The opinions expressed in this piece are solely my own and do not express the views or opinions of North Island Ventures or any company with whom I am affiliated. This is not an offer to buy, sell, or solicit securities, nor should you rely on anything I’ve written as legal, financial, accounting, investment, tax, or any other kind of regulated advice.
The recent controversy around Ledger’s firmware update highlights a major tension between the preferences of crypto’s risk tolerant early adopters, and the needs of the masses who must drive crypto’s next wave of adoption. The ostensible problem is seed phrase management, but, at a more fundamental level, the problem is transaction irreversibly
Background for the uninitiated: the game theory embedded in blockchain consensus algorithms guarantees that executed transactions cannot be undone. We call this feature “immutability,” and it is central to crypto’s value proposition. But this solution to the double-spending problem is a double-edged sword, as it makes crypto scary for ordinary users - particularly because transactions must be sent to brutally unreadable 64-character, 256-bit hexadecimal addresses. If one mistakenly sends crypto to an address with just one wrong character, there is nobody to call for help and the funds are likely lost forever.
Hacks are an even bigger problem than mistakes, and the main reason that guarding one’s seed phrase is so important (though loss of seed phrases is a separate problem, which enabling reversibility does not solve). In fact, hacks are arguably the biggest problem in crypto - over $2B was lost to exploits in 2022 and NFTs worth hundreds of millions have been stolen. In response, many companies are building crypto loss prevention solutions, including human readable addresses, seed phrase recovery services, MPC wallets, account abstraction, advanced auditing tools, smart contract monitoring systems, blockchain forensics, and bug bounty marketplaces. These products have made crypto safer, but they cannot fully defeat software bugs or human error.
Mistakes and crime have also led to large losses in traditional payments and trading, but TradFi has more systems, including fraud protection and legal mechanisms, that protect users. In any case, the crypto industry should learn from the hard won insights of the last few centuries in finance, and then use crypto rails to create a more transparent and efficient system - rather than aiming for some decentralized utopian vision and falling into a chaotic dystopia.
Thus, I believe more should be done to directly address irreversibility, and I’ll highlight a few possible approaches below. I recognize that variations of some of these ideas are being tried, that there are probably better ideas out there, and that there are big challenges – technical, economic, regulatory, and design – to implementing these ideas at scale. I am also aware that many in the blockchain space are ideologically opposed to centralized products and services, and believe the better path is to educate users on best practices and solve security problems in other ways. Nonetheless, I believe irreversibility is one of the greatest barriers to mainstream adoption of crypto and DeFi, and that offering optional systems that increase users’ margin for error must exist over the long-term for true mass adoption. Here are the ideas, from most centralized to most decentralized:
More protocols and token issuers could explore actively managing a mechanism for freezing funds, so users have somebody to contact when they’ve lost their funds. These mechanisms should be transparently disclosed and procedures should be scrupulously followed. This might require users to register and KYC unhosted wallets (as with the recent Ledger firmware update), or for protocol “managers” to get money transmitter licenses and build specialized fraud prevention teams. Additionally, we may need special enabling legislation to allow protocols developers or licensed third-party recovery services to do this without running afoul of any existing laws. Some stablecoin issuers have taken half steps in this direction – USDC, for example, notes in its terms and conditions that it may freeze any account it determines to be responsible for illegal activity, but also forces users to acknowledge that transactions are irreversible and accept all responsibility for mistakes.
Custodians and new entrants might build payments layer on top of base chains that allow the senders themselves to reverse transactions within some specified time-period. This would require the introduction of a trusted or (preferably) trustless escrow service, mean that the recipients cannot access the funds during some holding period, and indeed slow down on-chain settlement times. But this is no problem at all for some use cases - if you are selling a valuable piece of art, who cares if it sits in a smart contract escrow for a few days?
More companies should experiment with decentralized on-chain, third-party arbitration systems, such as Kleros, that can undo fraudulent transactions, without requiring the intervention of a single trusted entity.
A group of Stanford researchers proposed a reversible token standard last year, but as far as I can tell, there has been no pickup. Perhaps this is due to a lack of demand for such tokens, lack of awareness around these ideas, or the failure of early crypto adopters and developers to build for the next generation of users.
Non-custodial and MPC wallets should allow users to setup rules so they can cancel certain transactions within some time frame. A wallet’s primary job is to protect users from losses, and in my opinion, they are mostly failing. The wallets could offer pre-set parameters for cancellation and/or allow for customization based on transaction size or type. Once a transaction within such parameters is initiated, the wallet owners should receive a notification via an app, text, or email, and have the chance to pause the transaction. If the user believes their account has been compromised, they should be able to retake control off the wallet and send their assets to a special backup address (either one that they control or an omnibus account specially managed by a trusted backup custodial service) that have previously specified.
The systems described would introduce more centralization and “trust” into crypto. But they would all be opt-in, and the base layers could and should remain completely trustless, leaving the option of using tokens and protocols that are unfreezable and irreversible. Furthermore, the entities that provide these services could use the blockchain itself to provide transparency.
The introduction and proliferation of these systems will be challenging, and undoubtedly entails some major trade-offs. But I am optimistic that by tackling these problems head-on, crypto can deliver a next-generation financial system that provides different types of users with the sort of security that they value, while unlocking the benefits of global, interoperable, decentralized settlement networks. In the meantime, we cannot expect ordinary people to put their life savings on chain if they fear that their funds can be disappear, instantly and irreversibly.

