ICP is centralized & insecure! Any subnet can be taken down by attacking 4-26 nodes!
@dominic_w correctly points out that there is more to decentralization than node counts
However, a chain is only as strong as its weakest link!
That is the "Nakamoto Coefficient" approach: 🧵
1. The bottom line is that the decentralization of the system cannot be higher than the node count
At least not from the perspective of the Nakamoto Coefficient, as the node count then becomes the lowest possible bar
Your general critique regarding other chains is fair, for example, looking at SOL, its Nakamoto Coefficient is mostly measured as being 19
However, when accounting for stake distribution, the actual number is 12. However, it can never exceed the node count! Or in SOL's case, higher than the stake distribution, because the Nakamoto Coefficient always looks at the lowest possible denominator
That is where my critique against ICP holds water, as it is highly centralized from this perspective. At a similar level to SOL, as a matter of fact. As I am also an advocate for increasing node counts on SOL. I am personally less concerned about stake distributions as they tend to decentralize organically over time
We should be in agreement on this, since as far as I understand, ICP is actually in favor of developing randomized node shuffling, which would absolutely solve this problem in a similar vein to how sharding does as well
2.
This is where we might disagree, as a crypto researcher, it is absolutely possible to find out the "real" numbers
That is exactly what I do professionally. When people attempt to hide things, it tends to leave a big, very noticeable hole. Should it be more accessible to the general public? Absolutely, it should!
However, that does not mean some projects can be fully transparent today
Which is currently not the case for ICP, as we are still waiting for disclosure of the insider addresses from either Dfinity or Arkham Research! That information is still not available to the public today! Despite it being requested by major parties over the years, myself included. A perfect example of the type of bad practices you were talking about
That is an example of a red flag that might be a good reason to keep people away from this project. My critique this time was more focused on the technical aspects, though
In the case of SOL, for example, these numbers are at least transparent & knowable, with no giant holes in the chain analysis like there are in ICP
Furthermore, from this argument's perspective, criticizing another chain also has no bearing on my ICP critique. As ICP & SOL should both improve their decentralization!
3.
To clarify my position some more, I would define decentralization as a measurement of the "distribution of power"
We can agree on this point, as your definition is compatible with mine: "what matters is the number of independent parties involved in consensus"
4.
This is where we radically depart in terms of crypto philosophy & also where you massively depart from what is generally considered to be the basic assumptions most make in blockchain design
That does make ICP very novel, so I will give you that
I fundamentally disagree, the anonymity (permissionlessness) of the system is a key attribute that contributes to the system's security & censorship resistance
A great example of that was the recent OFAC & Tornado Cash sanctions
Most validators complied, as they had to within their legal jurisdiction. However, only because there were a few anonymous validators, those TX's were able to route around the censors
That is a practical example that highlights why this is a critical aspect of a blockchain's design
I would argue that if an ICP subnet is targeted by such regulations, it is far more likely that it will comply, which, from my perspective, would be a bad thing
5.
This is another example of where you radically depart from what is considered general crypto knowledge
Again, that is not a valid argument for why you are wrong, but it is worth noting that, in a crypto context, this is a radical argument. Ofcourse from a traditional perspective, yours is a normal position to take
Your response to my critique is that you are disconnecting the "cost of attack" of stake from the security model, which is, first of all, to agree & bite the bullet. Appreciate that!
While arguing, you replaced it with legal & reputational guarantees
However, that is exactly what fundamentally goes against the crypto ethos
The whole point of crypto is that we rely on crypto economic game theory, not reputation, legal & authoritarian systems
You have basically turned crypto philosophy upside down on its head. It goes against everything we stand for in crypto on the deepest and most fundamental possible level
6.
We clearly must have a different definition of shared security, if a subnet can be taken down by attacking those specific nodes, then security is not shared across all subnets...
Even if some of the verification takes place on the NNS
Again, this can be solved by doing randomized node shuffling! Something I know ICP is working on!
7.
Will again agree with you on the importance of having independent node operators
While completely disagreeing with you that this is not possible on a traditional PoS network. It is the opposite, only on a truly permissionless system at scale can we reach higher levels of decentralization
Effectively placing power in 4-26 operators is always going to be weaker compared to a system with thousands of independent operators
ICP limits the number of operators per subnet. What I am advocating for, "node shuffling," means that each subnet would have the security of all nodes!
So, in my analysis, it would go from 7-40 nodes to 800+ nodes. With a Nakamoto Coefficient closer to 500! (ignoring stake distribution)
Would that not be far better from a decentralization perspective? The great thing about this style of sharding is that it would not lead to any loss in performance either!
The random shuffling just means an attacker cannot target a specific set of nodes; they must target all nodes instead. Clearly, that would be a much harder attack to pull off
8.
Can also agree with you that ETH is not making the right trade-offs in terms of that balancing act
However, ICP takes sacrificing decentralization in the name of efficiency too far. I do not think it is safe; it is dangerous
The trade-off also makes very little sense to me from a design perspective in 2026. As ICP is extremely centralized, yet it still lacks capacity due to how the subnet fragments the usage, breaking up otherwise composable DeFi
This is, ofcourse, the old monolithic vs. modular argument all over again. A debate I have been having since day 1
Conclusion:
The ICP community often claims to be far ahead technologically. From my perspective, that is not the case at all
If anything, ICP is far behind; this is also reflected in the lack of adoption compared to chains like SOL & HYPE
I can respect the novel philosophy; however, the market clear still values decentralization in the traditional sense. Despite all of the shortcomings, you might correctly point out
There are real technological shortcomings, along with serious concerns around the safety of this system, especially if it ever gained serious traction
There are multiple solutions that could absolutely solve the critiques I made here
My motivation for writing this is to set the record straight. Bad design does not bother me, misrepresenting & misleading people around a bad design is where I take issue & spring into action
ICP has a bad design, as it is highly centralized & insecure compared to traditional PoS chains. While we get very little in return in terms of capabilities for that trade-off
However, it would take relatively small changes to make ICP great. That is why I have advocated for ICP to adopt a sharded design closer to what NEAR has. As most of the primitives are already in place to make that happen, it is not a giant leap to go from subnets in a modular design to shards in a monolithic design
Will also praise ICP's governance, as I also did in my original critique, as that might provide the path towards solving these problems
Hope you can all appreciate the role an outside critic can serve for a small cryptocurrency like ICP. The level of toxicity I receive is proportional to the likelihood of positive change from my perspective
So, do not close your minds to change, embrace criticism & do so civilly!
Thank you, Dom, for taking the time to counter my arguments. We might still strongly disagree with each other, but I hope the net result of the discussion can still be a positive influence for ICP as a whole ❤️
As always, I wish the ICP community the best! As I want you to succeed, at the end of the day, we should not care what three-letter acronym pulls us across the finish line! 🔥
https://t.co/s2PtCt0G3i
ICP uses a highly sophisticated security and decentralization model, which all blockchains that wish to function as clouds will need to copy.
Justin's latest misunderstandings (below) provide a good segue to talk about this, and share some expertise that even networks he's invested in might use.
1. Node count does not equal security or independence from centralized actors.
The claim that the number of nodes in a proof-of-stake network reflects decentralization and security is only an attractive idea that boils down to industry folklore and marketing. The node count doesn't matter per se, as I explain below.
For networks that depend on consensus to function, their security actually derives from the total number of *independent participants* involved consensus, and how voting power/participation power is divided between them.
In proof-of-stake networks, voting power derives from stake, rather than nodes. However, large stakers often stake via lots of nodes, sometimes to create the impression of decentralization, sometimes to partition access to their keys, and other times because their networks limit how much stake can be attached to a single node.
But here's the rub: if someone controls enough stake to control the network, it doesn't matter how many nodes they have spread their stake across.
Today, many networks have large numbers of nodes, but are in fact can be controlled by one entity, or a group of closely related entities.
This creates the following problems:
— They might make an honest mistake upgrading or configuring the network, and cause a disaster by accident;
— a hacker might commandeer their control to do something terrible;
— they might go bankrupt, and switch their nodes off, potentially causing loss of hosted data, and worse;
— they might subtly manipulate computations and data, to extact value from users somehow, sometimes without anyone being able to detect what is happening and;
— may other things
2. When someone says "the network is very secure and decentralized because it has lots of nodes..."
We know that across the "monolithic" proof-of-stake networks Justin is currently invested into, validator companies often operate tens of thousands of nodes using stake lent to them by customers in return for a share of the staking rewards.
In plain sight, this provides a demonstration of how the number of nodes in a network doesn't equal the number of independent consensus participants. However, hidden centralization is more of a problem.
For example, some time ago, the Crypto Leaks website shared video of a senior Ava Labs technical administrator claiming that in fact the company, and its founder and CEO, Emin Gün Sirer, own a huge portion of the AVAX supply that controls the Avalanche blockchain, and in fact, secretly operate the majority of its nodes, which they use to stake their holdings to both earn the lion's share of rewards and maintain hidden control.
They are not alone. Many proof-of-stake blockchains are run by companies and cabals of founders, execs and investors that secretly own a huge portion of the supply, and hide the fact by self-operating large numbers of nodes.
Aside from helping them get rich, this hidden centralization also helps them with two other things:
1) It provides them with hidden de facto control over their networks, which allows them to force through orderly node upgrades and configurations without the difficulty of decentralizing and having to invest effort developing specialized autonomous network governance and orchestration systems, such as the Internet Computer's Network Nervous System (NNS).
2) It inflates the price of their token: because they earn the lion's share of the staking rewards, they can stash them away for later, preventing them hitting the markets, which isn't a problem for them, because they have huge additional holdings they can sell from. By reducing the flow of tokens to the markets they keep the price higher, which i) enables to them to sell their holdings to the public at higher prices, and ii) keeps the market cap of their networks higher, which lends them prestige, which further attracts investors, including institutional investors who don't understand the game they're playing.
The public would be upset if they could see the truth. For this reasons, they often create large numbers of nodes while peddling the nonsense that the nodes are evidence of great decentralization.
3. Node count vs decentralization in open networks
For any decentralized network, whether its a monolithic network, or a subnet within a larger network, like a subnet on the Internet Computer, what matters for security and resilience is how consensus participation rights are divided amongst independent parties.
There are proven laws of mathematics governing how this works. If one party has 1/3 or more of the participation, then they can start exercising various forms of control over the network.
Thus, if participation is distributed equally over nodes, as it is on the Internet Computer (where the specialized hardware involved plays the role of a form of stake), it doesn't matter if a subnet has 1,000,000 nodes, and one party controls 333,334 of them, or 10 nodes, and one party controls 4 of them — each creates a similarly bad situation, since one party has 1/3 and can thus exert hidden control.
To capture this reality, the blockchain industry came up with the concept of the "Nakamoto Coefficient."
This is a number that tracks the number of independent parties that must collude to control a network. In both of the above examples, the Nakamoto coefficient is 1, even though vastly different numbers of nodes are involved, since a single party can exert control.
Again, what matters is the number of independent parties involved in consensus, not the number of nodes. People who claim otherwise are often just trotting out the same old snakeoil.
4. A key problem: the anonymity of node operators and stakers
A key challenge for proof-of-stake networks is that stakers/node operators are usually *anonymous*. This design choice is often sold to the public using old cypherpunk rubrics that anonymity allows networks to resist government control.
Of course, there is some truth in this, esepcially as concerns proof-of-work networks, but the proof-of-stake people making these argument are hardly ever cypherpunks!
The reality is that in practice anonymity has just become a way to fake decentralization, and hide massive unscrupulous profiteering.
(A further technical observation is that anonymity is anyway a weak shield in practice. For example, November 2022, Hetzner, one of Europe's largest clouds, decided to ban Solana nodes, and deleted 40% of the network's nodes overnight. The fact is they were able to easily identify the Solana nodes among the millions of other compute instances through technical means. The government could too.)
5. Moving on from anonymity, and creating powerful incentives for node operators not to be evil
The Internet Computer eschews node operator anonymity. When a prospective node operator wants go gain a "node provider" ID, through which they can join nodes to the network, they have to submit a proposal to the Network Nervous System, which includes identity and background information that allows the community to verify who they are, and what relationships they might have to other operators. Once they receive their node provider ID, this feeds back into how the Network Nervous System combines nodes.
Upon this foundation, the NNS combines nodes to form subnets that it knows are operated by independent parties — which combinations create the required levels of decentralization in a deterministic way, while using the minimum number of nodes for efficiency purposes.
Further, non-anonymous node providers join a system where they have powerful incentives to behave honestly.
Simply put, as the result of their declarations, if node providers act in an evil way, for example colluding to corrupt their subnets, they become legally liable, worldwide, for the results of their nefarious actions. Moreover, if they seriously disrupt the correct functioning of the network, they could additionally face criminal prosection under laws such as the UK's Computer Misuse Act from 1990.
The Internet Computer can slash misbehaving node providers, banishing their expensive hardware from the network, and proof-of-stake networks can similarly slash the stakes of their node operators.
However, slashing is a financial incentive that exists within a hypothesized microeconomic framework. In some scenarios, it's possible that a node operator might extract more value through dishonest actions than they lose when they get slashed.
The introduction of legal penalties for dishonest behavior act as a far more powerful real-world incentive.
The Internet Computer is more secure by design.
6. Scaling and efficiency using deterministic decentralization
The Internet Computer is essentially a network of super advanced subnet blockchains, which run under the control of its Network Nervous System, which runs on its own subnet (which also chains cryptographic keys to the subnets it creates, enabling the result of every call/tx into the network that triggers onchain computation to be transitively signed by the public key of the NNS — yes, Justin is talking nonsense when he says there is no shared security).
Individually, these subnets can host serious amounts of onchain computation and data, and they can even serve web. However, to scale-out horizontally, the network has to create additional subnets on demand.
This is only possible because the Network Nervous System can look at the available pool of nodes, and then draw down just the right combinations of nodes required to create new subnets with the necessary Nakamoto coefficients.
By design, it uses only the minimum number of nodes required to create the necessary Nakamoto coefficient, minimizing the replication of computation and data, driving incredible efficiency.
7. Going beyond node operator independence
Deterministic decentralization makes other considerations too, in addition to combining nodes from independent operators. Here they are:
Data centers — if a subnet's nodes are in the same data center, data center failure would also take the subnet down, so it combines nodes installed in different data centers.
Geographies — a nuclear strike might take out all the data centers in a geographical area, so its combines nodes in data centers that are geographically dispersed around the world.
Jurisdictions — if a jurisdiction such as the EU suddenly banned blockchain (hopefully not!) they might take down all nodes inside the regions they control, so it combines nodes based in different jurisdictions too.
Using this more nuanced understanding of decentralization, deterministic decentralization squeezes incredible security and resilience from the minimum number of nodes. This is something that just isn't possible on proof-of-stake networks with anonymous stakers and node operators.
8. Security and resilience on a cost curve
In practice, deterministic decentralization is also applied within the context of considerations about the most appropriate balance of security and cost.
Today, Ethereum replicates computation and data across hundreds of thousands of nodes. This is one of the reasons why its onchain computation costs are many orders of magnitude greater than on the Internet Computer. Yet, the computer science says that the amount of security and resilience they are gaining by adding more and more nodes exponentially decayed to zero long ago.
The Internet Computer, meanwhile, is focused on providing cloud, which demands efficiency.
In fact, the Internet Computer always aims to combine the minimum number of nodes required to produce the level of security and resilience appropriate for the application, because in reality, cost/benefit curves are often vastly different, and one size doesn't fit all.
Justin complains that shared public subnets used by the Internet Computer to host applications and services only use 13 nodes. In fact, this number of independent parties creates a Nakamoto coefficient of 5, which is much higher than actually exists on most proof-of-stake blockchains behind the scenes. Simply put, it is sufficient for these applications.
The soon to be released cloud engine technology will provide market validation (cloud engines are private subnets created by enterprises that wish to select their own nodes).
My bet is we will mostly see enterprises configure cloud engines with just 4 or 7 nodes, which will provide Nakamoto coefficients of 2 and 3 respectively, which they will see as easily sufficient for their needs. They will only add more nodes if they want to scale out query capacity, or reduce web latency times in different regions.
This works both ways.
For example, the Network Nervous System allocates ~50 nodes to its own subnet, and a similar number to subnets involved in the hosting of threshold cryptography, which allows hosted software to create public keys that the network can sign for on demand (e.g. to custody bitcoin within an application) and securely encrypt data stored on the network (e.g. the vetKeys functionality).
These subnets benefit from a huge Nakamoto coefficient of 17+, as well as the additional considerations that deterministic decentralization makes. If it wanted to, it could combine hundreds of nodes to create a subnet, thanks to the advanced nature of the network technology involved.
The ability of the Internet Computer to dynamically configure subnet nodes in pursuit of the precise amount of decentralization required, when considering all relevant factors, reflects its incredible sophistication, and why it can provide tamperproof unstoppable onchain cloud.
To date, the implementation of deterministic decentralization remains unique to the Internet Computer.
But, like other innovations the network pioneered years ago, which others are only now pursuing, such as reverse gas, chains that covet cloud provision will inevitably also attempt to adopt these methodologies.
Possibly, even those that Justin holds dear.
Hello MULTI/DEX 🔥 Should DFINITY release the most powerful DeFi application the world has ever seen?
What's cool about it? Here are some factoids, the craziest at the end:
1. It runs on an ICP cloud engine (soon everyone can have one) and is 100% network resident and tamperproof.
2. It is genuinely multi-chain, with no bridging hassles for users (users can deposit straight into their accounts, and withdraw directly, from the native chains of tokens).
3. It is order book based, but also provides a traditional swap interface, which swaps arbitrary assets by routing across the underlying markets.
4. It supports both spot trading, and margin trading that lets traders go long and short with leverage.
5. It has an AMM (Automated Market Maker) that uses Internet Computer outcalls to determine outside prices, then delayed matching against AMM limit orders to prevent arbitrageurs draining liquidity, as can occur with traditional DEXs providing swaps.
6. The AMM maintains a unified liquidity vault, and doesn't need two liquidity pools for every trading pair, providing outstanding capital efficiency and liquidity compared with traditional DeFi systems.
7. Users can earn by depositing into the AMM Vault, and into an insurance pool that protects the vault from margin calls that fail to recover all capital (the insurance pool gets 5% of all liquidations).
8. MULTI/DEX runs on the decentralized Internet Computer network, and is 100% open source — unlike HyperLedger, say, which remains closed source, and has an single-purpose architecture closer to federated CEX hosted on a symmetric cluster of federated servers.
9. If we go ahead, we would propose that MULTI/DEX runs as part of the Internet Computer, in the sense it is controlled and updated by the NNS (The Internet Computer's Network Nervous System, the world's largest and most sophisticated DAO, which directly orchestrates and updates the network) providing unparalleled levels of autonomy, transparency, and security.
10.... and this is the BIG ONE... its backend is built using the latest Motoko language framework (soon to be released) that puts AI *inside* of its software. That means, in another seminal inventive step from DFINITY and Caffeine Labs technology teams, that AI can see, browse and query the realtime data inside the app/dapp's persistent memory and can create and execute ad hoc queries and update logic on-the-fly (subject to permissions). So, while for much of the time traders will be using the traditional UX shown in the pic, increasingly, they will be interacting with the exchange through AI chats that have the "Internet Computer Connector" MCP installed (soon to be released). On the one hand, traders will be able to use chat to ask for simple things, like current spot pricing and market depth, and the likely slippage on a spot market order, and for orders to be submitted, but on the other, for much more demanding things that require the AI to execute ad hoc functionality, such as "Look at my positions and margin pools, and rebalance them to give me more blended market exposure, while also adjusting for risks indicated by social media coverage of forthcoming market events, but wait for my approval of your plan before proceeding."
This is a lot to take in, so I'm aiming to get a new demo video out ASAP that will demonstrate what's possible with this AIware, which will include MULTI/DEX — should be about a week!!
Btw. for those wondering what might be the big picture beyond what I just described with MULTI/DEX: At DFINITY, we are in the process of transforming ourselves into an "agentic organization," where all our existing apps/SaaS is replaced by custom on-demand apps/SaaS running on cloud engines that are created and updated by AI. Of course, these on-demand apps/SaaS are being built using the new technology described that automatically puts AI inside and provides users with fluid functionality via chat. The totality of the apps/SaaS represents an enterprise "World Model," which incorporates as much of the enterprise's data as possible, enabling AI to perform incredibly powerful analyses and actions — when you see this is in action, you can't unsee what you saw, because it's clearly a huge leap beyond the status quo of today's tech, which is exactly what the Internet Computer project is about. This wraps up our new technology stack, created by leaning on unique aspects of "The Network is The Cloud" paradigm, and years of work, and what, together with cloud engines, will finally enable the Internet Computer to strike out into the massive mainstream cloud technology market.
@itsmejeremy77@ohshiilabs@oisy@dgdg_app I don't have this issue. I suppose it's because you have set up your browser to forget all the history and passwords. But in the same time, this keeps you safe :)
@itsmejeremy77@ohshiilabs@oisy@dgdg_app Did you try Stoic wallet? It is the oldest for NFTs, still stays around. The only problem I had is that they appear in Stoic w. but takes a while untill I can see them in Enteprot when connected with the wallet.
@itsmejeremy77@Wiseowl_icp@dfinity@DFINITYDev@dominic_w It is, but there will be a benefit, although not too soon. After we have a real Altseason and all the sales are done, when we go into the bear market there will really be a smaller pressure from sellers at the bottom, from there the price will be able to recover faster.
@itsmejeremy77@Wiseowl_icp@dfinity@DFINITYDev@dominic_w Actually it will go even much lower. I expect that 20-25% more of ICP will be staked for short periods of 1-3 months, this is the idle ICP waiting to be sold. Staked ICP will increase to 70% and maturity distribution pool will be larger, so it will go down from 6.7%to 5-5.5%.
@itsmejeremy77@dfinity@dominic_w I guess this time people didn't bothered to vote themselves. When voting for Mission70 Divinity let the community to vote. I also delegate my VP for Governance to Definity, but I voted NEY previous to their vote.
Time to implement the last Part of Mission 70 on $ICP:
Proposal 141441 is live ✅
Proposal 141440 is live ✅
➡️Reduce max dissolve delay from 8 years to 2 years. This includes capping existing neurons via data migration.
➡️Reduce voting rewards pool by approximately 36.71% (equivalently, scale by 0.6329 times).
➡️Dissolve delay bonus: quadratic instead of linear, with a maximum of 3x instead of 2x.
➡️
Reduce the minimum dissolve delay needed to vote to 2 weeks instead of 6 months.
➡️8 year gang 10% bonus.
@itsmejeremy77@Gatorb8FL Yep, this is why many say it might be dangerous for the network. As an APR of realistically 5.5 * 1.25 * 1.1 = 7.56% - might seem insufficient for blocking money for 2 years. Other networks can give 4-7% with a maximum of 1 month blocking.
@itsmejeremy77@Gatorb8FL Yes it's corect. But take into consideration that Total ICP staked will increase a lot, so the pool for reward distribution will be bigger and probably 8yn will earn 5-6%, not 7%. Now we have 43.4 staked, I expect it to increase to 70%.
@ICP100X@icpp_pro@jerrybanfield My neuron follows 10 others on governance topic - just because I don't want to miss any vote. But on important proposals I vote manually.
@iPhelipeVR You can not expect the price to rise when you don't have adoption. Just 1mil new identities since 2021. We should have had active lending-borrowing DeFi, 30 mil users and by this date inflation wouldn't have been so important!