Recognitium
FR Create account

Formal response · Discussion paper

Eliminating the Rail

A response to FEDS 2026-037

On The Fragility of Perfectly Safe Digital Money, by Elizabeth C. Klee, Arazi Lubis, Chase P. Ross, Sharon Y. Ross and Alexandros P. Vardoulakis
Finance and Economics Discussion Series 2026-037, Board of Governors of the Federal Reserve System

José Niño, Recognitium 13 June 2026 Edited 9 October 2026


Preamble

A fragility that does not come from the reserves

The paper identifies a source of fragility in digital money that is independent of the quality of reserves. Even when a stablecoin is backed by perfectly safe and liquid assets, network externalities combined with congestion-sensitive settlement costs produce strategic complementarities in redemption, and with them a run. The run comes from the rail, not from the liability.

The result separates two things the market has long conflated: the creditworthiness of the issuer and the stability of the infrastructure it settles on. The evidence the authors bring, the regime shift in Ethereum-based stablecoins and the migration from Ethereum to Tron, gives the model empirical weight.

The paper closes on an open question:

"Designs that decouple transaction costs from network-wide congestion […] could mitigate the fragility, but they may come with their own impediments."

This note describes a rail in which settlement cost does not depend on congestion at all, and follows what the paper’s own model says about it. It claims exactly what the model allows, and states where that claim stops.


Section I

The mechanism, in the paper’s terms

The model (Section 3) formalises the fragility through two opposing forces.

Network externalities. Digital money becomes more valuable as adoption rises, through the benefit $v_k$ for $k \in \{l, h\}$.

Congestion costs. Settlement on a permissionless blockchain becomes more expensive as usage rises, through the cost $\alpha \cdot c(x)$, where $x$ is aggregate network transactions.

Their interaction generates the run. The closed-form threshold of the unique equilibrium (Equation 11) is:

$$\gamma^* = \frac{1}{\alpha} \left[ \frac{\hat{\lambda}}{m} \cdot \frac{n}{n-1} \cdot v_l + \left(1 - \frac{\hat{\lambda}}{m}\right) \cdot \frac{n}{n-1} \cdot v_h \right] - \frac{m(n+1)}{2}$$

Below $\gamma^*$ every agent holds; above it every agent redeems. The probability of stability is $\gamma^* / \Gamma$.

The structural feature that matters is the cost term. With $\alpha > 0$, $c'(x) > 0$ and $c''(x) \geq 0$, settlement cost rises convexly with aggregate transactions, and that convexity is what turns individual redemptions into strategic complements. Proposition 3 states it directly: "New money is more stable […] if transaction costs are smaller (lower $\alpha$)."


Section II

A rail where $\alpha \cdot c'(x) = 0$

Recognitium issues receipts. A participant sends the 32-byte fingerprint of an event, a transfer instruction for instance, and receives a receipt that fixes that event in a public order: each receipt commits to the one before it, to a fresh fingerprint and to the time, by one formula anyone can recompute.

$$\texttt{new\_tip} = \text{SHA-256}(\texttt{prev\_tip} \;\|\; \texttt{fingerprint} \;\|\; \texttt{payload\_hash} \;\|\; \texttt{timestamp\_ns})$$

Three properties of this rail bear on the paper’s model.

  1. There is no shared block space. Each receipt is an independent event. Nothing is auctioned, no fee rises with demand, and there is no public pool of pending transactions in which an order can be seen and overtaken before it is final.
  2. The marginal cost does not depend on aggregate demand. This is the architectural fact. The price we charge, one cent per receipt at any volume, is a policy that this fact makes possible; the model needs only the first, $c'(x) = 0$.
  3. Capacity is added, never bid for. One engine has a finite throughput. When demand exceeds it, requests wait in a queue; they do not pay more. Capacity grows by running more engines side by side, which is possible because receipts for unrelated events do not need a single global order.

The receipt moves no money. It fixes the instruction, its order and its time; the ledger stays with the issuer or the bank. What changes is the cost of making that record final, and its independence from everyone else’s activity.

Mapping to the model

Variable Permissionless blockchain Recognitium Consequence
$\alpha$ (cost parameter) $\alpha > 0$, volatile A fixed price per receipt Cost decoupled from demand
$c(x)$ (cost function) $c'(x) > 0$, $c''(x) \geq 0$ $c(x) = k$, a constant No congestion channel
$c'(x)$ Positive, convex $c'(x) = 0$ An extra transaction costs others nothing
$c''(x)$ $\geq 0$ $c''(x) = 0$ No convexity, no strategic complementarity
$\gamma$ (exogenous congestion) Stochastic, $\sim U[0, \Gamma]$ No channel to the agent’s cost No shared block space
Fee Endogenous, volatile €0.01, set in advance The fee never outgrows a small transfer

What becomes of $\gamma^*$

With $c(x) = k$ and $c'(x) = 0$, the cost term is a fixed and small amount, and an agent’s payoff differential becomes:

$$\pi(\gamma, \lambda) = n \cdot v_k - (n-1) \cdot \underbrace{\alpha \cdot c(m + (n-1)\lambda + \gamma)}_{\text{constant, small}}$$

The payoff no longer depends on $\gamma$: the congestion shock has no path to the decision to redeem. In the paper’s closed form, as the congestion-sensitive part of the cost goes to zero:

$$\gamma^* \to +\infty$$

The run threshold diverges. Within the paper’s model, the congestion-driven run equilibrium has no channel to form.

What remains is what the authors deliberately held constant: the quality of the issuer’s reserves. A rail without a congestion price removes the fragility that had nothing to do with the issuer. It does not make an insolvent issuer safe.


Section III

The three design questions of Section 5.6

Stablecoins with perfect reserves

The paper: a stablecoin fully backed by Treasuries remains exposed to congestion-driven fragility if it settles on a permissionless blockchain with volatile gas fees.

On a rail with a fixed price per receipt, the cost of recording a redemption is the same whether one holder redeems or a million do. The channel the paper isolates, rising settlement cost feeding the decision to run, is absent. The exposure that remains is the one the paper set aside on purpose: the reserves themselves.

Central bank digital currency on public blockchains

The paper: a CBDC circulating on a permissionless blockchain would inherit the congestion externality.

A central bank money that records its transfers on such a rail inherits nothing from unrelated activity, because there is no shared capacity to compete for. The central bank keeps its ledger and its rules; the rail supplies an order and a time for each transfer that anyone can check, at a cost that does not move with the market’s mood.

Layer 2 trade-offs

The paper: solutions that batch transactions and settle periodically on a base layer can decouple user cost from real-time congestion, at the price of trade-offs.

This rail does not batch and does not wait for a base layer: each event is fixed in order when its receipt is issued. The trade-off usually posed is between decentralisation and stable cost. Our answer does not rest on one engine being trusted. Independent engines record one another’s latest receipts, so that none can rewrite its history without contradicting the others, and the head of the public chain is anchored in the Bitcoin blockchain every day. Bitcoin reaches agreement on a single history by consensus; this rail reaches the same irreversibility of order by a different route, one in which any party can recompute the history rather than vote on it.


Section IV

A third category of trust

The paper distinguishes institutional trust, stable and predictable and independent of volume, as in Fedwire, from decentralised trust, volatile and congestion-sensitive and shared by every user of a blockchain. A rail of verifiable receipts adds a third: the record is trusted because anyone can check it, offline, with a published formula.

Property Institutional
(Fedwire)
Decentralised
(Ethereum)
Verifiable record
(Recognitium)
Cost structure Fixed fee per transfer Gas fee, congestion-sensitive €0.01 per receipt
Cost volatility None High (up to 40× Fedwire, per the paper) None
Congestion externality None Yes, shared block space None, independent receipts
Finality Final and irrevocable, by rule Probabilistic, then economic Order fixed at the receipt
Exposure to quantum attack on signatures Not applicable Yes, ECDSA None in the receipt; SHA-256 only
Run through congestion
(the paper’s mechanism)
No Yes, shown in the paper No, $c'(x) = 0$
Verification by a third party Through the operator Through a node or a provider Offline, SHA-256 alone

Section V

Orders of magnitude

The paper’s Table 1 prices Fedwire’s annual wholesale volume, about 176 million transfers averaging roughly \$5 million each, on Ethereum and on Fedwire itself. At one cent per receipt, the same volume would cost about €1.8 million a year to record. The figures below are the paper’s estimates in dollars beside ours in euros; they compare orders of magnitude, not exchange rates.

System Annual cost at Fedwire’s volume
Recognitium, at €0.01 per receipt about €1.8 million
Ethereum, low estimate (2025) \$23 million
Fedwire, low estimate (2025) \$42 million
Fedwire, high estimate (2025) \$210 million
Ethereum, high estimate (2021) \$7.5 billion

The point is not the level but the shape. The cost per receipt does not change with volume or with value: a \$5 transfer and a \$5 million transfer are recorded for the same cent, at a quiet hour or in a panic. There is no fee auction for a crowd to bid up.


Section VI

The claim, stated exactly

The paper proves that:

"Even when digital money is backed by perfectly safe reserves, the rail on which the money circulates can be a source of fragility."

We submit that:

Within the model of FEDS 2026-037, a settlement rail whose marginal cost does not depend on aggregate transactions sets $\alpha \cdot c'(x) = 0$. The agent’s payoff then no longer depends on the congestion shock $\gamma$, the threshold $\gamma^*$ diverges, and the reserve-independent run equilibrium has no channel to form. The claim does not extend to runs caused by the reserves themselves, which the paper held fixed.

This is not the trusted Layer 2 or the dedicated chain the paper considers, each with its acknowledged impediments. It removes the congestion-sensitive term from the cost of settlement rather than shielding users from it.

The rail is running. Its public chain is live, and every receipt it has issued can be verified by anyone, offline, at recognitium.com/verify.


Section VII

Invitation

The paper was circulated to stimulate discussion and critical comment, and this note is offered in that spirit.

The fragility of perfectly safe digital money is real, and the paper proves it. It is not inherent to digital money; it belongs to the choice of rail. When the cost of settlement is fixed, deterministic and independent of congestion, the source of instability the paper identifies loses its channel.

The liability and the rail can both be safe. We would welcome the authors’ criticism of this mapping.