The news landed quietly, like a stone dropped into a river that no one was watching. On a Tuesday that felt like any other, Shipyard — the team that had been the steady pulse of IPFS development — announced it was ending its work. Then came the deeper tremor: Protocol Labs, the funding parent, had stopped its financial support. IPFS, the foundational layer of decentralized storage, had lost its dedicated maintainers.
I remember the first time I truly understood IPFS. It was during a late-night audit of a TON whitepaper in 2017, sitting in a Mumbai café that smelled of cardamom and ambition. The protocol wasn't just a technical curiosity; it was a promise that data could live beyond the reach of any single server. That promise became the backbone of NFTs, of DApp frontends, of the Web3 we all believed in. Now, that backbone is whispering a question: what happens when the builders stop building?
Let me give you the context. IPFS (InterPlanetary File System) is not a blockchain with a token; it is a peer-to-peer hypermedia protocol that uses content-addressing to store and share files. It is the "data availability layer" for countless projects — from NFT metadata to decentralized social media. Shipyard, a development shop, was the primary maintainer of the core IPFS software (go-ipfs). They were the ones who fixed bugs, merged pull requests, and kept the network humming. Protocol Labs, the creators of IPFS and Filecoin, provided the funding. Now, both the maintainer and the funder are gone. The engine is still running, but no one is tending the boiler.
From code audits to community heartbeats — this is the moment when we must ask: is a protocol more than its code? Is it the people who maintain it? During the 2020 DeFi Summer, I founded the Mumbai Chain Guardians, a volunteer network of 200 moderators who monitored Aave and Compound for vulnerabilities. I learned that infrastructure without community is just a skeleton. IPFS has a community, but it has never been truly independent. It lived on a leash held by Protocol Labs. Now that leash is cut, and the dog is standing in the middle of the road.
Let me walk you through the technical implications. The immediate risk is not a catastrophic failure. IPFS is mature; the protocol will not break tomorrow. But the risk is a slow decay — a "maintenance vacuum." Without a dedicated team, known issues (like DHT routing inefficiencies, garbage collection lags, and potential security vulnerabilities in the libp2p stack) will accumulate. Each unresolved bug is a hairline crack. Over months, these cracks widen. Over years, the network becomes brittle.
I've seen this before. In my 2017 TON audit, I identified a game-theory flaw that ignored small-holder participation. The flaw wasn't fatal immediately, but it eroded trust. The same principle applies here: the absence of active maintenance is a silent trust erosion. New features will not be added. Performance optimizations will stall. The protocol will not keep pace with evolving threats — from sophisticated DDoS attacks on public gateways to new cryptographic standards.
Consider the public gateway. Most users access IPFS content through gateways like ipfs.io. These are operated by Protocol Labs and other third parties. If the gateway software becomes outdated or unpatched, it becomes a single point of failure. Imagine a million NFT images failing to load because the gateway is serving stale data. The user experience degrades, and with it, the entire narrative of decentralized storage as a reliable alternative to AWS S3.
Building bridges where DeFi once built walls — this is the moment for the community to build a bridge across the funding gap. But bridges require materials. The material here is not money alone; it is coordination. IPFS is a public good, and public goods in crypto have a notorious funding problem. We have seen it with Gitcoin grants, with public goods funding rounds, but rarely for core infrastructure that already has a billion-dollar ecosystem built on top of it.
The contrarian angle: maybe this is exactly what IPFS needs. Perhaps the loss of a single funding source will force the ecosystem to grow up. The community could fork the codebase and form a new maintenance collective — a DAO, a foundation, or a cooperative. Filecoin, which depends on IPFS, could step in and allocate a portion of block rewards to maintain the underlying protocol. (This is not unprecedented: Ethereum Classic survived after the DAO fork, though with a smaller footprint.)
But wishful thinking is not a strategy. The reality is that a community fork requires deep technical expertise, sustained coordination, and funding. The kind of expertise Shipyard had — the institutional knowledge of the go-ipfs codebase — is not easily replicated. It took years to build. During the 2022 bear market, I organized resilience calls for 300 female founders. The pattern was always the same: when the core team leaves, the project doesn't die instantly; it starves slowly.
Trust is not a protocol, it is a practice — and the practice of maintaining IPFS has been interrupted. The question is whether the practice can be revived by a distributed group of volunteers, or whether it will be gradually replaced by alternatives like Arweave, which offers permanent storage with a different incentive model. Arweave's community is smaller but more cohesive, and its funding model (endowment-based) is arguably more sustainable.
Let me offer a data point from my own experience. In 2021, I partnered with the Tata Trusts to launch "Heritage on Chain," an NFT initiative preserving 1,000 endangered Indian textile patterns. We stored the metadata on IPFS. At the time, it felt like a permanent choice. Now, I worry about the stories behind those patterns. If the gateways degrade, if the nodes disappear, the digital artifacts that remember who we are could become inaccessible. This is not just a technical problem; it is a cultural one.
The core of my analysis is this: the IPFS maintenance crisis is a stress test for the entire concept of decentralized infrastructure. It reveals that "decentralization" is not a binary state. It is a spectrum, and the spectrum includes the funding and governance of the underlying protocols. We have built a house on a foundation that was maintained by a single entity. Now that entity has walked away, and we must decide whether to rebuild the foundation ourselves or move to a different house.
Auditing the soul behind the smart contract — this is what I have done for years. The soul of IPFS was Shipyard, and now it is a ghost. But the community is still alive. I have seen the resilience of the crypto community in the face of collapses (Terra, FTX, 3AC). Each time, the survivors rebuild. The question is whether they will rebuild IPFS, or build something new.
Let me be clear about the risks. Over the next 6-12 months, if no new maintainer emerges, the frequency of security patches will drop. The number of active contributors on GitHub will decline. Public gateways may become unreliable. NFT projects that rely on IPFS for metadata will need to implement redundancy (e.g., pinning to multiple services, or using a hybrid approach with Arweave). The Filecoin network, which is deeply integrated with IPFS, could see a slight negative sentiment hit, though its price is driven by storage deals and speculation, not solely by IPFS health.
But I also see an opportunity. The crisis could catalyze a new governance model for IPFS — one that is truly decentralized. Imagine a "IPFS Maintenance DAO" funded by a small tax on Filecoin block rewards, or by a voluntary contribution from projects that use IPFS. This would align incentives: the users of the protocol become its stewards. It would turn IPFS from a project into a commons.
During the 2026 AI-Crypto ethical framework work, I led a global consensus-building process. It taught me that collective action is possible when the stakes are clear. The stakes here are high: the availability of millions of digital artifacts, the trust of users in decentralized storage, and the very narrative of Web3 as a resilient alternative to centralized clouds.
Liquidity flows, but culture remains — the culture of IPFS is one of openness, of content-addressing, of the belief that data should be free. That culture will not disappear just because Shipyard is gone. But it will need new champions.
Here is my takeaway, and it is not a summary but a forward-looking thought: The death of a protocol is rarely caused by a single event. It is caused by a thousand small cuts that go unbandaged. The IPFS community has a choice: it can either become the bandage, or it can watch the cuts grow. The next three months will tell us whether the Web3 ecosystem can truly practice the decentralization it preaches — not just in code, but in the messy, human work of maintenance.
Digital artifacts that remember who we are — they are waiting for us to decide. Let us not forget them.