Bitcoin-IPC: Scaling Bitcoin with a Network of Proof-of-Stake Subnets
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Bitcoin-IPC: Scaling Bitcoin with a Network of Proof-of-Stake Subnets".
Elias: Bitcoin-IPC introduces a protocol that scales Bitcoin by establishing a network of permissionless, interconnected Proof-of-Stake (PoS) Layer-2 chains called subnets, where stake is denominated in L1 BTC.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: The paper starts by laying out how they envision scaling Bitcoin through this network of permissionless, interconnected PoS Layer-two chains called subnets, where stake is denominated in L1 BTC. Elias I’m curious about the authors and what their background might bring to this kind of protocol design. Priya I wonder if the authors have a specific focus on how this structure handles data integrity when it's layered on top of something as established as Bitcoin.
Nadia: The paper introduces this framework, and the initial implication is that any group of Bitcoiners could create their own PoS L2 subnet by staking their L1 BTC, which is a permissionless way to start a new environment. Elias That permissionless creation aspect seems key; it moves away from fixed hierarchies you see in some older tiered consensus systems.
Priya: If they are building these environments on top of Bitcoin, the privacy implications for the users who interact with these subnets could be interesting, given how they manage value transfers between them.
Nadia: That's a good point about privacy; I want to know what happens when we talk about value movement across different subnets without needing pre-reserved liquidity, which is something they claim is interoperability by design.
Elias: That lack of pre-reservation for specific transactions contrasts sharply with some other Layer-two solutions, which makes this approach very compelling from a cryptographic perspective regarding liquidity management.
The paper's summary: Nadia: The summary explains that Bitcoin-IPC establishes a network of dynamic, permissionless, and interconnected PoS subnets that are secured by leveraging the security of Bitcoin L1, especially against things like long-range attacks. Elias So they are explicitly addressing the security concerns often associated with L2 solutions by tethering them to Bitcoin's established security foundation.
Priya: When they discuss this focus on known attacks on PoS, I’m thinking about how that relates to the data flow; does anchoring state changes periodically onto Bitcoin L1 provide a verifiable history of everything happening in these subnets?
Nadia: Precisely, Priya; the checkpoint mechanism is central here. They use two transactions, a "checkpointTx" and a "batchTransferTx," where the checkpoint includes an output UTXO with an OP RETURN script containing the height of the subnet block and state commitment. Elias That specific anchoring method sounds like it’s designed to ensure atomicity across all events that cross between a subnet and Bitcoin L1.
Priya: If every deposit, withdrawal, or validator change has to be committed this way, it means we can have a very strong audit trail for the state of these subnets without needing a central authority.
Elias: And the paper claims this formal definition of state anchoring exposes an operation that is ever-growing in liveness and append-only in safety, which prevents forging events. That sounds like a robust way to maintain integrity across the entire system.
The paper's improvements: Nadia: The suggested improvements focus heavily on achieving performance, stating that by encoding all critical subnet operations into ordinary Bitcoin transactions and using batching inspired by SWIFT messaging, they reduce the virtual-byte cost per transaction by up to twenty-three times. Elias A reduction of twenty-three times in virtual bytes per transaction is significant; how do you translate that byte saving into a tangible increase in throughput?
Priya: From a measurement standpoint, if we can reduce the size of the message used for settlement across L2 subnets by that much, it directly impacts network congestion and latency for all users.
Nadia: It effectively turns Bitcoin L1 into a settlement layer for the entire network instead of keeping it as a bottleneck, which is what they aim to do. Elias That shift in role for Bitcoin L1 is what really changes how we view its utility in this context.
Priya: I'm interested in the practical application of this throughput increase; if you go from seven transactions per second to over one hundred and sixty, that suggests a massive boost for applications dealing with high-frequency data streams.
Conclusion: Nadia: To wrap up, the Bitcoin-IPC: Scaling Bitcoin with a Network of Proof-of-Stake Subnets protocol provides a framework for creating scalable L2 chains secured by L1 BTC through dynamic, permissionless subnets. Elias The main implication is that it offers interoperability between these subnets without pre-reserving liquidity, which is a big deal for how value moves in this ecosystem.
Priya: What stands out to me is the mechanism for state anchoring; having that formal proof structure ensures that the integrity of those state changes across subnets remains verifiable and immutable on Bitcoin L1.
Nadia: And we saw how they boost throughput dramatically, achieving over one hundred and sixty transactions per second through their batching techniques inspired by SWIFT messaging. Elias Ultimately, this research shows a way to scale Bitcoin by building an interconnected network of PoS chains that leverage the existing security model efficiently.
Priya: I just think that for anyone interested in decentralized environments where you need both high throughput and verifiable state persistence, this paper provides a concrete architectural blueprint to consider.
Orestis Alpos, Jakov Mitrovski, Themis Papameletiou, Nikola Risti´c, Dionysis Zindros, Marko Vukoli´c
Bitcoin Scaling Labs
cs.DC, cs.CR
Submitted: 2025-12-29
Updated: 2026-09-29
Code: https://github.com/bitcoinscalinglabs/bitcoin-ipc
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 80/100
The gist: Bitcoin-IPC introduces a protocol that scales Bitcoin by establishing a network of permissionless, interconnected Proof-of-Stake (PoS) Layer-2 chains called subnets, where stake is denominated in L1
Key concepts
- Subnets
- These are dynamic, permissionless PoS Layer-2 chains created by any group of Bitcoiners staking L1 BTC. They allow for independent operations and programmability, such as tokenization, while leveraging the security of Bitcoin L1.
- vB/tx Reduction
- The protocol uses batching mechanisms inspired by SWIFT messaging to encode multiple subnet operations into a single Bitcoin transaction. This technique reduces the virtual-byte cost per transaction by up to 23x, drastically increasing monetary throughput.
- Checkpoint Mechanism
- State persistence is ensured by periodically anchoring subnet state onto Bitcoin L1 using a 'checkpointTx'. This atomic process links subnet events—like transfers or validator changes—to the main chain, guaranteeing safety and preventing forgery.
Terminology
Summary
Bitcoin-IPC introduces a protocol that scales Bitcoin by establishing a network of permissionless, interconnected Proof-of-Stake (PoS) Layer-2 chains called subnets, where stake is denominated in L1 BTC. This framework addresses the scalability limitations of Bitcoin as a Medium of Exchange by enabling seamless value transfer across these subnets without requiring modifications to Bitcoin L1. By encoding all critical subnet operations into ordinary Bitcoin transactions and utilizing batching mechanisms inspired by SWIFT messaging, the protocol achieves a reduction in virtual-byte cost per transaction (vB/tx) by up to 23x, effectively increasing monetary transaction throughput from 7 tps to over 160 tps.
Protocol Overview and Design Goals
Bitcoin-IPC is designed as a network of dynamic, permissionless, and interconnected PoS subnets that require no changes to Bitcoin L1. The primary design goals are:
-
Permissionless creation of subnets:
Any group of Bitcoiners can create a PoS L2 subnet, staking their L1 BTC.
-
Interoperability by design: Users can
transact across different subnets as seamlessly as within a specific subnet, without pre-reserving liquidity for specific transactions (in sharp contrast to LN).
-
Secured by Bitcoin: Subnets
leverage security of Bitcoin L1, in particular with respect to known attacks on PoS such as long-range attacks.
-
Performance: It aims to
Dramatically increase monetary transaction throughput compared to Bitcoin L1, in particular for cross-subnet transfers.
-
Programmability: It allows for
smart-contract programmability on subnets catering to important use cases (e.g., real-world asset tokenization, stablecoins).
-
Adhere to Bitcoin ethos: The protocol mandates that it
do not modify Bitcoin L1 in any way.
Subnet Lifecycle and Configuration
The lifecycle of a subnet is managed through specific Bitcoin transactions. Key operational steps include:
(See Figure 1 for the full lifecycle)
-
Subnet creation involves posting a dedicated
create-subnet tx
on Bitcoin, specifying the whitelist and minimum validators. The initial configuration (configuration number 0) is permissioned by this process. -
Validators join by posting a
join-subnet tx,
locking collateral under a specific multisig address derived from the whitelistMultisig. -
The subnet becomes active once the quorum of validators has joined, at which point it creates its first checkpoint (configuration number 1).
-
Configuration updates occur every checkpoint period;
The configuration of the subnet may be updated every checkpoint-period number of blocks.
-
Validators can dynamically join or leave, or change their stake using dedicated transactions (
stake,
unstake,
andleave
commands), with changes taking effect at the next checkpoint. -
Subnet termination is possible via a
kill-subnet tx,
requiring a 2/3 vote of validators to propose it, followed by a grace period for fund withdrawal before the subnet is marked as killed.
State Anchoring and Security
Bitcoin-IPC ensures state persistence through periodic anchoring on Bitcoin L1. This is achieved via the checkpoint mechanism:
(See Section 5.4 for details)
(See Theorem 1 for formal proof)
The checkpoint mechanism involves submitting two transactions: a checkpointTx
and a batchTransferTx.
The checkpointTx
includes an output UTXO with an OP RETURN script with the keyword CPT, the height of the subnet block at which the checkpoint was created, and the state commitment.
This process ensures that every event crossing between a subnet and Bitcoin—including state commitments, deposits, withdrawals, transfers, and validator changes
—is processed atomically.
The state anchoring functionality is formally defined as exposing an operation to retrieve a list of tuples [(h1, c1),...,(hm, cm)], ensuring it is Ever-growing (liveness),
Append-only (safety),
and prevents No forging.
Value Movement and Cross-Subnet Transfers
The protocol formalizes bridge protocols to allow value movement between Bitcoin L1 and subnets, as well as between subnets themselves.
(See Definitions 2, 3, and 4)
-
Deposit functionality: Users
lock BTC on the Bitcoin network
to obtainwBTC in a subnet
via a transaction that locks funds with the subnet's multisig address. This satisfies safety by ensuring that if the Bitcoin balance of S increases by v BTC, the user's balance on S decreases by v BTC. -
Withdrawal functionality: Users can
withdraw funds from a subnet to Bitcoin,
which is handled in Section 5.7, where a checkpoint handles all withdrawals found in the subnet within that pair of transactions.
Improvements for AI systems
As a fastidious and diligent researcher, I have analyzed the Bitcoin-IPC protocol. Based on its architecture, scalability mechanisms, and security guarantees, here are specific ways this research can be leveraged to improve AI systems:
)Improved AI Systems Capabilities Based on Bitcoin-IPC Research:
- (Hyper-Scalable Decentralized Data Storage & Computation Layer):
The core concept of Bitcoin-IPC—creating a network of permissionless, interconnected Proof-of-Stake (PoS) Layer-2 subnets anchored to Bitcoin L1—can be repurposed as a robust, decentralized execution and data storage layer for AI models.
- (AI Model Training and Inference Subnets):
Instead of using the L2 chains for simple token transfers, these subnets can host specialized execution environments (like the Filecoin Virtual Machine mentioned in the paper).
-
A dedicated subnet could be configured with an execution engine optimized for specific AI tasks (e.g., reinforcement learning simulation, large-scale model inference).
-
The
programmability
goal allows for smart contracts to define complex reward mechanisms or data access rules for decentralized compute nodes.
- (Decentralized Federated Learning (DFL) with Secure State Anchoring):
The state anchoring mechanism (Section A.2) is crucial here. AI models often require secure, verifiable state updates during federated learning where participants cannot trust each other's gradients or model weights directly.
- AI agents could use the Bitcoin-IPC checkpointing mechanism to periodically commit the aggregate model state or critical learning checkpoints onto Bitcoin L1. This provides an immutable, decentralized ledger for verifying that local subnets have correctly contributed to a global AI model without requiring a central, trusted coordinator.
- (Cross-Subnet Knowledge Transfer and Asset Interoperability):
The cross-subnet transfer functionality (Section 5.6) allows value (and by extension, critical information/model parameters) to move between independent AI subnets without relying on a single bridge operator or pre-reserved liquidity.
- This enables the seamless sharing of specialized AI knowledge or model weights between distinct, independently governed AI ecosystems running on different subnets (e.g., one subnet for vision tasks, another for language models).
- (Tamper-Evident Model Governance and Validator Slashing):
The dynamic participation and kill mechanism (Section 5.8 & 5.9) provide a mechanism for governance within the AI ecosystem itself, enforced by economic security derived from Bitcoin L1.
- Validators managing specific AI subnet configurations can be economically penalized (slashed) if they fail to maintain safety or liveness, ensuring that the integrity of the decentralized computation environment is maintained by stake held in Bitcoin, not a centralized authority.
- (High-Throughput Data Processing for Real-Time AI):
The massive throughput increase (up to 160 tps) achieved through batching transfers directly translates to high-speed data pipelines.
- This allows AI systems that process continuous streams of data (e.g., real-time sensor data, financial market feeds) to move and process information across subnets with minimal latency, achieving near real-time decision-making capabilities far beyond the constraints of Bitcoin L1.
Sources
- The latest gossip on BFT consensus
- Bitcoin Staking
- Babylon: Reusing Bitcoin Mining to Enhance Proof-of-Stake Security
Related papers
- iScheduler: Reinforcement Learning-Driven Continual Optimization for Large-Scale Resource Investment Problems
- SAMM: Sharded Automated Market Maker
- InferScale: GPU-Native KV Injection for Personalized LLM Serving
- Vigil: Accountable Liveness against Selective Silence
- Steelhead: Interleaving Partially Synchronous and Asynchronous Commit Rules on a Shared DAG
- Pushing CPU Speech Synthesis to the Wall: Extreme Inference Tuning under Serverless Architecture and Billing