Onpode
Cover art for Why blockchain's permanence enables security but prevents undoing theft

Why blockchain's permanence enables security but prevents undoing theft

September 30, 2026 · 14 min

Iris Holm & Lila Soto

Blockchain's immutability — the same feature that prevents governments from seizing funds — also makes stolen crypto essentially unrecoverable. A 51% attack is the only protocol-level reversal mechanism, and its cost is prohibitively high by design. Fraud victims and dissidents are protected and exposed by the exact same architectural fact.

Blockchain technology, introduced by the pseudonymous Satoshi Nakamoto with Bitcoin in 2008, achieves decentralized settlement through two interlocking architectural mechanisms: cryptographic hashing and distributed consensus.

0:0013:45
Get the next episode on Crypto →

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Crypto →

About this episode

When someone drains your bank account, there's a mechanism: fraud claims, deposit insurance, a human somewhere with authority to say 'undo this.' Blockchain was built so that person couldn't exist. This episode works through why that's not an oversight — it's the entire point. Starting from Bitcoin's 2008 design, the episode unpacks the two layers that make immutability real: cryptographic hashing, where changing a single character in any old transaction breaks every record that follows it, and distributed consensus, where thousands of independent nodes make a fraudulent revision prohibitively expensive to execute. The security isn't a mathematical absolute — it's a price tag set so high it functions like a lock. But the same logic that makes funds uncensorable makes them unrecoverable. The ledger cannot distinguish consent from coercion. A valid cryptographic signature looks identical whether you sent it willingly or were tricked into it by a Medicare scam. The 2016 Ethereum DAO hack showed what reversing a transaction actually costs: you split the network and debate the legitimacy of the fork for years afterward. The episode then turns to what regulation can actually reach — centralized exchanges, stablecoin issuers, the GENIUS Act's framework — and why those only govern the edges. The protocol is unchanged. The EU's right to erasure collides directly with a system architecturally incapable of forgetting. Consumer protection didn't disappear; it migrated to intermediaries with fewer obligations than the banks crypto was built to replace.

Frequently asked

Why can't stolen cryptocurrency be reversed or recovered?

Stolen cryptocurrency is essentially unrecoverable because blockchain immutability is an intentional design feature, not a bug. Each block cryptographically chains to the previous one via hashing; altering any transaction breaks every subsequent block. The FBI describes recovery as 'essentially impossible' — the protocol itself closes the door, not investigative limitations.

What is a 51% attack and can it reverse a crypto transaction?

A 51% attack is the only protocol-level mechanism that can reverse blockchain transactions. It requires controlling a majority of a network's computing power to rewrite recent transaction history. On Bitcoin, the energy and hardware cost of out-computing the entire global network makes this economically prohibitive — security is a price floor, not a mathematical absolute.

What happened when Ethereum reversed the DAO hack in 2016?

When Ethereum reversed roughly $60 million drained in the 2016 DAO hack, it split the entire blockchain. The chain that accepted the reversal became Ethereum; the chain that refused became Ethereum Classic. Both networks still run today. That split demonstrated that blockchain transaction reversal is technically possible but costs network unity and legitimacy.

Does blockchain comply with GDPR's right to erasure?

Public blockchains are architecturally incompatible with GDPR's right to erasure. Deleting or anonymizing a stored transaction would alter that block's cryptographic hash, breaking every subsequent block in the chain. There is no controller to send an erasure request to on a decentralized public chain, making GDPR compliance structurally impossible at the protocol level.

Does crypto regulation like the GENIUS Act change blockchain's immutability?

The GENIUS Act (2025), the first major U.S. federal crypto legislation, does not change blockchain's underlying protocol. It builds governance around centralized intermediaries — exchanges and stablecoin issuers like Circle — not the ledger itself. Satoshi Nakamoto's 2008 architecture remains unchanged; consumer protection shifts entirely to off-chain, edge-layer regulation.

Grounded in 12 sources
Autonomous Agents on Blockchains: Standards, Execution Models, and Trust Boundaries ↗ · arxiv.org
A Detailed Comparative Analysis of Blockchain Consensus Mechanisms ↗ · arxiv.org
Securing User Authentication and Data with Advanced Cryptographic Techniques and Blockchain Mechanisms in a Fintech Application ↗ · doi.org
Performance enhancement in blockchain based IoT data sharing using lightweight consensus algorithm ↗ · doi.org
BLOCKCHAIN-ENABLED VOTE VALIDATION THROUGH A CRYPTOGRAPHIC AND SYSTEM-LEVEL APPROACH TO SECURE ELECTIONS ↗ · doi.org
A Comprehensive Review of Cryptographic Solutions in Blockchain Consensus ↗ · doi.org
Digital assets: risks, regulations, mitigation - PMC - NIH ↗ · pmc.ncbi.nlm.nih.gov
A comprehensive review of blockchain technology ↗ · sciencedirect.com
Why stablecoin transactions are irreversible ↗ · uk.finance.yahoo.com
Smart Contract Immutability: A Legal Liability in 2024 ↗ · chainscorelabs.com
Stolen Crypto Recovery Guide | Collisionless ↗ · collisionless.com
Special Digital Currencies Issue: 
Bitcoin and CBDCs What Is Bitcoin? The Answer to Government Surveillance 
and Control Through Money An Essential Introduction, Glossary of Multidisciplinary 
Termino ↗ · criminallegalnews.org
Read transcript

Lila Soto: Iris, tell me something — if someone stole forty-seven thousand dollars from your checking account, what happens?

Iris Holm: Bank eats it. Deposit insurance. Maybe a fraud claim.

Lila Soto: Right, there's a mechanism. Now — same forty-seven thousand dollars, same phishing scam, someone tricks you into entering your seed phrase and by morning it's in a wallet you don't control. What happens?

Iris Holm: The FBI says essentially impossible to recover. That's their word — essentially.

Lila Soto: And that word is doing a lot of work. Because they're not saying we lack the budget or the investigators. They're saying the protocol itself closes the door. The blockchain shows you the transaction — permanent, timestamped, visible to everyone — and that visibility is all you get. Which is such a weird kind of cruelty, mm, total transparency and total helplessness at once.

Iris Holm: So — how did we get here? Structurally.

Lila Soto: That goes back to Bitcoin. Satoshi Nakamoto, 2008 going into 2009 — the first working system that combined cryptographic hashing with distributed consensus. And what that combination produced, deliberately, was immutability. The irreversibility isn't a glitch they didn't patch. It's the same feature that blocks a government from seizing your funds. You cannot have one without the other. That tradeoff was built in from the first block.

Iris Holm: So the fraud victim and the dissident are protected by the exact same mechanism.

Lila Soto: Protected and exposed by it, yeah. And to understand why that can't just be patched — we need to get into what immutable actually means, mechanically.

Iris Holm: Okay, mechanically — picture every transaction as a wax seal on an envelope. And the seal is made by folding the wax from every previous envelope into it. Tamper with any old envelope, and every single seal after it crumbles. And everyone in the room sees it instantly. That's the whole thing.

Lila Soto: Yeah, and the room is the key part — because it's not one room with one person watching.

Iris Holm: Right. Two layers. First layer: cryptographic hashing. You take transaction data — any data — run it through a mathematical function, out comes a fixed-length fingerprint. Change one character in the input. One character. The fingerprint is completely different. Tamper is instantly visible.

Lila Soto: And each block in Bitcoin stores that fingerprint — the hash — of the block that came before it. That's the Merkle chaining structure. So if you go back and alter a transaction from, say, three years ago, that block's hash changes, which breaks the next block's hash, which breaks every block after it.

Iris Holm: The older the transaction, the more chain you'd have to recompute.

Lila Soto: Exactly — the cost of rewriting history scales with how old the history is. That's not an accident. That's the design.

Iris Holm: Second layer: distributed consensus. Thousands of independent nodes worldwide each hold a full copy of the ledger. A fraudulent revision has to beat all of them simultaneously.

Lila Soto: Mm, but — wait, here's what I'd push on. If it's just nodes agreeing, why can't a majority vote to reverse a fraud? I mean, it's humans deciding, right?

Iris Holm: Technically — yeah, that exists. It's called a 51% attack. Control a majority of the network's hash rate, and you can rewrite recent transaction history. That is the only protocol-level reversal mechanism.

Lila Soto: Oh. So there is a door.

Iris Holm: There's a door with a price tag so high it functions like a lock. On Bitcoin — out-computing the rest of the entire network. The energy and hardware cost is economically prohibitive. Which is — look, that's the point. The security isn't a mathematical absolute. It's a price floor set so high that attacking it isn't worth it.

Lila Soto: So the security is a price tag so high it functions like a lock. And that means immutability isn't baked into nature — it's baked into incentives.

Iris Holm: Which is what makes the fraud victim's situation so structurally strange. The same economic logic that makes your funds uncensorable makes them unrecoverable. Remove either the hashing or the distributed consensus — either layer — and the whole thing unravels. You can't selectively undo the irreversibility for sympathetic cases.

Lila Soto: And the FBI's 'essentially impossible' quote lands differently now — they're not describing a gap in their capability. They're describing the architecture working exactly as Satoshi designed it.

Iris Holm: But here's the layer under that — the architecture working as designed is weirder than it sounds. Because the protocol doesn't know if you wanted to send those funds.

Lila Soto: Yeah — and that's the part that actually unsettles me. Private key authorization. The network sees a valid cryptographic signature and calls it legitimate. Full stop. It has no mechanism — none — to ask whether you signed under duress, or while asleep, or because someone phished your seed phrase.

Iris Holm: Consent and coercion look identical to the ledger.

Lila Soto: Identical. And — okay, picture this specifically. Someone's grandmother in Tucson. She gets a call, caller says they're from Medicare, there's a clawback on her account, she needs to move her savings into crypto to protect it. She buys Bitcoin through an exchange, sends it to a wallet they control. From the blockchain's perspective? She just authorized a transaction. Voluntary. Legitimate. Done.

Iris Holm: The signature is real. The consent wasn't.

Lila Soto: And the ledger — the ledger doesn't care. Which brings up the DAO. Because in 2016, on Ethereum, the community actually tried to care.

Iris Holm: The hack.

Lila Soto: Someone exploited a bug in a smart contract — drained what was then roughly sixty million dollars in Ether. And the Ethereum community said, actually, no, we're going to reverse this. But to do that — I mean, this is the part — they had to split the entire blockchain. The chain that reversed the transactions became Ethereum. The chain that refused became Ethereum Classic. Two competing networks, still running today, because of one reversal decision.

Iris Holm: Reversal is possible. It just costs you the network's unity.

Lila Soto: The legitimacy cost of that split is still debated. And it's not just transactions — on Ethereum, smart contracts inherit the same immutability. Once code is deployed, whatever bugs are in it are locked in too. The exploit that drained the DAO existed in deployed, immutable code. So the system that was supposed to be trustless... required us to trust that no one wrote a bug.

Iris Holm: That's — wait, that actually reframes the whole thing. It's not trustless. It just moved where the trust lives. From institutions to code. And code makes mistakes.

Lila Soto: And can't apologize for them afterward. Which is why — and this is the part that gets uncomfortable — weakening irreversibility to protect that grandmother in Tucson would require either a central authority that can override signatures or fracturing consensus every time there's a dispute. Neither of those is a patch. That's dismantling the architecture.

Iris Holm: The tradeoff is structural. Not incidental.

Lila Soto: Which is what makes the next part so interesting — there are centralized intermediaries that can actually freeze assets, and there's now legislation like the GENIUS Act trying to build on top of all this. That's where the founding promise of crypto starts to get very awkward very fast.

Iris Holm: And that's where the escape hatch gets uncomfortable — because the hatch exists. Circle can freeze USDC. Custodians can lock accounts. A centralized exchange catches a suspicious withdrawal and puts a hold on it. Recovery happens. Just not at the protocol. At the edge.

Lila Soto: Which is — I mean, think about what that actually is. That's a bank. With extra steps. And no deposit insurance.

Iris Holm: Right. And no FDIC backstop. So if most users are already routing through centralized exchanges — which most are — the practical result looks like traditional banking, but worse. You've paid the immutability tax at the protocol level and then handed your keys to an intermediary anyway.

Lila Soto: The institution blockchain was built to make unnecessary — you just went back to it. And the irony is that Circle freezing USDC works precisely because Circle controls those assets. Not because of anything Satoshi designed. In fact — kind of in spite of it.

Iris Holm: So what does 'crypto regulation' actually regulate?

Lila Soto: That's — yeah, that's exactly the right question. The GENIUS Act, 2025, first major federal legislation for crypto — and what it's actually doing is building governance around the edges. The centralized exchanges, the stablecoin issuers. Not the protocol. The protocol doesn't change because Congress passed something.

Iris Holm: The architecture is unchanged.

Lila Soto: Completely unchanged. A law that assumes there's a correction mechanism — it's legislating around a structural constraint, not through it. The ledger still doesn't forget. The ledger will never forget. So consumer protection shifts entirely to off-chain governance. Exchange compliance. Legal frameworks. Regulatory oversight. Because the protocol cannot self-correct.

Iris Holm: GDPR sharpens that even further, frankly. The EU says you have a right to erasure — a legal mandate to delete personal data. And a blockchain is structurally designed so no one can delete anything. That's not a gap in compliance. That's an architectural incompatibility.

Lila Soto: And it's not like you can anonymize old blocks after the fact. The hash breaks. The whole chain breaks. So — okay, picture someone who transacted on a public blockchain in 2019. Their transaction is in there. Permanently. And in 2024 they file a GDPR erasure request. Who do they send it to?

Iris Holm: There's no one to send it to.

Lila Soto: There's nobody. No controller. No delete button. The distributed consensus that makes Bitcoin secure is also the thing that makes GDPR compliance structurally impossible on a public chain. You can't have both. The EU said you have a right to be forgotten. The ledger said — actually, we don't forget.

Iris Holm: So the burden of consumer protection lands entirely off-chain. Regulation of the edges. Not regulation of the thing itself.

Lila Soto: Which means if your only real recourse layer is an intermediary like Circle or a compliant exchange, you're not using a decentralized system. You're using a decentralized-ish system with a centralized safety net that has fewer protections than the bank you left.

Iris Holm: States the whole thing in one sentence: you've kept the irreversibility and lost the privacy.

Lila Soto: Paid twice. And what's underneath that — I think — is a question about whether we've just rebuilt the old system inside a new aesthetic. Because the consumer protection didn't go away. It just migrated to entities that aren't required to provide it.

Iris Holm: That mechanism — exactly the same one — that protects a dissident from a government freezing their account. That's the mechanism that protected whoever took the forty-seven thousand dollars. There is no toggle. Censorship resistance and fraud immunity aren't two features sharing a roof. They're the same architectural fact.

Lila Soto: And I think — I mean, that's what finally settled for me. Because I kept wanting to believe there was a clever fix somewhere downstream. A regulatory layer, a compliance regime, the GENIUS Act doing something at the edge. But those only reach Circle, the exchanges, the intermediaries. The protocol is just... sitting there. Unchanged. Satoshi's 2008 design, still running, still producing the same tradeoff every single day. And no law touches it.

Iris Holm: We started with a woman calling her bank. Fraud. Reversal. Done. And the honest answer at the end is — that mechanism exists because somewhere, a human being had authority to say no, undo this. Blockchain was built so that person couldn't exist. That's not a flaw they left in. That's the whole point.

Lila Soto: Yeah. And I guess what I'm sitting with is — it's a real thing that was chosen. Not an oversight. Someone looked at the ability of governments and institutions to reverse, freeze, erase — and decided that power was the problem. The load-bearing wall is load-bearing because that was the building they wanted. The fraud victim just happens to live in it too.

Why blockchain's permanence enables security but prevents undoing theft · Onpode