The line of defense that the crypto market has never built

sourceBitpushNews·Wendy·02:39 编辑
The line of defense that the crypto market has never built

By Omer Goldberg, founder of Chaos Labs

Original title: The Market Crypto Never Built

Compiled and organized by: bitPushNews


1775586662812.jpg

I founded Chaos because I believe in two things:

  1. The future of finance is on-chain.

  2. In that future, no version allows on-chain systems to be less secure than the systems they replace.

Five years later, these two points are still true.

Chaos worked with partners such as Aave, Ethena, Kraken, PayPal, LayerZero, Jupiter, and GMX to achieve this vision, processing trillions of dollars in cumulative transaction volume and achieving zero bad debts.

Every security incident follows the same script

But five years of deep cultivation in this field also meant being able to closely observe everything that constantly went wrong.

Every exploit (exploit) follows the same script.

Some links have broken down, millions of dollars have disappeared, and the crypto Twitter (Crypto Twitter) community is furious.

Everyone agreed this sucks!

But then a few weeks passed, and we moved on to the next farce. As attention dissipated, nothing substantial changed.

The temptation is that people tend to zoom in (Zoom in) to a single team, a single vulnerability, or a single missed check item. Sometimes this kind of analysis is really important; I've written many similar articles.

But after observing the same cycle for years, the pattern is clear. These are not isolated failures.

Our industry structure was built to produce these results.

spurring

Charlie Munger once said, “Tell me the incentives and I can tell you the results.”

In traditional finance and Web2 security, risk management becomes a**non-discretionary (mandatory) ** once you touch customer funds or critical systems. There are standards, audits, procurement requirements, insurance companies, and regulators. None of them are perfect, but collectively they form the bottom line.

Cryptocurrency never built that layer.

So, yes, cryptocurrencies have a security issue.

However, this safety issue is a downstream product; upstream is a larger market incentive issue.

Without that structure, growth looks like progress, and risk looks like cost.

Rational decisions are not the same thing as good decisions, and they won't be the same thing until incentives change.

How is the market built

What if a cloud security company has an annual revenue (ARR) of $5 million and is growing rapidly in the right niche? Buyers and investors will compete for it at a revenue valuation of 20 times.

Google bought Wiz at a cost of $32 billion, with a projected revenue estimate of more than 30 times.

These valuations didn't come out of thin air.

They exist because buyers already exist; buyers exist because regulation created them.

If you process payment data, PCI DSS will tell you what your responsibilities are.

If you're a publicly traded company, SEC (US Securities and Exchange Commission) rules require you to disclose major cybersecurity incidents.

Once this accountability mechanism is defined, budgets, procurement processes, and industry categories follow.

Geniuses who could have developed games, social apps, or B2B software choose to build secure products because of the financial rewards. Accountability creates demand, and demand attracts talent, and talent is the core of truly making the system more secure.

An efficient marketplace will attract the people most needed by the industry.

The evidence is in the compliance stack

Some will say, “But cryptocurrencies do have big security companies. What about Chainalysis and TRM?”

That just proved my point. Check out why these businesses exist:

If you're a US money services business (and most crypto companies are), you must comply with the Bank Secrecy Act (BSA), OFAC sanctions screening, and FinCEN's anti-money laundering requirements.

  • The Department of Justice (DOJ) has fined OKX more than $500 million for anti-money laundering failures.

  • Bittrex paid $29 million for allowing users to evade sanctions in Syria, Iran, and Cuba.

And this enforcement is getting stronger, not weaker. The GENIUS Act included payment stablecoins in the BSA category, and FinCEN's new reporting framework means that every former employee is now financially motivated to report compliance flaws.

Companies don't buy just one compliance solution. They'll buy two or three because when the Department of Justice or FinCEN comes to account, the only question is whether you've done your “best efforts.”

This is “life-saving” (CYA) infrastructure.

The Internal Revenue Service (IRS) began working with TRM soon after it launched, even though it has been using Chainalysis for years, precisely because it doesn't want to put all of its eggs in one basket. TRM's valuation reached $1 billion. Chainalysis peaked at $8.6 billion.

They exist for only one reason: buyers don't need to think about whether this is important.

Where is the gap

Now let's take a look by name and see which fields don't have that kind of mandatory function (Mandatory Function):

  • There is no so-called “Bank Secrecy Act” for a loan agreement with $2 billion in user deposits.

  • There is no OFAC-like accountability for a perpetual contract DEX (Perp DEX) that processes multi-billion order flows without stress-testing its clearing engine.

  • There is no mandatory disclosure requirement when governance parameters or multisigs (multisigs) change and increase systemic risk.

  • When the agreement uses user funds to launch a new treasury strategy, there are no procurement requirements.

Chainalysis and TRM didn't falsify my arguments. They are the arguments themselves. Where there is mandatory regulation, a market will be established. Where there is no market, there is no market.

I'm not here to defend regulation

If you told me in 2013 when I was first drawn to the Bitcoin white paper (Nerd sniped) that I would write an article like this in the future, I wouldn't believe you.

I've been expelled from school, dropped out of college, and have never been disciplined. I've been working for Meta/Instagram for many years, and the motto is “Move Fast and Break Things” (Move Fast and Break Things).

So, when I entered the field of cryptography, I was deeply anti-authoritative, and I was convinced that we could build something better without any centralized authority telling us how to do it.

However, after more than a decade, I finally understood why there are standards and rules to protect users. It's not because they're perfect. They're clearly not perfect.

But because once we let ourselves be our own, we've proven time and again what our real priorities are.

We have our freedom. We have time, too.

Today's state of the industry is a result of our choices, and the results speak for themselves.

reverse selection

If there is no coercive function, the market will reverse.

In healthy markets, the entities most in need of security controls are often the most likely to adopt them because this is a must.

In the crypto world, the opposite is true:

  • The best teams buy security/risk infrastructure early because they want to survive for the long term.

  • The weakest teams will delay, narrow down, or compare prices until an accident occurs and demand becomes undeniable. And these teams are the ones most likely to explode.

In the end, this category was reverse-selected: the team that needed protection the most was the least likely to pay for it from a systemic perspective.

The asymmetry at the core is simple:

Growth will be reflected in dashboards and investor updates.

Safety manifests itself as “no news” when it works. In a regulated market, “safe and sound” still addresses compliance, audit preparation, board reports, and insurance company requirements. And in the cryptocurrency world, “no news” doesn't win you anything. It looks like it's just a cost item that could be cut.

Rational buyers, operating within these incentives, can always find reasons to delay investment.

You're selling “disaster absence” to buyers who are rewarded for growth.

The missing market structure doesn't just affect “who buys”. It also affects “what to buy” and “how much” to buy.

Bank of America spends 6-10% of revenue on compliance.

Financial crime compliance spending by financial institutions in the US and Canada exceeds $61 billion a year. The reason this expenditure exists is because the responsibility behind it is non-negotiable.

Meanwhile, the total bug bounty (bug bounty) spend across the DeFi sector in 2025 was $112 million. This is one of the only quantifiable metrics to measure active safety investments across the industry, accounting for only about 0.33% compared to $31 billion in agreement revenue. In the same year, the industry lost $3.4 billion due to exploits.

The prevention budget is just a rounding error (rounding error) in the face of loss.

This gap is no accident. In regulated industries, safety budgets track obligations rather than quarterly sentiments. It can withstand the downturn in the market because there is always a sense of responsibility. But in the crypto space, spending is discretionary, so it's cyclical.

In the downturn cycle, they disappeared.

The same agreement invests heavily in incentives, coin listing, KOL promotion, and conference sponsorship, but becomes frugal again when it comes to risky or safe projects.

This has a compounding effect that most people don't expect.

Companies that build risk and safety infrastructure are unable to recruit ahead of time based on demand, cannot maintain R&D in the downturn cycle, and cannot compound interest like companies with a solid bottom line of revenue.

Each cycle resets the mature capabilities of the category, which means that the industry's security infrastructure will always be under-built compared to the scale it protects.

In an industry that protects $130 billion in user deposits, investing in risk/safety is like buying optional plug-ins.

Attackers won't slow down in a bear market, but risk and security budgets will.

After being deeply involved in this field for five years, I know the difference between categories funded by belief and categories driven by real demand.

You don't need regulators to tell you this

If your app accepts user deposits, congratulations! You've entered a risky business. Whether the agreement wants to frame itself as an infrastructure, revenue platform, or something decentralized, risk management is no longer an option the moment you host value or provide leverage.

It's not just a matter of one single player.

It's a supply chain where every participant has a rational reason to view risk as someone else's responsibility.

Investors evaluate growth. The auditor narrows down the scope of the audit. The exchange optimizes the listing of coins. The custodian does not make hard requirements for control. No one is irrational. That's the problem.

The system worked exactly as predicted by the incentive mechanism until an exploit reminded everyone that the risk was always shared by everyone.

If the future of finance is on-chain, the path to it is to build systems worthy of hosting global capital.

Not the ones that require users to do better (??) A system that is economically efficient to tolerate more risk.

Motivation and results

The market either establishes this layer or continues to pay for its absence.

When an institution examines DeFi and decides that its risk model isn't mature enough to justify risk exposure, it's not a hypothetical cost. It's a measurable cost, and the industry is paying the price along with exploits and preventable losses every cycle.

After five years in the field, I've learned one thing: you can't expect the agreement to independently and consistently choose investment risks and secure infrastructure while all other incentives in the market are driving them in the opposite direction.

The voluntary model has hit the ceiling. No post-accident conviction (conviction) can permanently raise this limit. Asking individual founders and teams to be more responsible in a system that rewards irresponsibility isn't a strategy.

But I think some different conditions are beginning to emerge. The integration of on-chain finance with traditional finance is faster than most people can imagine. As the lines between the two blur, whether cryptocurrencies want to or not, the regulatory pull is increasing. Agencies entering this space brought with them their compliance expectations, procurement processes, and risk frameworks.

Cryptocurrency has never established a standard layer for itself, and may eventually be introduced by people who can't operate without standards.

Meanwhile, something more fundamental is changing. For most of financial history, top risk intelligence has been locked behind institutional budgets. AI is changing who gets it. It is now possible to directly provide institutional-grade risk tools to users and investors, regardless of whether the apps they use invest in risk and safety.

But technology alone cannot solve market structure problems.

The industry still has to decide what it really is worth.

Every cycle, we tell ourselves that the last exploit was a wake-up call, and the future will be different.

The crypto world excels at inventing new financial primitives. But making them secure enough to deserve the trust people put into them is an engineering problem — and I think the technology is already in place for the first time. But engineering only makes sense if the industry decides that “protection” is a necessary condition, not the icing on the cake.

Show me the motivation and I'll show you the results.


Twitter:https://twitter.com/BitpushNewsCN

Compare the TG exchange group:https://t.me/BitPushCommunity

Compare TG subscriptions:https://t.me/bitpush

Original Link
#Aave#AI#Chaos#Ethena#GMX#Jupiter#Kraken#LayerZero#Paypal#交易#加密市场#深度#激励#观点#黑客
说明: All Bitpush articles reflect the author's views only and do not constitute investment advice.

Related

Loading...