spent some time thinking about who actually has to show up for tbv to stay honest.
the vault doesn't verify fraud on its own. a garbled circuit checks the proof off-chain, and only if that proof is wrong does it reveal a preimage that unlocks a bitcoin hashlock as punishment. bitcoin itself never checks the loan logic, it just enforces the outcome someone else computed.
that outcome depends on a watcher.
the claimer set is fixed when the vault is created, so only pre-approved parties can ever run the challenge and catch a bad proof, no one outside that set is allowed to intervene.
at first that sounded like a formality.
but if none of those pre-set parties are online or watching when a fraudulent proof lands, the cheat just goes through, because bitcoin has no mechanism to notice on its own.
the security model isn't proof-based security, it's proof-based security plus availability.
cut-and-choose makes lying about the circuit unlikely, not impossible, and bitcoin can't independently verify the setup was honest.
that's a narrower guarantee than it sounds.
fewer required parties means fewer points of failure, but it also means fewer eyes checking the vault at any given moment.
worth sitting with.
more challengers means more redundancy, but every added party is someone else who could go offline right when it matters.
so does a smaller trust set make tbv safer, or just quieter about where the risk sits?
@BabylonLabs_io #baby $BABY
the vault doesn't verify fraud on its own. a garbled circuit checks the proof off-chain, and only if that proof is wrong does it reveal a preimage that unlocks a bitcoin hashlock as punishment. bitcoin itself never checks the loan logic, it just enforces the outcome someone else computed.
that outcome depends on a watcher.
the claimer set is fixed when the vault is created, so only pre-approved parties can ever run the challenge and catch a bad proof, no one outside that set is allowed to intervene.
at first that sounded like a formality.
but if none of those pre-set parties are online or watching when a fraudulent proof lands, the cheat just goes through, because bitcoin has no mechanism to notice on its own.
the security model isn't proof-based security, it's proof-based security plus availability.
cut-and-choose makes lying about the circuit unlikely, not impossible, and bitcoin can't independently verify the setup was honest.
that's a narrower guarantee than it sounds.
fewer required parties means fewer points of failure, but it also means fewer eyes checking the vault at any given moment.
worth sitting with.
more challengers means more redundancy, but every added party is someone else who could go offline right when it matters.
so does a smaller trust set make tbv safer, or just quieter about where the risk sits?
@BabylonLabs_io #baby $BABY