{
  "episodeId": "SLP113",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "dhruv_bansal": {
      "name": "Dhruv Bansal",
      "role": "guest",
      "tag": "DHRUV"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.83,
      "text": "Hi and welcome to the Stephan Livera podcast focused on Bitcoin and Austrian economics. Today, for episode one hundred and thirteen, we are speaking with the co-founder and C-SO of Unchained Capital, Dhruv Bansal. But first, let me introduce the sponsors of the show. So first up, it's Kraken, one of the world's longest standing Bitcoin exchanges. A seriously impressive exchange. They're known for a really, really strong focus on security, trying to protect their customers. They offer a high quality platform with some of the best liquidity available. They've got high trading volume and low fees, with no minimum or hidden fees. Kraken have twenty four seven support, and on the institutional and business solution side, they're providing best in class accounting, reconciliation, and reporting services for cryptocurrency hedge funds, asset asset managers and fund administrators. Kraken have an OTC desk for large block trades. They offer five fiat currencies and also offer margin and futures trading. To learn more and sign up, go to kraken dot com, there's a link in the show notes. My other sponsor is Unchained Capital. So just a quick overview on some of their products. They offer a two of three keys multi-signature vault product. It's managed through a web interface with a Trezor or Ledger wallet, and Unchained would hold the third key. In that scenario, they also offer Bitcoin collateralized loans, offering the possibility of getting USD liquidity without selling bitcoins. So while that loan is outstanding, it's stored in collaborative custody. So if you wanna learn more and sign up, go to unchaineddashcapital dot com. So today, Dhruv Bansal, the co-founder and CISO of Unchained Capital, rejoins me to talk about some different things that Unchained Capital are doing in relation to multi-signature and Shamir's Secret Sharing with some open-source contributions. Solutions, codenamed as Hermit and Caravan. So also just a quick note with the Bitcoin Custody series, I've had to reschedule some of the interviews, so just beware that this series will be dragging out a little bit, but I'll have plenty of normal episodes coming interspersed in with some of the Bitcoin Custody series interviews. I really enjoyed chatting with Dhruv, he's got a lot of intelligent perspectives to share, and here is the interview. Dhruv, welcome back to the show. Thank you, Stefan. So, yeah, I know you guys are doing a lot of work with, open source multi-signature, Bitcoin custody. There's all these different pieces that are interrelated here, but maybe it would be best to just start with a bit of, discussion around collaborative custody and what you guys are doing with Unchained Vault, and then maybe that can be the baseline for the listeners to understand what's going on here, what are we talking about? did you wanna just give a quick overview on what the Unchained Vault product is and how it works for the c- for the listeners?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "03:06",
      "start": 185.72,
      "text": "Yeah, absolutely. I think of Unchained Capital as a technology company that's delivering financial services. It means we do a little bit of both. and we started out, giving loans, so Bitcoin backed collateralized loans. in order to do that, we chose to deliver those services via some technology which was at the time a little bit newer and is now Coming in to, I think, mainstream a lot more, and that is multisig cold storage. and so we always had this technology backing our loan products, and earlier this year, we launched a dedicated vault product. I still think of it as a financial service ultimately, we're working with people's money, to help keep it safe and to bring it adjacent to the other services like loans and others that we're gonna plan in the future. But the core of the way we provide all these services still remains multisigature cold storage, and that's what we call collaborative. custody, which we think goes a little bit beyond just multisig and just cold storage, which already are pretty powerful tools to achieve security, and recognizes that the way that we do security is collaborative. That's true in our physical universe, our physical security relies on collaboration with our friends, neighbors, government, employees, in our neighborhoods, and it's the same online, and it's the same about with digital information. If we act collaboratively with each other and, let's say, in Bitcoin Bitcoin, that means using multisig, passing out keys to different parties that represent different interests in a given financial product or instrument, a vault, a loan, we can create some really interesting and compelling structures in which social security, like the, the, the security we have as individuals in society who know each other, can be used to increase our Bitcoin security. That's really, really powerful, 'cause remember, Bitcoin has no idea who we actually are. It only cares about public and private keys, and if we're overly reliant on ourselves or any one person or entity We lose some of the benefits of collaborating and acting as checks on each other. So, and, and what's really nice is that because Bitcoin is very forward-thinking, all this stuff is built in from the beginning, like the ability to have multiple keys and to build these custom, custodial arrangements is totally possible, it's just challenging. And where Unchained kinda comes in is that software layer, that professional company to help our customers achieve multisig in the way that they want, whether that's collaborating with us, collaborating with each other or combination of both."
    },
    {
      "speaker": "stephan",
      "time": "05:28",
      "start": 328.19,
      "text": "Excellent. And let's just outline for the listeners the difference between if they are an individual or if they are an institution. So just, I guess, talking through what it looks like, if I'm, individual, I come to Unchained Dash Capital and I sign up, I've got, say, one Trezor and one Ledger hardware wallet, and the general setup there would be I hold two of the three keys and Unchained holds the third key in that setup, and then in the- Institution case, it's more like the institution would hold one of the hardware keys, another third party would hold the second key, and then Unchained holds the third key. So can you just, elaborate on that for us and the different setup? Yeah,"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "06:12",
      "start": 372.26,
      "text": "that's a great example of the kind of flexibility that I was talking about. we're not a big believer here at Unchained that every single customer looks the same. People have different security needs, businesses and individuals have different security needs, different businesses and different individuals in each group have different- different needs from each other, and so we offer a lot of flexibility with how we, allow our customers to consume these services. the difference that you're alluding to is one of the, the two main flavors of our vault product. The first one you described, in which the customer has two out of the three keys which are required to move funds from the vault is what we call our client-controlled model, and the second model in which there are three different parties, a customer, Unchained, and an independent third-party key agent, each- Which of whom has one of the three keys required in this still two out of three arrangement, that's what we call multi-institution. and definitely there is a pattern where individuals tend to prefer the client-controlled model, as individuals, they're already in supreme authority over their Bitcoin, they don't wanna give that up when they work with a partner like us, institutions may be managing other people's Bitcoin, they may not be comfortable for very many reasons with having the same kind of control and authority that an individual individual would demand. And so these models are designed, not necessarily for businesses and individuals. I think we do have some individuals who like the multi-institution model, that's an interesting way to deal with issues like inheritance, and retirement planning. we do have businesses that want to use the customer-controlled model, because they are capable and willing to take on that risk and, and ownership. but very much these models are designed for, do you wanna have all the keys, or do you wanna have sufficient keys to- Spend on your own, or do you want to prevent yourself from doing that? there are people who want both, and sometimes the same person wants both in different contexts in their life or in their business. So yeah, that's one of the first ways that we offer to customize this experience. we also have some more advanced features that we're prototyping with some early customers, especially those who are interested in more group settings to be able to share keys with each other in various interesting ways. So an example might be, a husband and wife or Two partners, both have a key each, and they're able to independently sign up at Unchain Capital, each get their own account, each upload their own key, and then they're able to find each other on the platform and connect and say, \"Um, will you essentially be each other's-- they'll be each other's key agents? So they're gonna nominate each other to have some control together, collaboratively over the same vault, and then they'll build out a two of three vault with us, but they'll each have one of the keys.\" That's a pretty interesting structure, and Logs of that in the business context. So whether you pick the multi-institution model or whether you pick the customer-controlled model, you have some interesting ways to further change on your end, who actually holds these keys. remember, keys can be duplicated, keys can be split up. There's, we'll talk about it, I think, a little bit later in this conversation with Hermit and Slip thirty-nine, but there's a lot of interesting patterns that people adopt with keys, and our aim is to enable that, not prevent that from happening, while at the same time creating kind of a Shared contacts for all the communication and all the collaboration, that's really what Unchained does best."
    },
    {
      "speaker": "stephan",
      "time": "09:33",
      "start": 572.62,
      "text": "Excellent. And I think another point that listeners would want to understand is just this point around authentication, because obviously we're living in this world now with deepfakes and all this different stuff, and I guess the listener might be thinking, okay, if I sign up with Unchained, how does Unchained verify that I truly want them to cosign on this? transaction, or in the institutional model case, what's the typical way it would work if, let's say, I want to put, use the institutional model, right? So I would hold one of the three keys and another third party key agent, and then unchained, how would they authenticate or verify that this is truly who I want to spend to, for example, and it's not an attacker trying to bluff as me, for example?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "10:24",
      "start": 624.47,
      "text": "I think you've cut right to the heart of the matter there, right? And as I said earlier, Bitcoin doesn't know who we are, it only knows about our keys. And as long as those keys show up in the right transaction, the network will take it, it's valid. So a really important question becomes the \"who? \" Who is this person and what is their actual intent? So we think about it as the core issue here is identity and intent verification. I think an important thing to realize about identity is that identity isn't something in many ways that we get to decide. I'll come back to this theme. Identity is something that exists whether we ha- we realize Or not, I'm always gonna be Dhruv Bansal, even if I forget that fact about myself. our identity comes from the social context in which we're embedded in a lot of ways. I'll come back to that as we talk about KYC and some of the other issues, around identity management in financial services, but here we're really talking about the verification of a known identity. So it really depends on how you-- what you mean, by an identity. Some websites which are designed around automation say that identity is your user account. That's not sufficient for us, right? There's lots of ways to get into somebody's user account just by stealing a password, by hacking their email. we like to go, we like to at least have things like two-factor authentication and have several layers to protect user accounts. But even if someone were to get through all those layers, that shouldn't be sufficient for us to feel like that's really who this person is. with that said, we start to run into privacy issues. we want to go further than merely using the existence of an account on our site as sufficient verification, Into a channel of communication that they don't want to use. So for example, we offer, we can text you and call you, we, that's a minimum that we would like to be able to do, it's part of the reason we collect phone numbers on our accounts, signup pages, so that we can be able to reach out to you, email of course as well. ideally, we'd like customers to video themselves saying what they would like to be done. We have a program, our verification video program on our site, once you've signed up, you can opt"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "12:27",
      "start": 746.87,
      "text": "identity, saying, \"You know, this is the Revansult, this is today's date, using this is my real image and voice, and please use this as a reference when I make further recordings like this.\" And then later on, when you wanna spend funds from your- Vault, you can optionally set it up such that, such a video would be required before Unchained would ever countersign with you. again, you get to customize what level or percentage of the vault's asset that will trigger on, and you get to, in that moment, be recorded, and we will, as your partners in this, as human beings who are collaborating with you, be able to use our minds, not software, to evaluate whether these two videos really are the same person. That's a very strong indicator of identity. Now, I think things like Deep fakes and video that is so-- that is fake, but is so close to being real that it fools people, these are real threats. They're, they are happening, they're getting easier and easier. and in that sense, I don't wanna present anything I'm saying today as a final solution, especially for listeners who might be hearing this episode months or years from now. Security is a fast-moving space, especially, in the Bitcoin area. And so today, I think the risk of fake videos is somewhat low, realistic. Stephan, we got a, a little siren here outside, I'm just"
    },
    {
      "speaker": "stephan",
      "time": "13:43",
      "start": 822.82,
      "text": "holding. that's fine. Yeah, so you were saying, basically the risk of deepfakes right now is low, but as you're saying, things could change in the years to come."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "13:53",
      "start": 833.11,
      "text": "Yeah, exactly. Now, I think ultimately, as long as we are ahead and you are ahead as a user of most people out there, that's a really good start. For certain individuals, some of whom work with us already, who believe they are larger targets, there are further things that I won't, I won't, for obvious reasons, get into all the details of that, but a simple example is customers who might say, \"Look, I never, ever will reach out to you remotely. Like, if I need you to sign, I will come to your office, and we-- I'm willing to wait the days that would be required to arrange something like that, and I won't, I won't go back on this, and you can, you know, record that information.\" And so we have, since we're, you know, a, a company with resources and the eag Gain, customer quests like that. I think, companies which are intending to serve millions of customers at a relatively smaller per customer value point have difficulty extending that level of care and support to their customers, but in our case, it's, we're willing to do whatever it takes to make customers feel comfortable, and they're the ones who ultimately understand their own spending habits the best, and frankly, this is really good customer research for us. It helps us understand the directions we need to develop our product in. So I, I, I guess I'm trying to say there's no permanent answer to this question of how do we verify identity, because it's an arms race and it always changes, and there's no one size fits all answer. It's gonna depend on how much of your own privacy you're comfortable, exchanging for better verification, and exactly on the threats that you perceive you suffer from."
    },
    {
      "speaker": "stephan",
      "time": "15:28",
      "start": 928.42,
      "text": "An insightful answer. And I think the other point that listeners might wanna know here is just that when you sign in to the website, you can still have things like it would mean if- Someone were to try and hack you or attack you, they would still need to have your username, they'd still need to get past the two-factor authentication as well, which is the phone, like authenticator app rather than like an SMS one."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "15:50",
      "start": 949.6,
      "text": "so,"
    },
    {
      "speaker": "stephan",
      "time": "15:50",
      "start": 950.06,
      "text": "so these are components of it as well. and I think it might also be interesting now just to talk about what some of the benefits are of having that collaborative custody structure. So one example that I know of is that if you put your bitcoins into collateral, you can see them on the blockchain, so to speak. So you, you know they're there."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "16:10",
      "start": 969.97,
      "text": "Yeah, that's exactly right. There's, a really nice way to structure loans, and indeed the very first product we launched into the market was the, the idea of using a multisig address that sits on the blockchain and which the balance never moves as a form of very visible and very transparent collateral. with multi-- with a multi-institution collaborative custody where our customers are actually holding a key that is part of the multisig that protects those funds, they can even go further we share redeem scripts and bit thirty two paths for all keys, that's a little bit of technical, jargon, but it helps customers be able to verify in a very, very direct and strong sense, cryptographically, that they are still able to spend the funds that are in that address. Now, of course, they can't do it in-- like, wholly on their own, they're just one of the three keys, when they're participating in a loan. But most customers are doing, in a vault context or have in sufficient keys to do this on their own Which Unchained sort of gets a benefit that oftentimes we're only protecting one key, especially in a vault context, and even in a multi-institution context with collateral and loans, we're only ever one key in that quorum. And so what that means is, not only does the customer have to go through all these layers of protecting themselves in their own account, but they have their own keys. That is the fundamental protection that any customer has against hacks. This other issue really just shows up when the customer has already been hacked, an attacker has already gotten one of their keys at least, and then has to go further and convince Unchained to sign, falsely."
    },
    {
      "speaker": "stephan",
      "time": "17:45",
      "start": 1064.65,
      "text": "Gotcha. Yeah. And, let's talk a little bit now about, You, trying to open source or you are open sourcing the multi-signature solution, and there's a UI for that. Can you just give us some background on that?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "18:00",
      "start": 1079.88,
      "text": "Yeah, absolutely. the project that we've been working on is internally has been codenamed Caravan. that's gonna be the name of the open-source, web application that we'll be releasing, I hope here in just a few weeks. I just gave a demo of it last week here in Austin at a local Bitcoin meetup. It is exactly as you describe it. You can think of"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "18:20",
      "start": 1099.79,
      "text": "You can already do it on Chain Capital. It's a little bit more flexible than our commercial application. It's designed to be a little bit more broad reaching. it's also a little harder to use. There's a lot more state management that you have to do because you're doing everything on your own without any company or other entity helping you necessarily. why did we put this out there? Partly because we love open source and we think the best and most secure code bases in the world are open source code bases and As much as we love, and have, are proud of our own closed source code base, and as much as we've had it audited and reviewed by experts, we think the best possible thing to do is to get the way that we do transaction authoring, signatures, hardware wallet interactions out there into the open. one, it gives us a chance to show off some of our learnings. We've been doing this stuff a lot longer than a lot of the other people in the space, and we've learned a lot about the right ways you need to wrap hardware wallet UIs, the"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "19:19",
      "start": 1158.85,
      "text": "Getting actual stuff off the ground, in Bitcoin and especially in multisig, and cold storage. And so we get to show that off, we get to get feedback from the community, around our solutions. Hopefully we get some buy-in, from other developers who say, \"Hey, the libraries that are packaged into Caravan, which are of course open source, are really cool. I wanna use these.\" If we can get other people to use this stuff, that helps us tremendously. It means that there are more people, using the same code that we're using. Bugs, more users means more attention from hardware wallet manufacturers when we ask for bugs to be fixed. so for us, this is a way of getting a lot of stuff that was happening privately harder to see by, for the customer and for our partners and not creating as much of an impact since it was just being run by us, getting it out there into the open. That's the num-- one of the big internal benefits. I think for externally, if you, if you're, you know, that was a sort of a benefit to Unchained, but more broadly to One who wants to be doing multi-sig, but let's say you don't wanna work with a company like Unchained or, or any, other entity, you kinda wanna do this privately on your own and you wanna do it with open source, this is, I think, the way to do it. There of course are existing solutions for open source multi-sig, cold storage out there, Electrum is chief amongst them and probably a great choice, but Electrum does a lot. A lot of things, and it's an older piece of software, and it-- you can see that in the way it's architected. You can think of Caravan as sort of a next generation, past Electrum, learned a lot from Electrum, learned a lot from other stuff that came before, and really simple and focused on just multisig. It's not Ethereum, it's not any other currency, it's just Bitcoin. It's not trying to be the best payments engine, it's not trying to be a node, it's not trying to be a hardware wallet, it's to test and to build on and to serve as an environment where Unchain can kind of put our best foot forward and hopefully other folks can start to use it so this whole thing scales. standardization is a big hope of ours and something I'd like to talk about a little bit more in this conversation. but multisig really suffers today because there aren't good standards or well-followed or well-understood standards. By creating these kinds of open-source example applications that real people can use and solve real problems, we're hoping to cast more light on the lack of those standards. And start conversations with other developers and other companies in the space about how to standardize."
    },
    {
      "speaker": "stephan",
      "time": "21:47",
      "start": 1307.34,
      "text": "Great. And, I think it might be good to now just for the sake of understanding for the listeners, so I guess just for comparative sake, so a listener who wants to, quote unquote, roll their own right now, they might be doing something like Bitcoin Core full node, and then on top of that, they might be running some sort of one form of an Electrum server, being either Electrum Personal Server, Electrum X, or Electrum Rust server and then back on their laptop or their desktop computer they would have the Electrum client and then on the Electrum client there's a multi-signature UI and so on and they would, you know, they would, put it, plug in the treasurers and ledgers and so on and basically that's the stack. Can you outline what that would look like with Caravan?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "22:32",
      "start": 1352.22,
      "text": "Yeah, there, there's a tripartite structure to that stack, that might not be apparent to all listeners. A-and I think the way that I conceptualize it is that there's three things there. The first is the consensus, like what is the state of the network, what are the addresses that exist, what is the current balance or status of this UTXO, that's coming from Bitcoin D, or rather, on some level, you want that to come from Bitcoin D, because Bitcoin D has already solved the problem of how do you create trustless consensus. It's called That's your full node. if you don't wanna run a full node, you don't have to, you should be able to get that consensus from a different source, maybe a block explorer. You're choosing to trust that block explorer, but that might be easier or better for you than trying to run your own Bitcoin D node, which just might not be possible for you. So there's a dimension here of consensus, and you have choices. There's a second dimension, which is keys. Where's the actual private key stored when I interact with my Bitcoin? And sometimes the answer is it's just on my computer, because I'm running a software wallet. Electrum allows you to do that. That's not the safest answer, especially if that computer is the same computer that is trying to achieve consensus and is connected to the network. that's the easiest choice, and that's where Bitcoin D started on day one, but that's not the safest choice. things like hardware wallets try to be another option for you on the key side here, so you can keep your key just in the hardware wallet, and it solves just that one problem, and you have there are other tools, Hermit is one that we've made that, that focuses on that part of the problem. And then there's a third category, right? So the first two are consensus and keys, the third category is this idea of what I would call a transaction planner. Right? The thing that knows how to talk to the blockchain, look at consensus, find balances, author transactions, construct signature requests, combine signatures from keys, and push it back out into the world of consensus. Now Having those three roles of consensus keys and planner be separate things feels more complicated, but it's also more modular and that creates its own benefits. Software like Electrum and Bitcoin D implement all three of those, of all three of those functionalities really. I'm one of the believers that the way that Bitcoin D should evolve going forward is it should stop being a wallet, it should stop being a transaction planner, it should really focus on the consensus part. That might be controversial, that's just my personal opinion. and I love the idea of dedicated key devices. Hardware wallets, cold cards, trezers, like these are great examples of things that do one thing really, really well, they hold keys. There hasn't really been a good example of a dedicated planner software. I mean, there are some developers know about them, but users, tend to be focused on software which does, more than one of these three things at once. And Electrum is probably the chief example of such software. It can be its own source of con- consensus, you can use an Electrum server, it can hold keys, 'cause you can have a software That's bad. That's super convenient, and that's clearly the first thing that happened historically as software got laid on this space. But that second generation looks at this and says, \"Like, that's really monolithic. I really worry about the architecture there. I wanna draw some clean lines and separate out those responsibilities and give my users the choice of which key they plug in, or which transaction planner they plug in, or which source of consensus they plug in.\" So with that framework, I think of Caravan, the project that we are about to release, as very much a transaction planner. You can plug Your own Bitcoin D node to it, or you can have it just automatically go talk to Blockstream. You can plug in your hardware wallets, you can plug in other sources of keys, or you can just paste in directly, signature data and other kinds of cryptographic, representations. So it's really not very opinionated around consensus and keys. It's just trying to solve that one problem of how do we really make an elegant, simple to use, secure transaction planner, especially one focused on multi-sig where there isn't a lot of support from other wallets."
    },
    {
      "speaker": "stephan",
      "time": "26:23",
      "start": 1582.65,
      "text": "Excellent. And actually, can you Standards earlier, and obviously a big key one in this case is PSBT, Partially Signed Bitcoin Transaction. So can you, touch on your thoughts there around, is Caravan using PSBT and, just any other thoughts around, some of the open standards that you're trying to either use or create?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "26:44",
      "start": 1604.44,
      "text": "Yeah, I think PSBT is a great example of a great standard. there are some issues with it that I can cite that I don't think are, are, are sometimes hold it back a little bit, but I think it's a, otherwise a really well-designed standard, and I, I, I hope to see it achieve greater adoption. We're pushing towards it in all our tools, but we don't support it almost anywhere at the moment. So Caravan's not speak PSBT at the moment, we'd like to get it to. I actually think one of the first areas"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "27:14",
      "start": 1633.98,
      "text": "Supports Trezors, just like our own Unchain Capital commercial platform, Caravan supports Trezors, ledgers, Hermit, which is an open source, sharding wallet that Unchain's been working on, and it supports just raw signatures, as I mentioned. the number one thing we'd like to probably add to it is Coldcard, that's where we receive the num-most requests from customers asking for support on that wallet. and Coldcard, I think as some of the audience may know, it uses PSBT"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "27:44",
      "start": 1664.02,
      "text": "To integrate Coldcard into this, open source application, that'll be our first really area where we'll get to move over time the whole application to just use PSBT as an internal standard and then convert to whatever it needs to for non-PSBT speaking wallets like Trezor or Ledger or others. but right now the PSBT standard itself is somewhat new, and so that's a great example of where, you know, we hope to take the lead through Caravan, and other software and really push some of these standards. Another great example would be Bip32 paths. There Consistency. you can, for listeners that may be less familiar, you can think of BIP32 paths almost as like, well, what file, what directory on your computer do you wanna store this in? It's always one of those questions where like, there's really no wrong answer, like any directory will do, but the more organized you are about it, the more standards that emerge on how to organize the directories on your computer, probably the better you'll, off you'll be long term. Same idea here, that in theory any BIP32 path works, but it"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "28:44",
      "start": 1724.0,
      "text": "For example, has some very distinct and different conventions around multi-signature BIP thirty-two paths than are emerging in more recent wallets and more recent standards. So part of what Caravan tries to do is, first of all, act as a debugging tool and let you put in any crazy standard you like just to see what's going on, to explore. because I do have historical experiences working with customers and weird address formats or weird tools, migrating back and forth between things, it's nice to have a tool that's not opinionated. But at the same time, Caravan does understand standards, Exactly the right bit of thirty-two path you should be using here, and, it kind of forced you into a certain pattern. So again, it's meant to serve as an example, I think, for the community of what we think are the right standards around multisig, and frankly, also spur our wallet providers. Like, I think what's been really nice recently is having something like Coldcard show up and take the lead on something like PSPT, that's usually something I would expect to see from, like, the folks at Satoshi Labs or Trezor, right? space and push on this cool new feature that's driving standardization and seeing other folks have to respond to that. So I'm all for new keys and new players, especially when they drive standardization, that helps everybody."
    },
    {
      "speaker": "stephan",
      "time": "29:55",
      "start": 1794.99,
      "text": "That's great. so I guess for the listener, if they're thinking, okay, how do I use Caravan? is it basically just a software client with a GUI that they would use for, you know, Windows, Linux or Mac?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "30:07",
      "start": 1806.86,
      "text": "It's just a web-- It's, it's actually, it's actually a web application. So you can-- We'll We host on GitHub, but you can also just download it yourself and just run it in your own browser. we call Caravan the, the stateless multi-sig wallet. That's a little bit a pun on the idea of it, it has no internal state, that it doesn't store any files or on your computer. every time you reload the page, it's completely blank and fresh, like, like a calculator almost. you have to insert the state, you have to bring your keys, you have to bring your source of consensus. And so in that way, it's"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "30:44",
      "start": 1844.08,
      "text": "There is maximum compatibility across platforms just to make it as easy as possible for folks to plug into."
    },
    {
      "speaker": "stephan",
      "time": "30:50",
      "start": 1850.49,
      "text": "Yeah. And then if it's a web app, can you help me understand how does it connect with, say, my Bitcoin Core?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "30:57",
      "start": 1856.55,
      "text": "Right. actually just through the internet. you're able to talk to local devices that are, a web browser is able to talk to devices on the local computer that it's running on. That's in fact how your Trezor works. That behind the scenes, there's a piece of software called the Trezor Bridge. Which your browser winds up talking to, and then that winds up talking directly to your trezor. There are of course other ways to achieve stuff like this, but that's just an example of one. Similarly, your browser can just talk to your Bitcoin D node. It just sends a web request to it, and gets back an answer. Now, of course, you have to do some setup, and this is what I mean about statelessness. you have to ensure that first of all, you have a Bitcoin D node that is running at the URL that you input into Caravan to reach caught up with the network, and in particular, since the-- if you're using Caravan, you're probably doing multisig, that's not native in the Bitcoin D wallet. The Bitcoin D wallet isn't gonna really know about the addresses that are in your multisig wallet unless you actually import them. So you have to import those addresses manually yourself in a Bitcoin D, and then finally you have a primed and ready source of consensus. This is actually a good example of why sometimes allowing a little bit of trust and using a company or a provider like a block explorer or like a multisig provider like It saves you a lot of hassle. that doesn't always mean that you shouldn't take the hassle, sometimes for certain individuals, it's worth it to manage all this stuff yourself. for many others, it's just not, and the part that really matters is the keys. So that's kind of where Unchained's current product really pitches itself. But you can see us trying really hard to get out as much open source software as we can to make our own product better, but also to give folks who aren't ever gonna work with us because we're a private company and they value anonymity"
    },
    {
      "speaker": "stephan",
      "time": "32:45",
      "start": 1964.58,
      "text": "Great. And, while we're on the topic of web interface, it might also be good to discuss, now this is a risk again, but again, there are security trade-offs in however, whichever way you choose to, set up your software, but, there is a risk of, malicious extensions. Did you wanna just comment a little bit around, if, if the user has a malicious browser extension that may-- I guess there are probably two main risks, one, probably one key one One is around replacement of an address, so the user goes to the web interface and they think, \"Okay, I want to deposit bitcoins into my multisig vault,\" but then the malicious, hacker has put in a, you know, a, an extension that replaces the address with the hacker's address. Can you just outline some of your thoughts around that and, you know, what are some defenses or mitigations against that?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "33:37",
      "start": 2017.37,
      "text": "Yeah, I mean, that's terrifying, right? The idea of software that you use every single day being fundamentally insecure, right? It's terrifying. and every programmer knows that that's actually the reality of all computers. and so on some level, I don't wanna make light of this issue, like it is absolutely possible to d- to have downloaded a browser extension that corrupts your browser in various ways, either generically or specifically around Bitcoin or even specifically around Unchained Capital. It's absolutely possible to engineer such exploits. Now, you as a user, of course, have to be tricked into installing those kinds of extensions. So I think one of the first protections is just to be, a little cynical of the kinds of software you download and run and make sure it's trusted by you and, and people that you trust to, to, to determine that, before you run it. That's one of the first mitigations. I think another really simple mitigation is, given that it's a browser, it's really easy to start a new browser, like a new browser tab or a new browser window or a Or to have different profiles in your browser, depending on the browser that you use, that like, here's your work and p- here's your kind of play profile, here's your work profile, and here's your super secure financial or Bitcoin kind of profile, and that you just don't cross traffic or sites across those or extensions. There's a lot of techniques to mitigate and make browsers more secure. but I think the real problem here is just computers. It's, it's, browsers are just an example of, of computers being insecure and, and browser extensions are just one path by which you is in poor ways. I don't know if you saw the news, but like just this week, there was a hilarious example of, well, I shouldn't say hilarious, 'cause I know, I'm sure people suffered through this, but I just, I, I enjoyed the vector by which this, exploit was executed. I think it's, a, a, a, a, a bad Fortnite mod that if you download this Fortnite mod and help, it kind of helps you auto-aim and cheat a little bit and like be better at the game relative"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "35:37",
      "start": 2137.07,
      "text": "Clipboard and analyzed it for things you copied and pasted onto there, whether you got them from a browser, whether you got them from a terminal window, whether you got them from a completely isolated application or an email, whatever, and would analyze that for Bitcoin addresses and live replace them, right? Or, or be able to do other things on your computer. So there's no browser that's really involved in that exploit. It's just, again, Fortnite, the game, I'm not trying to throw shade on Fortnite by any means, there's lots of, there's lots of open doors PC, that's true, on the Mac, that's true, on Linux, probably more true on PC if we're being honest, I mean, Windows, it's true on mobile devices. There are horrific exploits and ways to fish people through their mobile, devices that are really terrifying. I don't mean to paint a grim picture here for people, like it is possible to feel relatively comfortable when you're computing if you take some precautions, things like, again, only installing trusted software, keeping your operating system up to date, don't use pirated Don't get software from locations that are, are shady. be minimalistic. Do you really need that little toolbar if that you didn't pay for and you wonder how they make money? you know, be a little cynical about what you install. But all of this really avoids the, I think, main issue. Like, we know computers are insecure. Satoshi knew that computers were insecure. That's why Bitcoin isn't like, i-is so different than traditional banking and software is that it deeply incorporates cryptography into its definition and toolset for Security. So instead of overly worrying about the browser or the operating system or the hardware that your computer's running on, I like to really think about like something I maybe first read years ago in the Trezor security model, like how can you conduct, secure transaction on a computer that you even know is compromised? Let's say you know there is a key locker and a bunch of viruses on there, like how might you still achieve some form of security? And the answer is always isolate the thing that you want to protect and put it on a really Really simple system that obeys a more limited set of rules. So a hardware wallet is a great example of that, an air-gapped wallet, that operates via cameras and QR codes, for example, like Hermit or many others is an example of that. there are a lot of techniques you can use to fundamentally move keys off of these fundamentally insecure devices like computers. And then, this is the final piece of that journey, you have to create primitives and, and APIs and ways of communication between the insecure system on the computer And the secure system on the hardware wallet or the offline wallet that gives the user confidence that whatever they're seeing on their computer is actually the truth in the hardware wallet, and they haven't actually been exploited on the computer or on the mobile phone. Now, I will say Trezor really and Coldcard seem to be at the forefront of this. Trezor, for example, allows you some great features when you're in a single signature world to verify addresses right on your device, to verify all this information in a way that you know it doesn't really matter what the computer is showing you if you Trust your device's screen. that's a very powerful ability that hardware wallets give you. and Trezor does a great job, I think, with single signature. It does a poor job with multi-signature. It's frustratingly difficult to get the Trezor to recognize a multi-signature address and display that. It is possible, but it's not possible from a browser for whatever reasons. Coldcard is another wallet that's really making some strides in this space and really creating primitives that represent multi-signature addresses and not doing it in sort of an ad-hoc way that Seems to do it, but doing it in a more ground up way. then you have, I think, hardware wallets like Ledger that are a little bit further behind on this. They don't understand multisig, they don't understand like the kind of pr- they don't give you the same kind of protections in that, in this world that they, or frankly, I think even in the single signature world. So I think the real solution here is that people who make keys, hardware wallet providers, need to, as Trezor and Coldcard have done, need to provide"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "39:37",
      "start": 2377.15,
      "text": "Help assert confidently to the users of those key devices that everything is copacetic and working as intended. And again, they're, they're, they do do that, they just maybe don't do it as quickly or as close to the cutting edge as we'd like for them to, and that's part of our hope again with Caravan and a lot of the open source stuff that we're releasing is that, the more people that are talking about this, Michael Flaxman on your show has been one, Justin Moon here in Austin is another one that talks about it, there's a Of, folks in the multisig space increasingly, if we're all talking about these issues and pushing on Trezor and Coldcard and Ledger to do a better job giving us the tools we need so that we don't have to have users trust browsers or operating systems or mobile phones, that's a win for everybody, and I think that's where the conversation needs to head."
    },
    {
      "speaker": "stephan",
      "time": "40:24",
      "start": 2424.18,
      "text": "Fantastic, yeah, there's a lot of, great insight there. I also wanted to ask around seed backups. So let's say I'm a customer and I'm using, two or three setup with Unchained. so for example, say Casa, they talk about this idea of going seedless, right? And the idea is that you've got enough redundancy across the devices. What, if somebody's using an Unchained setup using two or three, might they keep a CryptoSteel and or some similar kind of product? To backup the seed words for that underlying device, whether that's a cold card or a Trezor or a ledger, and then separate from the hardware device for that key. Do you have any thoughts around that or any suggestions for the listeners?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "41:07",
      "start": 2467.33,
      "text": "Yeah, I certainly recommend that users take steps to think about how they secure their wallet words, their seed phrase. things like, CryptoSteel or non-paper based methods for storing it that will survive things like fires or other kinds of disasters, floods. It's, that's a- It's a really cool thing to think about, and if you are someone who's storing your seed words in a home or in a non-professional business location where it's not your, it's, it's your job to protect them in the case of disaster, not somebody else's, maybe that's a worthwhile thing to consider doing. I also think it's worthwhile to split up your seed phrase. That's kind of a poor man's form of Shamir sharding, if you will. we call it scrapping at Unchained, so it's not a Shamir share, it Those of you who have Trezors may have noticed that the, the little booklet you get to store your seed words on, is folded. It has two very equal halves. Why not take a pair of scissors and cut it in half and now just store it in two different locations? Is this a perfect solution? No. For a variety of reasons, this is imperfect. each half doesn't have the exact same amount of randomness as the other, so there's one greater and lesser sh- scrap that's kind of annoying. if someone gets one of your scraps, they know"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "42:24",
      "start": 2544.0,
      "text": "For, for you to feel comfortable, like you, you should, you should b- feel like they can break the other twelve fairly quickly. So maybe you split it up into groups of four, okay? you can kinda see how this isn't-- it, it's, it's, the harder you do it, the more you do it, the probably better it is, but the more complex it becomes. so something we recommend is the simplest thing you can do that we think is a net win is just cut it in half and store it in two different locations,"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "42:50",
      "start": 2570.16,
      "text": "and Plain text for anybody that were to stumble across them or to exfiltrate them. now with that said, there is a better approach, right? And that better approach is called Shamir sharing. That you, I think not everybody may know this, so it's worth saying explicitly, if you took your wallet phrase and you split it into two, you would clearly need both of those scraps, so two of two, in order to recover the phrase. But if you had one of them, as I mentioned earlier, you would still have partial information about the key and you might be able"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "43:24",
      "start": 2604.1,
      "text": "With Shamir shares, let's say you did the same conceptual thing and you built, two of two Shamir shares, and you have to have both Shamir shares in order to be able to access the seed, it is absolutely true that if you find one of the shares, you actually know nothing. You've learned no additional information about the key, and you can't suddenly just maybe, you know, brute force your way into it. That's a very powerful difference that's been traditionally challenging to achieve for non-techny folks, folks who aren't programmers and comfortable running code. there are some things that are making it easier. chief among them, I think most recently is the push by Trezor and Satoshi Labs to put out a standard known as Slip thirty-nine, which is called hierarchical, I think of as hierarchical Shamir shares. So it's, what's cool about it is that it's a standard, which means it's something that we can build momentum around and hopefully get codified. there are already wallets that are supporting it. So Hermit, open source wallet that Unchain put out a little while ago, supports this. Hermit is a very, I would say it's a professional tool, it's not a consumer tool, but Trezor, which is very much designed for, you know, the normal people like myself and anybody listening to be able to"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "44:37",
      "start": 2677.41,
      "text": "39 as well. I think that might be already happening, in fact. So you can actually create Shamir shares directly out of a trezor, you don't necessarily need to use, a wallet word phrase. and just to make it really concrete for folks, a Shamir share can be defined in a lot of ways, but the way that Slope 39 does it, it's basically like a wallet word phrase. So instead of having one phrase of twenty-four words, and that's your master secret, you kind of wind up with, if you choose one, two of two, you wind up with forty-eight words. It's actually a different number, but you wind up with some larger number of words, and each of those is just like a wallet phrase, it's just a list of words. So they're very easy, and they're very ergonomic for those people who already understand wallet phrases. It's just an extension of that that has better cryptographic security, which makes it better for backup. Now, that word"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "45:28",
      "start": 2728.41,
      "text": "I personally think it is insane to run seedless. I personally have had Trezors fail on me during upgrade, and what is the solution? Reload them from their seeds with the new firmware. That works perfectly. It's frustrating to- Believe that you have a key in this treasure and actually have it, not be a key but access to a key. And so I think running without a seed phrase or throwing out your seed phrase because you believe you have sufficient other devices. I wouldn't feel comfortable doing that. the argument I think that is advanced sometimes by folks like us for doing that is seed phrases are complicated, I guess, and they can be lost, they're unencrypted, and maybe that's a, a hole. I think those are, those are fair statements. But I think- Sorry,"
    },
    {
      "speaker": "stephan",
      "time": "46:16",
      "start": 2775.57,
      "text": "just to add, I think the other one that might be good for you to respond on that is also around, having another thing to protect. To, yeah. yes, having, having"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "46:24",
      "start": 2783.51,
      "text": "yet one more thing to protect, you're right, you're right. yeah, so I'll come back to that point, but I'll say having those seed phrases, is really valuable, and things like Slip 39 make it so that, first of all, they might not necessarily be in plain text. That's actually one of the additions that Un Here to say that it's safer. It does now create this problem of more things to manage, I totally agree with that, but a little bit, by-- you've sort of already admitted that you need more things to manage by jumping up to three or five. if, for example, you really wanted to count the numbers here, at an unchained configuration, you have two out of three keys, so you have three separate keys. You as the customer have to protect two of those keys, and for each of those keys, you have a set of wallet words, so you're protecting"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "47:15",
      "start": 2834.95,
      "text": "that's not coincidentally the same number as three out of five with no seeds, except I think you have a lot of, I personally believe that's a, a, a better route, and that's why we've picked that route. I don't wanna cast aspersions by any means on the folks at Casa, they've done a lot of great thinking on this. this is what they believe is safer. I'm not gonna like push on it, and we don't really have enough data, I think, to decide long term about this. But I really like having seed"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "47:45",
      "start": 2864.71,
      "text": "it's easy to understand and describe, especially to a non-technical person, keep this piece of paper safe. That's, that's something that you can communicate, and they're very concrete. So for all those reasons, I really like having seed phrases. They do increase the number of things you have to protect, but that can give you some redundancy on its own."
    },
    {
      "speaker": "stephan",
      "time": "48:02",
      "start": 2881.64,
      "text": "Gotcha. so let's put, put that in with Hermit now. So Hermit is this open-source software, and it's more like a command line tool, as I've seen from the From the Unchained Capital YouTube, and did you wanna just touch on some of the comparisons? I know obviously it's not the same thing, multisig versus Shamir's Secret Sharing, but also, as I understand, with multisig, you are revealing certain things about the script type, the spending pathways. Did you wanna just comment on some of those, differences there?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "48:36",
      "start": 2916.42,
      "text": "Yeah, absolutely. Now, I think I'll, I'll preface this section by saying I don't think-- I think Hermit was designed for Unchained Capital and a small number of other companies. companies who are like Unchained Capital. I don't think Hermit is necessarily a great tool for individuals to use. I think native multisig, through like, just Caravan or Unchained or other providers is a better choice for the average person. and that's because Hermit is really focused on what is the best way for a group of people to protect one key. And that's an interesting problem, because it's very different than an individual protecting one key. Groups of people protecting a key have unique challenges beyond those that an individual protecting a key have. So an example would be communication. Like everything, if you're a hodler and you're super secure, and you got your whole plan, it's in your head, and you're cool with it, great. You don't have to talk to anybody. A company that wants to execute your same super secure plan has to communicate about it and coordinate about it, and that requires transmitting information over email. through other networks, how do we do that securely? So that's a challenge. Companies have, turnover. You know, you're not gonna fire yourself, presumably as a hodler, and you're not gonna move away from yourself, but companies have turnover. So how do you deal with turnover of trusted individuals? that's another issue. companies also have a huge amount of transactions typically relative to an individual. They're accessing their storage and their secure environment a lot more frequently, and there's this need for a rotation, right? Like, not the same responsible for signing transactions on behalf of a company, you need to be able to rotate, to, to make sure you have enough capacity and that your signing staff isn't, you know, stressed out and not doing things safely. these are unique problems. As much as I love hardware wallets, they're not great for companies because they're not designed to be used by multiple people at once. They're designed to be used by one person at once. So Hermit is really a solution that says, \"Look, I want a really secure wallet, I want it to be, command Hermit does that too. And then where Hermit is a little bit unique is it says, \"I want to be the kind of thing that multiple people at a company have to interact with at once. \" And that's part of the reason Hermit is complex to use, and CLIP-39 is a complex standard, and it's part of the reason I don't recommend it for the average user. But I think Hermit is really, really interesting for organizations like Unchain, which protect keys. So if you are doing cold storage, and, and by the way, Hermit, of course Many keys are involved in the multisig, but if you're a company that's doing cold storage and you're protecting funds, and you are a group of people having to protect one key or multiple keys using Slip thirty-nine and getting an air-gapped wallet that is designed for groups is potentially an interesting thing to do. So I, I recommend anybody listening, you don't have to be a huge company, by the way, maybe you're just a small team, you know, or an investment group or a family, and you're, I guess, technical enough to use the command"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "51:35",
      "start": 3094.74,
      "text": "It didn't harm it."
    },
    {
      "speaker": "stephan",
      "time": "51:36",
      "start": 3095.62,
      "text": "Got it. And let's talk through some of the scenarios where it might make sense. So presumably you would have to be careful because at the point that you reconstitute the seed, that's where you're vulnerable. So presumably it might be something like you need to move, spend from this setup and you're spending into a new setup that you've already created that is secure, let's say. and can we just talk through some of the scenarios where how, how it might- Be used. So for example, a, a quorum of senior executives in this company need to spend, but you need to set up differing, values to the seeds, as I, as I was from reading, the post, one, example in the blog post, and I'll put a link in the show notes for the listeners. But it, the blog post is sort of comparing this idea of, let's say, you've got a CEO and a CFO and some other team members, and the idea is is to represent that the CEO and the CFO are more senior, they might have been given two shares each out of the six or whatever. And then I think what you're getting at in that blog post is that with Hermit, you can set up almost like levels, so maybe the CEO's share is worth two, but they actually still only have one. set of, words to protect. So could you just elaborate a little bit on that setup?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "53:01",
      "start": 3180.86,
      "text": "Yeah, absolutely. So I think, you're absolutely right when you say the moment of vulnerability for any group is when they've reconstituted their key and they're about to use it. In general, that's the moment of vulnerability for any key, and it's the reason multisig is so attractive, is that that never happens necessarily simultaneously at the same location for a set of keys. You can stage the usage of your keys across time and space. of course, when you're Sharding, that's not possible. When you shard, you're breaking a key into pieces, and in order to use it, you have to bring at least some of those pieces back together in one location and one time. So the big worry of a company is that at that location, at that one moment in time, someone exfiltrates data about the key. Like with a hardware wallet or with other tools that are designed for one person to use, that's, that's pretty easy to achieve. how do you prevent that from occurring? So Hermit has one technique built in, which is sharding, as we've discussed, has been mostly a backup strategy, but can also be a strategy to create a little bit of adversarial, signing ceremonies. So what if you force it so that at any given moment, always three people minimally across the organization, or three representatives, or five people, however many you need to? It doesn't matter, whatever is appropriate for your organization, you can set up hermit and your shard configuration in such a way that that number is required in order to sign. And what that does is you can, depending on how you've arranged these groups of individuals, you can ensure that the right people are in the group so that everyone's kind of watching each other. and this becomes a very public ceremony, it becomes something that the team is taught how to do, and it becomes a ritual and a process that they can engage in. And crucially, it requires multiple people at the same time, so if someone wants to collude, they at least have to convince a few other people in what is potentially a rotating schedule that they can't even predict who will show up at a given moment to be their partner in unlocking this key. So the company gets to think a little more About its own employees. I mean, every company hopefully has trusted employees, but realistically, by removing the chances that an employee can act in a, in, in, in a poor way or by forcing them to have to collude in an unpredictable way, you make it much less likely that any kind of exploitation like that is going to occur. So that's the first comment. The second comment is, once you've decided that you want to have multiple employees be forced to be there at the same time in order to execute some kind of secure ritual, you now are fronted with, well, which employees? And where you inevitably will wind up is that some employees are more trusted than others, or some group members, if this isn't a company, if this is a family or an investment group or whatever it is, some people are going to be more trusted than others. And traditional Shamir sharing, one of n, two of five, whatever the m and n are here, is single level, that there is only one kind of shard, and the difference is how many shards there are and how many are required to spend. In a model like that, it's difficult, to, to, to model the idea that different people, different shard owners, are more or less trusted. What is unique about Slip thirty-nine and the reason we embedded it into Hermit, and the reason I think it's such a cool innovation, that Satoshi Labs and a whole bunch of put out is that it is multi-level, so you can create, essentially groups in which the shards are worth more. An example from the blog post is exactly what you described, where you might have, instead of, you know, having two of six or whatever, and then having the CEO and the CFO have a shard and passing out other shards to second level employees, you might make it so that the C-- either one of the CEO or the CFO has to sign, and that this other larger group of employees, it can be any one of them, so you get to distinguish between the level Levels of trust. Coming back to multisig, because this should start to sound maybe similar to folks who have talked, who have heard about the virtues of multisig and why that's important, this starts to sound like a lot of the kinds of things you can do with multisig, and that's absolutely true. On some level, you would prefer not to have to play this shell game of shards. You would prefer to just be able to use multisig directly. the problem with that is today practically, it is challenging to do multisig directly the way that you might like. Like, let's say"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "57:11",
      "start": 3431.47,
      "text": "You're really gonna have addresses with, an n of twenty multisig with some complex conditional logic in there. If so, your addresses are gonna get very expensive to spend from, you're not gonna be able to spend from them with traditional software, you're gonna need some custom stuff to do it. it's, it's-- there's some challenges there. Also, every time you spend, remember with Bitcoin today, you are revealing the redeem script behind the address in its entirety. So people will see that you have this structure and they'll start to ask questions maybe about who are these The situation where your exact signing team is mirrored in the public keys that you're writing to the blockchain, so you're not concealing a lot of information. There are some nice innovations coming in Bitcoin, like Schnorr signatures, Taproot, MAST, a whole bunch of awesome stuff is on the roadmap that will help address some of this, so you'll be able to, for example, build very complex multi-sig scenarios with conditional logic and different groups that look exactly, like this, but aren't-- but it's not obvious. No one else expects Currently can see that, and only if these additional paths actually get utilized in the process of producing a signature would anybody come to know they even existed. That's really cool, and I think over time, you-- once that becomes possible, you might see Hermit switching over to using primitives like that to structure its access controls. But until that stuff arrives, groups need some kind of ability to do stuff like this, and we think that slip thirty-nine, in the context of a single key at a time, is the right way to achieve that."
    },
    {
      "speaker": "stephan",
      "time": "58:40",
      "start": 3519.9,
      "text": "Right, yeah, that's a really, yeah, I was actually about to ask that as well around, so I guess just to summarize for the listeners, if you're having trouble following along, essentially Dhruv, what you're explaining there is that there are different ways to set up a Shamir's secret share such that you can have multi levels and"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "59:01",
      "start": 3540.87,
      "text": "In, in particular, that's the innovation that Slip thirty-nine added to traditional shumir sharing."
    },
    {
      "speaker": "stephan",
      "time": "59:07",
      "start": 3546.62,
      "text": "Right. And, I suppose people who would want to just use multi-signature, there are certain, additional costs and privacy, I guess negative trade-offs are around that, because currently you are revealing every possible spending pathway for that given UTXO, unspent transaction output, and theoretically in the future, once we have Schnorr signatures and we have Taproot, which, as I understand, Taproot allows you to re-spend from one of the given pathways or encumbrances kind of placed on that UTXO and reveal only the one that you are spending from, and the other com-cool component is with, the, aggregated signature approach, where rather than spending from one of these big multisignatures that would cost in terms of bytes on the blockchain space, that would be very big, but hopefully with Schnorr and aggregated signatures, then this would, reduce the cost of blockchain space used to achieve such a thing and therefore lower the fee for using this approach. Would you say that's a fair summary?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:00:18",
      "start": 3618.58,
      "text": "Absolutely. So there's technology coming that changes the calculus here, but for today, for right now, we think a really good rule of thumb is use multisig when you're either one person trying to get redundancy or You're a group of people collaborating and assign different keys to different parties within an entity, within a commercial organization, within a group, you shard's currently to spread out access control within that group. that's a pretty reasonable and efficient solution today, though with the new technologies that you describe, I can see that balance changing. Excellent."
    },
    {
      "speaker": "stephan",
      "time": "01:00:51",
      "start": 3651.65,
      "text": "okay, so one other point I think might be interesting to discuss is just around the decision that a user or a listener has to make when they're deciding, okay, am I gonna go with, service provider to do multi-signature? Now, I think one of the key ones, and I brought this up with Casa as well, is that essentially there is some Component around having to KYC to Unchained Capital, and also the com-probably a key component for most listeners that they have to think about is, am I comfortable doxing my coins to Unchained Capital? Now, in fairness to you, there are benefits and trade-offs here, right? So with Unchained Capital, you're getting access to financial services and you're getting loans. So for example, you can, when you want-- rather than selling your bitcoins and recognizing a capital gain for tax purposes, you can, you know, get a loan and therefore not recognize that gain Gain, and maybe that can help you huddle. So, so there's certain trade-offs there, and also multi-signature is difficult right now, so it's being made easy by using Unchained Capital. So, what, what, what were your thoughts there? and just wanted to give you an opportunity to comment on that."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:01:58",
      "start": 3718.2,
      "text": "Yeah, no, thank you for the opportunity. And I wanna, wanna preface everything that I say with this statement that Unchained Capital is very much a financial services institution. Like we, we engage in that industry, and we are regulated by that industry, and so there's certain things we have to do regardless of what we might wish or hope for. So in the spirit of that, let's get into what is this concept KYC AML. I wanna maybe dispel, first of all, some, some ideas around it. there is no requirement that Unchained or other"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:02:27",
      "start": 3747.92,
      "text": "Report activity directly to the government when you sign up and use our products. That, that isn't the what, that's not the meaning or the spirit of those laws, as much as they may be vilified that way, in certain quarters. We are required to collect data about our customers because we're required to know who they are, and we are required to, for example, check their information against a public OFAC database that anybody literally on the internet can use to look up anybody else. our customers, it's fair, aren't anonymous to us. We know who they are Our customers may lack anonymity because we know them, but we preserve their privacy when they work with us. so as I said, you know, why do we do this? It's because we have to. We're a financial institution, this is a requirement for us. Now, I, I, I won't get into my personal feelings on this, but I, the listeners here are free to feel that KYC is wrong, that it's inefficient, that it's immoral, unnecessary, and that financial institutions shouldn't be required to do it, and that, you know, they don't want to For those changes, hopefully in our government. But you should also recognize that if you are a US-based financial institution, those are the rules that you have to play by. And not playing by those rules, deciding not to, because you believe that somehow you are special, is probably not going to work, and it means that you're taking undue risk, again, for all your customers. and you might not have that land on you today, but in the future, it might happen. So if you think you're a financial institution, you should play by these rules. I also want Well, it's not really, actually about the government in any way, I don't think. The bigger stress is about linking identity, your privacy, your anonymity information to your Bitcoin holdings and transactions, right? and it's not necessarily that the government will know that, that might be part of the worry that certain individuals have, it's more that anyone would know who's not you. So some people are rightly worried about, about that, and, and I understand why, it makes complete sense to me. But I'd also then like to remind those people that what you're really worried about isn't What you are worried about is connecting your identity to your coins. So anybody, you know, like, like, so ju-let's just keep that i-idea in mind here, because I think if the number one thing to you is anonymity, there are pathways like open source software, Electrum, hopefully Caravan, and other ways for you to never have to talk to a company. You can achieve that kind of security without working with anyone. Like, I wouldn't believe a company that claims to preserve your anonymity but asks you for your name Your shipping address, your email, your phone number, if they, even if they're not doing KYC/AML with that data, like they know who you are. Companies are always gonna be incentivized to know who their customers are. Anybody who's running a business knows that. Knowing about your customers helps you find them, sell to them, and serve them better, and help build better products for them. Not everybody wants to be known by a company, and you don't have to do it that way in Bitcoin, there are other options. But as you say, if you are willing to a professional member of my quorum to help protect my coins, financial services to help me not incur capital gains tax on my Bitcoin, a source of advice and a trusted partner for things that I'm doing in this space, those are all valuable things and Sometimes exchanging some anonymity and gaining, and having to rely on privacy is worth it. We're working at Unchained on some new ways to continue to allow our customers to get some of the benefits of working with us, so, you know, all the things I mentioned before, the financial services, the trusted partner, without necessarily revealing their addresses or balances. again, the trade-off there is usability, that a big reason that companies like Unchained and Casa construct addresses and run all that stuff on behalf- Half of their customers is because it's confusing. There's state management and other kinds of issues that aren't impossible, but are challenging for customers to do on their own. As the software gets better, as there are better standards, that will become easier and easier, and the trade-off will be less and less. But today, that's one of the things, that's one of the benefits. Doing this 100% on your own using a tool like Caravan, the very first thing you will run into is, or Electrum for that matter, is, \"Where do I store this information?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:06:40",
      "start": 4000.97,
      "text": "to work in companies, if we could manage it in a way that we didn't know anything about your balances and transactions, that's a direction we'd like to head in, and we are working on some stuff in that area. I'm not available, I'm not able to talk about it right here today, but I am excited, for what we're coming out with in the future around this stuff."
    },
    {
      "speaker": "stephan",
      "time": "01:06:55",
      "start": 4015.44,
      "text": "Fantastic. And let's talk a bit about, if you've got any thoughts around inheritance planning and those concepts, what should listeners be thinking about when they're doing, say, multi-sign"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:07:10",
      "start": 4030.85,
      "text": "Identity really does matter, right? And it's another, I think, great example of where we realize that people's identities aren't controlled by them, they're controlled by the society that they're part of. When you die, you haven't lost your identity, you're just dead, and your body can't access it anymore, and you can't cause anything to happen with it. You still exist as a legal entity in some way, you still have an estate, you have all these obligations, and there are all these mechanisms that are part of the real world, like that we all live in, that existing Sort of show up and start operating, and if you don't understand what those are, like, you're not really doing inheritance right. Like, you can think about your keys all day long and pretend that protecting a treasure is the be-all and end-all of inheritance, but that's just not true. You need to start at what the legal concept looks like of, of estate planning and, and inheritance. And so something that Unchain has been really excited about is making some strides in that area, partnering with some folks in the inheritance space to be able to provide our customers with, like Some nice, like, fast pathways to do the legal work required to do things like establish estates and the necessary documents to understand what happens to their Bitcoin in the event of their death or their inability to, to, to access it anymore. and what's remarkable is that, again, it boils down to identity. Because we do KYCAML, we know our customers, right? That's the KYC. We know who they are. We're able to therefore work with estate management, we're able to work with attorneys and understand what- Their desires would have been, given what they communicated to us prior to their death. And so a little bit, this is another example of why estate, you know, inheritance isn't just multisig, and it's not even just collaborative custody, it's a special product on top of all that. You need the multiple keys, you need a collaboration to understand who those keys belong to and how to communicate and verify identity intent around them, and you need an actual, real inheritance plan that describes what should be happening in all these places. and so that's- It's something that, it's the ch- the reason this product has been challenging for us is that it has almost nothing to do with cryptocurrency. like that part is really solved by some of the core primitives around multisig and some of the existing stuff we've done with collaborative custody. This has been a hard product to get out because a lot of Bitcoiners don't understand inheritance. We didn't really understand it as individuals when we were first approaching this. So getting that to the point where we can recommend plans and partners that can help you execute on that part of the story and then afterwards set up the These and the necessary structures you need on our side with the beneficiaries, with clearly clear delineations of can they sign for you, can they not sign for you, are they holding a key, are they holding a Shamir share of a key? That's the kind of stuff that you can kind of configure and tell us about so that when it comes time to it, your estate can work with us collaboratively if we are also a keyholder to get those funds moved to the beneficiaries."
    },
    {
      "speaker": "stephan",
      "time": "01:10:03",
      "start": 4203.27,
      "text": "One more thing I was keen to ask about. I've got approximately forty-five or fifty percent of my listeners are in the US. but for those listeners who are overseas, obviously Unchain Capital is a US financial institution. Can you talk about anything that an overseas listener might need to think about in terms of if they wanna use Unchain Capital and the Vault and so on? Is there anything special that they need to think about or even for the funding of a loan, if they get one? Can you just touch on that for overseas listeners?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:10:32",
      "start": 4232.25,
      "text": "Yeah, absolutely. It's very fair to say that we are primarily US focused as a- Institution today, that's where we are based and that's where we understand the market the best. so absolutely, we are biased, unfortunately, I think, sometimes towards our American customers. With that said, we do have a few borrowers on our loan product outside the United States. We tend to be very conservative, with that because they're-- that's the most regulated area that we operate in, and the rules are different almost everywhere. We're most likely, if you are international, we're most likely to work with you, if you are a commercial entity, so not an And, and our loan sizes tend to be a little bit larger, larger minimums, because we-- it's just a little bit more involved. for the vault product, it's actually very simple. We believe we can vault customers from almost any country as long as, again, they're not on an OFAC sanctions list. So that's the only thing we'd really be checking that would be different for an international vault customer as compared to a US-based customer. I think international vaults are really interesting. I know a few folks in different countries who, who have a, have Sometimes it's easy to, to poo on, on where we fall down, but we actually are an amazingly well-regulated country, as is Australia, as is much of Europe. But there are a lot of, friends and family I have in places like India, China, the Middle East, where they're much more concerned about their ability to physically, and practically protect their coins, custodial with a US domiciled company and having that be a collaborative process, sometimes even surrendering part of the control might be advantageous there. and we're certainly able to work with customers on That's something that I think we will, once we understand the shape of the product and how indeed US-centric it is versus, rest of world, that's something I'll be able to speak to a little bit more in detail."
    },
    {
      "speaker": "stephan",
      "time": "01:12:14",
      "start": 4334.9,
      "text": "Fantastic. So look, I think, there, there are all the key points I was keen to ask you about. Actually, d-did anything else you wanted to bring up with Unchained that listeners should keep an eye out for?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:12:24",
      "start": 4344.99,
      "text": "No, I think you should look to Unchained as continuing to push on the two areas that we really focus on."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:12:36",
      "start": 4356.04,
      "text": "And easier to use, so more open source software, more libraries, more user interface innovation, and also new products. I think you should look for new loan types from us, we've been discussing a few different interesting options that we've learned, from customers over the last couple of years, different ways to do interest payments and, and balance those against, principal repayment. we're also really interested in new classes of fixed income products, ways to get customers a return from holding Bitcoin with us. Unfortunately, the chief way to do that so far has been And, wanton rehypothecation all around the, the, the ecosystem, and that's great, if you want the risk. we'd like to have some vehicle by which we could offer customers a small, dependable return with that, with a little bit less risk, and more in the spirit of self-custody and collaborative custody. So we're working on some projects like that which are really exciting and I hope to announce next year, but on the whole, I think the biggest ask we would have of the listeners is obviously come"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:13:35",
      "start": 4415.94,
      "text": "Anonymity really matters, or we can't work with you because you're in a different jurisdiction, or you just wanna try out some cool open source software, maybe you're a developer. Do check out some of the stuff we're putting out on our GitHub. there'll be YouTube videos coming in the next few weeks as we release these projects, and, we're always looking for feedback and bug reports. So everybody start trying it out and, and let's make multi-sig and cold storage something that is so easy that anybody can do it for free, easily, online themselves."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:14:05",
      "start": 4445.94,
      "text": "We're excited to support."
    },
    {
      "speaker": "stephan",
      "time": "01:14:07",
      "start": 4447.12,
      "text": "Fantastic, so thank you so much for that. and yeah, look, before we let you go, where can the listeners go if they wanna find Unchained Capital or if they wanna follow you online?"
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:14:16",
      "start": 4456.9,
      "text": "Yeah, come check out our website, we're at www. Unchained-dash-capital. dot com. you can also follow us on Twitter, we're Unchained Cap and I am Dhruv Bansal on Twitter."
    },
    {
      "speaker": "stephan",
      "time": "01:14:27",
      "start": 4467.11,
      "text": "Fantastic, thank you very much for joining us."
    },
    {
      "speaker": "dhruv_bansal",
      "time": "01:14:29",
      "start": 4469.77,
      "text": "Thank you, Stefan, for having us. It's"
    },
    {
      "speaker": "stephan",
      "time": "01:14:32",
      "start": 4472.67,
      "text": "So what do you think of the collaborative custody model that Unchained are applying? I think it's really interesting. If you're interested, go and check out the links there in the show notes. Also, keep an eye out for some awesome episodes coming next week: Jean Epstein and Trace Mayer. Can't wait to release these, but I need to space out the releases. So make sure you subscribe to my podcast at stephanlivera.com. The show notes and the transcripts for the episodes are there also. That's it from me. Thanks, guys, and I will see you in the citad"
    }
  ]
}
