Ethereum co-founder Vitalik Buterin recently shared his views on when rollup-based layer-2 platforms should make the transition to decentralization. In an X post on May 5, Buterin emphasized that there is an ideal time for this transition, and that “as soon as possible” is not the right approach.
Buterin stated that the transition to a decentralized model depends on the probability of the proof system failing relative to the risks that centralization entails. He was responding to an earlier post by Daniel Wang, founder and CEO of the decentralized exchange Loopring. Wang pointed out that the maturity of a system is crucial to its security. “Not all code is created equal,” he said. A rollup can be in phase 2, but at the same time it can be running on new code that has never been tested under real pressure.
Rollup development is divided into different phases: phase zero, phase one, and phase two. Each phase offers a greater degree of decentralization, with phase two being fully decentralized and trustless.
Cryptocurrency systems that manage significant assets are vulnerable not only to technical flaws, but also to malicious actors with profit motives. Even without a bug bounty program, projects are subject to relentless scrutiny — often paying more for vulnerabilities. This threat is growing, especially with the growing influence of nation-state-sponsored hackers. A notable example is the Lazarus hacker group, which is responsible for several high-profile hacks, including the $1,4 billion hack of Bybit.
Wang proposed introducing a new benchmark for veteran code that has passed the test of advanced hackers: “BattleTested.” This badge would be awarded to a rollup that has continuously secured at least $100 million in assets for at least six months, with at least $50 million in ether (ETH) and a major stablecoin. However, the badge would expire with each update, as new code must prove itself resilient to attacks.
Buterin added that it is important to realize that it is not only phase 2 that matters for security; the quality of the underlying evidence system also plays a crucial role.
According to Buterin, the best time for a protocol to decentralize is when the on-chain proof system is secure enough that the central components that act as a risk for failure or collusion can pose a greater threat. Until a system is proven secure, decentralization, which increases dependency on that system, can actually make it less secure.
Mike Tiutin, chief technology officer at decentralized compliance protocol PureFi, warned that decentralizing too early could leave users vulnerable.
Kronos Research’s John noted that decentralization is not a race, but a long-term responsibility that must be shared across the ecosystem. He warned that moving too quickly to phase two puts ideology before security and increases risk. “In phase one, boards can step in when something goes wrong. In phase two, a single bug can cost billions with no rollback,” he added.
Tomas Fanta, principal at crypto Venture capital firm Heartcore called Buterin’s proposal for gradual decentralization a breath of fresh air. He clarified that rollups are still in development and their components have not been fully tested in the field, which could potentially cripple a too-rapid decentralization. He argued that decentralization is a benefit that comes with maturity, but is a real cost in earlier lifecycle stages.
While outright decentralization is problematic, some experts are highlighting the dangers of no decentralization. Arthur Breitman, co-founder of the Tezos blockchain, explained that prominent Ethereum L2s are essentially custodial. “Privileged entities control the core logic, which compromises the integrity of assets; relying on their invulnerability to collusion is fragile,” Breitman said.
Yishay Harel, co-founder and CEO of rollup-centric blockchain Dymension, noted that the underlying architecture wasn’t originally designed to settle rollups, which entails several workarounds. “Go too fast and you risk breaking critical systems; go too slow and you essentially remain custodial, governed by multisigs and upgrade keys.”
Why shouldn't decentralization happen immediately?
Because a system that is not yet proven to be safe can become more vulnerable with decentralization. Until the system is strong enough, the risk of centralization is still greater.
What happens if a rollup loses the BattleTested badge?
The badge expires with each update. New code must prove itself against attacks to earn the badge back.
Why is system maturity so important for safety?
A mature system has the qualities and stability to manage risks, especially against advanced malicious attacks.
