Unmanaged growth can lead to slow confirmation times, rising storage and bandwidth costs, and weaker user experience. It can also increase pressure for shortcuts such as larger blocks or more centralised infrastructure, which may undermine the original trust model. In practice, scaling failure is often a mix of technical slowdown and architectural drift.
Why This Matters for Security Teams
Blockchain performance problems are not just an engineering inconvenience. When transaction demand grows faster than capacity, confirmation latency increases, fees become less predictable, and operators start to compensate with shortcuts that change the trust model. That can push networks toward heavier infrastructure, more centralised validation, or off-chain workarounds that are functionally useful but governance-sensitive. NIST Cybersecurity Framework 2.0 is useful here because it frames resilience as an operational property, not a one-time design choice.
NHIMG’s Ultimate Guide to NHIs — Why NHI Security Matters Now makes the same broader point for digital systems: when scale is unmanaged, control degrades before failure becomes obvious. In blockchain environments, the symptoms often show up first as slower settlement and then as governance pressure to relax constraints. In practice, many teams notice the trust impact only after users have already routed around the intended protocol path.
How It Works in Practice
Blockchains absorb demand through a combination of throughput, propagation speed, validation cost, and storage growth. If any of those dimensions lag behind transaction volume, the network starts queueing work. That usually means mempool congestion, longer confirmation windows, and more volatile fees. As the backlog rises, users and applications compete for inclusion, which can make smaller or time-sensitive transactions uneconomic.
Operationally, unmanaged growth also changes how nodes are run. Full nodes need more disk, more bandwidth, and more CPU to stay synchronized. If those costs rise too quickly, participants may prune historical data more aggressively, outsource validation, or rely on a smaller set of well-resourced operators. That is where architectural drift begins. The system still works, but it may work with fewer independent validators and weaker decentralisation than the original design assumed.
For teams evaluating this risk, the practical questions are:
- Can transaction demand be forecast with enough confidence to adjust capacity before congestion becomes chronic?
- Are block size, gas limits, or throughput tweaks being used as permanent fixes rather than temporary relief?
- Do node-operator requirements remain realistic for independent participation, or are they silently excluding smaller actors?
- Are layer-2 or off-chain dependencies creating new trust assumptions that have not been reviewed?
The NIST Cybersecurity Framework 2.0 is relevant because growth management is a resilience issue as much as a scaling issue. NHIMG’s Top 10 NHI Issues is also instructive in a broader governance sense: uncontrolled expansion tends to create hidden operational debt that only becomes visible during stress. These controls tend to break down when demand surges faster than fee markets and node capacity can adjust, because backlog pressure then turns into protocol-level compromise pressure.
Common Variations and Edge Cases
Tighter throughput controls often increase latency or cost elsewhere, requiring organisations to balance user experience against decentralisation and operational simplicity. That tradeoff is especially visible when networks use larger blocks, aggressive batching, or layer-2 dependencies to relieve congestion. Those approaches can improve short-term throughput, but best practice is evolving on how much trust shift is acceptable before the network’s security assumptions materially change.
Private and permissioned chains face a different problem. They may scale technically more easily, but the governance risk is that central operators absorb growth by expanding hardware and control surfaces rather than improving protocol efficiency. Public chains face the inverse: they may preserve decentralisation longer, but only if demand management is realistic and node economics remain sustainable.
Another edge case is when growth appears healthy because throughput is rising, while actual utility is concentrated in a narrow set of high-value transactions. In that scenario, the network may look scalable on paper but still fail ordinary users through fee spikes or inclusion delays. Current guidance suggests treating scalability as a service-quality and trust question together, not as a throughput metric alone. NHIMG’s NHI Lifecycle Management Guide reinforces the same operational principle: unmanaged growth becomes a lifecycle problem before it becomes a headline outage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.IP-1 | Scaling must be built into operational planning and maintenance. |
| NIST SP 800-53 Rev 5 | SC-5 | Bandwidth and throughput constraints map to denial-of-service resilience. |
| NIST AI RMF | Growth management needs lifecycle governance and risk monitoring. | |
| OWASP Non-Human Identity Top 10 | NHI-02 | Centralisation pressure often follows resource and identity sprawl. |
Track network growth against capacity baselines and update scaling plans before congestion becomes chronic.
Related resources from NHI Mgmt Group
- What breaks when customer demand changes are managed outside the ERP?
- What breaks in transaction monitoring when teams do not track blockchain addresses tied to designated actors?
- What breaks in an investigation when blockchain activity cannot be connected into a coherent transaction story?
- What breaks when Active Directory controls are managed only through quarterly reviews?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org