Stablecoins
Safeguarding trusts and stablecoin reconciliation
Native and wrapped stablecoins carry identical redemption claims but are different property objects. A ledger that reports them as one balance hides the exposure.
- Written by
- Massive Distribution Dynamics
- Published
- 12 September 2026
- Length
- 9 min read

Stablecoin layering has profound implications for situs, asset tracing, and insolvency proceedings. While a digital token can be frozen, tracked, and held in trust like any other property, the underlying reserve claim remains governed by contract law. Determining the 'situs', the legal location, of an asset is critical for international tax, choice of law, and jurisdictional authority. It raises the fundamental question: where does your wealth actually reside?
Tax treatment and legal situs.
For tax purposes, the token itself, rather than the underlying claim, is generally the taxed object.
- 01United States: The IRS classifies digital assets as property rather than currency. Consequently, every disposal of USDC is technically a realisation event. While gains or losses are often negligible, the compliance burden is significant, and the GENIUS Act’s stablecoin regime has not altered this fundamental tax characterisation.
- 02Canada: The CRA similarly views stablecoins as commodities. Dispositions are treated as barter transactions, though the definition of a “virtual payment instrument” generally excludes most crypto payments from GST/HST.
- 03United Kingdom: HMRC treats stablecoins as exchange tokens: they are considered intangible capital assets for Capital Gains Tax (CGT) purposes, not money. The permissionless nature of the blockchain is tax-irrelevant; the key factor is that transferring the asset constitutes a disposition.
Beyond tax, courts may struggle to treat stablecoins as property when enforcing rights. This legal ambiguity can hinder access to essential judicial remedies, such as equitable relief, rectification, or specific performance.
The operational reality: asset non-fungibility.
A common misconception is that 'USDC' represents a single, unified asset. In reality, Circle does not issue a monolithic USDC token; it deploys distinct native token contracts on each supported blockchain. These contracts maintain separate minting authorities and independent ledgers.
There is no on-chain mechanism that makes a Solana balance inherently spendable on Ethereum. Fungibility exists only through Circle’s own cross-chain transfer protocol (CCTP), which burns on one chain and mints on another, or through third-party bridges.
Each deployment carries the settlement properties of its host chain. For instance:
- 01Ethereum: Finality typically occurs in approximately 13 minutes.
- 02Solana: Confirmation occurs in seconds, but under a different consensus mechanism with a unique history of network halts.
- 03Base: As an Ethereum Layer 2, its fast confirmations rely on a centralised sequencer, with true settlement only occurring upon L1 integration.
Because these assets have identical redemption claims but different property objects, operational profiles, and reorg risks, they are, in any legal or accounting sense, distinct assets.
The treasury reconciliation challenge.
For a safeguarding trust, the assets in the pool must be granularly identified by chain, contract, and wallet. A generic balance entry of '1,000,000 USDC' is a dangerous abstraction because it masks critical operational risks. Safeguarding reconciliation requires matching liabilities to specific assets, acknowledging that two units of 'USDC' are not interchangeable if they exist within different settlement environments.
If a ledger aggregates positions across chains, or between native and wrapped assets, the treasurer effectively blurs distinct failure modes into a single, misleading number. This masking obscures three primary categories of hidden exposure:
1. Bridge-Counterparty Risk: Many holdings are not native assets but wrapped tokens issued by a bridge. In a ‘lock-and-mint’ model, the holder does not possess a direct claim on the issuer’s reserves, but rather an unsecured structural claim on the bridge’s collateral pool. If the bridge’s collateral contract is drained, as occurred in major exploits like Wormhole and Ronin, the wrapped tokens may lose their value, even if the stablecoin issuer remains fully solvent. A ledger that simply displays 'USDC' leaves the treasurer blind to the concentration of risk in specific bridge multisigs.
2. Sequencer-Liquidity Risk: On Layer 2 networks like Base, funds may be cryptographically secure and issuer-backed, but they are subject to infrastructure-level liquidity risk. Because these networks rely on a centralised sequencer to order transactions, a sequencer halt effectively freezes all assets on that chain. Without granular visibility into these dependencies, a firm cannot manage its liquidity against single-point-of-failure events.
3. Property Differentiation: Because native and bridged assets reside on different ledgers, have different reorg risk profiles, and utilise different settlement finality rules, they are distinct property objects. A token-level ledger that silently nets these positions fails the fiduciary duty to accurately reflect the true economic value of the holdings. The treasury cannot hedge, cap, or exit positions it cannot distinguish.
Understanding bridge and sequencer risk.
1. Bridge Exposure:
When using a wrapped stablecoin, the holder does not possess a direct claim on Circle’s reserves; they hold an unsecured structural claim on the bridge's collateral pool. Bridges typically utilise a 'lock-and-mint' design: native USDC is locked in a contract on Chain A, and a receipt token is minted on Chain B. If the bridge's collateral pool is drained, as seen in exploits like Wormhole or Ronin, the wrapped tokens lose their value, despite the issuer (Circle) remaining fully solvent.
2. Sequencer Exposure:
On Layer 2 networks like Base, funds are not necessarily 'stolen' if the network fails, but they can become operationally frozen. If the centralised sequencer that orders transactions for the network halts, the assets become illiquid. A trust ledger must record these distinct settlement mechanisms to ensure that the firm can adequately hedge, cap, or exit positions before a failure occurs.
The mechanics of interoperability: bridges, wrapping, and collateral risk.
1. The bridge function and lock-and-mint architecture.
Cross-chain interoperability in decentralised finance relies heavily on blockchain bridges to transfer value across disparate networks. A bridge functions as an intermediary infrastructure designed to facilitate asset movement between sovereign ledgers that otherwise share no shared state, execution environment, or consensus rules. The primary operational model deployed by cross-chain bridges is the 'lock-and-mint' mechanism.
Under the lock-and-mint paradigm, native tokens are not physically transferred from one blockchain to another, as cross-chain token teleportation is technically impossible without native minting authority on both layers. Instead, when a user initiates a transfer of native stablecoins (e.g., native USDC on Ethereum) to a destination chain (e.g., Sui or Solana), the bridge protocol mandates the following sequential process:
- 01Locking Native Assets: The user deposits native stablecoins into a specialised smart contract owned and operated by the bridge on the source chain. Once confirmed, these assets are escrowed and locked within the smart contract vault.
- 02Observation and Attestation: The bridge’s off-chain validator set, multisig signers, or oracle networks observe the lock event on the source chain smart contract and verify its finality.
- 03Minting Receipts: Upon validation, the bridge infrastructure issues an instruction to its token contract on the destination chain to mint an equivalent quantity of receipt tokens (wrapped tokens) to the recipient's target address.
A mandatory component of this design is the creation of a collateral pool on the source chain. The locked escrow contract forms the bridge's effective balance sheet, acting as the mandatory 1:1 backing for all receipt tokens issued across destination environments. Each wrapped token circulating on a secondary network is notionally intended to represent a ticket redeemable for one unit of locked native collateral in the source pool. Without this collateral pool maintaining parity with total minted supply, wrapped receipts lose their underlying economic backing.
2. The concept of wrapping and structural rights shifts.
Wrapping is the technical and financial process of encapsulating a native asset within a derivative smart contract container to render it spendable on non-native blockchain networks. While wrapped stablecoins frequently carry the same ticker symbol, name, and visual branding as their native counterparts, wrapping induces a fundamental shift in legal character, claim structure, and property rights.
Native stablecoins (such as native USDC issued directly by Circle) represent a direct contract-law claim against the reserves of the primary issuer. The token holder holds an enforceable debt obligation backed by short-term U.S. Treasuries and cash reserves managed in segregated institutional accounts by the primary issuer. In contrast, a wrapped stablecoin issuer (the bridge) holds no reserves with the primary issuer. Circle holds zero contractual relationship with wrapped token minters on secondary chains where it has not deployed native contracts.
Consequently, holding a wrapped stablecoin alters the holder’s legal position: the holder possesses an unsecured structural claim on the bridge's collateral pool, rather than a direct credit claim against Circle’s cash reserves. This structural distinction is captured by the principle: “Native USDC is issuer credit; wrapped USDC is bridge credit wearing the issuer’s ticker.”
3. Secondary market risks and digital property characterisation.
In secondary markets, market participants and treasury operational teams frequently operate under the flawed assumption of total fungibility across wrapped and native token variants. They treat wrapped stablecoins as identical economic substitutes for native coins due to historical price peg stability. However, evaluating wrapped stablecoins through the lens of property rights reveals substantial legal and operational risk asymmetries:
- 01Collateral Depletion and Insolvency Risk: If a bridge's smart contract on the source chain suffers a catastrophic exploit, reentrancy bug, or private key compromise (e.g., the historic Wormhole or Ronin bridge hacks), the locked collateral pool can be completely drained. Because the locked collateral is gone, the secondary wrapped receipts depeg toward zero. Crucially, the primary native issuer remains fully solvent and unaffected by the breach, leaving wrapped receipt holders with claims against an empty smart contract vault.
- 02Multisig Counterparty Exposure: Native stablecoin issuers operate under strict regulatory regimes, public audits, and fiduciary reserve management requirements. Conversely, bridge collateral pools are routinely secured by off-chain multisig keys, federated relayers, or complex smart contract code. Holding wrapped stablecoins replaces regulated institutional issuer exposure with concentrated counterparty risk tied to a small group of multisig keyholders or smart contract security parameters.
4. Operational reality and governance imperatives for treasurers.
Treasurers, institutional custodians, and safeguarding trustees must recognise that native and wrapped stablecoins represent entirely distinct property objects with independent failure modes. The common practice of netting native and wrapped balances under a single generic line item (such as '4,000,000 USDC') on internal ledgers represents a severe governance and risk-management breakdown.
Aggregating these positions hides critical bridge counterparty concentration and operational liquidity risks from risk managers. Effective fiduciary oversight and three-tier accounting standards mandate that enterprise ledgers explicitly differentiate balances by host chain, contract address, bridge issuer, and underlying settlement mechanism. Without this granular classification, institutional treasuries remain unable to cap, hedge, or mitigate catastrophic bridge exploits and infrastructure outages.
Conclusion: The Ledger as Institutional Comprehension. A stablecoin balance is only accurately represented when the ledger records precisely what is held, where it is held, the applicable contract code, and the settlement system’s specific rules for finality and access.
The ledger schema is merely the output of rigorous systems analysis. Because blockchains upgrade, contracts migrate, and bridges deprecate, this analysis is not a one-time task but a continuous function. The trustee must maintain an ongoing mapping between each network’s mechanics and the firm's booking rules. Only by capturing this granularity can a firm comply with the fiduciary duty to accurately reflect the true economic value and risk of its holdings.
