CBDCs, Stablecoins and Programmable Money

My illustration entitled: “The Three Rivers of Digital Money” – Three luminous rivers—CBDCs, stablecoins and Bitcoin—flow through a futuristic city. I stand at their intersection, examining who controls each current and where it leads.


Money is becoming software.

Cash, bank deposits, central-bank digital currencies, stablecoins and cryptocurrencies may all be described as money or money-like instruments, but they create profoundly different relationships between the individual and the institutions that issue, administer or validate them.

The difference is not merely technical. It concerns power.

Who issues the unit? Who guarantees its value? Who records the transaction? Who can see the payment? Who can reverse it, freeze it or prevent it? Who may alter the rules? Must every participant be identified? Can the individual hold the asset directly, or does ownership depend upon an institutional account?

As money becomes programmable, another question appears: who writes the program?

A programmable payment can execute automatically when agreed conditions are satisfied. Programmable money can go further by carrying restrictions concerning where, when, how or by whom it may be spent. The first can expand individual agency. The second can create an unprecedented system of financial control.

Cypherpunkism therefore does not evaluate digital money according to novelty, speed or branding alone. It evaluates the architecture of monetary power.

The future of money will be determined not only by who issues it, but by who can observe it, program it, freeze it and refuse it.

Digital Money Is Not One Thing

Most money is already digital. Salaries arrive as entries in bank databases. Cards transmit payment instructions through electronic networks. Mobile applications allow balances to move without physical currency changing hands.

Yet the digitization of existing money is not the same as the creation of a new monetary architecture.

A bank deposit is a liability of a commercial bank. Physical cash is generally a liability of the central bank and can circulate directly between people. A central-bank digital currency would extend central-bank money into electronic form. A stablecoin is usually a privately administered digital token designed to maintain a stable value relative to a currency or another asset. Bitcoin is a digitally scarce asset issued by no state, bank or company.

These instruments can resemble one another at the interface. Each may appear as a number inside a wallet. But beneath that number are different issuers, ledgers, redemption promises, governance structures and mechanisms of control.

The wallet tells us how money looks. The architecture tells us who holds power.

Cash: The Existing Bearer Instrument

Physical cash possesses qualities that are easy to overlook precisely because they are familiar. A banknote can be transferred directly. It does not require the payer to open an account, ask permission from a network or reveal an identity to the issuer. The note does not transmit a record of its location or maintain a permanent history of its owners.

Cash is not perfectly anonymous in every circumstance, nor is it immune to theft, seizure, counterfeiting or inflation. Large cash transactions may be regulated, and physical possession creates its own risks. Nevertheless, cash establishes an important standard for monetary freedom.

It permits ordinary transactions without constructing a permanent institutional memory of them.

Cash also cannot ordinarily be frozen from a distance. A banknote does not expire because its owner expressed an unpopular opinion. It does not refuse to purchase a lawful product because a central database has classified the transaction as undesirable. It does not require continuous network access to remain usable.

These are not accidental limitations awaiting technological correction. They are properties that distribute power toward the holder.

Commercial Bank Deposits: Money by Permission

A commercial bank deposit is different. The customer does not possess particular banknotes held under his or her name. The customer holds a claim against the bank, represented by an account balance.

This arrangement offers convenience, security services, credit and access to modern payment networks. It also creates dependency. The bank maintains the ledger, verifies identity, monitors transactions and determines whether an instruction will be accepted. Transfers may be delayed, reversed or reported. Accounts may be restricted or frozen under contractual rules, regulatory obligations or legal orders.

Such powers can serve legitimate purposes, including fraud prevention and the enforcement of lawful judgments. Their existence nevertheless means that a bank balance is not equivalent to a bearer asset under the direct control of the individual.

The depositor possesses money through an institutional relationship. Access depends upon continued recognition by the institution and the networks with which it connects.

What Is a Central-Bank Digital Currency?

A central-bank digital currency, or CBDC, is a proposed electronic form of central-bank money. A retail CBDC would be available to households and businesses, while a wholesale CBDC would primarily serve financial institutions and settlement systems.

A CBDC should not be confused with an ordinary bank deposit. If designed as a direct claim upon the central bank, it would carry a different issuer and risk structure. Nor should it automatically be called a cryptocurrency. As the Bank of England explained in its March 2020 discussion paper, a CBDC would not necessarily use distributed-ledger technology.

CBDCs can assume many forms. A central bank might maintain individual accounts directly. Private intermediaries might provide wallets and customer services while the central bank operates a core ledger. Access might be account-based, token-based or built through a hybrid of both models.

The phrase “central-bank digital currency” therefore does not identify a complete system. It identifies the issuer and monetary status of the instrument. Questions of privacy, access, custody, programmability and institutional control remain matters of design.

The Promise of CBDCs

A well-designed CBDC could provide genuine public benefits. It could preserve public access to central-bank money as the use of physical cash declines. It could increase competition in payments, reduce settlement friction and extend basic payment services to people underserved by commercial banks.

It might support resilient payment infrastructure and permit transactions to settle without the credit risk of a private issuer. Open technical standards could allow regulated private providers to build competing wallets and services upon a common public foundation.

The Bank for International Settlements’ 2020 Annual Economic Report argued that CBDCs could foster competition among private intermediaries and establish high standards for safety and risk management. Its August 2020 working paper, Rise of the Central Bank Digital Currencies, documented the growing intensity of central-bank research and experimentation.

A CBDC could therefore function as digital public infrastructure rather than merely another payment application.

But the same infrastructure that makes payments efficient can make financial life observable and controllable. The public character of the issuer does not eliminate this danger. It may intensify it.

The CBDC Surveillance Risk

Cash separates the issuer of money from the observation of each individual transaction. A centrally recorded digital currency could collapse that separation.

If every unit passes through an identifiable account on a centrally accessible ledger, the payment system can become a comprehensive map of human activity. Purchases reveal health, religion, political association, travel, relationships, habits and economic dependence. Monetary metadata can describe a person even when the purchased item itself appears ordinary.

The problem is not limited to whether a central-bank employee personally reads the ledger. Data may be available to intermediaries, law-enforcement bodies, tax authorities, intelligence agencies, contractors or other institutions through routine access, automated analysis or later changes in law.

A system designed for one political administration may be inherited by another. An authority created for exceptional circumstances may become an ordinary instrument of governance.

In Metadata Is Power, I argued that transactional patterns can expose identities, locations, associations and routines even when message content remains protected. A universal digital ledger could extend this informational power into nearly every economic relationship.

A CBDC that replaces cash without reproducing a meaningful degree of cash-like privacy would not simply modernize money. It would alter the balance of power between the individual and the state.

What Is a Stablecoin?

A stablecoin is a digital token intended to maintain a comparatively stable value, commonly by reference to a national currency such as the United States dollar.

The term describes an objective, not a single mechanism. Stablecoins can be broadly divided into several models:

  • Fiat-backed stablecoins depend upon an issuer or custodian holding currency, bank deposits or other reserve assets against tokens in circulation.
  • Crypto-collateralized stablecoins use digital assets and smart contracts to support issuance, often requiring collateral worth more than the stablecoins created.
  • Algorithmic models attempt to influence supply or incentives through programmed rules rather than full backing by conventional reserve assets.
  • Global stablecoin proposals seek broad adoption across countries and may be connected to large technological platforms or associations.

Each model relocates trust rather than eliminating it. A fiat-backed token requires confidence in the issuer, the custodian, the reserve and the promise of redemption. A crypto-collateralized system requires confidence in its smart contracts, collateral, price information and liquidation mechanisms. An algorithmic design requires confidence that its incentives will continue to function under stress.

Stability is therefore not a natural property of the token. It is the outcome of an institutional or computational arrangement.

The Stablecoin Paradox

Stablecoins unite two worlds that were previously more separate. They can move across blockchain networks and interact with smart contracts, yet their value may remain anchored to conventional currency and banking infrastructure.

This makes them useful. A dollar-referenced token can travel between compatible wallets, exchanges and applications without exposing its holder to the full price volatility of many cryptocurrencies. It can serve trading, settlement, remittance and emerging decentralized financial applications.

But the appearance of a token in a personal wallet does not necessarily mean the holder possesses sovereign digital cash.

A centrally issued stablecoin contract may give an administrator the power to freeze addresses, block transfers, create or destroy tokens and replace the contract. A custodian may control the reserves while token holders remain unsecured claimants. Redemption may depend upon identity checks, jurisdiction, minimum amounts or continued cooperation from banks.

The blockchain may be decentralized while the monetary asset operating upon it remains centrally governed.

This is one of the central architectural lessons of stablecoins: a decentralized settlement network does not automatically decentralize the issuer, the collateral, the redemption gateway or the power to define valid ownership.

The Libra Question

Facebook’s announcement of Libra in 2019 transformed stablecoins from a specialized cryptocurrency instrument into a matter of global monetary policy. In April 2020, the project published a revised white paper proposing single-currency stablecoins supported by reserves of cash, cash equivalents and short-term government securities.

The project illustrates both the attraction and danger of platform-based money. A payment instrument integrated into an enormous communications network could reduce friction and expand access rapidly. The same integration could unite identity, social relationships, commercial behavior and financial activity within a powerful technological ecosystem.

Even if formal separation exists between a platform and a monetary association, the broader architecture must still be examined. Who controls the user interface? Who determines access? What identity is required? Can transactions be linked to social accounts? Can competitors build interoperable services? Can the individual leave with funds, contacts and transaction history intact?

In June 2020, the Financial Action Task Force approved a report concerning so-called global stablecoins, concluding that its standards applied to stablecoin arrangements and highlighting the regulatory consequences of potential mass adoption.

The political reaction to Libra demonstrates an important fact: money is never merely a payment feature. At sufficient scale, control over payment becomes a form of governance.

Bitcoin: Money Without an Issuer

Bitcoin represents a different architecture. It has no central issuer promising redemption at a fixed value. Its ledger is replicated across a peer-to-peer network, and control over a bitcoin is exercised through cryptographic keys rather than an account maintained by a central bank or commercial issuer.

This eliminates several forms of institutional dependence. No central administrator can create arbitrary units, reverse a confirmed transaction or freeze a protocol-level address. A person who controls the private keys can transfer value without obtaining permission from a bank or stablecoin issuer.

But Bitcoin also involves trade-offs. Its market value is volatile. Its public ledger does not provide the transactional privacy of cash. Address analysis and information obtained from exchanges can connect activity to real identities. Custodial platforms can recreate the very permission structures that Bitcoin’s architecture was designed to avoid.

Bitcoin is consequently neither a digital version of cash nor a stablecoin. It is a separate monetary architecture: scarce, non-sovereign, cryptographically controlled and resistant to unilateral institutional alteration.

Its importance to Cypherpunkism lies not in the claim that every currency should imitate it. Bitcoin demonstrates that digital ownership and transfer need not always depend upon a central issuer’s ledger.

Privacy-Preserving Digital Cash

CBDCs and stablecoins are not the only paths available. Long before Bitcoin, cryptographer David Chaum proposed electronic-cash systems using blind signatures. These methods were designed to allow a financial institution to issue digital value without automatically learning where each unit was later spent.

This distinction remains essential. Central issuance does not logically require universal transaction visibility. A digital currency can be designed so that validity is verified without constructing a complete, identity-linked history of every payment.

Privacy-preserving digital cash could combine stable denomination with stronger transactional boundaries. Depending upon its design, it might allow limited-value transfers, offline use or cash-like payments while preserving mechanisms for preventing duplication and maintaining monetary integrity.

Privacy need not mean the absence of every safeguard. Different thresholds and procedures may apply to different risks. The important principle is that the entire population should not be subjected to continuous financial observation merely because particular transactions may justify investigation.

The architecture should begin with data minimization, not total collection followed by a promise of responsible use.

Programmable Payments and Programmable Money

The phrase “programmable money” is often used too broadly. It is useful to distinguish a programmable payment from programmable money itself.

A programmable payment occurs when software initiates or completes a transfer according to instructions. Standing orders, subscriptions and escrow arrangements already contain elements of this idea. Smart contracts can extend it by releasing funds when verifiable conditions are fulfilled.

Programmable money goes further. Rules can be attached to the monetary instrument or its ledger so that the money itself behaves differently according to the identity of the holder, the recipient, the time, the location or the intended purchase.

This distinction separates user-directed automation from issuer-directed control.

Programmability can enable useful arrangements. Funds can be released in stages, divided among recipients, placed into escrow or returned automatically when contractual conditions fail. Software can reduce administrative friction and allow strangers to coordinate without trusting a single intermediary.

Ethereum’s smart-contract model demonstrates how code can define rules for digital assets and execute state changes across a decentralized network.

Yet programmability can also allow an issuer or administrator to decide that money may be spent only on approved products, within approved regions, before an expiration date or by people who satisfy changing institutional criteria. Taxes, penalties or restrictions might be executed automatically before the individual can challenge them.

Money would cease to be a neutral medium available for general exchange. It could become a permission system.

When Money Becomes a Policy Instrument

Every monetary system embodies policy. Interest rates, issuance rules, banking regulation and legal-tender laws already influence how money is created and used. Programmability changes the precision and immediacy with which policy can reach the individual transaction.

A conventional law may prohibit a transaction and require investigation, evidence and adjudication before punishment. Programmable money could make the transaction technically impossible from the beginning. The code may enforce the rule before any human being can consider context, error, necessity or appeal.

This may appear efficient. But efficiency is not the highest political value. A perfectly efficient system of control remains a system of control.

Automated enforcement also relocates political decisions into technical design. Whoever writes the conditions governing the currency acquires power over economic participation. Errors in identity, classification or software can become immediate exclusions from ordinary life.

As argued in The Architecture of Power, code is not merely an instrument operating beneath society. Code determines permissions and therefore functions as political architecture.

The Power to Freeze

The ability to freeze money is among the clearest tests of monetary sovereignty.

Freezing can serve legitimate purposes. Courts may preserve disputed assets, governments may impose lawful sanctions and service providers may intervene when credentials are stolen. A system that makes every intervention impossible can leave victims without effective remedies.

But the same capacity can be used without due process, applied to the wrong person or extended from exceptional crimes to ordinary political disagreement. When access to food, housing, travel and communication depends upon one digital balance, financial exclusion becomes an instrument of comprehensive social control.

The issue is therefore not whether freezing must always be impossible. It is who possesses the capability, what evidence is required, how narrowly the restriction operates, how quickly it can be challenged and whether alternative means of economic participation remain available.

A CBDC controlled through a single national ledger, a stablecoin administered through a privileged contract key and a bank account maintained through a centralized institution each produce different answers. Bitcoin minimizes protocol-level freezing, but custodial services built around it may restore institutional control.

One must examine the whole system, not merely the asset’s name.


My illustration “The Three Rivers of Digital Money” work-in-progress. THe art represents: digital money can share similar technology while operating under very different systems of authority.


A Cypherpunkist Comparison

Instrument Primary authority Privacy tendency Remote freezing Programmability Direct individual control
Physical cash Central-bank issuance; bearer custody Comparatively strong for ordinary transactions Generally unavailable Minimal Strong while physically possessed
Commercial bank deposit Bank, payment networks and regulators Limited; identity-linked records Available to institutions Mostly payment-level Dependent upon account access
Retail CBDC Central bank and designated intermediaries Entirely dependent upon design Potentially extensive Potentially extensive Entirely dependent upon custody model
Fiat-backed stablecoin Issuer, reserve custodian and contract administrator Pseudonymous ledger, often linked through gateways Often technically possible Strong application-level potential Keys may be held directly, but value depends upon issuer
Bitcoin Distributed protocol and network consensus Pseudonymous but publicly traceable Not at the protocol level Deliberately limited compared with general smart-contract platforms Strong when private keys are self-custodied
Privacy-preserving digital cash Varies by issuance model Designed to minimize transactional disclosure Dependent upon architecture Can be deliberately constrained Potentially strong

This comparison describes architectural tendencies, not unavoidable outcomes. A CBDC can be designed with privacy protections. A stablecoin can provide transparent reserves and limited administrative powers. A Bitcoin user can surrender control to a custodial exchange. Every system must be assessed according to its actual implementation.

Principles for a Sovereignty-Preserving CBDC

If a retail CBDC is developed, its legitimacy should depend upon more than monetary stability and technical performance. It should preserve the individual’s position within the payment system.

At minimum, a sovereignty-preserving design should include the following principles:

  1. Cash must remain available. A digital option should not immediately become a compulsory identity and surveillance infrastructure.
  2. Privacy must be architectural. Ordinary payments should not automatically become visible to a central authority merely because the technology makes collection possible.
  3. Data must be minimized. Institutions should collect only the information necessary for a defined function and retain it only for a defined period.
  4. Identity should not be universalized unnecessarily. The system should distinguish the validation of value from the disclosure of a person’s complete legal identity.
  5. Freezing and reversal require due process. Exceptional powers should be narrow, reviewable and visible through appropriate oversight.
  6. Issuer-directed programmability must be constrained. The currency should not become a general mechanism for controlling lawful personal behavior.
  7. Wallets and services should be interoperable. Individuals should not be trapped inside one governmental or corporate interface.
  8. Rules and technical standards should be open to examination. Public money should not depend upon an architecture the public is forbidden to understand.
  9. Offline and resilient use should be pursued. Economic participation should not disappear whenever connectivity or a central service fails.
  10. The right to exit must remain meaningful. People should retain lawful alternatives rather than becoming dependent upon one programmable monetary rail.

These safeguards should not be added after the monetary infrastructure is complete. They must shape its foundations.

Principles for Sovereignty-Preserving Stablecoins

Stablecoins require a related but distinct set of protections. Users should be able to understand what asset they hold and which promises support it.

Reserve composition, custody, redemption rights and significant risks should be disclosed clearly. Assets intended to secure redemption should be separated appropriately from the issuer’s own funds. Administrative keys and freezing functions should be documented rather than concealed behind the language of decentralization.

Users should be able to withdraw tokens to personally controlled wallets where technically and lawfully possible. Open standards should allow stablecoins to move among compatible services instead of becoming captive balances inside one platform.

Most importantly, no stablecoin issuer should be treated as infallible merely because its token maintains a stable price. Stability in the market does not prove solvency, sound governance, privacy or respect for user rights.

Applying the Cypherpunkist Test

The Cypherpunkist Test asks who a technology ultimately empowers. Applied to digital money, that inquiry can be expressed through twelve questions:

  1. Who issues the asset, and what obligation does the issuer owe the holder?
  2. Who controls the ledger on which ownership is recorded?
  3. Can the individual hold the asset through personally controlled cryptographic keys?
  4. Must every transaction be connected to a verified identity?
  5. Who can observe, analyze and retain the transaction history?
  6. Who can freeze, reverse or refuse a payment?
  7. Can the issuer change the monetary or technical rules unilaterally?
  8. Can spending conditions be imposed without the holder’s consent?
  9. Are the code, reserves and governance structure open to independent examination?
  10. Can competing wallets and services connect through open standards?
  11. Can an incorrect restriction be challenged through meaningful review?
  12. Can the individual exit without losing lawful access to money and economic participation?

No instrument will answer every question perfectly. The test reveals where trust resides, where coercion is possible and which freedoms depend upon promises rather than architecture.

The Choice Is Architectural

The debate over digital money is often presented as a competition among currencies: central-bank money against stablecoins, national currencies against Bitcoin or private innovation against public authority.

The deeper choice concerns architecture.

A public currency may preserve freedom if it minimizes surveillance, limits administrative power and protects open access. A privately issued stablecoin may expand choice while still concentrating control over reserves, redemption and permitted transactions. A decentralized asset may resist censorship at the protocol level while exposing users through a transparent ledger or custodial gateway.

The identity of the issuer matters, but it does not answer every question. Public institutions can abuse power. Private institutions can abuse power. Decentralized systems can produce their own concentrations and dependencies.

Cypherpunkism is therefore neither automatically pro-CBDC nor automatically anti-CBDC. It is neither automatically pro-stablecoin nor persuaded by every claim of decentralization. It asks whether the resulting monetary system preserves privacy, individual control, open architecture and meaningful alternatives.

Conclusion: Who Programs the Money?

Digital money can reduce costs, expand access and enable forms of economic coordination that physical instruments cannot support. Programmability can allow people to create transparent agreements, automate voluntary transactions and build new financial services.

It can also unite money, identity and institutional permission within a single system.

When every payment is observable, money becomes surveillance. When every balance can be disabled remotely, money becomes permission. When every unit carries restrictions imposed by its issuer, money becomes an instrument for programming human behavior.

The decisive question is not whether money will become digital. Much of it already has. Nor is it whether money will become programmable. That process has begun.

The decisive question is who will possess the authority to program it.

Programmable money should execute the choices of its owner—not silently impose the choices of its issuer.

A sovereign monetary future must allow innovation without constructing total visibility, coordination without permanent dependency and legitimate authority without unlimited financial control.

Privacy is sovereignty.

Cryptography is applied freedom.

Decentralization is a check on power.

Code is political architecture.

Digital sovereignty belongs to the individual.


References