1 of 101

Centralization and Stability in Formal Constitutions

Ben-Gurion University Economics Seminar

April 2026

Yotam Gafni

Weizmann Institute of Science

2 of 101

Topic of this talk…

1

3 of 101

In Formal Systems!

2

“Blockchain Governance: An Empirical Analysis of User Engagement on DAOs”, Falk et. al 2024

4 of 101

A lot of assets under smart contract control…

3

Source: https://defillama.com/treasuries, retrieved April 21st 2026

5 of 101

4

” The key ingredients of a successful nonviolent resistance movement […]:

The ability to create loyalty shifts among key regime-supporting groups such as business elites, state media, and—most important—security elites such as the police and the military.”

(https://www.hks.harvard.edu/faculty-research/policy-topics/advocacy-social-movements/paths-resistance-erica-chenoweths-research)

6 of 101

Goals and general roadmap

5

  • Develop a simple model to study dynamics of power in voting systems.

  • Characterize stable voting rules, under different assumptions.

  • Draw actionable conclusions for Decentralized Autonomous Organizations (DAOs)?

7 of 101

Two Conceptual Pillars

6

Barbera & Jackson (QJE 2004)

Koray (Econometrica 2000)

Study qualified majority rules (simple majority -> consensus)

Threshold T

n voters

More Effective

More Conservative

Unanimous and neutral social choice functions are

``self-selective’’ iff they satisfy IIA (Independence of

Irrelevant Alternatives)

-> Only dictatorship is self-selective (by Arrow’s Theorem!)

Neutral rules!

Anonymous rules!

To understand centralization, we need non-anonymous rules.

To understand passing decisions, we need non-neutral rules.

We need new theory!

8 of 101

Model

7

 

 

Still missing: Tie-breaking, belief specification

9 of 101

Example I (Stylized):

The Bolsheviks, the Mensheviks, and the Whites

8

9 voters

3 Bolsheviks

2 Mensheviks

4 Whites

10 of 101

Example I (Stylized):

The Bolsheviks, the Mensheviks, and the Whites

 

 

11 of 101

Example I (Stylized):

The Bolsheviks, the Mensheviks, and the Whites

 

 

12 of 101

Example II:

Unanimity Vote in the European Union

11

 

 

``Whether Unanimity is the best protector of national sovereignty depends on

whether a state believes that maximizing the possibility of inaction [...] is better

for the national interest than a qualified-majority voting rule which increases the

possibility of action” [EU Law: Text, Cases and Materials, Craig & de Burca ‘24]

13 of 101

Back to the Model:

Tie-Breaking and Beliefs

12

14 of 101

13

 

Rationalizable!

Robust!

15 of 101

Highlights of Results:

14

Arbitrary Tie-Breaking

SQB Tie-Breaking

Conditionally self-maintaining

All (and only) non-dual-passing rules

All (and only) non-dual-passing or respect rejective-consensus rules

Universally self-maintaining

The constant-0 function

Dictatorship

3-oligopoly

Conservative, flower-form, entangled SCFs

(e.g., consensus-duopoly, 3-oligopoly with veto)

A rule must be: Non-dual-passing, downward-closed, respect rejective-consensus, bounded monotonicity violation, bounded downward sensitivity…

A gap exists between the necessary and sufficient conditions.

I.i.d. self-maintaining

The constant-0 function, dictatorship, and anti-dictatorship. Other rules exist only for the biased setting, but not with better social/Nash welfare.

+Consensus-duopoly , has better social/Nash welfare than dictatorship when 0<p<1/2

16 of 101

  •  

15

With arbitrary tie-breaking, an SCF is conditionally self-maintaining if and only if it is non-dual-passing.

 

17 of 101

  •  

16

 

With arbitrary tie-breaking, an SCF is conditionally self-maintaining if and only if it is non-dual-passing.

18 of 101

  •  

17

 

With arbitrary tie-breaking, an SCF is conditionally self-maintaining if and only if it is non-dual-passing.

19 of 101

  •  

18

 

With arbitrary tie-breaking, an SCF is conditionally self-maintaining if and only if it is non-dual-passing.

20 of 101

Highlights of Results:

19

 

Arbitrary Tie-Breaking

SQB Tie-Breaking

Conditionally self-maintaining

All (and only) non-dual-passing rules

All (and only) non-dual-passing or respect rejective-consensus rules

Universally self-maintaining

The constant-0 function

Dictatorship

3-oligopoly

Conservative, flower-form, entangled SCFs

(e.g., consensus-duopoly, 3-oligopoly with veto)

A rule must be: Non-dual-passing, downward-closed, respect rejective-consensus, bounded monotonicity violation, bounded downward sensitivity…

A gap exists between the necessary and sufficient conditions.

I.i.d. self-maintaining

The constant-0 function, dictatorship, and anti-dictatorship. Other rules exist only for the biased setting, but not with better social/Nash welfare.

Consensus-duopoly , has better social/Nash welfare than dictatorship when 0<p<1/2

21 of 101

  •  

20

With SQB tie-breaking, a Dictatorship is universally self-maintaining.

 

22 of 101

  •  

21

With SQB tie-breaking, a 3-oligopoly is universally self-maintaining.

 

23 of 101

22

With SQB tie-breaking, any conservative, flower-form, entangled SCF is universally self-maintaining.

  • Let’s break it down…

24 of 101

  •  

23

With SQB tie-breaking, any conservative, flower-form, entangled SCF is universally self-maintaining.

  • A pair of agents is entangled in f if it satisfies the above property
  • There may be several entangled pairs. Denote the set of all such pairs S(f)
  • E.g., in the 3-oligopoly, there are 3 entangled pairs
  • Flower form: There is an agent i so that every pair in S(f) includes i.
  • The 3-oligopoly is not flower-form.

25 of 101

  •  

24

With SQB tie-breaking, any conservative, flower-form, entangled SCF is universally self-maintaining.

  • A pair of agents is entangled in f if it satisfies the above property
  • There may be several entangled pairs. Denote the set of all such pairs S(f)
  • E.g., in the 3-oligopoly, there are 3 entangled pairs
  • Flower form: There is an agent i so that every pair in S(f) includes i.
  • The 3-oligopoly is not flower-form.
  • Combinatorial Observation: Every entangled SCF is either the 3-oligopoly or flower-form.

26 of 101

  •  

25

With SQB tie-breaking, any conservative, flower-form, entangled SCF is universally self-maintaining.

 

27 of 101

Highlights of Results:

26

 

Arbitrary Tie-Breaking

SQB Tie-Breaking

Conditionally self-maintaining

All (and only) non-dual-passing rules

All (and only) non-dual-passing or respect rejective-consensus rules

Universally self-maintaining

The constant-0 function

Dictatorship

3-oligopoly

Conservative, flower-form, entangled SCFs

(e.g., consensus-duopoly, 3-oligopoly with veto)

A rule must be: Non-dual-passing, downward-closed, respect rejective-consensus, bounded monotonicity violation, bounded downward sensitivity…

A gap exists between the necessary and sufficient conditions.

I.i.d. self-maintaining

The constant-0 function, dictatorship, and anti-dictatorship. Other rules exist only for the biased setting, but not with better social/Nash welfare.

Consensus-duopoly , has better social/Nash welfare than dictatorship when 0<p<1/2

No gap for Weighted Voting Games!

28 of 101

Weighted Voting Games:

27

Arbitrary Tie-Breaking

SQB Tie-Breaking

Conditionally self-maintaining

All rules

All rules

Universally self-maintaining

No rules

Exactly:

Dictatorship

3-oligopoly

Conservative, flower-form, entangled SCFs

(e.g., consensus-duopoly, 3-oligopoly with veto)

I.i.d. self-maintaining

Exactly dictatorships.

All the SQB universally self-maintaining rules

???

29 of 101

Zoom out: What’s missing in our model?

28

30 of 101

A Restaurant Story…

29

  • After the talk, we will hopefully head out to lunch
  • This is my second time in the BGU campus. Do I want the decision to match my ex-ante preference (as our model posits)?
  • Or do I prefer to trust the advice of the organizers?

31 of 101

Re-examining Our Model

30

  • Our model captures a world with ``fixed reality”
  • The classic ``Condorcet’s Jury Theorem’’ has an opposing perspective

32 of 101

Condorcet’s Jury Theorem

31

 

 

 

 

 

 

p

Pr[Majority = True State]

33 of 101

A Revised Model

32

 

34 of 101

Stability in the Revised Model

33

 

 

 

  • Two possible sources of instability:

  • Transition ``up’’:
    • A bigger oligarchy
    • Higher discursive utility, lower extractive utility
    • If it is an improvement, everyone in current oligarchy vote in favor

  • Transition ``down’’:
    • A smaller oligarchy of size > i/2
    • Higher extractive utility, lower discursive utility
    • Consolidation of power by a smaller elite (which has the votes to transform)

35 of 101

34

36 of 101

35

37 of 101

36

38 of 101

Takeaways, Part 1

  • With the right beliefs, almost any choice rule is stable
  • However, very few rules are robust, and power must be very concentrated.
  • Still, we can do slightly better than dictatorship

37

39 of 101

Takeaways, Part 2

  • In the extractive vs. discursive model, there may be several stable elite sizes.
  • Thus, the opening conditions matter
  • This is a good justification for ``airdrops’’: Investing in distributing voting rights and decentralization from the start.

38

40 of 101

A Call for Future Work

  • Applications in specific settings: Weighted Voting Games?

  • Axiomatizing the utility functions: Abstract the proofs away from the proprietary constructions

  • Empirical substantiation: In Lab, in Blockchain observations

  • Voters that plan ahead?

39

41 of 101

Thanks for listening!�

42 of 101

We Can Believe In?

41

“A more serious issue is collusion between the proposer and some transaction senders.

[Vitalik Buterin, “Blockchain Resource Pricing” 2018]

Frequent exchanges of information that facilitate a better common understanding of the market and monitoring of deviations increase the risks of a collusive outcome.“

[European Commission Guidelines to Horizontal Cooperation Agreements 2023]

Change

43 of 101

New�Technology

42

🡪

New�Assumptions

New�Mechanisms

🡪

44 of 101

43

Security

Align Incentives

with System Goals

Fairness

Make the System Work

for Everyone

Optimality

Tune the System

to Maximize Objectives

Robustness to Collusion

Safety of Data-Sharing Protocols

Weak Identity & Recourse

Consumer Effects of Learning

Fair Exploration & Allocation

Centralization Dynamics

Minority Rights

Prizes in Data Science Contests

Outsourcing

Priority under Time-Sensitivity

45 of 101

44

Security

Align Incentives

with System Goals

Fairness

Make the System Work

for Everyone

Optimality

Tune the System

for Max Performance

Robustness to Collusion

[GY EC’24 Revision@GEB,

FGR TLDR’24 🏭,

GY MARBLE’24, G’25]

Safety of Data-Sharing Protocols

[GT EC’22]

Weak Identity & Recourse

[GLT AAAI’20, GT TARK’23]

[GLT IJCAI’21, JAIR’22]

Prizes in Data Science Contests

[DGLLL AAAI’23, GEB’25]

Outsourcing

[FG’26]

Priority under Time-Sensitivity

[GY’22]

Consumer Effects of Learning

[GGT SAGT’24, Revision@TEAC]

Fair Exploration & Allocation

[BP-GM’25, GHLT-C TEAC’23]

Centralization Dynamics

[G’25]

Minority Rights

[GG’24 🏆]

46 of 101

Blockchains are Permissionless

45

🡪

No Trust in Miners

Collusion-Robust Mechanisms

🡪

47 of 101

Blockchains: A Soft Intro

  • A decentralized financial transaction system
  • Growing adoption since their inception in 2008
  • Not only Bitcoin… Some example of market caps
  • Bitcoin: $1.8T, Ethereum: $380B, USDC $75B, UNISWAP $3.5B

46

Total Blockchain Market Cap

Blockchain Market Cap Partition

$6T

$4T

$2T

$0

‘14 ’15 ‘16 ’17 ‘18 ‘19 ‘20 ‘21 ‘22 ‘23 ‘24 ‘25

‘14 ’15 ‘16 ’17 ‘18 ‘19 ‘20 ‘21 ‘22 ‘23 ‘24 ‘25

100%

75%

50%

25%

0%

Bitcoin

Ethereum

Stablecoins

Other

48 of 101

Blockchains: Why?

Why not traditional transaction systems?

47

Competition among service providers within the platform and free entry imply no entity can profitably affect the level of fees paid by users.”

Huberman, Leshno & Moallemi, REStud ‘21

“Competition among service providers within the platform and free entry imply no entity can profitably affect the level of fees paid by users.”

Huberman, Leshno & Moallemi, REStud ‘21

But it comes with its own set of challenges…

Cost to Send USD Internationally

$44 via International Wire Transfer

$12 via USDC on Ethereum, ’21 avg

$1 via USDC on Ethereum, Sep ’24 avg

<$0.01 via USDC on Base L2,Sep’24 avg

[a16z crypto, State of Crypto 2024 Report]

49 of 101

Blockchains: Technical Primer

Users

Miners

Block

Block

Transaction

Blockchain

Block

Block

A Random Miner is Given Temporary Monopoly Power

Block

Reward

Fees

To prevent Sybil Attacks, the random choice depends on a finite resource

In Bitcoin, transactions allow payments. In Ethereum, they are Turing-Complete and can encode any logic.

50 of 101

Transaction Fees

  • Blockchain throughput is limited
  • Demand ≫ supply
  • Goal 1: allocate block-space efficiently

49

Users

Block

Miner

TX

TX

TX

Max size:

2 TXs

Max Eth

Block

Source: mempool.jhoenicke.de

Pending TXs

Date

51 of 101

Bitcoin’s Transaction Fee Mechanism

  • Allocation rule: miners choose which transactions to include in their block
  • Payment rule: transactions pay their bid (if allocated)

  • Effectively, a first-price auction.
  • Not truthful, bid determination is hard

  • Goal 2: simple for users

50

52 of 101

EIP-1559: Ethereum’s New TFM

  • Users pay a pre-determined base fee, and can add tips
  • Allocation rule: miners can choose the highest-tipping bids that pay the base fee
  • Payment rule: transactions pay the base fee and tip
  • Burn rule: The base fee is burnt for each transaction
  • Effectively, a first-price auction with burnt reserve
  • Tips are still not truthful
  • How to determine base fee?

Goal 3: Understand whether burning matters

51

Tip

Base

Tip

Base

Ethereum fees before and after EIP-1559 [LLNZZZ CCS’22]

TX

New Block of Size 2

Base Fee

A total of >4m ETH were burned since EIP-1559

53 of 101

Transaction Fee Mechanisms (TFMs)�

  • Treat TFMs as auctions [Lavi, Sattath & Zohar ‘17], [Yao ‘18]
  • [Roughgarden ’21] put forward collusion as a primary concern
    • Simple for Users: Truthful Bidding
    • Robust to Miners: No Omission or Shill-Bidding
    • Robust to Miner-User Collusion

52

The foundational open problem of TFMs:

Existence of a simple for users, miner non-manipulable, and robust to collusion TFM?

54 of 101

53

No deterministic mechanism satisfies all desiderata.

A gap in welfare exists for randomized mechanisms.

[Gafni & Yaish EC’24, Minor revision at Games and Economic Behavior]

55 of 101

1st and 2nd price auctions

54

 

1st-price auction

 

 

 

 

2nd-price auction

 

 

 

Pays its own bid

 

 

We focus on single-item auctions in the talk.

The paper characterizes the multi-item setting.

Highest bidder wins

Pays second highest bid

Highest bidder wins

56 of 101

 

 

 

 

Simple for Users ✅

Robust to Miner manipulation ✅

Pays set price (1.5)

Ok, bidder 1, just say you’re willing to pay 1.5, and I’ll cash you back 1

 

1.5

1

 

The true value for bidder 1

Bidder 1’s payment

Miner’s transfer

Arbitrary winner above a set price

Problem?

Hint: Bad price discovery, which motivates collusion

57 of 101

Some Notations…

  •  

56

58 of 101

The Desiderata

  •  

57

59 of 101

 

58

 

”Myerson’s Lemma” [Myerson ‘81] :

UIC <=> monotone allocation, payment uniquely determined by allocation.

60 of 101

 

59

 

 

 

 

 

 

 

 

 

No revenue…

 

 

61 of 101

What if we only have Global-SCP?

  • Same burn whenever allocating.

60

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Less burn, same value.

Bidder and Miner can balance using transfers.

62 of 101

Adding UIC and MIC into the mix…

Our characterization of Global-SCP:

Constant burn, highest-bidder allocated if and only if higher than the burn.

61

Achieving all together is impossible.

With UIC:

Second-price auctions with a reserve that is burned.

With MIC:

“Generalized first-price” auctions

A slightly generalized EIP-1559/Bitcoin Mechanism!

63 of 101

Randomized Mechanisms

So far, we discussed only deterministic mechanisms.

We always assumed a specific bidder is allocated.

What if we allow a random choice of who is allocated?

62

64 of 101

General Randomized Mechanisms

  • We show a tension between the two-bidder and single-bidder cases.

  • By MIC, (P1) the burn for two bidders surpasses the high-bidder payment.

Proof-sketch: We have 0 revenue with a single bidder (burn=payment).

Without (P1), miner would create a shill bidder.

  • By Global-SCP, a marginally high burn for the second bidder pushes low bidder to drop.

63

65 of 101

General Randomized Mechanisms

  •  

64

66 of 101

Takeaways

  • We can not have it all: We need to compromise on either security (MIC, Global-SCP), or simplicity (UIC)

  • The fee design of Bitcoin and EIP-1559 is exactly right, if we stick to security

  • There was no security need to move away from Bitcoin’s mechanism to EIP-1559

  • If we can get randomized mechanisms on-chain, this reopens the impossibility
    • [GTW ITCS’26] show a non-trivial randomized construction, while we show gaps from optimality. Still a huge gap between the two!

65

67 of 101

Emergence of Data-Sharing Protocols

66

🡪

Exclusivity Attacks

🡪

Robust Protocols

68 of 101

�A growing interest in building shared models…

67

$1.8B USD Data Marketplace Revenue

~24% Expected Annual Growth

SNSInsider, December 2025

69 of 101

Building Shared Models

  • Two real estate marketplaces want to predict house prices
  • Users randomly go to each
  • They want to run linear regression of the price vs. square feet
  • They want to keep updating the model as more data is added (‘continual learning’)

68

70 of 101

69

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Model

Federated Learning

71 of 101

70

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Model

Model

Model

Federated Learning

72 of 101

71

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Local Gradients 1

Local Gradients 2

Local Gradients 3

+

+

3

Updated Model

Federated Learning

73 of 101

72

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Model

Free-Riding is a threat!

74 of 101

73

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Model

Model

Model

Free-Riding is a threat!

75 of 101

74

Coordinator Server

Client 1

Client 2

Client 3

Local Data 1

Local Data 2

Local Data 3

Local Gradients 1

Local Gradients 2

Local Gradients 3

+

2

Updated Model

Free-Riding is a threat!

76 of 101

75

Client 1

Client 2

Client 3

Updated Model

Updated Model

Coordinator Server

Local Data 1

Local Data 2

Local Data 3

Updated Model

Local Gradients 3

Free-Riding is a threat!

77 of 101

76

“For Federated Learning, incentive mechanism design for honest participation is an important practical research question […] particularly relevant in the cross-silo setting, where participants may at the same time be business competitors.“

[Kairouz et al., “Advances and Open Problems in Federated Learning” 2021]

78 of 101

A General Concept:�Exclusivity Attacks

  • by sending distorted data, a firm can learn the best model, while also misleading the other firms.

  • Given a communication protocol and learning algorithm,

where all other agents report truthfully and accept the model,

can an attacker launch a successful exclusivity attack?

77

79 of 101

Example: The one-shot function SUM

78

20

10

+

=

30

80 of 101

Example: The one-shot function SUM

79

30

30

81 of 101

A successful attack on one-shot SUM

80

20

 

10

+

=

 

82 of 101

A successful attack on one-shot SUM

81

 

 

30

83 of 101

A failed attack on one-shot MAX

82

 

20

 

10

,

)=

max(

84 of 101

A failed attack on one-shot MAX

83

 

 

??

85 of 101

84

We consider a long-term interaction

Continuous Protocol:

Conditionally Vulnerable

Universally vulnerable

Linear Regression in d features

(d-LR)

k-Center Clustering

Yes

Yes

 

 

 

No

Periodic Protocol: d-LR, k-Center are not vulnerable.

86 of 101

Formal model – Continuous Protocol

  •  

85

87 of 101

A failed attack on continuous MAX

86

Ledger update:

120

Ledger update:

90

Nature

Agent 1

Agent 2

Ledger

True update:

90

User update:

90

Ledger update:

90

User update:

120

Ledger update:

120

True update:

90<X<120

User update:

90<X<120

Ledger update:

120

Ledger update:

120

88 of 101

Observed history, Strategy and Vulnerability

87

Ledger update:

120

Ledger update:

90

Nature

Agent 1

Agent 2

Ledger

True update:

90

User update:

90

Ledger update:

90

User update:

120

Ledger update:

120

True update:

90<X<120

User update:

90<X<120

Ledger update:

120

Ledger update:

120

Observed History: All the messages agent j sees.

Update Strategy: Mapping from observed histories to user updates.

Truthful: a user updates U iff the user received true update U

89 of 101

Observed history, Strategy and Vulnerability

88

Ledger update:

120

Ledger update:

90

Nature

Agent 1

Agent 2

Ledger

True update:

90

User update:

90

Ledger update:

90

User update:

120

Ledger update:

120

True update:

90<X<120

User update:

90<X<120

Ledger update:

120

Ledger update:

120

 

90 of 101

Observed history, Strategy and Vulnerability

89

Ledger update:

120

Ledger update:

90

Nature

Agent 1

Agent 2

Ledger

True update:

90

User update:

90

Ledger update:

90

User update:

120

Ledger update:

120

True update:

90<X<120

User update:

90<X<120

Ledger update:

120

Ledger update:

120

 

91 of 101

Linear regression

  •  

90

Challenge for the Attacker:

How to ‘reverse’ effects of fake points submitted?

92 of 101

A temporary omission conditional attack

  • What if the line of the last output and the new update (by itself) are the same?

91

93 of 101

A Universal Attack

  •  

92

94 of 101

A Universal Attack

  •  

93

95 of 101

Example of a universal attack on �Linear Regression with one feature.

94

Truthful

Universal Attack

96 of 101

Example of a universal attack on �Linear Regression with two features.

95

97 of 101

Takeaways

  •  

96

98 of 101

Looking Forward…

  • Blockchains in need of better, rigorously studied, systems.
  • AI in need of better understanding for economic & strategic effects.

97

99 of 101

  • A systematic effort for refined collusion and miner manipulation notions
    • Cryptographic primitives, colluder-infighting [FGR’24 🏭], reductions [G’25]

98

UNISWAP Foundation Fellowship!

Robust TFM Design

Blockchains Beyond TFMs

  • My current focus: Decentralized Autonomous Organization (DAOs)
  • Voting Tokens are used to decide billions of dollars in treasuries.
  • Suffer from rage-quitting [GG’24 🏆], centralization [G’25]

100 of 101

  • Implications of a ”multi-polar” AI landscape:
    • Division of Labor
    • Guaranteeing consumer outcome diversity [GGT SAGT’24, Revision TEAC]

99

Incentives & Economics of AI

Fair Allocation: Theory to Practice

  • A big literature on fair allocation (“cake-cutting”)
  • Takes a normative rather than descriptive approach. What do people really think?
  • What if we can sell / outsource? Create copies [GHLT-C TEAC’23]?

101 of 101

Thanks for listening!�