Onpode
Cover art for Blockchain's irreversibility is a feature and a bug — why permanence creates the theft problem

Blockchain's irreversibility is a feature and a bug — why permanence creates the theft problem

October 7, 2026 · 14 min

Juniper Vale & Finn Brooks

Blockchain's irreversibility is not a flaw — it's the architecture. Americans lost over $9 billion to crypto fraud in 2024, and none of it could be recovered because immutability, the feature that prevents double-spending without a bank, also makes every fraudulent transaction permanent. There is no fraud department. The FTC says so plainly.

Blockchain technology records transactions in cryptographically linked sequential blocks, forming a ledger that is designed to be immutable — once a transaction is confirmed, altering it is computationally and economically infeasible under normal network conditions.

0:0013:46
Get the next episode on Crypto →

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Crypto →

About this episode

In 2024, Americans lost more than $9 billion to crypto scammers — the largest documented annual figure in U.S. crypto fraud history. None of it could be reversed. This episode asks why, and the answer turns out to be more philosophically uncomfortable than most coverage lets on. The episode traces blockchain's immutability back to where it actually came from: not an arbitrary design choice, but the only viable solution to the double-spending problem — the fact that digital files copy perfectly, and money shouldn't. To eliminate the middleman, Bitcoin built a chain where every transaction is mathematically locked to every previous one. Permanence is the output of that architecture, not the intention. The trouble is, the system cannot distinguish a valid transfer from a fraudulent one. It sees a matching cryptographic key and moves on. From there, the episode works through the moments when communities actually tried to undo that permanence — the 2016 DAO hack and Ethereum's hard fork, the $5.2 billion Mt. Gox theft and the proposal to rewrite Bitcoin's chain — and why every attempted fix collides with the same wall. Redactable blockchains, custodial layers, protocol forks: each one quietly hands centralized authority back to someone. The trilemma reasserts itself every time. What emerges isn't a verdict on crypto. It's a clearer picture of the trade-off — one the FTC has flagged, researchers have flagged, and that most users don't fully encounter until after they've sent the transaction.

Frequently asked

Why can't cryptocurrency transactions be reversed if you're scammed?

Blockchain transactions cannot be reversed because the ledger's immutability is the core design, not a limitation. Reversibility requires a central authority — exactly what Bitcoin was built to eliminate. The FTC states explicitly that cryptocurrency payments generally cannot be reversed, meaning fraud victims have no recourse once a transaction is confirmed.

How much money did Americans lose to crypto scams in 2024?

Americans lost more than $9 billion to cryptocurrency scammers in 2024, the largest documented annual crypto fraud figure in U.S. history. Because blockchain transactions are irreversible by design, those funds cannot be recovered unless the scammer voluntarily returns them, which does not happen.

What was the DAO hack and did Ethereum reverse it?

In 2016, hackers exploited a bug in an Ethereum smart contract and stole $50 million. The Ethereum community executed a hard fork — a backward-incompatible protocol change — to reverse the theft and recover funds. A portion of the community refused and kept mining the original chain, which survives today as Ethereum Classic.

What is a blockchain hard fork and why is it controversial?

A blockchain hard fork is a backward-incompatible protocol change where the majority of nodes adopt new rules and the old chain is abandoned. It is controversial because executing one to reverse transactions proves that the ledger's finality is social consensus, not a hard guarantee — making every previously confirmed transaction retroactively provisional.

Can redactable blockchains solve the theft and fraud problem?

Redactable blockchains allow authorized parties to modify or delete specific records under governance-controlled conditions, but the word 'authorized' reintroduces a permission structure — centralized trust with extra steps. Researchers have not identified a design that restores reversibility without pulling authority back to a central decision-maker, undermining the trustless model.

Grounded in 10 sources
A Formal Rebuttal of “The Blockchain Trilemma: A Formal Proof of the Inherent Trade-Offs Among Decentralization, Security, and Scalability” ↗ · arxiv.org
Blockchains (Chapter 9) ↗ · cambridge.org
Blockchain Smart Contract Security: Threats and Mitigation Strategies in a Lifecycle Perspective | ACM Computing Surveys ↗ · dl.acm.org
Centralized Trust in Decentralized Systems: Unveiling ... ↗ · dl.acm.org
Towards a Secure Blockchain Ecosystem: Current Vulnerabilities and Future Directions in Smart Contract Security ↗ · doi.org
Beyond immutability: A comprehensive review of redactable blockchain systems ↗ · sciencedirect.com
Blockchain technology through a paradox lens ↗ · sciencedirect.com
Why stablecoin transactions are irreversible ↗ · uk.finance.yahoo.com
Paradise lost? How crypto failed to deliver on its promises and what to do about it ↗ · ecb.europa.eu
Frontiers | The DAO Controversy: The Case for a New Species of Corporate Governance? ↗ · frontiersin.org
Read transcript

Finn Brooks: Okay, weird week — I've been reading FTC consumer warnings for fun, which tells you something about where my head is at.

Juniper Vale: That does tell me something, yeah. What did you find?

Finn Brooks: So the FTC just flatly says: cryptocurrency payments generally cannot be reversed. Not 'it's complicated,' not 'contact your provider.' Cannot. And then you look at the 2024 fraud numbers — Americans lost more than nine billion dollars to crypto scammers in a single year — and those two facts sitting next to each other started bothering me in a way I couldn't shake.

Juniper Vale: Nine billion. One year.

Finn Brooks: One year, largest documented annual figure in U.S. crypto fraud history. And the reason it can't be fixed — the actual structural reason — goes back to this moment in 2016 that I think is kind of the hinge for the whole conversation. Hackers exploited a bug in an Ethereum smart contract and stole fifty million dollars. And then the community had to sit down and answer a question that should have been simple: do we undo it?

Juniper Vale: And the answer wasn't simple.

Finn Brooks: The answer was — no, actually it blew the room apart. Because if you reverse those transactions, you're admitting that the thing blockchain promised — once a transaction is confirmed, it cannot be changed — was never a hard guarantee. It was more like a strong preference. Which is a very different thing.

Juniper Vale: Okay, so the question underneath all of this is — what are people actually signing up for when they use crypto? Because clearly 'your money is safe and permanent' and 'your money is gone forever if something goes wrong' are both true at the same time, and that's — that doesn't quite make sense to me yet.

Finn Brooks: That tension is the whole episode. And I think the answer has to start with why immutability existed in the first place — because it wasn't arbitrary. It solved a real problem. And then we can figure out where the solution became its own problem.

Juniper Vale: I'll be honest with you — I came in assuming this was mostly a consumer-protection story. But you're telling me it goes deeper than that.

Finn Brooks: So much deeper. Like, the same design choice that solved the original problem is the exact reason those nine billion dollars are just — gone. Those are not separate issues. They're the same issue.

Juniper Vale: Then let's figure out what that design choice actually was.

Finn Brooks: Okay, so the design choice — it comes from a really specific problem. Before Bitcoin, digital money had this fatal flaw. Like, imagine you take a photo on your phone and you text it to a friend. You still have the photo. You both have it now. Digital files copy perfectly, right? Money should not work that way.

Juniper Vale: You could email a dollar and keep the dollar.

Finn Brooks: Exactly — that was the double-spending problem. And before blockchain, the only fix was a middleman. A bank sits in the middle and says, no no, I watched you send that dollar, it's gone, your copy is invalid. Which works, but — you've now handed all the power to one institution.

Juniper Vale: And Bitcoin's whole pitch was: get rid of the middleman.

Finn Brooks: Right, but then you need something ELSE to prevent the copying problem. And here's what Bitcoin actually did — it made a ledger that thousands of computers around the world all hold simultaneously, and every entry is mathematically locked to the one before it. Like — okay, think of it like a chain of wax seals. You press a seal, and the next seal has to incorporate the shape of the previous one. Break any seal and the whole chain is visibly wrong.

Juniper Vale: So to fake a transaction, you'd have to redo every seal behind it.

Finn Brooks: While also — and this is the part that gets wild — while also convincing the majority of thousands of computers worldwide that your fake version is the real one. That's distributed consensus. The network agrees on what's valid, and overpowering that agreement is... I mean, it's not impossible in some physics sense, it's just prohibitively expensive. We're talking computational costs that would run into the billions.

Juniper Vale: Wait — so it's not a law of physics. It's a cost calculation.

Finn Brooks: Not a law of physics. An economic and social fact. Which — yeah, that distinction matters more than people realize.

Juniper Vale: Okay, but I want to make sure the logic lands cleanly. The immutability isn't the goal — it's the byproduct. Bitcoin needed to solve double-spending without a bank, so it built this interlocking system where changing history gets more expensive the deeper you go. And permanence just... falls out of that.

Finn Brooks: That is it. That is the whole thing in one sentence, actually. And the reason it matters — no, wait, this is the part that should bother people — that same architecture that makes your legitimate transaction permanent also makes a scammer's transaction permanent. The system cannot tell the difference. It just sees: valid signature, add to chain.

Juniper Vale: So immutability was never designed to protect criminals. It just — doesn't know it isn't.

Finn Brooks: And that's — okay, that's the part that doesn't get said enough. The network isn't indifferent to you. It literally cannot see you. All it sees is a signature that matches a key. That's it. That's the whole identity check.

Juniper Vale: So the key IS you, as far as Bitcoin is concerned.

Finn Brooks: The key is you. Completely. Like — okay, picture this. It's a Sunday afternoon in Tucson. A retired schoolteacher gets an email that looks like it's from her crypto wallet provider. She clicks through, she approves a transaction — and from the network's perspective, that is a perfectly valid signature from the rightful owner. Confirmed. Done. The ledger moves on.

Juniper Vale: And she's calling... who, exactly?

Finn Brooks: That's the thing — there's no one. The FTC is explicit about this: crypto payments generally cannot be reversed. There's no fraud department. No hold you can put on it. Recovery means the scammer has to voluntarily give the money back. Which — I mean, they're not going to do that.

Juniper Vale: But banks reverse fraud all the time. Why can't blockchain just — do the same thing?

Finn Brooks: Because — no, wait, this is exactly backwards from how it sounds. The ability to reverse a transaction IS the thing Bitcoin was built to eliminate. Institutional reversibility, the bank being able to say 'actually, no, we're freezing that' — that's not a safety net, from Bitcoin's design perspective. That's the centralized authority they were replacing. You can't add it back in without unwinding the whole trustless consensus model.

Juniper Vale: So the consumer protection IS the centralization. You don't get one without the other.

Finn Brooks: Exactly. And when you put that next to the $9 billion Americans lost to crypto scammers in 2024 alone — like, that number isn't a bug report. It's the cost of the design.

Juniper Vale: Nine billion in one year. That's not — okay, I knew the number, but sitting with it now it lands differently.

Finn Brooks: And smart contracts make it worse, actually. Because a smart contract is also immutable once it's deployed — it's code locked into the chain. So if there's a bug in the contract? A vulnerability someone can exploit? That flaw is permanent too. The DAO hack was fifty million dollars through exactly that door.

Juniper Vale: The architecture protects the exploit the same way it protects the transaction.

Finn Brooks: Which brings us to the moment the community actually tried to do something about it — Mt. Gox, Mark Karpelès, a proposed hard fork to reverse a $5.2 billion theft — and the reason every fix anyone has ever proposed, including redactable blockchains, keeps running into the same wall. That part gets genuinely strange.

Juniper Vale: Because Mark Karpelès actually tried to open that door. He was the administrator running Mt. Gox when $5.2 billion disappeared, and his answer was: do a hard fork. Rewrite the chain. Give it back.

Finn Brooks: And the Bitcoin community basically said — no. Hard no.

Juniper Vale: Right, but I want to make sure the why lands. Because the counter-argument wasn't 'it's too hard technically.' A hard fork is possible — it's a backward-incompatible protocol change, the majority of nodes adopt new rules, and the old chain gets abandoned. You can rewrite history. The argument was: if you do it once, every transaction that has ever been confirmed is now... provisional. You've told the world that social consensus can override the ledger whenever enough people agree.

Finn Brooks: Which means — wait, the security guarantee isn't gone, it's just... contingent on whether a developer meeting goes badly.

Juniper Vale: That's exactly the argument that won. And that's why Mt. Gox never got its fork. The community decided the $5.2 billion was less dangerous than the precedent.

Finn Brooks: Okay but — Ethereum did it. The DAO hack, fifty million dollars, 2016 — they forked, they recovered the funds, and Ethereum did not collapse. So why is that not the proof of concept? Why isn't Bitcoin looking at that and going, 'see, it works'?

Juniper Vale: This is actually — I mean, this is where the philosophical split lives between those two communities. Bitcoin's identity is built around absolute immutability as the non-negotiable core. Ethereum made the exception, yes, but a chunk of the Ethereum community refused to follow the fork and kept mining the original chain. That's Ethereum Classic now. The split is still there.

Finn Brooks: So the fork didn't resolve the disagreement. It made it permanent in a different way.

Juniper Vale: Two chains, two communities, still arguing about who has the real Ethereum. And that's the cost. Hard forks don't just fix one thing — they require core developers and miners to coordinate, which means you've handed human authority back to a small group of people over something that was supposed to be trustless. The fix reintroduces the exact problem blockchain was built to remove.

Finn Brooks: Okay wait — so researchers have actually tried to solve this differently, right? Redactable blockchains. I keep seeing that term. Is that — does that actually change anything?

Juniper Vale: It's a real design — authorized parties can modify or delete specific records under governance-controlled conditions. But the word 'authorized' is doing a lot of work there. You've just recreated a permission structure. Someone decides who's authorized. That's centralized trust with extra steps.

Finn Brooks: So the blockchain trilemma just — shows up again. Decentralization, security, and now consumer-protection flexibility — you can have two. The moment you add reversibility, you're pulling a thread that unravels one of the other two.

Juniper Vale: And nobody in the research — nobody — is offering a way around that. The proponents of absolute immutability argue that the $9 billion in annual fraud losses is actually the lesser systemic risk compared to what you'd break by allowing reversals. Which is a real position. I'm not sure I'm comfortable with it, but it's internally consistent.

Finn Brooks: That is — I don't know, that is a hard thing to sit with. Someone losing their retirement savings in Tucson on a Sunday afternoon, and the honest answer from the system's architects is: your loss is structurally acceptable. The integrity of the ledger costs exactly that much.

Juniper Vale: You came in this week reading FTC warnings for fun — 'cryptocurrency payments generally cannot be reversed' — and at the start that just sounds like a legal disclaimer. But it's not. It's the whole design, stated plainly.

Finn Brooks: It really is. Like — the FTC isn't warning you about a flaw. They're describing the feature. Bitcoin works exactly as intended. Distributed consensus, cryptographic keys, immutability as the output of all of it — none of that failed. The nine billion dollars gone in 2024, the Mt. Gox billions, the DAO fifty million — those aren't malfunctions. The ledger did its job every single time.

Juniper Vale: Which means — and I don't think there's a cleaner way to say this — when you choose blockchain, you're not choosing better banking. You're choosing a different deal entirely. No central authority, no reversal, no fraud department. The European Central Bank has flagged this, researchers have flagged this, the FTC has flagged this. The structure is the answer.

Finn Brooks: And the uncomfortable part is — I mean, both sides are internally consistent. The Bitcoin position: allow one reversal, even a $5.2 billion theft like Mt. Gox, and every confirmed transaction in history is now provisional. Mark Karpelès asking for that fork wasn't crazy, but the people who said no weren't crazy either. The disagreement is just — what is a financial system actually for?

Juniper Vale: Is it for protecting the integrity of the ledger, or protecting the person who sent the transaction.

Finn Brooks: And there's no version where you get both. Not fully. Every fix — hard forks, redactable blockchains, layer-2 custodial stuff — you pull that thread and centralized trust walks back in the door. The trilemma doesn't care how elegant your solution sounds.

Juniper Vale: The question is just whether enough people understand that before they send the transaction. Not after.

Blockchain's irreversibility is a feature and a bug — why permanence creates the theft problem · Onpode