本可阻止 rsETH 漏洞利用的 DeFi 熔断器,以及 Linea 为何部署它
- Phylax 的熔断器自约1月起运行在 Linea 排序器上,已拦截逾4,000次资金抽取尝试,累计涉及150万美元资金,其中包括一起原本无法修复的漏洞利用事件:第三方 0x 集成方诱导用户向一个不可变的 0x 合约授权,后者随后将资金抽走。 Odysseus 强调,这套设计没有破坏区块链的基本属性:策略存放在公开的链上注册表中,协议自愿接入,Phylax 不控制任何环节——“如果 0x 不愿添加这项策略,我们什么也做不了”。
- Declan Fox 的核心判断是:在机构区块链领域,自建私有许可制 L1 如今已是“最大的反模式”。 ZK 证明带来原生互操作性:银行可以保留具备隐私和合规能力的封闭式 L2,同时连接交易对手和 Ethereum,无需依赖受信中介——“现在可以鱼和熊掌兼得”。如今“80%的活动”运行在 Hyperledger Besu 上,每日处理数十亿美元级别的交易额,却全部彼此隔离。
- Kelp/rsETH 漏洞事件本可能成为 Linea 的一次险情:事件发生前3个月,Kelp 的大部分 TVL 还在 Linea 主网上——“那对我们来说可能会是一个非常、非常大的问题”。 Declan 认为安全委员会“绝对不是”L2 治理的终局,但将 Arbitrum 的冻结行动类比为 Ethereum 的 DAO 决策;他的解决方案是,各条链公开自己的治理理念,让用户自行选择是否接入。
- Odysseus 推测 Circle 为何没有冻结黑客资金:“没有好答案,只有坏答案”。 如果今天无需法院命令就冻结资金,未来敌意监管者可能要求 Circle 对其他目标采取同样做法——他以加拿大卡车司机账户被冻结为例;此后“所有人都会停止使用 USDC”,甚至可能演变成“灭绝级事件”。他说,Circle 对保护自身业务负有受托责任。
- Odysseus 认为,安全性是机构采用区块链的共同阻碍:“黑客攻击是一次物理事件”(a hack is a physics event)。 如果链上终局性成为法律终局性,那么“一旦朝鲜在法律上拥有这笔资金,它们就是自己的”;因此,加密安全“不是金融安全,而是更接近航空航天”。如果黑客可以拿到 Apple 股票、完成交易,最后让纽约的交易员持有数百万美元被盗股票,就不可能实现高水平的资本形成。
- 关于2028年的监管风险,Declan 认为产品市场契合度就是政治防御,Odysseus 则预计意识形态敌意仍将存在。 Declan 认为,代币化货币市场基金和 24/7 金融将成为地缘政治问题,MiCA 时代的欧洲和亚洲已经准备好争夺美国市场,因此“不会有新一届政府试图让这列火车停下来”。Odysseus 则认为,2008年后接受重监管的银行和机构相信自己控制着受监管体系,而它们无法控制的不可变系统会引发本能反应——反加密阵营正在“记录 Arbitrum 冻结资金这件事”。
- 未来5年,所有银行都会运行自己的账本,并通过 ZK 证明实现互操作,提供“同样的 24/7 服务”,而“EVM 和 JSON-RPC 将成为新的 Excel 表格”。 真正的突破在于 TradFi 资产能够与 DeFi 原语组合;黑客风险下降后,保险公司才有可能为 DeFi 承保。Phylax 计划通过应用特定排序扩展至 Ethereum、Solana、Tempo 和 Arc。
1. 私有许可制链是反模式——ZK 证明让银行“鱼和熊掌兼得”
- 这期节目围绕 Declan 在 Paris Blockchain Week 的一段发言展开:“银行、CSD 或其他机构可以把自己的链私下连接到所有其他链以及 Ethereum,同时保留可扩展性、隐私和合规能力。”迁移将是渐进式的:各类混合系统先相互镜像运行,直到监管机构认定“链上终局性确实等同于法律终局性”,并在法律上承认智能合约。
- 大多数人忽视的实际规模是,银行已经在内部运行区块链多年——“如今80%的活动实际上运行在 Hyperledger Besu 上”,每天处理数十亿美元级别的价值和交易量,但这些系统完全彼此隔离。Declan 所说的“机构区块链三难困境”包括隐私与控制、流动性与互操作性,以及性能;直到最近,这3点还无法同时实现。
- 具体机制是:银行在 Ethereum 内部启动一个带有角色权限控制的许可制 L2,将客户现金和证券代币化,然后实现原生互操作——在链 A 上锁定现金端,向托管机构的独立链发送经 ZK 验证的消息,后者最终在 Ethereum 上结算,再释放证券或访问代币化货币市场基金。与其依赖近期频频暴露安全问题的第三方跨链桥,不如“直接利用数学”实现原生互操作,更适合重视风险的买方。
- Odysseus 提到,2019年的一篇学术论文已经证明,无需受信第三方也能实现跨账本通信;ZK 证明本身就承担了这一角色。Cosmos “很早就在推动这条前沿路线”,但也存在其他问题;而监管机构不可能允许银行账本完全私有,因此 ZK 提供的选择性可见性是一种更现实的架构。
2. “黑客攻击是一次物理事件”——安全才是真正的阻碍
- Odysseus 将机构采用区块链拆成两件事:把资金搬到链上,以获得收益和低成本的大额转账;把工作流搬到链上,解决过去缺少隐私能力的问题。他认为,这两条路径最终都卡在安全性上。
- 他最尖锐的表述是,一旦智能合约具备法律效力,“一旦朝鲜在法律上拥有这笔资金,它们就是自己的——没有任何办法撤销”。TradFi 黑客攻击“不过是一套账本……开几次会……最后回头更新电子表格”。因此,加密安全“不是金融安全,而是更接近航空航天”——一旦发生故障,结果同样无法逆转。
- 这也是资本形成的上限所在:黑客拿到代币化的 Apple 股票并完成交易,纽约的交易员随后持有数百万美元的被盗 Apple 股票——“你要找谁追责?这件事要怎么处理?在这种环境下,不可能实现高水平的资本形成。”
3. rsETH 险情与冻结困境
- 对于 Arbitrum 安全委员会在一宗与 Aave 相关、最终被他描述为牵涉 LayerZero 的漏洞事件中冻结资金,DeFi Dad 坦率地表示自己既兴奋、又松了一口气、又感到沮丧:这提醒人们,“在那条链上,你的资金最终并不真正属于你”,也是他持有的资产几乎都放在 Ethereum L1 上的原因之一。
- Declan 披露,在 Kelp DAO 和 rsETH 事件发生前3个月,Kelp 的大部分 TVL 还在 Linea 主网上——“换一种情况,这对我们来说可能会是一个非常、非常大的问题”。他认为安全委员会“绝对不是”终局,但仍以 DAO 决策为类比,理解并支持 Arbitrum 的做法——“我想那是2017年”:整个行业仍处于早期阶段,不能任由数百万资金落入朝鲜手中。他的答案是,各条链公开自己的治理理念,由用户——包括资金库——自行选择适合自己的体系。
- 根据与 SharpLink 等机构的交流,机构真正筛选的是风险调整后收益,以及哪些风险可能把存款直接减记为零:智能合约风险、L2 风险、托管风险、密钥管理风险等,而不是抗审查性;因为“他们本来就在处理法律合同和已知交易对手,也接受这种风险”。
- 对于 Circle,Odysseus 的判断是:“没有好答案,只有坏答案。”如果今天在没有法院命令的情况下冻结黑客资产,未来的敌意监管环境可能要求 Circle 对其他目标采取同样做法;他以加拿大卡车司机银行账户被冻结为类比。一旦信任崩塌,“所有人都会停止使用 USDC”,事件甚至可能演变为“灭绝级事件”。Circle“对保护自身业务负有受托责任”。
4. 熬过2028年:产品市场契合度是政治防御
- DeFi Dad 担心,加密行业如今已经与共和党深度绑定;如果民主党在2028年获胜,上一轮熊市时期那批敌意监管者可能重新回归。
- Declan 的答案是产品市场契合度:代币化货币市场基金正在取代企业现金,GENIUS Act 已经推进,CLARITY Act 也有望通过,MiCA 和亚洲市场同样在向前发展。阻止这一进程,就等于“降低本国经济对全球金融服务业的影响”;一旦 24/7 新银行开始与企业的客户群重叠,企业自身也会站出来反对阻拦。如果行业专注于产品市场契合度,他认为,“不会有新一届政府试图让这列火车停下来”。
- Odysseus 没有那么乐观。他认为 CLARITY 很重要,因为它“保护我们免受任意决策的影响”,尤其是在灰色地带;但无论如何,他都预计意识形态上的敌意会持续存在。2008年后建立重监管体系的银行和机构相信自己控制着整个系统,而 Ethereum 或 Uniswap 这类不可变、无需许可的系统会引发“非常本能的反应……未必理性”。他还警告,反加密阵营正在“记录 Arbitrum 冻结资金这件事——未来他们会利用这一事件”。
5. 熔断器内部机制:拦截4,000次资金抽取,Phylax 零控制权
- 典型案例是:第三方 0x 集成方误导用户向一个不可变的 0x 合约授予授权额度,而由于智能合约不可变,这条资金抽取路径“根本无法修复”。由于 Phylax 约在1月上线 Linea,0x 随即加入一条策略,拦截逾4,000笔交易,累计涉及150万美元资金抽取额,潜在受害者达数十人。
- DeFi Dad 将其类比为 Fluid 与 Aave 的差异:Aave 没有熔断器,而 Fluid 的新设计可以在某一特定资产约20%或30%已被提取或借出时触发。他将这些阈值作为应用层保护的近似示例。
- 机制包括一个公开的链上策略注册表,用户可以准确看到每个协议防范的风险;同时,排序器旁路组件会在交易进入区块前,逐笔检查其是否符合适用策略。策略可以是运行时不变量或熔断器,例如“1小时或1天内流入额不得超过5,000万”。违反策略的交易不会导致整条链暂停:交易会从区块中丢弃,转交协议团队复核,并留下合规日志。
- 双方都强调了这套系统的中立性:软件以本地部署方式运行在 Linea 的排序器上,Phylax 不控制流程中的任何环节,是否接入完全由协议决定。Declan 表示,这正是 Linea 选择 Phylax 而非竞争对手的原因——它是“唯一一个我们认为真正符合 DeFi 属性的方案”。他还称赞 Besu 是一个被低估、且非常容易扩展的集成底座。
- Declan 的下一步判断是,随着 AI 的发展,黑客攻击“实际上正在变得越来越严重”;如果风险下降能够被证明,保险公司就可以为 DeFi 承保。“DeFi 的安全与保险将成为非常重要的一部分”,尤其是在未来一波建立于链上原语之上的新银行将零售用户带入市场之际。
6. 未来5年:TradFi 与 DeFi 组合起来
- Declan 先打预防针,称“五年预测非常难做”,但仍给出判断:每家银行和金融机构都会运行一套账户及客户资产账本,在保留自身合规和隐私的同时实现无缝互操作,提供“与今天完全相同的服务,只不过是 24/7”。员工仍会使用笨重的 ERP,区块链则藏在底层,理想情况下由 Ethereum 的去中心化能力和 ZK 证明共同支撑。
- 真正的突破在于,如今的代币化资产大多只是“链下资产的数字孪生”——一块黄金被代币化后,在 DeFi 中什么也做不了。当 TradFi 与 DeFi 融合,并与过去5–10年的加密原生原语组合起来,“这才会成为真正的技术创新”,而这将在未来5年内发生。Odysseus 最后表示:“EVM 和 JSON-RPC 将成为新的 Excel 表格。”
- Phylax 的扩展路径是:它兼容 EVM 且向后兼容,因此应用和 L2 可以快速接入;同时通过“应用特定排序”触达 L1,包括 Ethereum、Solana、Tempo 和 Arc。具体而言,应用只允许运行该软件的特定节点或区块构建者为其交易排序,目标是“成为安全领域的标准”。
完整逐字稿
We integrated with Linea, and then we worked with 0x, where we helped them add a policy because a third-party integrator of 0x had mistakenly been pushing users to give an allowance to an immutable contract of 0x, and then they started being drained. Right? So that was an ongoing vector that was impossible to fix because of the immutability of the smart contracts. Because Phylax was on Linea, 0x could actually add a policy there to stop these drains. So far, our system—which, by the way, runs on the Linea sequencer, by the Linea sequencer, on-premises, with us having no control of it—has stopped over 4,000 transactions.
Guys, thank you both for joining us. How are you doing?
I'm good. Thanks for having us.
Very good. Yeah, thank you for having us.
This one's going to be a bit of a mixed bag. We're going to take an institutional angle here and talk through some of the missing puzzle pieces needed for institutions to come on-chain in an even bigger way. We're going to talk about this merging of private and public blockchains. It seems that they're going to be somewhat compatible with one another, which wasn't on my personal bingo card, but that's interesting. We'll get into what all that actually means.
1. Declan’s work as Head of Linea
Why don't we start with a brief introduction about who you are? Maybe we'll start with Declan. What are you doing at Linea?
Yeah, maybe just a quick background. I've spent nearly a decade now working on decentralized protocols, helping big institutions come on-chain and leverage this technology, all the way back from Hyperledger Fabric to R3 Corda and Digital Asset. More recently, at Consensys, I worked to build the Linea protocol, and we launched Linea mainnet 3 years ago, in the summer of 2023. Since then, we've helped to secure billions of dollars in value and onboard lots of DeFi applications.
The focus right now, as we go through this institutional wave, is leveraging that technology to help institutions come on-chain, bring their assets and their clients' assets on-chain, and essentially connect that all together, whether that's to other instances of blockchain or to the public mainnet, Ethereum included. That's really the key focus of the team at the moment and something I'm spending the majority of my time on.
2. What Is Phylax? Preventative security for blockchains and apps
And then, Odysseus, tell us all about what you're building at Phylax.
Yeah. We started this journey 2 years ago with a very simple quest: How can we make security actually preventative in crypto? How can we build systems that not only prevent hacks but at the same time keep the properties of blockchains, which means transparency, censorship resistance, trustlessness, and so on?
This led to building the circuit breaker, which we have built now. It's a piece of technology that integrates with blockchains—networks like Linea, for example—and allows them to offer a new set of tools to application developers on top of the network. They can define constraints to protect their protocols and, at the same time, create evidence such that their users know exactly what they are being protected against.
3. Ethereum’s security, with privacy and more protective controls for users
On one side, we want to protect the protocols themselves from malicious hackers. But at the same time, we want to surface to the end users, the investors, and the allocators what the actual risk-adjusted yield is that they're receiving when they're investing in a protocol. What is the counterparty risk they're taking, which is actually very opaque?
Wow. I want to play this clip from Declan, I believe. Yeah, Paris Blockchain Week. I feel like this 1-minute clip encompasses exactly what we want to talk about today. I'm just going to play this for everybody, and we can all watch it together.
I think the biggest anti-pattern I see today is the belief that you should still have your own private, permissioned Layer 1 blockchain. The reason for that is that the technology has now evolved, with zero-knowledge proofs and advances in consensus mechanisms, so that you can basically take your chain as a bank, as a CSD, as an institution, and privately connect it to every other one and Ethereum, while keeping scalability, privacy, and compliance. So you basically get the best of both worlds.
I think the key thing I would want people to take away is that you can now have your cake and eat it. You keep your own world, but you can also talk to everyone else, much like the internet. We're recreating the internet here, but focused around financial services. And I think—will financial institutions rip and replace, or will it happen incrementally? I think it has to be incremental.
Realistically, these systems work in parallel. You actually can show that the on-chain settlement is happening, the smart contracts are working, and the systems are mirroring this, and then they're showing it as well. Eventually, we'll get to a place of regulation when they'll say, “Right, on-chain finality is actually legal finality. We can recognize smart contracts legally,” and then we can do a big transition from this hybrid migration path.
Okay, so, Declan, listening to that, I feel like I've always been in this mindset that it's an either-or future: things are either going to be permissioned or permissionless. What I didn't realize is that these walled gardens—these banks—can literally just plug into Ethereum and still operate and use all the benefits of Ethereum while retaining all the benefits of their internal operations.
This is new to me. I didn't even know this was in existence. Can you break this down a little bit more for us? And what does this enable ultimately in DeFi?
Yeah. Maybe not everyone realizes this, but a lot of financial institutions have been experimenting with blockchain for a number of years, whether that's under the name of distributed ledger technology, enterprise blockchain, or private blockchains. I think 80% of activity today actually runs on Hyperledger Besu. All of these chains are sitting internal to these banks, to these financial institutions. They're effectively completely siloed and completely walled off. They're processing billions in value and volume per day—serious amounts of volume, serious amounts of activity—but it's all internal.
The big issue there is that, until recently, doing things on-chain, onto Ethereum or other Layer 2s, meant using systems that were completely public and permissionless, and that's just not going to work for most institutions. They still want to have control, compliance, and privacy. You sort of had what I call an institutional trilemma, right? You want to have privacy and control, which permissionless chains like Ethereum can't give you right now. You want to have liquidity and interoperability. You still want to be able to connect to and access retail, DeFi, and other customers.
But you also want to have performance, right? You want to have security, cost, and scalability. Up until recently, you weren't able to get all of these pieces. So what's changed? Why is this changing? And why does not everyone realize it yet? It's really down to zero-knowledge proofs.
Zero-knowledge proofs are the net-new innovation, with lots of investment in R&D, that now allow you to have what I call native interoperability. You can have, inside Ethereum, your own sort of walled garden, where you can spin up a Layer 2 and manage the permissioning around it.
You can have role-based access control, so the admins inside your bank who are using all of these internal applications—the existing interface—just plug into their local blockchain. They're then able to bring their clients' assets on-chain. This is the thing: Most banks have enormous client bases and lots of assets, and now they're able to tokenize them and bring them on-chain, whether that's cash, through tokenized deposits, or even securities. Now they're actually able to interoperate with their counterparties, whether that's a custodian, another bank, or a CSD. You can now basically interoperate through zero-knowledge proofs.
So you don't have to add an intermediary. You basically just leverage technology and math. Then you're able to verify that, yes, on Chain A, you're able to lock up the cash leg of a transaction. You want to put $100 into Account A on your local chain, your local bank, and send a message to a custodian, which is a separate blockchain that's all settling to Ethereum with zero-knowledge proofs. On that destination chain, they're able to confirm and actually release the security, or do something where they might access a tokenized money market fund.
That just wasn't possible until recently. There are still some tweaks to work out around interoperability. I think an interesting part of that conversation is what's happened recently with third-party bridge providers, all the security and risks happening there, and why native interoperability is a much better solution for this more risk-conscious target audience.
4. How Phylax can protect L2s and apps without sacrificing decentralization
To wrap up, I would say that until now, everyone has felt the need, because they have to have privacy and compliance, to have their own isolated chain. That actually brought some value, but it wasn't connecting them like the internet. They weren't able to connect to other counterparties or to Ethereum. A lot of institutions now want to bring tokenized money market funds and cash deposits on-chain and actually distribute them. Now they can do that without adding new intermediaries, and it's all able to happen through Layer 2 technology and through advancements in Ethereum, as well, including on Layer 1 itself, in terms of speed and finality. The key ingredient is zero-knowledge proofs, because we don't have to add these trusted intermediaries, who could obviously add security risk, latency, and other complexity.
Odysseus, how do we get that privacy, compliance, and permissionlessness? How do we get to that future based on where you're coming from building Phylax? Linea is live on Phylax, and I feel like what you're building is based on all the principles Declan laid out here.
Yeah, so it's interesting that in 2019 there was an academic paper that actually proved you can have cross-ledger communication without a trusted party. In this case, the trusted party becomes the zero-knowledge proofs, because the destination chain can verify the consensus—effectively, the zero-knowledge proof—of the sender chain.
This is something that, in a lot of ways, Cosmos was very early in pushing for, but they had a lot of other issues. Now, with zero-knowledge proofs, as Declan mentioned, you can have both privacy, because you only verify the proof of the state transition, and trustless interconnectivity.
I think it's very interesting how Declan mentioned that privacy means a lot of things to a lot of different people. This construct actually gives you the best of both worlds: on one side, you have the chain—the bank—that has access to all this data and needs access to all this data for compliance reasons. There's no way regulators will allow a bank ledger to be completely private from everybody, but at the same time, everybody else doesn't have access to the data; they can't see it. I think that's a very practical solution for bringing privacy and bringing these institutions on-chain in a way that's also regulatory-compliant.
5. What are institutions still waiting for, in order to come onchain?
Actually, okay, this is something I want to key in on a bit more. We've always been talking about bringing institutions on-chain for as long as I've been in crypto, almost to the point that I'm sick of saying it because they're here. But there are still impediments for them to really lean in even harder.
I want to ask both of you: what are still the missing pieces here, the missing pieces of the puzzle that we alluded to at the start of this podcast? Things that come to mind are privacy, security guarantees, governance, and just better infrastructure. What do you think they're still waiting for?
I think there are 2 important things to delineate when it comes to bringing institutions on-chain. On one side, they want to bring their money on-chain and benefit from on-chain yield opportunities, interoperability, permissionlessness, and new markets. There's a huge use case in being able to transfer huge amounts of money with lower fees.
Then there's the other part, which we started the conversation on: they want to bring their workflows on-chain. There are 2 different components. Right now, you see deployments happening on Ethereum mainnet in terms of capital, but a big missing part was how to bring workflows on-chain, which is what Declan mentioned about privacy. All these things were missing. But in both cases, at least from what we're working on day and night, it's security.
A hack is a physics event. If we're moving to, as Declan mentioned, a world where smart contracts become legal, it's a legal boundary. That means, by necessity, that once North Korea has the funds, legally, they're theirs; there's no way to undo it. That's very different from traditional finance, where it's just a ledger: you do a couple of meetings, it's expensive, and at the end of the day, you go back and update the spreadsheet.
In blockchain, you can't do that. Security in crypto is not like finance; it's closer to aerospace, where a bug or a fault results in people dying. Here, people aren't dying, but the result is similarly irreparable. This is why I think security is now becoming a huge concern, and that's why we're introducing this new technology.
You can't have capital formation where a hacker can end up with Apple stock, trade it, and then have Ethereum. A trader in New York could then own millions of dollars in stolen Apple stock. Who do you go after? What do you do there? You can't have high capital formation in that environment.
I've definitely experienced both perspectives: I want maximum permissionlessness, the most radical free market, and I want the good guys to come in and save our money. Lately, of course, with what we experienced in the Aave-related exploit—it wasn't Aave; it was ultimately LayerZero—but at the end of the day, all that money gets borrowed on Aave, and part of it ends up on Arbitrum, I was excited, relieved, and frustrated that the Arbitrum Security Council, if I'm saying that correctly, ultimately froze those funds. It was a reminder to me that your funds are not ultimately yours on that chain if these folks step in. This is sometimes referred to as multisig DeFi.
6. How Linea is helping institutions come onchain
I want a truly permissionless, free on-chain finance experience where my property is ultimately mine and no one can take that away from me. That's part of the reason a lot of my funds—nearly everything—ends up on an Ethereum Layer 1.
Declan, you're working more from the Layer 2 angle, obviously through Linea. You interface with big institutions and big institutional-type investors. SharpLink is one that's really leaned into Linea. As far as I know, they've already deployed or will be deploying more ETH on Linea. What do players like SharpLink tell you that they need to see from a security-guarantee standpoint and a governance-neutrality standpoint? What are the items on a checklist that they're communicating to you in order to deploy more funds on-chain?
For the persona of SharpLink, let's say a digital asset treasury company, or even just a financial institution, they care a lot more about the risk-adjusted returns of their deployments. They have an LP base and commitments to shareholders. The worst thing in their mind is for that deposit to basically go to zero. So they have to look at things from the risk profile of what would actually lead this investment to be written off.
In the case of DeFi, what is the underlying risk of the smart contracts? If it's a Layer 2, then what is the underlying risk of a Layer 2 or a Layer 1? What custodian am I using? What key management is signing? These are the things that come up more than what feels like a crypto-native conversation around censorship resistance.
In the day-to-day, these counterparties are already dealing with legal contracts and known counterparties, and they accept that risk. What they're actually looking for is better yield and better access to liquidity. Those are the things that are most important.
When it comes to the incident involving Kelp DAO and rsETH, I think that 3 months before that incident, Kelp had the majority of its TVL on Linea mainnet. In a different scenario, that could have been a very, very large problem for us, but it obviously landed a little bit more on Arbitrum's plate, with a lot of repercussions around the ecosystem. Do I think the security councils are the endgame for governance of Layer 2s? Absolutely not.
There needs to be an evolution there. I think the tricky thing is that if you really push people who are running L2s today on where they fall on the sort of cypherpunk values versus the practical reality of legal liability, if there is a hack that writes off more than 50% of the chain's economy—which almost happened to Ethereum back in the day, right? You think about the DAO; I think it was 2017, right? Basically, Ethereum made a decision: “Hey, this is too early in the journey. We need to resolve this.” I think Arbitrum is almost saying the same thing, is my interpretation, and I think it’s the right thing to do, given their stage.
At the end of the day, I can’t remember the exact TVL on Arbitrum, but it’s millions of dollars of people’s money. If that ends up in the wrong hands—in North Korea’s or terrorist groups’ hands—that is obviously not a good outcome, regardless of what you think about the cypherpunk stuff. It’s a sensitive line, right? I think there’s going to be an ongoing conversation to weigh that. Ultimately, different chains have to put down their governance philosophy, and then people can choose to opt into what works for them. The same will be true for enterprises as well, like treasury companies and financial institutions.
7. Freezing assets vs programmatic rules: what's the right threshold for action?
Yeah. I want to kick this over to Odysseus because you’ve sort of been writing about some of the stuff we’re talking about. We’ve gone through a scenario where a group of people made a decision, and there are other kinds of people in this loop that can make decisions. The issuers can make certain decisions if they’re there at the right moment in time. For example, some people sometimes criticize Circle for not acting or freezing tokens when some bad actor does a hack.
Again, I’ll let you speak to this, Odysseus, but this puts the issuer in a very precarious position. When do I act, and what is the threshold for acting? In a perfect world, this stuff is programmatic and people aren’t really in the loop, but I don’t think we’re quite there yet. I’d love to get your perspective, Odysseus.
Yeah, I think there’s no good answer. There are only bad answers, and it’s about choosing the least bad option. Specifically for Circle, do they want to be able to freeze the assets from North Korea? Of course they do, right? But the problem is that they’re a public company and they’re very regulated, right? They’re trying to make their stablecoin be sort of like digital cash. So the rules are part of the product, if not the whole product, right?
Why do you use Circle’s USDC and not some other stablecoin? For a lot of people, it’s because it’s regulated, because there’s a big institution behind it, and because they have to keep rules around how they hold their assets. I think what Circle probably did is make a forecast and say, “Okay, let’s say now we freeze the assets for the hackers. Amazing, we get the Twitter—I mean, we protect people. In a couple of years, the regulatory environment is more hostile, and then they tell us, ‘You froze assets before without a court order. Now we want to freeze the assets,’” maybe similarly to what happened with the Canadian truckers and their bank accounts a couple of years ago.
So they force them now to start doing that, and what happens is that everybody stops using USDC because it can no longer be trusted, right? They end up losing market share, and at the end of the day, they end up closing the shop. I think freezing the assets now would be an amazing thing to do, but it would probably open the door for an extinction-level event for USDC. They just couldn’t take that risk. They have a fiduciary duty to protect the business.
8. Why institutional demand for DeFi should help crypto transcend politics
Guys, I want to pivot to crypto from a geopolitical and regulatory lens. We’re talking more about some of the worst-case examples of bad actors on-chain. This whole thing that happened with Kelp DAO and LayerZero is obviously very unfortunate. There have been a lot of DeFi hacks.
One thing we haven’t been concerned about in this bear cycle—which was the prevailing headwind of the last bear cycle—is anti-crypto regulation. We’ve lived most of our existence in DeFi with these awful regulators that wanted to essentially wipe out access to DeFi, especially in the United States, which had ripple effects across the rest of the world.
I’m thinking ahead. In 2028, there’s another US presidential election. I think crypto, for better or worse, has been very closely associated with one party now: the Republican Party. So if the Democratic Party wins, I know many of us, as US citizens and abroad, are worried about there being a sweeping change in the mindset of regulators as it relates to crypto.
Long story short, how does crypto build systems that can survive a future hostile political environment or a future hostile regulator? What are your thoughts there?
I think the main thing to focus on—the thing that most of us can focus on—is just building great products, right? If crypto has product-market fit, no government or administration is going to stand up and try to add friction to block that. You’ll just be committing—maybe it’s a bit too strong to say “committing suicide”—but you’ll basically be reducing the impact of your local economy on a global financial services industry, right?
We’ve already seen, with the GENIUS Act and hopefully the CLARITY Act as well, that this has unlocked a huge amount of interest from significant players in the space who are now actively bringing assets on-chain. You’re seeing tokenized money market funds get product-market fit as an alternative to people just holding cash. Who is going to want to hold cash on their corporate balance sheet when they could just hold a money market fund? Collateral mobility—these are real product-market fits.
Obviously, stablecoins for retail and beyond payments, and who knows what the AI agent space could bring as well? Those could even proliferate further. Focusing on product-market fit is going to create so much use for the technology that it becomes almost a political issue to go against that because, let’s take the US, which obviously everyone looks to in terms of paving the way for global regulation. Even if the US, with a new administration, starts to pivot away from the support that the current administration has had, what if they lose ground to Europe?
MiCA is present. Europe is doing a lot with tokenization. There’s a lot happening in Asia right now as well. Eventually, this will become a geopolitical issue of losing ground, and corporations will push back because they’re the ones ultimately—including financial institutions—who will be losing customers, right? Once anyone can access your customer base, it opens up threats, right?
In the world we’re moving into—a world of 24/7—anyone could essentially create a fintech or a neobank that starts to overlap with your customer base. Basically, they want to keep everyone in the tent. Everyone’s in a rush to offer these 24/7 financial services across the US, across Europe, across Asia, across everywhere. I think if we focus on that, while trying to influence and provide good information for regulators to make the right decisions, no new administration is going to try to halt that train.
I think 2 things are important here. One is getting support and adoption from institutions. Basically, you create a bigger and bigger critical mass of people with both soft power and hard power to support the systems and technologies we’re building.
At the same time, we’re moving away from this very gray regulatory area where the administration can do whatever it wants and it’s legal because it’s gray. That’s why things like the CLARITY Act are very good, because it creates rules that both regulate us and protect us from arbitrary decision-making.
There’s something interesting I’ve been thinking very hard about: why there are certain people or factions in certain political parties that are so anti-crypto, right? They’re taking notes when Arbitrum freezes. They’re taking notes, and they’re going to use that argument and that event in the future. Based on discussions I’ve had, I think it’s a very interesting subject that is worth keeping in mind.
When it comes to institutions and banks, after 2008 they implemented very heavy regulation, and they feel, in a more theoretical sense, that they’re in control of the situation. They’re dealing with the enemy they know and control, and they have a very tight leash. I think crypto scares them in a lot of ways because these are systems that are much harder to control, especially if you have immutable, permissionless systems like Ethereum or Uniswap. That creates a very visceral reaction in them.
From my side, I could expect a more unfriendly stance purely for ideological reasons, purely from the fact that they feel they’re losing control and that scares them more, even if it’s better for the end consumer.
9. How a Phylax circuit breaker could have stopped the Aave rsETH exploit
It’s not necessarily rational. I want to bring this more to life with an example of the work you’re doing with Phylax because, again, we’re talking about the frustrations of DeFi users who want free and open, permissionless access to whatever we want. We want to be able to have transactions settle nearly instantly. We want to be able to access these DeFi applications 24/7, but we’re also wanting some sort of safety, some sort of fallback protection.
Again, it comes back to almost this idea of a circuit breaker. One simple analogy that really made things click for me with Phylax is that we just saw Aave never had any sort of circuit breaker. Fluid is a newer design for those who want to lend and borrow. One of the things that got Nomadic and me really interested was that they had built in a kind of circuit breaker where, I think, something like 20% or 30% of a specific asset had been withdrawn or maybe borrowed. There’s some sort of circuit breaker that kicks in there.
Expanding further than just the application, when I look at L2s, when I look at Linea, I think of Linea almost as a super app for DeFi. Ultimately, it hosts all this DeFi, but part of the reason I use it is because of the cheaper transactions and the ability to settle transactions faster. If I’m using the super app for DeFi that is Linea, I want a sort of circuit-breaker fallback safety mechanism to protect me if some terrible, worst-case scenario happens.
Talk to us about what you’re building. You guys tweeted something recently saying, “So far, we have stopped over 4,000 distinct drain attempts, $1.5 million in cumulative drain volume, and tens of distinct users who would have been victims.” I think this is all related to being live on Linea. Can you just contextualize this more for us?
Yeah. We integrated with Linea. I think we launched around January. By the way, I want to mention how amazing Besu is as a piece of technology. People in crypto don’t know that enough, but it’s actually a very good piece of software that allows you to very easily expand and extend it, which was great for us. It was a very easy integration, actually.
We then worked with 0x, where we helped them add a policy because a third-party integrator of 0x had mistakenly pushed users to give allowance to an immutable 0x contract, and then they started being drained. That was an ongoing vector that was impossible to fix because of the immutability of the smart contracts. So, because Phylax was on Linea, 0x could actually add a policy there to stop these drains.
So far, our system—which, by the way, runs on the Linea sequencer, on-prem, with no control from us—has stopped over 4,000 transactions.
10. What actually triggers the Phylax circuit breaker to detect and stop an attack?
I’ve got one follow-up here. Can you explain a little bit of the decision-making process that your system takes into account for how it stops something? Do you have an example of one of these? What actually goes on? What triggers it? How does it know to be like, “Oh, wait, this looks suspicious or malicious. Let’s put a stop to it”? What actually happens? Does the whole chain come to a halt? What is the interruption, essentially?
Basically, it’s 2 components. There is a set of smart contracts that we deployed on Linea, and this acts as a sort of public registry for these policies. It was important for us to have this on-chain primitive so that users know exactly what policies are being set for the smart contracts they care about. DeFi Dad should know which protocols he wants to use and what policies those protocols have to maintain the properties of the blockchain.
At the same time, there is a sidecar that runs by the sequencer. Whenever there is a transaction that is about to be added to a block, it takes the transaction and says, “Does this transaction interact with any smart contracts that have policies on them?” If they have a policy, it will execute the policy to see whether it should allow the transaction to go through or not.
These policies could be around runtime invariants, keeping the properties of the smart contracts, or they could be a circuit breaker. For example, there could be a policy where you don’t allow more than $50 million of inflows over an hour or a day. If a transaction is detected to break this policy—the circuit breaker—it’s not added to the block. Instead, it’s sent to a platform so the protocol team can review it and understand what happened and why it was dropped. It also creates a very rich audit log, which is useful for compliance reasons. They want to know exactly what happened and why.
What’s fascinating about all of this—and I think also why Linea was so interested—is that we don’t control any part of the process. This software is run by Linea, and the policies are set on the smart contracts, which means that if 0x didn’t want to add this policy, we couldn’t do anything about it. It’s up to them.
So, we have our cake and eat it too: We have security and these extra properties we can defend against, but it’s up to the protocol itself to decide whether it wants to opt in or not.
Yeah, that was a key part of the decision-making for us because there were a few security providers looking at delivering a similar solution, but Phylax was the only one that we felt really matched the properties of DeFi, where you still need to give people that optionality. You’re not enforcing anything; it’s up to the developers to add their assertions, so they can opt in.
On the actual network side, on the sequencer, we can still run things without introducing an intermediary because Fylax is on-prem. It runs as part of the Linea stack.
I think the big value proposition that I hope to see from this as well is providing other primitives like insurance in the future. If we think about traditional finance, especially for retail, people want access to insurance; they want guarantees. If you can start to reduce the security risk of DeFi hacks—which are actually getting worse over time with AI—and that allows insurers to underwrite that, you can start to give people insurance. It just gives them that extra comfort to come on-chain.
Ultimately, look, there are going to be all these neobanks leveraging financial primitives on blockchains. I think it’s pretty clear that that’s happening and will continue to happen. So, I think security and insurance in DeFi are going to be a huge piece of that offering.
11. TradFi can build private, composable walled gardens on Ethereum
If this kind of future that we’re talking about plays out, with these walled gardens being able to communicate with permissionless chains and banks tapping directly into Ethereum, what does this look like in 5 years? Do we have native privacy everywhere? Are institutions just interacting with Ethereum and L2s on a day-to-day basis? Either one of you, give us a future vision of what this could look like.
In 5 years—and I would always say it’s very hard to make 5-year predictions in crypto, but even more so in the world with the way that technology is moving—I would feel confident saying that in 5 years every major bank—not even a major bank, every bank, every financial institution—will have a ledger, a ledger of accounts and balances of their deposits, their clients’ assets, and their own assets.
They will be able to seamlessly interoperate with everyone else in a way that maintains their own levels of compliance and privacy. That will just look like being able to offer the exact same services they offer today, but 24/7. There will be some operational gains in the middle, but for the most part, it’ll just be effectively the same services 24/7. This will all be happening on blockchains underneath the hood.
People who will be using this inside these companies are still using the same ERPs, the same clunky enterprise UIs that we're all used to, right? But they're connected and integrated with these blockchains. I would like to think that the majority of that is all happening with the decentralization of Ethereum underpinning the overall architecture, and all leveraging zero-knowledge proofs. I think it's a pretty confident bet for the future.
And what I would like to see as well, or what I expect to see, is, maybe to your previous point, that most of the assets on-chain today—most of the tokenized assets outside of the crypto-native ones—are just digital twins of off-chain assets, right? You have a lump of gold somewhere, and someone has tokenized it and put it on-chain. Not much of that is actually doing anything inside DeFi today, right?
So what will happen is that we'll see entities and organizations bring more assets on-chain, and then TradFi, let's call it, is going to meet DeFi eventually, right? They'll be able to compose all these primitives that we've spent the last 5–10 years, as crypto-native builders, creating and understanding. When that world connects, that's going to be the big unlock, right? The financial system that has composability with DeFi—that is going to be the real technology innovation. And I think that happens within a 5-year time horizon.
And to add to that, I think the EVM and JSON-RPC will become the new Excel spreadsheets. That's how we define programmable finance.
12. How dApp and networks can get started implementing Phylax
Before we wrap up, Odysseus, tell us again: how would any other L2 roll out support for Phylax? How do they get started with Phylax?
Our technology is EVM-compatible and backwards-compatible. So any app can just talk to us, and they can get up to speed very quickly. At the same time, it works with L1s as well. We have plans to expand to Ethereum, Solana, Tempo, Arc, all these L1s.
The way it works there is through what we call application-specific sequencing. You collaborate with specific block builders or node operators, and they run the software. Then the application basically adapts; it will say, “I will only allow certain nodes or certain block builders to sequence my transactions.” Hopefully, we can see this everywhere and it can become a standard in security.
Yeah, that's really interesting. So not just at the network level, but at the application level, which again would be very interesting if, let's say, an Ethereum mainnet were to implement this eventually. Very cool. I would love to see some of the bigger DeFi blue-chip-type applications look into this. Again, I think it's just about providing more safety and security benefits for those of us who are users on-chain.
13. Closing
Guys, I think this is a great place for us to wrap up. Guys, thank you again for joining us. We'd love to have both of you back in the future. Declan, great to have you back for a second time. Keep up the great work, and best of luck with all the development work you're doing.
Thanks for having us, guys. Really appreciate it. Thank you so much for having us.