GIP-153: Should Gnosis Chain transition into the Ethereum Economic Zone?

Hello Citrullin,

If I understand you correctly, you’re advocating a mesh model as opposed to the EEZ, which could be characterized as hub-and-spoke. I understand why the mesh is more intellectually stimulating, and possibly the optimal long-term architecture — at least hypothetically. But looking at it from Gnosis’s position, I have some doubts.

In a mesh model, wouldn’t Gnosis have to rely on other chains building and running their side of the proving system in order to gain access to liquidity? Gnosis’s interest here isn’t primarily to share its own liquidity — it’s to gain access to Ethereum’s. In the EEZ model, with Ethereum as the hub, that’s something Gnosis can initiate from its own side, without waiting for other players to reciprocate. That difference in who has to act seems significant. You mention chains tapping into EURe liquidity on Gnosis — but isn’t Gnosis’s problem the reverse? It needs access to mainnet liquidity more than it needs to serve as a source of it.

There’s also a security asymmetry. In the EEZ model everything routes through Ethereum, so every interaction rests on Ethereum’s security. In a mesh, each interaction depends on the security of whichever chain you’re interacting with, and those guarantees can differ greatly. That becomes an open-ended series of security judgments — and eventually a burden you have to translate to the user.

You’ve also argued that if Gnosis is going to build on Ethereum, it should use Ethereum’s sequencer, and stay more decentralized that way. But wouldn’t that mean slowing down to a 12-second ordering cadence, when the proposal is going the other direction — from 5-second blocks today to 2? That seems like a real cost, and one users would notice.

This discussion also reminds me of Cosmos, which I only followed from a distance. As I understand it, Cosmos set out to be the horizontal mesh model, but the Cosmos Hub ended up becoming a hub anyway, largely through economic gravitation rather than protocol design. Which suggests the outcome isn’t determined only by the technical capabilities of proof-meshing, but also by economic forces and by the risks people perceive — or fail to perceive.

So maybe Gnosis is indeed being conservative here. But I’m not going to be the one to say they’re wrong.

PS — writing as a curious user of Gnosis products rather than anyone with a stake in the outcome.

4 Likes

Hi @Joera thanks for the thoughtful pushback. These are good questions to ask, but looking at them solely through the lens of Ether short-term dynamics misses the critical architectural trade-offs Gnosis would be forced to make.

Here is what the EEZ/Based Rollup model actually forces on us, and why the meshed prover model is fundamentally superior:

Displacing Gnosis’s Validator Set & Paying Unnecessary Rent

The EEZ model requires sovereign chains to become L2s, meaning block sequencing is outsourced to Ether’s L1 proposers.

For Gnosis, this is the destruction of the validator ecosystem. It directly prices out (they NEED new hardware) and marginalizes Gnosis 100k+ independent validator set, stripping away their role in block ordering and local MEV capture while forcing Gnosis users to pay baseline settlement rent to Ethers validators. Why dismantle one of the most resilient, decentralized validator sets in the entire industry just to pump Ether’s L1 fee market?

A proof-meshed architecture allows Gnosis to tap into Ether liquidity asynchronously via trustless ZK-bridges and intent-driven solver networks without surrendering our base-layer economics or sacrificing our validators.

The Multi-Hop Reality (12s Settlement Beyond Ethers Silo)

It’s easy to look at Based Rollups and think they solve settlement latency, but that 12-second settlement window is strictly confined to the internal tree of Ether. The moment an EEZ rollup needs to interact with anything outside the Ether L1/L2 ecosystem, the illusion shatters, you are back to traditional, slow, risky bridging.

With meshed provers, 12-second cross-chain settlement works across multiple hops on completely sovereign chains. You get cryptographic validity proofs verified natively across distinct state machines within the same block window. That is something Ether’s hub-and-spoke model simply cannot provide natively without forcing everyone into its silo.
(Which btw. won’t ever work. It’s Quantum Physics. You cannot collapse all waves all at once.)

The Composability Trap: Trees vs. Webs

Based Rollups only allow composability within their specific anchored ecosystem (the L1 → L2/L3 tree). If Gnosis becomes an Ether Based Rollup, it builds a walled garden that restricts fluid composability exclusively to the EVM/Ethereum stack.

Cross-chain proof meshing is a physics problem, not a political one.

True cross-chain composability doesn’t care what language the state machine runs. You can compose seamlessly with systems running WebAssembly (WASM), Solana (SVM), or parallel EVMs. As long as the math checks out and the ZK validity proof can be verified within the block window, the execution is valid.

Scaling the inner manifold (what rollups do) is pointless if you cannot scale the outer topology. A mesh network scales horizontally across any chain willing to verify a cryptographic proof, the EEZ tree chokes the moment the root L1 gets congested.

I’ll step back from the thread here, as this is getting pretty exhausting. It’s frustrating when the focus of governance repeatedly drifts toward short-term TVL extraction and Ether alignment rather than foundational design choices and long-term network sovereignty.

Building on modular, proof-meshed sovereignty manifolds is simply resilient system architecture. Giving that up to become a dependent spoke in someone else’s hub is a massive step backward.

/e
I would like to remind everyone. Whatever “the DAO“ decides.
Ultimately: The Validator have to trigger the switch.

2 Likes

As a validator, I still think this is an exciting change and supports the idea, despite having to shut down and give up my validation node. The idea with running a copy of Ethereum’s proof-of-stake was interesting, but did anyone really care? The old time Xdai chain (before Gnosis) that used a much smaller validator set provided a similar service to end users but much cheaper I guess. Moving to the EEZ to improve bridging experience and save operating costs is a double win. User expercience is important, a faster than 12 sec block time on the EEZ Gnosis chain is also important I think.

So, will the change attract new or existing services to the chain?

3 Likes

Thanks Fredericke for putting together this detailed proposal. Being fundamentally attached to decentralization for all its benefits, this change in Gnosis Chain overall structure brings some questions.

  • Will there be a mechanism similar to OP’s forced inclusion which will provide an escape hatch in case the (now) centralized sequencer censors transactions? What would the reasonable delay be (24hours as in Base case, 72 hours as for arbitrum?) for a TX censored in the L2 to be forced included via Ethereum mainnet?

  • Will the bridge still play the role it has today and continue to act as the source of all xDAI?

  • Regarding the EEZ, the synchronous composability seems nice on paper, but how are txs which may modify state of both chains be guaranteed that both state changes are finalized? What would be the actual finality for this type of txs (give the 2s/12s discrepancy for one).

Looking forward to answers which will help determine what to build in the future!

7 Likes

Thanks @ernst for the reply but I think my original question is still not resolved. I was not asking about tradeoff itself. I was asking for clarity on the destination.

In the proposal, it reads like stronger guarantees might come later . In your reply, it sounds like centralized sequencing (with discretion) is simply required. These point in different directions.

So concretely: Is the current model (centralized sequencing) the intended steady state, or not?

Also, related to what others raised - if this is the model, is there at least a clear forced inclusion mechanism as a baseline guarantee? Because without that, it’s not just a tradeoff, it’s a fundamentally different trust assumption.

Right now it’s still unclear what direction you are actually pursuing with this GIP.

2 Likes

I will be honest and say what many here think: it feels like you are just spamming every thread at this point going on tangents.

Many people here are trying to seriously think through tradeoffs and give constructive input. When replies don’t address specifics and just add noise, it becomes hard to have productive discussion (as founders point out).

Maybe better to focus on fewer points, but engage with them more directly.

9 Likes

Yes, of course there will be checklists, but very short response here:

Chain ID, account addresses, token addresses stay the same. RPC endpoints may change (depending on which provider delivers the best service, but this has also periodically changed in the past.

If you want your wallet to be EEZ aware and not Gnosis-only, there will be some UX questions, for instance: How do you display balances a user holds on different EEZ networks? As one balance? Or do you list them separately? Etc.

1 Like

Thank you for your support – honestly, the validator response has been great overall despite the fact that this means the end of the validator set in this form at least. I so appreciate you and we’ll try to find ways to leverage you.

That’s the hope. Our BD team is currently speaking with different potential design partners, but it’s a bit of a chicken and egg problem, we can’t really sell this before the DAO hasn’t given a green light!

4 Likes

Yes, forced inclusion is a must – we don’t have the specification yet, so delay isn’t decided yet. Forced inclusion will not be present in the first version at the end of the year (engineering complexity), but firmly on the roadmap.

This is a good question, we will have to decide what to do with the fee token. It needs to remain USD pegged for technical reasons, so can’t use GNO instead, but we could either also upgrade to USDS, keep Dai, or use another one completely (GHO etc). But one way or another, the fee tokens needs to be bridged, you don’t want to touch Eth state every time you pay for a tx, that would defy the purpose of having a rollup.

Yes, this is the crux. Every chain in the EEZ needs to acknowledge that it will follow Ethereum’s lead in case of a reorg, you cannot technically have two chains synchronously compose if they have strict parity here. If Ethereum reorgs and the cross-chain tx was affected, the follow chain (in this case Gnosis) is forced to reorg too. Practically this won’t matter often because the transaction usually will just be included in the next block unless the tx is no longer valid for instance because it touched on state that changed from under it (eg trade against an AMM). These reorgs happen on Ethereum around 5-10 times a day. Deeper (i.e. two or more block) reorgs haven’t happened in many years.
So follow-chains finality is bounded by Ethereum finality. We’re petitioning the EF for faster (or ideally single slot) finality, and it looks like that may be coming sooner rather than later, but for now if Ethereum reorgs the follow chains have to be able to potentially reorg too.

As to block times: Gnosis will have 2s block times compared to Ethereum’s 12, so it will build 5 non-composing blocks between each pairl of blocks that compose with Ethereum. Ethereum only builds a block every 12 s, there is no way to compose more often than this. Crosschain tx consequently will have to wait for the next Ethereum block.

1 Like

The sequencer will be centralized out of technical necessity. It’s possible that in due course we can decentralize it while still retaining fast blocks, then this is definitely something we will evaluate. At this point I cannot promise it.
Let me explain why it’s difficult: for a block to be validated by the whole network three things must happen: The block is propagated through the network (first 1/3 of block time), attestation is propagated (second 1/3 of block time), and the aggregate is propagated (third 1/3 of block time). Speed of light in a fiber optic cable is 2/3 * speed of light, so 200k km/s. This means going to your antipodean point and back (40k km) will take you 200ms.
How many hops do you need for gossip to propagate? An Eth node has 8 peers essentially chosen by random, which means you need 4-6 hops to reach most nodes. Nodes have to receive the package, validate it (!) and send it on, so if you factor in 100ms travel time + 50ms validation time per hop you come out at a bare minimum of 900ms. This you need three times (once more for attestations and the final time for the aggregate). And here I’m assuming that there are no bandwidth issues (bandwidth has also historically gone up by 50%/ yr, it’s one of these Moore’s law like things).

You CAN optimize this if you don’t have a random gossip network but a well known list of participants. This may not give you the level of decentralization that several thousand distributed nodes give you, but it is much less centralized than a centralized sequencer. So there is middle ground and we are absolutely down for exploring what can be done!

In the first version, there will be no forced inclusion, but this will be added asap.

I hope this answered your questions?

2 Likes

I’m moving this proposal to phase 2!

6 Likes

Thanks, this clarifies the core compatibility questions.

From a wallet UX perspective, I think balances should initially remain separated by EEZ network so users can clearly see where assets and transactions reside. An aggregated portfolio view could still show the combined value, but presenting everything as a single balance may create confusion around available liquidity, fees and transaction routing.

The RPC changes and eventual wallet/integration checklist will be especially useful to communicate early.

SORRY, I though I’d replied to everyone, but I missed you!

I think we’re talking about two different things here:

1 – does the EEZ architecture make sense for augmenting Ethereum.

You said that Ethereum will scale enough on its own so that it doesn’t need the EEZ. I disagree – I also see how much Ethereum can scale on L1, but I think A) even if it does, it may still not be enough if it becomes the economic operating system of the global economy, and B) there are some things Ethereum is not well suited for [privacy, safety nets for users etc].

2 – does it make sense for Gnosis Chain to move into the EEZ.

I think there are some misunderstandings here: Gnosis Chain will eventually also have forced inclusion is some shape (not at the end of the year, but it’s firmly on the roadmap). This is not the same level of censorship resistance as Ethereum though.

I also think there needs to be risk level management on the dapp level, but I don’t think this is enough at the moment, evidently, systems are still nor hardened enough.

I think this is the one point where we fundamentally disagree – but the beautiful thing is that no one is forced to be on any specific network, you can pick the one that is commensurate with your risk appetite. And I would wager that a lot of web 3 users would trade off some CR for some more security.

2 Likes

Hello,

Would it be productive to create a space for discussion on a future purpose for the validator set? It is an asset worth a specific effort, more than being a downside to the EEZ proposal. Its not just infrastructure, its people, community, as well as an important factor in GNO economy, although that cuts many ways.

It could start with a transparent assessment. How many unique validators are there, honestly? What can be said about distribution, value, etc? There is many Gnosis data hidden deep inside Dune. Can someone from Gnosis dig that up, present it?

Followed by an informed guess what part of that set would remain, provided APR would drop to something sensible (3%?), and node runners would have to install other software, etc .. It’s worth doing a survey, ask the largest contributors. What would be the maintenance cost of that set?

Mentioning ‘perhaps the VPN’, means Gnosis will be making these calculations. Doing it openly could help communicating a possible transition and perhaps even yield some unexpected good ideas and alternative options from the community. It’s obviously the smartest validator set in the world. :wink:

6 Likes

Hi @Joera. Yes, I encourage you to start a space/thread discussing roles for validators. I believe actively participating in Gnosis DAO governance and this forum is one of these, so I’m pleased with the level and amount of engagement lately!

How many unique validators are there, honestly? What can be said about distribution, value, etc? There is many Gnosis data hidden deep inside Dune. Can someone from Gnosis dig that up, present it?

Much of this data can be found on the Gnosis Chain metrics page, specifically this one here on client distribution. This dashboard is based on transport-level information, similar to data we used for an interesting privacy assessment of P2P validator sniping before I joined Gnosis. TLDR: there are somewhat under 400 individual peers on the network that serve Gnosis Chain information to other peers. Not all of these are validators, but I consider this an upper bound of people who are actively running nodes for Gnosis Chain.

First, it’s important to point out that you can (and should) still run your node when Gnosis Chain transitions to an L2. This will give you local Gnosis Chain state, without relying on RPC providers or other centralized data sources. However, validators in the PoS sense won’t exist in Gnosis’ L2 vision, so those node runners who are currently also validators will sadly see that effort come to an end.

If people are looking for other ways to support the Gnosis ecosystem as a node runner, Gnosis VPN could indeed be a viable option, as @ernst alludes to in the GIP.

I spearheaded work on Gnosis VPN, as outlined in GIP-98 for a PoC, GIP-122 to bring it to market (ongoing) and GIP-127 to set up its legal framework and there are multiple roles that Gnosis Chain node runners and validators can play here.

Recently I demoed Gnosis VPN at Dappcon and made the case for why Gnosis needs a VPN. In brief: all Gnosis products and users benefit from the privacy and freedoms granted by an uncensorable VPN, and Gnosis gains a further stream of revenue and users by tapping into one of the world’s largest software markets.

What that talk didn’t cover is why the VPN needs Gnosis, or rather why Gnosis was chosen as the network where we build this thing. We’ve always known that Gnosis has many caring and engaged node operators who are capable of running crypto economic infrastructure at scale. That’s exactly Gnosis VPN and the underlying network need.

Gnosis VPN leverages the HOPR mixnet for its strong anonymity properties. The HOPR network currently comprises just under 400 peers and is thus of similar size to Gnosis Chain in terms of peers. A HOPR node relays data packets for others, mixing them up to prevent anyone from tracking flows of data. Nodes earn tokens for this work thanks to HOPR’s proof-of-relay mechanism – an innovation in the mixnet space. There is also stake-based earning from cover traffic, a mechanism which provides an additional blanket of anonymity for the whole network. Anyone who is interested in joining that set of nodes can already do so today. Check out our docs for convenient ways of running a HOPR node on a broad range of devices. Like Gnosis, HOPR is friends with DappNode, so validators with DappNodes will find dedicated HOPR DappNode packages in the DappNode store.

That’s the HOPR network. But Gnosis VPN also needs dedicated exit nodes which serve as connectors between the fully anonymous HOPR mixnet and the current internet. In addition to the standard relay rewards, exit nodes earn tokens for making their IP address available for Gnosis VPN users to access the internet, although it should be noted that the reward and risk profiles differ from vanilla node running. I invite people and organizations interested in running exit nodes to get in touch with me to explore possibilities, concerns and requirements.

Ultimately, Gnosis has always built resilient infrastructure and products that empower the individual. Gnosis VPN falls into that category as well and is bringing users, revenue and new use cases to the Gnosis ecosystem in a proven and multi-billion dollar VPN market. I mention these numbers to highlight that the potential for revenue distribution via a network of nodes, operated by the Gnosis community, is a serious one that we need to start building towards now.

Gnosis VPN will officially launch in Q4 but anyone who’s interested can already contact me to test the latest version or learn more about node running.

5 Likes

Goodmorning Sebastian,

Thanks for your support and the all the information. I am happy to curiously partake in the conversations, and even converse about governance, but Gnosis is the governing party. That said, i realized after sending out my previous post, that this is all still a proposal, and i was jumping the shark a little.

The information you provide is very interesting though. The number of 400 individual peers looks a lot more realistic than the number of 100.000+ ‘validators’. Still a valuable community. You also write Hoppr/Gnosis VPN already has around that same number of node runners. Congratulations, if these are not apples and pears perhaps the transition already happened? btw, what is the number of dappnode machines?

Perhaps the really interesting question is what role GNO could play. I was also thinking of Enclave, now Interfold. Aren’t they affiliated with Gnosis? I have no connection, but saw they launched smth this week.

Have a good day, Joera

1 Like

Hi everyone, thank you to @ernst, and the core team for putting so much thought and engineering effort into this proposal. I completely agree that liquidity fragmentation and UX are massive hurdles for our ecosystem, and I really appreciate the team’s drive to solve them.

While I share the goal of improving interoperability, I’d love to gently add a few perspectives to the discussion regarding our long-term strategy, security, and identity:

1. The Liquidity & L2 Adoption Assumption I understand the primary incentive here is to tap into Ethereum’s L2s liquidity and achieve deep interoperability. However, I’m not entirely convinced that major VC-backed L2s (which already hold the majority of the TVL) will adopt the full EEZ framework. They may be hesitant to give up their hard-earned sovereignty and introduce systemic risks just to sync with L1, which could limit the network effects we are hoping for.

2. AI-Driven Security Risks & Technical Debt From a security standpoint, tying Gnosis execution layer tightly to Ethereum L1 means inheriting its technical debt and large attack surface. We’ve seen this year how AI is incredibly effective at finding critical CVEs at scale, even in highly optimized, high-quality codebases like the Linux kernel. Ethereum L1 hasn’t fully faced this AI-driven exploit wave yet. I worry that leaning into EEZ exposes us to a massive, complex attack surface rather than mitigating risk.

3. Gnosis Economic Moat and Validator Community I dislike L2s liquidity fragmentation silos as much as anyone, but I worry about what we lose in the transition. Gnosis’s L1 validator community and sovereign neutrality are core to what gives Gnosis its unique economic value. If we sunset the L1 and transition to an L2, we enter a hyper-competitive market. Without our unique sovereign identity, what would be the primary incentive for a dApp to build on Gnosis EEZ over heavily funded, established L2s?

Perhaps the engineering focus is best spent on making Gnosis the most decentralized, neutral, and secure L1 possible. Interoperability could instead come from L1 zkEVM and trustless bridges, allowing us to avoid inheriting Ethereum’s technical debt while preserving the sovereign identity and validator community that makes Gnosis special. cc: @citrullin

Thanks again to the team for fostering this open discussion. I’m sharing these thoughts out of deep care for the long-term health, security, and unique identity of our ecosystem!

1 Like

Thanks for the tag @zakweb, happy to add some context here, as you’ve raised a fundamental set of questions the entire industry will eventually have to confront.

What does credible neutrality actually mean once this technology hits real-world scale, and what are we sacrificing if we abandon L1 sovereignty?

While we have rough consensus on quantifying decentralization (client diversity, validator count, stake distribution, diverse Block-Builder etc.), neutrality remains far more abstract and frequently misunderstood.

Neutrality as Validator Sovereignty

The prevailing assumption in crypto often conflates neutrality with a libertarian financial wild west. A hostile Mad Max environment where anything goes, and every actor is left to financially fight for survival in a regulatory void. I don’t share that view, nor do I think a global financial stack can scale on that premise.

To me, true neutrality is rooted in validator sovereignty:
(more importantly user sovereignty, but this goes too far here)

  • Base-Layer Indifference:
    If a validator or group of validators in a specific jurisdiction chooses, or is legally mandated, to enforce local rules, a credibly neutral base layer should hold zero opinion about those actions. The network role is purely to provide a stateless, mathematical foundation for state and filter validation, not to enforce a global political ethos.

  • Local Enforcement vs. Global Consensus:
    An action enforced in Jurisdiction A has no bearing on Jurisdiction B. Being restricted in one region does not alter state validity across the rest of the global mesh.

  • Resilience Through Geographic Diversity:
    To have a resilience network, we need a geographically and jurisdictional diverse network.
    Diverse enough that no single state authority can dictate terms to the entire system.
    Instead of treating the validator set as some underground outlaw operators.

Neutrality means enabling sovereign actors to make choices for their own infrastructure, even when you personally or ideologically disagree with those choices. That is how neutrality functions between sovereign nations in the physical world, and it is the only model that allows a protocol to survive contact with international law without sacrificing its base-layer integrity.

Internal Cartels vs. External State Censorship

When crypto insiders talk about censorship risk, they almost always frame it around foreign state actors or external firewalls. But state censorship is explicit, external, and easily routed around by a diverse, sovereign validator set.

The far more dangerous threat to protocol neutrality comes from internal cartelization:

  • Soft Institutional Capture:
    Informal delegate cliques, opaque internal VC structures, and core-team spin-outs don’t need state mandates to exercise control. They use discretionary treasury grants, closed-door voting blocks, and proprietary middleware to dictate who gets funded and which technical paths survive.

  • The Weaponized Shield:
    These cartels routinely invoke pure cypherpunk ideals to block formal accountability, audited data rooms, or structured legal firewalls. By keeping governance rules informal, the cartel ensures that its own discretionary power remains unchallenged while turning protocol treasury management into a closed feedback loop.

Technological Sovereignty and Capital Alignment

On a broader level, and this touches directly on technological sovereignty, we are watching a familiar pattern play out: foundational tech incubated in Europe being absorbed into the financial playbooks of US capital markets.

The European development ethos historically prioritized public infrastructure, decentralized validator sets, and sovereign, credibly neutral base layers. Converting a sovereign L1 into just another L2 sequencer pool surrenders that long-term infrastructure vision in favor of hyper-financialized, VC-driven liquidity capture.

If we treat Gnosis purely as a feeder pipe for American L2 capital rather than a sovereign protocol in its own right, we forfeit the very moat we set out to build. Staying an L1 powered by stateless cryptographic verification and true validator diversity is the only path that preserves both our economic independence and our technical foundation.

@Citrullin this is another off-topic, abstract wall of text that adds nothing to the proposal or to the conversation around it. What it does do is promote your own pending request, this time wrapped in accusations of “internal cartelization”, “delegate cliques” for “core-team spin-outs” aimed at the people building and answering questions in this thread. The moderators have asked you nicely, more than once, to keep your posts on topic.

Keep any further replies here to the substance of GIP-153.

3 Likes

Thanks for sharing your perspectives, and welcome to the Gnosis forum.

Gnosis Chain is arguably one of the most decentralized, neutral, and secure L1s outside of Ethereum itself. I agree that has merit, but unfortunately it hasn’t led to a self-sustaining ecosystem - however strong the dogmatic case for a stand alone L1, the pragmatic realities of operating an onchain protocol, particularly a financial one, mean an isolated L1 isn’t viable without subsidies to sustain liquidity. This challenge isn’t just unique to Gnosis.

To your specific points:

  1. The primary gain for Gnosis Chain is access to Ethereum’s liquidity and asset ecosystem, and every L2 that later joins the EEZ compounds that. You’re right that bringing the wider L2 landscape along is the challenge, but that’s a challenge for the broader EEZ initiative. In the meantime (through the lens of Gnosis Chain) being the only rollup with synchronous composability with Ethereum is a genuine go-to-market advantage, not a weakness.

  2. On AI-driven exploits, staying a sovereign L1 offers no shelter. The whole stack is open source either way, and if anything an independent L1 carries more exposure, given the incentives to exploit contracts and the volume of capital sitting on L1s.

  3. Agreed, it’s not an easy decision, and this is the main downside of the proposal. The upside is being able to call any contract on Ethereum atomically.

6 Likes