From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Thu, 08 Oct 2026 09:49:34 -0700 Received: from mail-oo1-f64.google.com ([209.85.161.64]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1xErJF-0002ch-Fk for bitcoindev@gnusha.org; Thu, 08 Oct 2026 09:49:34 -0700 Received: by mail-oo1-f64.google.com with SMTP id 006d021491bc7-6dd1142710fsf7046490eaf.3 for ; Thu, 08 Oct 2026 09:49:33 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1791478167; cv=pass; d=google.com; s=arc-20260327; b=s4F737yz7i5qchJS1sZaSVhLcbYRLtWv7biR1UXjfm42XiasTmvKqRu7S5873okCwe 56L/s77Wx6aDCPYy2cXMcSUiPIwzT3bjor7NIBoN+fYrry3gOTMoPdX9A4VmX6piYqe2 T5Pf/Bs2CM2cBFgOZEFMT9XUFkL0hG2Wck/NBt86XUqm6QRUrnJxliZaYEjCCEae6anc dWuytpEZr01rtQ62i0E4vksg6Wblig1vzb2WISG88aQvqI+khh5rMEZ7Yi7W838ibtRc SFh/L/gMDJunjDny76IpKfsDShLB7TyJ6BS6/Vne/rrIx31zRSh1ue/Oa3EupVxasAKv 0Zwg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:to:references:message-id :content-transfer-encoding:cc:date:in-reply-to:subject:mime-version :from:sender:dkim-signature:dkim-signature; bh=aAe1HZTrOltePM2h8r7/EIjd86ZTzQeg93zVZitG2r0=; fh=t02QihZGenlYR4EXX3lnJoPLW+FHAwKg2PHYUVuNytg=; b=Oh46wpFV4EP5StlPTs0UJSoPXhkshpvCjgfJLCpfLMofVsZpKEgkGp/AIG+sGOgiAf 4AP7wkC0UWaA2hKI6DOnMuSxQgmN/NJX68AlowKaJ6xlJZ2RhkCN9AyKM5cHzSAw+vtF ZZDca1EHq27OdO5UOSL45BGonTI9wqNrZWXHkQHaGtrf/VhB/7rMhMesR6yKj+z3SQxj aWkc1C/vOUDT4s9vYIuNiHu5004R47/1Q2KpRuc83k7bS4xZGxgQfo1+APxY1rZjknH4 Sxnc3hYVrB+/j3gE6iS5Ilz0yaaWT5NQbHpMR86kcohf/09FXQnVnBw2WkH18p3yXOQt uyOw==; darn=gnusha.org ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=B79mhdLQ; spf=pass (google.com: domain of oleganza@gmail.com designates 2a00:1450:4864:20::42b as permitted sender) smtp.mailfrom=oleganza@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1791478167; x=1792082967; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:to:references:message-id :content-transfer-encoding:cc:date:in-reply-to:subject:mime-version :content-type:from:sender:from:to:cc:subject:date:message-id :reply-to:content-type; bh=aAe1HZTrOltePM2h8r7/EIjd86ZTzQeg93zVZitG2r0=; b=SgcvrzZcF1YNMzTaPrT1eqbPbBBPa1tlrFvoN5oJHu40wH50NbehJoWEjVoTGnW8Fi aNno/FeTBJ+cjGMW4dpcn2g8SsqhBXecIP5SgIlpFiGlY9nh3j6/PwhMboItOwdv9ADU RS2ozbN9++vZvEIPc9CXtqhqx4RJpFcncIJ1929aSXCuEPquREsrHPmJfbOhesaEps83 NBJmEySUjXF/DFSPVzjeGWvfIl+f/Hnye9FdUFSg6vat37k9Zx8zIaoNqRJ6KIYWHPTA IsfxsMRJ79qo/285zc2vmI29ug3gVBzL7PRXLT5LAoYlfEcCF2CQME1DQ3uKEpBfnN7d RT5A== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791478167; x=1792082967; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:to:references:message-id :content-transfer-encoding:cc:date:in-reply-to:subject:mime-version :content-type:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=aAe1HZTrOltePM2h8r7/EIjd86ZTzQeg93zVZitG2r0=; b=noJt5HsytmBOL1wFIbOmM7MjPRvditVp8jT5n9ueEJX0jP/gMAomVPtKkbDhYlRMlz hnbnPCd8w3SWPXnKZr9K6eBtaUgvW7Gx6kc9d8WTNRj7d+KAxSAPc/JSN5B/zeNfKp6W LQrnUJEMAUYETvw2mbojqVb3nr5U9w2u+WFiDL+CCb8S7pkUHyJYnAoKbddusez8X1lj 5xQFfrDJdTjiu03l5efD6ZIVulmjqIdGACWEoEZWlIobaNyxR1DVbNKTe35AAO1RFxfL 8XPa5dcpIuty+a1bMgcnYYcjKuRD2whFaHAOvBEyDKDGPN8mT2dS56Bp2656X/xFWiXk g8rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791478167; x=1792082967; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:to:references:message-id :content-transfer-encoding:cc:date:in-reply-to:subject:mime-version :content-type:from:x-gm-gg:x-beenthere:x-gm-message-state:sender :from:to:cc:subject:date:message-id:reply-to:content-type; bh=aAe1HZTrOltePM2h8r7/EIjd86ZTzQeg93zVZitG2r0=; b=QhzDIBNQUfpHQCKQj8nZwFo0k6hm4QVoXrFNijwwTMcm93ehBsXq3U8tbrUi41DprH 2x66FmBYg3JCzO4v3CR2wMJ3o2CqpqZh36rMEBmHmZM1TY+/DdJznfLB8u/YqYJDuyCw qaGXD3269xSAYfMWMw5Mmh0u6hRqXZ+ekKwUxJweiEvKI0ubJ7k3ADxDwRHIEUOp/4xb /UnhQUB6QQ5y5N5n3Yz0qBJBGQMF3VdYBy4nC8EcHtQ1QY/32eAgQuvuG0bk3VxvQhzn QaSk3aFh/UoJGdU/UYkzNa4qmcTQrNNbX8yOM3LbA3hiLyt1/lLJlppAzWbr+/4dXtsF Jxyg== Sender: bitcoindev@googlegroups.com X-Forwarded-Encrypted: i=2; AKwUvBx+wZDRudZ68wnmVj3pYgHI2FyiqFsrwB1/0dFVrSMQCCKJ+pWMQtbkn4b+OZNkbAyOn0fDQcaFfPe/@gnusha.org X-Gm-Message-State: AFuF++l0pKrAjykdFDVljAc3TJkZkxRg3p95+XeUZ7kh4FB9MllEQ/0V HxdQXnhAHs/+MwwergGRO1Sc9ivImrpRAqZHO45OM/vL4/dHiUFSudZ1 X-Received: by 2002:a05:6820:f004:b0:6e0:44f8:14ed with SMTP id 006d021491bc7-6e7a480ff4cmr5248550eaf.4.1791478167287; Thu, 08 Oct 2026 09:49:27 -0700 (PDT) X-BeenThere: bitcoindev@googlegroups.com; h="ATskLdf632zvdrjJjInlcCa44TwifpJaazYvxIAqiSho1Sb9VA==" Received: by 2002:a05:687c:354:10b0:49d:f7b1:71ff with SMTP id 586e51a60fabf-4a2539fc28als1818735fac.1.-pod-prod-03-us; Thu, 08 Oct 2026 09:49:20 -0700 (PDT) X-Received: by 2002:a05:6808:2202:b0:4b9:a8ac:484 with SMTP id 5614622812f47-4fc45b55b8cmr5108068b6e.34.1791478159934; Thu, 08 Oct 2026 09:49:19 -0700 (PDT) Received: by 2002:a05:600c:6989:b0:49f:f266:ab42 with SMTP id 5b1f17b1804b1-4a17f497dfems5e9; Thu, 8 Oct 2026 09:48:35 -0700 (PDT) X-Received: by 2002:a05:600c:3e0a:b0:4a1:6c79:fd31 with SMTP id 5b1f17b1804b1-4a180459354mr104167235e9.12.1791478114291; Thu, 08 Oct 2026 09:48:34 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1791478114; cv=none; d=google.com; s=arc-20260327; b=HwTC1H/IWH70NJfC/exbqwWD4d0bro5q8xcyYdDDwyu25z3qw2sDWpEq1x4cfwVrEu 8qt6UxUqutRAT/5bKPpTv6xjQHvTEluforYIqljETI/FQvZCtbPYw7SSgWsZZcM+4ESh pMUrzZxLXk151bvqLL3p/qffvTZ1GIUvE68m5eKpoAyoA0v/SoXtIcxtBXRqiPzjho1V 1BlyQxGMDth0qcfk0kyIiZky8OMnDeznuspwcZJ1DdgN5GIq3tzCxtTLKAfHXAvW3949 FL4yuPFAKTIiUtIKuVYX8oJGPsESQs/qv7ICHvjhwraJHfmM731W0ddC+E402bJP9MHZ Uj8Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:subject:mime-version:from:dkim-signature; bh=azTkD9EvmUGnlWO0VA5UAlqs0tvKKJVobi7GHkSrQeg=; fh=yWJGkAOdAw4MqEViVFh1iSiDsdGPgba3zYnMigF6gTQ=; b=FZJ5/x3XDZSQYWsp5Phsz8QveaHpY6ln84rdB5JJV46ZmCO6IqZd0n+gmeUTbuopSc 2vXx4fRiJt9+PyPG52eSlN3aeNoI65q1gsVuetBzfjZK67t9mkcQtBlQFsnmGjsh6vt8 sF9xXrXSzoAlNS7nbtP51lB0XQK4rTtWH4SqTST2IqZTfZtutCMWTGONkEtgXQHmL8FX ZQerIvDdF33+OYzJ4er21Mvd/ldVxUfqia6PffwZygNcY7XoA8vgb+M4av+sU/FJWodq GefqF/Qb5DK6dbrF9G7PuzfB+a9qa29kJDiW6dx3Q8KCXeUAZtlD176vZJlSHrr4PHm2 2yyA==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=B79mhdLQ; spf=pass (google.com: domain of oleganza@gmail.com designates 2a00:1450:4864:20::42b as permitted sender) smtp.mailfrom=oleganza@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com. [2a00:1450:4864:20::42b]) by gmr-mx.google.com with ESMTPS id ffacd0b85a97d-48db6524614si3913f8f.4.2026.10.08.09.48.34 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 08 Oct 2026 09:48:34 -0700 (PDT) Received-SPF: pass (google.com: domain of oleganza@gmail.com designates 2a00:1450:4864:20::42b as permitted sender) client-ip=2a00:1450:4864:20::42b; Received: by mail-wr1-x42b.google.com with SMTP id ffacd0b85a97d-48441a2ba1bso3272761f8f.1 for ; Thu, 08 Oct 2026 09:48:34 -0700 (PDT) X-Gm-Gg: AYBFou2DAKGh4QJl9AC2+ZGIrKLsnsuSxRtcSWQt4NenywnJmHxyef3CoXpvoQ6L42X gDKPNW2L1R36PB+tklj11Ya5DhIWEDR3H0gtJ+nIvDyKFLsZhNFKQY2fEvxLidE4nLkCJwIXlPF HvbBPd54v96K+byGrM1bEAq9Xc1sQQDQI94gKMnybp0hvVkfFl+lmtgXvf36LDTvyE8wywievBQ ARNL6YGZFOSeo2wp/USd2kH+jvpWD676AOlhZz+t74l73Ii3rf4f+ij862N8Pq7Gc2khDe2NoG/ HnbNDp7AgnhbmriC4QQ5Cgw5r0tsFv/tYQPm3rTDpVcPQ0ajI+X0rVCrE00mWJclxls914/d+hl Meez4HcX78n6eRAftUrfb1JwHo5UH1X0gTYDlfgf3Ejz6f7pfRqZ1uNJceraOhW+2ni7GBcMZKB A4l6iaNvIVHl7ar5xKQu5rB0bM7LE/Gorr3fqI2IDNJnMOioBBN/oTKGQWpkcZzFYasPiTRaUNg h8snojZpSPCxLr/rYAQL5MUBRcffXStTEU5psfLvRqo29vSbz/UTzc6wicY8ETMPQDPuHKJR0zp sx0= X-Received: by 2002:a05:6000:4815:b0:48a:f404:695e with SMTP id ffacd0b85a97d-48c728a381bmr12188853f8f.50.1791478113480; Thu, 08 Oct 2026 09:48:33 -0700 (PDT) Received: from smtpclient.apple (brnt-02-b2-v4wan-169592-cust1744.vm7.cable.virginm.net. [81.99.54.209]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db654cd87sm439897f8f.58.2026.10.08.09.48.32 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 08 Oct 2026 09:48:32 -0700 (PDT) From: Oleg Andreev OOO Content-Type: text/plain; charset="UTF-8" Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81\)) Subject: Re: [bitcoindev] Flame: confidential transactions with Bitcoin proof-of-burn consensus In-Reply-To: Date: Thu, 8 Oct 2026 17:48:22 +0100 Cc: Bitcoin Development Mailing List Content-Transfer-Encoding: quoted-printable Message-Id: <9517998B-3019-4ADE-B566-F30D42F33C37@gmail.com> References: <7aa8774d-c650-457d-9013-dfb817b728d6n@googlegroups.com> To: waxwing/ AdamISZ X-Mailer: Apple Mail (2.3826.700.81) X-Original-Sender: Oleganza@gmail.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=B79mhdLQ; spf=pass (google.com: domain of oleganza@gmail.com designates 2a00:1450:4864:20::42b as permitted sender) smtp.mailfrom=oleganza@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: -0.5 (/) Hi Adam, thanks for showing interest in Flame! On burning. We have considered a one-way peg as Ruben proposes (meaning, when X units o= f BTC are converted one-way into X units of "SideCoin"). The problem is: su= ch conversion erases the information about the risk that earlier adopters o= f the sidechain take compared to later adopters: if you know that coming la= ter gives you the same reward opportunity, why come in now and bear the hig= her risk? Then, if you try to tackle that problem with an additional Reward= Coin, you face another problem (I really did consider a dual-coin architect= ure for some time) =E2=80=94 how do those assets play together, and how doe= s SideCoin erode the value of RewardCoin (in other words, erode "efficiency= ")? If we look at the risk/reward from the angle of network security (as oppose= d to the individual's financial calculation), the problem is the same. Sacr= ifice-based consensus, such as Bitcoin's PoW, requires maximum efficiency o= f the sacrifice: so that every penny of a sacrifice goes into the security = metric. If the honest nodes are not the most efficient, but the attacking n= odes are, then attackers have a better chance of reverting the chain with l= ess capital than all the honest nodes combined. Making the reward coin weak= er as an incentive makes the sacrifice less efficient. For example, by lock= ing the capital temporarily instead of permanently, only a portion of its b= itcoin value (the TVOM) is actually contributed, not 100% of the coins. The difference between RewardCoin and SideCoin is much smaller than one may= think because SideCoin would still be a qualitatively different asset with= a different and changing market value. Flame simply acknowledges that and = offers a fixed supply for whatever the market wishes to burn. In the long r= un, =E2=89=8899.99% of flames are produced out of X% of bitcoins. On utility. "It's not bitcoin" is a fair concern, but so is the security of all the oth= er chains where bitcoins are supposedly bridged. To be "the bitcoin", the f= unctionality of interest must be a part of Bitcoin's ossifying consensus ru= les. With every year, that possibility fades away similarly to how we'd see= an astronaut falling into a black hole: never quite disappearing, but sure= ly on the way out :) The problem with soft/hard fork consensus upgrades is = that everyone needs to "buy in" simultaneously and believe in the upgrade b= efore it is tested out in real life. Flame is adopted by the market: everyo= ne decides when and what portion of their bitcoin to "upgrade". Also, there are places that your bitcoins may "visit", but very few where t= hey want to "live". Flame hopefully gives you security model much closer to= Bitcoin's and, correspondingly, an asset that's by its nature is much clos= er to bitcoins than any altcoin. Cheers, Oleg. > On 4 Oct 2026, at 14:18, waxwing/ AdamISZ wrote: >=20 > Hi Oleg, > Interesting work! Personally I like this general class of ideas. If we th= ink about the simplest form of the idea: to enter the sidechain, you burn b= itcoin, I believe its first proponent is Ruben Somsen with 'spacechains' [1= ]. I think you should compare your design with that? At the time he propose= d it I was less positive; the obvious question/problem is that without the = reverse path the 'coin' can't truly be called bitcoin, it's a different thi= ng. And I also thought, it's hard to convince people a one way transfer is = worth it (yeah, that's really vague; who knows; it's more just intuition, l= ess fact). More recently, I put together a PoC of what I called "hodlchain= " [2] which, apart from fancy theorizing about time value of money aspects,= is basically just 'spacechains but with CLTV/fidelity bond style time lock= s instead of burn'. I liked this version because I saw it as an unlock of d= ormant value: the hodler gets rewarded for the positive externality of thei= r behavior without having to change it. >=20 > With regard to your minting and supply as per your Section 3: yes I wrest= led with that a bit in 'hodlchain' too. The reason I didn't like your minti= ng schedule: fixed per epoch minting --- is that it doesn't feel like the f= airest option for the ordinary user: they're forced into an auction/market = that they have to make a judgement about whether they're going to get good = value or not. But in holdchain I had another 'TVOM' variable to play with (= r) due to using locking. With burn, I guess your choice must be right: fixe= d minting lets the other side (burn) vary according to market's assessed va= lue of flame; if you had a fixed rate of flame:btc in minting then if the m= arket doesn't like it, the system doesn't work (your consensus relies on th= e minting). >=20 > Also, it's unfair of me to compare: you're actually trying to build *cons= ensus* from the burns; I wasn't bothering with that. That makes your design= intuitively seem like it must be the correct one: proof of sacrifice of va= lue ~=3D proof of work. I guess it's 1-layer-down PoW in the sense of, it h= as PoW security assuming bitcoin's value and consistency, so, assuming Bitc= oin's PoW security. >=20 > I won't comment on the detailed design of the flame-sidechain itself. It = looks pretty interesting :) I think this 'it's not bitcoin' thing is the ma= in thing that puts people off, though a counterpoint is, systems can get qu= ite some interest if they have a speculative element from mining for new/mi= nted coins. The problem with that angle is there are lots of other places t= o put your bitcoin into another system, speculatively, with all kinds of ne= w features. And it's not hard to get your bitcoin back when you want to via= swaps. > Cheers, > AdamISZ/waxwing > [1] https://medium.com/@RubenSomsen/21-million-bitcoins-to-rule-all-sidec= hains-the-perpetual-one-way-peg-96cb2f8ac302 > [2] https://github.com/AdamISZ/hodlchain >=20 > On Thursday, October 1, 2026 at 2:07:14=E2=80=AFPM UTC-3 Oleg Andreev wro= te: > I've been working on Flame, a Bitcoin "side chain", based on proof-of-bur= n consensus: a fully decentralized protocol in which nodes continuously bur= n bitcoins to protect against double-spending. I believe this approach avoi= ds shortcomings of proof-of-stake, merged mining, and alternative proof-of-= work protocols. There are no special privileges for developers, miners, or = validators. >=20 > The network architecture combines proposals by Bitcoin developers and a f= ew ideas from other networks, as well as my earlier work, which some of you= may know from Chain's TxVM (2017) and Interstellar's ZkVM (2019). Flame pr= ovides transaction confidentiality with a programmable constraint system ba= sed on Bulletproofs and Ristretto, Taproot-based predicates, Utreexo storag= e for unspent outputs, and actors with leased storage. I've aimed for a bal= anced, practical solution for decentralized applications and privacy, with = a security model as close to Bitcoin's as possible, while having a purely m= arket-driven adoption strategy that does not require changes to Bitcoin's c= onsensus rules. >=20 > I suppose proof-of-burn system on top of Bitcoin creates some interesting= dynamics for Bitcoin economics: in terms of demand for block space and lon= g-term relative effects on miners' rewards. >=20 > The overview is available at: > https://runflame.org/flame.pdf >=20 > The work-in-progress implementation: > https://github.com/runflame/flame-lib >=20 > The project is still under development. Mainnet launch is planned for Jan= uary 2027. >=20 > Oleg. >=20 > --=20 > You received this message because you are subscribed to a topic in the Go= ogle Groups "Bitcoin Development Mailing List" group. > To unsubscribe from this topic, visit https://groups.google.com/d/topic/b= itcoindev/Ov92xNLvm8w/unsubscribe. > To unsubscribe from this group and all its topics, send an email to bitco= indev+unsubscribe@googlegroups.com. > To view this discussion visit https://groups.google.com/d/msgid/bitcoinde= v/ccb16c4b-ede1-41dc-acf1-d4c286181e7dn%40googlegroups.com. --=20 You received this message because you are subscribed to the Google Groups "= Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoindev+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/= 9517998B-3019-4ADE-B566-F30D42F33C37%40gmail.com.