Showing posts with label fintech. Show all posts
Showing posts with label fintech. Show all posts

Friday, August 9, 2024

Stablecoins – a digital version of Swiss bearer savings books


Before anti-money laundering laws arrived in Switzerland, anyone could walk into a Swiss bank and open an account without showing any ID. The bank would then issue you something called a bearer savings book, otherwise known as inhabersparheften or livrets d'épargne au porteur. Ownership of the savings book was considered by the bank to be proof of ownership of the underlying funds in the account. The person who opened the account could keep the book or, if they wanted to, pass it on to someone else without notifying the bank, at which point this second person was now entitled to the underlying funds, who could pass the book on to a third person, etc.

In essence, Swiss banks were issuing their very own version of cash.

As time passed and society's awareness of money laundering grew, usage of Swiss bearer savings books accounts was circumscribed by law. In 1977, banks were required for the first time to identify the initial customer to open the account. Also, anyone who wanted to withdraw over CHF 25,000 had to be identified by the bank. But the savings books still enjoyed a significant degree of anonymity. After account opening and prior to withdrawal, books could continue to circulate without identity checks.

In 2003, the issuance of new bearer savings books was prohibited by the Swiss government. Banks were now required to cancel existing savings books when they were presented to a bank's physical desk. Existing bearer savings books could continue to circulate anonymously from hand to hand, like cash, but thanks to steady cancellations they represented just 0.002% of the total assets held in Swiss bank accounts by 2019.

And so ended the Swiss bearer savings book. In the meantime, however, a similar financial instrument has arrived: the stablecoin.

To get some stablecoins, you need to deposit funds with the issuer, which will identify you upon deposit, but after that the stablecoins are free to circulate in the wild without any sort of checks. You can send them to a friend, and she can send them to a relative overseas, and that relative can transfer them to a drug dealer, and none of these subsequent owners need to show their IDs to the issuer. Stablecoin issuers, much like Swiss banks that once issued bearer savings books, often have no idea who they are dealing with.

So if Swiss bearer savings books have long been prohibited, why are stablecoins allowed to proliferate?

This is exactly the point made last month by FINMA, Switzerland's financial regulator, when it indicated that it will no longer tolerate the anonymous transfer of stablecoins. New guidance states that the identity of anyone holding a stablecoin must be "adequately verified by the issuing institution." So not only yourself, but your friend, her relative, and the drug dealer in the above transaction chain will be required to provide their ID.

To justify its new policy, FINMA appeals to the idea of technological neutrality. My take on technological neutrality is that just because a financial productin this case a payments productappears on a novel medium, or substrate (i.e. a blockchain) doesn't mean it is exempt from the same rules that already apply to equivalent products like bank savings books, which are issued on older substrates. Same function, same regulations.

Up till now, stablecoin issuers like Tether have tried to dodge these identification requirements with the legal fiction that only primary holders of stablecoins (i.e. those who originally deposited funds to get stablecoins) are their customers, and so it is only to this batch of holders that they have a due diligence obligation. Secondary, tertiary, and subsequent holders are not "customers", and so the issuers say they don't need to identify them.

But FINMA isn't buying this argument, and rightly so. All holders, not just primary ones, have a "permanent business relationship" with the issuer, says FINMA, and so everyone must be identified. You can certainly understand why FINMA wants to get ahead of this problem. If regular Swiss banks all see that stablecoins are enjoying special treatment, then they'll all join in on the party by switching over to the new substrate.

FINMA's guidance may not seem like a big deal. There are only two Swiss franc stablecoins to which it applies, and they are both tiny. Bitcoin Suisse's XCHF has under 1 million CHF in circulation, and Centi's CCHF doesn't appear to have much more. (Facebook may have run into an earlier informal version of this rule when FINMA assessed initial versions of its Libra stablecoin.)

But as a respected part of the global regulatory fabric, FINMA could very well be copied by other regulators. More importantly, FINMA is a member of the  Financial Action Task Force, or FATF, an umbrella organization representing the anti-money laundering authorities of 38 major nations. FATF promotes global anti-money laundering standards by blacklisting countries that fail to adopt them. If FINMA's policy on stablecoins is indicative of an emerging FATF approach to stablecoins, then expect it to spread.

The shocking thing to me is that it has taken this long for a major global regulator to issue a concrete ruling on the issue of stablecoin anonymity. It's about time. Standard anti-money laundering practice requires financial institutions to verify who is using their platform. Stablecoin issuers shouldn't get a free ride.

Monday, June 10, 2024

"I didn't launder the cash, your honor. The robot did."

Crypto enthusiasts protest the trial of Alexey Pertsev

As the multiple Tornado Cash legal cases wend their way through courts in the Netherlands and the U.S., we continue to learn how society's money laundering laws will be applied to some of the more unique financial entities being created on the new technological medium of blockchains.

Last month Alexey Pertsev, a co-creator and co-administrator of privacy platform Tornado Cash, was found guilty of money laundering by a Dutch court. (The full decision translated into English is here). Meanwhile, Roman Storm and Roman Semenov, Pertsev's colleagues, are under indictment in the U.S. for engaging in money laundering, among other charges. Separately, Tornado Cash continues to be sanctioned by the U.S. Treasury.

In general, I think a guilty verdict is the right decision. It would have been dangerous to find Pertsev innocent, since to do so would have given all sorts of hardened money launderers  the mob, drug lords, and terrorist networks  the perfect techno-legal loophole for avoiding future money laundering charge. Shifts in the underlying technology used for disguising dirty money should not be enough to turn a crime into a non-crime.

Before I get into my reasoning, here's some context for people who are new to the issue of Tornado Cash.

Tornado Cash was introduced by Pertsev, Storm, and Semenov in 2019 as a means for crypto users to enjoy privacy, but it wasn't long before thieves and hackers began to regularly deposit large amounts of stolen crypto into the utility to be obfuscated. This was plain as day to anyone who was watching. Blockchains are radically transparent (that's why privacy tools like Tornado are needed) which meant that everyone could watch in real-time as criminal trails converged on Tornado Cash. 

Court cases in both the U.S. and the Netherlands reveal that Pertsev and his colleagues were well-aware that illicit activity passing through Tornado, yet they continued to work on the utility anyways. This is important because possessing a "knowing" state-of-mind is a key ingredient to being found guilty of money laundering. If he had had no idea that the money being disguised was dirty, Pertsev could not have been charged in the first place.

Criminals were not the only users of Tornado. Licit actors who wanted privacy also deposited funds into the entity, including Ethereum co-creator Vitalik Buterin. But the presence of good transactions amongst the bad ones doesn't dilute the seriousness of the alleged crime. All it takes to trigger a money laundering charge is a few dirty transactions. "C'mon! 82% of the money was licit!" is no alibi.

Tornado Cash is by no means the crypto economy's first privacy platform. The original generation of privacy tools, so called "mixers" or "tumblers," began to emerge in the early 2010s with the likes of ChipMixer, Helix, Bitcoin Fog, Sinbad, and Blender. Anyone who required anonymity could send their bitcoins to the platform owner, who would proceed to commingle, or "mix," all incoming bitcoins in a single address under their control, thus rendering them untraceable. After some time had passed, the platform owner manually re-sent the now obfuscated bitcoins to their original sender, less a fee.

Like Tornado Cash, the first generation of privacy utilities was used by both criminals and regular folks seeking privacy. None of these original mixers have had happy endings. The owners of Bitcoin Fog and Helix, Roman Sterlingov and Larry Harmon, were both found guilty of money laundering and are currently serving jail sentences. Minh Nguyen, the administrator of ChipMixer, has been indicted for money laundering and is on the FBI's most wanted cyber list. Blender and Sinbad have both been sanctioned by the U.S. government.

Source

By any legal standard, these bad endings were well-deserved. They may have been technological novelties, but ChipMixer, Helix, Bitcoin Fog, Sinbad, and Blender were very much text-book examples of money laundering. The owners of these entities knew that some of the transactions they were participating in involved proceeds derived from criminal sources, yet despite this knowledge they proceeded to disguise them anyways. The only thing new about Helix and the other first generation mixers was the medium they were disguising  bitcoin instead of cash or deposits.

And so professional mixers like Harmon and Nguyen join a long line of traditional money launderers  dirty bankers, drug cash couriers, crooked remittance shop owners, and hawala operators. The law shouldn't be fooled by technological novelty, and in the case of the first generation of mixers, it wasn't.

That these were textbook cases of money laundering isn't disputed by the crypto community. Crypto advocates are a vocal bunch, and while they have loudly voiced their complaints about the legal action taken against Tornado Cash, they have for the most part quietly accepted the punishments meted out to the first generation privacy platforms. A legal fundraiser to support the Tornado Cash accused, for instance, has raised hundreds of thousands of dollars; there have been no equivalent efforts to raise a legal defence for Harmon, Sterlingov, or Nguyen. Crypto lobbyists have gone to war for Tornado Cash by launching court appeals and filing amicus briefs in its support. But when it comes to defending the Bitcoin Fog or Helix operators, or challenging the government's sanctioning of Sinbad and Blender  crickets.

The Tornado Cash legal cases have been more controversial than those of the first generation mixers thanks to a technical innovation in Tornado's construction. Most of us would consider this to be a relatively obscure change, but crypto enthusiasts see it as a defining one.

Harmon and his counterparts controlled their platforms outright, taking possession of the dirty crypto before manually sending it back to criminals in disguised form. Not so Tornado Cash. When it was built, a layer of automation was inserted between Tornado Cash's users and Pertsev and his colleagues.

Instead of sending their crypto to wallets controlled by the trio, as users did with Helix, crypto was now deposited by users into a set of automated pools. These pools were not managed on an ongoing basis by Pertsev and his colleagues. Rather, they were built using fully automated code on the Ethereum blockchain. Originally co-created by Pertsev in 2019, this code was frozen in time by the designers in early 2020, at which point it could no longer be upgraded or changed by anyone, even Pertsev. To this day the pools continue to operate, even though the Tornado Cash creators are either jailed or under indictment.
 
Other parts of the Tornado Cash platform are not so set-in-stone and remained under the control of Pertsev and his colleagues throughout. This includes the main website by which users accessed the automated pools, which was regularly upgraded over time, as well as the relayer service. (A relayer is a way to guarantee the privacy of Tornado Cash users). Pertsev and his colleagues profited from their ongoing control over the website and relayers.

The lawyers for Pertsev, Storm, and Semenov have argued that this layer of automated code exonerates the trio of money laundering. After all, if they no longer control what the utility is doing, then how can they be said to be operating a money laundering enterprise? The lawyers also argue that as writers of code, Pertsev, Storm, and Semenov are protected by speech laws, much like an author who has written a book. It is the code-is-speech claim that has particularity riled up the crypto community.

I don't like the idea of someone being sent to jail, but I think it's a good thing that the Dutch court chose not to accept these arguments.

Using go-betweens is a time-tested criminal strategy for distancing oneself from the crime. In more conventional money laundering operations, this strategy might involve separating the leader of a cash laundering operation from the actual dirty cash with a layer of underlings. In the age of crypto, no need to use living human underlings; just insert a buffer of unliving code.  

But the law shouldn't be fooled by artificial distances between a launderer and dirty money, whether those intervening layers be living people or code.

Allowing a buffer of automated code to absolve folks like Pertsev of money laundering would make it much easier to be a professional money launderer. Bad actors like Harmon and Sterlingov who have already been deemed by the courts to be criminals would suddenly have the perfect techno-legal loophole at their disposal if they decide to reengage in crypto laundering once their jail terms are up. Instead of manually running their operations as before, Harmon an Sterlingov could insert a mute layer of automated code between them and their illicit clients, their criminal mixing no longer being a crime.

But this would be an absurd state of affairs. A simple technological change to the way a criminal mixer administers their back office shouldn't convert them into a non-criminal.

The danger of the "it was the code that did it" defence extends beyond the crypto economy. In the much-larger traditional economy, laundering physical cash is a relatively common criminal profession. Take the fictional example of Marty Byrde, the star of Ozark. If the Tornado Cash defence were to be accepted in a court of law, then Byrde need only program a set of self-operating cash-handling robots to do most of his tasks for him, and he can get away scot-free. "I don't exercise any control over the packages of cash, your honor. The robots did!"

Or take the example of drug cash couriers, who run the risk of being convicted for money laundering when they move cash across the U.S.-Mexico border. Taking a cue from Tornado Cash, if a courier were to deploy an autonomous fleet of AI-powered drones instead, then when charged with a money laundering offence he or she need only invoke the now-standard defence: "it was the drones who controlled the cash, not me."

Taken to an extreme, the Tornado Cash defence means that money laundering effectively ceases to exist as a crime. All the culpability shifts onto the undead intermediaries, which can't be punished. This eclipsing of money laundering laws would be unfortunate. Professional money laundering is a key sector within the broader criminal economy, greasing the wheels for the entire enterprise. Without any legal defences against launderers, we are all much more vulnerable to crime-in-general.

In what follows, I want to provide a historical example of how the law should act when confronted with the changing tactics and technologies of money launderers.

Money laundering is a relatively new crime, but it has a much older predecessor in the crime of fencing, also known as receiving. The laws against fencing and money laundering are similar, the idea being to punish not the original criminals but the third-parties who knowingly participate in the crime by accepting dirty proceeds.

Any thief runs a big risk of being caught with stolen goods. At some point in the middle ages, specialized intermediaries, or fences, emerged to absorb this risk by accepting stolen property from professional thieves and redistributing it. Thieves could now offload their goods much quicker, thereby achieving a degree of safe harbor. For their part the fences themselves were safe from prosecution. After all, they hadn't committed the original theft, and accepting stolen property was not a crime.

The addition of specialized wholesalers to the thievery production process helped drive a rise in the incidence of theft, according to historian Rictor Norton. To close this loophole, fencing was criminalized in England in 1692. For the first time, a third-party who knowingly accepted stolen goods could be punished as an accessory to the original theft. The business of reselling hot property, risk-free until then, suddenly became much more dangerous.

The illegal fencing market quickly evolved new tactics. Enter Jonathan Wild, an incredibly successful launderer of stolen goods who, by the mid 1710s, is said to have been the "undisputed leader in the fencing business of London," according to marketing professor Ronald Hill. Wild evaded the 1692 anti-fencing law by never himself handling stolen property. Instead, he acted as an early version of Craigslist, but for stolen objects. He arm-twisted all of London's thieves to secretly report any robbery immediately to him, asking them to retain possession until he contacted them. At the same time, the unfortunate victims of those thefts were encouraged to approach Wild with requests to help locate their missing property.

Once Wild knew who was at both ends of a theft, he would pay the thief and tell him to return the goods to the victim using an anonymous porter. The happy victim got their stolen goods back, paying Wild a large reward for his troubles.

With Wild running circles around the law, Parliament passed an additional anti-fencing law in 1718 that punished anyone who took a reward under the pretence of helping a victim of theft, without actually prosecuting the original felon. In 1725, Wild was apprehended, tried, and condemned to death on the basis of this statute. 

A gallows ticket to view the hanging of Jonathan Wild (Wikipedia)

Now, a death sentence is extreme. But this is a good example of the law staying hip to both the changing technology of theft and its evolving division of labour. As the profession began to be subdivided into specialist thieves and an emerging class of allied wholesalers of stolen goods, lawmakers recognized that wholesaling was really just an appendage of theft, and thus fencing was criminalized. Later on, when fences like Wild adapted with new methods, the law kept up by finding additional means to reach fencing operations.

With Tornado Cash, we are at a "Jonathan Wild" stage of the modern money laundering profession's development. Control of dirty proceeds is being shifted to autonomous intermediaries so that the perpetrators can avoid prosecution. Much like how the law adapted in the 1700s to encompass Wild's tactics of distancing himself from dirty property, it will have to do the same with money launderers who use crypto code, autonomous robots, or AI drones to dissociate themselves. While I don't enjoy the idea of anyone spending time in jail, finding Pertsev guilty is part of that process.

Unlike Jonathan Wild, who was a criminal mastermind, Alexey Pertsev and colleagues seem to have bungled into the crime partly out of an ideological commitment to crypto ethics, the wider community unhelpfully egging him on. That doesn't mean he's not guilty, but it does suggest a lighter sentence than the 64-month one he received might be appropriate.

I've been arguing throughout this article that money laundering law should extend to innovative financial entities created on blockchains, such as Tornado Cash. I want to close by pushing back on this a bit.

A guilty verdict for Pertsev and his colleagues should not be tantamount to a ban the creation of autonomous financial institutions, particularly those focused on privacy. If a coder wants to create an open privacy mechanism for crypto, promote it, and financially profit from it, I think that he or she should have the right to do so, subject to the following condition. The code needs to include a component that screens out dirty crypto  and this filter shouldn't be a sham attempt, it has to be a genuine effort.  

While I think the law got it right in this instance, shame on lawmakers and law enforcement if they don't accommodate future generations of code-based entities (and their creators) that actually do make good faith efforts to freeze out dirty money.

Monday, March 18, 2024

How PayPal can use stablecoins to avoid AML requirements and make big profits


There's a new financial loophole in town: stablecoins. Stablecoins are dollar, yen, or pound-based payments platforms that are built using crypto database technology.

Financial institutions are always looking for loopholes to game the system. Typically this has meant avoiding capital requirements or liquidity ratios in one jurisdiction in favor of a looser standards elsewhere. The new stablecoin loophole allows for a different set of financial standards to be avoided, society's anti-money laundering regulations.

I'll explain this new loophole using PayPal as my example.

PayPal now offers its customers two sorts of regulated platforms for making U.S. dollar payments. The first type will be familiar to most of us. It is a traditional PayPal account with a U.S. dollar balance, and includes PayPal's flagship platform as well as PayPal-owned platforms Xoom and Venmo. These all have strict anti-money laundering controls.

The second type is PayPal's newer stablecoin platform, PayPal USD, which has loose anti-money laundering controls. PayPal USD is built on one of the world's most popular crypto databases, Ethereum. Dollars held on crypto databases are typically known as stablecoins, the most well-known of which are Tether and USDC.

What do I mean by fewer anti-money laundering controls?

If I want to transfer you $5,000 on PayPal's traditional platform, PayPal will first have to grant both of us permission to do so. It does so by obliging us go through an account-opening process. PayPal will carry out due diligence on both of us by collecting our IDs and verifying them, then running our information against various regulatory blacklists, like sanctions lists. Only after we have passed a gamut of checks will PayPal allow us to use its platform to make our $5,000 transfer.

Contrast this to how a payment is made via PayPal's new stablecoin platform.

First, we both have to set up an Ethereum wallet. No ID check is required for this. That now allows us to access PayPal's stablecoin platform. Next, I have to fund my wallet with $5,000. I can get these these funds from a third-party who already holds money on PayPal's stablecoin platform, say from a friend, or from someone who buys goods from me, or from a decentralized exchange. Again, no ID is required for this transaction to occur. Once I have the funds, PayPal will process my $5,000 transfer to you.

Can you spot the difference? In the transaction made via PayPal's legacy platform, PayPal has diligently got to know everyone involved. In the second transaction, PayPal makes no effort to gather information on us. And lacking our names, physical addresses, email addresses, or phone numbers, it can't do a full cross-check against various regulatory black lists.  

More concretely, PayPal's legacy platform does its best to stop someone like Vladimir Putin, who is sanctioned, from ever being able to sign up and make payments. But if Putin wanted to use PayPal's new stablecoin platform, PayPal makes almost no effort to stop him from jumping on.

One of the biggest expenses of running a legacy financial platform is anti-money laundering compliance. Programmers must be deployed to set up onboarding and screening processes. Compliance officers must be hired. If a transaction is suspicious, that may trigger a halt, and the transaction will have to be painstakingly investigated by one of these officers. The platform is hurt by lost customer goodwill  no one likes a delay.

That's where the stablecoin loophole begins.

PayPal can reduce its costs of getting to know its customer by nudging customers off its traditional platform and onto its PayPal USD stablecoin platform. Now it can onboard them without asking for ID. Since it no longer collects personal information about its user base, fewer transactions trigger flags for being suspicious, and only rarely do they register hits on sanctions blacklists. That means fewer halts, delays, and costly investigations. PayPal can now fire a large chunk of its compliance staff. The reduction in costs leads to a big rise in earnings. Its share price goes to the moon.

For now, PayPal's stablecoin platform remains quite small. Only $150 million worth of value is held on the platform, as the chart at the top of this post shows. The company's legacy platforms are much larger, with around $40 billion worth of balances held. Given the compliance cost difference, though, I suspect PayPal would love it if its stablecoin platform were to grow at the expense of its legacy platform.

I've used PayPal as my example, but the same calculus works for the financial industry in general. If every single bank in the financial system were to convert over to a stablecoin platform for the delivery of financial services, and no longer use their legacy platforms, the industry's total anti-money laundering compliance costs would plummet.

So far I've just explained this all from the perspective of financial institutions, but what about from the viewpoint of the rest of us? Society has set itself the noble goal of preventing bad actors from using the financial system. A large part of this effort is delegated to financial institutions by requiring them to incur the expense of performing due diligence on their platform users. This requires a big outlay of resources. Many of these costs are ultimately passed on to us, the users.

If institutions like PayPal switch onto infrastructure that doesn't vet users, then resources are no longer being deployed for the purposes we have intended, and the broader goals we have set out are being subverted. Is that what we want? I'd suggest not.



Some followup thoughts:

1. PayPal's stablecoin platform employs fewer anti-money laundering controls than its regular platform. On the other hand, its stablecoin platform has stricter standards in other areas, including the safety of its customer funds. I wrote about this here: "It's the PayPal dollars hosted on crypto databases that are the safer of the two, if not along every dimension, at least in terms of the degree to which customers are protected by: 1) the quality of underlying assets; 2) their seniority (or ranking relative to other creditors); and 3) transparency."

2. The pseudonymity of stablecoins is something I've been writing about for a while. In a 2019 post, I worried that at some point this loophole would lead to "hyper-stablecoinization," a process by which every bank account gets converted into a stablecoin. I'm surprised that almost five years later, this loophole still hasn't been closed.

3. The typical riposte to this post will be: "But JP, stablecoins are implemented on blockchains, and blockchains are transparent. This prevents bad actors from using them, and so stablecoins should be exempt from standard anti-money laundering rules." I don't buy this. Bad actors are using stablecoin platforms, despite their pseudo-traceability. "Its convenient, it's quick," say a pair of sanctions breakers about payments made via Tether, the largest stablecoin platform. Society has deputized financial institutions to perform the crucial task of vetting all their users. By not doing so, stablecoin platforms are shirkers. Trying to outsource the policing task to the public or to the government by using a semi-transparent database technology doesn't cut it.

Wednesday, December 20, 2023

Are flatcoins a good idea?


I'll start with the conclusion. I don't think flatcoins are a good idea.

The idea for flatcoins has been around for a while, but it got a wider airing when it popped up in a Coinbase marketing piece from earlier this year. Now, arch-crypto hater Nouriel Roubini has undergone a Damascene conversion and is about to introduce a crypto flatcoin, suggesting that these novel instruments are "the way forward."  

What is a flatcoin?

If you own one dollar's worth of stablecoins or one dollar's worth of Wells Fargo deposits, both stay locked at $1 dollar indefinitely. A flatcoin, by contrast, slowly rises in value over time to compensate the holder for inflation. So if you own a single flatcoin worth $1 today, it will be worth $1.0001 tomorrow, and $1.0002 the next day, and so on. Twelve months later its value will have arrived at $1.05. This 5% appreciation protects you from 5% inflation, leaving your purchasing power unchanged.

Roubini and Coinbase are marketing flatcoins as a blockchain-specific thing, but there's no reason the concept couldn't by packaged up as a traditional financial product, one without a blockchain. Imagine a Wells Fargo account that holds 100 in Wells flatbalances which rise by 3-4% a year. Or imagine a flatnote, the issuer indexing the purchasing power of its paper banknotes to inflation by promising to buy them back at progressively higher prices.

Roubini stakes out a role for flatcoins as a potential "global means of payment." As far as monetary/payments technology goes, I disagree. I think flatcoins are an evolutionary dead-end.

One of the key features of money that makes it so popular is that it is directly fused to the dominant commercial language that we all use in our day-to-day economic lives.

What do I mean when I say commercial language? We converse and haggle with each other in terms of the dollar, we think and plan in terms of dollars, we dream in dollars, and we remember in dollars. Every facet of our day-to-day commercial lives revolves around this very basic measuring unit. (In Europe, the euro serves as the basis of Europe's commercial language, and in Japan it's the yen.)

The dollars that we own in our pockets (and in our bank accounts, as well as the stablecoins in our Metamask wallets) have been conveniently designed to be fully compatible with the dollar measuring unit that we refer to in language. That is, our media of exchange are pegged, or wed, to $1. For instance, if I've got to make a $1500 rent payment next week, I know that the 1500 units sitting in my bank checking account are a precise fit for meeting that obligation. I don't know the same about my other assets, say my S&P 500 ETF, my gold, my government bonds, or my dogecoins.

This standardization is a convenient feature. It takes a lot of hassle out of day-to-day commercial life. It means that when we buy things or make plans to buy things, it's not necessary to engage in constant translations between the dollar media in our pocket and the dollars in our speech and thoughts and plans. As Larry White once put it, harmonizing the unit we use in our speech with the units we transact with "economizes on the information necessary for the buyer's and the seller's economic calculation."

Since everyone tends to converge on these very useful standardized units for making payments (i.e. deposits, stablecoins, and banknotes), the markets for them have become highly developed and liquid. This only makes them more useful for payments, in effect locking in their dominance.

A flatcoin, by contrast, has been rendered incompatible with the dollars that we use in our speech. One unit might be worth 1.1145 times the dollars we use in our speech today, and 1.1147 tomorrow, and 1.1205 next month. This erases one of the most user-friendly features of money, its concordance with the commercial vernacular, alienating anyone who might use it for their day-to-day spending. Flatcoins will thus be less liquid than standardized 1:1 dollars, and this lack of liquidity will render them even less useful for making payments.

There's the secondary problem with flatcoins that stems from taxes. Since a flatcoin rises in value over time, all purchases made with flatcoins will generate a small taxable capital gain. This introduces an administrative burden which makes it even less likely that people will use flatcoins as an everyday medium of exchange.

This incongruity between linguistic dollars and flatcoins doesn't mean that people won't hold them. They might be useful as a type of long-term savings vehicle, much like how one might buy and hold a fixed income ETF. But unlike Nouriel Roubini, I don't think they are "the way forward" when it comes to acting as a medium of exchange. No one is going to be buying a coffee with a flatcoin.

Thursday, November 16, 2023

Kraken v Kraken, or how to protect the public from crypto exchange failures


It's been a full year since FTX International and FTX-US collapsed, and the shocking thing is  there is still no regulated crypto venue in the U.S.! You'd think some lessons would have been learnt.

To best protect the public from the Sam Bankman-Frieds of the world, what the U.S. requires is securities-level oversight of crypto exchanges. Exchanges like Coinbase and Kraken are offering the sorts of investment services to the public that the U.S.'s main securities regulator, the SEC, is ideally positioned to regulate, such as trading, margin, custody, and market making. But one year after FTX's collapse, there doesn't appear to be a single SEC-regulated exchange.

The exchanges blame this on the SEC's lack of clarity. The SEC blames this on exchanges refusing to come in and register. God knows who's telling the truth.

Whatever the case, this intransigence only increases the odds that there'll be another U.S. crypto exchange collapse in the next few years, one that appropriate regulation could have otherwise prevented, or at least sheltered investors from the fallout.

What sort of protections am I talking about? After Canada suffered through the collapse of QuadrigaCX a few years back, and a bunch of Canadians like myself lost money, crypto exchanges were brought under the auspices of our existing securities regulatory framework, with a few nips and tucks to the rules to make them fit. This has led to a lot of changes that make Canadian crypto customers safer. I'm going to share the best example in this blog post.

Kraken is a well-known crypto exchange that serves both American and Canadian customers. However, if you're an American customers who uses Kraken, you possess a very different sort of asset than Canadian customers do.

Let's look at the fine print of the U.S. platform:

Source: Kraken's terms of service for U.S. customers

So in the U.S., asset are held "by us for you." That is, Kraken itself is doing the holding, safekeeping, or providing custody of crypto for its customers.

A key observation I want to make here is how fundamentally different this is from how standard regulated marketplaces function like the NASDAQ or the Toronto Stock Exchange. Traditional marketplaces offer a venue to trade assets, but they don't offer custody. If they tried to introduce this, their regulator would very quickly say no. I'll explain why below.

But first, let's head over to Kraken Canada. Once again, here's the fine-print:

Source: Kraken's terms of service for Canadian customers

What the underlined wording says is that if you're a Canadian, Kraken does not hold your crypto for you. That's very different from the U.S. Instead, Kraken says that customer crypto is deemed to be "custodial assets" and delegates your crypto to a "designated trust account at a Crypto Custodian." Bingo. There's the separation of trading from custody that I was talking about earlier, which aligns with standard practices for marketplaces.

Scan further through the fine print and you learn who that crypto custodian is: Anchorage Digital Bank:

Source: Kraken's terms of service for Canadian customers


Who is Anchorage? Anchorage is a federally-charted trust that is overseen by the Office of the Comptroller of the Currency, one of the key U.S. federal banking regulators. So if you hold some coins on Kraken, and you are an American, you own what is essentially a Kraken IOU, and you have to trust Kraken, but if you are a Canadian, you're effectively putting most of your trust in a federally charted financial institution. That's pretty stern stuff. 

Canadian securities regulators require all crypto exchanges operating in Canada to delegate at least 80% of customer crypto to a third-party custodian. (The other 20% can be held in a hot wallet for liquidity purposes.) Kraken doesn't appear to be doing this for its American customers, and that's because there's no U.S. regulator prompting it to do so. On top of requiring this separation, Canadian regulators stipulate that third-party custodians must be qualified. That is, they can't just walk in off the street. The custodian has to meet the regulator's standards, which requires having a Systems and Organization Controls (SOC) designation, and a bunch of other stuff too.

You can probably see by now that if you're a customer of Kraken, it's better to be Canadian than American, for the following reasons:

Anchorage is a federally-regulated financial institution and subject to strict oversight. Kraken U.S. is for the most part unregulated. No one is peering over its shoulder to check whether it is doing a good job safekeeping your coins.
Kraken has its fingers in a lot of different businesses, but Anchorage specializes on custody, and so it's probably better at the task.
Anchorage is independent from Kraken. This separation mitigates the risk of loss, theft, or misuse of assets by Kraken management. This is particularly salient in Kraken's case because it engages in many other business activities, such as trading or market-making, and these pose potential conflicts of interest.

In the future, one hopes that Kraken's U.S. exchange provides the same level of customer protection as Kraken's Canadian platform. But that's only go to happen if and when the SEC dictates a fundamental separation of crypto trading from custody, and whether U.S. crypto exchanges actually listen to the SEC.

Addendum (Nov 21): Talk about good timing. The SEC just announced that it is suing Kraken's U.S. entity for, among many other things, failing to segregate customer crypto assets and dollar balances. Segregation is different than third party custody. It basically means that customer property is kept separate from corporate property. This helps to prevent double-dipping. An exchange can make use of a third party custodian, for instance, but not segregate those funds into corporate and customer buckets. The combination of segregation and third-party custody is optimal.

By contrast, Canadian securities law clearly specifies that Kraken and any other Canadian exchange must already be segregating customers crypto and funds from corporate funds. In the regulators' own words, exchanges must keep customer property "separate and apart from its own property." This is in addition to the requirement that they use a third party custodian to store customer crypto and fiat. We can verify by reading Kraken's undertaking with Canadian regulators, in which it promises that it will be keeping customer crypto "separate and apart from its own assets."

Segregation is just one other low-hanging bit of customer protection that U.S. crypto exchanges should already have implemented, but probably won't until prodded by the government.


The next section is for pedants only, of which I'm embarrassed to be, which is why I'm putting this in very small print:

Kraken owns a U.S. bank. How does this fit into the story? Here are the details: In the U.S., the Kraken crypto exchange is really just the trade name for Payward Ventures. Payward Ventures is in turn a subsidiary of Payward, Inc. Payward, Inc has another subsidiary, Payward Financial, Inc, that owns a state-charted bank -- Kraken Bank. Notably, when you sign up as a customer of the Kraken crypto exchange, you are entering into a relationship with Payward Ventures, not Payward Financial. There is no indication in the exchange's terms of service that Kraken Bank is in any way involved in custody. Which seems... odd? Why wouldn't Kraken use its bank for custody?

When Kraken first applied to do business in Canada earlier this year, it said it wanted to use Kraken Bank as its custodian. Given that Kraken is in fact using Anchorage Bank as we speak, I suspect that Canadian regulators told Kraken: "Hey, guys. Kraken Bank is not sufficiently independent, you're going to have to use a third-party." And I suspect they were right about this.

Meanwhile, what about Canada's most popular exchange, Coinbase? Coinbase's Canadian terms of service doesn't indicate that it is using a qualified custodian. Customer assets are "held by the Coinbase Group for your benefit." Yeah, that's not going to fly with the regulators. I suspect that within a few months you're going to see it using a third-party like Anchorage, or its just going to leave Canada.

Friday, September 22, 2023

Coinbase: "What if we call them rewards instead of interest payments?"


Here's a question for you: which U.S. financial institutions are legally permitted to pay interest to retail customers?

We can get an answer by canvassing the range of entities currently offering interest-paying dollar accounts to U.S. retail customers. It pretty much boils down to two sorts of institutions:

  • Banks
  • SEC-regulated providers like money market funds.

There seem to be a few exceptions. Fintechs like PayPal and Wise are neither of the above, and yet they offer interest-yielding accounts to retail customers. But if you dig under the hood, they do so through a partnership with a bank, in Wise's case JP Morgan and in PayPal's case Synchrony Bank. (Back in the 2000s, PayPal used a money market mutual fund to pay interest). So we're back to banks and SEC-regulated entities.

And then you have Coinbase.

Coinbase will pay 5% APY to anyone who holds USD Coins (USDC), a dollar stablecoin, on its platform. (Coinbase co-created USDC with Circle, and shares in the revenues generated by the assets backing USD Coin.) The rate that Coinbase pays to its customers who hold USDC-denominated balances has steadily tracked the general rise in broader interest rates over the last year or so, rising from 0.15% to 1.5% in October 2022, then to 4% this June, 4.6% in August, and now 5%.

Coinbase isn't a bank, nor is it an SEC-approved money market mutual fund. And unlike Wise and PayPal, Coinbase's interest payments aren't powered under the hood by a bank.

So how does Coinbase pull this off?

In short, Coinbase seems to have seized on a third-path to paying interest. It cleverly describes the ability to receive interest as a "loyalty program", which puts it in the same bucket as Starbucks Rewards or Delta's air miles program. The program itself is dubbed USDC Rewards, and in its FAQ, customers are consistently described as "earning rewards" rather than "earning interest."

This strategy of describing what otherwise appears to be interest as rewards extends to Coinbase's financial accounting. The operating expenses that Coinbase incurs making payments on USDC balances held on its platform is categorized under sales and marketing, not interest expense

Oddly, this key datapoint isn't disclosed in Coinbase's financial statements. Instead, we get this information from a conference call with analysts last year, in which the company's CFO described its reasoning for treating USDC payouts as rewards:

Source: Coinbase Q4 2022 conference call
 

The flow of "rewards" that Coinbase is currently paying out is quite substantial. Combing through its recent financials, Coinbase discloses in its shareholder letter that it had $1.8 billion of USDC on its platform at the end of Q2. Of that, $300 million is Coinbase's corporate holdings, as disclosed on its balance sheet. So that means customers have $1.5 billion worth of USDC-denominated balances on Coinbase's platform.

At a rewards rate of 5%, that works out to $75 million in annual marketing expenses. (Mind you, not everyone gets 5%. We know that MakerDAO, a decentralized bank, is only earning 3.5% on the $500 million worth of USDC it stashes at Coinbase). In any case, the point here is that the amounts being rewarded are not immaterial.

Interestingly, Coinbase does not pay rewards on regular dollar balances held on its platform. It only provides a reward on USDC-denominated balances. This gives rise to a yield differential that seems to have inspired a degree of migration among Coinbase's customer base from regular dollar balances to USDC balances. 

For instance, at the end of Q1 2023, Coinbase held $5.4 billion in U.S. dollar balances, or what it calls customer custodial accounts or fiat balances. (See below). By Q2 2023 this had shrunk to $3.8 billion. Meanwhile, USDC-on-platform rose from $0.9 billion (see below) to $1.5 billion.

Source: Coinbase Q1 2023 shareholder letter


As the above screenshot shows, Coinbase has tried to encourage this migration by offering free conversions into USDC at a one-to-one rate. It has also extended the program to non-retail users like MakerDAO, although its non-retail posted rates are (oddly) much lower than its retail rates. Institutional customers usually get better rates than retail.

Incidentally, Coinbase isn't the only company to have approached MakerDAO to sign up for its fee-paying loyalty program. Gemini currently pays MakerDAO monthly payments to the tune of around $7 million a year, but calls them "marketing incentives." Paxos has floated the same idea, referring to the payments as "marketing fees" that would be linked to the going Federal Funds rate. The aversion to describing these payments as a form of interest is seemingly widespread.

There's two ways to look at Coinbase's USDC rewards program. The positive take is that in a world where financial institutions like Bank of America continue to screw their customers over by paying a lame 0.01% APY on deposits when the risk-free rate is 5.5%, Coinbase should be applauded for finding a way to offer its retail clientele 5%.

The less positive take is that USDC Rewards appear to be a form of regulatory arbitrage. Given that Coinbase uses terms like "APY" and "rate increase" to describe the program, it sure looks like it is trying to squeeze an interest-yielding financial product into a loyalty points framework, which is probably cheaper from a compliance perspective. If Coinbase was just selling coffee, and the rewards were linked to that product, then it might deserve the benefit of the doubt. But Coinbase describes itself as on a mission to "build an open financial system," which suggests that these aren't just loyalty points. They're a financial product. And financial products are generally held to strict regulatory standards in the name of protecting consumers.

We've already seen hints of regulatory push back against the rewards-not-interest gambit so popular with crypto companies. In the SEC's lawsuit against Binance, it named Binance's BUSD Rewards program as a key element in Binance's alleged effort to offer BUSD as a security, putting it in violation of Federal securities registration requirements. Like Coinbase's USDC Rewards program, BUSD Rewards offered payments to Binance customers who held BUSD-denominated balances at Binance. BUSD is a stablecoin that Binance offered in conjunction with Paxos.

Coinbase's lawyers seem to have anticipated this argument and have already prepared the legal groundwork to rebut it. The SEC sent a letter to Coinbase in 2021 that asked why USDC Rewards was not subject to SEC regulation. In its response, Coinbase had the following to say:

Now, I have no idea whether this is a good argument or not. Having observed securities law from afar over the last few years, I'm always a bit flummoxed by the degree of latitude it offers. It seems as if a good lawyer could convincingly argue why my Grandma's couch is a security, or that Microsoft shares aren't securities.

If you think about it more abstractly though, loyalty points and interest are kind of the same thing, no? In an economic sense, they're both a way to share a piece of the company's revenue pie with customers. Viewed in that light, why shouldn't a program like USDC Rewards inherit the same legal status as Starbucks Rewards or air miles?

If Coinbase's effort to shape its USDC payouts as rewards ends up surviving, others will no doubt copy it. Wise and PayPal might very well stop using a bank intermediary to offer interest-paying accounts, setting up their own loyalty programs instead. A whole new range of investment opportunities marketed as loyalty programs might pop up, all to avoid regulatory requirements.

But it's possible to imagine the opposite, too. In a column for Atlantic, Ganesh Sitaraman recently described airlines as "financial institutions that happen to fly planes on the side." If loyalty points and interest are really just different names for the same economic phenomena, then maybe airline points, Starbucks Rewards, and USDC Rewards should all be flushed out of the loyalty program bucket and into stricter regulatory frameworks befitting financial institutions.

Tuesday, September 12, 2023

There are now two types of PayPal dollars, and one is better than the other

PayPal now offers its customers two types of U.S. dollars. In addition to having the option of opening a traditional PayPal account to maintain a balance of dollars, PayPal customers can now hold something new called PayPal USD, a crypto version of a dollar. Whereas PayPal USD uses a crypto database, Ethereum, to host U.S. dollar balances (which in industry-speak is sometimes known as a stablecoin), the first sort of dollar relies on a conventional database.

There are currently around $45 million worth of PayPal USD in circulation, as the chart below illustrates:

Source: CoinMarketCap


Which type of PayPal dollar is safer for the public to use?

If you listen to Congresswoman Maxine Waters, who in response to PayPal's announcement fretted that PayPal's crypto-based dollars would not able to "guarantee consumer protections," you'd assume the traditional non-crypto version is the safer one. And I think that fits with most peoples' preconceptions of crypto.

Not so, oddly enough. It's the PayPal dollars hosted on crypto databases that are the safer of the two, if not along every dimension, at least in terms of the degree to which customers are protected by: 1) the quality of underlying assets; 2) their seniority (or ranking relative to other creditors); and 3) transparency.

Here is a bit of commentary on each factor:

The quality of underlying assets

PayPal's crypto dollars, which are managed by a third-party called Paxos, are 100% backed by the safest sorts of short-term collateral: U.S. Treasury-bills, reverse repo (backed by U.S. government securities), and commercial bank deposits. In finance lingo, these assets are known as cash and cash equivalents. A big reason for this conservative investment approach is that Paxos is subject to a set of strict investment limits as determined by its regulator, the New York State Department of Financial Services (NYDFS). You can read about the NYDFS's stablecoin regulatory framework here.

By contrast, PayPal's regular dollars, which are regulated piecemeal under each U.S. states' own peculiar version of a money transmitter license, can almost always be legally backed by riskier assets. (Here is PayPal's list of state-issued licenses.)

For instance, if you comb through the fine print at the back of PayPal's annual report, the total amount of customer funds held in the form of regular PayPal dollars comes out to $36 billion at year-end 2022. Of this $36 billion, PayPal has invested $11 billion in "cash & cash equivalents." Put differently, just 30% of its dollars are backed by top notch assets, far less than the 100% ratio for PayPal's crypto dollars. PayPal invests another $17 billion of its customer's billions in something called available-for-sale debt securities which, if you dig further, is made up of stuff like government bonds, commercial paper, corporate debt securities, and more. See the list below:

Source: PayPal 2022 annual report

These available-for-sale securities assets are not as reliable as cash and cash equivalents, particularly treasury bills. First, they have riskier issuers, as is the case with commercial paper and corporate debt, both of which are emitted by companies. Second, they are characterized by longer terms-to-maturity, as is the case with government bonds and corporate debt securities. Prices of long-term debt are much more volatile than short term debt. 

It would be illegal for PayPal to back its new crypto-based dollars with the assets listed above, yet for some reason it is fine if it backs its traditional dollars with them.

Customer's ranking relative to other creditors

The second drawback of PayPal's regular dollars is that the assets underlying them don't really "belong" to customers in any strong sense of the word. They belong to PayPal. 

More precisely, PayPal's terms of service has this to say: "...any balance in your Balance Account and any funds sent to you which have not yet been transferred to a linked bank account or debit card if you do not have a Balance Account, represent unsecured claims against PayPal..."). The bold is my emphasis.

To understand what this means, let's say that PayPal goes bankrupt. You, a long time PayPal customer, hold $1000 worth of PayPal dollars. You might think that you are guaranteed to be made whole because there exists a corresponding set of underlying customer assets that has been specially earmarked for you and other PayPal customers. But that's not the case. Customers are what is referred to in finance as an unsecured creditor of PayPal, which means you'd be relegated to having to fight with PayPal's other creditors (banks, bond holders, etc) to get a piece of the pie, and that's only after PayPal's secured creditors – those highest in the pecking order – get first dibs. That could potentially mean getting maybe $600 or $700 instead of your original $1000.

The reason for this, as explained here by Dan Awrey, is the fairly lax state-by-state regulatory frameworks under which PayPal's regular dollars are issued, which "often do not require that permissible investments be held in trust for the benefit of customers—thus potentially forcing customers to compete with an [money services business]’s other unsecured creditors in the event that it is forced into bankruptcy."

By contrast, the regulator of PayPal's crypto-based dollars, the NYDFS, specifies that the reserves backing any crypto-based dollar "shall be held at these depository institutions and custodians for the benefit of the holders of the stablecoin, with appropriate titling of accounts." To translate, the assets underlying your $1000 in PayPal USD cryptodollars are not PayPal's assets. Nor are they Paxos's. They are yours. No need to squabble with competing vultures for what's left.

But oddly, PayPal is under no legal obligation to extend these very sensible protections to all of its regular PayPal dollars.  

Degree of transparency

The last big difference between the two types of PayPal dollars is that the crypto version offers far more transparency to customers. If you want to get current information about the assets underlying your crypto PayPal dollars, all you need to do is open up one of PayPal USD's soon-to-be published attestation reports. Published monthly, these reports must include market values of the assets backing PayPal USD's, both in total and broken down by asset class. These values must be recorded on two separate days each month, or 24 times per year. Furthermore, these attestation reports must be prepared by an independent auditor.

By contrast, the only way to get vetted financial information about the assets backing traditional PayPal dollars is to read its audited financial statements, which come out just once a year. For the rest of the twelve months, customers are left in the dark.

So where am I going with all of this?

This illustrates the absurdity of some of the rules we've created surrounding monetary instruments. The fact that one type of PayPal dollar has robust protections while the other is only haphazardly protected, and only because the first is managed with a crypto database and not a traditional database, seems incredibly arbitrary to me. 

Financial regulations exist, in part, to protect retail customers against shoddy financial providers. Shouldn't all PayPal customers, no matter what database technology they select, get to benefit from the same standard protections? What's the logic behind stipulating that one type of PayPal customer is to have the benefit of monthly attestation reports, for instance, while limiting the other type of customer to a black void of information? 

The problem here isn't just one of having a few bad standards. Doesn't having multiple standards add to people's confusion about how they are protected?

Just to make things even more absurd, there's actually a third type of PayPal dollar. It comes in the form of balances held in a PayPal Savings accounts. 

Unlike the two types of PayPal dollar described above, the third type is insured by the government up to $250,000. PayPal Savings dollars also pay interest, whereas the first two don't, or are prohibited from doing so. PayPal offers this product in conjunction with a bank, Synchrony Bank, which means this third type of PayPal dollar conforms to an entirely different set or rules than the other two: Federal banking law.

But this only reinforces what a Frankenstein of a monetary system we've created. Why are only PayPal Savings dollars protected by deposit insurance, whereas the other two types of PayPal dollars aren't? How does this cacophony of features (or lack of features) help retail customers who, amidst all their other duties in life, simply don't have time to peruse the fine print of each different dollar emitted into the economy?

Wednesday, July 5, 2023

The strange new world of multifunctional assets


I would never own it, but the cryptocurrency BNB is probably one of the strangest most interesting assets I've ever analyzed. No other asset (perhaps ever?) provides its owner with so much functionality. 

Is the sort of multi-functionality offered by assets like BNB a feature that all assets will have in the future? Is this the dawn of a multi-functional asset world? I'll explore this question at the end of this post.

BNB was issued by Binance, the beleaguered global crypto exchange, through an initial coin offering in 2017. It has around four, maybe five (?) different functions.

1. a medium of exchange


 BNB can be digitally transferred in a P2P fashion to other people. You can use it to buy stuff, send funds to friends or family, or move funds between crypto exchanges. It's like cash, except electronic (and volatile).

2. an investment security

BNB provides yield to its owner, sort of like a stock or bond. Most securities issuers pay securities owners an explicit return in the form of a stream of dividend payments or interest payments, generated out of the issuer's revenues. Rather than paying a return directly, Binance repurchases and cancels BNB using a portion of revenues.* It dubs this process burning, but it's functionally the same thing as paying a dividend.

3. loyalty points

Like the points issued by Starbucks, BNB can be used at the Binance.com exchange to get deals on trading fees and access to other Binance perks and services.

4. a ticket, or commodity

In addition to running a big crypto exchange, Binance controls a "decentralized" blockchain. The only way to use that blockchain is to have some BNB on hand to pay fees. No BNB, no play. So we can think of BNB as a ticket to get network access or, alternatively, a very select sort of commodity. That is, in the same way that the demand for pork bellies is driven by people's desire to consume bacon, the demand for BNB is driven by people's desire to consume the services available on Binance's blockchain.

So BNB is Swiss army-knife asset, with four functions packed into one instrument. There's probably more that I've missed.

The dawn of a multi-functional asset world?

Might this sort of multi-functionality, heretofore confined to the crypto ecosystem, become popular in the regular world? 

Let's imagine what Apple multi-functionality might look like. Apple shares wouldn't just be securities providing a yield. They could also be sent to friends and family as payment, or used to buy apples at the grocery store. They could also be used as loyalty points, say to get perks at the Apple store (i.e. priority in line to see a technician), and as a necessary commodity for accessing certain types of Apple product functionality.

Or, imagine if your Air Canada ticket also provided a flow of dividend payments, like Air Canada shares do. And say that ticket could also be used as a digital medium-of-exchange for buying stuff and/or remitting funds back home to family.

One thing that has historically prevented this sort of multi-functionality is that securities, media of exchange, coupons, loyalty points, and tickets have always existed on separate databases, each with its own set of rules,  none capable of communicating with the other. When you start out from scratch, however, with a single database, as was the case with blockchains, and thus a unified set of rules, then that opens the door to multi-functional assets.

But even if the technological problem is solved (as well as a legion of legal and regulatory issues), there's another key reason that multi-functionality may never become widely adopted. It may not offer end-users an ideal customer experience. The problem is that functions start to interfere with each other, the final result being that the total usefulness of the multi-functional asset is less than the total usefulness of the set of separate assets, each offering its functionality independently.

For instance, if loyalty points are imbued with features that turn them into securities, then they will become much more volatile. For folks who simply want to be able to reliably and consistently consume a given product, these fluctuations will be a turn-off.

Alternatively, if a bundle of features (like p2p transferability and loyalty benefits) are added to an existing security, this will probably increase its price, upsetting many asset managers who don't want those perks, but want to enjoy a stream of dividends at the cheapest price possible.

So even though new technologies may allow for multi-functional assets, a multi-functional world may never actually emerge because people naturally prefer that functions be split apart.


* More specifically, the revenue stream that funds repurchases, or "burns," of BNB comes from user fees levied on users of BSC Chain, Binance's "decentralized" blockchain. There's a formula that calculates how much fees get burned. Prior to this, revenues from Binance.com were used to fund repurchases and cancelleations of BNB.

Tuesday, June 6, 2023

When is a stablecoin a security? The strange case of Binance and BUSD


The SEC has been hinting for several years that stablecoins may be securities. I've always found the idea of regulating stablecoins as securities to be a bit odd. No one who buys a stablecoin expects to make a profit. That's because none of the big stablecoins (Tether, BUSD, or USD Coin) have ever paid interest. With no expectation of profit, stablecoins aren't like bonds or stocks or other investment contracts, and thus they shouldn't fall under SEC purview.

Never mind that PayPal, Wise, Payoneer and Cash App all create dollars in the same way as a stablecoin issuers do, and like stablecoins only pay 0% interest. Yet the SEC has never deemed a PayPal balance to be a security.

Anyways, over time we've been getting more clarity on the regulatory status of stablecoins. In February, the SEC issued a warning notice to stablecoin issuer Paxos that, in its view, one of Paxos's stablecoins, Binance USD, was an unregistered security. Notably, Paxos's other stablecoin, USDP, was not mentioned in the notice. Some types of stablecoins seem to be securities, others not.

A new lawsuit against Binance provides even more insight into what sorts of stablecoin activity the SEC deems to fall under securities law. Earlier this week, the SEC accused Binance of (among many other things) offering and selling Binance USD, or BUSD, as a security without bothering to register the offering. Paxos's USDP was not mentioned in the suit, nor was any other stablecoin. 

To clear up any confusion, BUSD is issued by Paxos but Binance puts its name on the label and markets the coin. It's a partnership.

One reading of the SEC's suit against Binance is that a stablecoin itself isn't a security. Rather, it is the particular way that BUSD's income is shared between Paxos and Binance, combined with the way that Binance offers BUSD to retail customers, that transforms this particular instance of a stablecoin into a security offering.

Here's a short explanation of how the whole BUSD sausage works. The main entry-way for the public into BUSD is via Binance's website. When retail customers buy BUSD on Binance, they submit fiat dollars. Next, the customers' funds are wired to Paxos, a New York-chartered limited trust, where they are pooled and invested in assets that yield interest. Paxos in turn sends BUSD back to Binance to be deposited into Binance-controlled addresses. These underlying BUSD tokens serve as stand-ins for customer U.S. dollar balances on Binance.

According to the SEC, some 90% of all BUSD was controlled by Binance. In a key bit of data, we also learnt that Paxos and Binance split the interest income 50/50.

Any investment of money in a common enterprise constitutes the first key steps towards an investment contract, and an investment contract falls under SEC jurisdiction. In its suit, the SEC is suggesting that when Binance customers bought BUSD, and their funds were pooled and invested by Paxos, the initial triggers for investment contract-status had been met.

However, for an asset to be an investment contract there also needs to be an expectation of profit. Recall that BUSD doesn't pay any interest to customers. A BUSD token is about as unfruitful as a U.S. dollar balance at PayPal or Wise, neither of which are securities.

Here's where the hook appears to have caught flesh. While BUSD tokens are themselves barren, BUSD tokens held on Binance do yield a profit. According to the SEC, Binance offered something called a BUSD Reward Program that "promised interest payments to BUSD investors merely for holding BUSD on the Ethereum blockchain."

The SEC then proceeds to connect Binance's ability to imbue BUSD with "profit potential" to the interest earned on the underlying pooled assets that it splits with Paxos.

And that's why this particular instance of a stablecoin may be a security. If Paxos were to directly pay interest to the public, then BUSD would obviously be a security, since that establishes an expectation of profit. What has happened instead is that streams of interest income are channeled through to the public by Paxos paying Binance and Binance rewarding end users. The SEC seems to be saying that this isn't an accepted workaround: two separate entities cannot cooperate and fabricate an interest return on stablecoins, and avoid having this entire contraption be deemed a security.  

Now, that's just my interpretation. I could be wrong. But assuming that I'm right, what does that mean if you are a stablecoin issuer and don't want to run afoul of securities law?

First, never pay direct interest to retail customers. That's why old-school money transmitters like PayPal, Wise, and Cash App don't directly offer interest on balances; and when their customers do get interest, it's either a bank or a money market fund that carries this business out on behalf of the money transmitter.

The particular lesson to be gleaned from the SEC's case against Binance seems to be that in addition to not paying interest to customers, stablecoin issuers should probably be wary of sharing interest income with partners. These partners may sluice the interest back to their own retail customer base, the whole amalgam thus synthesizing into an SEC-regulated security. That may explain why Paxos's BUSD is being targeted by the SEC as a security, whereas Paxos's USDP which never had a Binance yield-generating nexus isn't being targeted as a security... at least for now.

Tuesday, May 16, 2023

If Wise can pay interest, why can't USDC?

Wise, a fintech, is now offering its U.S. customers 4.13% interest as well as FDIC deposit insurance. Meanwhile, the native yield on USDC stablecoins is still at 0%. Nor is USDC insured.

If Wise can offer interest and insurance to customers, why can't Circle (the issuer of USDC) do the same?

Wise and Circle are alike in a legal sense. Neither is a bank. Both are licensed as money transmitters. So why can one money transmitter offer a valuable set of services, but the other seemingly can't?

To be more accurate, it's not Wise itself that is offering these services. Wise is neither a bank nor a money market fund, so I'm pretty sure it is legally prevented from paying interest. And since it's not a bank, it can't be a member of FDIC. Rather, it is Wise's own bank, JP Morgan Chase, that is offering these services to Wise customers. Wise simply passes on the interest along with the insurance coverage.

So if Wise is just a feeder for JP Morgan, connecting its customer base to the bank, why can't Circle perform the same feeder role with its own bank, BNY Mellon, and USDC users?

I suspect one factor preventing this is the pseudonymity of stablecoins. There are many users of USDC, but Circle has only collected ID from a small fraction of them. A big chunk of USDC's pseudonymous user base is comprised of financial machines, or smart contracts, for which the concept of identification is meaningless. As for individuals or businesses who hold USDC, they may not be willing to, or can't, pass through a traditional verification process. Banks, however, have very strict onboarding rules. They must collect the ID of every single customer.

In short, it's probably quite tricky for Circle to feed USDC's mostly pseudonymous user base into an underlying bank in order to garner interest and insurance, at least much harder than it is for Wise to feed its base of known users into a bank.

It's possible that some USDC users might be willing to give up their ID in order to receive the interest and protection from Circle's bank. But that would interfere with the usefulness of USDC. One reason why USDC is popular is because it can be plugged into various pseudonymous financial machines (like Uniswap or Curve). If a user chooses to collect interest from an underlying bank, that means giving up the ability to put their USDC into these machines.

This may represent a permanent stablecoin tradeoff. Users of stablecoins such as USDC can get either native interest or no-ID services from financial machines, but they can't get both no-ID services and interest.