ARK Invest and Glassnode published a decentralization scorecard on September 1 measuring blockchain resilience by calculating how many large entities would need to coordinate to disrupt consensus. The analysis found that Bitcoin requires coordination among three mining pools, Ethereum requires three staking entities, and Solana requires 19 validators.
The measure, called a critical resilience threshold, captures one form of network risk by examining block production and voting power concentration. However, the researchers emphasized that this metric alone does not determine overall network security, as different vulnerabilities operate through different channels.
What the Numbers Measure
Bitcoin's threshold of three reflects mining pools' control over block templates. A September 6 snapshot showed Foundry USA, AntPool, and F2Pool collectively coordinating 59.04% of observed block production. Individual miners can redirect their computing power between pools in roughly 30 seconds, preserving some decentralization at the hardware level despite pool concentration.
Ethereum's threshold of three staking entities reflects stake concentration, though the researchers noted a classification challenge: a single label like Lido can represent either a protocol or hundreds of individual operators. Ethereum's threat model involves multiple thresholds—33% of stake can delay finality, 50% can censor transactions, and 66% can finalize preferred chains.
Solana's coefficient of 19 indicates that its top validators are more widely distributed by stake. Independent dashboards recorded values between 18 and 20 depending on measurement date and methodology. The Solana Foundation's June 2025 report, using April 2025 data, recorded 20.
Hidden Dependencies and Infrastructure Risk
Beyond validator counts, shared infrastructure creates correlated failure modes. Data centers, cloud platforms, and network operators can affect multiple nodes simultaneously, even when validator distribution appears decentralized.
On Solana, the Foundation's April 2025 data showed that over 100 data-center providers hosted validators, but two providers—TeraSwitch and Latitude—hosted 45.70% of stake. More recent data showed expansion to 437 data centers, though concentration among leading providers persisted.
Client software poses a separate risk channel. On Solana, approximately 92% of stake used Agave or Jito clients in April 2025, while roughly 7% used Firedancer or hybrid implementations. A single software bug affecting the dominant client could disrupt the network regardless of validator distribution.
Ethereum's execution-layer clients showed similar concentration, with Geth representing 50.17% of measured nodes. The researchers noted that independent client implementations reduce the blast radius of shared bugs.
Exit Speed and Persistent Risk
How quickly participants can leave a network affects how long concentrated influence can persist. Bitcoin miners redirect hash power without protocol delays. Ethereum validators follow rate-limited exit queues; during normal conditions this can take roughly one day, but stressed conditions extend the timeline to weeks. This separation means that even if staking becomes concentrated, validators may remain tied to a protocol during high withdrawal demand.
Framework for Institutional Assessment
The researchers recommended that institutions evaluating blockchain infrastructure should match each threat to the corresponding measurement. Transaction censorship requires examining stake or hash-rate concentration at protocol thresholds. Infrastructure outages require mapping validators and nodes by provider, jurisdiction, and network operator. Software faults require analyzing client shares and shared codebases. Persistent capture requires examining beneficial ownership, delegation sources, and withdrawal timelines.
The composite ranking favored Bitcoin across multiple dimensions including auditability, ownership dispersion, geographic resilience, and exit fluidity. Solana's lower validator threshold reflects stronger distribution on that specific measure but does not eliminate risks from infrastructure, software, and other dependencies.


