Mitigating Hazards from Inside and Outside Transactions with Prifi
Two hazard classes threaten transactions: those inside the deal and (potentially) everyone else

PriFi, or private finance, is not about absolute secrecy, and it’s not about evading regulations. It’s about user-operated financial infrastructure, purpose-built to shield sensitive information from adversaries positioned to exploit it.
Properly designing such defences requires first understanding the types of hazards that could threaten transactions at various stages of their lifecycle. This article considers two classes of threats: those inside a transaction (the counterparties) and those outside it (potentially anyone else).
The previous two Logos blog posts explore a framework for understanding PriFi, starting from two related ideas. Firstly, a transaction should be understood as a supply chain rather than as a single act of settlement: any deal or exchange proceeds through discovery, diligence, negotiation, contracting, ordering, settlement, and enforcement, with each link introducing its own costs, dependencies, and potential failure points. The second is that the credibility of the commitments supporting those links hinges on what makes them hold when circumstances change, distinguishing commitments sustained by incentives from those enforced through structural constraints.

This post goes deeper into the two hazard classes that can exploit vulnerabilities at each stage in the transaction’s lifecycle. Threats from either class introduce risk, and mitigating those risks introduces costs. Risk and cost represent barriers to entry for many market participants, limiting their willingness to transact in a market. PriFi is a design philosophy aiming to minimise them both by eliminating all unnecessary information exposure and dependence on centrally hosted infrastructure, which is vulnerable to exterior pressures or breaches.
Threats inside the deal: Counterparty hazards
It should come as no surprise that those inside a deal or exchange – the parties actually transacting – would represent a class of hazards that can potentially introduce risks. Transaction-cost economics has traditionally devoted considerable attention to this problem. Oliver Williamson describes opportunism as “self-interest seeking with guile”: a party may misrepresent what they are offering, selectively disclose information, fail to honour an obligation, or otherwise exploit a position created through exchange (Williamson, 1985).
What distinguishes the counterparty from other potential threats is that some degree of access is inherent in their role. Transactions require participants to reveal information to one another and, in many cases, to place assets, authority, or decision-making power within the other's reach. A purchaser needs information about what they are buying. A lender requires information regarding a borrower's ability to repay. Parties negotiating a trade must disclose something about the terms on which they are willing to transact. Without such access, many exchanges could not take place at all.
The same access can nevertheless create opportunities for exploitation. A seller's superior knowledge of an asset can make misrepresentation possible. A buyer who receives goods before payment acquires temporary control over value that still belongs to the seller. A party negotiating a transaction may learn information about the other's constraints, urgency, or asset valuation and use that knowledge strategically. None of these hazards requires the counterparty to have entered the transaction with the intention to defect. They arise because participation creates informational and operational positions that did not exist before the parties began dealing with one another.
These positions can emerge at several points in the transaction lifecycle. During diligence, a counterparty may possess information that the other side cannot independently verify. During negotiation, each party learns something about the other's preferences and constraints. Contracting requires the parties to formalise terms and, depending on the arrangement, may assign particular permissions or authorities. Settlement can require one party to release value before every aspect of the exchange is complete, while enforcement may depend upon one participant continuing to comply with obligations after the principal transfer has occurred.
The risk posed by insiders is, therefore, closely connected to a basic feature of exchange: cooperation requires exposure. The parties need enough access to evaluate one another, agree on terms, and carry out the transaction, but every additional piece of information or capability granted to another actor can also enlarge the set of actions available to them.
Commercial institutions have developed an extensive range of mechanisms for managing this problem. Contracts, warranties, collateral, escrow, auditing, fiduciary duties, reputation, and courts all respond, in different ways, to risks created by placing another party in a privileged position during exchange (Williamson, 1983; Williamson, 1996). More recently, smart contracts have made it possible to constrain certain forms of discretion directly through executable conditions, so that some outcomes no longer depend solely upon a participant choosing to honour an obligation.
However, even where execution can be structurally constrained, the underlying requirement for access does not disappear. Counterparties still need enough information and capability to discover one another, assess the proposed exchange, negotiate its terms, and authorise the resulting transaction. PriFi, therefore, has to account for a hazard class that cannot simply be removed from the transaction's informational environment: the people with whom the user is deliberately choosing to deal.
Outsiders to the transaction: Predatory hazards
The second hazard class consists of actors who are not party to the transaction at all. They have not entered into the bargain, received rights under it, or accepted obligations towards the participants. Nevertheless, they may still be able to affect the transaction if they acquire information that creates opportunities for exploitation.
This class includes a wide range of potential actors. A competing bidder may benefit from learning the terms of an offer. A trader may profit from knowledge of an acquisition or large order before it has settled. A thief may become interested in an asset once its value and location are known. An extortionist may alter their demands after learning what a target can afford to pay. In onchain markets, a searcher may use information about a pending transaction to construct another transaction that captures value from the original user's intended trade.
What unites these examples is not the identity or motive of the actor, but their position relative to the exchange. Unlike a counterparty, they have no legitimate need for the information in order for the transaction to proceed. Their relevance is realised when information escapes the set of relationships in which disclosure is necessary.
This class of hazard has received comparatively less attention in traditional transaction-cost economics. Williamson distinguishes between the governance structures used to organise particular transactions and the wider “institutional environment” within which those structures operate (Williamson, 1991). Often, a degree of commercial confidentiality can be treated as part of that environment. Company negotiations take place privately, banks and lawyers develop duties of confidence, sealed bids conceal competing offers, and firms keep their ledgers and commercial records away from general view. These arrangements are imperfect, but continue to provide protection – at a cost. Universal publication is not, typically, the default condition of exchange.
That background determines which hazards must be addressed explicitly by the transaction itself. If commercially sensitive information is difficult for outside actors to obtain, many forms of predation remain largely outside the immediate governance problem. Once the cost of acquiring that information falls, however, actors who were previously irrelevant to the transaction can become significant.
Research into mergers and acquisitions provides a useful illustration. Studies of pre-announcement trading have found evidence consistent with private information about impending deals being incorporated into prices before public disclosure, allowing informed traders to benefit from information that originated within the transaction but was valuable outside it (Madura & Ngo, 2014; Madura, Ngo, & Susnjara, 2014). The transaction may still be completed, but some of the value expected by the participants can be transferred elsewhere through information leakage.
This suggests a useful predation model. An outside actor generally requires some combination of information, capacity, and impunity. Information allows the actor to identify a target or opportunity. Capacity determines whether they possess the means to exploit it. Impunity affects whether the expected consequences of doing so are sufficient to deter action.
The three conditions are related, but information has a distinctive role because it often determines whether the other two can be directed towards a particular transaction at all. A rival bidder cannot respond to an offer it does not know exists. A searcher cannot trade around an order it cannot observe. A thief may possess the general capacity to steal without having any reason to target a particular asset until its existence, value, or location becomes known.
Information alone is not enough to produce predation. An observer still needs the ability and incentive to act. However, absolute transparency of sensitive details can transform an otherwise irrelevant actor into one positioned to exploit the transaction.
Insider and outsider hazards across the transaction lifecycle
The distinction between insiders and outsiders is not confined to one stage in the transaction lifecycle. Both classes can appear at different points, although the information, capabilities, and opportunities available change from one stage to the next.
During discovery, the principal insider risk concerns the prospective counterparty itself. A participant may misrepresent who they are, what they control, or their ability to complete the proposed exchange. At the same time, the process of searching for a counterparty can reveal intentions to outsiders. Knowledge that a firm is seeking a particular asset, supplier, source of financing, or acquisition target may itself carry strategic value.
During diligence, the informational asymmetry between counterparties becomes particularly important. One party may possess facts that the other cannot independently verify, creating scope for misrepresentation or selective disclosure. However, diligence also requires the concentration and exchange of commercially sensitive information, which can become valuable to actors beyond the transaction if it is exposed.

The same pattern continues through negotiation and contracting. Participants necessarily reveal something about their valuations, constraints, priorities, and willingness to transact. That information can affect bargaining between the parties, while knowledge of the same negotiations may allow competitors, traders, or other outside actors to alter their own behaviour. Contracting can also assign permissions, authorities, or access needed to formalise the agreement, creating positions that did not exist before the parties entered the relationship.
At the time of ordering, the relevant capabilities change again. Actors responsible for sequencing transactions can occupy privileged positions by virtue of their role in determining the sequence in which competing instructions are processed. Meanwhile, observable transaction intentions can create opportunities for parties with no role in the original exchange to act before settlement occurs.
Settlement is the point at which blockchain systems provide their strongest guarantees. Protocol rules can sharply constrain which state transitions are accepted as valid. Yet settlement can still reveal economically significant information about asset movements, counterparties, and transaction history to observers outside the exchange. Furthermore, if an exploit occurs before settlement and an erroneous transaction is submitted, the chain will settle it with near-absolute finality, heightening the importance of securing all prior links. The case of the Bybit exploit of around $1.5 billion in 2025 provides a compelling example.
Finally, enforcement introduces further dependencies. Parties, intermediaries, or institutions may retain authority over obligations that continue after settlement, while actors outside the original transaction may influence those institutions or exploit information generated by the completed exchange.
Seen across the lifecycle, the two hazard classes are, therefore, not tied to particular actors or technologies. They describe positions that recur wherever a transaction creates access for participants or exposes information to those beyond it. The precise threat changes from link to link, but the analytical distinction remains useful: Who is involved because the transaction requires them to be, and who becomes relevant because the transaction reveals something they can use?
Blockchain infrastructure: Shifting the terms of transactional hazards
Public blockchains alter the conditions under which the hazards operate because transparency is not merely a side effect of their design. It is central to how their rules and state transitions become independently verifiable. A transparent ledger allows participants to inspect the system's state and determine whether transactions conform to shared protocol rules. This is what gives blockchain settlement its unusually strong guarantees: valid state transitions are accepted according to the network's rules, while invalid ones are rejected.
For counterparties, this can narrow the scope for certain forms of discretion. Where conventional exchange may depend on a participant or intermediary retaining the ability to decide whether an obligation is honoured and how it is performed, smart contracts can make particular outcomes conditional on rules that neither party can unilaterally override. The counterparty may still possess information or other forms of access, but the set of actions available to them at settlement can be more tightly constrained.
The same architecture changes the position of outsiders in a different way. In transparent blockchain systems, public verifiability is achieved through broad observability of transaction data and state. Information concerning balances, transfers, counterparties, contract interactions, and, in some cases, pending intentions can therefore become available not only to the parties involved in the exchange, but to any observer able to inspect the relevant infrastructure.
This represents a substantial departure from the informational environment in which most conventional commerce developed. Historically, transaction information was fragmented across private ledgers, banks, brokers, advisers, counterparties, and other institutions. An outsider seeking to understand a transaction often needed privileged access to at least one of those sources. On a transparent blockchain, information that once required such access may instead become trivially available through the system's ordinary operation.
The effect is to shift the terms facing both hazard classes at once. Insiders may have less room to manipulate the rules governing settlement, but outsiders face a much lower cost of discovering that a transaction, position, or asset exists. The architecture, therefore, constrains some forms of insider discretion while simultaneously broadening the set of actors able to observe economically useful information.
From hazard classes to transaction-level threat modelling
Once insiders and outsiders are treated as distinct hazard classes, threat modelling becomes less about identifying generic "attackers" and more about understanding the positions different actors occupy relative to a transaction.
At each stage of the lifecycle, the first question is who must participate for the transaction to proceed. These actors may be counterparties, intermediaries, advisers, sequencers, infrastructure providers, or other agents whose role gives them access to information, authority, or control. While such participation is integral to the deal itself, it can also create opportunities for opportunism.
The second question concerns actors outside those relationships. What information does the transaction reveal beyond the parties who need it? Who can observe that information, directly or indirectly? What can be inferred by combining it with other data? Most importantly, what new opportunities arise once the information becomes available?
This produces a more useful account of exposure than simply classifying information as "public" or "private". A communication may reveal little about the substance of a negotiation while still disclosing that two parties are in contact. A visible balance may say nothing about a holder's immediate intentions while revealing that the account is economically significant. A pending transaction may not disclose the legal identity of its originator, yet still reveal enough about the intended action for another market participant to respond.
The significance of a disclosure, therefore, depends upon the position it creates for the observer. Information that is necessary for one actor to fulfil a legitimate role in the transaction may give an unrelated actor a completely different set of opportunities.
For PriFi, this means that analysing transaction privacy requires looking beyond whether individual data points are concealed. The more relevant question is how information and capabilities are distributed across the lifecycle, which actors acquire them, and whether that distribution creates avoidable positions of advantage or vulnerability.
Making exposure visible with Muster
Dr Corey Petty's work on Muster provides a practical environment for examining these questions. Muster is an experimental application built with the Logos stack for coordinating transactional activity within private conversations while making visible the information disclosed during the process and the infrastructure involved in carrying an action through to execution.
That makes it useful for moving from an abstract threat model to a more concrete examination of transactional exposure. Instead of considering a transaction only at the point where value settles, participants can inspect which information becomes available during coordination, which systems handle it, and where dependencies remain.
Viewed through the lens of the two hazard classes, those observations take on additional meaning. A disclosure can be examined not only in terms of what information becomes visible, but also in terms of who receives it and what position that actor occupies in the exchange. Some recipients are present because the transaction requires their participation. Others may become relevant only because information escapes beyond those relationships.
This distinction is especially important in systems where infrastructure itself can become part of the threat model. A frontend, communications service, routing provider, or other intermediary may not be an economic counterparty to the underlying transaction, but its role can still give it access to information or control that affects how the transaction unfolds. The previous Logos blog article introduced this broader question by identifying where coordination still depends on participants or infrastructure behaving as expected.
The purpose of mapping these positions is not to assume that every participant or observer is adversarial. It is to understand where the possibility of exploitation exists if incentives, circumstances, or actors change.
That is the value of separating the two hazard classes. Counterparties and outsiders can both threaten the gains from exchange, but they do so in different ways. One is admitted into the transaction because an exchange requires access. The other may become relevant because information travels further than the exchange requires.
Identifying those positions is the first step towards designing transaction infrastructure around a realistic threat model.
Explore Muster / Read Corey's post on transactional information exposure / Download Basecamp
This article is based on research compiled by Logos cofounder Jarrad Hope and ideas emerging from it. PriFi is central to Logos’ mission to revitalise civil society. Effective parallel organising requires economic rails that can withstand outside efforts to obstruct and manipulate activity.
Selected references
Bybit (2025), “Bybit Confirms Security Integrity Amid Safe{Wallet} Incident – No Compromise in Infrastructure”, 26 February 2025.
Madura, Jeff, and Thanh Ngo (2014), “Private Information Leakages and Informed Trading Returns of Tech Target Firms”, The Journal of High Technology Management Research, 25(1), 36–53.
Madura, Jeff, Thanh Ngo, and Jurica Susnjara (2014), “Information Leakages and the Costs of Merging in Europe”, Applied Financial Economics, 24(8), 515–532.
Williamson, Oliver E. (1983), “Credible Commitments: Using Hostages to Support Exchange”, American Economic Review, 73(4), 519–540.
Williamson, Oliver E. (1985), The Economic Institutions of Capitalism (New York: Free Press).
Williamson, Oliver E. (1991), “Comparative Economic Organization: The Analysis of Discrete Structural Alternatives”, Administrative Science Quarterly, 36(2), 269–296.
Williamson, Oliver E. (1996), The Mechanisms of Governance (Oxford: Oxford University Press).