Web3 is not a technology and it is not a product category. It is a claim about ownership: that the layers of the internet which currently belong to a small number of companies — your identity, your data, the record of who owns what, the right to decide the rules — can instead be held by their users. The technology exists to make that claim arguable. Whether the claim has been delivered is a different question from whether it can be, and the useful way to examine it is one layer at a time.
The term was coined in 2014 by a co-founder of one of the largest smart contract platforms, as a description of a version of the web where publishing required no permission and where value moved natively rather than through payment processors. That is a coherent ambition with a long history, and the reason it deserves a careful reading is that almost every company now using the label implements two of its four parts and describes the whole.
Web1: a publishing medium with no identity layer
The first web was a set of open protocols for retrieving documents. Anyone could publish by putting a file on a server, and anyone could read it by asking for a URL. There was no account, no profile and no way to know who you were; the network’s identity layer was an address, and the address belonged to a machine rather than a person.
The economics of that arrangement were thin. Pages were hosted by universities, hobbyists and companies that wanted a shopfront, and there was no mechanism for a platform to intermediate the relationship between a publisher and a reader. Advertising existed and was crude. The absence of an identity layer was the defining limitation: a site could not personalise, could not retain a user, and could not build a business on knowing who returned.
That limitation is what the second web solved, and it is worth stating plainly because the trade that followed was deliberate rather than accidental. To personalise, you need to know who is asking. To know, you need an account. To make accounts useful, you need them to work across sites. Every step of that progression was an improvement for users and every step moved authority from the reader to the platform.
Web2: read and write, with an account in the middle
The second web put a database behind the page and a login in front of it. Users created content, and the platform stored it, ranked it, recommended it and monetised it. The arrangement produced an extraordinary amount of value and concentrated it in a small number of firms, because the business model and the architecture pointed the same way: whoever holds the database sets the terms, and whoever sets the terms captures the surplus.
Three properties of that model became the target of the Web3 argument. The first is that identity is rented rather than owned: a suspended account is a suspended presence, and the same identity cannot be carried to a competing service because the platform controls the namespace. The second is that the data produced by users accrues to the platform, including the parts a user would consider private. The third is that the user has no vote: the terms of service are set by the company, changed by the company, and enforced by the company, and the recourse available is exit.
None of those properties was hidden, and each came with a compensating benefit. Identity is managed for the user, which means recovery is a process rather than a catastrophe. Data is used to make products better and mostly free. Governance by a company is faster than governance by users, at least in the short run. Any honest account of the third generation has to begin from the fact that the second generation’s centralisation is a feature that people chose, repeatedly, in exchange for convenience.
Web3: the same three functions, with ownership moved to the edge

Against that background, the Web3 claim is specific rather than sweeping. Identity becomes a key pair that the user generates and holds. State becomes a public ledger that anyone can verify and that no single party can edit. Value moves on the same ledger as the record, so a payment and its entry are one operation rather than two systems reconciling afterwards. Governance becomes a vote by whoever holds the relevant token, executed by code rather than by the company that wrote the terms.
Each of those four substitutions has a cost that the marketing version leaves out. Holding a key means holding the recovery problem, which for most people is the hard part. A public ledger means the record is permanent, which is a feature for settlement and a hazard for privacy. Native value means the payment instruments are private liabilities rather than central bank money. And a token vote means the decision procedure is whoever accumulates votes, with no duty owed by the voters to anyone.
The four substitutions also explain why the third generation arrived first in finance rather than in social media. Financial records are where impermanence and central custody have the highest cost and where the participants are already accustomed to cryptographic identifiers and irreversible settlement. A social network gains less from an uneditable post and loses more from an unmanaged identity.
Layer one: identity, from an account to a key pair
The most consequential layer is also the one with the least adoption, and the reason is not technical. An address is a usable identity: it signs without asking a central service, it works across every application that accepts it, and it cannot be suspended by anybody. Against that, it has no recovery, no human-readable name tied to it by default, and no way to distinguish a person from a program, which is a problem for anything that needs to know whether a human is present.
The practical responses have been to reintroduce the very thing the design tried to remove. Most users hold assets in an account at a company. Many wallets add social recovery, in which a set of guardians can restore access, which is a quorum of trusted parties by another name. Naming services map a name to an address, and the name is registered through a contract, so the namespace is owned by whoever controls that contract.
None of those is a failure; each is a legitimate engineering trade. But the direction of travel is worth noticing. The identity layer is the one where convenience keeps winning, and the reason is that the alternative asks an ordinary person to be their own security operations team for decades.
Layer two: data, from a database to a state record
The phrase “you own your data” is the least examined part of the claim, and it becomes clearer when split into two questions. Where does the record live, and where does the content live?
The record — who owns which asset, what a contract’s parameters are, what a program’s state is — can live on a public ledger, and then it is verifiable by anyone and editable by nobody without a rule change. That is a real difference from a database, and it is why the phrase has force in finance. The content — text, images, video, documents — generally does not, because storing it in shared state is expensive by design, since every validating machine must be able to process it.
The usual solution is content addressing: store the content somewhere, and put a cryptographic hash of it on the ledger. That approach proves that a particular version existed at a particular moment, and it says nothing about availability. A record can survive while the content it points to disappears, because the ledger guarantees the hash and the network that stores the file is a separate system with its own incentives. Understanding that split is the difference between believing in on-chain data and knowing what is actually on the chain.
Layer three: value, from rails to native instruments
This is the layer where the third generation has delivered something measurable, and it did not happen the way the founding documents predicted. The prediction was that a native currency would replace payment networks. The reality is that the most widely used instruments on these ledgers are tokenised claims on national currencies, which are the least exotic idea in the entire field and the reason the layer works.
The reasons for that outcome are legible. A payment instrument needs a unit of account that businesses and employees recognise, and a national currency supplies one. It needs settlement that does not depend on a bank being open in two jurisdictions, and a public ledger supplies that. What it does not need is a new unit of account, which is what the founding documents assumed would be the point.
The result is a layer whose adoption is boring and real: corporate settlement pilots, remittances, venue collateral, and a growing set of businesses whose treasury operations run on tokens rather than on wires. The instrument doing the work is a liability of a private issuer, which means the layer’s most successful product also carries the credit risk of the companies that issue it.
Layer four: governance, from a board to a vote
The last layer is the most contested and the least resolved. A token vote can decide a protocol’s parameters, spend a treasury, or change the rules of a contract, and the procedure is transparent in a way that a board meeting is not. What it does not reproduce is the thing that makes corporate governance enforceable: a duty owed by decision-makers to the people affected by their decisions.
Three gaps follow from that. Voting power and economic exposure are not bound together, so tokens can be borrowed and voted with by a party with no lasting stake. Proposal thresholds and time locks determine what can be executed and when, which is a security feature and also a veto for whoever can afford the delay. And enforcement of a decision is limited to what the code can do, which means a governance vote cannot require anything of a party outside the system.
The practical consequence is that most protocols are governed by a small group of large holders and a constituency that mostly abstains. That is not unique to this industry, and it is a problem the same industry has studied: the mapping between token governance and corporate governance shows the vote but not the fiduciary duty, and the difference is precisely what makes the layer incomplete.
The four working parts

Stated as pieces rather than as a movement, the stack is small: an identity you can carry, a state everyone can verify, a unit that can pay for things, and a procedure for changing the rules. Each of those can be adopted independently, and the pattern of adoption follows the value of the problem it solves.
The ledger and the token were adopted first, because settlement is expensive and cross-border payment is slow. The carryable identity has been adopted where the user base is already technical. And the vote has been adopted mostly by projects that needed a way to distribute a treasury without an owner, which is a problem created by the industry itself rather than by the web.
Decentralisation is not one dial

The most common mistake in evaluating these claims is to treat decentralisation as a single scale that a project is either high or low on. It is at least four questions with separate answers, and a system can be genuinely distributed in one and entirely concentrated in another.
A network can be run by thousands of unrelated machines and its application layer can be gated by one company’s front end. Its rules can be changeable only by a vote and its access can require identity checks. Its infrastructure can be permissionless while its governance sits with a foundation. The framework developed in this field for “sufficient decentralisation” exists because regulators needed a threshold, and the more useful version of the question is descriptive: which row does this claim refer to, and what evidence is there for it.
What has actually been delivered
Setting the rhetoric aside, five things exist that did not before, and each is verifiable. Payments in tokenised national currencies settle across borders without banking hours, at a scale measured in hundreds of billions of dollars monthly, and corporate treasury pilots have moved from experiments to scheduled operations. Lending and trading exist without an intermediary holding the assets, at a scale of tens of billions of dollars, with the caveat that the participants are the lenders.
Access without permission is real: an address can use an application without an account, a jurisdiction or a credit history, at any hour, which is a genuine improvement for anyone the conventional system has declined to serve. Ownership of digital assets without a custodian is real, with the recovery problem attached. And verifiable state is real: any participant can reconstruct the position of a public contract without asking the company behind it for a report.
Those five are not nothing, and they are narrower than the slogans. Each one describes a function where the missing institutions of the conventional system mattered least: payments between parties who do not need credit, lending against collateral rather than against a promise, and record-keeping that benefits from being public.
What has not been delivered, and why
Three of the original ambitions remain unbuilt, and the reasons are consistent rather than technical. A decentralised identity that ordinary people use does not exist, because keys are unforgiving and the convenience of a managed account is hard to beat. A social protocol that users own does not exist at scale, because a social network’s value comes from the people already on it, and no ownership model compensates for an empty room.
User-held data in the general case does not exist either, and this one is the most misunderstood. Storage on a shared ledger is priced for scarce use, so most content will always live elsewhere, and “elsewhere” is either a company’s servers or a separate network with its own economics. A user who holds a hash and a private key holds the proof of what existed rather than the ability to keep it available, and those are different things.
The pattern across all three is that the missing layer is the one where convenience competes with a durable cost. Finance tolerates friction because the alternatives are expensive; social products do not, because the alternatives are free and the switching cost is social rather than financial.
Where the label has been stretched
Two uses of the term deserve to be separated from the claim above. The first is commercial: during the period when the word attracted capital, every product with a token attached to it was described as web3, including applications whose data, identity and governance were all held by a single company. That is not a definitional dispute so much as a description of a fundraising environment.
The second is architectural. A permissioned network in which a known set of institutions validates transactions shares the data structure with a public chain and not the ownership property. Such systems are useful, they are being deployed by the institutions that run the world’s settlement, and describing them as web3 mixes the parts of the claim that are about technology with the parts that are about who holds authority.
Three questions that evaluate any claim
A reader who wants to test a web3 claim rather than absorb it needs three questions, and each has a factual answer. Who holds the keys — the user, or the company that made the application? Who can verify the state — anyone, or only the party that produced the record? And who can change the rules — a vote that is executable, a company that can amend terms, or nobody at all?
Those three answers describe the same system more precisely than any adjective, and they separate the genuinely new from the relabelled. A product can be excellent while answering all three in favour of a company; it simply is not an example of the claim, and saying so is not an insult. The claim is about ownership, and ownership has a testable definition.
A short history of the term
The label has been in use since 2014, when a co-founder of a smart contract platform used it to describe something specific: a web in which publishing needs no permission and value moves natively rather than through a payment processor. That is the original meaning, and it is narrower than almost everything the term is applied to today.
The first wave of adoption was financial rather than social. Between 2017 and 2018 a fundraising format made it possible for a project to issue a token before it had a product, and the resulting boom attached the word decentralised to websites that were databases with a token bolted on. The second wave, from 2020 onward, produced two uses that survived: lending and trading without an intermediary holding the assets, and digital assets whose ownership record is public. Both are narrower than the slogan and both are real.
What followed was a change of register rather than a retreat. After the prices fell, the language of replacement gave way to the language of infrastructure, and the same capabilities began appearing in institutional form: tokenised securities with a depository in the loop, regulated payment tokens, and verifiable credentials. Those deployments share the data structures with the original ambition and share almost none of the ownership claim.
Today the word usually means on-chain assets plus token incentives, which is a description of a mechanism rather than of a web. A reader encountering it should assume the looser meaning and look for the three questions that test the stricter one.
The state of the claim
Eleven years after the term was coined, the ledger, the token and the verifiable state have been delivered at scale in the parts of the economy where settlement matters most. The carryable identity and the executable vote have been delivered to a technical minority and left unresolved for everyone else, and the two missing pieces are the two that require an ordinary person to accept a durable inconvenience.
That is a more interesting outcome than either the marketing or the dismissal. The ambition that succeeded was narrower than the slogan and larger than most people expected: the internet gained a settlement layer that nobody owns, and it gained it in the least fashionable part of the stack, where the record of who owns what is kept. Whether the rest of the claim follows depends on a problem the industry has been solving for a decade without a general answer, which is how to hand somebody a key without handing them a second job.






