Reserve Transparency Isn’t Enough: The Next Phase of Stablecoin Oversight
For years, the stablecoin debate has focused heavily on reserves. Are the assets really there? What are they invested in? Are they liquid? Has an
Stablecoins are often described as digital dollars that move across decentralized networks. That description is useful, but it leaves out one of their most important characteristics: many stablecoins depend on a centralized issuer.
The blockchain may be public. Transactions may occur between self-custody wallets. The asset may move through decentralized applications without direct involvement from a bank. Yet an issuer may still control minting, redemptions, reserves, smart contract upgrades, wallet restrictions, and other critical functions.
This creates a fundamental tension.
Users may value stablecoins because they can move across open blockchain networks, while regulators expect an identifiable organization to manage risks and remain accountable when something goes wrong.
Neither side of that tension can be dismissed. Without issuer control, it may be difficult to maintain reserves, process redemptions, respond to sanctions, correct technical problems, or protect the stability of the asset. With too much control, however, a stablecoin may lose some of the openness, neutrality, and predictability that make blockchain-based payments attractive.
The long-term success of stablecoins may depend on how effectively issuers balance those competing expectations.
The word “decentralized” is often used too broadly when discussing digital assets.
A stablecoin can move across a decentralized blockchain without being decentralized in every respect. The underlying network may allow transactions to be validated by independent participants, but control over the stablecoin itself may remain concentrated.
Depending on its design, a stablecoin issuer may have the ability to:
These powers can be necessary for operating a fiat-backed stablecoin. Someone must manage the assets supporting the token, reconcile supply with reserves, process redemptions, and ensure that the system complies with applicable law.
At the same time, users may not always understand how much control the issuer retains after a stablecoin enters circulation.
The token may sit in a self-hosted wallet and move across a permissionless network, but that does not necessarily place it beyond the issuer’s technical or legal reach.
Issuer control is not simply a feature added to undermine decentralization. In many cases, it is part of what allows the stablecoin to maintain its value.
A fiat-backed stablecoin represents a promise that the token can be redeemed according to specific terms. Delivering on that promise requires an organization to manage reserves, banking relationships, liquidity, issuance, and redemptions.
When a customer provides dollars to obtain stablecoins, the issuer must ensure that the correct number of tokens is created. When those tokens are redeemed, the issuer must remove them from circulation and return the appropriate amount of traditional currency.
These functions require coordination between the blockchain and the traditional financial system.
Control can also provide a way to respond when something goes wrong. If tokens are stolen through a hack or transferred to a sanctioned address, an issuer may be able to restrict the relevant wallet. If a smart contract contains a vulnerability, an upgrade mechanism may allow the issuer to correct the problem before the damage spreads.
From a regulatory perspective, these capabilities can make an issuer more accountable. Authorities have an identifiable organization that can receive legal process, maintain records, implement sanctions controls, monitor risk, and respond to investigations.
The GENIUS Act reinforces this model by creating a regulatory framework for permitted payment stablecoin issuers and treating those issuers as financial institutions for purposes of the Bank Secrecy Act. Treasury’s proposed implementing rules would require permitted issuers to maintain effective anti-money laundering and sanctions compliance programs.
Those responsibilities naturally increase pressure for issuers to retain some degree of control.
The same controls that create concerns about centralization may also support a stablecoin’s compliance program.
An issuer that can identify and restrict certain wallets may be better positioned to respond to sanctions exposure, fraud, stolen funds, or a valid government order. Minting and redemption controls can also help the issuer identify unusual activity at the points where stablecoins enter or leave circulation.
But technical capability is not the same as a complete compliance program.
A freeze function does not determine when it should be used. It does not resolve uncertainty around indirect wallet exposure, competing legal claims, or funds that have passed through several innocent holders. It also does not decide whether restricting a wallet is legally required, operationally appropriate, or likely to create unintended consequences.
Before exercising control, an issuer may need to assess:
These determinations require legal review, investigation, escalation procedures, and documented human judgment.
An issuer should not assume that having the technical ability to intervene automatically means intervention is appropriate. It must define the circumstances under which that authority will be used and ensure that similar situations are handled consistently.
Issuer control is often strongest at the points of issuance and redemption. Between those points, the stablecoin may move through an ecosystem the issuer does not directly control.
A token can be transferred to a self-hosted wallet, deposited into a decentralized protocol, bridged to another blockchain, placed into a liquidity pool, or used as collateral. The issuer may have no direct customer relationship with many of the people who eventually receive or interact with it.
This creates a difficult compliance boundary.
The issuer may retain technical authority over the token while lacking complete information about every downstream user. Blockchain analytics can provide visibility into transaction pathways and wallet exposure, but on-chain information does not always reveal the identity, intent, or circumstances of the person behind an address.
The result is an unusual combination of broad technical reach and incomplete customer context.
An issuer may be able to freeze an address without knowing every person whose funds will be affected. It may observe exposure to a high-risk service without knowing whether the activity reflects criminal conduct, legitimate business, or incidental interaction.
This is where decentralization complicates control. The issuer’s authority may travel farther than its information.
Control mechanisms may help manage risk, but they can also create it.
An administrative key capable of freezing wallets, pausing transfers, or changing contract logic can become an attractive target for attackers. If that key is compromised, the same mechanism designed to protect the stablecoin could be used to disrupt it.
Internal misuse is another concern. If authority is concentrated in too few individuals, an employee or executive could take significant action without sufficient review. Even an accidental mistake could restrict the wrong wallet, interrupt redemptions, or affect tokens across multiple networks.
Issuers therefore need controls around their controls.
Sensitive actions may require multiple approvals, segregated responsibilities, secure key management, detailed access logs, and immediate escalation when unusual administrative activity occurs. Emergency authority may also need to be narrower than routine authority and subject to review after it is used.
Governance is especially important when a stablecoin operates across several blockchains. Administrative controls may function differently on each network, creating inconsistencies in how restrictions, contract upgrades, or token migrations are implemented.
The issuer should understand those differences before an incident occurs.
A decentralized stablecoin may reduce reliance on a traditional company, but it does not eliminate governance. It changes where governance occurs and who participates in it.
Governance may be conducted through token voting, decentralized autonomous organizations, smart contract parameters, multisignature arrangements, or groups responsible for managing collateral and responding to emergencies.
These structures can distribute authority, but they may also make responsibility harder to identify.
Voting power may be concentrated among a small number of token holders. Participation may be low. Delegates may exercise substantial influence without the accountability expected of a traditional board. Emergency administrators may retain powers that are not obvious to ordinary users.
The Bank for International Settlements has noted that partially or fully decentralized stablecoin arrangements can present challenges when there is no clearly identifiable legal entity or individual responsible for critical functions.
A system may be decentralized in theory while depending in practice on developers, oracle providers, governance delegates, collateral managers, or key holders.
The relevant question is not whether the project uses decentralized terminology. It is whether control, responsibility, and accountability can be clearly understood.
Many users are attracted to blockchain-based payments because they appear more open than traditional financial channels. A stablecoin can often be transferred without the recipient opening an account directly with the issuer.
This accessibility creates an expectation of neutrality. Users may assume that transactions will proceed according to predictable technical rules rather than discretionary decisions by a centralized intermediary.
Issuer intervention can challenge that expectation.
If an issuer can restrict a wallet or alter how a token operates, users may question whether they truly control the asset. Businesses may also worry that a stablecoin they accept today could become inaccessible tomorrow because of an investigation, legal dispute, sanctions concern, or decision made by the issuer.
At the same time, complete neutrality may be incompatible with the responsibilities regulators are placing on permitted issuers. A company cannot reasonably claim to be powerless over an asset while also promising regulators that it can manage sanctions, money laundering, fraud, and operational risks.
The challenge is therefore not to eliminate issuer control. It is to make that control transparent, governed, and predictable.
Stablecoin issuers should be able to explain not only what powers they have, but how those powers are governed.
Users, counterparties, regulators, and business partners may need clear information about whether tokens can be frozen, who can authorize an intervention, what standards apply, and whether an affected party has any opportunity to challenge or resolve the restriction.
A credible control framework should address:
Not every detail can be made public. Issuers must avoid disclosing information that would help criminals evade controls or exploit the system.
However, users should not have to discover the nature of issuer control only after their funds are restricted. Basic intervention capabilities and governance principles should be communicated clearly.
Internal procedures will need much more detail. They should address legal review, sanctions escalation, fraud investigations, law enforcement requests, smart contract incidents, administrative key security, and cross-chain coordination.
These procedures should also be tested. A policy describing how to freeze a wallet is not enough if the authorized team cannot execute the action quickly, securely, and consistently during a real incident.
The stablecoin market is unlikely to resolve this tension by choosing complete centralization or complete decentralization.
Fiat-backed stablecoins will probably continue to depend on identifiable issuers because reserves, banking relationships, redemptions, and regulatory obligations require accountable organizations. At the same time, those stablecoins may continue circulating on open blockchain networks where users can transact without maintaining a direct relationship with the issuer.
That combination may become one of the defining features of stablecoins: centralized responsibility operating across decentralized infrastructure.
Other models will continue to experiment with decentralized collateral, automated stability mechanisms, and community governance. Those projects may reduce dependence on a single issuer, but they will face their own questions involving accountability, oracle risk, governance concentration, smart contract security, and crisis response.
The market may therefore produce different forms of stablecoins for different purposes rather than one model that satisfies every objective.
Institutions may prefer stablecoins with clear issuer accountability and strong intervention capabilities. Other users may place greater value on censorship resistance, transparent code, or distributed governance.
Each model involves tradeoffs.
Issuer control and decentralization are often presented as opposites, but stablecoins demonstrate that they can exist within the same system.
The blockchain can provide open transferability, transparency, programmability, and continuous settlement. The issuer can provide reserves, redemption, governance, compliance, and an accountable organization responsible for maintaining the asset.
The tension begins when users, issuers, and regulators have different assumptions about which side should take priority.
A strong framework does not hide that tension. It identifies where control exists, explains why it is necessary, limits how it can be used, and establishes accountability for significant decisions.
Stablecoins do not have to be completely decentralized to benefit from decentralized networks. But if issuers retain substantial authority, that authority must be accompanied by appropriate governance, transparency, security, and oversight.
The future of stablecoins may depend less on choosing between issuer control and decentralization than on building a credible structure in which both can coexist.
The balance between issuer control and decentralization will continue shaping the future of stablecoins, influencing everything from compliance and consumer protection to operational resilience and market adoption. As regulators, financial institutions, and digital asset businesses adapt to this evolving landscape, organizations that thoughtfully design their governance and control frameworks will be best positioned to meet emerging expectations without sacrificing innovation.
Have questions about stablecoin compliance or governance? BitAML advises stablecoin issuers, digital asset businesses, banks, fintechs, and payment companies on AML compliance, regulatory strategy, risk assessments, licensing, and governance. Contact us today to learn how we can help your organization navigate the evolving regulatory landscape while building a scalable, future-ready compliance program.
For years, the stablecoin debate has focused heavily on reserves. Are the assets really there? What are they invested in? Are they liquid? Has an