GIP-153: Should Gnosis Chain transition into the Ethereum Economic Zone?

  • In Favour
  • Against
0 voters
GIP: #153
title: Should Gnosis Chain transition into the Ethereum Economic Zone?
author: Friederike Ernst with co-authors Philippe Schommers and Ben Carvill
status: phase-3
type: strategic direction
created: 2026-07-22

1. Abstract

This asks GnosisDAO to align on transitioning Gnosis Chain from a standalone Layer 1 into a ZK-proven Ethereum Economic Zone (EEZ) rollup instance that settles natively on Ethereum. This is not a new chain and there is nothing to migrate to: it is Gnosis Chain, now based on Ethereum, inheriting Ethereum’s security and liquidity directly.

The transition ends the treasury-funded staking subsidy in favor of a fee capture from network activity, unlocks synchronous composability with Ethereum mainnet, and positions Gnosis Ltd, co-architect of the EEZ framework and operator of its first instances, at the center of the emerging market for EEZ deployment and services. The first iteration, targeted for genesis around the turn of the year 2026/27, already delivers 80% of the synchronous-composability unlock for around 40-50% of the total engineering effort, and serves as a stepping stone to the full EEZ specification, expected over the course of 2027.

No funds are requested, this GIP seeks alignment on direction. Aligning early on direction gives the engineering team a clear mandate to design.

2. Motivation: a candid assessment of where we’re at

Gnosis Chain has failed to deliver on its original value proposition. The core value proposition when we started was credible neutrality: a decentralized, low-cost EVM chain run by a large set of independent validators. It proved not to be a good one. Credible neutrality is Ethereum’s home turf, and a smaller chain offering the same qualities with less security and less liquidity gives builders and users no compelling reason to come. Without differentiation there is no usage, and without usage the economics do not close.

The numbers make this concrete. Fee revenue covers only a small fraction of even the minimal cost of security, so security is paid for by the DAO treasury, not by the network. Staking rewards are a dilution offset funded by non-stakers, not yield from activity. Ethereum has the same structure, but at a very different scale: its issuance runs below 1% a year and is partly offset by the fee burn, leaving net dilution even smaller. Gnosis dilutes non-stakers by roughly 2.3% a year. And the subsidy does not stop at security: GnosisDAO also carries the cost of the surrounding infrastructure, from block explorers and RPC endpoints to incentives for third-party protocols. Liquidity has had to be bootstrapped and defended in isolation, and network effects never approached mainnet’s. Every standalone alt-L1 pays these structural costs indefinitely; Gnosis pays them without the scale that could ever cover them.

This is not a failure of engineering: the chain is established, credible, and technically sound. It is a failure of differentiation. Becoming an ordinary L2 would not solve this either: the differentiation problem just moves down a layer. Of the over 100 L2s, most don’t have any meaningful usage and the few that do, don’t differentiate technically but through existing distribution channels.

The Ethereum Economic Zone changes the calculus. The EEZ framework makes it possible to keep everything that works about Gnosis Chain while in addition allowing full composability with Ethereum. This dramatically improves Gnosis Chain’s position from a chain where a fraction of what is available on Ethereum is available to a chain where EVERYTHING that exists on Ethereum, including full liquidity for all tokens, is a single atomic call away. Oracles, on- and offramps, and mainnet liquidity venues can be used directly, as if they were deployed on Gnosis Chain itself; even CEX rails become reachable without bridging.

The opportunity, concretely: speed and cost are the easy part. Gnosis EEZ produces blocks every 2 seconds at sub-cent fees, but faster and cheaper than Ethereum is table stakes; most of the 100+ L2s can claim the same. The singular upside is synchronous composability with Ethereum. No existing L2 offers it, and it is the one axis on which Gnosis EEZ competes alone rather than as one of a hundred interchangeable chains.

This upgrade also comes at a price. We give up what differentiated us so far. Synchronous composability in combination with fast block production is currently only possible in a centralized fashion. There is no version of this upgrade that keeps the large independent validator set at the core of the chain. But seeing that we need to go there anyway, we will leverage it: a chain that is operated rather than maximally neutral can be opinionated about security. It can hold suspect transactions and try to protect users from obvious hacks. The past years of relentless exploits have made it plain that adding layers of security where possible is still very much needed.

3. The upgrade

What is EEZ, and what is Gnosis EEZ?

Two things to hold apart:

  • EEZ (the framework) is a way to build rollups that are governed and economically aligned to Ethereum: a credibly neutral public good, with no token, co-led by Gnosis and ZisK, co-funded by the Ethereum Foundation, under Swiss-foundation governance. It is not a Gnosis product.
  • Gnosis EEZ (the instance) is a Gnosis-operated deployment of that framework, with GNO economics and xDAI gas, and the transition path for Gnosis Chain.

How it works

Currently, Gnosis Chain is a standalone L1 with its own validators, its own security, and its own liquidity, often bootstrapped courtesy of the DAO. After the transition, Gnosis EEZ produces blocks every 2 seconds against Ethereum’s 12-second slot, proves its state every Ethereum block, and settles to Ethereum L1, using Ethereum block building for execution. Proving starts pragmatic and hardens over time. The first iteration will use an interim proving setup, likely TEE-based, with the concrete mechanism to be selected during technical specification, and moves to real-time ZK proving as the EEZ specification completes. At full specification the instance inherits the complete security assumptions of Ethereum for finalized blocks, with no third-party trust considerations. In the first iteration that inheritance comes with one caveat: an interim proving setup adds an additional trust assumption until real-time ZK proving lands. The direction of travel only ever removes trust assumptions, never adds them.

The mechanism, per the EEZ core protocol: cross-chain state is coordinated through proxy contracts, state transitions are pre-computed off-chain, and ZK proofs verify them on-chain. Each instance registers with a central EEZ registry contract on L1 and appoints its own set of proof systems with a configurable M-of-N verification threshold (this represents a multi-prover design, so no single prover implementation is a trust bottleneck). Verified cross-chain calls execute atomically within a single L1 block, with rolling-hash integrity checks binding every call to the proof that committed it.

At launch, sequencing is centralized: Gnosis Ltd operates the composer that orders transactions, builds blocks, and submits them for proving and L1 settlement. This is a major design choice with consequences for downstream systems. What bounds the risk: every block is proven and settled on Ethereum, so the sequencer cannot forge state, steal funds, or roll back finalized history. The harm a misbehaving sequencer can do is limited to delaying or excluding transactions. We deliberately make no commitment on the future of sequencing here. We will operate the instance, observe what degree of censorship resistance the ecosystem actually needs, and return to the DAO with evidence before deciding whether to keep, constrain, or decentralize the sequencer. Mitigations such as a forced-inclusion path through L1 are options to evaluate then, not launch features.

Synchronous Composability

The unlock is synchronous composability: a contract on the Gnosis instance can call a contract on Ethereum mainnet and use the result in the same atomic transaction: all of it succeeds or all of it reverts. This is what removes the historic trade-off between app-chain performance and shared liquidity and it is something no existing L2 offers.

It is worth noting that at launch, composability is one-directional. Full bidirectional, cross-instance composability follows, as the development of the EEZ protocol progresses, with an intents-based bridge covering the interim and facilitating atomic bridging in both directions.

Consequences of the transition: the Gnosis Chain validator set is sunset, as settlement security moves to Ethereum’s validators, the bridge validator set is repurposed to operate the provers, and the ~350k GNO currently staked (≈27% of circulating supply) is unlocked. For everyone else, nothing changes. Users and dapps keep their addresses, balances, and contract state with full continuity, xDAI remains the fee token, and infrastructure providers run through the transition unchanged, as no redeployment is required outside of simple updates to a configuration.

We do not take the sunset lightly. Making the validator set superfluous is the main regret in this proposal: a large community of independent validators is part of what made Gnosis Chain special, and that loss is real even where security no longer requires them. We intend to find a new role for this community, potentially in the context of Gnosis VPN, where a distributed set of independent operators is exactly what the product needs.

A note on decentralization: We already touched upon this in Section 2, but we want to be explicit about this: Becoming less decentralized is a deliberate position. Ethereum is maximally censorship resistant, and that is exactly why we build on it: censorship resistance cannot be retrofitted, so it belongs at the base. But maximal censorship resistance is a niche, and a limited one. It is incompatible with most financial applications, which need fraud response, compliance, and recourse. Arguably, users should not interact directly on Ethereum at all. What we expect instead is a landscape of less censorship resistant networks on top of Ethereum that deliver the UX and protections security-conscious applications require, while inheriting the base layer’s guarantees where they matter most: for settlement and cross-zone flows. Ethereum becomes the economic operating system; Gnosis, one of its specialized economic zones.

4. Strategic position

Gnosis Ltd is both co-architect of the EEZ framework and operator of one of its first instances. This dual role is the strategic core of the proposal.

Operating the first production instance gives Gnosis Ltd what no one else will have: proven experience migrating a live chain, operating the composer and prover stack, and building the compliance, privacy, and control modules that regulated users need. That makes Gnosis Ltd the natural provider of EEZ-related services as the framework proliferates. This includes bespoke instances for banks and institutions that want on-chain operations with Ethereum settlement but without building a chain, design-partner builds for FinTechs, and instance operation as a service. The framework is a public good; the expertise to deploy and run it commercially is not.

Revenue for the instance itself comes from fee capture at the prover, priced dynamically by route (L2→L1, L2→L2, complex cross-chain flows). It is a volume game where break-even depends on ecosystem growth, not per-transaction margin. The ecosystem strategy targets the audiences that generate the most cross-domain flow such as DeFi protocols (perps, lending, and solvers that gain atomic access to mainnet liquidity), FinTechs and Neobanks (Ethereum’s reach plus the compliance and privacy a regulated business needs), asset issuers (one canonical asset zone-wide instead of bridged wrappers), and institutional operators, the highest-value, longest-cycle audience and the direct pipeline for Gnosis Ltd’s instance-as-a-service offer.

GTM would likely see the chain be embedded within FinTech products, and as such over time may see an SDK being developed to allow scale. But in the early phases we seek design partners to build key modules that enable products to be compliant, or to be privacy enhanced. Also the onboarding experience will be optimized for both humans and AI agents.

Gnosis Ltd’s own products (Pay, Circles, VPN) anchor the consumer layer and gain same-transaction access to L1’s significant stablecoin liquidity.

5. Economics, GNO & governance

GNO after the migration. The first question every delegate will ask: what does GNO do once staking ends? Today, GNO secures the chain through staking, with rewards paid from the treasury. That is a dilution offset, not yield from real activity. Post-transition the subsidy ends, and value is intended to accrue from fee capture on real network revenue instead. The concrete mechanism of how xDAI revenue is tied to GNO tokenomics is deliberately not detailed in this GIP; routes under consideration include a fee-share or buyback tied to instance revenue. A later-stage GIP will propose a specific design once prover economics are observable in production.

Governance: Currently the DAO does not govern the direction of Gnosis Chain, as the validators operate the network, and it is not possible for the DAO to enforce validators to take action. With the validator set being sunset, governance splits as follows:

  • EEZ governance (Ethereum-led) governs rollup protocol changes, prover specification, and L1-to-L2 messaging primitives. Governed through Ethereum’s processes, meaning EIPs introduced on L1 will be reflected on Gnosis Chain.
  • GnosisDAO governance governs gas token policy for Gnosis Chain, fee allocation, any potential ecosystem treasury, and anchor partner funding. This essentially continues what the DAO governs within Gnosis Chain currently.
  • Prover operation: today’s bridge validators take on a new role. Native L1 settlement supersedes the xDAI bridge and its validator committee, but the operators themselves are not discarded: the intent is for bridge validators to run the instance’s proof systems, shifting from validating the bridge to proving the chain. This keeps a known, accountable operator set inside the security model and gives the M-of-N multi-prover design its initial operators. How prover appointments are governed longer term is specified at the second-stage GIP.

6. Budget and timeline

Budget requested: none. The R&D contribution required to scope the Gnosis instance specifically has so far been funded from within the existing GIP-128 envelope. More resources will be requested within the framework of the GIP-128 successor proposal; that funding need exists regardless of whether the EEZ transition happens. The overall infrastructure budget should reduce in the mid term with the EEZ Gnosis instance.

Timeline: genesis targeted for December 2026/ Jan 2027 (validators sunset, first EEZ block produced), conditional on the broader EEZ dependencies landing by summer 2026. Full EEZ specification, including bidirectional composability, nested calls, and real-time ZK proving, is expected to land over the course of 2027. The framework runs on a working devnet today, including end-to-end cross-chain execution.

The first iteration of the Gnosis EEZ instance will already deliver 80% of the synchronous-composability unlock available today, for around 40-50% of the total engineering effort. Much more will be possible in the future when dapps are designed with EEZ interoperability in mind. Gnosis Chain will use the first iteration (atomic L2→L1 calls, interim proving) as a stepping stone to the full EEZ specification while already reaping part of the rewards on the way there.

7. Conclusion

Gnosis Chain as a standalone L1 has run its course. The EEZ transition keeps the chain, its users, and its applications, and upgrades the foundation underneath them: Ethereum’s security inherited every block, mainnet liquidity accessible in a single transaction, a security budget funded by revenue instead of dilution, and Gnosis Ltd positioned as the reference operator in a new category of Ethereum-aligned rollups.

GnosisDAO is asked to commit to the direction, not to a final technical design. Alignment now gives the engineering team a mandate to design against and the ecosystem team a green light to begin partner conversations in earnest.

21 Likes

Immensely bullish about this. It was always weird to me to have Gnosis be so Ethereum aligned as a company, but not actually contribute directly to the network. I also found Gnosis to have huge bridging/ecosystem problems (one of may main problems with the Gnosis App), and only recently bridging has become a bit less painful

Plus, this move worked out well for Celo!

8 Likes

lol, no.

How about instead of pivoting Gnosis Chain into a centralized, operated EEZ instance with a centralized composer, we focus on fundamental optimizations like a stateless chain and sovereign executions?

It’s already bad enough that Vitalik and the EF L1 core devs aren’t pushing aggressively enough to clean up the existing execution and state bloat via “the Purge”. Do we really need to drag Gnosis Chain into this as a based rollup experiment now?

If the goal is pushing based rollup architectures forward, why aren’t we just actively supporting and helping Taiko advance their stack instead of re-architecting Gnosis Chain’s entire validator model?
Wouldn’t that be in the true nature of open source ecosystems? To support fellow DAOs/teams?

Furthermore, we need to explicitly address splitting off from Ether economically rather than entangling ourselves deeper. You never want a based rollup or instance to become larger or more dependent on the mainnet it is anchored to, it completely destroys sovereign positioning and locks you into L1’s friction forever. Being exposed forever to pure extraction mechanisms.

So. . . lol, no.

whats centralized about this? you can decentralize the l2 sequencer

and w/ enough users/apps, you can decouple, if you ever want to (you shouldnt). it’s not that big of a lock in.

Lets go full speed..mega bullish

The idea that “you can just decentralize the L2 sequencer” and “decouple later” completely ignores the reality of the architecture, the economic gravity, and the regulatory baggage we would be inheriting.

1. The Centralization & Compliance Trap
We aren’t just adopting code. We are inheriting an architecture dictated by an EF that is currently a regulatory shitshow, especially from a European perspective. Look at the recent EF spin-outs under MiCA through the lens of “Substance over form” these are highly questionable. Furthermore, the main research hub for this (EthResearch) is heavily gatekept. Try discussing Quantum Social Physics there and watch how fast you get shadowbanned by a leadership tier that includes Virgil Griffith. Do we really want to permanently anchor Gnosis to a stack driven by a group carrying that kind of US-sanctioned compliance risk?

2. The Sequencer & MEV Reality
Decentralizing a sequencer doesn’t solve the core issue: a based/L2 setup hands MEV on a silver platter to a tiny oligopoly of centralized actors who have the infrastructure to fill orders across all chains. Contrast that with Witness Proofs, where you can theoretically handle cross-chain execution natively without funneling everything through a centralized composer.

3. Economic Lock-In and the Kickstart Illusion
Saying “it’s not that big of a lock-in” because you can “just decouple later” ignores our context entirely. Sure, if you are launching a brand-new chain backed by a Web2 giant, like Robinhood, an L2 is a great way to kickstart. They have an entire stock exchange attached to them and the external leverage to eventually spin out. But Gnosis is not Robinhood. We are not a new chain. We already have the ecosystem, which is the hardest part to build in the first place.

Transitioning an established L1 into an L2 completely reverses our leverage. Using ETH as the gas token structurally pushes our existing economic value away from Gnosis and towards Ether, turning us into a fee-extraction tributary. Without a massive external corporate engine like Robinhood’s to force a decoupling later, Gnosis would be permanently locked into Ether’s friction.

4. Cannibalizing Taiko
If the goal is to push based rollups and the EEZ, why are we forcing Gnosis to be the massive test ground? Taiko literally invented this tech stack. Having contributed a bit to Taiko myself, I can tell you firsthand that it introduces a some amount of complexity. Let Taiko lead the EEZ. It’s their natural development. Forcing Gnosis to re-architect just sucks the energy away from them.
Scaling the inner Manifold is interesting and important in the long run. We are in the middle of a Topology collapse. Maybe that’s something Gnosis could be focus on.

5. The Sovereign Manifold Alternative
Why sacrifice our sovereignty just to be Vitalik’s testbed to make Ether look more appealing? Tempo is already pushing in a sovereign direction (albeit in a corporate way). I don’t see a reason why Gnosis shouldn’t pick up on this trend and lead the way in true Sovereign Manifold technology. We cannot out-decentralize the physical stack we are on, but we can bring the backbone of the Internet stack on-chain transparently.

Instead of bloated rollups, we should be building:

  • Stateless Witness Proof chains, which enable parallel execution and finally remove the EVM single-thread execution lock.

  • Native Identity & Infrastructure, grounding everything in did:peer documents where you can prove and derive all keys from one seed. This creates a decentralized alternative to ICANN and DNS, removing the rent-seeking nature of centralized registries like ENS.

  • On-chain Accountability, utilizing SIWE + OIDC mappings tied seamlessly into the DAO service companies internal toolings. The DAO pushs collective proofs on-chain and make the DAO and DAO service companies actually auditable.

  • Network Resilience via DAS on IPFS, on-chain BGP negotiations, and direct low-latency P2P fiber peering.

Why would we give all of this up for Ether? A chain that doesn’t even want to remove its own state bloat, even though Vitalik has a billion dollars (and probably more) in funding to actually make it possible. Reth is actually moving in the right direction with ress, which is exactly what I am advocating for here. I don’t see a reason to full-on roll over and surrender our independence to the EF’s bloated mainnet when we can achieve this ourselves and support the right engineering teams.

Idk, this feels to me like a better approach than aligning more with a vision that doesn’t really have much appeal besides: "Well, Ether is large”. If Gnosis becomes just another rollup, what is the actual selling point?

2 Likes

Conceptually this seems to make a lot of sense as the next step for Gnosis Chain. As builders on the chain we love it for many reason but one of the difficulties at times has been the composability with certain tools that sometimes don’t support Gnosis Chain presumably because they ask for high fees to integrate new chains.

One thing that would help translate the technical achievement of the EEZ as described would be some kind of demo that shows how that would alter the actual UX of using Gnosis Chain. This would maybe help people understand the benefits of the EEZ more concretely.

4 Likes

@Bread.Cooperative

a view very concrete examples relevant to a project like yours:

  1. With EEZ: Anyone with funds on Ethereum can e.g. buy/bake “bread” with a single tx from Ethereum. This tx could directly trigger things on Gnosis (like buying/staking/ bread)

So generally you will no longer need a dedicated wallet with xDAI on Gnosis - anything than can be done on Gnosis can directly be done from any mainnet wallet.

The same if true for the other direction: Anything that can be done on Ethereum can be done from a Gnosis account. So, e.g. you can hold Bread on Gnosis and with a single tx swap this into another asset on Ethereum and send this asset (lets say USDC to e.g. any CEX or offramp service that accepts USDC on Ethereum)

More examples: you can read any price oracle on Ethereum directly from Gnosis. You can use protocols (e.g. register a name) on ENS or .wei again, directly from a Gnosis wallet.

5 Likes

First, thank you for putting this proposal together. It is clear that a lot of thought and engineering effort went into it. Scaling Ethereum while preserving its core properties is not simple problem, and I appreciate the willingness to tackle difficult trade-offs directly.

I have read the proposal twice, and I am still not sure I understand the intended destination.

Since this is a directional GIP, I think it would help to describe the expected end state more explicitly. As I understand it, the first step is for Gnosis Chain to become an L2 where several important roles are performed by Gnosis Ltd. Is this only a transitional phase, or is this the long-term model?

On one hand, the proposal says:

The first iteration of the Gnosis EEZ instance will already deliver 80% of the synchronous-composability unlock available today, for around 40–50% of the total engineering effort.

This made me think stronger decentralization guarantees, including censorship resistance, would come later.

But then I read:

It can hold suspect transactions and try to protect users from obvious hacks.

This seems to imply that Gnosis Ltd. is expected to retain discretion over transaction inclusion. Is this intended as a temporary capability, or a permanent feature of the architecture?

2 Likes

Gnosis Chain failed at credible neutrality because its bridge is validated by a 4/7 multisig and its beacon chain deposit contract is upgradable by a 8/15 multisig, not because the chain is smaller. This is absolutely a failure of engineering, in contrary of what the post claims.

I disagree that EEZ is an obvious differentiator, as synchronous composability is already trivial between contracts on L1, and Gnosis Chain would compete with it directly with a more complicated solution for little benefit for the end user vs just using L1. It would have made sense in a world where L1 wouldn’t be scaling, but Ethereum will increasingly get faster and cheaper, with a 3x gas limit increase already coming in Glamsterdam and more being expected in the future.

I fundamentally disagree with the proposal of adding censorship to the chain. As shown here, Gnosis Chain is today one of the few chains out there with an incredibly fast time to inclusion guarantee, even faster than Ethereum given the huge validator set and the short block times. It would be a great loss to remove such feature, even temporarily, given there is no guarantee to ever get it back. The claim that “users should not interact directly on Ethereum at all” is very sad in my opinion as I think that censorship resistance should be the norm and not a niche. Moreover, the vast majority of the 100s of L2s already mentioned as not having meaningful usage target the same institutional and regulated use cases via the same proposed centralized solutions.

I don’t understand what “EEZ Governance (Ethereum-led)” means. Is the expectation that ACD would decide on contract upgrades via hardforks? If yes, this is completely unrealistic. Gnosis Chain would either be governed by a multisig or a DAO and this needs to be decided beforehand.

I remain skeptical of the effectiveness of EEZ in bringing synchronous composability with contentious state on Ethereum. Based rollups are an old research topic and so far all teams that tried it failed at achieving meaningful coordination with L1 builders. It’s unclear how the same problem is solved here and it’s a huge technical risk to commit to EEZ before proving its effectiveness first.

3 Likes

I didn’t look at it from that angle until reading your comment, but it makes total sense.

If cross-state execution is fundamentally just stateless verification, where off-chain provers run the execution, generate a zk validity proof, and submit it alongside proxy calls, we get synchronous composability without needing permissioned sequencers, preconf markets, or multisig backdoors.

In fact, we could treat the proxy contracts as a core compiler design principle in core.
You call contracts 7 chains away and to the developer it just feels like one unified chain.

Is that the point you’re making? That wrapping Gnosis Chain in a based rollup architecture is basically over-engineering something L1 execution and stateless proofs already handle natively?

1 Like

So the EEZ is completely agnostic wrt how the blocks are built, so this is orthogonal. What comes later is mostly nested calls, that is calls going back between different zones in the EEZ multiple times in a single transaction.

Just to be super clear here: You cannot have fast blocks AND synchronous composability with Ethereum AND decentralized sequencing. You have to pick two. We’re also building a reference implementation for the EEZ called Rollup 1, which will have 12 second block times (like Ethereum) and be based in the sense that Ethereum validators build the Rollup 1 blocks, there is no separate sequencer. 12s blocktimes (and potentially more if you don’t get into every block) simply doesn’t work for many applications. It’s the credibly neutral solution though and extends Ethereum at a cheaper cost without additional security assumptions.

Let me turn around: There needs to be a centralized sequencer for technical reasons. Ofc you can take the stance that this needs to be unopinionated (and you can actually force this by encrypting transactions and only decrypting them once they’re already commited on chain). This is up for debate. I would take the view that if you have the power to intervene in something that is clearly malicious (say, an old lady gets robbed at gun point in the town square) you should, even if you always have the risk that you may have misconstrued the situation (the old lady is really actually the bad guy in the scenario and the supposed robber just wants his own bag back from her, or they’re in a theater performance or it’s just a grandma and her grandson horsing around), you can right it later. I would never argue that 1) Gnosis should take on compliance functions – we will not do AML or KYC or anything like this on some else’s behalf or 2) Gnosis should be the ultimate dictator here with no recourse. OFC there needs to be recourse and you need to be able to eventually get your tx through. I’m talking about OBVIOUS hacks – and we’ve already placed ourselves in the position with the balancer hack. We used social coordination among the validators to censor the hacker. It only worked because the hacker dealt with other chains first and we had the time, but I’m happy those 20 million weren’t stolen from users! So say a contract has an infinite mint bug or there is an exploit discovered in aave v3: I think if we have the power to intervene, we should. There is clearly the question of where to draw the line, but IMO just saying “we’ll never intervene because then we don’t have to have policy when to intervene” is a pretty bad cop out.

2 Likes

Just a quick clarifying note from the Gnosis VPN committee:

The GIP accidentally states that Gnosis VPN is a Gnosis Ltd product, which it is not. It’s funded by Gnosis DAO under GIP-122, which is why Gnosis VPN doesn’t appear in GIP-128 and the related reports. It’s controlled by Maelcum Inc, a separate entity set up deliberately to provide separation from Gnosis Ltd, and currently overseen by a committee of members drawn from Gnosis Ltd, HOPR and Gnosis DAO. However, Gnosis VPN does gratefully receive some devops and legal support from Gnosis Ltd, as laid out in GIP-122. Full technical, legal and governance details can be found in GIPs 122 and 129 and the associated update reports.

We are of course deeply proud that Gnosis VPN is a Gnosis ecosystem product (it’s in the name!), but a lot of work has gone into creating this separation, which works to protect the DAO, Ltd and the VPN, so we want to make sure GNO holders understand it.

If current Gnosis Chain validators are interested in learning more about Gnosis VPN and running exit or relay nodes, please reach out to us at support@gnosisvpn.com. We’d be delighted to show off the VPN and explain more.

5 Likes

Hey Luca, thanks for chiming in!

Acknowledged – we took steps to decentralize the bridge (light client bridge client built by succinct before they became a thing, Gnosis was the first instance) + Hashi. It added costs and latency and ultimately we abandoned these.

Blockspace on L1 has become cheaper and will continue to become cheaper. In my mental model there are three fundamental constraints: 1) state, 2) compute, and 3) networking. You are absolutely right in that we can scale L1 way beyond where it’s currently at, first with trivial upgrades (gas limit increase, block time decrease), then with statelessness, and with parallelizing compute. Where we will see an actual physical boundary at some point, is networking. There is only so-and-so much data you can move around between tens of thousand nodes in the 12 (or maybe then 6?) seconds for building the block.

My assumption is that Ethereum is going to be the economic operating system of the world and even if we can scale the blockspace efficiently, it will remain a scarce resource. We will have to make tradeoffs too – what are the minimum bandwidth and hardware requirements you can expect from a validator? Should they remain as easy to run as they are now, or should we move into solana territory? I have sufficient ETH and a 1000 Mbit line at home and a top of the line dappnode, I can run an Eth node myself easily and could so the same with 6 seconds blocks and 3x gas limit, but I absolutely cannot run a solana node.

That being said, where I see the advantage of the EEZ is that it allows chains that are different from Ethereum itself and make different tradeoffs to synchronously compose with Ethereum. We’re also building Rollup 1, which will be as close to Ethereum as possible (12s blocks, fully based) – but many applications need fast block times or other features Ethereum doesn’t natively support.

Gnosis Chain can have 2 second block times (and thus be forced to forgo the censorship resistance of Ethereum) and still synchronously compose with Ethereum in every block that has an Ethereum counterpart (so think 5 non-composing Gnosis blocks between every composing block). You can also be fully private. Aztec could synchronously compose with Ethereum, the design is purely call-based and works for non-EVM based chains too. You probably don’t want to do all your compute there, but having some functions on aztec? Game changer! By the same virtue, you can have permissioned networks join, you can have networks restrict which kinds of calls in and out they permit etc. IMO this permissiveness is what makes EEZ interesting for other chains to opt into. This architecture will drive the adoption of Ethereum as the gloabl economic operating system, for which Ethereum is uniquely suite exactly because of it’s censorship resistance. CROPS at the base, opinionated zones on top.

I value your feedback on this, but how would you tackle the security aspects? You think retail should just raw dog it on aave and eat the losses if they’re scammed/ they fat finger/ the contracts get hacked? IMO this simply doesn’t work, there needs to be some sort of user protection possible, or this is going to remain niche.

There is going to absolutely minimal governance. Ideally there should be none at all and the EEZ should just be a non upgradable smart contract. We haven’t worked out the exact scope yet, but this is the goal.

1 Like

Bandwidth will to be solved by posting blocks in blobs. See EIP-8142: Block-in-Blobs (BiB) and Blocks Are Dead. Long Live Blobs.

The L1 zkEVM upgrade will allow both to scale throughput and allow for cheaper nodes (succinct verification instead of tx replay, data sampling instead of full downloads). ZK is the solution to the scalability trilemma for L1 in the same way it has been for L2s so far.

I don’t understand how losing censorship resistance follows here. For example, OP stack allows for forced transactions to be included in the same L2 block that corresponds to the L1 block that includes it and they have a 2s block time.

This seems to be out of scope. The discussion here is on whether Gnosis Chain should transition to EEZ. Unless Gnosis Chain plans to become a private chain like Aztec, which is a change I would welcome!

I believe applications should implement their own mitigations rather than delegating them to a centralized entity that can misbehave. So for example, Aave itself should implement their own rate limits and security councils if they deem them necessary, so that if they misbehave their impact is contained to only their application and not everyone. Motivations are analogous to the mass surveillance vs local surveillance debate (e.g. see the recent Flock drama).

4 Likes

I see a future for on-chain communities that take a purist, decentralized approach to their stack, built on open source and idealism. However, these communities will likely number only in the thousands of people. Their liquidity and native token market caps will be a fraction of what Gnosis Chain has today. In such communities there can be paid roles for core developers, but no grants and project funding. That model was always predicated on a bet on mass adoption.

Gnosis has had too much capital involved from its inception to pivot toward a niche community existence. At its current size, maintaining the status quo without scaling is unsustainable. Since there is no realistic scenario where Ethereum fails and Gnosis succeeds, the only viable path forward is to bet entirely on Ethereum succeeding.

We are young as an ecosystem, but we already have legacies: baked-in expectations and value embedded in projects that cannot be ignored. Existing projects that have long proclaimed to pursue mass adoption must now make the necessary compromises to actually get there, or face significant deflation.

We can still build on-chain communities on a purist stack if we wish, but these must be entirely new endeavors. In these spaces, users will need to pay their own way, and the monetary value involved will be modest.

To DAO advocates, I want to say: please stop chasing treasuries filled with value created before the DAO existed. Instead, build a community that creates value from scratch and manage that as a DAO from inception.

We have come very far on a mix of self-interest and idealism, but that mechanism stopped working a while ago. Now, they’re just riding into each others wheels. As the broader ecosystem matures, the other opportunity lies in channeling our idealism into these new, independent communities.

I appreciate @Joera’s candid post regarding the tension between long-term sustainability, treasury management, and pure decentralization. It raises a core question many ecosystems face:

Must an established project make heavy compromises on sovereignty and censorship resistance to achieve scale and mass adoption?

I’d like to offer a perspective grounded in system architecture that suggests we don’t actually have to accept that trade-off.

Is Decentralization Inherently a Niche?

The assumption that maintaining a sovereign, highly decentralized L1 base layer restricts a network to a “niche existence” was reasonable under older execution models. However, as @donnoh highlighted in his response, modern L1 scaling research has fundamentally decoupled throughput from hardware bloat:

  • Decoupling Availability from Storage (EIP-8142 / Block-in-Blobs):
    Transaction payloads are encoded in ephemeral blob space and verified via Data Availability Sampling (DAS). Consensus nodes don’t need to permanently store or download entire execution histories, they only store the root delta consensus, allowing historical archive burdens to be offloaded off-chain (IPFS/Filecoin clusters, local RPC indexers, sovereign Manifold).

  • Succinct Verification Over Re-Execution:
    Transitioning toward zkEVM validity proofs and statelessness means nodes verify lightweight cryptographic proofs in milliseconds. Node operation remains cheap and accessible to home-stakers even as block gas limits scale aggressively.

True decentralization is an unique value proposition that underpins credible neutrality.
If anything it’s a selling point to make the technology widely adopted.

Protecting Users Without Sacrificing Base-Layer Neutrality

Often, the “compromises” discussed for mass adoption involve protocol-level controls or centralized sequencers to manage risk. But as @donnoh pointed out:

Application-layer security (smart contract rate limits, dApp-level circuit breakers, or application security councils) allows retail users to be protected without degrading the base layer’s permissionless guarantees. Mass adoption and consumer safety can be achieved cleanly at the application layer while keeping the underlying protocol neutral.

Preserving What Gnosis Has Already Built

Gnosis doesn’t need to start over from scratch to remain purist, nor does it need to surrender its L1 sovereignty to scale. It already possesses one of the most geographically diverse, resilient validator sets in the entire Web3 ecosystem (100k+ validators).

By pairing that validator set with modern L1 primitives, stateless verification, ephemeral payload availability, and application-isolated risk models as discussed, we can achieve the throughput needed for mass adoption while fully preserving the sovereign, censorship-resistant base layer that gives Gnosis its value in the first place.

Idealism and economic scale are no longer mutually exclusive. Cryptography has given us the tools to have both. We can separate the concerns easily, bypassing CAP entirely by simply splitting it into two distinct domains.

2 Likes

Hello Citrullin, good to meet you.

As I understand it, EEZ is more about improving composability, of liquidity among other things—rather than scale. Gnosis has plenty of blockspace as is. And I honestly don’t know if the solutions you advocate also address the liquidity fragmentation. You’re deeper into the technicals than I am.

And yes, I will miss my validators, assuming they will be slashed under this proposal. Pun intended. Validators matter a lot, not least as a social vector, tying people to the Gnosis ecosystem, being one of the easiest ways to experience what it means to be part of a validator set. On the other hand, yield was always too high, effectively subsidizing the validator set. That is not a sustainable model.

As said, I am not equipped to assess the technical points you raise. My contribution was more about my observations on the changes in the space over the past year. Things are breaking apart, and that’s not necessarily a bad thing. For a long time, we have been acting and thinking as if we can be and do everything at the same time, as if we could maximize all ends of the spectrum simultaneously.

You say “Idealism and economic scale are no longer mutually exclusive,” and I want to agree with you. But another perspective on the situation is that there is likely too little idealism to go around. That is my point about value-aligned communities being smaller in economic scale, and Gnosis’s aspirations being too large to be one of them.

And let me be clear that I don’t see Gnosis as a sellout. Tough choices have to be made to move forward, and I trust them to try and preserve original decentralization values as much as they can. Not a trustless answer.

And if they don’t, we would have to start something new. Correction: we have to start new things regardless.

4 Likes

Looking at this from the wallet support side, the “nothing to migrate” part is encouraging, but I think users and wallet developers would benefit from a more concrete description of the transition.

Will the existing chain ID, account addresses, token contracts and RPC behavior remain unchanged? What should users expect for native xDAI/GNO balances, transaction history, pending transactions and existing dApp connections around the transition?

I’m with Gem Wallet BD and Support, and these are usually the details that determine whether an infrastructure change feels invisible to ordinary users or creates a wave of “where did my assets go?” questions.

It may be helpful to include a wallet/integration checklist in the implementation plan, plus a test environment early enough for wallets and dApps to verify compatibility. We would be happy to relay practical feedback from our users and testing to our developers.

1 Like

@Joera You mentioned that there might be "too little idealism to go around”. But I want to clarify: This is the most pragmatic engineering path available.

True purist idealism would be trying to force everyone onto niche academic fantasies, like demanding the entire ecosystem rebuild on raw RISC-V assembly from scratch and throwing away all the battle-tested infrastructure we’ve built over the last decade.

Pragmatism is recognizing where the industry is actually heading. We live in a universe of thousands of specialized, sovereign chains, whether that’s a chain optimized for a micro block communtiy (tinyblock), a supply-chain logistics for the chocolate industry, or specialized settlement engines.

The path to scaling and liquidity isn’t forcing everything into a centralized sequencer or a single execution bucket (Which btw. doesn’t scale in topology). It’s connecting these sovereign networks through meshed provers that generate and verify state proofs across chains natively.

This approach completely eliminates the need for centralized intermediaries (or the extra middle-layers pushed in based rollup setups) while solving the real-world friction points we face today:

  1. Cross-L1 Synchronous Composability:
    Specialized chains can tap directly into established L1 liquidity pools, like EURe on Gnosis, without needing to migrate their execution or deal with heavy regulatory bottlenecks (e.g. MiCA compliance) during their early stages.

  2. Multi-Polar Real-World Settlement:
    High-volume global trade, such as bridging European liquidity (EURe on Gnosis) with Asian trade channels (eYuan on mBridge), requires a neutral, sovereign, highly decentralized base layer to handle settlement roots without single-jurisdiction counterparty risk.

  3. The Prover Hardware Trajectory:
    Proving overhead is an engineering and hardware commoditization challenge, not a theoretical dead end. With standard 12-second block windows, calculating proofs between state roots is well within reach, and as prover hardware commoditizes, generation costs drop to pennies without relying on centralized hyperscalers.

Gnosis doesn’t need to strip away its 100k+ validator set or surrender its L1 sovereignty to be relevant. It already has the block space, the validator diversity, and the liquidity primitives to act as the primary European settlement engine for a meshed, multi-polar multi-chain world.

Building on modular, proof-meshed sovereignty manifolds is simply good system architecture.
Why would we give that up to align with a network that struggles with its own past bloat?

1 Like

Hello Citrullin,

If I understand you correctly, you’re advocating a mesh model as opposed to the EEZ, which could be characterized as hub-and-spoke. I understand why the mesh is more intellectually stimulating, and possibly the optimal long-term architecture — at least hypothetically. But looking at it from Gnosis’s position, I have some doubts.

In a mesh model, wouldn’t Gnosis have to rely on other chains building and running their side of the proving system in order to gain access to liquidity? Gnosis’s interest here isn’t primarily to share its own liquidity — it’s to gain access to Ethereum’s. In the EEZ model, with Ethereum as the hub, that’s something Gnosis can initiate from its own side, without waiting for other players to reciprocate. That difference in who has to act seems significant. You mention chains tapping into EURe liquidity on Gnosis — but isn’t Gnosis’s problem the reverse? It needs access to mainnet liquidity more than it needs to serve as a source of it.

There’s also a security asymmetry. In the EEZ model everything routes through Ethereum, so every interaction rests on Ethereum’s security. In a mesh, each interaction depends on the security of whichever chain you’re interacting with, and those guarantees can differ greatly. That becomes an open-ended series of security judgments — and eventually a burden you have to translate to the user.

You’ve also argued that if Gnosis is going to build on Ethereum, it should use Ethereum’s sequencer, and stay more decentralized that way. But wouldn’t that mean slowing down to a 12-second ordering cadence, when the proposal is going the other direction — from 5-second blocks today to 2? That seems like a real cost, and one users would notice.

This discussion also reminds me of Cosmos, which I only followed from a distance. As I understand it, Cosmos set out to be the horizontal mesh model, but the Cosmos Hub ended up becoming a hub anyway, largely through economic gravitation rather than protocol design. Which suggests the outcome isn’t determined only by the technical capabilities of proof-meshing, but also by economic forces and by the risks people perceive — or fail to perceive.

So maybe Gnosis is indeed being conservative here. But I’m not going to be the one to say they’re wrong.

PS — writing as a curious user of Gnosis products rather than anyone with a stake in the outcome.

4 Likes

Hi @Joera thanks for the thoughtful pushback. These are good questions to ask, but looking at them solely through the lens of Ether short-term dynamics misses the critical architectural trade-offs Gnosis would be forced to make.

Here is what the EEZ/Based Rollup model actually forces on us, and why the meshed prover model is fundamentally superior:

Displacing Gnosis’s Validator Set & Paying Unnecessary Rent

The EEZ model requires sovereign chains to become L2s, meaning block sequencing is outsourced to Ether’s L1 proposers.

For Gnosis, this is the destruction of the validator ecosystem. It directly prices out (they NEED new hardware) and marginalizes Gnosis 100k+ independent validator set, stripping away their role in block ordering and local MEV capture while forcing Gnosis users to pay baseline settlement rent to Ethers validators. Why dismantle one of the most resilient, decentralized validator sets in the entire industry just to pump Ether’s L1 fee market?

A proof-meshed architecture allows Gnosis to tap into Ether liquidity asynchronously via trustless ZK-bridges and intent-driven solver networks without surrendering our base-layer economics or sacrificing our validators.

The Multi-Hop Reality (12s Settlement Beyond Ethers Silo)

It’s easy to look at Based Rollups and think they solve settlement latency, but that 12-second settlement window is strictly confined to the internal tree of Ether. The moment an EEZ rollup needs to interact with anything outside the Ether L1/L2 ecosystem, the illusion shatters, you are back to traditional, slow, risky bridging.

With meshed provers, 12-second cross-chain settlement works across multiple hops on completely sovereign chains. You get cryptographic validity proofs verified natively across distinct state machines within the same block window. That is something Ether’s hub-and-spoke model simply cannot provide natively without forcing everyone into its silo.
(Which btw. won’t ever work. It’s Quantum Physics. You cannot collapse all waves all at once.)

The Composability Trap: Trees vs. Webs

Based Rollups only allow composability within their specific anchored ecosystem (the L1 → L2/L3 tree). If Gnosis becomes an Ether Based Rollup, it builds a walled garden that restricts fluid composability exclusively to the EVM/Ethereum stack.

Cross-chain proof meshing is a physics problem, not a political one.

True cross-chain composability doesn’t care what language the state machine runs. You can compose seamlessly with systems running WebAssembly (WASM), Solana (SVM), or parallel EVMs. As long as the math checks out and the ZK validity proof can be verified within the block window, the execution is valid.

Scaling the inner manifold (what rollups do) is pointless if you cannot scale the outer topology. A mesh network scales horizontally across any chain willing to verify a cryptographic proof, the EEZ tree chokes the moment the root L1 gets congested.

I’ll step back from the thread here, as this is getting pretty exhausting. It’s frustrating when the focus of governance repeatedly drifts toward short-term TVL extraction and Ether alignment rather than foundational design choices and long-term network sovereignty.

Building on modular, proof-meshed sovereignty manifolds is simply resilient system architecture. Giving that up to become a dependent spoke in someone else’s hub is a massive step backward.

/e
I would like to remind everyone. Whatever “the DAO“ decides.
Ultimately: The Validator have to trigger the switch.

2 Likes

As a validator, I still think this is an exciting change and supports the idea, despite having to shut down and give up my validation node. The idea with running a copy of Ethereum’s proof-of-stake was interesting, but did anyone really care? The old time Xdai chain (before Gnosis) that used a much smaller validator set provided a similar service to end users but much cheaper I guess. Moving to the EEZ to improve bridging experience and save operating costs is a double win. User expercience is important, a faster than 12 sec block time on the EEZ Gnosis chain is also important I think.

So, will the change attract new or existing services to the chain?

3 Likes

Thanks Fredericke for putting together this detailed proposal. Being fundamentally attached to decentralization for all its benefits, this change in Gnosis Chain overall structure brings some questions.

  • Will there be a mechanism similar to OP’s forced inclusion which will provide an escape hatch in case the (now) centralized sequencer censors transactions? What would the reasonable delay be (24hours as in Base case, 72 hours as for arbitrum?) for a TX censored in the L2 to be forced included via Ethereum mainnet?

  • Will the bridge still play the role it has today and continue to act as the source of all xDAI?

  • Regarding the EEZ, the synchronous composability seems nice on paper, but how are txs which may modify state of both chains be guaranteed that both state changes are finalized? What would be the actual finality for this type of txs (give the 2s/12s discrepancy for one).

Looking forward to answers which will help determine what to build in the future!

7 Likes

Thanks @ernst for the reply but I think my original question is still not resolved. I was not asking about tradeoff itself. I was asking for clarity on the destination.

In the proposal, it reads like stronger guarantees might come later . In your reply, it sounds like centralized sequencing (with discretion) is simply required. These point in different directions.

So concretely: Is the current model (centralized sequencing) the intended steady state, or not?

Also, related to what others raised - if this is the model, is there at least a clear forced inclusion mechanism as a baseline guarantee? Because without that, it’s not just a tradeoff, it’s a fundamentally different trust assumption.

Right now it’s still unclear what direction you are actually pursuing with this GIP.

2 Likes

I will be honest and say what many here think: it feels like you are just spamming every thread at this point going on tangents.

Many people here are trying to seriously think through tradeoffs and give constructive input. When replies don’t address specifics and just add noise, it becomes hard to have productive discussion (as founders point out).

Maybe better to focus on fewer points, but engage with them more directly.

9 Likes

Yes, of course there will be checklists, but very short response here:

Chain ID, account addresses, token addresses stay the same. RPC endpoints may change (depending on which provider delivers the best service, but this has also periodically changed in the past.

If you want your wallet to be EEZ aware and not Gnosis-only, there will be some UX questions, for instance: How do you display balances a user holds on different EEZ networks? As one balance? Or do you list them separately? Etc.

1 Like

Thank you for your support – honestly, the validator response has been great overall despite the fact that this means the end of the validator set in this form at least. I so appreciate you and we’ll try to find ways to leverage you.

That’s the hope. Our BD team is currently speaking with different potential design partners, but it’s a bit of a chicken and egg problem, we can’t really sell this before the DAO hasn’t given a green light!

4 Likes

Yes, forced inclusion is a must – we don’t have the specification yet, so delay isn’t decided yet. Forced inclusion will not be present in the first version at the end of the year (engineering complexity), but firmly on the roadmap.

This is a good question, we will have to decide what to do with the fee token. It needs to remain USD pegged for technical reasons, so can’t use GNO instead, but we could either also upgrade to USDS, keep Dai, or use another one completely (GHO etc). But one way or another, the fee tokens needs to be bridged, you don’t want to touch Eth state every time you pay for a tx, that would defy the purpose of having a rollup.

Yes, this is the crux. Every chain in the EEZ needs to acknowledge that it will follow Ethereum’s lead in case of a reorg, you cannot technically have two chains synchronously compose if they have strict parity here. If Ethereum reorgs and the cross-chain tx was affected, the follow chain (in this case Gnosis) is forced to reorg too. Practically this won’t matter often because the transaction usually will just be included in the next block unless the tx is no longer valid for instance because it touched on state that changed from under it (eg trade against an AMM). These reorgs happen on Ethereum around 5-10 times a day. Deeper (i.e. two or more block) reorgs haven’t happened in many years.
So follow-chains finality is bounded by Ethereum finality. We’re petitioning the EF for faster (or ideally single slot) finality, and it looks like that may be coming sooner rather than later, but for now if Ethereum reorgs the follow chains have to be able to potentially reorg too.

As to block times: Gnosis will have 2s block times compared to Ethereum’s 12, so it will build 5 non-composing blocks between each pairl of blocks that compose with Ethereum. Ethereum only builds a block every 12 s, there is no way to compose more often than this. Crosschain tx consequently will have to wait for the next Ethereum block.

1 Like

The sequencer will be centralized out of technical necessity. It’s possible that in due course we can decentralize it while still retaining fast blocks, then this is definitely something we will evaluate. At this point I cannot promise it.
Let me explain why it’s difficult: for a block to be validated by the whole network three things must happen: The block is propagated through the network (first 1/3 of block time), attestation is propagated (second 1/3 of block time), and the aggregate is propagated (third 1/3 of block time). Speed of light in a fiber optic cable is 2/3 * speed of light, so 200k km/s. This means going to your antipodean point and back (40k km) will take you 200ms.
How many hops do you need for gossip to propagate? An Eth node has 8 peers essentially chosen by random, which means you need 4-6 hops to reach most nodes. Nodes have to receive the package, validate it (!) and send it on, so if you factor in 100ms travel time + 50ms validation time per hop you come out at a bare minimum of 900ms. This you need three times (once more for attestations and the final time for the aggregate). And here I’m assuming that there are no bandwidth issues (bandwidth has also historically gone up by 50%/ yr, it’s one of these Moore’s law like things).

You CAN optimize this if you don’t have a random gossip network but a well known list of participants. This may not give you the level of decentralization that several thousand distributed nodes give you, but it is much less centralized than a centralized sequencer. So there is middle ground and we are absolutely down for exploring what can be done!

In the first version, there will be no forced inclusion, but this will be added asap.

I hope this answered your questions?

2 Likes

I’m moving this proposal to phase 2!

6 Likes

Thanks, this clarifies the core compatibility questions.

From a wallet UX perspective, I think balances should initially remain separated by EEZ network so users can clearly see where assets and transactions reside. An aggregated portfolio view could still show the combined value, but presenting everything as a single balance may create confusion around available liquidity, fees and transaction routing.

The RPC changes and eventual wallet/integration checklist will be especially useful to communicate early.

SORRY, I though I’d replied to everyone, but I missed you!

I think we’re talking about two different things here:

1 – does the EEZ architecture make sense for augmenting Ethereum.

You said that Ethereum will scale enough on its own so that it doesn’t need the EEZ. I disagree – I also see how much Ethereum can scale on L1, but I think A) even if it does, it may still not be enough if it becomes the economic operating system of the global economy, and B) there are some things Ethereum is not well suited for [privacy, safety nets for users etc].

2 – does it make sense for Gnosis Chain to move into the EEZ.

I think there are some misunderstandings here: Gnosis Chain will eventually also have forced inclusion is some shape (not at the end of the year, but it’s firmly on the roadmap). This is not the same level of censorship resistance as Ethereum though.

I also think there needs to be risk level management on the dapp level, but I don’t think this is enough at the moment, evidently, systems are still nor hardened enough.

I think this is the one point where we fundamentally disagree – but the beautiful thing is that no one is forced to be on any specific network, you can pick the one that is commensurate with your risk appetite. And I would wager that a lot of web 3 users would trade off some CR for some more security.

2 Likes

Hello,

Would it be productive to create a space for discussion on a future purpose for the validator set? It is an asset worth a specific effort, more than being a downside to the EEZ proposal. Its not just infrastructure, its people, community, as well as an important factor in GNO economy, although that cuts many ways.

It could start with a transparent assessment. How many unique validators are there, honestly? What can be said about distribution, value, etc? There is many Gnosis data hidden deep inside Dune. Can someone from Gnosis dig that up, present it?

Followed by an informed guess what part of that set would remain, provided APR would drop to something sensible (3%?), and node runners would have to install other software, etc .. It’s worth doing a survey, ask the largest contributors. What would be the maintenance cost of that set?

Mentioning ‘perhaps the VPN’, means Gnosis will be making these calculations. Doing it openly could help communicating a possible transition and perhaps even yield some unexpected good ideas and alternative options from the community. It’s obviously the smartest validator set in the world. :wink:

6 Likes

Hi @Joera. Yes, I encourage you to start a space/thread discussing roles for validators. I believe actively participating in Gnosis DAO governance and this forum is one of these, so I’m pleased with the level and amount of engagement lately!

How many unique validators are there, honestly? What can be said about distribution, value, etc? There is many Gnosis data hidden deep inside Dune. Can someone from Gnosis dig that up, present it?

Much of this data can be found on the Gnosis Chain metrics page, specifically this one here on client distribution. This dashboard is based on transport-level information, similar to data we used for an interesting privacy assessment of P2P validator sniping before I joined Gnosis. TLDR: there are somewhat under 400 individual peers on the network that serve Gnosis Chain information to other peers. Not all of these are validators, but I consider this an upper bound of people who are actively running nodes for Gnosis Chain.

First, it’s important to point out that you can (and should) still run your node when Gnosis Chain transitions to an L2. This will give you local Gnosis Chain state, without relying on RPC providers or other centralized data sources. However, validators in the PoS sense won’t exist in Gnosis’ L2 vision, so those node runners who are currently also validators will sadly see that effort come to an end.

If people are looking for other ways to support the Gnosis ecosystem as a node runner, Gnosis VPN could indeed be a viable option, as @ernst alludes to in the GIP.

I spearheaded work on Gnosis VPN, as outlined in GIP-98 for a PoC, GIP-122 to bring it to market (ongoing) and GIP-127 to set up its legal framework and there are multiple roles that Gnosis Chain node runners and validators can play here.

Recently I demoed Gnosis VPN at Dappcon and made the case for why Gnosis needs a VPN. In brief: all Gnosis products and users benefit from the privacy and freedoms granted by an uncensorable VPN, and Gnosis gains a further stream of revenue and users by tapping into one of the world’s largest software markets.

What that talk didn’t cover is why the VPN needs Gnosis, or rather why Gnosis was chosen as the network where we build this thing. We’ve always known that Gnosis has many caring and engaged node operators who are capable of running crypto economic infrastructure at scale. That’s exactly Gnosis VPN and the underlying network need.

Gnosis VPN leverages the HOPR mixnet for its strong anonymity properties. The HOPR network currently comprises just under 400 peers and is thus of similar size to Gnosis Chain in terms of peers. A HOPR node relays data packets for others, mixing them up to prevent anyone from tracking flows of data. Nodes earn tokens for this work thanks to HOPR’s proof-of-relay mechanism – an innovation in the mixnet space. There is also stake-based earning from cover traffic, a mechanism which provides an additional blanket of anonymity for the whole network. Anyone who is interested in joining that set of nodes can already do so today. Check out our docs for convenient ways of running a HOPR node on a broad range of devices. Like Gnosis, HOPR is friends with DappNode, so validators with DappNodes will find dedicated HOPR DappNode packages in the DappNode store.

That’s the HOPR network. But Gnosis VPN also needs dedicated exit nodes which serve as connectors between the fully anonymous HOPR mixnet and the current internet. In addition to the standard relay rewards, exit nodes earn tokens for making their IP address available for Gnosis VPN users to access the internet, although it should be noted that the reward and risk profiles differ from vanilla node running. I invite people and organizations interested in running exit nodes to get in touch with me to explore possibilities, concerns and requirements.

Ultimately, Gnosis has always built resilient infrastructure and products that empower the individual. Gnosis VPN falls into that category as well and is bringing users, revenue and new use cases to the Gnosis ecosystem in a proven and multi-billion dollar VPN market. I mention these numbers to highlight that the potential for revenue distribution via a network of nodes, operated by the Gnosis community, is a serious one that we need to start building towards now.

Gnosis VPN will officially launch in Q4 but anyone who’s interested can already contact me to test the latest version or learn more about node running.

5 Likes

Goodmorning Sebastian,

Thanks for your support and the all the information. I am happy to curiously partake in the conversations, and even converse about governance, but Gnosis is the governing party. That said, i realized after sending out my previous post, that this is all still a proposal, and i was jumping the shark a little.

The information you provide is very interesting though. The number of 400 individual peers looks a lot more realistic than the number of 100.000+ ‘validators’. Still a valuable community. You also write Hoppr/Gnosis VPN already has around that same number of node runners. Congratulations, if these are not apples and pears perhaps the transition already happened? btw, what is the number of dappnode machines?

Perhaps the really interesting question is what role GNO could play. I was also thinking of Enclave, now Interfold. Aren’t they affiliated with Gnosis? I have no connection, but saw they launched smth this week.

Have a good day, Joera

1 Like

Hi everyone, thank you to @ernst, and the core team for putting so much thought and engineering effort into this proposal. I completely agree that liquidity fragmentation and UX are massive hurdles for our ecosystem, and I really appreciate the team’s drive to solve them.

While I share the goal of improving interoperability, I’d love to gently add a few perspectives to the discussion regarding our long-term strategy, security, and identity:

1. The Liquidity & L2 Adoption Assumption I understand the primary incentive here is to tap into Ethereum’s L2s liquidity and achieve deep interoperability. However, I’m not entirely convinced that major VC-backed L2s (which already hold the majority of the TVL) will adopt the full EEZ framework. They may be hesitant to give up their hard-earned sovereignty and introduce systemic risks just to sync with L1, which could limit the network effects we are hoping for.

2. AI-Driven Security Risks & Technical Debt From a security standpoint, tying Gnosis execution layer tightly to Ethereum L1 means inheriting its technical debt and large attack surface. We’ve seen this year how AI is incredibly effective at finding critical CVEs at scale, even in highly optimized, high-quality codebases like the Linux kernel. Ethereum L1 hasn’t fully faced this AI-driven exploit wave yet. I worry that leaning into EEZ exposes us to a massive, complex attack surface rather than mitigating risk.

3. Gnosis Economic Moat and Validator Community I dislike L2s liquidity fragmentation silos as much as anyone, but I worry about what we lose in the transition. Gnosis’s L1 validator community and sovereign neutrality are core to what gives Gnosis its unique economic value. If we sunset the L1 and transition to an L2, we enter a hyper-competitive market. Without our unique sovereign identity, what would be the primary incentive for a dApp to build on Gnosis EEZ over heavily funded, established L2s?

Perhaps the engineering focus is best spent on making Gnosis the most decentralized, neutral, and secure L1 possible. Interoperability could instead come from L1 zkEVM and trustless bridges, allowing us to avoid inheriting Ethereum’s technical debt while preserving the sovereign identity and validator community that makes Gnosis special. cc: @citrullin

Thanks again to the team for fostering this open discussion. I’m sharing these thoughts out of deep care for the long-term health, security, and unique identity of our ecosystem!

1 Like

Thanks for the tag @zakweb, happy to add some context here, as you’ve raised a fundamental set of questions the entire industry will eventually have to confront.

What does credible neutrality actually mean once this technology hits real-world scale, and what are we sacrificing if we abandon L1 sovereignty?

While we have rough consensus on quantifying decentralization (client diversity, validator count, stake distribution, diverse Block-Builder etc.), neutrality remains far more abstract and frequently misunderstood.

Neutrality as Validator Sovereignty

The prevailing assumption in crypto often conflates neutrality with a libertarian financial wild west. A hostile Mad Max environment where anything goes, and every actor is left to financially fight for survival in a regulatory void. I don’t share that view, nor do I think a global financial stack can scale on that premise.

To me, true neutrality is rooted in validator sovereignty:
(more importantly user sovereignty, but this goes too far here)

  • Base-Layer Indifference:
    If a validator or group of validators in a specific jurisdiction chooses, or is legally mandated, to enforce local rules, a credibly neutral base layer should hold zero opinion about those actions. The network role is purely to provide a stateless, mathematical foundation for state and filter validation, not to enforce a global political ethos.

  • Local Enforcement vs. Global Consensus:
    An action enforced in Jurisdiction A has no bearing on Jurisdiction B. Being restricted in one region does not alter state validity across the rest of the global mesh.

  • Resilience Through Geographic Diversity:
    To have a resilience network, we need a geographically and jurisdictional diverse network.
    Diverse enough that no single state authority can dictate terms to the entire system.
    Instead of treating the validator set as some underground outlaw operators.

Neutrality means enabling sovereign actors to make choices for their own infrastructure, even when you personally or ideologically disagree with those choices. That is how neutrality functions between sovereign nations in the physical world, and it is the only model that allows a protocol to survive contact with international law without sacrificing its base-layer integrity.

Internal Cartels vs. External State Censorship

When crypto insiders talk about censorship risk, they almost always frame it around foreign state actors or external firewalls. But state censorship is explicit, external, and easily routed around by a diverse, sovereign validator set.

The far more dangerous threat to protocol neutrality comes from internal cartelization:

  • Soft Institutional Capture:
    Informal delegate cliques, opaque internal VC structures, and core-team spin-outs don’t need state mandates to exercise control. They use discretionary treasury grants, closed-door voting blocks, and proprietary middleware to dictate who gets funded and which technical paths survive.

  • The Weaponized Shield:
    These cartels routinely invoke pure cypherpunk ideals to block formal accountability, audited data rooms, or structured legal firewalls. By keeping governance rules informal, the cartel ensures that its own discretionary power remains unchallenged while turning protocol treasury management into a closed feedback loop.

Technological Sovereignty and Capital Alignment

On a broader level, and this touches directly on technological sovereignty, we are watching a familiar pattern play out: foundational tech incubated in Europe being absorbed into the financial playbooks of US capital markets.

The European development ethos historically prioritized public infrastructure, decentralized validator sets, and sovereign, credibly neutral base layers. Converting a sovereign L1 into just another L2 sequencer pool surrenders that long-term infrastructure vision in favor of hyper-financialized, VC-driven liquidity capture.

If we treat Gnosis purely as a feeder pipe for American L2 capital rather than a sovereign protocol in its own right, we forfeit the very moat we set out to build. Staying an L1 powered by stateless cryptographic verification and true validator diversity is the only path that preserves both our economic independence and our technical foundation.

@Citrullin this is another off-topic, abstract wall of text that adds nothing to the proposal or to the conversation around it. What it does do is promote your own pending request, this time wrapped in accusations of “internal cartelization”, “delegate cliques” for “core-team spin-outs” aimed at the people building and answering questions in this thread. The moderators have asked you nicely, more than once, to keep your posts on topic.

Keep any further replies here to the substance of GIP-153.

3 Likes

Thanks for sharing your perspectives, and welcome to the Gnosis forum.

Gnosis Chain is arguably one of the most decentralized, neutral, and secure L1s outside of Ethereum itself. I agree that has merit, but unfortunately it hasn’t led to a self-sustaining ecosystem - however strong the dogmatic case for a stand alone L1, the pragmatic realities of operating an onchain protocol, particularly a financial one, mean an isolated L1 isn’t viable without subsidies to sustain liquidity. This challenge isn’t just unique to Gnosis.

To your specific points:

  1. The primary gain for Gnosis Chain is access to Ethereum’s liquidity and asset ecosystem, and every L2 that later joins the EEZ compounds that. You’re right that bringing the wider L2 landscape along is the challenge, but that’s a challenge for the broader EEZ initiative. In the meantime (through the lens of Gnosis Chain) being the only rollup with synchronous composability with Ethereum is a genuine go-to-market advantage, not a weakness.

  2. On AI-driven exploits, staying a sovereign L1 offers no shelter. The whole stack is open source either way, and if anything an independent L1 carries more exposure, given the incentives to exploit contracts and the volume of capital sitting on L1s.

  3. Agreed, it’s not an easy decision, and this is the main downside of the proposal. The upside is being able to call any contract on Ethereum atomically.

6 Likes

GIP-153 is now in Phase 3 and live for voting:
https://snapshot.org/#/s:gnosis.eth/proposal/0x5522f4cbd034c966a08d6901b05c7ad7300041b3e0d75a0ad3da868af1a98b98

At 14:00 UTC today we’ll be running through the GIP as part of the eco session in the Gnosis Discord. Our friends from OWN will also be sharing their on-chain mortgage product.

Please do bring any questions.

4 Likes

Thanks for the detailed and honest reply. I appreciate you addressing the pragmatic realities the team is facing.

I am not against the Gnosis EEZ experiment overall, but I’d love to explore a couple of follow-up thoughts:

1. Coexistence during the transition Could the Gnosis EEZ and the current L1 coexist during the transition, rather than sunsetting the L1 validators early next year? Running them in parallel would allow us to test the EEZ architecture while preserving our sovereign base and validator community as a fallback.

2. AI exploits and systemic risk While open-source exposure exists everywhere, It seems to me that the massive Ethereum’s TVL and liquidity would naturally attracts more AI-driven exploits. Additionally, patching vulnerabilities in a large, tightly coupled ecosystem is much harder than on a mid-range L1. A localized bug in an interdependent setup risks cascading, whereas an isolated L1 can mobilize and patch critical issues much faster without the friction of cross-chain coordination.

I respect the tough choices the team is making to ensure the ecosystem survives and thrives long-term. I just want to ensure we don’t accidentally burn our bridges (or our validators) before the new architecture is fully battle-tested. Thanks again for fostering such a great discussion!

1 Like

For many here, the biggest drawback of these GIPs is centralization and the power of the centralized sequencer. That makes sense: after all, the value that blockchains provide is precisely the decentralization we all love and expect from a chain. That’s essentially what crypto is all about. When I heard about the concept in June in Berlin during the talks by Frederike Ernst and Philippe Schommers (danke für die tollen Auftritte bei der DAppcon und dem web3-summit), I could already picture in my mind how EU authorities would effectively take control of Gnosis by putting pressure on Gnosis Ltd. But perhaps these concerns can be put into perspective. First of all, the fact is that a centralized sequencer, which replaces the validators, doesn’t change all that much when it comes to block validation. It will still only be possible to simply exclude transactions from certain addresses from being included in blocks, thereby freezing their funds, but the state of the chain won’t be retroactively altered just like that. In my view, this brings transparency. The even more important aspect is that exploits and stolen assets are a much bigger problem than attempts at manipulation by validators. And that’s a crucial factor when it comes to institutions’ use of blockchain technology. Institutions are reluctant to transfer large assets to the blockchain if a single error or exploit could suddenly wipe out all their funds. So while Gnosis becomes less attractive to fraudsters due to the ability to freeze funds more easily, this very circumstance makes the chain all the more attractive to other players. No Lazarus Group will even bother to exploit contracts on Gnosis if they know they cannot sell their assets. The risk of conditional centralization due to government pressure is real, but there is also a reliable safeguard against this: us, the users. As soon as unjustified interference (for example, at the government’s behest) occurs, no user who values censorship resistance in any way (i.e., all of us) will use that chain.

In conclusion, I am therefore very much in favor of this GIP, as this concept is unique so far and should be tested. This USP (or first-mover advantage) will give the Gnosis Chain new relevance. Simply “carrying on as usual” as just another sidechain won’t get us anywhere.

3 Likes