On June 2, 2026, five researchers at the Board of Governors of the Federal Reserve System published a paper that should be read by every institution operating in digital finance. Its central finding is deceptively simple and profoundly consequential:
"Even when digital money is backed by perfectly safe reserves, the rail on which the money circulates can be a source of fragility."
This means that a stablecoin backed 100% by U.S. Treasuries, fully compliant with every proposed regulation, can still suffer a run — not because the reserves are bad, but because the blockchain it settles on becomes congested and expensive.
The authors prove this both mathematically and empirically. Using a global games model and seven years of Ethereum data, they demonstrate that:
Congestion costs on permissionless blockchains are volatile, regressive, and shared. Gas fees can exceed the value of small transfers. They spiked to 40× the cost of Fedwire in 2021. And they are determined by all blockchain activity — NFT minting, speculation, DeFi — not just the stablecoin's own transactions.
The interaction of congestion and network externalities creates strategic complementarities. When congestion rises and network externalities are low, each user's decision to redeem makes the stablecoin less valuable for remaining holders, triggering further redemptions. The result is not gradual erosion but an abrupt regime switch — a run.
This applies to everything on a blockchain. The mechanism is not specific to stablecoins. Tokenized deposits, tokenized Treasuries, and central bank digital currencies (CBDCs) issued on permissionless blockchains would all inherit the same fragility. The authors specifically note the European Central Bank's exploration of running a Digital Euro on Ethereum.
The paper concludes with an open question: designs that decouple transaction costs from congestion could mitigate the fragility, but each known approach — Layer 2 solutions, application-specific chains, central-bank-operated blockchains — involves tradeoffs with decentralization, interoperability, and trust.
The Federal Reserve identified the disease. They did not prescribe a cure.
The paper formalizes the fragility through two variables that govern a user's decision to hold or redeem digital money:
The model derives a unique equilibrium threshold $\gamma^*$ — a level of congestion below which all users hold, and above which all users redeem. The closed-form solution (Equation 11 of the paper) is:
The probability of stability is $\gamma^* / \Gamma$. The higher $\gamma^*$, the more resilient the digital money.
The critical insight: the fragility is entirely mediated by the cost parameter $\alpha$ and the cost function $c(x)$. If settlement costs increase with congestion ($c'(x) > 0$) and do so convexly ($c''(x) \geq 0$), strategic complementarities form. If they do not, they cannot.
Proposition 3 of the paper confirms: "New money is more stable — i.e., $\gamma^*$ is higher — if transaction costs are smaller (lower $\alpha$)."
This immediately raises a question the paper does not address:
What happens when $\alpha \cdot c'(x) = 0$ — when settlement cost is fixed, deterministic, and independent of network-wide congestion?
The answer is immediate from the mathematics.
Consider a settlement architecture with the following properties:
In the notation of the Federal Reserve's model:
| Variable | Blockchain | Required Architecture |
|---|---|---|
| $\alpha$ (cost scaling) | $\alpha > 0$, volatile | Fixed constant |
| $c(x)$ (cost function) | $c'(x) > 0$, $c''(x) \geq 0$ | $c(x) = k$ (constant) |
| $c'(x)$ | Positive, convex | $c'(x) = 0$ |
| $c''(x)$ | $\geq 0$ | $c''(x) = 0$ |
| $\gamma$ (exogenous congestion) | Stochastic, $\sim U[0, \Gamma]$ | No transmission channel |
Under these conditions, the payoff differential for each agent becomes:
The payoff no longer depends on $\gamma$. The exogenous congestion shock — the very variable that triggers the regime switch in the Fed's model — has no transmission channel to the user's decision. There is no mechanism by which one user's redemption raises costs for remaining holders. Strategic complementarities cannot form.
In the closed-form solution, as $\alpha \to 0^+$:
The run threshold diverges to infinity. The run equilibrium ceases to exist.
This is not a mitigation. It is a mathematical elimination. The fragility that the Federal Reserve identified is a consequence of a specific architectural choice — pricing trust through congestion-sensitive gas fees. An architecture that removes this pricing mechanism removes the fragility entirely.
The Federal Reserve paper suggests several design features that "could mitigate the fragility." It is important to distinguish what we are proposing from each.
A Layer 2 batches transactions off-chain and settles periodically on a base layer. The user's cost is decoupled from real-time congestion, but final settlement still depends on the base layer's properties. The Fed correctly notes: "To be trusted, Layer 2 chains would likely require some degree of centralization, operated by a financial entity resembling CCPs in traditional finance." Our architecture does not batch. Each transaction achieves finality independently and immediately.
An app-chain reserves block space for a single application, preventing cross-contamination from unrelated activity. But it still uses consensus, still has validators, and still has a gas mechanism — merely with less contention. Our architecture has no block space, no validators, and no gas mechanism. Cost is deterministic by design, not by traffic management.
A central-bank-operated blockchain replaces decentralized trust with institutional trust. Settlement cost is set by policy rather than by market. This eliminates the congestion channel but introduces all the political, operational, and scalability constraints that have delayed CBDC projects for years. Our architecture achieves fixed settlement cost without requiring a central bank to operate it.
The architecture does not use blocks, does not use consensus, does not distribute a ledger, and does not require validators to agree on state. It achieves settlement finality through a fundamentally different mechanism — one that is protected by intellectual property and national defense classifications.
The Federal Reserve paper distinguishes between institutional trust — stable, predictable, decoupled from volume, as in Fedwire — and decentralized trust — volatile, congestion-sensitive, shared across all blockchain users. We propose a third category.
| Property | Institutional Trust (Fedwire) |
Decentralized Trust (Ethereum) |
Physical Trust (Recognitium) |
|---|---|---|---|
| Cost structure | Fixed, set by policy | Volatile gas fee | Fixed €0.01 per transaction |
| Cost volatility | None | Extreme (up to 40× Fedwire) | None |
| Congestion externality | None | Yes — shared block space | None |
| Settlement finality | Administrative (reversible) | Probabilistic | Absolute — bound to physics |
| Settlement latency | Seconds | Seconds to minutes | Microseconds |
| Quantum vulnerability | N/A | Yes | No |
| Run vulnerability (FEDS 2026-037) |
No | Yes | No — $c'(x) = 0$ |
| Offline verification | No | No | Yes |
| Operates today | Yes | Yes | Yes |
Physical trust differs from both categories in a fundamental way. Institutional trust is guaranteed by the reputation and legal authority of the institution. Decentralized trust is guaranteed by the economic cost of attacking the network. Physical trust is guaranteed by the laws of physics. Settlement finality is not a promise, a probability, or an economic deterrent. It is a physical state that cannot be reversed — by any party, any technology, or any intelligence.
The Federal Reserve paper's Table 1 compares the cost of processing Fedwire's annual wholesale volume on Ethereum. Fedwire is a large-value interbank payment system — it processes approximately 176 million wire transfers per year, with an average transaction value of roughly $5 million. Despite the relatively modest transaction count, the cost disparity is striking:
| System | Annual Cost (Fedwire Volume) | Cost Volatility |
|---|---|---|
| Recognitium | $1.76 million | Zero |
| Fedwire (2025, low–high) | $42M – $210M | None (policy-set tiers) |
| Ethereum (2025, P25–P75) | $23M – $223M | Extreme |
| Ethereum (2021, P25–P75) | $1.0B – $7.5B | Extreme |
But wholesale payments are only a fraction of global settlement activity. The true scale of the opportunity — and the fragility — becomes clear when we extend the comparison to the retail payment volumes where digital money is increasingly deployed:
| Network | Annual Transactions | Recognitium Cost (@€0.01) |
|---|---|---|
| Fedwire (wholesale) | ~176 million | $1.76 million |
| Mastercard | ~150 billion | $1.5 billion |
| Visa | ~260 billion | $2.6 billion |
| Global digital payments | ~1.8 trillion | $18 billion |
The critical point is not the absolute cost. It is that the cost does not change with volume. Processing 176 million transactions or 1.8 trillion transactions — the per-unit cost remains €0.01. There is no gas fee auction. There is no block space market. There is no congestion externality. The hundredth transaction costs exactly the same as the trillionth.
The regressive fee-to-value ratio documented by the Federal Reserve — where gas fees on small transfers can exceed 100% of the transfer value — is eliminated entirely. A $5 transfer and a $5 million transfer both settle for €0.01.
The Federal Reserve paper establishes a new framework for evaluating the stability of digital money. Reserve quality is necessary but not sufficient. The rail matters independently. This distinction has immediate consequences:
Backing stablecoins with Treasuries does not insulate them from runs. If the stablecoin settles on a congested blockchain with volatile gas fees, the fragility documented in FEDS 2026-037 applies. Settlement infrastructure is now a first-order risk factor. Choosing a rail with fixed, deterministic costs eliminates this risk entirely.
Issuing a CBDC on a permissionless blockchain — as the European Central Bank has explored — would expose sovereign digital money to the same congestion-driven fragility that affects private stablecoins. The safest possible liability (central bank money) would circulate on an unstable rail. This paper makes clear that the rail must be designed with the same care as the liability.
Current stablecoin regulation focuses almost exclusively on reserves, redemption rights, and issuer solvency. The Federal Reserve paper shows this is incomplete. Settlement infrastructure — its cost structure, volatility, and congestion properties — deserves explicit regulatory attention. An architecture that eliminates cost volatility and congestion externalities addresses a systemic risk that reserve regulation alone cannot.
If settlement cost is the source of fragility, then settlement cost is the variable to eliminate. The architecture described in this paper does exactly that — at a cost 24× below Fedwire, with finality measured in microseconds rather than seconds, and with zero vulnerability to quantum computing.
The technology exists. It operates today. It is protected by European patent law and cleared by the French Ministry of Defense.
The Federal Reserve proved that perfectly safe digital money can still be fragile — because the rail introduces a novel source of instability that is independent of the reserves.
We have shown, using the authors' own mathematical framework, that this fragility is a consequence of a specific design choice: pricing trust through congestion-sensitive fees on permissionless blockchains. When that design choice is replaced — when $c'(x) = 0$ and $\alpha$ is fixed — the run threshold $\gamma^*$ diverges to infinity. The strategic complementarities that generate runs cannot form. The fragility disappears.
The fragility of perfectly safe digital money is real. But it is not inherent to digital money. It is inherent to the choice of rail. A different rail — one that provides fixed-cost, immediate, and physically irreversible settlement — eliminates the fragility entirely.
The rail has a solution. It is called Recognitium.