Blockchain Regulation Matrix
The Blockchain Regulation Matrix (BRM) establishes a framework outlining the concerns of regulating the blockchain from both the government and the consumer perspective, and in doing so, provides a pragmatic and clear approach to Web3 regulation. The BRM outlines regulation aspects of the blockchain by viewing it as a blockchain stack in many layers starting with the electricity physically supporting the blockchain at the base layer, all the way to the process of offloading crypto to fiat currency. With centralization and decentralization on either side of the matrix, the primary objective of the BRM is to understand where and how regulation of the blockchain should be developed specific to each layer.
Beginning with the electricty supporting the blockchain, as you hover over the images of each row, you'll see the specifics for that topic within that layer. The left side refers to projects that are centralized, while the right side refers to projects that are decentralized. For example, if there was an organization or business that wanted to provide electricity to miners in their area, that would be a centralized project. However, if there was a solar farm operating as a DAO that wanted to provide electricity to miners, that could be a decentralized project.
There are two illustrations of the Blockchain Regulation Matrix below, a short-form immediately below and a long-form afterwards.
Hover over the icons to preview each topic, and click any icon to pin its details — the address bar then links straight to that cell, ready to share.
DeFi Architecture and Securitycentralized
This row applies to the security of DeFi architecture concerning the dependency of other third-party apps when building on the blockchain.
Partially addressedRisk assessments and IOSCO recommendations map the terrain; binding rules don't exist yet.
Government Concerns
- Systemic risk from protocols composing on shared dependencies: oracles, bridges, and stablecoins
- No reporting channel exists for critical vulnerabilities in live financial infrastructure
Consumer Risks
- Exposure to smart contract vulnerabilities leading to asset losses
- Risk of funds being locked or inaccessible due to unforeseen circumstances
- Dependence on the platform's security measures and risk management
- Lack of understanding of complex DeFi protocols and potential pitfalls
- Limited recourse in case of platform hacks or security incidents
Cons to over-regulation
- Excessive regulations stifling innovation and hindering DeFi development
- Higher compliance costs limiting the accessibility of DeFi products
- Slowing down the introduction of new features and functionalities
- Potential displacement of development activities to more permissive jurisdictions
Cons to lack of regulation
- Proliferation of insecure DeFi platforms and protocols
- Lack of standardized security practices leading to increased risks
- Difficulty in addressing disputes and liabilities arising from vulnerabilities
- Undermining public trust and confidence in DeFi due to frequent security incidents
Does blockchain technology currently exist to fulfill these obligations, and if so, what is it?
- Decentralized oracle networks with medianized, manipulation-resistant feeds
- Circuit breakers and rate limits capping single-exploit damage
- Real-time threat monitoring (Forta-class) watching live protocol state
Current regulatory landscape
- guidanceTreasury DeFi illicit finance risk assessment — US, 2023. The US government's first systematic map of DeFi risk — analysis, not yet rules.
- guidanceIOSCO DeFi policy recommendations — Global, 2023. Nine recommendations for regulating DeFi by economic function rather than legal form.
Notable incidents
- Mango Markets oracle manipulation (2022) — $114M extracted by pumping a thin oracle price and borrowing against it — prosecuted as fraud, testing whether 'the code allowed it' is a defense.
- Ronin bridge hack (2022) — $625M via compromised validator keys on a bridge — the largest DeFi loss, rooted in architecture (5-of-9 keys) rather than contract code.
- bZx flash-loan attacks (2020) — The first headline flash-loan exploits: composability let an attacker assemble uncollateralized leverage across protocols in one transaction.
