Withdrawals by miner vote
Moving coins out is slow on purpose: a long, public miner vote.
6 min readWithdrawals travel in bundles
To move coins back to L1, sidechain users request withdrawals on the sidechain. The sidechain periodically combines many requests into one withdrawal bundleWithdrawal bundleMany withdrawals from one sidechain combined into one L1 transaction. It pays everyone or no one.: a single L1 transaction that pays everyone. A bundle pays all of its withdrawals or none of them.
Propose (M3), then vote (M4)
A miner puts the bundle up for a vote with an M3M3 · Propose bundleA coinbase message that puts a withdrawal bundle up for a vote. It counts as the first vote. message. Miners vote on its M6 idM6 idThe identifier miners vote on for a bundle: the id of a "blinded" copy of the withdrawal transaction without its treasury input, which usually does not exist yet when voting starts., an identifier of the payout transaction, not on the transaction itself. Being proposed counts as its first vote.
From then on, each block carries an M4M4 · ACK bundlesA coinbase message with each block's withdrawal votes: upvote one bundle per sidechain, abstain, or raise an alarm. vote for every sidechain that has bundles pending. For each one, the miner can:
- Upvote one bundle. It gains a vote; the sidechain's other pending bundles each lose one.
- Abstain. Nothing changes. A block without an M4 counts as abstaining.
- Raise an alarm. Every pending bundle of that sidechain loses a vote.
Votes never drop below zero.
Pay out (M6), or expire
Once a bundle has more votes than the threshold, the payout transaction (M6M6 · WithdrawThe L1 transaction that pays out an approved bundle and returns the rest of the coins to a new treasury output.) can be included in a block. It spends the treasury, pays the withdrawals, and returns the rest to a new treasury output. A bundle that grows too old without passing is dropped and pays nothing.
It is a public countdown. Everyone can watch the votes for months before a single coin leaves, so a dishonest withdrawal cannot happen quietly.
The rules Betanet is running
Loading live data…
Withdrawals being voted on
Loading live data…
Withdrawal history
Loading activity…
Go deeper: how the M6 id hides the treasury input
When voting starts, the treasury output the payout will spend usually does not exist yet: more deposits may replace it. So the M6 id is computed from a "blinded" copy of the transaction with no inputs, and with the treasury output replaced by an output that records the total fee. The real payout must match it.
Each M4 can be encoded in several compact versions, such as "repeat the previous block's votes". The enforcer decodes them all to the same upvote, abstain and alarm choices.
Read the source
The rules in this lesson come from these documents and code:
Ask an AI assistant about this concept
Opens your assistant with a question about this concept and its sources already written. AI answers can be wrong: check them against the sources above. Your question goes to the assistant you choose, not to us.