pull down to refresh

Alright, I'd like to have a discussion regarding bitcoin's fungibility (or lack there of).

I am a bitcoiner and have been for a decent number of years but I would ask that we leave our maxi hats at the door and look at this objectively because in my opinion, it is one of the biggest issues that I see with Bitcoin. And I'm going to talk about the forbidden shitcoin Monero so please if I offend the NGU cult with my shitcoin talk, then stop reading here.

This will be a bit of rambling while I think through this issue.

As we know, on-chain Bitcoin is a public ledger and every transaction is there for all to see. Chainalysis creates risk scores based on each utxo's history and these scores are used by any regulated exchanges that interact with the fiat system.

Now already, there will be people that say "well, just don't interact with the fiat system at all and it won't matter". I mostly agree with this take but it is a non-answer to the problem. For the foreseeable future, 99% of people have to interact with the fiat system in some form or fashion. Even in a future where we are on a "Bitcoin standard", this issue of chainalysis flagging funds used at a business would likely still exist. The transaction would not be stopped from getting to its recipient but the utxos would be flagged like they are today if "tainted" utxos are sent to an exchange. I see the idea or mention of "tainted" Bitcoin as a failure in bitcoin's fungibility. While I reject the framing of "tainted" utxos, it is a real issue for anyone who needs to interact with fiat.

Enter lightning. Lightning does help with the fungibility issue of on-chain Bitcoin. As a sender, you have much better privacy. I have opened lightning channels with coinjoined funds and spent them at a square terminal. This is a great step in the right direction. I haven't tried to send them to strike or cash app or one of these exchanges to see if it gets frozen there.

The issue that I personally have with lightning is that the complexities of it almost force people to use a custodial solution. The idea of my parents or my grandma keeping 12 or 24 words safe and using an on chain wallet is actually doable. Thinking about them opening channels and balancing channels and dealing with some of the headaches of lightning to truly use it self custodially is laughable.

In my opinion, one of the main benefits of Bitcoin for me is being able to custody my money myself. The way that many people (and I'd venture to say most) use lightning is in a custodial fashion or in a quasi custodial fashion with spark where the liquidity provider sees every transaction.

I want to challenge people to think about the trade-offs that we are ushering newcoiners into. Many people learn and slowly upgrade their wallet setups as they learn to improve security and custody setup. However, it usually requires listening to 40HPW of Bitcoin podcasts and watching a bunch of btc sessions videos.

The fungibility issue is improved by using lightning but it's often coming at the expense of custody or privacy (LSP sees all transactions with the exception of maybe Zeus). Bitcoin on chain struggles with fungibility and lightning is generally adopted in a custodial way.

The purpose of me bringing this up is I guess I live in a fantasy land where I'd like to have the simplicity and reliability of on-chain Bitcoin with the fungibility of lightning. I'd like for future bitcoiners to not have to be a sysadmin to be able to use lightning in the most private and secure fashion without giving up custody.

Physical cash is fungible. It doesn't matter if the bill has been in a strippers crack or if it's straight from the money printer, it spends the same. Monero is fungible. It sacrifices the hard supply cap and the simplicity of auditing the supply for privacy/fungibility. If Bitcoin is going to be freedom money, it needs to be fungible.

Ok like I said, this was going to be rambly but hopefully it was enough information for people to be able to discuss what I believe to be the most frustrating aspect of Bitcoin.

Ok, discuss.

First and foremost, Lightning's difficulty is constantly overstated. To the extent that fungibility is an issue for any given individual, Lightning is hardly an insurmountable barrier. In my experience it actually forces the user to learn more than they otherwise would, and I think the knowledge needed to run a small personal Lightning node is a reasonable standard for anyone who is actually serious about Bitcoin in the first place (not that anyone is required to be serious...God knows I often am not). Those who are not as deep into the weeds (many refer to older, less-technical generations in these discussions) are also typically happy to comply and completely unfazed and unaffected by these regulatory hurdles that turn off the more liberty-oriented individual.

I think the bigger issue is that the fungibility problem as you've presented it exists largely outside of Bitcoin, in a jurisdictional layer that can only be applied case-by-case.
I often think of it in parallel with cannabis prohibition. We've seen a lot of different government strategies and postures toward enforcement between the 1930s and now, yet the plant itself has remained abundantly available the whole time. Even today, in arguably the most legally and culturally permissive environment since it was originally banned, it remains federally illegal.

So I think "fungibility" somewhat misidentifies the underlying problem. Bitcoin UTXOs are equally valid and spendable according to Bitcoin's consensus rules regardless of government decrees or third-party interest in their histories. The distinction is being imposed externally. It's a bit like ordinals: someone can consider a particular sat "rare," but that's an arbitrary designation that exists in an abstract layer on top of Bitcoin. The network itself doesn't know or care.
That doesn't mean those external distinctions are harmless. Legal issues are obviously interesting, annoying, and potentially dangerous, and they're difficult to discuss openly and honestly just because of their nature and implications. But that's a different problem from Bitcoin itself refusing to treat one valid UTXO like another.

Your Monero example seems to help solve the private-transfer side of that problem, but I'm less convinced that it solves the store-of-value side without introducing meaningful tradeoffs of its own.
In the end, I think the core of the problem we're discussing lies with governments, regulated intermediaries, and their enforcement decisions, not fundamentally with Bitcoin, or with any particular freedom or privacy technology. Organized power can become a problem for its perceived opponents regardless of the tools we have access to. I don't think that makes Bitcoin perfectly private, but I also don't think it makes Bitcoin fundamentally non-fungible or Monero a silver-bullet solution.

reply

Comparing fungibility to ordinals (an externally imposed system) is interesting. I certainly hadn't thought about it that way.

What is your response to this:

Bitcoin is useful in that it allows anyone to send sats to anyone else even if a government or set of governments doesn't want them to.

If OFAC has some list of addresses that they don't like, it doesn't really stop me from sending to one of those addresses or whoever owns one of them from sending out. What it does do though is increase the likelihood that a person won't accept their payment.

At the end of the day, I want my money to be useful. I want to buy stuff with it or use it as collateral. If most of the people I interact with don't want my sats because of the address they come from, it might be enough of a problem that the utility of those sats specifically is decreased (ie I have to spend more time/effort/resources to use them to buy something than if they were not coming from an address on an OFAC list).

While I agree that this is an external layering on the system, it possible because of how bitcoin works (transaction graphs are visible, fairly easy to track). It's one thing to say, bitcoin is perfectly fungible because the protocol doesn't have a mechanism for preventing any particular transaction from being included in a block, but what many people in the world might mean when they say "Bitcoin isn't fungible" is that technical aspects of how it works make it very easy for governments to target specific coins.

reply

To riff a bit on your example of wanting your money to be useful:

Typically if you wind up on a sanctions list, the people you do business with most often already are engaging with you economically in spite of this status. The mere fact that Bitcoin can circumvent certain sanctions imposed by these entities already makes it more fungible than anything we traditionally think of as "money".

I am always surprised at how often people advocate that Bitcoin should be used more privately or permissionlessly or sovereignly by "your average person" when this hypothetical person doesn't have any motive, incentive or desire to act in these ways (which by the way, all take extra effort as a matter of course). Meanwhile those who are motivated to act sovereignly, privately or permissionlessly already do so.

reply

Coinjoins and other methods exist to further obfuscate UTXO history, and chainalysis has been shown to be unreliable, to put it charitably.

Nonetheless, a motivated enough government has demonstrated they will prosecute whomever they wish for whatever they wish. If that is the standard, then nothing is fungible.

reply
133 sats \ 0 replies \ @anon 7 Oct

A-f’n-men Spence!
-KT

reply
2123 sats \ 0 replies \ @anon 7 Oct

Monero has significant scalability problems, and it also has been vulnerable to invisible inflation hacks, just like zcash and Liquid network.

confidential transactions turns out to be bad for security and verification of supply which is essential for money.

Scalability is important for decentralization, and monero for this reason won't be decentralized if it was mainstream, because it is not scalable, and monero transactoins are large compared to bitcoin onchain transactions, and monero has all transactions on chain which is silly for every day transactions. Every node would need to keep every transaction of all of history for everyone including for small payments for coffee. With layer 2 on bitcoin, you can fit a massive number if not unlimited number of transactions into the footprint of just one or two onchain transactions (in the case of lightning, channel opening and closing). And with channel factories you won't even need onchain footprint at all as I understand.

reply
538 sats \ 0 replies \ @Reed 7 Oct

I don't disagree with anything here, but it's important to keep things in perspective. The fungibility issues you're describing are largely a product of a probabilistic analysis that relies on centralized exchanges sharing KYC information with the government... a government who has shown that it is willing to throw people in jail regardless of if they are actually the owners of said "non-fungible" coins.

Also while it may not seem early to those who have been here a while now, it is still early. Lightning has gotten significantly better and easier to use in a sovereign way over the last few years and more innovations are coming out all the time (Cashu, Fedimint, Ark, Spark, Wavelength, etc.) with their own tradeoffs regarding custody and privacy. There is a massive amount of development in the bitcoin space, I'd be willing to bet more than all crypto projects combined.

To me, what makes Monero a shitcoin has to do with the ease with which its small dev team can hard fork it and the limited number of participants who are carefully ensuring the stability and scalability of the code and the network.

Gresham's Law states that people will prefer to spend monero and fiat before Bitcoin. There can be times where it is preferrable to spend monero, but I wouldn't choose to save in it for the long term. Saving in bitcoin while spending monero or USDT is where centralized swap providers come in; that may not be an issue for spenders, but it is an issue for merchants who don't want to hold monero.

I guess my point is that Monero has tradoffs too. In my experience, bitcoiners are much more willing to have a conversation about solving privacy issues on bitcoin than monero maxis are willing to talk about the tradeoffs of swap providers and changes to consensus code.

reply
85 sats \ 1 reply \ @anon 7 Oct

Great post, and thought provoking.

For lightning: I agree that it can be made easier to use for non-techy people in a way that also does not sacrifice self custody. I blame mobile wallets for failing to simply support the ability to open channels directly and failing to simply conncet to lightning routers, which would allow lightning routers to immediatly open inbound liquidity upon request. This should be an easy thing to do. Why devs do not do this I don't know. Or maybe we can also have some other layer 2 that is still intercompatible with lightning, if lightning cannot be improved in this aspect. I use lightning and in a self custodial way, but i also run my own node.

for onchain:

coinjoins work and is great, and coinswaps will be great also if that ever becomes production.

As for coinjoining being called "tainted", My argument is that anyone or anything that rejects a utxo with a coinjoin history, that is not an issue of btc rather that person or company is incomptable with bitcoin. I can agree that privacy should be enforced, otherwise the scrutiny of private use of something will make weak people (the majroity) opt to go with the less free, less private route if they are scared of the consequences of being "non-compliant with government". If enforced privacy means that bitcoin be totally banned, then so be it. Totally free and incompatible with gov regulations is better than being optionally free and compatible with gov regulations.

Maybe if we have onchain privacy that makes private vs non-private use indistinguishable from each other, that would give plausible deniability and thus fungibility to all onchain coins. Coinswap maybe? Coinswap means that a UTXOs history is no longer reliably valid as the real history of ownership.

If we cannot make onchain privacy the default, my idea is to make it to where private vs non-private use is indistinguishable .

reply
2010 sats \ 0 replies \ @anon 7 Oct
Coinswap means that a UTXOs history is no longer reliably valid as the real history of ownership.

If we cannot make onchain privacy the default, my idea is to make it to where private vs non-private use is indistinguishable .

highlight of my long post. I think this would be a solution for onchain fungibility, thoughts?
And by "default" I mean "enforced".

reply
441 sats \ 1 reply \ @Scoresby 7 Oct

I think you make many fair points.

The fungibility point is a tough one for bitcoiners to deal with. And it does feel like the current answer is either A) do really complicated careful stuff with coinjoins and coin management or B) use lightning...which often ends up looking custodial.

Custodial lightning doesn't seem like it is better than monero. Is Ark? or ecash? If I am willing to use a Spark wallet for daily spending and swap out to on chain when the balance gets too low or too high, why not use monero and swap?

Well, I am not knowledgeable enough of monero to evaluate whether it is a better set of tradeoffs, but I think that the progress I have seen in lightning over the last three years or so is encouraging enough that it's not just hopium that the tooling will get easier to use.

I probably make an error in emphasizing censorship resistance as the primary goal here. But I haven't been able to argue myself off the ledge, and so I tend to stick with the coin that I think offers me the greatest censorship resistance, even if fungibility is questionable.

(I might need to ask myself whether you really can have censorship resistance without fungibility)

reply
10 sats \ 0 replies \ @anon 7 Oct
Custodial lightning doesn't seem like it is better than monero. Is Ark? or ecash? If I am willing to use a Spark wallet for daily spending and swap out to on chain when the balance gets too low or too high, why not use monero and swap?

This is generally my opinion as well. I don't use anything that is custodial but if I've got to swap in and out of something, why does it matter if it's a tool that has improved privacy and is self custody instead of ecash or liquid or anything like that? I don't even bring spark into the equation because I think spark is surveillance tech.

Well, I am not knowledgeable enough of monero to evaluate whether it is a better set of tradeoffs, but I think that the progress I have seen in lightning over the last three years or so is encouraging enough that it's not just hopium that the tooling will get easier to use.

I agree with this as well. Hard to tell where we will go in terms of UX improvements because things change so fast and I think there is hope that it gets easier but it MUST get easier to be true self custody or imo we are fighting a losing battle. We should not shoe horn people into Bitcoin by showing them a great UX venmo replacement that offers little to none of the properties of actual Bitcoin.

I probably make an error in emphasizing censorship resistance as the primary goal here. But I haven't been able to argue myself off the ledge, and so I tend to stick with the coin that I think offers me the greatest censorship resistance, even if fungibility is questionable.

It is fungible until it goes back to an exchange. Then there is little to no fungibility. The powers that be can make the decision with their black box analysis tool on whether or not your utxos get the blessing of the regulator. Not a good situation to be in.

(I might need to ask myself whether you really can have censorship resistance without fungibility)

THIS is the question we need to be asking.

reply
The issue that I personally have with lightning is that the complexities of it almost force people to use a custodial solution.

How so? I'm a dummy and I've been running a lightning node for quite a while.

reply
210 sats \ 7 replies \ @anon 7 Oct

I am too and so have I. I am very left of the bell curve.

But the vast majority of bitcoiners I meet at meetups do not.

reply

That's different than it being too complex.

reply
121 sats \ 5 replies \ @anon 7 Oct

Is it? If it wasn't complex then they'd just run a node and balance their channels. People trend toward convenience and the convenient option is custodial so they don't have to deal with the complexities.

reply

In a sense, no, it's not different than "being too complex." It does seem to be too complex for how little effort people want to put into it (which is not very much).

I do think it's different than "the complexities of it almost force people to use a custodial solution", though. It's sufficiently simple that anyone who cares about not using a custodian can do so.

reply
81 sats \ 2 replies \ @anon 7 Oct

Fair. The ability to use lightning fully self custody is there if you want/need it and want to put in a little extra effort. I guess my point is, it's not nearly as simple as downloading whatever mobile on chain wallet and writing down a seed phrase and you're ready to spend/receive. Imo that is the bar for how simple it should be. And maybe in the future it might be? But currently the only way to get a similar UX is by sacrificing custody or privacy or both. This is I guess the crux of my gripe.

reply

I didn't find spinning up an Alby Hub to be much more difficult than that.

The only real extra step you have to take is opening a channel, but you can just pick a channel partner from a dropdown menu.

reply

If you are talking about dodging the watchful eye of the most powerful institutions on earth, I'm afraid that comes with a great deal of effort.

reply

Don't No kyc custodians mitigate fungibility issues? It's one thing to rely on custodians and it's another to use them effectively as a way to gain more utility for Bitcoin.

reply
10 sats \ 0 replies \ @anon 7 Oct

I use lightning, for me it is easy, and it is self-custodial also. I run bitcoin core and core lightning on a linux computer. Not everyone runs a node though.

lightning is easy to use by anyone, it is easy to use in a self-custodial way also if you have your own node.

It would be easy for people to use lightning in a self custody way without a node, even if they are not tech savy, if whatever app they are using simply supports opening lightning channels and connecting to lightning routers. If LN is hard to use in a self-custodial way I place blame on wallet developers for failing to simply implement what should be the basic funcitonality of what a lightning app should have.

reply
10 sats \ 0 replies \ @anon 7 Oct

I trust the UX will continue to improve and offer meaningful solutions. I also think for the vast majority of people, they are already KYC’d in, so holding small amounts of spending sats in a trusted custodial wallet for convenience isn’t a huge trade off imo. Even without pure self custody/privacy, bitcoin still offers so many other advantages. I absolutely agree with you from a purist/maxi/non-kyc coin holder perspective, but from a normie perspective, this won’t be a thought they have. Until the UX is there for you, though, I see the use case for swapping to something like Monero.

reply

FYI, someone reposted this on StasherNews today.

reply
1 sat \ 0 replies \ @mkmloom 7 Oct -30 sats

Noted crack