182 - Hasu Explains: Is Lido a Threat to Ethereum?
Lido has over 30% ETH staked. Should we be alarmed? Joining us is Hasu to shed some light on this question.
Up next
All episodesROLLUP: Curve Exploit | BASE Memecoins | Richard Heart vs SEC
The New DeFi Meta with Paradigm’s Head of Research, Dan Robinson
Will DeFi Survive This?
DEBRIEF - Afropolitan's Grand Plan To Start A Country
Afropolitan's Grand Plan To Start A Country
ROLLUP: Worldcoin Launch | New Crypto Bills | Twitter X | Layer 2 Wars
Coinbase's 'Base' Powering Layer 2 Summer
Polygon’s Endgame: Polygon 2.0 with Sandeep Nailwal & Mihailo Bjelic
Inside the episode
Lido has over 30% ETH staked. Should we be alarmed? Joining us is Hasu to shed some light on this question.
TIMESTAMPS
0:00 Intro
4:34 Is Lido's Perception Unfair?
9:08 Is Lido Too Big To Fail?
15:57 What Can An Entity Do With 33%?
21:27 TLDR Recap and Overview
24:11 When Does Lido Risk Become Systemic
32:54 Lido Is Not One Entity
36:40 Node Operators vs DAO
41:19 LDO Governance
49:39 Is Lido Forkable?
52:37 The Path To 5,000 Operators
58:46 Distributed Validator Technololgy
1:08:16 Addressing The Critics
1:17:31 The Staking Social Layer
1:24:40 Is Lido Treated Unfairly?
1:26:47 Can We Keep Ethereum Decentralized?
1:30:07 Risks and Disclaimers
Resources
Hasu on Twitter: https://twitter.com/hasufl
Uncommon Core v2: https://www.ucc2.xyz/
Hasu last on Bankless: https://youtu.be/1qqkoGatPdE
Transcript
welcome to bankless where we explore the frontier of Internet money and internet Finance this is how to get started how to get better how to front run the opportunity this is Ryan Sean Adams I'm here with David Hoffman and we're here to help you become more bankless Lido has over 30 each staked right now all of the eats taking 30 is in light out should we be alarmed by this is this a threat to ethereum's decentralization that's where we start this episode today but we didn't end the episode there we also got into the more meaty topic is it even possible to keep ethereum decentralized over the long run the
guest today is protocol researcher hasu and this is a fantastic episode a few takeaways for you number one we talk about the state of staking as it is today what happens when an entity controls over one-third of ethereum's stake what about two-thirds number two we talk about the state of Lido how can it become more decentralized is it on that path number three we talk about this cultural phenomenon in ethereum we've got idealists and we have pragmatists there seems to be a cultural class between these two ideals of ethereum and the reality of network effects and Milwaukee traps what's the
right balance and number four we end the episode actually where we start which is this question does Lido have a bad rep is that fair or is it unfair David this was a really interesting episode to me I love having hacuan it's not his first time coming on Bank list why is this episode significant to you the need for this episode has been crescendo I would say there has been a growing conflict with lydo between lydo and others taking as a service organizations out there and some of it is real and can and concerning and these concerns have been
elevated by some in the ethereum leadership uh some strong ethereum community members and other critiques of Lido I think might be narrative and might be opportunistic by other uh staking as a service Orcs And so we I want to really unpack this question in this episode does Lido deserve the bad rap that it gets so this is the in defense of Lido episode where elido representative can come and speak on behalf of the vision for Lyda which is not something that I don't think you and I have yet been able to articulate here
on the podcast and so what is real about the critiques of Lido and what is fake is something that we try to unpack here in this episode yeah and uh as always of course we have a debrief episode where David I can't wait to talk to you about this there's so many ideas in my brain about this I want to get your raw thoughts that's available to bankless premium subscribers on a premium RSS feed you can click a link in the show notes to access that and as always guys this is uh you know the first step in a conversation about Lido it's not the only step so we'll certainly have future
episodes taking the counter position to this and as a reminder guys this is just one episode on Bank list about Lido and I think we'll have future episodes to continue the conversation maybe from some alternate perspectives but first we disclose bankless holds investments in Lido and rocketpool and David I have Angel investments in some smaller staking startups for long-term investors not journalists we don't do paid content and there's a link to all bankless disclosures in the show notes we were really excited to host this conversation with hazu like Ryan said he's been on the show a number of times before I have a ton of respect for the man in the way
that he thinks so I think this is going to be a very enjoyable conversation for the broader ethereum ecosystem and hopefully can start many further conversations as well so let's go ahead and get right into that conversation but first a moment to talk about some of these fantastic sponsors that make the show possible bang the station I'm honored to welcome hazu an independent researcher and crypto back to bank list he's been affiliated with a number of different organizations pushing the frontier of this industry previously research at Paradigm governance inside of maker Dao and more recently strategy lead at flashbots and also the reason why he's here on the show today is he is
also a strategic advisor to the Lido organization Lido of course is a staking as a service dial that holds over 31 of all eats staked making it the largest staking entity in ethereum and has been the focus of a lot of support from certain parts of crypto and also a ton of controversy from others so today on the show we're going to unpack some of the nuances about the Lido organization the perceived risks the reality of risks all about Lido and what it means to be the largest staking as a service organization in ethereum hazu welcome back to banglas
I'm very excited to be back David Ryan it's a pleasure yeah I think this is a conversation that I think all of the crypto space I I think generally gets a bad rap and maybe some of it's Justified maybe some of it's not justified but I'd like to actually explore the Contours of that conversation and try to figure out what's reality and what's narrative and what's truth so you ready for that yeah let's Dive In so maybe we can start with this hazu do you think Lido has an unfair rap in crypto like do you think
the perception of Lido's um perhaps doesn't it doesn't deserve the perception that it receives I think it's a nuanced question I think that um so just to already kind of lay out what I guess the controversy is um the the argument against Lido is that um it's the biggest stake in protocol and because of its size it can have um a small but nonetheless possible impact on the validators of ethereum to
behave in certain ways um and um this I would say a secondary argument that says state if is is the uh is kind of the asset that is issued by the Lido protocol that represents stake um on the beacon chain in a metadata and that asset is also becoming increasingly used and increasingly attractive to users because if you compare it to ethereum you know ethereum is the best asset in the world um but if you have steak Thief then it's
ethereum but it's staked so it's also earning four to five percent um in you know if denominated Network rewards from the beacon chain and the consensus layer so it's it's like if but um it's it's also generating some return for you and um so because this asset is becoming increasingly used compared to ethereum I think there's also increasingly uh systemic concerns in the sense that um if it's if it's kind of the unencumbered asset it's you know it's
very unlikely that there's ever any problem with it at the Smart contract level um and if there is then it's very clear that you know what ethereum should do about it but it's not so clear about stake Leaf right um because take Eve is a smart contract on ethereum and it's it's kind of a it's it's it's a protocol it's not part of the ethereum stack it's something that is built on top that was developed by the free market right and I think if there's a problem ever with staked Eve then it's much harder a much harder
decision that could potentially cause a rift in the ethereum community for what to do about this maybe to explain some of the um some of the reasons why this debate is so big is I think if you re-rolled the dice of ethereum you would have this debate no matter what I just like how you said ether I totally agree with you it's the world's greatest asset but the only thing that's better than ether is of course staked ether and I think in this conversation it is takes the assumption that eventually staked ether
will be the dominant currency inside of ethereum the dominant form of collateral simply just because it is ether plus more plus plus more of itself and so this is why this this conversation naturally concludes is like which free market service provider is going to provide that version of staked ether into defy into the ethereum economy would you say that that's an accurate interpretation of the future 100 I and I really like how you said that if you reroll the dice um of ethereum and you'll play through the history a million times then I think
in in virtually every case you would have the same debate because you had ether and then you go to proof of stake you create the ability to have steak Diva and this always always creates the situation where people will of course want to delegate their stake two node operators and while having it on the beacon chain they still want to use it at the execution layer you know they want to trade it they want to collateralize it and in general they want the optionality to do with this asset to do like whatever they want and
not have to wait a month in the withdrawal queue and so you basically created this situation and there's no way to get out of it right so you have to deal with the consequences so any chain that has proof of stake a and has kind of aspires for the native token to be money um has the situation right and this will play out in every single blockchain ecosystem that has these properties and so it is a very hard fundamental question and and challenge
um that that we need to address and there are no easy answers I think presenting it as a as a market challenge is the right way to frame this um too often I feel like uh in crypto clearly sometimes there are bad guys and there are good guys in crypto um but sometimes crypto becomes overly tribal and we attack people and uh individuals and entities at times we should be tacking what we call moloch problems game theoretic type problems what you're illustrating here hasu is a
sort of a game theory type problem of um well who who wants this the market wants it why because the market wants to stake their eth if they are eath holders in order to receive the yield and they want that eth to be as as fungible and as usable as possible so we have these liquid staking tokens um that are you know staked in each that we want to use across other things and so the problem with that is it creates centralization it creates some sort of network effect for let's say the pool or
the apparatus or the entity the that can service that market need most effectively and I this almost resembles when you we're starting to illustrate the problem or the criticism of of Lido it kind of sounds like a too big to fail type of argument it it sounds a little bit like um the problem that ethereum faced in the early days of a lot of ether being concentrated yeah I'm so glad that you said this I just I was ready to make the same in my head I wanted to bring up the same thing because you had you had
already had this once in the sense that there was the Dao and I think it had between 15 and 20 percent of all Eve deposited right and what's this insanely popular project and then it had a security incident and yes it got resolved and there was a rift of course and I think that that left a lot of scar tissue in the ethereum you know community and the soul of ethereum not to go through a situation like that again um but what then happened afterwards was actually vitalik said you know please
guys if you make another Dao or another Ico please cap it at 10 million dollars you know don't raise any more money because we don't want to create any systemic risk 10 10 million dollars or 10 million each I think I think it was I don't know I think it was 10 million I can't remember it was something close to one in the same back end so I'm relatively some relatively small amount like maybe it was one percent of Eve maybe it was 10 million dollars I'm not sure anymore but the point was then the when the Ico boom happened this the
first projects were basically following this guidance and they sold out some within you know one or two blocks and like within minutes basically and so you know yes the kind of they they ended up respecting this wish and prevent um kind of the systemic risk to ethereum initially in the sale but it had all kinds of negative effects so first of all um it was extremely unfair who could contribute you know because only the most sophisticated whales were able to
participate because they had to stay you know contribute in the first block and they had to be in a very particular time zone They had to be at their computer at the right times or you know and so on and then once the share started trading in secondary Market of course they went to their where the market would have cleared anyway because the supply was not matching the demand at all and so I think it showed that um it's very hard to kind of make these rules and that the market will always find a way yeah I think that's a a great point hasu
and I want to um you know tap into kind of two points you made so one is it seems like you can't enforce this on the social layer right vitalik or the community saying hey out of the goodness of your hearts right we we'd request that you wouldn't pull more than one percent of eth in one smart contract location right well um that's not enforceable at the protocol nobody doesn't listen to that Bullock does not listen to that wrecks all of the plans and of course uh you know the market forces uh take hold so so that's one of
the points you're making the other point I think that um is important to make here is that this pattern of too much eth being pulled in one place plays out and has played out in in other cases so let's say a centralized exchange or a group of centralized exchanges start to pool a lot more eth let's say maybe just for trading purposes so ignore staking for a second let's say a coinbase and Kraken and binance held sixty percent of the eth right and we found out that one of
those actors was like a an SBF type character right well then the ethereum community has this dilemma of like wow a large portion of the eth supply is now uh controlled by a single entity and how do we get that back um I mean there have been other cases of this too I remember in the early days of maker Dao when maker Dao was just like a wrecking ball and everyone was like depositing eth inside of maker Dow smart contracts there was this question what happens if make your Dow gets hacked there's a lot of commentary on Twitter saying well now
maker Dow is so big it's the king maker right and so if maker doubt smart contracts get hacked well then um that would cause like a fork of ethereum kind of Dao style so this pattern and that now we're talking about this with eigenlayer as well so this pattern you know tends to play out and I just want to illustrate like what the what the problem actually is so let's say um Lida right now has 30 of all staked eth right and so what portion of total Supply is that is that like you know it's uh it's study time it's it's 30
times 20 because 20 is the number of all Leaf that's currently being staked on the beaten chain okay so it's thirty percent if you find something percent about about five or six percent eight million ether okay 7.9 okay so eight million ether right and so if something bad were to happen to that set of smart contracts like what's the outcome of that let's say an exploiter like a curse say there's there's a evm style issue we've seen that this week there's some kind of exploit or drainage of uh the
smart contract like worst case scenario here then some exploit or some black hat has all of this ether potentially I mean that's like worst case scenario what could happen and then the question is okay where does the community go from there is that one of the core problems of kind of accruing so much eth in one place uh yes absolutely so I I think this particular risk that you outlined could not really happen um because the eve cannot be with John from Lido because it is staked on the
beacon chain and um the the beaten chain has uh you know very long with joy delay so at least there's time uh to deliberate uh what to do so you could not have a kind of corrupt situation it would be more like the Tao situation I believe I think the the real Crux of the issue here isn't that there's a Honeypot of ether but it is what happens when a staking organization has a certain amount of uh ether Stakes specifically
there are a couple of thresholds in the mechanics of the way that proof of stake works that gives an operator who has control of enough ether over those thresholds gives them some influence over the protocol and I believe those numbers are 33 and 66 percent can you walk us through what can someone do some entity do if they have 33 or 66 of all ether staked um I don't have all the numbers in my head anymore it has to do with um it has to do with basically
preventing the chain from finalizing um there's something about you know the attestation committee I'd have to I'd have to look it up um but I mean the overall rule is is very clear like um all uh consensus protocols rely on um honest Behavior to a certain threshold and how do they encourage that by creating the right incentives for this honest Behavior to occur right in the case of ethereum um they you do it basically um by forcing the stake us to hold
um what is almost a form of you know Equity or stake um in the system itself so if the system itself gets attacked there's this implicit implicit assumption that you know Europe your if would also become worth a lot less um the the slashing is almost uh you know like an additional thing on top you know so proof of Stack would work also without slashing and there are some um staking protocols that don't have slashing um but of course if you can also add slashing then you don't just have the
carrot you also have the stick um so it is kind of this extra layer of security so that said um you're totally right so someone has someone who who has a stake above a certain threshold they can perform various kinds of attack in theory that doesn't mean they have the incentive to do that of course um and the second thing that I would point out is actually so in the case of Lido I think this doesn't like you have
to like really stretch kind of the argument for this to apply in the first place because Lido is a protocol for Distributing stake from stakers to note node operators but under the hood there's 29 different node operators right now and many more that are being onboarded right now and staking modules that are being developed so this number is is going to go up but already today in these 29 Auto readers are not near the same party nor do they hear like nor
do they listen to in many cases you know what that either protocol says you know what it could lie to even unstake them today so this is something that we can talk about um so this is not a feature that's yet enabled this ability for the Dow to say you know this NoDa breada didn't do what we want so we are going to exit them you know programmatically um today Lido can only say you know you bad node operator um I will not give you any more stake that is coming in um so we have seen in the past in many
instances so Mev boost is a great like the Mev policy in general was a great example then there are other examples around what to do about ofic you know when that happened um where we saw a lot of controversy between node operators that had very different views um they actively contributed to what the policy in given situations should be and uh and and so it's it's basically not possible for lighter to say
um we are making you know a policy for what node orbiters should do and for note about us to just you know accept that policy you know so they are very opinionated they are extremely aligned with the health of the network as is the Dao itself um because I mean when you look at the economic model of the Dao you know it makes revenue or it makes it makes money in perpetuity um if ethereum is healthy and ethereum thrives and if that's not the case then that's basically suicide for the dial so
I think some of these what is kind of really the risk that that that I am most focused on and we can talk about that I think we have some ideas uh here about the Dao how the dial can mitigate that but but there is that I see primarily is actually someone coming into governance from the outside some attacker who maybe Bice up you know a large amount of Ado or I could find some other way to three sneaker proposal through so like code injection like we have seen all kinds of attacks and DOW governance right um and they actually you know do some
something to the smart contract of State Eve and maybe for example they find that they they print state from thin air so there's more stake if now than Eve on the beaten chain and there are many safeguards so um for example there's a there's a heart limit on how much that it can be generated per day to really limit you know the risk that this can happen um but nonetheless I would say this is really uh the biggest Swiss that I see on a kind of short-term basis
and I think that is perhaps the Crux of this conversation and why we're having this conversation it's about the relationship between Lido governance and the state to Ether and its node operators I want to really just quickly tie off the conversation about the thresholds and in proof of stake because these two things are coupled of course if one staking entity passes certain thresholds of protocol control then all of a sudden the governance of that entity becomes very important and so that 33 and 66 percent that I was talking about these are the two
thresholds for proof of stake uh 33 like you said is um how you get finality uh so you need you need 66 of all ethers staked uh to um to be in consensus with each other in order to have finality and so if one entity controls 33 they influence and control finality right not too long ago we had this ethereum non-finality event which was a couple of client bugs which was an accidental non-finality event and if one staking uh operating or entity had 33 they would be
able to induce this if they so chose they would have and that just means stop the blocks from finalizing David right right the blocks still propagate but they are not um they are not beholden by the weight of ethereum proof of stake they can be reverted without ether being slashed that's what you can do if you have over 33 that if one entity has over 33 that is what they can do um and then if you have 66 percent you basically are ethereum you that is like a 51 attack for proof of work but in
proof of stake it's 66 so if one entity had 66 of all ether stake they get to basically choose the outcome you mean like the first blocks or that sort of thing it's like a bit more are we are we getting over recipes here yeah if I stop stop talking anymore in this direction trigger some of the ethereum devs this is the direction directionally correct they can probably do some kind of reorganization I would agree exactly what you cannot do still is make any kind of invalid State transition because yeah you cannot sign transactions on other people's behalf you can just do a
lot else though and so these are these are the risks right and so this is the protocol risk and so importantly to it's worth noting the philosophy that ethereum has about governance which is to not have it on chain at least uh and so uh this is there is no governance attack for ethereum on on chain specifically you would have to process through all the all-core devs calls but if one staking as a service entity perhaps Lido has more than 33 percent all of a sudden that off-chain governance philosophy actually becomes
routed around by an on-chain entity called Lido and like you said hazu there's this ldo token which is the governance token of Lido and so perhaps if Lido had over 33 and it currently has 31 percent the off-chain governance philosophy of ethereum becomes um ignored and routed around by an entity that has on-chain governance with this ldo token uh and so this is where the this becomes systemic towards ethereum at large where if one entity
had on-chain governance like Lido does had over 33 percent uh then all of a sudden Lido gets to govern uh some of the rules of the protocol I think this is part the The Contours of the conversation as it relates to yeah critiques what would you say to this I mean I I I think if we want to be precise then the concrete risk is that the light or Dao makes some kind of governance decision introduces some kind of policy that mandates that all of
these independent note operators who you know have their own in completely independent motivations and stories and you know utility functions that they all collude in some way that they behave in unison to destroy their own livelihood basically and the tech ethereum um and I I mean so I think um it's it's I I couldn't imagine how that would happen um just from like knowing them and like
how and like none of them individually would do something like that let alone all of them together I would also find it incredibly difficult operationally how you would coordinate something like that right so inside of Lido there are 29 node operators and what you're saying that even if Lido governance voted to like Nuke ethereum yeah you would still need to coordinate the 29 or maybe 27 28 of the almost the complete majority of all lito operators that you would need to coordinate them to even follow through on that yes because it is really
really important to understand that all of these note operators they run their own local infrastructure they run all of the hardware they run the validators they decide uh you know what block to build they decide um what block to a test they make all of these decisions Lido has some policies so I'd like to encourage people to think about the Lido lighter protocol as this like thin middleware layer that like get Stakes it it gets eat from from steak us
and then it has some key for how to distribute that across different node operators and then the node operators basically pay uh they they basically pay the reward back into the protocol and then five percent goes to the user and five percent goes sorry five percent goes to the node operator and five percent goes to the dial and ninety percent of it goes to the user um and um and so what's what's kind of really going on here is that this the Lido Dao is the organization that develops and improves the the protocol
and makes sure that that it's secure and that it's hardened and so on and what they all they can do is they can make policies for how they think the note operator should behave but the note operators are not compelled to listen right for one they can exit um they can just like not do it you know and Lido doesn't have um right now any strong uh way to punish that and neither today nor at any future point will they have the ability for a
node operator basically to take over their hardware and say you know this is the block that you should build this is you know whether you should attest to another block or not um the most and this is a I think it's an interesting case study to understand the most uh Hands-On that that Lido has been about this is uh the Mev policy and so what the Mev policy says is there was an open there was a period basically where laido said oh proof of stake is coming so we
are now upgrade so the the um the beacon Center had already been live right and then that was the merch right and so maybe six months before the merge Lido said okay so we know the merge is going to happen what does that mean so the the beacon chain validators are now going to be responsible not just for the beacon chain but also for the execution there what what does that mean that means there will be you know there will like all the actual ethereum transactions and there will be Mev and so we need to have some policy for
what to do with this Mev and uh you know should we extract Mev should we not extract nav if yes what is the mechanism because there are a lot of questions around this for example if you say or every uh every um value that I can do what they want then you get into the problem of Mev hiding where the the value that can just extract the another word I just extracts the Mev and says to Lido you know they extract you know the block has three Eve and they say oh yeah look at this one Eve block that I mined here you go live
here's the one youth block you know and then they pocket two ether that would be stealing from users right so Lido has the responsibility to make sure that uh there's no way for the note operators to kind of break this like 95.5 split off Rewards um and they also wanted to um basically look at what ethereum wants and so you know the ethereum foundation in flashbots at the community there was a general kind of acceptance so we want
you know nav is something that exists on ethereum you know there's no way to just make it go away and but what is really important is that we keep the barriers to entry into the valid data set as low as possible to encourage solo staking and so we want to make it very easy to join a permissionless and competitive market where you can Outsource the building of your blocks two right and so that was the idea behind proposal Builder separation and nav boost
and so Lido was actually the first of any exchanges of any second Protocols of everyone who publicly said we will support the idea of proposal Builder separation and we were on board Mev boost we're mandating the use of Mev boost for our node operators and he has like five Mev Boos relays that you have to include and here's five more that you can include if you want so the first list the must include list
that it guaranteed that it set a baseline for um basically the the minimum value of the block that the notepad I was seeing so Mev hiding is not a problem but then there was also the ability for them to include additional additional ones so for example if there was once there was the you know the the office for foreign asset control in the US had put tornado cash on their list of sanctioned transactions then some relays were saying uh I'm fine mining these