Decentralization is a core ethos in Web3 and DeFi. Bitcoin was designed to be a fully decentralized financial system, and the rest of the ecosystem (theoretically) followed suit.
However, the reality of Web3 isn't as decentralized as people think. Centralization exists at every level of the Web3 ecosystem, and this has significant implications for security, censorship, etc., the same things that Bitcoin was designed to address.
Where Decentralization Ideals Fall Short
In theory, each layer of the Web3 ecosystem is as decentralized as possible. In reality, each one often has a high level of centralization, whether intentional or accidental.
Some of the most important places where decentralization fall short include:
- Block Creation/Validation: Proof of Work (PoW) and other blockchain consensus algorithms are designed to decentralize control over the history of the blockchain. However, the growth of large mining pools, digital exchanges, and other groups means that small numbers of organizations have outsized control, and a small collaboration could create a 51% attack. Additionally, many blockchains have a small pool of validators capable of halting or rolling back the ledger.
- Contract-Level Control: Most smart contracts are controlled by a small pool of developers or blockchain accounts. Many DeFi hacks have involved a single compromised key resulting in a malicious update to an upgradeable proxy contract. The fact that code execution is decentralized and immutable doesn't matter if an attacker can rewrite the code.
- Centralized Governance: Often, DeFi teams try to manage the risk of centralized ownership by setting up decentralized governance systems where users can propose and vote on changes. However, these systems often fall prey to flash loan attacks or low participation that makes taking control relatively cheap and easy for an attacker.
- Infrastructure Dependencies: Most smart contract developers and Web3 users rely on a small set of providers for critical services, such as RPC, custody, and price oracles. If one of these providers is breached, goes down, or goes out of business, it will have outsized impacts on DeFi and Web3.
The Implications of Web3 Centralization
Web3 is theoretically decentralized because few of these areas of centralization are intentional. However, the gap between theory and reality can introduce significant risks and a false sense of security.
For example, the Bybit hack, the largest Web3 hack in history, involved the compromise of the JavaScript front-end for the project's multi-sig wallet. This supply chain hack resulted in about $1.5 billion in losses for a project that was following security best practices.
However, the potential damage and impact doesn't end there. The attacker had the access to Safe Wallet infrastructure required to carry out this attack but narrowly scoped their exploit code. The broad access to Safe's infrastructure could also have been used to target other Web3 projects.
Web3 centralization means that a single compromised provider could leave all of their clients vulnerable to attack. Similarly, a custody provider or mining pool with significant power could leave a blockchain vulnerable to 51% attacks if it can't participate in block production.
Managing the Security Risks of Centralization
Web3 is centralized to a certain degree at each level of its infrastructure stack. Often, consensus is controlled by a small number of parties, and DeFi teams exert significant control over their projects.
In some cases, teams can work to manage the risks of centralization, such as setting minimum quorum thresholds for decentralized voting or using multiple providers of various services. In others, the risks of centralization should be acknowledged and accepted as part of a Web3 risk management strategy.
New notes, roughly monthly per shift
No paywall, no membership tier — just an email when something new is published. Pick which shifts you care about.