Unleashing a $360B Market: A Conversation with Inder Singh on Securing DomainFi
Guest post by Halborn — Aug 2, 2026
As D3's security audit partner, we've had a front-row seat to how fast DomainFi has grown. We recently sat down with Inder Singh, D3's VP of Product & Technology, to talk through the thesis behind bringing domains onchain, what's shipping next, and how our two teams think about security at every layer of the stack.
Here's the full conversation.
// Welcome Inder! Tell us a bit about D3, and the journey behind it.
It started with a very simple premise: whether it's Web1, Web2, or Web3, the reality is it's all still the internet, and domains are single-handedly the best internet-native asset. You type in Amazon.com and you never worry about where you're going. Our goal was very simple: how do we bring this domain industry onto Web3? Not reinvent the whole industry, but still leverage the trust that comes with domains while bringing them on-chain. And since something with so much intrinsic value is now on-chain, and blockchains are really good for financializing assets, you can bring that structured asset on-chain in a way that works on both Web2 and Web3, and since it has intrinsic value, you can financialize it a lot better onchain.
That's where we started. We began by creating NFT versions of domains that provided certain guarantees. Since then, we've been able to use those guarantees to build products like fractional ownership, basket ownership, and yield based on domain names: early, attractive concepts that people can learn from.
// What was the thesis behind bringing domains on-chain? Was there any other incentive beyond ownership?
I've been in the blockchain space for a little over six years now, and the biggest thing that's always been attractive to me is obviously ownership, but also composability. Today, if you go buy a domain anywhere else, you're paying something like 20% in fees, transfers can take almost a month, and your domain is stuck at that registrar. Namecheap is one of our investors, and if you buy a name there, it only really works within Namecheap. We wanted to change that.
Blockchains enable a level of composability that isn't possible otherwise. Once you have a domain represented as, say, an ERC-20 token, you can use it as collateral, take a loan against it, do a hundred different things, given everything we've built in DeFi over the past decade. That composability is what attracted us: imagine every big institution in the domain industry being composable onchain to provide a lot of different products.
// Is it easier now to talk to traditional domain holders given the rise of “DomainFi” and the increasing volume and value of domains these days? We’ve seen domains like ai.com sell for $70M?
Yeah, I think it got a lot of attention. The funny thing is, that AI.com domain was sold by a crypto guy to a crypto guy with no escrow, a purely trust-based transaction, which in my mind could only really happen in crypto. It's bringing a lot of attention and a lot of new entrants to the industry. We're very active on Solana, and we were chatting with the COO of Solana Labs, who mentioned that every month they're buying a six-figure domain, because every new product requires a solid identity. So a lot of people are coming around to how valuable these names really are.
// Let's say I'm a user looking to buy or sell a domain using Doma, what does that journey look like, in a simplified sense?
Traditionally, you'd just have a marketplace, a very classic OpenSea-style NFT flow. You list a domain, someone makes an offer, and a transaction happens. That's the basic use case we've covered. But where we're seeing the biggest traction is people wanting to invest in premium names, because that's where the biggest upside is.
So the journey typically looks like this: people bring premium domains on-chain, individually or as baskets, and buyers browse these names and decide how much, anywhere from a dollar to thousands of dollars, they want to invest. All of these names can still be sold on Web2 as well; nothing changes there. If a sale happens on Web2, the proceeds flow back on-chain and get distributed. That's a pretty cool concept if you think about it.
// You've also got two new product launches: Domain Asset Vehicles and the Doma Agentic Engine. What are these, and who are they built for?
I'll talk about the domain asset vehicles, the DAVs, first. A lot of people on Web2 traditionally hold anywhere from 10,000 to 2 million domain names. So imagine owning a portfolio worth ten, twenty million, or even a billion dollars, wouldn't it be nice if you could buy into that entire portfolio? That's what this product does: instead of one domain, it packages many into an ETF-like basket of names that you can invest in and own a share of. This is actually something we're working on bringing to market with you as well, and we're very excited about it. It'll be natively on Solana, so most, if not all, of it will live there. The team's been extremely supportive.
This is how you grow the pie in crypto: the ownership proceeds are still being generated on Web2, and you're literally on-ramping them onto Web3 and giving them to owners there. There's never really been such a clean way to expand the pie and bring more ownership and real-world integration into the space. We're really proud of this and excited to launch it soon.
Institutional domain portfolios, now onchain 👇
The Agentic Engine is a bit more left-field, though still part of our core suite, slightly different from the financialization side of things. DomainFi only exists because everything has utility under the hood; if domains had no utility, they'd just be another NFT with no intrinsic value. A lot of the owners we work with are seeing how dramatically AI is changing how domains are used, as identity, for serving websites, and more. That's what the Engine addresses. We're still in a confidential, limited-data phase with a few design partners, but essentially it allows domains to be used as trusted identities.
The goal is that both sides can cryptographically verify a trusted identity, underpinned by an existing domain. We've seen a lot of excitement around this, because almost every identity protocol built around AI has used domains in some way, so the question is how we canonicalize that into a clear spec.
// Since tokenizing domains brings together the intersection of Web2 and Web3, a lot of the attack vectors and surfaces change quite a bit. What was your general approach to security strategy?
It's pretty complicated if you think about it. Let's use Amazon as an example again. Say Amazon somehow gets hacked and Amazon.com gets taken away from them. There's legal recourse built in: the domain can be returned to Amazon the company. That safety net exists, and it's not tied to a single country, it's a global system. So we're at this juncture where we have to comply with Web2 security norms, how domains are held, what information can or can't be shared, while also securing the asset once it's on Web3, since a lot of DeFi contracts are using these assets.
A lot of the time when we work with Halborn, we're thinking through the minutiae of the domain industry, bringing codified examples into the code and working with your team to enumerate how Web2 and Web3 lifecycles can differ. That's powerful because this is a very purpose-specific protocol, not a generic DeFi application. A lot of our security work goes into mapping real-world use cases, since this is a real-world asset, back to blockchain use cases.
Then the next layer of complexity comes from being multi-chain: where are the funds held on Solana, how do you secure them, how do you correctly attribute that, say, a user deserves $10,000 in yield, paid in USDC, not through inflation or printing more tokens? A lot of staking protocols are pretty naive; they just print more of a token or route it through some inflationary contract. We don't do any of that. Attribution and measurement all need to happen correctly, onchain.
// When you talk about the work we do together. Why did you decide to partner with Halborn on security, and how has that process been?
We've been working with Halborn for almost a year now. The partnership started when we first built the NFT engine, which is the base layer for everything else we do. Over time, real domain-specific knowledge started to build up within the team. Every time we request an audit, the team has more context from what came before. That continuity matters a lot to us, because everything is built on the same foundation, if you will, and Halborn has been at the base of that pyramid, helping us build it up securely.
// Is there a milestone or moment from this whole journey that really stands out for you?
It's been a roller coaster, to say the least. I think minting our first domain at the very end of last year was pretty monumental, no one had ever really done this before. People had tried blockchain naming, we love the ENS team, they were doing great work, but nothing had come close to creating a distributed ledger that spans both Web2 and Web3. It was a very proud moment seeing the first domain get minted on-chain, go through the whole lifecycle, and battle-test the whole system.
Fast forward six months, we've done over $200 million in transaction volume, close to $70 million of that in trading volume in just the last 30 days. Seeing that hockey-stick growth, and the fact that we haven't had any security issues, has been a proud moment. As a builder, the impact you can make is what I love about startups, and in Web3 that impact is very clear, adoption during a bear market is growing, which is always a good sign.

// Looking ahead to the next 12 months or so, is there anything exciting you'd like to share?
The next 12 months will be very exciting, partly because I think we'll see a dominant AI identity standard emerge. We're integrated into a lot of websites already, and I'd bet that if you check Halborn's own website traffic, at least 30% of it is now coming from AI agents rather than direct human traffic. Now imagine a world where people are browsing through their agents, whether that's on some assistant or search tool, or whatever platform is dominant by then. Websites are going to change, how users consume information is going to change, it's going to be the biggest shift we've seen in how internet traffic works, kind of like the YouTube/Netflix moment where video became the dominant form of traffic.
We think that shift leads to two things. One, I'm almost certain domain-based, cryptographically signed identity will see much wider adoption. And two, that will lead to an even bigger gold rush. If you have a personal website that's important to you, you'll want to go buy the right domain for it, and wherever there's that kind of demand, a speculative market follows. So the market is going to go through a kind of Cambrian explosion, as companies start issuing identities, maybe you won't get a fully personal one, but you might get a delegated identity. AI is going to dramatically change how we interact with the internet. Going back to the Amazon.com example: will you still be typing "Amazon.com," or will you just be telling an agent to go buy something on Amazon? None of us know for sure, but I do think identity anchors are going to change, and that will dramatically change how the industry works.
Watch the full interview on YouTube: