On the eve of a World Cup final, Joan Capdevila—a Spanish defender who had lifted the trophy in 2010—was told he couldn’t enter the United States. The reason? Years earlier, he had traveled to Iran. A single administrative decision, buried in a visa waiver rule change from 2021, turned a world champion into a persona non grata. No due process. No transparent appeal. Just a binary gate: approved or denied. This is not a story about sports. It’s a story about centralized gatekeeping—and why we should care about permissionless systems.
You are not the user; you are the product of a state’s foreign policy. Capdevila’s case is a stark reminder that when a single entity controls access, arbitrary exclusion becomes the norm. The Visa Waiver Program (VWP) allows citizens from allied countries like Spain to travel to the US for tourism or business without a visa—via ESTA authorization. But in 2021, the Department of Homeland Security quietly tightened the rules: anyone who had visited Iran, Iraq, Syria, or a handful of other countries since 2011 was automatically disqualified. No hearing. No exception for sporting events. Capdevila, who had played a charity match in Tehran, was caught in the net. He was only allowed to fly after a personal appeal—reportedly to then-President Trump—to recognize the significance of the match.
This incident isn’t an outlier. It’s the logical consequence of centralized power: control over borders, control over identities, control over who participates. In my years auditing DeFi protocols, I’ve seen the same pattern reproduced in smart contracts. A single multisig key that can freeze funds. A whitelist that only allows approved addresses. A governance quorum that excludes smaller holders. The mechanism differs, but the result is identical: someone with authority can deny access based on opaque criteria. Capdevila’s visa was his tokenized identity—and the US government acted as the ultimate centralized Oracle, refusing to verify his credential.
The parallels to blockchain are uncomfortable. We build protocols with the language of permissionlessness, yet many rely on centralized dependencies. Cross-chain bridges have been hacked for over $2.5 billion, yet the industry still depends on them—a fundamental security paradox. Similarly, Capdevila depended on a closed, non-auditable system (CBP’s discretionary decision) that had no fallback. When the bridge fails, there is no alternative path. The Tornado Cash sanctions set a dangerous precedent: writing code can now be a crime, placing all open-source developers at legal risk. Capdevila’s “crime” was visiting a country the US government disapproves of. In both cases, the message is clear: if you interact with disfavored entities (be they protocols or nations), you may be cut off from the mainstream.
But here’s the contrarian angle: Some argue that some gatekeeping is necessary—that borders and whitelists protect against bad actors. I do not deny that security requires boundaries. The question is: who sets them, and can they be challenged when wrong? In Compound’s governance debates of 2020, I saw how a single whale could manipulate votes to block community proposals. The solution was not to remove governance, but to make it transparent, auditable, and open to appeal. Similarly, visa policies could be encoded as smart contracts with clear rules, zero-knowledge proofs to prove compliance without oversharing data, and on-chain appeals through a DAO of neutral experts. Debate is the compiler for better consensus. Capdevila got his exemption because of political connections—but that’s not justice. Justice is a system where any player, regardless of fame, can prove their eligibility through verifiable credentials.
The deeper lesson is about ownership. True ownership begins where the server ends. Capdevila did not own his right to travel—it was a license granted by a centralized authority. In blockchain, we fight for self-sovereign identity, where individuals control access to their own data and permissions. Imagine a world where Capdevila could present a zero-knowledge proof that he visited Iran for a soccer charity, not a security risk. Imagine a world where the gate is not a government clerk but a piece of open-source code that anyone can inspect. That is the promise of decentralization: not anarchy, but auditable fairness.
We are still at the beginning of this transition. Institutions are adapting, but slowly. I’ve seen bankers dismiss blockchain as “slow and inefficient”—yet they applaud a visa system that takes weeks and offers no reasoning for denial. The same logic applies to regulation: a bear market should remind us that hype hides technical flaws. Capdevila’s case, though fortunate in outcome, exposes a system that is both fragile and unjust. As we build the next generation of decentralized protocols, we must embed the values we preach: permissionless access, transparent rules, and the right to be heard. Otherwise, we are just recreating the same gates, with different names.
The next time you hear a politician say “we need to centralize for security,” think of Joan Capdevila—and ask yourself: whose security? And at what cost to freedom?

