Skip to main content

ZetaChain’s tokenholders have voted to switch off their own blockchain. Governance proposal 68 passed on Sunday with 99.4% support and 58% participation, comfortably clearing the network’s 40% quorum. The Cosmos SDK layer 1 will be wound down and ZETA will be reissued as an SPL token on Solana at 1:1, same ticker, same total supply. The stated reason is focus: maintaining a chain no longer serves the project’s pivot to Anuma, its privacy-focused AI application, so the resources move to that instead.

It is, by the standards of this sort of thing, a tidy process. The vote does not itself pull the plug. A second proposal will set the withdrawal window for assets bridged in from other chains, the snapshot block height, the shutdown timetable, the claim process and the exchange conversion period. Validators keep running and staking rewards keep paying through the transition. Compare that to Harmony, which floated a non-binding shutdown proposal a fortnight ago and told users to exit their contracts inside four days, and ZetaChain looks like the grown-up in the room.

So this is not a post about a project behaving badly. It is a post about the half of the sentence “converting 1:1” that nobody put to a vote, because nobody could.

TL;DR

  • ZetaChain proposal 68 passed with 99.4% support on 58% participation, winding down its Cosmos SDK layer 1 and reissuing ZETA as an SPL token on Solana at 1:1.
  • “1:1” is a statement about quantity. Your balance, ticker and supply survive the move intact.
  • What does not survive is everything else the chain was providing: its consensus, its validator set, its finality, its fee market, its outage record. Those are replaced wholesale, not converted.
  • No ballot could have asked about them, because a trust assumption has no unit you can vote in. 99.4% agreement on the motion is not 99.4% agreement on the substitution.
  • Every “provably fair” claim in on-chain gaming is a conditional sentence whose second half is the chain underneath it. Satoshie names that half out loud: Base, and a Chainlink VRF coordinator address written into the deployed contract before anyone stakes.

The ratio has two sides, and only one of them is a number

A 1:1 conversion is a promise about counting. You had 1,000 ZETA on a Cosmos chain, you will have 1,000 ZETA on Solana, and the total supply is unchanged so nobody is being diluted in the swap. All of that is true, checkable, and genuinely worth doing properly.

Now ask what the first 1,000 was actually made of. A token is not the number. The number is a row in a database. What gives the row meaning is the set of properties the chain around it guarantees: how many independent parties would have to collude to rewrite your row, how long after a transaction you can stop worrying about it, who is able to halt the whole thing and under what circumstances, what it costs somebody to keep your transaction out, whose client software every validator is running, and what happens to all of it when demand spikes.

None of that converts. It gets replaced. Solana’s validator set is not ZetaChain’s validator set. Its consensus is a different design with a different failure surface. Its fee market behaves differently under load, and its liveness record is its own. This is not a swipe at Solana, which is a faster and vastly more liquid home than the chain being switched off, and for most ZETA holders the migration is probably an upgrade on every axis they care about. That is precisely what makes it a good example. The substitution can be an improvement and still be a substitution.

Here is the part that should bother you. There is no field for it. Your wallet shows a number and a ticker, both preserved. Block explorers report balances. Dashboards report supply. Proof-of-reserves attestations report quantities. The entire verification apparatus the industry has built measures the one property that survives a chain migration unchanged, which is exactly why migrations get described as 1:1. The things that were swapped are not in any of those readouts, and there is nowhere to look them up, because they were never written down as terms in the first place. You inherited them by deploying somewhere.

Why the vote could not have asked

Ninety-nine point four per cent is an enormous mandate, and the count is not in question. Everyone who held ZETA and cared could vote, quorum was cleared with room to spare, the result is on-chain and reproducible by a stranger. As governance goes, that is close to the best-case version of this event.

But notice what the ballot could physically contain. Governance needs a countable question. “Shall we wind down the layer 1 and reissue on Solana, yes or no” is countable, so it got asked and it got answered. “Is Solana’s trust model an acceptable replacement for the one you were relying on when you took this position” is not countable. There is no denomination in which to express “yes to the wind-down, but I underwrote a sovereign chain and I am not sure I underwrote this one”. You cannot vote 0.6 of a token’s worth of reservation about finality.

That makes 99.4% a number about a motion, not about a migration. The holders approved a plan. Approving a plan is not the same act as re-underwriting a security model, and nothing in the mechanism forced anyone to do the second thing or gave them a way to record it if they did.

This is a different defect from the one we wrote about when Solana ran its own first network-wide vote last month. There, the question was representation: whether the stake doing the voting actually expressed the preferences of the people who owned it, given that delegated stake votes with its validator by default. Here, representation is fine. The problem sits upstream of counting. The thing that changed was not on the ballot because it has no unit.

A chain built to make chains interchangeable, discovering they are not

ZetaChain was founded in 2021 as an interoperability project and raised $27 million in 2023, from Blockchain.com, Jane Street Capital, Human Capital and Sky9 Capital, to build a layer 1 that would connect assets and data across other blockchains. Its whole thesis was that which chain a thing sits on should stop mattering.

If that were true, this migration would be paperwork. Instead it needs a withdrawal window for bridged assets, a snapshot block height, a claim process and a conversion period negotiated with exchanges. Every one of those exists because moving between chains is not a transfer, it is an exit and a reissue, and the two are only equivalent in the column marked “amount”. The project’s own shutdown checklist is the strongest available evidence against the premise it was funded on.

There is also April to remember, when a flaw in ZetaChain’s cross-chain gateway contract drained about $334,000 from ZetaChain-controlled wallets on Ethereum, Arbitrum, Base and BNB Smart Chain. The project later acknowledged it had dismissed an earlier bug bounty report describing the vulnerability as intended behaviour. “Intended behaviour” is a judgement somebody makes. It looks identical to a proof right up until it isn’t.

What this means if you play anything on-chain

“Provably fair” is not a claim. It is a conditional. The full sentence reads: given that this chain executed this code, and given that this randomness source produced this value, and given that this history cannot be rewritten, the winner follows and you can check it yourself.

Everything after the word “given” is inherited from the chain. Operators quote the first half on the marketing page and never write the second half down, which is convenient, because the second half is the part that can be changed by a governance vote in which you hold no position, on a timeline nobody told you about. The marketing copy stays word-for-word true throughout. A draw settled on a chain that later winds down was fair when it happened and stays mathematically true forever; it just becomes progressively harder to reach once the nodes that served it stop. We have written before about who actually stores your proof. This is the other question: who defines what the proof was proving against.

So here is ours, in full, so you can hold us to it. Satoshie runs on Base. The raffle contract is deployed before entries open. The Chainlink VRF coordinator address is written into that deployed code, in public, before anyone stakes anything. The VRF proof is verified on-chain before the callback is permitted to act on it, the winner is computed in the callback, the payout settles in the same transaction, and there is no admin key that can reach in afterwards. The conditional is named rather than implied, which means you can go and read the assumptions instead of discovering them during a wind-down.

Our own exposure, stated plainly

Base has a company-operated sequencer. Our liveness depends on an operator, and that is a trust assumption whether or not we enjoy typing the words. If we ever deployed elsewhere, every proof from every draw we have already run would stay on Base, because that is where it happened, and anything we said about those draws afterwards would be a claim made from a place we had left. Naming an assumption does not delete it.

The claim we are making is narrow: a dependency you can read and check beats one you absorbed by default and will only meet when it changes. That is the whole of it.

Three questions worth asking about anything you hold

  • Can you name the assumptions you are currently holding? Where are they written down, and who is able to change them without asking you?
  • If the chain underneath your position swapped its consensus tomorrow, what in your wallet would change to tell you?
  • When something is described as 1:1, which two things are the sides of that ratio, and what is on neither side?

ZetaChain’s holders did this the right way round, with a real quorum and a staged timetable, and their tokens will come out the other side at the same number they went in. The containers come off one ship and go onto another, and every one of them still weighs exactly what it weighed. Nobody weighs the hull.

This is the seventy-second instalment in our series on the unasked half of fairness.

📷 Photo by Dominik Lückmann on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna