I now keep two mental models of the word ship open at the same time.By day I work inside Banco del Austro, where a change to a production system travels through a ticket, a reviewer, a staging environment, a sign-off and a release window before it is ever allowed near a customer's money. By night — and for years before the bank — I write Solidity and Rust for systems where deploy means broadcasting bytecode to a network that will execute it, byte for byte, forever, with nobody's approval and no undo button.The cliché is that banks are slow and rigorous and crypto is fast and reckless. After living in both, I think the cliché has the risk exactly backwards.
The deploy button means two different things
In the bank, a deploy is the tail end of a long and deliberately reversible pipeline: feature branch, pull request, a review gate nobody is allowed to skip, a staging environment, user-acceptance sign-off, a change window, a rollback plan written before the change goes out. Everything is instrumented so the change can be undone. A bad migration gets rolled back. A wrong posting gets a reversing entry. A broken release gets pulled in the next window. The whole ceremony exists to protect a system in which almost nothing is truly final.On-chain, the pipeline is often three people in a Telegram group — but the artifact is the exact opposite. Once a contract is deployed and value is sitting in it, the bytecode is immutable and the ledger is append-only. There is no rollback, no reversing entry, no quiet 3am hotfix, unless you engineered an upgrade path in advance: a proxy pattern, a timelocked admin key, a pause switch. And every one of those escape hatches is itself a new attack surface and a centralisation trade-off you then have to justify to people who chose your protocol because it had neither. The informal culture ships the most unforgiving artifact I have ever worked with.
Reversibility is the hidden variable
A bank runs on a double-entry ledger, and the quiet superpower of double-entry is that a mistake is corrected with another entry, never with a deletion. Add chargebacks, dispute windows and T+n settlement on top, and you have a system where most errors have a recovery path measured in days. That is why the bank can afford so much process: the ceremony is not buying finality, it is buying consistency and an audit trail. The slowness is the premium on a system where errors are survivable.A blockchain inverts the variable. Finality is not a risk to be managed — finality is the product. You reason about reorg depth and probabilistic versus deterministic finality precisely because, past some confirmation threshold, the state is settled against the whole world. An exploit is therefore not a bug ticket; it is a permanent, adversarial transfer of value. So the rigour the bank pours into process, a serious protocol has to pour into the code itself: property-based tests, invariant fuzzing in Foundry, formal verification of the critical paths, multiple independent audits, mechanism-design review of the economics, and a bug bounty that assumes the entire planet is reading your source — because it is.
Communication: a change-advisory board vs. a pinned message
The bank's process has named owners. Requirements are documents, roles are formal, legal and compliance sit in the loop, security review is a gate, and segregation of duties means the person who writes a change is not the person who approves it or the one who releases it. Every decision has an accountable owner and a paper trail. The cost is latency: a change that is technically a two-line diff can still take weeks to coordinate.On-chain, coordination is asynchronous, pseudonymous and meritocratic to a fault. A core contributor might be a handle you have never had on a call. Specs live in a Notion page and a GitHub issue; governance is a forum post and a token vote. The throughput is genuinely extraordinary — and the institutional memory is terrifyingly thin. When the one contributor who held the vault math in their head logs off, the knowledge logs off with them, and there is no runbook and no successor.
The two security postures are mirror images
A bank defends a perimeter with depth: private networks, WAFs, a SOC, scheduled penetration tests, PCI-DSS controls, and a working assumption that the attacker is on the outside and the walls can always be raised higher. The source is closed, and whether rightly or wrongly, some of the model leans on that.On-chain there is no perimeter. The source is public, the mempool is public, the state is public, and the reward for breaking you is denominated directly in dollars and paid out the instant you succeed. You design adversarially from the first line: reentrancy guards, the checks-effects-interactions ordering, oracle-manipulation resistance, MEV awareness, and the overflow checks you get for free in Solidity ≥0.8 but still reason through by hand. There is no SOC to page. The incident response is a Twitter thread at 4am and a war room spinning up a white-hat rescue before the next block.
Identity and trust are inverted
The bank runs on verified identity. KYC and AML mean every actor is known, regulated and accountable, and trust is ultimately institutional — you trust the bank because of what stands behind it. A blockchain runs on the deliberate absence of trusted identity: the entire point is that strangers who cannot verify each other still transact, because consensus and code do the verifying instead. "Code is law" reads like a slogan right up until you have watched it enforced, literally and without appeal, against someone's savings.
What each one taught me
From the bank I learned that process is not bureaucracy for its own sake. Change management, audit trails, segregation of duties and a boring release window are how you operate a system that thousands of people depend on without relying on heroics. I used to read all that ceremony as pure friction. I now read most of it as hard-won lessons that someone encoded so they would not have to be relearned the expensive way.From blockchain I learned that nothing sharpens an engineer like irreversibility and a public adversary. Writing code you cannot patch, for a system whose test environment is a hostile planet with a bounty on your head, makes you more careful than any amount of process ever could.The honest synthesis is that neither culture is the finished one. The bank has the rigour but treats finality as something to be engineered around; crypto has embraced finality but is still inventing the rigour to deserve it. I suspect the next decade of both looks like convergence — banks adopting the deterministic, cryptographically provable guarantees chains take for granted, and serious protocols quietly rediscovering why change-advisory boards exist in the first place.I happen to have a foot in each. Most days it feels less like two jobs and more like watching the same question — how do strangers trust a system with their money — being answered from opposite ends.