# Building Under CROPS: the Ethereum Mandate | ETHSofia 2026

- Channel: [ETHSofia](https://streameth.org/ethsofia)
- Date: 2026-10-06
- Duration: 28:20
- Topics: 0xbow, Blockchain Week Bulgaria, CROPS, Cyber Resilience Act, ETHSofia, ETHSofia 2026, Ethereum, Ethereum Foundation, European Ethereum Institute, Mike McCabe, Optimum, Sajida Zouarhi, Sofia Sukhinina, Vyara Savova, censorship resistance, open source, privacy, Science & Technology
- Watch: https://streameth.org/watch/yt-0LzuNOlUFFg
- YouTube: https://www.youtube.com/watch?v=0LzuNOlUFFg

## Description

With Vyara Savova (European Ethereum Institute, moderator), Mike McCabe (0xbow), Sofia Sukhinina (Ethereum Foundation) and Sajida Zouarhi (Optimum).

In March 2026 the Ethereum Foundation published a mandate committing to censorship resistance, open source, privacy and security (CROPS). Moderated by Vyara Savova, this panel asks what that means in practice. Sofia Sukhinina explains the walk-away test and why the Foundation aims to shrink its own role, Mike McCabe describes how 0xbow screens deposits by source of funds while keeping user transactions private, and Sajida Zouarhi discusses patents, open source and Optimum's MIT-backed technology. The panel also covers verifying open-weights AI, the EU Cyber Resilience Act, and the censorship risk from block building, where roughly three quarters of blocks come from two builders.

Panel at ETHSofia 2026, 24 September 2026, Sofia Tech Park, Sofia. Part of Blockchain Week Bulgaria 2026.

Speakers

▸ Vyara Savova, Senior Policy Lead, European Ethereum Institute (moderator)
Vyara is a web3 & human rights lawyer based in Sofia, Bulgaria. Senior Policy Expert at the European Ethereum Institute, shaping EU regulation for open, permissionless, decentralised blockchain applications. PhD candidate researching legal automation through smart contracts.
LinkedIn: https://www.linkedin.com/in/vyarasavova

▸ Mike McCabe, Product Lead, 0xbow
Mike McCabe is Product Lead at 0xbow. After building blockchain enterprise applications for the energy industry for several years, he realised onchain privacy is an essential missing building block in the tech stack. Since then, Mike has been putting all his effort into making privacy normal again.
X: https://x.com/0xmikemcc

▸ Sofia Sukhinina, Funding Coordination, OSPO Researcher, Ethereum Foundation
Sofia is an OSPO researcher working on understanding open source funding infrastructure and ways to improve it. She explores whether dependency-graph-aware funding on Ethereum rails could reduce frictions in current financial mechanisms, making the funder-to-beneficiary path more direct.
LinkedIn: https://www.linkedin.com/in/sofia-sukhinina
X: https://x.com/sonkiski

▸ Sajida Zouarhi, Chief Product Officer, Optimum
Sajida Zouarhi is Chief Product Officer at Optimum, building the universal data acceleration network for blockchains using RLNC. With 10 years in Web3, she previously led product at Blocknative and on the Ethereum client Besu at ConsenSys through the Merge.
LinkedIn: https://www.linkedin.com/in/sajidazouarhi

Chapters
00:00 Introduction
00:10 What is the CROPS mandate?
01:10 The walk-away test: a Foundation that steps back
06:02 Does CROPS apply beyond Ethereum?
07:34 Censorship resistance and privacy at the protocol level
10:47 Privacy versus compliance
12:49 Open source, patents and protecting inventions
16:58 Verifying open-weights AI with Ethereum
19:11 The Cyber Resilience Act and open source
22:00 Where censorship happens today
23:44 Block builders, relays and OFAC compliance
25:46 What the panelists will not compromise on
28:05 Closing titles

Blockchain Week Bulgaria: https://www.blockchainweek.bg
ETHSofia: https://www.ethsofia.com
Future Finance Forum: https://www.blockchainweek.bg/f3

Follow Blockchain Week Bulgaria
X: https://x.com/BWBulgaria
LinkedIn: https://www.linkedin.com/company/blockchain-week-bulgaria

Follow ETHSofia
X: https://x.com/EthSofiaBG
LinkedIn: https://www.linkedin.com/company/ethsofia
Telegram: https://t.me/+b-33LJUpAB5iODNk

Nothing in this video is financial advice.

About the organiser
Blockchain Week Bulgaria, ETHSofia and the Future Finance Forum are organised by the Bithope Foundation, founded in 2014 by Vladislav Dramaliev. Inspired by Andreas Antonopoulos, it is Europe's first non-profit operating exclusively with bitcoin donations. Over more than ten years, it has supported 50+ charitable campaigns, and in January 2016 it co-founded the Sofia Crypto Meetup, now the region's longest-running monthly crypto event.
https://bithope.org

## Transcript

[music] Thank you. Thank you so much. Uh thank you also for the brilliant introduction. It really cuts some of my uh work when also introducing this panel now. But just out of curiosity, out of the audience, how many of you have heard about the crops mandate by the Ethereum Foundation? Okay. So I hope there will be more of you raising hands after the panel and that you'll know more about it. Um so as as was already said it was uh a mandate a document quite interesting document that was published this March and indeed it introduces the crops framework which stands for censorship resistance open source privacy and security. So now that we have the framework, the next question is what are we going to do do about it and with it in practice. So that's why here on the stage we have this brilliant group of people that are going to now go more into the details of what that would mean in practice. And now without further ado, I'll give the floor to Sophia who perhaps can tell more about um what that means and particularly this very interesting aspect of the mandate which states that if successfully implemented this would mean that the the work and the role of the Ethereum foundation will get minimized. So, interestingly enough, not we don't often see something coming from a foundation even where they're saying we are introducing this so that uh we won't exist in the future. So, what does that mean and tell us a bit more about also your work? &gt;&gt; Can you hear? Yes. Hi everyone. My name is Sophia at the city of Bulgaria which is fun. Uh super happy to be here. So I work um on the funding coordination team at the foundation and uh for funding coordination. &gt;&gt; Can you hear me now? Yes. Perfect. Um so yes I work um on the funding coordination team at the Ethereum Foundation and what it means for our team the mandate basically our team is here to help to pass so-called the walk away test. So we are the more successful we are in passing that the less Ethereum foundation needs um has a role in uh Ethereum core development and maintenance. So um to give uh sort of a longer answers funding coordination uh team is the mission of this team is to um understand and create funding mechanisms uh for the Ethereum ecosystem uh from Ethereum and beyond and I work on the beyond part. So I'm actually working on O in crops. I work with the broader open-source community and industry where first I need to find uh the ways how we can use Ethereum for open source. So um basically finding new use cases for different industries beyond crypto. And then the second um goal uh that is connected to that is that how can we also get the funding into Ethereum ecosystem for public goods for as I mentioned core development and maintenance um from open source funding programs from for example governments philanthropic funds uh from bigger companies that support open source or sort of payback to the community etc. Um so yeah for us subtract sub subtraction as a success means that funding flows from multiple sources. So within the Ethereum ecosystem it will be through the centralized finance mechanisms and uh from other industries such as open source through the open source grants uh funding programs etc. Um maybe going a little bit more philosophical here. Um, so the organizations tend to stay forever. They want to stay forever and and sort of an instinctive level and I can't blame them. And we sort of did that historical mistake as well as the Ethereum Foundation where we maybe stayed for too long uh being the only steward in the industry uh for certain things and it's kind of like the problem is the the problem here is crowding others out. So why would we step up if there is an Ethereum Foundation that would solve a specific problem? So basically I think the main goal for the Ethereum Foundation would be to do things that we think are still needed to be done um that were not done yet and also to help others to step up and we see the change recently that is happening uh for example yeah in the previous years but in this year uh we've seen it quite a lot that we have new stewardship um companies that or organizations that uh carry stewardship roles uh for example we have um if labs uh responsible for R&amp;D institutional privacy if systems um if you're institutional for institutional relations etc etc and we think that uh this is the right way to go that there is multiple sort of points of contacts where um you can go and ask for a specific help and I also the reason why I hold this phone is to quote the mandate itself because I think the way how others are described there is is very beautifully put. So uh we call them loyal friends since the beginning and the new travelers who have discovered the infinite garden. So we welcome you all to contribute to Ethereum to help us build uh better um more resilient stronger Ethereum uh rather than abandoning it. &gt;&gt; Thank you Sophia. That's very uh I think a very good background for us all to kind of have a better understanding of what has been proposed. But I also want to zoom out a bit and go beyond Ethereum and s ask you in this case because you have been developing like writing different um on already on different chains uh and now you're also considering this as a more multi-chain as well approach. So do you think the crops like this ideas do you think they would have a broader representation also in other chains or is it something specific for Ethereum? &gt;&gt; Yeah. Um good question. So I I think crops is like specific mandate that Ethereum pushed out but it doesn't limit itself to Ethereum. I think any uh any project that is aiming to build a decentralized system or network has to strive to reach uh crops ideal. Uh for me it's not like a binary sync like either your props or not. Uh it's rather um desirable properties that you're trying to achieve in the system and then you have to make some trade-offs along the way. Uh one thing that is maybe uh sort of the the the other face of crops is also uh business viability u solving actual pain points and time to market. So how do you balance some of the ideals and engineering principle that you want to see in your blockchain with actually being a relevant network and solving issues for the people right now? &gt;&gt; Thank you. Yeah. Uh, I have many follow-up questions for you ladies, but let's give it to the only male participant in this panel. And here I need to actually um stop for a second and say that it's I think one of the first times that we have so many women on a panel uh at this very specific technical um kind of Ethereum conferences and technical blockchain conferences which I think is a very good uh thing to have. But Mike, uh, tell us about censorship resistance and privacy and why why is it so important? Because I know that's what you are focusing on in your work. Um, why is it so important that it's on the protocol level and what are the concerns in this? &gt;&gt; Yeah. Uh, you guys can hear me great. &gt;&gt; Um, so on a protocol level, I think I think the crops mandate makes total sense. I mean if Ethereum wants to be neutral settlement infrastructure then you need to have censorship resistance because everyone needs to be able to transact on it. If you start let's say censoring choosing sides almost then that whole kind of like idea of Ethereum as neutral settlement infrastructure kind of like disappears right &gt;&gt; um &gt;&gt; and so I think that is that is very important um but I do not think it applies so much to the application layer or um I think it is a bit naive to to think that censorship resistance applies to the application layer. um you only have to look at like the tornado cache president um where these developers have just like created a fully decentralized application right without any control over the contracts or code anymore. Um yet they are still already for like four or five years being persecuted in like different countries for for what they've built. Um and you know we are living in like a multipolar world and it is only um getting more extreme and sanctions is something that nation states take very seriously and if you as a developer uh publish something that um a sanctioned entity uses regardless of your intentions regardless of whether it is mutable or not. If a nation state deems that illicit, they will come after you and it puts you at great personal risk. So it is really like um I think important almost at the application layer to protect yourself as a developer to essentially not go to jail. Um and then privacy the other part is is I think uh a more obvious one right like currently on public ledgers everyone can just see all of everyone's activity like if you use one of those crypto uh bank cards or credit cards it is so so easy to to derive your basically entire economic economical profile from just like your wallet address. Um &gt;&gt; this should not be the default. uh your transactions should be private and we have the technology to do so and so um yeah I think that making Ethereum private making private transactions more prominent is is a very obvious thing to pursue. &gt;&gt; I absolutely agree. Um but um if if I am to go into more into the role of the devil's advocate here and also citing something that we hear as well quite often in our work is what about compliance? What about financial compliance? What about AML compliance and how do these two aspects privacy onchain censorship resistance as well go along with compliance? &gt;&gt; Yeah. So um as a general rule of thumb, nation states or like your government hates privacy. Um and so especially when you are doing anything in privacy, you have to be very very wary of what your government deems as a good and a bad thing because if you do bad things according to your government, um they can have very bad consequences for you personally as I said. Um so yeah um I am based in the Netherlands. We are based in Europe. uh we we follow as a privacy protocol. We essentially have a gatekeeper on our privacy protocol where if someone deposits into our pools we uh check what the source of funds is and if we can trace that to let's say a Coinbase or a Gemini or in the Netherlands Bit Favo then we know okay this user has KYC there at a reput reputable financial institution that has sufficient KYC and AML standards um that align with our governments um we can safely let this person into the pool. Uh but I mean there were also like I mean Lazarus is a bit big th F th F th F th F th F th F th F th F th F th Fred actor in the space right and um they are very sophisticated in the tooling and the tooling that they use and the things that they do and so we are we are very wary of any of let's say Lazarus deposits coming into our pool then um we would we would definitely decline those funds from comingling with our pool and they would only be able to withdraw back to their depositing address and thus not receive any privacy. So, our main goal is really to to keep our pool clean of any sort of illicit actors, whether that be like hacks, scams, extortion, whatever. Sounds great. And now that I have you here, I'm going to go into another topic of my um kind of close interest, which is open source. So, this one is for both of you. And don't worry if there is a bit of attention in in your response. I like a panel that gets a bit spicy. Uh but no pressure. Um but let's talk about open source and the role of open source and especially now with AI being the hot topic of the year of the decade let's say how does your work also align on that and what's the kind of role of open weights and kind of thinking about open source in a broader sense so that's probably more for Sophia but Asash for you because I also know that there is a quite a good reason why we also build closed source so is there really a tension and is that a really a decision that needs to be re really well uh thought of at first and what are the pros and cons if don't kind of be shy to talk about practicalities here it's a tech conference so just your hot take on that sure &gt;&gt; I don't know who wants to go first &gt;&gt; I mean the answer is quite short right like the um so open source is um driver of innovation so the more things are open the more people are you know able to collaborate and build on top of it. So it's desirable. &gt;&gt; And then there's the economic reality. So for example, if you take a patented tech that has come from, you know, decades of research that was funded by uh entities such as universities, there needs to be a model where that makes sense for them, right? So if after I don't know paying for the studies of many people and paying salaries of researcher they end up finding something pretty pretty cool and that has commercial application. This needs to sort of go back to fuel the system so that the next generation is also going to be able to do that research. For that to work if there is a commercial application there there needs to be a way to protect the invention. So that's why you can find uh some of this patented tech even in blockchain systems today. Uh however, the real tension is more about how um inspectable, auditable, interoperable your tech is. So how do you protect your invention but uh not own the network that you're uh building with it? something that we're dealing with also at optimum because optimum the company I work at is um quite backed in academia and the core technology that we're using is based on you know MIT invention from our co-founder Mural Medal and others and this is like the core so although the surface of the code is quite large and this is just one component it is a component that is important for builders to know about in the blockchain space but that doesn't prevent anyone from you know participating ing in the network in the future from building on it for building new services and application. So there is uh a point here to keep in mind but I don't think it is an opposition with blockchain values. &gt;&gt; Yeah. &gt;&gt; Yeah. Yeah, it's a good take. But um protecting your work, what that was very interesting because I feel like protecting your work in open source is really hard. Like anyone can fork whatever you're building and this is the sacrifice and the trade-off you make when you're building an open source knowing that when you share information openly and freely will be used and nobody will pay you back. So yeah, I totally agree with that. Um, however, open source building an open source is an ideological position. I I must say it's a moral good morally good thing to do if you decide to share information openly. That doesn't mean that you can't make money on open source. Um, you can build services around it. Um, you sell reputation, some yeah, I don't know, support uh for it. Um, in the open source industry, we see it quite a lot that uh there's uh some companies selling solutions to enterprise customers that are open source, but they just kind of like providing insurance uh that um this software is going to run and it's going to run uh correctly. But another interesting topic that you touched is about um the product the software being verifiable. So this is a a work stream that I'm currently working on and uh I'll give you a sneak peek on it because I just started working on this research but essentially open weights AI that's the topic that you mentioned and I wanted to touch upon that. So open weights AI sits in a great zone in a gray um area zone. I call it semi-open because um we can use AI models that are uh built on open weights. Uh we can build on them, we can inspect them, but what is the data behind it that it's been trained upon? We don't know. And uh that's an interesting challenge for Ethereum technology. I would say um verification. How do we verify without for example revealing all the data that that data exactly was used? How do I for example as an end user verify that um if I'm buying an inference provider space inference provider and I want it to be sit in the specific geographical location that that is exactly the geography that I can promise me. Um for now it's just a line on the UIX basically it's just a line on the website. Yeah we are sitting here and we will give you that open-source open weights model. uh but apart from that nobody can verify that and uh the thesis the the hypothesis that I'm working on right now is that Ethereum could potentially serve as a trustless coordination layer that would include multiple things uh payment rails um the whenever you can um attest certain claims against one another uh verify certain information in the shared infrastructure with one another and uh that would not require single controlling body or a vendor single vendor's infrastructure. So um if you are interested in um hearing more I'll be sharing more information is more I travel to different conferences but uh that's kind of like the um the work that I'm doing at the moment seeing if Ethereum has a place um in all of that. Yes, thank you for sharing more about that and because I'm in a very um I would say good position of also picking inside a bit what the EF is doing uh because of my role at the European Ethereum Institute. Basically, we're the policy arm more or less of the Ethereum um ecosystem. Um and I know for a fact that you're also working a bit on compliance in open source. I don't know if you feel like sharing a bit uh also about that. I think it's a very interesting use case as well. Yeah, that's a good question. So, compliance is a very hard challenge for open source because for example, one another work stream that I am still working on um is regarding the new law that is um um in the Europe that was introduced in the European Union back in 2024, but finally it will be fully introduced in December next year. It's called Cyber Resilience Act. I don't know if you've heard of it before, but essentially every software that is going to be sold in the EU market would have to go through specific cyber security checks and uh would have special vulnerability tracking system um in place. So that is all to protect EU citizens so that they use better software. However, it kind of like contradicts the principles that open source has been bu build upon because now open source developers would have to um explain what they what kind of components they used uh in their product and they would have to provide it to a single controlling body that would probably be the institution. So um yeah there is no kind of like free component in open source anymore and they would have to comply to every little check and that's also similar to open AI I'm looking into the role of Ethereum for that Ethereum as um trustless in that case authentification and attestation layer where again the open source maintainers can attest that these are the components that they've used in their software and they can attest to the upstream main um dependencies. So those that are using um their open source uh their open source products and uh they can do it in a sort of decentralized um trustless way uh without having a single controlling body there. Um but yeah, that's still work in progress. Same is with AI. But as you can see here, I'm kind of like um trying to use Ethereum for other use cases beyond crypto so that we can be put on the same pedestal as other open-source critical infrastructure uh components and products and then essentially the role of funding coordination is of course around funding so that we can uh also ask for funding from um other programs and mechanisms uh that work beyond crypto. Thank you for sharing that. And Mike and Sash, going back to the censorship topic, also a very interesting one, I think. Um, what are the main censorship risks at the moment? Where where does censorship occur at the moment? And aren't you worried that what you're building at the moment might create the next choke point when it comes to censorship? How do you tackle this? It's a bit of an uncomfortable question. Sorry for that, but I think it's also interesting to share more. I don't know, Mike, if you want to start. &gt;&gt; Sure. Yeah. Um, I mean, as I said, we employ censorship ourselves. &gt;&gt; Um, it's not because we really want to do that, but it's just because we have to be realistic about the environment that we build in. &gt;&gt; Um, as we can see, we've seen in the past, there has been uh very heavy law enforcement actions uh against builders of privacy protocols, especially on Ethereum. Um, building these tools is is is a risky thing to do. It's really as simple as that. And um, it's really for your own protection almost where you basically have to draw a line somewhere and be like, "Okay, well, I'd live in a specific jurisdiction." And this specific jurisdiction does not do business with Iran or North Korea. And so, um, if I do that, I'm in big trouble. And so I need to design my system in such a way that um I employ some forms of censorship that prevent that from happening. And so it's not something we like to do. Uh but it's something that is unfortunately necessary. So um yeah, we have to say we're reluctantly compliant. Um we'd rather have anyone be able to use our protocol, but um unfortunately this just not really the reality that we live in. I mean I think um the trap would be to think for example of Ethereum to think that because Ethereum is quite decentralized that we have less risk of censorship and not looking at the supply chain that leads the transaction to get included on chain because uh it is true that Ethereum today is the most decentralized network. So it's succeeding on that front. Uh however if you look at uh you know who are the actors that uh built the block which contained the transaction that landed on chain practically three quarter uh are only produced by two actors. &gt;&gt; So here you have a a source of censorship of uh I would say even choke point to to to the the comments you made. The good thing is that if they were to disappear it wouldn't help the chain. other builders could come in and start building block and actually validator themselves also uh although less lucrative for them they could build the block. So it's just an economic thing. Um we are un underestimating how certain actor might reintroduce censorship vectors by chasing a rational economic incentive. So at the end of the day it's people making decision and if those people want to use for example you know me uh I would say flavor tooling because it's better for them and for their business then that's going to lead to more you know censoring. So relays actually for the OFAC point that you are making earlier is we're filtering transactions. I think even today onethird of the um you know payloads that are getting onchain are coming coming from OFAC compliant relays. Doesn't mean that everything is censored just mean that those relays has adeared publicly to being of fact compliant so that the validators integrated with them you know would check the bugs that they need to check on the compliance front for the institution and the capital holder that they work with. So it's all connected and at the end you know have to look under the the cover a bit. Thank you for this. And now we unfortunately have to wrap this up. And usually when I wrap up a panel like in previous years I was asking what are you optimistic about? But now I don't want to turn this into a kind of a session um like mental health uh support session. So I'm going to ask you what are you not willing to compromise on when it comes to your work and your like the projects you work on the the part partners you partner with. Uh very briefly just one sentence, one word. Um start with Mike. &gt;&gt; Uh yeah, for us it's actually quite simple, which is like the privacy of our users. Um there are a lot of other privacy protocols that are like pitching compliant privacy, but it's like compliant privacy with like a global viewing key where like one admin can like see everything. Variations of that with like selective disclosures, these sort of things. Um, I mean, I don't trust that kind of privacy myself. I would never use that kind of privacy myself. So, uh, one thing we would never actually compromise on is like self custody and like your transactions actually being private. Um, yeah, we'll die on that hill. &gt;&gt; Sophia, how about you? &gt;&gt; I'll go personal here. If something or someone contradicts my values, I think I'll just step up. Step down. Does matter the size of the opportunity. Yeah, I think for me it would be the sort of exit path like if you're really uh serious about building an open network that you know aderes to let's say crops value you need to make sure that you're not building dependency so that you know if you were to disappear you know could be a for example EF as an actor could be a private company or whoever has been you know the inceptor of that network if you were to disappear that network still functions without you so you're not holding anyone hostage after having deployed this at scale Thank you for this. Thank you for this amazing panel. Unfortunately, we don't have time for questions, but catch us outside. And also, I think we scratched on a lot of interesting topics. So, you also have an idea of what this crops now means, I hope, or at least you know how how many different things it means in practice. And thank you again for being here and see you see you again next year hopefully. [music] All &gt;&gt; [music] &gt;&gt; right. &gt;&gt; [music]
