ETH Staking: Who Really Controls Your Funds?
Staking ETH into a validator sounds simple enough, but what happens to your funds afterward is more complex than it initially seems. In today's market where various staking products are abundant, users tend to overlook this crucial question.
The key to understanding non-custodial staking lies in Ethereum's underlying design at the consensus layer. Running a validator involves two distinct permissions: the Signing Key and the Withdrawal Credentials. The Signing Key is used for doing the work, such as participating in attestations and proposing blocks, while the Withdrawal Credentials determine where staked ETH and accrued rewards can be withdrawn to.
This design ensures that those responsible for running validators do not simultaneously hold control over users' funds. Node service providers can maintain validators on behalf of users without owning their ETH, as long as they don't have withdrawal rights. This is why non-custodial staking solutions like imToken work, node operators handle data center operations and network attack defense, but cannot withdraw staked funds to themselves.
Furthermore, the Ethereum protocol itself plays a significant role in determining what happens to staked ETH. Once funds enter a validator, they adhere to uniform rules established by the protocol, such as when they can be activated or withdrawn. This ensures that no party can transfer staked assets at will like regular wallet balances.