Blog

With 34% of ETH Staked, How Should You Stake in the Era of Native Compounding?

With 34% of ETH Staked, How Should You Stake in the Era of Native Compounding?

Two notable developments have recently emerged in Ethereum staking.The first is 34.7%.As of late August, approximately 42.4 million ETH was staked across Ethereum—about 34.7% of the total supply and a new all-time high. More strikingly, over 2.2 million ETH was still waiting in the validator entry queue. At the current activation rate, new staking deposits need to wait nearly 39 days before activation.The second development came from traditional finance.In August, Fidelity continued laying the groundwork for staking through its Fidelity Ethereum Fund (FETH). Fidelity entered into custody agreements with Anchorage Digital and BitGo and established a mechanism for allocating staking rewards.These two seemingly unrelated developments reflect the same broader shift. Over the past six months, Ethereum staking has rapidly evolved from a relatively technical onchain operation into an increasingly standardized form of asset management.For ordinary ETH holders, this raises a more practical question than whether to stake:If you decide to stake, should you run your own node, choose non-custodial native staking, use Lido, or simply leave your ETH on an exchange?1. Staking Is No Longer Just About “Locking Tokens to Earn Yield”Let us begin with the fundamentals.After The Merge, Ethereum moved away from proof of work. Validators now stake ETH to participate in block validation and consensus.The minimum requirement for operating an independent validator is 32 ETH.Validators earn consensus-layer rewards from the Ethereum protocol by remaining online, submitting correct attestations, and proposing blocks when selected. Conversely, prolonged downtime can result in penalties, while serious violations such as double-signing may lead to slashing.From this perspective, staking rewards are not “interest” generated from nothing. Users help secure Ethereum by staking ETH and receive protocol rewards in return.For years, however, Ethereum staking had a somewhat counterintuitive limitation: rewards did not compound natively.With legacy 0x01 validators, any balance above 32 ETH—including an additional 0.5 or 1 ETH earned in consensus-layer rewards—was periodically swept to the withdrawal address instead of continuing to participate in staking.To stake those rewards again, users had to accumulate enough funds to meet the staking requirement and deploy another validator.Pectra changed this.The maximum effective balance of the new 0x02 validators is 2,048 ETH. Once the balance exceeds 32 ETH, it can continue increasing the validator’s effective balance under protocol rules. For long-term stakers, the previous cycle of “earn rewards, withdraw them, and redeploy the funds” can now be completed automatically within Ethereum’s native protocol for the first time.Further reading:“As 8 Million ETH Starts Moving, Is Ethereum Staking Undergoing a Structural Shift?”Looking at developments over the past six months, ETH staking is clearly moving beyond the relatively basic model of “lock 32 ETH and earn rewards” toward a more mature asset-management system.Fidelity’s proposed move to incorporate staking rewards into an exchange-traded product addresses the question of who stakes on behalf of traditional investors. Pectra improves capital efficiency at the validator level. Liquid staking protocols such as Lido provide liquidity, while professional node operators separate validator operations from control over assets.Comparing staking options today therefore requires more than looking at APR. Users need to weigh several factors together.2. Four Ways to Stake ETH—and What Actually Sets Them ApartETH staking options currently available to ordinary users can broadly be divided into four paths.On the surface, they may appear to be four different ways of earning the same rewards. Their fundamental differences, however, lie in which responsibilities users delegate and which risks they assume.1. Running Your Own Node: The Most Direct Protocol Rewards and the Greatest ControlThe purest form of ETH staking is to provide 32 ETH, run execution- and consensus-layer clients, and maintain your own validator.You decide how the node is deployed, which clients it runs, and when the validator exits. Protocol rewards also do not need to be shared with a liquid staking protocol or exchange.The barriers are considerably higher, however.In addition to at least 32 ETH, you need reliable hardware and internet connectivity. You must also maintain client software, monitor validator performance, and protect the validator’s keys over the long term.Ultimately, running your own node means exchanging greater technical and operational responsibility for maximum control and more direct access to staking rewards.2. Non-Custodial Native Staking: Keep Control of Your Assets While Outsourcing OperationsThe second option can be understood as a middle ground between solo staking and fully custodial staking.Users still provide 32 ETH to create an independent validator. Their ETH enters Ethereum’s native staking system and is not exchanged for another token, while responsibility for operating the node is delegated to a professional provider.The most important distinction is that withdrawal authority can be separated from day-to-day validator operations.Ethereum validators use different keys for different purposes. The signing key is used for routine validator duties, including signing attestations and block proposals, and can be managed by a professional node operator. The withdrawal key, which determines where the principal and rewards can ultimately be withdrawn, remains under the user’s control.This separation is a critical dividing line between non-custodial native staking and custodial staking through an exchange.imToken’s non-custodial ETH staking service, for example, follows this model. Further reading:“What Is imToken’s Non-Custodial ETH Staking Service?”Users with at least 32 ETH can create an independent validator. They retain control over the withdrawal key while professional infrastructure providers handle node operations. imToken also offers a choice between compounding and auto-withdrawal validators.This option is best suited to users who have at least 32 ETH, want native staking rewards, value self-custody, but do not want to maintain a validator themselves every day.“Non-custodial,” however, does not mean “free of third-party risk.” A node operator could still experience downtime, configuration errors, or even a slashing event.What users delegate is therefore not ownership of the assets, but the operational risk associated with running the validator.3. Lido: Trading Some “Nativeness” for LiquidityFor users who do not have 32 ETH—or simply do not want their ETH tied up while waiting in a validator exit queue—liquid staking offers a very different path.Lido is the most prominent example.When users deposit ETH into Lido, the protocol allocates the funds to node operators for Ethereum staking and issues stETH to users in return.ETH that would otherwise remain locked in staking and could not be transferred directly is therefore represented by a liquid onchain asset. Users can transfer or trade stETH and deploy it across DeFi applications such as lending protocols and liquidity pools.Users who want to exit can redeem stETH for ETH through Lido’s withdrawal process or sell it for ETH directly on a decentralized exchange. The latter does not require waiting for the underlying validators to exit, but the user must accept the prevailing market price and slippage.stETH also reflects accumulated staking rewards through a rebasing mechanism. For ordinary users, this largely removes the need to claim rewards and manually restake them.That convenience comes with an additional layer of risk.Lido charges a protocol fee and allocates portions of the rewards to node operators, the DAO treasury, and other participants, with users receiving the remainder. More importantly, liquid staking introduces risks involving Lido’s smart contracts, protocol governance, node operators, and stETH’s secondary-market liquidity.It is also important to understand that the market price of stETH is not fixed at exactly 1 ETH and may trade at a discount during periods of heavy selling.Using stETH in additional DeFi protocols introduces further smart-contract and liquidation risks.imToken’s ETH staking interface is also integrated with Lido. Users can participate in liquid staking and hold stETH directly without owning 32 ETH.4. Exchange Staking: The Lowest Barrier, but What You Hold Is a Platform PromiseThe final option—and perhaps the one most familiar to new users—is to deposit ETH on an exchange and tap “Staking.”From a user-experience perspective, this is undoubtedly the simplest approach.There is no need to provide 32 ETH, understand validator infrastructure, manage signing or withdrawal keys, or worry about whether a server goes offline.The exchange pools ETH from many users, operates validators, and credits a portion of the rewards to user accounts according to its own rules.For the same reason, however, this option requires the greatest degree of trust.When an exchange displays “1 ETH staked,” that balance is often first and foremost an entry in the platform’s internal account system. How the underlying validators are deployed, how much ETH is actually staked, how rewards are compounded, how much the platform deducts, and how redemptions are funded all depend on the platform’s product design.More importantly, the assets themselves are held in custody by a centralized platform.This does not mean exchange staking is necessarily a poor choice. For beginners who already keep ETH on an exchange for the long term and do not intend to manage an onchain wallet themselves, it may still offer the lowest operational barrier.But that convenience comes from delegating custody, validator operations, reward allocation, and the entire exit process to the platform.3. There Is No Single “Highest-Yield” Option—Only a Risk Mix That Fits You BetterPutting the four options side by side reveals an interesting pattern.The evolution of Ethereum staking products is not driving every solution toward the same endpoint. Instead, the market is unbundling and recombining the capabilities different users actually need. Running your own node maximizes control. Non-custodial native staking separates ownership of funds from validator operations. Lido recombines staking rewards with liquidity. Exchanges hide more of the underlying complexity, offering the lowest operational barrier in exchange for centralized custody. Fidelity’s plan to incorporate staking into an exchange-traded product takes this one step further. Investors may not need to hold ETH onchain or understand how validators operate. A traditional financial product can manage custody, node operations, reward generation, and the eventual distribution of staking proceeds.From this perspective, staking is increasingly becoming part of mainstream financial infrastructure.So how should ordinary users choose?If you have at least 32 ETH, possess the necessary technical skills, place a high value on independent control, and want to participate directly in the Ethereum network, running your own validator still provides the greatest control.If you also have at least 32 ETH but do not want to handle long-term validator maintenance—and still want to retain withdrawal authority—non-custodial native staking offers a natural compromise.If you hold less than 32 ETH or regularly trade, lend, and use other DeFi applications, a liquid staking solution such as Lido provides considerably greater flexibility in exchange for an additional layer of protocol risk.Exchange staking is better suited to users who already accept centralized custody and want to minimize operational complexity, provided they understand that platform risk does not disappear simply because the interface includes a “Staking” button.When comparing Ethereum staking options today, APR should not be the first metric users compare.Suppose two products differ in annualized yield by only a few tenths of a percentage point. One requires users to surrender complete custody to a third party, while the other leaves withdrawal authority in their own hands. One requires waiting in the validator exit queue, while the other allows users to sell an LST on the open market. One compounds rewards natively, while the other depends on how a platform processes and distributes them.These differences are often far more important than the headline APR.Staking rewards never exist in isolation.How much you earn, how much liquidity and control you give up to earn it, and how much additional risk you assume are all part of the same calculation.
2026-08-31
AI Agents Come of Age: What’s Still Missing Between Simulation and Live Trading?

AI Agents Come of Age: What’s Still Missing Between Simulation and Live Trading?

If you are a frequent user of AI tools, you have probably witnessed a defining shift in how AI agents have evolved:Beyond the leap in intelligence delivered by foundation models themselves, agents are beginning to look increasingly like real “workers.”From the earliest chatbots to the growing maturity of infrastructure such as MCP, Skills, and agent harness, agents have gained a growing range of ways to act. They can open webpages, retrieve real-time data, operate software, and even connect to wallets and trading accounts.But this progress has exposed a practical problem: knowing how to use tools and being able to complete a real task are two very different things.An agent capable of taking responsibility for a task cannot simply receive an instruction and call an API once. It must operate in a constantly changing environment and continuously adapt its actions based on the outcomes it observes.Financial markets make this distinction particularly clear.You can ask an agent, “Which team is more likely to win this match?” Within seconds, it may produce a convincing analysis.But change the task to, “Here is some capital. Trade continuously in prediction markets over the next month and improve returns while keeping maximum drawdown under control,” and it becomes an entirely different problem.The agent must continuously monitor real-time news, odds, and order books; determine whether information has already been priced in; decide when to open, increase, or exit a position; and adjust its strategy when its previous judgment proves wrong.A wave of recent infrastructure innovations appears to be filling in these previously missing pieces, one by one.1. Do AI Agents Need a Simulated Training Ground?In mid-August, SKALE launched an intriguing new product called AgentPit.Put simply, AgentPit is a simulated trading sandbox built specifically for AI agents operating in prediction markets. It synchronizes market data from Polymarket and provides compatible APIs, while using a production-style central limit order book (CLOB), Conditional Token Framework (CTF) tokens, and settlement mechanics. The key difference is that real funds are replaced with simulated USDC.Developers can allow agents to read live market data, place orders, have them matched, and manage positions without risking financial losses. They can also observe the collective behavior that emerges when multiple agents compete within the same order book.At first glance, this may resemble the backtesting and paper-trading environments used in traditional quantitative finance. For AI agents, however, its significance runs much deeper.Agents face a long-standing question: how can we tell whether an agent can actually trade?The industry has traditionally relied heavily on static benchmarks to evaluate large models—solving math problems, repairing code, or summarizing long documents.Complex decisions in the real world, however, do not come with predetermined correct answers. This is especially true in financial markets.Suppose an agent estimates that the fair value of “YES” shares in a prediction market is $0.70, while the current market price is $0.55. After the agent buys, the price might continue falling to $0.45, or breaking news could send it sharply higher. The order book’s available liquidity at that moment will also directly affect the actual average execution price.This means the agent cannot make one prediction and consider the task complete. It must continue dealing with the real consequences of its previous decisions.That is the core value of AgentPit: it gives agents a dynamic feedback loop that closely resembles a production environment:Observe → Evaluate → Execute → Receive feedback → Adjust → Execute againHere, “training” does not necessarily mean that the agent automatically modifies the parameters of its underlying model after every trade. Instead, AgentPit provides an environment in which strategies can be rerun, results evaluated, and workflows iterated repeatedly.Just as an autonomous driving system must encounter a wide range of extreme situations in simulators before taking to public roads, a financial agent that may eventually manage real funds cannot be granted control over assets after only a few prompt tests. It first needs to demonstrate how it performs in an environment that requires continuous decision-making.But this raises another question.Strong performance in a simulated environment does not mean that real money can immediately be handed over to AI. A more critical layer is still needed in between.2. Infrastructure Converges as Payments and Trading Become Native Building Blocks for AgentsLooking at recent moves by leading cloud providers and trading platforms, one trend is difficult to miss: the infrastructure on which agents operate is rapidly becoming standardized and interconnected.The first major development is the arrival of machine-native payment protocols.On August 18, Amazon Bedrock AgentCore Payments became generally available. The service enables agents running on AgentCore to autonomously discover, access, and pay for third-party APIs, MCP services, and specialized data sources. It integrates wallet infrastructure from Coinbase, Stripe, and Privy, with native support for stablecoins and machine-payment protocols such as x402.This addresses a particularly disruptive break in agent workflows.Suppose an agent discovers that it needs to purchase a high-quality real-time dataset while analyzing a market. Previously, the workflow would have to stop while a human paid by card and configured an API key.With AgentCore Payments, payment becomes an automated step within the workflow itself. The user only needs to define a budget and payment policy in advance. When the agent encounters a paywall, it can initiate a micropayment and access the resource without human intervention. Wallet credentials and private key material remain isolated from the model itself.Two days later, on August 20, Binance introduced Agent OS and opened up agent-native interfaces.Rather than providing a single AI feature, Agent OS functions more like a financial infrastructure layer designed specifically for agents. It brings together components including Binance APIs, Wallet Agentic Hub, x402, Skills Hub, and MCP.Compatible AI applications can use MCP to retrieve market data and account information, then execute supported trading operations once authorized by the user. More importantly, the system emphasizes permission boundaries and isolation at the infrastructure level.Users can assign an agent a dedicated sub-account, separating its funds and trading activity from the main account, and configure specific permissions for that agent. Access can also be revoked at any time.Viewed together, AgentPit, AWS AgentCore Payments, and Binance Agent OS reveal an increasingly clear pattern: AgentPit provides an environment for strategy testing and continuous feedback. x402 and AWS AgentCore Payments enable machine-native payments. Binance Agent OS opens market data, accounts, trading, and onchain capabilities to agents. Capabilities that were once fragmented are gradually being connected into a complete workflow.Financial applications, however, have a unique characteristic. If a piece of code contains an error, it can usually be corrected and rerun. But once an agent executes an incorrect transaction, the assets may already have left the wallet.This means that one role cannot be bypassed as agents move from simulation into the real world:The wallet.3. What Is the Real Value of an Agent Wallet?A complete future workflow for AI agents could follow a clear sequence: Train and test strategies in a simulated environment such as AgentPit. Obtain information and tools through MCP, Skills, and APIs. Purchase data and computing resources through protocols such as x402. Further reading:“When AI Agents Get Wallets, Who Stays in Control?” Enter real markets and execute transactions. Continue refining strategies based on actual results. At the execution stage, wallets will play a very different role from the one they do today.Traditional Web3 wallet interactions were designed for humans. Every signature assumes that someone is looking at a screen, reviewing the transaction, and manually confirming it.But if a high-frequency trading agent needs to read multiple order books every second and continually adjust its positions, requiring a human signature for every action would defeat the purpose of automation.Handing the private key directly to AI, however, would mean abandoning the most fundamental security boundary.The real purpose of an Agent Wallet is therefore not to answer the question, “How can we give an AI the private key?”It is to answer a different question:How can an agent receive secure, controllable execution authority without the user surrendering ultimate control over their assets?This is the central approach proposed in imToken’s Agent Wallet design framework: Account isolation and session keys: Under imToken’s Agent Wallet design concept, every agent granted execution authority corresponds to a separate agent account. Its session key is generated and isolated within a trusted execution environment (TEE) and never leaves that secure environment. Policy-enforced constraints: Every agent account must be bound to an explicit policy covering protocol allowlists, per-transaction limits, daily spending limits, operating frequency, authorization periods, and other restrictions. In other words, the agent does not receive an unrestricted wallet. It receives an execution account enclosed by policy guardrails. Ultimate control remains with the user: The agent can act autonomously only within the policy authorized in advance by the user. Any operation outside those boundaries must return to the user for confirmation. Users can adjust the policy, pause or resume the agent, revoke its permissions, and recover control of the funds at any time. If a transaction is identified as abnormal or falls outside the predefined strategy, automated execution is suspended and the user must authenticate again. Viewed from this perspective, simulated training environments such as AgentPit and smart wallets such as imToken Agent Wallet address two stages of the same challenge.The former raises the upper limit of an agent’s decision-making ability.The latter establishes the guardrails for safe execution.Neither can replace the other.This may be the most important difference between an Agent Wallet and a traditional wallet.Final ThoughtsThe arrival of AgentPit signals the beginning of a new stage worth watching.AI agents are moving from “learning to use tools” to “learning how to work.”When they eventually leave simulated training grounds and enter the unpredictable world of live trading, whether they can proceed safely and sustainably will depend on more than the intelligence of their underlying models.It will also depend on the strength of the account and authorization boundaries we build around them.After all, in a complex real-world economy, what we need is not an agent that never makes mistakes.We need an agent whose mistakes remain within controllable boundaries.
2026-08-31
A Turbulent Time for Web3 Wallets: How Crypto Security’s “Sword and Shield” Are Evolving in the AI Era

A Turbulent Time for Web3 Wallets: How Crypto Security’s “Sword and Shield” Are Evolving in the AI Era

Over the past month, a series of incidents has once again put the crypto industry on high alert.First, Coldcard was found to have a critical vulnerability in its random number generation. Trezor and SafePal then disclosed separate incidents that involved potential exposure of users’ personal data.At first glance, the three incidents appear to have little in common. But viewed over a longer timeline, they point to an increasingly important question:As AI automates vulnerability discovery, exploit development, and social engineering, how many parts of a crypto wallet could become the next weak link targeted by attackers?1. How AI Is Turning Hacking From a Craft Into an IndustryObjectively speaking, the three incidents exposed entirely different attack surfaces.Coldcard’s issue affected private key generation and represented a serious security vulnerability. Trezor’s incident involved a third-party logistics provider, while SafePal’s involved its ordering system and browser extension permissions. The latter two primarily exposed risks stemming from personal data leaks.Although there is currently no evidence that AI was directly involved in all three incidents, one fact is becoming difficult to ignore: in the AI era, the hacker’s toolbox is undergoing a profound transformation.Many sophisticated cyberattacks were previously constrained by a very practical resource—human time.Studying a large codebase, understanding its call paths, and identifying logic flaws hidden for years could require an experienced security researcher to invest enormous amounts of time. Collecting information on a particular user, studying their habits, and crafting a convincing phishing email could require months of preparation to develop a sophisticated social-engineering campaign.This forced attackers to make a trade-off. They could either automate an attack at scale using relatively crude methods and wait for a small number of victims to take the bait, or meticulously target a high-value individual with an attack that was difficult to replicate at scale.As AI capabilities rapidly advance, however, that toolbox is receiving a complete overhaul: Automated vulnerability discovery: AI can help attackers rapidly analyze smart contracts, client software, and even firmware to uncover zero-day vulnerabilities and logic flaws. Scalable social engineering: Phishing emails that once required careful manual preparation can now be generated automatically using leaked identity data. AI can produce highly personalized and persuasive emails, text messages, voice recordings, and even videos. Further reading: Spring Festival Asset Security Guide: Protecting Your Tokens Amid the Holiday Rush Intelligent attack execution: From identifying targets to launching coordinated attacks across multiple channels, the cost of executing an entire attack chain has fallen to an unprecedented level. Capabilities that were once distributed across different specialists—from target selection and vulnerability research to malware generation, social engineering, and attack delivery—are gradually being compressed into a more automated workflow.This is the truly far-reaching impact of AI on cybersecurity.AI may not suddenly invent an entirely new form of attack. Instead, it rapidly lowers the cost of existing attacks. Finding a vulnerability becomes cheaper, analyzing a target becomes faster, and generating a thousand different versions of a phishing email becomes far easier than before.In other words, the fact that many systems were not attacked in the past did not necessarily mean they had no vulnerabilities. Sometimes, those vulnerabilities were simply too difficult to find, the attacks were too expensive to execute, or the potential targets were not worth the effort.The invisible security boundary created by the assumption that “attackers do not have enough time” is now growing thinner.From this perspective, the battle over crypto asset security is expanding beyond the relatively narrow contest for private keys. It is becoming an end-to-end struggle spanning code, devices, supply chains, user identities, and everyday interactions.AI is simply accelerating that shift.2. A Wallet’s Attack Surface Extends Far Beyond Its Seed PhraseThis is why the recent incidents are particularly revealing when examined together.Each affected a different stage of the wallet lifecycle, reminding us that wallet security has long since moved beyond the single question of whether a private key has been stolen. Risk can be embedded in every step, from private key generation and hardware devices to logistics and users’ personal information.Let us break down the three incidents.Coldcard is the most direct example. Its vulnerability arose before users had even begun using their wallets.A seed phrase could still appear as 12 or 24 ordinary words. The device could sign transactions and transfer assets normally, leaving the user with little reason to suspect anything was wrong. But if the randomness used to generate that seed phrase was not truly random, the wallet could still be at risk—even if the user had never shared the phrase with anyone.After all, the advice to “protect your seed phrase” assumes that it was generated securely and unpredictably in the first place.Trezor and SafePal illustrate a different type of risk.Unlike Coldcard, their hardware was not compromised, and users’ seed phrases remained intact. What was exposed instead was purchase information, including names, phone numbers, email addresses, and even delivery addresses.Imagine purchasing a top-of-the-line, tamper-resistant safe. The safe itself remains secure, but the shipping company loses a delivery manifest listing your name, email address, phone number, home address, and the fact that you purchased a hardware wallet designed specifically to store crypto assets.An attacker would then possess a list of potentially high-value crypto users. They could impersonate wallet support staff and send an “urgent firmware update” notice, create a phishing page tailored to the exact wallet model purchased, call users about an alleged order issue, or link their social media profiles and public identities to onchain addresses.In other words, being unable to break the cryptography does not leave an attacker without options.The crypto community has long used an extreme real-world example to illustrate this point: the “$5 wrench attack.” No matter how strong the encryption is, it cannot prevent an attacker from directly targeting the person who owns the assets.This is not purely a theoretical risk. According to data Chainalysis provided to the Financial Times, at least 46 violent attacks against crypto holders had been recorded by mid-August 2026. Kidnappings accounted for more than half of them, while home invasions represented over one-third.Looking back at the three wallet incidents, it becomes clear that “wallet security” now involves a very long chain:It begins with wallet code, randomness, and key generation, then extends to chips, firmware, and devices, followed by official websites, purchasing channels, supply chains, logistics providers, and order databases. Once a user begins using the wallet, it connects to RPC services, DApps, browser extensions, and smart contracts. It must then handle approvals, signatures, customer support, social media, and even AI agents.If any link becomes the weakest point, attackers may be able to bypass the defenses built throughout the rest of the chain.3. As Attacks Become Automated, Defense Must Embrace AIIf AI continues advancing at its current pace, the problems being exposed today may be only the beginning.One of AI’s greatest strengths is its ability to examine a large system continuously for anomalies, recurring patterns, and weak points.Attackers can deploy agents to scan open-source code around the clock, test websites, APIs, and browser extension permissions at scale, and automatically collect information from social media and public databases before identifying potentially high-value targets.Even phishing could evolve beyond generic messages such as “Your wallet is about to expire—please enter your seed phrase” into real-time conversations tailored to the victim. If an attacker knows that you recently purchased a particular hardware wallet, AI can generate a “firmware security notice” tailored to that exact model. If the attacker knows that you recently used a particular DeFi protocol, AI can impersonate the project team and instruct you to migrate your assets to a new protocol vault. If the attacker also gathers information from your social media profiles and public posts, AI may even imitate a team member, KOL, or customer support representative you already know and trust. From this perspective, wallets face an important challenge: when attacks evolve from fixed patterns into systems that can analyze, reason, and adapt, can defense continue to rely on static rules alone?Traditional wallet security mechanisms still largely resemble a rulebook. If an address has been identified as a phishing address, the wallet displays a warning. If a domain has been blacklisted, access is blocked. If a particular approval pattern is considered risky, an additional alert appears.These mechanisms remain important. But as attacks become increasingly dynamic, identifying the next threat solely by looking at threats that have already occurred is clearly not enough.AI can become an important addition to the defensive toolkit. Further reading: When Hackers Scale Up with AI: The Next Level of Web3’s Security Arms RaceIn fact, this is not an entirely new idea.In previous discussions about “AI × Web3 security,” imToken proposed a similar direction: wallet security should move beyond address blacklists, risk labels, and fixed pop-up warnings. With AI, security checks could be integrated earlier and more deeply into the user’s entire transaction process.Before code reaches production, for example, AI could continuously review dependencies, call paths, and anomalous logic. When a user visits a DApp, the wallet could assess its domain history, front-end behavior, contract addresses, and onchain relationships to detect suspicious activity. Before a signature is submitted, it could simulate the transaction’s actual outcome instead of merely displaying an incomprehensible string of hexadecimal data.Over time, wallets could even build dynamic security models for individual users.If an account that normally transfers only a few hundred dollars suddenly attempts to approve a contract deployed just two hours earlier to spend all of its assets, that is an anomaly in itself.If a user is about to grant unlimited token approval to an address they have never interacted with, the wallet should issue a higher-priority risk warning.And if an email claims to come from an official wallet team and asks the user to enter their seed phrase, it should be classified as high risk—no matter how convincing the message appears.The change brought by AI may therefore extend far beyond automatically telling users whether an address is safe. It could give wallets, traditionally passive tools for key management and transaction signing, an active layer of risk assessment.This also makes another security boundary previously discussed by imToken even more important: AI can help users understand and execute complex operations, but control over assets must not be delegated without limits.Critical actions—such as large transfers, approvals for new addresses, and interactions with sensitive contracts—should remain subject to least-privilege controls, human confirmation, pre-execution simulation, and clear explanations. AI’s capabilities must stay within explicitly defined permissions.Most importantly, when something genuinely appears abnormal, the wallet should clearly explain why it is dangerous, what will happen if the transaction is executed, and where the risk lies.In other words, the value of AI-powered defense lies in transforming wallets from passive signing tools into systems capable of actively understanding transactions, identifying anomalies, and constraining execution.Final ThoughtsThe recent series of wallet security incidents does not mean self-custody has lost its value. Nor does it suggest that users should return complete control of their assets to centralized platforms.What these incidents remind us is that self-custody has never meant automatic security. It means returning ultimate control over assets to the user.Protecting that control requires a security system capable of evolving alongside changing threats. Security is not a one-time product deliverable. It is an ongoing and dynamic process that requires users, projects, and wallet providers to work together.Attackers can use AI to understand code, users, and their environments.Defenders can do the same.The long-running “sword and shield” arms race has entered its next stage.
2026-08-31
Ethereum’s “Rate Cut” Debate: EIP-8363 Breaks the Mold—Is Now the Prime Window for Staking?

Ethereum’s “Rate Cut” Debate: EIP-8363 Breaks the Mold—Is Now the Prime Window for Staking?

While the Federal Reserve remains undecided on whether to raise or cut interest rates, the Ethereum community is already debating a “rate cut” for staking—a benchmark rate for on-chain finance.EIP-8363, which has recently sparked widespread community discussion, proposes an unconventional issuance mechanism: as the share of ETH staked increases, a progressively larger portion of validator rewards would be burned. Once the staking ratio approaches 50%, the burn would fully offset issuance rewards.In other words, when 50% of all ETH is staked, the annualized staking yield could fall close to zero.This does not mean total staking returns would strictly drop to zero. Validators could still earn execution-layer fees, MEV, and other income. But since issuance currently accounts for the majority of staking rewards, the proposal would strike at the heart of the existing reward model.Unsurprisingly, it has stirred up considerable debate.At the time of writing, more than 40 million ETH is staked—nearly 35% of the total supply—while the protocol-level APR has already fallen to around 2.6%. A question that once seemed distant is suddenly confronting Ethereum:As more and more ETH enters staking, does Ethereum still need to issue new ETH to encourage even greater participation?1. Is Ethereum Starting to Worry About “Too Much Staking”?To understand the issue, we first need to look back at the different stages of Ethereum staking.When Ethereum’s Proof-of-Stake mechanism was first introduced, its most important objective was simple: attract enough ETH to the Beacon Chain to establish sufficient economic security for the network.To achieve this, the protocol rewarded validators through new issuance and adopted a dynamic reward curve. Early participants could earn relatively high returns, while the yield would gradually decline as more ETH entered staking.This is why Ethereum’s staking APR was once far higher than it is today and has since fallen to around 2.6%. In theory, the mechanism already has a built-in brake.As yields decline, staking eventually becomes less attractive to some participants, allowing the market to find an equilibrium. EIP-8363, however, starts from the premise that this brake may not be strong enough.Under the current issuance curve, consensus-layer staking yield has an implied floor of around 1.5%, even as the amount of staked ETH continues to grow. In theory, this means that large amounts of capital could continue entering staking even when returns fall to just above 1%.Yet as a growing share of ETH is entrusted to exchanges, custodians, liquid staking token (LST) protocols, and professional operators, the marginal contribution of additional stake to economic security diminishes. At the same time, the risks of staking concentration, governance capture, and large amounts of ETH being controlled by a small number of operators may increase.Staking rewards also come from new ETH issuance. The higher the staking ratio, the more ETH the protocol must issue to pay for network security, while ETH holders who do not stake bear the corresponding dilution.EIP-8363 is therefore trying to answer a straightforward question: once the network has already purchased enough security, should it continue spending more ETH on additional security whose marginal value is steadily declining?The proposal is far from settled Ethereum monetary policy, and it remains highly controversial within the community.One practical objection is that if yields are pushed too low, solo stakers—who must cover hardware, electricity, and maintenance costs—may be the first to conclude that staking is no longer worthwhile and exit.Large institutions, by contrast, may be better positioned to remain due to economies of scale, MEV revenue, or product requirements. The result could be a lower staking ratio but a more concentrated validator set—the opposite of the proposal’s goal of improving decentralization and resistance to capture.The debate is still ongoing, and there is no certainty that EIP-8363 will be adopted or what form it might ultimately take.Nevertheless, it sends a clear signal: Ethereum is beginning to reconsider a question it rarely had to ask in the past—are staking rewards becoming too generous?2. Ethereum Is Preparing a “Rate Cut” Just as Staking Enters the Compounding EraInterestingly, while Ethereum is discussing lower long-term staking rewards, staking capital efficiency has just received a major upgrade.That upgrade is EIP-7251, introduced through Pectra.Further reading: “As 8 Million ETH Starts Moving, Is Ethereum Staking Undergoing a Structural Shift?”Put simply, native Ethereum staking previously lacked protocol-level automatic compounding. The original 32 ETH principal could earn rewards, but those rewards would not automatically become additional effective balance and generate further returns.EIP-7251 allows native staking to form a true compounding cycle for the first time:ETH principal generates rewards → rewards are added to the effective balance → the additional ETH generates further rewards.Over one or two years, compounding a yield of slightly above 2% may not produce a dramatic numerical difference.Its real value lies in time.Suppose a user already plans to hold ETH for three, five, or even more years. If they begin staking from day one and continually add the ETH rewards back to their principal, the gap between compounding and non-compounding becomes more significant as the holding period grows.Compounding is not new to ordinary users of LSTs. Many liquid staking products have already allowed users to benefit indirectly from accumulating staking rewards. Pectra’s importance is that it makes automatic compounding a protocol-native capability rather than something that must be provided by an external product.This would further improve the capital efficiency of the broader Ethereum staking infrastructure.Viewed together, EIP-8363 and Pectra may appear contradictory, but their objectives are actually complementary. Ethereum wants to make staking more efficient without necessarily continuing to increase the economic incentive to stake through ever-greater ETH issuance.Pectra addresses capital efficiency, while EIP-8363 asks how much the protocol should pay for security.For this reason, Ethereum staking may increasingly follow a clear trend: the mechanism will become more mature and compounding more accessible, while returns derived purely from protocol issuance may continue to decline.These protocol-level changes are also gradually reaching ordinary users. For example, imToken plans to support automatic compounding for native ETH staking, bringing Pectra’s new capabilities beyond validators and large staking institutions and into a wallet interface accessible to long-term ETH holders.3. Could This Be the Prime Window for Staking?This brings us to the question that ordinary ETH holders care about most.If staking APR is likely to keep falling, should users start staking now while yields are still relatively high?First, it is important to clear up a common misconception: staking today does not lock in the current yield of approximately 2.6%–3%.Ethereum staking is not a long-term bond with a fixed coupon. If EIP-8363 is eventually adopted—or if Ethereum changes its issuance curve through another mechanism—validator yields will adjust accordingly.The “window,” therefore, is not an opportunity to secure a long-term deposit paying 2.6% before Ethereum “cuts rates.”What matters is the cost of lost time.Suppose a user holds ETH that they already intend to keep for five years. If they do not stake during the first year and only begin in the second, the yield in the second year will not be any higher, nor can they recover the ETH rewards missed during the first year.More importantly, they also forgo four years of compounding on the rewards missed during the first year.If the long-term direction of Ethereum staking is indeed toward a higher staking ratio and lower yields, this effect becomes even more pronounced. The longer users wait, the less time they have to compound—and the lower the underlying yield may already be when they begin.This is the strongest argument for why the present may represent a window: it is a window of time.This is particularly relevant to users who already intend to hold ETH for the long term and have no significant short-term liquidity needs. For them, the way they evaluate staking may need to change.In the author’s view, EIP-8363 is a trial balloon. Whatever conclusion the community ultimately reaches, the broader direction of Ethereum’s token economics is likely to shift from broad-based incentives toward a more precise and restrained issuance policy.That does not mean everyone should stake all of their ETH. Every source of yield comes with costs and risks: Running a native validator offers the greatest degree of control and access to protocol-native rewards. However, it requires at least 32 ETH and involves node operation, routine maintenance, downtime penalties, and slashing risk. Staking-as-a-Service allows users to delegate the technical work to a professional operator, but requires them to place additional trust in the service provider. Liquid staking has a lower entry threshold and greater liquidity. Users can, for example, access services such as Lido through a self-custodial wallet like imToken, allowing them to manage their own wallet while participating in ETH staking. However, liquid staking introduces additional smart-contract, governance, and LST depegging risks. Centralized exchanges offer the simplest experience, but require users to accept greater custodial and centralization risks. For users who may need to sell their ETH in the short term, frequently move their funds, or are unwilling to assume these additional risks, restructuring their assets for a few percentage points of yield may not be worthwhile.But when the premise changes to “I already intend to hold this ETH for the long term,” the answer may begin to look very different.Final ThoughtsLooking back at how Ethereum staking has evolved over the past several years reveals a fascinating progression.The Beacon Chain and The Merge completed Ethereum’s foundational transition from Proof-of-Work to Proof-of-Stake. Shapella answered the question of whether staked ETH could be withdrawn, removing a major obstacle to the further growth of liquid staking. Pectra then gave native validators automatic compounding and greater capital efficiency.EIP-8363 now raises a new question: once enough participants are staking, how much newly issued ETH should Ethereum continue paying for that participation?The shift from “How can we encourage more people to stake?” to “Are we beginning to stake too much?” shows that Ethereum staking has entered a new phase.Markets are reshaped through steady, incremental change. This is a question that any market moving from early expansion toward maturity must eventually confront.Staking may become more accessible, more mature, and more like a standardized yield infrastructure for ETH—but that does not mean it will become more profitable.For those who genuinely intend to hold ETH for the long term, this may be another lesson from EIP-8363:As yield itself becomes increasingly scarce, the most valuable ingredient in compounding is time.
2026-08-24
When AI Agents Get Wallets, Who Stays in Control?

When AI Agents Get Wallets, Who Stays in Control?

On August 4, Cloudflare made a highly symbolic move by unveiling Cloudflare Wallets—infrastructure designed to give AI agents wallets of their own.With this infrastructure, AI agents are no longer limited to calling APIs, reading data, or executing code. They can also have independent virtual wallets and use stablecoins such as USDC to purchase APIs, data, content, and computing services within predefined budgets and permission boundaries.A different approach was gaining momentum in the same week.On August 6, MetaMask also rolled out agent wallet, allowing agents to connect to on-chain wallets and execute swaps, trade perpetuals, participate in prediction markets, and manage liquidity within permissions configured in advance by users.The two products may appear to serve different purposes, but together they provide a critical piece of infrastructure that AI agents have long lacked. This could be one of the most important structural developments to emerge from the recent convergence of AI and crypto—and one worth watching over the long term.1. Agents Have Long Lacked a Way to Pay on Their OwnConsider Cloudflare first.Although the capabilities of individual agents and multi-agent systems have advanced significantly this year, they can still become stuck in a very traditional process: find a service, visit its website, create an account, add a credit card, purchase a subscription, obtain an API key, and only then begin using the service.For a human, this process is merely inconvenient. For software trying to complete a task autonomously, however, any step involving login, registration, payment, or identity verification may force it to stop and ask a human to take over.In other words, the “brains” of agents have advanced rapidly over the past several years, but the internet’s payment infrastructure is still fundamentally designed for humans.This is precisely what x402 seeks to change.It revives the long-standing but rarely used HTTP status code 402 Payment Required, embedding payment requests directly into the internet’s basic request-response flow.Under Coinbase’s x402 design, when an agent requests access to a paid API, the server can tell it directly how much to pay, which assets it accepts, and where the payment should be sent. The agent completes the payment and retries the request with proof of payment. The server verifies the payment and returns the requested resource.The original process—“Create an account → connect a payment method → add funds or purchase a subscription → obtain an API key → call the service”—can therefore be compressed into:“Send a request → receive payment instructions → pay → access the resource.”This flow may not require an account or subscription. An agent would also no longer need to purchase a monthly or annual plan simply to make a handful of API calls.Removing a few steps may not sound transformative, but it is particularly well suited to AI agents.The payment mechanism an agent truly needs is not one that requires its owner to stop and enter a verification code before every purchase. It needs a payment protocol that software can understand and execute automatically, just like any other programmatic call, while supporting precise usage-based pricing.Stablecoins provide an ideal settlement layer for this model.Cloudflare’s current x402 developer documentation already supports machine-to-machine payments using USDC and other on-chain assets. An agent can pay directly when requesting an API, MCP tool, or other digital resource instead of being redirected to a traditional checkout page. Further reading: “Crypto AI Protocol Landscape: Building a New Operating System for AI Agents on Ethereum”This could even change how internet content is priced.The traditional internet generally offers two choices: provide content for free or place it behind a subscription wall that requires a human to register and become a paying member.For agents, a different model may be more natural. Instead of requiring them to subscribe to an entire service, providers could charge for the data consumed, API requests made, compute used, or content pages accessed.This is what makes Cloudflare Wallets worth watching.A research agent, for example, could receive a budget of 10 USDC and independently compare the price, speed, and quality of dozens of data sources. If an API call costs only a few cents, the agent could try the service immediately. If the result is unsatisfactory, it could move on to the next provider without asking its owner to approve every few cents of spending.Interestingly, these restrictions may appear to constrain the agent, but they are precisely what gives it greater autonomy.If a user must manually approve every 0.01 USDC request, the supposedly autonomous agent remains little more than a partially automated tool.Only when the user first establishes a sufficiently clear budget boundary—retaining ultimate control outside that boundary—can the agent operate freely within it.The launch of Cloudflare Wallets therefore reflects a deeper shift.Historically, internet infrastructure assumed that the participants in economic transactions would mainly be individuals and businesses.Now, from identity and payments to pricing models, part of that infrastructure is being deliberately redesigned for another category of participant: AI, or more specifically, the agent itself.2. How Can Agents Be Given Economic Autonomy?If Cloudflare is primarily addressing how agents can purchase services, MetaMask Agent Wallet takes the next step by asking how agents can use assets directly.It seeks to let agents perform on-chain operations within permissions predefined by users. This is fundamentally different from asking an AI to analyze whether ETH is worth buying.Historically, the division of labor between humans and AI was relatively straightforward: the AI gathered information, analyzed the problem, and made a recommendation. The human then decided whether to act.With an agent wallet, an instruction could gradually evolve into something like:“If ETH falls to around $3,000 while gas is below its 24-hour average, buy 0.2 ETH.”The user provides the objective, conditions, and permissions. Continuous monitoring, condition evaluation, transaction preparation, and even final execution can then be delegated—in whole or in part—to the agent.This is the layer that makes an agent’s “economic autonomy” genuinely significant.It does not mean that the agent owns property in its own right. Rather, it gains an account, a discretionary budget, and a set of economic permissions it can invoke as circumstances change.It can independently purchase external information and computing resources. It can also deploy real assets to accomplish objectives within rules defined by the user.This step may seem like a natural progression, but it also connects AI errors directly to real economic losses for the first time.If a conversational AI misunderstands a sentence, the usual result is simply an incorrect answer. Once it has a wallet and execution authority, the same misunderstanding, prompt injection, or malicious tool call could immediately result in an irreversible on-chain transaction. Further reading: “A Signature Is More Than a Signature: When an AI Agent Signs for You, Who’s in Control?”This is why an unrestricted wallet cannot simply be handed to an AI.Users can define daily spending limits, permitted protocols, and risk preferences in advance. Supported EVM transactions can also pass through transaction simulation, threat scanning, and MEV Protection.If a transaction is identified as abnormal or falls outside the user’s predefined policy, the system pauses automated execution and requires the user to reauthenticate via 2FA before proceeding.An important principle is therefore becoming clear: economic autonomy does not mean unlimited authorization.A genuinely useful agent is more like an employee with a corporate card and clearly defined responsibilities than someone handed the keys to the company vault.What it can buy, how much it can spend in a single transaction or over one day, which decisions it can make independently, and which actions require renewed approval should all be established before authority is delegated.From this perspective, the central innovation of an agent wallet is not merely giving AI a wallet. It is beginning to address systematically how humans can delegate economic authority to software without surrendering control.Once we reach this point, the wallet itself must also change.3. What Kind of “New Wallet” Is Needed When Agents Can Spend Independently?For more than a decade, the central challenge for crypto wallets has remained remarkably stable: how to manage private keys securely.No matter how wallet interfaces have evolved, the underlying relationship has remained the same. A human initiates the operation, reviews the transaction, and provides the final signature. The wallet’s most important responsibility is to protect the private key that determines asset ownership and grants final authorization.The arrival of agents introduces another layer into this process.Users may no longer need to construct every transaction themselves. The interaction model is gradually shifting from “a human operates the assets directly” to “a human defines an objective and delegates part of the execution authority to an agent.”This means future wallets must answer an entirely new set of permission questions: Who can use assets on my behalf? Which assets and protocols can it access? What is the maximum value of a single transaction, and how many transactions can it execute per day? Which decisions can it make independently, and which require renewed confirmation? If the agent behaves abnormally, can I immediately pause it, revoke its permissions, and recover the assets? For ordinary users, the key question is how they can confidently manage agents with real execution capabilities.This is another question imToken is exploring through UI 3.0 and its thinking around agent Wallets.In imToken’s vision for next-generation wallet interactions, one important change is that the user’s role begins to shift from “Operator” to “Manager.”Today, completing a transfer requires the user to select a network, enter an address and amount, assess the gas fee, review each step, and sign the transaction.In an intent-driven wallet, the user may only need to say:“Send Frank 500 USDT.”The system could translate that natural-language instruction into a structured intent, identify the recipient, amount, asset, network, and estimated fee, and then present the structured transaction details to the user for final confirmation.Reducing the number of visible steps does not mean that the boundaries of control can disappear with them.On the contrary, as more of the execution process becomes automated, the steps no longer visible to users must be governed by clearer authorization mechanisms.Under imToken’s Agent Wallet design concept, each agent granted execution authority corresponds to a separate agent account. Its session key is generated and isolated within a trusted execution environment, or TEE, and never leaves that secure environment.At the same time, every agent account must be bound to an explicit policy covering protocol allowlists, per-transaction limits, daily limits, operating frequency, validity periods, and other restrictions.The agent therefore does not receive an unrestricted wallet. It receives an execution account enclosed by policy guardrails.Within this relationship, the user retains a higher level of control. The user can adjust the policy, pause or resume the agent, revoke its permissions, and recover the funds at any time.AI can help interpret intent, plan execution paths, estimate fees, and identify risks. But the agent can execute only within the policy authorized in advance by the user. Any operation outside those boundaries must return to the user for confirmation.More importantly, authorization should not be a single leap from zero to complete control. It should expand gradually as trust develops.A newly adopted agent might begin in an observation and analysis role. As the user develops confidence in it, the agent could be allowed to make recommendations and prepare transactions. The next stage could permit execution after user confirmation. Only when the rules are sufficiently clear and the risks controllable should the agent be allowed to execute automatically within a predefined strategy.The progression from L0 observation to L1 recommendations, L2 execution after confirmation, and L3 autonomous execution within policy represents a gradual trust model.An agent’s autonomy is not something the system should grant by default. It is authority that the user confers one step at a time.This could also change why users open their wallets.Today, people generally open a wallet because they want to check a balance, make a transfer, or execute a swap.Once agents take over more routine operations, users may open their wallets with a different question in mind:“What has my agent done recently, and is there anything that needs my attention?”The wallet’s primary interface may therefore evolve from a transaction interface into a management dashboard.At that point, a wallet would no longer serve only as a place to store assets and initiate transactions. It would function as a permissions and control layer between users and their agents.This may represent an important shift in the wallet’s value proposition in the agent era—from “securely manage your private keys” to “securely manage your assets and the agents you authorize to use them.”Final ThoughtsViewed over a longer time horizon, giving AI agents economic autonomy may be one of the most important structural developments to emerge from the convergence of AI and crypto.Smarter models and agents capable of using more tools still operate primarily within the information world. Once an agent has an account, a budget, and the authority to move and deploy real assets, however, it becomes an active participant in real economic activity for the first time.The factor that ultimately determines whether agents can enter real financial environments at scale may therefore no longer be simply whether they are intelligent enough.The more important question is whether we can build a permission system that matches their capabilities.The other side of autonomy is always authorization.Wallets may not simply disappear into the background in the agent era. Instead, they may take on an even more important role: enabling genuine automation while ensuring that ultimate control always remains with the user.After all, allowing an agent to act freely does not mean that humans must surrender control.That boundary may be the central question wallets need to answer before economic autonomy can become a practical reality.
2026-08-21
From Blind Approval to Verifiable Signing: How Sigil Adds a Guardrail for AI Agents

From Blind Approval to Verifiable Signing: How Sigil Adds a Guardrail for AI Agents

Imagine a future in which all you need to tell an AI agent is:“Use half of the available funds in my wallet to buy more ETH.”The agent immediately begins checking your balance, searching across liquidity pools, comparing quotes, and building an execution route. A few dozen seconds later, it sends you a message:“I found a suitable route. Confirm?”You reply with a simple “Yes.”But what exactly have you approved?Which pool did the agent choose? What execution price and slippage should you expect? Which protocol will it interact with? Which wallet will it use, and how much will it spend? Does the operation involve token approvals or any other actions?You have not actually seen any of this information. You are simply choosing to trust the agent’s summary.This is a new category of risk emerging as AI agents move from answering questions to acting on behalf of users.Agents can now browse websites, log in to accounts, complete payments, and even initiate or sign on-chain transactions. Yet the final authorization step presented to users is often still little more than a vague chat message and a confirmation option containing almost no meaningful information.A single “Yes” can determine what happens to a user’s funds, data, and devices.This is why imToken’s latest brand evolution introduces a fourth S alongside Store, Send, and Stake: Sign.If the first three pillars correspond to asset custody, value transfer, and network participation, Sign addresses a new question: as more software begins acting on behalf of users, how can users retain the right to understand, approve, and remain in control?Sigil is the first proof-of-concept product built around this Sign vision.Its core principle is simple but important:What you see is what you sign.1. When Agents Start Acting, Why Do Wallets Need to Rethink Signing?Historically, many signing risks in crypto wallets have stemmed from users not understanding what they were signing.At the protocol level, an on-chain transaction may appear only as a contract address, function parameters, and hexadecimal data. For ordinary users, it can be extremely difficult to determine whether the request represents a transfer, a swap, or a more dangerous asset operation.That is why wallets need to translate raw transaction data into human-readable details that users can review before signing.Clear signing, also known as “what you see is what you sign,” is designed to bridge the gap between machine-readable data and human understanding.Further reading: Why Clear Signing Is Becoming Essential in the AI Era.AI agents, however, make the problem more complex.Users may no longer be authorizing a single on-chain transaction. Instead, they may be authorizing an entire chain of actions planned and executed by an agent.To complete a goal such as “use half of my available liquid funds to buy more ETH,” an agent may need to check wallet balances, search on-chain liquidity pools, call third-party tools, run scripts, and prepare a transaction.Users cannot realistically inspect every underlying request one by one. Yet before any assets are exchanged, they still need to make the final decision.Many agents today handle authorization by sending a short message in a chat window and waiting for the user to reply “Yes” or “Confirm,” or to tap a standard confirmation button.This may resemble user authorization, but in practice it creates several obvious problems.First, it is a black box.Users know they are approving something, but they may not know the exact amount, recipient, protocol, or action the agent will ultimately execute on their behalf.The real execution parameters are hidden behind a highly summarized natural-language sentence. The user is confirming only a vague intent, not the exact action the system is about to perform.Second, a chat reply is not equivalent to a digital signature.Anyone with access to an already authenticated device or session may be able to type “Yes.” At most, the system can verify that the message came from an authenticated account or session. It cannot necessarily confirm that the approval was intentionally provided by the account owner.More importantly, the confirmation interface itself may also be manipulated.If the same agent that initiates an operation also controls how that operation is presented to the user, it could omit key parameters, use ambiguous wording, or display something that appears harmless while submitting a different request in the background.This creates a clear trust paradox.We want the confirmation interface to constrain the agent, yet we may also allow the agent itself to determine what the user sees at the moment of confirmation.When an agent is only summarizing articles or organizing information, this lack of transparency may result in an inaccurate answer.But when an agent gains access to accounts, funds, file systems, and terminal environments, vague approval can lead to real asset loss, data leakage, or device-level risk.Further reading: A Signature Is More Than a Signature: When an AI Agent Signs for You, Who’s in Control?What agent-based systems need is not more “Yes” buttons.They need an authorization mechanism that can create a verifiable link between what the user saw, what the user approved, and what the system ultimately executed.2. Sigil: A Signing Guardrail Between AI Agents and WalletsThis is the problem Sigil, imToken’s newly introduced proof of concept, is designed to address.Sigil acts as a safety guardrail between AI agents and wallets.It does not seek to prevent agents from automating tasks altogether.Instead, during setup, users can explicitly authorize an agent and define which low-risk actions it may complete autonomously and which sensitive actions require separate, explicit, and verifiable user approval.Within the boundaries defined by the user, the agent can continue operating efficiently.But when an operation involves something the user has classified as sensitive—particularly spending funds or authorizing on-chain transactions—Sigil pauses the flow, parses the actual request into a structured confirmation card, and delivers it to the user through Telegram.The user must then approve the request using a passkey and biometric verification before the operation can continue.The flow can be summarized in four steps.Step 1: The agent initiates an actionThe agent continues its task, whether that involves browsing websites, booking services, sending requests, or preparing a transaction.Step 2: Sigil checks the user’s security policySigil determines whether the action triggers the user’s preconfigured security policy.If the action is classified as low risk and the user has allowed the agent to complete it autonomously, the flow can continue.If it involves actions such as sending messages, deleting files, executing code, spending funds, or authorizing on-chain transactions, Sigil pauses execution and parses the request.Step 3: The user reviews and approves the requestA structured confirmation card is delivered through Telegram.Depending on the operation, the card may display key parameters such as the action type, merchant, protocol, asset, amount, recipient, and other relevant details.The confirmation is not based solely on a natural-language summary generated by the agent. It is based on structured information parsed from the actual request.The user then provides explicit approval using a passkey and biometric verification.Step 4: Sigil verifies the approvalOnly after the Sigil gateway verifies the user’s signature can the agent continue.Without user approval, no funds are moved and no transaction is signed.The key point is not simply that Sigil adds another biometric verification step.More importantly, it establishes a verifiable connection between display, signing, and execution.What is displayed is derived from the actual request.What the user signs is cryptographically bound to the displayed content.What the system executes must match the signed request.If these elements do not match, Sigil blocks the operation.Sigil does not require users to approve every action an agent takes.Instead, it allows users to define in advance which actions may be automated and which require personal approval.Users can select different security levels, such as Relaxed, Balanced, or Strict, or use Custom mode to define rules for individual categories of actions.In Balanced mode, for example, some lower-risk actions may proceed without additional approval, while higher-risk actions involving code execution, terminal access, sensitive data, or asset security must go through Sigil confirmation.Spending funds and authorizing on-chain transactions always require user approval, regardless of the selected security mode.This requirement applies across all security settings.3. From Crypto to AI Agents: What Is Sigil Trying to Protect?Built around the principle of “What you see is what you sign,” Sigil provides three layers of protection.First, users can clearly see what they are approvingIn Sigil’s confirmation card, key parameters such as the protocol, amount, asset, recipient, and action type are presented as structured fields.Users do not need to rely solely on the agent’s summary, nor do they need to interpret raw data they cannot understand.The user’s approval is bound to the content shown on the card.Returning to the ETH transaction at the beginning of this article, the final confirmation should not simply say “Buy ETH.”It should show the asset being spent, the amount, the recipient or contract, the relevant protocol, and the key transaction parameters the user needs in order to make an informed decision.The same principle applies to real-world payments.The interface should not merely display “Confirm payment.” It should clearly show the merchant, amount, recipient, and other relevant details.The more closely the displayed information reflects the actual operation, the more meaningful the user’s authorization becomes.Second, approval requires the user’s registered authentication methodSigil uses a passkey as the authentication mechanism for approvals and verifies the request through device biometrics.This means that even if someone gains access to a device already logged in to Telegram and can view the confirmation message, they cannot complete approval simply by typing a sentence or tapping an ordinary button.Approval is tied to the user’s registered passkey and biometric verification, not merely to whoever has access to the active device or messaging session.Sigil also adopts a mnemonic-free design.Users do not need to store or enter a new mnemonic phrase, nor do they need to expose their wallet private key to the agent.The ability to approve requests remains controlled through the user’s passkey and biometric verification.Third, the confirmation interface is independent of the agentSigil’s confirmation page is not an ordinary message dynamically generated and controlled by the agent.It is a separately registered module whose rendering logic is anchored on-chain and executed in a sandboxed environment.This means that after initiating a sensitive operation, the agent cannot simply replace the page, alter its display logic, or imitate the confirmation interface in order to mislead the user.The party initiating the request no longer controls how that request is presented for approval.Sigil also uses mechanisms such as single-use approvals, short validity periods, and cryptographic binding between the signature and the request parameters.These mechanisms help ensure that the content displayed in the confirmation card corresponds to the request awaiting execution.An approval cannot be reused indefinitely, and the underlying request parameters cannot be altered after approval without invalidating the signature.If the previewed content does not match the request submitted for execution, the operation is blocked.Seen in this context, Sigil is not merely another wallet feature.It is imToken’s product-level exploration of the Sign vision and addresses a more fundamental question:When agents begin to act, how can we ensure that they continue operating only within the boundaries users have authorized?In crypto, this need is especially intuitive.On-chain agents may eventually help users manage recurring purchases, yield strategies, transaction fees, position adjustments, risk monitoring, and automated execution across multiple protocols based on predefined conditions.In that environment, one question becomes increasingly important:If an agent’s behavior deviates from the user’s expectations, can it be stopped immediately?At the same time, Sigil’s relevance is not limited to crypto.Whether through OpenClaw, Hermes, or future agents running on personal devices and in cloud environments, agents are gradually gaining access to email, messaging apps, calendars, files, browsers, terminals, payment tools, and a growing range of online services.These operations may not take place on-chain, but the underlying relationship is fundamentally similar.The agent is exercising a capability owned by the user and acting under the user’s identity or authority.Sigil could therefore extend beyond on-chain transactions into areas such as data access, identity use, file modification, content publishing, service purchases, and automated workflows.This also explains why capabilities developed by the wallet industry may take on new significance in the AI agent era.Private key management, digital signatures, identity verification, permission confirmation, and asset security were once used primarily for on-chain transactions.But the more fundamental problem they have always addressed is how to prove that an action was genuinely authorized by a specific user or entity.As agents begin acting on behalf of users at scale, these capabilities may expand from the crypto world into broader infrastructure for managing agent identities, automated actions, and machine permissions.As a joint exploration by imToken and OpenClaw, Sigil applies imToken’s ten years of experience in self-custody, wallets, and digital signatures to a new environment in which autonomous agents are beginning to perform real actions.It does not replace the agent.Nor does it replace the wallet.It stands between the two.Closing ThoughtsAI is making complex actions easier and cheaper to execute than ever before.Tasks that once required users to switch between multiple applications, search for information, complete forms, verify details, and make payments may soon be planned and executed automatically by an agent in response to a single natural-language instruction.But being capable of acting on behalf of a user and having received valid authorization from that user are two different things.What determines whether an intelligent system can be trusted is not only how many tasks it can complete.It is whether users can understand what the system is doing, limit its authority, and stop it when necessary.From this perspective, Sign is not merely an additional layer of friction that slows agents down.It may become one of the most important layers of trust required before agents can be safely integrated into financial and real-world services.Store gives users custody of their assets.Send enables value transfer.Stake enables participation in open networks.Sign helps users retain final authority when machines act on their behalf.The value of Sigil lies in turning this abstract question of control into a functional proof of concept that can be tested, validated, and continuously improved.
2026-07-11
When Even POAP Comes to an End: As a Wave of Closures Hits Crypto, How Should Everyday Users Navigate It?

When Even POAP Comes to an End: As a Wave of Closures Hits Crypto, How Should Everyday Users Navigate It?

Crypto seems to have entered a period of unusually frequent farewells.From BitMEX, which operated for 11 years and helped shape the crypto perpetual futures market, to Satori Finance, backed by leading investors including Polychain and Coinbase Ventures, one familiar name after another has ceased operations. The shutdowns span trading platforms, DeFi, wallets, NFTs, infrastructure, and more.Among them, POAP’s departure feels especially poignant.If you were around during the last crypto cycle—especially if you attended Devcon, ETHDenver, hackathons, DAO community events, or any number of online and offline meetups—there is a good chance you can still find a few POAPs in your wallet. One might have come from a major conference, another from an online talk, and another from a community event whose details you can barely remember anymore.Most of these POAPs are worth little or nothing. But that is precisely why they may come closer to what collecting was originally about than many NFTs that once carried enormous price tags.And that is precisely what makes POAP’s farewell so telling.It did not collapse overnight because of a hack. There was no anonymous team disappearing with user funds, and it did not even issue a native token whose price needed to be constantly supported. It simply reached a point where even with real users, a clear use case, and strong brand recognition, it still could not find a business model capable of sustaining the project over the long term.That is exactly the kind of shift taking place across crypto today.In the past, we were more accustomed to discussing how a project was born. Going forward, we may need to become increasingly comfortable discussing how projects die.And that is not necessarily a bad thing. But as everyday users, we need to understand how to avoid being caught in the aftershocks of a bear market.1. A New Wave of Shutdowns Is Sweeping Across Web3During crypto’s last expansion cycle, it was not particularly difficult for a project to get off the ground.Raise funding, launch a mainnet, issue a token or run an airdrop, launch a liquidity incentive campaign—and that was often enough to attract the first wave of users. TVL, address counts, and transaction volume could rise quickly. For a surprisingly long time, whether a project actually generated revenue was not even the most urgent question.But once the cycle turns and token prices and liquidity can no longer function as sources of funding, the model runs into a very simple question:If no new money comes in, can the project support itself?That is what makes the wave of project shutdowns in 2026 particularly noteworthy.Many of the projects disappearing today are not vaporware that never had a product to begin with. They raised funding, launched, attracted real users, and in some cases were technically sound and fully operational.Take BitMEX. On July 23, it announced that its trading platform would officially shut down on September 23, 2026.Founded in 2014, BitMEX was once one of the defining companies in the crypto derivatives market. Perpetual swaps, 100x leverage, and a range of trading products later adopted across the industry were all closely tied to BitMEX’s early rise.In its shutdown announcement, BitMEX even emphasized that during more than 11 years of operation, it had never lost user funds to a hack. But even that track record was not enough to turn BitMEX into a piece of infrastructure that could run indefinitely.Similar stories have played out across DeFi and infrastructure.Botanix, a Bitcoin L2 project nearly four years in the making, said that since launching its mainnet, the network had maintained 100% uptime with zero security incidents, processed roughly 25 million transactions, reached 200,000 wallet addresses, attracted tens of millions of dollars in assets, and integrated infrastructure and DeFi products including Chainlink and Morpho.By traditional crypto KPIs alone, it would be difficult to call Botanix a project that “achieved nothing.” The chain was built. The product worked. Users showed up. Capital flowed in—and in meaningful amounts.Yet Botanix ultimately decided to shut down the network. In its retrospective, the team said that organic transaction demand had failed to generate enough fee revenue to cover the long-term infrastructure costs of operating an independent network.Crypto has spent years measuring ecosystems by TVL, address counts, and transaction volume, while rarely asking the final question:How much real revenue are those users actually generating?As the industry matures, projects with little genuine usage, persistently weak revenue, and ongoing maintenance costs will gradually disappear. That looks more like a structural shakeout than an industry suddenly losing its value.In fact, once a project determines that it can no longer continue, halting new activity, publishing a clear shutdown timeline, and giving users time to migrate their assets is often far more responsible than letting development grind to a halt while pretending the project is still operating normally.2. What Should Everyday Users Watch for During a Project’s “Slow Death”?This brings us to an easily overlooked question.Crypto has repeated one security principle for years:“Not your keys, not your coins.”As a result, many people naturally assume that once their assets are held in a wallet where they control the private keys, the most important security problem has been solved.That principle is not wrong. But it only solves half the problem, because holding your own private keys gives you control over the account—it does not automatically guarantee that the asset itself will remain redeemable or that you will always have a viable exit path.The reason is simple: assets displayed in the same wallet can represent fundamentally different things.Imagine that your wallet shows $10,000 worth of assets. That balance could consist of: native ETH on Ethereum; a deposit or receipt token issued by a lending protocol; an LP token; a bridged representation of BTC issued through a cross-chain bridge. All four appear in your wallet, and all four require your private key to authorize transfers.But if the underlying protocol—or even the underlying network—stops operating, the outcomes can be very different.Scenario 1: The Project Shuts Down, but Users Can Still Exit Through Smart ContractsThe wind-down of dYdX v3 is a relatively ideal example.In 2024, dYdX decided to discontinue v3 and shift development toward the new dYdX Chain. Users were notified in advance to close their positions and withdraw USDC. After the product was shut down, the relevant contracts were frozen, while an exit mechanism remained available for users who had not yet withdrawn their funds.This is an almost textbook example of the “walkaway test”: the team can stop providing the product, but users’ ability to withdraw their assets does not completely depend on the team remaining in business.This is also a practical way to evaluate how truly “non-custodial” a DeFi protocol is: if the development team stopped maintaining the product tomorrow, could an ordinary user still withdraw their funds through on-chain contracts? Further reading: A Turning Point in a Decade-Long Debate: Could Ethereum Move Beyond the “Trilemma”?Scenario 2: The Token Really Is in Your Wallet—but It Is Only a Claim on Another AssetThe story of Ren Protocol illustrates the other side of the issue.Anyone who used DeFi during the previous cycle will probably remember Ren. It was once an important piece of BTC cross-chain infrastructure.Users could move BTC to Ethereum through Ren and receive a wrapped token called renBTC, which they could then use as collateral in Ethereum DeFi protocols to earn yield, borrow, and more.In theory, renBTC could sit in your own wallet. You controlled the private key, and the blockchain did indeed record your renBTC balance.The problem was that renBTC was not BTC on the Bitcoin network.It represented a claim on the BTC backing the Ren bridge.So when Alameda Research collapsed in 2022 and Ren lost critical financial backing, the Ren 1.0 network began shutting down. Projects including BadgerDAO urgently warned users to unwind their renBTC exposure, because once Ren 1.0 stopped operating, holders would no longer be able to use the original bridge to redeem renBTC for native BTC on Bitcoin.In other words, renBTC may still have been sitting in your wallet, and no one could simply burn or transfer it away. But your private key alone could not restart the Ren network after it had stopped operating and redeem that renBTC for native BTC.The same logic applies to many bridged assets, wrapped assets, LP tokens, lending receipts, and certain staking derivatives.What users control is the “receipt” or claim. Whether it can ultimately be redeemed for the underlying asset depends on whether the smart contracts, reserves, oracles, bridge validators, liquidity, and redemption infrastructure behind it are still functioning.Scenario 3: If the Underlying Network Shuts Down, a Private Key Cannot Keep the Chain Producing BlocksGo one layer deeper, and the problem becomes even more straightforward.Some chains may shut down entirely or become effectively abandoned, making reliable block production difficult to guarantee. We have seen cases of this kind with networks such as Eclipse and AO.If an entire network stops operating, you may still retain your private key, and historical blocks may still contain records showing how many tokens you owned.But that does not necessarily mean you can continue transferring those assets as freely as before.So if we break “asset control” down more fully, it contains at least three layers: Account control: Who controls the private key and mnemonic phrase? Claim on the asset: Is the asset in the wallet native, or is it a claim issued by a protocol, bridge, custodian, or asset pool? Ability to exit: When you actually decide to leave, do the underlying network, smart contracts, liquidity, and required infrastructure still allow the asset to be redeemed and migrated? “Not your keys, not your coins” mainly addresses the first layer.But when a project begins to decline, stops being maintained, or heads toward shutdown, the problems are often concentrated in the other two.That is why, amid an ongoing structural shakeout across the industry, the more important question is:If this project stopped operating tomorrow, would I still be able to recover my assets in full?3. Understanding “Self-Custody” More Fully and AccuratelyIn reality, most projects do not suddenly go from “fully operational” one day to “completely dead” the next.Real decline usually unfolds over a long period of time.A practical way to spot it is to look beyond the token itself and watch four things together: people, money, code, and exit paths. Start with the money—especially whether genuine demand remains once liquidity incentives disappear. A higher TVL does not automatically mean greater safety, and more transactions do not necessarily mean more value. The real questions are: once token rewards are removed, how many people keep using the product? Can protocol revenue cover the cost of maintaining the team and other ongoing expenses? Then look at the people—especially whether social media is the only part of the project still active. Many projects will never formally announce, “We no longer have anyone developing this.” In that sense, many of the projects discussed above were relatively responsible simply for making an official announcement. A more common pattern is that GitHub sees no meaningful core code updates for six months, serious bugs remain unresolved for long periods, roadmaps are repeatedly delayed, and communities are left unattended. Finally, look at the exit path. This is the step everyday users are most likely to overlook—and potentially the most valuable one. For any significant on-chain asset, you should at least know which network it is on, what its contract address is, whether the balance shown in your wallet is a native asset or a receipt, how it can be redeemed for the underlying asset, and whether another way to interact with the protocol exists if the official frontend goes offline. As the industry goes through more structural shakeouts, the meaning of “self-custody” also needs to be understood more fully.For core assets held over the long term, keeping them in a wallet where you control the private keys remains one of the most important security fundamentals.But once you start using DeFi, bridges, staking products, and other on-chain services, you need to ask one more question: where exactly did my assets go?Depositing ETH into a protocol and receiving a token in your wallet does not mean that ETH is still sitting at the original address.Bridging BTC and seeing a BTC balance on an L2 does not mean you still hold native BTC.And moving assets into an LP position, vault, or lending market and seeing a balance on screen does not guarantee that you will be able to redeem them later at the value shown.Closing ThoughtsPOAP’s departure has struck a chord with many long-time users because it once again reminds those still in Web3 of a simple reality:A product can have no token, no elaborate financial game, and a community that genuinely loves it—and still eventually reach the end of its life.That is not an anomaly unique to blockchain.Quite the opposite. It may be a sign that crypto is finally starting to look more like a normal industry:Products have life cycles. Teams change. Failed business models disappear. And limited developer resources, capital, and user attention continue flowing toward more productive parts of the market.We will probably see many more farewells like these in the years ahead.Some projects, like POAP, will leave behind on-chain memories from a particular era.Some protocols, like dYdX v3, will wind down in an orderly way while allowing users to continue exiting through smart contracts.And some assets, like renBTC, will remind people—only when the infrastructure behind them is about to disappear—to ask what exactly they have been holding in their wallets all along.Protocols can disappear. Projects can fail. Even an entire blockchain can eventually reach the end of its life.But the most important underlying principle of crypto asset security should remain unchanged:Do not make your ultimate control over your assets dependent on the assumption that any single project will stay in business forever.It is a reminder worth keeping in mind.
2026-08-14
Writing Censorship Resistance Into the Protocol: Who Decides Whether an Ethereum Transaction Is Included in a Block?

Writing Censorship Resistance Into the Protocol: Who Decides Whether an Ethereum Transaction Is Included in a Block?

In the blockchain world, one term comes up often: censorship resistance.At first glance, it may sound political, or even like a slogan tinged with anarchism. But for Ethereum, an open settlement network for users worldwide, censorship resistance is not primarily a political position. It is a concrete technical capability.Imagine that you submit a transaction in your imToken wallet.The signature is valid, your account has sufficient funds, and the gas fee is reasonable. Yet the transaction remains unconfirmed for a long time, with your wallet continuing to show it as “Pending.” Meanwhile, other transactions paying similar or even lower fees continue to be included in blocks.At that point, the question becomes: Who actually gets to decide whether a transaction is included in a block?After all, if Ethereum ultimately depends on a handful of centralized participants to decide which transactions can be included, there would be little fundamental difference between Ethereum and a traditional financial system.This is why Ethereum has been exploring censorship-resistance mechanisms such as FOCIL and FairFIL. They are attempts to answer a question that sounds simple but is critical to the network’s design:How can Ethereum ensure that every transaction that complies with protocol rules has a fair opportunity to be included in a block?1. Where Does Censorship Come From?To understand why Ethereum needs these mechanisms, we first need to look at what happens after a transaction is sent from your wallet.When a user signs and broadcasts a transaction, it typically first enters Ethereum’s public transaction pool, commonly known as the mempool. Think of the mempool as a waiting area containing large numbers of transactions that have not yet been included in a block.But entering the waiting area does not mean the transaction is already on-chain. Someone still needs to select transactions from the mempool, determine their ordering, assemble them into a complete block, and submit that block to the network for confirmation.This is where the problem begins.After Ethereum transitioned to proof of stake (PoS), it introduced the proposer-builder separation (PBS) model in part to reduce the risk that large staking pools could use MEV (maximal extractable value) to reinforce their economic dominance. Under this architecture, the block production process is effectively split between two roles: Builder: collects transactions, determines their ordering, identifies arbitrage and liquidation opportunities, and constructs a block designed to maximize revenue. Proposer: selects one of the candidate blocks submitted by builders and proposes it to the network. This separation of responsibilities has clear practical advantages.MEV strategies have become increasingly sophisticated in recent years. If every ordinary validator were expected to independently optimize transaction ordering and block construction, large operators with greater access to capital, data, infrastructure, and technical expertise would gain a significant advantage.By leaving complex block construction to specialized builders, ordinary validators can still propose blocks and earn rewards without having to develop advanced MEV capabilities themselves. This helps reduce the centralizing pressure MEV could otherwise place on Ethereum staking.But the model has also created another problem: block construction has become highly concentrated.Today, more than 90% of Ethereum blocks are produced by only a small number of professional builders. Because many of these builders are identifiable businesses operating in specific jurisdictions, they may also face external compliance pressure arising from laws and sanctions regimes, including those administered by the U.S. Office of Foreign Assets Control (OFAC). This concentration creates a real centralization risk.If several dominant builders decide to selectively filter transactions involving certain sensitive contracts, such as Tornado Cash, or particular addresses, those transactions may be delayed for a long time, or effectively censored.From an everyday user’s perspective, Ethereum is an open network that anyone can connect to, transfer assets through, and use to interact with smart contracts. At the protocol level, however, broadcasting a transaction is only the first step. For the transaction to actually take effect, it still needs to be selected, ordered, and included in a block by a block builder.This is why Ethereum’s discussion of “censorship resistance” is not merely a broad debate about politics, regulation, or sanctions. At its core, it is a very specific technical question:If a transaction complies with protocol rules, can the network ensure that it has a fair opportunity to be included in a block within a reasonable period of time?2. From FOCIL to FairFIL: How Ethereum Is Limiting Block BuildersAt this point, the underlying problem is clear.Builders can make block construction more efficient. But if the power to determine transaction inclusion remains concentrated among a small number of builders over the long term, Ethereum risks creating a new form of centralized control.To address this, Ethereum researchers have proposed a mechanism known as Inclusion Lists.The name may sound abstract, but the basic idea is straightforward.Builders can continue constructing blocks, but they should not have unilateral control over which transactions get included. Validators participating in Ethereum staking should also retain some authority to identify transactions that must be included, provided they satisfy the relevant protocol conditions.Think of a block as a bus with a limited number of seats.The builder gets to decide how most passengers line up and where they sit, using more efficient arrangements to maximize the block’s overall revenue. But validators can also submit a list of “passengers who must be allowed to board.”As long as those transactions remain valid, offer a reasonable fee, and there is sufficient space in the block, the builder should not be able to keep excluding them indefinitely simply because it prefers not to include them.That still leaves two important questions:Who should create the Inclusion List?And what happens if someone deliberately leaves an eligible transaction off the list?FOCIL and FairFIL approach these two problems from different directions.1. FOCIL: No Longer Letting a Single Proposer Control the Inclusion ListFOCIL, or Fork-Choice Enforced Inclusion Lists, shifts the power to require transaction inclusion away from a single proposer and distributes it across a committee of validators.During each block-production cycle, the network randomly selects a group of validators to form a temporary Inclusion List committee.Each committee member independently observes its local view of the network mempool and submits its own Inclusion List.This means that even if 99% of builders and proposers attempted to censor a particular transaction, a single honest committee member could still place that transaction on an Inclusion List and bring it under protocol-level inclusion requirements. To keep censoring the transaction, an adversary would then have to overcome multiple independent participants rather than a single decision-maker.This is one of FOCIL’s key strengths: the mechanism does not require every committee member to remain neutral.But producing an Inclusion List is not enough.If a builder could simply receive the list and choose to ignore it, the list would amount to little more than a recommendation.FOCIL therefore adds a second layer of enforcement through Ethereum’s fork-choice rule.Validators responsible for attesting to blocks check whether the builder has complied with the committee’s Inclusion List requirements. If the builder violates those requirements, attesters can refuse to support the block.As a result, a block that violates the relevant Inclusion List requirements would be rejected by the network’s fork-choice process and fail to become canonical.For the builder, this creates a substantial economic cost: the block it constructed may ultimately fail to gain network support.2. FairFIL: Not Just Filling Gaps, but Making Omissions VerifiableIf FOCIL uses consensus rules to constrain censorship, FairFIL, or Fair Forward Inclusion Lists, goes a step further by introducing accountability and economic consequences that make prolonged censorship far more expensive and difficult to sustain.The idea is simple in principle:If a transaction does not make it into a block, there should be, wherever possible, a publicly verifiable record explaining that omission.In practice, builders may need a brief window to optimize transaction ordering and pursue MEV opportunities. FairFIL allows some flexibility within defined constraints. But if a builder attempts to carry censorship over into the next block, the protocol can immediately trigger its accountability mechanism.The mechanism can be understood in three broad steps.First, the protocol establishes a set of public, verifiable reference rules for determining which transactions in the public mempool would normally qualify for inclusion in the current block. If a transaction that should have qualified under those rules is ultimately not included, the builder must publicly add it to the FairFIL.Second, validators check whether that disclosure is complete. If a builder omitted a qualifying transaction from the block and also failed to disclose it, the omission may be detected and could affect whether validators support that block.Third, valid transactions added to the FairFIL become priority inclusion obligations for subsequent blocks. The next builder can still decide exactly where those transactions appear within the block, but it cannot continue pretending they do not exist.If the same transaction continues to be omitted, the relevant block may lose validator support, potentially causing the builder to forfeit the revenue from an entire block.In other words, FairFIL’s “accountability” relies on escalating economic penalties. Builders that persistently censor transactions could risk forfeiting an entire block reward and may even face penalties on staked collateral, making sustained censorship increasingly expensive.This reflects the direction in which Ethereum’s censorship-resistance research is evolving: toward a more practical system of constraints.Even if a small number of participants want to censor transactions, maintaining control over transaction inclusion over time becomes increasingly difficult. Even if someone deliberately excludes a transaction, that decision should leave a trace—and continued censorship should come at an increasingly high cost.3. What This Means for Everyday UsersFor everyday users who transfer assets, swap tokens, or interact with DeFi through wallets, these underlying mechanisms would not require any change in how they use Ethereum if they are eventually deployed.Users would still enter an amount in their wallet, review the gas fee, sign the transaction, and wait for confirmation. What may change significantly is the invisible protocol logic determining whether that transaction makes it into a block.The most important improvement would be greater certainty around transaction inclusion.First, a valid transaction would no longer depend entirely on the decision of a particular builder. Even if the current builder does not want to process it, other validators could place the transaction on an Inclusion List, creating a protocol-level requirement for it to be considered for inclusion.Second, the power to determine whether a transaction can enter a block could gradually become separated from the power to determine where that transaction appears within the block.Builders could continue using sophisticated algorithms to optimize transaction ordering and block revenue. They could still compete for arbitrage, liquidations, and other MEV opportunities. But their ability to decide who is allowed to “enter the market” in the first place would become more constrained.More broadly, Ethereum’s credible neutrality could gradually shift from a value proposition that depends on participants’ commitments to neutrality into a set of rules automatically enforced by client software.Users would not need to know which builder constructed the current block, nor would they need to trust every builder to voluntarily remain neutral. Validators would check blocks against the same protocol rules, making it difficult for blocks that violate transaction-inclusion obligations to gain network support.In the future, wallets and block explorers could even use these mechanisms to provide more detailed transaction statuses.Instead of displaying only a generic “Pending” state, a wallet might eventually be able to tell users whether a transaction has already appeared on an Inclusion List, whether a subsequent block is obligated to include it, and why it is still waiting.Is the gas fee too low?Has the transaction become invalid?Or is something unusual happening during block construction?Censorship resistance, however, does not mean that every transaction will immediately succeed.Transactions can still fail to make it into a block because of insufficient balances, nonce conflicts, gas fees that are too low, or contract execution conditions that are no longer valid.When the network is congested and block space is scarce, users may still need to compete through transaction fees and wait for confirmation.These mechanisms are primarily designed to address a different problem:A transaction that is valid, pays a reasonable fee, and has already propagated through the public mempool should not be delayed indefinitely simply because a small number of block builders choose not to include it.As of August 2026, EIP-7805, which specifies FOCIL, remains in Draft status.However, it has already been selected by Ethereum core developers as a consensus-layer Headliner for the Hegotá upgrade and has reached the Scheduled for Inclusion stage. This means client teams have agreed to move forward with implementation work and development-network testing around the proposal, although a final mainnet activation date has not yet been determined.FairFIL remains at a much earlier stage.For now, it is primarily a research proposal published in July 2026. Whether it will eventually become part of Ethereum’s roadmap will depend on broader discussion, implementation work, and security validation.Final ThoughtsEthereum cannot guarantee that every builder, validator, and infrastructure operator will remain neutral forever.Participants may face regulatory pressure. They may act in their own economic interests. They may also respond to external incentives.A truly resilient decentralized network cannot be built on the ideal assumption that everyone will always do the right thing.Real censorship resistance means that even if some participants attempt to interfere with transactions, others can still break that control.It means that even when someone chooses to deviate from neutrality, the protocol can make that behavior visible, expensive, and difficult to sustain.From the original idea of Inclusion Lists, to FOCIL distributing constraints across a committee of validators, and then to FairFIL making transaction omissions publicly verifiable, Ethereum is gradually moving from simply allowing anyone to submit a transaction toward ensuring that everyone’s transaction has a fair opportunity to be seen.From this perspective, Ethereum is trying to take censorship resistance from a statement of values and, step by step, write that commitment into the protocol itself.That is worth watching.
2026-09-02
From “Speculative Asset” to “Next-Generation Financial Infrastructure”: Is Crypto Building a New TradFi System?

From “Speculative Asset” to “Next-Generation Financial Infrastructure”: Is Crypto Building a New TradFi System?

In practical terms, many crypto narratives over the past several years can be reduced to one persistent question:“Which asset will rally next?”From DeFi Summer to NFTs, Layer 1s and Layer 2s, restaking, meme coins, and AI tokens, each narrative has emerged from a different technical rationale and market backdrop. Yet most have ultimately been judged by price performance.Even stablecoins, wallets, and bridges—products with clear practical utility—have often attracted attention mainly for how much trading and speculative activity they can support.Since the beginning of 2026, however, several developments across very different sectors have begun to emerge in quick succession: The total stablecoin market capitalization has reached approximately $300 billion, entering a new phase of expansion into global payment networks. DTCC has completed its first asset-tokenization transactions in a live production environment and plans to officially launch the service in October. Prediction markets are moving from crypto-native products into brokerages and regulated exchanges. AI agents are beginning to use stablecoins to autonomously purchase data, model calls, and digital services. These developments may appear unrelated. Viewed together, however, they reveal a more complete pattern: the issuance, custody, trading, payment, and settlement capabilities built by the crypto industry over the past decade are beginning to expand beyond crypto assets and open up to broader financial activity and the machine economy.In other words, crypto has not left speculation behind. But beneath its speculative markets, an increasingly comprehensive infrastructure layer is taking shape.1. Why Are These Breakthroughs Happening at Almost the Same Time?Real-world assets, stablecoins, prediction markets, and AI agents did not suddenly become relevant because of a single new market narrative.A more important reason is that the different components required for a new financial infrastructure have spent years developing independently and are finally beginning to connect.1. Stablecoins Turn Money Into an InterfaceStablecoins are not new, but their role is changing.In their early years, stablecoins were primarily used as units of account on exchanges, on-chain safe-haven assets, and settlement instruments for crypto trading. Most funds continued to circulate within the crypto economy.Today, a growing number of issuers, banks, payment providers, and fintech companies are using stablecoins for merchant payments, global payroll, cash concentration, and cross-border settlement.According to Circle’s first-quarter 2026 disclosure, Circle Payments Network reached approximately $8.3 billion in annualized transaction volume based on activity during the preceding 30 days. Its partner Nium operates a payout network covering more than 190 countries and regions.In this context, stablecoins are no longer merely “on-chain dollars.” They are becoming a form of money that software can call directly.Stablecoins can be transferred around the clock, embedded in programs, released automatically when specified conditions are met, and used as the settlement asset immediately after a transaction is completed.For internet applications, sending a stablecoin is increasingly similar to calling a payment API. There is no need to understand correspondent banking, clearing windows, or cross-border account structures; the application only needs to confirm the amount, address, and execution conditions.This is the critical shift taking stablecoins from crypto trading instruments to payment infrastructure.2. RWAs Turn Assets Into Programmable ObjectsIf stablecoins answer the question of what money should be used for settlement, RWAs answer a different question: what assets can be traded and settled?Historically, most RWA products focused on U.S. Treasuries, money market funds, and private credit. Their primary value was giving crypto users access to returns generated by off-chain assets.More recently, however, traditional financial infrastructure providers have begun actively moving securities registration, custody, trading, and settlement on-chain.On July 15, DTCC completed tokenized-asset transactions in a live production environment with participation from more than 30 traditional financial institutions and digital-asset companies. It plans to formally launch its tokenization service in October.Unlike a conventional synthetic asset wrapper, DTCC’s model is designed to preserve the ownership, investor protections, and entitlements attached to the corresponding traditional securities.Earlier, in March, the U.S. Securities and Exchange Commission approved Nasdaq’s proposal to allow eligible listed securities to trade in tokenized form. Tokenized and traditional shares use the same CUSIP, convey the same material rights, and continue trading within the existing market system and securities-law framework.This is fundamentally different from simply issuing a token that mirrors a stock’s price.It means on-chain assets are beginning to connect with actual ownership, custody relationships, corporate actions, and legal rights, allowing them to support part of the lifecycle of traditional assets.As these connections are established, blockchains are no longer limited to creating new assets. They are also beginning to support part of the infrastructure through which traditional assets operate.3. Prediction Markets Turn Information About the Future Into PricesPrediction markets provide another missing layer: information and price discovery.Stocks price future corporate cash flows. Bonds price credit and interest rates. Prediction markets price the probability that an event will occur.Election results, interest-rate decisions, sporting events, corporate developments, and even product release dates can all be compressed into continuously changing market prices. Further reading: “World Cup Fever Propels Prediction Markets: How Polymarket and Peers Are Driving Mainstream Crypto Adoption”Robinhood has disclosed that more than 1 million customers participated in its prediction-market business during its first year, trading approximately 9 billion contracts in total. It has also acquired CFTC-regulated exchange and clearing infrastructure.From an infrastructure perspective, prediction markets provide a capability that traditional financial markets have struggled to deliver at scale: aggregating fragmented information into a probability that can be read in real time.4. AI Agents Become New Economic ActorsStablecoins and RWAs address the questions of money and assets. AI agents introduce a new variable: who initiates economic activity?Traditional software executes predefined processes. Agents can understand objectives, search for services, compare prices, and make decisions within a defined permission boundary.Once an agent can autonomously pay for API access, it is no longer merely an information tool. It becomes a new kind of economic actor.The challenge is that many agent payments may be worth only a few cents, or even less. The fixed fees, settlement cycles, and identity-verification processes of traditional card networks are not naturally suited to high-frequency, low-value, automated machine payments.This is precisely where stablecoins and low-cost blockchains can be useful.Coinbase has integrated x402 and stablecoin wallets into Amazon Bedrock AgentCore, allowing businesses to set budgets and governance rules for agents. Google’s Agent Payments Protocol, or AP2, uses cryptographically signed authorization credentials to record what an agent is permitted to purchase, how much it can spend, and who initiated the operation. Further reading: “Crypto AI Protocol Landscape: Building a New Operating System for AI Agents on Ethereum”2. What Capabilities Does This Next Generation of Financial Infrastructure Already Have?These developments are occurring simultaneously because they are different components of the same system.Stablecoins turn money into an API. RWAs turn assets into programmable objects. Prediction markets turn information about the future into prices. AI agents allow software to participate directly in asset exchange for the first time.It is worth emphasizing that asking whether crypto is becoming infrastructure does not require speculation to disappear.Stock, foreign-exchange, and commodity markets all contain substantial speculative activity. The more important standard is whether external businesses and users are beginning to rely on a technology to complete tasks that were previously impossible, too expensive, or inefficient.By this measure, crypto and Web3 have already developed the early layers of a next-generation financial infrastructure.The First Layer: Asset Issuance and RepresentationNative tokens are no longer the only assets that can exist on-chain.Stablecoins, government bonds, money market funds, private credit, gold, fund shares, and equities are now available in different on-chain forms. But bringing assets on-chain means more than placing a digital certificate inside a wallet.Once an asset can be recognized by a smart contract, it can enter collateral, lending, trading, treasury-management, and automated-investment workflows directly.Operations that were previously distributed across registrars, custodians, brokers, and clearing systems may be compressed into a more unified execution environment.The Second Layer: Around-the-Clock Payments and SettlementTraditional cross-border payments generally pass through multiple correspondent banks and remain constrained by operating hours, account structures, and regional networks.Stablecoins can transfer value almost instantly and around the clock under a common asset standard.J.P. Morgan has said that Kinexys has processed more than $4 trillion since its launch, with average daily transaction volume exceeding $7 billion. It has also expanded its blockchain deposit accounts to support multiple currencies, including the U.S. dollar, euro, British pound, Japanese yen, Hong Kong dollar, Singapore dollar, and Chinese renminbi.Put simply, on-chain settlement does not require all money to be converted into publicly issued stablecoins.Bank deposit tokens, regulated stablecoins, central bank digital currencies, and on-chain commercial bank money may all coexist. What they share is the ability to be read and directed by software and settled simultaneously with asset delivery.The Third Layer: Continuous Trading and Price DiscoveryCrypto has already demonstrated that markets can operate around the clock and use smart contracts to automate matching and liquidity management.These capabilities are now expanding into more asset classes.Tokenized securities can shorten the interval between trading and settlement. Prediction markets can assign probabilities to events that traditional financial markets struggle to price directly.In the future, a company might hold an on-chain money market fund and automatically adjust its cash position in response to changes in interest-rate expectations reflected by prediction markets.An AI agent could simultaneously read asset prices, event probabilities, and liquidity conditions before deciding whether to execute a transaction.At that point, markets would no longer provide quotes solely for humans to inspect. They would provide real-time signals that software could consume directly.The Fourth Layer: Identity, Permissions, and AuthorizationFinancial activity involves more than transferring assets. It must answer a series of questions:Who initiated the transaction? Who has permission? How long does that authorization remain valid? What is the spending limit? Who is accountable if something goes wrong?Early crypto systems answered these questions primarily through private keys. Possession of the private key meant full control.Once enterprises, institutions, and AI agents move on-chain, however, a single private key is clearly insufficient for complex permission management.Google’s AP2 uses verifiable mandates to record user intent. Visa is developing agent identity directories, credentials, and scoring mechanisms. Mastercard’s Agent Pay for Machines seeks to provide machines with identity verification, permissions, transaction, and settlement capabilities.Account abstraction, passkeys, multisignature wallets, session keys, and spending policies also allow users to grant limited permissions to an application or agent without surrendering full control of the account.This could fundamentally change the role of wallets.Future wallets may do more than store assets and private keys. They may need to manage user identities, institutional credentials, agent permissions, spending budgets, and authorization records, becoming a control interface through which users enter the on-chain economy. Further reading: “Ten Years of Web3 Wallets: A New Map for Crypto Users as the AI Inflection Point Arrives Faster”The Fifth Layer: Connections to Real-World Law and RegulationWhether a financial system can become genuine infrastructure depends not only on whether the technology works, but also on whether real-world law recognizes the resulting transactions.In January 2026, the U.S. SEC issued a statement on tokenized securities that distinguished among securities tokenized directly by an issuer, tokenized interests created by a third party holding the underlying asset in custody, and on-chain products providing only synthetic price exposure.This distinction matters because all three products may look like “on-chain stocks,” while giving holders very different legal rights.The CLARITY Act seeks to further define the respective jurisdictions of the SEC and CFTC and establish clearer rules for digital-asset issuance, trading platforms, software developers, DeFi, and investor protection.The legislation remains contested and has not completed the legislative process. Even so, the focus of regulation is gradually shifting away from whether crypto should be permitted to exist and toward more specific questions: who may issue an asset, who is responsible for custody, and which rules apply to each type of asset?That shift is itself an important sign of infrastructure adoption.Banks, brokerages, asset managers, and payment companies can make long-term investments only when they can reasonably understand their legal responsibilities rather than confining themselves to isolated experiments.3. The Necessary Path From “Speculative Market” to “Infrastructure”Is crypto moving from a speculative market toward infrastructure?The answer increasingly appears to be yes, and the direction is difficult to reverse. But this is not a binary replacement in which one role eliminates the other.Stablecoin payments and RWA growth will not suddenly remove crypto’s speculative character. More accurately, crypto is building an execution system beneath its existing markets—one that can be used by real-world assets, traditional institutions, and intelligent software.The first sign of this shift is the expansion of the industry’s revenue sources.Historically, a large share of protocol revenue came from leveraged trading, asset issuance, liquidation, and the recirculation of on-chain capital.A second category of cash flow is now beginning to emerge from external economic activity. Businesses use stablecoins for cross-border settlement. Funds distribute and manage assets through on-chain channels. Software purchases API calls on demand. Agents automatically pay for data and model usage.The participants in the on-chain economy are also expanding.The typical user was once a human trader sitting in front of a screen and clicking “Confirm” or “Sign.” In the future, a large share of on-chain interactions may be initiated by enterprise systems, payment programs, and AI agents.Humans will define the objectives, boundaries, and permissions. Software will handle execution.The regulatory debate is changing as well.The previous question was whether crypto should be incorporated into the existing financial system. The emerging question is how to define jurisdictional boundaries, protect investors, regulate intermediaries, and preserve room for self-custody and open software.Still, crypto infrastructure has a long way to go before it moves from being operationally possible to something institutions and users can depend on over the long term.First, on-chain confirmation is not the same as legal finality.Who holds the assets underlying a token? Can investors recover them if the issuer becomes insolvent? Do different jurisdictions recognize on-chain transfers of ownership? Do token holders possess dividend and voting rights, or merely price exposure?Smart contracts alone cannot resolve these questions.AI agent payments face a similar accountability problem.If an AI agent executes an incorrect transaction because of false information, prompt injection, or model hallucination, who is responsible: the user, the model provider, the wallet, or the merchant?There is currently no mature framework for resolving these cases.Future wallets will need to do more than simply let an agent make payments. They must determine which assets the agent can use, who it can pay, how much it can spend, and how permissions can be paused or revoked when something goes wrong.At the same time, liquidity fragmentation may become more severe as the number of assets and networks grows.The same stablecoin, fund, or security may exist across multiple public blockchains, bank ledgers, and permissioned networks without being freely transferable among them.The next phase therefore needs more than the continued issuance of new assets. It requires unified asset standards, cross-network communication, and secure settlement mechanisms.Privacy is another unavoidable requirement for institutional adoption.Public blockchains improve verification and auditability, but businesses will not want to expose every customer, supplier, payroll entry, and movement of funds.The ability to use zero-knowledge proofs, selective disclosure, and on-chain credentials to satisfy compliance requirements while preserving necessary privacy will directly determine how far on-chain finance can expand.A more fundamental limitation is that blockchains can improve the efficiency of trading and settlement, but they cannot create credit automatically.Unsecured lending, insurance, receivables financing, default resolution, and liquidity support all depend on complex systems of risk management, law, and accountability.Prediction markets do not automatically resolve insider information, inadequate liquidity, or outcome adjudication simply because their prices are public.Crypto today has therefore established much of the basic framework for assets, money, trading, and settlement. But credit, privacy, accountability, and legal finality have yet to form a complete loop.Crypto is becoming infrastructure, but it is still far from becoming infrastructure that everyone can trust unconditionally.Final ThoughtsLooking back, the most important development of 2026 is not the sudden breakout of any single sector. It is that several pieces of the puzzle, each developed separately over many years, are beginning to connect at the same time.Assets now have on-chain forms. Money has programmable rails. Markets provide around-the-clock prices. Software is gradually gaining the authority to make payments and execute trades. Regulation is moving from ambiguous gray areas toward more specific boundaries.These changes are not enough to prove that an entirely new financial system has already been built. But they are enough to show that crypto’s role is changing.Crypto has not left the speculative market. Beneath that market, it is gradually building an execution system that real-world assets, traditional institutions, and intelligent software can use.After 15 years of evolution, the crypto industry has taken an important step: from a social experiment around “digital gold,” to a high-frequency speculative casino, and now toward frictionless global financial infrastructure.The next 15 years are worth watching.
2026-08-14

Load more