Regulating Permissionless Blockchain: An Open Letter to the FCA (And Other Regulators)
Author
Angus Scott of the SRI
Published

On this page (29)
TL;DR
Public, permissionless blockchain protocols introduce a transformative paradigm for financial services by deploying open access, composability, rules-based governance, and comprehensive transparency at global scale. Far from being a simple story of operational efficiency, the combination of these features unleashes deep structural forces that redefine the delivery of finance—lowering barriers to entry, enhancing market inclusion, and dismantling the institutionalised rent extraction inherent in traditional, hierarchical infrastructure models.
This letter argues that realising those benefits requires a regulatory approach calibrated to what permissionless blockchain actually is, rather than one that forces it into the institutional and legal forms of traditional finance. Across seven regulatory domains, we identify where existing frameworks apply directly, where they require adaptation, and where targeted new legal infrastructure is needed.
Our key conclusions include:
- Sanctions and AML compliance at the infrastructure level is manageable through available technical tools; at the application level, a recognised on-chain credential scheme is the precondition — not merely a convenience — for regulated firm participation in DeFi, and must be developed as an international standard if it is to function in a stateless, borderless protocol environment.
- Permissionless protocols are not outsourcing arrangements: their public, continuously verifiable behaviour is in material respects a stronger assurance than a conventional contractual SLA, and should be recognised as such. Regulated firms should develop their own risk management frameworks for use of public chains, consistent with overall regulatory requirements regarding resilience. There is no case for mandating prescriptive standards with respect to network architecture, whether applied directly or indirectly.
- Interoperability across chains can and should be market-led. However, a legal framework to establish rights of cross-chain token holders would greatly strengthen the operational reality.
- Infrastructure providers such as wallets, and connectivity nodes are mere conduits and must not be regulated as financial intermediaries. Protocol-locked assets, including delegated staked assets, carry a fundamentally different risk profile from custodied assets and require a framework based on technical due diligence rather than the discretionary-control model.
- MEV is being addressed by market-led structural innovation faster than conduct regulation ever addressed its traditional finance equivalents.
- Open access networks present fundamentally different systemic risk environments compared to traditional, hierarchical systems. This presents both challenges and opportunities for regulators, and their approach to systemic risk management should adapt accordingly
- The Basel Committee's 1250% risk weight on permissionless blockchain assets — a de facto prohibition — should be revisited in light of the rapid development of technical mitigants that speak directly to the risks it was designed to address.
The asks we make are narrow, grounded in existing law, and designed to evolve the regulatory machinery rather than replace it.
Dear FCA,
This letter sets out the views of the Solana Research Institute on the regulation of financial services on permissionless blockchain.
Permissionless blockchain protocols challenge many assumptions about how finance works. Used correctly, they could improve access, reduce cost and risk, and address long-standing weaknesses in the financial system in areas such as conduct of business and financial inclusion. These benefits, however, come with risks. Finance and technology can both be complex, difficult to understand, and give rise to externalities, where people can be harmed by activities in which they play no part. Combined in new ways, challenges can multiply.
We are not, therefore, dismissing the need for regulation and indeed we believe that in some cases public blockchains help achieve the policy objectives underpinning regulation better than the opaque structures used in traditional finance. However, there is a real danger that policymakers discard the transformative potential offered by public blockchain through misunderstanding the true nature of distributed systems and rigidly applying frameworks designed for the very different environment of traditional finance.
In this letter, we address that danger. We start by setting out what we believe to be the true benefits of permissionless blockchain protocols like Solana, focussing on the deeper and more disruptive forces unleashed by the dramatic falls in the costs of access, product development, operation, and governance enabled by blockchain. We then examine seven areas of regulatory policy impacted by blockchain, identifying the underlying policy objectives and looking at how these may be impacted by and reconciled with the use of permissionless infrastructure. We fully recognise that there are many perspectives on the issues we raise, and that other issues will arise that we have not yet considered. We therefore do not pretend that this document is the last word on anything, but rather a contribution to an evolving conversation, and welcome comment, feedback, and further discussion.
The origins of this letter lie in conversations held with representatives of the UK's Financial Conduct Authority and the Solana Foundation on the FCA's broad approach to crypto regulations earlier in 2026. For this reason, we address it to the FCA and refer in certain places to UK-specific circumstances. However, the themes we address are not confined to the specific responsibilities of the FCA — many fall under the remit of the Prudential Regulatory Authority — or even to the UK. They are relevant in every jurisdiction attempting to reconcile long-standing principles of financial regulation with the brave new world of blockchain and we therefore hope that our discussion resonates with regulators and finance professionals everywhere.
A note on terminology. In this letter, we are primarily concerned with public, permissionless blockchain protocols, and when we use terms like "blockchain" or "crypto" it is to these systems that we are referring, unless we state otherwise. When we use terms like "traditional finance" we mean the existing financial system operating on conventional centralised infrastructure.
Part 1: The Unique Benefits of Public, Permissionless Blockchain
People in traditional finance often take a narrowly operational view of blockchain, evaluating it in terms of its ability to drive operational efficiency through better data management. For example, in its recent consultation on tokenisation, the Central Bank of Ireland classified blockchain as an example of Distributed Ledger Technology (DLT), which it defined as a "technological solution that achieves a single, shared 'source of truth' through a common ledger…to replace multiple independent ledgers with a synchronised digital record, in which transaction data are shared, validated, and replicated across a network of distributed nodes."
While technically accurate, definitions of this kind lack the resolution required to understand what makes blockchain genuinely distinctive.
First, DLT is not unique in achieving a shared source of truth: traditional transaction processing systems do this too. It is true that in traditional systems there is no single record shared by all participants, but this is because each participant only needs to ensure that its own records — built from the messages it exchanges with a central provider — match those of the centre: transactions to which it is not a counterparty are irrelevant to it. Arguably, this is a more efficient structure than a DLT-based system, since transaction messages are sent point-to-point rather than broadcast across a network, and reconciliations require only bilateral, not multilateral, consensus.
Second, although many treat "a shared source of truth" as the holy grail of financial operations, the multiple, conflicting stores of data that plague many firms and give rise to reconciliation costs and operational risk result from internal system architectures which must serve the requirements of many different users that overlap but are not identical.
Consider corporate actions for example. Front and middle office users require feeds covering the entire asset universe in which a bank trades, but are concerned only with economic variables that create trading opportunities and or impact the value of synthetic positions. Custodians, by contrast, need detailed operational data such as election deadlines, client votes and payment details, but only on the narrower set of stocks they currently hold. These differences in requirements feed through to the data architectures of the systems supporting each business line. It is simply not credible to envisage a future in which the entire system runs on a single platform.
In practice, we can expect incremental improvements in data management efficiency within the traditional system as banks and incumbent infrastructure providers deploy better technology and invest in improved workflow and automation. Some of these improvements may utilise cryptography or other techniques associated with DLT; the technology boundary between "DLT" and other systems is already fluid. Byzantine Fault Tolerance techniques used in DLT protocols, for example, have also been deployed in traditional distributed systems predating DLT. However, technology improvements that occur within the existing closed and exclusive structure of the financial system remain a matter for incumbents, and do not call for specific regulatory engagement beyond that already provided by existing operational risk management frameworks.
Third, many benefits commonly attributed to DLT — such as instant settlement — are not unique capabilities of the technology, but rather the result of implicit choices about market structure. It would, for example, be possible to deliver simultaneous trading and settlement using traditional technology, albeit at the cost of gross settlement and significant additional liquidity demands, which, incidentally, exist in many onchain marketplaces that trade and settle on the same instruction and so are unable to benefit from settlement netting.
So, if blockchain is not primarily an efficiency story, what is its true benefit? The technology offers four features that have not previously been available in combination and at scale, and it is their combination that creates its transformative potential. The features are:
- Open access for both users and application developers;
- Composability: all functionality is open-source and available to be re-used by others building on the network;
- Decentralised, rules-based governance, in which protocol behaviour is determined by code rather than institutional discretion;
- Comprehensive transparency, which exposes the system's workings — including its weaknesses and vulnerabilities — to scrutiny by all who choose to examine it.
These features can unlock deep structural economic forces that deliver not just efficiency gains, but a step change in the economic welfare created by financial services. They can exist up to a point on closed, permissioned networks, but their transformative potential is only fully realised when deployed on open, permissionless networks — and it is on these configurations that we focus. Some illustrative examples:
Open access makes robust, consistent transaction verification available on demand and, in the case of networks such as Solana, at extremely low cost. It also makes the use of credit intermediaries and custodians optional. These two factors have the potential to commoditise access to financial services, forcing service providers to move higher up the value chain if they are to win and retain customer business.
Composability radically reduces the cost of new product and service development. Common functions can be deployed across thousands of applications and use cases, spreading development costs and dramatically reducing time to market. A significant proportion of the functionality required to launch a financial institution operating with tokenised assets is already pre-deployed and available for free on Solana — including liability management, payments infrastructure, compliance functionality, trading operations and credit distribution interfaces. Of course, deploying this functionality gives rise to integration costs and there are myriad non-technology requirements that need to be met when bringing financial services to market, but the economics of new market entry have changed fundamentally. This is not a theoretical observation: a real world case study is Altitude.xyz, developed by Squads to offer bank-like services to deposits held in either stablecoin or onchain money market funds.
Composability also enables hyperpersonalisation, where product design and implementation can redefine how savers access investment products, supported by low transaction fees that fundamentally change the economics of scale within the financial system.
Decentralised, rules-based governance changes the approach to conduct of business. Services governed by smart contracts do precisely what their code specifies: there is no management discretion, significantly less scope for operational error, and complete transparency of execution.
Comprehensive transparency enables a new approach to risk management, in which vulnerabilities can be identified and addressed publicly rather than concealed, errors can be learned from, and structural weaknesses can be tackled by the market itself. The response to the Drift Protocol incident provides a good example. One of the enablers of the hack was the small size of the group of individuals which held signing authority within the DAO governance structure, making it vulnerable to social engineering. This structural weakness was identified publicly and is informing revisions to best practices around the size and composition of delegate sets that authorise decision-making in DAOs.
In other words, the combination of open access, composability, decentralised governance, and comprehensive transparency mobilises creative forces that can transform the way the financial system serves its end users. This is not to say that these forces will not give rise to challenges of their own — some of which may be significant. But it is our contention that a regulatory approach designed to harness these forces will deliver substantially higher welfare gains than one that seeks to constrain them in the name of preserving the status quo. In the remainder of this paper we sketch out what this might mean in practice.
Part 2: Reconciling Blockchain and Regulatory Policy
In this section, we look at how a regulatory approach based on encouraging openness, composability, decentralisation, and transparency might operate with respect to seven areas of priority for policy makers:
- Identity and access control
- Managing resilience
- Interoperability
- Custody and asset control
- Market structure and abuse
- Market infrastructure and systemic risk
- Prudential capital
For each area we start by summarising our understanding of the underlying policy objectives. We then look at how blockchain impacts those objectives, seeking to distinguish genuine challenges from those we believe to be artefacts of thinking rooted in traditional financial practice. Where we believe genuine gaps exist, we suggest ways that these could be addressed which preserve rather than suppress the transformational potential of open systems.
1. Identity and Access Control
Regulators expect financial institutions to validate the identity of their clients and counterparties for two distinct reasons: to prevent the financial system being used to support criminal or terrorist activity; and to ensure that services offered are appropriate to the needs, objectives and risk appetite of the client. However, while the rationale and legal basis for each objective is different, their operational impact is similar and in both cases requires consideration of both infrastructure operations and applications running on the infrastructure.
Infrastructure level
Under the Sanctions and Anti-Money Laundering Act 2018 (SAMLA), UK-based entities are prohibited from dealing with or making funds or economic resources available, directly or indirectly, to a "designated person"; and from engaging in actions that directly or indirectly circumvent financial sanctions prohibitions.
Permissionless blockchains rely on independent nodes to validate transactions and arrange them into blocks. Anyone can join a protocol as a validator, and this raises the possibility that a regulated financial institution transacting on a public network may interact with, and pay fees to, a validator which is a designated person under SAMLA.
The open participation framework and the constant rotation of leaders means that traditional approaches to vendor due diligence are inappropriate with respect to blockchain validators. However, tools are available on Solana that mitigate the risk of dealing with a sanctioned entity. Providers such as Helius and Triton One offer services which allow users to maintain allow-lists or block-lists of nodes to and from whom they are prepared to send or receive transactions, enabling them to choose to which entities they pay direct fees and filter out those of whose identity they are uncertain or that engage in other forms of abusive behaviour. There is a latency trade-off in the use of such tools, since blocks prepared by screened-out leaders are skipped. Nevertheless, we believe such tools offer a practical method of complying with sanctions legislation and regulators should recognise this. The sanctions risk at the infrastructure level is, in other words, manageable — and it is a risk that attaches to the identities of specific validators, not to the permissionless character of the protocol itself.
Application level
At the application level the two objectives converge on the same practical problem: a regulated firm transacting on a permissionless protocol has no visibility into the identity of its counterparties unless an identity layer exists on top of the protocol. This creates two connected issues. First, firms within the regulatory perimeter need tools to manage customer access to their own on-chain services efficiently, while giving users control over their own data. Second, they need a mechanism to manage counterparty identity when using protocols that, being permissionless, lack both a contracting entity and a base jurisdiction. The two issues are related but not identical, and they call for different treatment.
Access management for a firm's own on-chain services
Regulated businesses deploying on-chain services, including token mints and exchanges, can in principle manage their CDD obligations by conventional means, since they control the access point to their own service. On-chain composability makes this comparatively straightforward in many cases. For example, the Token-2022 programme on Solana offers pre-deployed functions, callable at run time, including allow-lists and block-lists, tools for information sharing during transactions, and delegation functions that allow authorised parties to take control of a token mint during specified off-chain events. These tools can support both AML and suitability objectives.
A more powerful model, and one we believe regulators should facilitate, would allow credentials to be issued by licensed identity providers using zero-knowledge proofs to verify identity, sanctions status, and suitability without requiring users to sacrifice anonymity or surrender control of their data. A user would hold and present a verified credential at the application layer rather than submitting to bespoke onboarding by each service provider. This would simplify compliance for firms across both AML and suitability dimensions, preserve user agency, and directly address the challenge of risk-assessing non-custodial wallet addresses prior to transfers under the 2023 amendments to the Money Laundering Regulations.
The current regulatory framework does not accommodate this model. Regulation 39 of the Money Laundering Regulations permits regulated entities to rely on third-party customer due diligence, but requires those third parties to be themselves regulated, to agree in writing to produce underlying documentation on request, and leaves full compliance liability with the outsourcing firm. This framework was designed for bilateral reliance relationships, not for a reusable credential presented across multiple counterparties and venues.
The UK's Digital Verification Services Trust Framework offers a more suitable basis. The "UK CertifID" trust mark and statutory register of certified providers, due to come into force on or after 1 September 2026, will certify Identity, Attribute, Orchestration, Holder and Component service providers against a common standard. Crucially, the Holder service role is built explicitly around the idea of an individual holding and presenting their own verified credential repeatedly, rather than each relying party going back to source.
We believe regulators should extend this framework to financial services, by defining the conditions under which a credential issued by a certified provider — including one presented cryptographically from a wallet — satisfies Regulation 39 for cryptoasset business customer due diligence, with the "documentation on request" condition met by the certified provider's retained records. Alongside this, the government should provide that a regulated firm relying in good faith on a credential issued under an approved scheme is not liable where that reliance inadvertently results in a breach of the Regulations.
The case for this safe harbour is stronger than in conventional reliance arrangements: a firm relying on a DVS-certified credential is doing more than existing practice requires, and the forensic transparency of on-chain transactions — traceable with a precision unavailable in conventional markets — provides a trust environment in which fraud or evasion is materially harder to sustain and easier to detect after the fact.
Counterparty identity in permissionless DeFi
Participation in DeFi protocols, as distinct from operating a firm's own on-chain service, raises a different problem. SAMLA 2018 prohibits regulated firms from dealing with designated persons. A permissionless protocol imposes no access controls and offers no mechanism for a participant to verify the identity of its counterparties, because the firm is not the gating party and exercises no control over who else transacts on the protocol. In fact, the US courts have gone further in the Tornado Cash case, and established that a protocol is not property, has no legal personality and cannot be held liable for the uses to which it is put.
This puts the ball firmly in the court of the users. In the absence of an identity layer embedded in the protocol's own rules, a regulated firm cannot know whether it is transacting with a designated person and therefore cannot demonstrate SAMLA compliance. This is not a theoretical concern: it is a structural feature of permissionless infrastructure that, unaddressed, places participation in DeFi protocols outside the reach of regulated firms entirely.
Given this, the credential scheme we outline above is not merely a convenience — it is the precondition. A permissionless DeFi protocol that incorporated credential verification into its access rules would, for the first time, offer regulated firms a compliant on-chain environment: one in which counterparty identity, sanctions status, and suitability would all have been attested before any transaction executes. Regulated firms that cannot currently participate in DeFi without breaching SAMLA would be able to do so. DeFi protocols that incorporate the standard would gain access to institutional liquidity presently unavailable to them. The result would be a material expansion of the market — new participants, new sources of competition, and new services for users — delivered not by regulatory direction but by the commercial logic that a workable compliance framework makes possible.
For this to work in practice, the credential standard must be international. Permissionless protocols are stateless: they have no base jurisdiction, are not subject to domestic law, and operate identically for all participants regardless of where those participants are located. A credential scheme recognised only in the UK cannot be adopted by a protocol whose participants span multiple jurisdictions, and a UK-regulated firm transacting on such a protocol needs its counterparty's credential to carry meaning regardless of that counterparty's domicile. The DVS Trust Framework therefore provides a domestic foundation, but its value as an enabler of DeFi participation depends on its development into, or alignment with, an internationally recognised standard. We urge the FCA and PRA to engage with IOSCO, the FSB, and relevant industry bodies to advance this objective alongside the domestic framework design, and to engage with industry on defining the parameters of both as a matter of priority.
Access and infrastructure
The Tornado Cash case establishes that protocols with no legal personality cannot be held liable for business conducted using them. However, blockchain systems also rely on more traditional infrastructure providers to manage and transport data, such as non-custodial wallet software providers and RPC nodes.
These providers are equivalent to the infrastructure operators that underpin conventional financial markets and, more broadly, the internet and telecommunications networks on which all modern commerce depends. A non-custodial wallet constructs and signs transactions at the user's direction; an RPC node routes transaction data between a user and the network. Neither has knowledge of the user's identity, financial position, or the purpose or terms of any transaction. They are, in the language of Electronic Commerce Regulation, "mere conduits". The same principle that exempts telephone networks from liability for calls made to arrange fraud, or internet service providers from liability for websites hosted on their infrastructure, applies here. Liability for how a service is used cannot rest with a provider that has no knowledge of, and no control over, that use.
The regulatory consequences follow directly. Infrastructure services such as non-custodial wallet providers and RPC nodes are not cryptoasset businesses or financial intermediaries and should not be treated as such. They should not be required to perform customer due diligence, suitability assessments, or sanctions screening on their users. Imposing such obligations would impose compliance costs that fall disproportionately on open-source and non-commercial providers, fragment the infrastructure layer along jurisdictional lines, and ultimately make permissionless blockchain less accessible to legitimate users while doing nothing to impede those with illicit intent, who would simply route around any such requirement.
We urge the FCA, along with the PRA, to establish an explicit safe harbour for infrastructure services, and confirm explicitly that they fall outside the regulatory perimeter for cryptoasset business and have no obligation to perform customer due diligence, suitability assessment, or sanctions screening. A regulatory framework that imposes service-provider obligations on infrastructure operators does not protect users from the risks of permissionless finance. It denies them access to it.
2. Managing Resilience
Regulators focus on resilience because major service outages can harm service users in ways ranging from inconvenient to devastating and can produce systemic consequences affecting firms and people far removed from the immediate failure. This section focuses on the dimension most directly affected by the use of permissionless infrastructure: the management of external service dependencies.
The UK's operational resilience framework addresses external dependencies through three distinct tiers. The outsourcing regime, implemented in Chapter 8 of the Senior Management Arrangements, Systems and Controls sourcebook (SYSC 8), places direct obligations on firms entering into arrangements with external service providers, including requirements for written contracts, audit and information rights, business continuity provisions, and, in some cases, advance regulatory notification. The firm-level operational resilience regime, introduced in Policy Statement 21/3 (PS21/3) and implemented in SYSC 15A, requires firms to identify their important business services, set impact tolerances, map all resource dependencies, including third parties, and test their ability to remain within those tolerances under severe but plausible disruption scenarios. The Critical Third Parties (CTP) regime, introduced under Financial Services and Markets Act 2023 and finalised in PS16/24, extends direct regulatory oversight to non-financial entities whose failure could threaten financial stability across multiple firms.
All three tiers rest on the assumption that there is an identifiable legal entity with which a regulated firm can form a contractual relationship. Permissionless blockchain protocols break that assumption at the foundation.
The outsourcing regime
In Consultation Paper 25/25 (CP25/25), the FCA proposes that use of permissionless blockchain protocols by cryptoasset firms should not be treated as an outsourcing arrangement for the purposes of SYSC 8. We fully support this position.
Outsourcing regulation rests on the fact that a firm delegating a function to a third party needs contractual mechanisms such as service level commitments, audit rights, exit provisions, and financial penalties to maintain effective oversight of a relationship it can no longer govern through direct operational control. Those mechanisms are unavailable for a permissionless protocol because no counterparty exists to be bound by them. But the rationale for the carve-out goes beyond mere practicality. A permissionless protocol itself provides, natively and by design, what a conventional SLA is trying to approximate.
A traditional vendor SLA is a private, negotiated description of expected behaviour, subject to the vendor's own reporting and enforceable only ex-post. A permissionless protocol is a public, non-negotiable, continuously verifiable specification of actual behaviour, observable by anyone in real time with no contract required. The protocol rules define with complete precision how the system is expected to operate; the chain's public record provides continuous, complete, independently verifiable data on how it has operated in practice. In several material respects, this is a stronger assurance than that provided by a contractual SLA.
It is true that financial penalties cannot be enforced against a protocol if it experiences operational degradation. But the validators on a public network bear direct financial losses during any halt because of foregone block rewards and staking yields that accumulate on a per-slot basis for the duration of the disruption. These losses create immediate, continuous, and self-scaling restoration incentives that are stronger and more direct than the capped, negotiated, post-hoc penalties that characterise conventional SLAs. Protocols that enforce slashing add a further layer of financial discipline to participants. Moreover, in practice, contractual penalties are not available against the most systemically important financial infrastructures, which benefit from statutory or rulebook immunity frameworks that make practical recovery of damages from outage losses either impossible or so attenuated from actual loss as to be commercially meaningless.
We note two respects in which the proposed carve-out from SYSC 8 requires clarification.
First, the disapplication of SYSC 8 is currently scoped to firms carrying on "qualifying cryptoasset activities" as defined in the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. This means it may not extend to other regulated firms using permissionless blockchain in their core operations — for example, a bank using a public chain to settle payment obligations or a fund administrator using on-chain records for NAV calculation. There is no principled basis for treating such firms differently from cryptoasset firms. We assume this is an unintended consequence of scoping the consultation to the new cryptoasset perimeter rather than a deliberate policy choice, and we would ask the FCA to confirm that the disapplication extends to the use of permissionless blockchain by any regulated firm, regardless of whether the relevant activity is a qualifying cryptoasset activity.
Second, there is ambiguity as to whether "permissionless blockchain protocols" in this context refers exclusively to layer one protocols or also encompasses other protocol-based services deployed on a permissionless chain, such as liquid staking protocols, decentralised exchanges, and collateral management protocols. The functional characteristics that justify the carve-out — no contractable counterparty, complete public visibility of code and operational performance — apply with equal force to these services. We believe that the disapplication should extend to any service where those characteristics are present, rather than limiting it to the base layer by implication.
The operational resilience framework
The SYSC 8 carve-out addresses whether a permissionless protocol dependency is an outsourcing arrangement. It does not address the separate question of how a firm using such infrastructure should satisfy the positive obligations under SYSC 15A: in particular, how it should construct the severe but plausible scenarios against which it must test its ability to remain within impact tolerance for any important business service that depends on permissionless infrastructure.
For a firm using a permissionless blockchain as a component of an important business service, this exercise is structurally more complex than its traditional equivalent. The determinants of network availability and liveness are not concentrated in a single provider; they are distributed across multiple interacting layers, each of which contributes independently to the probability and character of a disruption. At a minimum, a rigorous scenario construction would need to integrate:
- Protocol-layer characteristics: consensus mechanism design, finality model, the conditions under which block production degrades or halts, and network recovery procedures.
- Network composition: validator concentration by controlling entity, geography, data centre provider and node software client, and the physical topology of the network, both of which may influence the network's ability to maintain block production in stressed conditions.
- Application and smart contract layer: the operational profile of the services the firm relies on, including the code base of the smart contracts that underpin those services, upgrade and governance arrangements, the existence and operational testing of emergency pause or freeze mechanisms, dependency on external data sources such as price oracles, and the potential for application-layer failure to cause service disruption or asset loss independently of any consensus-layer event.
- The firm's own access architecture: its number and diversity of RPC providers, its approach to key management, and its own connectivity redundancy — recognising that two firms using the same network may face materially different risk profiles depending on their own infrastructure choices.
We note that CP25/25 does not attempt to define prescriptive severity thresholds for permissionless network dependency. We agree with that instinct: a fixed standard would simultaneously risk creating a false floor for firms with concentrated infrastructure exposure and imposing a disproportionate burden on firms that have demonstrably lower risk through their architecture choices.
What is needed instead are structured resilience assessment methodologies specific to permissionless networks. These should not be based on prescribed scenarios but rather provide documented analytical frameworks that a firm applies to its own specific circumstances to derive scenarios calibrated to the actual risk profile of the protocols it uses and its own service and technical architectures. It may not be for the FCA to develop such a framework itself, but it would be helpful if firms that used one were confident that their efforts would be recognised by the regulator.
There may also be scope to develop new infrastructure services that support business continuity — for example, a robust legal framework for bridging from a regulated firm's position on a primary chain to an alternative chain or off-chain record keeping system in the event of a severe outage on the primary chain, which may help reduce the impact on the regulated firm's liquidity. The tooling for such services already exists — Helius's data streaming product, LaserStream, has historical replay and backfilling, so users can pick up streaming from where they left off after an outage for example. However, the legal structure to support a formalised service is still lacking. We believe such initiatives should be market-led, but that the FCA should support and promote them, both conceptually and practically.
More broadly, regulators should resist the temptation to impose minimum technical standards on permissionless networks themselves — whether directly, or indirectly through requirements on regulated firms that effectively mandate a particular network architecture. Prescribing thresholds for validator concentration, client software diversity, or geographic distribution may appear to address resilience risk, but would in practice freeze network architecture at a point in time, penalise open networks whose characteristics are determined by decentralised participation rather than operator design, and displace the market and governance mechanisms that are already driving network improvements from the outside. A regulated firm that has conducted rigorous, documented scenario analysis calibrated to the actual characteristics of the network it uses is in a stronger risk management position than one that has mechanically verified compliance with a prescribed standard. The former produces genuine understanding of risk; the latter produces a checklist. Regulatory energy in this area is better directed at the quality of firms' own analysis than at the technical properties of the networks they analyse.
3. Interoperability
The traditional financial system has been plagued by silos which segment the world along geographical and product lines. As the financial world contemplates reinventing itself on blockchain, there is a natural desire to avoid recreating silos on a new infrastructure. The proliferation of layer one and layer two protocols has led to calls for regulator-driven interoperability standards as the solution. We believe this is unnecessary.
The case for market-led interoperability
Market-led solutions are emerging via two mechanisms. The first is technical competition. LayerZero provides generalised cross-chain messaging across more than 160 otherwise incompatible networks. Competing protocols — including Wormhole Lab's Sunrise, NEAR Intent, and Circle's Cross-Chain Transfer Protocol — offer alternative technical architectures and trust models, serving different use cases with different risk and latency profiles. This is not fragmentation: it is productive competition between approaches. Critically, market-led solutions have demonstrated an ability to iterate that no standards body can match: LayerZero's second version materially strengthened the trust assumptions of its first, addressing structural vulnerabilities identified through public scrutiny — a direct manifestation of the transparent, open development dynamic we described in Part 1 as one of blockchain's core structural advantages.
We therefore believe that regulators should resist the temptation to mandate technical interoperability standards and should instead allow the competitive market in cross-chain infrastructure to continue to develop. The FCA's role in this area should be to monitor the systemic implications of any concentration in critical bridging infrastructure — a matter we return to under Market Infrastructure and Systemic Risk — rather than to prescribe the technical means by which interoperability is achieved.
The second mechanism is industry-led collaboration. The Global Blockchain Business Council's Global Standards Mapping Initiative is the most comprehensive existing effort to map and analyse standards across the digital asset ecosystem, and Global Digital Finance has published a taxonomy for cryptographic assets and actively called for convergence on common definitional standards. We encourage the FCA, in conjunction with international regulatory colleagues, to engage with and lend regulatory weight to these initiatives rather than seeking to originate or direct this work itself.
Legal clarity for bridged instruments
There is one area where market mechanisms cannot provide clarity, because the problem is not one of coordination but of law: the legal status of bridged instruments. When a token issued on one chain is bridged to another, questions arise, such as what is the nature of the claim held by the owner of the bridged asset, and against whom does it lie? In the event of insolvency of a bridge operator, where do token holders sit in the creditor hierarchy? Which jurisdiction's law governs disputes?
What is needed is a legal recognition framework that clearly establishes the criteria a bridging arrangement must satisfy in order for the bridged token to be treated as inheriting the legal rights of the native token. We are not arguing for bridging services to be brought within the regulatory perimeter; the question we are raising is what conditions a bridging arrangement must satisfy for the rights of token holders to be legally enforceable. This approach preserves the technical openness we have argued for above while addressing a genuine gap that only law can fill. It is analogous in structure to the approach we describe under Identity and Access Control, where we argue for a legal recognition framework for on-chain credentials rather than a prescriptive technical mandate for how identity verification must be carried out.
4. Custody and Asset Control
Regulators focus on custody because the separation of asset ownership from asset control creates risks that markets alone cannot fully discipline: misappropriation, commingling, unauthorised disposal, and the conflicts of interest that arise when a custodian's interests diverge from those of the asset owner. Under the Cryptoasset Regulations, cryptoasset custody is within the regulatory perimeter, and we support that position in cases where an identifiable operator holds assets on behalf of clients and exercises discretionary control over them.
However, we believe that a materially different framework is required for assets locked in on-chain protocols, a class of arrangement that has no direct equivalent in traditional finance.
Delegated staking
We submitted a response to CP25/25 in which we argued that delegated staking at the layer one level should be exempt from custody regulation, and we restate that position here. The assets delegated to a validator cannot be misappropriated — they remain under the control of the delegator's private key and can only be deployed according to protocol rules. The relevant risks — validator slashing, network outage, client software failure — are categorically different from custody risks and are already addressed through the resilience framework discussed above. Treating delegated staking as custody would impose compliance costs and capital requirements on an arrangement that does not share the risk profile that those requirements exist to address, and would place UK-regulated firms at a material disadvantage relative to competitors in jurisdictions that have taken a more proportionate approach.
Other protocol-locked arrangements
Beyond layer one staking, a wide and growing range of on-chain arrangements share the essential characteristic that distinguishes delegated staking from custody: the absence of operator discretion. Liquid staking protocols, bridging arrangements, and on-chain collateral management systems all operate on the same principle — assets can only be deployed and redeemed according to rules encoded in the protocol itself. There is no management decision to misappropriate, no operational error that redirects assets, and no custodian whose interests might conflict with those of the asset owner.
We believe that regulated firms should be able to use such arrangements, even where there is no identifiable legal person capable of being regulated, subject to appropriate technical and governance due diligence. Such due diligence should address at minimum: the results of independent smart contract audits and the scope and methodology of those audits; the nature and provenance of any external data sources, such as price oracles on which the protocol depends; the existence, scope, and governance of any administrative override or upgrade mechanisms; and the protocol's track record, including prior incidents and the response to them. The FCA's forthcoming DLT guidance provides a natural vehicle for setting out what such due diligence should cover.
We note finally that several elements of the traditional custody framework have limited purchase in the context of protocol-locked assets and should not be applied by extension. Prudential capital requirements exist to absorb operational losses in entities with balance sheets, discretionary management, and creditors. None of those conditions obtain in a DAO or a fully decentralised protocol, and applying capital requirements to such structures would be conceptually incoherent and practically harmful. Similarly, conduct rules premised on the existence of a discretionary manager acting on client instructions have limited application where protocol behaviour is fully determined by code. The regulatory energy that would be consumed in attempting to apply these elements of the custody framework to protocol-locked arrangements would be better directed at the technical due diligence and disclosure requirements we have described above.
5. Market Structure and Abuse
Regulators address market abuse because asymmetric access to information and the power to control transaction flow create opportunities for rent extraction at the expense of other market participants. The policy objectives — deterring manipulation, ensuring price formation reflects genuine supply and demand, and protecting market users from structural exploitation by intermediaries — apply with equal force whether markets operate on traditional or blockchain infrastructure. The mechanisms, however, differ enough to require careful analysis before concluding that existing frameworks map cleanly onto DeFi.
MEV as structural rent extraction
Participants in DeFi markets have suffered from a form of value extraction that, while novel in its technical implementation, is recognisable in structure to students of traditional market microstructure. Maximum Extractable Value — the value that block leaders can capture, directly or indirectly, from their temporary monopoly on selecting and ordering the transactions included in a block — is the latest evolutionary form of a much older struggle over who controls transaction sequencing, information flow, and market infrastructure.
The mechanisms of MEV differ from traditional finance analogues, but the economic logic is the same. On the NYSE, specialists saw incoming order flow before the wider market, managed the auction process, and simultaneously traded for their own account: their informational advantages, combined with their transaction ordering rights, gave them a structural edge over other participants that bore no necessary relationship to the value of the liquidity provision service they formally provided. In London, the SEAQ regime allowed dealers to delay reporting large trades while warehousing inventory, and the old account settlement system — which netted all trades accumulated over a two-week period — gave brokers significant discretion to sequence client trades and allocate fills in ways that benefited their own book. In both cases, the formal justification was market function. The economic reality was rent extraction enabled by positional privilege.
MEV operates through an analogous mechanism at the protocol layer. Block leaders exploit the combination of pre-execution transaction visibility, the determinism of automated on-chain trading, and the periodic settlement rhythm of blockchains to insert transactions that either anticipate or respond to price movements caused by user trades. Sandwich attacks, where a searcher inserts buy and sell orders around a user's pending AMM trade to capture the price impact at that user's expense, are structurally equivalent to the front-running practices that regulators spent decades attempting to eradicate from traditional markets. Liquidation sniping and mint prioritisation share the same essential feature: a participant with privileged visibility over pending transaction flow uses that visibility to extract value from users who lack it.
The pro-MEV argument is that it rewards validators, incentivises node operation, and that atomic arbitrage reduces price discrepancies across complex trading environments. This mirrors the arguments historically advanced in defence of specialist and dealer privileges. The counter-argument is equally familiar: where rent extraction is enabled by structural position rather than earned by genuine service, it widens effective spreads, reduces market efficiency, and degrades the quality of price signals available to all participants.
Regulators in the United States and Europe spent the better part of three decades attempting to address these dynamics in traditional markets through initiatives such as decimalization, Regulation NMS, MiFID, and the shift to electronic central limit order books. The results were partial at best, dismantling many traditional monopolies without eliminating rent extraction. Instead, they transformed its technological basis: from floor specialists and interdealer broker networks to co-located servers, proprietary data feeds, and high-frequency execution infrastructure. Post-crisis clearing reforms repeated the pattern, transferring the gatekeeper role from exchange members to CCP members, who exploit their position in structurally equivalent ways — collecting margin on gross client positions while netting internally, and benefiting from the information revealed by the client flow they clear. The lesson is not that rent extraction is immovable, but that it is adaptive: structural privilege migrates rather than disappears when confronted with regulatory intervention that dismantles a particular mechanism without addressing the underlying informational and positional asymmetries.
The market's response: two paths
What distinguishes the blockchain environment from the equivalent arc of traditional market history is the speed and transparency with which the market is developing responses, and the availability of mechanisms that act on root causes rather than merely symptoms.
Two distinct paths are emerging simultaneously. The first is transparent value capture through competitive auction. Mechanisms such as Jito's MEV auction on Solana allow searchers to bid competitively for the right to exploit ordering opportunities, with proceeds flowing to validators and stakers rather than accruing silently to whoever controls the block. This does not eliminate MEV, but it routes its capture through a market mechanism, makes it legible, and distributes its proceeds more broadly. The analogy in traditional markets is the gradual shift from opaque payment for order flow arrangements toward lit exchange competition with explicit, disclosed execution quality metrics: transparency directs opportunities to those that value them most, which in itself improves efficiency.
The second path seeks to reduce MEV structurally by eliminating the conditions that produce it. The Anza-led Multiple Concurrent Proposers initiative on Solana would remove the single block leader's exclusive ordering rights by enabling concurrent block proposals from multiple validators simultaneously, addressing MEV at its architectural root rather than at the level of individual exploit mitigation. If successfully implemented, it would eliminate the single-leader bottleneck that makes sandwich attacks structurally possible — solving through protocol architecture what traditional finance tried and largely failed to solve through regulation applied to market participants.
These initiatives are compressing into a few years market structure evolutions that occupied a generation in traditional markets and remain incomplete after decades of sustained regulatory effort.
Regulatory implications
The appropriate response is therefore not to impose prescriptive conduct rules calibrated to the current state of the technology, which would risk locking in a market structure still in rapid and productive evolution. Two more targeted interventions are warranted instead.
First, the FCA should issue guidance on how existing market abuse prohibitions under MAR apply to block-producer conduct in DeFi contexts. The substantive conduct — front-running, transaction manipulation, exploitation of privileged order-flow visibility — falls squarely within the mischief that MAR was designed to address. Clarity on how those prohibitions map onto the technical mechanics of MEV would provide regulatory certainty for market participants without requiring new primary legislation or freezing the current technical architecture.
Second, the FCA should monitor and engage with the market-led structural initiatives described above, recognising that MCP and equivalent proposals, if successful, would achieve through protocol design what decades of conduct regulation in traditional markets could not. A regulatory framework that actively supports and recognises such developments — rather than treating them with suspicion because they lack a conventional regulated entity at their centre — will deliver substantially better outcomes for market users than one that attempts to replicate the traditional conduct toolkit in a structurally different environment.
6. Market Infrastructure and Systemic Risk
Regulators focus on market infrastructure because the concentration of critical functions — settlement, clearing, custody, price formation — in a small number of systemically important entities creates failure modes whose consequences extend far beyond the immediate participants. The policy objectives are to ensure that critical infrastructure is resilient, that its failure does not propagate across the financial system, and that systemic risk is visible and manageable before it crystallises. These objectives are unchanged on permissionless blockchain. The infrastructure, however, looks fundamentally different — and that difference cuts in both directions.
A different infrastructure architecture
In traditional finance, market infrastructure is a distinct and identifiable layer: exchanges, CCPs, CSDs and payment systems occupy defined positions in a hierarchical transaction stack, each with a recognised legal status, a regulatory designation, and a concentrated role in the processing of trades. The systemic importance of these entities derives precisely from that concentration: when a CCP or CSD fails, the consequences are catastrophic because there is no alternative path through which the functions it performs can be delivered.
On a composable public blockchain, this architecture does not exist in the same form. A token smart contract on a network like Solana can incorporate, natively, the functions that traditional finance distributes across multiple infrastructure layers: settlement finality, ownership transfer, compliance rule enforcement, corporate action processing and distribution logic are all encodable within the contract itself, without recourse to a separate infrastructure provider. Each token contract, in this sense, is its own settlement system, which in itself greatly reduces concentration risk.
The legal framework should recognise this reality. Just as we argued in the context of bridged instruments that the law needs to specify when a bridging arrangement confers legally enforceable rights on token holders, so the law needs to establish the conditions under which a token smart contract's settlement mechanics carry legal finality — the on-chain equivalent of the statutory finality protection that the Settlement Finality Directive provides for designated settlement systems. Without this, the operational certainty that blockchain infrastructure can deliver is not matched by equivalent legal certainty, and a significant part of its value for financial market participants goes unrealised.
Flatter networks and reduced risk concentration
The second structural difference concerns the distribution of systemic risk. Traditional financial infrastructure is hierarchical by design: settlement ultimately concentrates in a small number of nodes — central bank accounts, CCP guarantee funds, CSD participant registers — because concentration is what makes multilateral netting and guarantee arrangements economically viable. This concentration reduces operational friction but accumulates systemic risk: the failure of a sufficiently central node can trigger cascading consequences across the entire network.
Permissionless public blockchain networks have a materially different topology. Hundreds or thousands of independent validators participate in consensus; no single node controls settlement; and the economic incentives of the protocol distribute rather than concentrate the consequences of individual failure. The same openness that removes barriers to participation also removes the concentration points that make traditional infrastructure systemically fragile.
This has implications for the settlement asset question. The argument that central bank money is a necessary settlement asset rests substantially on the systemic risk that concentrates at the top of a hierarchical settlement stack. Where that hierarchy is absent — where settlement occurs peer-to-peer across a flat, open network with no central node whose failure could be catastrophic — the systemic case for mandating central bank money is substantially weaker. We do not suggest that central bank money has no role; we suggest that its role should be determined by the actual concentration of systemic risk in any given arrangement, not by the inherited assumption that all settlement systems replicate the hierarchical structure of traditional finance.
New concentration risks and the monitoring challenge
The picture is not, however, uniformly reassuring. Two distinct risk categories require explicit regulatory attention.
The first concerns concentration risk in critical shared infrastructure. As we noted under interoperability, the emergence of dominant cross-chain bridging protocols, widely used oracle networks, and shared RPC infrastructure creates new concentration points that, while structurally different from traditional financial infrastructure, carry analogous systemic implications. A dominant bridge protocol whose failure simultaneously disrupts asset transfers across dozens of chains, or an oracle network whose manipulation simultaneously corrupts price feeds across hundreds of DeFi protocols, could produce system-wide consequences qualitatively similar to those associated with a traditional infrastructure failure. The FCA should monitor the development of such concentrations and engage with the question of whether any cross-chain infrastructure or shared data layer is approaching the threshold at which a Critical Third Party designation — or an equivalent framework calibrated to decentralised infrastructure — would be appropriate.
The second, and more structurally novel, risk concerns the hidden interdependencies and pro-cyclical dynamics that can build within open composable systems. The events of 10 October 2025 illustrated this with unusual clarity. A macro shock — the announcement of 100% US tariffs on Chinese imports — triggered a cascade in which approximately $18 billion of leveraged crypto positions were liquidated over 14 hours, with $3.21 billion liquidated in a single minute at the height of the event. The speed and severity of the cascade reflected not a failure of any single infrastructure component, but the interaction of three factors that individually appeared manageable: extreme leverage concentrated in derivatives markets, liquidity that appeared deep in normal conditions but evaporated instantly under stress, and automated liquidation mechanisms that consumed the very liquidity they needed to execute, each liquidation widening spreads and triggering the next.
Critically, the event also revealed a structural distinction relevant to regulatory design. Centralised exchanges — where leveraged positions had accumulated and where automated deleveraging mechanisms operated — contributed most to the systemic cascade and, in several cases, experienced outages under the load. DeFi protocols, by contrast, largely continued to execute as designed: on-chain settlement functioned, and where stablecoins and collateralised lending protocols maintained over-collateralisation, they did so transparently and verifiably. The systemic fragility was concentrated in the centralised, opaque layer; the decentralised, transparent layer, while under severe stress, largely held.
This distinction matters for regulatory design, but it does not license complacency about DeFi systemic risk. The same composability that is the source of blockchain's transformative potential is also the mechanism through which leverage and collateral interdependencies can accumulate invisibly across protocols, and can behave in ways that no individual protocol's stress testing would predict.
Traditional finance developed its systemic risk monitoring toolkit — stress testing, exposure reporting, large exposure limits, trade repository reporting — in response to exactly this kind of hidden interconnection. The equivalent toolkit for DeFi does not yet exist, but the raw material for it is, uniquely, available in real time: every position, every collateral relationship, every liquidation threshold is on-chain and queryable. What is required is the analytical infrastructure to exploit that transparency systematically. We believe the FCA should engage actively with the development of on-chain systemic risk monitoring capabilities — both directly and in coordination with the Bank of England's financial stability function — treating the transparency of public blockchain not as a novel feature of a niche asset class but as a genuine supervisory resource that has no equivalent in traditional finance. The goal should be a monitoring framework capable of identifying the build-up of correlated leverage and collateral concentration across DeFi protocols before it reaches the threshold at which a macro shock can trigger a mechanical cascade — precisely the condition that was absent on 10 October 2025.
7. Prudential Capital
Whatever the intrinsic merits of blockchain, the Basel Committee's prudential standard for cryptoasset exposures represents a severe practical constraint on bank participation in permissionless blockchain, and merits specific attention.
The structure of the standard is well understood. Native crypto assets cannot satisfy the classification conditions required for Group 1 treatment, and are therefore classified as Group 2 by default. Group 2b assets are subject to a risk weight of 1250% applied to the greater of the absolute value of aggregate long and short positions. The practical consequence of this, when combined with a minimum Tier 1 capital ratio of 8%, is that banks are required to hold equity capital equal to the full value of any position in crypto assets. Banks' aggregate exposures to Group 2 cryptoassets are additionally capped at 1% of Tier 1 capital, with punitive cliff effects if that threshold is breached. For most PRA-authorised banks, this makes meaningful balance sheet exposure to permissionless chain assets and associated activities such as operating validator nodes economically non-viable regardless of the quality of the underlying asset, the robustness of the custody arrangement, or the adequacy of the risk management framework.
The BCBS's reasoning for this treatment is on the record. The Committee concluded that the use of permissionless blockchains gives rise to unique risks — including banks' limited ability to conduct due diligence and oversight over third parties, potential network disruptions, AML/CFT risks, and risks around settlement finality — that cannot be sufficiently mitigated at present, while acknowledging that technical solutions to many of these issues may develop rapidly. In other words, the standard was not calibrated as a permanent position but as a conservative floor pending the development of adequate mitigants. Industry submissions across multiple jurisdictions have argued that the Basel standard's categorical exclusion of permissionless blockchain assets is not technology neutral, and that the 1250% risk weight applies even where assets pose essentially the same risk as their traditional counterparts, with the distinction driven by the type of technological infrastructure rather than the underlying risk characteristics of the asset.
As we have shown in this letter, the anticipated rapid evolution of blockchain-based systems is demonstrably occurring. Validator-level screening, data roll-back services, cross-chain bridging protocols, and MEV mitigation techniques all speak directly to the risks the BCBS identified. We believe that this evolution, of itself, is sufficient grounds for the BCBS to reconsider its position. Practical proposals like those set out in this letter would only strengthen the case. We therefore urge the PRA to add its voice to those encouraging the BCBS to change its stance.
Conclusion
The seven areas we have examined — identity and access control, operational resilience, interoperability, custody and asset control, market structure and abuse, market infrastructure and systemic risk, and prudential capital — are genuinely challenging. We do not minimise the difficulty of adapting regulatory frameworks designed for a world of identifiable legal entities, bilateral contracts, and hierarchical infrastructure to a world of protocol-governed systems, permissionless participation, and composable, open-source code.
However, the central argument of this letter is that the response to those challenges should be to extend and adapt existing regulatory machinery rather than to constrain permissionless blockchain into conformity with traditional finance. The distinction matters because the unique benefits of public blockchain are not incidental features that can be preserved while its architecture is domesticated: they are structural properties that flow directly from openness, composability, decentralised governance and comprehensive transparency. A regulatory approach that requires blockchain systems to replicate the legal and institutional forms of traditional finance will, in suppressing those properties, suppress the benefits they generate.
This is not a theoretical concern. The history of financial regulation is replete with examples of frameworks that, designed to protect users of one generation of market structure, became barriers to the next. The specialist system on the NYSE was once a regulatory achievement; by the time of its dismantling, it had become the mechanism through which rent extraction was institutionally protected. The clearing mandates of Dodd-Frank were designed to reduce counterparty risk; their effect was to transfer gatekeeper privileges from dealer banks to CCP members. Good intentions, rigidly applied to a new environment, produced the very concentrations of structural advantage they were designed to prevent.
The specific asks we make across the seven sections of this letter share a common architecture. In each case, we argue for regulatory recognition of what blockchain infrastructure actually provides rather than penalising it for not providing what traditional infrastructure would. We ask the FCA to recognise that a permissionless protocol's public, continuously verifiable behaviour is a stronger assurance than a private SLA; that protocol-locked assets carry a fundamentally different risk profile from custodied assets; that MEV is being addressed faster and more structurally by the market than conduct regulation ever addressed its traditional finance equivalents; and that the transparency of on-chain systems is a supervisory resource of extraordinary potential that existing frameworks have barely begun to exploit.
We also make three asks that require action beyond the FCA's existing powers: legal clarity on the status of bridged instruments; a framework under which token smart contracts can carry statutory settlement finality; and the extension of the DVS Trust Framework to support on-chain credentials for financial services CDD. These are not requests for bespoke crypto regulation. They are requests for the legal infrastructure that permissionless blockchain needs to function as a full participant in the regulated financial system — the same kind of legal infrastructure that underpins every other settlement system, every other identity verification framework, and every other category of financial instrument that has come before it.
The financial system that public blockchain makes possible — more open, more transparent, more accessible, and more resistant to the structural rent extraction that has characterised every previous generation of market infrastructure — is a system that serves the FCA's statutory objectives more fully than the one we have. We urge the FCA and PRA to engage with it on those terms.
The Solana Research Institute welcomes further engagement on any of the issues raised in this letter and would be pleased to discuss them in person with FCA and PRA staff.
Solana Research Institute
July 2026
Related Research

A practical guide to Solana for senior FI practitioners. Covers technology, economics, governance, and regulatory status.
The FCA's 2026 cryptoasset regulations risk cutting the UK off from permissionless blockchains. Why staking and wallet rules misread the actual risk.

