Quick Take
- Bitcoin leads the composite ranking despite its smaller block-production coalition.
- Pool and validator counts measure coordination risk, while hosting and shared software create separate exposures.
- Institutions must assess ownership, infrastructure and exit speed alongside consensus thresholds.
ARK Invest and Glassnode have put a new number on blockchain capture risk: the smallest group of block-production entities needed to cross a protocol-relevant control threshold.
Their joint scorecard, published Sept. 1, put the threshold at three entities for Bitcoin and Ethereum and 19 for Solana. The same framework placed Bitcoin first in its composite decentralization ranking. The apparent tension reflects different forms of network exposure. The coalition needed to disrupt consensus is one risk measure; ownership, infrastructure, software, auditability and exit speed describe other routes to pressure a network.
Institutions considering a blockchain as settlement infrastructure must define the failure they need to survive before selecting a metric.
What the 3/3/19 result measures
The report calls the measure a critical resilience threshold. It asks how many of the largest entities must coordinate to pass a concentration point governing block production or voting power.
The inputs change by network. Bitcoin weights hash rate attributed to mining pools. Ethereum and Solana weight stake, while their dashboards may classify a liquid-staking protocol, exchange, distributed validator network, underlying operator or individual validator as the relevant entity. Protocol rules then determine what a given percentage can accomplish.
| Network | Reported count | Coordination unit | Risk captured | Outside the measure |
|---|---|---|---|---|
| Bitcoin | 3 | Mining-pool labels by hash rate | Concentrated block-template coordination at the report's threshold | Hardware ownership, pool switching and node distribution |
| Ethereum | 3 | Staking entities under the report's taxonomy | Stake concentration at the selected threshold | Underlying operators, attack level, clients, hosting and exit queues |
| Solana | 19 | Validators by delegated stake | A coalition crossing the measured one-third voting-power threshold | Common owners, delegation sources, software and data centers |
A seven-day Bitcoin mining snapshot on Sept. 6 attributed 26.88% of blocks to Foundry USA, 16.91% to AntPool and 15.25% to F2Pool. The three pools coordinated block templates for 59.04% of observed production, consistent with the report's three-pool result.
Pool share remains distinct from miner ownership. Individual miners supply work to a coordinator and can redirect that hash rate. The report estimates that a miner could leave a 1% Bitcoin position in roughly 30 seconds by switching off hardware. This mobility makes pool concentration important for short-term censorship and template selection while leaving ultimate control of the machines more dispersed.
Ethereum highlights the classification problem from the other direction. Rated Network, an Ethereum validator analytics provider, listed Lido at 21.17%, SSV at 16.56% and Binance at 7.77% in its Sept. 6 pool view. The same table described Lido as 544 entities. One label can therefore represent a protocol, hundreds of operators or both, depending on the grouping.
Ethereum's own threat model adds another distinction. Official protocol documentation says at least 33% of stake can delay finality. More than 50% can censor transactions and control short-range fork choice. At least 66% can finalize a preferred chain and alter finalized history. Each attack maps to a different threshold.
Solana's coefficient also changes with stake distribution. Solana Compass, an independent network dashboard, showed a Nakamoto coefficient of 18 on Sept. 6. ARK and Glassnode reported 19, while the Solana Foundation's June 2025 health report, using April 2025 data, recorded 20.
Solana Compass defines the coefficient as the fewest validators whose combined stake reaches 33.4% of voting power. The Foundation links that coalition to censoring blocks or stopping consensus. A value of 18 means that this specific disruption requires coordination across more top validators than a count of three would suggest. Shared ownership, stake sources, hosting, jurisdiction and software create separate exposures.
The dependencies that reshape capture risk
Infrastructure can give nominally separate entities a correlated failure mode. A data-center operator, cloud platform, government or network carrier can affect many nodes or validators together, even when the consensus coefficient looks widely distributed.
Bitcoin's node footprint illustrates how measurements can shift with the crawler. The joint report cited 63% of Bitcoin nodes operating behind Tor. A Clark Moody network dashboard showed 12,959 Tor nodes among 26,837 reachable nodes on Sept. 6, or 48.3%. Different node populations and collection methods can produce materially different shares. In either case, Tor usage speaks to node visibility and geographic resilience, while mining pools remain the direct block-production measure.
Ethereum hosting data varies for the same reason. The report cited roughly 20% of nodes on AWS. Rated Network's host view showed AWS at 14.4% of measured validator hosts. Ethernodes, an execution-layer node crawler, tracks another slice of the network and separates Amazon infrastructure across several ISP labels. A single AWS percentage loses meaning unless the node population and provider taxonomy travel with it.
Solana exposes the performance side of the tradeoff. High-throughput validators generally operate in commercial data centers. The Solana Foundation's dated 2025 report counted more than 100 providers, with TeraSwitch and Latitude hosting 45.70% of stake between them. Solana Compass's current broader view counted 437 data centers. The large facility count coexists with a sizable stake concentration among the leading providers.
Client software creates a second common dependency. Ethereum's client-diversity guidance explains that independent implementations reduce the blast radius of a shared bug. Rated showed Geth at 50.17% of measured execution clients. On Solana, the Foundation reported about 92% of stake using Agave/Jito and about 7% using Firedancer or the hybrid Frankendancer in April 2025. These figures measure exposure to a shared codebase, a failure mode separate from deliberate collusion.
Exit speed determines how long concentrated influence can persist. Bitcoin miners can redirect work without waiting for a protocol queue. Ethereum validators follow a rate-limited exit process. ARK and Glassnode's estimate of weeks applies to stressed conditions. On Sept. 6, beaconcha.in's live queue showed an empty validator exit queue and a withdrawal estimate near one day. Ethereum's withdrawal documentation explains that the delay moves with demand.
During coercion, the separation becomes practical. Hash power can leave a pool quickly when miners defect. Stake can remain tied to a validator during a congested exit queue, even when a liquid-staking token trades freely. Market liquidity and protocol exit provide different escape routes.
How institutions should read the scorecard
An institutional decentralization review can pair each threat with the corresponding measure:
- Transaction censorship or finality disruption calls for stake or hash-rate concentration at the relevant protocol threshold, with transparent entity grouping.
- Coordinated legal pressure and infrastructure outages call for validator and node maps by provider, jurisdiction and network operator.
- Software faults call for client-share and shared-codebase analysis.
- Persistent capture calls for beneficial ownership, delegation sources and the time required to withdraw or redirect resources.
- Independent verification and recovery call for the cost of running a verifier and reconstructing network state.
The joint report's composite ranking favors Bitcoin because the framework combines auditability, ownership dispersion, geographic resilience, exit fluidity and other dimensions. Solana's 19-entity result, now 18 on one live dashboard, describes one form of coordination risk.
The figure describes the largest-validator coalition needed to cross Solana's measured voting threshold. An institutional decision also requires the rest of the map, including who supplies the stake, where the machines run, which software they share, how quickly participants can leave and how independently users can verify the ledger.
Solana is -1.12% over the past 24 hours and currently sits at rank #7 by market cap.
Facts Only
ARK Invest and Glassnode published a blockchain capture risk scorecard on September 1.
The critical resilience threshold for Bitcoin and Ethereum is three entities; for Solana, it is 19.
Bitcoin's ranking considers hash rate attributed to mining pools.
Ethereum and Solana's rankings weight stake.
A September 6 Bitcoin snapshot showed Foundry USA (26.88%), AntPool (16.91%), and F2Pool (15.25%) controlled 59.04% of blocks.
A September 6 Ethereum pool view listed Lido at 21.17%, SSV at 16.56%, and Binance at 7.77%.
Solana Compass reported a Nakamoto coefficient of 18 on September 6.
The Solana Foundation's June 2025 health report used April 2025 data to record a coefficient of 20.
Approximately 63% of Bitcoin nodes operate behind Tor according to the ARK/Glassnode report, while a Clark Moody dashboard showed 48.3% on September 6.
Rated Network measured Geth at 50.17% of Ethereum execution clients.
TeraSwitch and Latitude hosted 45.70% of Solana stake according to a 2025 Foundation report.
Executive Summary
Blockchain decentralization is measured through various lenses, primarily the "critical resilience threshold," which identifies the minimum number of entities required to coordinate and cross a control threshold. While Bitcoin and Ethereum require only three entities to reach this point in some models, Solana requires 19. However, these numbers do not tell the full story of network risk. Bitcoin leads composite rankings because it balances this coordination risk with high geographic resilience, auditability, and rapid exit speeds for miners.
True network exposure involves multiple layers of dependency beyond consensus voting. Infrastructure concentration in cloud providers like AWS, shared software clients like Geth or Agave, and the speed at which participants can withdraw stake or redirect hash power create distinct failure modes. For example, while Solana shows a higher coordination threshold, it possesses significant stake concentration within a few commercial data centers. Consequently, institutional assessment requires a multi-dimensional approach, mapping jurisdiction, hosting, and codebase diversity alongside raw voting power to define which specific failure modes a system must survive.
Full Take
The strongest version of this narrative is that "decentralization" is not a single number but a multidimensional risk map. By decomposing the concept into coordination thresholds, infrastructure dependencies, and exit liquidity, the framework moves the conversation from ideological purity to operational resilience.
This analysis operates in SKEPTICAL MODE. It avoids the trap of a "single metric" victory by admitting that a high Nakamoto coefficient (Solana) can be offset by high infrastructure correlation (data centers). It effectively steelmans the trade-off between high-throughput performance and the resulting lean toward commercial hosting.
The root cause of this narrative is the institutionalization of crypto. As settlement infrastructure moves from hobbyists to banks, the paradigm shifts from "censorship resistance" (a political goal) to "systemic risk management" (a compliance goal). The unstated assumption is that "capture" is an inevitable risk to be mitigated rather than a possibility to be eliminated.
The implication is a shift in agency: power is no longer just about who owns the coins, but who owns the servers and writes the client code. This creates a second-order effect where "decentralization" becomes a technical optimization problem solved by vendors rather than a social property of a network.
Bridge Questions:
1. If a network is computationally decentralized but hosted on two cloud providers, is it actually decentralized, or is the "consensus" merely a facade for a centralized infrastructure provider?
2. How does the "exit speed" of a participant change the actual power of a coordinating coalition in a real-time crisis?
Patterns detected: none
Counterstrike Scan: A coordinated campaign to pump a specific asset would use these numbers to claim "mathematical superiority" while ignoring the "Outside the measure" column. This content does the opposite, explicitly highlighting the gaps in its own metrics. Clean.
