GIP-153: Should Gnosis Chain transition into the Ethereum Economic Zone?

  • In Favour
  • Against
0 voters
GIP: #153
title: Should Gnosis Chain transition into the Ethereum Economic Zone?
author: Friederike Ernst with co-authors Philippe Schommers and Ben Carvill
status: phase-1
type: strategic direction
created: 2026-07-22

1. Abstract

This asks GnosisDAO to align on transitioning Gnosis Chain from a standalone Layer 1 into a ZK-proven Ethereum Economic Zone (EEZ) rollup instance that settles natively on Ethereum. This is not a new chain and there is nothing to migrate to: it is Gnosis Chain, now based on Ethereum, inheriting Ethereum’s security and liquidity directly.

The transition ends the treasury-funded staking subsidy in favor of a fee capture from network activity, unlocks synchronous composability with Ethereum mainnet, and positions Gnosis Ltd, co-architect of the EEZ framework and operator of its first instances, at the center of the emerging market for EEZ deployment and services. The first iteration, targeted for genesis around the turn of the year 2026/27, already delivers 80% of the synchronous-composability unlock for around 40-50% of the total engineering effort, and serves as a stepping stone to the full EEZ specification, expected over the course of 2027.

No funds are requested, this GIP seeks alignment on direction. Aligning early on direction gives the engineering team a clear mandate to design.

2. Motivation: a candid assessment of where we’re at

Gnosis Chain has failed to deliver on its original value proposition. The core value proposition when we started was credible neutrality: a decentralized, low-cost EVM chain run by a large set of independent validators. It proved not to be a good one. Credible neutrality is Ethereum’s home turf, and a smaller chain offering the same qualities with less security and less liquidity gives builders and users no compelling reason to come. Without differentiation there is no usage, and without usage the economics do not close.

The numbers make this concrete. Fee revenue covers only a small fraction of even the minimal cost of security, so security is paid for by the DAO treasury, not by the network. Staking rewards are a dilution offset funded by non-stakers, not yield from activity. Ethereum has the same structure, but at a very different scale: its issuance runs below 1% a year and is partly offset by the fee burn, leaving net dilution even smaller. Gnosis dilutes non-stakers by roughly 2.3% a year. And the subsidy does not stop at security: GnosisDAO also carries the cost of the surrounding infrastructure, from block explorers and RPC endpoints to incentives for third-party protocols. Liquidity has had to be bootstrapped and defended in isolation, and network effects never approached mainnet’s. Every standalone alt-L1 pays these structural costs indefinitely; Gnosis pays them without the scale that could ever cover them.

This is not a failure of engineering: the chain is established, credible, and technically sound. It is a failure of differentiation. Becoming an ordinary L2 would not solve this either: the differentiation problem just moves down a layer. Of the over 100 L2s, most don’t have any meaningful usage and the few that do, don’t differentiate technically but through existing distribution channels.

The Ethereum Economic Zone changes the calculus. The EEZ framework makes it possible to keep everything that works about Gnosis Chain while in addition allowing full composability with Ethereum. This dramatically improves Gnosis Chain’s position from a chain where a fraction of what is available on Ethereum is available to a chain where EVERYTHING that exists on Ethereum, including full liquidity for all tokens, is a single atomic call away. Oracles, on- and offramps, and mainnet liquidity venues can be used directly, as if they were deployed on Gnosis Chain itself; even CEX rails become reachable without bridging.

The opportunity, concretely: speed and cost are the easy part. Gnosis EEZ produces blocks every 2 seconds at sub-cent fees, but faster and cheaper than Ethereum is table stakes; most of the 100+ L2s can claim the same. The singular upside is synchronous composability with Ethereum. No existing L2 offers it, and it is the one axis on which Gnosis EEZ competes alone rather than as one of a hundred interchangeable chains.

This upgrade also comes at a price. We give up what differentiated us so far. Synchronous composability in combination with fast block production is currently only possible in a centralized fashion. There is no version of this upgrade that keeps the large independent validator set at the core of the chain. But seeing that we need to go there anyway, we will leverage it: a chain that is operated rather than maximally neutral can be opinionated about security. It can hold suspect transactions and try to protect users from obvious hacks. The past years of relentless exploits have made it plain that adding layers of security where possible is still very much needed.

3. The upgrade

What is EEZ, and what is Gnosis EEZ?

Two things to hold apart:

  • EEZ (the framework) is a way to build rollups that are governed and economically aligned to Ethereum: a credibly neutral public good, with no token, co-led by Gnosis and ZisK, co-funded by the Ethereum Foundation, under Swiss-foundation governance. It is not a Gnosis product.
  • Gnosis EEZ (the instance) is a Gnosis-operated deployment of that framework, with GNO economics and xDAI gas, and the transition path for Gnosis Chain.

How it works

Currently, Gnosis Chain is a standalone L1 with its own validators, its own security, and its own liquidity, often bootstrapped courtesy of the DAO. After the transition, Gnosis EEZ produces blocks every 2 seconds against Ethereum’s 12-second slot, proves its state every Ethereum block, and settles to Ethereum L1, using Ethereum block building for execution. Proving starts pragmatic and hardens over time. The first iteration will use an interim proving setup, likely TEE-based, with the concrete mechanism to be selected during technical specification, and moves to real-time ZK proving as the EEZ specification completes. At full specification the instance inherits the complete security assumptions of Ethereum for finalized blocks, with no third-party trust considerations. In the first iteration that inheritance comes with one caveat: an interim proving setup adds an additional trust assumption until real-time ZK proving lands. The direction of travel only ever removes trust assumptions, never adds them.

The mechanism, per the EEZ core protocol: cross-chain state is coordinated through proxy contracts, state transitions are pre-computed off-chain, and ZK proofs verify them on-chain. Each instance registers with a central EEZ registry contract on L1 and appoints its own set of proof systems with a configurable M-of-N verification threshold (this represents a multi-prover design, so no single prover implementation is a trust bottleneck). Verified cross-chain calls execute atomically within a single L1 block, with rolling-hash integrity checks binding every call to the proof that committed it.

At launch, sequencing is centralized: Gnosis Ltd operates the composer that orders transactions, builds blocks, and submits them for proving and L1 settlement. This is a major design choice with consequences for downstream systems. What bounds the risk: every block is proven and settled on Ethereum, so the sequencer cannot forge state, steal funds, or roll back finalized history. The harm a misbehaving sequencer can do is limited to delaying or excluding transactions. We deliberately make no commitment on the future of sequencing here. We will operate the instance, observe what degree of censorship resistance the ecosystem actually needs, and return to the DAO with evidence before deciding whether to keep, constrain, or decentralize the sequencer. Mitigations such as a forced-inclusion path through L1 are options to evaluate then, not launch features.

Synchronous Composability

The unlock is synchronous composability: a contract on the Gnosis instance can call a contract on Ethereum mainnet and use the result in the same atomic transaction: all of it succeeds or all of it reverts. This is what removes the historic trade-off between app-chain performance and shared liquidity and it is something no existing L2 offers.

It is worth noting that at launch, composability is one-directional. Full bidirectional, cross-instance composability follows, as the development of the EEZ protocol progresses, with an intents-based bridge covering the interim and facilitating atomic bridging in both directions.

Consequences of the transition: the Gnosis Chain validator set is sunset, as settlement security moves to Ethereum’s validators, the bridge validator set is repurposed to operate the provers, and the ~350k GNO currently staked (≈27% of circulating supply) is unlocked. For everyone else, nothing changes. Users and dapps keep their addresses, balances, and contract state with full continuity, xDAI remains the fee token, and infrastructure providers run through the transition unchanged, as no redeployment is required outside of simple updates to a configuration.

We do not take the sunset lightly. Making the validator set superfluous is the main regret in this proposal: a large community of independent validators is part of what made Gnosis Chain special, and that loss is real even where security no longer requires them. We intend to find a new role for this community, potentially in the context of Gnosis VPN, where a distributed set of independent operators is exactly what the product needs.

A note on decentralization: We already touched upon this in Section 2, but we want to be explicit about this: Becoming less decentralized is a deliberate position. Ethereum is maximally censorship resistant, and that is exactly why we build on it: censorship resistance cannot be retrofitted, so it belongs at the base. But maximal censorship resistance is a niche, and a limited one. It is incompatible with most financial applications, which need fraud response, compliance, and recourse. Arguably, users should not interact directly on Ethereum at all. What we expect instead is a landscape of less censorship resistant networks on top of Ethereum that deliver the UX and protections security-conscious applications require, while inheriting the base layer’s guarantees where they matter most: for settlement and cross-zone flows. Ethereum becomes the economic operating system; Gnosis, one of its specialized economic zones.

4. Strategic position

Gnosis Ltd is both co-architect of the EEZ framework and operator of one of its first instances. This dual role is the strategic core of the proposal.

Operating the first production instance gives Gnosis Ltd what no one else will have: proven experience migrating a live chain, operating the composer and prover stack, and building the compliance, privacy, and control modules that regulated users need. That makes Gnosis Ltd the natural provider of EEZ-related services as the framework proliferates. This includes bespoke instances for banks and institutions that want on-chain operations with Ethereum settlement but without building a chain, design-partner builds for FinTechs, and instance operation as a service. The framework is a public good; the expertise to deploy and run it commercially is not.

Revenue for the instance itself comes from fee capture at the prover, priced dynamically by route (L2→L1, L2→L2, complex cross-chain flows). It is a volume game where break-even depends on ecosystem growth, not per-transaction margin. The ecosystem strategy targets the audiences that generate the most cross-domain flow such as DeFi protocols (perps, lending, and solvers that gain atomic access to mainnet liquidity), FinTechs and Neobanks (Ethereum’s reach plus the compliance and privacy a regulated business needs), asset issuers (one canonical asset zone-wide instead of bridged wrappers), and institutional operators, the highest-value, longest-cycle audience and the direct pipeline for Gnosis Ltd’s instance-as-a-service offer.

GTM would likely see the chain be embedded within FinTech products, and as such over time may see an SDK being developed to allow scale. But in the early phases we seek design partners to build key modules that enable products to be compliant, or to be privacy enhanced. Also the onboarding experience will be optimized for both humans and AI agents.

Gnosis Ltd’s own products (Pay, Circles, VPN) anchor the consumer layer and gain same-transaction access to L1’s significant stablecoin liquidity.

5. Economics, GNO & governance

GNO after the migration. The first question every delegate will ask: what does GNO do once staking ends? Today, GNO secures the chain through staking, with rewards paid from the treasury. That is a dilution offset, not yield from real activity. Post-transition the subsidy ends, and value is intended to accrue from fee capture on real network revenue instead. The concrete mechanism of how xDAI revenue is tied to GNO tokenomics is deliberately not detailed in this GIP; routes under consideration include a fee-share or buyback tied to instance revenue. A later-stage GIP will propose a specific design once prover economics are observable in production.

Governance: Currently the DAO does not govern the direction of Gnosis Chain, as the validators operate the network, and it is not possible for the DAO to enforce validators to take action. With the validator set being sunset, governance splits as follows:

  • EEZ governance (Ethereum-led) governs rollup protocol changes, prover specification, and L1-to-L2 messaging primitives. Governed through Ethereum’s processes, meaning EIPs introduced on L1 will be reflected on Gnosis Chain.
  • GnosisDAO governance governs gas token policy for Gnosis Chain, fee allocation, any potential ecosystem treasury, and anchor partner funding. This essentially continues what the DAO governs within Gnosis Chain currently.
  • Prover operation: today’s bridge validators take on a new role. Native L1 settlement supersedes the xDAI bridge and its validator committee, but the operators themselves are not discarded: the intent is for bridge validators to run the instance’s proof systems, shifting from validating the bridge to proving the chain. This keeps a known, accountable operator set inside the security model and gives the M-of-N multi-prover design its initial operators. How prover appointments are governed longer term is specified at the second-stage GIP.

6. Budget and timeline

Budget requested: none. The R&D contribution required to scope the Gnosis instance specifically has so far been funded from within the existing GIP-128 envelope. More resources will be requested within the framework of the GIP-128 successor proposal; that funding need exists regardless of whether the EEZ transition happens. The overall infrastructure budget should reduce in the mid term with the EEZ Gnosis instance.

Timeline: genesis targeted for December 2026/ Jan 2027 (validators sunset, first EEZ block produced), conditional on the broader EEZ dependencies landing by summer 2026. Full EEZ specification, including bidirectional composability, nested calls, and real-time ZK proving, is expected to land over the course of 2027. The framework runs on a working devnet today, including end-to-end cross-chain execution.

The first iteration of the Gnosis EEZ instance will already deliver 80% of the synchronous-composability unlock available today, for around 40-50% of the total engineering effort. Much more will be possible in the future when dapps are designed with EEZ interoperability in mind. Gnosis Chain will use the first iteration (atomic L2→L1 calls, interim proving) as a stepping stone to the full EEZ specification while already reaping part of the rewards on the way there.

7. Conclusion

Gnosis Chain as a standalone L1 has run its course. The EEZ transition keeps the chain, its users, and its applications, and upgrades the foundation underneath them: Ethereum’s security inherited every block, mainnet liquidity accessible in a single transaction, a security budget funded by revenue instead of dilution, and Gnosis Ltd positioned as the reference operator in a new category of Ethereum-aligned rollups.

GnosisDAO is asked to commit to the direction, not to a final technical design. Alignment now gives the engineering team a mandate to design against and the ecosystem team a green light to begin partner conversations in earnest.

17 Likes

Immensely bullish about this. It was always weird to me to have Gnosis be so Ethereum aligned as a company, but not actually contribute directly to the network. I also found Gnosis to have huge bridging/ecosystem problems (one of may main problems with the Gnosis App), and only recently bridging has become a bit less painful

Plus, this move worked out well for Celo!

7 Likes

lol, no.

How about instead of pivoting Gnosis Chain into a centralized, operated EEZ instance with a centralized composer, we focus on fundamental optimizations like a stateless chain and sovereign executions?

It’s already bad enough that Vitalik and the EF L1 core devs aren’t pushing aggressively enough to clean up the existing execution and state bloat via “the Purge”. Do we really need to drag Gnosis Chain into this as a based rollup experiment now?

If the goal is pushing based rollup architectures forward, why aren’t we just actively supporting and helping Taiko advance their stack instead of re-architecting Gnosis Chain’s entire validator model?
Wouldn’t that be in the true nature of open source ecosystems? To support fellow DAOs/teams?

Furthermore, we need to explicitly address splitting off from Ether economically rather than entangling ourselves deeper. You never want a based rollup or instance to become larger or more dependent on the mainnet it is anchored to, it completely destroys sovereign positioning and locks you into L1’s friction forever. Being exposed forever to pure extraction mechanisms.

So. . . lol, no.

whats centralized about this? you can decentralize the l2 sequencer

and w/ enough users/apps, you can decouple, if you ever want to (you shouldnt). it’s not that big of a lock in.

Lets go full speed..mega bullish

The idea that “you can just decentralize the L2 sequencer” and “decouple later” completely ignores the reality of the architecture, the economic gravity, and the regulatory baggage we would be inheriting.

1. The Centralization & Compliance Trap
We aren’t just adopting code. We are inheriting an architecture dictated by an EF that is currently a regulatory shitshow, especially from a European perspective. Look at the recent EF spin-outs under MiCA through the lens of “Substance over form” these are highly questionable. Furthermore, the main research hub for this (EthResearch) is heavily gatekept. Try discussing Quantum Social Physics there and watch how fast you get shadowbanned by a leadership tier that includes Virgil Griffith. Do we really want to permanently anchor Gnosis to a stack driven by a group carrying that kind of US-sanctioned compliance risk?

2. The Sequencer & MEV Reality
Decentralizing a sequencer doesn’t solve the core issue: a based/L2 setup hands MEV on a silver platter to a tiny oligopoly of centralized actors who have the infrastructure to fill orders across all chains. Contrast that with Witness Proofs, where you can theoretically handle cross-chain execution natively without funneling everything through a centralized composer.

3. Economic Lock-In and the Kickstart Illusion
Saying “it’s not that big of a lock-in” because you can “just decouple later” ignores our context entirely. Sure, if you are launching a brand-new chain backed by a Web2 giant, like Robinhood, an L2 is a great way to kickstart. They have an entire stock exchange attached to them and the external leverage to eventually spin out. But Gnosis is not Robinhood. We are not a new chain. We already have the ecosystem, which is the hardest part to build in the first place.

Transitioning an established L1 into an L2 completely reverses our leverage. Using ETH as the gas token structurally pushes our existing economic value away from Gnosis and towards Ether, turning us into a fee-extraction tributary. Without a massive external corporate engine like Robinhood’s to force a decoupling later, Gnosis would be permanently locked into Ether’s friction.

4. Cannibalizing Taiko
If the goal is to push based rollups and the EEZ, why are we forcing Gnosis to be the massive test ground? Taiko literally invented this tech stack. Having contributed a bit to Taiko myself, I can tell you firsthand that it introduces a some amount of complexity. Let Taiko lead the EEZ. It’s their natural development. Forcing Gnosis to re-architect just sucks the energy away from them.
Scaling the inner Manifold is interesting and important in the long run. We are in the middle of a Topology collapse. Maybe that’s something Gnosis could be focus on.

5. The Sovereign Manifold Alternative
Why sacrifice our sovereignty just to be Vitalik’s testbed to make Ether look more appealing? Tempo is already pushing in a sovereign direction (albeit in a corporate way). I don’t see a reason why Gnosis shouldn’t pick up on this trend and lead the way in true Sovereign Manifold technology. We cannot out-decentralize the physical stack we are on, but we can bring the backbone of the Internet stack on-chain transparently.

Instead of bloated rollups, we should be building:

  • Stateless Witness Proof chains, which enable parallel execution and finally remove the EVM single-thread execution lock.

  • Native Identity & Infrastructure, grounding everything in did:peer documents where you can prove and derive all keys from one seed. This creates a decentralized alternative to ICANN and DNS, removing the rent-seeking nature of centralized registries like ENS.

  • On-chain Accountability, utilizing SIWE + OIDC mappings tied seamlessly into the DAO service companies internal toolings. The DAO pushs collective proofs on-chain and make the DAO and DAO service companies actually auditable.

  • Network Resilience via DAS on IPFS, on-chain BGP negotiations, and direct low-latency P2P fiber peering.

Why would we give all of this up for Ether? A chain that doesn’t even want to remove its own state bloat, even though Vitalik has a billion dollars (and probably more) in funding to actually make it possible. Reth is actually moving in the right direction with ress, which is exactly what I am advocating for here. I don’t see a reason to full-on roll over and surrender our independence to the EF’s bloated mainnet when we can achieve this ourselves and support the right engineering teams.

Idk, this feels to me like a better approach than aligning more with a vision that doesn’t really have much appeal besides: "Well, Ether is large”. If Gnosis becomes just another rollup, what is the actual selling point?

2 Likes

Conceptually this seems to make a lot of sense as the next step for Gnosis Chain. As builders on the chain we love it for many reason but one of the difficulties at times has been the composability with certain tools that sometimes don’t support Gnosis Chain presumably because they ask for high fees to integrate new chains.

One thing that would help translate the technical achievement of the EEZ as described would be some kind of demo that shows how that would alter the actual UX of using Gnosis Chain. This would maybe help people understand the benefits of the EEZ more concretely.

2 Likes

@Bread.Cooperative

a view very concrete examples relevant to a project like yours:

  1. With EEZ: Anyone with funds on Ethereum can e.g. buy/bake “bread” with a single tx from Ethereum. This tx could directly trigger things on Gnosis (like buying/staking/ bread)

So generally you will no longer need a dedicated wallet with xDAI on Gnosis - anything than can be done on Gnosis can directly be done from any mainnet wallet.

The same if true for the other direction: Anything that can be done on Ethereum can be done from a Gnosis account. So, e.g. you can hold Bread on Gnosis and with a single tx swap this into another asset on Ethereum and send this asset (lets say USDC to e.g. any CEX or offramp service that accepts USDC on Ethereum)

More examples: you can read any price oracle on Ethereum directly from Gnosis. You can use protocols (e.g. register a name) on ENS or .wei again, directly from a Gnosis wallet.

5 Likes

First, thank you for putting this proposal together. It is clear that a lot of thought and engineering effort went into it. Scaling Ethereum while preserving its core properties is not simple problem, and I appreciate the willingness to tackle difficult trade-offs directly.

I have read the proposal twice, and I am still not sure I understand the intended destination.

Since this is a directional GIP, I think it would help to describe the expected end state more explicitly. As I understand it, the first step is for Gnosis Chain to become an L2 where several important roles are performed by Gnosis Ltd. Is this only a transitional phase, or is this the long-term model?

On one hand, the proposal says:

The first iteration of the Gnosis EEZ instance will already deliver 80% of the synchronous-composability unlock available today, for around 40–50% of the total engineering effort.

This made me think stronger decentralization guarantees, including censorship resistance, would come later.

But then I read:

It can hold suspect transactions and try to protect users from obvious hacks.

This seems to imply that Gnosis Ltd. is expected to retain discretion over transaction inclusion. Is this intended as a temporary capability, or a permanent feature of the architecture?

2 Likes

Gnosis Chain failed at credible neutrality because its bridge is validated by a 4/7 multisig and its beacon chain deposit contract is upgradable by a 8/15 multisig, not because the chain is smaller. This is absolutely a failure of engineering, in contrary of what the post claims.

I disagree that EEZ is an obvious differentiator, as synchronous composability is already trivial between contracts on L1, and Gnosis Chain would compete with it directly with a more complicated solution for little benefit for the end user vs just using L1. It would have made sense in a world where L1 wouldn’t be scaling, but Ethereum will increasingly get faster and cheaper, with a 3x gas limit increase already coming in Glamsterdam and more being expected in the future.

I fundamentally disagree with the proposal of adding censorship to the chain. As shown here, Gnosis Chain is today one of the few chains out there with an incredibly fast time to inclusion guarantee, even faster than Ethereum given the huge validator set and the short block times. It would be a great loss to remove such feature, even temporarily, given there is no guarantee to ever get it back. The claim that “users should not interact directly on Ethereum at all” is very sad in my opinion as I think that censorship resistance should be the norm and not a niche. Moreover, the vast majority of the 100s of L2s already mentioned as not having meaningful usage target the same institutional and regulated use cases via the same proposed centralized solutions.

I don’t understand what “EEZ Governance (Ethereum-led)” means. Is the expectation that ACD would decide on contract upgrades via hardforks? If yes, this is completely unrealistic. Gnosis Chain would either be governed by a multisig or a DAO and this needs to be decided beforehand.

I remain skeptical of the effectiveness of EEZ in bringing synchronous composability with contentious state on Ethereum. Based rollups are an old research topic and so far all teams that tried it failed at achieving meaningful coordination with L1 builders. It’s unclear how the same problem is solved here and it’s a huge technical risk to commit to EEZ before proving its effectiveness first.

3 Likes

I didn’t look at it from that angle until reading your comment, but it makes total sense.

If cross-state execution is fundamentally just stateless verification, where off-chain provers run the execution, generate a zk validity proof, and submit it alongside proxy calls, we get synchronous composability without needing permissioned sequencers, preconf markets, or multisig backdoors.

In fact, we could treat the proxy contracts as a core compiler design principle in core.
You call contracts 7 chains away and to the developer it just feels like one unified chain.

Is that the point you’re making? That wrapping Gnosis Chain in a based rollup architecture is basically over-engineering something L1 execution and stateless proofs already handle natively?

So the EEZ is completely agnostic wrt how the blocks are built, so this is orthogonal. What comes later is mostly nested calls, that is calls going back between different zones in the EEZ multiple times in a single transaction.

Just to be super clear here: You cannot have fast blocks AND synchronous composability with Ethereum AND decentralized sequencing. You have to pick two. We’re also building a reference implementation for the EEZ called Rollup 1, which will have 12 second block times (like Ethereum) and be based in the sense that Ethereum validators build the Rollup 1 blocks, there is no separate sequencer. 12s blocktimes (and potentially more if you don’t get into every block) simply doesn’t work for many applications. It’s the credibly neutral solution though and extends Ethereum at a cheaper cost without additional security assumptions.

Let me turn around: There needs to be a centralized sequencer for technical reasons. Ofc you can take the stance that this needs to be unopinionated (and you can actually force this by encrypting transactions and only decrypting them once they’re already commited on chain). This is up for debate. I would take the view that if you have the power to intervene in something that is clearly malicious (say, an old lady gets robbed at gun point in the town square) you should, even if you always have the risk that you may have misconstrued the situation (the old lady is really actually the bad guy in the scenario and the supposed robber just wants his own bag back from her, or they’re in a theater performance or it’s just a grandma and her grandson horsing around), you can right it later. I would never argue that 1) Gnosis should take on compliance functions – we will not do AML or KYC or anything like this on some else’s behalf or 2) Gnosis should be the ultimate dictator here with no recourse. OFC there needs to be recourse and you need to be able to eventually get your tx through. I’m talking about OBVIOUS hacks – and we’ve already placed ourselves in the position with the balancer hack. We used social coordination among the validators to censor the hacker. It only worked because the hacker dealt with other chains first and we had the time, but I’m happy those 20 million weren’t stolen from users! So say a contract has an infinite mint bug or there is an exploit discovered in aave v3: I think if we have the power to intervene, we should. There is clearly the question of where to draw the line, but IMO just saying “we’ll never intervene because then we don’t have to have policy when to intervene” is a pretty bad cop out.

2 Likes

Just a quick clarifying note from the Gnosis VPN committee:

The GIP accidentally states that Gnosis VPN is a Gnosis Ltd product, which it is not. It’s funded by Gnosis DAO under GIP-122, which is why Gnosis VPN doesn’t appear in GIP-128 and the related reports. It’s controlled by Maelcum Inc, a separate entity set up deliberately to provide separation from Gnosis Ltd, and currently overseen by a committee of members drawn from Gnosis Ltd, HOPR and Gnosis DAO. However, Gnosis VPN does gratefully receive some devops and legal support from Gnosis Ltd, as laid out in GIP-122. Full technical, legal and governance details can be found in GIPs 122 and 129 and the associated update reports.

We are of course deeply proud that Gnosis VPN is a Gnosis ecosystem product (it’s in the name!), but a lot of work has gone into creating this separation, which works to protect the DAO, Ltd and the VPN, so we want to make sure GNO holders understand it.

If current Gnosis Chain validators are interested in learning more about Gnosis VPN and running exit or relay nodes, please reach out to us at support@gnosisvpn.com. We’d be delighted to show off the VPN and explain more.

5 Likes

Hey Luca, thanks for chiming in!

Acknowledged – we took steps to decentralize the bridge (light client bridge client built by succinct before they became a thing, Gnosis was the first instance) + Hashi. It added costs and latency and ultimately we abandoned these.

Blockspace on L1 has become cheaper and will continue to become cheaper. In my mental model there are three fundamental constraints: 1) state, 2) compute, and 3) networking. You are absolutely right in that we can scale L1 way beyond where it’s currently at, first with trivial upgrades (gas limit increase, block time decrease), then with statelessness, and with parallelizing compute. Where we will see an actual physical boundary at some point, is networking. There is only so-and-so much data you can move around between tens of thousand nodes in the 12 (or maybe then 6?) seconds for building the block.

My assumption is that Ethereum is going to be the economic operating system of the world and even if we can scale the blockspace efficiently, it will remain a scarce resource. We will have to make tradeoffs too – what are the minimum bandwidth and hardware requirements you can expect from a validator? Should they remain as easy to run as they are now, or should we move into solana territory? I have sufficient ETH and a 1000 Mbit line at home and a top of the line dappnode, I can run an Eth node myself easily and could so the same with 6 seconds blocks and 3x gas limit, but I absolutely cannot run a solana node.

That being said, where I see the advantage of the EEZ is that it allows chains that are different from Ethereum itself and make different tradeoffs to synchronously compose with Ethereum. We’re also building Rollup 1, which will be as close to Ethereum as possible (12s blocks, fully based) – but many applications need fast block times or other features Ethereum doesn’t natively support.

Gnosis Chain can have 2 second block times (and thus be forced to forgo the censorship resistance of Ethereum) and still synchronously compose with Ethereum in every block that has an Ethereum counterpart (so think 5 non-composing Gnosis blocks between every composing block). You can also be fully private. Aztec could synchronously compose with Ethereum, the design is purely call-based and works for non-EVM based chains too. You probably don’t want to do all your compute there, but having some functions on aztec? Game changer! By the same virtue, you can have permissioned networks join, you can have networks restrict which kinds of calls in and out they permit etc. IMO this permissiveness is what makes EEZ interesting for other chains to opt into. This architecture will drive the adoption of Ethereum as the gloabl economic operating system, for which Ethereum is uniquely suite exactly because of it’s censorship resistance. CROPS at the base, opinionated zones on top.

I value your feedback on this, but how would you tackle the security aspects? You think retail should just raw dog it on aave and eat the losses if they’re scammed/ they fat finger/ the contracts get hacked? IMO this simply doesn’t work, there needs to be some sort of user protection possible, or this is going to remain niche.

There is going to absolutely minimal governance. Ideally there should be none at all and the EEZ should just be a non upgradable smart contract. We haven’t worked out the exact scope yet, but this is the goal.

1 Like

Bandwidth will to be solved by posting blocks in blobs. See EIP-8142: Block-in-Blobs (BiB) and Blocks Are Dead. Long Live Blobs.

The L1 zkEVM upgrade will allow both to scale throughput and allow for cheaper nodes (succinct verification instead of tx replay, data sampling instead of full downloads). ZK is the solution to the scalability trilemma for L1 in the same way it has been for L2s so far.

I don’t understand how losing censorship resistance follows here. For example, OP stack allows for forced transactions to be included in the same L2 block that corresponds to the L1 block that includes it and they have a 2s block time.

This seems to be out of scope. The discussion here is on whether Gnosis Chain should transition to EEZ. Unless Gnosis Chain plans to become a private chain like Aztec, which is a change I would welcome!

I believe applications should implement their own mitigations rather than delegating them to a centralized entity that can misbehave. So for example, Aave itself should implement their own rate limits and security councils if they deem them necessary, so that if they misbehave their impact is contained to only their application and not everyone. Motivations are analogous to the mass surveillance vs local surveillance debate (e.g. see the recent Flock drama).

4 Likes

I see a future for on-chain communities that take a purist, decentralized approach to their stack, built on open source and idealism. However, these communities will likely number only in the thousands of people. Their liquidity and native token market caps will be a fraction of what Gnosis Chain has today. In such communities there can be paid roles for core developers, but no grants and project funding. That model was always predicated on a bet on mass adoption.

Gnosis has had too much capital involved from its inception to pivot toward a niche community existence. At its current size, maintaining the status quo without scaling is unsustainable. Since there is no realistic scenario where Ethereum fails and Gnosis succeeds, the only viable path forward is to bet entirely on Ethereum succeeding.

We are young as an ecosystem, but we already have legacies: baked-in expectations and value embedded in projects that cannot be ignored. Existing projects that have long proclaimed to pursue mass adoption must now make the necessary compromises to actually get there, or face significant deflation.

We can still build on-chain communities on a purist stack if we wish, but these must be entirely new endeavors. In these spaces, users will need to pay their own way, and the monetary value involved will be modest.

To DAO advocates, I want to say: please stop chasing treasuries filled with value created before the DAO existed. Instead, build a community that creates value from scratch and manage that as a DAO from inception.

We have come very far on a mix of self-interest and idealism, but that mechanism stopped working a while ago. Now, they’re just riding into each others wheels. As the broader ecosystem matures, the other opportunity lies in channeling our idealism into these new, independent communities.

I appreciate @Joera’s candid post regarding the tension between long-term sustainability, treasury management, and pure decentralization. It raises a core question many ecosystems face:

Must an established project make heavy compromises on sovereignty and censorship resistance to achieve scale and mass adoption?

I’d like to offer a perspective grounded in system architecture that suggests we don’t actually have to accept that trade-off.

Is Decentralization Inherently a Niche?

The assumption that maintaining a sovereign, highly decentralized L1 base layer restricts a network to a “niche existence” was reasonable under older execution models. However, as @donnoh highlighted in his response, modern L1 scaling research has fundamentally decoupled throughput from hardware bloat:

  • Decoupling Availability from Storage (EIP-8142 / Block-in-Blobs):
    Transaction payloads are encoded in ephemeral blob space and verified via Data Availability Sampling (DAS). Consensus nodes don’t need to permanently store or download entire execution histories, they only store the root delta consensus, allowing historical archive burdens to be offloaded off-chain (IPFS/Filecoin clusters, local RPC indexers, sovereign Manifold).

  • Succinct Verification Over Re-Execution:
    Transitioning toward zkEVM validity proofs and statelessness means nodes verify lightweight cryptographic proofs in milliseconds. Node operation remains cheap and accessible to home-stakers even as block gas limits scale aggressively.

True decentralization is an unique value proposition that underpins credible neutrality.
If anything it’s a selling point to make the technology widely adopted.

Protecting Users Without Sacrificing Base-Layer Neutrality

Often, the “compromises” discussed for mass adoption involve protocol-level controls or centralized sequencers to manage risk. But as @donnoh pointed out:

Application-layer security (smart contract rate limits, dApp-level circuit breakers, or application security councils) allows retail users to be protected without degrading the base layer’s permissionless guarantees. Mass adoption and consumer safety can be achieved cleanly at the application layer while keeping the underlying protocol neutral.

Preserving What Gnosis Has Already Built

Gnosis doesn’t need to start over from scratch to remain purist, nor does it need to surrender its L1 sovereignty to scale. It already possesses one of the most geographically diverse, resilient validator sets in the entire Web3 ecosystem (100k+ validators).

By pairing that validator set with modern L1 primitives, stateless verification, ephemeral payload availability, and application-isolated risk models as discussed, we can achieve the throughput needed for mass adoption while fully preserving the sovereign, censorship-resistant base layer that gives Gnosis its value in the first place.

Idealism and economic scale are no longer mutually exclusive. Cryptography has given us the tools to have both. We can separate the concerns easily, bypassing CAP entirely by simply splitting it into two distinct domains.

2 Likes

Hello Citrullin, good to meet you.

As I understand it, EEZ is more about improving composability, of liquidity among other things—rather than scale. Gnosis has plenty of blockspace as is. And I honestly don’t know if the solutions you advocate also address the liquidity fragmentation. You’re deeper into the technicals than I am.

And yes, I will miss my validators, assuming they will be slashed under this proposal. Pun intended. Validators matter a lot, not least as a social vector, tying people to the Gnosis ecosystem, being one of the easiest ways to experience what it means to be part of a validator set. On the other hand, yield was always too high, effectively subsidizing the validator set. That is not a sustainable model.

As said, I am not equipped to assess the technical points you raise. My contribution was more about my observations on the changes in the space over the past year. Things are breaking apart, and that’s not necessarily a bad thing. For a long time, we have been acting and thinking as if we can be and do everything at the same time, as if we could maximize all ends of the spectrum simultaneously.

You say “Idealism and economic scale are no longer mutually exclusive,” and I want to agree with you. But another perspective on the situation is that there is likely too little idealism to go around. That is my point about value-aligned communities being smaller in economic scale, and Gnosis’s aspirations being too large to be one of them.

And let me be clear that I don’t see Gnosis as a sellout. Tough choices have to be made to move forward, and I trust them to try and preserve original decentralization values as much as they can. Not a trustless answer.

And if they don’t, we would have to start something new. Correction: we have to start new things regardless.

4 Likes

Looking at this from the wallet support side, the “nothing to migrate” part is encouraging, but I think users and wallet developers would benefit from a more concrete description of the transition.

Will the existing chain ID, account addresses, token contracts and RPC behavior remain unchanged? What should users expect for native xDAI/GNO balances, transaction history, pending transactions and existing dApp connections around the transition?

I’m with Gem Wallet BD and Support, and these are usually the details that determine whether an infrastructure change feels invisible to ordinary users or creates a wave of “where did my assets go?” questions.

It may be helpful to include a wallet/integration checklist in the implementation plan, plus a test environment early enough for wallets and dApps to verify compatibility. We would be happy to relay practical feedback from our users and testing to our developers.

1 Like

@Joera You mentioned that there might be "too little idealism to go around”. But I want to clarify: This is the most pragmatic engineering path available.

True purist idealism would be trying to force everyone onto niche academic fantasies, like demanding the entire ecosystem rebuild on raw RISC-V assembly from scratch and throwing away all the battle-tested infrastructure we’ve built over the last decade.

Pragmatism is recognizing where the industry is actually heading. We live in a universe of thousands of specialized, sovereign chains, whether that’s a chain optimized for a micro block communtiy (tinyblock), a supply-chain logistics for the chocolate industry, or specialized settlement engines.

The path to scaling and liquidity isn’t forcing everything into a centralized sequencer or a single execution bucket (Which btw. doesn’t scale in topology). It’s connecting these sovereign networks through meshed provers that generate and verify state proofs across chains natively.

This approach completely eliminates the need for centralized intermediaries (or the extra middle-layers pushed in based rollup setups) while solving the real-world friction points we face today:

  1. Cross-L1 Synchronous Composability:
    Specialized chains can tap directly into established L1 liquidity pools, like EURe on Gnosis, without needing to migrate their execution or deal with heavy regulatory bottlenecks (e.g. MiCA compliance) during their early stages.

  2. Multi-Polar Real-World Settlement:
    High-volume global trade, such as bridging European liquidity (EURe on Gnosis) with Asian trade channels (eYuan on mBridge), requires a neutral, sovereign, highly decentralized base layer to handle settlement roots without single-jurisdiction counterparty risk.

  3. The Prover Hardware Trajectory:
    Proving overhead is an engineering and hardware commoditization challenge, not a theoretical dead end. With standard 12-second block windows, calculating proofs between state roots is well within reach, and as prover hardware commoditizes, generation costs drop to pennies without relying on centralized hyperscalers.

Gnosis doesn’t need to strip away its 100k+ validator set or surrender its L1 sovereignty to be relevant. It already has the block space, the validator diversity, and the liquidity primitives to act as the primary European settlement engine for a meshed, multi-polar multi-chain world.

Building on modular, proof-meshed sovereignty manifolds is simply good system architecture.
Why would we give that up to align with a network that struggles with its own past bloat?