Midnight’s Centralization Questions Are Real. Its Most Serious Allegations Still Need Evidence
Allegations about Midnight’s validator structure, token controls, administrator keys and production software raise legitimate governance questions. They do not, on the evidence reviewed here, establish that the project is fraudulent or that its validators secretly switched to an undisclosed closed-source codebase.
The distinction matters. A network can launch with centralized controls and decentralize later. A project can publish part of its software while retaining private components. Neither fact is automatically misconduct. Both should be disclosed clearly to users, developers and investors.
The claims attributed to Justun Bons should be linked to the original post, interview or document in which he made them. The material reviewed for this article does not independently verify every quotation or specific allegation attributed to him.
What Midnight is building
Midnight is a privacy-focused blockchain project associated with Input Output, the company founded by Charles Hoskinson. Its design is intended to let applications keep selected information private while allowing users or applications to disclose specific facts when required.
The privacy question is not simply whether data is hidden. It is private from whom: other users, validators, application operators, the public, or all of them? Midnight’s model is built around selective disclosure rather than an assumption that every transaction is invisible to every participant.
The system uses two principal assets:
- NIGHT, the network’s transferable token, is intended to support economic incentives, governance and other network functions.
- DUST is a resource used for transaction and computation costs. It is designed to separate fee consumption from direct spending of NIGHT and to make application costs more predictable.
DUST should not be described as an ordinary second currency without qualification. Its role is to pay for network resources, while NIGHT is the transferable asset used in the project’s economic model.
Midnight’s initial distribution was tied closely to Cardano. That does not make NIGHT the same asset as ADA, and it does not make Midnight the Cardano main chain. It means that parts of the early distribution and user experience rely on Cardano-based assets, policies and contracts while Midnight’s own network infrastructure develops.
That creates an important distinction: token ownership is not the same as network usage. A project may distribute a large supply of tokens while having limited transaction activity, few applications and a small number of independent operators.
The useful metrics are therefore not just the number of NIGHT tokens distributed. They include active users, transactions, deployed applications, independent validators and the ability to move assets between Cardano and Midnight without relying on a small administrative group.
The validator question
The allegations attributed to Bons describe Midnight’s early network as permissioned and closer to proof of authority than to an open proof-of-stake system. That claim needs to be tied to the relevant Midnight technical documentation and network-status information.
The underlying issue is straightforward. A network may begin with a restricted validator set. Operators can be admitted by a foundation, administrator or governing group rather than joining through an open staking process. That approach can help with testing, controlled deployment and incident response. It is not equivalent to an open validator network in which participation is broadly available under published rules.
The word “validator” can also conceal several different categories:
- registered or approved operators;
- operators running infrastructure but not producing blocks;
- active block producers;
- planned future operators; and
- governance or administrative signers.
If Midnight documentation refers to one number while only a smaller number of operators are active, the project should define the terms and publish the current set. A count of approved entities is not the same as a count of independent entities currently securing the chain.
The more important question is what those operators can do. A permissioned launch is not necessarily a problem if it has a public transition plan, narrow authority and a clear route to broader participation. It becomes a governance risk when admission rules are discretionary, emergency powers are indefinite or the project presents a restricted system as though it were already permissionless.
Administrator keys require a control map
The claim that Midnight has ten administrator keys is not independently established by the material reviewed here. If the figure is used, the article should identify the underlying documentation and explain what those keys control.
The number of keys alone does not determine the level of risk. The relevant questions are:
- Can the keys freeze accounts?
- Can they censor or reverse transactions?
- Can they change validator membership?
- Can they upgrade consensus software?
- Can they alter token supply or distribution rules?
- Is a threshold of signatures required?
- Are key holders identified or independently audited?
- Do the powers expire automatically?
A key used only for an emergency pause presents a different risk from a key that can rewrite balances or appoint every validator. Midnight should publish a control map covering each administrative role, the threshold required for action, the events that permit intervention and the conditions under which the authority expires.
Anonymous key holders are not automatically evidence of wrongdoing. Cryptographic systems often protect operational identities. But anonymity reduces accountability when the same keys can change protocol behavior or control user assets. Independent audits, threshold signing and published procedures become more important in that situation.
What the Cardano-side NIGHT policy can and cannot do
The allegation that NIGHT held on Cardano is controlled by a contract or administrative key capable of stealing users’ funds combines several different technical risks. It should not be stated as fact without the relevant Cardano asset policy, contract code, policy identifier and signing configuration.
Cardano native assets are governed by minting policies. A policy may control whether additional units can be minted or burned, depending on its rules and the lifetime of its policy keys. That is different from having a general account-based function that can arbitrarily transfer every token held by users.
Whether a Cardano-based NIGHT representation can be frozen, transferred or otherwise restricted depends on the exact implementation. A minting policy alone does not automatically give its holder the power to seize all existing balances. Separate scripts, bridge contracts or application controls could introduce additional powers, but those must be examined individually.
The article should therefore distinguish among:
- the ability to mint new tokens;
- the ability to burn tokens;
- the ability to prevent transfers;
- the ability to move tokens held by a contract; and
- the ability to upgrade or replace the controlling code.
Those are not interchangeable capabilities.
NIGHT’s supply and distribution
The arithmetic cited in the allegations is correct:
- 8.4 billion out of 24 billion is 35%;
- 3.66 billion out of 24 billion is approximately 15.25%.
The arithmetic does not establish that the allocations are improper.
Midnight’s published token-distribution materials describe a total NIGHT supply of 24 billion and a distribution process that includes the Glacier Drop and other mechanisms. The full supply should not be described as though it were all distributed directly to claimants through the Glacier Drop. The distribution categories, eligibility rules, claim deadlines and any unclaimed-token treatment must be stated separately.
A large foundation, treasury or ecosystem allocation is common in blockchain projects. The material question is whether those tokens are subject to binding restrictions. Readers need to know:
- who legally controls each allocation;
- whether tokens are vested or locked;
- when they become transferable;
- whether the restrictions are enforced by code or only by policy;
- whether the holder can change the terms unilaterally; and
- whether treasury movements are publicly reported.
A statement that tokens are reserved for partnerships, development or ecosystem growth is not the same as a coded lockup. If a foundation or related entity can move its entire allocation immediately, holders face concentration and selling risk even if the underlying protocol is secure.
The open-source allegation
The most serious allegation is that validators changed to a closed-source codebase on September 25 and that the production software does not match any public repository.
That is a testable claim, but the evidence supplied does not establish it.
A credible technical comparison would require:
- the exact date and time zone;
- the chain version;
- the validator binary or container image;
- a cryptographic hash of the running software;
- the repository commit expected to match it;
- the method used to obtain the production binary;
- signatures or attestations from the relevant operators; and
- a reproducible comparison showing any differences.
A public repository is not automatically the same thing as reproducible production software. A project may publish source code while delaying a release, withholding build instructions or keeping some components private. Conversely, a project that advertises an open-source network should explain any private validator software, proprietary modules or delayed source releases.
If Midnight’s public documentation promises open-source implementation of the network, a material change should be disclosed. The consequences are practical: independent operators cannot verify that they are running the same code, researchers cannot reproduce reported behavior and users cannot assess whether the network is governed by the software they were shown.
Until hashes, repository history and build information are independently compared, the claim about a secret closed-source switch remains unverified.
Restrictions on applications and transactions
The allegation that Midnight restricts applications involving political donations also requires the original statement and the applicable policy document. If such a restriction exists, its location in the stack matters.
There is a significant difference between:
- a consensus rule that rejects a transaction;
- a foundation policy that refuses to approve an application;
- a wallet provider’s compliance decision; and
- an application’s own terms of service.
These controls have different implications for censorship and neutrality. Midnight should state which layer imposes any restriction, who can change it, whether it applies to all users or only approved applications and whether it is temporary.
A promise to remove a restriction after launch is not a timetable. The project should publish the rule, its legal or technical basis and the conditions for its removal.
What the evidence supports
The available material supports a narrower conclusion than the strongest allegations.
Midnight may have legitimate reasons to begin with a restricted validator set, administrative controls and a token distribution connected to Cardano. Those design choices can support a controlled launch. They also create centralization, custody and execution risks that should be disclosed plainly.
The evidence reviewed here does not establish that Midnight’s validators secretly adopted a closed-source codebase, that administrator keys can steal user funds or that every statement attributed to Bons was made in the quoted form. Those claims require primary documents and technical evidence.
Midnight should publish:
- the current validator set and admission rules;
- the difference between approved and active validators;
- a complete administrator-key and threshold-signing map;
- emergency powers and expiry conditions;
- the Cardano NIGHT policy and associated contract controls;
- allocation owners, vesting terms and treasury movements; and
- reproducible production-build information for validator software.
Until that information is available, NIGHT should be evaluated as an early-stage network with meaningful centralization and execution risk. A large token allocation is not evidence of network usage. A public repository is not proof of reproducible production software. A decentralization roadmap is not decentralization already delivered.
Midnight may develop into a capable privacy network. The relevant question today is not what the project promises to become, but which parties can change the network, move its assets, admit its validators and determine what code users are actually running.
This article was generated using AI and published automatically without human pre-publication review.
How this article was made
The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.