Today's topic is machine payments. What happens when your software starts buying things by itself, and every payment it makes is written down in public, forever.
今日のテーマは、機械による支払いです。ソフトウェアが自分で買い物を始めて、その支払いが一件残らず公開の場に、永久に記録されるとどうなるか、という話です。
Software buying things by itself? Like a subscription renewing?
ソフトウェアが自分で買い物? サブスクの自動更新みたいなことですか?
Bigger. Imagine an assistant program — an agent — that goes off and buys the data it needs. It calls a news service, pays a fraction of a cent. Calls a market data service, pays again. No human clicking anything.
もっと大きな話です。助手のようなプログラム、いわゆるエージェントが、自分に必要なデータを買いに出かけると想像してください。ニュースの配信サービスを呼び出して、一セントの何分の一かを支払う。市況データのサービスを呼び出して、また支払う。人間は何もクリックしていません。
And that works today?
それ、もう動いているんですか?
It does. There's a standard for it called x four-oh-two. The name comes from an old web error code. When a server wants money before it answers you, it replies with the number four oh two, meaning "payment required."
動いています。そのための規格があって、エックス・フォー・オー・ツーと呼ばれています。この名前は昔からあるウェブのエラーコードに由来します。サーバーが答えを返す前にお金を求めるとき、フォー・オー・ツーという番号で返事をするんです。意味は「支払いが必要」です。
So the server says "that'll be one cent," and the program just pays.
つまりサーバーが「一セントいただきます」と言って、プログラムがそのまま払う、と。
Request, payment required, pay, get your answer. And here's the part worth ten minutes of your time. Those payments settle on a public ledger.
リクエスト、支払いが必要、支払う、答えを受け取る。そしてここからが、十分間かける価値のある部分です。それらの支払いは、公開された台帳の上で決済されます。
Public meaning anyone can look?
公開って、誰でも見られるということですか?
Anyone. Forever.
誰でも。しかも永久にです。
It's a few cents though. Who cares?
でも数セントですよね。誰が気にするんですか?
Nobody cares about the cents. People care about the pattern. Picture yourself watching one of these agents from outside. You can't see its code. You can only see its payments.
セントの額を気にする人はいません。みんなが気にするのはパターンの方です。こういうエージェントの一つを、外から眺めている自分を想像してみてください。コードは見えません。見えるのは支払いだけです。
Okay, I'm watching.
はい、眺めています。
Nine in the morning. It pays a news service. Three seconds later, a market data service. Five seconds after that, a trade execution service. Then silence. Fifteen minutes later, the same three payments, same order.
朝の九時。ニュースの配信サービスに支払います。その三秒後、市況データのサービスに。さらに五秒後、取引執行のサービスに。そして沈黙。十五分後、同じ三件の支払いが、同じ順番で。
Ohh. It reads the news, checks the market, then makes a move.
ああ。ニュースを読んで、相場を確認して、それから動いているんですね。
You just reverse-engineered somebody's trading strategy without seeing a line of their code. You saw four payments.
あなたはいま、誰かの取引戦略を、そのコードを一行も見ずに逆算しました。見たのは四件の支払いだけです。
That's unsettling.
それは落ち着かない話ですね。
And it cuts both ways. Look at the seller instead. If a company collects payments at one fixed address, anyone can count the money arriving there.
しかも、これは両方向に効きます。今度は売る側を見てみましょう。ある会社が一つの固定したアドレスで支払いを受け取っているなら、そこに届くお金は誰にでも数えられます。
Which tells you their revenue.
それで売上が分かってしまう。
Their revenue, their growth, whether business is up this month, and whether one big customer is carrying them. A competitor just watches the address and builds a chart.
売上も、成長率も、今月の事業が上向きかどうかも、一社の大口顧客に支えられているかどうかも。競合はそのアドレスを眺めているだけで、グラフを作れます。
Nobody agreed to publish any of that.
そんなことを公開すると誰も同意していないのに。
It's a side effect. The payment log becomes a strategy log. So that's the problem. Now let's look at one attempt to fix it, a project called SubEtha.
副作用なんです。支払いの記録が、戦略の記録になってしまう。これが問題です。では、これを解こうとしている一つの試みを見てみましょう。SubEtha というプロジェクトです。
And it makes payments invisible?
それは支払いを見えなくするんですか?
No. This is the most important sentence in the show, so I'll say it slowly. It does not hide the payments. Both ends of every payment stay completely visible.
いいえ。ここがこの番組で一番大事な一文なので、ゆっくり言います。支払いそのものは隠しません。すべての支払いの両端は、完全に見えたままです。
Then what does it hide?
では、何を隠すんですか?
The line between them. You see that a payer spent money. You see that a provider got paid. What is never written on that ledger is which payment became which deposit.
両者を結ぶ線です。支払った側がお金を使ったことは見えます。提供した側がお金を受け取ったことも見えます。その台帳に決して書かれないのは、どの支払いがどの入金になったのか、です。
Hang on. If I see money leave and money arrive, can't I match them up?
待ってください。お金が出て行くのも、届くのも見えるなら、突き合わせられるのでは?
Exactly the right question, and the honest answer is "sometimes." We'll come back to it. First, how the trick works. Three steps.
まさに正しい問いです。そして正直な答えは「時々はできる」です。あとで戻ってきます。まずは仕掛けの仕組みから。三段階あります。
Go.
どうぞ。
Step one. The agent calls the paid service. The service says "payment required," and hands back a price and an address to pay.
第一段階。エージェントが有料のサービスを呼び出します。サービスは「支払いが必要」と答え、価格と、支払い先のアドレスを返します。
Standard.
普通ですね。
Except that address is a decoy. It's generated for this one payment and never used again. It is not the company's real account.
ただし、そのアドレスはおとりです。この一回の支払いのためだけに生成され、二度と使われません。会社の本当の口座ではないんです。
So where does the money go?
では、お金はどこへ行くんですか?
Nowhere. It gets destroyed.
どこにも行きません。破壊されます。
Destroyed?
破壊?
The technical word is "burned." The agent sends money to that one-time address and it's gone, permanently. That's step two.
専門用語では「バーン」、焼却と言います。エージェントはその使い捨てのアドレスへお金を送り、それは永久に消えます。これが第二段階です。
I need you to explain why anyone would design that.
なぜそんな設計にするのか、説明してもらう必要がありますね。
Because of step three. Minutes later, completely separately, brand new money appears in the company's real account. Same amount.
第三段階があるからです。数分後、まったく切り離された形で、真新しいお金が会社の本当の口座に現れます。同じ金額で。
Money destroyed over here, money created over there.
こっちでお金が壊されて、あっちでお金が作られる。
And the record of the creation never says which destruction it came from.
そして、その「作られた」という記録は、どの「壊された」に由来するのかを決して語りません。
So the ledger says "somebody burned money," and separately, "somebody received money," with no arrow between them.
つまり台帳には「誰かがお金を焼いた」とあり、別のところに「誰かがお金を受け取った」とあって、その二つを結ぶ矢印がない。
That's the whole idea in one sentence.
それがこの仕組みの全体像を、一文で言い表したものです。
But how does the system know it's legitimate? Couldn't I just claim money appeared for me?
でも、システム側はそれが正当だとどうやって分かるんですか? 自分にお金が現れたと勝手に主張できてしまいませんか?
There's a mathematical proof attached. The technique is called a zero-knowledge proof. It lets you prove something is true without revealing the details behind it.
数学的な証明が添えられています。その技術はゼロ知識証明と呼ばれます。裏側の詳細を明かさずに、ある事柄が真実だと証明できる方法です。
Give me a normal-life version.
日常生活の例で言うと?
Proving you're over eighteen without showing your birthday.
誕生日を見せずに、十八歳以上であることを証明する、というようなものです。
So here it proves what?
では、ここでは何を証明しているんですか?
That a real payment was burned, for this amount, and this recipient is entitled to it — without revealing which burn it was. That fact stays sealed inside the proof.
本物の支払いが焼却されたこと、その金額であること、そしてこの受取人がそれを受け取る資格があること。ただし、どの焼却だったのかは明かさずに、です。その一点だけが証明の中に封じられたままになります。
So the money's real, the accounting works, but the link is missing.
お金は本物で、帳尻は合っていて、それでも繋がりだけが欠けている。
And notice money never moved directly from payer to company. That transfer doesn't exist on the ledger, so there is no direct record to look up.
そして注目してほしいのは、支払った側から会社へ、お金が直接動いた瞬間は一度もない、ということです。その送金は台帳の上に存在しないので、直接引ける記録がありません。
Now back to my question. Can I match them up anyway?
では、さっきの質問に戻ります。それでも突き合わせられますか?
Sometimes, yes. And the project states this limitation itself.
時々はできます。そしてこの限界は、プロジェクト自身が明示しています。
Where does it break?
どこで崩れるんですか?
Volume. And these are made-up numbers to show the shape of it, not measurements. Say it's a quiet day and exactly two payments happen. Two burns, two arrivals. Guessing which goes with which, you have a one in two chance.
件数です。それと、これから言うのは形を示すための架空の数字で、実測値ではありません。静かな一日で、支払いがちょうど二件だけ起きたとします。焼却が二つ、着金が二つ。どれとどれが対応するかを当てるなら、二分の一の確率です。
A coin flip. That's not hidden at all.
コイン投げじゃないですか。全然隠れていない。
Barely. Make it six payments, your odds drop to about one in six. Sixteen payments, about one in sixteen. The busier it is, the better it works.
ほとんど隠れていません。では六件にしてみましょう。当たる確率はおよそ六分の一に下がります。十六件なら、およそ十六分の一。混んでいるほど、よく効くわけです。
So it's weakest exactly when a small user needs it most.
つまり、小さな利用者が一番必要としている時に、一番弱い。
That's the honest shape of it. And nobody can promise you a number, because it depends on how busy the system is at that moment.
それが正直なところの形です。そして誰も具体的な数字を約束できません。その瞬間にシステムがどれだけ混んでいるかに左右されるからです。
What else stays visible?
ほかに、見えたままのものは?
Four things. First, amounts. Every amount is public. Pay eleven cents, the world sees eleven cents.
四つあります。一つ目は金額です。すべての金額が公開されます。十一セント払えば、世界には十一セントと見えます。
That's a clue by itself. If only one burn is eleven cents, and only one arrival is eleven cents...
それ自体が手がかりですね。十一セントの焼却が一つだけ、十一セントの着金も一つだけ、なら……
Then you've matched them. Second, the payer's own address is on the record. "This agent burned this amount at this time" is fully visible.
それで突き合わせ完了です。二つ目、支払った側のアドレスそのものが記録に残ります。「このエージェントが、この金額を、この時刻に焼いた」は完全に見えています。
So people know it's me spending. They just don't know who I paid.
つまり、私が使っていることは知られる。ただ、誰に払ったかが分からないだけ。
Precisely. Third, the company's real account is visible too, at the moment the new money appears. It's not a secret account.
その通りです。三つ目、会社の本当の口座も見えています。新しいお金が現れるその瞬間に。秘密の口座ではありません。
So both parties are identifiable. Only the pairing is missing.
では両方の当事者が特定できる。欠けているのは組み合わせだけ。
Only the pairing. And fourth, timing. Every event has a timestamp. If a burn happens and something arrives ninety seconds later, and nothing else is going on, you can guess.
組み合わせだけです。そして四つ目、時刻です。すべての出来事にタイムスタンプが付いています。焼却が起きて、その九十秒後に何かが着金して、ほかに何も起きていなければ、推測できてしまいます。
Amount plus timing would crack a lot of cases.
金額と時刻の組み合わせなら、かなりの数を破れそうですね。
When traffic is low, yes. Which is why this is not anonymity, and the project doesn't claim it is.
交通量が少なければ、そうです。だからこそ、これは匿名化ではありませんし、プロジェクトもそうは主張していません。
Somebody has to be running all this, right?
これ全体を、誰かが運用しているはずですよね?
Good instinct. There's a component in the middle called the facilitator. It generates those one-time addresses and handles settlement.
いい勘です。真ん中にファシリテータと呼ばれる構成要素があります。あの使い捨てのアドレスを生成し、決済を処理しているのがそれです。
And it sees everything.
そして、そこからは全部見えている。
Everything. It processes every payment, so it knows exactly who paid whom, the entire time.
全部です。すべての支払いを処理するので、誰が誰に払ったかを、常に正確に把握しています。
So the secrecy is against the public, not the operator.
では、秘密にされている相手は公衆であって、運用者ではない。
Hold that thought in your head. It's hidden from the crowd. It is not hidden from the referee. If you don't trust whoever runs that piece, none of this helps you.
その理解を頭に置いてください。群衆からは隠れています。審判からは隠れていません。その部分を運用している相手を信頼できないなら、この仕組みは何の助けにもなりません。
Good to hear that said out loud.
それを口に出して言ってもらえるのはいいですね。
One more piece of fine print, and it's sharp. Because the money is destroyed before the service is delivered, that destruction can't be undone.
もう一つ、細かい但し書きがあります。そして鋭いものです。サービスが提供される前にお金が破壊されるので、その破壊は取り消せません。
So if I pay and they don't deliver?
では、払ったのに提供されなかったら?
Once the payment is confirmed, your money is genuinely gone. No reverse button, no automatic refund.
支払いが確定してしまえば、あなたのお金は本当に消えています。取り消しボタンも、自動返金もありません。
That sounds scary.
怖い話に聞こえます。
Less than it sounds, because of the sequence. If settlement fails, nothing is delivered and your funds aren't consumed either. It fails safely in both directions.
聞こえるほどではありません。順序の作りのおかげです。決済が失敗した場合は、何も提供されず、あなたの資金も消費されません。両方向に対して安全に失敗するんです。
So it's either both or neither.
つまり、両方成立するか、どちらも起きないか。
Either both or neither, normally. The uncomfortable edge case is paying and then being refused. Then you're holding evidence, not a refund, and sorting it out is a manual conversation.
通常は、両方か、どちらも起きないか、です。居心地の悪い例外は、払ったうえで拒否された場合。その時あなたの手元に残るのは返金ではなく証跡で、解決は人の手による話し合いになります。
How finished is this? Can I use it tomorrow?
これ、どのくらい完成しているんですか? 明日から使えます?
No, and they say so plainly. The whole flow does work — you can run it end to end today, and there's a guided demo.
いいえ。そしてそれを、彼ら自身がはっきり言っています。流れ全体は確かに動きます。今日、端から端まで実行できますし、案内付きのデモもあります。
But?
でも?
But it only runs as a local setup on a developer's own machine. The software refuses to accept payments unless it's explicitly configured in local mode.
でも、開発者自身のマシン上でのローカル構成としてしか動きません。ローカルモードだと明示的に設定されていない限り、ソフトウェアは支払いの受け入れを拒否します。
It refuses? Deliberately?
拒否する? 意図的に?
Deliberately. Unlocking it isn't a settings change, it needs new code that hasn't been written and tested yet. They locked the door on purpose, and they tell you it's locked.
意図的にです。解除するのは設定変更ではなく、まだ書かれてもテストされてもいない新しいコードが必要です。彼らは意図して鍵をかけ、鍵がかかっていることを伝えているわけです。
Security review?
セキュリティの審査は?
Not audited. Their own words. No outside audit, and not built for real-money production use.
監査は受けていません。彼ら自身の言葉です。外部監査はなく、実際のお金を扱う本番用途に向けて作られてもいません。
So what's happening right now?
では、いま実際に進んでいることは?
Recruiting. They're looking for design partners — research teams, data providers, agent builders — to pressure-test whether the problem is real before building more.
募集です。デザインパートナー、つまりリサーチチーム、データ提供者、エージェントの開発者を探しています。さらに作り込む前に、この問題が本物かどうかを検証するためです。
And after that?
その後は?
A roadmap where nothing has shipped. Spending limits for agents. Approved-vendor lists. Requiring a human to approve big purchases. Later, compliance tools — voluntarily opening your records to an auditor for a limited window.
何一つ提供されていないロードマップがあります。エージェントごとの支出上限。承認済み取引先のリスト。大きな買い物には人間の承認を要求すること。その後にコンプライアンス機能、つまり自分の記録を、限られた期間だけ監査人に自発的に開示する仕組みです。
Private to the public, but openable when you need to prove something.
公衆に対しては伏せておいて、証明が必要な時には開ける、と。
That's the ambition. But not one of those has shipped, including the auditor feature.
それが目指すところです。ただし、そのどれ一つとして提供されていません。監査人向けの機能も含めてです。
Sum it up for me.
まとめてもらえますか。
Machine payments leak strategy, and this is one attempt to reduce that leak by removing a specific link from the public record. It is not anonymity. Amounts are public, both parties are visible, the operator sees everything, and it's weakest when traffic is thin.
機械による支払いは戦略を漏らします。そしてこれは、公開の記録から特定の繋がり一つを取り除くことで、その漏れを減らそうとする一つの試みです。匿名化ではありません。金額は公開、両方の当事者は見えていて、運用者からは全部見えていて、そして交通量が少ないときに最も弱くなります。
And it's early.
しかも、まだ初期段階。
Very early. Local only, unaudited, and documented as such by the project.
非常に初期です。ローカル限定、未監査、そしてそのようにプロジェクト自身が文書化しています。
Where do we leave people?
聞いている人には、何を持ち帰ってもらいましょう?
With a question. As more software spends money on our behalf, the ledger quietly becomes a record of what all our machines are doing, and why. Somebody has to decide how much of that stays public.
一つの問いを。より多くのソフトウェアが私たちに代わってお金を使うようになるほど、台帳は静かに、私たちの機械たちが何をしていて、それはなぜなのか、という記録になっていきます。そのうちのどれだけを公開のままにするのか、誰かが決めなければなりません。
Bigger question than a few cents.
数セントよりずっと大きな問いですね。
It always was. One last note. Everything today is our own reading of a public project. This is an independent explainer, not an official statement, and nothing here is investment advice.
最初からそうでした。最後に一つ。今日お話ししたことはすべて、公開されているプロジェクトについての私たち自身の読み解きです。これは独立した解説であって公式見解ではなく、また投資助言でもありません。
Thanks for walking me through it.
案内してくれてありがとうございました。
Thanks for the awkward questions. See you next time.
答えにくい質問をありがとうございました。それではまた次回。