Ethereum direct economic security (stake under slashing) is very strong for a very long time. Strong enough that any potentially successful attack on Ethereum will have to be indirect. It’s going to be through identity hijacking (e.g. stealing validator keys), custodial intermediaries compromise, government coercion, supply chain attacks etc. Threat model is not a malicious open market ETH buyer. A strong proposal to tweak Ethereum security has to quantify that in some way; otherwise, the change will about as arbitrary as original curve or mechanism design. The proposal doesn’t make an attempt to do that.
One reason I’m raising this question is that I can tell from the get go that practical security of Ethereum consensus against indirect attacks is strained at this moment. Ethereum first line of defense historically is diversity and decentralization of node operators. Many professional node operators (who run most of Ethereum stake) are barely breaking even. Cyber security weather is the worst ever, we’re in the slow crash era of LLM-driven cyberattacks. And ETH price dollars, which you need to spend to pay for expertise, is not feeling so good.
Making economic conditions worse will forcefully transform the security model from decentralization-driven to concentrated professionalism-driven, switching the market model to a much smaller consolidated set of operators. It is certainly a choice one can make. But I think that without understanding of first and second order effects on practical Ethereum consensus security and brand value it’s a bit of a yolo one. Tight timing on decision making and closed doors proposal development doesn’t help either.
For the most technical aspects of proposal:
- don’t get why it’s designed as “mint and burn” instead of “mint less”, especially that rationale for the change is partially driven by the tax law issues. Why not go for less tax ambiguous option?
- I like that it’s got a slow adjustment period. Gives an opportunity to roll back if it turns out that validator set we’re getting is not secure enough.