> **Source:** https://permissionless.fi/en/01-digital-assets
> From *Permissionless Finance* (Permissionless Finance: From Perpetual Futures to the On-Chain Global Market) by Eric Cheung. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

# Chapter 1: The Distinctiveness of Digital Assets Compared with Traditional Assets

In January 2024, the U.S. Securities and Exchange Commission (SEC) approved the first spot Bitcoin exchange-traded funds (ETFs). Net inflows over the first full year (2024) reached approximately $35 billion; by the end of 2025, assets under management had climbed into the hundreds of billions of dollars, and 13F filings showed that institutional investors had become major holders [1]. The immediate catalyst was Grayscale's 2023 courtroom victory over the SEC: the court ruled that the SEC's rejection of Grayscale's application to convert its Bitcoin trust into an ETF lacked a reasonable basis, forcing the agency to approve the product under judicial pressure rather than through any genuine shift in its regulatory stance. The regulatory trajectory for digital assets thus remains deeply uncertain. The seventh annual global crypto hedge fund report, jointly published by AIMA and PwC, found that 55% of the hedge funds surveyed had added digital assets to their portfolios, nearly double the under-30% share of roughly two years earlier [2]. Together these figures mark the passage of digital assets from fringe experiment to the core of global institutional asset allocation. Yet in November 2022 the collapse of FTX erased more than $8 billion in customer assets [3]. Hundreds of billions of dollars in institutional inflows, set against the sudden evaporation of billions, define the tension of the present moment: institutional allocation has reached systemic scale, yet the safety infrastructure has not matured to match it. That tension frames the chapter's central question. Is the difference between digital assets and traditional assets merely a set of technical features to be enumerated, or is it a more fundamental reorganization of the trust paradigm?

Answering it requires first understanding, in precise terms, the institutional logic of traditional finance. This chapter opens with the full journey of an ordinary stock trade, following the sequential involvement of at least nine independent institutions, a settlement cycle longer than 24 hours, and successive layers of capital lockup. From that journey it distills the five-layer functional architecture of trust in traditional finance: asset custody, trade execution, clearing and settlement, data verification, and rule governance. Each layer has suffered a defining failure, and each failure has prompted a new round of institutional repair. The institutional costs abstracted from the journey and its failures, namely settlement delay, compliance overhead, entry barriers, information asymmetry, and cross-border friction, appear unrelated but share a single root. In the absence of technological trust, society must build trust through institutions; because those institutions are costly, their cost passes systematically to market participants. This chapter unifies these dispersed costs under a single analytical concept, the trust tax, and uses it to show, dimension by dimension, how the six distinctive properties of digital assets (permissionlessness, atomic divisibility, embedded settlement finality, around-the-clock continuous trading, smart-contract execution, and on-chain transparency) compress that systemic cost from different directions.

Once these properties are examined individually, a deeper structural feature emerges: they interact multiplicatively. Financial primitives impossible in traditional finance, such as flash loans, maximal extractable value (MEV), and protocol-level arbitrage, all emerge from several properties acting at once. Composability is at once a channel for innovation and a channel for contagion. On-chain transparency, even as it removes old information barriers, creates a new asymmetry rooted in the capacity to process information, so that fairness itself must be redefined. More fundamentally, this transformation changes not only how markets operate but the statistical character of risk itself. Traditional finance faces a risk surface of low-frequency but systemic shocks; digital assets face one of high-frequency shocks of highly variable magnitude, and the two demand fundamentally different approaches to risk management. Finally, the layered blending of three trust paradigms (institutional trust, platform trust, and architectural trust) offers a framework for choosing rationally between the two systems, one that moves beyond a simple binary.

These analytical tools form the starting point for the chapters that follow. The market for digital assets is not a simple narrative of decentralization replacing centralization; it is the largest natural experiment in financial history, using trillions of dollars of real capital to test, in real time, which elements of two centuries of financial institutions are essential, which can be replaced by technology, and which will reveal their indispensability only in the next crisis.

## 1.1 The trust architecture of traditional finance

The depth of the digital-asset transformation can be measured only against a full grasp of the institutional logic of traditional finance. This section therefore follows a single trade from start to finish, through the hands of at least nine independent institutions, and abstracts from that journey the five layers of trust on which traditional finance rests. It then unifies the institutional costs these functions generate under the analytical concept of the trust tax and argues that those costs, though high, buy real services.

### 1.1.1 The complete journey of a trade

The complexity of the traditional financial system is not the product of redundant design; it is the institutional response, evolved over two centuries, to a fundamental problem: how to transfer value safely among strangers who do not trust one another. This apparatus is best understood not from an abstract architecture diagram but by tracing a single trade from order submission to asset delivery, identifying at each step why a given institutional node exists and what it costs.

Alice decides to buy 100 shares of Microsoft stock. Through her broker's trading software she enters a limit buy order: 100 shares of MSFT at $450 or below. Behind this action, the broker, the first layer of intermediation between investor and market in traditional finance, performs three functions. Account management requires Alice to complete identity verification and anti-money-laundering (AML) screening when she opens the account; this is the first threshold of market access, ensuring that a participant's identity is traceable and accountable within the legal framework. Risk management and credit provision allow Alice to trade on leverage in a margin account, for which the broker monitors her margin ratio in real time and retains the right to liquidate her positions when risk exceeds limits. Smart order routing searches across more than 10 public exchanges and dozens of alternative trading systems for the best execution price. The SEC's Regulation NMS requires brokers to meet a best-execution obligation for their clients, one of the regulator's core requirements [4].

Between Alice and the market, the traditional financial system forms a clear pyramid. At the top are regulators, such as the SEC, the CFTC, and national central banks, which set rules, conduct oversight, and define the operating boundaries of the entire market. In the middle are infrastructure institutions, such as exchanges, central counterparties, and central securities depositories, which perform the core functions of price discovery, risk management, and asset delivery. At the bottom are client-facing intermediaries, such as brokers, market makers, and custodian banks, the channels through which investors reach the market. Trust flows from top to bottom: the broker at the bottom is trustworthy because the exchanges and clearing institutions above bind it to their rules, and those middle-tier institutions carry authority because the regulators at the top vouch for them. This hierarchical dependency means that a failure at any layer can unsettle the trust foundation of every layer above and below it. Yet the hierarchy also provides firewall isolation: each layer's institutional design can arrest contagion independently. The central counterparty (CCP) default waterfall, for instance, is itself an institutional firewall at Layer 3, designed precisely to contain an individual member's default losses within that layer. This firewall stands in sharp contrast to the flattened contagion paths of on-chain composability, which Section 1.3.3 examines.

Alice's limit buy order is routed to the Nasdaq exchange, where it enters the central limit order book. Harris (2003) [4] notes that the central limit order book is the core mechanism through which modern securities markets achieve effective price discovery, whereas on-chain order books face different constraints in latency and front-running risk, a subject taken up in later chapters. All unfilled limit orders are ranked by price priority and then time priority: higher-priced buy orders and lower-priced sell orders take precedence, and orders at the same price are ranked by arrival time. When a new market order arrives, it fills against the best available counterparty price and works down the book. This process is anonymous, automatic, and completed within microseconds. Through it the exchange aggregates countless dispersed, anonymous trading intentions into a public, continuous, and widely accepted transaction price, which is the essence of price discovery. On the book sits a limit sell order placed by a trader, Bob: 200 shares of MSFT at $450. Alice's 100-share buy order matches Bob's sell order, and the matching engine executes the trade within microseconds. Alice's 100 shares are filled at $450, and the remaining 100 shares of Bob's order stay on the book. The exchange sends trade confirmations to both brokers.

Yet making a trade is not the same as completing it. At this moment the two parties have merely reached a legally binding contract, a promise to exchange assets and funds at some future point; no transfer of the assets or funds themselves has yet occurred. From here the trade enters the more complex phase of post-trade processing. The gap between execution and asset delivery is the very source of all the institutional complexity of traditional finance: it creates a window of counterparty-risk exposure, and the entire post-trade apparatus exists to manage the defaults, errors, and systemic risks that may arise within that window.

The post-trade phase brings in the single most important institutional innovation of traditional finance: the central counterparty. In the U.S. equity market, post-trade processing follows a T+1 settlement cycle, and before May 2024 it ran as long as T+2. The National Securities Clearing Corporation (NSCC), a subsidiary of DTCC, interposes itself in every trade through a legal process known as novation, becoming the seller to every buyer and the buyer to every seller. This novation is completed during a batch process on the evening of the trade date; until then, the two parties still bear the credit risk of their original counterparties. The original contract between Alice and Bob is replaced by two independent contracts, Alice with the NSCC and the NSCC with Bob, so that neither party owes a delivery obligation directly to the other. As long as the NSCC does not default, the trade's final completion carries an institutional guarantee. This arrangement lets market participants trade with anonymous counterparties in confidence, and it deepens market liquidity substantially. To manage the concentrated risk it assumes, the NSCC builds a multi-layered defense, the loss-sharing waterfall, whose layer-by-layer absorption sequence is detailed in Figure 1-1 of Section 1.1.2. Through strict membership admission, initial and variation margin posted against unsettled positions, and a default fund contributed jointly by all clearing members, it ensures that the clearing system keeps operating even if a member defaults. At the same time, the NSCC performs multilateral netting across the thousands of trades in a single day, offsetting a given clearing member's buys and sells in the same asset to compute a final net position. This reduces the volume that actually requires settlement by an order of magnitude and markedly lowers operating costs and liquidity needs.

Final asset delivery is carried out by the central securities depository, the DTC, also a DTCC subsidiary. The DTC is the centralized ledger that holds and records ownership of U.S. securities. Settlement is completed through delivery versus payment (DVP): the delivery of securities and the payment of funds are mutually conditional and occur simultaneously, eliminating principal risk, a principle realized more completely on-chain in the form of atomic settlement. Only after the final book-entry update on T+1 are 100 shares of MSFT formally credited to Alice's securities account, and only then does Bob receive the corresponding funds.

A seemingly simple purchase of 100 shares involves, in the back office, the sequential participation of at least nine independent institutions (broker, exchange, matching engine, clearing corporation, central counterparty, depository, payment system, regulator, and various data-service providers); it takes more than 24 hours, freezes substantial capital during settlement, and generates friction at every step. According to the post-transition assessment jointly published by SIFMA, ICI, and DTCC, the NSCC clearing fund fell by an average of about $3 billion after the move to T+1, a decline of 23% [5]. Even under a T+1 cycle, then, settlement delay still levies a considerable cost in time. The internal logic of traditional finance becomes clear here: settlement delay buys the time that risk management requires, and centralized institutions supply the credit guarantees that make anonymous trading possible. These intermediation steps, compliance reviews, and waiting periods constitute the institutional cost society pays to keep trading safe in the absence of technological trust.

### 1.1.2 The five layers of trust

Alice's trading journey yields the five-layer functional architecture of trust in traditional finance. These layers are not the product of a single design; they are the accumulated sediment of two centuries of repeated failure, repair, further failure, and further repair. Each layer carries a core promise, and each has dedicated institutions to secure it. The primary lens for understanding these layers is not their flaws but the real protection they afford participants, protection that makes possible the worldwide allocation of hundreds of trillions of dollars.

The asset-custody layer ensures that client assets are strictly segregated from the intermediary's own assets. In the United States, SIPC insures each brokerage account up to $500,000 (of which $250,000 covers cash), and the FDIC insures bank deposits up to $250,000. These institutionalized safety nets allow ordinary savers and investors to participate in the market with confidence, without needing to understand the workings of the financial system. Alice need not assess her broker's solvency; the institution has made that judgment for her. The trade-execution layer ensures that orders are handled fairly, through independent exchanges and the best-execution obligation. The SEC's Regulation NMS requires brokers to seek the best price for clients across multiple venues rather than routing orders to whichever venue most benefits the broker itself [4]. At the clearing-and-settlement layer, the CCP mechanism expresses the protective power of traditional institutional design in its most concentrated form. Figure 1-1 presents the multi-layered defensive structure of the CCP loss-sharing waterfall: losses are absorbed starting with the defaulter's own resources and progressing to industry-wide mutualization, on the core principle that whoever creates the risk bears the loss first.

![Figure 1-1](./images/fig-1-1-en.png)

**Figure 1-1.** The CCP loss-sharing waterfall: when a clearing member defaults, losses are absorbed layer by layer in a preset order, extending from the first line of defense (the defaulter's own resources) to the second (industry mutualization), protecting the entire financial system's continued operation (the tiers indicate the sequence of loss absorption, and their widths do not represent proportional amounts; the default-management auction is a disposal step preceding the financial waterfall, and the tail includes assessment rights and recovery tools)

Most major CCPs contribute a portion of their own capital to the default waterfall, positioned ahead of the default fund contributions of non-defaulting members (the exact proportion and arrangement vary by institution and jurisdiction). This skin in the game ensures that the CCP has ample economic incentive to manage risk prudently. The waterfall defense withstood an extreme test in the 2008 financial crisis: when Lehman Brothers failed, tens of thousands of unsettled derivatives contracts were involved, yet the CCP system ultimately completed all clearing, and not a single CCP itself defaulted [6]. The data-verification layer ensures the authenticity of market prices through independent audits and regulated data vendors, providing trustworthy inputs for asset pricing and risk management. The rule-governance layer ensures the legitimacy and predictability of rule changes through the legislative process and the judicial system, giving market participants a stable set of expectations; a complete system of legal remedies, from arbitration to litigation to class action, offers investors a clear path of recourse.

The cumulative effect of these five layers of protection is a kind of trust free of understanding, the institutionalized expression of what Luhmann (1979) [7] defined as system trust. Most people need not understand the CCP default waterfall to entrust their savings to the stock market with confidence; this default trust is precious social capital accumulated over two centuries of institutional track record. But system trust exhibits a threshold effect: it accumulates gradually and is lost suddenly. Each layer of protection, however, has also suffered a defining failure that revealed the boundary of institutional safeguards. Table 1-1 sets out the five trust functions layer by layer, listing for each its core promise, the specific institutional arrangements that deliver it, and its most consequential historical failure. From the $1.6 billion scandal of MF Global's misappropriation of client funds at Layer 1 (asset custody) to the LIBOR manipulation affecting the pricing of $350 trillion in financial products at Layer 4 (data verification), each failure precisely exposed the boundary of the corresponding layer's safeguard.

| Layer | Trust function | Core promise | Institutional implementation | Defining failure |
| :--- | :--- | :--- | :--- | :--- |
| Layer 1 | Asset custody | Assets will not be misappropriated | CSD/DTC; SIPC insurance ($500,000 per account); FDIC deposit insurance ($250,000) | MF Global (2011): the futures broker behind the eighth-largest bankruptcy in U.S. history misappropriated $1.6 billion of segregated client funds to speculate on European sovereign debt [8] |
| Layer 2 | Trade execution | Orders are executed fairly | Independent exchanges; best-execution obligation; market-surveillance systems | Dark pool scandals (2014–2016): dark pools operated by major banks such as Barclays systematically allowed high-frequency trading firms to front-run client orders; the SEC imposed $70 million in penalties [9] |
| Layer 3 | Clearing and settlement | Trades will be delivered | CCP default waterfall; multilateral netting | Lehman Brothers (2008): the bankruptcy of the world's fourth-largest investment bank required the emergency handling of tens of thousands of unsettled OTC derivatives contracts, exposing the fatal weakness of OTC derivatives that lacked central clearing [6] |
| Layer 4 | Data verification | Prices and data are authentic | Regulated data vendors; independent audits; benchmark-rate administrators | LIBOR manipulation (2012): the world's most widely referenced benchmark rate was systematically manipulated by more than 10 banks for years, affecting the pricing of over $350 trillion in financial products, with cumulative fines exceeding $9 billion [10] |
| Layer 5 | Rule governance | Rule changes are lawful and transparent | SEC/CFTC; legislative process; judicial system | Post-2008: the financial crisis exposed systemic failures of the regulatory apparatus (the SEC failed to detect Madoff's 17-year Ponzi scheme), prompting the sweeping institutional repair of the Dodd-Frank Act [6] |

**Table 1-1.** The five-layer trust functions of traditional finance and their defining failures (Data source: public records of the respective regulators [8][9][6][10]. Case-selection criterion: each layer's case is a landmark event with a completed regulatory investigation and an impact large enough to drive institutional reform)

These failures should not be read simply as institutional incompetence. On the contrary, each prompted stricter institutional repair, and the system's capacity for self-correction is itself part of institutional trust. After MF Global, the CFTC strengthened the requirements for segregating client funds; after the LIBOR scandal, benchmark-rate setting shifted from banks' self-reported quotes to calculation from real transaction data; after the 2008 crisis, the Dodd-Frank Act brought previously unregulated OTC derivatives into central clearing and raised CCPs' capital and risk-control standards across the board. This cycle of failure, repair, further failure, and further repair yields three conclusions: trust is an institutional product that must be produced continuously rather than a natural endowment; the cost of failure is real and quantifiable; and these five functions give the later analysis a precise target as digital assets attempt to replace institutions with technology. Architectural trust must prove that it delivers at least an equivalent level of protection at each layer, or honestly acknowledge which layers it cannot yet replace. This five-layer structure is developed further in the verifiability ladder of Chapter 5 and the trust-stack design of Chapter 28.

### 1.1.3 The trust tax: a unified view of institutional cost

Alice's journey and the five layers of trust distill into a single unifying concept: the trust tax, the systemic cost society pays to maintain orderly trading in the absence of technological trust. The concept overlaps with, but is sharply distinct from, the transaction-cost economics of Williamson (1985) [11]. Williamson attributes transaction costs to two behavioral assumptions, bounded rationality and opportunism, and they span a broad range of costs such as search, bargaining, and monitoring. The trust tax is a specific subset of transaction costs: it concerns only the institutional costs that arise because the parties to a trade cannot establish trust at the technological level. Search and bargaining costs are not part of the trust tax, because they persist even under complete trust. The analytical value of this distinction is that it identifies precisely which costs digital assets can compress: architectural trust can replace part of what institutional trust does, but it cannot eliminate trust-independent frictions such as search and bargaining costs. The many seemingly unrelated trust costs of the traditional financial system all trace to the same root, and they are levied across six dimensions.

> The trust tax: the institutional cost society bears because it cannot establish trust at the technological level, the specific subset of transaction costs that architectural trust can compress.

These six dimensions are not an arbitrary list; they are extracted systematically from Alice's trading journey in Section 1.1.1, each corresponding to a class of observable institutional friction. Liquidity fragmentation (the splitting of liquidity across exchanges) and standardization costs (incompatible protocols across markets) are also real market frictions, but their root cause is coordination rather than an absence of trust, and they are therefore excluded from the trust-tax framework.

The settlement-delay tax manifests as the capital lockup and counterparty-risk window created by the T+1 settlement cycle. Alice's funds are locked from T to T+1, unavailable for other trades, with counterparty-risk exposure exceeding 24 hours. As noted in Section 1.1.1, even though T+1 reduced the clearing fund by about $3 billion [5], the delay tax itself remains considerable. Figure 1-2 presents the historical evolution of the U.S. securities settlement cycle from T+5 to T+1 over more than three decades, each shortening demanding an industry coordination cycle on the order of a decade.

![Figure 1-2](./images/fig-1-2-en.png)

**Figure 1-2.** The historical evolution of the U.S. securities settlement cycle (Data source: SEC Rule 15c6-1, SEC Release 34-80295, SEC Release 34-96930 [5]; as of June 2026, T+1 remains the settlement cycle in force)

Each shortening released frozen capital, but the path itself reveals how entrenched settlement delay is: even when the technology had long permitted faster settlement, institutional inertia and coordination costs still held reform to a roughly decade-long cadence.

The trading-hours-fragmentation tax arises because restricted trading hours prevent information from being priced continuously. The New York Stock Exchange's regular session runs from 9:30 to 16:00 Eastern time, and the London Stock Exchange's from 8:00 to 16:30 Greenwich Mean Time; both close on weekends and public holidays. The U.S. stock market has roughly 252 trading days a year, meaning that on about 31% of days it does not trade at all. Information accumulates continuously while the market is closed but cannot be reflected in prices until it reopens, producing opening gaps and weekend risk exposure. If Alice holds positions in both New York and London, she also faces hedging difficulties created by the incomplete overlap of the two sessions.

The intermediary tax comes from the operating costs of brokers, clearinghouses, custodian banks, and similar institutions, costs ultimately borne by investors. Alice's trade passes through at least nine intermediaries, each with operating costs, compliance costs, and profit objectives. According to industry data cited by DTCC in advancing the T+1 reform, clearing and settlement is the main component of post-trade operating expenditure in traditional finance, accounting for roughly 20% to 25% [5]. The entry tax manifests as the licenses, capital requirements, and compliance thresholds that exclude the vast majority of potential participants. Alice must pass identity verification and AML screening before she can open an account; a market maker needs millions of dollars in capital and a months-long approval process; and the threshold for CCP clearing membership is higher still. Each entry barrier narrows the pool of participants and limits competition.

The opacity tax arises from the information asymmetry that barriers to data access open up between institutions and retail investors. Professional-grade market-data terminals cost tens of thousands to hundreds of thousands of dollars a year [12], and Alice cannot obtain market data of the quality available to institutional investors. The LIBOR scandal [10] further demonstrated that even with institutional safeguards, key market data can still be manipulated through collusion among a handful of insiders; the question of who watches the watchers has never been fully resolved in traditional finance. The jurisdictional tax comes from the legal, time-zone, and currency frictions of cross-border transactions. According to World Bank data, the average cost of a global cross-border remittance is about 6.35% of the amount sent (based on a $200 remittance benchmark, first-quarter 2024 data; 6.4% in the fourth quarter of 2023) and takes three to five business days [13]. This figure reflects the cost structure of small retail remittances; institutional cross-border transfers are completed through the SWIFT/CLS system, and the percentage cost of large transfers is markedly lower. The trust tax is levied in structurally different proportions across participant tiers. If Alice wants to buy shares listed in London, she faces time-zone differences, exchange-rate risk, and multiple regulatory-compliance requirements all at once.

The analytical value of the trust-tax concept is that it unifies dispersed institutional costs into a single causal account: every cost traces to the same root. Parties cannot trust one another at the technological level, so institutions must supply that trust; and because institutions are costly, the cost is passed on. The five-layer function defines what trust must do; the trust tax measures what it costs. This framework gives precise coordinates for the analysis that follows: each of the six distinctive properties will be shown to compress some dimension of the trust tax, and the value of any financial innovation can be measured by how much trust tax it compresses against how much new cost it introduces.

### 1.1.4 The rationale for the trust tax

The trust tax is not useless institutional redundancy; it corresponds to four classes of real service. Systemic stability is the first. In the 2008 financial crisis, the CCP default waterfall proved to be the key institutional safeguard for the continued operation of the global financial system: as noted in Section 1.1.2, not a single CCP itself defaulted in the Lehman crisis [6]. The cost of this stability (the margin system, default funds, operating costs) is precisely the trust tax. Investor protection is the second: the institutionalized SIPC/FDIC safety net described in Section 1.1.2 lets the vast majority of people participate in the market with confidence, without understanding how the financial system works, and in doing so mobilizes trillions in capital. FTX's loss of more than $8 billion in customer assets [3] shows exactly what the absence of such protection costs. The FTX disaster was in essence a failure of the platform-trust model, not a defect of on-chain architectural trust: a centralized platform reproduced, in a new form, the misappropriation risk of traditional intermediaries, a distinction systematized in Section 1.4.3. Legal recourse is the third service. When a trading dispute arises, traditional finance provides a complete system of legal remedies from arbitration to litigation to class action, and investors have clear legal standing and a path of recourse. In on-chain finance, once assets are transferred through a code vulnerability or an attack, there is almost no legal mechanism for recovery; irreversibility is both a feature and a cost. The cumulative effect of institutional reputation is the fourth service. Two centuries of track record have created a default trust, the trust free of understanding discussed in Section 1.1.2. Although the DYOR culture of on-chain finance is healthier in principle, in practice it places the entire burden of risk management on each user. Behavioral-finance research shows that, faced with information overload, individual investors typically do not conduct genuinely independent research but rely on social proof and narrative shortcuts, which in crypto communities take the form of following KOLs, imitating smart-money addresses, and FOMO-driven decisions. The gap between the principle and the practice of DYOR is systemic, and self-directed diligence is unrealistic for most ordinary people.

The right question, then, is not how to abolish the trust tax but whether its current level far exceeds the value of the services it provides, and whether technology can deliver an equivalent level of service more efficiently. The existing evidence suggests that it can, but with one important qualification. Some dimensions of the trust tax can be compressed completely by technology: atomic settlement eliminates the T+1 delay, and on-chain transparency removes information barriers. Others can currently be compressed only in part; here the governance layer's trust tax stands out. The question of who has the right to modify the code is one the code itself cannot answer, and discretion in extreme cases may still require human judgment. At the governance layer, this projects the power and limits of *code as law* that Lessig (2000) [14] described (elaborated in Section 1.2.5). Whether the trust tax has an incompressible floor, whether some trust functions cannot in principle be replaced by code, is a question that runs through the entire book and is examined formally in the final chapter. Acknowledging the value of the trust tax while arguing that it can be compressed is the analytical stance that raises the book's framework above the one-dimensional narrative in which traditional finance is inefficient and digital assets are omnipotent.

## 1.2 The six distinctive properties and the compression of the trust tax

The six distinctive properties of digital assets are not a flat inventory of technical features; each property is a direct response to one dimension of the trust tax. This section adopts a single analytical framework throughout: the target of the trust tax, the technical response of digital assets, and the cost and limits of that response.

### 1.2.1 Permissionlessness: compressing the entry tax

The entry tax is the most perceptible dimension of the trust-tax system in traditional finance. From identity verification and anti-money-laundering screening for individual investors, to the capital and technical requirements imposed on market makers, to the top-tier banking credentials required of the clearing members of a central counterparty, traditional finance is essentially a system of nested permissions in which each layer narrows the range of participants. Across the five layers of trust, the entry threshold at each layer is a direct expression of the entry tax.

Public blockchains fundamentally restructure this logic. Access rules are defined by code rather than administrative approval, and anyone who complies with the protocol's rules can participate. On Uniswap, for example, any user can interact directly with the smart contract to trade tokens, or become a de facto market maker by providing liquidity, without approval from any institution. The marginal cost of deploying a smart contract is minimal and the exit cost is zero; trust derives not from institutional endorsement but from the open-source nature of the code and the mathematical determinism of the protocol. Users retain full control of their assets by holding their private keys—a fundamental departure from the identity-based, permissioned system of traditional finance. Baumol's (1982) [15] theory of contestable markets provides an economic framework for understanding this shift: the persistent threat of potential competition forces incumbents to hold prices near marginal cost, systematically compressing the scope for rent-seeking. On-chain activity is not entirely free of sunk costs—gas fees, impermanent loss, and smart-contract deployment costs all constitute de facto entry barriers—but these costs are several orders of magnitude lower than the millions of dollars in capital and months-long approval cycles required to become a market maker in traditional finance. Market-making thus shifts from the privilege of a few institutions to open competition in which anyone can participate, and thousands of retail participants pool idle assets into liquidity pools whose total value locked reaches tens of billions of dollars. In execution quality (slippage and the capacity to absorb large orders) and dynamic price adjustment, however, automated market makers (AMMs) still lag well behind professional market makers, and liquidity providers bear the risk of impermanent loss. Even so, this permissionless model of liquidity provision has no precedent in traditional finance. On order-book decentralized exchanges (DEXs) such as Hyperliquid, permissionlessness likewise means that anyone can submit orders, yet effective market-making still requires sophisticated pricing algorithms and low-latency infrastructure; a lower entry threshold does not eliminate competitive advantage. This order-book model more accurately reflects the market structure that is the central subject of this book.

Permissionlessness compresses not only the entry tax but also the jurisdictional tax, in three directions at once. By removing geographic entry barriers, protocols on public blockchains treat users worldwide identically, without cross-border account opening or multiple layers of regulatory approval. Around-the-clock trading eliminates time-zone fragmentation. Atomic settlement eliminates cross-border settlement delay. A traditional cross-border remittance takes 3 to 5 business days and costs about 6.35% of the amount remitted (for the basis of this figure, see Section 1.1.3) [13], whereas an on-chain transfer completes in seconds to minutes and typically costs less than $1 on Layer 2 networks or low-gas-fee chains, though on Ethereum mainnet the cost can reach tens of dollars during periods of congestion. Together, these three shifts systematically compress the jurisdictional tax, moving financial services from the constraints of geographic jurisdiction toward global uniformity at the protocol level.

Permissionless access also lowers the cost of malicious behavior. It sits, at the same time, in growing tension with legal compliance obligations: the Financial Action Task Force (FATF) Travel Rule [16] and the European Union's Markets in Crypto-Assets (MiCA) regulation are beginning to constrain technical permissionlessness from the legal side, and technical accessibility is not the same as legal accessibility. A lower entry threshold also lowers the cost of fraud: according to CertiK, crypto-asset losses from security incidents totaled approximately $3.35 billion over the course of 2025 [17]. Permissionlessness has also given rise to new strategic behaviors such as MEV bots and sandwich attacks, which preserve price efficiency while introducing new fairness problems. The net social benefit of permissionlessness depends on the maturity of the accompanying safeguards—disclosure regimes, reputation systems, and investor-protection tools.

### 1.2.2 Atomic divisibility: compressing the granularity barrier

Beyond licensing and compliance barriers, the entry tax also operates along an easily overlooked dimension, granularity—the institutional constraint on an asset's minimum tradable unit. When a single Class A share of Berkshire Hathaway trades above $600,000, the minimum investment unit is itself an entry barrier that excludes the vast majority of investors. The divisibility of traditional assets is tightly constrained by physical, legal, and institutional factors: a stock split requires a complex corporate action, trading distinguishes between round lots and odd lots, and price movements are limited by a minimum tick of $0.01 [4].

Digital assets remove these constraints at the protocol level. A single bitcoin can be divided into 100 million satoshis, and ether is divisible into as many as $10^{18}$ base units. On chain, transferring 0.000001 BTC is no different at the protocol level from transferring 1,000 BTC. In microstructural terms, this atomic divisibility means that prices can be distributed across a nearly continuous spectrum, giving the order book a price granularity far finer than that of traditional markets and thereby, in principle, improving the precision of price discovery. Combined with low transaction costs, atomic divisibility makes micropayments economically viable and provides the technical foundation for entirely new business models such as streaming payments and per-second billing. Together with the trend toward asset tokenization, atomic divisibility becomes the technical precondition for any asset to be split into arbitrarily small fractions and circulated worldwide—whether a tokenized U.S. Treasury fund or the tokenized real estate that may emerge in the future [18].

This property is not without cost. Excessively fine price granularity increases the complexity of the order book: when prices can be specified to 18 decimal places, liquidity is dispersed across an enormous number of price levels, the order book becomes *wide and shallow*, and effective liquidity may actually decline. Divisibility precision at the asset level must, however, be distinguished from the tick-size setting at the trading level. On real on-chain order-book DEXs, the tick size is set explicitly by protocol parameters—for a BTC/USD perpetual futures contract, for instance, the tick size is typically $0.1 to $1—far coarser than the smallest divisible unit of the underlying token; the risk of a wide, shallow book therefore arises more from the continuous price curve of AMMs than from the order book. This is also one of the sound reasons traditional markets impose a minimum tick. Price precision exhibits diminishing marginal returns: once precision exceeds a trader's decision resolution, additional precision no longer creates economic value. An extremely low minimum investment threshold democratizes access, but it may also attract risk-unaware small investors who bear disproportionate losses in highly volatile markets.

### 1.2.3 Settlement finality: compressing the time tax

The time tax is one of the costliest dimensions of the trust-tax system. Alice's funds are locked between day T and day T+1, and this time gap has given rise to an entire institutional apparatus—central counterparties, margin systems, and loss-sharing waterfalls. Layer 3 of the five layers of trust is precisely the institutional response to this time gap.

Digital assets compress trade and settlement cryptographically into a single atomic operation: to trade is to settle. Once a transaction receives a sufficient number of network confirmations, the probability that it will be reversed falls exponentially with each additional confirmation. Different consensus mechanisms provide different types of finality guarantee. Bitcoin provides probabilistic finality; industry convention treats a transaction as effectively irreversible after 6 block confirmations (about 1 hour). Ethereum proof-of-stake (PoS) reaches economic finality—backed by validators' economic stake—after approximately 12.8 minutes. Purpose-built application chains typically reach finality on subsecond-to-second timescales. Whatever the type, this finality is secured by the computational resources or economic stake that the network commits, not by the promise of any centralized institution. In its 2025 annual report, the Bank for International Settlements (BIS) emphasizes that atomic settlement is a core feature of the next generation of monetary and financial systems: it allows assets to be exchanged simultaneously and thereby, in principle, eliminates principal risk [19]. Capital efficiency improves fundamentally as a result: market makers can recycle inventory more quickly, and operational friction across the financial system falls markedly. Atomic settlement, however, comes at a cost: while it eliminates the net-settlement time window, it also means that every transaction requires full, immediate funding, correspondingly raising the system's demand for instantaneous liquidity. Whether an equivalent batch-settlement mechanism (such as frequent batch auctions) exists on chain is an open design question.

Atomic settlement eliminates the settlement cascade—the chain of defaults triggered when one party fails to deliver on time, of which the domino effect set off by the collapse of Lehman Brothers is the classic case—but it cannot eliminate the liquidation cascade: the positive-feedback loop in which falling prices trigger forced liquidations, selling pressure, further declines, and still more liquidations. Atomic settlement not only fails to halt the liquidation cascade; by executing efficiently it may even accelerate the cascade's spread, compressing a liquidation process that takes days to weeks in traditional finance into minutes to hours. The factors that accelerate a liquidation cascade include the maintenance-margin ratio, the smoothing of the mark price, and the size of the insurance fund; Chapter 11 analyzes these design choices systematically, in its treatment of the endogenous reflexivity of leverage and liquidation. The focus of risk thus shifts from whether the counterparty will perform to three new dimensions: whether the protocol code is correct, whether there is sufficient liquidity amid extreme volatility, and whether external data inputs are reliable. In perpetual futures, the mark price depends on oracle price feeds, and an oracle failure or manipulation can directly trigger an erroneous liquidation—neither a code vulnerability nor a liquidity problem, but a reliability risk in external data. This is the substitution of risk, not its elimination.

> The settlement cascade and the liquidation cascade are two fundamentally different mechanisms of risk transmission. Atomic settlement eliminates the former but may accelerate the latter—which explains why on-chain finance, having eliminated counterparty risk, still experiences violent shocks.

### 1.2.4 Around-the-clock trading: compressing temporal fragmentation

The fragmentation of trading hours makes it impossible to price information continuously. The regular trading session of the New York Stock Exchange covers only 6.5 hours of each business day, and information that arises during the remaining hours cannot be reflected in prices immediately. Blockchain networks have no concept of a market open or close: any piece of information can be priced immediately, turning the hard constraint of being unable to trade into the soft constraint of trading costs that vary across the hours of the day. Trading activity worldwide follows a cyclical rotation of liquidity over each 24-hour period. Figure 1-3 depicts this global liquidity cycle: trading activity across the three major time zones overlaps in successive waves, with liquidity concentrating in the overlap windows and falling markedly during the late-night gaps.

![Figure 1-3](./images/fig-1-3-en.png)

**Figure 1-3.** The 24-hour global liquidity cycle of digital-asset markets—the overlapping liquidity of the three major time zones: Asia, Europe, and the Americas (schematic modeling, not measured volume; because digital assets trade continuously 24/7, their troughs are shallower than those of foreign-exchange markets, and the timing of the overlap peaks drifts slightly with daylight saving time)

The activity peak of the Asian session typically falls between 1:00 and 7:00 UTC, and the European session between 8:00 and 14:00 UTC; when the European and American sessions overlap (roughly 13:00 to 15:00 UTC), the market reaches its daily liquidity peak, while liquidity falls to a trough between 21:00 UTC and 0:00 the following day. During this low-liquidity window, the bid-ask spread can widen to several times its peak-session level, order-book depth drops noticeably, and the market-impact cost of large trades rises accordingly; this day-night variation in execution quality is a hidden cost specific to around-the-clock markets. Such cyclical rotation of global liquidity requires market makers and high-frequency trading firms to build global teams and infrastructure that continuously cover every session. The weekend effect—rising volatility accompanied by falling liquidity—already has systematic empirical support in crypto markets: Baur et al. (2019) [20], analyzing the intraday and cross-day patterns of Bitcoin trading volume and returns, confirm the statistical significance of this pattern.

Around-the-clock trading eliminates the systemic gap risk caused by market closures, but it does not eliminate price jumps caused by discontinuous liquidity or extreme events: when order-book depth thins abruptly during a low-liquidity period, a large order or a sudden news item can still produce a substantial price discontinuity. At the same time, around-the-clock trading removes three implicit protective functions that market closures once provided. After the close, market makers have time to reassess inventory, adjust models, and clear risk exposures; in an around-the-clock market this window for risk reassessment no longer exists, and market makers must manage all risk in real time under continuous operation. The suspension of trading during a closure dampens the immediate transmission of panic selling; in an around-the-clock market a liquidity crisis can spread without restraint in the thin-liquidity environment of the small hours. During a closure, an exchange can update its risk-control models and repair technical vulnerabilities; in an around-the-clock market such maintenance must be performed while the system is running. Exchanges in traditional markets have begun to explore extending trading hours: the Depository Trust & Clearing Corporation (DTCC) and Ernst & Young have discussed the possibility of a transition toward around-the-clock settlement [21], and BlackRock, in market research from the same period, likewise argues that 24-hour trading has structural implications for capital markets [22]. This reflects, in part, the competitive pressure that the around-the-clock trading model of digital assets exerts on traditional market structure; but it also demonstrates that around-the-clock operation is not without cost—otherwise traditional markets would have adopted it long ago.

### 1.2.5 Smart-contract execution: compressing the intermediary tax

The intermediary tax arises from the costs of interpreting and enforcing legal contracts, the inefficiency of manual processes, and the operating overhead of multiple layers of intermediaries. In traditional finance, each of the five layers of trust requires a specialized institution to operate it, and these operating costs constitute the core of the intermediary tax.

Smart contracts encode the terms of a financial agreement as a program that executes automatically on the blockchain, replacing ambiguous natural language with deterministic computation and human-intensive performance with automated execution. Lessig (2000) [14] presciently observed that code would become a regulatory force of decisive influence in cyberspace, its power deriving both from its determinism and from its unavoidability. Smart contracts systematically replace the core functions of traditional intermediaries and have given rise to entirely new market mechanisms such as AMMs, decentralized lending, and algorithmic stablecoins. MakerDAO—a decentralized issuance system built from a cluster of smart contracts—shows that certain financial functions once borne mainly by sovereign institutions can be implemented in code [23]. This functional substitution, however, faces a challenge of legal characterization: MakerDAO's 2024 restructuring and rebranding to Sky was driven in part by regulatory pressure; DAI faces the risk of being classified as electronic money or a payment instrument in several jurisdictions; and MiCA imposes strict reserve and compliance requirements on stablecoin issuance. Once deployed, an AMM-based decentralized exchange executes its core matching function automatically through smart contracts, at very low marginal operating cost and without the back-office operations teams, physical trading infrastructure, and tiered compliance departments that a traditional exchange requires. Order-book DEXs such as Hyperliquid and dYdX v4, however, run on purpose-built application chains and require the continuous operation of a validator or sequencer network; although their total operating cost is far below that of a traditional exchange, it is nowhere near zero.

The principle of *code as rule* carries an inherent tension. Code cannot exercise discretion, cannot handle extreme situations its designers did not foresee, and, when code is law, the vulnerabilities in that code are executed automatically as well. According to Immunefi, losses from hacks and fraud of all kinds in 2023 alone amounted to approximately $1.8 billion (of which hacks accounted for about $1.6 billion, mostly related to DeFi smart contracts); this figure encompasses many distinct attack types—smart-contract logic flaws, cross-chain bridge attacks, and oracle manipulation—each with a different risk profile and defensive strategy [24]. Code must be upgraded, and the question of who has the authority to modify the code is itself a governance problem that only an institution can answer. Code as rule does not escape human governance entirely; it merely shifts the focus of governance from the enforcement of rules to their modification. Replacing legal compliance with code audits is not costless: formal verification and security audits themselves constitute a new trust tax, typically costing tens of thousands to hundreds of thousands of dollars depending on the complexity of the contract—though this remains far below the cost of traditional legal compliance.

### 1.2.6 On-chain transparency: the opacity tax and the transparency paradox

The opacity tax arises from information barriers: the information asymmetry between institutions and retail investors, and the monopolization of key market data by a handful of institutions. Layer 4 of the five layers of trust exists precisely to address the risk that data may not be truthful, yet this verification is itself opaque—the LIBOR scandal [10] demonstrated that data can still be manipulated even under institutional safeguards.

On a public blockchain, every transaction record and state change is publicly inspectable, and anyone can audit it independently. The actual degree of transparency, however, depends on the underlying architecture: there is a marked difference between the full openness of Ethereum mainnet and the partial centralized operation of application chains (Hyperliquid's sequencer, for example, is operated by the team), where the accessibility and auditability of data depend on the transparency built into the sequencer's design. On-chain data-analytics platforms such as Dune Analytics, Nansen, and Arkham Intelligence parse, aggregate, and visualize raw data, greatly lowering the barrier to data analysis. For the first time, retail investors have the opportunity to obtain raw data of almost the same scope as institutions; yet democratizing access to data is not the same as democratizing decision quality. Behavioral-finance research suggests that greater access to information may increase overconfidence and trading frequency rather than improve investment decisions. The source of trust shifts, in part, from institutional brands and regulatory licenses to open-source code and verifiable data.

While it compresses the opacity tax, on-chain transparency creates a paradox of its own—the transparency paradox. In traditional finance, information asymmetry originates in differential rights of access to data, whereby some participants can reach information that others cannot. In on-chain finance, all participants can observe the same raw data, yet information asymmetry does not thereby disappear; it shifts from an asymmetry of access rights to an asymmetry of processing capability. Participants with stronger computational infrastructure and algorithmic capability can extract tradable signals more quickly from the same public data. Greater transparency therefore does not eliminate the information advantage but shifts the dimension of competition from data acquisition to data processing. MEV is the concentrated expression of this paradox: a public mempool makes all pending transactions visible to everyone, yet only searchers with the fastest infrastructure and the most sophisticated algorithms can convert that visibility into profit. The European Securities and Markets Authority (ESMA, 2025) [25] notes that MEV searchers typically pay more than 90% of their revenue to block proposers, making the right to order transactions a scarce resource; to address this, the Ethereum community has developed proposer-builder separation (PBS), which attempts to channel this competition from disorderly gaming into an orderly, market-based auction. Two forms of MEV must be distinguished, however: Ethereum-style public-mempool MEV (governed through the PBS architecture) and application-chain sequencer-style MEV, in which the sequencer determines transaction ordering—closer to a traditional exchange's last-look privilege. Later chapters analyze the MEV problems specific to order-book DEXs. Although on-chain markets are fully transparent, they are not necessarily fairer than traditional markets; the very definition of fairness needs to be re-examined—one of the central topics of the market-quality evaluation in Chapter 25.

> The transparency paradox: on-chain finance moves the competitive dimension of information asymmetry from the right to access data to the capability to process it. Transparency does not equal fairness.

Pseudonymity is also not the same as anonymity. The possibility of linking on-chain addresses to real-world identities through transaction-graph analysis has raised privacy concerns. The search for a balance between radical transparency and necessary privacy is a key driver of frontier cryptographic techniques such as zero-knowledge proofs [26].

Each of these six distinctive properties compresses the trust tax along a different dimension: permissionlessness compresses the entry tax and the jurisdictional tax; atomic divisibility compresses the granularity dimension of the entry tax; embedded settlement finality compresses the time tax; around-the-clock trading compresses the trading-hours-fragmentation tax; smart contracts compress the intermediary tax; and on-chain transparency compresses the opacity tax. The mapping between the six properties and the six dimensions of the trust tax is not one-to-one but many-to-many: permissionlessness, for instance, compresses both the entry tax and the jurisdictional tax, while around-the-clock trading and atomic settlement jointly act on the time-related dimensions of the trust tax. This cross-mapping foreshadows the multiplicative interaction effects discussed in the next section. Thus far, however, each of these six analyses has proceeded in isolation, and the relationships among the dimensions have not yet been examined. Yet deep multiplicative interactions exist among the six properties, and it is these interactions that create entirely new financial primitives impossible in traditional finance.

## 1.3 The composability thesis

The previous section analyzed the six distinctive properties one by one, using the compression of the trust tax as its framework, but that property-by-property analysis obscured a deeper fact: the disruptive force of the six properties comes not from any single feature but from the multiplicative interactions among them. Schär (2021) [27], in the Federal Reserve Bank of St. Louis Review, was the first to analyze the economic implications of DeFi composability systematically, and Harvey, Ramachandran, and Santoro (2021) [28] extended this framework to institutional investment. Building on these analyses, this section shows both how the multiplicative effect of composability creates financial primitives impossible in traditional finance and how the same mechanism serves as a channel for risk contagion.

### 1.3.1 The interaction matrix of the six properties

Traditional finance can partially realize any one of the six distinctive properties—the extension of trading hours is being actively explored [21], and trials of T+0 settlement are under way—but it cannot realize all six at once; and it is precisely the simultaneous presence and interaction of all six that create the financial primitives impossible in traditional finance.

Table 1-2 presents, as a 6×6 symmetric matrix, the interaction effects produced by pairwise combinations of the six properties. Each cell in the matrix represents not the simple superposition of two features but the entirely new capability that emerges from their multiplicative interaction; several of these combinations give rise to financial primitives that are, in principle, impossible within the architecture of traditional finance.

| | Permissionless | Divisible | Atomic settlement | 24/7 | Programmable | Transparent |
| :--- | :--- | :--- | :--- | :--- | :--- | :--- |
| Permissionless | — | Democratized micro-investing | Instant settlement with no entry barrier | Anyone, anywhere, anytime can participate | Anyone can deploy a protocol | Anyone can audit |
| Divisible | | — | Atomic transfer of tiny amounts | Continuous streaming micropayments | Programmable precise fractions | Complete record of micro-transactions |
| Atomic settlement | | | — | Around-the-clock instant settlement | Flash loans | Fully verifiable settlement process |
| 24/7 | | | | — | Continuous operation of the funding rate | Real-time monitoring |
| Programmable | | | | | — | MEV |
| Transparent | | | | | | — |

**Table 1-2.** The interaction matrix of the six distinctive properties (Data source: compiled by the author)

The 15 interaction cells above the diagonal display not the individual effect of each of the six features but the emergent results of 15 combinations. Three of these cells—flash loans, the continuous operation of the funding rate, and MEV—represent emergent products of paradigmatic significance: in traditional finance they are not merely unrealized but impossible to realize under that architecture.

### 1.3.2 Financial primitives impossible in traditional finance

The flash loan is the product of three interacting features: permissionlessness, atomic settlement, and programmability. Within a single atomic transaction, one can borrow, use, and repay any amount of an asset; if repayment fails, the entire transaction automatically reverts, achieving an instantaneous loan with zero collateral and zero risk. The Aave protocol pioneered this mechanism in 2020 [29]. In traditional finance, lending requires credit review (permissioned), incurs settlement delay (non-atomic), and involves manual approval (non-programmable); because none of these three preconditions is met, the flash loan is in principle impossible under that architecture. Flash loans change the economics of arbitrage: whereas arbitrage in traditional finance requires substantial upfront capital, flash loans make zero-collateral arbitrage possible (the real execution costs include gas fees, priority-fee payments in MEV competition, and infrastructure investment). They raise market efficiency while also lowering the cost barrier to attacks, and they are widely used for arbitrage, collateral swaps, and self-liquidation.

MEV arises from the interaction of three features: around-the-clock trading, transparency, and programmability. Because the market never closes, arbitrage opportunities persist continuously; because all pending transactions are visible to everyone in the public mempool, a program can analyze them within milliseconds and execute ahead of them. In traditional finance, comparable front-running is subject to a triple constraint: strict legal prohibition, non-public information, and exchanges' self-regulation. MEV is the economic embodiment of the transparency paradox. It both guards market efficiency (arbitrage corrects mispricing) and erodes fairness (sandwich attacks harm ordinary users); this dual nature makes the governance of MEV a central topic to which the Ethereum ecosystem continually devotes research resources [25].

Protocol-based arbitrage, exemplified by Ethena, combines three features: around-the-clock trading, atomic settlement, and programmability. Because the market runs continuously, the funding rate can settle automatically every 8 hours, and settlement is atomic; this allows the strategy of shorting perpetual futures while buying spot to earn the funding rate to be packaged into a single smart contract that anyone can join with one click and that manages billions of dollars in assets [30]. In traditional finance, this strategy cannot be turned into a protocol, for three reasons. First, settlement is not atomic: in a traditional arbitrage trade, the spot purchase and the derivative short settle through different clearing channels with a lag of several days, so the two cannot be packaged into a single indivisible operation. Second, rate settlement is not automated: adjusting the rate on a traditional interest rate swap or futures contract requires manual processes and multi-party confirmation. Third, access is not permissionless: a traditional trade of this kind requires an International Swaps and Derivatives Association (ISDA) master agreement, a prime-brokerage relationship, and a minimum position of millions of dollars. In addition, the maturity structures do not match: traditional futures have an expiry date and a basis trade has a definite convergence endpoint, whereas the absence of any expiry date for perpetual futures exposes a funding-rate strategy to the structural difference of an indefinite horizon—which is at once a precondition for turning the strategy into a protocol and a distinctive source of its risk. The simultaneous absence of these preconditions means that turning the strategy into a protocol is, in principle, impossible under the architecture of traditional finance, not merely difficult. Ethena's architecture packages a strategy once exclusive to institutional hedge funds into open, permissionless, protocol-level financial infrastructure. Its risk dimensions cannot be ignored, however: Ethena's hedging positions are concentrated on a handful of centralized exchanges, creating significant counterparty-concentration risk; the funding rate can turn negative for extended periods, so the yield on USDe can reverse into a loss; and USDe faces the risk of being classified as a security. More fundamentally, the degree to which Ethena is a protocol has a clear boundary: its core hedging operations rely on the platform trust of centralized exchanges rather than on pure architectural trust, so in the classification of trust paradigms in Section 1.4.3 it straddles two modes.

### 1.3.3 The dark side of composability

The multiplicative effect of composability runs both ways: it amplifies innovation and risk alike. When the output of protocol A becomes the input to protocol B and then serves as collateral in protocol C, a single failure in A propagates instantly to B and C, at a speed approaching the block time of the blockchain. Werner et al. (2022) [31], in a systematic review of DeFi, characterize this inter-protocol dependence as the core structural source of risk contagion in on-chain finance.

The collapse of Terra/LUNA in May 2022 was an extreme demonstration of composability acting as a channel for risk contagion [32]. After UST lost its peg, LUNA entered a negative-feedback loop; several lending protocols that relied on UST as collateral underwent cascading liquidations; the entire DeFi ecosystem was shaken; and roughly $40 billion in market value (the total value of the LUNA and UST ecosystem, of which UST accounted for about $18 billion) evaporated within days. Behavioral-finance factors also played a substantial role here: Anchor Protocol's 19.5% "fixed yield" constituted a classic yield illusion, drawing many risk-unaware retail investors into overconcentrated allocations; and during the collapse, panic narratives spread on social media no slower than liquidations propagated on chain. The dark side of composability is not only technical and structural but also behavioral. This case is the intersection of composability with the settlement-cascade/liquidation-cascade distinction: atomic settlement accelerated the contagion, and composability widened its reach. Especially dangerous here is wrong-way risk: the core problem for protocols that relied on UST as collateral was that the value of the collateral and the positions it secured collapsed in the same direction under stress, a hidden correlation that is systematically underestimated in normal times.

The flash-loan attack on Euler Finance in March 2023 illustrated another contagion pathway. The attacker exploited a logic flaw in the Euler protocol and, through a series of flash-loan transactions, amplified the scale of the attack to extract about $197 million (the funds were later returned by the attacker). Because several DeFi protocols had deposited assets in Euler or used it as a source of yield, the impact of the attack extended far beyond Euler itself: protocols that depended on Euler, including Balancer, Angle Protocol, and Idle Finance, suffered losses simultaneously. Inter-protocol dependence in DeFi exhibits a highly concentrated hub-and-spoke topology in which a few core protocols anchor many dependency chains, so that an attack on a hub has a disproportionate systemic impact. The case is another clear instance of composability risk: inter-protocol dependence spreads the impact of a single vulnerability along the dependency chain to the entire protocol network.

Composability drives the marginal cost of financial innovation toward zero, but it also greatly accelerates the contagion of financial risk: intra-chain contagion can complete within a single transaction, or even a single block—faster than one block interval (in the Euler attack, the attacker extracted about $197 million within a few blocks)—whereas cross-chain contagion, constrained by bridging and oracle latency, spreads comparatively slowly. Innovation and risk contagion use the same set of inter-protocol call mechanisms, and this constitutes the core structural contradiction of on-chain finance. Protocol design in on-chain finance should not pursue maximum composability; it must strike a balance between the efficiency gains of composability and the contagion of risk—a subject taken up in depth in Chapter 20, on the endogenous fragility of liquidity, and Chapter 29, on the design of the clearing and settlement architecture.

> The core contradiction of composability: innovation and risk contagion share the same set of inter-protocol call mechanisms. This contradiction cannot be eliminated, only managed.

## 1.4 Microstructure reconstruction and the transformation of the risk surface

The transformations set in motion by the six distinctive properties and their composability ultimately converge into a systematic reconstruction of market microstructure and a fundamental transformation of the statistical properties of risk. Using the classic framework of Harris (2003) [4], this section summarizes the reconstruction of three elements—participants, processes, and information—then argues why the risk surfaces of the two financial systems require fundamentally different risk-management methodologies, and finally proposes a layered, hybrid framework of three trust paradigms.

### 1.4.1 The reconstruction of the three microstructure elements

The reconstruction of these three elements—participants, processes, and information—by digital assets has recurred throughout the analysis of the six distinctive properties in Sections 1.2.1 through 1.2.6; here it is consolidated within the Harris framework.

The reconstruction at the level of participants is the broadest in scope. Roles change from fixed identities defined by licenses to fluid states attached to wallet addresses: a single address can act as trader, market maker, arbitrageur, and liquidator on the same day. Automated economic agents—MEV searchers and liquidation bots, for example—become significant new market participants, and the traditional microstructure dichotomy between informed and uninformed traders no longer fully applies. The competitive structure flattens from a tiered, franchised hierarchy into open competition, but this can also lead to rent dissipation: competitors expend substantial resources contesting a fixed pool of MEV rents, driving the net social benefit toward zero. The PBS architecture is essentially a way to reduce this dissipation by converting disorderly competition into an auction mechanism. Chapter 4 develops a detailed model of seven categories of participants.

At the level of processes, once atomic settlement (Section 1.2.3) eliminates the T+N window of risk exposure, the focus of risk management shifts from assessing counterparty credit to auditing code security [19]. Smart contracts (Section 1.2.5) encode intermediary functions, structurally reducing operating costs. The atomicity of settlement guarantees the composability of financial operations, and the mode of innovation changes from designing new products to combining existing protocols.

At the level of information, information asymmetry shifts, as described in Section 1.2.6, from the right of access to processing capability. Tracking smart-money addresses and imitating their trades has become a common strategy, but it may intensify herding. The basis of trust changes from institutional brands to open-source code and verifiable data. The concept of privacy is redefined, and techniques such as zero-knowledge proofs are seeking a balance between radical transparency and necessary privacy [26].

The reconstruction of these three elements is the convergent expression, at the microstructure level, of the six distinctive properties. Building on this, two further questions arise: how these changes have altered the statistical properties of risk, and how the sources of trust should be reorganized.

### 1.4.2 The transformation of the risk surface

The risks of traditional finance and of digital assets differ not only in type but also fundamentally in their statistical properties, and therefore cannot be addressed with the same risk-management methodology. In his seminal paper, Mandelbrot (1963) [33] first demonstrated that the distribution of financial returns does not follow a normal distribution but instead exhibits fat tails—that is, extreme events occur with a probability far higher than the normal assumption predicts. Taleb (2007) [34] further argued that humans systematically underestimate the probability and impact of extreme events, and that traditional risk-control frameworks, designed under the normality assumption, fail systematically in a fat-tailed world. The risk surface of digital assets is an extreme expression of the fat-tailed world that Mandelbrot and Taleb described.

Table 1-3 compares the risk surfaces of the two financial systems along five dimensions: frequency, shock distribution, visibility, recovery speed, and risk-control tools. Each of the five dimensions points to the same conclusion: the risks of the two systems differ not in degree but in kind, and no single risk-management methodology can address both.

| Dimension | The risk surface of traditional finance | The risk surface of digital assets |
| :--- | :--- | :--- |
| Frequency | Low—major crises occur on average once every 10 to 15 years [35] | High—protocol vulnerabilities and attacks occur weekly |
| Shock distribution | High-impact—once it occurs, it is systemic | Variable impact—most events have limited effect, but the tail is extremely fat |
| Visibility | Often invisible before a crisis, attributed only afterward | Many risks are visible on chain, but visible does not mean manageable |
| Recovery speed | Slow—institutional repair is measured in years | Fast—protocol repair is measured in days to weeks, but it may also be irreversible |
| Risk-control tools | VaR, stress testing, the Basel framework—based on the low-frequency, high-impact assumption | Require a new methodology that handles high-frequency small events and rare catastrophic events at once |

**Table 1-3.** Comparison of the risk surfaces of traditional finance and digital assets (Data source: compiled by the author based on [35])

Figure 1-4 contrasts this difference in statistical properties with two probability-distribution curves: the tail probability of a fat-tailed distribution decays far more slowly than that of the normal (thin-tailed) distribution, and extreme events several standard deviations from the mean occur far more frequently than the normal assumption predicts. This is precisely why traditional value at risk (VaR) models fail systematically in on-chain markets.

![Figure 1-4](./images/fig-1-4-en.png)

**Figure 1-4.** Comparison of the risk distributions of traditional finance and digital assets—the difference in tail probability between the normal (thin-tailed) distribution and the fat-tailed distribution (conceptual/theoretical illustration; the fat tail is modeled with a Student's t-distribution with 3 degrees of freedom; the Terra/LUNA and FTX labels in the figure are illustrative examples of tail events, not measured data points; the right panel uses a logarithmic vertical axis to highlight the tail difference; theoretical basis: Mandelbrot 1963 [33], Taleb 2007 [34])

To ask whether digital assets are more dangerous or safer is the wrong question. The right question is how the risk surfaces of the two systems differ and what different tools are needed to manage them. The risk surface of traditional finance is a distribution of low-frequency but systemic shocks. Reinhart and Rogoff's (2009) [35] systematic study of eight centuries of financial crises shows that banking crises recur on average every 10 to 15 years but are highly clustered and transmit across borders—and that traditional finance is not without high-frequency operational-risk events either (the 2010 U.S. stock-market flash crash, for instance, erased trillions of dollars in market value within minutes). The risk surface of digital assets is a distribution that is high-frequency and highly variable in the scale of its shocks: protocol vulnerabilities occur weekly, most with limited impact, but occasionally catastrophic. More striking still, the two risk surfaces are not independent: with the approval of Bitcoin exchange-traded funds (ETFs) and the entry of institutional investors, the correlation between digital assets and traditional finance rises markedly in periods of stress, and institutions that hold both asset classes become contagion channels when they deleverage, so the two are beginning to show signs of mutual contagion. This recognition is a prerequisite for understanding the risk analysis in Chapters 20 through 24.

The transformation of the risk surface also means that existing financial-regulatory frameworks such as Basel III—whose core parameter assumptions, such as the 10-day holding period in VaR and the 30-day stress period in the liquidity coverage ratio, are designed for the risk surface of traditional finance—may fail in two directions: overreacting to high-frequency small events (because the traditional framework treats any event as a potential systemic risk) while at the same time being underprepared for genuine tail risk (because the traditional framework's stress-test scenarios may not cover the extreme situations specific to on-chain markets, such as protocol-level vulnerabilities and the superposition of composability contagion and liquidation cascades). Investors accustomed to traditional finance may misread the high-frequency volatility of on-chain markets as higher risk. Prospect theory shows that the psychological pain of frequent small losses can exceed their economic impact, prompting premature exit, while their underestimation of the probability of rare large losses leaves them underprepared for genuine tail risk. Systemic events on the scale of Terra/LUNA and FTX require a fundamentally different mental model and risk budget.

While compressing the traditional trust tax, digital assets introduce an entirely new cost structure. The security tax is the cost of smart-contract security audits and formal verification. As noted in Section 1.2.5, the one-time audit fee (tens of thousands to hundreds of thousands of dollars) is only the starting point: ongoing expenditures include bug-bounty programs (ranging from hundreds of thousands to millions of dollars), re-audits after contract upgrades, the operation of real-time monitoring systems, and the capital tied up in an insurance fund—and even after all of this, zero vulnerabilities cannot be guaranteed. The gas tax is the execution cost of on-chain transactions, which can spike tens of times over during network congestion and render small transactions economically infeasible. The private-key management tax is the cognitive burden and operational risk users bear in managing their own private keys: losing a private key means permanent loss of the assets, with no forgot-password recovery mechanism. Based on an analysis of dormant on-chain addresses, Chainalysis (in a 2020 report) estimated that about 3.7 million bitcoin—roughly 20% of the supply at the time—were permanently inaccessible because of lost private keys (this estimate rests on a dormancy heuristic and is somewhat contested, since it may conflate long-term holders with genuinely lost coins, though its order of magnitude is widely cited in the industry) [36]. The smart-contract vulnerability tax comprises the asset losses caused by exploited code flaws—irreversible and with no legal recourse [24]. The MEV-extraction tax is the hidden cost that competitive extraction of transaction-ordering rights imposes on ordinary users [25]. The governance-uncertainty tax shows up as low participation in DAO voting and the risk of governance attacks. Digital assets do not eliminate the trust tax; they replace an old trust tax with a new one. The standard for judging this paradigm shift is not whether the new trust tax is zero but whether its total is significantly lower than the old one and whether its distribution is fairer.

### 1.4.3 Three trust paradigms

Moving beyond the binary opposition of centralization and decentralization, trust can be organized into three paradigms. The concept of architectural trust builds on Werbach's (2018) [37] systematic analysis of blockchain trust mechanisms. Werbach distinguishes three traditional modes—peer-to-peer trust, Leviathan trust (state coercion), and intermediary trust—and argues that the blockchain creates a new trust architecture, one that establishes trust through technical design rather than interpersonal relationships or institutional authority. This chapter develops that analysis further into a threefold division of institutional trust, platform trust, and architectural trust; the introduction of platform trust reflects the key role that centralized platforms (such as FTX) play in practice in the digital-asset domain, a category not yet fully analyzed in Werbach's original framework.

Institutional trust draws on law, regulation, and specialized institutions; it offers a 200-year track record, legal recourse, and consumer protection, but it is costly, opaque, slow, and difficult to enter, and the LIBOR scandal [10] proved that it can be manipulated by insiders. Platform trust draws on the operator of an exchange or platform; it offers high performance and a good user experience but depends entirely on a single entity, and the collapse of FTX [3] demonstrated the catastrophic consequences of that dependence—platform trust is essentially a repackaging of traditional centralized trust in the digital domain. Architectural trust draws on code, cryptography, and decentralized consensus; it is verifiable, globally accessible, and independent of any single entity, but it faces challenges such as code vulnerabilities, limited performance, and governance difficulties.

The three paradigms are not substitutes for one another; they can be mixed across layers. At the asset-custody layer, the self-custody approach of architectural trust eliminates, through private-key control, the risk of assets being misappropriated by a single centralized entity, but self-custody introduces a new spectrum of operational risks—key management, physical security, and disaster recovery. At the trade-execution layer, the centralized matching engine of platform trust offers an irreplaceable performance advantage in high-frequency settings, whereas the decentralized exchange of architectural trust is more competitive in transparency and censorship resistance; the optimal choice depends on the specific use case. Notably, the most successful on-chain order-book DEXs today (such as Hyperliquid and dYdX v4) adopt a hybrid architecture, in which centralization at the ordering and matching level coexists with on-chain settlement; this engineering compromise should not be classified simply as one paradigm or the other but as a pragmatic combination of the two. At the clearing and settlement layer, the atomic settlement of architectural trust eliminates the settlement cascade but cannot prevent the liquidation cascade, and extreme circumstances may still require the discretion that institutional trust provides. History already offers precedents: in the JELLY incident of March 2025, Hyperliquid's validator committee voted to delist the token and liquidate positions at a manually set price, and after The DAO incident of 2016 the Ethereum community reversed transactions through a hard fork—both instances in which architectural trust, under extreme stress, degenerated into discretionary decisions by a small number of people. At the data-verification layer, the on-chain transparency of architectural trust eliminates the possibility of LIBOR-style manipulation, but oracles (which bring off-chain data on chain) still require a degree of trust. At the rule-governance layer, the ultimate discretion and final arbitration that the legal and judicial systems of institutional trust provide in extreme cases remain, for now, irreplaceable; the question of who has the authority to modify the code still requires human judgment, and low participation in DAO governance and the risk of governance attacks together cast doubt on the reliability of pure architectural trust at this layer. In 2022, the Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash, demonstrating that state power can intervene directly in protocol-level permissionlessness (a 2024 ruling of the Fifth Circuit later overturned the sanctions, and OFAC removed the entity from the Specially Designated Nationals (SDN) list in March 2025—a reminder that the exercise of state power is itself subject to judicial checks). The freezing orders that courts in several countries have developed in crypto-asset recovery cases, in turn, demonstrate that legal recourse is extending onto the chain.

The optimal financial infrastructure is neither fully decentralized nor fully centralized; it is a layered architecture that makes the most reasonable choice of trust paradigm at each layer. This insight is systematized into concrete engineering choices in Chapter 5's spectrum of verifiability and Chapter 28's design of the trust stack. Combining the three paradigms with the trust-tax framework closes the loop: institutional trust carries the highest trust tax but the most comprehensive service; platform trust carries a moderate trust tax but an extremely high concentration risk; and architectural trust carries the lowest trust tax but incomplete service coverage. The optimal combination selects, at each layer, the paradigm with the lowest trust tax that still provides an adequate level of service—an engineering optimization problem, not an ideological stance.

## 1.5 Chapter summary

This chapter has assembled a complete analytical toolkit for understanding digital assets—the largest-scale natural experiment in financial history. The five layers of trust reveal the internal structure of traditional finance's trust architecture; each layer has a reason to exist, and each has failed at some point. The trust tax unifies the entire institutional cost of traditional finance into a causally explicable whole whose root cause is the absence of trust; the architecture of digital assets compresses this tax through technical means, but compression is not free, and the trust tax has its rationale. The composability thesis shows how the multiplicative interactions among the six distinctive properties create financial primitives impossible in traditional finance—flash loans, MEV, and protocol-based arbitrage—while composability is at the same time a channel for risk contagion. The transparency paradox establishes that on-chain transparency does not equal fairness: the dimension of competition shifts from who possesses information to who can process it fastest. The transformation of the risk surface demonstrates that the statistical properties of risk in the two financial systems are fundamentally different—not a question of more dangerous or safer, but one that requires different risk-management methodologies. The three trust paradigms provide a framework for choosing among different sources of trust, mixed across different functional layers, and the optimal solution is a layered, hybrid engineering problem.

These six concepts form a logical chain—from root-cause analysis (the trust tax), to technical response (the six distinctive properties), to emergent effects (the composability thesis and the transparency paradox), to risk reconstruction (the transformation of the risk surface), and finally to the reorganization of trust (the three trust paradigms)—and this chain is the starting point for the analysis developed in the chapters that follow.

The most far-reaching product of this experiment is perpetual futures—with an annual notional trading volume of about $86.2 trillion (on a centralized-exchange basis; about $92.9 trillion including decentralized exchanges) and accounting for more than 90% of crypto-derivatives trading volume [38]. Crypto-derivatives volume data, however, suffer from wash trading, so actual volume may be lower than the reported figures, and notional volume is inflated by high leverage; traditional exchange-traded derivatives lack a uniform annual notional-principal measure (the Futures Industry Association (FIA) counts by number of contracts—about 180 billion worldwide in 2024), making the two difficult to compare directly. Perpetual futures are the subject of the next chapter. The emergence of perpetual futures was no accident: it is the concentrated expression, in the derivatives domain, of the composability of the six distinctive properties. In a market that trades continuously around the clock and settles in real time, the fixed-expiry design of traditional futures comes into structural conflict with the market's continuity. The theoretical conception of perpetual futures was proposed by Shiller (1993) [39], and BitMEX first engineered it in crypto markets in 2016. By abolishing the expiry date and introducing the funding-rate mechanism—which functionally replaces the price-convergence role of the expiry date—perpetual futures became a derivative form highly consonant with the continuous structure of this market, and they are the central object of the analysis that follows in this book.

## References

[1] CoinShares. (2025). *Institutional report: 13F Bitcoin ETF data Q3 2025*. CoinShares. https://coinshares.com/us/insights/research-data/13f-filings-of-bitcoin-etfs-q3-2025-institutional-report/

[2] Alternative Investment Management Association & PwC. (2025). *7th annual global crypto hedge fund report*. AIMA. https://www.aima.org/article/press-release-crypto-friendly-regulatory-changes-accelerate-institutional-investment.html

[3] U.S. Securities and Exchange Commission. (2022). *SEC charges Samuel Bankman-Fried with defrauding investors in crypto asset trading platform FTX* [Press release]. https://www.sec.gov/news/press-release/2022-219

[4] Harris, L. (2003). *Trading and exchanges: Market microstructure for practitioners*. Oxford University Press.

[5] Depository Trust & Clearing Corporation. (2024). *Accelerating the U.S. securities settlement cycle to T+1*. DTCC. https://www.dtcc.com/ust1

[6] Financial Crisis Inquiry Commission. (2011). *The financial crisis inquiry report: Final report of the National Commission on the Causes of the Financial and Economic Crisis in the United States*. U.S. Government Publishing Office.

[7] Luhmann, N. (1979). *Trust and Power*. Wiley.

[8] Commodity Futures Trading Commission. (2013). *CFTC orders MF Global Inc. to pay more than \$1 billion penalty for unlawful misuse of customer funds* [Press release]. https://www.cftc.gov/PressRoom/PressReleases/pr6776-13

[9] U.S. Securities and Exchange Commission. (2016). *Barclays Capital Inc. charged with violations in handling of dark pool* [Press release]. https://www.sec.gov/news/pressrelease/2016-16.html

[10] Hou, D., & Skeie, D. (2014). LIBOR: Origins, economics, crisis, scandal, and reform. *Federal Reserve Bank of New York Staff Reports*, No. 667. https://www.newyorkfed.org/research/staff_reports/sr667

[11] Williamson, O. E. (1985). *The Economic Institutions of Capitalism: Firms, Markets, Relational Contracting*. Free Press.

[12] Burton-Taylor International Consulting. (2024). *Global market data revenue report 2024*. Burton-Taylor.

[13] World Bank. (2024). *Remittance prices worldwide: An analysis of trends in the cost of remittance services* (Issue 49). World Bank Group. https://remittanceprices.worldbank.org/

[14] Lessig, L. (2000). Code is law: On liberty in cyberspace. *Harvard Magazine*. https://www.harvardmagazine.com/2000/01/code-is-law-html

[15] Baumol, W. J. (1982). Contestable markets: An uprising in the theory of industry structure. *American Economic Review*, *72*(1), 1–15.

[16] Financial Action Task Force. (2021). *Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers*. FATF. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html

[17] CertiK. (2025). *Hack3d: The Web3 security report 2025*. CertiK. https://www.certik.com/resources/blog/hack3d-the-web3-security-report-2025

[18] Boston Consulting Group & Aptos Labs. (2024). *Relevance of on-chain asset tokenization in crypto winter*. BCG. https://web-assets.bcg.com/1e/a2/5b5f2b7e42dfad2cb3113a291222/on-chain-asset-tokenization.pdf

[19] Bank for International Settlements. (2025). *Annual economic report 2025*. BIS. https://www.bis.org/publ/arpdf/ar2025e.htm

[20] Baur, D. G., Cahill, D., Godfrey, K., & Liu, Z. F. (2019). Bitcoin time-of-day, day-of-week and month-of-year effects in returns and trading volume. *Finance Research Letters*, *31*, 78–92. https://doi.org/10.1016/j.frl.2019.04.023

[21] Depository Trust & Clearing Corporation & Ernst & Young. (2025). *Moving toward 24/5 and beyond: Extending US securities settlement hours*. DTCC.

[22] Cohen, S., Brennan, M., De Jesus, H., Warr, J., Merwin, S., Nguyen, N., Cronin, R., & Shen, A. (2025). *Market spotlight: 24 hour trading*. BlackRock. https://www.blackrock.com/corporate/literature/whitepaper/blackrock-market-spotlight-24-hour-trading.pdf

[23] Brennecke, M., Guggenberger, T., Schellinger, B., & Urbach, N. (2022). The de-central bank in decentralized finance: A case study of MakerDAO. *Proceedings of the 55th Hawaii International Conference on System Sciences*, 6370–6379. https://doi.org/10.24251/hicss.2022.737

[24] Immunefi. (2024). *Crypto losses in 2023*. Immunefi. https://immunefi.com/research/

[25] European Securities and Markets Authority. (2025). *Maximal extractable value: Implications for crypto markets* (TRV Risk Analysis). ESMA. https://www.esma.europa.eu/sites/default/files/2025-07/ESMA50-481369926-29744_Maximal_Extractable_Value_Implications_for_crypto_markets.pdf

[26] Ethereum Foundation Privacy and Scaling Explorations. (2025). *End-to-end privacy roadmap for Ethereum*. https://pse.dev/

[27] Schär, F. (2021). Decentralized Finance: On Blockchain- and Smart Contract-Based Financial Markets. *Federal Reserve Bank of St. Louis Review*, *103*(2), 153–174. https://doi.org/10.20955/r.103.153-74

[28] Harvey, C. R., Ramachandran, A., & Santoro, J. (2021). *DeFi and the Future of Finance*. Wiley.

[29] Aave. (2020). *Aave Protocol V2: Flash loans*. Aave. https://docs.aave.com/developers/guides/flash-loans

[30] Ethena Labs. (2024). *Ethena: Internet native money*. Ethena. https://ethena-labs.gitbook.io/ethena-labs

[31] Werner, S. M., Perez, D., Gudgeon, L., Klages-Mundt, A., Harz, D., & Knottenbelt, W. J. (2022). SoK: Decentralized Finance (DeFi). In *Proceedings of the 4th ACM Conference on Advances in Financial Technologies* (pp. 1–16). ACM. https://doi.org/10.1145/3558535.3559780

[32] Liu, J., Makarov, I., & Schoar, A. (2023). Anatomy of a run: The Terra Luna crash. *NBER Working Paper*, No. 31160. https://www.nber.org/papers/w31160 https://doi.org/10.2139/ssrn.4416677

[33] Mandelbrot, B. (1963). The variation of certain speculative prices. *Journal of Business*, *36*(4), 394–419. https://doi.org/10.1086/294632

[34] Taleb, N. N. (2007). *The black swan: The impact of the highly improbable*. Random House.

[35] Reinhart, C. M., & Rogoff, K. S. (2009). *This Time Is Different: Eight Centuries of Financial Folly*. Princeton University Press.

[36] Chainalysis. (2020). *60% of Bitcoin is held long term as digital gold, while just 19% is used for trading*. Chainalysis. https://www.chainalysis.com/blog/60-of-bitcoin-is-held-long-term-as-digital-gold-while-just-19-is-used-for-trading/

[37] Werbach, K. (2018). *The Blockchain and the New Architecture of Trust*. MIT Press. https://doi.org/10.7551/mitpress/11449.001.0001

[38] CoinGecko. (2026). *2025 annual crypto industry report*. CoinGecko. https://www.coingecko.com/research/publications/2025-annual-crypto-report

[39] Shiller, R. J. (1993). *Macro Markets: Creating Institutions for Managing Society's Largest Economic Risks*. Oxford University Press.
