Today we release BABE, a new Groth16 proof verification protocol for Bitcoin. It improves the state-of-the-art by three orders of magnitude in setup and storage costs.
https://t.co/Yxfwql6y1E
BABE (BAbylon-BErkeley) is a synthesis of two key ideas:
Witness encryption on linear pairing, and Argo MAC, a recently introduced garbling primitive.
Witness encryption on linear pairing reduces the complex pairing operations in Groth16 verification to a single scalar multiplication on the BN254 elliptic curve. The single scalar multiplication can further be transformed into a vector homomorphic MAC, which can be efficiently computed by Argo MAC.
BABE will be launched as part of Babylon's alpha-testnet for the Trustless Bitcoin Vault in February.
We thank:
- our Berkeley collaborators @SanjamGarg and Dimitris Kolonelos for teaching us so much about witness encryption
- @liameagen and @therealyingtong for sharing their amazing work on Argo MAC
- the Babylon engineering team, for turning our theoretical ideas into a real system with demonstrable performance gains
Check out the paper and give us feedback!
BitVM2 suffers from a huge on-chain fee of > $15,000. BitVM3 dramatically reduces this to be less than $100, but the off-chain costs are very significant: terabytes to store the garbled circuits and hours of compute and communication to set things up. Bulky.
Three months ago we embarked on a totally different approach based on witness encryption. Happy to report today that we got a 3 orders of magnitude reduction in storage and in the setup time while keeping the transaction fees as BitVM3. More details later.
Today we published a temp check on the @aave governance forum: Babylon Trustless BTC Vault Integration on Aave v4.
The temp check proposes two new Aave v4 Spokes to onboard native BTC as collateral via Trustless Bitcoin Vaults and seeks community input.
https://t.co/l4oa3MdXJA
@MillieMarconnni Sometimes you work on a research problem not because you already know it is the most important problem but because you are curious to understand something. Only later does it become really important. Claude Shannon’s information theory is a good example .
Babylon is looking for a researcher! Let me know if you or your colleagues are interested. Here is a short blurb:
Babylon (https://t.co/6N9GMO1mbD) is a blockchain infrastructure startup founded by David Tse of Stanford and Fisher Yu, and backed by a16z, Paradigm, Polychain, and other leading investors. Babylon’s vision is to enable the trillion-dollar Bitcoin asset to be used trustlessly in the DeFi economy.
Babylon invented Bitcoin staking, now a live protocol with over $4 billion in BTC staked (https://t.co/pB2gwXDIFw). The team is currently focused on launching trustless Bitcoin vaults (https://t.co/0Q65iPrhTR), enabling native Bitcoin to be used as collateral in DeFi protocols such as Aave, without wrapping or bridging. This work is powered by BABE (CCS 2026), a proof-verification protocol for Bitcoin based on witness encryption and garbled circuits, achieving a 1000× cost reduction over the state of the art (https://t.co/5YopjydOd3).
The ideal candidate has a Ph.D. in distributed consensus, cryptographic protocols, or a related area, and a strong interest in doing impactful research in the blockchain space. In this role, the Senior Researcher will work closely with Babylon’s engineering team as well as external research collaborators at a16z, Common Prefix and leading universities.
Today we published SCRIPT - Bitcoin Collateral Risk Assessment Framework.
Bitcoin holders and applications can use SCRIPT to assess the counterparty risks of any Bitcoin collateral solution, including Babylon’s.
The framework consists of six risk categories.
Read more 🧵👇
https://t.co/Ux5w76aEN9
📢Paper accepted at ACM CCS 2026:
📜 https://t.co/KBqkp6OeAC
@dntse@SanjamGarg
BABE: an efficient protocol for verifying SNARKs on Bitcoin, being implemented by @babylonlabs_io
🗓️Also presenting at: Bay Area Crypto Day (Stanford, May 1) and @Designing_DeFi (NYC, May 20)
Babylon brings native Bitcoin into DeFi and bringing more Bitcoin into DeFi means supporting in hard moments.
Babylon Foundation will deposit $3M USDT into Aave, with $2M allocated to V3 and $1M to V4, as a show of support and confidence in @aave and DeFi.
Any interest earned from this deposit would be directed back into the Aave ecosystem through Aave x Babylon integration incentives, so the same capital can support recovery now and future adoption later.
We believe DeFi is a core part of the modern financial system. That means competing, building, and rallying with the ecosystem when it needs it.
We’re putting capital behind conviction and our commitment to the @aave ecosystem.
https://t.co/hxMJrYFUnc
I've loved collaborating with the team at Berkeley (including @SanjamGarg and Dimitris Kolonelos), but we have set a high bar by solving a breakthrough problem in our very first work together.
When we entered the BitVM space 12mos ago, we were learners studying existing approaches. Fast forward and we've developed the 4G equivalent
The way I see it. BitVM2 is like 2G, BitVM3 is 3G, and BABE is 4G
By entering later, we got to skip generations.
Dan Boneh gets phone calls every few days asking whether quantum computing threatens Bitcoin.
I'm not an expert in quantum cryptography, but Robin Linus thinks the fear is overblown.
Right now, I'm focused on the more immediate challenge: launching the Bitcoin vault without losing anyone's bitcoin.
Ethereum's long-term goal: Everything should be proven, nothing trusted.
Every transaction, every operation, formally verified as correct.
They're starting with ZK proof systems. The ambition is remarkable even if fully achieving it remains distant.
Every time you move to a new research area, you lose everything except your thinking.
No reputation. No relationships. No credibility.
Just the problem in front of you.
Four years to find product-market fit.
Four years to continuously improve it.
That's the honest timeline for most successful protocols.
Anyone claiming a shorter path is measuring something else.
Ep 3 of Beyond Digital Gold is out!
Will the real Bitcoin DeFi Please Stand Up??
Everyone disagrees with what Bitcoin DeFi is. Some say it already exists through wrapped Bitcoin on Ethereum.
Others argue it will happen on Bitcoin Layer 2s, while disagreeing on what Bitcoin Layer 2s are.
And some believe the only real Bitcoin DeFi must happen directly on Bitcoin itself.
In our latest episode in our Beyond Digital Gold documentary series with @StarkWareLtd , we map the entire ecosystem and break down the six competing models trying to unlock Bitcoin’s trillion-dollar liquidity.
Watch here 👇🏻
Full episode: https://t.co/1lnev6HSwN
I'm learning cryptography through two methods:
1. Shamelessly asking our collaborator cryptographers "stupid" questions
2. ChatGPT as a 24/7 tutor
After Dan Boneh's course, I can't ask him questions daily. But collaborators are captive audiences, and ChatGPT never sleeps.
Hackers perform cost-benefit analysis: How much benefit versus how much effort to find the exploit?
Smart contract vulnerabilities offer better ROI than Bitcoin protocol attacks.
This economic reality provides an additional security layer beyond cryptographic guarantees.
AI learns from human-written papers. That means it also inherits our bad habits.
The most common one in academic writing: when you're not sure about something, you cover it with language. "This is obvious" or "it follows that." No proof. No explanation.
AI is doing the same thing. Confident hand-waving at the exact step where rigor matters most.
If AI is trained on human shortcuts, how does it learn to do better than us?
Our 10.000x reduction in BitVM proof verification transforms three critical dimensions:
1/ Speed: Engineering cycles accelerate from months to weeks
2/ Cost: Operating expenses drop from $14,000 to $37 per transaction
3/ Sovereignty: What was technically possible but economically impractical becomes viable for everyday use