EIP-8363: Tapered Issuance Burn

Thank you for the respectful framing.
I am probably agreeing with more of it than you might expect. The demand for staking is genuine and nobody on the author side disputes that. You’re right that deflationary pressure shouldn’t be Ethereum’s value driver, it was never this proposal’s case yet dilution remains a fundamental criterio for an asset’s valuation. The case we are trying to make here is about security and about who pays for it.

Nevertheless, “Respect the market” cuts the other way. Today’s staking yield is not a market price, it is an administered schedule. The protocol fixes the rate curve, and the quantity follows wherever that subsidy pushes it. Users accepting a fixed offered price tells you that demand exists at that price but it doesn’t tell you the market chose the ratio. The tapering is the more market-respecting design because it turns the yield into an actual market price, with the ratio settling where yield meets the premium the marginal staker demands, instead of being set by an emissions schedule. Nobody, at any ration, is prevented from staking. What changes is that the subsidy stops growing without bound.

I would genuinely love that design to exist. To a certain extent, for valididy, it kinda already does since every full node enforces correctness at any ratio. But one fundamental property can’t be engineered to be ratio-proof: the community’s last resort against a captured or coerced validator set is a credible fork that unstaked holders can adopt and value, and that reserve shrinks by definition as the ratio grows.
The tools you’re pointing at, correlation penalties, inclusion lists, distributed validation etc. I totally support them and they address the centralization problems you name. What they don’t do is replace the reserve of unstaked ETH. That’s the reason why staking needs a ceiling and not just cheaper security and also why the ceiling sits at half the supply in EIP-8363.

Hope it helps better understand the design!

Thank you for this and welcome to the forum,
I appreciate your opening move of setting the small-versus-large fight aside. You’ve stated the EIP’s core logic better than we usually manage and I will definitely reused this:
Issuance is a collective subsidy, paid by non-stakers through dilution, sustaining a rent for stake that no longer adds marginal security.

As you rightfully point out, the adoption raises the dollar cost of attack through price, and nothing in the proposal denies that channel. I am even leaning towards the fact that the proposal helps that channel by improving the store of value fundamentals of ETH.

Let’s talk about staking and adoption because to some extent the first comptes with the second. In your own framing ( let me know if I got this wrong), adoption is real usage: ETH working as collateral, as payment, as the float moving through the economy. An administered premium, plus dilution charged to whoever abstains, makes locking ETH in the validator set its de facto best use of ETH. As long as the staking market can’t find an equilibrium, and as long as dilution is on the rise, staking is a standing bid against every other use of the asset.

@gunboatsss puts it well later in the thread: plain ETH “shouldn’t just be one token before you deposit to Lido or lend to Aave… it should be currency for everything.” A network whose native asset is subsidised hardest for leaving circulation towards staking is not necessarily optimizing for adoption.

Your central observation is correct: neither the current curve nor the tapered version observes value. If ETH fell 90% tomorrow, the dollar security budget would fall with it and issuance wouldn’t react under either of the design. The ratio is the only variable the protocol can observe natively and to do so we actually need to add a new parameter via our EIP. The problem with the price of ETH is that it has to be imported through an oracle, and an oracle-fed monetary lever comes with several problems of manipulations, downtimes, what Fiat reference etc. Neverthless in terms of design, eventhough we had a satisfying way to get the price of ETH at the beaconchain level, a dollar-value target would the behave the worst exactly when it matters: after your 90% crash it would try to restore the budget by printing into the collapse, thereby diluting holders the hardest at the moment confidence is the weakest and… ultimately fail anyway since no issuance rate conjures ten times the stake. If I remember correctly, this is more of less the type of scenarios we have witnessed with the TERRA/LUNA crash not so long ago.

The LST discount deserves a serious answer, because it is the best version of the oracle idea. You’re right that it’s a real, continuously traded risk premium. Yet, three things stop it being a protocol input:

  • It prices particular wrappers, ie one venue’s contract, exit and liquidity risk, not trust in Ethereum, so enshrining it enshrines the LST venues.
  • It’s movable by anyone large in a thin market, which turns monetary policy into a coordination target, see Elowsson’s analysis of targeting mechanisms for reference
  • it’s circular in its logic, ie the discount depends on yield expectations that depend on issuance. That circularity was notably mentioned by @vshvsh earlier in the thead

I stand on the core idea that the mechanism to discover the price of trust is the staking market itself. The tapering removes the administered floor and lets the ratio settle where net yield meets the premium the marginal staker demands, a discovery by entry and exit, not by formula. The following property needs no price input at all: the unstaked reserve behind the social layer’s last resort is a share of the total supply. Specifically for that endgame property, the ratio isn’t a proxy for the thing that matters most, it is litterally the thing that matters most.

An aside. We are pretty much acting here as unregulated central bankers for a very important and very complex monetary system. I don’t know how many of us are actually qualified to do so – that usually takes postgraduate education in economics and many years of relevant experience. In our case that includes cutting-edge blockchain and Ethereum expertise. So no disrespect, but I don’t know that there are very many people in the world who can truly understand proposals like these. I also don’t know for how long the world’s government regulators will let us get away with this.

1 Like

Expertise should help us find assumptions we missed, build better models, and understand consequences. It should not change the result of something another person can independently reproduce. I think that distinction matters here.

8363 can mechanically change the aggregate staking ratio and the marginal issuance economics. What it does not mechanically establish is that the resulting validator set becomes more decentralized.

The protocol observes a global quantity: how much ETH is staked. Decentralization is a distributional property. It depends on who independently owns the ETH, who decides where it is allocated, who can move it, who custodies it, who operates the validators, and how many genuinely independent centers of coordination remain. A lower staking ratio can coexist with more concentrated control.

That does not invalidate the separate social-layer argument made above. If the objective is specifically to preserve a reserve of unstaked ETH, then the staking ratio itself is relevant. But preserving an unstaked reserve and improving the decentralization of the validator set are two different claims.

So I would not call 8363 a decentralization mechanism yet. It is a staking-ratio mechanism with a decentralization hypothesis attached to it. It becomes a decentralization mechanism when the resulting distribution of independent control is part of what is actually being tested instead of something inferred from the aggregate ratio.

I don’t think resolving that requires changing 8363 or extending this thread into another large modeling debate.

The narrow solution is to predeclare the consequence test: apply the 8363 transition across credible behavioral ranges, allow capital to move between solo staking, delegation, LSTs, exchanges, custodians and professional operators, and measure what actually happens to the distribution of independent control.

Thread just for that question:

https://ethereum-magicians.org/t/research-proposal-what-happens-to-validator-control-if-eip-8363-works/29568

If independent control becomes more distributed, that strengthens the decentralization case for 8363. If it becomes more concentrated, it does not. If legitamate assumptions produce opposite results, then the correct answer is simply that we do not know yet.

Thanks for this long post and I won’t be dealing with every points one after the other so as to avoid repeating myself in the thread.

This EIP is indeed the work of its six named authors independant of the Ethereum Foundation. It is thus not a position of the Ethereum Foundation, whichever institutions individual authors are affiliated with. I said something similare in this previous comments. You’re right that the ambiguity had real costs and that some teams may have felt obliged to respond. That’s on us.

Note that the Ethereum Foundation in its recently published tier list did indeed expressed itself (somehow) on the matter:

See here for a full read: EF Protocol: The Hegotá EIP Opinion Post and Tier List

You’re right. The size-progressive description assumes the operator decides how much stake exists. For a provider staking other people’s ETH it doesn’t necessarily hold: declining a deposit just moves it to a competitor, so no competitive provider stops growing to avoid the curve. Several comments in the thread refers to this problem, notably @awma here, @youssef there, and @knoshua with a counterexample over here.

The Motivation sentence is currently being re-scoped to what survives: aggregate stake, and operators deploying their own capital. The wording will come back to this thread so it can be argued with after adjustment.

Your cross-subsidy term is a good exit-ordering objection and my wedge related arguments does not price it properly. An operator for whom staking is a retention feature can hold at zero, or below. We usually rule that out because this relates to the (false imho) idea that the market will indeed equilibrate beyond a 50% ratio and that neither the industry will necessarily introduce more attractive ETH strategies nor will allocators seek something different than very low yielding staked ETH. Nevertheless, I totally agree with the missing impact assessment regarding “what happens to operating businesses on the way there”. This is the cascade analysis we offered to build with the teams that run those staking related produts rather than by us alone because we don’t have first hand access to the critical parameters. If you want to join the effort please slide in my dms!

2 Likes

While dealing with the Lido contributors response at #71 and #231 I realized you asked several times about the rational behind "a large reserve of unstaked ETH as the last credible counterweight the social layer holds in defence of neutrality”. I want to avoid the responses being mixed up notably as I have started to address it in #248.

Indeed, vanilla ETH does not cast vote in consensus. It is not either “all stakers on one side, all holders on the other.” The scenario of social slash is not a vote.

Indeed, you’re right, plain malicious behavior such as equivocation would likely result in the malicious destroying its own money. There’s nevertheless an important difference between acquisition cost and coercition cost. Your own observation that stakers “put their money behind a concrete entity, which they can pressure” is exactly the vector for third party (State, Regulators, Cartels…) can pressure that same entity, with a licence to revoke or inclusion to refuse, and no acquisition cost at all.

As we dive deeper into the feedback given in this thread it feels like a dedicated article on our PoS security and threat mitigation tools would be needed. Nevertheless for the sake of the discussion, here’s an example of scenario to consider:

The operators collude (however many entities that takes) and have 2/3 of the staking power. This cartel agrees to attest only to blocks from one builder, and that builder applies a sanctions list or anything against credible neutrality. Every other proposer’s block is orphaned. Nothing in the protocol fires: declining to attest isn’t equivocation (nobody is slashed) and the coalition has finality (no inactivity leak). The chain keeps finalising but censored. The remaining operators either uses the coalition’s builder (the whole set is captured) or holds out and watches its blocks get discarded.

Note that:

  • this cartel destroys none of its ETH in the process, it collects rents while the chain keeps finalising.
  • the staked ETH at the cartel are getting better yield than the other
  • this collusion can be rather hard to detect, for example let’s not censor all non compliant blocks but just 1 out of 4 to start with and nudge other operators to comply
  • choosing to attest only blocks originating from one builder doesn’t have to be malicious capture oriented per se, you may simply be compeled to apply the local OFAC rules,
  • for reference, last November “only” 20% of the builders where applying OFAC sanctions see this dashboard https://censorship.pics/

What should the remaining operators and ETH holders do?

Unstaked ETH is the only ETH that can enter on the neutral operator side. Honest stake past a third can deny the coalition finality, at the holdouts’ own cost, which is likely enough to turn a quiet censorship regime into a crisis the whole economy has to settle. Note that the amount needed for denying finality scales with the staking ratio while the protocol entry rate doesn’t. Should the cartel try to hold its staking power share, it has to censor deposits in the open. At that point the remedy is a minority fork, and it needs three things only unstaked ETH provides:

  • people who can adopt it cleanly (holders whose funds aren’t inside the compromised validator set;
  • deposits for the replacement validators the honest chain needs;
  • enough weight that adopting it is credible rather than symbolic.

Past half the supply staked, a captured validator set is a majority of the economy by construction, and a fork against it has no larger constituency to appeal to. That’s what the reserve is for, and why we put the ceiling has a share of supply.

3 Likes

A coalition with 2/3 of the staking power can keep finality while enforcing censorship, and the remaining operators can be pushed toward the coalition’s builder because their own blocks otherwise get discarded. Nothing necessarily has to trigger slashing for the validator set to become operationally captured. That makes the coercion case much stronger than a simple “malicious staker burns their own money” model.

A large reserve of unstaked ETH is clearly valuable in that situation. It gives Ethereum capital that is already outside the compromised validator machinery, gives neutral operators somewhere to draw stake from, and makes it easier for a competing successor to form without first unwinding the captured set.

The distinction I keep coming back to is what exactly has been captured once the remaining operators comply.

Their validator behavior has been captured. That still does not tell us that the beneficial owners behind that ETH, the custodians, allocators, node operators, applications, exchanges, or the rest of the economy have all inherited the same preference. In the scenario itself, some validators comply precisely because refusing to comply makes their blocks worthless. Their behavior is evidence of coercion, not necessarily agreement. That is why I hesitate at “a captured validator set is a majority of the economy by construction.”

If more than half of ETH is staked and the whole validator set becomes operationally captured, then yes, more than half of the supply is sitting inside that captured system. But the economic constituency that can recognize and continue from a successor is broader than the validator set containing those balances.

I think that actually gives 50% a very clean justification without asking the number to prove more than it can. At that ceiling, 8363 stops issuance from encouraging Ethereum toward a state where the majority of ETH is inside the validator set. A majority reserve can remain outside consensus, cleanly available if the validator layer itself becomes compromised. That materially increases the room the social layer has to respond.

The strength of that response ultimately depends on how much independent control remains across Ethereum and whether those independent actors can converge on and continue from a neutral successor.

So the staking ratio tells us something important and concrete: how much of the supply is exposed to the validator layer at once.

The distribution of independent control tells us how much of Ethereum can still choose what happens when that layer fails. Preserving a majority outside the validator set gives that choice substantially more room to survive.

@jdetychey — three problems with the reserve argument in #253.

1. A fork writes its own rules

Your remedy is already a minority fork. The patch can change the active set, force-exit validators, burn balances, or change issuance.

The staking ratio on the old chain does not come with it. It does not decide whether the new chain can finalize. If the cartel is dropped from the active set, the remaining validators are the new set.

Who follows the fork is a social question (LST holders, ETF shares, exchanges). Crossing 50% staked does not turn the fork off.

2. High staking ratio doesn’t mean high operator concentration

The example is operators attesting to one builder. That depends on how few entities can be coerced. 30% staked through a handful of custodians and LSTs is easier to capture than 55% across uncorrelated operators.

The EIP only sees aggregate D. It does not see operator count or jurisdiction.

Only consensus rewards get burned. Proposers still keep MEV and priority fees. That leftover income is what pays for scale and builder relationships. Fixed costs hit small operators first. That compresses the set toward the entities in your scenario.

And aren’t we changing the whole censorship resistance architecture anyway with PBS? That would render this scenario obsolete anyways (and is a much better way to solve these kinds of issues).

3. The reserve is people who already chose not to stake

You want unstaked holders to deposit on the honest chain. They already declined ~2.6% on the live chain. A minority fork is even more risky.

If the fork wipes the old set, the tapered curve actually pays the first deposits well - the burn is ~0 while D is small.

If the fork leaves the old set in place, D stays large and net issuance is already compressed (and ~0 near the cap). Then the rate is bad too.

The current curve paid people to take validator risk when D was small. Counting on non-stakers to bootstrap a crisis chain is not a reserve.

If the real claim is that a confiscation fork would not be adopted, say that. That does not imply a 50% staking-ratio ceiling.

1 Like

This is misguided, in my view.

’Power lies where people believe power lies’

The same is true for monetary legitimacy.

If 50% of ETH is staked, and the validators are captured via collusion, then we’re in big trouble. But having the other 50% unstaked doesn’t solve it at all. In fact, it’s much easier to capture the 50% that’s unstaked. Just write a smart contract where they all coordinate to collude. Staked validators can’t participate, but the unstaked ones can.

We cannot solve governance this way. It just can’t be done. There is a better way.

This is where, IMO the thread finally converges.The 50% line can do one job very cleanly: define the point where protocol issuance stops encouraging additional stake. That gives 8363 a concrete policy boundary and solves the problem the mechanism can actually observe. It does not require us to know the eventual staking equilibrium in advance, and it does not require the current curve to continue subsidizing stake indefinitely.

The trouble starts when the same number is asked to tell us how decentralized the validator set is, how easily operators can be coerced, how independently the remaining ETH is controlled, or which fork the economy would recognize after a catastrophic failure. Those depend on the topology of control around the balances, not simply whether the balances are currently staked.

The recovery discussion makes that especially clear. ETH outside the validator set is useful because it remains immediately available outside compromised consensus machinery. That is real option value. But unstaked holders can still be concentrated, coordinated or coerced, just as staked ETH can represent beneficial owners whose preferences are completely different from the operators acting on their behalf. Balance location alone cannot tell us where independent control or legitimacy sits.

Once we are discussing a recovery fork, we have already crossed into a different layer anyway. The successor can change the validator set, remove compromised actors, change issuance and define whatever state transition the community is actually willing to inherit. Whether that successor becomes Ethereum is ultimately determined by the independent actors who continue from it. Ethereum already treats that kind of catastrophic recovery as a social-layer problem rather than something ordinary fork choice can settle.

So I think the clean resolution is to let each layer carry the property it can actually support. Issuance policy can determine how strongly Ethereum subsidizes staking. Protocol mechanisms can address censorship and validator behavior directly. The distribution and correlation of control determine how difficult coordinated capture is. If those protections fail, legitimacy comes from whether enough independently acting parts of Ethereum converge on the same successor and continue from it.

That still leaves 8363 with a strong reason for 50%. It is a conservative point at which Ethereum stops paying through issuance to move a majority of the supply into consensus. Keeping substantial ETH outside the validator set can improve recovery optionality and supports the monetary-policy goals of the proposal. It just does not create a discontinuity where decentralization, capture resistance or social legitimacy suddenly changes at 50%.

I think the rationale becomes much stronger if it simply says that directly. Something close to:

“50% is the saturation point at which protocol issuance stops incentivizing additional stake. It is a conservative policy boundary, not a mechanically derived threshold for decentralization, capture, or social recoverability.”

Then the staking curve no longer has to solve governance. The governance argument no longer has to prove the staking curve. The censorship discussion can live with the mechanisms actually being built for censorship resistance, and the decentralization discussion can stay focused on the distribution of independent control.

At that point I don’t think there is much left for the staking ratio itself to resolve. The disagreement came from several different properties being carried by the same number. Once those properties are separated, 8363 can be judged on the mechanism it actually implements. The allowance of this state-to-state flow is what’s needed for PQ.

1 Like

Thanks for this writeup Greg, I will answer directly on your followup at #231 since your two posts are rather similar with lattest giving more colors on the mechanisms.

What is the defensible position for 50%?

Why is 60% worse than 50%?

I’d really like someone to explain that to me.

1 Like

There’s a semi-famous paradox in probability theory called the Sleeping Beauty Paradox. You can google it and go to the Wikipedia and read up on it so I won’t explain it here. But what it highlights is that people make wildly different assumptions in the face of uncertainty. And when something is framed as a dichotomy to us, we tend to fall into the 50/50 trap. But it’s all about the framing. There’s no actual reason to approach it one way or another. And that’s what I think a lot of this discussion has boiled down to. Perspectives. If I tell you that you’ll either eat a burger tomorrow or eat a pizza, you are inclined to assign a 50/50 chance to either one of those happening. But that’s completely unfounded. You have zero reason to believe that the distribution curve would be uniform. You haven’t taken the statistical sample of the population to actually form any priors. That’s why it’s a trap. No, it’s not equally likely to rain or sunshine tomorrow. We know this. But we fall for it anyway. Which is the point of the Sleeping Beauty Paradox. Just how many people fall for it. Or some variant of it. Bayesian statistics requires that we understand our priors, and update them. So let’s do that please. Thank you.

(Quoting myself on the comment above responditng to post #19 )

You’re partially right and let me clarify the sentence you quoted. The issuance debate being old is not the same as this curve having been consulted on and apology for the confusion.

Let me clarify what the “Yes” at my quote was meant to cover since it read as more than it was. In the months before publication I had many conversations with staking and DeFi actors about the principles, the design space and the transition. The Ethereum Foundation even hosted this public roundtable that gathered many orgs and individuals. We (the authors) didn’t pick this tapered curve and go on a community feedback tour with it before the publication. The reality is that it was a long process internally among the authors and researchers involved to converge to this curve (typically its tapering mechanism). We took inputs on principles, yes; did we consult widely on the proposal, no. Your point stands on the part that matters. I won’t say who said what in private conversations, as it’s useless at this stage and shouldn’t be weighed as evidence either way.

What I take from your feedback, in line with many others here, is that the level of contention calls for more tradeoffs and a proper process for convergence towards a middleground. I also don’t know which venue a consultation on a specific curve should use before publication. I notably relate to the quote you’re giving from @adietrichs " A “community decision” is much fuzzier and harder to operationalize". Happy to read your suggestion if you have one. What consultation means for this proposal as of now is the work already on the table and we already got a lot out of the discussion here, notably on the solo-staker impact assessment, Motivation section edits, eventually adding a Monitoring and Response section, collaborating with DeFi-Staking venues’ risk teams on cascade models etc.

Thanks a lot @gregkfor all of those elements and responding to this newer version of your initial comment at #71.

On the three process facts, I won’t argue them: the EIP went up about 48 hours before the PFI deadline, the concrete curve wasn’t put in front of this forum for review until 4 August, and no structured consultation on this curve preceded it. On the third nevertheless, let me be precise because the framing matters. Engagement is not what’s in dispute, you say it yourself that Lido contributors “have tried to engage constructively in the issuance discussion” and that concerns were raised “across different venues”, and we’ve been in the same rooms for months, including a roundtable at EthCC. What didn’t happen is a review of this curve before it was written. This reply is also later than it should have been.

I’ll take that as the shared ground and read the rest as a disagreement about how and when.

You asked for a record of which material objections have been raised, how the proposal responds to them, and which questions remain open. Here’s the list as it stands today from my PoV. It isn’t closed, anyone can add comments. It’s not final in its form and deserves a better look (I’ll update the link when it’s done). I’ll keep collecting through the end of the month, from this thread and elsewhere. I plan to publish the compressed version alongside what the status quo carries so the objections are weighed against something rather than nothing. It’s just a list at this stage and not a rebuttal. The objections we think are correct are marked as such, and the work still owed is listed too. Others among the EIP authors are working on the solo-staker impact assessment we agreed previously in this thread.

On the broader process: yes. I’d be great to have Lido help facilitate it, and the EF hinted at wanting to assist as well in its recent blogpost. Let’s build this better process together. I have a few ideas I’ll run by you directly. Everything in the design should be arguable in that process, the parameters included. What I hope we can agree on as a starter is the problem, not yet the fix: the current curve subsidises stake growth without limit, and the question of where it should stop is one Ethereum has never actually answered.
Importantly, your list mentions involving economists, modelers, DeFi stakeholders, operators and solo stakers. It doesn’t name the holders who don’t stake and pay for issuance through dilution, which includes the L2s that hold raw ETH and are absent from this thread. @jmiehau put it above at #136: “whatever process kills or ships this should honestly claim the payers were in the room”.

The tipping-point argument, the social-slashing likelihood and the intermediation point each deserve their own reply, and they’ll come separately. I can tell you where I stand on the second, in one sentence: composition decides how likely that day is, and the reserve of unstaked ETH decides whether there’s anyone left to answer it.

1 Like

In the current bear market, while ETH is still in the early stages of rapid development, this proposal should not even need to be discussed .

Frequent discussions about changing the underlying economics to address a hypothetical problem will increase the unpredictability of ETH and ultimately hinder its development. Today, we are discussing reducing something. In the future, will we also discuss increasing it because of problems that we have not encountered today?

If, during ETH’s early stage of development, its underlying economics give people the impression that they can be changed arbitrarily, that is itself fatal for a global underlying asset.

The worst part is that everything we are doing is still only intended to solve a hypothetical problem. We do not even know whether this problem will ultimately exist.

The current market will also naturally adjust the amount of ETH being staked. During a bear market, people tend to hold ETH, and they may put their idle ETH into staking to earn a small amount of yield. During a bull market, many people will unstake their ETH and sell it. The market has its own mechanisms and natural dynamics.

Given the current unfavorable crypto environment, repeatedly discussing changes to ETH’s underlying economics in order to address a hypothetical problem, while increasing the unpredictability of ETH, could hinder its development.

ETH’s underlying economics should not be changed arbitrarily. This is not a good thing. Changing the underlying economics today because of one person’s hypothetical problem, and then discussing another change tomorrow because of someone else’s hypothetical problem, creates a very negative impression.

The underlying economics can be changed, but such changes should be made to solve problems that actually exist—not to address problems that other people merely imagine might exist.

2 Likes

Indeed, we haven’t costed this specifically, and the scenario is coherent. Yet, I also think it’s an edge case.

Who can run this attack? Price-insensitive actors.
Pushing the ratio means adding stake and not just holding it. An exchange or an LST stakes its customers’ ETH and their customers follow the yield. As the net consensus yield falls toward zero they leave, and the operator can’t push with ETH it doesn’t own. So the actor in your scenario has to deploy its own balance, both at scale and at a loss. Typically that would be a state, or possibly a strategic holder. No issuance policy can fully deter a price-insensitive actor, what a policy can nevertheless decide is who pays for the attempt.

The tapered curve effectively changes is who pays during such scenario and it favours everyone else.
As the ratio rises, more of the issuance is burnt thus creating a transfer to every holder (at staked or not and including the ones being pushed out). The same squeeze arguably exists under the current curve and in a worse shape: every ETH the ill-intentioned well-capitalized actor adds at stake compresses every staker’s nominal yield, raises the dilution everyone pays, and the attacker collects at least about 1.5% nominal consensus yield forever for doing it.

The opportunity cost of keeping the ratio low for the attacker.
Every exit lowers the ratio and lifts net yield for every staker staying in or coming back because the taper is a deterministic function of total balance. Entry stays free, so there’s no recoupment. as soon as the push of the attacker stops, the yield it created draws back ETH at stake. This attack is also very hard to keep quiet. The attacker has to push considerable amount of ETH through an entry queue capped near 1.75M a month and then to sustain being at stake for zero yield. In the meantime, unstaked ETH can access a low but positive yield say at lending market as it had before staking existed. The lower the ratio at the staking market equilibrium the stronger this effect is. Of course if equilibrium sits closer to the threshold then forcing stakers out is easier from this perspective but there’s also almost nothing left to squeeze, ie. the net yield there is already near zero and the participants the attacker would force out have already left.

What’s trickier is your “even temporarily” case. If exit is stickier than entry, a squeeze needn’t be held forever to do damage. We have no cost for that yet, and it belongs in the solo-staker impact assessment we already committed before.

Haha good one. So you read through this thread and concluded that “many” are converging towards a “middleground”. Nice try. The consensus is very clearly, leave it the f alone. Thanks for coming.

2 Likes

@jdetychey

I carefully read through everyone’s suggestions, as well as your responses. I’ve noticed that when addressing the issues others have raised, you often seem to miss the core of the question and instead work around it, using descriptive language to express your own views in a way that gives the impression that you have directly addressed the concerns.

Also, some of your longer responses seem to have been assisted by AI.

So far, I don’t think your responses have done much to move the discussion forward. Perhaps you could try changing your communication style and focusing more directly on the core issues being raised.

I support the general direction of EIP-8363, and after following the discussion over the past month, I have become increasingly convinced that Ethereum should eventually move toward a tapered issuance model.

However, I think there is one additional factor worth considering when discussing the current 50% saturation point.

As I understand it, one of the arguments for using 50% is related to social-fork resilience. Once more than half of all ETH is staked, the non-staking side of the ecosystem becomes a minority in terms of ETH supply. In an extreme scenario where the validator set becomes captured or behaves against the broader interests of Ethereum, this could weaken the independent economic base available to coordinate around a social fork.

Conceptually, 50% is therefore a very clean threshold.

But I am not sure that the on-chain staking ratio alone fully captures the real economic balance between stakers and non-stakers.

In practice, most stakers probably do not stake 100% of the ETH they control.

Solo stakers may keep some ETH liquid for taxes, validator expenses, hardware costs, transaction fees, or emergencies. Professional staking operators may hold liquid ETH for operational purposes. Institutional holders may maintain liquidity buffers, and users of staking products may also hold unstaked ETH alongside their staked positions.

This means that the economic actors participating in staking may collectively control more ETH than the amount visible in the validator set.

For example, suppose staking-aligned actors on average stake 90% of the ETH they control and keep the remaining 10% liquid.

If 45% of the total ETH supply is actively staked, then the total amount of ETH controlled by those staking-aligned actors would be approximately:

45% / 0.90 = 50%

In other words, at a 45% on-chain staking ratio, the economic actors behind staking could already control around half of the total ETH supply.

If the average staking ratio of those actors were lower, the difference could be even larger.

This suggests that a 50% on-chain staking threshold may not necessarily correspond to a 50/50 economic balance between staking-aligned and non-staking-aligned holders.

For social-fork resilience, the more relevant variable may be the total ETH controlled by staking-aligned economic actors, rather than only the ETH that is currently deposited in validators.

Because of this, I think it may be worth considering a safety margin below 50%.

A saturation point around 45%, for example, could provide such a margin if staking participants typically retain around 10% of their ETH outside staking.

I am not arguing that 45% is necessarily the correct number, and I do not think this should be decided based on a simple assumption.

The important point is that the saturation threshold could perhaps incorporate the difference between:

  1. ETH actively staked in the validator set, and

  2. the total ETH economically controlled by the actors who participate in staking.

If this distinction matters for social-fork resilience, then it would be useful to gather empirical data on how much ETH stakers typically keep outside staking.

For example, it may be possible to estimate liquid reserve ratios across solo stakers, professional staking operators, liquid staking protocols, custodians, and institutional staking participants.

That data could help determine whether 50% provides enough safety margin, or whether a lower saturation point such as 45% would better preserve an independent non-staking economic majority.

More broadly, I think EIP-8363 is valuable precisely because it creates room to think about these kinds of second-order effects.

The goal should not simply be to maximize staking participation. The goal should be to achieve sufficient economic security while preserving Ethereum’s neutrality, social-fork resilience, monetary properties, and the ability of non-staking ETH holders to remain economically meaningful participants in the system.

For that reason, I would be interested in whether the authors have considered adjusting the saturation point based on the total ETH exposure of staking-aligned actors rather than the validator balance alone.