The Lawless Blockchain Is a Story We Tell for Small Change

2026-06-15 · 4,372 words · Singular Grit Substack · View on Substack

A forthcoming paper extends Eric Budish’s famous limit on cryptocurrency security — and shows that the moment the stakes turn serious, the rule of law walks back into a room it was never really absent

A forthcoming paper extends (and corrects) Eric Budish’s famous limit on cryptocurrency security — and shows that the moment the stakes turn serious, the rule of law walks back into a room it was never really absent from.

Based on “Legal Deterrence in ‘Permissionless’ Consensus,” by Craig Wright, forthcoming in the International Journal of Cryptocurrency Research, Vol. 6, Issue 1 (June 2026).

There is a story the cryptocurrency industry likes to tell about itself, and like most flattering stories it has survived chiefly because nobody with serious money has yet had a reason to test it. The story is that a blockchain is a law unto itself: a self-contained machine that secures value through mathematics and electricity alone, serenely indifferent to courts, prosecutors, exchanges, and the grubby apparatus of human enforcement. It is a romantic picture. It is also, for any transaction large enough to be worth stealing, false.

My new paper — Legal Deterrence in ‘Permissionless’ Consensus, forthcoming in the International Journal of Cryptocurrency Research (Volume 6, Issue 1, June 2026) — sets out to say precisely where that story stops being true, and why. It does so not by waving the usual flags, but by taking the most rigorous statement of the lawless view, granting it everything it asks for, and then showing how narrow its territory actually is. The subject is blockchain security, and the argument is that we have been modelling it with one hand tied behind our backs.

The benchmark worth taking seriously

The rigorous statement belongs to Eric Budish. In Trust at Scale, published in the Quarterly Journal of Economics, Budish derived a deterrence condition for proof-of-work consensus and proved something genuinely uncomfortable: in a purely permissionless system, trust at scale is expensive. If you want a Nakamoto-style ledger to deter an attacker from rewriting history — from spending the same coin twice, which is the only attack that actually matters here — then the honest network must keep spending. Not once, but continuously. The flow of resources burned to secure the chain has to be large enough that no attacker can profitably assemble enough hash power to overwhelm it.

Budish’s condition is simple to state in plain words. The cost of mounting an attack — the share of network power the attacker must control, multiplied by the ongoing cost of sustaining the network’s level of trust support, multiplied by the length of time the attack must be held — has to exceed the value the attacker stands to capture from a double-spend. If that inequality holds, the attack is deterred. If it does not, the attack pays.

I want to be unambiguous about this, because the temptation in my corner of the world is to treat Budish as an adversary. He is not. His theorem is correct. Within the domain he specifies, it is precise, and it is important. My paper does not lay a finger on it. What the paper does is read the fine print — and the fine print is a single phrase that does an enormous amount of work.

Budish derives his result under what he calls a no-rule-of-law scope condition. In plain terms: he assumes the attacker operates in a world without legal consequence. No prosecution. No civil liability. No seizure. No exchange freezing the proceeds. No counterparty refusing to deal. The attacker is a ghost, reachable by nothing but the protocol itself.

That assumption is not an error. It is a modelling choice, and a useful one, because it isolates the cost of securing a ledger in pure form. But an assumption that is useful is not the same as an assumption that is true, and the entire argument of my paper turns on that difference.

One narrow move, made carefully

The paper makes a deliberately narrow move. It extends Budish’s framework along two dimensions and no more.

The first extension is organizational. Budish’s attacker is a monolith — a single anonymous entity that can acquire whatever hash power it likes and hold it for as long as it pleases. That is not how mining works, and it has not been how mining works for well over a decade. The second extension is institutional, and it is the heart of the paper: it admits the rule of law into the attacker’s payoff.

Here is the part that matters for anyone inclined to accuse me of special pleading. Set both extensions back to zero — strip out the law, strip out the pool structure — and the model collapses exactly onto Budish’s original condition. Not approximately. Exactly. The paper contains a formal proposition to this effect, with a two-step proof. Budish’s theorem is recovered as the no-law, no-pool special case of a more general model. I do not refute him. I contain him. The disagreement is not about whether his result is right; it is about how much of the world it describes.

Mining is not a crowd of hermits

Start with the organizational extension, because the institutional one cannot stand without it.

The folk image of blockchain security is a vast field of solitary miners, each grinding away independently, anonymous and interchangeable. That image is dead. The mining literature buried it years ago. Bitcoin production is organised through mining pools — coordinated operations run by managers who assemble the block, choose which transactions go into it, decide which chain to extend, and distribute the rewards to contributors according to a payout rule. Cong, He and Li showed that pools became the dominant organizational form early in Bitcoin’s history. Chatzigiannis and colleagues showed that contributors shift their hash power between pools in response to expected returns and risk, much as an investor rebalances a portfolio. Arnosti and Weinberg went further still and proved that mining is a natural oligopoly: economies of scale drive the market toward concentration even when nobody is colluding.

This matters for one reason above all others. A contributor who points his machine at a pool is not the entity deciding to attack. The pool operator is. The operator builds the block; the operator chooses the chain; the operator coordinates the double-spend. The contributor merely supplies horsepower — necessary for the attack, but not sufficient, and certainly not the decision-maker. So when a deliberate double-spend runs through a pool, the first-order actor to whom attribution runs is the coordinating operator, not the thousands of machine owners feeding it.

The analogy the paper leans on here is, I confess, an indecent one, which is precisely why it works. Henry Thompson’s study of the industrial organization of the mafia — published, with no apparent sense of irony, in the Journal of Law and Economics — describes how criminal enterprises adopt a hierarchy: a boss who monopolises the right to authorise extreme action, an internal mechanism for settling disputes quietly, and a structure of incentives that keeps everyone aligned. The hierarchy exists precisely to limit the disputes that would raise the organization’s public profile. Replace “boss” with “pool operator” and “soldier” with “contributing miner” and you have described pooled mining with uncomfortable accuracy. The boss decides. The soldiers can walk. And the moment the boss’s conduct threatens the soldiers’ livelihood or liberty, they do.

The legal term, in plain English

Now the institutional extension. The paper introduces a single new quantity into Budish’s payoff: the expected cost of legal enforcement, net of the cost of invoking it.

In words, that legal cost is the probability that the attack is detected, multiplied by the probability that it is correctly attributed to a responsible party, multiplied by the probability that a sanction actually lands — a freeze, an injunction, a settlement, a prosecution, a recovery — multiplied by the size of that sanction. From this gross figure you subtract the cost the enforcing party must bear to invoke the law at all. And then — this is the crucial design choice — you take whichever is larger: that net figure, or zero.

That last operation is not a mathematical nicety. It is the engine of the entire argument. It encodes a participation constraint on the enforcer. A law that exists on the books is worth nothing if no rational party will pay to use it. If the cost of pursuing the attacker exceeds the expected recovery, no victim sues, no prosecutor charges, no exchange lifts a finger — and the attacker faces no legal risk whatsoever. The legal term is zero, and we are back in Budish’s world.

So the paper draws a sharp line between two things the lawless story quietly conflates: the existence of law, and the economic value of using it.

Why a five-dollar theft and a five-million-dollar theft are different worlds

Consider a double-spend worth five dollars. Who calls a lawyer? Who opens an investigation? Who convenes a prosecutor? Nobody, because the cost of doing any of it dwarfs the loss. At that value the enforcer participation constraint binds, the legal term is exactly zero, and the system relies on protocol-side deterrence alone. Budish is not merely approximately right here. He is exactly right. The paper concedes this without reservation and proves it as a proposition: for sufficiently small transaction values, the pure protocol-cost benchmark applies, full stop.

Now consider a double-spend worth five million dollars, executed against an identified pool operator with seized assets and balances sitting on exchanges. The calculus inverts. The expected sanction is enormous; the cost of enforcement, while real, is dwarfed by the prize being clawed back. Victims sue. Prosecutors charge. Exchanges freeze. The legal term is large and positive.

The paper proves that the legal cost rises with the size of the prize over the economically relevant range. The intuition is almost embarrassingly direct. Disgorgement alone returns at least the stolen amount, so the sanction grows at least dollar-for-dollar with the theft. Fines, forfeiture, and the threat of imprisonment pile on top. Meanwhile, the bulk of enforcement cost is fixed overhead — filing, investigation setup, institutional capacity — so it grows far more slowly than the sanction does. Bigger thefts are therefore more legally dangerous, not less.

This does not require the law to switch on at some magic number. The paper is careful to insist there is no hard threshold, only a region where the no-law approximation steadily weakens as the stake, and the visibility of the actor, rise. The honest answer is a gradient, and the paper gives a gradient.

The coalition is not a fortress

Here the two extensions fuse, and the result is the most economically interesting claim in the paper: pooled attacking capacity is not a fixed asset you buy once. It is a coalition you must hold together under deteriorating conditions — and there are two distinct ways it falls apart.

The first channel operates before anyone knows an attack is under way. When a pool secretly diverts effort to a hidden chain, its ordinary performance degrades. Payouts slip. Variance rises. Stale shares climb. Contributors need not understand the cause; they need only notice that this pool now pays worse than the one next door. And so they leave, for the most boring economic reason imaginable — better money elsewhere. This is the mining analogue of a result by Bloch and Kranton on corporate cover-ups: concealment can be sustained while outsiders’ beliefs remain favourable, but the very act of concealment generates the observable distortions that eventually erode those beliefs. A covert attack, in other words, leaks.

The second channel opens once the misconduct is suspected or named. Now continued association is no longer a neutral commercial decision. A contributor who keeps feeding hash power to a pool credibly accused of an attack risks legal scrutiny, contract termination, exclusion from the exchanges he needs in order to sell his coins, and — most painfully — the impairment of his hardware. So he exits to protect himself.

The arithmetic of this is brutal for the attacker. Effective attacking hash power is not the nominal capacity the pool advertises; it is what remains after contributors flee through both channels. A pool that nominally controls a third of the network can watch that share evaporate during the attack itself — not over weeks, but over hours.

Four more ways the prize bleeds out

Beyond the law and beyond contributor flight, the paper identifies four further losses that the lawless benchmark simply omits, each of them growing more severe as the prize grows.

Reputational sanctions. Here the paper refuses to hand-wave, and the refusal is instructive. It would be lazy to assert that reputation matters and move on. The evidence is more particular than that. Karpoff and Lott studied 132 firms caught committing criminal fraud and found that the reputational penalty — the collapse in market value over and above the legal fines — accounted for more than ninety percent of the total punishment. But Karpoff and colleagues later studied 478 firms caught committing environmental violations and found the reputational penalty there to be negligible: the market docked them roughly the value of the fines, and no more. Why the difference? Because fraud has identifiable victims who can withdraw their future business, whereas environmental harm is diffuse, with no single counterparty bearing a concentrated loss. A double-spend is structurally fraud against specific transaction recipients who accepted payments later invalidated. It therefore sits squarely in the category where reputational sanctions bite hardest. This is the disciplined way to invoke reputation, and it is the way the paper invokes it.

ASIC-capital loss. Mining hardware is not a general-purpose asset you can repurpose into a server farm. It is exquisitely specialised silicon with essentially no productive use outside Bitcoin and its close relatives. That specificity is ordinarily a mere inconvenience; in an attack it becomes a noose. A pool that is excluded, sanctioned, or rendered commercially toxic does not lose a few days of revenue — it risks the value of its entire capital base, stranded with nowhere to go. The paper converts part of Budish’s flow-cost problem into a stock-loss problem, which is a far heavier deterrent.

Honest-longest-chain exclusion. This one is elegant because it asks nothing of the honest network at all. Honest miners do not need to organise, coordinate, or change a single rule. They simply keep mining on the longest valid chain, exactly as the protocol instructs them to. If the attacker’s effective hash power falls below the honest remainder — through contributor flight, through degraded connectivity, or both — the attacker’s hidden chain is orphaned automatically. The protocol does the work. The attacker’s chain dies of natural causes.

Network-friction loss. A pool depends on infrastructure it does not own: domain naming, internet routing, interconnection, propagation. Root-zone and identifier coordination remain externally governed, and the security literature — Apostolaki and colleagues on routing attacks against Bitcoin, and the routing-integrity guidance from the National Institute of Standards and Technology — shows that interference at this layer can isolate mining capacity, slow propagation, and raise the rate at which a pool’s blocks are stranded. The paper is careful here: it makes no claim that any single state can simply switch off another country’s miners. The narrower, more defensible point is that a publicly identified, dishonest pool is operationally entangled with infrastructure it cannot unilaterally control, and that entanglement is one more margin on which an attack can be made to bleed.

Stacked together, these terms produce the paper’s central object: a net-gain function for the attacker that subtracts, from the realised value of the theft, the protocol-resource cost and all five of these losses. The attack pays only if that net figure comes out positive. The lawless benchmark keeps only the first cost and throws the rest away — which is exactly why it overstates how profitable a large attack can be.

The numbers are not gentle

A theory of this kind invites the obvious objection: fine in principle, but do these terms amount to anything in practice? The paper answers with three calibration exercises, and it is scrupulous about their status — they are illustrative, drawn from public filings and disclosed data, not econometric estimates. They are meant to establish orders of magnitude, and on that modest ambition they succeed comprehensively.

First, who actually runs the pools. Using thirty days of block data ending in March 2026 — 4,149 blocks, identified by the coinbase tags that pools stamp into the blocks they mine — the coordination layer of Bitcoin turns out to be startlingly legible. United-States-linked pools account for just over 42 percent of pool share, with Foundry USA alone at 31.48 percent. China-linked pools account for roughly 41.5 percent. F2Pool, registered in Singapore, accounts for 11.33 percent. More than 98 percent of hash power is attributable to pools with a verifiable, public operator identity. Less than two percent is attributable to pools you cannot name. This is not a swarm of anonymous ghosts. It is a small set of identifiable companies in a handful of jurisdictions — several of them, like MARA, listed on public stock exchanges and filing accounts with regulators.

Second, where the enforcement threshold actually sits. By bounding the probability of detection and attribution from the pool data, the magnitude of sanction from real enforcement settlements, and the cost of enforcement from litigation-cost surveys, the paper estimates the transaction value at which the legal term first turns positive. Across a range of parameter assumptions it lands between roughly one million and four-and-a-quarter million dollars. Even under the assumptions most generous to the attacker, the threshold sits below five million. Below it, Budish’s world. Above it, the law is in the room. And these are upper bounds, because they exclude criminal penalties, imprisonment, and reputational loss — any one of which would push the threshold lower.

Third, how much capital an attacker is actually risking. Take a single listed miner, MARA Holdings, which disclosed in its 2024 annual report roughly 400,000 mining rigs, energised hash power of 53.2 exahashes per second, and a treasury of 44,893 bitcoin. Set its total capital exposure against various attack targets and the ratios are absurd in the attacker’s disfavour. For a ten-million-dollar prize, capital exposure exceeds the prize by something on the order of 540 to 620 times. For a hundred-million-dollar prize, by 54 to 62 times. And that is one firm. A pool the size of Foundry aggregates the capital of many such operators. The plain statement is this: a pool operator contemplating a double-spend faces capital destruction measured in billions against a prize measured in millions.

Then the dynamics. The paper simulates a hidden attack by a pool starting with 31.5 percent of an 800-exahash network — roughly the Bitcoin network’s scale in March 2026 — diverting a rising fraction of its effort to a hidden chain. Across a thousand Monte Carlo runs, and tested under three different assumptions about how contributors decide to leave, the pool’s effective capacity after twenty-four hours falls to somewhere between 10.6 percent and 26.8 percent of where it began. Under the central specification it retains 26.8 percent. Every single specification leaves it far below the 50 percent it would need to sustain a majority attack. The capacity does not erode over days. It erodes over hours. Budish’s assumption of a static attacking capacity, the simulation suggests, badly understates how fragile a pooled attack really is.

What the mafia, the EPA, and DUI checkpoints have to do with Bitcoin

One of the quiet pleasures of writing this paper was the company it forced me to keep. To turn a protocol-only deterrence condition into one that includes the rule of law, you need tools — and the right tools already existed, not in the cryptocurrency literature, which is curiously incurious about enforcement, but in the law-and-economics literature, where deterrence has been studied seriously since Gary Becker formalised it in 1968.

So the paper borrows. From Thompson’s anatomy of the mafia it takes the structure of a hierarchical coordinator surrounded by members who can defect. From Bloch and Kranton’s work on cover-ups it takes the dynamics of concealment and the result that penalties must escalate to offset the temptation to hide. From Gulen and Myers it takes hard evidence that enforcement is selective and politically contingent — their finding that Clean Water Act violation rates run nearly 40 percent lower in electorally important battleground states is a gift to anyone modelling an enforcer who must decide whether to act. From Matsuzawa it takes deterrence through salience: his finding that banning DUI checkpoints raised alcohol-related traffic deaths by over twelve percent shows that visible, targeted enforcement deters a far wider population than the few it directly touches — which is exactly why sanctioning one identified pool operator changes the risk calculus for every other pool watching. And from Belnap and colleagues it takes the economics of transparency regimes, drawn from automatic information-sharing between tax authorities, where the great majority of institutions commit to sharing but the quality of what they actually share varies — a useful caution that detection is never perfect, even where the obligation plainly exists.

Not one of these papers is about Bitcoin. That is the point. The vocabulary of modern enforcement economics was sitting on the shelf, fully developed, waiting to be pointed at proof-of-work double-spending. Nobody had done it. That gap is what the paper fills.

Two regimes, one system

I have saved the most counterintuitive consequence for last, because it is the one that matters most to anyone who actually wants to build a payment system rather than merely admire one.

If the legal term only turns positive above a threshold of a few million dollars, then a system that processes an enormous volume of small payments — each one individually trivial, each one below the value at which any enforcer would bother — never leaves Budish’s protocol-only regime at all. Every one of those payments is secured by protocol cost alone, and because each payment is small, that cost is small. The per-transaction security cost falls as volume rises. Aggregate turnover can be vast while every individual transaction stays safely inside the lawless regime where Budish reigns.

So the system does not have one security model. It has two, running at once. Protocol-only deterrence for the ocean of small payments. Protocol-plus-law deterrence for the comparatively rare large transfers that pass through identifiable institutions and become worth attacking. Budish’s theorem describes the first regime with complete accuracy. My paper describes the second. Neither displaces the other, and the same chain runs both simultaneously.

This is not a rhetorical flourish. It is the resolution of an apparent paradox that has haunted the economics of these systems. Budish’s result has been read by some as a death sentence — proof that blockchains are uneconomic at scale. It is no such thing. It is a precise statement about the cost of securing a single high-value transfer in a world without law. The moment you populate the world with the law that actually exists, and the moment you recognise that most economic activity consists of small payments rather than nine-figure transfers, the supposed death sentence becomes a sensible division of labour.

What this does, and does not, claim

Let me be exact about scope, because precision is the whole point, and an argument that overclaims deserves to lose.

The paper does not claim that the law makes Bitcoin safe. It does not claim that every attack is detectable, or that every miner is easily attributable. It does not claim that enforcement is perfect, that courts reliably restore every victim, or that permissionless consensus intrinsically requires law for all its uses. A high-volume, small-payment system can and does operate happily inside Budish’s protocol-only regime with no legal recourse at all.

What the paper claims is narrower and, I think, much harder to dismiss. Once economically significant value moves through legally legible pooled organizations, the no-rule-of-law benchmark stops being the correct positive description of how profitable an attack is. The relevant deterrence condition becomes value-dependent and organizationally specific. It is jointly determined by protocol costs, by legal sanctions net of enforcement cost, by reputational loss, by the mobility of pool members, by the destruction of specialised capital, and by the protocol’s own quiet habit of orphaning a chain that has lost its majority.

Why it matters

The broadest contribution is methodological, and it is the one I would ask a reader to carry away. The interesting contrast in this field was never between a lawless blockchain and a law-governed outside world. That framing flatters the technology and corrupts the analysis. The real contrast is between different bundles — different combinations of protocol incentive, organizational structure, legal exposure, and infrastructural dependence. Once you frame the problem that way, the economics of double-spending stop fitting inside a single flow-cost inequality. They become a question about whether an attacker can preserve the legal, commercial, and operational environment he needs in order to convert a clever rewrite of the ledger into durable wealth he can actually keep.

For a five-dollar theft, he can. The enforcer shrugs, the legal term is zero, and the gain is his to keep. For a five-million-dollar theft against a named operator with a fleet of stranded ASICs, a treasury sitting on an exchange, and a contributor base already heading for the exits, he very probably cannot — and the protocol he tried to subvert orphans his chain while the lawyers are still filing their first motion.

Budish gave us the lower bound: the irreducible cost of trust where no law reaches. That bound is real, and it is his. The work that remains — the work this paper begins — is to map the far larger territory where law does reach, where mining is a concentrated and identifiable industry rather than a swarm, and where the rule of law was never actually absent. It was simply waiting, as it usually does, for the numbers to grow large enough to be worth its attention.

The lawless blockchain, in the end, is a story we tell for small change. It is a perfectly good story for small change. It is only when we mistake it for the whole economy that we begin to believe our own romance.


← Back to Substack Archive