article

[BTCFi Series 9] Babylon: TVL Up, Yields Thin

Babylon secures ~$5.6B in native BTC with a token worth ~$78M. The unit economics of Bitcoin security-as-a-service, and why realized yield stays thin.

15 min read
Share 공유 共有 分享 Compartir X LinkedIn

cover

Introduction

In mid-May 2026, Babylon’s staking vaults held 56,853 BTC, worth roughly $5.64 billion at the prices used in that snapshot. The token that compensates those stakers, BABY, carried a circulating market capitalization of about $78 million on the same date. The asset paying for the security is worth roughly 1.4% of the collateral it is paying for.

That ratio is the central tension, and it does not resolve by pointing at growth. Babylon has the growth. More than 250 finality providers operate on Babylon Genesis. Phase 3 multi-staking has begun rolling out to the first Bitcoin Secured Networks, with Corn, BOB and Pell Network named in Babylon’s own ecosystem materials. No slashing incident has been reported, though none of the sources we reviewed independently verifies that absence rather than simply omitting one. BABY traded near $0.020 in May 2026, up about 30% on the week from a March 2026 low of $0.0107, and still roughly 88% below the $0.1661 all-time high set in April 2025.

The reported TVL itself is not settled. Cryptonomist reported Babylon crossing $4 billion in TVL on 15 May 2026, describing it as one year after launch. Phemex, writing in the same month, reported 56,853 BTC at $5.64 billion. Neither source reconciles with the other. The gap is most plausibly a difference in snapshot date, BTC price assumption, or whether Phase 1 locked deposits and Genesis-delegated stake are counted together, but we could not confirm which. Anyone modelling Babylon’s economics should treat the $4B to $5.6B band as the honest range rather than picking the larger figure.

Pricing Babylon’s core offering reveals the structural constraint. Bitcoin-denominated economic security is abundant and nearly costless to supply. The constraint on this business was never collateral. It is whether any network will pay a real price for it.

From locked UTXOs to a shared-security marketplace

img1

Babylon’s three phases are often described as a sequence of releases. They are better understood as three distinct products stacked on the same collateral base.

Phase 1, the Bitcoin locking phase, established the core cryptographic claim. A holder locks BTC into a staking script on the Bitcoin chain itself. There is no wrapping, no bridge, and no custodian holding a redemption liability. The UTXO stays on Bitcoin, encumbered by a covenant-style contract that defines a slashing spend path and an unbonding path. Phase 1 ran in capped deposit rounds and accumulated over 57,000 BTC from 135,290 unique stakers, which Babylon’s documentation frames as roughly 0.2% to 0.3% of circulating Bitcoin depending on the snapshot. That phase produced no yield in itself. It produced points, positioning, and the liquid staking tokens built on top of it, of which Lombard’s LBTC became the largest.

Phase 2 launched Babylon Genesis, a Cosmos SDK chain with a dual security model. Two separate stakes secure two separate functions. BABY stakers delegate to CometBFT validators, who produce blocks. BTC stakers delegate to finality providers, who sign finality votes on those blocks. A block is not final until finality providers representing sufficient BTC weight have signed it. The Bitcoin-backed layer therefore does not order transactions; it ratifies an ordering produced by a token-weighted validator set. Separately, Babylon Genesis checkpoints its own state into Bitcoin transactions, which gives light clients an objective ordering to fall back on and closes the long-range attack surface that pure proof-of-stake chains carry.

Phase 3 generalizes the finality layer. The same locked BTC can be delegated to finality providers serving other chains, the Bitcoin Secured Networks, with Babylon Genesis acting as the control plane that registers BSNs, tracks delegations and routes rewards. Lombard’s March 2025 explainer describes this as a marketplace for shared security, which reflects promotional framing from a party that earns fees on Babylon’s success, but the mechanical description is accurate enough. A BSN registers, finality providers opt in, BTC stakers delegate, and the BSN’s rewards flow back along the same path.

The architectural achievement is real and narrow. Babylon has made Bitcoin capable of carrying a slashable commitment without leaving Bitcoin. What it has not yet demonstrated is a buyer who pays a meaningful price for that commitment.

What the first BSNs pay, and where disclosure stops

img2

We could not find, in Babylon’s documentation, in Lombard’s ecosystem materials, or in the secondary coverage we reviewed, any figure for what Corn, BOB or Pell Network remit for Babylon security. Not an amount, not a rate, and not an asset denomination. The topic brief that prompted this analysis also lists Manta as an early BSN; we found no corroboration of that in any primary or secondary source and treat it as unconfirmed.

This is not a minor documentation gap. It is the single number that determines whether Babylon is a services business or a subsidy program, and its absence is itself informative. A security marketplace with real revenue tends to publish its revenue, because revenue is the argument. When a protocol publishes TVL, finality provider counts and integration announcements while leaving the fee schedule unstated, the most parsimonious reading is that the fees are small enough that stating them would undercut the other numbers.

Consider what an early BSN is economically. Corn, BOB and Pell are young networks with their own token supplies, their own treasuries and their own need to bootstrap. They are not cash-rich entities shopping for security the way a bank shops for custody. The plausible structures available to them are payment in their own native token, payment in ecosystem allocation or points with future conversion, or reciprocal arrangements where the BSN receives a Babylon integration and Babylon receives distribution. Each of those makes the BSN a net consumer of subsidy rather than a source of it. If BSNs paid in stablecoins or BTC, that would be a strong signal and it would almost certainly be advertised.

So the reward reaching BTC stakers today is overwhelmingly BABY. Babylon’s own documentation states that Phase 2 introduces base staking rewards, language that describes issuance rather than fee distribution. BABY’s initial supply is 10 billion tokens with, per the same documentation, no hard cap. Phemex reported 3.87 billion of 10.76 billion tokens circulating in May 2026, roughly 36%, with approximately 6.9 billion still to enter circulation through team unlocks, ecosystem grants and staking rewards.

The distinction between revenue and dilution matters because the two behave differently under stress. Fee revenue paid in an external asset is a transfer from BSN users to BTC stakers and is roughly price-independent from the security token. Emissions paid in the security token are a transfer from existing token holders to stakers, and their value collapses exactly when the token does. A yield funded by emissions is a yield whose denominator moves against the staker in every bad state of the world.

The arithmetic of a BABY-denominated yield

img3

No source we reviewed publishes an audited, BTC-denominated realized APY for Babylon stakers, so we will not assert one. The emission schedule allocated specifically to BTC stakers is also not broken out in the materials available to us. What can be established is the size of the budget from which any yield must come, and that bound is severe.

Take the staked base at the more generous figure, $5.64 billion. A 0.5% BTC-denominated annual yield on that base requires distributing about $28 million of value to BTC stakers over a year. Against BABY’s roughly $78 million circulating market capitalization in May 2026, that is close to 36% of the entire circulating float, distributed annually, to one claimant group. At 1%, it approaches 72%. Measured against the fully diluted valuation of roughly $217 million, a 0.5% yield still consumes around 13% of the token’s total worth every year.

Now look at the stock rather than the flow. The approximately 6.9 billion BABY tokens not yet circulating are worth about $138 million at $0.020. That is every remaining token, including the portions earmarked for team vesting and ecosystem grants that will never reach BTC stakers. Even under the fiction that the entire unissued supply were paid to BTC stakers and nothing else, the total is under 2.5% of the value of the Bitcoin currently staked. That is a one-time amount, not an annual rate.

There is a reflexive loop inside this. Emissions denominated in BABY are sold by rational stakers into a market whose capitalization is a small fraction of the collateral base. Selling pressure depresses the price, which depresses realized yield, which is answered by higher nominal emissions if the protocol targets a headline APY, which increases selling pressure. The loop is not unique to Babylon. It is more acute here than in most cases because the ratio of secured value to token value is unusually extreme. Ethereum’s validators are paid in the asset they are securing. Babylon’s BTC stakers are paid in an asset with no claim on the collateral and, so far, no demonstrated claim on external fees.

Why anyone stakes anyway

The thin yield does not make staking irrational, and this is where the bear case must concede a key mechanism.

A BTC staker on Babylon does not sell, wrap, or transfer the BTC. The coin stays in a UTXO the staker controls, encumbered but not surrendered. The real costs of staking are the slashing risk on the covenant path, the liquidity cost of the unbonding delay, and the operational risk of interacting with the staking script correctly. For a holder with a long horizon and no intention of moving the coin, those costs are close to zero. When the marginal cost of supplying a factor is near zero, the market clears at a near-zero price. Thin yield on Babylon is not a pricing failure. It is the correct price for an abundant input.

The composition of stakers reflects this. Liquid staking token issuers derive their economics from LBTC’s circulation and DeFi integration rather than from BABY rewards, so BABY’s drawdown barely touches their business case. Holders farming prospective BSN allocations are underwriting an option on future airdrops, not a coupon. Treasuries and long-horizon holders with structurally idle BTC take whatever accrues. None of these participants needs the yield to be good. They need it to be non-negative.

That is a durable supply base and an informative fact about TVL persistence. It is also why TVL cannot be read as evidence of product-market fit. Babylon’s supply side is oversubscribed at prices approaching zero. The binding constraint is demand from BSNs willing to pay, and nothing in the current data shows that constraint loosening.

Slashing that can only punish equivocation

img4

Babylon’s slashing enforcement is the strongest engineering claim in the stack and the most misunderstood in comparison to Ethereum restaking.

Finality providers sign with Extractable One-Time Signatures. An EOTS key can safely sign one message per height. Sign two conflicting messages at the same height and the two signatures together algebraically reveal the private key. Once revealed, anyone can construct the transaction that spends the slashing path of the delegators’ Bitcoin UTXOs. No committee votes, no oracle reports, no governance action. The penalty is a consequence of the cryptography and the enforcement is permissionless, executed on Bitcoin against Bitcoin UTXOs.

This is objectively enforceable in a way that few slashing systems are. It is also extremely narrow. EOTS extraction punishes exactly one fault: equivocation at a height. It cannot punish a finality provider that simply stops signing. It cannot punish censorship, because refusing to sign a valid block is indistinguishable at the signature layer from being offline. It cannot punish a provider that signs a technically valid but semantically harmful state, because validity is what the signature attests to. A BSN buying Babylon security is buying insurance against double-finalization and nothing else.

EigenLayer’s design sits at the other end of this tradeoff. Slashing conditions there are defined per service and enforced by Ethereum contracts, which permits a much broader fault set, including conditions that are subjective and require an attestation or dispute process to adjudicate. Broader coverage, weaker objectivity. Babylon’s coverage is minimal and its objectivity is close to absolute. Neither is strictly better; they answer different questions about what a service actually needs protection against. For a rollup worried about liveness or censorship, Babylon’s mechanism is not the relevant instrument.

The severity parameter is where we hit a documentation wall. The brief prompting this analysis cites a 0.1% penalty for double-signing. We could not corroborate that figure, or any figure, in Babylon’s documentation or the secondary coverage we reviewed, and the sources that describe slashing say only that a portion of delegated BTC is burned. The ambiguity is not cosmetic. If a double-sign burns 0.1% of the delegation, then a finality provider controlling meaningful BTC weight faces a penalty that could be trivial relative to the value of a successful attack on a BSN with a large bridge. If it burns a much larger share, the economics invert. A security buyer cannot price protection without knowing the penalty, and the fact that the penalty is not prominently published is a real obstacle to the enterprise-grade positioning Babylon has pursued since raising roughly $96 million from Polychain Capital, Hack VC, Galaxy Digital, OKX Ventures and others, with audits from Coinspect, Zellic and Cantina.

Multi-staking adds reward streams and fault domains together

img5

Phase 3’s proposition is that one BTC delegation can secure several BSNs and earn from each. The reward side of that statement is straightforwardly additive. The risk side is where the analysis must be careful, because additivity there depends on a correlation assumption that the architecture works against.

Slashing exposure across BSNs is not diversified in the portfolio sense. The same UTXO backs each commitment, so a fault at any one BSN reaches the same collateral. Adding the second and third BSN adds independent chances to be slashed against a collateral base that does not grow. In expectation that is fine if the per-event penalty is small and the fault probability is genuinely independent across networks. Independence is the assumption that deserves scrutiny.

The fault being punished is equivocation by a finality provider, and equivocation is overwhelmingly an operational failure rather than a strategic choice. Duplicate signing processes after a failover, a restored snapshot that replays old state, a key management error during migration. If the same operator runs finality provider instances across Corn, BOB and Pell Network using shared infrastructure and shared key material, then a single operational incident produces equivocation on several BSNs simultaneously. The economic fault domains are distinct; the operational fault domain is one. We have no public data on the degree of finality provider overlap across BSN sets, and that overlap is the single most important input to whether multi-staking is diversification or leverage.

The counterargument deserves a fair hearing. BSNs have genuinely distinct applications, users and revenue models, so a BTC staker collecting rewards from several of them is less dependent on any one network’s survival than a staker exposed to Babylon Genesis alone. That is real diversification of the reward stream. The point is that reward diversification and fault diversification are different properties, and Phase 3 delivers the first much more cleanly than the second.

Concentration in the provider set compounds this. Lombard was, as of March 2025, the largest finality provider on Babylon with over 40% of all staked BTC delegated to it, 22,508 BTC split between 15,038 BTC arriving via LBTC and 7,470 BTC delegated directly. We found no updated figure for 2026, and the count of 250-plus finality providers says nothing about how stake is distributed among them. If anything close to a 40% share persists, then a single operator’s signing infrastructure sits astride a plurality of the Bitcoin securing the network, and multi-staking propagates that operator’s operational risk into every BSN it serves. The absence of a current concentration disclosure is, again, the part that should concern an analyst more than any particular number.

What would settle the question

Babylon has built the cryptography. The EOTS construction and Bitcoin-native slashing path solve a problem that BTCFi spent years unable to solve without a bridge or a custodian, and the self-custodial property is why 56,853 BTC were willing to show up at a yield that rounds to nothing. That should not be discounted.

What remains unbuilt is the revenue side, and a handful of specific disclosures would resolve most of the ambiguity in this analysis.

  • The BSN fee schedule. What Corn, BOB and Pell Network remit, in what asset, on what cadence. A single stablecoin- or BTC-denominated payment from an operating BSN would change the character of the argument more than another billion dollars of TVL.
  • A split of staker rewards between BSN-paid fees and BABY issuance. Until that split is published, every advertised APY figure is unauditable.
  • The BABY unlock schedule against the roughly 6.9 billion tokens still to enter circulation, with the portion earmarked for BTC staker rewards identified separately from team and ecosystem allocations.
  • The slashing parameter, stated numerically, with its base and its trigger conditions.
  • Current finality provider concentration, so that the 250-plus provider count can be read as something other than a headcount.

Babylon’s roadmap suggests management sees the revenue problem. The publicized Aave V4 integration, which would let native BTC collateralize stablecoin borrowing through zero-knowledge proofs of Bitcoin state rather than through a bridge, points toward fee income that does not depend on BSN willingness to pay. The supporting claim that on-chain ZK verification costs have fallen from around $15,000 to $10 to $20 per proof comes from the company’s own framing and we have not seen it independently verified, but if verification is genuinely that cheap, lending demand is a far deeper market than shared security. The Babylon Foundation’s $3 million USDT deposit into Aave in May 2026 is small, though it is at least denominated in something other than its own token.

The condition to watch is not TVL and not BABY’s price. It is the first BSN payment made in an asset Babylon does not issue. Until then, the 1.4% ratio between BABY’s market capitalization and the Bitcoin it coordinates is the most accurate available statement of what the market thinks Bitcoin-backed security is currently worth.

References

cover

서론

2026년 5월 중순 기준, 바빌론의 스테이킹 볼트에는 56,853 BTC가 예치되어 있었고, 이는 당시 스냅샷 기준 가격으로 약 56억 4천만 달러에 해당한다. 이 스테이커들에게 보상을 지급하는 토큰인 BABY의 유통 시가총액은 같은 시점 기준 약 7,800만 달러였다. 보안을 대가로 지불되는 자산의 가치가, 그 보안이 지키고 있는 담보 가치의 약 1.4%에 불과한 셈이다.

이 비율이 핵심 긴장이며, 성장세를 근거로 이를 해소할 수는 없다. 바빌론은 실제로 성장하고 있다. 바빌론 제네시스에서는 250개가 넘는 파이널리티 프로바이더가 운영 중이다. 3단계 멀티스테이킹은 첫 번째 비트코인 시큐어드 네트워크(Bitcoin Secured Networks)들로 롤아웃되기 시작했으며, 바빌론이 직접 공개한 생태계 자료에는 Corn, BOB, Pell Network가 명시되어 있다. 슬래싱 사고는 보고된 바 없지만, 우리가 검토한 어떤 자료도 이것이 실제 부재인지 단순히 언급되지 않은 것인지를 독립적으로 검증하지는 않는다. BABY는 2026년 5월 기준 약 $0.020에 거래되었고, 2026년 3월 저점인 $0.0107 대비 주간 약 30% 상승했지만, 2025년 4월에 기록한 사상 최고가 $0.1661 대비로는 여전히 약 88% 낮은 수준이다.

보고된 TVL 자체도 확정된 수치가 아니다. Cryptonomist는 2026년 5월 15일, 바빌론이 출시 1년 만에 TVL 40억 달러를 돌파했다고 보도했다. 같은 달 Phemex는 56,853 BTC, 56억 4천만 달러라는 수치를 보도했다. 두 출처는 서로 일치하지 않는다. 이 격차는 스냅샷 시점의 차이, BTC 가격 가정의 차이, 혹은 1단계에서 락업된 예치금과 제네시스에 위임된 스테이크를 합산했는지 여부의 차이로 설명하는 것이 가장 그럴듯하지만, 확인할 수는 없었다. 바빌론의 경제 구조를 모델링하려는 사람이라면 더 큰 숫자를 선택하기보다 40억~56억 달러 구간을 정직한 범위로 취급해야 한다.

바빌론의 핵심 상품에 가격을 매겨보면 구조적 제약이 드러난다. 비트코인 표시 경제적 보안은 풍부하고 공급 비용이 거의 들지 않는다. 이 비즈니스의 제약 요인은 담보였던 적이 없다. 문제는 어떤 네트워크든 그 보안에 실제 값을 지불할 것인가이다.

잠긴 UTXO에서 공유 보안 마켓플레이스로

img1

바빌론의 3단계는 흔히 순차적인 릴리스로 설명되지만, 사실은 동일한 담보 기반 위에 쌓인 세 가지 별개의 상품으로 이해하는 편이 정확하다.

1단계, 즉 비트코인 락업 단계는 핵심적인 암호학적 주장을 확립했다. 보유자는 비트코인 체인 자체에서 스테이킹 스크립트에 BTC를 락업한다. 래핑도, 브릿지도, 상환 부채를 짊어진 커스터디언도 없다. UTXO는 비트코인 위에 그대로 남아 있으며, 슬래싱 소비 경로와 언본딩 경로를 정의하는 코버넌트 방식 컨트랙트에 의해 제약을 받는다. 1단계는 상한이 설정된 예치 라운드로 진행되었고, 135,290명의 고유 스테이커로부터 57,000 BTC 이상이 모였는데, 이는 바빌론 문서 기준 스냅샷에 따라 유통 중인 비트코인의 약 0.2~0.3%에 해당한다. 이 단계 자체는 수익률을 만들어내지 않았다. 대신 포인트, 포지셔닝, 그리고 그 위에 구축된 리퀴드 스테이킹 토큰을 만들어냈고, 그중 가장 규모가 큰 것이 롬바드(Lombard)의 LBTC다.

2단계는 바빌론 제네시스를 출시했는데, 이는 이중 보안 모델을 갖춘 코스모스 SDK 체인이다. 두 개의 별도 스테이크가 두 개의 별도 기능을 지킨다. BABY 스테이커는 블록을 생성하는 CometBFT 밸리데이터에 위임하고, BTC 스테이커는 그 블록에 대한 파이널리티 투표에 서명하는 파이널리티 프로바이더에 위임한다. 충분한 BTC 가중치를 대표하는 파이널리티 프로바이더들이 서명하기 전까지 블록은 파이널리티를 얻지 못한다. 따라서 비트코인 담보 레이어는 트랜잭션 순서를 정하는 것이 아니라, 토큰 가중치 기반 밸리데이터 세트가 만들어낸 순서를 추인하는 역할을 한다. 별도로, 바빌론 제네시스는 자신의 상태를 비트코인 트랜잭션에 체크포인트로 남기는데, 이는 라이트 클라이언트가 참조할 수 있는 객관적 순서를 제공하고, 순수 지분증명 체인이 안고 있는 장기 공격 표면을 차단한다.

3단계는 파이널리티 레이어를 일반화한다. 동일하게 락업된 BTC를 다른 체인, 즉 비트코인 시큐어드 네트워크(BSN)에 서비스하는 파이널리티 프로바이더에게도 위임할 수 있으며, 바빌론 제네시스는 BSN을 등록하고 위임을 추적하며 보상을 라우팅하는 컨트롤 플레인 역할을 한다. 2025년 3월 롬바드의 설명 자료는 이를 공유 보안을 위한 마켓플레이스라고 묘사하는데, 이는 바빌론의 성공에서 수수료를 얻는 당사자의 홍보성 프레이밍을 반영한 것이지만, 기계적 설명 자체는 충분히 정확하다. BSN이 등록하고, 파이널리티 프로바이더가 참여를 선택하고, BTC 스테이커가 위임하면, BSN의 보상이 같은 경로를 따라 되돌아온다.

이 아키텍처의 성취는 실재하지만 범위가 좁다. 바빌론은 비트코인을 떠나지 않고도 비트코인이 슬래싱 가능한 커밋먼트를 담당할 수 있게 만들었다. 아직 입증하지 못한 것은 그 커밋먼트에 의미 있는 값을 지불할 구매자의 존재다.

초기 BSN들이 지불하는 것, 그리고 공시가 멈추는 지점

img2

바빌론의 문서에서도, 롬바드의 생태계 자료에서도, 우리가 검토한 2차 보도에서도, Corn, BOB, Pell Network가 바빌론 보안 대가로 얼마를 송금하는지에 대한 수치는 찾을 수 없었다. 금액도, 요율도, 지급 자산의 종류도 나와 있지 않다. 이 분석을 촉발한 브리프에는 Manta도 초기 BSN으로 언급되어 있지만, 어떤 1차 자료나 2차 자료에서도 이를 뒷받침하는 내용을 찾지 못했으며 미확인 상태로 처리한다.

이는 사소한 문서 누락이 아니다. 바빌론이 서비스 비즈니스인지 아니면 보조금 프로그램인지를 가르는 단 하나의 숫자이며, 그 부재 자체가 의미 있는 정보다. 실제 매출이 있는 보안 마켓플레이스는 대체로 매출을 공개하는데, 매출이야말로 그 사업의 논거이기 때문이다. 프로토콜이 TVL, 파이널리티 프로바이더 수, 통합 발표는 공개하면서 수수료 체계는 밝히지 않는다면, 가장 간명한 해석은 그 수수료가 밝히면 다른 수치들의 설득력을 깎아먹을 만큼 작다는 것이다.

초기 BSN이 경제적으로 어떤 존재인지 생각해보자. Corn, BOB, Pell은 자체 토큰 공급량과 자체 트레저리를 가진, 그 자체로 부트스트래핑이 필요한 신생 네트워크들이다. 은행이 커스터디 서비스를 구매하듯 보안을 사려는 현금 부자 주체가 아니다. 이들에게 가능한 구조는 자체 네이티브 토큰으로 지급하거나, 향후 전환 가능한 생태계 배분·포인트로 지급하거나, BSN이 바빌론 통합을 받는 대가로 바빌론이 유통을 받는 상호 협정 형태일 가능성이 높다. 이 각각의 경우 BSN은 보조금의 원천이라기보다 순수 소비자가 된다. 만약 BSN이 스테이블코인이나 BTC로 지급한다면 이는 강력한 신호가 될 것이고, 거의 확실히 홍보되었을 것이다.

따라서 오늘날 BTC 스테이커에게 도달하는 보상은 압도적으로 BABY다. 바빌론 자체 문서에도 2단계가 기본 스테이킹 보상을 도입한다고 나와 있는데, 이는 수수료 분배가 아닌 발행을 가리키는 표현이다. BABY의 초기 공급량은 100억 개이며, 같은 문서에 따르면 상한이 없다. Phemex는 2026년 5월 기준 유통량이 107.6억 개 중 38.7억 개, 약 36%라고 보도했으며, 팀 언락, 생태계 그랜트, 스테이킹 보상을 통해 약 69억 개가 아직 유통에 진입할 예정이라고 밝혔다.

매출과 희석의 구분이 중요한 이유는 두 가지가 스트레스 상황에서 다르게 작동하기 때문이다. 외부 자산으로 지급되는 수수료 매출은 BSN 사용자로부터 BTC 스테이커로의 이전이며, 보안 토큰 가격과는 대략 무관하다. 반면 보안 토큰 자체로 지급되는 발행분은 기존 토큰 보유자로부터 스테이커로의 이전이며, 그 가치는 토큰 가격이 무너지는 바로 그 순간 함께 무너진다. 발행분으로 조달되는 수익률은, 세상이 나빠지는 모든 시나리오에서 분모가 스테이커에게 불리하게 움직이는 수익률이다.

BABY 표시 수익률의 산술

img3

우리가 검토한 어떤 자료도 바빌론 스테이커의 감사된, BTC 표시 실현 APY를 공개하지 않으므로 이를 단정하지 않겠다. BTC 스테이커에게 구체적으로 배정된 발행 스케줄 역시 우리가 확보한 자료에서는 세분화되어 있지 않다. 확인 가능한 것은 어떤 수익률이든 그 재원이 되는 예산의 규모이며, 그 한계는 심각하다.

더 관대한 수치인 56억 4천만 달러를 스테이킹된 기반으로 잡아보자. 이 기반에 대해 연 0.5% BTC 표시 수익률을 지급하려면 BTC 스테이커들에게 연간 약 2,800만 달러 상당의 가치를 분배해야 한다. 2026년 5월 기준 BABY의 유통 시가총액 약 7,800만 달러와 비교하면, 이는 유통 물량 전체의 약 36%를 한 청구권자 집단에게 매년 분배하는 것에 가깝다. 1%라면 그 비율은 72%에 근접한다. 완전 희석 밸류에이션 약 2억 1,700만 달러를 기준으로 잡아도, 0.5% 수익률은 매년 토큰 전체 가치의 약 13%를 소진한다.

이번에는 흐름이 아니라 잔량을 보자. 아직 유통되지 않은 약 69억 개의 BABY는 $0.020 기준으로 약 1억 3,800만 달러에 해당한다. 이는 팀 베스팅과 생태계 그랜트에 배정되어 BTC 스테이커에게 결코 도달하지 않을 몫까지 포함한, 남아 있는 공급량 전체다. 미발행 공급량 전체가 BTC 스테이커에게 지급되고 다른 곳에는 전혀 쓰이지 않는다는 허구적 가정을 세워도, 그 총액은 현재 스테이킹된 비트코인 가치의 2.5% 미만이다. 그것도 연간 요율이 아니라 일회성 금액이다.

여기에는 자기강화적 루프가 존재한다. BABY로 표시된 발행분은 담보 기반 대비 시가총액이 작은 시장으로 합리적인 스테이커들에 의해 매도된다. 매도 압력은 가격을 낮추고, 이는 실현 수익률을 낮추며, 프로토콜이 헤드라인 APY를 목표로 삼는다면 이는 더 높은 명목 발행으로 대응되고, 이는 다시 매도 압력을 높인다. 이 루프는 바빌론만의 문제가 아니다. 다만 담보 가치 대비 토큰 가치의 비율이 유독 극단적이기 때문에 여기서 더 첨예하게 나타난다. 이더리움의 밸리데이터는 자신이 지키는 자산으로 보상을 받는다. 바빌론의 BTC 스테이커는 담보에 대한 청구권이 없는 자산으로, 그리고 지금까지는 외부 수수료에 대한 입증된 청구권도 없이 보상을 받는다.

그럼에도 스테이킹하는 이유

수익률이 얇다고 해서 스테이킹이 비합리적인 것은 아니며, 이 지점에서 약세론은 핵심 메커니즘 하나를 인정해야 한다.

바빌론에서 BTC 스테이커는 BTC를 팔지도, 래핑하지도, 이전하지도 않는다. 코인은 스테이커가 통제하는 UTXO에 그대로 남으며, 제약은 있지만 넘겨지지는 않는다. 스테이킹의 실질적 비용은 코버넌트 경로상의 슬래싱 리스크, 언본딩 지연에 따른 유동성 비용, 그리고 스테이킹 스크립트와 정확히 상호작용해야 하는 운영상 리스크다. 장기 보유 목적이고 코인을 옮길 의사가 없는 보유자에게 이 비용들은 거의 0에 가깝다. 어떤 생산요소를 공급하는 한계비용이 0에 가까울 때, 시장은 거의 0에 가까운 가격에서 청산된다. 바빌론의 얇은 수익률은 가격결정의 실패가 아니다. 풍부한 투입물에 대한 정확한 가격이다.

스테이커의 구성이 이를 반영한다. 리퀴드 스테이킹 토큰 발행사들은 BABY 보상이 아니라 LBTC의 유통량과 DeFi 통합에서 경제성을 얻으므로, BABY의 하락은 이들의 비즈니스 논리에 거의 영향을 주지 않는다. 향후 BSN 배분을 노리고 파밍하는 보유자들은 쿠폰이 아니라 향후 에어드랍에 대한 옵션을 인수하는 셈이다. 구조적으로 유휴 상태인 BTC를 보유한 트레저리와 장기 보유자들은 무엇이 들어오든 받는다. 이들 중 누구도 수익률이 좋을 필요는 없다. 마이너스가 아니기만 하면 된다.

이는 지속력 있는 공급 기반이며 TVL의 지속성에 대해 시사하는 바가 있다. 동시에 TVL을 제품·시장 적합성의 증거로 읽을 수 없는 이유이기도 하다. 바빌론의 공급 측은 거의 0에 가까운 가격에서도 초과 청약 상태다. 구속력 있는 제약은 기꺼이 지불할 의사가 있는 BSN의 수요이며, 현재 데이터 어디에도 그 제약이 완화되고 있다는 증거는 없다.

이의 제기(equivocation)만 처벌할 수 있는 슬래싱

img4

바빌론의 슬래싱 집행은 이 스택 전체에서 가장 강력한 엔지니어링 성과이며, 이더리움 리스테이킹과 비교했을 때 가장 오해받는 부분이기도 하다.

파이널리티 프로바이더는 Extractable One-Time Signatures(EOTS)로 서명한다. EOTS 키는 한 높이(height)당 하나의 메시지에만 안전하게 서명할 수 있다. 같은 높이에서 상충하는 두 메시지에 서명하면, 두 서명을 합쳐 대수적으로 개인키가 노출된다. 키가 노출되면 누구든 위임자의 비트코인 UTXO에서 슬래싱 경로를 소비하는 트랜잭션을 구성할 수 있다. 위원회 투표도, 오라클 보고도, 거버넌스 조치도 필요 없다. 처벌은 암호학의 필연적 귀결이며, 집행은 비트코인 위에서 비트코인 UTXO를 대상으로 무허가로 이루어진다.

이는 대부분의 슬래싱 시스템이 갖추지 못한 수준의 객관적 집행 가능성이다. 동시에 극도로 좁은 범위이기도 하다. EOTS 추출은 정확히 하나의 위반, 즉 특정 높이에서의 이의 제기(equivocation)만을 처벌한다. 단순히 서명을 멈추는 파이널리티 프로바이더는 처벌할 수 없다. 검열도 처벌할 수 없는데, 유효한 블록에 서명을 거부하는 행위는 서명 계층에서 오프라인 상태와 구분되지 않기 때문이다. 기술적으로는 유효하지만 의미론적으로 해로운 상태에 서명하는 프로바이더도 처벌할 수 없는데, 유효성이야말로 서명이 증명하는 대상이기 때문이다. 바빌론 보안을 구매하는 BSN은 정확히 이중 파이널라이제이션에 대한 보험을 구매하는 것이며, 그 이상은 아니다.

아이겐레이어의 설계는 이 트레이드오프에서 반대편 극단에 있다. 그곳의 슬래싱 조건은 서비스별로 정의되고 이더리움 컨트랙트에 의해 집행되므로, 훨씬 넓은 범위의 위반, 즉 주관적이어서 증명(attestation)이나 분쟁 절차를 통한 판정이 필요한 조건까지 포함할 수 있다. 넓은 커버리지, 약한 객관성. 바빌론의 커버리지는 최소한이지만 객관성은 거의 절대적이다. 어느 쪽이 절대적으로 우월한 것은 아니며, 각각은 서비스가 실제로 무엇으로부터 보호받아야 하는가라는 서로 다른 질문에 답한다. 라이브니스나 검열을 걱정하는 롤업에게는 바빌론의 메커니즘이 적합한 수단이 아니다.

심각도 파라미터는 문서상 벽에 부딪히는 지점이다. 이 분석을 촉발한 브리프는 이중 서명에 대한 0.1% 페널티를 인용한다. 우리는 바빌론 문서나 우리가 검토한 2차 보도 어디에서도 이 수치, 혹은 다른 어떤 수치도 확인할 수 없었으며, 슬래싱을 설명하는 자료들은 위임된 BTC의 일부가 소각된다고만 언급한다. 이 모호함은 사소하지 않다. 이중 서명이 위임량의 0.1%를 소각한다면, 상당한 BTC 가중치를 가진 파이널리티 프로바이더는 대형 브릿지를 가진 BSN을 공격해 성공했을 때 얻는 가치에 비해 사소한 수준의 페널티에 직면할 수 있다. 만약 훨씬 큰 비율이 소각된다면 경제학은 뒤집힌다. 보안 구매자는 페널티를 모른 채 보호 수준을 가격 매길 수 없으며, 그 페널티가 눈에 띄게 공개되지 않았다는 사실 자체가, 폴리체인 캐피털, 핵 VC, 갤럭시 디지털, OKX 벤처스 등으로부터 약 9,600만 달러를 조달하고 Coinspect, Zellic, Cantina의 감사를 받으며 추구해온 엔터프라이즈급 포지셔닝에 실질적인 걸림돌이다.

멀티스테이킹은 보상 스트림과 위반 도메인을 함께 더한다

img5

3단계의 제안은 하나의 BTC 위임이 여러 BSN을 보호하고 각각으로부터 수익을 얻을 수 있다는 것이다. 이 명제의 보상 측면은 단순히 더해지는 문제다. 리스크 측면은 신중하게 분석해야 하는데, 그 가산성이 아키텍처 자체가 거스르는 상관관계 가정에 의존하기 때문이다.

여러 BSN에 걸친 슬래싱 노출은 포트폴리오적 의미에서 분산되어 있지 않다. 동일한 UTXO가 각 커밋먼트를 뒷받침하므로, 어느 한 BSN에서의 위반이 동일한 담보에 도달한다. 두 번째, 세 번째 BSN을 추가하는 것은 늘어나지 않는 담보 기반에 대해 슬래싱당할 독립적인 기회를 추가하는 것이다. 건별 페널티가 작고 네트워크 간 위반 확률이 진정으로 독립적이라면 기댓값 상으로는 문제가 없다. 독립성이야말로 면밀히 검토해야 할 가정이다.

여기서 처벌 대상이 되는 위반은 파이널리티 프로바이더의 이의 제기(equivocation)이며, 이는 압도적으로 전략적 선택이 아니라 운영상 실패다. 페일오버 이후의 중복 서명 프로세스, 오래된 상태를 재생하는 복원된 스냅샷, 마이그레이션 중의 키 관리 오류 등이 그 예다. 동일한 운영자가 공유 인프라와 공유 키 자재를 사용해 Corn, BOB, Pell Network 전반에서 파이널리티 프로바이더 인스턴스를 운영한다면, 단 하나의 운영상 사고가 여러 BSN에서 동시에 이의 제기를 발생시킬 수 있다. 경제적 위반 도메인은 서로 구분되지만, 운영상 위반 도메인은 하나다. BSN 세트 전반에서 파이널리티 프로바이더가 얼마나 중복되는지에 대한 공개 데이터는 없으며, 이 중복도야말로 멀티스테이킹이 분산인지 레버리지인지를 가르는 가장 중요한 변수다.

이에 대한 반론도 정당하게 다뤄야 한다. BSN들은 진정으로 서로 다른 애플리케이션, 사용자, 수익 모델을 가지고 있으므로, 여러 BSN으로부터 보상을 받는 BTC 스테이커는 오직 바빌론 제네시스 하나에만 노출된 스테이커보다 특정 네트워크 하나의 생존에 덜 의존적이다. 이는 보상 스트림의 실질적 분산이다. 요점은 보상 분산과 위반 분산이 서로 다른 속성이며, 3단계가 전자는 훨씬 더 명확하게 제공하지만 후자는 그렇지 않다는 것이다.

프로바이더 집합의 집중도가 이를 가중시킨다. 2025년 3월 기준 롬바드는 바빌론에서 가장 큰 파이널리티 프로바이더였으며, 전체 스테이킹된 BTC의 40% 이상인 22,508 BTC가 위임되어 있었는데, 이 중 15,038 BTC는 LBTC를 통해, 7,470 BTC는 직접 위임을 통해 들어온 것이었다. 2026년 기준 업데이트된 수치는 찾지 못했으며, 250개 이상이라는 파이널리티 프로바이더 수는 스테이크가 그들 사이에 어떻게 분포되어 있는지에 대해서는 아무것도 말해주지 않는다. 만약 40%에 근접한 점유율이 지금도 유지되고 있다면, 단일 운영자의 서명 인프라가 네트워크를 지키는 비트코인의 절반 가까이를 차지하고 있는 셈이며, 멀티스테이킹은 그 운영자의 운영상 리스크를 자신이 서비스하는 모든 BSN에 전파한다. 최신 집중도 공시의 부재는, 다시 한번, 특정 숫자보다 분석가가 더 우려해야 할 지점이다.

무엇이 이 질문에 답을 줄 것인가

바빌론은 암호학을 구축했다. EOTS 구성과 비트코인 네이티브 슬래싱 경로는 BTCFi가 브릿지나 커스터디언 없이는 수년간 풀지 못했던 문제를 해결했으며, 이 자기 보관(self-custodial) 속성이야말로 56,853 BTC가 거의 0에 수렴하는 수익률에도 기꺼이 참여한 이유다. 이는 폄하할 사항이 아니다.

아직 구축되지 않은 것은 매출 측면이며, 몇 가지 구체적인 공시가 이 분석의 모호성 대부분을 해소할 것이다.

  • BSN 수수료 체계. Corn, BOB, Pell Network가 어떤 자산으로, 어떤 주기로 얼마를 송금하는지. 운영 중인 BSN으로부터의 스테이블코인 혹은 BTC 표시 단 한 건의 지급만으로도, TVL 10억 달러 추가보다 이 논거의 성격을 더 크게 바꿀 것이다.
  • BSN이 지불한 수수료와 BABY 발행분 사이의 스테이커 보상 분할. 이 분할이 공개되기 전까지 광고되는 모든 APY 수치는 검증 불가능하다.
  • 아직 유통에 진입할 약 69억 개 BABY의 언락 스케줄, 그리고 그중 BTC 스테이커 보상에 배정된 몫을 팀 및 생태계 배분과 별도로 명시하는 것.
  • 수치로 명시된 슬래싱 파라미터와 그 기준, 발동 조건.
  • 현재의 파이널리티 프로바이더 집중도, 250개 이상이라는 프로바이더 수가 단순 인원수 이상의 의미를 갖도록.

바빌론의 로드맵은 경영진이 이 매출 문제를 인식하고 있음을 시사한다. 공개된 Aave V4 통합은, 브릿지가 아니라 비트코인 상태에 대한 영지식 증명을 통해 네이티브 BTC가 스테이블코인 대출의 담보가 될 수 있게 하는 것으로, BSN의 지불 의사에 의존하지 않는 수수료 수익으로 향한다. 온체인 ZK 검증 비용이 약 1만 5천 달러에서 건당 10~20달러로 낮아졌다는 뒷받침 주장은 회사 자체의 프레이밍에서 나온 것이며 독립적으로 검증된 것을 우리는 보지 못했지만, 만약 검증이 실제로 그만큼 저렴하다면 대출 수요는 공유 보안보다 훨씬 더 깊은 시장이다. 2026년 5월 바빌론 재단이 Aave에 예치한 300만 달러 규모의 USDT는 작은 금액이지만, 적어도 자체 토큰이 아닌 다른 자산으로 표시되어 있다는 점은 의미가 있다.

주목해야 할 조건은 TVL도, BABY의 가격도 아니다. 바빌론이 자체 발행하지 않는 자산으로 이루어지는 첫 BSN 지급이다. 그때까지, BABY의 시가총액과 바빌론이 조율하는 비트코인 사이의 1.4%라는 비율이, 비트코인 담보 보안이 현재 시장에서 실제로 얼마의 가치를 인정받고 있는지에 대한 가장 정확한 진술이다.

참고 자료

cover

はじめに

2026年5月中旬、バビロンのステーキングボールトには56,853 BTCが預けられており、そのスナップショット時点の価格でおよそ56.4億ドル相当だった。このステーカーに報酬を支払うトークンBABYの時価総額は、同日時点で約7,800万ドル。セキュリティの対価となる資産が、その対価の対象となる担保のわずか1.4%程度の価値しかないということだ。

この比率こそが中心的な緊張関係であり、成長を指摘したところで解消するものではない。バビロンには確かに成長がある。250以上のファイナリティプロバイダーがBabylon Genesis上で稼働している。フェーズ3のマルチステーキングは最初のBitcoin Secured Networksへの展開を開始しており、バビロン自身のエコシステム資料ではCorn、BOB、Pell Networkの名が挙げられている。スラッシングの発生事例は報告されていないが、我々が確認したソースのいずれも、それが単に記載漏れではなく本当に発生していないことを独自に検証したわけではない。BABYは2026年5月時点で$0.020近辺で取引され、2026年3月の安値$0.0107から週間で約30%上昇したものの、2025年4月に付けた過去最高値$0.1661からは依然として約88%下落した水準にある。

TVLの数字自体、確定していない。Cryptonomistは2026年5月15日、バビロンのTVLがローンチから1年で40億ドルを超えたと報じた。同月、Phemexは56,853 BTC、56.4億ドルと報じている。両者は整合しない。この差はスナップショットの取得日、BTC価格の前提、あるいはフェーズ1のロック済み預け入れとGenesisへの委任ステークを合算しているかどうかの違いである可能性が最も高いが、どちらが正しいかは確認できなかった。バビロンの経済性をモデル化しようとする者は、大きい方の数字を選ぶのではなく、40億ドルから56億ドルの範囲を正直な数値として扱うべきだろう。

バビロンの中核サービスに値付けをしようとすると、構造的な制約が浮かび上がる。ビットコイン建ての経済的セキュリティは潤沢に存在し、供給コストはほぼゼロに近い。このビジネスの制約は担保の量ではなかった。問題は、どこかのネットワークがそれに対して実際の価格を支払うかどうかである。

ロックされたUTXOから共有セキュリティ市場へ

img1

バビロンの3つのフェーズは、しばしば一連のリリースとして語られる。しかし実際には、同じ担保基盤の上に積み重なった3つの異なるプロダクトとして理解する方が正しい。

フェーズ1、ビットコインロックフェーズは、中核となる暗号学的な主張を確立した。保有者はビットコインチェーン自体のステーキングスクリプトにBTCをロックする。ラッピングもブリッジもなく、償還債務を抱えるカストディアンも存在しない。UTXOはビットコイン上にとどまり、スラッシング用の支出経路とアンボンディング経路を定義するコベナント型のコントラクトによって拘束される。フェーズ1は上限付きの預け入れラウンドで実施され、135,290のユニークなステーカーから57,000 BTC超を集めた。これはバビロンのドキュメントによれば、スナップショットの取り方次第で流通ビットコインの約0.2~0.3%に相当する。このフェーズ自体は利回りを生まなかった。生んだのはポイント、ポジション、そしてその上に構築された流動性ステーキングトークンであり、その中で最大のものがLombardのLBTCとなった。

フェーズ2ではBabylon Genesisが立ち上がった。これはデュアルセキュリティモデルを持つCosmos SDKチェーンである。2つの独立したステークが2つの独立した機能を担保する。BABYステーカーはCometBFTバリデータに委任し、バリデータがブロックを生成する。BTCステーカーはファイナリティプロバイダーに委任し、プロバイダーがそのブロックへのファイナリティ投票に署名する。十分なBTCウェイトを代表するファイナリティプロバイダーの署名が揃うまで、ブロックは確定しない。つまりビットコイン担保のレイヤーはトランザクションの順序付けを行わず、トークン重み付けのバリデータセットが生成した順序を追認する役割を持つ。これとは別に、Babylon Genesisは自身の状態をビットコインのトランザクションにチェックポイントとして刻み込んでおり、これによりライトクライアントに客観的な順序の拠り所を与え、純粋なプルーフ・オブ・ステークチェーンが抱えるロングレンジ攻撃の攻撃面を塞いでいる。

フェーズ3はファイナリティレイヤーを汎用化するものだ。同じロック済みBTCを、他のチェーン、すなわちBitcoin Secured Networks(BSN)にサービスするファイナリティプロバイダーへ委任できるようになり、Babylon GenesisがBSNの登録、委任の追跡、報酬の経路付けを行うコントロールプレーンとして機能する。Lombardが2025年3月に発表した解説記事はこれを共有セキュリティのマーケットプレイスと表現しているが、これはバビロンの成功から手数料を得る当事者によるプロモーション的な表現である一方、機構上の説明としては十分正確だ。BSNが登録し、ファイナリティプロバイダーが参加し、BTCステーカーが委任し、BSNの報酬が同じ経路を通じて還流する。

このアーキテクチャの達成は実在するが、範囲は狭い。バビロンはビットコインをビットコインから出ることなくスラッシュ可能なコミットメントを担えるようにした。まだ実証されていないのは、その約束に対して意味のある価格を支払う買い手の存在である。

最初のBSNが支払っているもの、そして開示が止まる場所

img2

バビロンのドキュメント、Lombardのエコシステム資料、我々が確認した二次的な報道のいずれにも、Corn、BOB、Pell Networkがバビロンのセキュリティに対して何を送金しているかを示す数字は見当たらなかった。金額も、レートも、建値通貨も不明である。本分析の元となったブリーフではMantaも初期BSNとして挙げられているが、いかなる一次・二次ソースにもその裏付けは見つからず、未確認として扱う。

これは些細な資料の欠落ではない。バビロンがサービス業なのか補助金プログラムなのかを決定する、まさにその一つの数字であり、その不在自体が情報を持つ。実際に収益がある安全保障マーケットプレイスは、その収益を公表する傾向がある。収益こそが説得材料になるからだ。TVL、ファイナリティプロバイダー数、統合の発表は公表しながら手数料体系だけを伏せているとすれば、最も単純な解釈は、その手数料が公表すれば他の数字の説得力を損なうほど小さいということだ。

初期BSNの経済状況を考えてみよう。Corn、BOB、Pellはいずれも若いネットワークであり、それぞれ独自のトークン供給、独自のトレジャリー、そして自らのブートストラップの必要性を抱えている。銀行がカストディを買うようにセキュリティを買い付ける、現金潤沢な事業体ではない。彼らにとって現実的な支払い形態は、自社ネイティブトークンでの支払い、将来の転換を前提としたエコシステム配分やポイントでの支払い、あるいはBSNがバビロンとの統合を得てバビロンがディストリビューションを得るという相互取り決めだろう。いずれの場合も、BSNは補助の供給元ではなく純消費者になる。もしBSNがステーブルコインやBTCで支払っているなら、それは強いシグナルであり、ほぼ確実に喧伝されているはずだ。

つまり、現在BTCステーカーに届いている報酬は圧倒的にBABYである。バビロン自身のドキュメントには、フェーズ2が基本ステーキング報酬を導入すると記されているが、これは手数料分配ではなく発行を表す言い回しだ。BABYの初期供給量は100億トークンで、同じドキュメントによればハードキャップはない。Phemexは2026年5月時点で107.6億トークンのうち38.7億トークン、約36%が流通していると報じ、残りの約69億トークンがチームのアンロック、エコシステム助成、ステーキング報酬を通じて今後流通に入るとしている。

収益と希薄化の区別は重要だ。この二つはストレス下で異なる振る舞いを見せるからだ。外部資産で支払われる手数料収益は、BSNのユーザーからBTCステーカーへの移転であり、セキュリティトークンの価格からはおおむね独立している。セキュリティトークン建てで支払われる発行分は、既存のトークン保有者からステーカーへの移転であり、その価値はトークン価格が下落するのとまさに同じタイミングで崩壊する。発行によって賄われる利回りとは、悪い局面ではことごとくステーカーに不利な方向へ分母が動く利回りである。

BABY建て利回りの算術

img3

我々が確認した限り、バビロンのステーカーに対する監査済みでBTC建ての実現APYを公表しているソースはなく、したがってその数字を断定することはしない。BTCステーカーに特化して割り当てられた発行スケジュールも、入手可能な資料では内訳が示されていない。ただし、その利回りが出てくる元手の予算規模は確定でき、それは厳しい水準だ。

より寛大な数字、56.4億ドルをステーク基盤として取ってみよう。この基盤に対してBTC建てで年率0.5%の利回りを与えるには、1年間でBTCステーカーへ約2,800万ドル相当の価値を分配する必要がある。2026年5月時点のBABYの時価総額約7,800万ドルに対して、これは流通量の約36%に相当する額を、一つの受益者グループに毎年分配することを意味する。1%になればほぼ72%に達する。完全希薄化後の評価額約2億1,700万ドルを基準にしても、年率0.5%の利回りはトークン総価値の約13%を毎年消費することになる。

次にフローではなくストックを見てみよう。まだ流通していない約69億トークンは、$0.020換算で約1億3,800万ドル相当だ。これはチームのベスティングやエコシステム助成に充てられ、決してBTCステーカーには届かない分も含めた残り全トークンの価値である。未発行供給の全てがBTCステーカーに支払われるという架空の前提を置いたとしても、その総額は現在ステークされているビットコインの価値の2.5%未満にしかならない。しかもそれは一回限りの金額であり、年率ではない。

この中には自己強化的なループが存在する。BABY建ての発行分は、時価総額が担保基盤のごく一部でしかない市場に、合理的なステーカーによって売却される。売り圧力が価格を押し下げ、それが実現利回りを押し下げ、プロトコルが表面上のAPI目標を掲げていれば名目発行量の増加でそれに応え、それがさらに売り圧力を増す。このループはバビロン固有のものではない。ただし、担保価値とトークン価値の比率が異常に極端であるため、他の多くのケースよりも顕著に現れる。イーサリアムのバリデータは自らが担保している資産で報酬を受け取る。バビロンのBTCステーカーは、担保に対する請求権を持たない資産で報酬を受け取り、今のところ外部手数料への請求権も証明されていない。

それでもなぜステークするのか

利回りが薄いからといって、ステーキングが不合理になるわけではない。ここは弱気論が一つの重要なメカニズムを認めるべき点だ。

バビロンのBTCステーカーはBTCを売却も、ラップも、譲渡もしない。コインはステーカーが管理するUTXOにとどまり、拘束されるが手放されるわけではない。ステーキングの実質的なコストは、コベナント経路上のスラッシングリスク、アンボンディング遅延による流動性コスト、ステーキングスクリプトを正しく操作する上での運用リスクである。長期保有志向でコインを動かすつもりのない保有者にとって、これらのコストはほぼゼロに近い。ある要素の供給に伴う限界コストがほぼゼロであれば、市場はほぼゼロの価格で均衡する。バビロンの利回りの薄さは価格付けの失敗ではない。潤沢な入力に対する正しい価格である。

ステーカーの構成もこれを裏付ける。流動性ステーキングトークンの発行者は、その経済性をBABY報酬ではなくLBTCの流通量とDeFi統合から得ているため、BABYの下落は彼らの事業ケースにほとんど影響しない。将来のBSN配分を狙って積み立てているホルダーは、クーポンではなく将来のエアドロップに対するオプションを引き受けているにすぎない。トレジャリーや構造的に遊休状態のBTCを持つ長期保有者は、発生するものを何であれ受け取る。この参加者のいずれも、利回りが良いものである必要はない。ただ非負であればよいのだ。

これは持続的な供給基盤であり、TVLの持続性についての情報を与える事実でもある。同時にこれこそが、TVLをプロダクトマーケットフィットの証拠として読めない理由だ。バビロンの供給サイドはほぼゼロに近い価格でも供給過剰である。制約となっているのは、支払う意思を持つBSNからの需要であり、現在のデータのどこにもその制約が緩んでいるという兆候はない。

二重署名しか罰せないスラッシング

img4

バビロンのスラッシング執行機構は、このスタックの中で最も強力なエンジニアリング上の主張であり、イーサリアムのリステーキングと比較したときに最も誤解されやすい部分でもある。

ファイナリティプロバイダーは抽出可能ワンタイム署名(EOTS)で署名する。EOTSの鍵は各高度につき1つのメッセージにのみ安全に署名できる。同じ高度で2つの矛盾するメッセージに署名すると、2つの署名が代数的に組み合わさって秘密鍵が暴露される。鍵が暴露されれば、誰でも委任者のビットコインUTXOのスラッシング経路を使う支出トランザクションを構築できる。委員会の投票もオラクルの報告もガバナンスによる行動も必要ない。ペナルティは暗号学の帰結であり、その執行はパーミッションレスで、ビットコイン上でビットコインUTXOに対して直接実行される。

これは、多くのスラッシングシステムにはない客観的な執行可能性を持つ。ただし極めて狭い範囲でもある。EOTSの鍵抽出が罰するのは、ある高度での二重署名という一種類の不正行為だけだ。ファイナリティプロバイダーが単に署名を止めるという不正は罰せられない。検閲も罰せられない。有効なブロックへの署名を拒むことは、署名レイヤーではオフラインであることと区別がつかないからだ。技術的には有効だが意味的に有害な状態への署名も罰せられない。署名が証明するのはあくまで妥当性そのものだからだ。バビロンのセキュリティを買うBSNは、二重ファイナライゼーションに対する保険を買っているのであって、それ以外の何物でもない。

EigenLayerの設計はこのトレードオフの反対側に位置する。そこでのスラッシング条件はサービスごとに定義され、イーサリアムのコントラクトによって執行されるため、はるかに広い範囲の不正行為をカバーできる。主観的な条件や、アテステーションや紛争解決プロセスを要する条件も含まれる。カバー範囲は広いが客観性は弱い。バビロンのカバー範囲は最小限だが、客観性はほぼ絶対的だ。どちらが厳密に優れているというわけではなく、あるサービスが実際に何から保護を必要とするかという問いに対して、それぞれ異なる答えを出しているにすぎない。ライブネスや検閲を懸念するロールアップにとって、バビロンの機構は適切な手段ではない。

深刻度パラメータについては、資料の壁にぶつかる。本分析の元となったブリーフは二重署名に対して0.1%のペナルティを挙げている。しかしバビロンのドキュメントにも、我々が確認した二次的な報道にも、この数字、あるいはいかなる具体的な数字も裏付けを見つけることができなかった。スラッシングを説明するソースは、委任されたBTCの一部が焼却されるとしか述べていない。この曖昧さは些細なことではない。もし二重署名が委任額の0.1%を焼却するだけなら、大きなBTCウェイトを持つファイナリティプロバイダーが直面するペナルティは、大規模なブリッジを持つBSNへの攻撃を成功させた場合の価値に比べれば些細なものになりかねない。もっと大きな割合であれば経済性は逆転する。セキュリティの買い手はペナルティを知らずにその保護に値付けはできず、そのペナルティが目立つ形で公表されていないという事実そのものが、バビロンが目指してきたエンタープライズ級の位置付けにとって現実の障害となっている。バビロンはPolychain Capital、Hack VC、Galaxy Digital、OKX Venturesなどから約9,600万ドルを調達し、Coinspect、Zellic、Cantinaによる監査を受けている。

マルチステーキングは報酬ストリームと不正ドメインを同時に足し合わせる

img5

フェーズ3の提案は、1つのBTC委任で複数のBSNを担保でき、それぞれから報酬を得られるというものだ。この報酬側の主張は単純に加算的である。リスク側は慎重な分析が必要であり、加算性はアーキテクチャが逆行させている相関の前提に依存しているからだ。

複数のBSNにまたがるスラッシングエクスポージャーは、ポートフォリオの意味での分散にはなっていない。同じUTXOが各コミットメントを担保しているため、どこか一つのBSNでの不正が同じ担保に到達する。2つ目、3つ目のBSNを追加することは、成長しない担保基盤に対してスラッシュされる独立した機会を追加することを意味する。1件あたりのペナルティが小さく、ネットワーク間で不正の確率が真に独立していれば、期待値としては問題ない。この独立性という前提こそ、精査に値する。

罰せられる不正はファイナリティプロバイダーによる二重署名であり、これは戦略的な選択というよりも圧倒的に運用上の失敗である。フェイルオーバー後の重複した署名プロセス、古い状態を再生する復元済みのスナップショット、移行時の鍵管理ミス。もし同じオペレーターが共有インフラと共有鍵材料を使ってCorn、BOB、Pell Networkにまたがるファイナリティプロバイダーのインスタンスを運用していれば、単一の運用インシデントが複数のBSNで同時に二重署名を発生させかねない。経済的な不正ドメインは分かれていても、運用上の不正ドメインは一つである。BSNセットをまたぐファイナリティプロバイダーの重複度合いについて公開データはなく、この重複こそが、マルチステーキングが分散なのかレバレッジなのかを決める最も重要な要素である。

反論にも公平に耳を傾けるべきだ。BSNはそれぞれ真に異なるアプリケーション、ユーザー、収益モデルを持っており、複数のBSNから報酬を得るBTCステーカーは、Babylon Genesisのみに依存するステーカーよりも特定の一ネットワークの存続に依存する度合いは低い。これは報酬ストリームにおける実在の分散である。ポイントは、報酬の分散と不正の分散は別の性質だということであり、フェーズ3は前者ははるかに明確に提供しているが、後者ははるかに不明瞭にしか提供していない。

プロバイダー集合の集中度がこれを増幅させる。2025年3月時点で、Lombardはバビロン最大のファイナリティプロバイダーであり、全ステークBTCの40%超、22,508 BTCが委任されていた。うち15,038 BTCがLBTC経由、7,470 BTCが直接委任だった。2026年時点での更新された数字は見つからず、250超というファイナリティプロバイダー数は、ステークがその中でどう分布しているかについては何も語らない。もし40%に近いシェアが今も続いているなら、単一のオペレーターの署名インフラがネットワークを担保するビットコインの過半近くを跨いでいることになり、マルチステーキングはそのオペレーターの運用リスクを、そのオペレーターが仕えるあらゆるBSNへ伝播させる。集中度に関する現在の開示がないこと自体、いかなる個別の数字よりも分析者が懸念すべき点である。

何が決着をつけるのか

バビロンは暗号学を作り上げた。EOTSの構成とビットコインネイティブなスラッシング経路は、BTCFiがブリッジもカストディアンもなしには何年も解決できなかった問題を解決しており、そのセルフカストディ性こそが、56,853 BTCが実質ほぼゼロに近い利回りにもかかわらず集まった理由である。これは軽視されるべきではない。

まだ構築されていないのは収益側であり、いくつかの具体的な開示があれば本分析の曖昧さの大半は解消されるはずだ。

  • BSNの手数料体系。Corn、BOB、Pell Networkが何を、どの資産で、どの頻度で送金しているのか。稼働中のBSNからのステーブルコインまたはBTC建ての支払いが一件でも明らかになれば、TVLがさらに10億ドル増えるよりも議論の性格を変えるだろう。
  • ステーカー報酬のうち、BSNが支払う手数料とBABYの発行分の内訳。この内訳が公表されない限り、喧伝されるAPIの数字はいずれも検証不能である。
  • 今後流通に入る約69億トークンに対するBABYのアンロックスケジュール。BTCステーカー報酬に充てられる分をチームおよびエコシステム配分と分けて特定すること。
  • スラッシングパラメータを数値で示し、その基準と発動条件を明らかにすること。
  • 現在のファイナリティプロバイダーの集中度。それによって初めて250超というプロバイダー数を単なる頭数以上の意味を持つものとして読めるようになる。

バビロンのロードマップは、経営陣が収益問題を認識していることを示唆している。公表されたAave V4統合は、ネイティブBTCをブリッジではなくビットコイン状態のゼロ知識証明を通じてステーブルコイン借り入れの担保にできるようにするもので、BSNの支払い意思に依存しない手数料収入への道を示している。オンチェーンのZK検証コストが約15,000ドルから1証明あたり10~20ドルへ下落したという裏付けとなる主張は、同社自身のフレーミングによるものであり、我々は独立した検証を確認していない。しかし検証が本当にそこまで安価であれば、レンディング需要は共有セキュリティよりもはるかに深い市場となる。Babylon Foundationが2026年5月にAaveへ行った300万ドルのUSDT預け入れは小規模だが、少なくとも自社トークン以外の建値である点は評価できる。

注視すべき条件はTVLでもBABYの価格でもない。バビロンが発行していない資産で行われる最初のBSN支払いである。それまでは、BABYの時価総額とバビロンが調整するビットコインの間の1.4%という比率こそが、ビットコイン担保のセキュリティに現在市場が付けている価値を最も正確に示す指標である。

参考文献

cover

引言

2026年5月中旬,Babylon的质押金库持有56,853枚BTC,按当时快照采用的价格计算价值约56.4亿美元。为这些质押者提供报酬的代币BABY,同期流通市值约为7800万美元。支付安全费用的资产,其价值大约只是它所担保的抵押品的1.4%。

这个比例是核心矛盾所在,指出增长并不能化解它。Babylon确实有增长。Babylon Genesis上运行着250多个finality provider。Phase 3多重质押已开始向首批Bitcoin Secured Networks推出,Babylon自己的生态材料中点名了Corn、BOB和Pell Network。目前没有报告显示发生过罚没事件,不过我们查阅的资料中没有一个能独立证实这种”没有”,而不只是遗漏未提。BABY在2026年5月交易价接近0.020美元,较3月0.0107美元的低点周内上涨约30%,但仍比2025年4月创下的0.1661美元历史高点低约88%。

TVL的具体数字本身也没有定论。Cryptonomist报道称Babylon在2026年5月15日突破40亿美元TVL,称这是上线一年后的成绩。Phemex在同月的报道中则称有56,853枚BTC,价值56.4亿美元。两者对不上。差距最可能是快照日期、BTC价格假设不同,或者是否把Phase 1锁仓存款和Genesis委托质押合并计算所致,但我们无法确认具体原因。任何试图为Babylon经济模型建模的人,都应该把40亿到56亿美元这个区间当作诚实的范围,而不是挑更大的那个数字来用。

给Babylon的核心业务定价,会暴露出结构性的制约。以比特币计价的经济安全供给充裕,几乎没有成本。这门生意的约束从来不是抵押品。问题在于是否有网络愿意为它付出真金白银的价格。

从锁定的UTXO到共享安全市场

img1

Babylon的三个阶段常被描述为一系列版本发布。更准确的理解是,它们是建立在同一个抵押品基础上的三种不同产品。

Phase 1,即比特币锁定阶段,确立了核心的密码学主张。持有者将BTC锁定进比特币链自身上的一个质押脚本中。没有包装,没有桥,也没有托管方承担赎回负债。UTXO留在比特币链上,被一个契约式(covenant-style)合约所约束,该合约定义了一条罚没花费路径和一条解绑路径。Phase 1以限额存款轮次的方式运行,累计吸引超过57,000枚BTC,来自135,290个独立质押者,Babylon的文档将此描述为约占流通比特币的0.2%到0.3%,具体取决于快照时间点。这一阶段本身不产生收益,产生的是积分、卡位以及建立在其上的流动性质押代币,其中Lombard的LBTC成为规模最大的一个。

Phase 2启动了Babylon Genesis,一条采用双重安全模型的Cosmos SDK链。两笔独立的质押分别保障两种独立功能。BABY质押者委托给CometBFT验证者,由其生产区块。BTC质押者委托给finality provider,由其对这些区块签署最终性投票。只有当代表足够BTC权重的finality provider签署完成后,区块才算最终确定。因此,比特币支持的这一层并不负责排序交易,它只是对代币加权验证者集合产生的排序进行确认。另外,Babylon Genesis会把自身状态的检查点写入比特币交易中,这让轻客户端有了一个可回退的客观排序依据,也堵上了纯权益证明链所面临的长程攻击面。

Phase 3将finality层泛化。同一笔锁定的BTC可以委托给服务于其他链——即Bitcoin Secured Networks(BSN)——的finality provider,由Babylon Genesis充当控制层,负责注册BSN、追踪委托关系并分发奖励。Lombard在2025年3月的说明文章将此描述为一个共享安全的市场,这种说法带有推广色彩,毕竟其作者本身从Babylon的成功中获利,但机制描述本身足够准确。BSN注册,finality provider选择加入,BTC质押者进行委托,BSN的奖励沿同一路径回流。

这一架构上的成就是真实的,但也很局限。Babylon确实让比特币具备了在不离开比特币的前提下承担可罚没承诺的能力。它尚未证明的是,有买家愿意为这份承诺支付有意义的价格。

首批BSN支付了什么,信息披露又止步于何处

img2

无论是在Babylon的文档、Lombard的生态材料,还是我们查阅的二手报道中,都找不到Corn、BOB或Pell Network为Babylon安全支付了多少费用的具体数字。没有金额,没有费率,也没有计价资产。促成本次分析的主题简报中还提到Manta是早期BSN之一,但我们在任何一手或二手资料中都未能找到佐证,故将其视为未经证实。

这不是个小小的文档缺失。这恰恰是决定Babylon究竟是一门服务生意还是一个补贴项目的关键数字,而它的缺失本身就很能说明问题。一个真正有收入的安全市场往往会公布自己的收入,因为收入就是最有说服力的论据。当一个协议乐于公布TVL、finality provider数量和集成公告,却对费用结构只字不提时,最合理的解读是:这笔费用小到公布出来反而会拆穿其他数字的台。

设身处地想想早期BSN的经济处境。Corn、BOB和Pell都是年轻的网络,有自己的代币供给、自己的国库,自己也需要冷启动。它们不是像银行采购托管服务那样,拿着大把现金去采购安全服务的富裕主体。它们可行的方案大概是用自己的原生代币支付、用生态分配额度或积分支付并承诺未来兑换,或者搞成互惠安排——BSN获得Babylon的集成,Babylon获得分发渠道。这几种方式都会让BSN变成补贴的净消耗方,而不是补贴的来源方。如果BSN真的用稳定币或BTC支付,那将是一个强烈的信号,也几乎必然会被大肆宣传。

所以目前流向BTC质押者的奖励绝大部分是BABY。Babylon自己的文档写道,Phase 2引入了基础质押奖励,这种措辞描述的是发行,而不是费用分配。BABY的初始供应量为100亿枚,同一份文档称没有硬顶。Phemex报告称截至2026年5月,107.6亿枚代币中有38.7亿枚流通,约占36%,还有约69亿枚将通过团队解锁、生态补助和质押奖励陆续进入流通。

收入和稀释之间的区别很重要,因为二者在压力下的表现截然不同。用外部资产支付的费用收入,是从BSN用户向BTC质押者的转移,与安全代币本身的价格基本无关。而用安全代币支付的发行,是从现有代币持有者向质押者的转移,其价值恰恰会在代币下跌时同步崩溃。靠发行支撑的收益,其分母恰恰会在最糟糕的情形下对质押者不利。

一份以BABY计价的收益的算术

img3

我们查阅的资料中没有一份公布经过审计、以BTC计价的Babylon质押者实际年化收益率,所以我们不会妄下断言。专门分配给BTC质押者的发行计划,在我们能看到的材料中也没有单独列出。能确定的是这份收益必须从中支取的预算规模有多大,而这个上限相当严峻。

以更宽松的56.4亿美元质押基数计算。如果BTC质押者要获得0.5%的以BTC计价年化收益率,一年就需要向他们分发约2800万美元的价值。对照BABY在2026年5月约7800万美元的流通市值,这几乎相当于把全部流通盘子的36%,每年分给一个单一的索取群体。若收益率是1%,这个比例逼近72%。即便按约2.17亿美元的完全稀释估值来算,0.5%的收益率也会每年吞掉这个代币总价值的约13%。

再来看存量而非流量。约69亿枚尚未流通的BABY代币,按0.020美元计算价值约1.38亿美元。这还是全部剩余代币,包括那些注定不会流向BTC质押者、而是留给团队归属和生态补助的部分。哪怕假设——这纯属虚构——全部未发行供应量都付给BTC质押者,别的一分不给,总额也不到当前质押比特币价值的2.5%。而且这还是一笔一次性的总额,不是年化比率。

其中还存在一个反身性循环。以BABY计价的发行会被理性的质押者卖出,而这个代币的市值相对于抵押品基数只是一个很小的比例。抛压压低价格,价格下跌又压低实际收益率,如果协议要维持一个headline APY目标,就得靠提高名义发行来弥补,而这又会加剧抛压。这种循环并非Babylon独有,但在这里格外剧烈,因为被担保价值与代币价值之比极端悬殊。以太坊的验证者是用自己所担保的那种资产来获得报酬的。Babylon的BTC质押者获得报酬的资产,对抵押品没有任何索取权,而且到目前为止,对外部费用也没有表现出任何索取权。

为什么大家还是照样质押

收益微薄不代表质押就是不理性的,这一点熊市论点必须承认一个关键机制。

Babylon上的BTC质押者不需要出售、包装或转移BTC。这枚币留在质押者自己控制的UTXO里,只是被约束,并没有被交出去。质押的真实成本是契约路径上的罚没风险、解绑延迟带来的流动性成本,以及正确操作质押脚本的操作风险。对于持有周期长、本来就没打算动用这枚币的持有者来说,这些成本接近于零。当供给某种要素的边际成本接近零时,市场就会在接近零的价格上出清。Babylon的微薄收益并非定价失灵,而恰恰是对一种充裕投入品的正确定价。

质押者的构成也印证了这一点。流动性质押代币发行方的经济模型建立在LBTC的流通和DeFi集成之上,而不是BABY奖励,所以BABY的暴跌几乎不影响它们的商业逻辑。冲着未来BSN空投分配去的持有者,本质上是在为一份未来空投的期权买单,而不是为了一份票息。国库和长期持有者反正BTC本来就闲置,能拿多少算多少。这些参与者都不需要收益率有多好,只需要它不为负。

这是一个持久的供给基础,也解释了TVL为什么能维持——但同样说明TVL不能被读作产品市场契合度的证据。Babylon的供给端在接近零的价格上就已经超额认购了。真正的约束在于BSN愿不愿意付费购买这份安全服务,而目前没有任何数据显示这个约束正在松动。

只能惩罚双签的罚没机制

img4

Babylon的罚没执行机制是整套体系中工程层面最强的主张,也是相较于以太坊再质押最容易被误解的部分。

Finality provider使用可提取一次性签名(EOTS)进行签署。一把EOTS密钥在同一高度只能安全地签署一条消息。如果在同一高度对两条冲突消息签了字,这两个签名放在一起就会以代数方式暴露出私钥。一旦私钥暴露,任何人都可以构造出花费委托人比特币UTXO罚没路径的交易。不需要委员会投票,不需要预言机报告,也不需要治理行动。惩罚是密码学的直接后果,执行是无需许可的,直接在比特币上针对比特币UTXO完成。

这种客观可执行性在罚没体系中是很少见的。但同时它也极其狭窄。EOTS提取只惩罚一种过错:某个高度上的双签。它无法惩罚一个干脆不签名的finality provider。它无法惩罚审查行为,因为拒绝签署一个有效区块,从签名层面看和掉线没有区别。它也无法惩罚一个签署了技术上有效但语义上有害状态的provider,因为签名本身证明的正是”有效”。BSN购买Babylon安全服务,买到的是针对双重最终性的保险,仅此而已。

EigenLayer的设计站在这个权衡的另一端。那里的罚没条件是按服务单独定义、由以太坊合约执行的,这允许覆盖更宽泛的过错集合,包括那些主观、需要证明或争议流程来裁决的条件。覆盖更广,客观性更弱。Babylon的覆盖极小,客观性接近绝对。二者没有孰优孰劣之分,它们回答的是关于一项服务究竟需要防范什么的不同问题。对于一个担心活性或审查问题的Rollup来说,Babylon的这套机制根本不是对症的工具。

严重程度参数是我们碰到文档瓶颈的地方。促成本次分析的简报援引了双签惩罚0.1%的说法。我们在Babylon的文档或我们查阅的二手报道中都找不到这个数字,也找不到任何其他数字的佐证,描述罚没机制的资料只说会烧毁一部分委托的BTC。这种模糊不是无关紧要的细节。如果双签只烧毁委托量的0.1%,那么一个控制着可观BTC权重的finality provider,面对成功攻击一个拥有大额桥资产的BSN所能获得的收益,可能只承担一个微不足道的惩罚。如果烧毁比例大得多,经济账就反过来了。安全买家在不知道惩罚力度的情况下无法为保护定价,而这个惩罚参数没有被显著公布的事实,本身就对Babylon一直以来追求的企业级定位构成了实实在在的障碍——尽管它已从Polychain Capital、Hack VC、Galaxy Digital、OKX Ventures等机构融资约9600万美元,并接受了Coinspect、Zellic和Cantina的审计。

多重质押把奖励叠加起来的同时也把风险域叠加起来

img5

Phase 3的主张是,同一笔BTC委托可以同时保障多个BSN,并从每个BSN获得收益。这句话的收益部分显然是可以简单相加的。风险部分才是需要仔细分析的地方,因为叠加是否成立取决于一个相关性假设,而这套架构恰恰在与这个假设作对。

跨BSN的罚没敞口在投资组合意义上并不是分散的。同一枚UTXO承担着每一份承诺的担保责任,所以任何一个BSN出问题,冲击的都是同一份抵押品。增加第二个、第三个BSN,等于是在一份不会增长的抵押品基数上,增加了独立被罚没的机会。如果单次事件的惩罚很小,而各网络间的过错概率确实相互独立,那么从期望值角度看这没问题。独立性正是那个值得推敲的假设。

被惩罚的过错是finality provider的双签,而双签绝大多数情况下是操作失误而非策略选择——故障切换后重复运行的签名进程、重放旧状态的快照恢复、迁移过程中的密钥管理失误。如果同一个运营方使用共享基础设施和共享密钥材料,同时在Corn、BOB和Pell Network上运行finality provider实例,那么一次操作事故就可能同时在多个BSN上造成双签。经济上的过错域是各自独立的,操作上的过错域却是同一个。我们没有找到关于finality provider在各BSN集合之间重叠程度的公开数据,而这个重叠程度恰恰是判断多重质押究竟是分散风险还是放大风险的最关键输入。

反方论点也应该得到公正的对待。BSN确实拥有各自独立的应用、用户和收入模式,所以一个从多个BSN获得奖励的BTC质押者,对任何单一网络存续的依赖度都要低于只押注Babylon Genesis本身的质押者。这是奖励流真实的分散化。关键在于,奖励的分散化和过错的分散化是两种不同的属性,而Phase 3在前者上做得远比后者干净利落。

Provider集合的集中度加剧了这个问题。截至2025年3月,Lombard是Babylon上最大的finality provider,委托给它的BTC占全部质押量的40%以上,共22,508枚BTC,其中15,038枚通过LBTC进入、7,470枚为直接委托。我们没有找到2026年的最新数字,而250多个finality provider这个数量本身,并不能说明质押量在它们之间是如何分布的。如果接近40%的份额一直延续,那么单一运营方的签名基础设施就横跨了网络中相当大一部分比特币安全保障,而多重质押会把这个运营方的操作风险传导进它服务的每一个BSN中。当前集中度披露的缺失,再一次是比任何具体数字都更值得分析者担心的部分。

什么能够解决这个问题

Babylon已经把密码学部分做出来了。EOTS构造和比特币原生的罚没路径,解决了BTCFi多年来在不依赖桥或托管方的情况下始终无法解决的问题,而这种自托管属性正是56,853枚BTC愿意在收益率几乎为零的情况下入场的原因。这一点不该被忽视。

尚未建成的是收入端,而以下几项具体的信息披露能够解决本文分析中的大部分不确定性。

  • BSN费用结构。Corn、BOB和Pell Network支付了多少、以什么资产、按什么频率支付。哪怕只是一笔来自正在运营的BSN、以稳定币或BTC计价的实际付款,对这个论证性质的改变都会比再多十亿美元TVL更有意义。
  • 质押者奖励中BSN支付费用与BABY发行的拆分比例。在这个拆分被公布之前,任何宣传出来的APY数字都无法审计。
  • BABY的解锁计划,针对尚未流通的约69亿枚代币,把专门留给BTC质押者奖励的部分,与团队和生态分配部分分开列出。
  • 罚没参数,给出具体数值,以及其基数和触发条件。
  • 当前finality provider的集中度,这样250多个provider这个数字才能被解读为不仅仅是一个头数。

Babylon的路线图显示管理层意识到了收入问题。已公开的Aave V4集成计划——让原生BTC通过零知识证明比特币状态、而非通过桥,来抵押借出稳定币——指向了一种不依赖BSN是否愿意付费的费用收入来源。支撑这一说法的论据是,链上零知识验证成本已从约15,000美元降至每次证明10到20美元,这个数字来自公司自己的说法,我们没有看到独立验证,但如果验证成本真的这么低,那么借贷需求是一个比共享安全深得多的市场。Babylon基金会2026年5月向Aave存入300万美元USDT,金额不大,但至少是以自身代币以外的资产计价的。

真正值得关注的条件不是TVL,也不是BABY的价格。而是第一笔以Babylon自己不发行的资产支付的BSN费用。在此之前,BABY市值与它所协调的比特币价值之间1.4%的比例,是市场对”比特币支持的安全服务目前值多少钱”这个问题给出的最准确答案。

参考资料

cover

Introducción

A mediados de mayo de 2026, los vaults de staking de Babylon contenían 56.853 BTC, con un valor aproximado de $5,64 mil millones a los precios usados en esa instantánea. El token que compensa a esos stakers, BABY, tenía una capitalización de mercado circulante de unos $78 millones en la misma fecha. El activo que paga por la seguridad vale aproximadamente el 1,4% del colateral por el que está pagando.

Esa proporción es la tensión central, y no se resuelve señalando el crecimiento. Babylon tiene el crecimiento. Más de 250 finality providers operan en Babylon Genesis. El multi-staking de la Fase 3 ha comenzado a implementarse en las primeras Bitcoin Secured Networks, con Corn, BOB y Pell Network mencionadas en el propio material de ecosistema de Babylon. No se ha reportado ningún incidente de slashing, aunque ninguna de las fuentes que revisamos verifica de forma independiente esa ausencia en lugar de simplemente omitirla. BABY cotizaba cerca de $0,020 en mayo de 2026, con un alza semanal de aproximadamente 30% desde un mínimo de $0,0107 en marzo de 2026, y todavía cerca de un 88% por debajo del máximo histórico de $0,1661 alcanzado en abril de 2025.

El propio TVL reportado no está zanjado. Cryptonomist reportó que Babylon superó los $4 mil millones de TVL el 15 de mayo de 2026, describiéndolo como un año después del lanzamiento. Phemex, escribiendo el mismo mes, reportó 56.853 BTC por $5,64 mil millones. Ninguna fuente concuerda con la otra. La brecha es más plausiblemente una diferencia de fecha de instantánea, de supuesto de precio de BTC, o de si los depósitos bloqueados de la Fase 1 y el stake delegado en Genesis se cuentan juntos, pero no pudimos confirmarlo. Cualquiera que modele la economía de Babylon debería tratar el rango de $4.000M a $5.600M como el rango honesto en lugar de elegir la cifra mayor.

Ponerle precio a la oferta central de Babylon revela la restricción estructural. La seguridad económica denominada en Bitcoin es abundante y casi gratuita de proveer. La restricción de este negocio nunca fue el colateral. Es si alguna red pagará un precio real por ella.

De UTXOs bloqueados a un mercado de seguridad compartida

img1

Las tres fases de Babylon suelen describirse como una secuencia de lanzamientos. Se entienden mejor como tres productos distintos apilados sobre la misma base de colateral.

La Fase 1, la fase de bloqueo de Bitcoin, estableció la reclamación criptográfica central. Un tenedor bloquea BTC en un script de staking en la propia cadena de Bitcoin. No hay wrapping, no hay bridge, y no hay custodio con una obligación de redención. El UTXO permanece en Bitcoin, gravado por un contrato de tipo covenant que define una ruta de gasto por slashing y una ruta de desvinculación. La Fase 1 se ejecutó en rondas de depósito con tope y acumuló más de 57.000 BTC provenientes de 135.290 stakers únicos, lo que la documentación de Babylon enmarca como aproximadamente 0,2% a 0,3% del Bitcoin circulante según la instantánea. Esa fase no produjo rendimiento en sí misma. Produjo puntos, posicionamiento, y los liquid staking tokens construidos sobre ella, de los cuales LBTC de Lombard se convirtió en el mayor.

La Fase 2 lanzó Babylon Genesis, una cadena basada en Cosmos SDK con un modelo de seguridad dual. Dos stakes separados aseguran dos funciones separadas. Los stakers de BABY delegan a validadores CometBFT, que producen bloques. Los stakers de BTC delegan a finality providers, que firman votos de finalidad sobre esos bloques. Un bloque no es final hasta que finality providers que representan peso suficiente de BTC lo hayan firmado. La capa respaldada por Bitcoin, por lo tanto, no ordena las transacciones; ratifica un orden producido por un conjunto de validadores ponderado por tokens. Por separado, Babylon Genesis registra su propio estado en transacciones de Bitcoin mediante checkpoints, lo que da a los light clients un orden objetivo al que recurrir y cierra la superficie de ataque de largo alcance que arrastran las cadenas de proof-of-stake puro.

La Fase 3 generaliza la capa de finalidad. El mismo BTC bloqueado puede delegarse a finality providers que sirven a otras cadenas, las Bitcoin Secured Networks, con Babylon Genesis actuando como el plano de control que registra BSNs, rastrea delegaciones y enruta recompensas. La explicación de Lombard de marzo de 2025 describe esto como un mercado para seguridad compartida, lo cual refleja un enfoque promocional de una parte que gana comisiones por el éxito de Babylon, pero la descripción mecánica es suficientemente precisa. Un BSN se registra, los finality providers se suman, los stakers de BTC delegan, y las recompensas del BSN fluyen de vuelta por el mismo camino.

El logro arquitectónico es real y acotado. Babylon ha logrado que Bitcoin sea capaz de portar un compromiso sujeto a slashing sin salir de Bitcoin. Lo que aún no ha demostrado es un comprador que pague un precio significativo por ese compromiso.

Lo que pagan los primeros BSN, y dónde se detiene la divulgación

img2

No pudimos encontrar, en la documentación de Babylon, en el material de ecosistema de Lombard, ni en la cobertura secundaria que revisamos, ninguna cifra sobre lo que Corn, BOB o Pell Network remiten por la seguridad de Babylon. Ni un monto, ni una tasa, ni una denominación de activo. El brief que motivó este análisis también menciona a Manta como un BSN temprano; no encontramos corroboración de eso en ninguna fuente primaria o secundaria y lo tratamos como no confirmado.

Esto no es un vacío documental menor. Es el número único que determina si Babylon es un negocio de servicios o un programa de subsidio, y su ausencia es en sí misma informativa. Un mercado de seguridad con ingresos reales tiende a publicar sus ingresos, porque el ingreso es el argumento. Cuando un protocolo publica TVL, conteos de finality providers y anuncios de integración mientras deja el esquema de comisiones sin especificar, la lectura más parsimoniosa es que las comisiones son lo bastante pequeñas como para que declararlas debilitaría las demás cifras.

Consideremos qué es un BSN temprano en términos económicos. Corn, BOB y Pell son redes jóvenes con sus propios suministros de tokens, sus propias tesorerías y su propia necesidad de arrancar. No son entidades ricas en efectivo comprando seguridad como un banco compra custodia. Las estructuras plausibles a su disposición son el pago en su propio token nativo, el pago en asignación de ecosistema o puntos con conversión futura, o arreglos recíprocos donde el BSN recibe una integración de Babylon y Babylon recibe distribución. Cada una de esas opciones convierte al BSN en un consumidor neto de subsidio en lugar de una fuente de él. Si los BSN pagaran en stablecoins o BTC, eso sería una señal fuerte y casi con certeza se anunciaría.

Así que la recompensa que llega hoy a los stakers de BTC es abrumadoramente BABY. La propia documentación de Babylon establece que la Fase 2 introduce recompensas base de staking, lenguaje que describe emisión más que distribución de comisiones. El suministro inicial de BABY es de 10 mil millones de tokens sin, según la misma documentación, tope máximo. Phemex reportó 3.870 millones de 10.760 millones de tokens circulando en mayo de 2026, aproximadamente 36%, con cerca de 6.900 millones aún por entrar en circulación mediante desbloqueos del equipo, subvenciones de ecosistema y recompensas de staking.

La distinción entre ingreso y dilución importa porque los dos se comportan de manera diferente bajo estrés. El ingreso por comisiones pagado en un activo externo es una transferencia de los usuarios del BSN a los stakers de BTC y es aproximadamente independiente del precio del token de seguridad. Las emisiones pagadas en el token de seguridad son una transferencia de los tenedores existentes del token hacia los stakers, y su valor colapsa justo cuando lo hace el token. Un rendimiento financiado con emisiones es un rendimiento cuyo denominador se mueve en contra del staker en cada mal escenario del mundo.

La aritmética de un rendimiento denominado en BABY

img3

Ninguna fuente que revisamos publica un APY auditado, denominado en BTC y realizado para los stakers de Babylon, así que no afirmaremos uno. El calendario de emisión asignado específicamente a los stakers de BTC tampoco se desglosa en el material disponible para nosotros. Lo que sí se puede establecer es el tamaño del presupuesto del cual debe salir cualquier rendimiento, y ese límite es severo.

Tomemos la base en staking en su cifra más generosa, $5,64 mil millones. Un rendimiento anual del 0,5% denominado en BTC sobre esa base requiere distribuir unos $28 millones de valor a los stakers de BTC en un año. Frente a la capitalización de mercado circulante de BABY, de unos $78 millones en mayo de 2026, eso es cercano al 36% de todo el float circulante, distribuido anualmente, a un solo grupo reclamante. Al 1%, se acerca al 72%. Medido contra la valuación totalmente diluida de aproximadamente $217 millones, un rendimiento del 0,5% sigue consumiendo alrededor del 13% del valor total del token cada año.

Ahora observemos el stock en lugar del flujo. Los aproximadamente 6.900 millones de tokens BABY aún no circulantes valen unos $138 millones a $0,020. Eso es todo el suministro restante, incluyendo las porciones reservadas para vesting del equipo y subvenciones de ecosistema que nunca llegarán a los stakers de BTC. Incluso bajo la ficción de que todo el suministro no emitido se pagara a los stakers de BTC y nada más, el total es menos del 2,5% del valor del Bitcoin actualmente en staking. Y eso es un monto único, no una tasa anual.

Hay un bucle reflexivo dentro de esto. Las emisiones denominadas en BABY son vendidas por stakers racionales en un mercado cuya capitalización es una fracción pequeña de la base de colateral. La presión de venta deprime el precio, lo que deprime el rendimiento realizado, lo que se responde con mayores emisiones nominales si el protocolo apunta a un APY publicitado, lo que aumenta la presión de venta. El bucle no es exclusivo de Babylon. Es más agudo aquí que en la mayoría de los casos porque la proporción entre valor asegurado y valor del token es inusualmente extrema. Los validadores de Ethereum son pagados en el activo que están asegurando. Los stakers de BTC en Babylon son pagados en un activo sin reclamo sobre el colateral y, hasta ahora, sin reclamo demostrado sobre comisiones externas.

Por qué de todas formas hacen staking

El rendimiento escaso no vuelve irracional el staking, y aquí es donde el caso bajista debe conceder un mecanismo clave.

Un staker de BTC en Babylon no vende, no envuelve, ni transfiere el BTC. La moneda permanece en un UTXO que el staker controla, gravado pero no cedido. Los costos reales del staking son el riesgo de slashing en la ruta de covenant, el costo de liquidez del período de desvinculación, y el riesgo operativo de interactuar correctamente con el script de staking. Para un tenedor con horizonte largo y sin intención de mover la moneda, esos costos son cercanos a cero. Cuando el costo marginal de proveer un factor es cercano a cero, el mercado se equilibra a un precio cercano a cero. El rendimiento escaso en Babylon no es un fallo de precio. Es el precio correcto para un insumo abundante.

La composición de los stakers refleja esto. Los emisores de liquid staking tokens derivan su economía de la circulación de LBTC y su integración en DeFi más que de las recompensas de BABY, así que la caída de BABY apenas toca su tesis de negocio. Los tenedores que buscan asignaciones prospectivas de BSN están asegurando una opción sobre futuros airdrops, no un cupón. Las tesorerías y tenedores de horizonte largo con BTC estructuralmente ocioso toman lo que se acumule. Ninguno de estos participantes necesita que el rendimiento sea bueno. Necesitan que sea no negativo.

Esa es una base de oferta duradera y un hecho informativo sobre la persistencia del TVL. Es también por qué el TVL no puede leerse como evidencia de ajuste producto-mercado. El lado de la oferta de Babylon está sobresuscrito a precios que se acercan a cero. La restricción vinculante es la demanda de BSNs dispuestos a pagar, y nada en los datos actuales muestra que esa restricción se afloje.

Slashing que solo puede castigar la equivocación

img4

La aplicación del slashing de Babylon es la afirmación de ingeniería más sólida del stack y la más malentendida en comparación con el restaking de Ethereum.

Los finality providers firman con Extractable One-Time Signatures. Una clave EOTS puede firmar de forma segura un solo mensaje por altura. Firmar dos mensajes en conflicto a la misma altura hace que las dos firmas revelen algebraicamente en conjunto la clave privada. Una vez revelada, cualquiera puede construir la transacción que gasta la ruta de slashing de los UTXOs de Bitcoin de los delegantes. No hay comité que vote, ni oráculo que reporte, ni acción de gobernanza. La penalización es una consecuencia de la criptografía y la aplicación es sin permiso, ejecutada en Bitcoin contra UTXOs de Bitcoin.

Esto es objetivamente aplicable de una manera que pocos sistemas de slashing logran. También es extremadamente acotado. La extracción por EOTS castiga exactamente una falta: la equivocación en una altura. No puede castigar a un finality provider que simplemente deja de firmar. No puede castigar la censura, porque negarse a firmar un bloque válido es indistinguible, a nivel de firma, de estar fuera de línea. No puede castigar a un provider que firma un estado técnicamente válido pero dañino en cuanto a semántica, porque la validez es justo lo que la firma atestigua. Un BSN que compra seguridad de Babylon está comprando un seguro contra la doble finalización y nada más.

El diseño de EigenLayer se sitúa en el otro extremo de este compromiso. Las condiciones de slashing ahí se definen por servicio y se aplican mediante contratos de Ethereum, lo que permite un conjunto de faltas mucho más amplio, incluyendo condiciones que son subjetivas y requieren un proceso de atestación o disputa para adjudicarse. Cobertura más amplia, objetividad más débil. La cobertura de Babylon es mínima y su objetividad es cercana a absoluta. Ninguna es estrictamente mejor; responden preguntas distintas sobre lo que un servicio realmente necesita que se proteja. Para un rollup preocupado por la liveness o la censura, el mecanismo de Babylon no es el instrumento relevante.

El parámetro de severidad es donde chocamos con un muro documental. El brief que motiva este análisis cita una penalización del 0,1% por doble firma. No pudimos corroborar esa cifra, ni ninguna cifra, en la documentación de Babylon ni en la cobertura secundaria que revisamos, y las fuentes que describen el slashing dicen solamente que se quema una porción del BTC delegado. La ambigüedad no es cosmética. Si una doble firma quema el 0,1% de la delegación, entonces un finality provider que controla peso significativo de BTC enfrenta una penalización que podría ser trivial en relación con el valor de un ataque exitoso a un BSN con un bridge grande. Si quema una porción mucho mayor, la economía se invierte. Un comprador de seguridad no puede ponerle precio a la protección sin conocer la penalización, y el hecho de que la penalización no esté publicada de forma prominente es un obstáculo real para el posicionamiento de nivel empresarial que Babylon ha perseguido desde que levantó cerca de $96 millones de Polychain Capital, Hack VC, Galaxy Digital, OKX Ventures y otros, con auditorías de Coinspect, Zellic y Cantina.

El multi-staking suma flujos de recompensa y dominios de falla juntos

img5

La propuesta de la Fase 3 es que una delegación de BTC puede asegurar varios BSN y ganar de cada uno. El lado de la recompensa de esa afirmación es directamente aditivo. El lado del riesgo es donde el análisis debe ser cuidadoso, porque la aditividad ahí depende de un supuesto de correlación en contra del cual juega la arquitectura.

La exposición al slashing entre BSNs no está diversificada en el sentido de portafolio. El mismo UTXO respalda cada compromiso, así que una falta en cualquier BSN alcanza el mismo colateral. Agregar el segundo y el tercer BSN suma probabilidades independientes de sufrir slashing contra una base de colateral que no crece. En expectativa eso está bien si la penalización por evento es pequeña y la probabilidad de falta es genuinamente independiente entre redes. La independencia es el supuesto que merece escrutinio.

La falta que se castiga es la equivocación por parte de un finality provider, y la equivocación es abrumadoramente un fallo operativo más que una decisión estratégica. Procesos de firma duplicados tras un failover, un snapshot restaurado que reproduce estado antiguo, un error de gestión de claves durante una migración. Si el mismo operador ejecuta instancias de finality provider en Corn, BOB y Pell Network usando infraestructura compartida y material de claves compartido, entonces un solo incidente operativo produce equivocación en varios BSN simultáneamente. Los dominios de falla económicos son distintos; el dominio de falla operativo es uno solo. No tenemos datos públicos sobre el grado de solapamiento de finality providers entre conjuntos de BSN, y ese solapamiento es el insumo individual más importante para determinar si el multi-staking es diversificación o apalancamiento.

El contraargumento merece una consideración justa. Los BSN tienen aplicaciones, usuarios y modelos de ingresos genuinamente distintos, así que un staker de BTC que cobra recompensas de varios de ellos depende menos de la supervivencia de cualquier red individual que un staker expuesto solo a Babylon Genesis. Eso es diversificación real del flujo de recompensa. El punto es que la diversificación de recompensa y la diversificación de falla son propiedades diferentes, y la Fase 3 entrega la primera de forma mucho más limpia que la segunda.

La concentración en el conjunto de providers agrava esto. Lombard era, en marzo de 2025, el mayor finality provider en Babylon con más del 40% de todo el BTC en staking delegado hacia él, 22.508 BTC divididos entre 15.038 BTC llegados vía LBTC y 7.470 BTC delegados directamente. No encontramos una cifra actualizada para 2026, y el conteo de más de 250 finality providers no dice nada sobre cómo se distribuye el stake entre ellos. Si algo cercano a una participación del 40% persiste, entonces la infraestructura de firma de un solo operador se sitúa sobre una pluralidad del Bitcoin que asegura la red, y el multi-staking propaga el riesgo operativo de ese operador hacia cada BSN al que sirve. La ausencia de una divulgación de concentración actual es, de nuevo, la parte que debería preocupar a un analista más que cualquier cifra en particular.

Qué zanjaría la cuestión

Babylon ha construido la criptografía. La construcción de EOTS y la ruta de slashing nativa de Bitcoin resuelven un problema que BTCFi pasó años sin poder resolver sin un bridge o un custodio, y la propiedad de autocustodia es la razón por la que 56.853 BTC estuvieron dispuestos a aparecer a un rendimiento que redondea a nada. Eso no debería descontarse.

Lo que queda sin construir es el lado del ingreso, y un puñado de divulgaciones específicas resolverían la mayor parte de la ambigüedad de este análisis.

  • El esquema de comisiones de los BSN. Qué remiten Corn, BOB y Pell Network, en qué activo, con qué cadencia. Un solo pago denominado en stablecoin o en BTC proveniente de un BSN en operación cambiaría el carácter del argumento más de lo que lo haría otro billón de dólares de TVL.
  • Una división de las recompensas de los stakers entre comisiones pagadas por BSN y emisión de BABY. Hasta que se publique esa división, toda cifra de APY publicitada es no auditable.
  • El calendario de desbloqueo de BABY frente a los aproximadamente 6.900 millones de tokens aún por entrar en circulación, con la porción reservada para recompensas de stakers de BTC identificada por separado de las asignaciones de equipo y ecosistema.
  • El parámetro de slashing, indicado numéricamente, con su base y sus condiciones de activación.
  • La concentración actual de finality providers, para que el conteo de más de 250 providers pueda leerse como algo más que un simple recuento de cabezas.

La hoja de ruta de Babylon sugiere que la dirección ve el problema de ingresos. La publicitada integración con Aave V4, que permitiría que el BTC nativo colateralice préstamos de stablecoins mediante pruebas de conocimiento cero del estado de Bitcoin en lugar de un bridge, apunta hacia un ingreso por comisiones que no depende de la disposición a pagar de los BSN. La afirmación de respaldo de que los costos de verificación ZK en cadena han caído de unos $15.000 a entre $10 y $20 por prueba proviene del propio encuadre de la empresa y no lo hemos visto verificado de forma independiente, pero si la verificación es genuinamente tan barata, la demanda de préstamos es un mercado mucho más profundo que la seguridad compartida. El depósito de $3 millones en USDT de la Fundación Babylon en Aave en mayo de 2026 es pequeño, aunque al menos está denominado en algo distinto de su propio token.

La condición a vigilar no es el TVL ni el precio de BABY. Es el primer pago de un BSN hecho en un activo que Babylon no emite. Hasta entonces, la proporción de 1,4% entre la capitalización de mercado de BABY y el Bitcoin que coordina es la declaración disponible más precisa de lo que el mercado cree que vale actualmente la seguridad respaldada por Bitcoin.

Referencias

Read next다음으로 읽기次に読む继续阅读Leer a continuación

Follow the next market structure breakdown 다음 시장 구조 분석 받기 次の市場構造分析をフォロー 关注下一篇市场结构分析 Sigue el próximo análisis de estructura de mercado

New Steadyrain research is published several times a week across DeFi risk, BTCFi, stablecoins, and RWA. Steadyrain은 DeFi 리스크, BTCFi, 스테이블코인, RWA 분석을 매주 여러 차례 발행합니다. SteadyrainはDeFiリスク、BTCFi、ステーブルコイン、RWAの分析を毎週公開しています。 Steadyrain 每周发布 DeFi 风险、BTCFi、稳定币和 RWA 研究。 Steadyrain publica análisis sobre riesgo DeFi, BTCFi, stablecoins y RWA varias veces por semana.