[AMA] Will Martino and Stuart Popejoy, Founders of Kadena

Kadena was invited to answer questions during a private AMA on Telegram. This is an edited transcript of the conversation.

Group: Will/Stuart - Could you guys start off by giving us a brief bio touching on your background as well as how you got started in crypto? And then a short overview of your project, how the idea came to be, and how it’s going so far? We’ll then be off to the races with questions.

Kadena (Stuart Popejoy): Hi, I’m Stuart! I’m a co-founder of Kadena, I’ve been coding for over 25 years, with 15 years of experience in building trading systems and exchange backbones for the financial industry. Before starting Kadena in 2016 with my co-founder Will Martino, I led the blockchain team at JP Morgan in the new products division. I'm a Comp Lit major from UC Berkeley in ‘92 and a gigging NYC musician, and I love decentralized, rock-solid tech (and Haskell).

Kadena (Will Martino): Hi, I’m Will, co-founder and CEO of Kadena. Prior to starting Kadena, I worked in JP Morgan’s emerging technology group along with Stuart Popejoy, where we built Juno, JPM’s first blockchain (effectively JPMcoin v0). Before that, I was a senior science advisor for the U.S. Securities and Exchange Commission, which is where I got my start in blockchain. I was there when Val started the cryptocurrency working group and they needed a tech lead to help. Before that, I was a data engineer for AxialMarket and worked in client services for ION Trading. My academic background is Yale 2010 Economics and Mathematics, where I met my co-author for a number of fractal geometry papers, Professor Michael Frame.

Kadena (Stuart Popejoy): About us: Kadena came out of our work on high-performance private blockchain at JP Morgan, where we open-sourced Juno, a prototype of our current permissioned platform, ScalableBFT. We released Pact, an open source smart contract language for safe and easy building of dApps, in Fall 2016, and we just launched the testnet of Chainweb, our scalable Proof of Work blockchain.

Kadena (Will Martino): Stuart and I are both technical founders, with him as the father of Pact, our smart contract language, and myself focused more on consensus protocol research (ScalableBFT and Chainweb) and briefly moonlighting as a Formal Verification engineer.­

Group: Outside of BTC and Grin, almost all new projects in this space have been converging towards Proof of Stake (PoS). What's the best, most succinct case for Chainweb?

Kadena (Will Martino): Most succinct? If it ain’t broke, don’t fix it. PoS, beyond finality, which is achievable and makes more sense for layer-two, is attempting to replicate the features that Proof of Work (PoW) has.

Now that the energy argument that PoW consumes large amounts of (non-renewable) electricity––which was never a good argument for switching core consensus approaches––has been debunked by researchers, the question is closer to, “Why switch if we can actually solve scaling with PoW?”

Group: Are braided / parallel PoW chains an option that could be implemented on Bitcoin to scale layer 1 or is there something unique about the Chainweb architecture that makes it uniquely suited to Chainweb?

Kadena (Stuart Popejoy): The Chainweb idea started as a bitcoin-dev mailing list proposal actually, called “betacoin.” So yes, Bitcoin could move to braided chains––but I don’t think they will. Betacoin and another similar proposal, “blockrope,” have been around since 2014 but have not been implemented.

Group: How does Chainweb compare to other Proof of Work systems and the known challenges around scalability, security, etc.?

Kadena (Will Martino): In short, far more efficiency (more blocks, and thus throughput, for the same energy needed to advance the state of the chain one blockheight), higher security (more blocks = more samples from a probability space = faster convergence to the real distribution via law of large numbers = lower confirmation times).

It disproves or, at the very least, heavily questions, “the trilemma” of security, scalability and decentralized block production––which, remember, was made up as a model for thinking about crypto issues, but isn't a real law––because more scalability in Chainweb (throughput = more chains) means more security (more blocks) and more DBP (easier for miners to win individual blocks).

Group: What does Kadena tradeoff in order to get scalability?

Kadena (Will Martino): The big tradeoff is that the coin itself is distributed over each individual chain, so for Alice on Chainweb Chain 1 to pay Bob on Chainweb Chain 2, it requires an SPV-based burn-create operation, with one finality interval in between. The big gain, however, is that transactions on independent chains can proceed independently.

Group: PoW and PoS have vastly different security properties in terms of cost to attack vs. cost to defend, so is it fair to say PoS is simply trying to emulate PoW excluding finality?

Kadena (Will Martino): Yes, PoS has far worse security profiles, which modern approaches are trying to mitigate. Should they prove successful, they’ll get effectively the same security profile of a solid PoW system. Remember that PoW has been out and about and working, with known limitations, for almost a decade.

Chainweb incorporates multiple Proof of Work chains into a single network, which offers increased security against Sybil attacks.

Group: Can you explain what a censorship attack looks like?

Kadena (Will Martino): It’s not a new attack as it’s possible now, but we needed to check the cost of it with Chainweb. It looks like a 51% attack looks today, except that instead of mining in private, you mine everyone’s transactions (tx’s) except for some set of accounts’ tx’s. i.e.: you can’t get your tx’s accepted to new blocks. Once we ran the calculations, the cost looks similar to attacks on a non-braided chain POW network.

Group: Are the Kadena blockchains ultimately rooted in the Bitcoin blockchain? Do you envision the existing large scale BTC and ETH miners as the same groups that will be mining Kadena?

Kadena (Will Martino): No, Chainweb is a distinct protocol from Bitcoin that happens to also use Proof of Work, no different than Grin or Ethereum in this respect. I believe miners are in two camps: the believers and the profit-driven. Chainweb is attractive to both.

Group: What impact, if any, would a broad move to WASM have on PACT?

Kadena (Will Martino): It’s key to remember that eWASM is the implementation of an EVM bytecode VM on WASM; they aren’t fundamentally changing WASMs shape. As such, this question isn’t that different from, “Would a broad move to C-based EVM impact Pact?” There are real problems with smart contracts that need to be addressed at the design level, which Pact takes head-on (like governance and Formal Verification) that a shift to WASM doesn’t even pretend to address.

Group: Can you talk a bit about your go-to-market and how you’re thinking about competing with the likes of R3/IBM in the private/enterprise blockchain space?

Kadena (Stuart Popejoy): Sure. We are working with Fortune 500 companies and entrepreneurs in insurance, healthcare, and fintech to bring use cases to our hybrid blockchain platform. Our focus is on getting use cases that demand scalability and safety into production, whether that’s on a permissioned platform, on Chainweb, or (in many cases) both. We work both as partners as well as legging in on the solution side. We also have serious technical differentiators from both R3/IBM, in that (a) we have a public blockchain layer (b) our permissioned blockchains are much faster and easier to manage than theirs (c) we have smart contracts in a purpose-built language that is fast and safe.

Group: Can the team share any security research around “tire-kicking” Chainweb?

Kadena (Stuart Popejoy): Not yet, ARGH! So close, the paper is embargoed for just a little while longer. We'll be presenting a ton of research we did with Tarun Chitra at Gauntlet athttps://www.ieee-security.org/TC/EuroSP2019/ [Moderator’s note: The paper is now published.]

Kadena (Will Martino): Specifically, this workshophttps://blockchain.kcl.ac.uk/ieee-sb2019/

The tl;dr is that the protocol works as we've been expecting, a bit better actually. Censorship attacks are much more expensive than we thought they’d be.

Group: You’re a PoW blockchain network that hasn’t announced its mining algo. What gives?

Kadena (Stuart Popejoy): Choosing a mining algo is a very important strategic question for us, and the space has gotten a lot more sophisticated in the past year. We want to ensure that miners have good options for being able to scale up and also have a unique algorithm. We look to be making announcements in this space this summer.

Group: Since you built JPM coin V0, any thoughts on how this eventually panned out? Do you think it will actually interoperate with public Ethereum in the future / do you think it will actually support say billions of flows within JPM?

Kadena (Will Martino): Interop with Ethereum Mainnet? Doubt it, at least not in a real way. There is a ton of potential in that project, but it’ll never get there on Quorum and EVM. Why do you think we left JPM? We were on the front lines of trying to get EVM to work for real enterprise use cases... and realized it’ll never get there after over a year of hard R&D. If you want enterprise use, you need to design with enterprise in mind upfront.

Group: Curious to see how the miner interest has been for Kadena up till this stage - Where are you currently generating the most interest from in terms of development with the future use of your platform?

Kadena (Stuart Popejoy): Miners have shown a lot of interest in Chainweb’s braided-chain architecture, as this allows miners a lot of flexibility with how they allocate hashpower across the network. As mentioned before, we are looking into options that would allow miners to use hashpower-as-a-service, or invest in hardware, but also align with particular chains that are transacting smart contracts and tokens that they might be partnering with, etc.

Group: What is the expected initial number of chains that Kadena expects to launch with at Genesis?

Kadena (Stuart Popejoy): We haven’t finalized this. Our initial intention was to launch with 10 (Petersen graph) and fork fairly soon after to 20 chains, but if the interest is there we might just start with 20. There’s not a ton of overhead to launch more chains given the same tx workload and it can give miners more options. Stay tuned!

Group: Kadena claims to be the first open-source smart contract language with Formal Verification (FV)? Don’t other languages like Tezos also provide FV?

Kadena (Will Martino): When we first demoed FV of smart contracts back at the first Stanford BPASE Conference in 2017, everyone looked at us like we were speaking a different language. Few, if any, had the background to really think about what user-driven FV of user-written code implied. I bring this up because the market more broadly is still learning about FV, including how a verified VM differs dramatically from a verifiable language. To be brief, a FV-ed VM like Tezos’ is a step on the path to having user-driven FV of user-written code, but it’s one of many steps (translation layers) needed. The way that Pact handles FV is where that path terminates: you write code in a user-friendly language, then you use a sub-language that is still user-friendly to express your intent about what the code you wrote should do, and z3 goes and proves it. Tezos’ approach will get there eventually, much like data61 made a verified microkernel, but it’s a long road to becoming comparable to Pact FV’s feature list.

Group: In order for the SPV proofs to be accepted and have reasonable security with regards to proving the headers belong to the longest chain, there must be a proof of PoW for multiple blocks, which grow linearly with the number of blocks. Are you utilizing NiPoPoWs by Zindros et al, or looking into Flyclient for compact SPV proofs?

Kadena (Stuart Popejoy): Chainweb is actually different here, as we’re the first network to be verifying SPV proofs for itself. The implication here is that SPV-linked transactions live in the same “cut” (cross-chain fork), and can rely on the fork-local headers in their own node for verification, so there is no need for a longest-chain oracle. Note: this is only for cross-chain transactions within Chainweb; interop with other chains would of course need to resolve longest-chain questions.

Group: Can you expand on “verifying SPV proofs for itself” or point me to a relevant resource?

“… ‘cut’ (cross-chain fork), and can rely on the fork-local headers in their own node for verification”...How do you secure against an attack where I make a spend on chain A, orphan that block, and then move my coins from chain A to chain B? It’s not clear to me how cross-chain tx’s within Chainweb differ from generally cross-chain, and how it achieves scalability + security without long SPV proofs.

Kadena (Stuart Popejoy): The Chainweb consensus is constantly ensuring that other chains are participating in the same history or “cut.” This ensures that past 1 or 2 blocks, censorship is effectively impossible as you quickly get to a place where you would have to censor the whole network to own one chain. Within a given “cut” reorg, all chains are verified as reflecting each other’s merkle roots. Thus, the SPV proofs supplied only need to reference the source chain’s index + blockheight + header and the receiving chain can source the rest of the path to the local chain.

Group: Could you characterize Kadena as a network of PoW sidechains, or some shared PoW arch, similar to Zilliqa?

Kadena (Will Martino): It’s parallel PoW. Every block is mined; the global hashrate is spread over the various blocks at a given height. It’s not sidechains, because there is no “main chain.” Every chain in the network is the “main chain.” Think of it like Hashgraph, except with a fixed threaded configuration and a proven consensus protocol. There’s no pBFT (e.g. Zilliqa). It’s just PoW, but instead of a new block pointing at its previous block (BTC) or its previous and some uncles (ETH’s GHOST), a new block points at its previous and some of its peers’ previous. As new blocks reference it, it gets buried in the “probabilistic mass” that PoW generates.

Group: With Pact, please explain in what way besides the syntax that would make it the ideal smart contract language for future projects to adopt? When will public participation be available for testnet?

Kadena (Stuart Popejoy): The main advantage of Pact is “we've done most of the work for you.” Example: key signatures. You don’t have to worry, or even decide, whether to support multi-signature or single-sig, as it is supported out-of-the-box. Another example: error messages! Another example: upgrades, where you can control exactly how an upgrade happens (if at all) and how it affects downstream contracts. The net result is you don’t have to write nearly as much code, and our SDK makes it really easy to write unit tests, deploy to a local testnet on your laptop, and finally deploy to your permissioned network on AWS or Azure or better yet, release it on Chainweb. Lastly, Pact is launching some amazing features for cross-chain compute where SPV happens “in the background,” such that you can do really interesting things scaling your app across Chainweb.

Group: How do you see your ideal scenario for hybrid chain adoption and how do you envision enterprise uses accruing value back onto public chains? So far with Ethereum, Stellar, etc. this hasn’t happened. What will be different with Kadena?

Kadena (Will Martino): I have a whole post about this on our Medium:https://medium.com/kadena-io/blockchain-future-smart-contract-sharing-economy-134a318fef55

When I think about the first few examples (Ethereum, Stellar), they are all “smart services” running on smart contracts that are on-chain, charging fees for data. But take a simple example: a smart contract on ETH that has yesterday’s price of BTC in ETH. Why doesn’t this exist today? Because smart contract interop (contracts interacting a single tx) is wildly unsafe (see: Parity multi-sig). Moreover, governance (how to upgrade broken things) is also unsafe and non-native to EVM.

So, it’s base-design failings that hold back smart contracts. Kadena is different because Pact is a from-scratch redesign of how to approach smart contracts, and had the most sophisticated, interlaced enterprise use cases in mind during the early design phase. It’s night and day.

Group: Do Kadena tokens need to accrue a monetary premium for the network to be maximally secure? If so, do you guys have a strategy for making this happen?

Kadena (Will Martino): So, do you mean in a similar way to how PoS is cheaper to bribe so it needs to be priced high enough to be secure? Not really, we’re still PoW so the same restrictions apply. You can bribe miners, but we’re pretty sure we’ll be on ASICs within a year of launch so while you can bribe miners, it is very expensive as any network that has a security problem will find it hard to regain trust (and thus the miner’s infrastructure will become a loss, so you effectively need to buy out enough miners to bribe them).

PoS, not being tied to objective physics, doesn’t have the feature natively, which is why modern PoS networks are trying to make bribery harder by randomly picking validators from a longer list. VRFs, should they prove to function as expected, will help PoS to replicate one feature of PoW’s existing security profile.

Group: Infura is not a light client service, it’s just providing you with arbitrary data, which happens to align with what happens in the chain. In order for people to run light-nodes which require only headers, they need to get the SPV proofs from full nodes. If you have a chain which does a lot of operations (and is not sharding), running a full node is usually costly / requires non-trivial infrastructure. How do you approach that, i.e. make it easy to run a full node + incentivize users to run full nodes w/o ending up in an Infura situation? (Note that I don’t think any project has solved incentivizing full nodes and is mostly an altruistic act that contributes to the network’s security, so it’s ok if you do not have a clear answer.)

Kadena (Stuart Popejoy): It's a very involved question. Infura basically exists as one answer for Ethereum, that many are dissatisfied with. Chainweb will make it easy to run a headers-only node for pretty much any network size. For other chains, all the usual options are available, and Pact has an open architecture which will allow us to consume SPV proofs from other chains while remaining gas-efficient. The longest-chain always comes down to either (a) run a node or (b) engage in some kind of trustful relationship with a service provider.

Chainweb benefits from a decoupled architecture so we can offer some unique run modes, notably header-only, where a node is simply validating block headers and cross-chain links (i.e., cut consensus), but not even replicating the full payloads. Or, you can run full headers and a single chain doing full payloads, etc.

A header-only node will be feasible on a laptop for many years, and we can introduce checkpointing of headers (and payloads) to continue to make this feasible for longer. The more interesting problem emerges if Chainweb were to grow to >10,000 chains, but that’s a good problem to have and plenty of time to plan for it.

Kadena (Will Martino): It’s also discussed in section 5 of the chainweb paper -- see the role of large mining pools

Kadena (Will Martino): Nota bene: I’ve been working for a few years to see if PoS with a Chainweb arch could work and I’ve bounced it off a number of the top minds in the space. No one has come up with a solution. The stochastic nature of mining and the objective, transportable target (hash’s difficulty) are core to getting Chainweb to work and thus reaping the massive throughput bump that it gives you.

Group: How can people get in touch?

Kadena (Will Martino): Thanks for having us! We're based in Brooklyn (come say hi!)

Website

Discord

Twitter

Also, follow our blog on Medium, the fun’s just starting!

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

Suggested Research Based on your Watchlists

Create a new watchlist