Blockchain Regulation Matrix
The Blockchain Regulation Matrix (BRM) establishes a framework outlining the concerns of regulating the blockchain from both the government and the consumer perspective, and in doing so, provides a pragmatic and clear approach to Web3 regulation. The BRM outlines regulation aspects of the blockchain by viewing it as a blockchain stack in many layers starting with the electricity physically supporting the blockchain at the base layer, all the way to the process of offloading crypto to fiat currency. With centralization and decentralization on either side of the matrix, the primary objective of the BRM is to understand where and how regulation of the blockchain should be developed specific to each layer.
Beginning with the electricty supporting the blockchain, as you hover over the images of each row, you'll see the specifics for that topic within that layer. The left side refers to projects that are centralized, while the right side refers to projects that are decentralized. For example, if there was an organization or business that wanted to provide electricity to miners in their area, that would be a centralized project. However, if there was a solar farm operating as a DAO that wanted to provide electricity to miners, that could be a decentralized project.
There are two illustrations of the Blockchain Regulation Matrix below, a short-form immediately below and a long-form afterwards.
Hover over the icons to preview each topic, and click any icon to pin its details — the address bar then links straight to that cell, ready to share.
Internet Browsercentralized
This row applies to internet browsers and their context of the blockchain.
UnaddressedNo fitness, security, or disclosure standard governs wallet-bearing browsers — the gap our wallet bill targets.
Government Concerns
- Browsers and extension stores are unvetted gatekeepers to users' keys and transactions
- No disclosure standards for wallet-integrated browser telemetry and data collection
Consumer Risks
- Privacy concerns due to browser tracking and data collection
- Potential exposure to malicious websites and phishing attacks
- Risk of unauthorized access to integrated wallets and sensitive data
- Dependence on browser security for safeguarding cryptocurrency transactions
Cons to over-regulation
- Excessive regulations stifling innovation and development of blockchain-integrated browsers
- Potential barriers to international collaboration and cross-border data flows
- Complex compliance requirements hindering user adoption and accessibility
Cons to lack of regulation
- Lack of specific support for addressing social engineering threats through the browser
- Malicious extensions and fake wallets circulate with no vetting or recall standard
Does blockchain technology currently exist to fulfill these obligations, and if so, what is it?
- EIP-6963 wallet discovery preventing extension impersonation and injection races
- Human-readable signing (EIP-712) and in-wallet transaction simulation
- Maintained phishing blocklists (Blockaid-style) acting at the wallet layer
Current regulatory landscape
- proposedDigital Wallet Security and Accreditation Act (draft) — Crypto Policy Center, 2024. This organization's draft bill: provider accreditation, secure key handling, and mandatory consumer education — aimed squarely at this layer's gap.
- guidanceBrowser and extension store policies — Private, ongoing. Store review is today's only vetting layer for wallet extensions, and counterfeits repeatedly pass it.
Notable incidents
- Fake Ledger Live app in Microsoft Store (2023) — A counterfeit wallet app passed store review and stole funds — the browser/store layer failing as gatekeeper exactly where users trust it most.
- Clipboard-hijacking malware families (ongoing) — Malware silently swaps copied wallet addresses at paste time — a browser/OS-layer attack no smart contract audit can prevent.
