralization pressure, leading large mining pools to cannibalize smaller pools and centralize hashrate and block template production for the whole bitcoin network. The longer we allow this pressure to saturate the mining pool market, the more these pools pose a systemic risk to the bitcoin project. Not only are soft forks much more dangerous with centralized block producers, but it gives governments the chokepoint they need to force financial surveillance and control onto their residents.

PPLNS will play a crucial role in limiting the stochastic risk of finding blocks to the right layer of the mining pool stack. Since the largest pools pose a systemic risk to the stability of bitcoin, we need to enable smaller, more innovative pools to operate by aggregating their hashrate to a larger pool without the large pools dictating payout calculations or share accounting to the end-users, the miners. In rolling out layered pools, we will also be setting the stage to decentralize block template production amongst a larger number of players. One thing that has deepened my conviction in this idea is that Bob McElrath and his Braidpool team have also determined that a layered mining pool design solves many of their payout problems. When multiple problem solvers converge on the same idea from different starting points, it's a very good sign!

Market Efficiency

Another problem with existing mining pools is that they do not enable the miner to trade their mining shares. Miners are trapped in a walled garden of the pool's creation. In exchange for reliable payouts, the miner's work is locked up in the mining pool's accounting system. This creates inefficient markets for hashrate. It is both time-consuming and expensive to resell hashrate: buyers must have a pool account to accrue shares into, an always-on proxy server to redirect hashrate, and a way to form and execute legal contracts to enforce these arrangements. Even after the arrangement is in place, it is tricky to verify that the right amount of hashrate was delivered by the seller and received and paid out by the mining pool.

Ecash offers us a unique tool to create efficient markets for digital goods. Instead of locking up shares in pool accounts, what if we instead enable a second layer of pools that issue tokens in exchange for mining shares? This arrangement lets the large mining pool focus on what it's good at: aggregating hashrate and issuing payouts. And, equally important, it offloads the buying and selling of hashrate to a third party using a super efficient and private new (old) technology: ecash mints. PPLNS mining schemes smooth out payout variance without the pool assuming additional risk by amortizing each share over a time window of blocks. We can leverage this time window into a coinbase futures instrument by issuing a token for each proof of work share and expiring it in exchange for bitcoin when the maturity window closes.

The Arrow of Time

Ecash introduces a novel challenge, though. No external state can be attached to an ecash token. Doing so would erode the privacy benefits of ecash and limit the ability to exchange, split, or join tokens. So there can't exist a one-to-one mapping of ecash tokens for contributed shares. We also need a way to expire shares after a period of time has elapsed.

Fortunately, there is a novel solution in the form of Calle's Proof of Liabilities Protocol. This protocol is not only useful for verifying the fair operation of a mint, but it also introduces the arrow of time to ecash operations. By regularly rotating the private keys used to sign new tokens, the ecash mint can limit the growth of its spent tokens database and introduce a means of expiring old ecash tokens. Hashpool will use this arrow of time to sort all submitted proof of work into buckets and expire those buckets one at a time.

Fully Verifiable

Proof of Liabilities does not only create an arrow of time. It also serves as an automated audit of the cashu mint. It does this by regularly releasing proofs that the mint has been operating fairly. Users can verify every time they exchanged a token with the mint by finding their own mint and burn proofs in the report. If any proofs are missing, the user can prove fraud on the part of the mint by publishing a signature from one of the mint's private keys without a corresponding entry in the verification proofs.

There is one small gap in the proof of liabilities protocol as applied to ecash mints. Proving fraud relies on the users checking their proofs against the mint. But if users don't redeem their ecash tokens before expiry, the mint can get away with inflating the ecash supply by an amount equal to or less than the unclaimed ecash. This is tricky to pull off since the mint needs to guess how much unclaimed ecash will be in each epoch (an epoch is defined as the time between keyset rotations).

Hashpools can completely close this gap by publishing the proof of work used to generate each share. A mining share is simply a block template, block header, and some nonce fields that can be put together and hashed to produce a number starting with a bunch of zeroes. All of this can be verified after the fact. By publishing proofs for all mining work and all ecash operations, we can build a 100% auditable mining pool, proving with mathematical certainty that every share accepted by the pool was paid out.

This isn't a silver bullet, though. The pool can still refuse to honor redemptions or reject shares, but, just like in the real world, this will be immediately apparent to customers and harmful to the continued operation of the business.

Accountless Mining

By tokenizing mining shares, we can also remove the need for accounts. Each ecash epoch is a self-contained universe for which shares can be mined, value accrued through the finding of bitcoin blocks, and redeemed to the share holders in the form of bitcoin payouts. Instead of tracking work done by each user, the pool can instead focus on tracking only the total work submitted during each keyset epoch.

This is an inherently more private arrangement for miners. Anyone in the world can participate in this market by buying or selling "ehash"—ecash tokens backed by proof of work. This key capability will usher in a new, global, borderless, KYC-free onramp for bitcoin. With one hashpool instance, anyone anywhere in the world that can produce hashrate can earn ehash tokens to hold to maturity or sell for a profit. Let's fucking go!

Economic Impact

I believe these new hashrate markets will have many positive externalities. Hashers can sell their hashrate for a profit during on-chain fee spikes. This should bring more inefficient or expensive miners online to churn through those mempool mountains. Much like miners can be incentivized to turn off ASICs during periods of high demand for electricity, they can also be incentivized to turn on ASICs when blockspace demand spikes. We can already see this happen on a large scale. Every time there is a fee event, blocks come in fast and heavy, but small miners are forced to trust that the pool they mine with will pass on these profits. Hashpools will unlock this market for small miners, enabling extremely rapid price signals that should help smooth out the on-chain fee market.

My hope is that the privacy premium that we know exists from coinjoin and p2p marketplaces can be funneled directly to small miners, taking marketshare away from the large FPPS mining pools and improving the overall level of systemic risk for bitcoin. It may not pan out this way if the large mining pools start offering privacy services. In this scenario, I would still be very happy; we would score a huge win for financial privacy, and the problems of mining centralization would not be worse than today.

Long Term Impact

In addition to the substantial human freedoms the hashpool model can bring, bitcoin-backed ecash also offers unparalleled usability benefits. With a global onramp to mine bitcoin from anywhere and ubiquitous ecash wallets, we can usher in the future that sci-fi authors have dreamed about for decades.

Picture a bitaxe in every device. Wifi routers and meshnet radios passively mine sats that they use to open ad-hoc connections with other nodes in range, expanding the reach of mesh networks across the land. The nostr shitpost economy finally awakens in earnest thanks to the newfound micropayment wealth of hobbyist miners.

New communities can sprout anywhere on Earth with access to stranded energy. First, the intrepid frontiersmen and women move in with power generation and ASIC hardware. They set up a hashpool to aggregate their mining rewards and serve as a community bank. The initial settlers literally print money that they use to buy goods and services, opening up opportunities for their new community to grow and thrive. I see hashpool quite literally as a key technology to usher in a new golden age of abundant energy and to rewrite the geography of human settlement on the surface of our planet.

Hashpool Development

But if we focus too hard on grandiose visions, we lose sight of all the hard work necessary to bring it about. Right now, the project is little more than an idea. I have a github repo that spins up a full stratum v2 mining stack with some cdk code spliced in to generate a blinded message when a mining share is found (the first half of an ecash token). I am currently working to build proper message passing between pool roles.

With some financial support, I would like to work on this project full time. My first development goal is to issue ehash tokens automatically upon share submission. The next step after that is to build ehash redemptions. I may need to take a detour to help the cashu community build keyset rotation software. I don't think any mints are regularly rotating their keysets yet, which is a critical part of this proposal. Once issuance and redemption are working smoothly, I think we can begin packaging up hashpools for self-hosted operation, first on vanilla linux but eventually on umbrel and/or start9. The package will consist of two installable components: the pool/mint and the proxy/wallet. Many proxies can mine to a single pool.

Verification proofs can be developed last since they are not necessary to the operation of a hashpool. Proofs will be important for large hashpools and for anonymously operated hashpools to grow trust with their userbase. I am hoping we get some help from the major mining pools to develop an open source library since hashrate verification solves a business problem for the pools. However, I recognize that we may not get any help from an entrenched and possibly hostile industry.

Future Work

Coinbase Outputs

I am also exploring the possibility of selling coinbase outputs. This could open up a whole new market for high-value privacy-preserving UTXO purchases, funneling untold wealth into bitcoin mining and supercharging the growth of this industry. This will require negotiating block templates (including the coinbase transaction) with the upstream pool or launching a standalone monolithic hashpool.

In concept, it's pretty simple. Users will peg in some amount of bitcoin ecash and lock it to a pubkey using NUT-11 pay-to-pubkey. They can earn this ecash from ehash redemptions or by buying it from the mint with an on-chain or lightning payment. The pool will keep some percentage as a fee and include a coinbase output in the block templates it sends out to miners. When a block is found and the coinbase output is confirmed, the mint destroys an equivalent value of NUT-11 locked tokens and considers the transaction complete. Miners submitting their own block templates is not a problem; they must commit to the right coinbase transaction in order to aggregate hashrate with the pool.

Including a coinbase output does entail an opportunity cost that miners should be compensated for: it takes up space in the block that could be used to mine fee-paying transactions. I think there is probably a clever way for the pool to claim a fraction of the funds used to buy the coinbase output and pay the rest to their miners. The naive approach is to use a standard bitcoin transaction that doesn't specify an output, in effect "leaving money on the table" that flows to the coinbase output as miner fees. The problem with this approach is that the transaction can be leaked via the block template and mined by a different pool, routing those profits to the wrong set of miners. I think the solution lies in creating connector outputs that are only valid to spend if the block includes the right coinbase transaction. I'm still working on this problem, but my gut tells me it's very solvable.

Transaction Accelerator

With a market in place for hashrate, it makes sense to also sell access to your miner's transaction selection. It should be possible to sell merkle tree inclusion proofs showing that the miner is working on a block template that includes a specific transaction. I haven't worked out exactly how the transaction will be structured but I think there is a clever way to build an incentive compatible transaction accelerator service into hashpool. This would lead to increased miner profitability and create an economic incentive for miners to produce their own block templates, driving block template decentralization to new heights and making all of bitcoin more robust and secure.

It will be crucial to study the MEV risks associated with this proposal. The current MEV debate frustrates me because of how non-specific the arguments are. I think it will be very fruitful to spend some time nailing down the factors that lead to or amplify MEV risk in order to design a system that minimizes these factors.

Fedimint Module

Long-term, I think a fedimint module would be sick. The hashpool custodies all block rewards for the maturity window of each keyset epoch, so if hashpool proves to be a popular model for bitcoin mining, we will want to split up the single signature hot wallet into the multisig model championed by fedimint. There is an open question of whether or not we can reuse the ecash logic that forms one of the core modules of fedimint. Right now the fedimint ecash core module is restricted to only representing bitcoin-backed ecash in order to simplify the codebase. We could duplicate the ecash logic in a module, for example, by incorporating the cdk library, but this is an inelegant solution that adds a lot of complexity to one area of the code in order to avoid complexity elsewhere. It's possible that fedimint will add support for multi-asset ecash in the future. This question may determine the feasibility or direction of the hashpool fedimint module project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment