Who Actually Controls a Blockchain? An Economist’s Map of the Power Structure

2026-05-21 · 4,959 words · Singular Grit Substack · View on Substack

On institutional separability, the dynamics of producer choice, and why the same protocol can produce two very different distributions of power.


Here is a question that sounds naive and turns out to be hard: who controls a blockchain?

The folk answer is “nobody — that’s the point.” The slightly more sophisticated answer is “the miners,” or, after the Merge, “the validators.” Both answers are wrong, or at least badly incomplete, and the way in which they are wrong is the subject of a paper I have just finished and the reason for this post.

Miners and validators — I will call them block-producers throughout, because the economics is the same whether the consensus mechanism is proof-of-work or proof-of-stake — do something very specific. They assemble blocks and append them to a chain according to a set of rules. They do not write those rules. They do not write the software that implements those rules. They do not decide whether a given chain’s token gets listed on Coinbase, and they do not decide whether a regulator in New York or Singapore declares their activity unlawful. Each of those decisions is made by someone else, somewhere else in the system, and each of them constrains what the producer can profitably do.

For about a decade, the economic literature on crypto-asset systems has modelled producers as agents choosing effort, fees, or strategies within a fixed institutional environment. The protocol is treated as exogenous — a given, like the weather. This is a perfectly reasonable modelling choice. Producers really don’t author the rules. But it contains a buried assumption that nobody had named, let alone tested, and once you name it, a lot of structure falls out. The assumption is what I call institutional separability: the claim that the actors who author the rules, the actors who implement them in software, the actors who run the software to produce blocks, the actors who enforce law against them, and the actors who provide the liquidity that makes the token worth producing are distinct groups of people and organisations.

Most of the time, in most chains, that is roughly true. But “roughly” is doing a lot of work, and where it fails, it fails in ways that matter enormously for how the system behaves under stress. This post is about how to make that claim precise, how to measure it, what dynamics it generates, and what one small piece of evidence looks like when you actually take it to data.

I want to be honest up front about what this work is and is not. It is a theoretical framework with one executed empirical illustration. It is not a finished empirical programme. I will flag the difference clearly when we get there, because the temptation in this corner of economics — where the data are messy, the samples are small, and the stakes feel large — is to dress up a suggestive correlation as a settled fact. I would rather show you the scaffolding honestly than sell you a finished building that isn’t there.

The five layers

Start with the decomposition, because everything else hangs off it. I divide the institutional authority over a crypto-asset system into five layers, each populated by a distinct set of actors.

Layer 1 — Rule authorship. Someone writes the consensus rules: the improvement proposals, the specification documents, the decisions about what counts as a valid block. On Ethereum these are the EIP authors and the core protocol researchers; on Bitcoin, the BIP authors. This is a small group, and its membership is a matter of public record — you can read the authorship of every activated proposal.

Layer 2 — Software implementation. The rules in Layer 1 are abstract. Someone has to turn them into running code: the client implementations. On Ethereum’s execution side that means Geth, Nethermind, Besu, Erigon, and more recently Reth, each maintained by a different team. On Bitcoin it is overwhelmingly Bitcoin Core, with a handful of alternatives. Client teams make independent decisions about release scheduling, feature priorities, and how faithfully and how quickly to implement what Layer 1 specifies.

Layer 3 — Operational validation. This is the producers’ layer: the miners and validators who actually run the clients and produce blocks. This is the layer the existing literature models. It is also, crucially, the only layer where the actor has to choose a regime — which chain to extend, which client to run, which fork to follow — under economic incentives that can be written down.

Layer 4 — Institutional enforcement. Courts, regulators, sanctions authorities. The OFAC SDN list, the SEC, ESMA, the FCA, national courts. These actors do not participate in the protocol at all, but they impose costs — fines, litigation, forced exits, operational disruption — on producers and on the firms producers depend on. Their decisions are events with dates, jurisdictions, and targets, which makes them tractable.

Layer 5 — Liquidity coordination. Exchanges and custodians. Binance, Coinbase, Kraken, OKX, and the rest. They decide what gets listed, what gets delisted, how deep the order book is, and therefore what a given chain’s token is actually worth to a producer who is paid in it. This is the layer that closes the economic loop: a chain with no liquidity is a chain no rational producer will secure, regardless of how elegant its rules are.

The point of the decomposition is not taxonomy for its own sake. It is that the producer’s payoff depends on the state of all five layers, but the producer controls only the third one. The block reward and fees depend on Layer 1’s rules. Whether a production-grade client even exists depends on Layer 2. The legal exposure depends on Layer 4. The expected token price — the single largest term in most producers’ payoff — depends on Layer 5. The producer optimises over a menu that four other groups of actors have set.

Separability is the assumption that those four other groups are genuinely other. And the moment you state it that way, you can see it is an empirical question, not a definition.

Making separability measurable

Here is where I think the framework earns its keep, because it refuses to leave separability as a rhetorical gesture.

For each pair of layers, take the set of controlling entities active in each — resolved to the legal or operational unit, not the natural-person handle, so that a developer paid by a staking firm is attributed to the firm. Then compute the overlap between the two sets. I use the Jaccard index: the size of the intersection divided by the size of the union. Zero means the two layers share no actors; one means they are identical. Stack these pairwise overlaps into a five-by-five matrix, and you have a single object that summarises how separable a given chain’s institutional structure actually is over a given window.

I computed this matrix for Ethereum and Bitcoin over 2022Q4 to 2025Q3. Let me give you the headline number and then the interesting exception.

The headline: for the Layer-3 row — the row that matters most, because Layer 3 is where the separability assumption lives — the mean overlap is 0.053 for Ethereum and 0.013 for Bitcoin. Most off-diagonal entries are exactly zero. The people who author Ethereum’s rules are, with two exceptions, not the people who validate; the people who run exchanges are, with one cluster of exceptions, not the people who write clients. Separability, as an actor-set claim, holds at the data-zero level for most layer pairs in this sample. The existing literature’s exogeneity assumption is, to a first approximation, empirically defensible. That is a reassuring result, and it is worth knowing it is reassuring rather than merely assuming it.

Now the exceptions, because the exceptions are where the institutional content lives.

There are two non-empty intersections. The first is Layer 1 ∩ Layer 2: a small number of people author consensus rules and maintain the clients that implement them. On Ethereum this is a couple of named individuals who appear both as proposal authors and as long-tenured client maintainers; on Bitcoin it is essentially one person of comparable dual standing. This overlap is small and, frankly, unsurprising — it reflects the well-known fact that the people who deeply understand a protocol are often the people who write both the spec and the code. It qualifies separability between the two “rule-side” layers, but it does not touch the producers’ layer.

The second exception is the one that matters: Layer 3 ∩ Layer 5. The intersection of operational validators and liquidity coordinators. On Ethereum this is a cluster of major centralised exchanges — Binance, Coinbase, Kraken, OKX — that operate as large staking entities and as the venues that determine the token’s liquidity. They are validators and market-makers at once, under common corporate control. On Bitcoin the analogous overlap is smaller (mining and exchange operations are run by more nearly distinct firms) but non-zero, via exchange-affiliated mining pools.

This is not a rounding error. It is the single structural channel through which the actors who set the token’s price can also influence consensus directly, by virtue of being producers themselves. Any honest model of producer behaviour under liquidity shocks has to reckon with the fact that some non-trivial share of producers are the liquidity providers. The overlap matrix doesn’t just confirm separability where it holds; it points a finger at exactly where it breaks and how badly.

I want to stress what this measurement is and is not. It is a sample-restricted computation over two chains and a particular window, using disclosed senior maintainers and share-threshold criteria for entity inclusion. It is not a definitive cross-chain census. I do not assert a numerical threshold below which an overlap “counts as” small — setting such a threshold without empirical calibration across many chains would itself be a defect, and I avoid it. What the computation does is move separability from a conditional postulate to a conditional empirical regularity in the sample used: informative, not definitive. The full cross-chain enumeration is the next step, not a completed one.

The producer’s problem

With the layers in place, the model is almost forced on you.

A producer at Layer 3, entering a period, holds some prior regime — the chain and client it was running last period — and chooses which regime to operate this period. The choice maximises the expected discounted sum of per-period payoffs, net of the cost of switching. The per-period payoff is a sum of the components the five layers determine: block reward and fees (Layer 1), expected price-change gains on the token held (Layer 5), a continuation value, minus operating cost, switching cost, legal exposure (Layer 4), orphan or finality risk, and governance-participation cost. Write that down as a Bellman equation and you have a forward-looking dynamic discrete-choice problem of an entirely standard kind.

I do not, however, assume producers solve the full dynamic programme with rational expectations and unbounded computation. Instead I derive the working model as the bounded-rationality, mean-field approximation of that programme. Add the usual extreme-value shocks to the choice-specific values and you get a logit best-response: producers choose better-performing regimes with higher probability, with a sensitivity parameter that measures how sharply they discriminate. Aggregate the logit choices across a population of producers and let them revise their choices at some rate, and the mean-field limit of the share dynamics is the replicator equation — the workhorse of evolutionary game theory, in which the share of producers on a regime grows in proportion to how much that regime’s payoff exceeds the population average.

I emphasise that the logit and replicator specifications are derived approximations, not postulates. This matters for honesty about the model’s failure modes: the approximation breaks when revision is fast relative to the share dynamics, when the producer population is small, or when the choice-sensitivity parameter is degenerate. Those are the conditions under which the model should not be trusted, and naming them is part of stating the model properly. A model whose assumptions you cannot violate is a model that is not saying anything.

Why the dynamics get interesting

If that were the whole story, the dynamics would be dull: producers flow toward the most profitable regime, the system settles, end of analysis. What makes it interesting is Layer 5 coordination feedback.

Liquidity is not exogenous to producer behaviour. As more producers operate a regime, the chain becomes more credible, exchanges deepen its markets, custodians support it, and the token’s liquidity improves — which raises the expected payoff to producing it, which attracts more producers. This is a positive feedback loop, and positive feedback in adoption is the classic ingredient that economists since the 1980s — Katz and Shapiro, Farrell and Saloner, and above all Brian Arthur — identified as the source of multiple equilibria and path dependence.

Run the continuous-time replicator with this feedback and analyse the Jacobian at its steady states, and you get the central dynamic result. In the two-regime case, when the coordination-feedback differential dominates the differential in fundamental payoffs, the system is bistable: both “corner” states — one regime captures essentially all producers, or the other does — are locally stable, and the interior state where producers split between them is unstable. The system is pulled toward one monopoly or the other, and which one it reaches depends on where it started. This is Arthur’s lock-in, derived rather than asserted, with the increasing-returns mechanism coming explicitly from liquidity coordination rather than from generic learning-by-doing.

There is a knife-edge between the regimes where the dynamics undergo a pitchfork bifurcation: as you tune the balance between fundamental payoffs and coordination feedback through a critical point, a single stable equilibrium splits into two stable ones separated by an unstable boundary. I derive the condition for this bifurcation to be the “nice” (supercritical) kind explicitly, in terms of the curvature of the coordination-feedback function, rather than waving at it — because the difference between the supercritical and subcritical cases is the difference between a chain’s dominance shifting continuously and shifting in a sudden, discontinuous jump, and that is exactly the kind of qualitative behaviour an empirical researcher would want to look for.

The economic content of all this is a sentence worth pausing on: two chains with nearly identical rules can end up with completely different distributions of producer share, and the difference can be due entirely to history rather than to any difference in fundamentals. The locked-in regime is not necessarily the better one. If you have ever wondered why an obviously superior technical design failed to displace an entrenched incumbent in this space, the lock-in result is the formal version of your intuition.

Four predictions, one executed test

A framework that only rationalises what we already see is not worth much. The model generates four directional predictions about producer behaviour, each falsifiable:-

H1: Profitability dominates declared preference. When the profitability of a regime shifts, producer share follows, and stated ideological or governance preferences do not independently drive adoption once profitability is controlled for.

-

H2: Production-grade client availability is a binding ceiling on producer share — and, in its directional form, client readiness precedes producer adoption rather than the reverse.

-

H3: Proof-of-stake systems adjust to shocks more slowly than proof-of-work systems, because the bonding and unbonding frictions raise the effective switching cost.

-

H4: Legal-exposure shocks shift adoption at regulated entities specifically, with producers exposed to the affected jurisdiction responding and others not.

Now the honesty clause, and I mean it as the most important paragraph in this post. I have executed exactly one of these — H2 — and I have executed it as a directional pilot test, not as a completed validation. H1, H3, and H4 are specified in the paper with their regression forms, identification strategies, instrument sets, and falsification conditions, but they are stated as work to be done, not work I have done. The numerical capacity-share bound in H2 likewise awaits a proper multi-chain panel. Presenting the framework as if all four predictions stood on equal footing would be a misrepresentation, and the paper is built to avoid exactly that.

So what does the one executed test show?

The Reth experiment

Ethereum’s execution layer is run by validators who each choose a client implementation. Over 2022–2025, five clients had non-trivial share: Geth (long dominant, though declining), Nethermind, Besu, Erigon, and Reth. Reth is the interesting one, because it is the only client whose maturity varied materially over the window — it went from an alpha-stage research project to a production-ready client over the course of about two years, reaching production-readiness in the third quarter of 2024.

H2’s directional prediction is that readiness leads adoption: a validator cannot run a client that is not yet production-grade, so realised share should be zero while the client is immature and should rise only after it becomes production-ready — and the lead should run from readiness to share, not the other way around. If adoption instead led readiness, that would be evidence for the opposite story, in which client developers respond to where producers already want to be.

I built a quarterly panel of Reth’s share alongside an ordinal maturity index coding its readiness stage, and ran a bivariate Granger-causality test in both directions. I want to be precise about a measurement point that the paper takes seriously: the maturity index is an ordinal readiness proxy, not the theoretical capacity-share variable, and I label it as such throughout. The executed test is therefore a test of the weaker directional prediction — that readiness precedes adoption — and not a numerical test of the capacity-share bound, which needs a panel I have not yet built. With a percentage share on one side and an ordinal index on the other, observing that a 7% realised share sits below a maturity index of 1.0 would be a meaningless “bound” test, and I say so in the paper rather than dressing it up.

The result: in the forward direction (readiness → share) the Granger F-statistic is 4.88 with a p-value of 0.049; in the reverse direction (share → readiness) it is 1.05 with a p-value of 0.33. The asymmetry is in the predicted direction — readiness leads share, share does not lead readiness.

And now the caveats, which are not optional. The sample is fifteen quarterly observations on a single chain. The forward p-value of 0.049 is barely under the conventional threshold and would not survive a stern multiple-testing correction. The maturity index is hand-coded. This is a pilot. To its credit, the directional asymmetry is robust: I re-ran the test under a coarse binary coding and a milestone-shifted coding, at two lag lengths, and in every one of those specifications the forward F exceeds the reverse F and the reverse direction never rejects. But the forward direction’s significance is not uniform across those specifications — under one coding it sits at p = 0.08, under another at p = 0.17. The honest summary is: the qualitative pattern (readiness leads, not the reverse) is robust; the exact significance level is fragile, exactly as you would expect with fifteen data points. I report all of this, including the specifications where significance weakens, because suppressing the inconvenient cells would be a form of fraud, and the robustness script and its full output are in the replication package for anyone who wants to check.

There is a nice complementary episode in the same data. In one quarter, Nethermind’s share jumped from 14% to 22% — an eight-point move in three months — contemporaneous with a publicly announced decision by Coinbase to diversify its execution clients toward Nethermind. The same demand shock could not have moved share to Reth in that quarter, because Reth was still at release-candidate stage, not production-ready. A large producer wanted to migrate; client availability determined where it could go. That is the H2 mechanism playing out as a single observable event — and it is also, incidentally, the Layer-3 ∩ Layer-5 overlap in action, since Coinbase is simultaneously a major validator and a major exchange. I treat this as an illustration of the structural prediction, not as identification of the underlying feedback coefficient, because a single event with obvious confounds cannot carry that weight.

What the framework buys you

Step back from the econometric weeds and ask what the whole apparatus is for. I think it earns three things.

First, it reframes the decentralisation debate as a measurement problem rather than a slogan. “Is this chain decentralised?” is a question that usually generates heat and no light, because people mean different things by it. The overlap matrix lets you ask a sharper version: across which layers, and by how much, do the controlling actors overlap? A chain can be beautifully decentralised at Layer 3 — thousands of independent validators — and simultaneously concentrated at Layer 5, where a handful of exchanges set the price and a subset of them are themselves the largest validators. The single scalar “decentralisation” hides exactly the structure that determines how the system behaves under pressure. The Layer-3 ∩ Layer-5 overlap I measured is, I would argue, a more honest decentralisation diagnostic than validator counts, because it captures the channel through which economic power actually concentrates.

Second, it tells you where regulation bites. Producers are at Layer 3. Regulators are at Layer 4 and act largely through Layer 5 — they cannot easily compel an anonymous validator, but they can sanction an exchange, and the exchange’s listing and custody decisions propagate back through the liquidity term in every producer’s payoff. If you want to understand how a regulatory action in one jurisdiction reshapes producer behaviour globally, the five-layer structure tells you the transmission path: enforcement → liquidity coordination → producer payoff → share dynamics → possibly lock-in. The model says the effect should be concentrated among producers exposed to the affected jurisdiction (that is H4), and it tells you to look for the effect in the liquidity channel rather than in any direct constraint on validators. That is a testable, structured story about regulatory transmission in a domain where most commentary is unstructured.

Third, it disciplines the theory. Once you insist that separability is measurable and that the dynamics are derived rather than assumed, you lose the freedom to tell just-so stories. The model has to commit to falsifiable predictions, and the predictions have to be the kind you could actually run. I find that constraint clarifying. A great deal of writing about crypto economics is unfalsifiable in practice — it explains every outcome after the fact. The point of building the model this way is to make it possible to be wrong.

What I am not claiming

Let me draw the boundary explicitly, because in this field the boundary is usually the first casualty.

I am not claiming to have shown that liquidity coordination causes lock-in in the data. I have shown that if coordination feedback is strong relative to fundamentals, the model produces lock-in, and I have measured that the Layer-3 ∩ Layer-5 channel through which such feedback would operate is non-trivial in one sample. The causal claim is a prediction, not a finding.

I am not claiming that client readiness causes adoption in general. I have a fifteen-point, single-chain, directional pilot that is consistent with readiness preceding adoption and inconsistent with the reverse, robust in pattern but fragile in significance. That is a foothold, not a conclusion.

I am not claiming the separability assumption is correct as a matter of principle. I have measured it for two chains over one window and found it largely holds, with two specific and interpretable exceptions. Other chains, other windows, may look different — and the framework is built precisely so that the cross-window evolution of the overlap matrix would detect a breakdown of separability rather than assume it away. If a chain’s Layer-2 and Layer-3 overlaps rise over time because validators start funding and steering client development, the matrix will show it.

And I am not claiming that the proof-of-work versus proof-of-stake distinction reduces to switching costs. H3 — that proof-of-stake adjusts more slowly because bonding raises the effective switching cost — is a clean prediction, but I have not run it, and the cleanest test (the Ethereum Merge as a within-chain natural experiment, holding the producer population and legal environment roughly fixed) is specified for future work.

The discipline of saying what you have not shown is, I think, the part of academic writing that gets eroded fastest when the subject is exciting and the audience is hungry for conclusions. I would rather be boring and right about the boundary than thrilling and wrong about it.

Where this goes

The obvious next step is the full cross-chain panel. Two chains and fifteen quarters is enough to demonstrate that the overlap matrix is computable and that the H2 directional relationship is detectable. It is not enough to characterise how separability varies across the ecosystem, how the overlap matrix evolves as chains mature, or whether the lock-in dynamics show up in the share histories of the dozens of forks that have lived and died since 2016. The hazard-model side of the framework — which treats a chain’s “death” as an exit from the regime set and predicts its hazard from share, coordination feedback, overlap, legal exposure, and client maturity — is specified and estimable on the panel of observed forks (Bitcoin Cash, Bitcoin SV, Ethereum Classic, and the long tail of minor forks), but it is, again, future work.

The H1, H3, and H4 tests each require their own data construction: a profitability measure cleaned of measurement error for H1, the Merge event-study for H3, and a jurisdiction-coded enforcement panel with a difference-in-differences design for H4. Each is a paper. The contribution of this paper is the framework, the dynamic theory, and the one bounded illustration — and I think that is the right size for a single contribution, even if it is less than the full programme the framework implies.

There is also a methodological generalisation that I find genuinely interesting and that I have only gestured at. Nothing about the five-layer decomposition is specific to blockchains. Any technical system in which rule-authoring, software-implementing, and operational-executing roles are performed by distinct actors admits a similar decomposition: internet protocols, financial-market infrastructures, standards-based industries. The separability assumption, the overlap matrix as a measurement of it, and the dynamic-discrete-choice model of the executing layer are all transportable. Whether they are useful outside crypto is an empirical question I have not touched. But the crypto setting is an unusually clean laboratory for the general structure, because the layers are unusually legible: improvement proposals are public, client repositories are public, enforcement actions are dated, and exchange listings are announced. You can actually build the actor sets. In most institutional settings you cannot.

A closing thought

The reason I find this problem worth the effort is that it sits exactly at the seam between two literatures that rarely talk to each other. On one side is the institutional economics of Coase, Williamson, North, and Ostrom — the study of how institutional arrangements get selected as solutions to the problem of economising on transaction, contracting, and enforcement costs. On the other is the modern theory of crypto-asset producer behaviour, which is technically sophisticated about incentives within a fixed protocol but takes the institutional environment as given. The first tradition has the right questions about where institutions come from; the second has the right tools for modelling behaviour within them. The five-layer framework is an attempt to weld the two: to take the institutional-economics question — who has authority over what, and is that authority separable? — and answer it with the discrete-choice and dynamical-systems tools that the producer literature has developed.

What I keep coming back to is that the question I started with — who controls a blockchain? — does not have a single answer, and the framework’s main payoff is to explain why it doesn’t. Control is distributed across five layers, the producer holds only one of them, and the system’s behaviour under stress depends on how separable the other four are from each other and from the producer’s. When separability holds, the existing models are roughly right and the chain behaves as the textbook says. When it fails — when the people setting the price are the people producing the blocks — the feedback loops that drive lock-in get a direct channel, and the chain can tip toward a concentrated outcome that no individual chose and that history, not fundamentals, selected.

That is a claim about dynamics, and dynamics are the thing this field tends to skip in favour of static snapshots. A chain’s validator count today tells you very little about where its power will sit in three years. The overlap matrix, the coordination feedback, and the lock-in condition together tell you what to watch. Whether they tell you correctly is, in the end, an empirical question — and I have answered a small, honest slice of it, with the rest laid out as work to be done rather than work pretended to be finished.

If you take one thing from this, let it be the reframing rather than the result: stop asking whether a system is decentralised, and start measuring, layer by layer, who overlaps with whom. The answer is usually more interesting, and more uncomfortable, than the slogan.


The full paper, including the formal propositions, the proofs, the overlap-matrix computation, and the replication package for the H2 pilot, is available as a working paper. The replication code and data are deposited in a public repository under an open licence. Comments and criticism — especially of the kind that finds the places where I have overclaimed — are very welcome.

https://zenodo.org/records/20320274


← Back to Substack Archive