18 MIN15 SEPT 2026

PriFi and the Incomplete Institution: Securing the Transaction Supply Chain

Extending imperative credibility beyond transaction settlement to reduce risks and costs

L

Logos

Share
Blockchains solved one of the oldest economic problems: how to make a promise hold even when the party making it would prefer otherwise. But transactions do not begin or end at settlement. If security is concentrated at the moment value moves, while information and discretion remain exposed everywhere around it, the transaction remains vulnerable. PriFi aims to secure the entire transaction supply chain.

For most of crypto’s history, we have treated onchain transactions as if they were atomic events. We tend to consider them as self-contained moments: a signed instruction enters the network, executes, and settles. In reality, they comprise a series of links in a wider chain. They include discovery, diligence, negotiation, contracting, ordering, settlement, and enforcement.

Settlement is where blockchains are extraordinary. Bitcoin demonstrated that monetary rules could be enforced without reliance on a central operator who can make exceptions. Ethereum extended the principle to programmable agreements. A valid state transition is accepted; an invalid one is rejected. Counterparties do not need to trust a minister, bank manager, or platform operator to consistently honour rules.

Institutions have always struggled with the problem of credible commitment: How can we trust that a party will act in accordance with agreements made when breaking their word may be in their interest? Blockchains realised historically unprecedented guarantees by removing the discretion to defect and making rules self-enforcing.

Yet the absolute transparency that enables blockchain to structurally constrain defection introduces new attack surfaces by making information about the transaction available to every network observer. These attack surfaces discourage wider participation in onchain finance and define the problem space for those building PriFi infrastructure. 

The proposition is not simply that financial transactions should be “more private”. It is that the correct unit of analysis is the entire transaction lifecycle, and that strengthening commitments requires heightened privacy and security at each link.

The transaction lifecycle

Ronald Coase observed that exchange itself is costly. Finding somebody to trade with, discovering prices, negotiating an agreement, and ensuring the other party holds up their end of the deal all require effort and therefore involve costs (Coase, 1937). Carl Dahlman later grouped these costs into three broad categories: search and information costs, bargaining and decision costs, and policing and enforcement costs (Dahlman, 1979).

Building on Dahlman’s ideas, we can consider the transaction having a seven-step lifecycle:

  1. Discovery: finding a potential counterparty.
  2. Diligence: establishing who they are and whether their claims are credible.
  3. Negotiation: reaching an agreement on terms.
  4. Contracting: fixing those terms in a form intended to bind the parties.
  5. Ordering: determining the order in which transactions are processed.
  6. Settlement: the only link where value actually moves.
  7. Enforcement: making the agreed outcome stick after settlement.
Transaction Supply Chain.png
Transaction Supply Chain.png

Settlement is the hinge. Everything before it prepares the parties to transfer value; everything after it makes the transfer durable.

Consider a house purchase. The payment at completion may settle in a few minutes, but the economically meaningful transaction has already spent weeks passing through estate agents, inspections, searches, mortgage underwriting, price negotiations, contracting, and title verification. Securing the final bank transfer while leaving the previous stages open to fraud or manipulation would not secure the purchase in a way that would satisfy the counterparties to the deal. Similarly, if an institutional investor wants to build a large position, but their intentions leak during discovery or negotiation, other market participants can take advantageous positions that could compromise the profitability of the investor’s planned trade well before settlement occurs.

Clearly, the security of a transaction cannot be judged by settlement alone. At every stage, somebody is entrusted with information, discretion, or control that could be exploited. Securing the transaction, therefore, requires more than protecting the movement of value: it requires safeguards at each of the seven links. That raises the question: What makes safeguards credible in the first place?

What makes a commitment credible?

Governments, banks, courts, companies, and protocols make promises about their future conduct. A government promises not to confiscate property. A central bank promises to protect the integrity of money. A regular bank promises to return deposits. An exchange promises to follow its stated rules. A platform promises not to misuse privileged information. The quality of those promises cannot be judged when keeping them is convenient. The real test is when defection becomes the more attractive option.

Barry Weingast captured the political version of this commitment problem succinctly: a government strong enough to protect property is also strong enough to confiscate wealth (Weingast, 1995). The power that makes an institution useful can also make it a threat.

The history of institutional development can, in part, be read as a history of attempts to manage that dilemma. Douglass North and Barry Weingast’s study of England after the Glorious Revolution argued that institutional changes, including greater parliamentary control over public finances, constrained the Crown’s ability to interfere arbitrarily with property and public credit. Over the following decades, government borrowing costs fell from 14% to around 3% as lenders became more confident that repayment was no longer simply a matter of royal discretion  (North & Weingast, 1989).

We can broadly consider the quality of institutional commitments through two lenses: motivational credibility and imperative credibility. In the former case, the promiser can defect on a commitment but has a reason not to. This might be upholding their reputation, protecting pledged collateral, or securing repeat business. 

commitments-logos-prifi
commitments-logos-prifi

Oliver Williamson’s work on private ordering and credible commitments describes arrangements designed to make opportunistic defection costly enough that continued cooperation becomes preferable (Williamson, 1983). Much of commercial society depends upon this form of credibility. However, its effectiveness depends on the incentives that sustain it.

Imperative credibility is much stronger. Here, the discretion to defect has been removed structurally or made prohibitively expensive to exercise. The promise does not depend only on the operator choosing to uphold their side; some structural mechanism constrains their ability to renege on a deal. This is where cryptonetworks made their historic contribution. 

A Bitcoin node does not reject an invalid block because protecting Bitcoin’s reputation seems commercially attractive. It rejects the block because the rules determining validity are constitutive of the system. The promise has migrated from institutional behaviour into institutional structure.

Motivation and imperative commitments respond differently to pressure. Motivational credibility must be sustained by incentives. If those incentives change, the behaviour they support may also change. Imperative credibility instead narrows the space in which discretion can be exercised at all.

This is the institutional breakthrough that cryptonetworks introduced. However, it only protects one link in the transaction lifecycle – settlement – while the absolute transparency required to achieve this unprecedented level of imperative credibility exposes other links to attacks.

Two different hazards

Classical transaction-cost economics is deeply concerned with opportunism. Williamson describes opportunism as “self-interest seeking with guile”: a counterparty may misrepresent what they are selling, withhold information, default after receiving payment, exploit an incomplete contract, or take advantage of a dependency that emerges after the other party has committed resources. These are hazards inside the transaction, and modern economies have developed an enormous institutional apparatus to manage them, including contracts, courts, escrow services, collateral, warranties, reputation, fiduciary duties, auditing, and, more recently, smart contracts. 

However, there is another class of hazards in which an attacker may have no part in the transaction at all. These out-of-transaction hazards include thieves with knowledge of where assets are custodied, competitors taking advantage of known terms, extortionists who know what you can afford to pay, and searchers looking for onchain transactions to frontrun. 

Each of the two hazard classes operates differently, and therefore, the defences against them are different. An opportunistic counterparty already has access to certain information. Dealing with somebody necessarily involves revealing things like who you are and what you hold. Therefore, protection must rely heavily on binding the counterparty’s behaviour through contracts, collateral requirements, possible reputational damage, or penalties for not upholding their end of the bargain.

Those outside a deal usually do not have any relationship to the parties of the deal. Therefore, information becomes an essential first input. A burglar cannot target a safe whose existence is unknown. Nor can a rival bidder undercut a confidential offer it has never seen. Onchain, a searcher cannot frontrun an order it is unaware of. While information is not sufficient for predation on its own because an attacker still needs the capacity to act, it often determines whether there is a target in the first place.

Blockchain strengthens settlement but reverses the informational default

Classical transaction-level theory pays relatively little attention to this second class of hazard because commercial confidentiality was, to a significant extent, part of the institutional background in which exchange took place. A merchant kept their ledger private, banks developed duties of confidence, lawyers protected privileged communications, companies negotiated acquisitions behind closed doors, governments used sealed bids, and financial markets developed mechanisms for concealing large orders. These arrangements were imperfect, and information could still leak, but universal publication was not the default.

Williamson distinguished between the “institutional environment” – the rules of the game – and the institutions of governance operating within that environment. Features of the environment could therefore be treated as background conditions while different governance structures were compared (Williamson, 1991). Confidentiality was, to a large extent, one of those background conditions.

Transparent blockchains invert that condition. Information that was once fragmented across private ledgers, institutions, and counterparties is instead recorded in a common, persistent, and widely observable data structure. The cost of acquiring information, therefore, falls dramatically: what might require access to a bank, broker, counterparty, or court order outside of crypto becomes a database query.

This changes the economics of the threat itself. An outsider who previously had to put effort into discovering that a transaction, asset, or position existed may now query information as a byproduct of the system’s operation. A hazard that could previously be mitigated as part of the institutional background moves into the transaction itself.

Blockchain achieves unprecedented verifiability by making everything transparent by default. However, the same transparency that allows an honest observer to verify the system can also supply an unbound outsider with the information needed to identify, monitor, and potentially exploit a target.

Security and secrecy are complements

With the two hazard classes identified, we can consider different approaches to protecting against them. The first is to bind or deter the actor who might harm you. Contracts, collateral, legal penalties, access controls, signature requirements, and consensus rules all fit this family. For this article, we will call this “security”. The second is to deny would-be attackers the information that makes targeting possible. For this article, we will call this “secrecy”.

These protections do not map perfectly onto the two hazard classes, but there is a strong asymmetry. You normally cannot starve a counterparty of all information. If somebody is lending against your assets, acquiring your company, or entering into a bilateral trade with you, they need to know something about you and your ability to honour the deal. The answer is selective disclosure plus binding.

Outsiders present almost the reverse problem. They have signed nothing. They may live beyond your jurisdiction. They may never reveal their intentions unless they attack. You cannot negotiate confidentiality agreements with every thief, frontrunner, hostile competitor, data broker, or coercive authority that might eventually take an interest in your transaction. Therefore, when binding them becomes unfeasible, the efficient defence is to avoid sharing exploitable information with them.

The two protections are complementary. Secrecy without security is fragile. Revealing everything privately to an intermediary that remains free to betray you simply concentrates the attack surface. Security without secrecy is incomplete. Perfectly protecting an asset while broadcasting a detailed targeting map tells every unbound outsider where to concentrate their attention.

Secrecy.png
Secrecy.png

This insight has implications for property itself. An important strand of property theory treats the right to exclude as central to ownership (Honoré, 1961; Merrill, 1998). If information is an input into appropriation, it follows that controlling access to information about an asset may form part of the practical ability to exclude others from exploiting it. Mayshar, Moav, and Neeman make a related argument in political economy: the transparency of productive activity affects the ease with which its returns can be appropriated, and, in turn, the institutions that emerge around it (Mayshar, Moav, & Neeman, 2017).

PriFi takes that intuition and applies it to the transaction level. A property right can be extraordinarily secure in the narrow sense that nobody can alter the ledger without authorisation, while remaining unusually weak in the informational sense that every potential claimant can observe the asset and its history. The result is a peculiar institutional object: a vault with exceptionally strong locks and perfectly transparent glass walls.

Blockchain and the glass-vault problem

Transparent blockchains create a genuine institutional inversion. At the rule layer, they are exceptionally strong. At the information layer, they are exceptionally legible. These two properties arise from the same architecture.

Broadcasting everything to every participant made verification possible without relying upon a privileged insider. Anyone could reproduce the state transition and confirm that the rules had been followed. While that is a major achievement without historical parallel, a broadcast cannot distinguish between audiences. The same information reaches the counterparty, the verifier, the competitor, the thief, the analytics company, the searcher, and the state.

Persistent ledgers compound the problem. Pseudonymity may protect an identity for some period, but identity and addresses can later be connected through an exchange, a payment for a physical good, an operational error, a public disclosure, or another external dataset. Once a connection is established, information recorded years earlier can acquire new meaning retrospectively.

Furthermore, some attacks do not need the connection at all. For address poisoning, an onchain address is itself enough of a target. For many forms of maximal extractable value, transaction intention is the crucial input. For such strategies, the economically relevant fact may simply be that a sufficiently large position is visible and approaching a threshold. The human name behind the transaction may be irrelevant. This is why the transparency question cannot be reduced to anonymous addresses alone.

When the chain works perfectly, but an attack is still successful

The 2025 Bybit theft of $1.5 billion provides a clear illustration of transaction lifecycles extending far beyond settlement. The attack occurred around the signing process. The interface through which authorised participants understood the transaction they were approving was compromised. Once the signed instruction entered the mempool, the chain executed it. The settlement mechanism was not cryptographically defeated. 

The uncomfortable lesson is that the blockchain could work exactly as intended, while the economic transaction still failed catastrophically. The settlement layer enforced what had been signed, not what was intended. The sixth link held, but the exploit had already occurred by that point.

Privacy must not be patched in

The obvious response is to make individual blockchain functions private. While that work is essential, the transaction-supply-chain framing leads to a more demanding conclusion: protection has a weakest-link structure. If the settlement is private but discovery reveals counterparties, an attacker moves to discovery. If balances are private but intentions enter a public queue before execution, an attacker moves to ordering. The vulnerability has been relocated, and so will the attack.

Something similar happens when privacy is provided by a trusted intermediary. A private order-flow service can shield an order from the public mempool. That may materially improve the user’s position. However, the service itself acquires privileged information. The user has, therefore, exchanged public exposure for reliance upon a named intermediary. 

The protection has migrated from imperative credibility back towards motivational credibility. The intermediary could misuse the information, but promises not to. That may be acceptable, and sometimes motivational commitments are entirely appropriate. However, a privacy mechanism that relocates discretion has moved, not eliminated, the commitment problem. As such, “PriFi” cannot simply mean “a private ledger”. It requires codesigning protection, considering both secrecy and security, across the lifecycle under a common threat model.

Checkability and readability are not the same

There is an important objection to this argument: information can improve markets. George Stigler and Richard Posner both emphasised the economic costs of privacy, where it allows parties to conceal information relevant to a counterparty’s assessment or pricing of a transaction (Stigler, 1980; Posner, 1981). A borrower concealing insolvency from a lender is not creating a better market, and a seller concealing a defect from a buyer is not exercising economically productive privacy.

The objection is real but applies most directly to the relationship between transacting parties. While a lender may need to know that a borrower satisfies a collateral requirement, it does not follow that every observer needs the borrower’s entire financial history. Similarly, a counterparty may need assurance that an offer is valid but would not appreciate competing bidders being able to see the bid ahead of an auction’s close. 

The objective is, therefore, appropriate information revelation, not absolute secrecy. The distinction is between information disclosed because a particular relationship requires it and information disclosed merely because the infrastructure broadcasts it. 

Modern cryptography makes this distinction increasingly actionable. Zero-knowledge proofs, selective disclosure systems, commitments, secure computation, and related techniques open a design space between the two extremes of “just trust me” and “show everyone everything”. For PriFi, the institutional objective should be to preserve auditability without requiring universal readability.

PriFi as a research problem

Under this framing, private finance is a problem of institutional completeness, rather than simply a niche for users with unusually strong preferences about privacy. Crypto has already demonstrated that architecture can remove discretion from one crucial part of exchange. PriFi asks what follows if we apply the same protections to the rest of the transaction. 

How should counterparties discover one another without unnecessarily broadcasting their intentions? How can counterparties get the information necessary for exchange without creating permanent public dossiers? How should negotiation occur when metadata may reveal economic strategy? How should the operators who maintain network order be protected against coercion when identifying them is itself part of the attack? And so on.

These questions sit across economics, distributed systems, cryptography, networking, mechanism design, information security, and institutional theory.

PriFi: Protecting the entire transaction lifecycle

Transactions pass through seven links. Every link creates positions from which somebody may be able to exploit the transaction. Those threats can be categorised into two different classes: opportunism among the parties and predation from outside them. 

Each class requires a different form of protection. While security binds, constrains, and deters, secrecy reduces unnecessary knowledge and, therefore, reduces the surface available for targeting. Neither protection substitutes completely for the other because a transaction inherits the weakness of the least protected link in the supply chain.

Blockchains represent a remarkable institutional achievement because they supply imperative credibility at settlement. But the radical transparency required to achieve this introduces new vulnerabilities at other links in the chain. 

PriFi involves bringing the same level of credibility to each link in the chain. It is not privacy bolted onto existing systems but rather systems designed from the ground up to allow counterparties to conceal valuable and exploitable information such that they can confidently enter into trades.

Build PriFi infrastructure on Logos Basecamp

Explore sample PriFi tools on Logos

Learn more about how Logos secures the complete transaction supply chain.

 

This article is based on research compiled by Logos cofounder Jarrad Hope and ideas emerging from it. PriFi is central to Logos’ goal to revitalise civil society. Effective parallel organising requires economic rails that can withstand outside efforts to obstruct and manipulate activity.

Selected references

Coase, Ronald H., "The Nature of the Firm", Economica 4, no. 16 (1937), 386–405.

Dahlman, Carl J., "The Problem of Externality", Journal of Law and Economics 22, no. 1 (1979), 141–162.

Dharmapala, Dhammika, and James R. Hines Jr., "Which Countries Become Tax Havens?", Journal of Public Economics 93, nos. 9–10 (2009), 1058–1068.

Hines, James R. Jr., "Treasure Islands", Journal of Economic Perspectives 24, no. 4 (2010), 103–126.

Hirshleifer, Jack, "The Private and Social Value of Information and the Reward to Inventive Activity", American Economic Review 61, no. 4 (1971), 561–574.

Honoré, A. M., "Ownership", Oxford Essays in Jurisprudence (Oxford: Oxford University Press, 1961).

Mayshar, Joram, Omer Moav, and Zvika Neeman, "Geography, Transparency, and Institutions", American Political Science Review 111, no. 3 (2017), 622–636.

Merrill, Thomas W., "Property and the Right to Exclude", Nebraska Law Review 77 (1998), 730–755.

North, Douglass C., "Institutions and Credible Commitment", Journal of Institutional and Theoretical Economics 149, no. 1 (1993), 11–23.

North, Douglass C., and Barry R. Weingast, "Constitutions and Commitment: The Evolution of Institutions Governing Public Choice in Seventeenth-Century England", Journal of Economic History 49, no. 4 (1989), 803–832.

Palan, Ronen, "Tax Havens and the Commercialization of State Sovereignty", International Organization 56, no. 1 (2002), 151–176.

Posner, Richard A., "The Economics of Privacy", American Economic Review 71, no. 2 (1981), 405–409.

Romano, Roberta, "Law as a Product: Some Pieces of the Incorporation Puzzle", Journal of Law, Economics, & Organization 1, no. 2 (1985), 225–283.

Shepsle, Kenneth A., "Discretion, Institutions, and the Problem of Government Commitment", Social Theory for a Changing Society (Boulder, CO: Westview Press, 1991).

Stigler, George J., "An Introduction to Privacy in Economics and Politics", Journal of Legal Studies 9, no. 4 (1980), 623–644.

Überbacher, Florian, and Andreas Georg Scherer, "Indirect Compellence and Institutional Change: U.S. Extraterritorial Law Enforcement and the Erosion of Swiss Banking Secrecy", Administrative Science Quarterly 65, no. 3 (2020), 565–605.

Weingast, Barry R., "The Economic Role of Political Institutions: Market-Preserving Federalism and Economic Development", Journal of Law, Economics, & Organization 11, no. 1 (1995), 1–31.

Williamson, Oliver E., "Credible Commitments: Using Hostages to Support Exchange", American Economic Review 73, no. 4 (1983), 519–540.

Williamson, Oliver E., "Comparative Economic Organization: The Analysis of Discrete Structural Alternatives", Administrative Science Quarterly 36, no. 2 (1991), 269–296.

Williamson, Oliver E., The Mechanisms of Governance (Oxford: Oxford University Press, 1996).

 

Discussion

No discussion yet.
Basecamp in Testnet v0.2: The Local-First Launcher for Privacy-Preserving Applications
L

Logos

28 July 2026
Logos Dev Update: August 2026
L

Logos

13 September 2026

Freedom needs builders

Stay ahead with the latest updates

Logos
GithubWork With UsTerms & ConditionsPrivacy PolicySecurity