About Vitalik Buterin
Vitalik Buterin has been promoting the concept of the Ethereum Economic Zone (EEZ), which he described as a rethinking of layer-2 networks to achieve greater integration with Ethereum at lower cost. He stated that the EEZ allows chains to use Ethereum as an "ultimate economic operating system for the internet." Buterin also discussed the convergence of AI and crypto, arguing that Ethereum should serve as a public data layer and on-chain computation layer for multi-party coordination, rather than a traditional operating system. He emphasized the importance of CROPS (Censorship Resistant, Open Source, Private, Secure) AI, advocating for local models and privacy-preserving techniques such as ZK payments to protect user data when interacting with remote AI services.
Buterin has also reflected on the evolution of his own philosophy, describing a shift from "autopilot" to active decision-making and a deeper understanding of crypto's role in preserving human agency. He contrasted the vision of safety offered by centralized powers with the decentralized, empowering safety he believes crypto can provide, stating that "crypto does not have the ability to fix the dollar" but can create alternatives that individuals are free to use. On the Ethereum protocol roadmap, Buterin outlined priorities including quantum safety, account abstraction via EIP-8141, and improvements to block building and privacy, with the goal of making Ethereum maximally robust and easy to verify.
Source: AI-verified profile updated from Vitalik Buterin's recent appearances.
Browse all interviews →
Transcript (291 segments)
L
Lex Fridman0:00
The following is a conversation with Vitalik Buterin, co-creator of Ethereum. This is the Artificial Intelligence podcast. I'll do a couple of minutes of ads now. The ads are for MasterClass and ExpressVPN. Please consider supporting the podcast. And now, here's my conversation with Vitalik Buterin.
So, before we talk about the fundamental ideas behind Ethereum, perhaps it'd be nice to talk about the origin story of Bitcoin and the mystery of Satoshi Nakamoto. You gave a talk that started with asking, what did Satoshi Nakamoto actually invent? Maybe you could say, who is Satoshi Nakamoto and what did he invent?
V
Vitalik Buterin5:27
Sure. So, Satoshi Nakamoto is the name by which we know the person who originally came up with Bitcoin. This is an anonymous fellow who showed himself to us only over the internet, first publishing the white paper, then releasing the source code, and then talking to the early Bitcoin community. He helped the project along for a couple of years and then in late 2010 to early 2011 he disappeared. Bitcoin is a fairly unique project with this mythical, quasi God-like founder who just popped in, did the thing, and then disappeared.
L
Lex Fridman6:30
So in 2008, the white paper was the first time the name Satoshi Nakamoto appeared?
L
Lex Fridman6:42
So how is it possible that the creator of such an impactful project remains anonymous?
V
Vitalik Buterin6:48
That's a tough question and there's no similarity to it in history of technology as far as I'm aware.
Yeah. So one possibility is that it's Hal Finney because Hal Finney was kind of also active in the Bitcoin community. He is one of the people in the early Cypherpunk community, a computer scientist, cryptographer, interested in technology and internet freedom.
L
Lex Fridman7:11
Hal Finney maybe?
V
Vitalik Buterin7:12
He is one of the people in the end of early Cypherpunk community he was a...
L
Lex Fridman7:20
So he's a computer scientist just one of the...
V
Vitalik Buterin7:21
Scientists, cryptographers, people interested in technology, internet freedom, like those kinds of topics.
L
Lex Fridman7:31
Is it correct that I read that he seemed to have been involved in either the earliest or the first transaction of Bitcoin?
V
Vitalik Buterin7:38
Yes. The first transaction of Bitcoin was between Satoshi and Hal Finney.
L
Lex Fridman7:43
Do you think he knew who Satoshi was if he wasn't Satoshi?
V
Vitalik Buterin7:46
Probably no.
L
Lex Fridman7:48
How is it possible to work so closely with people and nevertheless not know anything about their fundamental identity? Is this like a natural characteristic of the internet?
L
Lex Fridman8:02
Like if we were to think about it, you and I just met now. There's a depth of knowledge we now have about each other that's physical. My vision system can recognize you. I can verify your identity. It's very hard to fake you being you. So the internet has a fundamentally different quality. Can you talk about that?
L
Lex Fridman8:06
There's a depth of knowledge we now have about each other that's physical. My vision system can recognize you. I can verify your identity. It's very hard to fake you being you. So the internet has a fundamentally different quality. Can you talk about that?
V
Vitalik Buterin8:19
Yeah.
L
Lex Fridman8:19
This like it's very hard to fake you being you. So the internet has a fundamentally different quality to it which is just fascinating. Can you maybe talk about that?
V
Vitalik Buterin8:24
[laughter]
L
Lex Fridman8:24
The internet has a fundamentally different quality to it which is just fascinating. Can you maybe talk about that?
V
Vitalik Buterin8:30
Definitely interesting. I definitely just know a lot of people just by their internet handles. To me when I think of them, I see their internet handles. One of them has a profile picture that's kind of not quite human with psychedelic colors. When I visualize him, I just visualize that.
L
Lex Fridman8:54
That's not an actual face.
V
Vitalik Buterin8:56
Yeah.
L
Lex Fridman8:57
You are the creator of the second most popular cryptocurrency, Ethereum. So on this topic, if we stick on Satoshi Nakamoto a little bit longer, you may be the most qualified person to speak to the psychology of this anonymity. Your identity is known. From your perspective, what are the benefits of creating a cryptocurrency and remaining anonymous? If we can psychoanalyze Satoshi Nakamoto, is there something interesting there? Or is it just a peculiar quirk?
L
Lex Fridman9:16
Like your identity is known. From your perspective, what are the benefits of creating a cryptocurrency and remaining anonymous? If we can psychoanalyze Satoshi Nakamoto, is there something interesting there? Or is it just a peculiar quirk?
V
Vitalik Buterin9:37
It definitely helps create this kind of image of a neutral thing that doesn't belong to anyone. You created a project and because you're anonymous and you disappear, all that's remaining is the thing itself. No one can interpret your other behavior or try to understand that this person wrote something at age 16 and therefore the project is a statement trying to do a specific thing. Instead, it creates an environment where the thing is what you make of it.
L
Lex Fridman10:47
It doesn't have the burden of your other ideas, political thought and so on. So now that we're sitting with you, do you feel the burden of being the face of Ethereum? There's a very large community of developers, but nevertheless, is there a burden associated with that?
V
Vitalik Buterin11:05
Yeah.
L
Lex Fridman11:06
Is there like a burden associated with that?
V
Vitalik Buterin11:09
There definitely is. This is a big reason why I've been trying to push for the Ethereum ecosystem to become more decentralized in many ways. Encouraging core Ethereum work to happen outside of the Ethereum Foundation, expanding the number of people making decisions, having multiple software implementations. I've tried to remove myself as a single point of failure, because that is something a lot of people criticize me for.
L
Lex Fridman11:48
So, if you look at the most fundamentally successful open source projects, it seems that one person is a crucial contributor. Often, if you look at Linus for Linux, for the kernel.
V
Vitalik Buterin11:53
Uh-huh.
L
Lex Fridman11:54
It seems that it's a sad reality that one person is a crucial contributor. Often, if you look at Linus for Linux, for the kernel.
V
Vitalik Buterin12:08
Yeah, that is possible, and I'm definitely not planning to disappear.
L
Lex Fridman12:12
[laughter]
That's an interesting tension that projects like this desire a single entity, and yet they're fundamentally distributed. I don't know if there's something interesting to say about that structure and thinking about the future of cryptocurrency. Does there need to be a leader?
V
Vitalik Buterin12:24
Mhm.
L
Lex Fridman12:25
I don't know if there's something interesting to say about that structure and thinking about the future of cryptocurrency. Does there need to be a leader?
V
Vitalik Buterin12:34
There's different kinds of leaders. There's dictators who control all the money, people who control organizations, and high priests that have themselves and their software followers.
L
Lex Fridman12:47
What kind of leader are you, would you say?
V
Vitalik Buterin12:49
Yeah, these days I'm a bit more in the high priest direction than before. I definitely don't do all that much of ordering Ethereum Foundation people to do things. If there's something I think is important, I usually just say it publicly or to people, and quite often projects just start doing it.
L
Lex Fridman13:22
So, let's ask the high philosophical question about money. What at the highest level is money? What is money?
V
Vitalik Buterin13:26
Yeah.
L
Lex Fridman13:27
What at the highest level is money? What is money?
V
Vitalik Buterin13:32
It's a kind of game where we have points. If you have points, there's a move where you can reduce your points by a number and increase someone else's points by the same number. It's a fair game. But there are other kinds of fair games. Money is easy to set up and serves a lot of useful functions, so it survives as a meme in society for thousands of years.
L
Lex Fridman13:45
So it's a fair game, hopefully.
V
Vitalik Buterin13:47
Well, it's one kind of fair game. For example, you can have a game where if I give someone a point and you give someone a point, instead of that person getting two points, they get four points, and that's also fair. But money is easy to set up and serves a lot of useful functions, so it survives as a meme in society for thousands of years.
L
Lex Fridman14:14
So it's useful for the storage of wealth. It's useful for the exchange of value.
V
Vitalik Buterin14:20
And it's also useful for denominating future payments. A unit of account.
L
Lex Fridman14:26
A unit of account. So if you look at the history of money in human civilization, how has its role or the mechanisms of money changed over time in your view? Even if we just look at the 20th century or before, leading up to cryptocurrencies. Is that something you think about?
V
Vitalik Buterin14:50
Yeah, I think the big thing in the 20th century is we saw a lot more intermediation. The move from bank adding more kinds of banking, then the move from dollars backed by gold to dollars backed by gold only redeemable by certain people to dollars not backed by anything, to a system of free-floating currencies, bank accounts becoming electronic, people getting accounts with payment processors.
L
Lex Fridman15:37
So, what do you make of that? That's a fascinating philosophical idea that money might not be backed by anything.
V
Vitalik Buterin15:45
Mhm.
L
Lex Fridman15:46
What is that like? Is it fascinating to you that money can exist without being backed by something physical?
V
Vitalik Buterin15:52
It definitely is.
L
Lex Fridman15:54
Like, what do you make of that? How is that possible? Is that stable? If you look at the future of human civilization, is it possible to have money at a large scale in hugely productive and rich societies operate successfully without money being backed by anything physical?
V
Vitalik Buterin16:12
I feel like the interesting thing about the 21st century is that a lot of the important valuable things are not backed by anything. If you look at tech companies like Twitter, you could theoretically imagine that if all the employees wanted to, they could quit and start working on Twitter 2.0. The value of the original Twitter would just not have people left. The reason why the thing has value is network effects and coordination problems. Employees aren't going to switch all at once, and users aren't all going to switch at once. There are metastable equilibria in interactions between thousands and millions of people that are quite sticky, even if you assume everyone is a perfectly rational spherical cow.
L
Lex Fridman17:44
That's that stickiness. Do you have a grasp of the fundamental dynamic, the physics of that stickiness? It seems to work, and I think some of the cryptocurrency ideas rely on it working.
V
Vitalik Buterin18:00
Yeah, it's the sort of thing that's been economically modeled a lot. An analogy often seen in textbooks is: what is a government? If 80% of people in a country suddenly had the idea that the current laws and government are just people and some other thing is the government, and they start acting like it, that would become the new reality. The question is what happens if between zero and 80% of people start believing that. If there is a revolution, the first person to join probably doesn't have the incentive, but if you're the 55th percentile person, it becomes quite safe. It can be analyzed mathematically, but when the switch happens can be chaotic.
L
Lex Fridman19:26
Yeah, but still, to me the idea that network effects, the fact that human beings at a scale of millions can share even the idea of currency and all agree, that's just... I know economics can model it. I'm a skeptic on economics. My favorite field recreationally is psychology, trying to understand human behavior. I think sometimes people pretend they can grasp human behavior even though it's such a messy space. All the models from psychology or economics are different perspectives, but it's difficult to know how much is wishful thinking and how much is actually getting to the core. On that idea, what do you think is the role of money in human motivation? Do you think money from an economic and psychological perspective is core to human desires?
V
Vitalik Buterin20:35
Money is definitely very far from the only motivator. It is a big motivator and one of the closest things to a universal motivator. In almost any person, if you ask them to do something, they'll be more inclined if you offer them money. There are many cases where people do things that don't maximize their money, but those other things are much more specific to who that person is and their situation.
L
Lex Fridman21:19
What do you think is the interplay of the other motivator from a Nietzsche perspective, power? Do you think money equals power? Do you think those are conflicting ideas? I mean, that's one of the ideas that decentralized currency and applications are looking at: who holds the power.
V
Vitalik Buterin21:37
Yeah. Money is definitely a kind of power. There are people who want money because it gives them power. Even if money doesn't seem to be explicitly about money, a lot of things people spend money on are ultimately about social status. I view those two things as interplaying. There's also money as a way of measuring how successful you are, a scoreboard. If you have $4 billion, one of the big benefits of going up to $6 million is that now you're above the guy who has five.
L
Lex Fridman22:30
So, you think money could be, in the game of life, a measure of self-worth. It's how we define ourselves in the hierarchy of society.
V
Vitalik Buterin22:38
It's definitely how a lot of people perceive it.
L
Lex Fridman22:42
Define ourselves in the hierarchy of society.
V
Vitalik Buterin22:45
Yeah, I'm not saying it's a healthy thing that people define their self-worth as money, because it's far from a perfect indicator of how much value you provide to society. But as a matter of current practice, a bunch of people do feel that way.
L
Lex Fridman23:09
So, what does utopia from an economic perspective look like to you? What does a perfect world look like?
V
Vitalik Buterin23:17
I guess the economist's utopia would be one where everything is incentive-aligned in the sense that there aren't conflicts between what satisfies your goals and what is good for everyone in the world as a whole.
L
Lex Fridman23:39
What do you think that would look like? Does that mean there are still poor people and rich people? Income inequality? Do you think Marxist ideas are strong? Do you think ideas of objectivism where the market rules is strong? Are there different economic philosophies that seem reflective of what utopia would be?
V
Vitalik Buterin24:09
So, I definitely think that existing economic philosophies systematically deviate from utopia in a lot of ways. One of the big things I talk about is public goods. Public goods are especially important on the internet. The idea with money as a game where I lose a few coins and you gain the same number usually happens in a trade where I lose money, you gain money, you lose a sandwich, I gain a sandwich. This model works well for private goods. But on the internet, there are actions where the benefit goes to many people at the same time and you can't control who it goes to. For example, this podcast: when published, you don't have fine-grained control over who can watch it. Once the number goes high enough, people just copy it. Scientific research, climate change mitigation are other examples. There are actions with concentrated costs and distributed benefits, and money as a point system does not encourage these things. I work on a mechanism called quadratic funding. The way to think about it is: if one person gives coins to another, it works like money. But if multiple people give coins to one person anonymously, the number of coins received is greater than the sum. The formula is: take the square root of each person's contribution, add the square roots, then square the sum. This compensates for the tragedy of the commons.
L
Lex Fridman24:44
[laughter]
V
Vitalik Buterin24:44
And this kind of model works really well when the thing we're using money to incentivize is private goods. But on the internet, there are actions where the benefit goes to many people. Quadratic funding compensates for the tragedy of the commons.
L
Lex Fridman25:26
When a lot of people are contributing like funding a particular entity. That's really interesting. Is there something special about the quadratic, the summing of the square roots and taking the square root?
V
Vitalik Buterin27:30
[snorts] The like there is basically the fact that you get more than the sum, you get this square of sum of square roots of these tiny amounts. This actually compensates for the tragedy of the commons. There's even a mathematical proof that it optimally compensates for it.
L
Lex Fridman27:49
What is the tragedy of the commons?
V
Vitalik Buterin27:50
This is the idea that if there is a public good that lots of people benefit from, no individual wants to contribute because they only get a small part of the benefit but pay the full cost.
L
Lex Fridman28:11
In which context is this mechanism useful? Obviously you said to combat the tragedy of the commons, but in which context do you see it as useful practically?
V
Vitalik Buterin28:15
Quadratic funding is the mechanism.
L
Lex Fridman28:17
Yeah, like what's in which context is this mechanism useful? So obviously you said to combat the tragedy of the commons, but in which context do you see it as useful practically?
V
Vitalik Buterin28:27
Yeah.
L
Lex Fridman28:27
In which context do you see it as useful actually practically speaking?
V
Vitalik Buterin28:30
Yeah, theoretically public goods in general. Within the Ethereum ecosystem, we've actually tried using this mechanism. I wrote articles on vitalik.ca about the most recent rounds. Some of the top ones supported were online user interfaces for Ethereum, documentation, podcasts, software clients, privacy tools, lots of things useful to many people.
L
Lex Fridman28:34
Like services, what are we talking about? What's a public good?
V
Vitalik Buterin28:36
Yeah, so within the Ethereum ecosystem, we've actually tried using this mechanism. I wrote articles on vitalik.ca about the most recent rounds. Some of the top ones supported were online user interfaces for Ethereum, documentation, podcasts, software clients, privacy tools, lots of things useful to many people.
L
Lex Fridman29:26
When a lot of people are contributing like funding a particular entity. That's really interesting. Is there something special about the quadratic, the summing of the square roots and taking the square root?
V
Vitalik Buterin29:39
Another way to think about it is: imagine if n people each give a dollar, then the person gets n squared. Each individual's contribution gets multiplied by n. That perfectly compensates for the n to one tragedy of the commons.
L
Lex Fridman29:59
I just wonder if the squared part is somehow fundamental.
V
Vitalik Buterin30:02
No, it is. I'd recommend you go to vitalik.ca, I have an article called 'Quadratic Payments: A Primer.' Highly recommended. It's my attempt so far at explaining the intuition behind this.
L
Lex Fridman30:18
The intuition. So if we could, can we go to the very basic: what is the blockchain? Or perhaps we might start at the Byzantine generals problem and Byzantine fault tolerance in general that Bitcoin was taking steps to providing a solution for.
V
Vitalik Buterin30:42
Mhm. So, the Byzantine generals' problem is a paper by Leslie Lamport published in 1982. The thought experiment: if you have two generals camped on opposite sides of a city planning when to attack, how can they coordinate? They can send messengers, but those messengers could be sniped or become traitors. With just two generals, there is no solution in a finite number of rounds that guarantees coordination. But with more than two generals, depending on whether messages are oral or signed, there are different bounds on how many traitors can be tolerated. It's a misconception that the problem was unsolved; Lamport solved it. The unsolved part was that all solutions assume a fixed list of who the generals are, and they must be semi-trusted. They can't be anonymous because the enemy could be 99% of the generals. In the 1980s and 1990s, the use case for distributed systems was more enterprisey, where you could assume you know who the nodes are.
L
Lex Fridman32:41
Right. Right.
V
Vitalik Buterin32:42
The thing that was unsolved is that all of these solutions assume you've already agreed on a fixed list of who the generals are. They can't be anonymous. In the 1980s and 1990s, the general use case for distributed systems was more enterprisey, where you could assume you know who the nodes are.
That are running these kinds of computer networks. So, if you want to have some kind of decentralized network that pretends to be a single computer and that you can do operations on, then it's made out of these 15 specific computers, and we know who and where they are, so we have a good reason to believe that at least 11 of them would be fine.
L
Lex Fridman33:22
And it could also be within a single system, almost like a network of devices, sensors, and so on, like in airplanes. I think flight systems in general still use these kinds of ideas. Yeah. Yep. So,
So, that's the '80s.
V
Vitalik Buterin33:37
That's the '80s and '90s. Now, the cypherpunks had a different use case in mind, which is that they wanted to create a fully decentralized global permissionless currency. And the problem here is that they didn't want any authorities and they didn't even want any kind of privileged list of people.
V
Vitalik Buterin33:55
And so now the question is, well, how do you use these techniques to create consensus when you have no way of measuring identities, right? You have no way of determining whether or not some 99% of participants aren't actually all the same guy. And so the clever solution that Satoshi had, this is going back to the presentation I made at Def Con a few months ago where I said that the thing Satoshi invented was crypto economics, is this really neat idea that you can use economic resources to limit how many identities you can get. And if there isn't any existing decentralized digital currency, then the only way to do this is with proof of work, right? So, with proof of work, the solution is just you publish a solution to a hard mathematical puzzle that takes some clearly calculable amount of computational power to solve, you get an identity. And then you solve five of those puzzles, you get five identities. And then these are the identities that we run the consensus algorithm between.
L
Lex Fridman35:09
So, the proof of work mechanism you just described is like the fundamental idea proposed in the white paper that defines Bitcoin. What is the idea of consensus that we wish to reach? Why is consensus important here? What is consensus?
V
Vitalik Buterin35:29
So, the goal here in just simple technical terms is to basically wire together a set of a large number of computers in such a way that they pretend to the outside world to be a single computer where that single computer keeps working even if a large portion of the computers that make it up break.
V
Vitalik Buterin35:52
And break in arbitrary ways, like they could shut off, they could try to actively break the system, they could do lots of mean things. So, the reason why the cypherpunks wanted to do this is because they wanted to run one particular program on this virtual computer. And the one particular program that they wanted to run is just a currency system, right? It's a system that just processes a series of transactions, and for every transaction, it verifies that the sender has enough coins to pay for the transaction, it verifies that the digital signature is correct, and if the check is passed, then it subtracts the coins from one account and adds the coins to the other account, roughly.
L
Lex Fridman36:33
So, first of all, the proof-of-work idea seems pretty fascinating, at least to me.
V
Vitalik Buterin36:41
It is.
L
Lex Fridman36:42
I mean, that's a revolutionary idea. I mean, is it obvious to come up with that you can exchange basically computational resources for identity?
V
Vitalik Buterin36:55
Mhm.
V
Vitalik Buterin36:56
It actually has a pretty long history. It was first proposed in a paper by Cynthia Dwork and Moni Naor in 1994, I believe. And the original use case was combating email spam. So, the idea is that if you send an email, you have to send it with a proof of work attached, and this makes it reasonably cheap to send emails to your friends, but it makes it really expensive to send spam to a million people.
L
Lex Fridman37:22
Yeah, that's a simple, brilliant idea. So, maybe taking a step back, what is the role of blockchain in this? What is the blockchain?
V
Vitalik Buterin37:33
Sure. So, the blockchain, my way of thinking about it is that it is this system where you have this one virtual computer created by a bunch of these nodes in the network. And the reason why the term blockchain is used is because the data structure that these systems use so far is one where the different nodes in the network periodically publish blocks, and a block is a list of transactions together with a pointer, like a hash of a previous block that it builds on top of. And so, you have a series of blocks that nodes in the network create, where each block points to the previous block, and so you have this chain of them.
L
Lex Fridman38:23
Is a fault tolerance mechanism built into the idea of blockchain, or is there a lot of possibilities of different ways to make sure there's no funny stuff going on?
V
Vitalik Buterin38:33
There are indeed a lot of possibilities. So, in a simple architecture as I just described, the way the fault tolerance happens is like this. You have a bunch of nodes, and they're just happily occasionally creating blocks, building on top of each other's blocks. Let's say you have block one. Then someone else builds another block honestly, we'll call it block two. Then we have an attacker. What the attacker tries to do is revert block two. The way they revert block two is instead of doing the thing they're supposed to do, which is build a block on top of block two, they're going to build another block on top of block one. So, you have block one, which has two children, block two and block two prime. This might sometimes happen by random chance if two nodes in the network just happen to create blocks at the same time and they don't hear about each other's things before they create their own. But this also could happen because of an attack. If this happens, the nodes in the Bitcoin system follow the longest chain. So, if this attack had happened and the original chain had more than two blocks on it, so if it was trying to revert more than two blocks, then everyone would just ignore it and keep following the regular chain. But here, we have block two and block two prime, so the two are even. Then whatever block the next block is created on top of, say block three is now created on top of block two prime, then everyone agrees that block three is the new head, and block two prime is forgotten, and everyone just peacefully builds on top of block three, and the thing continues.
L
Lex Fridman40:25
So, how difficult is it to mess with the system? I
L
Lex Fridman40:28
So, how like if we look at the general problem, like how many what fraction of people who participate in the system have to be bad players
L
Lex Fridman40:40
in order to mess with it truly? Like what's your Is there a good number
V
Vitalik Buterin40:44
There is.
V
Vitalik Buterin40:46
Well, depending on what your model of the participants is and what kind of attack we're talking about, it's anywhere between 23.2 and 50%.
L
Lex Fridman40:57
Of what?
V
Vitalik Buterin40:58
Of all of the computing power in the network.
L
Lex Fridman41:02
Sorry, so 22 and
V
Vitalik Buterin41:04
23. Between 23.2 and 50%.
L
Lex Fridman41:06
And 50% can be compromised.
V
Vitalik Buterin41:11
So, once your portion of the total computing power in the network goes above the 23.2 level, then there are things that you can potentially do. And as your percentage of the network keeps going up, your abilities as a mean thing go higher. And if you have above 50%, then you can just break everything.
L
Lex Fridman41:34
So, how hard is it to achieve that level? It seems that so far historically speaking it's been exceptionally difficult.
V
Vitalik Buterin41:43
This is a challenging question. The economic cost of acquiring that level of stuff from scratch is fairly high. I think it's somewhere in the low billions of dollars.
L
Lex Fridman41:55
And when you say that stuff, you mean computational resources?
V
Vitalik Buterin41:59
Yeah, specifically specialized hardware, ASICs, that people use to solve these puzzles to do the mining these days.
L
Lex Fridman42:07
Small tangent. So, obviously I work a lot in deep learning with GPUs and ASICs for that application. And I tangentially hear that so many of these, you know, sometimes Nvidia GPUs are sold out
V
Vitalik Buterin42:21
Uh-huh.
L
Lex Fridman42:22
because of this other application. What do you, if you can comment, I don't know if you're familiar or interested in this space, what kind of ASICs, what kind of hardware is generally used these days to do the actual computation for the proof of work?
V
Vitalik Buterin42:37
Sure. So, in the case of Bitcoin and Ethereum are a bit different. In the case of Bitcoin, there is an algorithm called SHA-256. It's just a hash function. The puzzle is just coming up with a number where the hash of the number is below some threshold. Because hashes are designed to be random, you just have to keep trying different numbers until one works. The ASICs are just specialized circuits that contain circuits for evaluating this hash over and over again. You have millions or billions of these hash evaluators stacked on top of each other inside a box, and you just keep running the box 24/7.
L
Lex Fridman43:17
In the ASICs, there's literally specialized hardware designed for this.
V
Vitalik Buterin43:20
Yes.
L
Lex Fridman43:21
Oh, we're living in an amazing world. Another tangent, and I'll come back to the basics, but does quantum computing throw a wrench into any of this?
V
Vitalik Buterin43:31
Very good question. Quantum computers have two main families of algorithms relevant to cryptography. One is Shor's algorithm. Shor's algorithm completely breaks the hardness of some specific kinds of mathematical problems. The one you've probably heard of is it makes it very easy to factor numbers, to figure out what prime factors multiply together to get some number, even if that number is extremely big. Shor's algorithm can also be used to break elliptic curve cryptography. It can break any kind of hidden order groups, so it breaks a lot of cryptographic nice things we're used to. But the good news is that for every major use of things that Shor's algorithm breaks, we already know of quantum-proof alternatives. We don't use these quantum-proof alternatives yet because in many cases they're five to ten times less efficient, but the crypto industry in general knows that this is coming eventually and is ready to take the hit and switch to that stuff when we have to. The second algorithm relevant to cryptography is Grover's algorithm. Grover's algorithm might be more familiar to AI people. It's usually described as solving search problems. The idea is that if you have a problem of the form find a number that satisfies some property, then with a classical computer you need to try n times before you find a number, but with a quantum computer you only need to do a square root of n computations. Grover's could potentially be used for mining, but there are two possibilities. One is that Grover's could be used for mining and whoever creates the first working quantum computer that can do Grover's will just mine way faster than everyone else, and we'll see another round of what we saw when ASICs came out, where the new hardware just dominated the old stuff and then eventually it switched to a new equilibrium.
L
Lex Fridman45:49
But by the way, way faster, not exponentially faster.
V
Vitalik Buterin45:53
Quadratically faster.
L
Lex Fridman45:54
Quadratically faster, which is not game changing, I would say. It's like ASICs, like you said it would be
V
Vitalik Buterin46:02
Exactly. Yeah, so it would not necessarily break proof of work.
L
Lex Fridman46:07
That's right, yeah.
V
Vitalik Buterin46:07
Now, the other possible world is that quantum computers have a lot of overhead, a lot of inner complexity involved in maintaining quantum states, and as we've been realizing recently, making quantum computers actually work requires quantum error correction, which requires a thousand real qubits per logical qubit. So, there is the very real possibility that the overhead of running a quantum computer will be higher than the speedup you get with Grover's, which would be sad, but would also mean that even proof of work will just keep working fine.
L
Lex Fridman46:43
That's beautifully put. So, proof of work is the core idea of Bitcoin. Are there other core ideas before we take a step towards the origin story and the ideas of Ethereum? Is there other stuff that was key to the white paper of Bitcoin?
V
Vitalik Buterin46:59
There's proof of work, and then there's just the cryptography, just public keys and signatures that are used to verify transactions. Those are the two big things.
L
Lex Fridman47:08
So, then what is the origin story, maybe the human side, but also the technical side of Ethereum?
V
Vitalik Buterin47:15
Sure. So, I joined the Bitcoin community in 2011, and I started by just writing. I first wrote for this online thing called Bitcoin Weekly. Then I started writing for Bitcoin Magazine.
L
Lex Fridman47:32
Sorry to interrupt, you have this funny story, true or not, that you were disillusioned by the downsides of centralized control from your experience with World of Warcraft. Is this true, or are you just being witty?
V
Vitalik Buterin47:48
I mean, the event is true, but the fact that that's the reason I do decentralization is witty.
L
Lex Fridman47:53
[laughter]
Maybe just a small tangent. Do you have always had a skepticism of centralized control? Is that sort of a
V
Vitalik Buterin48:02
To a degree, yeah.
L
Lex Fridman48:03
Has that feeling evolved over time, or is that just always been a core feeling that decentralized control is the future of our human society?
V
Vitalik Buterin48:12
I mean, it's definitely been something that felt very attractive to me ever since I could have a word that such a thing is possible.
L
Lex Fridman48:19
Even technically.
V
Vitalik Buterin48:19
Yeah.
L
Lex Fridman48:20
So, great. So, you joined the Bitcoin community in 2011, you said you began writing.
V
Vitalik Buterin48:25
Mhm.
L
Lex Fridman48:25
So, what's next?
V
Vitalik Buterin48:27
Started writing, moved from high school to university, halfway in between that, and spent a year in the university. Then at the end of that year, I dropped out to do Bitcoin things full-time. This was a combination of continuing to write for Bitcoin Magazine, but also increasingly work on software projects. I traveled around the world for about six months, going to different Bitcoin communities. I went to New Hampshire, then Spain, other European places, Israel, then San Francisco. Along the way, I met a lot of other people working on different Bitcoin projects. When I was in Israel, there were some very smart teams working on ideas that people were starting to call Bitcoin 2.0. One of these was colored coins, which is basically saying, 'Hey, let's not just use the blockchain for Bitcoin, but also issue kinds of assets on it.' Then there was a protocol called Mastercoin that supported issuing assets, but also supported many other things, like financial contracts, domain name registration, and a lot of different things together.
[clears throat] Spent some time working with these teams, and I quickly realized that this Mastercoin protocol could be improved by generalizing it more. The analogy I use is that the Mastercoin protocol was like a Swiss Army knife with 25 different transaction types for 25 different applications, but what I realized is that you could replace a bunch of them with things that are more general purpose. One of them was that you could replace three transaction types for three types of financial contracts with a generic transaction type for a financial contract that just lets you specify a mathematical formula for how much money each side gets.
L
Lex Fridman50:26
By the way, a small pause. What's you say financial contract, just the terminology. What is a contract?
L
Lex Fridman50:33
What's a financial contract?
V
Vitalik Buterin50:35
So, this is just generally an agreement where either one or two parties put collateral in, and then depending on certain conditions, like this could involve prices of assets, the actions of the two parties, could involve other things, but they get different amounts of assets out that depend on things that happened.
L
Lex Fridman51:02
So, a contract is really a financial contract at the core, it's the core interactive element of a financial system.
V
Vitalik Buterin51:10
Yeah, there are many different kinds of financial contracts. There are things like options where you give someone the right to buy a thing that you have for some specific price for some period of time. There are contracts for difference where you are basically making a bet that says for every dollar this thing goes up, I'll give you $7, or for every dollar this thing goes down, you give me $7, or something like that.
L
Lex Fridman51:37
But the main idea is that these contracts have to be enforced and trusted that
V
Vitalik Buterin51:41
Yes, exactly.
L
Lex Fridman51:42
You have to trust that they will work out in a system where nobody can be trusted.
V
Vitalik Buterin51:46
Yes.
L
Lex Fridman51:48
This is
[laughter] such a beautiful complicated system. Okay, so you were seeking to generalize this basic framework of contracts.
V
Vitalik Buterin51:58
Mhm.
L
Lex Fridman51:59
So what does that entail? What technically are the steps to creating Ethereum?
V
Vitalik Buterin52:06
Sure. So, I guess just continue a bit with this Mastercoin story. I started by giving ideas for how to generalize the thing. Eventually this turned into a much more fully fleshed proposal that just says, 'Hey, how about you scrap all your futures and instead you just put in this programming language.' I gave this idea to them, and their response was something like, 'Hey, this is great, but this seems complicated and something we're not going to be able to put onto our roadmap for a while.' My response to this was, 'Wait, do you not realize how revolutionary this is? Well, I'll just go do it myself.'
L
Lex Fridman52:45
What was the name of the programming language?
V
Vitalik Buterin52:46
[clears throat]
I just called it Ultimate Scripting.
V
Vitalik Buterin52:50
So then I went through a couple more rounds of iteration, and then the idea for Ethereum itself started to form. The idea here is that you just have a blockchain where the core unit of the thing is what we call contracts. These are accounts that can hold assets and have their own internal memory, but are controlled by a piece of code. So if I send some ether to a contract, the only thing that can determine where that ether goes after that is the code of that contract itself. So basically, sending assets to computer programs becomes this paradigm for creating these self-executing agreements.
L
Lex Fridman53:46
Self-executing. That's so cool that code is part of this contract. So that's what's meant by smart contracts.
V
Vitalik Buterin53:53
Yeah.
L
Lex Fridman53:54
So, how hard was it to build this kind of thing?
V
Vitalik Buterin53:57
Harder than expected. I originally thought this would be something I would casually work on for a couple of months, publish, and then go back to university. Then I released a white paper. A whole bunch of people came in offering to help. A huge number of people expressed interest, and this was something I was totally not expecting. I realized this would be much bigger than I had ever thought, and then we started on a much longer development slog of making something that lives up to this much higher level of expectations.
L
Lex Fridman54:45
What are some of the Is it fundamentally software engineering challenges? Or is there social? Okay, so there's
V
Vitalik Buterin54:52
And social.
L
Lex Fridman54:54
[laughter]
So, what are the biggest interesting challenges that you've learned about human civilization and in software engineering through this process?
V
Vitalik Buterin55:04
So, I guess one of the challenges for me is that I'm one of the apparently unusual geeks who was never treated with anything but kindness in school. So when I got into crypto, I expected everyone would just be altruistic and nice in that same way. But the algorithm I used for finding co-founders for this thing was not very good. It was literally what computer scientists call the greedy algorithm. The first 15 people who applied offering to help became the co-founders.
L
Lex Fridman55:42
I mean, literally the people that would form to be the founders, co-founders of the community. The algorithm. I like how you call it the algorithm.
V
Vitalik Buterin55:52
Yeah, and what happened was that as the project got really big, there started to be a lot of infighting. There were people who wanted it to be a nonprofit and some wanted it to be for-profit, and there were people who were just totally unable to work with each other. There were people trying to get an advantage for themselves in a lot of different ways. About six months later, this led to a big governance crisis. We reshuffled leadership a bit, and the project kept going. Then nine months later, there was another governance crisis, and then a third.
L
Lex Fridman56:41
Is there a way to, if you're looking at the human side of things, is there a way to optimize this aspect of the cryptocurrency world? It seems that from my perspective, there are a lot of different characters and personalities and egos. I also like to think that most people in the world are well-intentioned, but the way those intentions are realized may come off as negative. Is there a hopeful message about creating a governance structure for cryptocurrency where everyone gets along?
V
Vitalik Buterin57:24
After about four rounds of reshuffling, I think we've actually come up with something that seems pretty stable and happy. I definitely do think that most people are well-intentioned. I just think that one of the reasons I like decentralization is because power attracts people with egos, and that allows a very small percentage of people to ruin so many things.
L
Lex Fridman57:54
You think ego has a use? Is ego always bad?
V
Vitalik Buterin58:01
Yeah, it sometimes does. But the Ethereum research team, I feel like we've found a lot of very good people who are primarily just interested in the technology, and things seem to be going quite well.
L
Lex Fridman58:23
Yeah, when the focus and passion is in the tech. So that's the human side, but the technology side, what have you learned? What have been the biggest challenges of bringing Ethereum to life? On the technology side.
V
Vitalik Buterin58:38
So, I think first of all, there's the first law of software development: when someone gives you a timetable, switch the unit of time to the next largest unit and add one. We basically fell victim to that. Instead of taking three months, it ended up taking 20 months to launch. That was underestimating the sheer technical complexity. There were research challenges. For example, one of the things we said from the start we would do is switch from proof of work to proof of stake. Proof of stake is an alternative consensus mechanism where instead of wasting a lot of computing power on solving meaningless mathematical puzzles, you prove that you have access to coins inside the system, and that gives you some level of participation in the consensus.
L
Lex Fridman59:40
Can you elaborate on that a little bit? I understand the idea of proof of work. I know that a lot of people say that proof of stake is really appealing. Can you linger on it a little longer and explain what it is?
V
Vitalik Buterin59:52
Sure. Basically, the idea is that if I lock up 100 coins, I turn that into a virtual miner. The system automatically and randomly assigns that virtual miner the right to create blocks at particular intervals. If someone else has 200 coins and locks them, they get a twice as big virtual miner and can create blocks twice as often. So it tries to do similar things to proof of work, except instead of rate-limiting your participation by your ability to crank out solutions to hash challenges, the thing that rate-limits your participation is how many coins you lock into this mechanism.
L
Lex Fridman1:00:46
Okay, so that limited participation doesn't require you to run a lot of compute. Does that mean that the richer you are, your identity is more stable, verifiable, or whatever the right terminology is?
V
Vitalik Buterin1:01:05
Right. And this is a common critique. My usual answer is that proof of work is even more of that kind of system.
L
Lex Fridman1:01:20
Yes, exactly. I didn't mean it as a criticism. I think you're exactly right. That's equivalent. Proof of work is the same kind of thing, but in proof of work you also have to use physical resources.
V
Vitalik Buterin1:01:32
Yes, and burn computers and burn trees and all of that stuff.
L
Lex Fridman1:01:36
Is there a way to mess with the system of proof of stake?
V
Vitalik Buterin1:01:42
There is, but you would need to have a very large portion of all the coins locked in the system to do anything bad.
L
Lex Fridman1:01:48
Got it. So, just to take a small tangent, one of the criticisms of cryptocurrencies is that for the proof of work mechanism, you have to use so much energy in the world.
V
Vitalik Buterin1:02:01
Yes.
L
Lex Fridman1:02:02
Is one of the motivations of proof of stake to move away from this?
V
Vitalik Buterin1:02:06
Definitely.
L
Lex Fridman1:02:07
What's your sense? Maybe I'm just under informed. Is there legitimately environmental impact from this?
V
Vitalik Buterin1:02:15
Yeah, the latest thing was that Bitcoin consumed as much energy as the country of Austria. Ethereum right now is maybe only half an order of magnitude smaller than Bitcoin.
L
Lex Fridman1:02:29
I've heard you talk about Ethereum 2.0. What's the dream of Ethereum 2.0? What's the status of proof of stake as the mechanism that Ethereum moves towards? And also, how do you move to a different mechanism of consensus within a cryptocurrency?
V
Vitalik Buterin1:02:48
Ethereum 2.0 is a collection of major upgrades we've wanted to do for quite some time. The two big ones are proof of stake and sharding. Sharding solves another problem with blockchains: scalability. Sharding says instead of every participant in the network having to personally download and verify every transaction, each participant only downloads and verifies a small portion of transactions. You randomly distribute who gets how much work. Because the distribution is random, it still has the property that you need a large portion of the entire network to corrupt what's going on inside any shard, but the system is still very redundant and secure.
L
Lex Fridman1:03:39
That's brilliant. How hard is that to implement, and how hard is proof of stake to implement? On the technical level?
V
Vitalik Buterin1:03:47
Yeah.
L
Lex Fridman1:03:48
Software level?
V
Vitalik Buterin1:03:49
Proof of stake and sharding are both challenging. Sharding is more challenging because it changes both consensus and networking layers. Instead of gossiping everything, you need sub-networks. It's a more complex architecture not yet done in cryptocurrency.
L
Lex Fridman1:04:32
So most of the networking layer in cryptocurrency is shouting broadcasting messages, like ad hoc networks.
V
Vitalik Buterin1:04:42
Yeah, shouting within smaller groups.
L
Lex Fridman1:04:45
Smaller group, but do you have a bunch of subnets?
V
Vitalik Buterin1:04:47
Exactly.
L
Lex Fridman1:04:48
And you have to switch between... So from a graph theoretic perspective, but just the software: who's responsible? Is the Ethereum project like the people involved? Would they be implementing? How does that work? Is there a software engineering lead? Is this a large-scale open source project?
V
Vitalik Buterin1:05:19
Mhm.
L
Lex Fridman1:05:22
Is it a legit almost like large scale open source project?
V
Vitalik Buterin1:05:25
Yes, we have Danny Ryan as de facto development coordinator. Ethereum Foundation does research in-house, independent teams implement around the world. We need lots of coordination.
L
Lex Fridman1:06:20
How far into the future are we from Ethereum 2.0? What's the timeline?
V
Vitalik Buterin1:06:36
Ethereum 2.0 has three phases: Phase zero creates a proof of stake network separate from proof of work. Phase one adds data sharding. The merger phase moves everything from ETH 1 to ETH 2. Phase zero is almost fully implemented, in auditing. Feels like 4 months away from launch.
L
Lex Fridman1:07:59
But that's just a hunch?
V
Vitalik Buterin1:08:01
That's just a hunch, yeah.
L
Lex Fridman1:08:03
How do you see the move from Python to Python 3? Drastic phase shift?
V
Vitalik Buterin1:08:25
In phase zero, not many people will do much because the new chain lacks functionality. It's for validators. Existing applications stay on ETH 1. The merger happens all at once.
L
Lex Fridman1:09:06
What's Casper FFG?
V
Vitalik Buterin1:09:09
Casper FFG is the consensus algorithm for proof of stake.
L
Lex Fridman1:09:14
Anything interesting specific about it?
V
Vitalik Buterin1:09:20
Casper FFG combines two schools: 50% fault tolerant with network synchrony, and 33% fault tolerant safe under asynchrony. It provides best of both worlds: chain works normally with synchrony, but finalised blocks cannot be reverted even if synchrony fails.
L
Lex Fridman1:10:16
That's fascinating. How would you make that happen?
V
Vitalik Buterin1:10:20
It's quite clever. I'd recommend the Casper FFG paper on arXiv.
L
Lex Fridman1:10:30
That's on arXiv. Who are the authors?
V
Vitalik Buterin1:10:34
Myself and Virgil Griffith.
L
Lex Fridman1:10:37
That's awesome. Tangent: putting white papers on arXiv publicly. Is that necessary for cryptocurrency?
V
Vitalik Buterin1:11:00
Yes, openness is mandatory for crypto because you need to trust without trusting operators. We have ETHResearch forum for publishing half-formal ideas. It's been great for collaboration.
L
Lex Fridman1:12:34
That's brilliant.
V
Vitalik Buterin1:12:34
Yeah, it's been great for us.
L
Lex Fridman1:12:37
I interrupted you. Was there something else on Casper FFG?
V
Vitalik Buterin1:12:41
It just combines these two schools.
L
Lex Fridman1:13:21
Okay, I'm going to read the Casper FFG paper. What are some of the most beautiful ideas in Ethereum? Something surprising, beautiful, powerful?
V
Vitalik Buterin1:13:40
Money emerging from a database if people believe in it is up there. Also, composability: applications can talk to each other without permission. Example: CryptoKitties and CryptoDragons.
L
Lex Fridman1:14:52
So it's arbitrarily composable. You could build entire ecosystems.
V
Vitalik Buterin1:15:06
Yes, especially in DeFi. Stablecoins like Dai, decentralized exchanges like Uniswap with its simple x*y=k curve. Very easy to set up and provides value.
L
Lex Fridman1:16:58
And the distributed infrastructure allows that.
V
Vitalik Buterin1:17:06
Yes, it's a computer program on Ethereum.
L
Lex Fridman1:17:12
Smart contracts are fascinating.
V
Vitalik Buterin1:17:15
They are.
L
Lex Fridman1:17:16
Do you think cryptocurrency may become the main currency? Where are we headed?
V
Vitalik Buterin1:17:29
Fiat will continue and digitise. Cryptocurrencies are important as alternatives when fiat breaks. Their global neutrality is key.
L
Lex Fridman1:18:39
You're humble. You don't think it could become the main?
V
Vitalik Buterin1:19:03
It's possible, but need price stability. Stablecoins help. The challenge is volatility due to fixed supply. Supply flexibility can absorb volatility.
L
Lex Fridman1:20:42
Bitcoin has fixed supply, Ethereum doesn't. Can you clarify? Is Ethereum the kind of currency with flexible supply?
V
Vitalik Buterin1:21:01
It's a bit more flexible, but what you really want is flexibility in response to value. Look at stablecoins like Dai, which is issued by a smart contract holding ether, pairing leveraged users with stability seekers.
L
Lex Fridman1:22:23
Fascinating. This world is awesome technically. But as an outsider, I see hype and charlatanism. How to learn without that?
V
Vitalik Buterin1:23:04
Follow the right people: cryptographers, researchers, Ethereum crew, academics like Dan Boneh. If someone is too self-promotional, remove them.
L
Lex Fridman1:23:58
Just crawl along that, start with Ethereum group and academics, then expand.
V
Vitalik Buterin1:24:07
Yeah, exactly.
L
Lex Fridman1:24:13
Are there books for introductory material?
V
Vitalik Buterin1:24:28
For history: 'Digital Gold' and Matthew Leising's Ethereum book. For technical: 'Mastering Ethereum' by Andreas Antonopoulos.
L
Lex Fridman1:24:46
Great. Let me ask about governments and decentralized currency. Can they be friends?
V
Vitalik Buterin1:25:27
It's not entirely enemy. Government regulation prevented big tech from issuing currencies, which helped decentralized ones. They've gone after fraud. They can use blockchains for identity, property, etc.
L
Lex Fridman1:27:17
Yeah, they can leverage technology. You met Putin. What was that like?
V
Vitalik Buterin1:28:12
He's shorter in person. I only had a minute. Some ministers were interested in blockchains for corruption, but hard to gauge.
L
Lex Fridman1:28:59
When Obama talks about AI, he seems to have thought deeply. Did Putin or ministers think about blockchain fundamentals?
V
Vitalik Buterin1:29:40
Some are old school, some new school. It depends.
L
Lex Fridman1:29:47
That's an open question. But you only talked to him a minute.
V
Vitalik Buterin1:29:52
Yeah.
L
Lex Fridman1:29:55
But you can pick up insights. There are about 3,000 cryptocurrencies. Is that diversity good? Should there be a winner?
V
Vitalik Buterin1:30:34
Diversity is good but too many. Number should be greater than one but not 3,000. Experimentation is healthy.
L
Lex Fridman1:31:37
Do you see overlap between distributed apps and AI? Do you think about AI?
V
Vitalik Buterin1:31:57
Yes. AI control problems. Both fields have the challenge of a simple system directing a complex one.
L
Lex Fridman1:33:06
Do you think about your own mortality? What do you hope to accomplish?
V
Vitalik Buterin1:33:12
I think about ending mortality. If eternal life is fulfilling with friends and challenges, then yes.
L
Lex Fridman1:33:54
Live forever but check fine print. Thank you, Vitalik.
V
Vitalik Buterin1:34:16
Yeah, thank you.
L
Lex Fridman1:34:17
Thanks for listening. Sponsors: Express VPN and MasterClass. Subscribe, review, support on Patreon. Connect on Twitter @LexFridman. And now words from Vitalik: 'The thing I often ask startups on top of Ethereum is, can you please tell me why using Ethereum blockchain is better than using Excel? And if they can come up with a good answer, that's when you know you've got something really interesting.' Thank you for listening.