ContentsBrowse sections
Basis of analysis
Four evidence layers carry the technical claims here and are kept apart throughout. Implemented capability comes from pinned source in ccip-owner-contracts, chainlink-evm, and payment-abstraction, together with comparator source from api3-contracts, scribe, and pyth-crosschain. The code records and References name the reviewed revision behind each of those repositories. Blockscout verification connects that source to ManyChainMultiSig, RBACTimelock, and Reserves at their deployed addresses. State calls at block 25,539,196 report configured roles and delay. The receipt for transaction 0x9ccabfbc...9c24 and a 250,000-block trace of three Ethereum CCIP on-ramps covering blocks 24,645,139 through 24,895,139 report executed conduct. The two authorizing addresses are recovered from the signatures in the calldata of transaction 0x47602774...2bf0 rather than from its receipt. Outside those four layers, Chainlink's 2017 white paper, CCIP billing documentation, and Payment Abstraction and Reserve announcements state design and policy rather than measurement. None of these layers identifies sunk provider investment or the legal persons behind the signer keys.
Abstract
On April 15, 2026, Ethereum transaction 0x9ccabfbc…9c24 carried one authorized operation through ManyChainMultiSig, RBACTimelock, and the Reserves contract. The receipt contains 45 EarmarkSet events, 45 Withdrawn events, and 45 LINK transfers from Reserves to the same recipient set. The transfers total 95,884.386471 LINK. Two valid signatures appear in the preceding root transaction, recoverable to two addresses in the same authorized signer group. Neither address has a public name, ENS record, or organizational tag on the reviewed explorer surface.
That transaction supplies the focal executed example. Chainlink’s public Payment Abstraction code supplies a separate architectural fact: a designed pathway can receive varied fee assets, consolidate and swap them into LINK, account for provider obligations in LINK, and pay those obligations in LINK. A 250,000-block trace of three Ethereum CCIP on-ramps adds a third fact: the sampled customer-facing fee rail was exercised mainly in WETH, with GHO second and LINK rare.
Together, these facts establish a layered denomination architecture. They do not establish instrumental nonseparability, bilateral monopoly, or hybrid-to-hierarchy drift. Repository code shows capability, explorer verification identifies deployed code, state calls identify configured authority, and receipts show executed conduct. None of those layers identifies sunk provider investment or the legal persons behind the signer keys. Transaction-cost economics therefore enters as an uncompleted test, not as the result. Two-sided pricing, common-unit accounting, and token-value accrual remain serious rival explanations for the same architecture.
Keywords: Chainlink, LINK, payment abstraction, CCIP, service-provider settlement, multisig, denomination, two-sided pricing, asset specificity, transaction-cost economics.
What the Record Shows
A sampled fee interface accepted heterogeneous assets while a separately observed provider-payment lane denominated and discharged obligations in LINK. Administration sat upstream of the transfer: an earmark manager controlled eligibility and amounts, while the final withdraw function was open to any caller and could transfer funds only to the recorded providers.
The missing link is causal. The public record does not show that providers incurred sunk investments whose value would collapse outside a LINK-denominated relationship. It does not identify a bilateral counterparty, measure opportunism, or reconstruct a change in governance form from 2017 to 2026. Those omissions prevent the payment architecture from carrying a Williamsonian conclusion on its own.
Follow the Transaction
The case begins at Ethereum block 24,886,158, mined at 2026-04-15 15:37:23 UTC. Transaction 0x9ccabfbc…9c24 was sent by 0x1868602d…e7a5 to ManyChainMultiSig at 0x28617b62…b99e (Blockscout 2026a). Its calldata invoked execute, with operation nonce 80 and destination 0x08558d8b…5115, an RBACTimelock.
The operation was authenticated one block earlier. Transaction 0x47602774…2bf0 called setRoot with two ECDSA signatures (Blockscout 2026b). Reconstructing the contract’s signed message, keccak256(abi.encode(root, validUntil)) under the Ethereum signed-message prefix, recovers:
-
0x4250121068468df4f15F688Fd9853e45a68428f0 -
0xD4294d1465966baa78985A90fE3d0b123E3d0e49
Both addresses belonged to signer group 1 under the active 13-signer configuration. Group 1 required two signatures, the root accepted one successful subgroup, and the authorization therefore met the configured threshold. The caller of setRoot and execute, 0x1868602d…e7a5, was not one of those two signers. This distinction follows the contract design: in the multisig and timelock source, valid signatures authorize a root, while any address may relay setRoot and any address may execute an authenticated operation (SmartContractKit 2026a).
The authenticated operation called bypasserExecuteBatch on RBACTimelock. Its two calls targeted Reserves at 0x5680681e…171d: first setEarmarks, then withdraw. The receipt contains a one-for-one sequence:
| Receipt item | Count | Observed relation |
|---|---|---|
|
45 |
One event per service-provider address |
|
45 |
The same 45 service-provider addresses |
LINK |
45 |
From |
The 45 transfers total 95,884.386471824065069056 LINK. Event-to-transfer matching carries more analytical weight than that aggregate: the receipt shows Reserves labelling an obligation in LINK, clearing it, and transferring the same asset to recorded beneficiaries in one executed batch. The receipt does not identify legal persons controlling those beneficiary addresses, describe their service contracts, or prove that this batch represents all provider compensation.
The label timelock would mislead at the later state. At block 25,539,196, getMinDelay() returned zero for 0x08558d8b…5115. The April operation had used the bypasser path. Read at that block, 0x08558d8b…5115 was a role-gated execution contract whose configured delay was zero.
Evidence Has Layers
Source code shows implemented capability. Verified deployment connects that code to an address, state at a named block shows configured authority, and transaction receipts show executed conduct. Economic dependence and legal identity require evidence beyond those technical layers.
Explorer source and deployed runtime support how ManyChainMultiSig, RBACTimelock, and Reserves are read here (Blockscout 2026c; Blockscout 2026d; Blockscout 2026e). April claims follow that transaction and its receipt. Later state calls describe the July configuration and are not projected backward onto that execution. A March ConfigSet event and the recovered April signers provide the historical bridge for the signer claim (Blockscout 2026f).
One Architecture, Several Denominations
Historical Direct-Request Model
The 2017 Chainlink white paper describes clients paying node operators in LINK for oracle services (Chainlink Labs 2017). A legacy operator implementation in chainlink-evm retains the same grammar. In the operator-forwarder source, ChainlinkClient sends a request through LINK’s transferAndCall, and Operator records the payment and permits the contract owner to withdraw earned LINK (SmartContractKit 2026b).
This pairing supports a historical design proposition: LINK was the specified payment asset in the original direct-request model. It does not reconstruct the deployed 2017 contracts byte for byte. It also supplies no 2017 measurement of signer identity, compensation governance, bargaining relations, or organizational form. Calling that endpoint hybrid governance would add a classification the primary artifacts do not measure.
Heterogeneous Payment at the CCIP Edge
CCIP separates the fee asset chosen at the interface from other settlement functions. Chainlink’s billing documentation describes fee payment in LINK and alternative assets, including native gas tokens and wrapped forms (Chainlink Documentation 2026). The router and on-ramp source encode the selected fee token and fee amount.
An Ethereum trace of blocks 24,645,139 through 24,895,139 covered three named on-ramps associated with Base, Arbitrum, and Optimism destinations and decoded 2,666 CCIPSendRequested events:
| Fee token | Decoded sends | Share of sampled sends |
|---|---|---|
WETH |
2,547 |
95.54% |
GHO |
112 |
4.20% |
LINK |
7 |
0.26% |
LINK was rare on those exercised fee-token fields during the sampled Ethereum blocks. That finding is a lane-and-window statistic. It does not estimate all CCIP traffic, all Chainlink revenue, or the asset ultimately retained after each send. The window shows interface plurality in actual use, a point source capability alone would leave open.
Conversion as Repository Capability
The Payment Abstraction repository describes a funnel. Its README says the system accepts various fee tokens, consolidates them through CCIP, converts them into LINK, and passes LINK to a service-provider withdrawal contract (SmartContractKit 2026c). The payment-abstraction source allocates the work across modules:
-
FeeRouterforwards allowlisted assets to a fee aggregator. -
FeeAggregatorlets role holders move assets for swapping and bridging. Its bridge message specifies LINK as the CCIP fee token. -
SwapAutomatoris configured around a LINK token, a LINK/USD feed, and a LINK receiver, and automates swaps into LINK. -
ReservesrecordsamountLinkOwedandlinkBalancein juels and transfers LINK to service-provider addresses.
These files establish designed capability and a shared LINK-facing vocabulary. They do not establish that every deployed revenue path invokes every module. The source also fails to prove strong nonseparability. Accounting, conversion, bridging, reserve custody, and payout sit in connected code, yet a proof that changing one denomination requires redesign across all five functions would need dependency analysis, alternative implementations, or observed failed substitutions. No such intervention appears in the record, which leaves nonseparability open at the level of designed capability.
Deployed Obligations and Payout
Reserves narrows the distance between design and use. At the deployed address, its ABI and verified source expose LINK-specific service-provider balances, an allowlist, setEarmarks, and withdraw (Blockscout 2026e). The April receipt then shows those functions operating together.
The control boundary is exact. addAllowlistedServiceProviders, removeAllowlistedServiceProviders, and setEarmarks require EARMARK_MANAGER_ROLE. withdraw(address[]) has no corresponding manager-role check. Once a provider has a positive recorded balance and the contract is unpaused, any caller can trigger the withdrawal, while the funds can go only to the provider address supplied to and checked by the contract. Administrative discretion lies in eligibility, obligation amount, correction, and pause authority. The last mechanical transfer is permissionless within those recorded constraints.
This is stronger than a generic tokenomics claim. Within the focal contract and transaction, LINK is the contractual payout asset in which the observed obligation was recorded and discharged. Product-wide extrapolation would require a complete map of payment-abstraction deployments and service lines. The payment-system meaning of settlement asset is not imported into this one-contract observation (CPSS 2003).
Control Is Visible; Identity Is Not
At block 25,539,196, the role path was:
| Function | Configured authority | Observed boundary |
|---|---|---|
Set provider allowlist and earmarks |
|
The April batch came through this address |
Bypass the earmark-manager timelock |
|
Two recovered group-1 signers authorized the April root |
Own the multisig and administer |
|
A second multisig controls that timelock’s bypasser role |
Relay an authenticated root or operation |
Any address |
Unlabelled EOA |
Trigger withdrawal after a positive earmark |
Any address while unpaused |
The April governance batch triggered it immediately |
The first two rows show cryptographic and role-based authority. They do not identify an employer, corporation, DAO, node-operator association, or contractual principal. On July 15, 2026, the two recovered signer addresses and the relay address had no name, ENS domain, or public tag on the reviewed Blockscout records. Absence of a label is weak evidence about real-world identity, so the analysis records identity as unresolved.
The beneficiary addresses do not resolve the question. A recipient may be an EOA, proxy, small contract, custody address, or payment endpoint. Repeated receipt of LINK can show continuity of an address in a payout series. It cannot show that the recipient controls the signer, made a relationship-specific investment, lacks alternative customers, or accepted a low-powered employment incentive.
This correction changes the institutional description. The observed relation is an administered service-provider obligation inside a role-governed contract system. A bilateral provider-governance dyad would require two identified economic parties and evidence of reciprocal dependence. A hierarchy finding would require evidence of unified ownership, fiat, forbearance, employment-like incentive design, or another operational equivalent. Address roles alone supply neither kind of evidence.
Rival Explanations Earn Priority
The same architecture is compatible with several mechanisms. Any asset-specificity account must outperform them rather than coexist with them as an untested gloss.
Two-Sided Pricing
Oracle infrastructure connects demand for data and cross-chain execution with a supply side that produces, transmits, and maintains those services. Platform theory predicts asymmetric pricing when adoption elasticity, multihoming, and cross-side effects differ across participant groups (Rochet and Tirole 2003; Armstrong 2006). Accepting convenient assets from users while standardizing the provider side in LINK fits that logic. The architecture can reduce payer friction while preserving a separate compensation instrument.
This explanation predicts heterogeneous customer payment even when provider settlement stays uniform. It needs no claim that LINK-specific capital became sunk. Testing it would require fee schedules, subsidies, pass-through rates, provider multihoming, and elasticity estimates beyond the current record.
Common Internal Unit
Heterogeneous receipts create an accounting problem. A system that owes many providers needs a common unit in which to record balances, check reserve sufficiency, correct prior amounts, and clear payouts. LINK may function as that internal unit because the service-provider side already uses it. The Reserves variables and events directly support the common-unit description.
This explanation is operational rather than causal. It accounts for why conversion and obligation accounting converge on one asset. It does not explain why LINK was chosen over ETH, a stablecoin, or a synthetic ledger unit. Answering that question would require comparative cost data and changeover estimates.
Token-Value Accrual
The official Payment Abstraction and Reserve announcements describe conversion into LINK and strategic accumulation of LINK from revenue (Chainlink 2025a, 2025b). Token-based platform models supply a familiar economic rationale: platform activity can be linked to demand for, or accumulation of, a native token (Cong, Li, and Wang 2022). That rationale can produce the observed conversion path even if the operational modules are technically replaceable.
Value accrual and provider settlement can operate together. A design may convert fees to support token demand, use the resulting asset as a common accounting unit, and pay providers in that asset. The present evidence does not rank the relative importance of those purposes.
What Remains Distinctive
The strongest residual observation is narrower than the earlier theory. Customer-facing denomination and provider-facing denomination diverge. LINK is scarce in the sampled fee-token field and decisive in the observed provider obligation. Administrative keys set who qualifies and how much is owed; public execution can complete payment after those decisions.
Abstraction at the edge can hide denomination deeper in the stack. The observed arrangement supports questions about who selects the internal unit, who bears conversion risk, how provider amounts are calculated, and how easily a service provider can demand another asset. The current record answers the first question at the contract-role level and leaves the others open.
Williamson Test Fails on Its Present Evidence
Williamson’s asset specificity concerns investments whose productive value falls when redeployed to another transaction or user (Williamson 1985, 1991). Empirical work must therefore identify an investment, its owner, its best alternative use, the loss on redeployment, and the governance response to the resulting dependency. Contract duration or repeated dealing may be consistent with specificity, but each can arise for other reasons (Joskow 1987).
The observed contracts and transactions establish no provider-level redeployment loss. Running oracle infrastructure, holding working balances, integrating an API, or receiving LINK may involve costs. The record does not measure which costs are sunk, whether they are specific to LINK, whether providers can hedge or convert promptly, whether the same infrastructure serves other networks, or whether alternative customers remain available. Address persistence cannot substitute for those measurements, and the observed record contains none of them.
The proposed five-function compound adds another burden. A compound-specificity claim needs evidence that swapping the instrument at one function propagates material redesign costs through the others. The repository shows a LINK-oriented module graph. It does not contain an intervention, migration estimate, failed redesign, or dependency proof establishing that graph as jointly nonseparable. Bridging in LINK and paying providers in LINK may share an asset while remaining technically separable decisions.
The governance endpoint also fails the Williamson test. On-chain permissions show configured command over contract functions. Williamsonian hierarchy is an institutional form defined through a supporting syndrome that includes fiat, forbearance, and low-powered incentives. The available evidence contains no employment relation, internal dispute regime, compensation schedule, or evidence that incentives became lower powered. It also lacks a measured 2017 governance endpoint. A trajectory from hybrid to hierarchy cannot be estimated from one unmeasured baseline and one ambiguous endpoint.
At most, this is candidate evidence for a compound-specificity mechanism; it is not treated here as a closed result. The phrase marks a research programme whose decisive variables remain unobserved. The documented result is settlement layering with administered obligation setting.
Comparators Are Architectural Controls
API3, Chronicle, and Pyth clarify what can be built. They do not supply a ranked scale of governance drift.
API3. Api3MarketV2.buySubscription accepts native value and funds a sponsor wallet that pays update-transaction costs (API3 2026). API3’s token and DAO operate on other surfaces. The case demonstrates that an oracle service can keep a governance token separate from a native-asset service-payment path. It does not show that API3 lacks provider contracts or off-chain dependency.
Chronicle. The Scribe core contract verifies signed feed updates and gates reads through its toll access-control mechanism (Chronicle 2026). No protocol-token settlement path appears in that core contract. Permissioning can therefore be technically central even when a native token is absent from the reviewed service core. Commercial agreements and compensation remain outside this code-level comparison.
Pyth. The pyth-crosschain EVM interface requires update fees in wei and exposes getUpdateFee, while PYTH governance and staking occupy distinct modules (Pyth Network 2026). The case demonstrates separation between a native-gas update fee and a governance-token system. It does not identify the full compensation arrangement for publishers.
These controls defeat technological inevitability. Oracle delivery does not require a native-token payout lane, and access control does not require token settlement. They leave the Chainlink choice economically interesting. They do not prove that the choice caused lock-in or hierarchy.
What Would Establish Dependence
A stronger institutional claim requires a joined money path from customer fee through conversion, reserve accounting, earmarking, and provider payment, together with the identities and changing authority of the relevant actors. Provider contracts, treasury exposure, integration costs, alternative customers, multihoming, and the cost of changing denomination would show whether the observed LINK path creates economic dependence.
A denomination change, provider exit, price shock, or contested earmark policy would help separate the rival explanations. Common-unit accounting predicts adjustment concentrated in ledgers and pricing, token-value accrual predicts resistance around reserve policy, and asset specificity predicts measurable losses for parties unable to redeploy their investment.
Scope of Inference
The observed population is one protocol family: three sampled Ethereum CCIP on-ramps, one deployed Reserves lane, and one focal payout transaction. Observation is indexed per layer: a 250,000-block CCIP trace across blocks 24,645,139 through 24,895,139, a focal payout at block 24,886,158, and state calls at block 25,539,196. A March ConfigSet event bridges the signer claim and is named here without a block number. The explorer label check is dated July 15, 2026 rather than block-indexed. Four evidence layers carry the result: implemented capability from repository source, deployed identity from verified explorer source, configured authority from state at a named block, and executed conduct from receipts. Within those bounds the claim domain is denomination and administered obligation setting.
Sampled sends cannot estimate all CCIP use. The focal payout cannot estimate all Chainlink provider compensation. The source graph cannot establish that every production fee reaches the observed reserve. Deployments of CCIP or Payment Abstraction beyond the sampled Ethereum surface, periods outside the sampled windows, and service lines outside the observed lane sit outside the record entirely.
The institutional inference stops at configured authority and executed settlement. Public keys do not identify legal persons. Contract events do not reveal service terms, treasury policy, hedging, alternative customers, or redeployment cost. The article therefore makes no claim about private motive, organization-wide control, product-wide revenue composition, bilateral dependency, or governance form.
Falsification
The affirmative claim under test is narrow: on the records examined here, a sampled CCIP fee interface was exercised mainly in non-LINK assets while a separately observed Reserves lane recorded and discharged provider obligations in LINK under administered eligibility and amount setting. Five observations would defeat it, each anchored in a record this analysis already names or one that could be located on the same chain.
Receipt reconstruction. If an independent decoding of transaction 0x9ccabfbc…9c24 returned counts other than 45 EarmarkSet events, 45 Withdrawn events, and 45 LINK transfers to the same 45 addresses, or a total other than 95,884.386471824065069056 LINK, the reconstruction in Follow the Transaction would fail.
Authorization. If re-recovering keccak256(abi.encode(root, validUntil)) from transaction 0x47602774…2bf0 under the Ethereum signed-message prefix returned addresses outside signer group 1, or if the March ConfigSet record placed either recovered address in a different group, the two-signature authorization claim would fail, and the April batch would stand without a demonstrated authorization path.
Deployment identity. If Blockscout’s verified source for 0x28617b62…b99e, 0x08558d8b…5115, or 0x5680681e…171d diverged from the repository code used to read those contracts, the bridge from source capability to deployed identity would fail, and the interpretation set out in Evidence Has Layers would lose its middle layer.
Role gating. If setEarmarks, addAllowlistedServiceProviders, and removeAllowlistedServiceProviders at the deployed Reserves address ran without an EARMARK_MANAGER_ROLE check at the observed block, or if a setEarmarks call succeeded from an address outside that role, the administered half of the claim would fail.
Fee-token distribution. If a rerun of the trace across blocks 24,645,139 through 24,895,139 on the same three on-ramps decoded a materially different distribution across the 2,666 CCIPSendRequested events, the divergence between customer-facing and provider-facing denomination would fail for that window.
Falsifying the withheld inferences runs the other way. Provider contracts showing redeployment loss, an identified bilateral counterparty, or a measured 2017 governance baseline would defeat the restraint rather than the result, and What Would Establish Dependence sets out what such evidence would have to contain.
Conclusion
The April transaction is unusually legible. Two authorized signer keys approved a root. An unlabelled relay executed it. A role contract set 45 LINK-denominated obligations and triggered their payment through its bypass path. The same 45 recipients appear in the earmark events, withdrawal events, and token transfers. This is direct evidence of administered LINK settlement for one provider-payment batch. The zero delay observed in July is not projected backward onto the April execution.
The surrounding architecture is legible in a different way. CCIP permits heterogeneous fee assets, the sampled on-ramps were exercised mainly in WETH and GHO, and Payment Abstraction source describes conversion, reserve accounting, and payout in LINK. These pieces support settlement layering. They do not establish a single product-wide flow without a joined trace.
Denomination is not asset specificity, and a multisig is not a legal person. Repetition is not bilateral dependency, and role-based administration is not Williamsonian hierarchy. Each may become evidence inside a larger design; none closes the inference alone.
LINK recedes at the customer edge and reappears where obligations are named and paid. That documented design fact is where the political economy of this arrangement begins.
References
API3. 2026. api3-contracts. GitHub.
Armstrong, Mark. 2006. "Competition in Two-Sided Markets." RAND Journal of Economics 37(3): 668-691. https://doi.org/10.1111/j.1756-2171.2006.tb00037.x.
Blockscout. 2026a. "Ethereum Transaction 0x9ccabfbc…9c24." https://eth.blockscout.com/tx/0x9ccabfbc8dd9177f77d0e2f2dfe6a4562d9897745477253be80df65cf4589c24.
Blockscout. 2026b. "Ethereum Transaction 0x47602774…2bf0." https://eth.blockscout.com/tx/0x4760277410faab8c34efaa575cce6dfbaa88de68ec4cb3f0aa1aade373c62bf0.
Blockscout. 2026c. "ManyChainMultiSig at 0x28617b62…b99e." https://eth.blockscout.com/address/0x28617b6210a18483fa28e485b4f38060d033b99e.
Blockscout. 2026d. "RBACTimelock at 0x08558d8b…5115." https://eth.blockscout.com/address/0x08558d8bb5e792839fc6a21367e6590071305115.
Blockscout. 2026e. "Reserves at 0x5680681e…171d." https://eth.blockscout.com/address/0x5680681ed3767b96914ce741a308155c7fb9171d.
Blockscout. 2026f. "Ethereum Transaction 0x971f53c6…dc2e." https://eth.blockscout.com/tx/0x971f53c659f55a961ddc929e5b098e9601b7150dff788b60bef540495a05dc2e.
Chainlink. 2025a. "Chainlink Payment Abstraction Is Now Live: SVR Fee Conversion and User Fee Staking Rewards." March 31. https://blog.chain.link/payment-abstraction-svr-fee-conversion/.
Chainlink. 2025b. "Introducing the Chainlink Reserve: Creating a Strategic LINK Token Reserve." August 7. https://blog.chain.link/chainlink-reserve-strategic-link-reserve/.
Chainlink Documentation. 2026. "CCIP Billing." Accessed May 4, 2026. https://docs.chain.link/ccip/billing.
Chainlink Labs. 2017. ChainLink: A Decentralized Oracle Network. https://research.chain.link/whitepaper-v1.pdf.
Chronicle. 2026. scribe. GitHub.
CPSS. 2003. A Glossary of Terms Used in Payments and Settlement Systems. Committee on Payment and Settlement Systems. Bank for International Settlements. https://www.bis.org/cpmi/glossary_030301.pdf.
Cong, Lin William, Ye Li, and Neng Wang. 2022. "Token-Based Platform Finance." Journal of Financial Economics 144(3): 972-991. https://doi.org/10.1016/j.jfineco.2021.10.002.
Joskow, Paul L. 1987. "Contract Duration and Relationship-Specific Investments: Empirical Evidence from Coal Markets." American Economic Review 77(1): 168-185.
Pyth Network. 2026. pyth-crosschain. GitHub.
Rochet, Jean-Charles, and Jean Tirole. 2003. "Platform Competition in Two-Sided Markets." Journal of the European Economic Association 1(4): 990-1029. https://doi.org/10.1162/154247603322493212.
SmartContractKit. 2026a. ccip-owner-contracts. GitHub.
SmartContractKit. 2026b. chainlink-evm. GitHub.
SmartContractKit. 2026c. payment-abstraction. GitHub.
Williamson, Oliver E. 1985. The Economic Institutions of Capitalism. New York: Free Press.
Williamson, Oliver E. 1991. "Comparative Economic Organization: The Analysis of Discrete Structural Alternatives." Administrative Science Quarterly 36(2): 269-296. https://doi.org/10.2307/2393356.
Code Records
SmartContractKit. 2026. ManyChainMultiSig and RBACTimelock contract source; smartcontractkit/ccip-owner-contracts, reviewed revision be2b07d0e2e526f62aaa2837bf2cebc6d1cff6bc. Source.
SmartContractKit. 2026. ChainlinkClient and Operator contract source; smartcontractkit/chainlink-evm, reviewed revision 51b1fce46d0193a6f650107cc38f666de9d12fa1. Source.
SmartContractKit. 2026. FeeRouter, FeeAggregator, SwapAutomator, and Reserves contract source; smartcontractkit/payment-abstraction, reviewed revision cc79a03cde960b36049e0f44607811788bcde64a. Source.