{beacon}
| |||||||||||
| |||||||||||
| | |||||||||||
Happy Monday, Fintech Takers! I hope you had a productive weekend. Mine was smokey, but that didn’t stop us. My family and I cut down a 90-foot pine tree that was starting to rot and was uncomfortably close to my cabin. It was a challenging set of conditions, but, fortunately for me, no tree is too tall for Nate Johnson to climb and Tom Johnson is a steely-eyed chainsaw man. See the image below for the before and after. And read on for some fintech news and analysis! - Alex P.S. — Software companies embedding payments within their platforms are about to learn the same lessons that co-brand card issuers and retailers spent the last five decades learning. If you’re curious to understand what those lessons are (and how you might learn from them), please register for my upcoming virtual event! Was this email forwarded to you? Sponsored by Persona Airport security treats every traveler roughly the same, whether they fly 50 times a year or once. Persona's Strategic Guide to Identity Verification explores a more adaptive approach. ![]() You can just do things … especially if you do them with people who know what they’re doing and trust their instincts. 3 FINTECH NEWS STORIES#1: Gates vs. PrimitivesWhat happened?Bank trade associations and fintech trade associations are working with regulators to define a common set of standards for managing the risks of bank-fintech partnerships:
And SOLO, a collaborative data-sharing network, is running a pilot — that is being observed by regulators — to enable banks to share customer verification data:
So what?I’m not going to go super deep into the details on the FDIC standards story that Evan Weinberger at Bloomberg Law originally broke. Jason Mikula — our permanently embedded reporter on BaaS Island (whether he wants the job or not!) — already did that. Instead, I’d like to make a broader point, which connects the FDIC standards story with the SOLO pilot story. The fundamental problem we’re trying to solve is that fintech companies have made the financial services ecosystem far more competitive than it used to be. “What’s the problem with more competition?,” I hear you asking. On a surface level, nothing. Competition is good. It leads to innovation and, ultimately, better products and pricing for customers. However, one emergent property of a more competitive financial services ecosystem is the incentive for all participants to move faster and to take more risks in order to win, which can, if left unchecked, become a race to the bottom. Bank regulatory supervision is not well suited to address this challenge. Our system is designed around the idea of a “regulatory perimeter.” Inside that perimeter are banks, which are directly and closely supervised by agencies like the Fed, OCC, and FDIC. Due to this constant supervision, the resting assumption is that the companies inside the perimeter are, comparatively, safe. Conversely, companies outside that perimeter are not under constant regulatory supervision, and are, therefore, considered, comparatively, unsafe. Historically, the main way that companies inside the perimeter interacted with companies outside the perimeter was to engage their services as vendors. This model of bank/non-bank “partnership” was the dominant model for many decades and it is governed by a number of different laws, regulations, and processes — the Bank Service Company Act, Third-party Risk Management Guidance, etc. — all built around the assumption that risk always flowed from the outside in. Those laws, regulations, and processes obviously didn’t work very well when they were applied to bank-fintech partnerships in the 2010s and (so far) in the 2020s, especially the banking-as-a-service model, which inverted the historical relationship and made banks, functionally, vendors to fintech companies. This is why the FDIC is spearheading this initiative around standard setting, which is designed to reduce the amount of time and work that any one bank has to spend vetting new fintech partners. Instead, the idea would be to create a set of uniform standards that all fintech companies could be assessed against and a registry of all the fintech companies that are deemed to be "manageable" risks for banks to work with. I see a few problems with this approach. First, according to Evan’s and Jason’s reporting, regulators would not endorse any particular standard-setting or certification organization under this framework. Additionally, banks and fintech companies would not be required to adhere to these standards and inclusion in the registry of "manageable" service providers would not provide a bank that chose to work with one of them safe harbor in the event of a problem. Second, fintech is a very big industry, and different categories of fintech companies present very different risks to banks, end customers, and the safety and soundness of the financial system overall. A BaaS middleware provider, a KYC vendor, a lead-gen affiliate, a core processor, and a lending-as-a-service platform share almost no risk surface. So the baseline standard either gets set generically enough to cover all of them — in which case it certifies nothing meaningful — or it fragments into dozens of domain-specific standards, and you've rebuilt the entire diligence problem inside the standard-setting body. Third, and most importantly, even if the FDIC figures out how to define sufficiently specific standards and gives them real teeth, they still wouldn’t be solving the fundamental race-to-the-bottom problem. A highly competitive marketplace encourages all market participants, inside and outside the regulatory perimeter, to move fast and to take risks. When you erect barriers to slow companies down and to stop them from taking risks, you aren’t solving for this incentive. It still exists. And unless you (the regulator) think that you can stop everyone working at every one of the tens of thousands of banks and fintech companies operating in the U.S. from doing something bad before they do it, you’re not going to be as successful as you want to be. They will just find a way around you and the bad thing you were trying to stop will happen anyway. This is why I’m intrigued by what SOLO is doing. It’s both a complement to robust regulatory supervision and an acknowledgement of its limitations. Both SOLO and the FDIC are trying to create standards to make risk and compliance data reusable. The difference is that the FDIC is trying to make judgments about firms reusable, which is inherently broad, subjective, and context dependent (hence the lack of any teeth in its effort). Standards only work when they are narrow, specific, and easy to document and audit. By applying standards not to banks’ and fintech companies’ customer verification methods, but to the outputs of those methods instead, SOLO is trying to sufficiently limit the scope so as to make collaboration across institutions achievable. Think of it less like a gate to collaboration (which is what the FDIC is doing, albeit a gate that can’t be locked or even closed) and more like a collaboration primitive; a building block that lowers the cost of following the safer path (rigorous due diligence) without trying to steer away from the incentive that all banks and fintech companies are still subject to — to move fast and take risks. #2: Option ValueWhat happened?Circle has named the founding validators for its upcoming payments-focused L1 blockchain:
So what?My simplified explanation for why Stripe created Open Standard and the OUSD stablecoin is that it is trying to become Circle before Circle can become Stripe. The construction of Open Standard as a consortium owned by many members and controlled by none of them and the decision to pass almost all of the stablecoin yield to members rather than hoarding it appears to be specifically designed to fast-track the growth of OUSD, so that it can cut into USDC’s lead as the predominant regulated payment stablecoin, before USDC gets too far out ahead to catch. James Wester and I talked through this theory in a lot more detail in this podcast episode, if you’re curious to dig deeper. But, of course, this logic applies to Circle as well. Circle is, I believe, trying to become Stripe before Stripe can become it. And one of the things that Stripe already has is Tempo, a payments-optimized (i.e., more centralized) layer-1 blockchain. Circle is building its own payments-focused L1 blockchain — Arc — and its validators (the institutions that run the network's consensus and confirm its transactions) are made up of many of the same companies that signed on as members of Open Standard, including Visa, Mastercard, Standard Chartered, and BlackRock. This may strike you as odd (I thought Open Standard and Circle are competitors!) but it’s really not. OUSD isn’t real, yet. Arc isn’t quite real, yet (it officially launches on September 16th). These announcements — featuring big names like Visa and BlackRock — are designed to make them feel real, to make their success feel inevitable. But the reality for these companies is that their participation in Stripe’s and Circle’s various crypto payments initiatives — which also includes Visa and Standard Chartered acting as validators for Tempo — is, at this moment, entirely about cheap option value. The same thing happened with Libra in 2019. Visa and Mastercard (and Stripe) were members, until it became politically toxic. Visa, Mastercard, BlackRock, and Standard Chartered don’t know if Circle will become Stripe before Stripe becomes Circle, or if Stripe will become Circle before Circle becomes Stripe, and they don’t need to know. They just need to purchase seats at both tables (which they can easily afford) and wait to see which one wins. #3: Stablecoins + Gift CardsWhat happened?These words really shouldn’t be used together:
So what?The reason those words don't belong together isn’t vibes (though I don’t like the vibes!). It’s mechanical, and it cuts against one of the best arguments the stablecoin industry has for itself. You've heard that argument on every panel for three years: Cash is the money launderer's ideal instrument because it's a bearer asset that moves without leaving a record. Stablecoins are the inverse. Every transfer is written to a public ledger, permanently, and a compliant issuer can freeze a wallet in minutes. Criminals who use them are volunteering an evidence trail. Now, in that context, consider what a gift card is. It's a bearer instrument. Whoever holds the code holds the value, and the code can be handed to anyone, no questions asked. So wrap a stablecoin in one. The stablecoin stops moving. It sits in a KuCoin-controlled wallet while the claim on it circulates the way anything digital circulates: Forwarded emails, screenshots, Telegram messages. The ledger records a mint and, eventually, a redemption. Everything in between is invisible to KuCoin, to Circle, to Tether, and to every regulator on earth. You've taken the most traceable dollar-denominated instrument ever built and bolted an untraceable transfer leg onto it. The gift card wrapper isn't incidental to the product. The wrapper is the product. In fairness, there is one control here: Redemption runs through KuCoin, so whoever converts a code into spendable USDT has to clear KuCoin's KYC. So, as long as we trust KuCoin, we should be good. One problem: We shouldn’t trust KuCoin! In January 2025, KuCoin's operator pleaded guilty to operating an unlicensed money transmitting business and agreed to pay more than $297 million. Per the DOJ, it failed to implement effective AML and KYC programs, failed to report suspicious transactions, and failed to register with FinCEN. Until at least July 2023 it didn't require customers to provide any identifying information at all, and employees repeatedly posted on public social media that KYC wasn't mandatory, including in replies to customers who'd said they were in the U.S. When KuCoin finally made KYC mandatory in August 2023, it still didn't apply it to existing users who only wanted to withdraw. This March, a CFTC consent order converted KuCoin's two-year U.S. exit into an indefinite bar. So the only point in this architecture where a human being gets identified is redemption KYC, administered by a company with a criminal conviction for not administering redemption KYC. Here's the part that should bother the policy people. When FinCEN exempted low-risk prepaid products in 2011, it named three capabilities that disqualify a product from the low-risk exemption: International use, person-to-person transfers, and reloading from a non-depository source. Any one is enough to blow the exemption. KuCoin's product has all three — global from day one, freely transferable, funded with stablecoins. And it's built for volume: bulk issuance with API integration, sold to businesses, so you can programmatically mint ten thousand bearer claims on dollars. KuCoin is functionally prohibited from operating in the U.S., so FinCEN’s exemption criteria are irrelevant in this case. But still, the design of the product points at exactly the risks that FinCEN and other regulators worry about. If on-chain traceability is why stablecoins are safer than cash, then a bearer wrapper on a stablecoin isn't a feature, and the people who make the traceability argument for a living owe the rest of us an opinion about this one. Sponsored by Gradient Labs Lots of conversations about AI agents start at "should we?" 2 READING RECOMMENDATIONS#1: Sponsor Banks Doing It For Themselves (by Matthew Goldman, CardsFTW) 📚A fun update from Matthew on sponsor banks bringing processing and program management in-house, which is a trend I had not spotted until I read this edition of his newsletter. #2: The Future Of Distribution (In Lending) Seems Obvious (by Carlos Caro, The Free Toaster) 📚This article (and this one and this one) provide a good foundation for anyone who is curious about the role that AI will have on distribution in consumer lending. 1 QUESTION FROM FINITYThere are a TON of interesting questions being asked in Finity (our digital community for fintech and banking nerds). I’ll share one question, sourced from the community, each week. However, if you’d like to join the conversation, please apply to join! As stablecoins have become payments infrastructure, I’ve found myself writing about them (and the crypto industry, more broadly) more often than I used to. This is, to a degree, foreign territory for me, as I am more TradFi in my fintech heart of hearts than I am DeFi.So, here’s my question: Are my occasional thoughts on crypto and stablecoins useful to you? Do they add something to the discourse that is missing? Or is there something missing from my coverage of stablecoins and crypto that you’d like to see me add in?I’m happy to consider anything except NFTs.If you have any thoughts on this question, reply to this email or DM me in Finity! Thanks for the read! Let me know what you thought by replying back to this email. — Alex | |||||||||||
|
