Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Crypto Digital Marketing: A Full-Funnel Guide from Seed Round to Tier-1 Listing

7 September 2026 at 08:42

Scale Crypto Growth from Funding to Exchange Listing Success

image created by @emmacaldwell0305

Launching a crypto project requires more than innovative technology or tokenomics. Success depends on executing a well-planned digital marketing strategy that adapts to every stage of growth, from attracting seed investors to securing a Tier-1 exchange listing. Each phase demands different messaging, channels, and community-building efforts to maintain momentum and credibility. Founders must combine branding, content, community engagement, public relations, influencer collaborations, and performance marketing to achieve sustainable adoption. This guide explains how to build a full-funnel crypto digital marketing strategy that supports fundraising, user acquisition, token growth, and long-term ecosystem development while avoiding common marketing mistakes.

Understanding Full-Funnel Crypto Digital Marketing

What is Crypto Digital Marketing?

Crypto digital marketing is the strategic use of SEO, content marketing, social media, community management, PR, influencer outreach, and paid campaigns to attract investors, acquire users, increase token adoption, and support long-term blockchain project growth.

Why Full-Funnel Marketing Matters

  • Builds awareness before fundraising and token launches.
  • Converts interested audiences into active users and investors.
  • Strengthens community engagement throughout the project lifecycle.
  • Supports sustainable growth beyond exchange listings.

Mapping the Crypto Customer Journey

  • Create awareness through content, PR, social media, and influencer campaigns.
  • Convert prospects into investors, token holders, or platform users with targeted campaigns.
  • Retain users through community engagement, product updates, and loyalty initiatives.

Aligning Marketing with Project Milestones

  • Build brand credibility before seed and private funding rounds.
  • Increase community growth before token generation events (TGEs).
  • Execute launch campaigns during public token sales and listings.
  • Expand user acquisition after product and token launches.
  • Strengthen brand trust and ecosystem growth before Tier-1 exchange listings.

Stage 1: Building Market Presence Before the Seed Round

Defining the Project’s Value Proposition

A clear value proposition explains the blockchain project’s purpose, target audience, unique benefits, and market position. Strong messaging helps attract investors, partners, and early users by showing why the project stands apart from competitors.

Creating a Professional Brand Identity

A professional brand identity includes visual elements, communication style, and clear positioning. Consistent branding improves recognition, builds trust, and creates a credible image that supports investor confidence before the funding stage.

Developing a Launch-Ready Website

A launch-ready website should showcase the project vision, technology, roadmap, token details, team information, and documentation. An informative and user-friendly website helps convert visitors into potential investors and community members.

Preparing Investor-Focused Messaging

Investor-focused messaging highlights the project’s market opportunity, technology advantages, token utility, growth strategy, and future goals. Clear communication helps investors understand the project’s potential and make informed decisions.

Stage 2: Marketing During Seed and Private Funding

Reaching Angel Investors and VCs

Crypto projects should connect with angel investors and venture capital firms through networking, industry events, investor platforms, and targeted outreach. Building relationships early can create funding opportunities and strategic partnerships.

Thought Leadership Content

Publishing expert articles, founder opinions, market analysis, and research content helps establish authority. Thought leadership attracts investors by demonstrating industry knowledge, project expertise, and a clear understanding of market trends.

Community Building Before Token Launch

Building a community before launch creates early supporters who believe in the project’s vision. Regular updates, discussions, AMAs, and engagement activities help develop trust and maintain audience interest.

Public Relations and Media Outreach

PR campaigns through crypto publications, interviews, podcasts, and press releases increase project visibility. Media exposure helps establish credibility, attract investors, and introduce the project to a wider blockchain audience.

Stage 3: Growing Community Before Public Launch

image created by @emmacaldwell0305

Discord and Telegram Growth

Growing Discord and Telegram communities requires consistent engagement through discussions, announcements, AMAs, and community events. Active communities create stronger relationships and prepare users for upcoming project milestones.

Social Media Strategy

A strong social media strategy focuses on sharing educational content, project updates, industry insights, and community interactions. Platforms like X, LinkedIn, and YouTube help increase awareness and audience engagement.

Educational Content Marketing

Educational content such as blogs, videos, guides, and tutorials helps users understand the project’s technology and benefits. Informative content builds trust, attracts organic attention, and supports community growth.

Ambassador and Referral Programs

Ambassador and referral programmes encourage community members to promote the project through rewards, recognition, and incentives. These initiatives help expand reach, increase participation, and create dedicated brand supporters.

Stage 4: Token Launch Marketing Strategy

Launch Campaign Planning

A successful token launch requires a structured campaign covering awareness, community engagement, investor communication, and user acquisition. Planning promotional activities, content schedules, partnerships, and launch events helps create momentum before and during the token release.

Influencer and KOL Collaborations

Collaborating with crypto influencers and Key Opinion Leaders (KOLs) helps projects reach targeted audiences. Strategic partnerships with trusted voices can increase awareness, educate users, and generate interest among potential token holders.

Paid Advertising Channels

Paid advertising through crypto-friendly platforms helps increase visibility and attract potential users. Targeted campaigns across search engines, social platforms, and blockchain media can improve reach while driving qualified traffic.

Email Marketing for Conversions

Email marketing helps nurture leads through token launch updates, educational content, announcements, and community invitations. Personalised campaigns can convert interested audiences into active participants and long-term ecosystem users.

Stage 5: User Acquisition After Token Launch

Performance Marketing Campaigns

Performance marketing focuses on measurable user growth through targeted advertising, conversion tracking, and campaign optimisation. These strategies help attract new users while improving acquisition efficiency after the token launch.

SEO and Organic Growth

SEO and organic content strategies improve long-term visibility by helping users find project information through search engines. Blogs, guides, and educational resources attract organic traffic and build ongoing awareness.

Ecosystem Partnerships

Strategic partnerships with blockchain projects, platforms, and communities can expand user reach. Collaborations create new growth opportunities through integrations, joint campaigns, and shared audiences.

Incentive-Driven Campaigns

Reward-based campaigns such as referral programmes, community activities, and user incentives encourage participation. These initiatives help increase adoption, improve engagement, and attract new users to the ecosystem.

Stage 6: Preparing for Tier-1 Exchange Listings

Building Trading Volume Organically

Organic trading growth comes from genuine user interest, active communities, product adoption, and ecosystem activity. Maintaining healthy market participation helps improve credibility when approaching major exchanges.

Strengthening Community Engagement

A highly engaged community demonstrates project stability and user commitment. Regular updates, discussions, educational initiatives, and interactive events help maintain support before exchange listing discussions.

Exchange-Focused PR Campaigns

Exchange-focused PR campaigns highlight project achievements, milestones, partnerships, and market progress. Media coverage across relevant crypto platforms can increase visibility and strengthen reputation among exchanges.

Increasing Brand Credibility

Building credibility requires consistent communication, transparent updates, strong community relationships, and proven project progress. A trusted brand image improves confidence among users, investors, and potential exchange partners.

Measuring Marketing Performance Throughout the Funnel

image created by @emmacaldwell0305

Key Performance Indicators

Tracking key performance indicators helps crypto projects measure campaign success across different growth stages. Important metrics include website traffic, community growth, user acquisition, conversion rates, token participation, engagement levels, and investor interest.

Marketing Analytics Tools

Marketing analytics tools provide insights into audience behaviour, campaign performance, and user interactions. These platforms help teams monitor traffic sources, content performance, conversion patterns, and campaign effectiveness to improve future strategies.

Community Metrics

Community metrics reveal the health and activity level of a project’s audience. Important measurements include member growth, engagement rates, active users, discussions, participation in events, and overall community sentiment.

ROI Tracking

ROI tracking helps projects evaluate the financial impact of marketing activities. By analysing campaign costs, user acquisition results, conversions, and revenue generated, teams can identify effective strategies and allocate resources efficiently.

Common Crypto Digital Marketing Mistakes

Inconsistent Branding

Inconsistent branding across websites, social media, and marketing materials can reduce trust and confuse audiences. Maintaining a unified visual identity, messaging style, and communication approach helps create a recognisable project presence.

Overreliance on Paid Marketing

Depending only on paid advertising can create short-term visibility without building lasting growth. Successful crypto projects combine paid campaigns with organic strategies such as content marketing, community building, and partnerships.

Weak Community Management

Poor community management can reduce user interest and damage project reputation. Regular communication, active moderation, meaningful discussions, and timely responses are important for maintaining a supportive community.

Ignoring Post-Launch Engagement

Many projects focus heavily on launch activities but neglect users afterward. Continuous updates, community interactions, educational content, and ecosystem activities help maintain engagement and support long-term adoption.

Best Practices for Sustainable Crypto Growth

Consistent Communication

Regular communication through announcements, updates, blogs, and community channels helps maintain transparency. Keeping users informed builds trust and strengthens relationships throughout the project’s development journey.

Data-Driven Campaign Optimisation

Using campaign data helps identify successful strategies and areas for improvement. Analysing user behaviour, engagement rates, and conversion results allows teams to make informed marketing decisions.

Multi-Channel Marketing

A multi-channel approach combines social media, content marketing, PR, influencer collaborations, email campaigns, and community platforms. This approach helps projects reach diverse audiences and maintain consistent visibility.

Long-Term Ecosystem Development

Sustainable growth requires focusing beyond token launches and short-term campaigns. Continuous product improvements, partnerships, community support, and ecosystem expansion help create lasting value for blockchain projects.

Conclusion

A successful crypto project is built through consistent marketing across every growth stage rather than short-term promotional campaigns. From establishing credibility before fundraising to maintaining community engagement after a Tier-1 exchange listing, each phase requires a different combination of content, public relations, community management, partnerships, and performance marketing. Projects that treat marketing as a continuous process are better positioned to attract investors, retain users, and strengthen token adoption. By implementing a full-funnel crypto digital marketing strategy, founders can build lasting brand recognition, support sustainable ecosystem growth, and improve their chances of long-term success in an increasingly competitive blockchain industry.


Crypto Digital Marketing: A Full-Funnel Guide from Seed Round to Tier-1 Listing was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

What Are Decentralized Derivatives and How Do They Work? — 36Crypto

By: 36Crypto
1 September 2026 at 11:53
  • Decentralized derivatives let traders speculate on asset prices or hedge portfolio risks without holding the underlying assets or relying on intermediaries.
  • Smart contracts execute trades transparently, while blockchain oracles supply external price data required to value contracts and settle open positions.
  • Greater accessibility and asset control accompany substantial risks involving leverage, limited liquidity, contract vulnerabilities, volatility, and regulatory uncertainty.

Decentralized derivatives are blockchain-based financial contracts that allow traders to speculate on price movements or protect their portfolios against unfavorable market conditions. Their value comes from underlying assets such as cryptocurrencies, stocks, commodities, or other financial instruments.

Unlike conventional derivatives, which generally involve brokers, clearing houses, or centralized exchanges, decentralized derivatives operate through smart contracts on decentralized exchanges. These contracts automatically enforce trading conditions, manage collateral, calculate profits or losses, and settle positions without requiring a traditional intermediary.

This structure gives users greater control over their funds while creating an open and transparent trading environment. However, decentralized derivatives remain complex instruments, and their combination of leverage, volatile assets, and experimental technology can expose traders to substantial losses.

Also Read: What Are Crypto Points and How Do They Work?

What Are Decentralized Derivatives?

A decentralized derivative is a financial contract whose value depends on the price or performance of another asset. Traders can use these contracts to gain exposure to an asset without purchasing or holding it directly.

For example, a trader expecting a cryptocurrency’s price to increase may open a long derivatives position. Another trader anticipating a decline may take a short position. Investors can also use derivatives to hedge existing holdings, potentially offsetting losses when the market moves against their portfolios.

Decentralized derivatives transfer these familiar financial functions onto blockchain networks. Rather than relying on an institution to process transactions and maintain records, users interact with protocols governed by programmed rules.

How Do Decentralized Derivatives Work?

Smart contracts form the operational foundation of decentralized derivative platforms. Once a trader opens a position and supplies the required collateral, the contract records the transaction and applies the protocol’s rules throughout the trade.

These rules may determine collateral requirements, leverage limits, fees, liquidation prices, and settlement procedures. When predetermined conditions are met, the contract can execute the required action automatically, reducing delays and limiting direct human involvement.

Transactions are recorded on a blockchain, allowing users to inspect trading activity and contract execution. Although this transparency can reduce opportunities for hidden manipulation, it does not guarantee that every protocol is secure or that every trade will be profitable.

What Types of Decentralized Derivatives Are Available?

Decentralized derivatives appear in several forms, including futures, options, perpetual contracts, and synthetic assets. Each product offers a different approach to speculation and risk management.

Futures contracts establish an agreement to buy or sell an asset at a predetermined price on a specified date. Options give their holder the right, but not the obligation, to complete a transaction under agreed conditions.

Perpetual contracts resemble futures but do not have expiry dates, allowing positions to remain open provided traders maintain sufficient collateral. Synthetic assets, meanwhile, are blockchain-based instruments designed to track the value of cryptocurrencies, stocks, commodities, or other reference assets.

Why Are Blockchain Oracles Important?

Blockchains cannot independently access information about prices and events outside their networks. Consequently, decentralized derivative protocols often rely on blockchain oracles to obtain the data needed to value positions and complete settlements.

An oracle delivers external information, such as the market price of Bitcoin or a traditional stock, to a smart contract. The contract then uses that information to calculate profits, losses, collateral requirements, and possible liquidations.

Oracle reliability depends on factors such as data accuracy, decentralization, source quality, and update frequency. Incorrect, delayed, or manipulated data could cause positions to be valued improperly and create significant losses for users.

Benefits of Decentralized Derivatives

Transparency is one of the principal advantages of decentralized derivatives because transactions and contract activity are recorded on an immutable blockchain ledger. Users can independently examine this information instead of relying entirely on reports produced by a centralized institution.

Smart contracts also remove many intermediary functions, which may improve efficiency and reduce certain administrative costs. Furthermore, traders can retain control of their private keys and assets rather than transferring custody to an exchange or third-party custodian.

Accessibility represents another important benefit. Anyone with a compatible wallet and sufficient collateral may be able to access markets that would otherwise require brokerage accounts, geographic eligibility, or approval from financial institutions.

Decentralized derivative platforms can also support numerous assets and trading strategies, giving users opportunities to speculate, hedge risk, or gain market exposure across multiple blockchain networks.

Risks and Drawbacks of Decentralized Derivatives

Leverage presents one of the greatest risks because it increases both potential returns and possible losses. A relatively small market movement can liquidate a highly leveraged position, resulting in the loss of some or all deposited collateral.

Smart contract vulnerabilities create another concern. Programming errors, exploits, or poorly designed economic mechanisms may cause contract failures or allow attackers to remove funds from a protocol.

Liquidity may also be limited, particularly on newer platforms or within less popular markets. Insufficient trading activity can increase slippage, delay execution, and make it difficult for traders to close positions at expected prices.

Additionally, decentralized exchanges can be difficult for inexperienced users to navigate. Wallet management, collateral deposits, network fees, liquidation rules, and blockchain transactions introduce responsibilities that are generally handled by centralized platforms.

Popular Decentralized Derivative Platforms

GMX is a decentralized platform that uses smart contracts to facilitate derivatives trading without conventional intermediaries. Its available markets give users several ways to build speculative or hedging strategies within a transparent blockchain environment.

dYdX has become known for perpetual futures, substantial trading activity, relatively deep liquidity, and limited slippage. These characteristics can improve order execution, particularly for traders managing larger positions.

Gains Network offers derivatives trading alongside cross-chain functionality, enabling users to access markets across different blockchain ecosystems. Its native token also supports governance, allowing holders to participate in protocol decisions.

Other platforms, including Dopex and Lyra, have expanded the decentralized derivatives sector by offering additional products and trading models.

How Do Native Tokens Support These Platforms?

Native tokens may serve several functions within decentralized derivatives protocols. Holders can use them to vote on governance proposals involving fees, supported markets, platform upgrades, or risk parameters.

Some protocols accept native tokens as collateral, although this can expose traders to additional volatility if the collateral’s value declines. Platforms may also distribute tokens as incentives to liquidity providers or market makers who support efficient trading.

While these rewards can attract users and capital, token incentives do not eliminate the underlying financial and technical risks associated with a protocol.

Regulatory Challenges Facing Decentralized Derivatives

Decentralized derivatives operate across borders, creating difficult questions about jurisdiction and regulatory responsibility. A transaction can involve anonymous users, globally distributed developers, blockchain validators, and protocols without a traditional corporate structure.

Authorities must also determine whether particular products qualify as securities, commodities, or another form of financial instrument. Their classification can affect registration requirements, taxation, consumer protections, and enforcement procedures.

Investor protection presents an additional challenge because decentralized systems may lack a central institution that can reverse transactions or compensate users after an exploit. Balanced regulations could support responsible innovation while reducing fraud, manipulation, and wider market instability.

Conclusion

Decentralized derivatives bring futures, options, perpetual contracts, and synthetic assets into blockchain-based markets. Through smart contracts and price oracles, they allow users to speculate or hedge without relying on traditional financial intermediaries.

Their transparency, accessibility, flexibility, and self-custodial structure offer meaningful advantages. Nevertheless, leverage, volatility, limited liquidity, oracle failures, smart contract vulnerabilities, and uncertain regulations make careful research and disciplined risk management essential.

FAQs

1. What is a decentralized derivative?
It is a blockchain-based financial contract whose value is determined by an underlying asset, such as a cryptocurrency, stock, or commodity.

2. Do traders need to own the underlying asset?
No. Decentralized derivatives provide price exposure without requiring traders to purchase or directly hold the underlying asset.

3. What role do smart contracts play?
Smart contracts automatically manage collateral, execute trading conditions, calculate outcomes, and settle positions according to programmed rules.

4. Why are decentralized derivatives risky?
They carry risks involving leverage, volatility, liquidation, insufficient liquidity, inaccurate oracle data, smart contract failures, and regulatory uncertainty.

5. Which platforms offer decentralized derivatives?
Popular platforms include GMX, dYdX, Gains Network, Dopex, and Lyra, although their available products and operational structures differ.

Also Read: What Are Crypto Market Makers and How Do They Work?

Originally published at https://36crypto.com on August 31, 2026.


What Are Decentralized Derivatives and How Do They Work? — 36Crypto was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

The Trade Nobody Puts in the Wallet Infrastructure Pitch Deck

1 September 2026 at 11:51

A finance team I keep hearing about runs month-end close on a spreadsheet that used to be one tab. Now it’s forty. Not because the business grew forty times — someone kept saying yes to new assets, and every asset meant a new wallet, a new balance to fetch, and another key to manage.

Nobody designed it that way on purpose. Wallet-per-asset is the architecture you fall into when the first integration works and the second looks almost identical. It’s only around asset thirty that finance starts asking why reconciliation takes four days instead of four hours.

What Forty Wallets Actually Cost

The visible cost is obvious: more infrastructure, more keys, more places to fail. The cost nobody budgets for shows up somewhere else — in finance, support, and operations.

A user asks where another balance went because it sits behind a different wallet. Finance runs forty reconciliation processes where one could have done the job, and each can fail differently. A fix to one flow doesn’t necessarily improve the other thirty-nine. At a small scale, that’s annoying. At forty assets, it becomes a second job.

The One-Wallet Fix and What It Actually Changes

Collapsing that architecture into one balanced view sounds like a UI decision. It isn’t. Underneath the interface, it’s an infrastructure and custody decision.

Instead of treating every asset as its own operational lane, the product gives users and finance one place to see balances and one process to reconcile them. The report becomes simpler because the architecture underneath it becomes simpler first.

The second-order effects are more interesting. Support gets fewer questions about missing balances. New-asset launches can move faster because the team no longer has to recreate the same custody setup every time. Finance gets one reporting process instead of dozens — and eventually starts trusting the numbers again.

The Part That Doesn’t Disappear

Consolidating custody doesn’t remove risk; it relocates it. Forty small operational risks become one larger relationship that has to be governed properly, which is often a cleaner model but still comes with its own responsibilities.

Someone still has to own provider oversight, permissions, security policies, access controls, and the consequences if the underlying infrastructure fails. The difference is that the risk is now concentrated enough to be visible, documented, and managed instead of being scattered across dozens of separate wallet setups.

Three Answers to Who Actually Holds the Key

Once a team decides that one wallet is better than forty, the next question is harder: where should that unified infrastructure actually live? The three models below solve the same operational problem differently, mainly in how much infrastructure and control the business chooses to hand off.

1 | Coinbase | Managed Wallet Infrastructure

Coinbase CDP Wallets take the managed-platform route. The stack includes TEE-backed key infrastructure, KYT screening, and APIs covering embedded and server wallets.

For a product team, the attraction is consolidation: wallet creation, security infrastructure, and compliance tooling sit behind one development layer rather than being assembled asset by asset.

The trade-off is equally clear. More infrastructure is delegated to an established provider, so the team has less of the underlying wallet stack to build and operate itself. Governance therefore shifts toward managing the provider relationship, permissions, policies, and integration rather than managing every key system independently.

2 | WhiteBIT | Unified Multi-Asset Custody

WhiteBIT’s Wallet-as-a-Service approaches the same problem from a multi-asset custody angle. It supports 340+ assets across 80+ networks within a single wallet, with address generation and AML checks built into the infrastructure.

For businesses managing many assets, the practical gain is fewer parallel systems. The same environment can support multiple networks and assets instead of requiring a new custody workflow every time the product expands its asset list.

Here too, simplification comes with concentration. Custody and a larger part of the operational layer sit with one provider, which reduces internal complexity but makes provider governance, security standards, access controls, and operational resilience more important.

3 | Openfort | More Control Over the Key Layer

Openfort takes a different route. Its Wallet-as-a-Service stack is built around non-custodial infrastructure, with self-hostable key management through OpenSigner and a policy layer for controlling how wallets operate.

The practical difference is configurability. Teams can define transaction rules, session permissions, contract allowlists, spending limits, and gas sponsorship without rebuilding the wallet stack around each use case. That makes Openfort especially relevant for products that need wallet behavior to vary across users, applications, or workflows.

That flexibility also keeps more operational responsibility with the product team. Key policies, security rules, and wallet behavior need to be actively governed, which can suit teams that want a more programmable infrastructure layer rather than simply outsourcing most of the wallet logic to a provider.

The Design Principle Underneath the Reconciliation Win

The clean balance view is real, and finance may feel the benefit first. But the honest way to judge wallet infrastructure isn’t by how clean the demo looks. It’s by what happens three years later, after asset coverage, transaction volume, and headcount have all moved in directions nobody predicted.

A system that turns forty reconciliation problems into one can remove a surprising amount of operational noise, but that simplification only works if the remaining relationship is governed properly. Forty risks becoming one is valuable only when somebody is clearly responsible for the one.

That responsibility isn’t a footnote to the architecture decision. It sits at the center of it, because the goal was never simply to make the balance screen cleaner — it was to make the underlying system easier to understand, operate, and trust.

Disclaimer: This is not financial or investment advice. Do your own research before making any decisions. Use at your own risk.


The Trade Nobody Puts in the Wallet Infrastructure Pitch Deck was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Crypto Retention Marketing: The Ultimate Growth Guide for Web3 Founders

29 August 2026 at 01:23

Retain Web3 Users With Effective Crypto Marketing Tactics

image created by @emmacaldwell0305

Launching a Web3 project is only the beginning; keeping users engaged after acquisition determines long-term success. Many blockchain projects focus heavily on attracting new users but overlook the importance of retention, community activity, and continuous value creation. Crypto retention marketing helps founders understand user behaviour, strengthen relationships, and encourage ongoing participation through personalised communication, rewards, education, and community initiatives. With increasing competition across the Web3 ecosystem, retaining users requires more than token incentives. It demands a clear understanding of user expectations, market trends, and engagement patterns that create meaningful connections between projects and their communities.

Understanding Crypto Retention Marketing and Its Importance for Web3 Projects

What Is Crypto Retention Marketing

Crypto retention marketing focuses on keeping Web3 users engaged after acquisition through community building, personalised communication, rewards, and continuous value creation to encourage long-term participation. Platforms and teams such as Blockchain App Factory help Web3 projects strengthen user engagement through structured retention-focused approaches that support ecosystem growth.

Why User Retention Matters After Token Launches

  • Builds Long-Term Community Loyalty: Retained users become active community members who support the project beyond the initial token launch phase.
  • Improves Ecosystem Activity: Consistent user engagement increases platform usage, transactions, and participation across Web3 products.
  • Reduces User Churn: Retention efforts help prevent users from leaving after short-term incentives or market hype fade.
  • Increases Project Credibility: An active user base demonstrates trust, adoption, and real interest in the blockchain ecosystem.
  • Creates Sustainable Growth: Long-term users contribute to steady ecosystem development instead of relying only on new user acquisition.

Difference Between User Acquisition and Retention in Web3

image created by @emmacaldwell0305

Why Many Web3 Projects Struggle With User Retention

Short-Term Hype Versus Long-Term Community Value

Many Web3 projects depend heavily on launch excitement, token speculation, and temporary campaigns to attract users. However, without continuous value, meaningful utility, and community involvement, users often lose interest after the initial hype fades.

Lack of Continuous Engagement Strategies

User retention requires ongoing interaction through education, updates, rewards, community events, and product improvements. Projects that fail to maintain regular engagement opportunities often experience declining activity and reduced user participation.

Poor Communication After Launch Events

After token launches or major announcements, weak communication can create uncertainty among users. Regular updates, transparent progress reports, and open discussions help maintain trust and keep the community connected.

The Role of Community Building in Crypto User Retention

Creating Active Discord and Telegram Communities

Discord and Telegram communities provide direct channels for user interaction, support, and feedback. Active communities help users stay informed, participate in discussions, and develop stronger connections with the Web3 project.

Building Trust Through Transparent Communication

Transparency plays a key role in retaining Web3 users. Sharing development updates, roadmap progress, challenges, and future plans helps projects build credibility and maintain long-term relationships with their communities.

Encouraging User Participation Through Community Activities

Community activities such as AMAs, governance discussions, challenges, and educational sessions encourage users to participate regularly. These interactions create a sense of belonging and increase long-term involvement.

Using Data Analytics to Understand Web3 User Behaviour

Tracking Wallet Activity and Engagement Patterns

Analysing wallet transactions, platform usage, and interaction frequency helps Web3 projects understand user behaviour. These insights reveal engagement trends and identify opportunities to improve user experiences.

Identifying Active and Inactive User Segments

User segmentation helps projects classify audiences based on activity levels, interests, and participation patterns. Identifying inactive users allows teams to create targeted campaigns to bring them back.

Using Insights to Improve Retention Campaigns

Data-driven insights allow Web3 teams to optimise retention efforts by understanding what motivates users. Projects can improve communication, rewards, and engagement methods based on real user behaviour.

Personalised Communication Strategies for Crypto Retention

Segmenting Users Based on Behaviour

User segmentation helps Web3 projects understand different user groups based on activity, interests, transaction patterns, and engagement levels. By analysing these behaviours, projects can create more relevant communication that matches user expectations and improves retention.

Sending Relevant Updates and Educational Content

Regular updates, product announcements, tutorials, and educational resources help users stay connected with a project. Providing useful information keeps communities informed and encourages users to continue participating in the ecosystem.

Improving User Experience Through Targeted Messaging

Targeted messaging allows projects to deliver personalised notifications, recommendations, and updates based on user activity. This approach creates more meaningful interactions and helps users receive information that adds value to their journey.

Reward-Based Retention Models for Blockchain Projects

Loyalty Programmes and Incentive Systems

Loyalty programmes encourage users to remain active by offering benefits for continued participation. Web3 projects can use achievement-based rewards, community privileges, and engagement incentives to build stronger connections with users.

Staking Rewards and Ecosystem Benefits

Staking rewards and ecosystem benefits provide users with reasons to stay involved beyond initial participation. These models encourage long-term commitment by offering additional value for supporting network activity and platform growth.

Avoiding Dependency on Short-Term Token Incentives

Relying only on token rewards can attract temporary users who leave once incentives decrease. Sustainable retention requires combining rewards with product value, community engagement, and meaningful user experiences.

The Impact of Content Marketing on Web3 User Loyalty

Educating Users Through Valuable Content

Educational content helps users understand blockchain products, token utility, and ecosystem developments. Clear guides, tutorials, and insights reduce confusion while helping users make informed decisions and remain engaged.

Building Credibility Through Thought Leadership

Consistent thought leadership content helps Web3 projects establish expertise and trust within their communities. Sharing industry insights, research, and expert perspectives strengthens relationships with users and stakeholders.

Keeping Communities Informed and Engaged

Regular blogs, newsletters, social posts, and community updates keep users connected with project developments. Continuous communication maintains interest, encourages discussions, and supports long-term community participation.

Leveraging Gamification to Improve User Engagement

image created by @emmacaldwell0305

Creating Interactive User Experiences

Gamification helps Web3 platforms make user interactions more engaging through activities, challenges, and rewards. Interactive experiences encourage users to spend more time within the ecosystem while creating stronger connections with the platform.

Implementing Quests, Achievements, and Challenges

Quests, achievement systems, and community challenges motivate users to complete actions and participate regularly. These elements create a sense of progress while encouraging continuous involvement with Web3 products and services.

Increasing Participation Within Web3 Platforms

Gamified features can increase platform activity by giving users clear goals and reasons to return. Rewarding participation through meaningful experiences helps create active communities and improves long-term user engagement.

Email and Social Media Strategies for Crypto Retention

Maintaining Regular Communication With Users

Consistent communication through emails, newsletters, and social channels keeps users connected with project updates. Regular interactions help maintain awareness, strengthen relationships, and encourage continued participation within the ecosystem.

Sharing Product Updates and Ecosystem Developments

Providing timely information about new features, roadmap progress, partnerships, and ecosystem changes keeps users informed. Transparent updates help users understand project growth and maintain confidence in the platform.

Using Social Platforms to Strengthen Relationships

Social media channels allow Web3 projects to interact directly with their communities. Engaging discussions, educational posts, and community-focused content help build stronger connections with users.

Measuring Crypto Retention Marketing Performance

Key Retention Metrics for Web3 Projects

Tracking retention metrics helps Web3 teams evaluate user engagement and campaign performance. Important indicators include active users, repeat interactions, community participation, and user activity over specific periods.

User Activity, Churn Rate, and Lifetime Value

User activity shows how frequently participants engage with a platform, while churn rate measures users who stop interacting. Lifetime value helps estimate the long-term contribution of retained users to the ecosystem.

Analysing Campaign Effectiveness

Performance analysis helps projects understand which retention activities generate better results. Reviewing engagement data, user feedback, and campaign outcomes allows teams to improve future retention efforts.

Building a Long-Term Retention Framework for Web3 Growth

Combining Community, Content, Rewards, and Analytics

A successful retention framework combines community engagement, valuable content, reward systems, and data insights. This integrated approach helps projects create consistent user experiences and maintain ongoing participation.

Creating Sustainable User Relationships

Long-term retention depends on building trust and delivering continuous value. Projects that focus on user needs, transparent communication, and meaningful interactions can develop stronger relationships with their communities.

Preparing Retention Plans Before and After Launch

Retention planning should begin before a project launch and continue throughout its growth journey. Early preparation helps teams design engagement methods that support user loyalty and maintain ecosystem activity.

Conclusion

Crypto retention marketing has become a critical factor for Web3 projects aiming to build sustainable ecosystems. While attracting users creates initial momentum, retaining them requires consistent value, transparent communication, and meaningful engagement opportunities. Founders who focus on community relationships, data insights, personalised experiences, and continuous education can create stronger user loyalty. A successful retention approach helps projects reduce user drop-offs, increase participation, and develop a more active ecosystem. As the Web3 space continues to mature, retention will play a major role in separating temporary trends from projects that achieve lasting growth.


Crypto Retention Marketing: The Ultimate Growth Guide for Web3 Founders was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

2026 Crypto’s Most-Hacked Year, and the AI Race to Defend It

25 August 2026 at 10:06
TL;DR. 2026 has recorded more crypto exploits than any year on record, over 200 in the first half alone, more than one a day. The dollars stolen are actually lower than 2025, because no single theft matched last year’s $1.5 billion Bybit hack, but the number of attacks has roughly doubled. The driver is AI, which has lowered the cost and skill needed to probe software until attacking a small protocol became economical for the first time. That same technology is now the strongest defense.

What the numbers actually show

The clearest way to see 2026 is to separate two things that usually get merged, how often protocols are attacked and how much is taken when they are.

The picture is a divergence. Total value stolen peaked in 2021 and 2022, dipped through the bear market, and has stayed well below those highs. The number of incidents did the opposite, holding steady for years and then climbing sharply. By CoinGecko’s count, 2026 logged 164 separate incidents through early August, already more than any full prior year, with the next-highest annual figure being 2025’s 97. TRM Labs recorded 207 hacks in just the first half of 2026, more than double the 83 from the same period a year earlier, and Blockaid independently verified 212.

The dollar figures need care, because they are easy to misread as good news. H1 2026 losses came in around $972 million to $1.1 billion, below H1 2025. But as TRM’s Ari Redbord noted, that decline happened almost entirely because North Korea did not repeat an operation on the scale of the $1.5 billion Bybit hack. One outlier event in 2025 flattered the year-over-year comparison. Set it aside and the trend is more attacks, spread across more protocols, each taking less. That is a specific signature, and it points to a specific cause.

The evidence for the AI thesis

There is a straightforward economic reading of that signature. If attacks suddenly get cheaper to run, you would expect many more of them, reaching down to targets that were previously too small to bother with. That is what the data shows, and it lines up with what the security firms are measuring directly. TRM reported in August 2026 that AI adoption across crypto crime rose 40% year on year, and framed the mechanism plainly, AI did not invent new crimes, it removed the constraints on old ones. The skill floor dropped, the scale ceiling lifted, and fake identity went industrial.

The economics were put most directly at the Wyoming Blockchain Symposium, where Global Settlement Network’s Ryan Kirkley observed that it used to be too costly to hack someone worth $20,000, because the time was not worth it, and that an AI agent can now go after everyone at once. Three recent incidents show the range of what that enables.

Small teams overwhelmed by volume

In August 2026, two Bitcoin swap services shut down within weeks of each other citing the same cause. Boltz suspended operations, describing months of steadily rising automated, AI-assisted probing that its team could not patch fast enough. Atomiq followed, taking its swap routes offline because, as a small team, it could not fight the numerous sophisticated AI-assisted attacks on its infrastructure.

Governance nobody was watching

On August 23, Term Labs lost about $8.5 million, and the mechanism is worth understanding because no code was broken. Term’s vaults were governed by a token almost nobody had bothered to hold. The attacker simply acquired the governance tokens, which cost a few dollars in vault shares, then held 100% of the vote on five of the drained vaults. He opened a proposal styled to look like a routine parameter update, waited out the six-day minimum, and executed a bundle of 17 actions that recalled every asset into a strategy contract he controlled.

Scale as the point

On August 22, Blockaid detected an ongoing exploit of The Sandbox’s SAND token on Base, where attackers hijacked LayerZero delegate permissions and minted unbacked SAND across hundreds of transactions. The mechanism was a permissions oversight, and the automation is what made it relentless.

The frontier of this is already visible. Researchers disclosed JadePuffer, described as the first fully agentic ransomware, where an AI agent ran reconnaissance, credential theft, lateral movement, and encryption end to end, and Blockaid flagged a $216,000 exploit of an AI trading agent as the first of its kind, expecting prompt-injection attacks on agents to grow through the year.

Why this is a whole-industry problem, not a crypto flaw

It is worth being precise about what these incidents do and do not say about crypto. Very little of the 2026 record is smart-contract cryptography failing. The two largest H1 losses, Drift at roughly $285 million and KelpDAO at roughly $292 million, both traced to LinkedIn social engineering leading to a compromised multisig signer, the same human-layer attack that hits banks and enterprises. The Bybit hack that defined 2025 was a compromised interface at a wallet infrastructure provider, not a flaw in Ethereum.

And on the pure-code side, the direction is genuinely encouraging. Immunefi’s six-year data shows DeFi protocol losses fell about 80% from the 2022 peak of $2.62 billion to $534 million in 2024, with the median loss per incident dropping from $6 million to $1.5 million even as total value locked grew substantially. The old ecosystem-class attacks, flash-loan oracle manipulations and reentrancy, collapsed from nearly 19% of losses in 2022 to under 1% in 2025. Crypto’s core smart-contract security has been maturing, not decaying. What changed in 2026 is not that the code got worse. It is that AI made probing every layer, especially the human and operational layers, cheap enough to do at scale, and that pressure is arriving everywhere software runs. Crypto simply feels it first, because its infrastructure is open-source, its value is liquid, and its teams are often small.

The defense is the same technology, but access to it is gated

The encouraging half of the story is that the capability driving the attacks is also the strongest available defense. The important qualifier is that this defense is not something a protocol can simply switch on, and that is by design.

Anthropic launched Project Glasswing on April 7, 2026 on a deliberate premise. It had built a frontier model, Claude Mythos, that it assessed could surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Releasing that openly would hand the same capability to attackers, so Anthropic did the opposite and distributed it narrowly, to defenders of software whose compromise would be catastrophic. The launch cohort was around 50 organizations and reads like a list of the world’s most critical infrastructure, Apple, Microsoft, Amazon, Google, NVIDIA, JPMorgan Chase, Cisco, CrowdStrike, and the Linux Foundation among them. Access is invitation-only with no self-serve signup, and every organization has to meet Anthropic’s security requirements before it is granted the model.

The early results were substantial. In roughly a month, Glasswing partners used the model to find more than 10,000 high- or critical-severity vulnerabilities across systemically important software, including a critical flaw in a cryptographic library used by billions of devices, since patched, and one partner bank used it to detect and stop a fraudulent $1.5 million wire transfer. In May the program expanded to roughly 150 organizations across more than 15 countries, still centered on critical infrastructure in power, water, healthcare, and communications, and the US Federal Reserve and Treasury convened bank leaders over its implications. Anthropic has signaled that a broader, application-based access program for security organizations is in development, but it is not open yet.

That gating is why crypto’s entry point matters. In August 2026, Payward, the parent company of Kraken, joined Project Glasswing and adopted Claude Mythos for security, which makes it one of the first crypto firms known to reach this tier of defensive capability. It is a large, regulated exchange, exactly the profile the program targets, and its inclusion is a signal rather than a broadly available option. Most crypto teams cannot join Glasswing today. What they can do is use the widely available Claude and other AI models for defensive review, adopt the third-party security tooling being built on top of them, and prepare for the moment the capability becomes more accessible, which by Anthropic’s own timeline is months, not years, away for both sides.

How this could progress

Reading the current evidence forward, a few things look likely rather than certain.

Incident counts keep rising before they fall

As long as running an attack stays cheap, the frequency stays high, and the targets keep getting smaller. The near-term trend line is more incidents, lower average value, which is the 2026 signature intensifying rather than reversing.

The human and operational layers become the main battleground

The largest losses of 2026 were social engineering and unwatched governance, not broken math. Hardware-enforced signing, out-of-band verification of large transfers, active governance participation, and multisig hygiene are where the most value can be protected, and where AI-driven phishing will keep applying pressure.

Defensive AI adoption widens as access opens up

Today the most powerful defensive models sit behind gated programs like Glasswing, reaching a handful of large, vetted firms such as Kraken’s parent. But Anthropic expects Mythos-class capability to be available from multiple providers within 6 to 12 months, and is building a broader application-based access path. As that gate widens, running these models on your own systems first shifts from a rare advantage to a baseline expectation, and the teams that prepared their processes early will move fastest when it does.

Patch cadence compresses toward machine speed.

When bugs are found in hours, quarter-long patch windows are untenable. The maintainers who keep pace, and the disclosure norms that let them, become as important as the audits themselves.

The honest summary is the one the security firms keep returning to. AI removed the constraints that used to limit attacks, and that will not be undone. But the same technology, in defenders’ hands, finds the same flaws first, and the industries deploying it are moving. Crypto is early to this fight because of how it is built, open, liquid, and lean, and that makes it the clearest place to watch how the balance settles. The goal is not an unhackable system, which has never existed in any industry. It is to close the speed gap, and 2026 is the year that race began in earnest.

Sources


2026 Crypto’s Most-Hacked Year, and the AI Race to Defend It was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

The Most Dangerous Person in the World Might Be a Clerk

21 August 2026 at 10:22

That power is finally changing hands, and not where anyone is looking.

Somewhere tonight, a family will lose a house theyve lived in for thirty years. Not to a fire. Not to a flood. To a line in a book.

Someone with access to the right record will change one entry, a name, a plot number, and land that belonged to three generations now belongs to a stranger. No broken window. No theft you can point to. Just ink.

This isn’t rare. In Honduras, officials once quietly rewrote the government’s land database and handed themselves beachfront property. Across huge stretches of the world, families farm the same soil their whole lives and still cant prove a single inch of it is theirs. One clerk, one bribe, one “sorry, your file was lost,” and the ground under a life is gone.

Heres the part that should stop you cold. The same is true of almost everything you think you own.

Everything you own is a line in someone’s book

Your house isn’t yours because you live in it. Its yours because a record somewhere says so. Your money isnt really in your pocket, its a number in your bank’s book, and the bank promises the number is real. Even your name, your birthday, the plain fact that you legally exist, its all an entry in some official register.

Strip life down to the wiring and you keep hitting the same thing underneath all of it. A ledger. A list. Who owns what. Who owes what. Who is who.

Civilization doesnt actually run on money, or gold, or armies. It runs on ledgers. And heres the truth weve lived with so long we stopped seeing it.

Someone has always kept the book. And whoever keeps the book holds the power.

We have only ever swapped scribes

Go back five thousand years. The oldest human writing anyone has ever dug up isnt poetry or prayer. Its accounting. Clay tablets from the first cities, scratched with who owed how much grain. Before we wrote down a single story about ourselves, we wrote down the ledger.

And from that day, whoever held it ruled. The temple scribe decided what you owed the gods. The king’s men decided what you owed the crown. If the scribe made a mark against your name, you were in debt, and there was no arguing with the book.

Not much has really changed. Weve just kept swapping scribes.

Today the book is kept by banks, and land offices, and government databases. Nicer buildings. Same deal. You are rich because a bank’s computer says so. You own your home because a registry’s file says so. You exist because a database says so. Every time, youre trusting a keeper, some stranger, some system, to hold the truth about your life and not lose it, not sell it, not change it.

Most of the time, they dont. But youve seen what happens when they do. A currency printed until your savings turn to wallpaper. A land record that “disappears.” An account frozen by someone who never has to explain themselves to you. Every one of those is the same ancient wound. The keeper had power over you, and you had none over the keeper.

The quiet earthquake nobody explained to you

Now. For the first time in five thousand years, that is changing. And almost nobody is telling the story straight, because they keep burying it under words designed to make your eyes glaze. Crypto. Tokens. Coins. Moon. Forget all of it.

Heres the whole idea, in a picture a child could follow.

Imagine a village where everyone owns a bit of land. Instead of one big book locked in the chief’s hut, every single family keeps their own identical copy of the record. Someone sells a field, and everyone updates their copy at the same moment. Now picture one man sneaking home to rewrite his copy so it says he owns his neighbor’s land too. He marches to the market waving it. And every other family opens their copy, a hundred books that all say hes lying. His fake doesnt stand a chance.

Thats it. Thats a blockchain. Not a coin. A book that everyone holds a copy of, so no single person can quietly change it, because to rewrite the truth you’d have to rewrite everyone’s copy at once, and you cant.

I keep circling this idea in this newsletter, that blockchain is best understood as plumbing and rails, not a casino (The New Rails is the long version). But heres the plainest way I can put it. For the first time, we have a record with no keeper. A ledger that sits in no one’s drawer. No one to bribe, because theres no single clerk. No one to trust, because you dont have to. You can just check it yourself.

Read that twice. The oldest lever of power on earth, keeping the book, just stopped needing a keeper.

So where does a change this big show up first?

Not where youd expect. And this is the part almost everyone gets wrong.

Everyone stares at the top. Will there be one world currency, whats the Fed doing, is the dollar finished. And everyone stares at the bottom. Is my coin up, is it down, should I buy. Up there, and down here. Thats where all the noise lives, and all the fireworks.

But your ledgers, the ones that actually run your daily life, arent up there or down here. Theyre not at the world bank and theyre not in a coin on your phone. The deed to your home, the record of your birth, the title to your land, those sit in a filing cabinet, in a building, in your city.

The city is where the book has always physically lived. Which makes the city the one place the keeper’s grip is quietly being pried loose, right now, one unglamorous upgrade at a time. Not by revolution. By clerks quietly changing which kind of book they use.

Let me show you it happening, in real places, to real people. Because once you see it, you cant unsee it.

Your name

Start with who you are.

In Buenos Aires, more than three and a half million people now carry their own identity, their birth record, their proof they exist, in a wallet on their phone. Not a copy the city lets them peek at. The real thing, in their hands, that they control.

And the city built it so cleverly it barely made the news. Normally, to prove youre old enough, or married, or a citizen, you hand over everything, your whole ID, all your data, to whoever asks. Buenos Aires uses a quiet trick that lets you prove just the one fact that matters, yes, over eighteen; yes, a resident, without handing over the rest. Picture a bouncer who can confirm youre old enough without ever learning your name or your address. You prove it. He learns nothing else. The keeper who used to hold your whole identity, and could lose it or leak it, is simply cut out of the middle.

Your home

Remember that family, losing a house to a line of ink? This is the fix.

The country of Georgia, the one by the Black Sea, moved its land titles into a keeper-less record and cut the time to sell a property from days to minutes, and made “sorry, your file was lost” close to impossible. India is doing it at a scale thats hard to even picture. By late 2025, hundreds of millions of government records were anchored into a book no clerk can quietly rewrite. City after city, the same move, taking the ledger out of the drawer.

And once a record gets that solid, something wild becomes possible. In Dubai, ownership got so trustworthy that you can now slice a single apartment into thousands of tiny shares and trade them like nothing. One flat, split into pieces, and a slice of it sold out in under two minutes, to strangers on the far side of the planet who never met, never signed a paper, never had to trust a keeper. They just trusted the book that no one can fake. (That slicing-up of the world’s assets has a name and a staggering scale, I mapped it in Tokenization: The 16 Trillion Dollar Shift.)

Your money

A tiny Swiss town called Zug, smaller than a lot of city neighborhoods, let people start paying taxes in digital money years ago, and told businesses plainly, in writing, how the new records would be treated. It didnt promise no rules. It promised a book you could rely on.

And that alone pulled in builders from all over the world. Because the thing everyone is really starving for isnt hype, and it isnt some coin going up. Its a record they can finally trust without trusting a person. (One entire country, Estonia, put nearly its whole government onto this kind of backbone, I broke that down here. A city is that same move, shrunk to a size that can happen almost anywhere on earth.)

Now the part the sales-people leave out

You deserve the whole truth, not a pitch. So here it is.

Taking the book away from the old keeper is not the same as setting you free. Sometimes the old keeper just gets swapped for a new one, with a friendlier logo, and your money in his pocket.

A few years back, the mayor of Miami launched a city coin and dangled a dream. Buy in, and maybe one day the city gets so rich off it that it stops taxing you. People bought. It soared. Then it fell more than ninety-nine percent and quietly died. It never recorded anything. It never proved anything. It never protected a single home or name. It did exactly one thing, go up, then down, and take real money from real people on the way. That wasnt a book with no keeper. That was a new keeper, in a hoodie, running the oldest trick there is.

Theres a grander version too. Off the coast of Honduras, investors built a private city that runs less like a town and more like an app you live inside. Its own rules, its own courts, pay in Bitcoin, register a company in an hour. Same technology as Buenos Aires. Opposite spirit entirely. One hands the book to the people. The other hands it to a company. The country called the whole thing unconstitutional; the project sued for a sum near a third of the nation’s yearly income. Watch closely and you learn the real lesson. Sometimes “innovation” isnt taking the keeper away at all. Its just becoming the keeper.

The one question to keep for life

So heres the single thing to carry out of all this. The question that will keep you clear for decades, long after youve forgotten every name in this piece.

Whenever anyone, a city, a company, a founder, a government, tells you theyre putting something “on the blockchain,” dont ask whether its exciting. Ask one thing.

Did the keeper actually disappear, or did the keeper just change costume?

Three quick ways to tell. Can you check it yourself, without asking anyone’s permission? A book with no keeper is open to all. A new keeper keeps the key. Does it still protect you if the price of everything crashes to zero? A real record, your home, your name, doesnt care about any price. A new keeper’s coin lives and dies on it. And if it all falls apart, who gets hurt, you, or them? If youre the one who can lose everything while someone else collects, youve just met the new keeper.

No keeper, and youre freer than any generation before you. New keeper, and its the same old chain with a shinier link. That one question cuts through all of it.

Where this is all going

Zoom out, and heres the destination.

Every city that takes its book out of the drawer is doing it in roughly the same way, to the same standards, on records built to talk to each other. Which means, slowly and quietly, the books are starting to connect. Picture a world where your name, your home, your money live in records that no single power, no clerk, no bank, no government, anywhere, can secretly change or seize.

Thats the real thing this newsletter keeps pointing at. Not one currency for the planet, handed down from on high by treaty. Something deeper than that. One earth where proving what is yours finally doesnt depend on trusting whoever happens to be holding the pen. The rails for it are being laid right now, and not from the top, and not from the bottom, but from the middle. From your city.

So stop watching the coin prices. They are the fireworks, not the fire.

Watch your city instead. The morning it moves your deeds, your ID, your records onto a book that no one can quietly rewrite, that is the morning a leash you never knew was around your neck goes slack. It wont make the news. It never does. But it will change, forever, the answer to the oldest question a human being can ask.

When I say this is mine, and this is who I am, who do I have to trust to make it true?

For five thousand years, the answer was: someone else.

For the first time, the answer can be: no one. Just the book. And a copy of it, at last, in your own hands.

If you want to understand where finance is heading before it becomes obvious, Naked Market is where these dots get connected every week.
Subscribe free →

Start here — the pinned welcome post

One Planet, 180 Currencies. Something’s Got To Give.

Keep reading, in this thread

-More soon


The Most Dangerous Person in the World Might Be a Clerk was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

ROFLize an App: Bonus Guide to Features & Troubleshooting (Part 2)

17 August 2026 at 12:42

In this 2-part bonus guide on the features and troubleshooting once you ROFLize an app, the first part covered in detail the marketplace, secrets, and persistent storage. Let’s continue.

Public Variables

You will remember that we learned about secrets for confidential values. But an app may also consist of containers that need to access non-sensitive values and configurations. API endpoints, contract addresses, feature flags, etc are some examples of information that do not have or need any confidential attributes. This is when we use public variables. They are basically arbitrary key-value pairs that are exposed to containers as environment variables.

You can manage these public variables using the Oasis CLI. Take this example where we create a public variable called API_URL.

echo -n "https://api.example.com" | oasis rofl public-var set API_URL -

You will notice that this command only updates the local app manifest file. The public variable, however, is not yet propagated to the app. As a result, you will be able to easily configure as many public variables as you want without having to constantly update the on-chain app configuration.

Once the required public variables are created, you can update all of them in the on-chain configuration using the usual command.

oasis rofl update

The Oasis CLI documentation is useful if you need to consult comprehensive public variable management commands, including importing from .env files, removing public variables, and other advanced features.

Now, inside the containers, the public variables can be passed via environment variables. This is possible because each public variable is automatically exposed in the Compose environment and can be used in the Compose file.

services:
test:
image: docker.io/library/alpine:3.21.2@sha256:f3240395711384fc3c07daa46cbc8d73aa5ba25ad1deb97424992760f8cb2b94
command: echo "API URL is $API_URL"
environment:
- API_URL=${API_URL}

rofl.yaml Manifest File

Before proceeding in this section, let’s familiarize ourselves with the metadata in the yaml root, consisting of these valid fields.

  • name: A short name for your app that is readable by humans. e.g. my-app
  • version: The ROFL version you are using. e.g. 0.1.1
  • repository: A path to the git repository. e.g. https://github.com/user/my-app
  • author: The author name and the e-mail address. e.g., if you are John Doe, then it will show John Doe <john@doe.com>
  • license: The ROFL license in SPDX format. e.g. Apache-2.0
  • tee: The Trusted Execution Environment type that is being used. tdx is the default option, while sgx is also valid.
  • kind: As outlined in the initialization process of the workflow. Valid options for TDX TEE are containers, which is the default, or raw. If you use SGX TEE, then only raw is the valid option.

App Resources (resources)

Each containerized app running in ROFL needs pre-defined resources such as the number of assigned vCPUs, amount of memory, storage requirements, GPUs, etc, for its execution. In the app manifest file, these will be headed under resources.

resources:
memory: 512
cpus: 1
storage:
kind: disk-persistent
size: 512

If you decide to change the requested resources, it will result in the creation of a different enclave identity for the app. Then you will have to update the policy accordingly.

Let’s now see what these resources signify.

  • Memory (memory)
    The amount of memory is specified in megabytes. It is initialized to 512 by default.
  • vCPU Count (cpus)
    The number of vCPUs allocated to the VM. It is initialized to 1 by default.
  • Storage (storage)
    You can choose different storage options for your ROFL app based on its utility. Currently, it can be one of four options.
  1. disk-persistent: When the disk of the given size is persistent, it is encrypted and authenticated using a key derived by the decentralized on-chain key management system after successful attestation. This is what our example shows.
  2. disk-ephemeral: When the disk of the given size is ephemeral, it is encrypted and authenticated using an ephemeral key randomly generated on each boot.
  3. ram: Here, an ephemeral filesystem is entirely contained in encrypted memory.
  4. none: Here, no storage provision has been made. This option is not valid for containerized apps, so you have to choose one of the previous three.

The size field defines the amount of storage to provision in megabytes.

Artifacts (artifacts)

This configures locations of artifacts used during the ROFL build process with builder, firmware, kernel, stage2, container.runtime, and container.compose as supported fields. If any fields are left unspecified, they will use the default artifacts from the CLI. For containerized apps, container.compose points to the Compose file included in the ROFL bundle.

artifacts:
container:
compose: compose.yaml

Deployments (deployments)

This contains ROFL deployments on specific networks.

The deployment you have defined will show as deployment_name.

Deployment artifacts are optional and merged field by field on top of global artifacts.

deployments:
testnet:
network: testnet
paratime: sapphire
artifacts:
container:
compose: compose.testnet.yaml

There are four components to policy under which your app will spin up.

  • quotes: Include TEE-specific policy requirements such as the TCB validity period and the minimum TCB-R number. This helps to indicate what security updates must be applied to the given platform.
  • enclaves: Include permissioned enclave IDs for running your app.
  • endorsements: Include a list of conditions defining who can run the app.
  • any: {} indicates any node can run the app.
  • node: <node_id> indicates only a specified node ID can run the app.
  • provider: <address> indicates nodes belonging to the specified ROFL provider can run the app.
  • provider_instance_admin: <address> indicates machines having the specified admin can run the app.

You can choose one or multiple conditions in a nested format by using and and or operators.

policy.yaml

endorsements:
- and:
- provider: oasis1qp2ens0hsp7gh23wajxa4hpetkdek3swyyulyrmz
- or:
- provider_instance_admin: oasis1qrk58a6j2qn065m6p06jgjyt032f7qucy5wqeqpt
- provider_instance_admin: oasis1qqcd0qyda6gtwdrfcqawv3s8cr2kupzw9v967au6

This example indicates that the app can be run only on the specified provider, and on machines owned by either of the two admin addresses.

  • fees: <fee_policy> specifies who pays for the registration and other fees. It can be either endorsing_node when the node running the app pays, or instance when the app instance pays.

The final piece of this section is machines, where the specific app deployment takes place. If you remember the oasis rofl deploy tutorial, it creates a new default machine if there is no existing machine. If there is one, then the app is redeployed here.

  • <machine_name> is the name you choose for the machine.
  • provider: <provider_address> is the Oasis native address of the ROFL provider hosting the machine.
  • offer: <offer_name> specifies what offer you have chosen.
  • id: <machine_id> is the ID of the machine per provider.
  • permissions are optional, and when present, indicate ROFL scheduler-specific permissions.
  • log.view will list all the Oasis native addresses that can access machine logs.

appd REST API

Each containerized app running in ROFL runs a special daemon called rofl-appd. It exposes additional functions via a simple HTTP REST API. To enable easier access isolation, the API is exposed via a UNIX socket located at /run/rofl-appd.sock.

Let’s consider this example where we have used the short syntax for Compose volumes.

services:
mycontainer:
# ... other details omitted ...
volumes:
- /run/rofl-appd.sock:/run/rofl-appd.sock

ROFL clients

For your ROFL app, it is strongly recommended that you follow the steps to bind the UNIX socket by accessing the ROFL REST API through one of the ROFL clients. You can choose any one of the following languages.

  1. oasis-rofl-client for Python
  2. @oasisprotocol/rofl-client for TypeScript
  3. oasis-rofl-client for Rust

Note: Although the communication with rofl-appd is through UNIX sockets, the REST service still uses the HTTP protocol. In our examples, we will be using the http://localhost/<endpoint_path> format throughout. You are free to provide any name instead of a hostname.

Endpoints

App Identifier is where the endpoint is used to retrieve the app ID.
Endpoint:/rofl/v1/app/id ( GET)
Example response:

rofl1qqn9xndja7e2pnxhttktmecvwzz0yqwxsquqyxdf

Key Generation

Here, each registered app automatically gets access to a decentralized on-chain key management system. Now, the keys can only be generated inside properly attested app instances. They remain unchanged even if the app is deployed elsewhere, or even if its state is erased.
Endpoint:/rofl/v1/keys/generate ( POST)
Example request:

{
"key_id": "demo key",
"kind": "secp256k1"
}
  • key_id is used for domain separation of different keys. It is a unique identifier, with every key ID corresponding to a different key.
  • kind defines what kind of key should be generated. Options include:
  1. raw-256 to generate 256 bits of entropy
  2. raw-386 to generate 384 bits of entropy
  3. ed25519 to generate an Ed25519 private key
  4. secp256k1 to generate a Secp256k1 private key, as used in our example

The generated key is returned as a hexadecimal string.
Example response:

{
"key": "a54027bff15a8726b6d9f65383bff20db51c6f3ac5497143a8412a7f16dfdda9"
}

Authenticated Transaction Submission

This is important if your app is registered with a different chain instead of Oasis. It enables your ROFL app to submit authenticated transactions to that chain. As these transactions are signed by an endorsed ephemeral key, they get automatically authenticated.

This also helps to easily authenticate the transaction origin in smart contracts by simply invoking an appropriate subcall.

Subcall.roflEnsureAuthorizedOrigin(roflAppID);

Endpoint: /rofl/v1/tx/sign-submit (POST)
Example:

{
"encrypt": true,
"tx": {
"kind": "eth",
"data": {
"gas_limit": 200000,
"to": "1234845aaB7b6CD88c7fAd9E9E1cf07638805b20",
"value": "0",
"data": "dae1ee1f00000000000000000000000000000000000000000000000000002695a9e649b2"
}
}
}

Let’s decipher the fields before proceeding further.

tx describes the transaction content. Different transaction kinds are supported as defined by the kind field.

Ethereum-compatible calls ( eth) use standard fields such as gas_limit, to, value, and data.

For gas_limit, you can input a JSON number (as used in the example), a decimal string, or a 0x-prefixed hex string. There should not be any whitespace, and irrespective of the input, it will be interpreted as a non-negative 64-bit integer.

For value, you can input a JSON number up to 2^64 - 1, a decimal string, or a 0x-prefixed hex string. There should not be any whitespace in the string forms, and the value must represent a non-negative integer up to 256 bits.

For hex-encoded fields such as to and data, you can input strings with or without a leading 0x prefix, but there should not be any whitespace or prefix-only input. Empty strings are accepted for contract creation or empty calldata, e.g. to: "" or data: "". If you are providing input for the to field, it must decode to exactly 20 bytes representing an Ethereum address.

Alternately, Oasis SDK calls ( std) support CBOR-serialized hex-encoded Transactions to be specified.

encrypt is a boolean flag specifying whether the transaction should be encrypted. This field is true by default. When an ephemeral key is being used, the encryption is handled transparently for the caller, and any response is first decrypted before being passed on.

Now, as the outcome of the example request, the example response inside data is generated as a JSON response containing a CBOR-serialized hex-encoded call result that you will need to deserialize.

If the call result is successful:

{
"data": "a1626f6b40"
}

It deserializes as {"ok": ''}.

If it is unsuccessful:

{
"data": "a1646661696ca364636f646508666d6f64756c656365766d676d6573736167657272657665727465643a20614a416f4c773d3d"
}

It deserializes as {"fail": {"code": 8, "module": "evm", "message": "reverted: aJAoLw=="}}.

Replica Metadata

This allows apps to publish arbitrary key-value pairs included in the on-chain ROFL replica registration and automatically namespaced with net.oasis.app.

  • Get Metadata: With this, you can retrieve all user-set metadata key-value pairs.

Endpoint: /rofl/v1/metadata (GET)
Example response:

{
"key_fingerprint": "a54027bff15a8726",
"version": "1.0.0"
}
  • Set Metadata: With this, you can set metadata key-value pairs to replace all existing app-provided metadata.

Endpoint: /rofl/v1/metadata (POST)
Example request:

{
"key_fingerprint": "a54027bff15a8726",
"version": "1.0.0"
}

The parameters for metadata validation are the number of pairs, key size, and value size.

  • Upsert Metadata: With this, you can input or update metadata key-value pairs. However, if you did not specify it in your request but there is existing app metadata, that will not be affected.

Endpoint: /rofl/v1/metadata (PUT)
Example request:

{
"version": "1.0.1"
}
  • Delete Metadata: With this, you can delete given metadata keys, while keys that no longer exist will be skipped.

Endpoint: /rofl/v1/metadata (DELETE)
Example request:

["version", "key_fingerprint"]

Whenever you use Set, Upsert, or Delete Metadata, any change in the metadata triggers a registration refresh.

Query

This runs arbitrary query methods defined in the Oasis Runtime SDK module and returns the result.

Endpoint: /rofl/v1/query (POST)
Example request:

{
"method": "rofl.App",
"args": "a16269645500694cb01f85408d624ea267f657bf285787a61db3"
}

Here, method refers to the internal name of query methods; in our example, it is rofl.App. You will recognize query methods by the #[handler(query = "...")] annotation in the Oasis Runtime SDK source.
args represent query parameters for the method serialized as CBOR and hex-encoded.

Example response:

{"data":"a76269645500ffe981cceff2d759d19fa926faebb7d90c0a59a56373656b582056c6d4841fa5ad24ad761088cb7053ad312ef13f3c2f405640fdba2bde4c14386561646d696e55007814f3d954f41b6459eb9e4bc8fbc6767ece5aa9657374616b658249056bc75e2d631000004066706f6c696379a56466656573026671756f746573a263696173f663706373a363746478a173616c6c6f7765645f7464785f6d6f64756c657380737463625f76616c69646974795f706572696f64181e781e6d696e5f7463625f6576616c756174696f6e5f646174615f6e756d6265721268656e636c6176657382a2696d725f7369676e6572582000000000000000000000000000000000000000000000000000000000000000006a6d725f656e636c6176655820bd4844a79a12ba365e890ddeaebbc4e4292797c7d956b42c2e25e4aefce3b124a2696d725f7369676e6572582000000000000000000000000000000000000000000000000000000000000000006a6d725f656e636c6176655820412c94a9baa0949f718dbba41ab89c38ea5c320345bba36b07e2ef857ffe2fb96c656e646f7273656d656e747381a163616e79a06e6d61785f65787069726174696f6e036773656372657473a26a50494e4154415f4a5754590327a462706b58207f88546291174f854a8ce2eb4bbfc8e62e40d60cdae2d600920a766d3006bf6c646e616d65581aad0460d0f742ad697b6d7c8462cc2b153deeb051a791553ef52b656e6f6e63654f8cbbe6631910d9a702e49bd30ee8f46576616c75655902c1352d823e54f75c846579066e2c1a750387f0630e3f29dba5524984712883bb33371ff017e507ae432b135312af64bfb85f3b17def05b2ac2744256f5accf1a26b29cd8cd412f08bfc9204f9bfa670b2d65972cfc4a8d4e2074402f21c18dfe554b1f0a8a731c077699f741807b3a4047ef4dc570958b8b46111a445259e93c9b92a5f72a23d32cbbef875efe586a8ddda38f1fa286d19b369a2022c3eae1cdbf6f6de4dc055bbab36a2c4830f8e2c64437f5f878f419e21f3a4c0f13c47b63697668b34722eaa61bdffa12e82be6d0266a41590254c9d70e9237475f6115c2867065c49afa8032acdfe0bc5dc671ef48ebc58d893937659243479e2eaa38815cd8665541e4c7e40349524cda15f2d410cba100ee27f0a59dc63534f7cff2444b57c7b74060cf8c3e21e1590b597384a89a463d6bb4a52fc52a4592889448a8f8e0c02fef1689c1efea58ddc08783f6d22d7a908cdf2a45bc46a79a3b73ff5f13bbbf7219973a7382eee84b3b4d48036b5e87fb24223e6387a3e37f9c1ac9722534adfef0201ec13db2e70fe9cd0336f020e50b59d7d32951378f568a4ef3a8117386ff0f1ba4b7d33dcf913daa696a6a7d64d20220b0e5eec994ea56aa9c01f56f5e12bf7d555b3f4a218ddbd8ae1586d5cb1e76802c90e26472b233686e8449284829378163acd77d1b65d4953a76cc497584580c1a5ac4fe6d97fd818fa53c2eb43c6f1b7a79211ef57f24036b1f8ed37f4c3d36873bbbd876769a5fde17add6926317afc96c9707e10b150735c63877ffd6475b1a27b6dd108940f0097375e422b1d308c6c8a0a83847368f5760778c54f2a70b44f9365c55c4b5d69341cad62d6fdb11aa25a9e26b4977adebd65718042bda1cbbf988298d293547107c2f5899352188179bc4d22febc66e8e351885498e707dee583d052c0b7c13f930e4529b59c36c20ee3ee6d29d1a3e2bb65bd489b7206cd45d2ae046f1e147d6407c166e494e465552415f4150495f4b45595899a462706b582074be2e227be81a5e35943ac1b79e238395b9bc367f7a0d1eed740c259ae23a37646e616d65581ee5190cda87688753f6f221890bfed8fe0e27b3ced4a9bc54537da1f4cd90656e6f6e63654fcf5411193abf4f4711f17179ea4b6f6576616c756558304675a29c8398bc94b5057063b4badeb9937a6e019ef7f8095d6b5a035106d4e8e7d710af9b6883848886481c1d180cbc686d65746164617461a7736e65742e6f617369732e726f666c2e6e616d656f76616c696461746f722d6167656e74756e65742e6f617369732e726f666c2e617574686f72782a4d61746576c5be204a656b6f766563203c6d617465767a406f6173697370726f746f636f6c2e6f72673e766e65742e6f617369732e726f666c2e6c6963656e73656a4170616368652d322e30766e65742e6f617369732e726f666c2e76657273696f6e65302e312e30776e65742e6f617369732e726f666c2e686f6d6570616765784f68747470733a2f2f6769746875622e636f6d2f6f6173697370726f746f636f6c2f6572632d383030342f626c6f622f6d61737465722f524541444d452e6d642376616c696461746f722d6167656e7478196e65742e6f617369732e726f666c2e7265706f7369746f7279782968747470733a2f2f6769746875622e636f6d2f6f6173697370726f746f636f6c2f6572632d38303034781a6e65742e6f617369732e726f666c2e6465736372697074696f6e787f4c697374656e7320746f2056616c69646174696f6e52657175657374206576656e7473206f6620746865204552432d383030342076616c69646174696f6e20726567697374727920616e642076616c696461746573207768657468657220746865206167656e7420697320706f776572656420627920524f464c205445452e"}

Inside data, the JSON response contains the CBOR-serialized method's return value in hex format.

If you want to try other examples, you can check out the relevant section of the ROFL demo repository for querying with curl directly.
There is also a production-ready Python example at hand — in the ROFL-8004 implementation where the query endpoint is used to fetch various app on-chain metadata for registration in the ERC-8004 identity registry.

Port Proxy

When you publish a port in your compose.yaml file, the ROFL proxy automatically makes your services accessible via public URLs. It also ensures the routed traffic is done correctly.

This uses TLS, which is terminated inside your ROFL enclave, maintaining confidentiality and integrity protection. As a result, even the provider cannot see or modify the traffic. Moreover, the default terminate-tls mode generates and configures a Let's Encrypt certificate in ROFL to authenticate your services.

To enable the proxy and expose a port from your container, you need to publish it in your compose.yaml file.

compose.yaml

services:
frontend:
image: docker.io/hashicorp/http-echo:latest
ports:
- "5678:5678" # Expose container port 5678 on host port 5678

After deploying your app, you can find the generated URL by running the usual command.

oasis rofl machine show

The output generated in this way will show a Proxy section with the public URL for each published port.

Proxy:
Domain: m602.test-proxy-b.rofl.app
Ports from compose file:
5678 (frontend): https://p5678.m602.test-proxy-b.rofl.app

Configuration

You can use the annotations in your compose.yaml file to configure the proxy behavior.

The general format of an annotation is net.oasis.proxy.ports.<published_port>.<setting>: <value>.
Here,<published_port> is the external port exposed in your compose.yaml, and <setting> indicates the specific proxy configuration like mode or custom_domain.

Example:
Here I will configure port 80 to use the default terminate-tls mode with a custom domain and port 8080 to use TCP passthrough.

compose.yaml

services:
myservice:
image: docker.io/my/service:latest
ports:
- "80:80"
- "8080:8080"
annotations:
net.oasis.proxy.ports.80.custom_domain: mydomain.com
net.oasis.proxy.ports.8080.mode: passthrough

This shows:

  • The application container exposes ports 80 and 8080.
  • On port 80, the proxy terminates TLS for mydomain.com and forwards traffic to the application container.
  • On port 8080, the proxy forwards the raw TCP connection to your application container (mode: passthrough).

Annotation Reference

net.oasis.proxy.ports.<published_port>.mode defines how the proxy should handle connections for the specified port.

net.oasis.proxy.ports.<published_port>.custom_domain assigns a custom domain name to the published port.

Here, when using the default terminate-tls mode, you need to use special configuration for your custom domain to route through the proxy. Once the app is deployed, you can use Oasis CLI for instructions to configure A and TXT records in your DNS.

oasis rofl machine show
Proxy:
Domain: m897.opf-testnet-rofl-25.rofl.app
Ports from compose file:
5678 (frontend): https://demo.rofl.build
* Point the A record of your domain to: 131.153.241.25
* Add a TXT record to your domain:
oasis-rofl-verification=4SKHCn4E2SNDB5tXayQeHZsvH/+kJSNGuQaTAPepYJc=

If you choose to go with passthrough mode, the proxy will not terminate TLS and your app will then need to handle it directly. Also, here the custom_domain setting is not needed, so you can configure the domain directly to the ROFL instance's address.

For the ignore mode, the port isn't published, so the custom_domain setting has no effect.

Troubleshooting

Here I will cover some common errors and the troubleshooting process.

Compilation

Sometimes you will see an error message if the aes and ssse3 compiler flags are not enabled during compilation of your SGX and TDX-raw ROFL.

error: The following target_feature flags must be set: +aes,+ssse3.
--> /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/deoxysii-0.2.4/src/lib.rs:26:1
|
26 | compile_error!("The following target_feature flags must be set: +aes,+ssse3.");
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

The workaround is to add default flags to your .cargo/config.toml file.

[build]
rustflags = ["-C", "target-feature=+aes,+ssse3"]
rustdocflags = ["-C", "target-feature=+aes,+ssse3"]

[test]
rustflags = ["-C", "target-feature=+aes,+ssse3"]
rustdocflags = ["-C", "target-feature=+aes,+ssse3"]

Compose file

A couple of errors are possible here due to an upstream podman compose bug.

The first is when environment variables defined are not considered.

services:
oracle:
platform: linux/amd64
environment:
CONTRACT_ADDRESS: 0x5FbDB2315678afecb367f032d93F642f64180aa3
entrypoint: /bin/sh -c 'python main.py $${CONTRACT_ADDRESS}'

In this type of error, the CONTRACT_ADDRESS field will return as empty in ROFL. You need to inject the variable value directly inside entrypoint as a workaround.

services:
oracle:
platform: linux/amd64
entrypoint: /bin/sh -c 'python main.py 0x5FbDB2315678afecb367f032d93F642f64180aa3'

The other type of error that may occur is when depends_on is ignored.

services:
contracts:
image: "ghcr.io/foundry-rs/foundry:latest"
platform: linux/amd64
volumes:
- ./contracts:/contracts
entrypoint: /bin/sh -c 'cd contracts && forge create'

oracle:
platform: linux/amd64
entrypoint: /bin/sh -c 'python main.py'
restart: on-failure
depends_on:
contracts:
condition: service_completed_successfully

In this type of error, instead of oracle spinning up once the contracts service successfully deploys the contracts and finishes, they start in parallel by ignoring the depends_on command.

There is no immediate workaround as of now. You can try to implement customized logic in your oracle service to crash it, and then trigger the restart mechanism and try again.

appd

If you encounter the 422 Unprocessable Entity error, when the provided request couldn't be decoded, you need to ensure all the required fields are present and correctly formatted in accordance with the appd REST API section described above.

ROFL Proxy URL is not working

Sometimes the app might be using outdated artifacts, which will result in the proxy URL returned by oasis rofl machine show being inaccessible. This is easily fixed by updating to the latest Oasis CLI version. The next step is to run oasis rofl upgrade in your project directory to update the artifacts in your rofl.yaml file, and finally, rebuild and redeploy your app.

oasis rofl build
oasis rofl update
oasis rofl deploy

This concludes our 2-part bonus guide describing the various features for your ROFL app, and some common troubleshooting hacks. Looking forward to your feedback in the comments section.

For technical specs, APIs, architecture, and integration guides, the Oasis documentation is your starting point.
For direct support on specific issues, the Oasis engineering team is available in thedev-central channel on the official Discord.

Originally published at https://dev.to on August 14, 2026.


ROFLize an App: Bonus Guide to Features & Troubleshooting (Part 2) was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

❌
❌