Four real, independently-documented cases of trust delegation in decentralized systems — a DAO foundation moving tokens before a vote finished counting; a decentralized platform found liable as a legal “unincorporated association,” with a related conviction now under appeal; a liquid-staking protocol governing the very operators it depends on, its dominance declining but still roughly five times its nearest rival; and a smart-contract feature that grants standing execution authority from a single signature — were tested against four plain questions:
Does the vote count?
Who’s on the hook?
Does yes ever expire?
Are too few hands holding too much?
None of the four cases answers every applicable question cleanly, and none reaches a fully safe, complete state. The clearest, most fixable single gap is the consent problem in smart-contract delegation, already being exploited through phishing.
No single reform closes more than one of these gaps at a time.
The power may be transmitted, but not the will.
— Jean-Jacques Rousseau, The Social Contract
This is the seventh report in the nemo 3 series. Report 4 (Reserve Architecture) established that delivery capacity and confidence-maintenance capacity can diverge independently within the same channel — this report’s central finding confirms that principle, in a new form, for trust delegation specifically.
Report 6 (Accountability Architecture) examined a structurally adjacent but distinct question — backward-looking responsibility after action, rather than this report’s forward-looking grant of authority.
In April 2023, the Arbitrum community was asked to vote on how to use roughly $1 billion worth of ARB tokens. The vote failed — overwhelmingly. And it didn’t matter. Weeks earlier, the tokens had already been moved into accounts the Arbitrum Foundation controlled directly, in a way that made the vote’s outcome structurally beside the point regardless of how the community felt about the plan. The vote happened. The tokens moved anyway.
This isn’t a story about one foundation making an unpopular call. It’s the first of four stories in this report, each showing a different way that delegating trust — handing authority, execution, or responsibility to someone or something else — can quietly stop working the way everyone assumed it would. For a regulator, the question these four stories raise together isn’t “did something go wrong here?” It’s harder:
Is there any version of delegated trust in this space that holds up all the way through — a vote that genuinely decides the outcome, someone genuinely answerable if it goes wrong, permission that doesn’t outlive its own relevance, and no single point of failure holding too much of the system together?
Across four different, independently-evidenced delegation mechanisms, this report finds the answer is: not yet, not fully, anywhere.
Four delegation mechanisms anchor this report, each drawn from documented, real-world incidents.
The Ratification Illusion covers cases where a decentralized organization’s formal vote exists but doesn’t actually control the practical outcome — Arbitrum’s pre-vote token transfer, and a related but importantly different case at Uniswap, where years of stalled votes eventually gave way to a decisive one, bundled with dissolving the administrator that had been standing in the way.
The Liability Question covers who — if anyone — can be held legally responsible when a decentralized structure causes harm, and the two paths organizations are now taking to answer that question before it’s forced on them: waiting to find out through enforcement — as happened to Ooki DAO, and to Avraham Eisenberg’s Mango Markets case, an outcome still being actively litigated — or adopting a legal wrapper in advance, such as Wyoming’s DUNA statute or a Cayman Foundation Company, to try to settle the question proactively.
Governing What You Depend On covers Lido, the largest Ethereum liquid-staking system, whose governing token holders both set the rules for, and rely on, the same relatively small set of technical operators — a structure whose risk has been easing in recent years, but hasn’t gone away.
One Signature, Standing Authority covers EIP-7702, a newer Ethereum feature that lets an account grant a smart contract the standing ability to act on its behalf, based on a single signature, with no requirement that the account holder confirm or renew that grant each time it’s used. Researchers and security firms have already documented this being exploited through phishing and automated “sweeper” attacks.
Each of these raises a different piece of a bigger, four-part question:
Does the Vote Count?
Who’s on the Hook?
Does Yes Ever Expire?
Are too few hands holding too much?
Four plain questions this report asks of every mechanism it examines.
Picture a company’s board asking shareholders to approve a merger, only for the CEO to have already signed the paperwork weeks before the vote closed. That’s structurally what happened with Arbitrum’s AIP-1 proposal in April 2023 — the Arbitrum Foundation moved the disputed tokens into its own operating accounts before the community’s vote against the proposal had even finished being counted. Facing sharp backlash — including a Foundation employee’s own blog post conceding the vote had been framed as “ratification, not a request” — the Foundation agreed to split the proposal and revisit parts of it. But the tokens it had already moved stayed moved. The DAO’s formal decision-making apparatus existed, functioned, and produced a clear result — 76.67% voted against. It just didn’t bind the outcome.
Uniswap’s history touches the same underlying question but resolves it differently, and the two aren’t quite parallel cases. For years, Uniswap’s token holders had the formal authority to activate a “fee switch” — a mechanism letting the protocol capture value for token holders rather than only for outside liquidity providers. That authority went unexercised, repeatedly, through a Foundation-administered process that never quite completed. When the vote finally happened, in December 2025, it was not a formality: 99.9% support, over 125 million tokens in favor against just 742 opposed — as decisive a governance outcome as this report’s evidence base contains. What keeps Uniswap’s case relevant here is not that the vote was hollow — it wasn’t — but that its resolution came bundled with dissolving the Uniswap Foundation itself and folding its functions into a for-profit company, Uniswap Labs, a structural change the vote wasn’t cleanly separable from.
Arbitrum shows a vote overridden by action taken before it
Uniswap shows a vote that was genuinely decisive, but only once it was bundled with a change to who administers the protocol at all
Does the Vote Count? At Arbitrum: no, not when it mattered most. At Uniswap: yes, decisively — but only after years of delay, and only alongside a change to the underlying administrative structure the vote wasn’t fully separate from.
Two starkly different accountability stories sit side by side here. In the first, the U.S. Commodity Futures Trading Commission pursued Ooki DAO — successor to a lending protocol called bZeroX — under a theory that a decentralized autonomous organization is, legally, an “unincorporated association,” meaning its participating token holders can be held personally liable for the association’s violations. A federal court agreed, by default judgment, that Ooki DAO qualified as a legal “person” that could be sued.
In the second, Avraham Eisenberg was convicted in 2024 of commodities fraud and market manipulation for what he described at trial as a maximally aggressive but fully protocol-compliant trade against Mango Markets — one that drained roughly $110 million using price mechanics the protocol itself allowed. In 2025, a federal judge threw out every count of that conviction, on procedural and evidentiary grounds. Prosecutors weren’t finished: in January 2026, they appealed, arguing the ruling “would unsettle traditional understandings of fraud.” That appeal remains unresolved as of this report — leaving the underlying question — does acting within a protocol’s own rules count as a legal defense? — not just open, but actively contested in court, rather than quietly settled by default.
Meanwhile, DAOs aren’t only waiting to find out which way liability theories eventually break. Wyoming’s 2024 DUNA statute and the long-standing Cayman Islands Foundation Company structure both let a DAO become a recognized legal entity before any enforcement action forces the question — two jurisdictions competing, in effect, to be the answer decentralized organizations reach for first.
Who’s on the Hook? Right now: it depends which path was taken, and the path forced by litigation is still being actively fought over rather than settled in either direction.
Lido lets Ethereum holders stake their ETH without running their own validator hardware — Lido’s governance token holders set the rules, and a set of 683-plus independent node operators actually run the validators that make the system work. What’s structurally interesting is that Lido’s governance simultaneously governs those operators and depends on them: if the operators underperform or coordinate against the DAO’s wishes, the DAO’s own decisions become hollow, regardless of how legitimately those decisions were reached.
Lido’s share of all staked Ethereum peaked around 32% in 2023 — close enough to the roughly one-third share at which a single actor could theoretically interfere with the network’s own consensus process that it became a live community concern. Since then, competition from rival providers has pulled that share down to roughly 22–25%, according to on-chain data tracked via Dune Analytics. Lido remains the dominant single provider by a wide margin — still around five times the size of its nearest competitor — but the direction of travel is toward less concentration, not more. The response hasn’t come only from Lido itself: in September 2025, Ethereum researchers drafted “Rainbow Staking,” a protocol-level proposal — building on an idea Ethereum Foundation researcher Barnabé Monnot first floated in 2024 — that would explicitly cap any single liquidity protocol’s share at 25%. Lido’s own 2025 “dual governance” mechanism adds a narrower, second layer of response: it lets stETH holders, not just LDO governance-token holders, veto DAO decisions, though only after a proposal has already passed a first vote.
Too Few Hands? The concentration is real, and Lido is still the dominant single actor by a wide margin — but the trend is toward less of it, not more, and the Ethereum community is actively engineering a structural cap rather than leaving the concern unaddressed.
Ethereum’s EIP-7702 upgrade lets a regular account temporarily behave like a smart contract — letting it batch transactions, sponsor its own gas fees, and generally act more flexibly. To do this, the account signs a single authorization that hands a specified contract standing execution authority over that account.
The design choice worth pausing on: that authorization doesn’t need to be renewed or reconfirmed each time it’s used. It’s closer to signing a single power of attorney that never expires and can be invoked by anyone who later gains control of the paperwork, than to approving each transaction as it happens.
Researchers studying real-world use of this feature found over 150,000 authorization events across more than 26,000 addresses, and identified concrete ways this exact design has already been turned into a phishing vector. Independent security firms have separately documented automated “sweeper” contracts and whitelist-bypass techniques exploiting the same underlying gap — tricking someone into signing away standing authority once, then exploiting that grant at a time of the attacker’s choosing, with no further action required from the victim.
Does Yes Ever Expire? For this mechanism, specifically: no — and that specific gap is already being actively exploited, not just theorized about.
Lay these four side by side, and a pattern emerges that none of the individual stories fully reveals on its own.
The Ratification Illusion involves formal authority not fully controlling outcomes at Arbitrum, and a more complicated version of the same question at Uniswap — but says nothing about who’s accountable when something goes wrong, how consent is maintained, or concentration risk.
The Liability Question involves whether responsibility ultimately attaches to anyone — an actively contested question right now, not a settled one — but says nothing about vote-binding, consent, or concentration.
Governing What You Depend On speaks partly to vote-binding and partly to accountability, but its sharpest finding is about concentration — real, easing, but not resolved.
One Signature, Standing Authority speaks only to consent, and speaks to it as its single most severe finding in this entire report: this mechanism actively fails the one test it can be measured against.
None of the four stories, examined on its own terms, reaches a fully clean result on every question that applies to it. Ask which of the four comes closest to a genuinely well-functioning, trustworthy delegation architecture — one where the vote counts, someone’s on the hook, yes doesn’t quietly expire, and too few hands don’t hold too much — and the honest answer, across this entire evidence base, is: none of them.
There’s a reason no single fix closes this gap:
“Whether a delegated authority’s formal decision actually controls the outcome and whether responsibility for that outcome can be legally attributed to someone are answered by entirely different mechanisms in this evidence base — one by administrative timing and technical capacity, the other by ex post litigation — so a delegation structure can fail completely at one while never even being tested against the other, and no single reform closes both gaps at once.”
In plainer terms: whether a vote actually controls what happens, and whether someone can be held responsible for what happens, get decided by completely different processes in every case this report examined — one by who moves fastest and holds the technical keys, the other by what a court eventually rules, sometimes years later, sometimes reversing itself, sometimes appealed again after that. A delegation structure can fail one test entirely while never even being checked against the other.
What this report finds, taken as a whole, is not that trust delegation in this space is broken beyond repair, or that any single actor is acting in bad faith. It’s that the functions anyone would want a trustworthy delegation system to perform — a vote that counts, someone who’s on the hook, consent that doesn’t silently expire, and safety from too few hands holding too much — are, in every case this report examined, handled by different, disconnected mechanisms rather than one coherent architecture. No mechanism examined here integrates more than two of these four functions at once, and none reaches a fully clean state on any of them.
This configuration looks reasonably stable in the near term — not because it’s healthy, but because its four pieces aren’t wired to each other. Some pieces are already moving on their own: Lido’s concentration is easing, and the Ethereum community has proposed a structural cap; Avraham Eisenberg’s Mango Markets case is actively before an appeals court rather than quietly settled either way. Neither development, even together, resolves the other two gaps, because nothing currently connects them.
For a regulator, the clearest, narrowest, most tractable next step in this evidence base remains the consent gap in EIP-7702-style delegation — it carries the most direct empirical documentation and the most identifiable fix, a wallet or protocol-level standard requiring renewed confirmation, and unlike the other three phenomena, shows no sign of resolving on its own. Concentration in liquid staking still carries the widest consequence if it were ever to reach a dangerous threshold — its stakes extend beyond Lido’s own users into the integrity of Ethereum’s underlying consensus mechanism generally — but both the trend and the community’s own response point toward this risk easing rather than demanding the most urgent intervention of the four.
None of this argues for a single sweeping rule covering “trust delegation” as one category.
The evidence here doesn’t support treating these four problems as one problem — a fix for any one of them, on its own, would leave the other three completely untouched.
Genre declaration: This is a structured, evidence-based analysis of real, documented cases — not opinion journalism, and not a prediction of future outcomes. Every claim traces to a publicly verifiable source, listed below.
Epistemic Boundary Statement: This report does not claim to have identified every delegation mechanism relevant to trust delegation, nor does it predict which of the four gaps identified will close first, or whether they will close at all. It describes a specific, evidenced structural pattern across four independently-verified cases as of August 2026.
Method: Sources were gathered directly from primary and credible secondary documents — government press releases, court records, protocol specifications, peer-reviewed and preprint research, and established industry outlets — organized into a formal structural model, and evaluated against four functional requirements, plain-language versions of which appear throughout this report as
Does the Vote Count?
Who’s on the Hook?
Does Yes Ever Expire?
Are too few hands holding too much?
Each phenomenon was scored against each requirement as Full, Partial, Absent, Contested, or Not Applicable, where a requirement simply doesn’t pertain to what a given mechanism does.
Analytical lens coverage: Nine analytical lenses drawn from a broader 81-lens catalogue were applied across six conceptual perspectives — examples include Legitimacy Gap, the distance between formal and practically-recognized authority, and Accountability Structures, how responsibility gets assigned after the fact — chosen for direct structural fit with the evidence, not applied uniformly to every case.
Zone assignments and migration: Each phenomenon’s overall position, or “zone,” reflects how close it comes to fully meeting the functional requirements that apply to it — full performance sits at the center of the model, partial or contested performance sits in the margins, and at least one fully unmet requirement places a phenomenon outside. “Migration” refers to a predicted future shift in that position if a specific, named trigger condition occurs; none of the four migrations predicted in this report is treated as certain.
Geographic scope: Primarily the United States and offshore legal-wrapper jurisdictions (Wyoming, Cayman Islands), reflecting where the evidence concentrated. European Union material — digital identity regulation, AI governance — was investigated but did not yield evidence robust enough to support a distinct finding at this report’s evidentiary bar, and is not included in the findings above.
Contested reference count: This report carries 20 references rather than the standard 18 because one functional requirement — the accountability question in The Liability Question — is rated Contested, a rating reinforced rather than resolved by Eisenberg’s active appeal.
For readers who want the underlying analytical vocabulary: each phenomenon above also has a formal, mechanism-descriptive label used in the underlying analytical model, available in the companion technical artifacts for this report.
Understanding Key Metrics
Zone (Center / Margins / Outside): How close a phenomenon comes to fully meeting the functional requirements that apply to it.
Migration: A predicted future shift in zone, tied to a specific, named trigger condition — never treated as certain.
Functional requirement: A specific capability a trustworthy delegation system would need. This report uses four: does the vote count, who’s on the hook, does yes ever expire, too few hands.
Not Applicable vs. Absent: “Not Applicable” means a requirement simply doesn’t pertain to what a given mechanism does; “Absent” means the requirement does pertain, and the mechanism fails to meet it.
This report combines research conducted by a human research team with work by multiple AI models. The AI contributed to source research and verification, comparative analysis, and the drafting of the narrative, under ongoing human direction and review. The report was reviewed at each stage and was not published without explicit human approval.
AI systems are capable of errors, including errors that can survive ordinary checking. This report therefore does not present AI involvement as a guarantee of accuracy, but as part of a supervised research process. If you identify something that appears incorrect or unsupported, we welcome the correction.
20 references — Contested status, per Methodology above. Grouped by exact analytical lens name, per the Reference Subsystem. Several sources support more than one lens and appear once per lens they support, each time with an annotation specific to that lens.
Arbitrum’s First Governance Proposal Turns Messy, With $1B ARB Tokens at Stake
CoinDesk (2023)
https://www.coindesk.com/business/2023/04/01/arbitrums-first-governance-proposal-turns-messy-with-1b-arb-tokens-at-stake
[accessed 2026-08-04]
For The Ratification Illusion: establishes the “ratification, not a request” framing at the center of the distance between Arbitrum’s formal DAO vote and the Foundation’s actually-recognized administrative authority.
Arbitrum reels from voting drama as concerns over decentralisation loom large
DL News (2023)
https://www.dlnews.com/articles/defi/arbitrum-governance-vote-arb-dao-airdrop-aip-1-proposal/
[accessed 2026-08-04]
For The Ratification Illusion: documents delegate voting patterns showing the DAO’s near-unanimous formal opposition, underscoring how far that formal position sat from what actually happened.
Arbitrum Backtracks on AIP-1 After Community Backlash
Unchained (2023)
https://unchainedcrypto.com/arbitrum-backtracks-on-aip-1-after-community-backlash/
[accessed 2026-08-04]
For The Ratification Illusion: records the Foundation’s own concession, in its own communications, that the vote had been framed as ratification rather than a genuine request for authorization.
Uniswap Governance Rejects Proposal Enabling DAO To Make Fee Changes
The Defiant (2024)
https://thedefiant.io/news/defi/uniswap-governance-shoots-down-fee-switch-proposal-again
[accessed 2026-08-04]
For The Ratification Illusion: establishes the multi-year gap between Uniswap DAO’s formal fee-switch authority and its actual exercise.
Uniswap DAO to activate ‘fee switch,’ burn almost $600m UNI
DL News (2025)
https://www.dlnews.com/articles/defi/uniswap-dao-to-activate-fee-switch-and-burn-100m-uni-tokens/
[accessed 2026-08-04]
Vote margin (99.9%, 125,342,017 for / 742 against) corroborated by CryptoNews, The Block, and AMBCrypto, December 25–26, 2025.
For The Ratification Illusion: establishes that Uniswap’s formal authority, once finally exercised, was genuinely decisive — the distinguishing fact that separates this case from Arbitrum’s.
Arbitrum’s First Governance Proposal Turns Messy, With $1B ARB Tokens at Stake
CoinDesk (2023)
https://www.coindesk.com/business/2023/04/01/arbitrums-first-governance-proposal-turns-messy-with-1b-arb-tokens-at-stake
[accessed 2026-08-04]
For The Ratification Illusion: establishes that the Arbitrum Foundation held independent administrative capacity over the disputed 750M ARB regardless of the DAO’s formal vote.
Arbitrum reels from voting drama as concerns over decentralisation loom large
DL News (2023)
https://www.dlnews.com/articles/defi/arbitrum-governance-vote-arb-dao-airdrop-aip-1-proposal/
[accessed 2026-08-04]
For The Ratification Illusion: documents the specific timing of the token transfer, showing the administrative capacity was exercised while the system remained fully operational and the vote still open.
Arbitrum Backtracks on AIP-1 After Community Backlash
Unchained (2023)
https://unchainedcrypto.com/arbitrum-backtracks-on-aip-1-after-community-backlash/ [accessed 2026-08-04]
For The Ratification Illusion: shows that even after backlash, the Foundation’s administrative control extended to deciding which parts of its own prior action to revisit — the tokens already moved were not among them.
Arbitrum’s First Governance Proposal Turns Messy, With $1B ARB Tokens at Stake
CoinDesk (2023)
https://www.coindesk.com/business/2023/04/01/arbitrums-first-governance-proposal-turns-messy-with-1b-arb-tokens-at-stake
[accessed 2026-08-04]
For The Ratification Illusion: establishes that the token transfer, once executed, was not undone even after the Foundation conceded to community pressure on other points.
Arbitrum reels from voting drama as concerns over decentralisation loom large
DL News (2023)
https://www.dlnews.com/articles/defi/arbitrum-governance-vote-arb-dao-airdrop-aip-1-proposal/
[accessed 2026-08-04]
For The Ratification Illusion: pins the transfer’s timing to weeks before the vote closed, marking the specific point past which the DAO’s eventual opposition could no longer change the practical outcome.
Uniswap DAO to activate ‘fee switch,’ burn almost $600m UNI
DL News (2025)
https://www.dlnews.com/articles/defi/uniswap-dao-to-activate-fee-switch-and-burn-100m-uni-tokens/
[accessed 2026-08-04]
For The Ratification Illusion: establishes that Uniswap Foundation’s dissolution, executed alongside the UNIfication vote, is not a position a future contrary vote could easily unwind.
U.S. Department of Justice — “Man Convicted for $110M Cryptocurrency Scheme,” Office of Public Affairs (2024)
https://www.justice.gov/archives/opa/pr/man-convicted-110m-cryptocurrency-scheme [accessed 2026-08-04]
For The Liability Question: establishes Eisenberg’s original conviction on commodities fraud, market manipulation, and wire fraud charges.
Federal Judge Overturns All Criminal Convictions in Mango Markets Case Against Avraham Eisenberg
TRM Labs (2025)
https://www.trmlabs.com/resources/blog/breaking-federal-judge-overturns-all-criminal-convictions-in-mango-markets-case-against-avraham-eisenberg
[accessed 2026-08-04]
For The Liability Question: establishes the vacatur of that conviction on venue and evidentiary grounds, the first reversal in an accountability question this report finds still unsettled.
Prosecutors appeal acquittal of Mango Markets exploiter Avraham Eisenberg
DL News (2026)
https://www.dlnews.com/articles/defi/prosecutors-appeal-acquittal-of-mango-markets-exploiter/
[accessed 2026-08-04]
For The Liability Question: establishes the government’s January 2026 appeal, confirming the underlying legal question is actively contested rather than settled by the vacatur alone.
U.S. Commodity Futures Trading Commission — Press Release 8590-22
”CFTC Imposes $250,000 Penalty Against bZeroX, LLC... and Charges Successor Ooki DAO” CFTC (2022)
https://www.cftc.gov/PressRoom/PressReleases/8590-22
[accessed 2026-08-04]
For The Liability Question: establishes the CFTC’s foundational theory that a DAO’s participating token holders can bear personal liability as an unincorporated association.
Perkins Coie — What’s Next for DAOs in the Wake of the Ooki Decision?
Global Fintech & Digital Assets Blog (2023) https://www.fintechanddigitalassets.com/2023/07/whats-next-for-daos-in-the-wake-of-the-ooki-decision/
[accessed 2026-08-04]
For The Liability Question: confirms the CFTC’s theory succeeded judicially, via default judgment establishing Ooki DAO as a legal “person.
The DUNA: An Oasis For DAOs
a16z crypto (2024)
https://a16zcrypto.com/posts/article/duna-for-daos/
[accessed 2026-08-04]
a16z crypto is a venture firm with a direct financial interest in DAOs having a workable legal wrapper; cited for statutory description, not as neutral commentary.
For The Liability Question: describes the Wyoming DUNA statute as a legal-wrapper option DAOs can adopt in response to the general enforcement-exposure environment, without any direct negotiation between adopters and any regulator.
CoinGeek — “Wyoming’s new law recognizes DAOs as non-profits,”
CoinGeek (2024)
https://coingeek.com/wyoming-new-law-recognizes-daos-as-non-profits/
[accessed 2026-08-04]
For The Liability Question: independently corroborates the DUNA statute’s specific language and legislative history.
Mourant — “Cayman Islands foundation companies:
The ideal vehicle for DAOs and crypto trading,”
Mourant (2024)
https://www.mourant.com/updates/cayman-islands-foundation-companies-the-ideal-vehicle-for-daos-and-crypto-trading/
[accessed 2026-08-04]
Mourant is a law firm that markets and profits from Cayman Foundation Company formations; cited for structural description, not as neutral commentary.
For The Liability Question: establishes the competing offshore legal-wrapper option, evidencing the same trace-driven adoption dynamic in a different jurisdiction.
U.S. Department of Justice — “Man Convicted for $110M Cryptocurrency Scheme
Office of Public Affairs (2024)
https://www.justice.gov/archives/opa/pr/man-convicted-110m-cryptocurrency-scheme [accessed 2026-08-04]
For The Liability Question: establishes that Eisenberg’s trade was executed entirely within Mango Markets’ own protocol rules — the “technically rule-compliant” defense theory at the center of the case.
Ethereum Foundation
EIP-7702: Set Code for EOAs
eips.ethereum.org (2024)
https://eips.ethereum.org/EIPS/eip-7702
[accessed 2026-08-04]
For One Signature, Standing Authority: establishes that delegation under this mechanism operates entirely through code-level authorization rather than a legal instrument requiring case-by-case sanction.
Qi, M., Wang, Q., Li, R., Zhu, T., Chen, S. — EIP-7702 Phishing Attack
arXiv:2512.12174 (2025)
https://arxiv.org/abs/2512.12174
[accessed 2026-08-04]
For One Signature, Standing Authority: empirically measures how that code-level authorization is exploited in the wild, independent of any legal characterization of the underlying act.
Lido Loses Ground: Staked ETH Market Share Falls to 22.82% YTD Low While LDO Slides
CCN (2026)
https://www.ccn.com/analysis/crypto/lido-loses-ground-staked-eth-market-share-falls/ [accessed 2026-08-04]
For Governing What You Depend On: establishes Lido’s current, Dune Analytics-sourced stake share and its decline from a 2023 peak, relative to the systemic threshold at which a single protocol could interfere with Ethereum consensus.
Did Lido fly too close to the sun? Inside the centralization debate
Blockworks (2023)
https://blockworks.co/news/lido-centralization-debate-ethereum
[accessed 2026-08-04]
For Governing What You Depend On: documents the community concern that first formed around Lido’s approach toward that same threshold, and Lido’s own initial response.
Lido Loses Ground: Staked ETH Market Share Falls to 22.82% YTD Low While LDO Slides CCN (2026)
https://www.ccn.com/analysis/crypto/lido-loses-ground-staked-eth-market-share-falls/
[accessed 2026-08-04]
For Governing What You Depend On: establishes where brittleness currently sits — a single provider still roughly five times the size of its nearest competitor, even after a multi-year decline.
Did Lido fly too close to the sun? Inside the centralization debate
Blockworks (2023)
https://blockworks.co/news/lido-centralization-debate-ethereum
[accessed 2026-08-04]
For Governing What You Depend On: describes Lido’s dual-governance veto mechanism as a direct institutional response to that concentrated fragility.
The ‘Decentralization’ Battle of Ethereum Staking:
Vitalik Buterin Promotes ‘Rainbow Staking,’ Lido Faces Siege as the Dominant Player
AiCoin (2025)
https://www.aicoin.com/en/article/488240
[accessed 2026-08-04]
For Governing What You Depend On: establishes that the Ethereum research community itself has proposed a protocol-level structural response — an explicit 25% share cap — evidencing that this fragility is recognized and actively engineered against, not merely latent or unaddressed.
EIP-7702: Set Code for EOAs
eips.ethereum.org (2024)
https://eips.ethereum.org/EIPS/eip-7702
[accessed 2026-08-04]
For One Signature, Standing Authority: establishes the technical design itself — a single signed authorization grants standing execution capacity with no built-in mechanism requiring renewed consent.
Qi, M., Wang, Q., Li, R., Zhu, T., Chen, S. — EIP-7702 Phishing Attack
arXiv:2512.12174 (2025)
https://arxiv.org/abs/2512.12174
[accessed 2026-08-04]
For One Signature, Standing Authority: documents over 150,000 authorization events and identifies the specific pathways by which the absence of renewed consent becomes exploitable.
Security First Approach to EIP-7702
Fireblocks (2026)
https://www.fireblocks.com/blog/security-first-approach-to-eip-7702
[accessed 2026-08-04]
Fireblocks sells wallet-security infrastructure and has a commercial interest in publicizing this risk category.
For One Signature, Standing Authority: independent institutional- security corroboration of the same underlying consent gap, from a different vantage than the academic study above.
EIP 7702 Security Considerations
Halborn (2025)
https://www.halborn.com/blog/post/eip-7702-security-considerations
[accessed 2026-08-04]
Halborn sells security-audit services and has a commercial interest in publicizing this risk category.
For One Signature, Standing Authority: documents a demonstrated whitelist-bypass exploit, showing the consent gap being defeated through a distinct technique from the phishing vector documented elsewhere.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.