[IDEA] Native Ethereum Delegation (NED) — Split-Neutral Capacity and Bond-Weighted Delegation Growth
Discussion topic for Native Ethereum Delegation (NED) . This is an idea-stage proposal, not yet an EIP. I’m approaching it mainly from staking incentives/economic design rather than as a consensus-layer researcher, so I’m especially interested in corrections where my protocol assumptions are wrong. Update Log 2026-08-07: Initial idea draft. 2026-08-07: Added split-invariance analysis and bond-backed delegation capacity. 2026-08-08: Reworked the mechanism after further market/adversarial analysis. The original concentration-sensitive reward curve and maturity penalty are no longer part of the proposed core. The current direction uses linear bond-backed capacity plus a bond-weighted limit on gross inbound delegated weight. Outstanding Issues Whether native delegation should exist at the protocol level. Whether delegation domains are the right economic abstraction. Whether slashable collateral is an appropriate basis for delegation capacity and growth. Whether the mechanism improves operator distribution in equilibrium or instead advantages institutions with cheaper capital. Slashing, bond rewards, withdrawal/recovery, redelegation and churn mechanics. Queue financialization through LSTs or secondary markets. Multi-brand domains and the gap between domain diversity and real operator diversity. Concentration at LST/router/wallet layers. Relevant prior work or attacks I have missed. The basic idea Ethereum already has delegation economically. An ETH holder who wants staking exposure without running infrastructure will generally use a staking provider, liquid staking protocol, exchange or similar intermediary: ETH holder → delegation/aggregation layer → validators The protocol just doesn’t provide that delegation relationship itself. So the question I’m interested in is: If delegation has become a fundamental part of Ethereum staking anyway, should Ethereum provide a neutral native delegation primitive and let providers compete above it? Under NED, an ETH holder could delegate through the protocol while retaining ownership and withdrawal control over the ETH, subject to the lock and slashing conditions required for that stake to secure consensus. Conceptually: ETH holder → NED delegation domain → validators The delegator chooses where the ETH goes. The operator does not take custody of the delegated ETH and cannot redirect it. Existing providers could continue offering LSTs, liquidity, DeFi integrations, insurance, institutional services, compliance, interfaces, analytics and other products. Ethereum would provide the delegation primitive underneath them. Rainbow Staking and especially eODS are relevant prior work on operator/delegator separation and Ethereum-native delegation. Delegation domains I think the relevant economic object may be a delegation domain , rather than an individual validator. One domain could operate one validator or thousands. A domain could associate delegated ETH, domain-specific slashable collateral, validators, performance/slashing state and admission/withdrawal state. The important point is that validator keys are not treated as economic identities, and Ethereum does not need to know whether two domains belong to the same real-world operator. Why the original mechanism changed My original idea was to make delegation progressively less rewarding as one domain captured a larger share of native delegated ETH. The problem is fundamental. Suppose delegated stake $D$ earns: $$ R(D)=D,a(D) $$ where $a(D)$ decreases as the domain gets larger. If the same actor divides that position among $m$ pseudonymous domains: $$ mR(D/m)=D,a(D/m) $$ and since $a(D/m)>a(D)$: $$ mR(D/m)>R(D) $$ The original mechanism therefore depended on an unstated assumption that maintaining multiple credible economic identities would itself be costly enough to offset the gain from splitting. I don’t think a permissionless protocol should rely on that assumption. The current direction instead asks whether the relevant economic constraints can be designed so identity count simply does not create the scarce resource . Don’t try to make pseudonymous identity scarce. Make delegated capacity and delegated growth depend on economic state that survives identity splitting. Bond-backed delegation capacity Let: $B_i$ = domain-specific slashable collateral $D_i$ = active delegated ETH $\lambda$ = delegation supported per unit of collateral Raw security capacity is: $$ C_i^S=\lambda B_i $$ A reserve $\mu$ can keep ordinary admission below the raw security limit: $$ C_i^A=\lambda(1-\mu)B_i $$ so normally: $$ D_i\le C_i^A $$ while the broader security condition is: $$ D_i\le C_i^S $$ The reserve is not intended to cover every possible slash; it simply leaves some security headroom. The collateral should also have a genuine cryptoeconomic security purpose rather than being an arbitrary Sybil tax. Why linearity matters For any partition: $$ B=\sum_jB_j $$ aggregate admission capacity remains: $$ \sum_jC_j^A \lambda(1-\mu)\sum_jB_j \lambda(1-\mu)B $$ Creating more domains creates no additional capacity. If smaller anonymous collateral positions were intrinsically more efficient, a large actor could split to obtain that advantage. If larger positions were more efficient, the mechanism would reward capital concentration. Linearity makes the partition neutral. This general idea has clear prior art. Cardano CIP-50 uses pledge leverage to bound efficiently rewarded stake relative to operator pledge. I do not consider bond-backed capacity itself novel. Capacity is only a stock constraint Capacity answers: How much delegated ETH can this position support? It does not answer: How quickly can it acquire that delegated ETH? A sufficiently capitalized operator could otherwise post a large bond and immediately absorb a large amount of third-party delegated consensus weight. Ethereum already treats validator-set change as security-relevant. EIP-7251 moved important churn accounting toward ETH weight, and EIP-8061 retains an activation cap while continuing work around stake-entry/exit dynamics. EIP-8061 was included in glamsterdam-devnet-1 during the Soldøgn interop work . That suggests a second constraint. Bond-weighted delegated-weight growth Let: $$ \dot D_i^+ $$ represent gross inbound delegated weight to domain $i$. The proposed flow constraint is: $$ \boxed{\dot D_i^+\leq\rho B_i} $$ where $\rho$ determines how quickly a given amount of slashable collateral can acquire additional delegated weight. So the current core is: $$ \boxed{D_i\leq\lambda(1-\mu)B_i} $$ and: $$ \boxed{\dot D_i^+\leq\rho B_i} $$ The first limits economically supported scale. The second limits growth velocity. Capital limits size. Bonded capital-time limits growth. An operator can grow faster by supplying more collateral. What it cannot do is grow faster merely by creating more keys, domains or pseudonymous identities. For a split: $$ B=\sum_jB_j $$ aggregate inbound allowance remains: $$ \sum_j\rho B_j=\rho B $$ A bounded burst allowance could follow the same rule: $$ \text{burst}_i\leq\beta B_i $$ so splitting cannot manufacture burst capacity either. Admission has three constraints Let: $Q_i$ = pending inbound delegation $H_i=C_i^A-D_i$ = unused admission headroom $F_i$ = current bond-weighted flow allowance Then immediately eligible inbound delegation is: $$ \boxed{Y_i=\min(Q_i,H_i,F_i)} $$ This asks: Is there demand? Is there bond-backed capacity? Is the domain allowed to grow this quickly? For any valid partition: $$ Q=\sum_jQ_j,\qquad H=\sum_jH_j,\qquad F=\sum_jF_j $$ we have: $$ \boxed{ \sum_j\min(Q_j,H_j,F_j) \leq \min(Q,H,F) } $$ So arbitrary partitioning cannot manufacture additional aggregate admission eligibility. This is what I mean by economic split resistance . It does not depend on any assumed cost of maintaining another identity. What objective changed? The original version attempted to penalize concentration itself. The current mechanism does not. A sufficiently capitalized actor can still become very large while satisfying the stock and flow constraints. This is a deliberate narrowing, not an assumption that concentration disappeared. I have not found an identity-free way to make small anonymous actors intrinsically more efficient than large actors without letting a large actor reproduce the advantage through splitting. The narrower objective is: Third-party delegated ETH alone should not create unlimited consensus leverage, and rapid acquisition of delegated consensus weight should require proportionally more slashable collateral. Whether those constraints actually produce a more decentralized real-world operator market is an empirical question. Queueing and financialization If demand exceeds a domain’s capacity or flow allowance, some delegation must wait. That creates scarce admission access, which can be financialized. An LST could issue a liquid claim against queued ETH, a provider could subsidize waiting, or a secondary market could implicitly price access to a popular domain. Large providers may be better able to offer those products. For that reason NED should not rely on the pain of waiting as its primary decentralizing assumption . Queueing is an allocation consequence. Financial products can change who bears the waiting cost, but they do not create additional: $$ B_i,\qquad C_i^A,\qquad \rho B_i $$ and therefore do not create additional admitted consensus weight. Possible soft-saturation extension There may still be a role for price pressure, but I currently think it belongs outside the minimal core. For example, define a full-reward threshold: $$ C_i^F=\frac{C_i^A}{\kappa},\qquad\kappa\ge1 $$ and reward-eligible delegation: $$ E_i=\min(D_i,C_i^F) $$ This is also split-neutral: $$ \sum_j\min(D_j,C_j^F) \leq \min\left(\sum_jD_j,\sum_jC_j^F\right) $$ so splitting cannot manufacture aggregate reward eligibility. I am not proposing this as part of the current core , because it reintroduces difficult questions about suppressed-reward accounting and whether another price lever is necessary. Bond withdrawal, slashing and recovery Collateral should not be immediately withdrawable after supporting delegation. A possible lifecycle is: ACTIVE → SHADOW → RELEASED On withdrawal request: The collateral immediately stops supporting new admission and flow allowance. It remains slashable. Existing delegation depending on it is allowed to drain or redelegate. It releases only after relevant historical slash liability expires and remaining delegation is safely supported without it. Conceptually: close → drain → release A fixed timer alone seems insufficient because the timer could expire while delegation still depends on the collateral. A terminal retirement path is also needed so delegators cannot hold operator collateral hostage indefinitely. The exact loss allocation between domain collateral and delegated ETH is unresolved. If a slash pushes a domain outside the required security relationship, it could enter RECOVERY : new inbound delegation stops, fresh collateral can restore security, and otherwise delegation drains or redelegates. Fresh collateral should be able to restore security immediately. Restoring security is not the same as receiving unlimited new growth capacity. New delegation and redelegation Moving already-active stake between domains does not increase Ethereum’s total active stake, so new delegation and redelegation may deserve different network-wide churn resources. But inbound redelegation still increases the destination domain’s delegated consensus weight, so it should count toward: $$ \dot D_i^+ $$ Using gross inbound flow , rather than net change, matters. Otherwise coordinated inflows and outflows could produce little net change while bypassing the intended rate limit. The exact consensus mechanics need further work. Economic split resistance does not prove operator independence The split-neutrality arguments concern protocol economics . They do not prove that different domains belong to independent real-world organizations. One company could operate several differently branded domains. That does not bypass the bond or growth constraints, but it could increase user demand or make the market appear more diverse than its underlying control structure. I don’t see a clean permissionless consensus-layer solution to this without reintroducing identity/attribution assumptions. So the claim should be precise: Splitting provides no protocol-economic advantage under these capacity and growth rules. It may still provide marketing, discovery, liquidity, regulatory or UX advantages. Wallets and routers therefore should not treat “number of domains” as equivalent to “number of independent operators.” Concentration and correlation are different problems “Staking centralization” combines several different problems. Concentration asks how much of an important resource/control is held in relatively few hands. Correlation asks whether nominally separate participants behave or fail together. Problem Type Example approach Economic concentration Share/concentration NED/Flanders Operational correlation Behavior/correlation EIP-7716-like mechanisms Organizational concentration Common real-world control Requires attribution outside ordinary consensus state Regulatory/policy correlation Correlated behavior under common pressure Censorship-resistance mechanisms such as FOCIL Economic concentration NED deals with protocol-visible economic state such as: $$ B_i,\qquad D_i,\qquad\dot D_i^+ $$ without needing to know the operator’s real-world identity. Operational correlation Economically separate validators may still share infrastructure, clients, hosting or other dependencies and fail together. EIP-7716 explores anti-correlation attestation penalties based on correlated non-participation. I view this as complementary to NED rather than part of NED itself. Organizational concentration Several domains can ultimately have the same controller. Consensus state generally does not prove beneficial ownership, and NED does not attempt to solve that attribution problem. Regulatory/policy correlation Economically, operationally and organizationally independent actors can still behave similarly because of common legal or policy pressure. The behavioral pattern may be observable even when its cause is not. Actors can remain online and fulfill consensus duties while systematically excluding the same transactions. Ethereum’s MEV-Boost history provides a concrete example of the broader censorship-resistance problem. MEV Watch reports that the share of MEV-Boost relay payload deliveries attributable to relays it classifies as censoring peaked at 94.8% on October 26, 2022 . Its August 7, 2026 snapshot reported 40.7% , up 14% over the preceding 30 days . This is a relay-delivery-share metric, not a direct count of censored Ethereum blocks. FOCIL/EIP-7805 addresses censorship structurally through fork-choice-enforced inclusion lists. FOCIL has been selected as Hegotá’s consensus-layer headliner and is listed as Scheduled for Inclusion in EIP-8081 . NED contains no mechanism intended to solve this form of censorship correlation. Structural constraints versus penalties Some mechanisms discourage undesirable behavior by pricing it . EIP-7716 is an example: correlated missed attestations receive stronger penalties. Other mechanisms try to make the unwanted strategy ineffective . FOCIL does not need to identify why a builder excluded a transaction and calculate a penalty; it changes the inclusion process so unilateral builder exclusion does not by itself determine canonical inclusion. The current NED direction is closer to that second philosophy. The original reward curve priced concentration. The current construction instead tries to make identity multiplication ineffective at manufacturing capacity or growth: $$ D_i\leq\lambda(1-\mu)B_i $$ $$ \dot D_i^+\leq\rho B_i $$ This does not prove that the resulting market equilibrium will be decentralized. It establishes the narrower structural property that: Pseudonymous identity multiplication cannot manufacture the protocol-economic resources being constrained. Concentration can move between layers Even if NED produced many diverse delegation domains, one LST, router, wallet or governance system could aggregate much of the market above them. So operator diversity does not imply liquidity, governance, routing or discovery diversity. NED should therefore be evaluated specifically on the distribution and growth of delegated consensus weight , not treated as a complete decentralization mechanism for the staking economy. Existing providers could continue competing through LSTs, liquidity, DeFi, insurance, institutional relationships, interfaces, reputation and routing. Lido’s Community Staking Module is useful practical prior art for operator bonds and stake-allocation queues, although its architecture and objectives differ from NED. Related work Important prior work includes: Rainbow Staking and eODS for Ethereum operator/delegator separation and native delegation. Cardano CIP-50 for pledge-leverage-based capacity and split resistance. EIP-7251 and EIP-8061 for balance-weighted churn and stake-flow constraints. EIP-7716 for operational anti-correlation penalties. FOCIL/EIP-7805 for structural censorship resistance through inclusion lists. Lido’s Community Staking Module for practical bond/capacity/queue mechanics. I do not think any individual ingredient above should be described as novel. The part I am specifically interested in is combining Ethereum-native delegation with: $$ \boxed{\text{linear collateral-backed stock capacity}} $$ and: $$ \boxed{\text{linear collateral-backed gross inbound flow}} $$ so neither supported delegated weight nor its growth velocity can be increased merely by partitioning the same economic resources among pseudonymous domains. I have not found that exact construction in the delegation mechanisms I’ve looked at so far, but I would particularly appreciate prior-art references if it already exists. What this does not solve NED does not guarantee a decentralized operator market. A genuinely capital-rich actor can still become very large. Large institutions may also have cheaper access to financing than small operators, meaning a poorly calibrated collateral requirement could reinforce incumbency. NED does not prove separate ownership, guarantee infrastructure diversity, prevent jurisdictionally correlated censorship, prevent concentration at LST/router/wallet layers, or address the separate question of Ethereum’s total staking level and issuance policy. The narrower objective is: Delegated consensus weight should not scale without corresponding slashable economic support, and it should not grow at unlimited speed merely because a provider can attract large amounts of third-party ETH. What would make this idea fail? Split-neutrality is necessary but not sufficient. I would consider the economic thesis unsuccessful if realistic modeling or evidence showed that: cheaper institutional capital makes the collateral requirement reinforce incumbent concentration; queue financialization removes most competitive benefit for smaller operators; multi-brand strategies make apparent domain diversity diverge substantially from real operator diversity; LST/router concentration relocates enough power above NED to make underlying operator improvements unimportant; normal redelegation/recovery becomes too slow; useful parameters create unacceptable barriers for new or small operators; or any improvement in operator distribution is too small to justify the consensus complexity. The algebra removes one obvious class of mechanism-design failure. It is not proof of a decentralized equilibrium . Questions I’d especially like feedback on Is native delegation desirable at the protocol level? Is a persistent delegation domain the right abstraction? Is linear bond-backed capacity the right split-neutral stock constraint? Is gross inbound delegated weight worth constraining at the domain level? Is $\dot D_i^+\leq\rho B_i$ a sensible split-neutral flow constraint? Is there a splitting attack on the stock + flow construction that I am missing? How should $\lambda$, $\mu$, $\rho$ and any burst allowance be chosen? Does the collateral requirement advantage capital-rich incumbents too much? Should domain collateral earn normal staking issuance, and what slashing obligation should it carry? How should recovery, withdrawal, redelegation and historical slash liability work? How should queue tokenization, subsidies and external collateral financing affect the design? Can multi-brand demand capture undermine the competitive effect even when protocol economics remain split-neutral? Is a split-neutral soft-saturation band useful, or unnecessary complexity? Is there a simpler construction with the same stock and flow properties? What relevant prior work am I missing? What I’m hoping to accomplish I’m not trying to prescribe a finished implementation. The mechanism has changed as I’ve tried to break the earlier versions. The first version tried to make concentration itself economically unattractive through a declining reward curve. That relied on an assumption that pseudonymous economic identity was costly. Bond-backed capacity provided a cleaner scarce variable, but capacity alone did not constrain how quickly a well-capitalized provider could accumulate delegated consensus weight. The current direction is therefore: $$ \boxed{D_i\leq\lambda(1-\mu)B_i} $$ and: $$ \boxed{\dot D_i^+\leq\rho B_i} $$ The first limits scale. The second limits growth. Both depend on slashable economic state rather than identity count. Capital limits size. Bonded capital-time limits growth. More broadly: First identify what the protocol can actually observe. Then ask whether the unwanted strategy can be made structurally ineffective. Only rely on penalties when the desired property cannot be enforced more directly. If there is something useful here, I’d much rather see people with deeper experience in Ethereum consensus, staking economics and mechanism design break it, simplify it or take it further than pretend this is already a finished EIP. The working name is Native Ethereum Delegation (NED) . Informally, the Flanders Protocol . 3 posts - 1 participant Read full topic
DeFi Intel is an entity-graph aggregator: we curate, tag and link crypto news to a typed knowledge graph of protocols, tokens, people and incidents. We do not republish the full article body. Use the link above to read the original report at Ethereum_magicians.
Want the full article?
Continue reading on Ethereum_magicians →