Your keys, your crypto. Not your data.
Published

Satya Nadella wrote something last week that most of crypto will read, nod along to, and then fail to apply to itself.
His piece, The Reverse Information Paradox, makes a simple point about AI. You pay for intelligence twice. Once in dollars. Once by handing over the proprietary knowledge you need to feed the model to make it any good. The vendor learns more about you every time you use the thing you bought. You learn almost nothing about them in return. His fix is a “trust boundary”: own your data, your evals, your memory, decouple from any single model, and the asymmetry stops compounding against you.
Good piece. I think he’s underselling how bad this problem already is somewhere he probably wasn’t even thinking about: public blockchains.
Don’t get me wrong. Public blockchains are one of the most significant innovations in financial technology since the invention of the cheque, and I’ve spent a big part of my career building on them and arguing for open systems. I’m not walking any of that back. That’s exactly why I think the industry owes the people using it more honesty than a slogan.
The paradox crypto’s had for a decade
Here’s the pitch every self-custody advocate has been making since 2017: public blockchains are transparent, permissionless, and trustless. You don’t need a bank to vouch for you. You don’t need to trust a middleman. Trust the math.
That pitch skips over one question it can’t actually answer. Transparent to whom?
In theory, every transaction on Ethereum is public and anyone can read it. In practice, almost nobody who uses Ethereum can actually read Ethereum. Parsing a wallet’s full transaction history, working out which counterparties are the same entity, correlating on-chain activity with off-chain identity: that’s a skill set. A small number of people and a smaller number of well-funded firms have it. Everyone else is publishing their financial life to an audience they can’t see and would never knowingly choose.
That’s Nadella’s paradox again, just with the direction of harm flipped. With an AI vendor, at least you know a negotiation is happening. You signed something. You can, in principle, build a trust boundary around it later. On a public blockchain, there’s no boundary to build. The disclosure already happened, it’s permanent, and most people who made it didn’t know they were making a choice at all.
Say hello to pelle.eth
Take an ENS name. Registering one feels like a cosmetic upgrade: a
memorable handle instead of 0x71C7...8976. Nobody explains to you, at the
point of purchase, that you just linked a human-readable identity to every
balance, every trade, every vault position, every NFT you’ve ever touched, and
every wallet you’ve ever sent funds to or from. Forever. Searchable by
anyone with the right tooling, which today means anyone, because the tooling
got good and cheap.
You didn’t sell that information. You didn’t get paid for it. You gave it away for a slightly nicer username, and you almost certainly didn’t know that’s the trade you were making.
Compare that to handing your prompts to an AI vendor. At least you got something legible in return, and at least there’s a company you could theoretically hold accountable. What’s the equivalent recourse for an ENS name that doxxed your entire net worth to a stranger (or a neighbor or a distant family member) running a Dune dashboard? There isn’t one. That’s not a trust boundary problem. That’s a “there was never a boundary” problem.
Who’s actually reading your chain
A panopticon is Jeremy Bentham’s 18th-century prison design: a circular building with a single central watchtower that can see into every cell, while no prisoner can ever tell whether they’re being watched at that moment. That’s the picture on this article, and it’s a closer description of a public blockchain than most people realize.
I’ve always called this crowd “the etherati.” For ten-plus years the loudest voices in crypto have pushed the line that self-custody means you own your data. That’s not true, and I think a lot of the people saying it know it’s not true.
You own your keys. You own your tokens. Your data belongs to whoever has the tools and the incentive to make sense of it.
This matters because “not your keys, not your crypto” isn’t really two positions depending on the situation. It’s the same move wearing two outfits. When a protocol gets exploited and users lose money, the builders say “we’re just developers, we don’t control what people do with the software.” When someone suggests there should be disclosures, recourse, or basic accountability for products people are told to trust with their savings, the same builders say “you have full control, it’s your keys, your responsibility.” Read those side by side and the pattern is obvious: whichever way the risk points, it lands on the user, never on the people who built and profited from the thing. That’s not two philosophies in tension. That’s one philosophy: no accountability, in either direction.
But isn’t KYC the same violation?
Here’s the etherati’s favorite comeback, and it’s worth taking seriously instead of waving it off. Banks and centralized exchanges build deep profiles on you too. Where’s your privacy there?
You don’t have much with respect to the bank, and I won’t pretend otherwise. But there’s a real difference between that kind of private disclosure and what happens on a public chain, and it’s exactly the thing Nadella is pointing at: whether there’s a boundary, and whether you get anything for crossing it.
Know Your Customer is a regulatory requirement, but it isn’t only that. It’s also the other half of an actual deal. The institution takes on the obligation to safeguard your funds, watch for fraud, unwind mistakes, and answer for its own failures, in exchange for knowing who you are. Your data goes to one identified, accountable party, not to whoever downloads a block explorer. That’s Nadella’s trust boundary, built with a compliance department instead of a data schema.
Whether that trade is worth it should be up to the user, not decided for them by whichever infrastructure they happened to pick. But most people this industry claims to want to serve, in rich countries and the developing world alike, have never lost sleep over self-sovereignty.
They’d very much like to not lose their savings to a bug or a phishing link. For most of them, “a regulated company knows who I am and is on the hook if something goes wrong” is a better deal than “nobody knows who I am, until the day someone with a Dune dashboard finds out everything, and there’s nobody to call when it goes wrong.”
Nadella’s asymmetry, three ways
| AI vendor relationship | Public blockchain | KYC’d bank or exchange | |
|---|---|---|---|
| Who’s exposed | The enterprise customer, knowingly | The retail user, usually unknowingly | The retail user, knowingly |
| Governed by | A contract | Nothing | Regulation and a contract |
| Reversible | In principle, with a trust boundary | Never | Contained to one accountable party |
| Do you know it happened | Yes, you signed up for it | Often not until someone else points it out | Yes, you filled out the form |
| What you get for the disclosure | Access to the model | Nothing | Fraud protection, recourse, custody of your funds |
| Who benefits from the asymmetry | The model vendor | Whoever has the tooling: chain analytics firms, sophisticated traders, anyone doxxing you for fun | Shared: you get safety, they get to serve you |
Nadella is describing the mild version of this problem and proposing a real fix for it. Crypto has the severe version, the only one on this table with no boundary and nothing given back, and mostly pretends it isn’t a problem at all, because admitting it would mean admitting that “transparent and permissionless” isn’t automatically the same thing as “safe.”
Follow where the institutional money is actually going
You don’t have to take my word for it. Watch what the most sophisticated financial institutions on the planet are doing right now, because it isn’t “deploy on Ethereum mainnet and let the whole world read our balance sheet.”
Canton Network, the chain DTCC is using to tokenize US Treasuries and that JPMorgan and HSBC are settling real assets on, was built privacy-first from day one: participants set disclosure at the transaction level, sharing only what a counterparty or regulator actually needs to see. Visa just signed on as a Super Validator specifically to extend that privacy-preserving model to banks. Nobody at DTCC or JPMorgan wants their settlement activity readable by whoever happens to have a Dune dashboard.
Same story at Tempo, the Stripe and Paradigm payments chain that launched this year with Visa, Mastercard, and Deutsche Bank as design partners. It ships with opt-in private zones where Banks can hide sensitive transaction details and account balances, because the enterprises actually moving money at scale were never going to build on infrastructure that broadcasts every payment to the public internet by default.
The institutions with the most at stake, and the most legal and competitive reasons to think hard about this, already concluded that “fully public and permissionless” isn’t a feature you want for real money. They just didn’t write a blog post about it. They funded new chains instead.
This isn’t an argument against self-custody
I want to be precise here, because I know how this reads to the maximalist crowd, and I’ve spent too many years arguing for open systems to enjoy telling part of that world it’s wrong about something. I’m not saying custodians are the answer and self-custody is the problem. Plenty of self-hosted wallet teams take this seriously: better signing UX, clearer warnings, privacy-preserving tooling. That’s the right direction and I’d like to see more of it.
What I’m against is the ideology that lets an entire industry skip the work of building that direction, by hiding behind a slogan that was never fully true. “Not your keys, not your crypto” was a fine bumper sticker for Bitcoin in 2013. It was never a complete theory of user protection, and it was never a substitute for telling people what they’re actually giving up.
Nadella built a five-point framework for enterprises to defend their data against model vendors. Crypto owes retail users something at least as serious, and right now the answer to “who’s protecting my data on-chain” is nobody, dressed up as “you are, because it’s decentralized.” That’s not sovereignty. That’s just an information asymmetry nobody’s willing to name.
I don’t have the fix fully worked out yet, but I’d push back on the move people jump to next: swap the public chain for a privacy-preserving one and call the problem solved. That fixes the exposure half of it. It doesn’t fix the safety half, and it can make it worse, because the same privacy that keeps strangers off your wallet also erases the trail that lets anyone, you, an exchange, an investigator, reconstruct what happened after you’re phished or a contract gets drained.
A KYC’d bank or neobank is the opposite trade: it can see and trace your funds internally, which is exactly what makes it accountable when something goes wrong. Privacy from the public and recourse when you’re robbed are two different problems. For most people this industry claims to want to serve, a safe, well-run, regulated neobank buys you both. A hardware wallet on a privacy-preserving chain only buys you one.