This paper introduces the concept of protocol geoeconomics â an analytical framework in which the infrastructure of digital governance is treated as an autonomous instrument for the distribution of power amid the systemic crisis of the multilateral order. The central argument holds that as the traditional mechanisms of global governance lose their function as neutral arbiters, control over the rules of verification, enforcement, and sanctioning of international commitments becomes a key resource of geopolitical agency. Distributed Ledger Technology (DLT) in this perspective is not a replacement for diplomatic institutions but the next logical form of infrastructural power â the appropriation of political influence through the ownership of coordination protocols. The paper introduces two operational categories: the sovereign node (a national point of participation in a distributed ledger that cannot be unilaterally disconnected) and protocol Westphalianism (a digital-age analogue of the Westphalian system in which a state's sovereignty is defined by its capacity to maintain a verifying node in critical international coordination systems). A formal model of algorithmic stability is developed through a slashing function and quadratic weighting of influence, providing structural protection against unipolar capture of the system. The dynamic National Influence Index (NI) operationalises representation as a function of verifiable contribution rather than historical privilege. Three contributions emerge. First, infrastructural power is established as a self-standing analytical category describing power exercised through rules of computation rather than through resources or territory. Second, the sovereign node operationalises the concept of digital sovereignty, hitherto largely declarative in the literature. Third, protocol Westphalianism provides a structural exit from the false dichotomy between national sovereignty and global governance. The framework is positioned as the digital extension of Infrastructure Projection of Geopolitics (IPG, WP-IPG-2026-01), with strategic implications for Russia, BRICS+, and the Global South in the construction of Multipolar World Order 2.0.
Compliance verification in regulated markets requires that verifiers obtain confidence in an entity's regulatory status before making downstream decisions. The conventional resolution of this requirement is full disclosure of underlying evidence to each verifier on each verification occasion, with substantial cost to the entity's informational privacy and substantial duplication of sensitive-data storage across verifier organisations. Modern cryptography offers, in principle, the tools to better balance verifier information needs against entity privacy: zero-knowledge proof systems, selective-disclosure credentials, vector commitments, and privacy-preserving aggregation primitives are now mature enough for serious regulatory consideration. Yet the legal and regulatory frameworks under which these tools would be deployed have not caught up with their technical readiness. We develop the legal and policy case for adoption of a cryptographic framework for selective disclosure in regulated markets. We analyse the framework's interaction with data-protection law (UK GDPR, EU GDPR, US state-level privacy regimes), financial-services regulation (FATF Recommendations, FCA rules, BSA/AML obligations), employment law (right-to-work, employment background screening), and identity system regulation (eIDAS 2.0, US REAL ID, digital identity wallets). We identify the principal legal uncertainties that constrain adoption and propose specific reforms to resolve them: data-protection safe harbours for cryptographic verification protocols; reconceiving regulatory data-retention requirements in terms of cryptographic attestations rather than underlying evidence; standardising regulator-grade revocation mechanisms; clarifying the legal status of zero-knowledge proofs as admissible evidence in supervisory and enforcement actions. We make four policy recommendations: (i) data-protection regulators (ICO, EDPB, equivalent) should issue guidance affirming that cryptographic selective-disclosure protocols meeting specified properties are compliant with data-protection law; (ii) financial-services regulators should issue guidance clarifying that cryptographic attestations satisfying specified properties can substitute for evidence retention obligations under AML/KYC rules; (iii) standard-setters should coordinate cross-jurisdictional protocol standards through W3C, IETF, and ISO/TC 307 with regulator participation; (iv) legislators in jurisdictions with active digital-identity programmes (UK, EU, US, Singapore) should ensure that statutory frameworks accommodate selective-disclosure verification. The paper contributes to the law-and-economics literature on data sharing under privacy constraints, to the policy economics of RegTech, and to the legal-academic literature on emerging-technology regulation. It complements the technical and economic threads of work developed in companion papers in this series.
Quantum computing is forcing law, technology, and public policy to confront a new category of dual-use knowledge: cryptanalytic research that may advance science while accelerating the capacity to compromise public cryptographic infrastructure. For decades, the risk that a sufficiently powerful quantum computer could break RSA and elliptic curve cryptography (ECC) remained a largely theoretical concern. That era of theoretical comfort is ending; quantum computing is moving from theoretical risk toward practical consequence. Specifically, recent work in quantum algorithms, resource estimation, quantum error correction (QEC), and architecture-specific implementation suggests that cryptographically relevant quantum computers may be closer, and may require fewer resources, than earlier assumptions suggested. In April 2026, Google Quantum AI and collaborators released a white paper estimating resources for quantum attacks on elliptic curve cryptography used, for example, in cryptocurrencies, including Bitcoin, while using a zero-knowledge-proof mechanism to support verification of the reported computation without disclosing attack-enabling implementation details. The Article proposes a hybrid governance model: preserve a strong presumption of publication; adopt voluntary quantum cryptanalysis disclosure norms; recognize zero-knowledge-proof-backed verifiable nondisclosure as a legitimate scholarly publication mechanism; establish an advisory Quantum Cryptanalysis Review Board (QCRB); clarify export-control treatment of quantum cryptanalysis; require quantum-risk impact statements for federally funded research; and tie disclosure norms to post-quantum cryptography (PQC) migration readiness. These proposals should not be understood as advocating broad, restrictive regulation of quantum-computing technologies, which would be premature and could harm innovation. The objective should not be secrecy for its own sake, nor government control of quantum research. Rather, law and policy should encourage voluntary action, scientific self-governance, and cooperation across the quantum-computing ecosystem while reducing unnecessary public alarm, avoiding premature weaponization, and accelerating migration to quantum-resistant solutions and systems.
This research paper reconstructs the historical, technical, and sociopolitical foundations of Bitcoin by examining the contributions of Adam Back, Hal Finney, Satoshi Nakamoto, and the cypherpunk movement that shaped early digital cash concepts. Drawing on primary sources, cryptographic literature, archived mailing-list communications, and interdisciplinary historical analogies, the study situates the development of Hashcash (1997) and Finneyâs reusable proof-of-work (2004) within the broader evolution of cryptographic trust mechanisms, tracing their lineage back to ancient systems of authentication, secrecy, and economic signaling. By analyzing Adam Backâs academic formationâincluding A-levels in mathematics, physics, economics, and his 1995 PhD in distributed systems at the University of Exeterâalongside his work on applied cryptography, credlib e-cash libraries, and non-interactive forward secrecy, the paper demonstrates how these innovations directly influenced Bitcoinâs proof-of-work architecture. The study incorporates Hal Finneyâs role as the first recipient of a Bitcoin transaction, his involvement in early cryptographic networks, and forensic insights such as the Patoshi Pattern , while contextualizing Satoshi Nakamotoâs 2011 disappearance and the subsequent transition of leadership to Gavin Andresen. Drawing historical parallelsâfrom Mesopotamian accounting tokens to Roman ciphers and Renaissance secrecy practicesâthe research highlights recurring civilizational patterns in which cryptographic systems emerge during periods of institutional fragility and technological transformation. It concludes that Bitcoin represents the culmination of decades of scientific innovation and centuries of human experimentation with trust, illustrating how principles of costly signaling, privacy, and decentralized authority persist in modern digital monetary systems.
In 2022, an image of a âbored apeâ accessible through a non-fungible token (NFT) was stolen from actor Seth Green. The thief then sold the bored ape to a good faith purchaser. Had this been a physical painting, the outcome would have been clear: a thief cannot convey title they do not have, and the purchaser would acquire nothing. Yet the ensuing debate proceeded as though the NFT's technical features had altered this settled principle, as though blockchain records could bestow property rights on the new purchaser. They cannot. Ownership rights in digital assets stem from law, not from the software systems that create and maintain them. When Lawrence Lessig famously proclaimed âcode is law,â he meant that code functions as behavioral regulation by imposing technical limitations on users, not that it generates enforceable rights. His insight was descriptive: code shapes what people can do within digital environments, just as physical architecture channels movement through physical space. Yet the advent of blockchain networks, cryptocurrencies, and smart contracts has morphed this observation into the flawed conviction that what code makes possible, the law must recognize as legally enforceable. While legal scholarship has noted this misconception, it has yet to offer a rigorous framework to resolve it. This Article fills this gap by applying H.L.A. Hartâs legal theory to demonstrate that code acquires legal force only to the extent that positive law grants such power. This investiture occurs through two pathways: public empowerment through legislation, and private empowerment through contracts, trusts, and other ordering instruments. Absent such formal investiture, code remains "soft law," a structural constraint lacking normative force. The relevance of our analysis extends beyond the conceptual malaise affecting the blockchain ecosystem, addressing a foundational conflict poised to reappear with every wave of new technology, from large language models to autonomous robots.
The Court of Justice of the European Union's landmark ruling in Skatteverket v. David Hedqvist (Case C-264/14) established that Bitcoin-to-fiat exchanges constitute VAT-exempt services under Article 135(1)(e) of the VAT Directive, on the basis that Bitcoin serves as a contractual means of payment analogous to legal tender. However, the rapid proliferation of Non-Fungible Tokens (NFTs)-which are increasingly characterized as electronically supplied services (ESS) rather than currency-has fragmented the uniform fiscal landscape envisioned by the ruling. This paper examines a critical, underexplored nexus: whether divergent VAT/GST treatments of NFTs across EU Member States create incentives for regulatory arbitrage that systematically increases the cyber-risk profile of decentralized exchanges (DEXs). As recent incidents involving Aerodrome Finance, CoW Swap, and dYdX demonstrate, the decentralized finance (DeFi) sector remains acutely vulnerable to Domain Name System (DNS) hijacking attacks that exploit the Web2 front-end infrastructure upon which DEXs rely. The paper argues that when tax uncertainty drives platforms toward jurisdictional optimization-often involving complex routing, cross-border operations, and reliance on lessregulated infrastructure-they inadvertently expand their attack surface for adversarial DNS tunneling. Employing a socio-technical analysis that bridges fiscal harmonization and network security, this study proposes a harmonized VAT framework for NFTs to reduce the compliance-security paradox that currently incentivizes risk-increasing operational behaviors. It further recommends the integration of decentralized naming systems, such as the Ethereum Name Service (ENS), as a countermeasure to DNS-based exploitation. The findings contribute to both tax policy discourse and cybersecurity scholarship by demonstrating that fiscal harmonization is not merely an economic concern but a foundational component of DeFi infrastructure resilience.
This Volume completes the constitutional theory of cryptographic protocols developed in the pre- ceding two Volumes by turning, after architecture (Volume I) and epistemology (Volume II), to historiography and prospect. It identifies three eras of network cooperation, each governed by a distinct value-scaling law and supporting a distinct constitutional form. The Sarnoff era ( đ â đ ) was the era of broadcast cooperation, in which a sovereign center distributed information and au- thority to a passive periphery; its constitutional achievement was the territorial nation-state and its administrative apparatus. The Metcalfe era ( đ â đ 2 ) was the era of bilateral cooperation, in which peer-to-peer connection generated value at quadratic scale; its institutional realization was platform capitalism, in which intermediaries captured the surplus that user-to-user connection produced. The Reed era ( đ â 2 đ ), now beginning, is the era of group-forming cooperation: com- binatorial subgroup formation generates value at exponential scale and, for the first time in the history of communications networks, is not structurally captured by any intermediary. The cryp- tographic substrate is the first medium that supports Reed-scale value formation without platform extraction. The Volume develops three substantive theses. First, the three eras are a historical sequence in which each succeeding form does not annihilate the prior form but reorganizes the space of possi- bilities around itself; the Reed era does not abolish Sarnoff and Metcalfe institutions but subsumes them as particular cases of a richer combinatorial topology. Second, the constitutional architecture of the Reed era is three-tiered: a substrate-agnostic cryptographic foundation; tenant-entities (com- panies, decentralized autonomous organizations, voluntary associations) operating on the substrate without owning it; and individuals as final nodes ( elos finais ) participating in many subgroups si- multaneously across many substrates. Third, the local description of the individual and the global description of the civitas stand in the Bohrian conjugate relation identified in Volume II, but at Reed scale the conjugacy becomes constitutionally structural rather than merely epistemic: the individual cannot be specified independently of the civitas in which his subgroup memberships are constituted, and the civitas cannot be specified independently of the individuals whose memberships constitute it. The reconstruction of civil society on the cryptographic substrate is unfolding now and will continue through the present century. We are at the beginning of an era whose institutional forms cannot be enumerated in advance. The proper response, reaïŹirmed from Volume II, is Knightian humility paired with the architectural strategy of robust commitment. This Volume specifies the historical and structural conditions under which that humility and that strategy operate.
Decentralized and autonomous systems associated with Web 3.0 challenge long-standing assumptions about security governance, responsibility, and control. Although advances in cryptography, consensus mechanisms, and automation have strengthened technical protections, they have also fragmented accountability across software agents, organizations, and ecosystems, producing security failures in environments where responsibility for prevention, response, and remediation is unclear or contested. This paper demonstrates that many such failures stem not from inadequate technical safeguards but from governance gaps created by sociotechnical complexity. Drawing on sociotechnical systems theory, it introduces the LAG (Layers-Accountability-Governance) framework, which distinguishes among information technology security, information security, and enterprise-level governance, and clarifies the misalignment between ex ante preventive mechanisms and ex post response and recovery processes. Through analysis of decentralized architectures, autonomous agents, and machine identities, and case studies of the DAO, Poly Network, and oracle-related failures, the paper shows how technically correct system behavior can nonetheless produce governance failure and discusses implications for the design and governance of secure systems in complex digital ecosystems where traditional organizational boundaries no longer apply.
Abstract This chapter reviews and contributes to the debate concerning the fiduciary duties of network participants of blockchain systems, with a focus on software developers and decentralized autonomous organization (DAO) members. After briefly introducing the concept of fiduciary duties in the UK and the US, the chapter surveys the early academic debates on the fiduciary status of core developers. It then turns to an analysis of the main case law in England and California relating to fiduciary duties in this space, before arguing that the imposition of implicit fiduciary duties could lead to unjust outcomes, deter participation in blockchain systems, and stifle innovation. Instead, the remainder of the chapter contends that pursuing co-regulatory efforts which are grounded in the principle of regulatory equivalence, such as the adoption of the COALA DAO Model Law, will secure the public policy objectives of imposing fiduciary duties, without sacrificing the distinctive features of blockchain networks.
Early cryptocurrency discourse centered on digital scarcity as the primary source of value in non-sovereign monetary systems. While scarcity was foundational to the emergence of cryptoassets, the rapid diversification of distributed ledger architectures has increasingly decoupled scarcity from long-term value attribution. This paper argues that cryptoassets may be entering a post-scarcity phase in which value formation is driven less by fixed supply and more by settlement capacity, infrastructural interoperability, and the efficient clearing of obligations. Drawing on historical financial practices, internet protocol development, and contemporary ledger architectures, the paper proposes a structural distinction between asset-centric and protocol-centric systems. It suggests that mature crypto valuation may increasingly reflect the role of ledgers as settlement infrastructure rather than as bearer assets. The analysis is descriptive rather than prescriptive and does not privilege any specific network or token.
This chapter covers Proof of Stake in fullâhow locked capital replaces burned electricity as the security mechanism, the nothing-at-stake problem and the fixes that make PoS shippable, Ethereumâs Gasper consensus (LMD-GHOST fork choice and Casper FFG finality), slashing mechanics, long-range attacks and weak subjectivity, validator economics and MEV, and how PoS security compares to PoW. Roughly what youâll be able to defend in conversation:
The Internet has evolved from its early promise of global connection and freedom into a centralized system dominated by Big Tech and governments, resulting in widespread data exploitation, surveillance, censorship, and erosion of user privacy and ownership. This paper traces the historical development of Web2 infrastructure, its foundational flawsâparticularly the linkage of digital identities to real-world persons and the unchecked power of intermediariesâand the societal pressures that have exposed these vulnerabilities through events such as the Great Firewall of China, the Snowden revelations, the Cambridge Analytica scandal, and large-scale hacks. In response, the paper positions Web3 , underpinned by blockchain technology, as a necessary paradigm shift toward a decentralized, user-centric Internet. Web3 severs the tie between digital and physical identities, enables true data ownership, peer-to-peer encryption, global accessibility without geo-restrictions, and algorithmic governance that reduces reliance on potentially abusive middlemen. It argues that Web3 can encode core democratic values, including freedom of expression as articulated in Article 19 of the Universal Declaration of Human Rights, while addressing resistance from governments (concerned with control and taxation), Big Tech (threatened by loss of data monopolies), and everyday users (wary of complexity and perceived risks). The paper examines ethical considerations, potential misuse by bad actors, and the dual nature of technological innovation. It proposes four critical criteria for evaluating successful Web3 implementations: 1) affordability and equitable access with long-term cost reduction; 2) robust protection of individuals through privacy and bias mitigation, coupled with "freedom of speech, not reach"; 3) absence of any central governing body with control over development; and 4) a community-representative judicial system for handling violations of shared terms of service. Ultimately, this work contends that Web3 represents an inevitable evolution capable of empowering billions of usersâparticularly those in repressive regimesâby fostering transparency, equity, and self-governance, provided implementations adhere to these ethical and practical standards. It calls for cautious optimism, due diligence, and open-source verification in the transition to a more liberated and democratic digital era.
Abstract This article critically examines how Web3 decentralization policy trends impact global digital governance, questioning whether they genuinely distribute power or merely shift influence to a new, tech-savvy elite. Based on fieldwork in Silicon Valley since August 2022 and engagement with scholars and practitioners up to December 2025, the article provides a conceptual analysis with emerging empirical insights around the nascent global Web3 movement. While Web3 advocates challenge centralized data monopolies and traditional state structures, this analysis critiques the assumption that Web3 democratizes power, highlighting both its potential for inclusion and risks of exclusion, insofar as it may reinforce hierarchies rooted in technical expertise and digital access. While acknowledging the broader landscape of Web3 governance (including hybrid and federated models) and scoping the Global North and Global South contexts considering global adoption cases, the article particularly focuses on three post-Westphalian paradigms: (i) Network States, (ii) Network Sovereignties, and (iii) Algorithmic Nations. While Network States advocate for crypto-libertarian governance, Network Sovereignties and Algorithmic Nations emphasize cooperative governance aimed at empowering minority communities, such as indigenous groups, stateless nations, and e-diasporas, through decentralized, data-driven systems. By engaging with both the limitations and some promises, prospects, and pitfalls of Web3, this article questions whether Web3 can create a more inclusive global order or if influence is increasingly concentrated among a new elite. This article contributes to debates on sovereignty, governance, and citizenship by advocating hybrid policy frameworks that balance global and local dynamics, emphasizing solidarity, digital justice, and international cooperation for equitable Web3 governance.
Purpose The purpose of this study is to identify how Ethereum transforms the concepts of power, resilience and ethics in decentralized digital systems using the theories of Michel Foucault and Nassim Taleb. Design/methodology/approach The research relies on a conceptual approach that includes a literature review and qualitative analysis of key cases, such as the decentralized autonomous organizations (DAO) hack and Ethereumâs transition to the Proof of Stake mechanism. Data synthesis is carried out through the theoretical frameworks proposed by Foucault and Taleb. Findings Ethereum alters the dynamics of power through the use of smart contracts and DAO. The platform demonstrates antifragility by successfully adapting to crises and embodies the âSkin in the Gameâ principle through the staking mechanism. However, ethical challenges related to privacy arise, highlighting the importance of finding a balance between transparency and privacy. Research limitations/implications The research focuses exclusively on Ethereum, which limits the generalizability of the findings. Future research should consider other blockchain platforms. Social implications The work emphasizes the need to resolve the conflict between blockchain transparency and the right to privacy in the digital environment. Originality/value This work offers a new conceptual framework for studying decentralized systems by combining Foucaultâs ideas on power with Talebâs theories on antifragility and ethical participation. Special attention is given to the ethical aspects of digital governance.
Digital systems face not a security failure but an ontological one. Authority on the internet is implemented as code, and code is inherently simulable, reproducible, and scalable. As artificial intelligence exposes this flaw at scale, efforts to secure digital authority through identity, credentials, and probabilistic verification prove structurally insufficient. This paper argues that authority cannot ontologically originate from code, and that all code-based authority systems are therefore structurally vulnerable, regardless of implementation quality. We outline the historical origins of the error, explain why vulnerability is unavoidable in code-based authority systems, and propose a return to presence as the only non-simulable foundation for digital authorityâimplemented through local cryptographic proof generation that preserves privacy by architectural design. The core claim is simple: code cannot be authority. Authority must arise from being. This is not a technological decision, but an ontological oneâand ontological mistakes cannot be patched. Keywords: ontological cryptography, HISPU, digital trust, code-based authority, human presence verification, cryptographic attestation, privacy-preserving architecture, cybersecurity, authentication, biometric entropy, local processing, zero-knowledge presence, environmental embedding, physical unclonability, quantum-resistant, AI safety, digital sovereignty, proof of being, presence-based authority
Abstract This essay argues that social media document (rather than fuel) the decline of political democracy while helping revive organizational democracy, including through âdecentralized autonomous organizationsâ (DAOs). Yet, despite giving everyone a voice and the ability to organize across borders, social media could overâconcentrate power if, in the future, a few large but siloed platforms ended up shrinking viewpoint diversity â the oxygen of democracy. How can we curb corporate platform concentration without dulling democracy? Due to tradeâoffs in platform design, no single service can deliver free speech, free usage, and safe usage simultaneously. Fortunately, this âtrilemmaâ can be transcended at the industry level with an interoperability mandate that fosters user multihoming and lets various platforms provide different bundles of democratic benefits. Email works across service providers, and so can social media. Interoperability thus represents a viable answer based on six advantages: practical feasibility; competition on merit; faster complementor innovation; jurisdictional flexibility; unlocking network effects between, rather than just within platforms; and alignment with democratic values. Platform interoperability can make social media social again and futureâproof democracy. This proposal is a clarion call for blaming the Internet a little less for democracyâs problems and instead leveraging its infrastructure strategically to address them.
During the first decade of cryptocurrencies (2008â2017) there were few connections established between crypto and the conventional finance sector, but in the US in 2025 the integration of these two sectors is proceeding at speed. This paper examines one part of this integration â the centralisation of cryptocurrency trading inside of large, digital platformed exchanges, which is theorised as a shift from cryptocurrency to cryptofinance. Furthermore, the paper shows how this shift to cryptofinance has been aided by an emergent crypto-state nexus. The novel contribution of the paper is explaining how the US crypto markets have progressed from niche, relatively decentralised and blockchain-based, with little association with or regulation by nation-states, into what is now competition between FinTech-fuelled, digital platform firms that provide suites of financial services and instruments and collect fees for mediating access to the underlying blockchain markets. Empirically, the paper traces the rise of Sam Bankman-Friedâs firm, FTX, as it evolved from a small, California-based start-up running arbitrage trades in 2017 into one of the worldâs largest crypto exchanges servicing over a million customers in 2022. In light of the FTX story, the paper analyses the geographical political economy of platformed cryptofinance as it struggles with both the incumbent financial sector and the US state.
This research examines how emerging forms of digital sovereignty, decentralized infrastructures, and anticipatory AI governance are reshaping nationhood in the algorithmic age. Drawing on the conceptual framework of Algorithmic Nations (Calzada 2018) and incorporating new empirical insights from embedded action research (2022â2025), the study analyses the Basque Country as a paradigmatic case of a âsmall stateless nationâ navigating the global reconfiguration of power between states, corporations, and communities. The presentation synthesizes three competing post-Westphalian paradigmsâNetwork States (Srinivasan 2022), Network Sovereignties (De Filippi 2024), and Algorithmic Nations (Calzada 2018)âas shown in the comparative table on page 19, highlighting their differing assumptions regarding governance, identity, participation, and technological control. Building on the diagnostic indicators of Europeâs digital dependence (page 10) and the transition from Gaia-X to EuroStack (page 11), the study evaluates the strategic implications of digital public infrastructures, data cooperatives, federated architectures, and Web3 ecosystems for stateless nations. Through comparative analysis of the Global North (e.g., Scotland, Quebec, Flanders), the Global South (e.g., Kurdistan, SĂĄmi, Tamil, Amazigh), and the Basque Country (pages 16â17), the work demonstrates how communities with diverse geopolitical constraints can articulate forms of AI sovereignty grounded in rights-based, culturally rooted, and community-driven governance. The Basque case illustrates how fragmented digital systems (.eus, EJIE/Izenpe, Osakidetza, MUBIL, etc.) can evolve toward an interoperable, multi-scalar technopolitical architecture, aligning linguistic, territorial, and infrastructural dimensions. The analysis argues that AI-driven infrastructures, data governance, and decentralized architectures are not merely technical layers but emerging geopolitical terrains where stateless, indigenous, diasporic, and minority nations can renegotiate autonomy. The concept of Algorithmic Nations provides a framework for understanding how community sovereignty can be built through data commons, federated systems, and anticipatory governance, particularly in multilingual and culturally distinct territories such as the Basque Country. Overall, the study contributes to debates on global digital governance, digital sovereignty, and the future of nationhood by proposing that algorithmic infrastructures are becoming central to political organization. It calls for democratic, inclusive, and community-oriented models of AI governance capable of avoiding techno-authoritarianism, Big Tech dependency, and âsovereignty washing,â while enabling emancipatory, culturally anchored, and future-oriented forms of collective self-determination.
Cryptocurrency exchanges are integral to the digital asset economy; however, their rapid growth has been accompanied by recurrent high-impact cyberattacks that erode trust and inflict substantial losses. Guided by the PRISMA-ScR framework, this review systematically screened peer-reviewed and industry sources to construct a validated dataset of 220 major incidents (2009â2024) across centralized (CEX) and decentralized (DEX) exchanges. We classify attack vectors, analyze repeated high-impact patterns, and identify systemic vulnerabilities spanning cryptographic mechanisms and exchange infrastructure. Across CEX platforms, four of ten identified attack types accounted for 62 of the 80 incidents and approximately $1.764 billion in losses (42.1% of the $4.191 billion CEX total). Across DEX platforms, five of eighteen attack types were responsible for 120 of 140 incidents, totaling $3.755 billion (87.3% of the $4.303 billion DEX total). The overall losses sum to $8.494 billion across 220 incidents (80 CEX; 140 DEX). Repeated vectors comprised 182/220 incidents and $5.519 billion (65.0%) of losses, dominated by wallet/key compromise (78 incidents; $2.394 billion) and DEX system/server/protocol exploits (56 incidents; $1.939 billion); these two classes account for 134/182 repeated incidents (79.1%) and $4.333 billion (78.5%) of repeated losses. We examine the susceptibility of cryptographic defenses to emerging quantum adversaries and assess the exchange readiness for post-quantum threats. This study is the first to systematically compile and quantitatively analyze cybercrime incidents affecting both centralized and decentralized cryptocurrency exchanges in a unified dataset, enabling unprecedented comparability of systemic risks with actionable insights for cybersecurity researchers, regulators, and exchange operators seeking quantum-safe infrastructure evolution.