Web3 has a metadata problem, and it’s not going away  

16 March 2025

Cointelegraph by Casey Ford

  ​

Web3 has a metadata problem, and it’s not going away

Opinion by: Casey Ford, PhD, researcher at Nym Technologies

Web3 rolled in on the wave of decentralization. Decentralized applications (DApps) grew by 74% in 2024 and individual wallets by 485%, with total value locked (TVL) in decentralized finance (DeFi) closing at a near-record high of $214 billion. The industry is also, however, heading straight for a state of capture if it does not wake up. 

As Elon Musk has teased of placing the US Treasury on blockchain, however poorly thought out, the tides are turning as crypto is deregulated. But when they do, is Web3 ready to “protect [user] data,” as Musk surrogates pledge? If not, we’re all on the brink of a global data security crisis.

The crisis boils down to a vulnerability at the heart of the digital world: the metadata surveillance of all existing networks, even the decentralized ones of Web3. AI technologies are now at the foundation of surveillance systems and serve as accelerants. Anonymity networks offer a way out of this state of capture. But this must begin with metadata protections across the board.

Metadata is the new frontier of surveillance

Metadata is the overlooked raw material of AI surveillance. Compared to payload data, metadata is lightweight and thus easy to process en masse. Here, AI systems excel best. Aggregated metadata can reveal much more than encrypted contents: patterns of behaviors, networks of contacts, personal desires and, ultimately, predictability. And legally, it is unprotected in the way end-to-end (E2E) encrypted communications are now in some regions. 

While metadata is a part of all digital assets, the metadata that leaks from E2E encrypted traffic exposes us and what we do: IPs, timing signatures, packet sizes, encryption formats and even wallet specifications. All of this is fully legible to adversaries surveilling a network. Blockchain transactions are no exception.

From piles of digital junk can emerge a goldmine of detailed records of everything we do. Metadata is our digital unconscious, and it is up for grabs for whatever machines can harvest it for profit.

The limits of blockchain

Protecting the metadata of transactions was an afterthought of blockchain technology. Crypto does not offer anonymity despite the reactionary association of the industry with illicit trade. It offers pseudonymity, the ability to hold tokens in a wallet with a chosen name. 

Recent: How to tokenize real-world assets on Bitcoin

Harry Halpin and Ania Piotrowska have diagnosed the situation:

“[T]he public nature of Bitcoin’s ledger of transactions […] means anyone can observe the flow of coins. [P]seudonymous addresses do not provide any meaningful level of anonymity, since anyone can harvest the counterparty addresses of any given transaction and reconstruct the chain of transactions.”

As all chain transactions are public, anyone running a full node can have a panoptic view of chain activity. Further, metadata like IP addresses attached to pseudonymous wallets can be used to identify people’s locations and identities if tracking technologies are sophisticated enough. 

This is the core problem of metadata surveillance in blockchain economics: Surveillance systems can effectively de-anonymize our financial traffic by any capable party.

Knowledge is also an insecurity

Knowledge is not just power, as the adage goes. It’s also the basis on which we are exploited and disempowered. There are at least three general metadata risks across Web3.

  • Fraud: Financial insecurity and surveillance are intrinsically linked. The most serious hacks, thefts or scams depend on accumulated knowledge about a target: their assets, transaction histories and who they are. DappRadar estimates a $1.3-billion loss due to “hacks and exploits” like phishing attacks in 2024 alone. 

  • Leaks: The wallets that permit access to decentralized tokenomics rely on leaky centralized infrastructures. Studies of DApps and wallets have shown the prevalence of IP leaks: “The existing wallet infrastructure is not in favor of users’ privacy. Websites abuse wallets to fingerprint users online, and DApps and wallets leak the user’s wallet address to third parties.” Pseudonymity is pointless if people’s identities and patterns of transactions can be easily revealed through metadata.

  • Chain consensus: Chain consensus is a potential point of attack. One example is a recent initiative by Celestia to add an anonymity layer to obscure the metadata of validators against particular attacks seeking to disrupt chain consensus in Celestia’s Data Availability Sampling (DAS) process.

Securing Web3 through anonymity

As Web3 continues to grow, so does the amount of metadata about people’s activities being offered up to newly empowered surveillance systems. 

Beyond VPNs

Virtual private network (VPN) technology is decades old at this point. The lack of advancement is shocking, with most VPNs remaining in the same centralized and proprietary infrastructures. Networks like Tor and Dandelion stepped in as decentralized solutions. Yet they are still vulnerable to surveillance by global adversaries capable of “timing analysis” via the control of entry and exit nodes. Even more advanced tools are needed.

Noise networks

All surveillance looks for patterns in a network full of noise. By further obscuring patterns of communication and de-linking metadata like IPs from metadata generated by traffic, the possible attack vectors can be significantly reduced, and metadata patterns can be scrambled into nonsense.

Anonymizing networks have emerged to anonymize sensitive traffic like communications or crypto transactions via noise: cover traffic, timing obfuscations and data mixing. In the same spirit, other VPNs like Mullvad have introduced programs like DAITA (Defense Against AI-guided Traffic Analysis), which seeks to add “distortion” to its VPN network. 

Scrambling the codes

Whether it’s defending people against the assassinations in tomorrow’s drone wars or securing their onchain transactions, new anonymity networks are needed to scramble the codes of what makes all of us targetable: the metadata our online lives leave in their wake.

The state of capture is already here. Machine learning is feeding off our data. Instead of leaving people’s data there unprotected, Web3 and anonymity systems can make sure that what ends up in the teeth of AI is effectively garbage.

Opinion by: Casey Ford, PhD, researcher at Nym Technologies.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

 

You might also like

Hashdex amends S-1 for crypto index ETF, adds seven altcoins  
Hashdex amends S-1 for crypto index ETF, adds seven altcoins  

Asset manager Hashdex has amended its S-1 regulatory filing for its cryptocurrency index exchange-traded fund (ETF) to include seven altcoins in addition to Bitcoin (BTC) and Ether (ETH), according to a March 14 filing. The revision proposes adding seven specific altcoins to the index ETF — Solana (SOL), XRP (XRP), Cardano (ADA), Chainlink (LINK), Avalanche (AVAX), Litecoin (LTC), and Uniswap (UNI). As of March 17, the Hashdex Nasdaq Crypto Index US ETF holds only Bitcoin and Ether. Previous versions of Hashdex’s S-1 suggested the possibility of adding other cryptocurrencies in the future but didn’t specify which ones.According to the filing, the proposed altcoins additions “are decentralized peer-to-peer computer systems that rely on public key cryptography for security, and their values are primarily influenced by market supply and demand.”The revised filing signals how ETF issuers are accelerating planned crypto product rollouts now that US President Donald Trump has instructed federal regulators to take a more lenient stance on digital asset regulation. As part of the transition, the ETF plans to switch its reference index from the Nasdaq Crypto US Index — which only tracks BTC and ETH — to the more comprehensive Nasdaq Crypto Index, the filing said. The asset manager did not specify when it plans to make the change. The US Securities and Exchange Commission (SEC) must sign off on the proposed changes before they can take effect. Hashdex plans to add seven altcoins to its index ETF. Source: SECRelated: US crypto index ETFs off to slow start in first days since listingAccelerating approvalsIn December, the SEC gave the green light to both Hashdex and Franklin Templeton’s respective Bitcoin and Ether index ETFs. Both ETFs were listed in February, initially drawing relatively modest inflows, data shows. They are the first US ETFs aiming to offer investors a one-stop-shop diversified crypto index. Asset manager Grayscale has also applied to convert its Grayscale Digital Large Cap Fund to an ETF. Created in 2018, the fund holds a crypto index portfolio comprising BTC, ETH, SOL and XRP, among others. Industry analysts say crypto index ETFs are the next big focus for issuers after ETFs holding BTC and ETH listed in January and July, respectively.“The next logical step is index ETFs because indices are efficient for investors — just like how people buy the S&P 500 in an ETF. This will be the same in crypto,” Katalin Tischhauser, head of investment research at crypto bank Sygnum, told Cointelegraph in August.In February, the SEC acknowledged more than a dozen exchange filings related to cryptocurrency ETFs, according to records.The filings, submitted by Cboe and other exchanges, addressed proposed rule changes concerning staking, options, in-kind redemptions and new types of altcoin funds.Magazine: US enforcement agencies are turning up the heat on crypto-related crime

Robinhood shares up 8% after launching betting markets hub  
Robinhood shares up 8% after launching betting markets hub  

Robinhood has launched a betting markets hub as the online brokerage — best known for stock trading — expands its presence in emergent asset classes, including cryptocurrencies and event contracts, according to a March 17 announcement. Robinhood’s stock, HOOD, rose roughly 8% on the Nasdaq after the announcement, according to data from Google Finance. The new betting feature will let users “trade contracts for what the upper bound of the target fed funds rate will be in May, as well as the upcoming men’s and women’s College Basketball Tournaments,” it said. HOOD’s intraday performance on the Nasdaq on March 17. Source: Google FinanceThe online brokerage is tapping Kalshi, the US’ first CFTC-regulated prediction platform, to operate the event contract platform, it said. Kalshi is already registered to list dozens of event contracts, covering outcomes ranging from election results to Rotten Tomatoes movie ratings.Prediction markets “play an important role at the intersection of news, economics, politics, sports, and culture,” JB Mackenzie, vice president and general manager of futures and international at Robinhood, said in a statement. Experts say political betting markets often capture public sentiment more accurately than polls. Platforms such as Kalshi and Polymarket accurately predicted US President Donald Trump’s November election win even as polls indicated a tossup.Related: Robinhood tips Singapore launch, touts memecoin interest: ReportRising popularityPrediction markets have become increasingly popular in the US since September 2024, when Kalshi prevailed in a lawsuit challenging a CFTC decision to bar it from listing political event contracts.By November, trading volumes across popular prediction markets neared $4 billion for contracts tied to the US elections.Robinhood tested the waters of political event contracts in October when it started letting certain users bet on the outcome of the presidential election between former Vice President Kamala Harris and Trump.In February, Robinhood suspended Super Bowl betting after receiving a request from the CFTC to nix its customers’ access to the event contracts.Beyond stock tradingRobinhood has been expanding its footprint in emerging asset classes, including cryptocurrencies and derivatives. On March 13, the company listed memecoins like Pengu (PENGU), Pnut (PNUT) and Popcat (POPCAT) in a bid to expand its presence in crypto. Back in January, it rolled out futures contracts tied to cryptocurrencies such as Bitcoin (BTC).Robihood’s latest earnings report shows the firm posted a 700% year-over-year jump in crypto revenues in the fourth quarter of 2024 as Trump’s election win and rising market prices fueled boosted crypto trading.X Hall of Flame: Memecoins will die and DeFi will rise again — Sasha Ivanov 

XRP’s role in US Digital Asset Stockpile raises questions on token utility — Does it belong?  
XRP’s role in US Digital Asset Stockpile raises questions on token utility — Does it belong?  

Ripple’s XRP (XRP), the third-largest cryptocurrency by market cap, gained national recognition after President Donald Trump mentioned the “valuable cryptocurrency” alongside BTC, ETH, SOL, and ADA as part of a planned US strategic crypto reserve. Trump’s executive order on March 6 established a new structure for the altcoins — the Digital Asset Stockpile, managed by the Treasury. While the crypto community remains divided on whether XRP is truly as valuable as President Trump suggests, a closer look at the altcoin’s utility is warranted. XRP’s potential role in bankingLaunched in 2012 by Ripple Labs, the XRP Ledger (XRPL) was designed for interbank settlements. It initially offered three enterprise solutions: xRapid, xCurrent, and xVia, all later rebranded under the RippleNet umbrella. XCurrent is real-time messaging and settlement between banks, xVia is a payment interface allowing financial institutions to send payments through RippleNet, and xRapid, now part of On-Demand Liquidity (ODL), facilitates cross-border transactions.Only ODL actually requires XRP; the other services allow banks to use RippleNet without ever holding the token. This means bank adoption of Ripple technology does not always drive XRP’s price.Some of the world’s largest banks have used xCurrent and xVia, including American Express, Santander, Bank of America, and UBS. There is less data on the entities that use XRP-powered ODL service. Known adopters include SBI Remit, a major Japanese remittance provider, and Tranglo, a leading remittance company in Southeast Asia.XRP’s role in Web3XRP is also used as a gas token. However, unlike the Ethereum network, where fees go to validators, a small amount of XRP is burned as an anti-spam mechanism.XRP’s role in Web3 is minimal. Unlike Ethereum, Ripple does not support complex smart contracts or DApps. It offers only basic Web3 functionality, such as a token issuance mechanism and native NFT support under the XLS-20 standard, introduced in 2022.The XRPL Web3 ecosystem is small. Its modest DeFi sector holds $80 million in total value locked (TVL), according to DefiLlama. XRPL’s tokens have a combined market cap of $468 million, according to Xrpl.to. Most of them are DEX tokens (SOLO) and memes (XRPM), as well as wrapped BTC and stablecoins.So far, XRPL’s Web3 sector remains niche and trails true smart contract platforms like Ethereum and Solana.Related: SEC delays decision on XRP, Solana, Litecoin, Dogecoin ETFsCrypto pundits split hairs on XRP’s role in a strategic reserveRipple Labs representatives have long advocated for equal treatment of cryptocurrencies, with CEO Brad Garlinghouse reiterating this on Jan. 27. Garlinghouse said,  “We live in a multichain world, and I’ve advocated for a level-playing field instead of one token versus another. If a government digital asset reserve is created—I believe it should be representative of the industry, not just one token (whether it be BTC, XRP or anything else).”However, not all cryptocurrencies serve the same purpose. Bitcoin’s primary role is to be a “geopolitically neutral asset like gold,” in the words of crypto analyst Willy Woo. XRP’s purpose remains less clear, but few in the crypto space would argue that it could qualify as independent money. This is primarily due to one of Ripple’s most uncomfortable aspects—its permissioned nature. Unlike Bitcoin or Ethereum, Ripple does not rely on miners or staked tokens to secure the network. Instead, it uses a Unique Node List—a group of trusted validators responsible for approving transactions. While this optimizes speed and efficiency, it raises concerns about censorship, corruption, and security risks.Bitcoin proponent and co-founder of Casa Jameson Lopp didn’t hold back when discussing XRP’s potential:“There’s Bitcoin, then there’s Crypto, then there’s Ripple. Ripple has attacked Bitcoin at a level rivaled only by BSV’s lawsuits. Ripple explicitly wants to power CBDCs. They have always been focused on servicing banks. Few projects are as antithetical to Bitcoin.”There’s no love lost between Bitcoiners and Ripple supporters, especially after Ripple co-founder Chris Larsen partnered with Greenpeace to fund an anti-Bitcoin campaign. However, Lopp’s comparison to CBDCs holds some weight, given XRPL’s permissioned nature. It reflects a common view in the crypto community that XRP functions more like a banking tool than a truly independent cryptocurrency.While the XRPL blockchain sees widespread use in banking, XRP’s utility remains a point of concern. It is underscored by the fact that approximately 55% of the 100 billion pre-mined coins are still held by Ripple Labs. This concentration raises concerns about potential market manipulation and the coin’s long-term stability. This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.
BlockFo
BlockFo