Showing posts with label censorship resistance. Show all posts
Showing posts with label censorship resistance. Show all posts

Friday, September 2, 2022

Some thoughts about the resilience of decentralized stablecoins

If a decentralized blockchain protocol is worried about being shut down by the authorities, how can it defend itself? A recent discussion surrounding MakerDAO explores this question. MakerDAO (or just Maker) issues the Dai stablecoin, of which there are around $7 billion in circulation.

Rune Christensen, the founder of Maker, sees a precedent for a clampdown on Maker in the US Treasury's recent sanctions on Tornado Cash, a mixer. He worries that the authorities may try to shut down Maker by seizing its assets, specifically its real-world assets, or "RWA." To counter this threat, Christensen suggests that Maker turtle into what he calls phoenix stance:

Source: MakerDAO forum

While in phoenix stance, Maker would no longer rely on RWA. By RWA, he is referring to centralized stablecoins such as USD Coin and loans to banks and other financial institutions that have a physical address and a regulator. These are the sorts of assets that can be used by authorities as a lever to hurt the Maker protocol. With nothing for authorities to confiscate, presumably Maker would be resilient to attempts by authorities to shut it down.

I disagree. Christensen exaggerates the degree to which Maker's resilience relies on seizability. Seizing a protocol's assets is just one of many levers that authorities have to stop a protocol like Maker. In the case of Tornado Cash, for instance, sanctions were used, not seizure. Even though no ether in Tornado's smart contracts has been confiscated (indeed, it would be impossible to do so), the sanctions have effectively cut off much of Tornado Cash activity:

A ban or sanctioning of Maker would mean less licit usage of Dai, a removal of collateral from Maker, delistings of Dai at off-ramps like Coinbase, a drying-up of liquidity, and employees and investors abandoning it. Dai would shrink to irrelevance all this achieved without the government seizing an ounce of the collateral behind Dai.

To sum up, a focus on seizure-resistance, so-called Phoenix stance, won't render Maker meaningfully more resilient.

That being said, I agree with Christensen that removing real-world assets will make Maker less susceptible to being attacked. But the way I get to this conclusion is different.

Removing real-world assets from Maker would make the Maker system less usable. First, without centralized stablecoin reserves, Dai's peg to the dollar wouldn't be as tight. A looser Dai price would make it more inconvenient to own Dai. It would also make it riskier to borrow Dai, since borrowers couldn't know ahead of time precisely how much they'll have pay back. Secondly, the sorts of collateral acceptable for loans would be restricted to one asset, ether, which effectively cuts off huge parts of the market for Dai loans.

As Maker becomes more awkward, fewer people will use it, and it'll shrink... perhaps to the point that it begins to fly under everyone's radar. No regulator or authority is going to bother trying to shut down a rarely-used $50 million protocol. So it's the irrelevance that a no-RWA policy brings, and not the inability to seize assets, that leads to safety from attack.

Conversely, introducing real-world assets makes Maker more practical, attracts additional users, and brings Maker onto everyone's radar, which increases the odds of authorities shutting it down using any of the many levers they have at their disposal. (Conversely, the jump in relevance that RWAs entail also increases the odds of authorities finding regulatory space for Maker.)

To finish off, here's a way for Maker stakeholders to think about the system's susceptibility to being shut down, and how real-world assets enter into the equation:

Stakeholders should ask themselves how relevant Maker has become. Has Maker become so important (and its public perception so negative) that it is about to attract the baleful eyes of regulators? If so, one defensive option is to engage in a rational form self-sabotage: make the tool less useful. This will shrink the pool of Maker users, and thus the tool's visibility to regulators, and therefore the likelihood of it being shut down. Real-world assets enter into the picture because their removal is one way to impinge on the system's usefulness.

Of course, if a protocol is going to start engaging in self-sabotage, then the people making this decision better be pretty sure that their original assumption that regulators are furious is correct.

Monday, August 15, 2022

How to stop Forsage, Meta Force and other smart contract pyramid schemes

Serial smart contract pyramid schemer Lado Okhotnikov
 

[This is a republication of my latest opinion piece from CoinDesk.]

Last week the U.S. Securities and Exchange Commission (SEC) charged 11 individuals with creating and marketing Forsage, the world’s largest and longest-running smart contract-based pyramid scheme.

Alas, Lado Okhotnikov, the ring leader of Forsage and rumored to be based in the Republic of Georgia, remains at large. And while the original Forsage smart contracts are nowhere near as popular as they once were, they continue to welcome new money, SEC be damned.

Worse, Okhotnikov's new smart contract pyramid, Meta Force, continues to grow. Over $42 million in DAI stablecoins have been deposited into Meta Force by unwitting investors since the alleged scam debuted a month ago.

Smart contract pyramid schemers like Okhotnikov prey on the weak and vulnerable. What can we do to better fight them?

A quick history of smart contract-based pyramids

A pyramid scheme is an illegal business model where returns to existing investors are generated from newly recruited investors' money or fees. They are ultimately unsustainable because the supply of new investors is finite.

Pyramid schemes have existed for centuries. But pyramid schemers quickly realized the benefits of blockchain technology. MMM Global, a pyramid that tore through Nigeria, India, China and other developing nations through 2014 to 2016, used bitcoin (BTC) for payments. A group of researchers who studied the pyramid found that, at its peak, MMM Global was processing $150 million per day.

The advantages of bitcoin are clear. While authorities can shut down a pyramid scheme by leaning on its payments processors or bank, the Bitcoin blockchain can't be turned off.

The rollout of Ethereum led to the next big innovation in pyramids: the smart contract pyramid scheme. In addition to relying on blockchains for payments, this type of alleged scam built its pyramid apparatus on the Ethereum blockchain using smart contracts.

There are advantages to using a smart contract to run a pyramid. The entire back office structure can be automated using code, which makes administration easier for the scammer. It also allows the pyramid to be marketed as an "honest" Ponzi; that is, because it is implemented by code rather than by hand, it can be said to always run correctly.

Furthermore, because that code is public, it can – in theory, at least – be audited by users.

Smart contract pyramids are safer for the scammer to run than traditional pyramids because they afford a degree of anonymity. And while the authorities can shut down a traditional pyramid by visiting the office out of which it operates, building it on Ethereum makes it much harder to stop.

Smart contract pyramids soon became endemic to Ethereum. A 2019 study by a group of Italian researchers cataloged 184 smart contract pyramids in play at the time.

Most of these were quite small. It was Lado Okhotnikov's Forsage that broke the mold. Forsage's first Ethereum smart contract, x3/x4, would process almost $240 million in payments in 2020. At one point it was Ethereum's second busiest contract, after tether.

Ethereum gas fees would soon rise, forcing alleged pyramid alleged scammers like Okhotnikov to migrate to cheaper blockchains. Over the next few years Okhotnikov launched five other smart contract Ponzis on the Tron and Binance Smart Chain blockchains. Recently, scammers have begun to move back to Ethereum thanks to level 2, or subsidiary blockchain, systems that have lowered costs. In Okhotnikov's case, he has set up his newest pyramid, Meta Force, on the Polygon Network.

A forensic analysis of Forsage

Thanks to the transparency of blockchains, Sarah Meiklejohn and other researchers carried out a precise analysis of Forsage’s payouts and losses, focusing on the $240 million Ethereum x3/x4 contract.

While the founders boasted that the system was transparent and open source, it took the researchers weeks of effort to understand the code, which meant that almost no Forsage participants could have actually audited the smart contract. So much for transparency.

Meiklejohn et al. found that the system had been coded at the outset to benefit only a few people. For instance, participants had to buy slots that offered the right to get payments from new recruits. After recruiting three participants, a slot would be blocked and the recruiter had to pay fees to reopen it and receive payment. The organizers’ slots, however, were coded to be exempt from this rule.

The SEC found that Okhotnikov had coded one of his subsequent pyramids, Ethereum xGold, to divert a portion of investor funds to a wallet that was not associated with a Forsage ID. This contradicted Okhotnikov’s representation that all funds were paid out to investors. By 2022, that address had diverted over 1,000 ETH.

In the end, Meiklejohn et al. report that 1 million Forsage accounts lost money, a remarkable 88% failure rate. The top 1,000 users made 50% of all profits. Okhotnikov and his fellow cofounders capitalized by positioning themselves at the top of the pyramid. The SEC accuses them of owning the best five spots in the x3/x4 Forsage pyramid, the topmost of which earned 5409 ether (ETH), well over $1 million, according to Meiklejohn et al.

Okhotnikov and his colleagues aggressively marketed their scams on social media. Forsage's official YouTube channel, which is now dedicated to the new Meta Force pyramid, currently has over 47,000 subscribers. The most popular Forsage video, which is in Hindi, has been viewed 384,000 times. This is despite YouTube's terms of service having a blanket ban on marketing pyramid schemes.

In their paper, Meiklejohn and her colleagues traced the location of most of the victims of Forsage to developing nations, in particular Nigeria, Philippines and Venezuela. This reveals these alleged scams for what they are: a way for a few rich people to steal from the poor and vulnerable. They need to be stopped. But how?

What can be done?

Because smart contract pyramids are built on censorship-resistant blockchains, they can't be attacked at the root, nor can they be undermined indirectly by removing them from the payments system.

Writing on CoinDesk, Lex Sokolin has proposed that white hat hackers organize to find vulnerabilities in smart contract pyramids and bring them down. It's a nice idea, but so far white hat hackers haven't shown much interest in chasing after pyramids.

Perhaps the most effective way to hurt smart contract Ponzis is by attacking their reputation. The SEC's charges will certainly help on this front. Now when a potential victim searches for Okhotnikov or one of his "investment" products, they'll have the opinion of the world's largest securities regulator to rely on.

The good news is that the SEC's actions seem to have had an effect. The rate of deposits to Okhotnikov's newest (alleged) scam, Meta Force, which has already attracted $42 million in deposits, began to decline the day after charges were announced. On YouTube, a nervous Lado Okhotnikov described the SEC’s charges as slander and defamation.

But we needed the SEC to begin its attack long ago. Publishing a cease and desist early on, like securities regulators in Montana and the Philippines did, would have helped tarnish Okhotnikov's reputation before his alleged scams could hurt more people.

Regulators like the SEC should try to harness the transparency of blockchains to their advantage. It's possible to see these things popping up and monitor how big they get, so regulators can very quickly mobilize resources to combat them.

The SEC should also consider fighting like with like. Smart contract Ponzi scams spread through garish videos on YouTube. Alas, the SEC didn't post its charges to its YouTube channel. A catchy video about Forsage would go much further than a terse tweet.

Finally, influential blockchain personalities like Ethereum co-founder Vitalik Buterin and Binance CEO Changpeng Zhao should step up and speak out against smart contract Ponzis when they crop up. They may not wish to do so, because admitting the problem may attract negative attention to the technology. But addressing these scams as early as possible will not only reduce damage to innocent people, it will also limit damage to the long-term reputation of blockchains.

Monday, March 28, 2022

Why does crypto work for Russian ransomware, but it wasn't useful for the Ottawa truckers?

[This is a repost of my recent article for CoinDesk exploring why bitcoin has been demonstratively useful for certain illegal activities, like ransomware, but fails when it comes to others, like the Ottawa trucker convoy. Spoiler: bitcoin's usefulness for engaging in non-permitted transactions very much depends on the onramping and offramping processes, and whether these threshold points are tightly controlled or not.] 

 The Ramps Killing Bitcoin's Dissident Thesis

 Crypto is marketed by its fans as an unstoppable dissident technology and feared by governments for its subversiveness. But the many shortcomings of a recent bitcoin fundraiser to support an illegal Ottawa, Ontario, trucker convoy (more on that later) suggests that crypto isn't as unstoppable or subversive as it is often made out to be.

But if Ottawa contradicts the standard crypto narrative, we also have an example that confirms it. Waves of successful Russian ransomware attacks relying on the Bitcoin network to extract ransom payments suggest that crypto is an incredibly effective technology for evading rules.

So which is it: unstoppable or not? The short answer: It depends on the off-ramps and on-ramps. Let's explore why crypto was a dud in Canada, but is highly successful for Russian ransomware operators.

What crypto brings to the table is the ability for two people to make a digital peer-to-peer transfer that cannot be preempted by a third party. But a peer-to-peer crypto transfer is only the middle step in a three-step circuit that begins with on-ramping into crypto and ends with off-ramping out of crypto. If either the on-ramping or the off-ramping processes are closed or guarded, much of crypto's fabled ability to circumvent restrictions is neutered.

The Ottawa trucker convoy bitcoin fundraiser is a good example of the off-ramping process being leveraged by law enforcement to defang crypto. I described the convoy’s financing last month for CoinDesk. Over the last few weeks various Canadian parliamentary committees and court rulings have shed more light on the fate of the convoy’s finances.

By early February, the convoy of truckers blockading downtown Ottawa had transitioned from legal protest to illegal mischief. Sending donations through centralized fiat-based crowdfunding sites became impossible. The convoy’s main fundraising campaign, hosted on GoFundMe, was shut down on Feb. 4. A pivot by convoy organizers to rival crowdfunding platform GiveSendGo [which is powered by Stripe] was rendered useless by an Ontario court's restraint order a few days later.

That left a bitcoin fundraiser by the name of HonkHonk Hodl as the only way to connect with the rogue blockaders.

The on-ramping stage of the convoy’s bitcoin fundraiser proceeded unimpeded. Any American who wanted to donate to the illegal blockade could freely swap U.S. dollars for bitcoin via an exchange such as Coinbase. Once the cryptocurrency was acquired, no force on earth could stop that bitcoin from being transferred from an American’s personal wallet across the border to the Canadian organizers' bitcoin address.

The bitcoin fundraiser eventually raised $1.1 million in bitcoin. It was at the final stage, off-ramping back into Canadian dollars, that things fell apart.

From the outset, the identities of the people in control of the convoy’s bitcoin wallets had been broadcast across social media. Once the convoy was deemed illegal mischief, these public-facing organizers and their wallet addresses became easy targets of police investigations, freezing orders, injunctions and class-action suits, all of which prevented them from off-ramping out of donated bitcoins into spendable fiat.

The strategy of publicizing the identities of the organizers might seem like a mistake, but it wasn’t. A fundraiser can't gain any momentum if the people collecting the money aren't identified. Anonymous organizers could very well be scammers, and the whiff of fraud would doom fundraising.

Nicholas St. Louis, the lead organizer of the bitcoin fundraiser and a suspect in a criminal investigation, was forced to give up seed phrases for his fundraising wallets to the Royal Canadian Mounted Police, which is Canada’s version of the FBI. Parallel to that, a separate civil court injunction on behalf of an Ottawa class-action suit named hundreds of bitcoin addresses associated with the fundraiser. To comply with the order, St. Louis eventually forfeited $250,000 in undistributed bitcoins to a court-appointed escrow agent. That sum will potentially be used to compensate Ottawa citizens damaged by the convoy's actions.

Just hours before the court injunction fell, St. Louis managed to distribute two-thirds of the donated bitcoins to around 100 truckers. To prove they were honestly distributed, St. Louis recorded himself giving envelopes to each trucker and published the recordings on social media. That made it a cinch for the RCMP, litigators and aggrieved Ottawa citizens to determine the identities of the truckers who received the donations.

The transparency of bitcoin’s blockchain means that all of the distributed bitcoin has been flagged by law enforcement as well as being listed in the court’s freezing order. Anti-money laundering officers at exchanges are on guard, and any effort on the part of the 100 truckers to off-ramp their cryptocurrencies into spendable currency by selling marked bitcoin on an exchange will result in forfeiture. Worse, the truckers could run into potential legal trouble if they try, because ignoring the court’s freezing order is punishable by fine or imprisonment.

Truckers brave enough to risk contravening the court order might try to evade exchange blacklists by directly buying goods and services with bitcoin. (They would have to use retailers that don’t rely on compliant crypto payments processors like BitPay.) Given that bitcoin is so rarely accepted in trade, this is tantamount to barter, and bartering is inconvenient.

So the truckers have been left holding a bunch of mostly useless, even dangerous, injuncted crypto. As for the remaining undistributed donations, they have all been confiscated by the courts. What a mess.

If bitcoin failed the truckers, let's see why it has worked so well for ransomware operators. Ransomware is malicious software that takes control of a computer by encrypting files or threatening to publicly expose data. The ransomware operator, typically located in Russia, releases that control only after receiving a ransom payment, usually bitcoin. In one of the more notorious incidents, JBS USA, the world’s largest meat supplier, paid an $11 million bitcoin ransom to free its computers.

The ransom payment on-ramping process is completely fluid. That is, it is 100% legal for the U.S. victim of a ransomware attack – usually a corporation such as JBS, a school board or a government agency – to buy bitcoin on an exchange like Coinbase in order to pay the ransom. In fact, a new industry known as ransomware payments facilitation has emerged to service this need.

Whereas a wire payment to a Russian bank account might be frozen or clawed back, a bitcoin payment made to a Russian ransomware operator's wallet can't be. That's tremendously useful to ransomware operators.

Most importantly, Russian officials have made little attempt to inhibit the off-ramping process. As long as ransomware gangs don’t attack Russian companies, their ability to operate on Russian soil has been tolerated as has their access to Russian off-ramps. For instance, nested exchanges with Russian links such as Suex and Chatex have been used by Ryuk and Conti ransomware operators to convert bitcoin ransoms into useful currency.

And that's why ransomware has been so successful. The combination of 1) unimpeded U.S. on-ramping 2) a US-to-Russia bitcoin bridge and 3) unimpeded Russian off-ramping creates an unstoppable monetary circuit. By contrast, Canadians' closure of the off-ramping process crippled the convoy's bitcoin fundraising circuit.

(Incidentally, this is why one of the quickest ways to end the ransomware threat is to shut off the on-ramps: Make it illegal for U.S. entities to pay crypto ransoms. It also illustrates why Russians can’t rely on crypto to evade sanctions: the big off-ramps like Binance and Bitfinex can be controlled by U.S. sanctions policy.)

Governments, whether they be democracies or dictatorships, are often fearful of crypto's censorship-resistance, leading to calls for bans. The lesson from the Ottawa trucker convoy and Russian ransomware gangs is that as long as the on-ramping and off-ramping process are regulated, these fears are overblown.

As for advocates of bitcoin’s capacity to help dissidents, if the trucker convoy proves anything, it’s that these advocates have their work cut out for them.

Thursday, February 3, 2022

Don't bank on bitcoin banking the unbanked

Bitcoin evangelist Andreas Antonopoulos thinks that bitcoin can solve the unbanked problem.

If you've spent any amount of time studying the unbanked problem, you'll know that Antonopoulos's claim is wrong for all sorts of reasons. Firstly, the World Bank estimates that there are 1.7 billion people who lack a bank account or mobile money access, not 4 billion. More importantly, the main hurdle to having a bank account isn't lack of ID, as implied in Antonopoulos's tweet. It's that people don't have enough money to open an account.

According to FDIC [pdf], 49% unbanked U.S. households cite “don’t have enough money to meet minimum balance requirements” as a reason for not having an account—the most cited reason. "Personal identification, credit, or former bank account problems" is far down the list of most-cited reasons, coming in at fifth.

In the Philippines, the number of unbanked Filipino adults stood at an incredible 51.2 million in 2019, or 71% of total adult population. The topmost reason for not having an account is "not enough money" as reported by almost half (45%) of the unbanked (see below). Lack of ID documents is the third most cited reason, at 26%.

Bangko Sentral ng Pilipinas 2019 Financial Inclusion Survey [pdf]

The World Bank's 2017 Global Findex survey, which surveys more than 150,000 adults in over 140 economies, found that the most common reason (cited by two-thirds of the unbanked) for not have an account was "having too little money to use an account." Only one-fifth cited "lack of documentation and distrust in the financial system."

So let's not misconstrue the unbanked problem. As Yaya Fanusie put it last year: "People mainly lack financial services because they lack income and not the other way around. So, to effectively bank the unbanked, the key problem to solve is how to help people generate more income." Do read the rest of Fanusie's post, in which he provides level-headed critique of the ability for crypto to bank the unbanked.

Antonopolous really wants bitcoin to solve the unbanked problem. But if a household is too poor to to open a bank account, it's also too poor to buy some bitcoins. (Never mind that the last thing low-income families should be doing is gambling on wild bitcoin price changes.)

Bitcoin does solve a niche type of financial problem. Those who have been cut off from the payments system for political or legal reasons can use bitcoin as an censorship-resistant alternative payment rail. Sanctioned Cubans are using it. So do online shops that sell legal but controversial products like salvia divinorum or kratom. White supremacists cut off from PayPal rely on it for funding. And criminals use the bitcoin network, say to extract ransomware extortion payments or sell kiddie porn.

But this category of "unbanked" is small, and only partially overlaps with the 1.7 billion who are unbanked primarily because of poverty. Antonopolous does a disservice in grouping them together. He is banking on bitcoin solving a problem it's simply not fit to solve.

Saturday, October 9, 2021

Embargoed by MasterCard/Visa, kratom vendors turn to crypto and eChecks


I spend a fair amount of time tracking real-world use cases for cryptocurrencies. I'm not talking about silly speculation, or millionaire crypto hobbyists using their bitcoins to buy Teslas, or illegal dark web markets that use Monero for payments. I'm talking about actual licit businesses that have turned to cryptocurrency payments -- not because they particularly care about crypto -- but because they need to.

To date, the retail kratom industry is one of the best examples I've been able to find of broad non-speculative licit cryptocurrency adoption. Kratom is a plant that grows in southeast Asia. The kratom leaf can be ground into a green powder that, when ingested, acts as a stimulant. In the U.S., online kratom stores are ubiquitous.

I'm not going to get into whether kratom is dangerous or has medicinal value, or whether it should be legal or not. (For that sort of discussion, I'd suggest visiting the FDA, WebMD, or the Mayo Clinic.) The main point I want to make in this post is that kratom is legal in the US (although several states have banned it).

Although kratom is legal, MasterCard and Visa have decided to prohibit kratom sales from their networks. This poses big problems for online kratom shops. Because the card networks dominate online payments, exile by these oligopolies causes serious financial damage to the unfortunate targets. To survive, the kratom industry has been forced to turn to backup payments systems.

MasterCard's Business Risk Assessment and Monitoring (BRAM) policy, for instance, lists a number of impermissible activities:

Source: Netpay

Most of the prohibited transactions listed by MasterCard are illegal, such as the sale of child pornography. But some are legal, including the sale of "certain types of drugs or chemicals." MasterCard specifically mentions salvia divinorum, a legal drug that has hallucinogenic properties. Although it isn't listed as an example, kratom is usually considered to fall into the same category as salvia.

Acquirers, the financial institutions that connect businesses to the card networks, face large penalties if Visa or MasterCard catch them facilitating prohibited card transactions. To reduce this risk, acquirers will often hire what are called Merchant Monitoring Service Providers, or MMSPs, to scan through retailer data and spot anything that looks dangerous. MMSPs such as LegitScripts are very aggressive about rooting out kratom sales.

Despite the card networks disallowing kratom sales, many of the 20 or so sites that I scanned through still offer card payments. According to my research, kratom sites have a number of ways of securing card availability, one of which is called transactions laundering. That is, a kratom site camouflages its prohibited product sales by routing them through a front store that sells legitimate goods. Eventually these prohibited transactions get caught by the card network or the acquirer, and the site's card network access is revoked. It then has to scramble to build another front.

One commenter on Reddit describes kratom transaction laundering thusly:

"...we can do manual credit cards (as I can) over the phone because we use standard processors that don’t know it’s kratom. We do this by creating Dba’s that have fake web presences selling other products and they don’t find out it’s kratom for a while. Usually we can get a processor to work for 3-12 months before it gets shut down."
(Note: Dba refers to "Doing Business As". A DBA is a business pseudonym or a “fictitious name filing.”)

Another route that kratom sites take to get access to the card networks is to use an overseas aggregator. Kratom Crazy, a website that has since closed for business, describes how and why:

"International is the only way to go because card schemes are less aggressive on banks in international communities. This doesn’t mean they can’t be fined or shut down – oh because they can and still do. No aggregate account we have ever seen has lasted over 6 months before being shut down. The major downside is these accounts are usually 9% fees and up plus 10% rolling reserve over 6 months. So the merchant takes 19%+ off the top immediately plus they have to wait for 2-3 weeks before seeing the first days processing payout. Its a bad deal all around and a massive risk for losing money. In addition, when these accounts get shut down, there is usually no payout to the merchants."
So the upshot is that the sort of card network access that many kratom sites have managed to secure is unreliable and spotty. Indeed, many sites don't accept cards at all, including (at the time of writing) OG Botanicals, Canada Kratom Express, Krypto Kratum, and Rhizohm. Rhizohm's payments page goes to some pains to explain how it would rather be honest than lie to get card access:

Source: rhizOhm


Which gets us to cryptocurrency. Almost all of the kratom sites, including those that haven't been able to sneak themselves into the card networks, accept cryptocurrencies including Bitcoin, Ethereum, Litecoin, XRP, Stellar Lumens, or some other one. Third-party crypto processors like CoinPayments or Coinbase Commerce are typically used for payments processing.

When they accept cards, kratom sites often offer discounts for cryptocurrency payments. For instance, Happy Hippo's checkout page offers a 20% discount:

It's easy to understand why kratom sites would offer such discounts. It's expensive to use overseas aggregators for card payments. By steering a customer to Bitcoin or Ethereum, a kratom vendor saves itself the pain of a 10-15% card processing fee.

But cryptocurrency isn't the only payments option that kratom sites fall back on. Even more popular than crypto is eChecks, a traditional "fiat" form of payment that gets processed via an automated clearing house, or ACH. A kratom buyer inputs their bank routing and account numbers into the payments page, the payment then gets routed to the ACH network and, once cleared & settled, the funds arrive in the kratom merchant's bank account.

In the same way that a business must work with a card acquirer to get access to Visa or MasterCard payments, they must work with an eCheck acquirer in order to accept eCheck payments. But onboarding standards seems to be much looser with eCheck acquirers than card acquirers. For instance, in the screen shot below an eCheck acquirer is actively soliciting all sorts of high-risk industries, including not only kratom but also CBD oil and MLM-based businesses.  

Many kratom sites also accept a bespoke payments method called GreenBean Pay. Users open an account with GreanBean Pay and submit their banking account information. The service then uses Plaid -- a piece of financial plumbing that allows apps to hook into banks -- to link to the buyer's bank account and process the kratom payment.

Lastly, a bunch of kratom sites accept person-to-person payments options such as Cash App, Venmo, Zelle, and Interac eTransfer. (This probably goes against these services' terms of service, which generally limit usage to person-to-person payments).

While these backup options have become vital for connecting kratom retailers to the public, they are not really a great substitute for a card network connection. Cryptocurrency is clunky, awkward, and risky. eCheck is slow. By not offering the convenience of card payments, kratom sites lose out on a steady stream of would-be buyers. And this is evident by how desperate they are to find hacks that get them back into the Visa and MasterCard walled gardens.

In closing, I want to touch on something I mentioned in my previous post on MasterCard and porn. A big reason that card networks refuse to process legal transactions for things like kratom (or, similarly, for salvia divinorum, which I wrote about here) is they don't want to damage their brand. These substances may be permitted by law but they are controversial, and so the networks refuse to touch them.

All businesses have the right to protect their brands. But the card networks are oligopolies, and thus necessary for online survival. And so in my view the card networks should be required to forfeit their right to protect their brands. That is, Visa and MasterCard (insofar as they retain their oligopolistic powers) should not be be allowed to police vendors for what they deem to be controversial but legal products.

Which is not to say that I'm a champion of kratom. I'm only suggesting that the appropriate way to control such a product is not by card network bans, but by the Drug Enforcement Agency declaring it to be a scheduled drug.

The good news is that these sorts of situations are very rare. The card companies allow almost every legal transaction under the sun on to their networks, save a few outliers like kratum. This means that the population of licit businesses that need to use a back-up system like cryptocurrency payments (or echecks) is not very big. But examples like this still warrant our attention. Even if we don't particularly care about kratom, one day a product that we regularly consume could get censored by Visa or MasterCard.

Friday, June 11, 2021

Why do ransomware gangs like bitcoin? It's the censorship resistance

A new type of crime has recently emerged: big-ticket repeatable ransomware. Bitcoin is the chosen payments method for ransomware gangs. But these gangs don't use bitcoin because it is anonymous. They've chosen it because it is censorship-resistant.

Here's a quick illustration of how ransomware works. A university's servers are encrypted by a ransomware operator. Common victims also include corporations, hospitals, or police departments. Only a payment of, say, $1.14 million in bitcoins will release them (see below). The gang may up the ante by threatening to auction off the institution's data if a ransom isn't paid.

Ransomware isn't new. What is new and unique about the recent spate of ransom attacks is that they are:
 
big-ticket
factory-scale

That is, the average size of these attacks registers around $170,000, according to Sophos. Prior bouts of ransomware involved much smaller amounts. Secondly, these aren't isolated one-off attacks. They are manufactured at industry-scale with gangs like Ryuk or REvil carrying out dozens of attacks each day.

What makes bitcoin such a great tool for carrying out big-ticket repeatable attacks?

It's not the anonymity. A lot of people think that bitcoin is anonymous it's actually pseudonymous. All bitcoin transfers can be seen on the blockchain, or Bitcoin's public ledger. This is inconvenient for ransomware gangs because a ransom can be tracked from the original victim to its final destination. While it's possible to use a tool called a mixer to obfuscate one's bitcoin transactions, most ransomware gangs don't bother. Nor do gangs use cryptocurrencies that provide native anonymity, like Monero.

All of this points to the fact that anonymity is not really important to Ryuk, REvil, and other ransomware operators.

So what is it about Bitcoin that is attractive to these gangs? The feature they are after is something called censorship resistance. That is, Bitcoin allows value to be electronically transferred across vast distances without being halted or frozen. A ransomware gang can extort $1.14 from a victim in a country like the U.S. with strong law enforcement and repatriate it to a country with weak law enforcement like Russia, and then sell it for hard cash all without having to worry about a bank or the FBI freezing their funds somewhere in-between.

Bitcoin isn't the only censorship resistant payment network.

You wouldn't think it, but gift cards like iTunes and Google Play cards are (semi) censorship resistant payments networks, and it is for this reason that they've become popular with criminals. Scammers in call centres located in India frighten their U.S. victims with the fake threat of being apprehended by IRS agents, then tell the victim send a $500 gift card number by text in order to be exonerated. The gang will either resell the card number for cash or spend the balances in an app that they control. Gift card issuers don't have effective measures to freeze balances, so the bad guys can more-or-less use gift card networks with impunity.

So why are today's ransomware gangs using bitcoin instead of gift cards to extort money from the likes of the University of California San Francisco?

At the outset of this post I specified that one of the unique features of modern ransomware is that it is big ticket. A gang that wants to extort a victim for $1.14 million can't do so using gift cards. The maximum gift card size is $500. University of California San Francisco would have to buy 2,500 cards and send the attacker all the card numbers. And then the gang would have to launder all those cards. It's just too inconvenient. 

No, some other payment rail is necessary to do big ticket ransoms. Bitcoin is perfect for this there is no limit on transfer size.

What about carrying out big ticket ransom attacks via wire transfers? A wire transfer is an electronic payment from one bank account to another, often overseas.

Wire transfers are ideal for big ticket payments, but they aren't censorship resistant. Banks require identification and can freeze suspicious transfers. Our ransomware gang might be able work around this by setting up a network of money mules and accounts using fake ID in a foreign jurisdiction with weak law enforcement. They could then order a victim such as the University of California San Francisco to wire $1.14 million to the gang's foreign bank account. If the $10 million successfully arrives without being frozen, the gang  quickly withdraws the funds as cash before an injunction arrives.

But remember, the second key feature of modern day ransomware is that these gangs are carrying out multiple attacks each day. Setting up fake accounts at various foreign banks in order to receive wire transfers requires a lot of effort. Once one account has been used, it is compromised forever. By contrast, using the Bitcoin network over and over is a cinch. 

In short, wire transfers don't scale. Only Bitcoin allows for the mass production of ransom payments.

So now we know why ransomware gangs like to use Bitcoin. It's not the anonymity. Rather, Bitcoin opens up the field to big-ticket repeatable censorship-resistant payments. 

The next question we may want to ask ourselves is this: should we try and modify the Bitcoin payment network to stop these attacks?

We have a long history of making changes to payments systems that have become popular with criminals. When electronic gold issuer E-Gold became a tool for carders, it had to introduce a customer identification program. Western Union became a haven for “wire money to get me out of jail!” scams. It was fined and introduced much stricter know-your-customer rules. In the early 2010s Green Dot's MoneyPak became a popular network for FBI scams. Green Dot shut MoneyPak down for a year and rebuilt it from scratch to make it much harder for scammers to penetrate.

Bitcoin can't be modified, though. It is censorship-resistant. Which means we need other responses.

One possibility is to ban cryptocurrency. But as I wrote in a recent article for the Sound Money Project, I'm not a big fan of that solution. It seems like overkill. Rather, I suggested putting an embargo on the ransom payments themselves in order to cut off ransomware gangs' revenue. (I also fleshed this idea in an article for Coindesk in 2020.)

Here's another option. The U.S. government could make it difficult for ransomware operators by dusting off Section 311 of the USA Patriot Act. Let me explain how this would work.

A big chunk of the ransom payments that gangs like REvil collect are routed to cryptocurrency exchanges in jurisdictions with minimal anti-money laundering controls. The bitcoins then get converted into cash. Without these liquid offshore exchanges, it would be difficult for ransomware operators to launder their funds into spendable cash.

According to cryptocurrency analysis firm Chainalysis, one large Russian cryptocurrency took in nearly 44% of all ransomware funds sent to exchanges in 2019. (Chainalysis refused to name names). More recently, I stumbled on the following anecdote. It shows how a certain Russian exchange (perhaps the same one that Chainalysis mentions?) converts incoming bitcoin ransomware directly to U.S. dollar banknotes.

Now, without rogue exchanges such as the one above it would be difficult for ransomware operators to engage in business. But these exchanges are usually located outside of U.S. jurisdiction, so there seems to be little that the U.S. can be done about it.

This is where Section 311 comes in.

Section 311 allows the the Financial Crimes Enforcement Network (FinCEN), an arm of the U.S. Treasury, to designate any foreign based financial institution (like our Russian cryptocurrency exchange) as a primary money laundering concern. Once so designated, it becomes illegal for any U.S. financial institution to interact with the listed entity. 

For those readers with long memories, Section 311 was used to shut down Liberty Reserve, a Costa Rican-based electronic money issuer that became popular with criminals involved in identity fraud and credit card theft. Below is a list of entities that have been designated under Section 311.

Entities designated by FinCEN under Section 311 of the Patriot Act

What really provides Section 311 with the extra oomph for reaching rogue exchanges is that it allows FinCEN to require that U.S. financial institutions stop doing business with any other entity that provides banking services to the designated entity. Think of this strategy as the friend of my enemy is my enemy. Any Russian bank that offers an account to the offending Russian cryptocurrency exchange could be cut off from the U.S. banking system, too. Because the U.S. market is such an important market, most Russian banks will stop doing business with the exchange just to stay friendly with the US.

So Section 311 would cripple ransomware-friendly exchanges by severing them from the financial system. And without these rogue exchanges, it becomes much trickier to be a ransomware gang.

To sum up, Bitcoin is censorship-resistant. That's why ransomware gangs like it. This very same feature also prevents democratic societies from modifying the Bitcoin protocol to exclude ransomware gangs. Bitcoin may be censorship resistant, but the venues where it is traded are not. Section 311 and other tools that allow for leverage over these venues remain one of the best ways to attack bitcoin-based ransomware.

Thursday, December 24, 2020

Dolphin Safe Tuna and Fair Trade bank accounts?


The Royal Bank, Canada's largest bank, says that it won’t lend to clients that get more than 60% of their revenue from thermal coal or coal-fired power generation. Should a bank be able to avoid providing services to businesses just because they don't engage in the sorts of activities the bank, or its depositors, approve of? 

Put differently, should the Royal Bank be able to avoid "dirty" loans so that it can offer its depositors the semblance a Fair Trade, or green, bank account?

Critics would say that the Royal Bank shouldn't be allowed to avoid banking coal-fire dependent companies because it operates within a “regime of privilege.” That is, the Royal Bank benefits from a system of government regulation, central bank lender of last resort benefits, Federal deposit insurance, and direct access to core public payments systems. Given how deeply it is fused with public infrastructure, the Royal Bank is sort of like a utility, and like any utility it has a public duty to consider all customers, even coal energy guzzlers.

A related argument is that because banks must obtain a charter in order to operate, and this is difficult, there are not enough banks competing with each other. And thus it would be unfair for Royal Bank to avoid doing business with coal-fired power generators; financial banishment could doom these businesses to failure.

I draw the above arguments from a recent paper by Brian Knight and Trace Mitchell. Hopefully I have accurately captured their views. Given their specialness, banks should not be permitted to act as "de facto regulators," say the authors.

Now for the counterargument. People should be free to enter whatever contracts they see fit, including avoiding ones they find distasteful or against their beliefs. This freedom shouldn't be available to some people but not others. For instance, say that Sarah and Tom are both worried about global warming and sustainability. Tom is a skilled cook and decides to set up a sustainable restaurant that serves only ethically sourced ingredients. Sarah, for her part, is trained in finance and wants to set up a sustainable bank. Her source material for creating 100% green bank deposits is ethical loans to green businesses.

A law disallowing banks from choosing their customers means that Tom can self-actuate his beliefs by only dealing with green food suppliers, but Sarah cannot do the same by only lending to green borrowers. That hardly seem fair.

So there are two conflicting ideals at play here: the right to receive core services vs the freedom of association.

In the U.S., the Office of the Comptroller of the Currency (OCC), a key U.S. bank regulator, is choosing a side in this conflict. In an effort to stop banks from “politically driven discrimination,” the OCC is proposing a rule that would prevent bankers from using anything other than regular credit and operational criteria for evaluating a company seeking financial services. Were the OCC's "no discrimination rule" to be applied in Canada, it would require Royal Bank to lend to companies hooked on coal-fire energy.

In proposing this rule, the OCC has adopted the same rational as Knight & Mitchell. In an op-ed for the Wall Street Journal, OCC head Brian Brooks and Chief Economist Charles Calomiris argue that government chartering and direct access to the Federal Reserve obligate banks to provide services to all companies.

I recently wrote about this "no discrimination" rule for Coindesk. In that article I took the pro-Royal Bank side, arguing in favour of fair trade bank accounts. The 21st century consumer wants to know more about the provenance of the things they buy. We don’t just want tuna, we want dolphin-friendly tuna. We don’t want our T-shirts to be made in sweatshops with Xinjiang-grown cotton. We want ethical T-shirts. So why shouldn't we get clean bank accounts?

I want to explore this tension a bit more.

If we are going to apply a no discrimination rule to any segment of the banking and payments market, I think it should be placed on the card networks, Visa and MasterCard. The card networks have the power to exercise far more de facto regulation over the economy than any bank. If a bank disconnects a business, that'll certainly a hassle for the debanked business. But at least there are dozens of other banks in Canada to turn to, and thousands in the U.S. Even if no bank is willing to step forward, there is a whole host of non-bank financial institutions that can provide a business with financing or payments services.

Not so if the two card networks disconnect a retailer. Since there is no good alternative to Visa and MasterCard (especially online), a banned business could be in very real jeopardy. For instance, the card companies currently allow gun and porn purchases across their networks. But were they to ban gun and porn sales because they deem them unsavoury, Visa and MasterCard would be doing incredible damage to both industries, far more than if two large banks were to cease providing services to gun retailers or porn sites.

For a demonstration of this power, look at Pornhub's recent reaction to the threat of being deplatformed by Visa and MasterCard. After being accused of hosting child porn, Pornhub completely redesigned its platform to try and keep the two card networks on side (it failed.) 

By the way, I wrote about this incident for the Sound Money Project. Porn is legal, but child porn is illegal. Any financial institution that knowingly allows illegal transactions to cross its platform could be accused of money laundering. So Pornhub's deplatforming wasn't a case of the card networks acting as de facto regulators of content. Rather, they were doing what the actual regulators, i.e. the law, dictate. (That doesn't mean we shouldn't be worried that card networks can engage in de facto regulation. It just means that in this case, they didn't exercise that power).

So to reiterate, card networks have more power than banks. But unlike banks, card networks don't operate within a “regime of privilege” as described by Knight & Mitchell or in Brooks & Calomiris's op-ed. They don't have lender of last resort benefits, Federal deposit insurance, or direct access to core public payments systems. Nor do they have to get to get a bank charter. 

Visa and MasterCard are powerful because they are networks. Once everyone is connected to a network, there is very little reason for any one to leave to a competing network since only the incumbent can offer a large number of connections. (A bank is not a network, it is a member of a network.) 

And so Visa and MasterCard evade—unjustifiably so, in my opinion—all of the criteria for being targeted by the OCC's no discrimination rule. Instead, it is less powerful banks that would be handicapped by it on the basis of their proximity to government infrastructure and their obligation to get a charter.

Which gets me to my final point. The OCC and Knight & Mitchell have proposed that the criteria for triggering a no discrimination rule should be the existence of a "regime of privilege" and chartering. But doesn't a wide swath of the economy operate within a "regime of privilege" and chartering? 

A restaurant, for instance, must get a restaurant license before opening its doors. It also needs to secure building, ventilation, and signage permits. It is encumbered by zoning requirements and needs to secure a license to sell alcohol. Restaurants benefit from a government-funded system of food inspection. The ingredients that a restaurateur purchases has passed through some sort of a food safety regulatory process.

In sum, I do agree that we may need some sort of no discrimination rule for financial institutions. I'm just not sure that the OCC and Knight & Mitchell have found the right criteria for applying this rule. Let's choose whatever criteria get us to a situation that the card network Visa and MasterCard are the prime candidates for a "no discrimination" rule, not banks (or restaurants).

Sunday, March 31, 2019

Prepaid debit cards. The other anonymous payments method


When it comes to financial privacy, good old fashioned banknotes and privacy cryptocurrencies like Zcash & Monero get all the attention. But as I recently wrote for the Sound Money Project, let's not forget about prepaid debit cards.

Having written a bunch of posts over the last two years about financial privacy, I recently decided that it was time to step up my own personal financial privacy game. A few months ago I walked into my local pharmacy and bought my first non-reloadable prepaid debit card (i.e. gift card), a Vanilla card.

You've probably seen the rack of prepaid cards near the front of pharmacies and department stores. Some of them are closed-loop cards. They can only be used to buy things at the issuer, say Tim Horton's or Starbucks. But some of them, like my new Vanilla Prepaid card, are open-loop cards. That means they can be used wherever Visa or MasterCard are accepted. In Canada, Vanilla cards are sold in denominations from $25 to $250.

The Vanilla card that I bought doesn't have my name on it, nor did I have to show any ID to buy it. I paid for it in cash. This means that whenever I use my card, my identity won't be associated with the purchase. My card is backed by dollars held in a pooled account at Peoples Trust Company, a Canadian bank. It gives me the right to anonymously route my portion of the pooled funds along the MasterCard network to a retailer who operates a MasterCard terminal.

Given that authorities and banks have spend decades constructing a vast financial surveillance apparatus (the Bank Secrecy Act, FATF, AML, CFT, suspicious transaction reporting etc), it seems odd that this small window for accessing the digital payments system anonymously would have remained intact. To comply with Canadian anti-money laundering requirements, card-issuing banks require that the prepaid card seller (my pharmacy) collect the buyer's personal information if the face value of the card exceeds $1000. For amounts below that, due diligence is waived. The same practice is followed in the U.S. This regulatory exemption is why I didn't have to give up my anonymity when I bought my card.

The idea motivating the sub-$1000 exemption is that small amounts of anonymity can't easily facilitate criminal activity, but larger amounts can. (Note that I can convert my non-reloadable Vanilla card into reloadable format—i.e. a card that I'll be able to add money after the first batch is used up—but I'll have to register and forfeit my information. Only non-reloadable cards below the $1000 cap are exempt from due diligence.)

I'm not obsessed with privacy. I still use my information-laden credit card for a big chunk of my day-to-day purchases. But from time-to-time I want to have the option of shielding my data from outside observers. Cash is good for that. I already use banknotes and coins to pay for about half of my face-to-face purchases. This is usually for the sake of convenience, but sometimes it's because I'd prefer not to give up too many of my personal details to the retailer (especially small shops I've never been to before).

By adding a non-reloadable prepaid debit card to my wallet, I've gained an extra degree of protection. Say that I've used up all of the cash in my wallet, or I need to make a purchase in a place that doesn't accept cash, or I want to buy something online—well, a prepaid gift card offers me a way to make a transaction while still protecting my data.   

Law abiding citizens who are conscious of their financial privacy are a pretty small demographic. Sellers of non-reloadable prepaid cards have much larger markets in mind, specifically: 1) people looking to buy convenient gifts for friends and family or; 2) the unbanked and underbanked, i.e. those who don't have bank accounts or have them but don't use them. By allowing people to buy prepaid cards without identification, those without formal credentials such as driver's licenses, social insurance numbers, or credit scores can still make digital payments. Think the homeless, children and teenagers, immigrants, and refugees.

The post-9/11 brigade of security-at-all-costs zealots would love for regulators to shut the prepaid anonymity window. They worry that terrorists and money launderers will abuse prepaid cards. The anonymous prepaid window has only stayed open because these zealots have been countered by a collection of banking lobbyists who want to keep doing business with the unbanked and politicians who care about the disadvantaged.

I'm neither unbanked nor underbanked. I've got several bank accounts that I often use. Nor am I buying these cards as gifts. So I'm not really the target market for non-reloadable debit cards. My ability to get anonymous access the digital payments system is really just a by-product of the wider effort to make it easy for the unbanked to plug in. This is a precarious position for a privacy-conscious individual to be. In the U.S., where only ~93% of the population is banked, the constituency for anonymous prepaid access is relatively large. But in places where the banked population is approaching 100% (Canada, Finland, Germany, Netherlands, Denmark, Belgium, Sweden, UK), there is probably diminishing political support for providing anonymous access to the banking system.

In Europe, for instance, the window for anonymous access to digital payments seems to be closing. When the EU's 4th Anti-money laundering directive was passed in 2015, up to €250 in electronic money (the EU's term for prepaid instruments that reside on a device, say a card or a phone) could be bought without being asked to give up personal information. With the passage of the 5th Anti-money laundering directive in 2018, this amount has been reduced to just €150. And a new ceiling on online purchases of €50 was introduced. As I wrote in my recent Breakermag article, such a tiny amount of anonymity just isn't that useful.

One thing I've noticed about prepaid financial anonymity is that it is expensive. My first Vanilla card had a face value of $25. But I had to pay an onerous $3.95 to activate it. Buying higher value cards defrays this expense, but it still costs $7.50 to activate a card with a face value of $250. That's a 3% levy. Keep in mind that when I use an anonymous prepaid card not only am I paying the activation fee, I am also forgoing 2% cash back that my not-so anonymous credit card would otherwise provide me with.

Think about it this way. Let's say I decide to buy my groceries anonymously using a prepaid card. My $250 only gets me $242.50 worth of goods ($250 less the $7.50 activation fee). With my credit card, I can get $255 worth of food ($250 plus $5 cash back). That's an extra $12.50 in spending power if I decide to go the non-anonymous route. Sure, by using a prepaid card I've prevented my grocery store from being able to collect information about my eating habits. But is the $12.50 I've given up worth it? (Incidentally, this calculation also indicates how costly it is to be unbanked!)

While prepaid anonymity is handicapped by a low ceiling and high fees, the drawbacks don't stop there. Non-reloadable prepaid debit cards are great for buyers who want small amounts of privacy, but they don't help out retailers who want to shield themselves. In a recent article, privacy advocate Timothy May made a great distinction between buyer privacy and seller privacy:    

If someone is selling a controversial product (May uses birth control information as an example), they must always be wary of snitches who make a purchase only to "out" the seller, either by reporting the transaction to the authorities or posting it to social media. Controversy-wary payments providers will quickly cut the seller off. To protect themselves, sellers need a payments method that doesn't leave a paper trail. They also need a payments system from which they can't be censored. Cash is a good example—it doesn't leave a paper trail and is censorship resistant. So are privacy-friendly cryptocurrencies. But prepaid cards don't cut it. The seller can easily be reported to the network and banished.

The last drawback of non-reloadable prepaid debit cards is that they can't be used to make anonymous person-to-person payments. As far as I know, there is no technical reason that I shouldn't be able to use my Vanilla debit card to anonymously send $100 to anyone else with a Visa card, just by inputting their card number and clicking send on a website. In theory, this payment should get pushed across the Visa network.

But there are regulatory reasons that I can't do so. In the U.S., the Financial Crimes Enforcement Network (FinCEN) prohibits anonymous debit cards from offering person-to-person capabilities, and I believe the same rule applies in Canada. Meanwhile, cash and privacy-friendly cryptocurrencies do allow for anonymous person-to-person payments.

In sum, non-reloadable prepaid debit cards allow for a small extension of one's financial privacy. But in an age where the ability to make payments without someone snooping is getting increasingly rare, I suppose we have to take whatever crumbs we can get.

Wednesday, February 20, 2019

Death of a Northern Irish banknote

I was disappointed to see that First Trust Bank, a commercial bank based in Northern Ireland, will stop issuing its own brand of banknotes. Under different names, First Trust has been in the business of providing paper money for almost two hundred years, starting with the Provincial Bank of Ireland back in 1825.

Source: First Trust

99.9% of the world's population uses government-issued banknotes. A small sliver of us—those who live in Northern Island, Scotland, Hong Kong, and Macau—get to use privately-issued banknotes. Prior to First Trust's announcement, I count twelve private issuers scattered across the globe:

Northern Ireland: Bank of Ireland, Danske Bank (formerly Northern Bank), First Trust Bank, and Ulster Bank
Scotland: Bank of Scotland, Clydesdale Bank and The Royal Bank of Scotland
Hong Kong: HSBC, Standard Chartered, Bank of China (Hong Kong)
Macau: Banco Nacional Ultramarino, Bank of China (Macau)

Now there are just eleven.

To our modern sensibilities, privately-issued banknotes seem just strange. But before central banks emerged on the scene, privately-issued banknotes were the norm. Larry White and George Selgin have chronicled how the Scots were particularly adept at this task. Scotland's banking system, which was much more free than the British one, had relatively few bank failures in the 1700 and 1800s compared to the British one, which tried to put limits on banks' ability to issue notes.

In the 1800s this Scottish "free banking" system was imported into my country, Canada, by Scottish immigrants. People might assume that private banknotes were risky instruments, and that's why we needed governments to do the task. But as the chart below shows, between 1868 and 1910 Canadians experienced almost no losses on banknotes.

Only a minute trace of our private banknote heritage remains. In addition to the four jurisdictions that have been allowed to maintain the tradition, a few central banks are still publicly-traded—a vestige of their old status as private issuers. In the case of banks in Northern Ireland and Scotland, their ability to issue notes has been grandfathered. Only the seven existing licenses are allowed and no new entrants are permitted. Once First Trust gives up its banknote franchise, it can never get it back.

First Trust says that its exit from the banknote game is a commercial decision. Let's take a quick look at the profitability (or not) of issuing banknotes. First Trust ATMs and branches can either dispense government-issued Bank of England banknotes or its own brand. If First Trust dispenses its own brand, then it must incur an extra set of costs including printing & design, note destruction, and policing against counterfeits. If it stocks its ATMs with Bank of England notes, it avoids these costs.

But there is a benefit to issuing its own brand of notes. For each note it issues, First Trust "earns the spread". Unlike its other forms of debt, First Trust needn't pay any interest to its banknote holders. But like its other forms of debt, it can earn income on the set of associated assets it holds to "back" those liabilities. If this income outweighs production costs, then it makes sense for First Trust to issue its own notes.

How much does First Trust make on its note issue? For each paper pound that Northern Irish and Scottish banks issue, they are obliged to lodge 1) 60 pence at the Bank of England in the form of banknotes and 2) 40 pence in the form of deposits. Given that Scottish and Irish banks have issued around £7.6 billion in private notes, this means they have collectively invested in some £4.6 billion worth of Bank of England banknotes. Since regular notes like £50 are bulky, the Bank of England issues massive 'Titans' and 'Giants' to cut down on storage costs.

For issuers like First Trust, the £4.6 billion worth of Titans and Giants is dead money—they don't earn any interest on it. But the other £3 billion or so in backing assets held in the form of deposits earns interest. The gap between an issuer's 0% funding costs and interest income paid by the Bank of England is what generates a profit for their banknote franchise.

On Twitter, John Turner points out that it was once very profitable for Northern Irish and Scottish banks to issue notes, but new regulations in 2009 changed this:
"Prior to legislation passed in 2009, issuing notes was extremely lucrative for banks because they only had to hold backing assets (essentially reserves at the Bank of England) at the weekend, leaving those funds free to generate income during the trading week.  Some estimates suggest that this generated £70m per year for Northern Irish banks alone.  Since the passage of the Banking Act (2009), banks are required to hold backing assets against their note issue at all times." (source)
Another reason seigniorage has shrunk is a decade of low interest rates. Northern Irish and Scottish banks currently earn just 0.75% on the deposits held at the Bank of England, but in the 2000s they would have been earning as much as 5.75%.

All four Northern Irish issuers (and the Scottish ones too) will have suffered from both the 2009 legislative change and generally low rates, but First Trust particularly so—its banknote issue is far smaller than that of Bank of Ireland and Ulster. Looking at its 2017 Annual Report, First Trust issued just £333 million of the £2.6 billion worth of Northern Irish banknotes in circulation. Which means it earned just £990,000 in seigniorage last year (£333 million x 40% x 0.75%). It's hard to imagine that this is enough to compensate it for its printing and other costs.

By comparison, the Bank of Ireland has issued around £1.2 billion in banknotes with Ulster Bank accounting for another £800 million. Both of these competitors can spread their fixed costs around far more efficiently than First Trust can.

-------

First Trust's announcement puts me in a bit of a conundrum. I think the financial privacy provided by cash is important. And so is the robustness that it engenders. Banknotes are a decentralized payment instrument that can't break down in the face of disasters. Cash systems are also open: no one can be censored from using them.

At the same time, I see no reason why commercial banks shouldn't be allowed to issue banknotes. But what happens when the private provision of cash breaks down? In countries like Northern Ireland with privately issued cash, we are seeing low interest rate go hand-in-hand with banks eliminating cash. And this in turn means less financial privacy, openness, and robustness.

In short, when interest rates fall to zero, private banks will try to preserve their spreads by pushing the interest rate that they pay on their short-term liabilities (like savings and chequing accounts) into negative territory, say by implementing higher account maintenance fees. But they can't do this with cash. A banknote's rate is fixed at 0%. Rather than absorbing losses from banknotes, private issuers will simply cancel their note issue, much like First Trust has done, forcing everyone into account-based products.

If the UK's low rates persist for another few years (and fall even further) then the remaining private issuers in Northern Ireland and Scotland—Clydesdale Bank, Bank of Scotland, Ulster, Danske, etc—would also be forced to stop printing notes. Both countries would become cash-free zones. And since cash is the best way to transact anonymously, Scotts and Northern Irish would have little to no financial privacy. All transactions would proceed through easily-censored account-based payments systems that break when the power goes down. 

Luckily for the Scots and Northern Irish, they have a backup. The Bank of England can fill any void left by commercial banks with its own notes. Unlike commercial issuers like First Trust, the Bank of England isn't driven by profits. Even as its banknote profits shrinks to nothing, the central bank can keep on supplying currency—and thus financial privacy, openness, and robustness—to the people. Perhaps there is a role after all for public issuers of paper money to play.