mirror of
https://github.com/logos-co/assembly.git
synced 2026-08-27 11:11:08 +00:00
Rework thesis draft into threat-model forum post per comms feedback; economics deferred to whitepaper
This commit is contained in:
@@ -9,7 +9,7 @@ It is important to have clarity on who is coordinating around any given [[artifa
|
||||
|
||||
| Article | Component | Status | Target | Audience | Links |
|
||||
|---------|-----------|--------|--------|----------|-------|
|
||||
| [[prifi-thesis-forum-draft\|The Transaction Supply Chain Thesis]] | All modules / PriFi narrative | **First Draft — adversarially reviewed** (3 rounds) | forum.logos.co post + companion tweet; supersedes tweet storm as primary | Forum audience, institutional-crypto, privacy researchers | [[prifi-thesis-forum-draft\|Draft]] |
|
||||
| [[transaction-supply-chain-threat-model-draft\|The Transaction Supply Chain: A Threat Model]] | All modules / PriFi narrative | **First Draft** (reworked from thesis draft per Jonny: threat-model-first, economics deferred to whitepaper) | forum.logos.co research post + companion tweet; coalition/KOL engagement | Research forum, savvy KOLs, privacy researchers | [[transaction-supply-chain-threat-model-draft\|Draft]] |
|
||||
| [[prifi-supply-chain-tweetstorm-draft\|PriFi Tweet Storm: The Transaction Supply Chain, Module by Module]] | All modules / PriFi narrative | **First Draft — on hold** | Rework as amplification after forum thesis posts | X audience, crypto-privacy general | [[prifi-supply-chain-tweetstorm-draft\|Draft]] |
|
||||
| [[validated-data-feeds-draft\|Validated by Default: Why Logos Treats Every Data Feed Like a Blockchain Transaction]] | Logos Core / Architecture | **First Draft** | TBD | Developers, cryptographers, protocol engineers | [[validated-data-feeds-draft\|Draft]] |
|
||||
| [[privacy-preserving-file-sharing\|Introducing Logos Storage: Decentralized Storage for the Logos Tech Stack]] | Storage | **First Draft** | After above | Developers, infrastructure engineers, privacy engineers | [[privacy-preserving-file-sharing-draft\|Draft]] |
|
||||
|
||||
@@ -1,133 +0,0 @@
|
||||
# The Transaction Supply Chain Thesis
|
||||
|
||||
*Draft of a forum.logos.co post. Companion tweet at the bottom. Status: revised through three rounds of adversarial review.*
|
||||
|
||||
---
|
||||
|
||||
Here's a claim I want you to attack: **securing the full supply chain of a transaction unlocks more value than anything else this industry is building.** A transaction is seven jobs, from finding a counterparty to enforcing the outcome, and crypto secured exactly one of them. Not because privacy is a right (it is, but that argument doesn't move markets), and not because surveillance is creepy (it is, but people shrug). Because transaction costs are the most leveraged variable in economics, an unsecured transaction supply chain is a permanent transaction cost, and nobody has secured one end-to-end. Yet.
|
||||
|
||||
That's the thesis, and yes, the superlative is a provocation with a purpose: if you think something else on this industry's roadmap beats it, price yours and we'll compare. The rest of this post is the argument, the numbers, and the parts I think are most attackable. I'd rather have this fight in public, so bring it.
|
||||
|
||||
## Part 1: The economics, or why this is about money and not ideology
|
||||
|
||||
Start with Coase. [The Nature of the Firm](https://onlinelibrary.wiley.com/doi/10.1111/j.1468-0335.1937.tb00002.x) (1937) asked why firms exist at all if markets are efficient, and the answer reshaped economics: coordination is expensive. Finding a counterparty, verifying them, negotiating, committing, executing, and enforcing all cost something, and organizations exist precisely to lower those costs. Firms, banks, courts, exchanges: every institution you can name is a machine for making exchange cheaper. This train ends at your mempool.
|
||||
|
||||
[Dahlman (1979)](https://www.jstor.org/stable/725216) sorted transaction costs into three buckets: search and information costs, bargaining and decision costs, policing and enforcement costs. And [Kovač and Spruk](https://www.cambridge.org/core/journals/journal-of-institutional-economics/article/abs/institutional-development-transaction-costs-and-economic-growth-evidence-from-a-crosscountry-investigation/50630A6113E3A5A556F1588CD8EE9EDB) (Journal of Institutional Economics, 2016) found a persistent, robust negative effect of transaction costs on long-run growth across countries. Frictions taxed on every exchange in an economy compound forever. So do reductions.
|
||||
|
||||
Now the part economists already know but this market keeps forgetting: institutions lower transaction costs by making credible commitments. [North and Weingast's](https://www.cambridge.org/core/journals/journal-of-economic-history/article/abs/constitutions-and-commitment-the-evolution-of-institutions-governing-public-choice-in-seventeenthcentury-england/2E0D2B2D3490BE5C556D836ACB096362) classic study of England after 1689 showed that when the Crown became constitutionally unable to default at will, its borrowing costs collapsed and its capital markets exploded. The commitment did the work. Nothing about the underlying economy changed; what changed is that promises became structurally hard to break.
|
||||
|
||||
There are two flavors of credibility, and the distinction carries this whole thesis. **Motivational credibility**: the institution can break its promise but has reasons not to. **Imperative credibility**: the institution cannot quietly break its promise, because violations are prohibitively costly or publicly detectable. (Detectable, note, not "everything is public." That difference matters later.) Swiss banking secrecy was motivational, and it broke from the inside: a single UBS banker walked into the DOJ as a whistleblower in 2007, the deferred-prosecution agreement landed in 2009, FATCA followed in 2010, automatic information exchange after that. A promise with centuries of tradition and statute behind it held through wars and superpower pressure, then unraveled the moment one insider's incentives flipped. That's the thing about reasons-not-to: they can hold for a very long time, and you can't price when they stop.
|
||||
|
||||
Capital knows what commitments are worth, and it pays for them. [Dharmapala and Hines](https://www.nber.org/papers/w12802), studying which jurisdictions become tax havens, found that governance quality, not the tax rate, is the predictor: for a typical small country, moving from Brazil-level to Portugal-level governance raises the probability of being a haven from 24% to 63%, and low taxes only attract capital when paired with governance credible enough to commit against expropriation. [Hines (2005)](https://www.nber.org/papers/w10936) found haven economies grew 3.3% a year per capita against a 1.4% world average across 1982-1999, 2.4x the rate.
|
||||
|
||||
There's a wrinkle in this literature worth stating plainly, because it's the pattern I'll claim capital repeats onchain. After 2008, the havens that kept winning were the ones that sold credible *compliance* alongside confidentiality. Capital doesn't buy maximal opacity. It buys credible commitments about information: who gets to see what, under which rules, with what assurance the rules hold.
|
||||
|
||||
The obvious counterargument to all of this is that regulators will just enforce it away. The record is more specific than that. [Johannesen and Zucman (2014)](https://www.aeaweb.org/articles?id=10.1257/pol.6.1.65) studied the G20's coordinated crackdown on bank secrecy and found deposits didn't come home; they moved to the havens that hadn't signed. The broader coordination that followed (the Common Reporting Standard) genuinely compressed offshore bank secrecy, and the response was another migration of venue, not a homecoming. So the honest lesson cuts both ways: enforcement works where coordination reaches, and demand for confidential capital keeps relocating to whichever venue offers the most credible combination of confidentiality and legitimacy. Competition among institutions for capital is the standing condition. The only question is which institutions win it.
|
||||
|
||||
So here's the setup. Blockchains entered this landscape and did something new: they moved one link of the transaction, settlement, dramatically toward the imperative end of the spectrum. It is a spectrum, not a binary; Ethereum rolled back the DAO by social consensus in 2016, and every protocol has developers, foundations, and upgrade paths. But "hard-forking a global chain in public" and "a bank quietly amending its ledger" are different universes of difficulty, and capital noticed. An asset class measured in trillions grew up around that property. To be clear about the inference: not all of that value prices settlement assurance, and plenty of it is monetary premium and speculation. But the premise underneath the premium, the reason the industry exists to speculate on at all, is that self-enforcing settlement was worth building on.
|
||||
|
||||
A transaction is not settlement, though. A transaction is seven jobs: **discovery** (finding who has what you want), **diligence** (verifying they are who they claim), **negotiation** (agreeing price and terms), **contracting** (committing in enforceable form), **ordering** (deciding whose trade goes when), **settlement** (moving the value), and **enforcement** (making the outcome stick). Loosely, that's Dahlman's buckets unpacked: search costs up front, bargaining costs in the middle, enforcement at the end. Blockchains secured settlement. One link. The other six run on infrastructure that watches, logs, and leaks.
|
||||
|
||||
Call the resulting tax **exposure cost**: what you pay because doing every job on transparent rails leaks information that someone else monetizes against you. MEV is exposure cost. Getting front-run is exposure cost. Being deanonymized retroactively, targeted for what you hold, censored for who you are: exposure cost. And the fix for exposure cost is not opacity. The fix is control: nothing leaks except what you choose to disclose, to whom, provably. Keep the thesis in that form, because it's the form the haven literature supports: capital pays for credible commitments about information, and "disclosed only under rules I agreed to" is such a commitment. "Visible to everyone, forever, by default" is not.
|
||||
|
||||
Two claims before the walk-through, and keep them separate. First: partial fixes buy real harm reduction. They do, and the data below shows it. Second: only full coverage turns controlled disclosure from a mitigation into a commitment, because an *unchosen* leak anywhere in the chain voids the control everywhere else. A levee covering 80% of the shoreline still floods the town. Your privacy is bounded by the leakiest link you didn't choose; your security by the weakest link you can't verify. Whether capital prices that difference, commitment versus mitigation, is the bet this whole post is making, and I'll mark it as a bet every time it appears. Patch one link and the leak moves to the next; that's the recurring structure of this industry's biggest failures, and I'll walk each link to show it.
|
||||
|
||||
## Part 2: The threat model, link by link
|
||||
|
||||
For each link: what leaks today, who collects it, what it costs, and what we're building at Logos to close it. I'll flag what runs today versus what's roadmap, because a thesis that hides its schedule behind the present tense isn't a thesis, it's marketing. And yes, you'll notice Logos has a module per link. Read that as suspicious tailoring if you like, then attack the decomposition itself; that's fair game and there's an attack surface for it below. Fuller sourcing for the lifecycle claims is in [The Anatomy of Exposure](https://blog.logos.co/article/how-blockchain-transactions-leak-data).
|
||||
|
||||
### 1. Discovery
|
||||
|
||||
Finding who has what you want happens through browsers, wallets, and hosted frontends, all of which leak. Your browser fingerprint, your IP, your wallet's balance queries, and the trackers embedded in nearly every dapp frontend tell an observer what you're interested in before you've committed to anything. Traditional finance treats intent as radioactive: institutional block trades route through dark pools specifically so the market doesn't see them coming, and [off-exchange trading overall has grown to roughly half of US equity volume](https://www.nasdaq.com/articles/exchange-trading-increases-across-all-types-stocks). Onchain, intent leaks by default.
|
||||
|
||||
The Logos answer is [Basecamp](https://blog.logos.co/article/logos-basecamp): the interface runs locally on hardware you control. No hosted frontend, no trackers, no third party between you and the network. Live today; it's the same application node operators already run on the testnet.
|
||||
|
||||
### 2. Diligence
|
||||
|
||||
Verifying a counterparty onchain requires no verification work at all, because the chain-analytics sector has already built the dossier: address clustering, cross-chain tracing, behavioral fingerprinting, sold to exchanges, trading firms, and governments. [The market leader alone books hundreds of millions a year](https://sacra.com/c/chainalysis/) doing it. Your address history is the identity graph, and it cuts in both directions: [address-poisoning attacks](https://arxiv.org/abs/2501.16681), which exploit exactly this graph legibility, drew 270 million attempts across Ethereum and BSC over two years and cost users at least \$83.8M.
|
||||
|
||||
The graph has two halves, and the split is the insight. The off-chain half is tracker telemetry, frontend logs, and the IP-to-address pairings that hosted interfaces hand to their operators; Basecamp closes the interface part of that now (your node still speaks from your own IP until propagation privacy ships; see link 5). The onchain half is the permanent record itself, and no interface can fix that. That's the settlement story below.
|
||||
|
||||
### 3. Negotiation
|
||||
|
||||
Size, terms, and reservation price leak through the channels we negotiate in. Telegram retains metadata even when content is encrypted. Public mempools broadcast your terms before execution. The market has voted on whether this matters: [roughly 80% of Ethereum DeFi interactions now route through private RPCs](https://arxiv.org/abs/2505.19708), per a CoW DAO research paper, to keep intent out of the public mempool. Notice what that workaround actually did, though: it moved the flow from a public mempool to a handful of private operators who now see everything. The leak relocated. It didn't close. That's the weakest-link dynamic in miniature, and it's why patches keep producing new trusted parties instead of fewer.
|
||||
|
||||
[Logos Messaging](https://docs.logos.co/) is built for private, peer-to-peer counterparty discovery and coordination, with anonymity as a design requirement rather than an add-on. It's the most battle-tested lineage in the stack: the protocol it grew from (Waku) has run in production for years, integrated by RAILGUN and Status.
|
||||
|
||||
### 4. Contracting
|
||||
|
||||
The moment of commitment is the moment of maximum exposure. [RPC providers log your IP against your wallet address](https://www.theblock.co/post/189717/consensys-says-it-collects-ip-addresses-of-metamask-users-via-infura); their own privacy policies say so. The frontend you sign on is unverifiable: DNS, hosting, and script injection make every signature an act of faith. [Bybit lost \$1.5B in 2025](https://www.cnbc.com/2025/02/21/hackers-steal-1point5-billion-from-exchange-bybit-biggest-crypto-heist.html) and the chain worked flawlessly the entire time; the compromise sat in the signing infrastructure around it. [Wallet-drainer phishing ran to \$494M in 2024 alone](https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/) on the same principle. Neither of those two is a privacy leak; they're integrity failures in the contracting layer, and I'm citing them for the shape of the problem, not booking them to privacy's account. The chain has to hold against both reading and rewriting, and the same unverifiable infrastructure enables both. (Whether verifiable frontends would have saved Bybit's particular multisig setup is arguable; that the signing surface is where the money dies is not.)
|
||||
|
||||
Logos Storage is being built to close this: content-addressed frontends whose integrity you verify before signing, served from the decentralized stack itself. Honest status: file sharing runs on testnet today; serving verifiable frontends is roadmap, targeted later this year.
|
||||
|
||||
### 5. Ordering
|
||||
|
||||
Your pending transaction sits in a public mempool that gets archived wholesale; [one firm accumulated over 15TB of mempool history](https://web.archive.org/web/2025/https://www.blocknative.com/blog/blocknatives-historic-mempool-data) before winding down, [its team absorbed into Deloitte](https://www.theblock.co/post/401912/deloitte-absorbs-blocknative-team-as-crypto-infra-firm-winds-down-apis-and-gas-network). The archives don't decay; who holds them just changes. [Two builders assemble the large majority of Ethereum blocks](https://explorer.rated.network/builders) and read strategy straight out of calldata. [Sandwich attacks have extracted \$400M+ from Ethereum users](https://eigenphi.io/mev/ethereum/sandwich) by EigenPhi's count, and total MEV extraction since 2020 runs to billions. Ordering is the most nakedly monetized leak in the chain.
|
||||
|
||||
The Logos design splits this problem the way it actually decomposes. Whoever *proposes* the block is a target, so Blend, live in testnet v0.2, anonymizes block proposals: an anonymous broadcast layer purpose-built for that one job, layered encryption, cover traffic, randomized delays, with latency measurement and parameter tuning ongoing on testnet. (Blend is operator privacy, not transaction privacy, and it is not a general mixnet; a proper mixnet is being built into the Logos networking layer for the stack's other traffic, and that's where transaction propagation privacy will live.) And ordering itself stops being a global auction: each Zone, an application-level execution environment on Logos, orders its own transactions, with decentralized sequencing delivered as a working proof-of-concept through the Zone SDK in v0.2.
|
||||
|
||||
### 6. Settlement
|
||||
|
||||
The one link crypto secured, and it secured it by publishing everything. Balances, approvals, positions, and validators sit in public, permanently. The ledger is the disclosure, and every transparent settlement layer is a standing subsidy to the analytics sector in link two, forever, retroactively, because analysis improves every year against a record that can't decay.
|
||||
|
||||
Here's where the parenthetical from Part 1 pays off. Imperative credibility requires that violations be detectable, not that everything be public. England's 1689 fix made the Crown's finances *more* visible; Bitcoin published everything. Both bought detectability with total visibility because that was the only technology available. Zero-knowledge proofs are the first technology that separates the two: you can verify the rules were followed without seeing the contents. That separation is the entire technical thesis in one sentence.
|
||||
|
||||
[Cryptarchia](https://blog.logos.co/article/anonymous-block-proposers) plus Blend is Private Proof of Stake built on it: leader election run in zero-knowledge, designed so proposers can't be linked to their stake, with no published validator registry, while the proof that consensus rules were followed stays publicly checkable. The guarantee is honest: expensive to break, not impossible, and long-horizon stake inference is an open research line the team works on in public. Running on testnet now, where private transfers already work in the execution zone. Full programmable privacy, the piece that closes the ledger-as-disclosure leak for applications, is the roadmap beyond that.
|
||||
|
||||
### 7. Enforcement
|
||||
|
||||
Whoever operates the infrastructure can be pressured, and identifiable operators get pressured one by one. At the post-Merge peak, [nearly 80% of Ethereum blocks flowed through OFAC-compliant relays](https://www.mevwatch.info/). Swiss secrecy broke from the inside through one incentivized insider. And architecture has pressure surfaces too: developers are nameable, foundations have addresses, fiat ramps are chokepoints. The design goal is not zero squeeze points, which don't exist; it's ensuring no single squeeze point breaks user protection when squeezed. That's the difference between a system that degrades under pressure and one that folds. Applied consistently, this standard says something uncomfortable: a project is motivationally credible at the organizational level until it can survive its own org. That's the bar, it's why everything here is open source, and Logos hasn't cleared it yet either. Nobody has.
|
||||
|
||||
Logos separates the layers accordingly. The base settlement layer minimizes what there is to squeeze: anonymous proposers, no published validator registry, minimal execution. Disclosure is meant to live in Zones, which choose their own rules, selective and voluntary; that's design intent, stated here so you can hold us to it, not shipped compliance machinery. And note that on the control framing, a Zone's chosen disclosure isn't a hole in the guarantee: the guarantee was never secrecy, it's that nothing leaks *except what you choose, to whom, provably*. A regulator you disclose to by agreement is a counterparty; a mempool archive you never consented to is a leak. The weakest-link claim is about the second kind.
|
||||
|
||||
### The loop
|
||||
|
||||
One more structural fact, because it's why partial fixes decay. The chain of links isn't a line, it's a cycle. Everything archived from this transaction's leaks becomes the discovery and diligence input against your next transaction, and against everyone who has ever touched your addresses. The surveillance economy is the loop closing. This is why the weakest-link property compounds instead of merely persisting, and why "we'll add privacy later" is a plan to be retroactively deanonymized.
|
||||
|
||||
## Part 3: What securing the chain is worth
|
||||
|
||||
Add it up, and keep the categories honest. Exposure costs, the tax this thesis is actually about: billions in MEV extraction since 2020, \$400M+ of it sandwiches; \$83.8M in address poisoning; a surveillance sector whose product sharpens every year the record grows. Adjacent integrity failures on the same unsecured infrastructure, cited for shape rather than booked to privacy's account: \$1.5B in a single contracting compromise, \$494M in drainer phishing in one year. That's the direct ledger, and it's the small number.
|
||||
|
||||
The large number is the institutional one, and I won't fake a figure for it; the point is the shape. The credible-commitment literature says capital pays for commitments, grows faster where they exist, and relocates rather than complying when suppressed. Those are jurisdiction-level results; whether they transfer to protocols is attack surface material below, and I'm using them for direction, not magnitude. The direction says: the substrate that extends credible commitment about information across all seven links doesn't collect a fee, it collects a migration. Look at behavior: four-fifths of DeFi flow routes around the public mempool, and half of US equity volume executes away from lit exchanges. Most of that is capital avoiding being front-run, exposure cost in its narrowest form, handled today by trusted intermediaries. The bet, marked as a bet, is that the same logic extends up the chain as stakes rise: the capital with the most to lose from exposure eventually wants the commitment version, not the trust-me version. Wei Dai (now at 1kx) [argued in a 2022 essay](https://wdai.us/posts/navigating-privacy/) that privacy is "the final hurdle to wide-scale adoption" of public blockchains; he's a privacy investor talking his book, so discount accordingly. All that tokenizable capital in everyone's TAM slides isn't waiting for faster blocks. It's waiting for rails it can commit to without disclosing its entire strategy to every counterparty, competitor, and adversary simultaneously.
|
||||
|
||||
And yes, securing the chain costs something per transaction: cover traffic, proving overhead, propagation delay. The bet is that a bounded latency cost beats an unbounded exposure cost. If you think the overhead outruns the leak, that's attack surface material below.
|
||||
|
||||
Settlement-only credibility bootstrapped this industry. Full-chain credibility offers the same trade six more times, and no, the links aren't symmetric: settlement had no substitute when Bitcoin shipped it, while several other links have cheap partial mitigations already priced in. The bet is not that each link pays like settlement did. It's that control over disclosure, which no combination of mitigations adds up to, is what the most exposure-sensitive capital ends up paying for. That's falsifiable, and the falsifier is named below.
|
||||
|
||||
## What would break this thesis
|
||||
|
||||
This is the part where I tell you where to aim. Seven attack surfaces, fittingly, in rough order of lethality:
|
||||
|
||||
**The compliance kill.** Regulated capital operates under AML, KYC, and travel-rule obligations, and the obligation attaches to the rail, not just the app: under current FATF-style guidance, a privacy-by-default base layer may be per-se unbankable no matter what provable disclosure sits on top. The precedents: Monero and Zcash delisted from major exchanges; Tornado Cash sanctioned in 2022 (delisted in 2025 after the courts pushed back, its developers prosecuted on both sides of the Atlantic).
|
||||
|
||||
The harsher version: if institutions end up transacting in disclosed Zones anyway, you can argue the anonymous base is load-bearing only for retail users the institutional thesis isn't about. My answer is that a disclosed annex on a squeezable base inherits the squeeze, so base-layer neutrality is exactly what makes Zone-level commitments credible; that argument deserves its own post, and the honest status is that institution-grade provable compliance over an anonymous base is design-stage work.
|
||||
|
||||
Also honest: the confidential-capital demand documented in the haven literature is heavily tax-evasion capital, which is precisely the demand regulated institutions can't be. If you work in compliance, this is the surface to sharpen.
|
||||
|
||||
**The adverse-selection objection.** The transaction-cost tradition says information *asymmetry* raises costs: verifiable public history is part of why onchain lending can price collateral instantly and market makers quote tight. The analytics sector I've been kicking is, in part, the diligence infrastructure that lets regulated capital touch crypto at all. Anonymity-by-default could raise search, diligence, and enforcement costs even as it lowers exposure costs. The control framing is the answer on offer: prove what the counterparty needs (solvency, ownership, rule-compliance) without publishing everything else, so diligence stays cheap while exposure dies. But whether selective proofs can actually substitute for open history at market scale is unproven, the net is uncomputed, and this is the sharpest purely economic objection I know of.
|
||||
|
||||
**The comparative.** The headline says "more value than anything else this industry is building" and the body never prices the alternatives. Stablecoins are the strongest counterexample: trillions in settlement volume on fully transparent, compliant rails, with institutional adoption accelerating right now. Some of the most commitment-hungry capital in the industry is visibly not waiting for privacy. My reading is that stablecoin flow is capital for which exposure cost is currently low, and the migration argument concerns the capital for which it's high. That reading is falsifiable, and here's the falsifier for the whole thesis: if tokenized institutional flow keeps compounding on transparent rails for years after full-chain substrates ship and sit idle, I'm wrong, measurably and publicly.
|
||||
|
||||
**The analogy gap.** The haven-economics results are about geographic jurisdictions competing on legal credible commitments, and jurisdictions have an accrual mechanism: banks, employment, GDP. A protocol "collecting a migration" needs its own story for who captures the value and how, and this post doesn't supply one. If you think capital treats architectural guarantees as categorically different from legal ones, or that the accrual story can't be told, that's a real objection; argue it.
|
||||
|
||||
**The weakest-link claim.** I've separated commitment from harm reduction, but you can attack the separation itself: maybe capital doesn't price the difference, and an 80% solution captures most of the value. The private-RPC data is evidence for you here (a cheap patch, massively adopted, capturing real value), and there's a stronger version still: dark pools and private RPCs show sophisticated capital satisfied with *accountable trusted intermediaries*, the exact institutional form this thesis bets against. My answer, that trusted intermediaries hold only while trust holds and law reaches, and that the logging-subpoena-breach record is the counter-ledger, is a mechanism claim you can test. There's also a scope limit to concede: the supply chain extends past any protocol, into your OS, your browser, the conference hallway where you first mentioned the deal. No stack closes those links. The claim is scoped to every link a protocol can reach; if you think the unreachable links dominate the threat model, that's a real objection too. And the self-referential version: until Logos ships every link, Logos is itself a partial fix by this post's own logic. If a composition of partial fixes gets institutional capital moving before any full-chain substrate ships, this thesis is wrong.
|
||||
|
||||
**Revealed preference cuts both ways.** I read dark pools and private RPCs as demand for exposure reduction; both have alternative readings (execution quality, MEV cost avoidance), and I've conceded most of that flow is avoiding front-running rather than buying confidentiality as such. On the direct evidence from privacy chains: Zcash's shielded usage, [a minority of its chain's activity for years, surged through 2025-26 to a majority of transactions](https://crypto.news/why-30-of-zcash-supply-is-now-in-the-shielded-pool/) (~59% of transactions by February 2026, ~30% of supply shielded). Read that as privacy demand arriving or as a bull-market rotation; I'm letting this datum count in both directions, so on the record: if shielded adoption collapses next cycle, that's evidence against the demand story, and I'll treat it that way. Separately, the design argument stands on its own: privacy you opt into marks you as someone with something to hide, and the crowd you hide in is only the others who opted in. Default-on is a different product.
|
||||
|
||||
**The delivery risk.** Parts of this run today (Blend and Cryptarchia's PPoS with private transfers on testnet, Messaging's protocol lineage in production, Basecamp) and parts are roadmap (verifiable frontends, programmable privacy, Zones' disclosure machinery). Meanwhile Aztec, Penumbra, Zcash, and Ethereum's own privacy roadmap ship subsets now, and privacy has a bootstrap problem the loop makes worse: anonymity sets are only as strong as the crowd, competitors have a head start on users and liquidity, and every year of delay adds to the archive that gets replayed against late arrivals. The integrated-stack bet has to beat best-of-breed composition, not just exist. If you think the unshipped parts are the load-bearing ones, or that composition wins, those are the critiques we'd learn the most from.
|
||||
|
||||
Bring better numbers if you think mine are wrong. Bring a better frame if you think the frame is wrong. People have strong opinions about their money; this is the place to have them.
|
||||
|
||||
---
|
||||
|
||||
## Companion tweet (drives to forum)
|
||||
|
||||
Blockchains secured settlement, and a multi-trillion-dollar asset class grew on that single credible commitment.
|
||||
|
||||
A transaction has seven links. The other six still leak, and the failures have cost billions.
|
||||
|
||||
The thesis, the numbers, and seven ways to attack it: [FORUM LINK]
|
||||
|
||||
---
|
||||
|
||||
*Notes for reviewers: revised through three adversarial review rounds (debate artifacts and summary in the private repo). The round-3 structural move: the thesis is restated as control over disclosure rather than opacity, which reconciles the weakest-link claim with Zones (a chosen, provable disclosure is a counterparty relationship, not a leak), aligns the thesis with what the haven literature shows capital buying, and gives the adverse-selection surface its answer. The guarantee-premium claim is now marked as the post's central bet everywhere it appears, and the thesis carries a named falsifier. Known weaknesses left open by design: the headline comparative is a provocation, not a priced ranking; the adverse-selection net is uncomputed; the value-accrual story is deferred; org-level motivational credibility is conceded as uncleared by anyone including Logos. Capability status per the public roadmap and v0.2 announce draft, 2026-07-17.*
|
||||
@@ -0,0 +1,103 @@
|
||||
# The Transaction Supply Chain: A Threat Model
|
||||
|
||||
*Draft of a forum.logos.co research post. Companion tweet at the bottom. Status: First Draft (reworked from the earlier thesis draft per comms feedback: higher-level, threat-model-first, economic argument deferred).*
|
||||
|
||||
---
|
||||
|
||||
Everyone in this industry threat-models the contract. Auditors crawl the bytecode, formal verification gets funded, bug bounties pay seven figures. Almost nobody threat-models the *transaction*: the full chain of work that has to happen for an exchange to happen and hold. That chain is where the money actually dies. [Bybit lost \$1.5B](https://www.cnbc.com/2025/02/21/hackers-steal-1point5-billion-from-exchange-bybit-biggest-crypto-heist.html) while the contracts executed flawlessly.
|
||||
|
||||
A transaction is seven jobs: **discovery** (finding who has what you want), **diligence** (verifying they are who they claim), **negotiation** (agreeing price and terms), **contracting** (committing in enforceable form), **ordering** (deciding whose trade goes when), **settlement** (moving the value), and **enforcement** (making the outcome stick). Blockchains secured settlement. The other six run on infrastructure that watches, logs, and leaks.
|
||||
|
||||
This post maps the threat model for the whole chain: who's watching each link, what they gain, what it costs you, and why the patches on offer keep failing in the same way. I'm deliberately not arguing what closing the chain is worth; that argument deserves its own treatment and it's coming. This is the map. I want the forum's help stress-testing it, so the last section is open questions, and I mean them as questions.
|
||||
|
||||
## The adversaries
|
||||
|
||||
Four classes, distinguished by what they want and how long they'll wait. A useful threat model has to hold against all four at once, because they feed on the same substrate: the observable record of you transacting.
|
||||
|
||||
**The archivist** collects everything and monetizes it later. Chain-analytics firms cluster addresses, trace across bridges, and fingerprint behavior; [the market leader alone books hundreds of millions a year](https://sacra.com/c/chainalysis/) selling the graph to exchanges, funds, and governments. Mempool observers archive pending transactions wholesale; [one firm accumulated over 15TB of mempool history](https://web.archive.org/web/2025/https://www.blocknative.com/blog/blocknatives-historic-mempool-data) before winding down, [its team absorbed into Deloitte](https://www.theblock.co/post/401912/deloitte-absorbs-blocknative-team-as-crypto-infra-firm-winds-down-apis-and-gas-network). [RPC providers log your IP against your wallet address](https://www.theblock.co/post/189717/consensys-says-it-collects-ip-addresses-of-metamask-users-via-infura); it's in their privacy policies. The archivist's defining property: patience. The record can't decay, analysis improves every year, and what's safe against today's techniques is not safe against 2035's.
|
||||
|
||||
**The extractor** monetizes visible flow in real time. [Two builders assemble the large majority of Ethereum blocks](https://explorer.rated.network/builders) and read strategy straight out of calldata. MEV searchers watch the mempool and trade against you before you execute; [sandwich attacks alone have extracted \$400M+](https://eigenphi.io/mev/ethereum/sandwich) by EigenPhi's count, with total MEV extraction since 2020 in the billions. The extractor's defining property: speed. It doesn't care who you are, only what you're about to do.
|
||||
|
||||
**The predator** uses leaked information to steal directly. [Wallet drainers took \$494M in 2024](https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/) through phishing and malicious signatures. [Address-poisoning attacks](https://arxiv.org/abs/2501.16681) exploited transaction-history legibility 270 million times across Ethereum and BSC in two years, taking at least \$83.8M. And the leak goes kinetic: physical-coercion attacks against identified holders are a documented, growing category. The predator's defining property: targeting. Every leaked balance, position, and address pairing is target-selection data.
|
||||
|
||||
**The enforcer** pressures identifiable operators. At the post-Merge peak, [nearly 80% of Ethereum blocks flowed through OFAC-compliant relays](https://www.mevwatch.info/), assembled one squeezable intermediary at a time. This class plays by different rules: it doesn't need to break anything technical, only to find a nameable operator with something to lose. Its defining property: leverage. It attacks the people and companies around the protocol, not the protocol.
|
||||
|
||||
Notice what the four classes share. None of them breaks cryptography. The contract-level security this industry is good at is simply not where any of them operates.
|
||||
|
||||
## The chain, link by link
|
||||
|
||||
For each link: what leaks, who's watching, the observed damage, and the mitigation on offer today, with its trust assumption named. The trust assumptions are the point; watch what they have in common.
|
||||
|
||||
### 1. Discovery
|
||||
|
||||
Finding who has what you want happens through browsers, wallets, and hosted frontends. Your fingerprint, IP, balance queries, and the trackers embedded in nearly every dapp frontend broadcast your interest before you've committed to anything. Watching: archivists (trackers, RPC logs) and predators (target selection). Traditional finance treats intent as radioactive; institutional blocks route through dark pools, and [off-exchange trading has grown to roughly half of US equity volume](https://www.nasdaq.com/articles/exchange-trading-increases-across-all-types-stocks). Today's onchain mitigation: use a VPN, hope the frontend is honest. Trust assumption: the VPN provider and the frontend operator.
|
||||
|
||||
### 2. Diligence
|
||||
|
||||
Verifying a counterparty onchain takes no work, because the archivist already built the dossier and sells it. Your address history is the identity graph, and it cuts both ways: the same legibility that powers compliance powers the predator's [address poisoning](https://arxiv.org/abs/2501.16681). Today's mitigation: fresh addresses, manual hygiene. Trust assumption: your own operational discipline, forever, against an adversary whose analysis improves annually against your permanent record.
|
||||
|
||||
### 3. Negotiation
|
||||
|
||||
Size, terms, and reservation price leak through the channels we negotiate in. Telegram retains metadata even when content is encrypted. Public mempools broadcast terms before execution. The market's revealed answer: [roughly 80% of Ethereum DeFi interactions now route through private RPCs](https://arxiv.org/abs/2505.19708), per a CoW DAO research paper. Watch what that mitigation did: it moved the flow from a public mempool to a handful of private operators who now see everything. Trust assumption: the RPC operator, who is an archivist with a service agreement.
|
||||
|
||||
### 4. Contracting
|
||||
|
||||
The moment of commitment is the moment of maximum exposure. The frontend you sign on is unverifiable: DNS, hosting, and script injection make every signature an act of faith, and the signing surface is where the money dies at scale ([Bybit](https://www.cnbc.com/2025/02/21/hackers-steal-1point5-billion-from-exchange-bybit-biggest-crypto-heist.html), [drainers](https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/)). These are integrity failures rather than privacy leaks; the chain has to hold against both reading and rewriting, and the same unverifiable infrastructure enables both. Today's mitigation: hardware wallets (protects the key, not the payload you're signing) and "verify the URL." Trust assumption: DNS, the host, the extension store, and every script the page loads.
|
||||
|
||||
### 5. Ordering
|
||||
|
||||
Whose trade goes when is decided by whoever sees the pending flow, and the pending flow is public. Archivists store it, extractors trade against it, builders order it. Today's mitigation: private order flow to trusted builders, MEV-protection RPCs. Trust assumption: the builder duopoly you're routing around the mempool to reach.
|
||||
|
||||
### 6. Settlement
|
||||
|
||||
The one link crypto secured, and it secured it by publishing everything. Balances, approvals, positions, and validators sit in public, permanently. The ledger is the disclosure: every transparent settlement layer is a standing feed to the archivist, forever, retroactively. Today's mitigation: opt-in privacy tools and mixers. Trust assumptions and failure modes: opt-in privacy marks you as someone with something to hide, the crowd you hide in is only the others who opted in, and the tooling around the private core still leaks (the RPC you queried, the explorer you checked, the frontend you used).
|
||||
|
||||
### 7. Enforcement
|
||||
|
||||
Making the outcome stick depends on operators, and identifiable operators get pressured one by one; the OFAC-relay numbers above are what that looks like in production. Today's mitigation: jurisdiction shopping and operator goodwill. Trust assumption: that the operators between you and finality keep resisting pressure they have no structural reason to resist.
|
||||
|
||||
### The pattern
|
||||
|
||||
Every mitigation on offer is a trust swap, not a close. The leak doesn't stop; it relocates to a party you've agreed not to worry about: the VPN provider, the RPC operator, the builder, the relay. Each swap creates a new archivist with better data and a new pressure point for the enforcer. That's not an accident of immature tooling. It's what patching one link at a time structurally produces.
|
||||
|
||||
## Three dynamics that make it worse
|
||||
|
||||
**Weakest link, per property.** Your privacy is bounded by the leakiest link you didn't choose; your integrity by the weakest link you can't verify. Strong cryptography at settlement does nothing about the frontend that lied to you at contracting or the mempool that sold you out at ordering. The properties are only as strong as their weakest carrier, and the links carry different properties, so a complete threat model has to be built per-link and held simultaneously.
|
||||
|
||||
**The loop.** The chain of links isn't a line, it's a cycle. Everything archived from this transaction becomes the discovery and diligence input against your next one, and against everyone who has ever touched your addresses. The surveillance economy is the loop closing. This is why partial fixes decay rather than accumulate, and why "we'll add privacy later" is a plan to be retroactively deanonymized.
|
||||
|
||||
**Asymmetric time.** You defend in real time; the archivist attacks your history at leisure. Every defensive mistake is permanent; every adversary improvement is retroactive. This asymmetry is unique to transparent, immutable substrates: the same properties that make settlement credible make surveillance compound.
|
||||
|
||||
## What the defender is actually trying to get
|
||||
|
||||
Stating the goal precisely matters, because the sloppy version ("privacy") invites the sloppy rebuttal ("criminals"). The defender's goal is not opacity. It's **control over disclosure**: nothing leaks except what you choose to disclose, to whom, provably. A disclosure you choose (to a counterparty, an auditor, a regulator) is a relationship; a mempool archive you never consented to is a leak. Verifiability and disclosure are separable, which is the technical fact the whole design space turns on: zero-knowledge proofs let a network check that rules were followed without seeing the contents. Transparent-by-default systems bought their credibility by publishing everything because that was the only technology available when they shipped. It no longer is.
|
||||
|
||||
Mapped per link, control over disclosure requires: an interface that doesn't report you (discovery, diligence), coordination channels that don't leak intent (negotiation), signing surfaces you can verify (contracting), propagation that doesn't reveal origin (ordering), verifiability without disclosure at the ledger (settlement), and no single squeezable operator, with disclosure living at the application layer where it's chosen (enforcement). That property list is the requirements document for what we're building at Logos, and the honest status ledger lives in the docs and roadmap: [Basecamp](https://blog.logos.co/article/logos-basecamp) (local-first interface) is live; Messaging's protocol lineage runs in production; [Cryptarchia plus Blend](https://blog.logos.co/article/anonymous-block-proposers) delivers anonymous block proposals on testnet v0.2, with private transfers working in the execution zone; verifiable frontends, the networking-layer mixnet, and programmable privacy are roadmap. I'll take fire on any of that in the thread, but this post's claim is the threat model, not the product.
|
||||
|
||||
## Open questions, and I mean them as questions
|
||||
|
||||
**Is the adversary ranking right?** I've implicitly ranked the archivist as the apex threat (patience plus a non-decaying record). You could argue the enforcer is, since it operates on people rather than systems and no protocol fully escapes its own developers. Which ordering should drive design priority?
|
||||
|
||||
**The transparency dividend.** Open history is also diligence infrastructure: it's why onchain lending prices collateral instantly and why market makers quote tight. Selective disclosure claims to keep the dividend while killing the exposure (prove solvency without publishing history), but whether ZK proofs can substitute for open history at market scale is unproven. What would the experiment even look like?
|
||||
|
||||
**The trust-swap counterargument.** Dark pools and private RPCs show sophisticated capital satisfied with accountable trusted intermediaries. Maybe the trust swap is fine, and what looks like a structural flaw is just a functioning market for accountability. The counter-ledger is the logging, breach, and subpoena record of those intermediaries. Which way does the evidence actually point for institutional-scale flow?
|
||||
|
||||
**The scope limit.** The supply chain extends past any protocol: your OS, your browser, the group chat where the deal was first mentioned. If the unreachable links dominate the threat model, protocol-level coverage buys less than this post implies. Where's the crossover?
|
||||
|
||||
**The bootstrap problem.** Anonymity sets are only as strong as the crowd, and the loop punishes late arrivals: every year of delay adds to the archive that gets replayed against them. How does a new private-by-default network bootstrap a crowd against incumbents with a liquidity head start?
|
||||
|
||||
If you think the model's wrong, incomplete, or mis-ranked, that's exactly the feedback this post exists to collect. Bring the attack; the thread is the venue.
|
||||
|
||||
---
|
||||
|
||||
## Companion tweet (drives to forum)
|
||||
|
||||
Everyone threat-models the contract. Almost nobody threat-models the transaction.
|
||||
|
||||
Seven links. Four adversary classes. One permanent archive that gets sharper every year. And every patch on offer is a trust swap, not a fix.
|
||||
|
||||
The full threat model, open for attack: [FORUM LINK]
|
||||
|
||||
---
|
||||
|
||||
*Notes for reviewers: reworked from the earlier thesis draft per Jonny's feedback (2026-07-17): the economic/credible-commitment argument is deferred (whitepaper territory), the threat model is the piece. Carried over from the 3-round adversarial review: all primary-source links, the trust-swap framing, the per-property weakest-link claim, the loop, control-over-disclosure, and the open questions (which are the review's surviving attack surfaces, reframed as research questions for forum/KOL engagement). Capability claims per the public roadmap and v0.2 announce draft, 2026-07-17. The physical-coercion claim is deliberately unquantified pending a public source.*
|
||||
Reference in New Issue
Block a user