Eliminating the Rail
A response to FEDS 2026-037
On The Fragility of Perfectly Safe Digital Money, by Elizabeth C. Klee, Arazi Lubis, Chase P. Ross, Sharon Y. Ross and Alexandros P. Vardoulakis
Finance and Economics Discussion Series 2026-037, Board of Governors of the Federal Reserve System
Preamble
A fragility that does not come from the reserves
The paper identifies a source of fragility in digital money that is independent of the quality of reserves. Even when a stablecoin is backed by perfectly safe and liquid assets, network externalities combined with congestion-sensitive settlement costs produce strategic complementarities in redemption, and with them a run. The run comes from the rail, not from the liability.
The result separates two things the market has long conflated: the creditworthiness of the issuer and the stability of the infrastructure it settles on. The evidence the authors bring, the regime shift in Ethereum-based stablecoins and the migration from Ethereum to Tron, gives the model empirical weight.
The paper closes on an open question:
"Designs that decouple transaction costs from network-wide congestion […] could mitigate the fragility, but they may come with their own impediments."
This note describes a rail in which settlement cost does not depend on congestion at all, and follows what the paper’s own model says about it. It claims exactly what the model allows, and states where that claim stops.
Section I
The mechanism, in the paper’s terms
The model (Section 3) formalises the fragility through two opposing forces.
Network externalities. Digital money becomes more valuable as adoption rises, through the benefit $v_k$ for $k \in \{l, h\}$.
Congestion costs. Settlement on a permissionless blockchain becomes more expensive as usage rises, through the cost $\alpha \cdot c(x)$, where $x$ is aggregate network transactions.
Their interaction generates the run. The closed-form threshold of the unique equilibrium (Equation 11) is:
Below $\gamma^*$ every agent holds; above it every agent redeems. The probability of stability is $\gamma^* / \Gamma$.
The structural feature that matters is the cost term. With $\alpha > 0$, $c'(x) > 0$ and $c''(x) \geq 0$, settlement cost rises convexly with aggregate transactions, and that convexity is what turns individual redemptions into strategic complements. Proposition 3 states it directly: "New money is more stable […] if transaction costs are smaller (lower $\alpha$)."
Section II
A rail where $\alpha \cdot c'(x) = 0$
Recognitium issues receipts. A participant sends the 32-byte fingerprint of an event, a transfer instruction for instance, and receives a receipt that fixes that event in a public order: each receipt commits to the one before it, to a fresh fingerprint and to the time, by one formula anyone can recompute.
Three properties of this rail bear on the paper’s model.
- There is no shared block space. Each receipt is an independent event. Nothing is auctioned, no fee rises with demand, and there is no public pool of pending transactions in which an order can be seen and overtaken before it is final.
- The marginal cost does not depend on aggregate demand. This is the architectural fact. The price we charge, one cent per receipt at any volume, is a policy that this fact makes possible; the model needs only the first, $c'(x) = 0$.
- Capacity is added, never bid for. One engine has a finite throughput. When demand exceeds it, requests wait in a queue; they do not pay more. Capacity grows by running more engines side by side, which is possible because receipts for unrelated events do not need a single global order.
The receipt moves no money. It fixes the instruction, its order and its time; the ledger stays with the issuer or the bank. What changes is the cost of making that record final, and its independence from everyone else’s activity.
Mapping to the model
| Variable | Permissionless blockchain | Recognitium | Consequence |
|---|---|---|---|
| $\alpha$ (cost parameter) | $\alpha > 0$, volatile | A fixed price per receipt | Cost decoupled from demand |
| $c(x)$ (cost function) | $c'(x) > 0$, $c''(x) \geq 0$ | $c(x) = k$, a constant | No congestion channel |
| $c'(x)$ | Positive, convex | $c'(x) = 0$ | An extra transaction costs others nothing |
| $c''(x)$ | $\geq 0$ | $c''(x) = 0$ | No convexity, no strategic complementarity |
| $\gamma$ (exogenous congestion) | Stochastic, $\sim U[0, \Gamma]$ | No channel to the agent’s cost | No shared block space |
| Fee | Endogenous, volatile | €0.01, set in advance | The fee never outgrows a small transfer |
What becomes of $\gamma^*$
With $c(x) = k$ and $c'(x) = 0$, the cost term is a fixed and small amount, and an agent’s payoff differential becomes:
The payoff no longer depends on $\gamma$: the congestion shock has no path to the decision to redeem. In the paper’s closed form, as the congestion-sensitive part of the cost goes to zero:
The run threshold diverges. Within the paper’s model, the congestion-driven run equilibrium has no channel to form.
What remains is what the authors deliberately held constant: the quality of the issuer’s reserves. A rail without a congestion price removes the fragility that had nothing to do with the issuer. It does not make an insolvent issuer safe.
Section III
The three design questions of Section 5.6
Stablecoins with perfect reserves
The paper: a stablecoin fully backed by Treasuries remains exposed to congestion-driven fragility if it settles on a permissionless blockchain with volatile gas fees.
On a rail with a fixed price per receipt, the cost of recording a redemption is the same whether one holder redeems or a million do. The channel the paper isolates, rising settlement cost feeding the decision to run, is absent. The exposure that remains is the one the paper set aside on purpose: the reserves themselves.
Central bank digital currency on public blockchains
The paper: a CBDC circulating on a permissionless blockchain would inherit the congestion externality.
A central bank money that records its transfers on such a rail inherits nothing from unrelated activity, because there is no shared capacity to compete for. The central bank keeps its ledger and its rules; the rail supplies an order and a time for each transfer that anyone can check, at a cost that does not move with the market’s mood.
Layer 2 trade-offs
The paper: solutions that batch transactions and settle periodically on a base layer can decouple user cost from real-time congestion, at the price of trade-offs.
This rail does not batch and does not wait for a base layer: each event is fixed in order when its receipt is issued. The trade-off usually posed is between decentralisation and stable cost. Our answer does not rest on one engine being trusted. Independent engines record one another’s latest receipts, so that none can rewrite its history without contradicting the others, and the head of the public chain is anchored in the Bitcoin blockchain every day. Bitcoin reaches agreement on a single history by consensus; this rail reaches the same irreversibility of order by a different route, one in which any party can recompute the history rather than vote on it.
Section IV
A third category of trust
The paper distinguishes institutional trust, stable and predictable and independent of volume, as in Fedwire, from decentralised trust, volatile and congestion-sensitive and shared by every user of a blockchain. A rail of verifiable receipts adds a third: the record is trusted because anyone can check it, offline, with a published formula.
| Property | Institutional (Fedwire) |
Decentralised (Ethereum) |
Verifiable record (Recognitium) |
|---|---|---|---|
| Cost structure | Fixed fee per transfer | Gas fee, congestion-sensitive | €0.01 per receipt |
| Cost volatility | None | High (up to 40× Fedwire, per the paper) | None |
| Congestion externality | None | Yes, shared block space | None, independent receipts |
| Finality | Final and irrevocable, by rule | Probabilistic, then economic | Order fixed at the receipt |
| Exposure to quantum attack on signatures | Not applicable | Yes, ECDSA | None in the receipt; SHA-256 only |
| Run through congestion (the paper’s mechanism) |
No | Yes, shown in the paper | No, $c'(x) = 0$ |
| Verification by a third party | Through the operator | Through a node or a provider | Offline, SHA-256 alone |
Section V
Orders of magnitude
The paper’s Table 1 prices Fedwire’s annual wholesale volume, about 176 million transfers averaging roughly \$5 million each, on Ethereum and on Fedwire itself. At one cent per receipt, the same volume would cost about €1.8 million a year to record. The figures below are the paper’s estimates in dollars beside ours in euros; they compare orders of magnitude, not exchange rates.
| System | Annual cost at Fedwire’s volume |
|---|---|
| Recognitium, at €0.01 per receipt | about €1.8 million |
| Ethereum, low estimate (2025) | \$23 million |
| Fedwire, low estimate (2025) | \$42 million |
| Fedwire, high estimate (2025) | \$210 million |
| Ethereum, high estimate (2021) | \$7.5 billion |
The point is not the level but the shape. The cost per receipt does not change with volume or with value: a \$5 transfer and a \$5 million transfer are recorded for the same cent, at a quiet hour or in a panic. There is no fee auction for a crowd to bid up.
Section VI
The claim, stated exactly
The paper proves that:
"Even when digital money is backed by perfectly safe reserves, the rail on which the money circulates can be a source of fragility."
We submit that:
Within the model of FEDS 2026-037, a settlement rail whose marginal cost does not depend on aggregate transactions sets $\alpha \cdot c'(x) = 0$. The agent’s payoff then no longer depends on the congestion shock $\gamma$, the threshold $\gamma^*$ diverges, and the reserve-independent run equilibrium has no channel to form. The claim does not extend to runs caused by the reserves themselves, which the paper held fixed.
This is not the trusted Layer 2 or the dedicated chain the paper considers, each with its acknowledged impediments. It removes the congestion-sensitive term from the cost of settlement rather than shielding users from it.
The rail is running. Its public chain is live, and every receipt it has issued can be verified by anyone, offline, at recognitium.com/verify.
Section VII
Invitation
The paper was circulated to stimulate discussion and critical comment, and this note is offered in that spirit.
The fragility of perfectly safe digital money is real, and the paper proves it. It is not inherent to digital money; it belongs to the choice of rail. When the cost of settlement is fixed, deterministic and independent of congestion, the source of instability the paper identifies loses its channel.
The liability and the rail can both be safe. We would welcome the authors’ criticism of this mapping.