October 2017 Journal
WORDS is a monthly journal of Bitcoin commentary. This issue collects the October 2017 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. Thatâs why we made this journal, to preserve and further the understanding of Bitcoin.
Introducing NVT Ratio (Bitcoinâs PE Ratio), use it to detect bubbles
By woonomic
Posted October 5, 2017
kg-card-begin: markdown
Preface
February of this year, I tweeted a chart that presented the idea of a PE ratio for Bitcoin, something I temporarily called MTV Ratio before my buddy Chris Burniske suggested the less confusing term of NVT Ratio (Network Value[1] to Transactions Ratio). Later in May, Chris was the first to present NVT Ratio at Token Summit 2017. Subsequently, this ratio has been mentioned in blog and media articles across the web. In my original tweet, I promised an article; it lay unwritten until now.
The idea behind NVT Ratio
In traditional stock markets, price-earnings ratio (PE Ratio) has been a long standing tool for valuing companies. Itâs simply the ratio of a companyâs share price to its equivalent earnings per share. A high ratio describes either over valuation or a company in high growth.
What would be the equivalent in Bitcoin-land? We have a price per token, but itâs not a company so there are no earnings to do a ratio. However since Bitcoin at its essence is a payments and store of value network[2], we can look to the money flowing through its network as a proxy to âcompany earningsâ.

As you can see the value transmitted on the Bitcoin blockchain is closely tied to its network valuation. The idea that we can use the money flowing through the network as a proxy for network valuation is valid.
We can express this as a ratio. I call it NVT Ratio, short for Network Value to Transactions Ratio. Below is a historic chart of Bitcoinâs NVT ratio. A live and interactive chart is available on my site at Woobull.com.

NOTE: Estimation of daily on-chain transaction value provided by blockchain.info
How to Use NVT Ratio
1) A high NVT Ratio can indicate high speculative value

We can see in the early years of the Bitcoin network, growth was very steep. This resulted in the markets valuing the network high in comparison to the actual transaction value flowing through the network. In other words, weâre seeing a network growing explosively which then demands a premium valuation based on future potential. This is very similar to what we see in PE ratios in the high growth stages of young companies.
2) Using NVT Ratio to detect bubbles
Predicting a bubble before the fact is rather elusive as a price explosion does not necessarily mean the asset is in a bubble. We can only determine this after the peak when the market reassesses the new valuation and we see if the price consolidates or crashes.
For example Ethereumâs valuation during Q1 of 2016 grew by a factor of 15x from $70 million to well over $1 billion. To the uninitiated, it looked like a bubble, yet there was no crash, its new valuation was sustained, thus it proved not to be.
Similarly, NVT Ratio can not reliably determine a bubble ahead of time, but it is very useful for discerning between a crash or a consolidation after the price has peaked. It can determine this relatively quickly.

During a price explosion thereâs a short term flurry of trader activity and new users hitting the network which serves to drive transactional value through the network. Itâs only after the frenzy has subsided do we see whether the value flowing through the network has kept in tandem with its higher valuation. Sometimes it does (itâs a consolidation), and in other times it does not (hence, a crash).
Using the NVT ratio we can detect the difference between consolidation and bubbles very visibly. If the NVT ratio stays within a normal range, we are not in bubble territory. If it climbs above the normal range, itâs a sign that the transactional activity is not sustaining the new valuation and we can expect a lengthy price correction.
EXAMPLE 1: Bitcoinâs two bubbles according to NVT Ratio

The chart above shows the NVT ratio in action detecting two of Bitcoinâs historic bubbles. In 2011 and early 2013, Bitcoin exploded in price followed by NVT ratio rising above the normal range. These were deemed bubbles under NVT ratio analysis. Subsequently we saw lengthy 92% and 83% corrections in price.
EXAMPLE 2: A bubble that wasnât a bubble

Of particular interest is the first rapid price rise of 2013 (highlighted with a rectangle in the chart above). We saw a 83% consolidation from peak to trough. Itâs interesting as the NVT ratio did not rise high enough to signify a bubble, yet you would think a 83% correction would be fit to be called a bubble, right?
Not so! If we dig into the networkâs undergrowth, we find that the value transmitted by the network was high enough to keep the NVT ratio within normal range. Though the markets sold off until the price experienced a sudden dip that was 83% off the peak, that dip was very short lived and the long range chart reveals a pattern more akin to a consolidation which completed quicky. This is a case where the NVT ratio, had it been around back then, was telling the markets it was undervaluing the network at the peak of market fear.
Hey NVT, are we in a bubble today?
Now for the golden moment - letâs apply the NVT ratio to test the Bitcoinâs market at the time of writing. Weâve suffered a large pullback from $81b network value to a low of $49b, with market fearing the potential onset of a bear season.

As we can see in the chart above, NVT ratio is within normal bounds. NVT ratio is saying this is a price consolidation. The transaction value flowing through Bitcoinâs network is perfectly healthy and supports the currenct valuation.
NVT Ratio on other crypto-assets?
The question arises, can NVT Ratio be used as a valuation metric for other crypto-assets? My tentative answer, subject to further study, would be âusually, but not alwaysâ.
At its essence, Bitcoinâs NVT ratio is a comparison of how much the network is being valued to how much the network is being used. If youâre applying the NVT ratio to a different network, the value transmitted on-chain needs to be a good representation of how much the network is being used. This is not always the case.
Ethereum
Ethereum launched in 2015, as a smart contract computing network thatâs fast become the most popular platform for token sales this year. Since the token sales conducted on Ethereum require payment in Ether, thereâs a very strong correlation between the transactional value and network value as seen below.

Ethereum is only two years old and its high growth phase. It will take some time before its NVT ratio settles into a meaningful long term range for bubble detection.
Currencies that provide staking rewards
Networks like Decred and Dash have transactional activity resulting from staking, a process where stakeholders of a network lock up and collateralise their tokens to provide services to the network in return for revenue.
This revenue flowing back to the stakeholders is not reflective of the networkâs utility and will skew the results coming from the NVT ratio. For these types of networks it would make sense to provide a corrected NVT ratio which subtracts the transactional value resulting from staking which is numerically predictable.
Fungible Networks
Private and fungible currencies like Zcash and Monero hide some, or all of their value transmitted on-chain so itâs impossible to determine their NVT ratio accurately.
Notes
This article was first published by Forbes on 29 Sep 2017.
- The term Network Value or Network Valuation is defined by the last traded price multiplied by the total number of tokens in circulation. Typically the term âMarket Capitalisationâ has been used for this, however this confuses the term with stock markets, so instead prefer Network Valuation in the field of cryptocurrencies. â©ïž
- Purists may argue other use cases that presents transactional data onto the Bitcoin blockchain, such as notorisation or even the basis for token platforms in the case of CounterParty and OMNI Protocol. But this actual USD value transmitted is insignificant, meaning it does not significantly impact this metric. Letâs see if this statement is true. The chart below shows Bitcoinâs historic valuation plotted alongside the USD equivalent value flowing through its network. â©ïž
kg-card-end: markdown
Privacy on the blockchain
By Jordan Clifford
Posted October 5, 2017

Privacy in an open society requires anonymous transaction systems. Until now, cash has been the primary such system⊠An anonymous system empowers individuals to reveal their identity when desired and only when desired.
â Eric Hughes, 1993
Co-founder of the cypherpunk movement, UC Berkeley mathematician
Background
Thereâs a popular misconception that Bitcoin is anonymous and untraceable. Itâs an understandable mistake given Bitcoinâs first popular use case was the infamous Silk Road â a market known for dealing in illicit substances. The truth is that Bitcoin is pseudonymous and fully traceable. In fact, every transaction in Bitcoin maps inputs to outputs, allowing anyone to follow the money trivially.
Satoshi even went so far as defining a bitcoin â literally â as a history of its custody:
We define an electronic coin as a chain of digital signatures.
â Satoshi Nakamoto, 2009
Bitcoinâs transactions are tracked as a graph that resides on the blockchain permanently. If someone learns of information that links your identity to your bitcoin address, they can learn a ton about you. Itâs possible to infer your spending patterns (where you spend, how much, how often), your wealth and income, whom you associate with. How do you feel knowing those whom you transact with may be able to learn so many personal facts about you?
There are countless ways that identities can be linked to a wallet address. Some people share their address publicly. The exchange you bought your bitcoin from has both your identity and your addresses. Merchants you pay can make the association. Two companies, Elliptic and Chainalysis, are in the business of linking identities to addresses, and compiling all their insights into commercialized databases that track all bitcoin activity in an effort to de-anonymize Bitcoin.
So what? Iâve done nothing wrong
Itâs easy to fall into the trap of thinking that you, presumably a law abiding citizen, have nothing to gain from privacy. There are a few problems with this line of thinking:
First, the government isnât the only entity out there trying to snoop on you. Unsavory attackers are also collecting as much information as they can to identify marks. Second, your government may be fine and trustworthy, but many governments in the world are not. Financial tools are needed to help citizens of these nations express their financial self sovereignty and find financial inclusion. Third, a lack of privacy actually has a chilling effect on a monetary system. It can even destroy the money.
Fungibility
Money â at a minimum â must be scarce, divisible, transferrable and fungible. Fungibility is a fancy way of saying all units are worth the same amount. If you have a ten dollar bill and I swap it out for another ten dollar bill, you donât mind. They have the same value, and thus ten dollar bills are considered fungible.
Fungibility is dependent on money carrying no history. If cash could speak, suddenly a bank note that was received from selling drugs or stolen goods would carry extra risk. This risk would cause that note to be worth less, breaking fungibility. Please note that this is a problem not only for criminals, but also for innocent individuals and merchants who are accepting payment. Suddenly, theyâre responsible for doing diligence on incoming payments to ensure they wonât be looked at funny, or worse â called in for questioning by law enforcementâ when it comes time to spend their money.
Recall that a bitcoin is defined literally as its chain of custody. Each and every bitcoin has a fully transparent history recorded on the blockchain. Many are now in the business of understanding the flow of the bitcoin stock. Requiring everyone to check various lists adds significant friction, damaging bitcoinâs utility. Breaking fungibility has a chilling effect on bitcoin acceptance, and itâs not a theoretical threat.
Remedies
Financial privacy means being able to transact without revealing or leaking identifying information. The goal is to make it as difficult as possible for others to profile your crypto use. Privacy puts the user in charge of their data. They can remain compliant by selectively revealing themselves without revealing their activity to the entire world.
When making a payment, itâs of course impossible to avoid creating observable information. At a minimum, the recipient must be able to confirm the funds are now theirs. It is however possible to limit how much information is created, how identifying it is, how long the information lives, how far it spreads, and who has the ability to interpret this information.
Itâs important to note that following are just a sampling of efforts to improve privacy on the blockchain. More technologies are being proposed and developed all the time.
Bitcoin
Today, most bitcoin wallets and users are atrocious at privacy. The following are common and damaging for privacy:
- Wallet address re-use, linking your transactions together into a single profile. Note: Ethereum is designed to encourage this behavior.
- IP address re-use, hinting to the world that a single party â you â controls various addresses.
- Combining inputs from multiple transactions, revealing the contours of addresses you control.
- Using lite clients, effectively revealing to a third party your full set of addresses.
Using bitcoin privately is an expert level undertaking, and an uphill battle. Each bitcoinâs history is permanently etched in a transparent ledger. Therefore, even if the tools to de-anonymize donât exist now, they can be developed and deployed later â publicizing previously thought private activity. However, that doesnât mean broken fungibility will doom bitcoin as a medium of exchange.
Many schemes have been devised to erase a bitcoinâs history â restoring privacy and preserving fungibility.
Existing
- CoinJoin offers the ability to join transactions together creating ambiguity about who is paying whom. JoinMarket takes it a step further and commercializes this process on a decentralized market place. CoinJoin violates clustering heuristics used by blockchain analytics companies to identify wallets, creating a modicum of plausible deniability for ordinary bitcoin users. One drawback is that these technologies are interactive, requiring all participants be online.
- Commercial mixers (offshore altcoin exchanges can serve the same purpose) can be used to exchange bitcoins tied to your identity for ones that are not. One weakness with this approach is that it requires trust in the entity performing the mixing. The mixer can steal your funds and they also may keep logs that link your transaction history. These entities are also heavily targeted by governments and could even be honey pots.
Proposed
- Confidential Transactions is a scheme invented by Gregory Maxwell for hiding the transaction amounts. It uses incredible math called homomorphic encryption along with range proofs to completely obscure transaction amounts while still verifying that no coins are created out of thin air. This improves privacy by preventing others from learning your account balances and also prevents analysts from tracing funds based on amounts. By hiding the amounts, it greatly strengthens transactions using CoinJoin.
- TumbleBit improves on existing mixers by preventing the mixer itself from being able to link the payer and payee. It accomplishes this in a way that does not require trusting the mixer.
- Schnorr Signature Aggregation + CoinJoin takes CoinJoin to the next level by providing an economic incentive to participate. Wider adoption improves the privacy benefits for everyone. Schnorr signatures allow a fixed size signature to authorize an arbitrary number of inputs. When users combine their transactions, theyâll not only gain privacy, but also shrink the size of their transactions, reducing fees.
- Lightning Network is a payment layer built on top of bitcoin. Itâs essentially write caching and aids in privacy by preventing many transaction details from ever reaching the blockchain, limiting the scope of whoâs able to observe them. Payments are aggregated off chain and details are learned only by people directly involved.
DASH
DASH is a fork of Bitcoin that was originally called Darkcoin. It was pitched as a more anonymous version of Bitcoin. DASH uses incentivized nodes called masternodes to operate the CoinJoin protocol at the protocol level. One weakness in this approach is that the masternodes are able to trace funds, and many believe that law enforcement are running honeypot masternodes.
Since the privacy features are weaker than other coins and Darkcoin sounded a bit nefarious, the coin was rebranded to DASH which stands for Digital Cash. It remains an interesting coin thanks to its better than nothing privacy and its efforts to become the easiest to use cryptocurrency in the world.
ZCash
ZCash offers privacy through a scheme using a technology called Zero Knowledge Succinct ARguments of Knowledge, or zk-SNARKs. A zk-SNARK is a proof that something is true without revealing anything (zero knowledge) about what specifically makes it true.
This scheme, called Zerocash, was first proposed for Bitcoin. The basic idea is that rather than publishing the transaction graph transparently on the blockchain, we instead give each coin a serial number and deposit it into a pool with many other coins. When it comes time to spend, we prove ownership of our coin with a zk-SNARK without revealing which one. Itâs a theoretically perfect global mixer.
Bitcoin protocol development remains quite conservative, and ambitions to incorporate Zerocash into Bitcoin have been largely abandoned. ZCash is the first production use of this technology, and continues to be a promising experiment.
Monero
Monero is a fork of the CryptoNote protocol. The protocol aims to achieve privacy through a its use of traceable ring signatures, stealth addresses, and most recently an adaptation of Confidential Transactions called RingCT.
Monero obfuscates the transaction graph through ring signatures. When a payment is made, a passive (can be done offline) form of mixing is used to combine the input being spent with decoy inputs. A ring signature proves one of the inputs is controlled by the user, but the real input and decoy inputs are indistinguishable without further information. To prevent double spending an input, the ring signature also emits a key image that is unique to the input being spent, without revealing which input. This set of key images must be retained forever making Monero a bit more difficult to scale than other protocols.
Stealth addresses are random single use addresses that prevent users from being able to identify who the recipient is or whether any two given payments are being sent to the same recipient. The newest tool in Moneroâs arsenal, RingCT takes the Monero to the next level by concealing the amounts and allowing spenders to mix with inputs of any denomination.
Conclusion
Hiding oneâs financial affairs from a motivated nation-state will likely be out of reach for all but the most careful and skilled. However, hiding oneâs affairs from the average cashier at the local corner store should be possible, and my preference is that it is easy and handled for the user by default.
Privacy and fungibility are inextricably linked and needed for a frictionless and sound money system. Privacy is not binary, but rather a smooth continuum and a protracted arms race between privacy seekers and destroyers. Over the next decade, it should be fascinating to watch this story unfold.
Thanks to Adam Back and Linda Xie for reviewing drafts of this post.
Networked Liquidity
By Radar Relay
Posted October 7, 2017

Projects solving the chicken and egg problem
At Radar Relay we are excited for the arrival of the new Modular Trade Network (MTN) ecosystem. In fact, we created https://relayer.network to lay out our high-level vision of the future. While it is fun to dream about what the future landscape of decentralized applications will look like, we are still in the very early days. This post focuses on looking into the short term of MTNs, projects developing there, and how Radar and other relayers fit in.
Weâll be using the phrase ânetworked liquidityâ quite a bit. For those new to the term, weâve defined our perspective.
Similar to network effects, the phenomenon where a product or service gains additional value as more people use it, decentralized networked liquidity aggregates liquidity pools from projects built on Ăx for enhanced utility and value.
Chicken and Egg Problem
Networked liquidity is about to face an age-old dilemma: the chicken and egg problem. For the liquidity networked by relayers to be useful it must also be functional, and for it to be functional there must be enough utility and volume to not disrupt its other utilities.
If No One Spends Bitcoin, How Can It Have Value?
By Elaine Ou
Posted October 9, 2017

Medieval mint, engraving by Leonard Beck (1516).
Itâs hard to imagine a world without penny candy and nickel newsreels, but for most of human history, petty transactions were a pain in the ass.
Prior to the Industrial Revolution, coinage was a labor-intensive process. Metal had to be melted, refined, hammered, and cut. Because it took just as much effort to hammer out a small coin as it did a big one, mintmasters were inclined to create only the largest denomination coins.
If it werenât for taxation and church collections, the state would have had no reason to issue small denominations at all. To encourage the creation of small change, medieval states authorized seigniorage â mints reduced the relative quantity of silver in small denominations to offset production costs.

Production costs of coinage (brassage).
Debasement! Where legal tender laws are enforced, bad money drives out good. Creditors complained that debts were being repaid in shittier coins than what was lent out. In states without legal tender, the large-denomination coins became the unit of account, and smaller coins had a floating exchange rate depending on their level of debasement.
The more the small denominations were debased, the worse the exchange rate got. Seeing small denominations as a poor store of value, people melted them for the commodity silver, exacerbating the small-change shortage. Small coins provided liquidity, but the liquidity service was not valuable enough to counteract debasement.
The biggest transaction cost is trust.
The title question is backwards. Value does not come from the ability to spend; the ability to spend comes from value. The full-bodied large coins were more valuable than liquidity-providing small coins because the gold and silver content securely constrained their supply.

There are plenty of cheap solutions for illiquidity. When small coins were scarce, retailers and craftsmen issued lead and copper tokens as a substitute for change. The tokens had no commodity value, but customers accepted them because they trusted their local businesses.
Foreign trade doesnât have the benefit of localized trust, so merchants must rely on a scarce and unforgeable intermediate commodity. The Group 11 elements (Copper, Silver, Gold) have been universally employed as coinage metals thanks to the eons-old neutron star collisions that created a limited supply. Their shared electron configurations make them pliable and corrosion resistant. Atomic weight corresponds to the required energy input and hence, unforgeable value.

Thereâs no cheap substitute for securely constrained scarcity, especially since humans are so good at making scarce things abundant. Domesticated livestock, designer knockoffs, genetically engineered plants. Even labgrown diamonds are nearly indistinguishable from the real thing. We try to mimic scarcity with patents and licensing and zoning regulations, but these are all expensive solutions. Fiat money pretends to be scarce, and that costs us $600 billion a year.
[
People are trying to make Bitcoin knockoffs. After all, itâs human nature to want to make a scarce thing abundant. If they succeed, then Bitcoin has no value. But if Bitcoin has no value, how can anyone spend it?
See Also:
- Nick Szabo, Unforgeable Costliness, 2004.
- Thomas J. Sargent & François R. Velde. The Big Problem of Small Change, 2002.

A Crash Course in Mechanism Design for Cryptoeconomic Applications
By BlockChannel
Posted October 17, 2017
Understanding the Basic Fundamentals of âCryptoeconomicsâ

Note: This post was written byAlex Evans, and was edited bySteven McKieforBlockChannel
If youâve spent any amount of time in the cryptocurrency world in 2017, youâve probably come across the term âcryptoeconomics.â If not, you can perhaps be excused for missing it among some of the more entertaining linguistic creations in the cryptocurrency space. This post by Nick Tomaino and this video by Vitalik Buterin should get you up to speed.
In short, cryptoeconomics describes the combination of cryptography and economic incentives to design robust decentralized protocols and applications. According to this strain of thinking, Bitcoin succeeded where other decentralized protocols failed, not because of Proof-of-Work, the idea of decentralized cash, or even fault-tolerant consensus, but because it incorporated cryptoeconomics at the core of its consensus protocol. The grand vision of cryptoeconomics is therefore to extrapolate this success to embed cryptoeconomic incentives into everything â transactions, computation, storage, prediction, power.
Blockchains enable us to enforce scarcity and facilitate value transfer in areas where that would otherwise be impossible and, therefore, radically expand the range of problems to which economic incentives can successfully be applied. Viewed through this prism, cryptoeconomic systems are fundamentally new ways of incentivizing human behavior. And their potential is massive.
While this may be easy to see in theory, actually designing economic incentives is hard. In fact, there is an entire sub-discipline of economics dedicated to studying how to design protocols that incentivize rational actors to behave in socially desirable ways. This is called mechanism design. Though much ink has been spilt on the topic of cryptoeconomics in the last few months, we have little evidence that formal methods from mechanism design are being incorporated in the development of most new blockchain protocols (with some notable exceptions that will be discussed).
To put it mildly, this represents a missed opportunity. Others have stated it more assertively:

The purpose of this post is to introduce the basic concepts of mechanism design, and give a taste for their usefulness in the cryptocurrency world. If youâre working on a blockchain protocol or application, this will ideally provide you with some introductory resources for accessing the literature of mechanism design. My hope is that you walk away from this post, 1) convinced that mechanism design is extremely important to building robust decentralized systems and 2) equipped with the basic resources to start learning how to use tools from mechanism design in your own work. Please note that I am not expert on either crypto or mechanism design and would love feedback on this post from those of you who are.
To start, I provide a brief description of the key concepts and definitions from mechanism design. The goal is to introduce the basic vernacular of mechanism design in the most accessible way possible, in order to make the subsequent discussion of cryptocurrency applications comprehensible. This is not meant to provide a formal introduction to mechanism design. That is better accomplished by reviewing one or more of the following:
This chapter
by Vincent Conitzer;
This article
by Matthew Jackson and
his two-part course
with collaborators; Chapter 7 from
this introductory text
on Game Theory by Fundenberg and Tirole
Note that these are just a few resources that I found useful to getting introduced to the subject. Since mechanism design is an established area of economics research, Iâm sure there are many others. If you know of any additional materials that you would recommend, please list these in the comment section.
What is Mechanism Design?
A useful caricature is to think of mechanism design like inverse game theory. In game theory, we take the game as a given and analyze its outcomes according to playersâ utilities. In mechanism design we start by defining desirable outcomes and work backwards to create a game that incentivizes players towards those outcomes. Another (similarly caricatured) way of looking at it is to think of game theory as the positive side and mechanism design as the normative side of the same coin.
For example, you may be designing an auction where the goal is to allocate a good to the participant with the highest utility for it. Assuming everyone has some utility for the good, participants have an incentive to lie. So how do you design a game that incentivizes everyone to report their utilities truthfully? Should you implement open or sealed, ascending or descending bids? Should the winner pay the highest announced price or some other price? Equivalently, when designing a voting process that always choses the candidate that all voters prefer over all other candidates, should you chose winners based on plurality or majority? should there be one or multiple rounds of voting? Should voters submit a single choice or preference ordering? These are typical questions in mechanism design.
Some Definitions
Formally, a mechanism includes a finite set of players and a set of potential social decisions. Think of a set of voters and the group of potential candidates that can be chosen by the society. Players possess private information, also referred to as signals or types. Each individualâs type can represent her preferences â such as her preference for candidate A over B or her valuation for a good being sold in an auction â but the type can also be used to encode other types of private information â for example, she alone may know whether the good being sold is of high or low quality. We may also have a common prior, which is a probability distribution over types. Think of this in the context of poker: you may not know the playersâ hands, but you know the probability of each hand occurring in a deck of 52 cards. Since the âoptimalâ decision will inevitably depend on individualsâ types, we also typically define a decision rule, which maps types to social decisions.
Individualsâ utilities will thus be a function of their reported type (i.e. what they tell the type/preference aggregator, which may not be true), their actual type, and the output of the decision rule. Furthermore, we frequently include transfer functions, where a transferrable good (conveniently like a token) is used to incentivize players, usually by capturing the externalities that their actions impose on others. We can thus envision the social choice function, which maps reported types to outcomes as having segregated monetary and non-monetary components. This is what is being talked about when you see references to âquasi-linearâ utilities, i.e. preferences are linear in the monetary/transfer component.
In practice, as a designer you get to control the choice of mechanism, but not the players or their types. You may see these âgivenâ elements referred to as the setting. Adding a mechanism turns this Bayesian setting into a game (also referred to as a âgame formâ). Formally, a mechanism is a pair of message/strategy spaces and a function which maps messages/strategies to resulting social decisions and transfers. The mechanism can be deterministic, always outputting the same decision and payouts for a given, or can be probabilistic/randomized according to some rule.
The central task in mechanism design is to
specify a mechanism that incentivizes rational agents to behave in certain ways, based upon their private information, that lead to socially desired outcomes
.
Generally, a mechanism is said to âimplementâ a social choice function if, in equilibrium, the mapping from types to outcomes is the same as the mapping that would be chosen by the social choice function (you might therefore see mechanism design referred as âimplementation theoryâ). We can require this to be an implementation in dominant strategies (where this holds for the agent regardless of the strategies of other agents) or simply an implementation in Bayes-Nash equilibrium (where no player has profitable deviations based on their beliefs about other playersâ types and the strategies of those payers). The former obviously being a much stronger (and hence more limiting) assumption.
The Revelation Principle
One of the foundational results in mechanism design is the Revelation Principle. In very broad strokes this states that any social choice function that can be implemented by any arbitrary mechanism, can also be implemented by a truthful, direct-revelation mechanism with the same equilibrium outcome. Here, a direct-revelation mechanism is one where agents simply declare their types to the mechanism, leading to a decision and set of transfers. A direct-revelation mechanism is truthful if truthfully reporting preferences is a dominant strategy (though, in the general case, we can require this to just be true in a Bayes-Nash equilibrium). You will find such mechanisms referred to as truthful, incentive compatible, or strategy-proof. The revelation principle has exceptionally powerful implications. In short, if youâre able to prove something to be true for these mechanisms, you have proved it to be true of all mechanisms! To see why this is true, imagine a random untruthful mechanism with an interface layer, which takes your preferences and strategically interacts with the mechanism to maximize your payout (like a fiduciary). Then you wouldnât want to misreport your true preferences to the interface or you would get suboptimal payout. In essence, you donât have to lie, because the mechanism lies for you! The observation that there is no loss in generality by focusing on just truthful, direct-revelation mechanisms is the key result that makes mechanism design work. Otherwise, you would have to prove theorems to be true for the massive set of indirect or untruthful mechanisms, which would make the subject practically useless.
Mechanism Design as Constrained Optimization
Now that weâve defined some basic terms, what are the types of outcomes we can use mechanism design to enforce? What is a âgoodâ mechanism and how do we make sure we select it? You can think of this is as an optimization problem, where you are trying to maximize an objective function (such as your revenue), under a set of constraints. It makes sense to introduce some of the more common constraints you will come across.
Incentive compatibility is perhaps the most frequent constraint you will encounter. Other common constraints include individual rationality, where no agent loses by participating in the mechanism and efficiency, where the sum of individual utilities are maximized (not including monetary transfers). Budget balance constrains the mechanism to transfers that net to zero across individuals, while weak budget balance (also referred to as feasibility) simply requires that the mechanism not pay out more than it receives. A key problem that arises in the theory of mechanism design is that constraints, such that budget balance, efficiency, and individual rationality are often impossible to simultaneously satisfy under incentive compatibility and several impossibility theorems have been proven. Generally, the features of mechanisms can be said to hold for agents ex-post(regardless of the types of the agents), ex-interim(given any type for the agent and in expectations of the types of other agents), or ex-ante (i.e. in expectation over their own and other agentsâ types). Returning to our poker analogy, you can think of what claims you can make before any cards are drawn from the deck (ex-ante), when you know your own hand (ex-interim), and when all hands are revealed (ex-post).
Imposing constraints will typically leave you with a set of several mechanisms to choose from, converting mechanism design to a (constrained) outcome optimization problem. For instance, in an auction you may be looking for an incentive compatible, individually rational mechanism that maximizes revenue. You may need your mechanisms to be efficiently computable, or to satisfy more complicated social goals such as equitable distribution of value. Those are just some examples and the list is practically infinite. As weâll see in some of the examples, formally stating the goal of the mechanism can itself be one of the more difficult problems in mechanism design.
Vickrey-Clarke-Groves Mechanisms
A set of very powerful mechanism that you will encounter frequently are known as Vickrey-Clarke-Groves mechanisms. To explain these, letâs first think about an auction where a single good is being sold. Perhaps, the most obvious design would be to have all participants write down the price they would pay on piece of paper. After the bids are revealed, the player who bid highest price will receive the good and pay the price she bid. This would obviously not be incentive-compatible, as any player bidding her true value for the good would receive a utility of zero. A far better mechanism for incentive compatibility would be to allocate the good to the player with the highest bid, but have her only pay the value of the next highest bid. This is called a Vickrey auction. Each player in this setting has an incentive to bid her exact valuation for the good.
A generalization of the Vickrey auction, is the pivotal mechanism (also called the Clarke mechanism or âtheâ VCG mechanism, though VCG can sometimes refer to the more general class of mechanisms). The mechanism works as follows. For every individual, we run the mechanism without her and choose the outcome that maximizes the utility of all other players given their reported types. Then we include the individual and run the mechanism again. The latter is the outcome chosen. Each player pays (or collects) the difference between the sum of utilities for the other players in the two cases. Effectively, this payment is equivalent to the individualâs social cost or benefit. Since the individual has no way of affecting the sum of utilities that occurs without her, she is effectively trying to maximize the sum of her own and everyone elseâs utility. But this is exactly the same as maximizing total social utility! Aligning incentives in this way ensures not just incentive-compatibility, but also guarantees efficiency. It is also easy to find ex-post individually rational and weakly budget balanced versions of this mechanism with some pretty mild additional assumptions. We can also add arbitrary terms to the payout that the individual canât influence (such as giving each individual some constant amount regardless of the outcome), without changing the underlying incentives. This more general set of mechanisms are called Groves Schemes, which are always dominant strategy incentive-compatible. They also happen to be to be the only efficient mechanisms where truth is a dominant strategy.
Though Groves Schemes are clearly a powerful class of mechanisms, they are highly susceptible to collusion between actors. We will see later how this can be highly problematic in a cryptoeconomic setting.
Straightforward Applications
Now that we have assembled the basic ingredients from mechanism design, letâs look at some potential applications to the cryptocurrency world. I start with by mentioning (a non-exhaustive set) of direct applications, before we dive into more involved areas of research.
One of most obvious and direct applications of mechanism design is token sales. Auction theory is by far the most developed application space for mechanism design. Mechanisms for auctions have also been studied extensively in computer science, in no small part due to the fact that large technology companies like eBay and Google derive most of their revenues from online auctions. If youâre planning a token sale this is where you can find true âoff-the-shelfâ solutions from studying mechanism design (though we will encounter some of the failures of traditional auction theory in a crypto setting later on). You can find some arguments about competing token sale models, here, here, and here. Many of these can trivially be formulated in terms of traditional auction theory.
Prediction markets, which have recently seen several decentralized variants, are another example of an area where traditional mechanism design research has a lot to say. Here, the objective might be to specify incentive compatible mechanisms that extract the true beliefs of agents about the probability of different events in order to make accurate predictions. As with auctions, the theory has tools to deal with more sophisticated assumptions, such as situations where agents behave strategically and/or may seek to manipulate the beliefs of other agents in order to alter market prices in their favor. There are also some more awkward problems, such the fact that agentsâ private information isnât always easily convertible to discrete probabilities. For example, say I have a friend on the coaching staff for Golden State who told me that Steph Curry injured his ankle. Itâs not clear how a piece of private information like this can be converted to a precise probability for whether Golden State will win their next game (P.S., I harbor no ill will for Steph Curry or his ankle). As with auctions, a special set of problems arises when considering a decentralized version of these markets. I refer you to projects such Augur or Gnosis, though more theoretical treatment of the topic of decentralized prediction markets can be found here and here.
Analyzing Namecoin
This paper by Carlsten et al is a great example of how mechanism design can be used when reasoning about decentralized systems. The authors argue that while Namecoin solves a critical technical problem (effectively squaring Zookoâs triangle), the system runs into a number of thorny economic challenges. The article shows that barely 0.02% of registered domains belonged to non-squatters and displayed non-trivial content at the time of writing, while the secondary market for domains was practically nonexistent. I believe this reinforces the point that as a protocol creator, you simply cannot neglect the design of proper user incentives, regardless of technical merits of your project.
What makes Namecoin suitable for mechanism design is the intrinsic scarcity of human-meaningful domains, which necessitates a proper resource-allocation process. The authors therefore deploy mechanism design thinking to explain Namecoinâs failures and reason about the goals of decentralized namespaces under different user utility models. This demonstrates one of the trickiest challenges of mechanism design in practice: specifying the model of user utilities and deriving clear design objectives. For instance, if we assume agents to have fixed, independent preferences for each name, then a Vickrey auction will result in an efficient outcome (as discussed in the introduction). If, more realistically, we assume diminishing marginal utilities for names (e.g. John Doeâs utility for the domain âJohnDoeâ is significantly lower after he has already received the âJohn_Doeâ domain), then perhaps similar results can be achieved through the priority mechanism. However, when incorporating time-varying preferences, the mechanism design problem becomes too complex to even clearly articulate what the goals of the system should be.
The analysis also looks at the effects of different choices in the design space: How strong should the individualâs control over a name be? How should the primary market allocate names? How should the system redistribute revenue from name sales? Methodically laying out the design space in this manner and analyzing economic tradeoffs is an indispensable tool in designing any blockchain application. Beyond serving as a case study for how mechanism design can be used to analyze decentralized systems, the analysis also reveals several practical paths forward for improving Namecoin: higher fees to deter squatters, deploying auctions/algorithmic pricing schemes to narrow the gap between the price for a name and its true market value, and a mechanism for users to recuperate investment by returning unused names to the primary market.
Open Challenges: Ethereum Foundation
Perhaps the most active research about applications of mechanism design in the cryptocurrency world is the work of the Ethereum foundation. To get a sense, I again refer to you to Vitalikâs video linked to in the introduction, as well as this deck. Of particular importance are the security models that he proposes and assumptions used, so it makes sense to briefly review these here for completeness.
A common model used in traditional fault tolerance research is the honest majority model, which assumes that at least 51% of participants are fundamentally honest. Vitalik and company argue that this can be a problematic assumption. As such, researchers should instead reason about security under specific assumptions about 1) The level of coordination between participants; 2) The budget of the attacker (the maximum amount the attacker would have to pay) and 3) The cost of the attacker (the actual cost incurred by the attacker). Correspondingly we can think of several different security models, outside of honest majorities. We can then look at fault tolerance and cryptoeconomic security margins (i.e. the economic cost of violating certain protocol guarantees) under the assumptions of each model.
Uncoordinated majority models assume protocol participants make independent choices and no actor controls more than a given percentage of the network (here participants are self-interested and not necessarily honest). Coordinated choice models on the other hand assume that most or all actors are colluding through some agent or coalition of agents, though we can sometimes assume free entry from non-colluding actors. The bribing attacker model is one where actors make independent decisions, but an attacker exists who can incentivize other actors to make certain choices through conditional bribes. For illustrative purposes, take a look at the Shellingcoin example Vitalik uses in both presentations. In short, in a model where payments are only made to actors who vote with the majority, an attacker can guarantee a fixed payment higher than that of voting with the current consensus to those who deviate from the consensus and end up in the minority. The attacker can thus effectively corrupt the game with a high budget, but an actual cost of zero, as none all the bribed defectors end up in the majority. Bitcoin and other proof-of-work protocols are, at least in theory, susceptible to this type of attack (though someone would have to credibly demonstrate a massive budget).
Introducing Cooperative Game Theory
As a supplement, I also found this story from Vlad Zamfir to be especially interesting. It chronicles the evolution of thinking in Proof-of-Stake research that led the team to arrive at its current set of cryptoeconomic methodologies as well as the security deposit and penalty mechanism in the current version of Casper. I especially recommend the fourth and fifth parts of the series where he discusses cooperative game theory. Not to spoil the story, but the punchline (to me) is the observation that âblockchain architecture is mechanism design for oligopolistic markets.â Regardless of your thinking on the topic, it is hard to argue that centralization in both cryptocurrency holdings and mining power is not a realistic assumption in practice. What makes this incredibly challenging from a modelling standpoint is that most mechanism design work youâll find addresses settings from noncooperative game theory. Indicatively, some of the most widely studied mechanisms (such as the Groves Mechanism introduced above), collapse under assumptions of collusion between agents.
Thankfully, cooperative/coalitional game theory is a well-developed field and you can find many good introductions online. Generally, the goal is to analyze what types of coalitions can be created, what the payouts are under each (through a function called the characteristic function), and how the coalition should divide its payout to achieve goals such as stability. Often, we think about the grand coalition where all agents participate (e.g. everyone mining on the longest consensus chain) and think about distributing the payoffs under a transfer scheme/solution concept called the Shapley Value, where each individual receives her marginal contribution to the coalition. We could also often think about the âcoreâ set of imputations (individually rational and efficient payments), where coalitions of agents donât have an incentive to deviate and analyze stability based on whether this set is empty vs non-empty, unique vs not. Following Vitalik et al, we can think of incentives in two broad categories. One being payments, such as mining rewards (which jive well with our idea of transfers) and the other being privileges, which allow their holders to extract rents, such as transaction fees.
Smart Contact Applications
Beyond analyzing the consensus layer, Vitalikâs presentation discusses direct applications of mechanism design to smart contracts. For example, the Vickrey auction that we had so many nice things to say about can suffer from challenges in a crypto setting. For example, users could submit multiple bids and selectively open the one that guarantee the highest payout. You could then may respond by suggesting a deposit to deter such actors. But then you would have to specify a deposit size relative to the bid size in the mechanism, which can destroy the key features of the sealed-bid, second-price auction. The challenge Vitalik identifies is that mechanism design often relies on a trusted intermediary to ensure correctness and privacy for players. A blockchain can guarantee correctness, but not privacy.
There are also typically more factors to specify in the cryptoeconomic setting than in traditional applications of mechanism design. In centralized settings, we often think of a central agent running the mechanism in a way that maximizes revenue subject to certain constraints. This makes things much simpler to analyze. In a decentralized setting, however, we may have to define an algorithmic agent to ârunâ the mechanism and have to reason carefully about the behavior of that agent in the mechanism as well as the implications for the monetary policy of the protocol. For example, if we expect the mechanism to violate budget balance, should the agent redistribute revenue to players? Should excess currency collected be removed from circulation? Should the agent be able to mint new currency when making transfers to players? These questions require close attention, as decisions can introduce undesirable kinks into the incentives of players (e.g. maximizing the amount to be redistributed can become a non-trivial component of their utility).
Final Thoughts
While mechanism design has become a staple in computer science research, few entrepreneurs and developers appear to be thoughtfully applying this type of thinking to designing blockchain protocols. Even fewer academic economists have started to seriously study the game theoretic properties of blockchain protocols.
That said, I am optimistic that as the enormous opportunities presented by cryptoeconomics become clearer, these disjoint communities will start to converge. In the interim, I hope that you found this article to be useful in introducing some of the tools and open questions that definite the possibilities of cryptoeconomic mechanism design. For feedback, comments, and discussion, feel free to get in touch at alexander.evans@lowes.com (Loweâs Ventures) or in the comment section.
Want more perspective? Hereâs a recent post by Coindesk.com also explaining âcryptoeconomicsâ:
Why You Canât Define Bitcoin
By Beautyon
Posted October 18, 2017


Everyone ends up trying to define Bitcoin at some stage, and the prosaic descriptions of it are as varied as the people who come up with them. I put it to you that trying to define Bitcoin is pointless, and causes more trouble than the benefits of the understanding a definition may bring.
Imagine someone involved in software who has taken it upon him or herself to appear before regulators to define Bitcoin. They run a business that uses Bitcoin, in this case, a company that keeps track of cupcakes. When the regulator gruffly asks what Bitcoin is, without the sugar coating, this person says, âIt is a way of keeping track of cakeâ.
This description is not wrong. Bitcoin can be use to keep track of who received what cake, but thatâs like saying, âTweezers are for picking your noseâ. Yes they can be used for picking your nose but they can also be used for sorting rough diamonds.
Since Bitcoin can be used for literally any purpose, it is entirely wrong that self appointed men and women try and force their private definitions on millions of other people. Itâs totally unethical to tell other people what they can and cannot do with their software, and this is the direct end result of well meaning computer illiterates running to legislators to define Bitcoin.
The best of these people admit that they may be wrong, but that makes their crime even worse. They are appealing to authorities to regulate Bitcoin admitting that they donât understand it fully; and of course, itâs certainly true that they canât see the future, and have absolutely no idea whatâs coming next.
Youâre free to write whatever you want (unless its software apparently, then you need a license to do so in New York), to speculate and run thought experiments in public. All of that activity is very useful, and enjoyable. What is not at all useful is to try an definitively pin down Bitcoin using an analogy, that will be weaponised against everyone by thugs. You donât need to go to the enemy to explain Bitcoin to him; his lack of understanding is an asset. Do you really want very powerful people who are about to be put out of business and who are in bed with the State to be given advance warning?
Are you really that stupid?
So what if the fossil class donât understand Bitcoin? Who cares? How will that fossil class understanding Bitcoin help you discover and build your products? There is no way they are going to invest in your company because they donât understand what you are doing, and if they did, they would understand that you are an existential threat to them, and theyâll dial it up to 11 to try and destroy you completely, and openly boast and threaten that this will happen.
Your best manĆuvre is to be quiet, stop running to appear before committees and congress and regulators and work on your software and business model. This is how Skype managed to start a telephone company without any regulators bothering them. In case you didnât know, you are not making anyone feel safer when you talk about âdisruptionâ; you make them feel and look stupid, and this is perceived as an open threat to them. Disruption is what happens in blizzards and hurricanes. It makes people frightened, and yet you explicitly say that disruption is coming, and speak in terms that are incomprehensible to them and make them feel uncomfortable.
MISSION ACCOMPLISHED
Bitcoin is software. That means it is infinitely flexible, and can be used to do literally anything. Your narrow vision of what it will do, a person who admits that you may not understand it yourself, should not be the standard by which everyone has to conform; your ideas are your problem, not anyone elseâs.
As I said before, all of this is going to end up in court. Then the florid, image soaked descriptions of Bitcoin will be stripped away, and we will be left with the actual definition of Bitcoin, which is the correct one:
IT IS SOFTWARE
We will prove this categorically, and no judge will be able to say we are not correct, because we will prove it. Two judges have already handed down decisions pointing in this direction. The age of the do good âBitcoin Analogizerâ is coming to a welcome end. When it ends, all the pointless arguments will end, and the people pushing narratives will have to come up with some new narratives somewhere else.
But theyâre good at that, so it wonât be a problem!
No one can stop you sending Bitcoin to this address. It is an act of defiance. âŽ

The Slow Death of the Firm
By Nick Tomaino
Posted October 21, 2017
Most people think of Bitcoin as a digital asset, but it can be thought of as something more general than that: a decentralized organization. Years from now, Satoshiâs creation may be looked at as a catalyst for the slow death of the firm.

The slow death of the firm may already be underway
Why do firms exist?
Economists typically suggest that firms exist for two main reasons: to minimize transaction costs and to aggregate capital and people. Ronald Coase wrote about the firmâs ability to minimize transaction costs in 1937 in his famous essay âThe Nature of the Firm.â Seventy five years later, Nicholas Vitalari and Haydn Shaughnessy wrote about the firmâs ability to aggregate capital and people in the Elastic Enterprise. In addition to the economic arguments, some argue that firms provide people with structure and stability (i.e. job security), which risk-averse humans inherently seek.
Firms have played an important role in society for decades for these reasons (and likely a variety of others). Despite their prominence, most people dislike them.
Bitcoin thrives with no firm
In January of 2009, Satoshi released software that combined cryptography and incentives to offer users a digital service (a ledger to store and transfer value) that persists over time without any central party behind it. There is no firm behind Bitcoin; thereâs simply code (rules for organization) and incentives (the BTC token) that brings together many different participants who are all incentivized to contribute their time and resources to maintain the service.
Bitcoin relies on proof-of-work consensus to secure the network and align the workers in the network. There are three types of workers in the network: miners, developers, and users. The miners work is measured objectively and that work gets compensated directly from the protocol: hash power contributed to the network earns BTC. To be a miner, you just need electricity and an Internet connection and you can earn BTC. Miners are the only group of workers that get paid directly from the protocol and the other two groups (developers and users) work indirectly for the protocol if they own BTC. If developers and users add value through coding, holding, or marketing, they add value to BTC and the BTC they own appreciates.
This new organizational structure has resulted in close to $100B worth of value creation (today the total market value of Bitcoin is now larger than the market capitalization of Goldman Sachs).
So what?
Bitcoin is the first example of an organizational structure that has the beneficial characteristics of the firm (minimizing transaction costs, aggregating capital and mindshare, and providing job security for contributors) combined with some new characteristics:
- Ownership isnât controlled by an exclusive group of founders, employees, and investors
- Data isnât controlled by any one entity
- Decision making power is not controlled by one person or group and there are checks and balances from a broad variety of market participants
These things donât seem important to most people today. But I think they will ultimately allow decentralized organizations to impact billions of people by:
- Offering new earning opportunities to people around the world who otherwise would not have them (without favoring people in any particular jurisdiction).The internet is global but the economy is still not truly global. Blockchain-based organizations that arenât bound to a physical location offer new earning opportunities to billions, as the elimination of a legal entity reduces the need for legal contracts and friction and opens up new short-term, global labor opportunities. 1protocol and21.co are two examples of platforms that have the potential to open up new labor opportunities for billions.

A microtasks marketplace is one of many blockchain-native services offering new earning opportunities globally
- Creating clear incentive alignment between users, employees, and founders. In traditional firms, the incentives between users, employees, and owners are often not clearly aligned. When a token on a global blockchain is the business model, incentives are no longer muddled by legal entities, jurisdictions, and business models that conflict with the best interest of the users. I see a future world where users have ownership of the products they use.
- Creating new products that werenât possible with firms.Bitcoin is the best example of this to date â p2p cash had been attempted before but was always thwarted by regulators. Bitcoin came along and the decentralized nature made it resistant to being thwarted by regulators. It turns out that traditional firms fundamentally cannot build some products that people want and need.
So if Bitcoin has demonstrated the positive characteristics of a firm along with all of the added benefits of a decentralized org, why isnât the death of the firm obvious?
There are clear hurdles holding back decentralized organizations from broader adoption
The main challenges that come with this new organizational structure are:
- Decentralized decision making is hard.To date there are no clear best practices around governance and there is still a lot of learning to be done. Bitcoin has a truly decentralized governance structure (thereâs no founder that the community looks to and its very hard to make any changes to the protocol) which works OK if youâre trying to be a protocol that serves as a store of value and doesnât need to iterate much, but does not work well for most early stage technology projects that need to iterate often and quickly. My view is that some centralization of decision making is generally necessary in the early days of a project. The best projects will likely be designed to be decentralized across all facets of the org for the long-term, but not necessarily right from the beginning.
- It is difficult to accurately measure contributions in most types of work today.Bitcoin works well because labor contributed to the system can be measured objectively and is very difficult to game. Most labor still requires some centralized human judgement to effectively allocate resources. There are some interesting efforts in the works around proof-of-stake and other systems that may enable the decentralization of resource allocation across a wide variety of labor types in the future.
- Decentralization means a lot of different things to a lot of people and often gets abused.Some people are religious about decentralization and view anything that is not Bitcoin to be centralized. Others abuse the term and masquerade their centralized âICOsâ as decentralized organizations. Right now itâs difficult to differentiate the good approaches to building a decentralized org from the bad, and not many people are thinking about quantifying decentralization.This is a step in the right direction, but thereâs a long way to go (and there will be lots of blow ups along the way).
Where do we go from here?
Digital assets are now worth over $200B in aggregate and penetrating the mainstream, but weâre still in the very early days of high functioning decentralized organizations at scale.
I think there are two ways that weâll ultimately get to a world of far more decentralized organizations and far fewer firms:
- New decentralized organizations will emerge.Bitcoin is just the first decentralized organization to offer a digital service that people want and need. Ethereum (smart contracts) and Sia (file storage) are others and I think weâre just scratching the surface in seeing innovative approaches to governance, token distribution, and collaboration. Lots of experimentation in these areas is needed.
- Traditional firms will transition to decentralized organizations. Weâre already seeing this happen slowly. Brave and Kik are two early examples of firms that have tokenized and Dust and YouNow are two firms that are in the process of tokenizing. Tokenization is an important first step, but after tokenization itâs equally important that these projects put in place systems that persist over time with good incentive structures and govern themselves without central decision makers. This is easier said than done. Many more traditional companies will follow in this transformation (2018 mayeven be the year of bankcoins), most traditional firms will fail, but there will be diamonds in the rough.
Additional reading:
- The Blockchain Man**describes the practical differences between a world of firms to a world of blockchain-based decentralized organizations
- Vitalikâs The Meaning of Decentralization discusses what decentralization means from a software perspective
- Balajiâs Quantifying Decentralization proposes a framework for measuring decentralization

About me:I run 1confirmation, an early stage crypto fund. Sign up for our newsletter and check out the next Token Summit in SF on December 5th.
Velocity of Tokens
By James Kilroe
Posted October 31, 2017
The velocity of tokens is a key aspect that affects future token value; however, it is also one of the least understood. This post attempts to describe velocity, how it impacts any token price over time and analyses the velocity of the Dala token as an example.

Equation of exchange
The equation of exchange is defined as: MV=PT
Where: M= money supply,V= velocity of money,P= average price level of goods, T= index of expenditures (such as the total number of economic transactions)
In token economies, this has been adopted by two prominent people â Chris Burniske and Vitalik Buterin.
Burniske definition: MV=PQ
Where: M= size of the asset base, V= velocity of the asset (the number of times that an average coin changes hands every day), P= price of the digital resource being provisioned, Q= quantity of the digital resource being provisioned
Using the Burniske definition, valuations typically solve for M by rearranging the equation: M=PQ/V
In order to solve for token price, one must calculate M, by working out the size of the market in dollars (PQ), divide it by the velocity (V) and then divide M by the number of coins in supply.
Buterin definition: MC=TH
Where: M= total money supply (or total number of coins), C= price of the currency (or 1/P, with P being price level), T= transaction volume (the economic value of transactions per time), H= 1/V (the time that a user holds a coin before using it to make a transaction)
Using the Buterin definition, to solve for the token price, one must solve for C:
C=TH/M
In either definition, one can see that the velocity of the coin is inversely proportional to the value of the token i.e the longer people hold the token for, the higher the price of each token. This is intuitive, because if the transactional activity of an economy is $100 billion (for the year) and coins circulate 10 times each over the course of the year, then the collective value of the coins is $10 billion. If they circulate 100 times, then the collective coins are worth $1 billion. Thus, understanding and calculating the velocity in any token economy is extremely important.