Go to main content
7 min read

Half a Stack: What the case for permissionless networks borrows from the internet, and what it leaves behind

Half a Stack: What the case for permissionless networks borrows from the internet, and what it leaves behind

By Miguel Angel Calero, executive director, ISBE.

This week a16z crypto published ๐—•๐—ฎ๐—ป๐—ธ๐˜€ ๐—ฑ๐—ผ๐—ป'๐˜ ๐—ป๐—ฒ๐—ฒ๐—ฑ ๐—ฐ๐—น๐—ผ๐˜€๐—ฒ๐—ฑ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ๐—ฐ๐—ต๐—ฎ๐—ถ๐—ป๐˜€. ๐—ฆ๐—ผ ๐˜„๐—ต๐˜† ๐—ฑ๐—ผ ๐˜๐—ต๐—ฒ๐˜† ๐—ธ๐—ฒ๐—ฒ๐—ฝ ๐—ฐ๐—ต๐—ผ๐—ผ๐˜€๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ๐—บ?, by Rebecca Rettig, adapted from a paper she wrote with Omid Malekan and Michael Mosier: ๐—ง๐—ต๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐˜๐—ถ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—ผ๐—ณ ๐—ฃ๐—ฒ๐—ฟ๐—บ๐—ถ๐˜€๐˜€๐—ถ๐—ผ๐—ป๐—น๐—ฒ๐˜€๐˜€ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—™๐—ถ๐—ป๐—ฎ๐—ป๐—ฐ๐—ถ๐—ฎ๐—น ๐—œ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ถ๐˜๐˜†: ๐—” ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—š๐˜‚๐—ถ๐—ฑ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—™๐—ถ๐—ป๐—ฎ๐—ป๐—ฐ๐—ถ๐—ฎ๐—น ๐—œ๐—ป๐˜€๐˜๐—ถ๐˜๐˜‚๐˜๐—ถ๐—ผ๐—ป๐˜€. It argues that regulated financial institutions can build on permissionless networks while meeting their financial integrity obligations. It is a serious piece of work, and Mosier's record at FinCEN and OFAC gives it standing. Whether its AML and sanctions analysis holds is not what I want to discuss.

I want to discuss one sentence, because everything else rests on it.

"๐˜—๐˜ฆ๐˜ณ๐˜ฎ๐˜ช๐˜ด๐˜ด๐˜ช๐˜ฐ๐˜ฏ๐˜ญ๐˜ฆ๐˜ด๐˜ด ๐˜ฃ๐˜ญ๐˜ฐ๐˜ค๐˜ฌ๐˜ค๐˜ฉ๐˜ข๐˜ช๐˜ฏ ๐˜ฏ๐˜ฆ๐˜ต๐˜ธ๐˜ฐ๐˜ณ๐˜ฌ๐˜ด ๐˜ข๐˜ณ๐˜ฆ ๐˜ฅ๐˜ช๐˜ด๐˜ต๐˜ณ๐˜ช๐˜ฃ๐˜ถ๐˜ต๐˜ฆ๐˜ฅ ๐˜ฅ๐˜ช๐˜จ๐˜ช๐˜ต๐˜ข๐˜ญ ๐˜ฅ๐˜ข๐˜ต๐˜ข๐˜ฃ๐˜ข๐˜ด๐˜ฆ๐˜ด ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ณ๐˜ฆ๐˜ค๐˜ฐ๐˜ณ๐˜ฅ ๐˜ต๐˜ณ๐˜ข๐˜ฏ๐˜ด๐˜ข๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด ๐˜ข๐˜ค๐˜ณ๐˜ฐ๐˜ด๐˜ด ๐˜ฎ๐˜ข๐˜ฏ๐˜บ ๐˜ค๐˜ฐ๐˜ฎ๐˜ฑ๐˜ถ๐˜ต๐˜ฆ๐˜ณ๐˜ด ๐˜ด๐˜ช๐˜ฎ๐˜ถ๐˜ญ๐˜ต๐˜ข๐˜ฏ๐˜ฆ๐˜ฐ๐˜ถ๐˜ด๐˜ญ๐˜บ ๐˜ข๐˜ค๐˜ค๐˜ฐ๐˜ณ๐˜ฅ๐˜ช๐˜ฏ๐˜จ ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ณ๐˜ถ๐˜ญ๐˜ฆ๐˜ด ๐˜ฐ๐˜ง ๐˜ข ๐˜ฑ๐˜ณ๐˜ฆ๐˜ด๐˜ฆ๐˜ต ๐˜ด๐˜ฐ๐˜ง๐˜ต๐˜ธ๐˜ข๐˜ณ๐˜ฆ ๐˜ฑ๐˜ณ๐˜ฐ๐˜ต๐˜ฐ๐˜ค๐˜ฐ๐˜ญ. ๐˜๐˜ฏ ๐˜ต๐˜ฉ๐˜ช๐˜ด ๐˜ณ๐˜ฆ๐˜ด๐˜ฑ๐˜ฆ๐˜ค๐˜ต, ๐˜ต๐˜ฉ๐˜ฆ๐˜บ ๐˜ณ๐˜ฆ๐˜ด๐˜ฆ๐˜ฎ๐˜ฃ๐˜ญ๐˜ฆ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ค๐˜ฐ๐˜ฎ๐˜ฎ๐˜ถ๐˜ฏ๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด ๐˜ฑ๐˜ณ๐˜ฐ๐˜ต๐˜ฐ๐˜ค๐˜ฐ๐˜ญ๐˜ด (๐˜ฆ.๐˜จ., ๐˜›๐˜Š๐˜—/๐˜๐˜—) ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ถ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ณ๐˜ฑ๐˜ช๐˜ฏ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ช๐˜ฏ๐˜ต๐˜ฆ๐˜ณ๐˜ฏ๐˜ฆ๐˜ต."

If that resemblance holds, the rest follows. Transport layers are not held responsible for what moves across them. The obligations sit with whoever operates above. The paper says so explicitly, and it is the same argument circulating far beyond finance: permissionless networks are the internet of value, and infrastructure regulation does not reach infrastructure this neutral.

The analogy is worth taking seriously. More seriously, in fact, than the paper takes it.

๐—ง๐—ต๐—ฒ ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฒ๐˜ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜ ๐—ง๐—–๐—ฃ/๐—œ๐—ฃ

TCP/IP is a transport layer. It carries packets and forgets them. A router does not read the payload, and that is precisely why holding it responsible makes no sense: it neither knows nor determines what it carries.

But nobody does anything consequential on TCP/IP. You do not sign a contract on a transport layer. You do not log into your bank on one.

What makes those things possible is a second layer the analogy skips. Above neutral transport sits a layer of identifiable, accountable authorities: DNS, and above all the public key infrastructure. When you open your bank's website, what protects you is not that IP is indifferent to your packets. It is that a Certification Authority vouched for that identity, is auditable, and can revoke it. In Europe, qualified CAs operate under eIDAS with defined liability. Somebody answers.

That layer is hierarchical, identified, revocable and regulated. It is the structural opposite of permissionlessness. And it is the layer that turned a neutral transport network into infrastructure people could rely on.

The internet solved trust not by being neutral, but by adding accountable authorities on top of neutrality.

๐—ช๐—ต๐—ฎ๐˜ ๐˜„๐—ฎ๐˜€ ๐—ฐ๐—ผ๐—ฝ๐—ถ๐—ฒ๐—ฑ, ๐—ฎ๐—ป๐—ฑ ๐˜„๐—ต๐—ฎ๐˜ ๐˜„๐—ฎ๐˜€ ๐—ฑ๐—ฟ๐—ผ๐—ฝ๐—ฝ๐—ฒ๐—ฑ

Permissionless networks took the first half of that architecture and left the second. Neutral base layer, no trust layer. No issuer of identity who answers for it. No revocation. Nobody to ask.

Which is why the claim "we are like the internet" reads to me as the opposite of what it intends. If the analogy holds, permissionless networks have implemented half a stack, and it is the half that does not make trust enforceable.

There is a second thing the sentence does. It defines the object as a database that records, then compares it to a protocol that transports. Transport forgets; a record keeps. A router that mishandles a packet causes a retransmission. A ledger that accepts a bad entry keeps it, and keeps it authoritative, until somebody with the standing to act corrects it. Where nobody holds that standing, the error is permanent by design. Which brings us to the question the paper never asks.

๐—ง๐—ต๐—ฒ ๐—พ๐˜‚๐—ฒ๐˜€๐˜๐—ถ๐—ผ๐—ป ๐—ป๐—ผ๐—ฏ๐—ผ๐—ฑ๐˜† ๐—ฎ๐˜€๐—ธ๐—ฒ๐—ฑ

The paper answers whether an institution can manage financial integrity on a permissionless network. That is one regulatory domain, and it is the one the authors know best. There is another that never appears, and it is the one that decides whether infrastructure can be depended on at all: who is accountable for the security of the infrastructure itself.

The paper analyses transaction integrity: screening, provenance, monitoring. It does not ask who answers for the base layer those transactions settle on. When a failure occurs there rather than in the transaction, a bank's screening program is irrelevant, because the problem is not on its layer. Resilience is not the same as accountability. A network can stay up indefinitely and still have nobody obliged to answer for its integrity.

The clearest case is the supply chain. The paper's own framework requires third-party risk management โ€” due diligence, contractual protections, monitoring, exit planning โ€” and applies it to node providers, staking providers, custody technology vendors and analytics firms. Every supplier around the network, that is, except the one that settles the transaction. The validator set is the supplier of settlement, and it is pseudonymous, open to join, and different for every block. The framework does ask for network-level diligence, but what it can measure is shape: client diversity, stake distribution, finality characteristics. Those are statistical properties of a population, not knowledge of a counterparty. You cannot run due diligence on a supplier you cannot identify, you cannot contract with one, and you cannot write an exit plan for one you never onboarded.

The same gap shows up in incident response. A regulated institution has to report a significant incident within hours, to a named authority, and is expected to know whom to call at each of its critical suppliers. On a permissionless base layer nobody is under a duty to notify anyone. When something goes wrong at that layer, an institution finds out the way everyone else does: from the public post-mortem of whoever chooses to write one.

Concentration is the same problem in different clothes. The paper points to the October 2025 AWS outage, during which major base layers kept producing blocks while centralised services went down, and the point is fair โ€” that day the distributed system was the resilient one. But knowing whether that still holds tomorrow requires knowing how many validators sit in the same region, on the same cloud, behind the same hosting provider. That is precisely what pseudonymity withholds. The concentration risk is not absent. It is unmeasurable.

Europe has written parts of this down โ€” NIS2 makes supply chain security a direct obligation, and DORA requires a register of critical ICT third-party providers with an exit strategy for each โ€” but the principle is not regional. An institution that calls something critical infrastructure is expected to be able to name who runs it.

๐—ง๐—ต๐—ฒ ๐—ฐ๐—ผ๐—ป๐—ฐ๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป ๐—ฎ๐—น๐—ฟ๐—ฒ๐—ฎ๐—ฑ๐˜† ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐˜๐—ฒ๐˜…๐˜

What that omission asks for is the one thing credible neutrality is designed to exclude: an actor able to intervene and obliged to answer.

The paper's own framework reintroduces exactly that actor where the stakes are highest. Its closing section notes that the GENIUS Act requires stablecoin issuers to hold the technical capability to freeze, to burn, and to execute lawful orders. For money, pure neutrality was not deemed sufficient. Somebody has to be able to act.

The question is only where that somebody sits. Placing them inside each application works for a private issuer. It does not work for the layer beneath every application โ€” the one carrying identity, public records and sovereign money. You cannot have a kill switch in each app and none in the layer that holds them all up.

Take the internet analogy seriously and it does not describe a network without authorities. It describes one that learned to add them. That is the half of the stack we are building at ISBE.

Would you like to receive our newsletter?

Leave us your details and you will be the first to know the latest news about ISBE.
Contact information

Basic Data Protection Information: Alastria will process the data to deal with your queries or requests and to send you communications that may be of interest to you, if you have consented to this. No automated decisions or profiling will be carried out on the basis of the data collected. You can exercise your data protection rights by emailing hello@redisbe.com and access information about the processing of your data in the Privacy Policy.

By clicking the "Send" button I declare that I have read and understand the Privacy Policy and how my data will be processed for the management of my query or request.

Follow us

  • next-generation
  • ministerio
  • plan-de-recuperacion
  • cam
  • alastria
Project 'INFRAESTRUCTURA DE SERVICIOS BLOCKCHAIN โ€‹โ€‹DE ESPAร‘A (ISBE)', part of the framework of the Collaboration Agreement signed between the Community of Madrid and Consorcio Red Alastria, within the Program of Territorial Networks of Technological Specialization in the Framework of the Recovery, Transformation and Resilience Plan - financed by the European Union - Next Generation EU.