Cointime

Download App
iOS & Android

7 Sanity Checks Before Designing a Token

Tokens are a powerful new primitive that can be defined in many ways; I’ve argued why we ought to consider the study and design of tokens as much broader than just “tokenomics” here.

Tokens clearly allow for a very rich design space. But we’re still in the early stages of exploring, let alone improving token design. The holy grail to attain here would be the modern equivalent of what’s commonly referred to as “the Dragon Book” by computer scientists. This book, which refers to Compilers: Principles, Techniques, and Tools (by Alfred Aho, Monica Lam, Ravi Sethi, and Jeffrey Ullman; and could sometimes also refer to earlier editions of that book or Aho’s and Ullman’s older work Principles of Compiler Design) — unified, defined, and influenced the study of compiler design for generations of computer scientists. So much so that two of the authors were named ACM Turing Award winners just a few years ago “for fundamental algorithms and theory underlying programming language implementation” and “for synthesizing these results and those of others in their highly influential books, which educated generations of computer scientists”.

We are far from the Dragon Book for token design — it is too early to produce a definitive text on tokens. Our Head of Research Tim Roughgarden notes though that we are likely a little under a decade away from this, it’s an ongoing body of work. Because the Dragon Book helped turn the “impossibly messy”, big computer science problem of the 1950s — of compiler design — into a more well-solved problem that could be tackled in stages, applying rigorous principles at each stage.

But some of the early opportunities, and pitfalls, are already becoming clear — so I thought it would be helpful to builders out there if I curated a list of some of the sanity checks our team often discusses when working with others on token design. I also encourage you to watch this recent talk on token design by Eddy Lazzarin, which covers mental models, common patterns and pitfalls, current token capabilities, and many design spaces left to explore.

The practical reality is that many teams endeavoring to find the “right” token design for their projects are often working without a tested framework for design — and thus run into the same challenges others have encountered before them. Fortunately, there are also early successes and examples of “good” token design. Most effective token models will have elements unique to their objective, but most flawed token designs share a number of common pitfalls. So here’s a list of instructive tips to avoid the most common failure modes.

#1 Have a clear objective

The greatest pain in token design comes from building a complex model before explicitly stating an objective. There is no such thing as a good token model or a bad token model — there is only a token model that achieves your objective, or a token model that doesn’t.

The first step should always be to rigorously interrogate the objective, and ensure you (and your team) fully understand it: what is it, why does it matter, and what are you really trying to accomplish? Failure to rigorously define an objective usually results in a redesign and lost time. Clearly defining an objective also helps avoid the “tokenomics for the sake of tokenomics” issue that’s a common (and not unfair) criticism of some token designs.

Furthermore, the objective should be specific to the token. This may seem obvious, but is often overlooked. Examples of such objectives could include:

  • A game that wants to design a token model that best enables extensibility and supports modding.
  • A DeFi protocol that wants to design a token model that optimally distributes risk amongst participants.
  • A reputation protocol that wants to guarantee money is not directly fungible for reputation (for instance, by separating liquidity from reputation signaling).
  • A storage network that wants to guarantee that files are available with low latency.
  • A staking network that wants to provide the maximum economic security.
  • A governance mechanism that wants to elicit true preferences or maximum participation.

…the list could go on and on. Tokens can support any use case and objective — not the other way around.

So how do you start to define a clear objective? Well-defined objectives often arise from a mission statement. While a mission statement tends to be high level and abstract, an objective should be concrete and reduced to the most elemental form.

Let’s consider EIP-1559 as an example. One clear objective of EIP-1559 is perhaps best stated by Roughgarden as: “EIP-1559 should improve the user experience through easy fee estimation, in the form of an ‘obvious optimal bid,’ outside of periods of rapidly increasing demand.”

He continues by codifying another clear objective: “Could we redesign Ethereum’s transaction fee mechanism so that setting a transaction’s gas price is more like shopping on Amazon? Ideal would be a posted-price mechanism, meaning a mechanism that offers each user a take-it-or-leave-it gas price for inclusion in the next block. We’ll see … that the transaction fee mechanism proposed in EIP-1559 acts like a posted-price mechanism except when there is a large and sudden increase in demand…”

What both of these examples share in common is stating a high-level objective; offering a relatable analogy (possible in this case) to help others understand that objective; and then proceeding to outline the design that best supports that objective.

#2 Evaluate existing work from first principles

When creating something new it’s always a good idea to study what already exists. As you evaluate incumbent protocols and existing literature, you should evaluate them objectively on the basis of their technical merits.

Token models are often evaluated based on the price of the token or the popularity of the associated project. These factors can be unrelated to the ability of the token model to meet its stated objectives. Valuation, popularity, or other naive ways of evaluating a token model can lead builders astray.

If you assume other token models function correctly when they don’t, you can create a broken token model. If you repurpose a token model with a different objective, you can implicitly inherit assumptions that don’t make sense for your token model.

#3 Articulate your assumptions

Be explicit about articulating your assumptions. It’s easy to take basic assumptions for granted when you are focused on building a token. It’s also easy to incorrectly articulate the assumptions you’re really making.

Let’s take the example of a new protocol that assumes that its hardware bottleneck is compute speed. Using that assumption as part of the token model — by bounding the hardware cost required to participate in the protocol, for instance — could help align the design to the desired behavior.

But if the protocol and token designers don’t state their assumptions — or are wrong in their stated assumptions — then it’s possible that participants who realize that mismatch will be able to extract value from the protocol. A “hacker” is often someone who simply understands a system better than the people who built it in the first place.

Articulating your assumptions makes it simpler to understand your token design and ensure it works properly. Without articulating your assumptions, you also can’t validate your assumptions…

#4 Validate your assumptions

As the popular saying goes, “It ain’t what you don’t know that gets you into trouble. It’s what you know for sure that just ain’t so.” [Often attributed to Mark Twain and others, this quote evolved incrementally over time.]

Token models often make a set of assumptions. This approach comes in part from the history of Byzantine system design as an inspiration for blockchains. The system makes an assumption and builds a function where, if the assumption is true, some output is guaranteed. For example: Bitcoin guarantees liveness in the synchronous network model, and consistency if 51% of hashpower in the network is honest. Several smaller blockchains have been 51%-attacked, violating the honest majority assumption Nakamoto consensus requires for a blockchain to function correctly.

Token designers can validate their assumptions in a variety of ways. Rigorous statistical modeling, often in the form of an agent-based model, can help test those assumptions. Assumptions about human behavior can also often be validated through talking with users, and better yet, by observing what people actually do (vs. say they do). This is possible especially through incentivized testnets that generate empirical results in a sandbox environment.

Formal verification or intensive audits will also help ensure that a codebase acts as intended.

#5 Define clear abstraction barriers

An “abstraction barrier” is an interface between different levels of a system or protocol. It is used to separate the different components of a system, allowing each component to be designed, implemented, and modified independently. Clear abstraction barriers are useful in all fields of engineering and especially software design, but are even more a requirement for decentralized development and large teams building complex systems that a single person can’t grok.

In token design, the goal of clear abstraction barriers is to minimize complexity. Reducing the (inter)dependencies between different components of a token model results in cleaner code, fewer bugs, and better token design.

Here’s an example: Many blockchains are built by large engineering teams. One team might make an assumption about the cost of hardware over time, and use that to determine how many miners contribute hardware to the blockchain for a given token price. If another team relies on token price as a parameter, but isn’t aware of the first team’s assumptions about hardware cost, they could easily make conflicting assumptions.

At the application layer, clear abstraction barriers are essential for enabling composability. The ability to adapt, build on top of, extend, and remix will only grow more important as more protocols compose with each other. Greater composition leads to greater possibility but also greater complexity. When applications want to compose, they have to understand the details of the protocol they compose with.

Opaque assumptions and interfaces have occasionally led to obscure bugs, particularly in early DeFi protocols. Murky abstraction barriers also extend development times by increasing the required communication between teams working on different components of the protocol. Murky abstraction barriers also increase the complexity of the protocol overall, making it difficult for any single person to fully understand the mechanism.

By creating clear abstraction barriers, token designers are making it easier to anticipate how specific changes will affect each part of the token design. Clear abstraction barriers also make it easier to extend one’s token or protocol, and to create a more inclusive and expansive community of builders.

#6 Reduce dependence on exogenous parameters

Exogenous parameters that are not inherent to the system, but that affect overall performance and success — such as the cost, throughput, or latency of a computing resource — are often used in the creation of token models.

Dangerously, unexpected behavior can arise when a token model only functions while a parameter remains in a limited range. For example, consider a protocol that sells a service and provides a rebate in the form of a fixed token reward: If the price of the token is unexpectedly high, the value of the token reward could be greater than the cost of the service. In this case it’s profitable to purchase an infinite amount of service from the protocol, leading to either the reward being exhausted or the service being fully utilized.

Or to take another example: Decentralized networks are often reliant on cryptographic or computational puzzles that are very hard, but not impossible, to solve. The difficulty of these puzzles is generally dependent on an exogenous variable — like how fast a computer can compute a hash function or a zero knowledge proof. Imagine a protocol that makes an assumption about how fast it’s possible to compute a given hash function and pays out token rewards accordingly. If someone invents a new way to compute that hash function more quickly, or simply has outsized resources to throw at the problem disproportionate to their actual work in the system, they can earn an unexpectedly large token reward.

#7 Re-validates assumptions

Designing a token should be approached like designing an adversarial system. Assume Byzantine behavior. Users’ behavior will change with changes to how the token works.

A common mistake is to adjust one’s token model without ensuring that arbitrary user behavior still results in an acceptable outcome. Do not assume user behavior will remain constant for variations in your token model. Usually this mistake happens late in the design process: Someone has spent a lot of time defining the objectives for the token, defining its function, and validating to ensure it works as intended. They then identify an edge case and shift the token design to accommodate for it… but forget to re-validate the overall token model. By fixing one edge case, they created another (or several other) unintended consequences.

Don’t let the hard work be for naught: Anytime a project changes its token model, re-validate that it works as intended.

If you find a better way to design tokens or like to think creatively and solve problems, I’d like to talk with you.

A big thank you to Scott Kominers, Tim Roughgarden, Sam Ragsdale, Ali Yahya, Eddy Lazzarin, Elena Burger, Carra Wu, Michael Blau, and especially to Sonal Chokshi and Stephanie Zinn for their feedback on this piece.

Editors: Sonal Chokshi & Steph Zinn

—

The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the current or enduring accuracy of the information or its appropriateness for a given situation. In addition, this content may include third-party advertisements; a16z has not reviewed such advertisements and does not endorse any advertising content contained therein.

This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments for which the issuer has not provided permission for a16z to disclose publicly as well as unannounced investments in publicly traded digital assets) is available at https://a16z.com/investments/.

Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

Read more: https://a16zcrypto.com/content/article/designing-tokens-sanity-checks-principles-guidance/

Comments

All Comments

Recommended for you

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,020.19, with a 24-hour decline of 0.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • ETH Surpasses $2500

    Market data shows that ETH has surpassed $2500, currently priced at $2500.03, with a 24-hour increase of 0.33%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Houthi Forces Claim Saudi Airstrikes on Sana'a Airport in Yemen

    On October 10, according to information released by the Houthi forces in Yemen, on the afternoon of the same day local time, the Saudi-led coalition conducted airstrikes on Sana'a International Airport, which is under the control of the Houthi forces, dropping four bombs. Additionally, the Saudi coalition also targeted a communication facility in Hajjah Province, controlled by the Houthi forces, dropping three bombs. There has been no response from the Saudi side regarding these incidents. (Jinshi)

  • French Finance Committee Approves Amendments on Stablecoin Exchange Tax and Crypto Exit Tax

    On October 10, Decrypt reported that the Finance Committee of the French National Assembly approved two amendments related to cryptocurrency taxation this week: starting January 1, 2027, exchanges of stablecoins regulated under MiCA will be considered taxable sales; and an exit tax will be imposed on taxpayers who have been French tax residents for at least six of the past ten years and have moved abroad with crypto assets totaling over 800,000 euros. On October 9, the committee voted 31 to 3 to reject the budget revenue portion, and the full National Assembly will review based on the government's original text. The amendments will not be automatically included; supporters must reintroduce them during the debate starting on October 13, with a formal vote scheduled for October 20. The related measures have not yet become law. The stablecoin amendment was proposed by Nicolas Sansu, a member of the left-wing GDR party group, along with 16 co-signers, and does not set a new tax rate but aims to include the revenue under France's existing 31.4% flat tax system. The committee also passed an amendment allowing crypto asset losses to be carried forward for ten years to offset future gains.

  • Luxshare Precision: Company and Luxshare Technology Involved in 337 Investigation, Currently in Initial Filing Stage

    On October 10, Luxshare Precision announced that the company and its holding subsidiary, Dongguan Luxshare Technology Co., Ltd., have been listed as respondents in a 337 investigation by the U.S. International Trade Commission (ITC), involving U.S. Patent US 10,903,700. The ITC officially launched the investigation on October 9, 2026, with investigation number 337-TA-1526. The case is currently in the initial filing stage, and no substantial determination has been made regarding the relevant infringement claims. The products involved are in the customer verification stage and have not yet entered mass production.

  • South Korea's Financial Commission: Shareholding Restrictions for Exchange Major Shareholders Not Targeting Specific Companies

    On October 10, Lee Ik-yeon, chairman of the Financial Services Commission of South Korea, stated that the provisions regarding shareholding restrictions for major shareholders of virtual asset exchanges in the ongoing 'Basic Law on Digital Assets' are not aimed at specific individuals or companies. Instead, they are designed to ensure that exchanges, once institutionalized, bear a higher level of public responsibility. Currently, South Korean virtual asset exchanges operate under a system that requires updates every three years, but this will transition to a licensing system after the implementation of the 'Basic Law on Digital Assets.' Lee emphasized that exchanges have infrastructure attributes and must possess public accountability and responsibility commensurate with their status.

  • SVRN Acquires Infrastructure Platform FastNEAR

    On October 10, it was officially announced that NEAR Treasury Company SVRN has acquired the NEAR infrastructure platform FastNEAR. FastNEAR will join SVRN as a wholly-owned subsidiary, with its co-founders Evgeny (Eugene) Kuzyakov and Mike Purvis also joining the SVRN team. The announcement stated that FastNEAR is a high-performance RPC infrastructure provider behind NEAR applications and supports most of the data layer for NEAR, including server clusters for handling network read and write operations, archival infrastructure for storing complete transaction histories, and NEARDATA, a data source for developers to process these historical records.