Has Crypto Been Measuring Decentralization Wrong? Inside the Debate Over Internet Computer Architecture
For years, much of the blockchain industry has relied on familiar metrics to evaluate decentralization: validator count, stake distribution, and the cost required to attack a network. Those metrics have shaped how investors, developers, and researchers compare competing Layer 1 protocols.
The Internet Computer (ICP) challenges many of those assumptions.
That challenge has sparked one of the most technically detailed public debates the industry has seen in years.
Cyber Capital Founder and CIO Justin Bons recently published a comprehensive critique of the Internet Computer, arguing that ICP’s subnet architecture fragments security, weakens decentralization, and overstates several of its technical capabilities. His criticism extends beyond architecture to the project’s communication, questioning claims surrounding native Bitcoin integration, HTTPS Outcalls, and the long-standing narrative of “infinite scalability.”
DFINITY Founder and Chief Scientist Dominic Williams responded with an equally comprehensive technical rebuttal. Rather than disputing every implementation detail individually, Williams argues that Bons is evaluating the Internet Computer through the lens of conventional proof-of-stake blockchains, while ICP was intentionally designed around a different security model altogether. According to Williams, decentralization is not fundamentally determined by validator count, but by the number of independent participants involved in consensus and how those participants are selected.
Although both authors analyze the same protocol, they begin from different first principles. Much of the disagreement stems not from conflicting facts about ICP’s implementation, but from fundamentally different definitions of what constitutes decentralized security.
Two Definitions of Security
At the center of the debate lies a deceptively simple question:
What actually secures a blockchain?
Bons approaches the question from a crypto-economic perspective.
His argument is that security should primarily derive from a large, economically unified validator set. In traditional proof-of-stake systems, the cost of attacking the network scales with the amount of capital required to acquire or control sufficient stake. Under this framework, security is closely tied to economic incentives, stake concentration, and the financial cost of compromising consensus.
Williams approaches the problem differently.
Rather than focusing on stake alone, he argues that consensus security should be measured by the number of independent organizations capable of influencing consensus. In this model, operator independence, geographic distribution, jurisdictional diversity, and infrastructure diversity become equally important security variables alongside cryptography and consensus algorithms.
These competing assumptions frame nearly every disagreement that follows.
The Subnet Debate
Unlike monolithic blockchains where every validator participates in securing the same global state, the Internet Computer distributes computation across multiple independent subnets.
Each subnet maintains its own Byzantine Fault Tolerant (BFT) consensus, executes canister smart contracts independently, and communicates asynchronously with other subnets through protocol-level messaging.
For Bons, this architecture introduces fragmentation.
Because applications execute within individual subnets, he argues that each application ultimately inherits only the security guarantees of the subnet executing its state. If that subnet contains relatively few validators compared to an entire Layer 1 network, he contends that the application’s effective security is correspondingly reduced.
His broader criticism is that ICP lacks what many modular blockchain architectures refer to as shared security, where the complete validator set collectively protects all execution environments.
Williams argues that this characterization overlooks how Internet Computer subnets are actually constructed.
Rather than assembling validator groups randomly or through stake delegation alone, the Network Nervous System (NNS) deliberately selects node providers according to multiple constraints, including independent ownership, geographic separation, jurisdictional diversity, infrastructure providers, and data center distribution. The objective is not simply maximizing validator count, but maximizing independence among consensus participants while minimizing unnecessary computational replication.
Validator Count vs. Nakamoto Coefficient
One of the most important concepts raised during the exchange is the Nakamoto Coefficient, a metric intended to estimate how many independent entities would need to collude to compromise a decentralized network.
This is where the debate becomes particularly nuanced.
Bons argues that validator count remains an important practical measure because smaller subnet validator sets necessarily reduce the number of participants directly protecting a given application.
Williams responds that validator count, by itself, can be misleading.
If one organization controls hundreds or even thousands of validators, increasing validator count does not necessarily increase decentralization. What matters is the number of independent parties capable of influencing consensus, not the raw number of machines participating in it. A network with fewer validators operated by genuinely independent organizations may, under this framework, exhibit stronger decentralization than a much larger validator set controlled by a handful of entities.
The disagreement therefore is not simply over mathematics.
It is over which measurement best captures real-world decentralization.
Shared Security or Deterministic Decentralization?
Another major point of contention concerns shared security.
Bons argues that ICP’s independent subnets function as separate security domains. Because consensus occurs independently within each subnet, he contends applications do not inherit the full security guarantees of the broader Internet Computer network.
Williams counters that the Network Nervous System itself provides an overarching security framework.
Rather than every subnet relying upon identical validator participation, the NNS continually manages subnet composition while specialized system subnets, including governance and threshold cryptography subnets, operate with substantially larger validator sets where stronger security assumptions are required.
The distinction reflects two different architectural philosophies.
One prioritizes globally shared validator participation.
The other prioritizes deterministic construction of independently resilient consensus groups.
The Scalability Question
Scalability represents another area where the authors diverge.
Bons argues that describing ICP as possessing “infinite scalability” risks overstating what any finite distributed system can realistically achieve. Additional subnets introduce coordination overhead, Distributed Key Generation (DKG) complexity, and cross-subnet communication costs. From his perspective, these engineering realities impose practical limits on horizontal scaling.
Williams does not dispute that distributed systems involve tradeoffs.
Instead, he argues that ICP’s architecture was explicitly designed to scale horizontally by provisioning additional subnets as demand grows. While finite physical resources always impose limits, he views the architecture as enabling effectively unbounded expansion through modular subnet creation rather than requiring every validator to execute every computation.
The disagreement ultimately centers less on engineering than on language: whether “infinite scalability” should be interpreted as a literal claim or as shorthand for an architecture capable of continuous horizontal expansion.
Bitcoin Integration and Threshold Cryptography
Few Internet Computer features have received more attention than Chain Key cryptography and native Bitcoin integration.
Bons argues that threshold ECDSA signatures ultimately inherit the security assumptions of the subnet responsible for generating and managing distributed key material. Under this interpretation, Bitcoin assets remain dependent upon subnet integrity, making the description of “native” Bitcoin potentially misleading.
Williams argues that threshold cryptography fundamentally changes how key management is performed.
Rather than exposing complete private keys to individual validators, distributed key generation and threshold signing allow cryptographic operations to occur collectively across participating nodes. Specialized system subnets responsible for threshold cryptography employ significantly larger validator sets specifically because stronger security guarantees are required.
Beyond Architecture: A Debate About Communication
Perhaps the most interesting aspect of the exchange is that it extends well beyond engineering.
Bons argues that terminology such as Canisters, Neurons, and the Network Nervous System unnecessarily diverges from established blockchain vocabulary, making familiar concepts appear entirely novel.
Williams views the terminology differently.
His position is that Internet Computer introduces architectural abstractions that differ sufficiently from traditional blockchain systems to justify distinct terminology, particularly given ICP’s ambition to function as decentralized cloud infrastructure rather than solely as a transaction settlement layer.
Whether readers interpret those naming conventions as innovation or unnecessary abstraction remains largely subjective.
More Than an ICP Debate
Although this discussion centers on the Internet Computer, its implications extend well beyond a single protocol.
The debate exposes a larger question confronting blockchain engineering:
Should decentralization be measured primarily through validator count and economic stake, or through the independence and diversity of the participants who actually operate the network?
There is no industry-wide consensus today.
As modular architectures, decentralized cloud computing, shared-security systems, and horizontal execution continue evolving, these questions will become increasingly important for protocol designers, infrastructure providers, institutional investors, and developers alike.
Regardless of where one ultimately stands, the exchange between Justin Bons and Dominic Williams represents far more than a disagreement over one blockchain. It is a rare public examination of the assumptions that underpin modern decentralized systems themselves, and a reminder that the future of blockchain infrastructure may depend as much on how we define decentralization as on how we implement it.
New to Crypto
The Swop is a media platform and social network built for the next generation of the internet.
Instead of relying on a single company to control your content, identity, or audience, The Swop is built on decentralized technology that gives creators and communities more ownership over what they create.
If you’re new to blockchain, don’t worry. You don’t need to understand the technology to follow along.
Our goal is simple: make emerging technology easier to understand through news, deep dives, podcasts, interviews, and educational content, while building a social platform where creators can own and monetize their work.
If you’d like to learn more, subscribe to our Substack for beginner-friendly articles, or join our public alpha to experience The Swop for yourself.
Join The Swop Alpha: https://theswop.app/signup?ref=msuut-nt2f6-urcen-khh6h-w4s7z-gv77z-l3gqq-au3zz-4jpk7-l2swg-bae






