Previous Article in Journal
Mythos-Class AI and Blockchain Systemic Risk: A Comparative Analysis of Bitcoin and Ethereum/L2 Architectures
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Blockchain-Enabled Central Bank Digital Currency: Technological Architecture, Privacy, and Institutional Design

1
Faculty of Applied Mathematics and Control Processes, St. Petersburg State University, 7/9 Universitetskaya Emb., St. Petersburg 199034, Russia
2
DGT Technologies AG, 31 Versailles Crescent, Barrie, ON L4M 0B8, Canada
*
Author to whom correspondence should be addressed.
Blockchains 2026, 4(3), 12; https://doi.org/10.3390/blockchains4030012
Submission received: 24 March 2026 / Revised: 13 May 2026 / Accepted: 23 July 2026 / Published: 10 August 2026
(This article belongs to the Special Issue Blockchain-Enabled Distributed Machine Learning)

Abstract

This paper develops an analytical framework for the joint design of central bank digital currency (CBDC) and its underlying ledger architecture. We treat a digital monetary system as a tuple M = (S, R, C, I)—supply state, rule set, circulation parameters, and incentive structure—and read centralized, permissioned-distributed, and hybrid ledger designs as parameter settings on M. Two analytical propositions extend the framework. Proposition A locates a threshold above which a retail holding cap ceases to bind, building on the Brunnermeier–Niepelt neutrality condition. Proposition B characterizes the fixed point of the rule-update map under bounded policy shocks and reports its mean-square convergence rate. Each proposition is paired with a stylized numerical exercise; neither claims empirical validation. A comparative section then traces how the institutional environments of Singapore, the European Union, the United States, and China fix admissible regions in M before any architectural choice. What we contribute is a parametric vocabulary for techno-institutional comparison, not a new architecture; the principal limitation is the absence of pilot-data calibration, which we list as the highest-priority continuation.

1. Introduction

1.1. Research Background and Significance

The global financial system is undergoing a profound transformation driven by digital technologies. Among the most significant developments in this wave is the emergence of Central Bank Digital Currency (CBDC)—a digital form of central bank liability that promises to reshape the monetary architecture [1]. According to the Atlantic Council, 134 jurisdictions are currently studying or piloting a CBDC, a dramatic increase from just 35 in 2020 [2]. This global momentum reflects a recognition that the digitalization of money is no longer a theoretical possibility but an impending reality.
The rise of CBDC must be understood within the broader context of financial technology (FinTech) innovation. Privately issued cryptocurrencies and stablecoins have expanded rapidly, with their total market capitalization once approaching $3 trillion, raising concerns about financial stability, monetary sovereignty, and consumer protection [3]. Concurrently, the underlying technology of these private digital currencies—blockchain and distributed ledger technology (DLT)—has matured to a point where its potential application to official currency systems warrants serious examination [4].
The intersection of blockchain technology and CBDC is particularly significant. Blockchain offers features—decentralized verification, immutability, traceability, and programmability—that could address longstanding pain points in traditional financial infrastructure [5]. However, the integration of blockchain into central bank operations also introduces new technical challenges and institutional complexities. Understanding this technology–institution nexus is therefore essential for both policymakers designing CBDC systems and researchers studying the future of money.

1.2. Literature Review

Academic research on blockchain and CBDC has accumulated substantial results across several interrelated strands.
Blockchain Technology in Finance. As the underlying technology for digital currencies, blockchain is regarded as a revolutionary tool for building trust mechanisms due to its decentralization, immutability, and programmability [6]. The extensive literature explores its application potential in payment settlement, trade finance, and securities trading [7]. Bibliometric studies indicate that research themes have expanded from early discussions of digital currency attributes to more specific application levels such as technology adoption, risk management, and platform operations [8].
CBDC Design and Challenges. With the advancement of numerous CBDC projects, research has shifted from arguments of necessity to specific design and implementation challenges. Scholars have systematically compared the different positioning and architectures of retail and wholesale CBDCs [9], exploring their potential in enhancing payment efficiency, promoting financial inclusion, and strengthening monetary policy transmission [10]. Concurrently, studies identify challenges including potential “disintermediation” risks to traditional banking, balancing privacy with compliance (“controlled anonymity”), scalability and resilience of technological systems, and cross-border coordination difficulties [11]. Research from institutions like the Bank for International Settlements (BIS) provides important empirical foundations for these discussions [12].
Technology–Institution Co-evolution. A growing body of literature examines the relationship between technological choices and institutional outcomes in CBDC design. Studies show that different CBDC architectures—centralized, distributed, or hybrid—exhibit systematic trade-offs between technical performance and institutional adaptability [13]. Recent work by the International Monetary Fund distinguishes between implementation models with varying degrees of centralization and DLT integration, highlighting how technological choices shape institutional consequences [14]. Similarly, research on institutional systems suggests that factors such as rule of law, citizen trust, and financial literacy profoundly influence CBDC design choices, implying that implementation pathways will inevitably exhibit diversity across jurisdictions [15].
Despite these contributions, the existing literature leaves room for further investigation. First, research perspectives remain relatively dispersed, with insufficient integration between technological and institutional analyses. Second, while individual design features are well-studied, there is inadequate discussion of how these features interact within a unified analytical framework. This paper aims to address these gaps by constructing a formal framework that integrates technological architecture and institutional design.

1.3. Research Design, Contributions, and Structure

To achieve the above objectives, this paper adopts an interdisciplinary research perspective integrating theoretical insights from the economics of technology, institutional finance, and digital governance. CBDC is viewed as a new type of institutional arrangement embedded within specific technological infrastructure, whose development is constrained and shaped by multiple factors including technical feasibility, economic incentives, and social governance rules.
This paper introduces a formal analytical framework for digital monetary dynamics, abstracting a digital financial system into four interacting dimensions:
M = ( S t , R t , C t , I t )
where
S t —Supply State, representing issuance dynamics and supply control mechanisms [16].
R t —Rule Set, representing policy constraints and programmable logic [17].
C t —Circulation Parameters, representing money velocity and transaction patterns [18].
I t —Incentive Structure, representing economic incentives for network participants [19].
This framework provides an analytical tool for systematically comparing different CBDC implementation approaches, enabling monetary policy transmission, institutional design trade-offs, and cross-case comparisons within a unified parameter space.
Building upon the research gaps identified in the literature review, this study proposes the following exploratory proposition:
Proposition 1.
Different CBDC architectures (centralized, distributed, hybrid) exhibit systematic trade-offs between technical performance and institutional adaptability, a phenomenon that can be elucidated through a technology–institution co-evolutionary framework.
This proposition will be examined through systematic analysis of technological architectures and their institutional implications in subsequent chapters.
The contribution is threefold and analytical rather than empirical. First, M = (S, R, C, I) and the value-unit tuple V = (issuer, holder, value, Π, σ) act as a single object on which technological and institutional choices appear as parameter settings. We do not claim novelty for the observation that architecture–institution trade-offs exist; that observation is well established. What is new is the parametric vocabulary that lets such trade-offs be written down, compared, and (in future work) calibrated against pilot data. Second, two propositions develop M far enough to admit closed-form reasoning. Proposition A identifies the non-binding threshold of a retail holding cap κ and maps it onto the Brunnermeier and Niepelt (2019) neutrality condition [20]. Proposition B characterizes the fixed point of the rule-update map Φ under bounded policy shocks. Third, two stylized numerical exercises operationalize the propositions on illustrative parameter grids, without depending on any particular CBDC pilot dataset. Empirical validation lies beyond the present scope; Section 5 lists calibration against e-CNY, eNaira, and Sand Dollar usage data, and against the digital euro once live, as the principal continuation of this work.
The remainder of the paper is structured as follows. Section 1.4 sets out the methodology and underlying assumptions of the framework. Section 2 analyzes blockchain as critical infrastructure for CBDC, examining architectural choices, privacy technologies, and programmability. Section 3 investigates institutional innovation, ending with a four-jurisdiction comparison in Section 3.4. Section 4 develops the AB2023 model as a formal framework for CBDC institutional design and, in Section 4.4, states two analytical propositions with accompanying stylized numerical exercises. Section 5 concludes with key findings, policy implications, and limitations.

1.4. Methodology and Underlying Assumptions

The methodology is conceptual and analytical. We synthesize the technical CBDC literature with monetary-economics formalism, state two analytical propositions inside the M = (S, R, C, I) framework, and illustrate each proposition with a stylized numerical exercise at parameter values chosen for clarity rather than from calibration. We do not run a DSGE estimation. We do not evaluate any deployed pilot against live transaction data. Both belong to separate research programs.
Three assumptions shape the boundary of what the framework can say.
(A1) Representative-agent set-up. The holding-cap analysis collapses the household side to one representative agent characterized by a composite liquidity preference α and a convenience-yield wedge ρ, with heterogeneity in wealth, age, and digital access absorbed into these two parameters. A micro-data treatment (e.g., replacing the representative agent with a full wealth distribution for the digital euro) lies outside our scope.
(A2) Bounded shock support. The rule-update map Φ in Proposition B is driven by a shock process whose support is bounded—adversarial cases with unbounded tails fall outside the proposition. We test heavy-tailed shocks numerically. The proposition itself is not claimed for that regime.
(A3) Symmetric, non-strategic policymaker. The central bank revises R in response to realized shocks via Φ and does not anticipate strategic counter-moves from private digital-money issuers. Strategic interaction between the central bank and a competing issuer alters the fixed point—we flag that as a continuation, not as something the present framework resolves.
We have revised the text of the paper so that no claim of empirical validation appears where the underlying argument is analytical. The numerical exercises in Section 4.4 are explicit illustrations of the propositions, not validations against pilot data.

2. Blockchain as Infrastructure for CBDC: Architectural Choices

The emergence of CBDC is built upon the increasing maturity of distributed ledger technology. Technological architecture choices and capability characteristics directly determine CBDC’s performance in terms of efficiency, security, privacy, and scalability. This chapter delves into the core role of blockchain technology in CBDC system architecture and systematically examines key design choices and challenges.

2.1. Distributed Ledger vs. Centralized Systems

CBDC design does not necessarily mandate the use of blockchain or DLT, but these technologies offer innovative ideas for addressing certain pain points in traditional financial infrastructure [1]. In practical architectural design, a spectrum exists from fully centralized to fully distributed systems, with central banks’ choices based on trade-offs among multiple objectives [21].
Purely centralized architectures—such as digital upgrades to traditional Real-Time Gross Settlement (RTGS) systems—offer advantages in control, performance, and settlement finality, particularly suitable for high-concurrency retail payment scenarios. For example, China’s e-CNY uses a centralized ledger with the central bank at its core and operating institutions as nodes, designed to meet processing demands of hundreds of thousands of transactions per second [10]. The Digital Yuan processed over 7 trillion RMB by mid-2024 alone, demonstrating the scalability achievable with hybrid architectures [22].
However, in scenarios involving multiple independent participants—such as cross-border or multilateral wholesale settlement—the value of DLT becomes evident. Distributed ledgers, through shared and synchronized databases, enable participants to reach consensus without relying on a single centralized intermediary, enhancing transparency and simplifying reconciliation processes [23].
The International Monetary Fund’s analysis of tokenized reserves distinguishes between three implementation models with varying degrees of centralization and DLT integration [14]. The “compatible ledger model” maintains traditional RTGS systems while establishing technical bridges to external DLT platforms. In contrast, the “single ledger model” places both tokenized reserves and other tokenized assets on a shared distributed ledger, enabling “strict atomic settlement.” Within the single ledger approach, further variants exist: the “integrated model” where central banks govern a dedicated DLT platform; the “distributed model” where central banks co-govern with other stakeholders (exemplified by Project mBridge); and the “separated model” where central banks delegate ledger operation to third parties while retaining issuance authority [14].
The BIS-led mBridge project employs permissioned DLT under a distributed governance model, connecting central banks and commercial banks across different jurisdictions to achieve real-time synchronized delivery-versus-payment for cross-border payments [24]. Research on hybrid blockchains suggests that combining features of public and private ledgers provides conditions to strike a balance between transparency and centralized control [25].
Therefore, many current CBDC projects tend to adopt hybrid architectures: employing centralized or partially centralized designs for the retail layer requiring absolute central bank control and extremely high throughput, while introducing DLT in the wholesale layer or specific functional modules for cross-institutional or cross-border scenarios to leverage multi-party coordination advantages [10,23]. This approach reflects a pragmatic recognition that different use cases require different technological solutions—a key insight for Proposition 1 regarding the contingency of technological choices on institutional requirements. The technological trade-offs among the three architectures are summarized in Table 1.

2.2. Privacy Computing and Controlled Anonymity

“Controlled anonymity” is a core principle in CBDC design, aiming to balance user privacy with compliance requirements such as Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT). Privacy-enhancing technologies (PETs)—including zero-knowledge proofs, multi-party computation (MPC), and oblivious transfer—offer solutions to safeguard end-user privacy while meeting rigorous data protection standards [26].
Zero-knowledge proofs (ZKPs) are particularly relevant for CBDC privacy design. ZKP allows a verifier to be convinced of the truth of a statement without learning any specific information behind it—for example, confirming a transaction is valid and within limits without knowing the specific identities of transacting parties [27]. Recent research has developed quantum-private designs that prevent quantum adversaries from inferring any information about transactions (payer, payee, amounts) [28]. The Rayls system, currently in production with one of the largest clearing houses in the world and being explored in CBDC pilots, demonstrates the practical feasibility of such privacy-preserving architectures [29].
A mainstream design approach for CBDC privacy is tiered or graded anonymity. For small-value transactions, the system can achieve high privacy protection through cryptographic tools. As transaction amounts increase, the system can require higher levels of identity verification. The Swedish Riksbank in its e-krona exploration, and the European Central Bank in digital euro discussions, have both delved into similar graded privacy models [20]. This “value-based privacy” or “risk-based anonymity” architecture relies on sophisticated privacy computing technologies, ensuring regulators can trace large or suspicious transactions under legal authorization while protecting the privacy of daily transactions [11].
The challenge of balancing privacy with regulatory compliance is particularly acute in the context of quantum computing advances. As quantum computers develop, traditional cryptographic assumptions may be undermined, necessitating post-quantum cryptographic solutions [30]. Emerging quantum algorithms pose threats to prevalent public-key cryptosystems like RSA and Elliptic Curve Cryptography, driving the development of post-quantum cryptography standards. Protocols such as MPC and OT remain paramount in ensuring secure and private transactions in this evolving landscape [27]. The trade-off among privacy, compliance, and performance is illustrated in Figure 1.

2.3. Smart Contracts and Programmable Money

The programmability of blockchain, embodied in smart contracts, endows CBDC with functions beyond traditional money. Smart contracts are code stored on the blockchain that automatically execute when predetermined conditions are met. In the CBDC context, this enables conditional and targeted monetary functions. For example, government welfare subsidies can be encoded to be usable only for purchasing specific categories of goods (e.g., food, education) within a specific timeframe, preventing fund misuse [31].
The IMF’s analysis of tokenized reserves emphasizes that programmability is a key breakthrough enabled by the transition from account-based to token-based architectures [14]. When reserves are tokenized on DLT platforms, they can be integrated with smart contracts to automatically execute payment or settlement operations when preset conditions are satisfied, achieving deep integration of value and information. In wholesale finance, smart contracts can automatically execute complex securities transactions (Delivery versus Payment), conditional payments in trade finance, or trigger specific operations based on preset rules during liquidity stress [22].
Project Pine, a research initiative led by the BIS Innovation Hub and the New York Fed, explored how central banks could run monetary policy in a future where money and securities are digital tokens managed on blockchain systems [2]. The project built a working prototype testing whether tools like interest on reserves, repo operations, and asset purchases can be executed using smart contracts. In simulated scenarios, the system automatically conducted reverse-repo operations, responded to liquidity shocks through emergency lending facilities, and settled asset purchases instantly, demonstrating the practical feasibility of programmable monetary policy [2].
This programmability enhances the precision and efficiency of policy execution, reduces operational risk and costs, and opens new space for financial product innovation. However, the security and legal validity of smart contracts, and their potential unintended impacts on money velocity and monetary policy, require careful evaluation [32]. Smart contract vulnerabilities represent significant operational risk, as coding flaws can have cascading consequences. The irreversibility of atomic settlements means errors could propagate rapidly across assets and currencies, potentially triggering systemic clearing crises [14].

2.4. Technology Development Support for CBDC

The feasibility and evolutionary depth of CBDC are closely dependent on the maturity and innovative vitality of underlying blockchain and related technologies. Global technology research and patent landscapes provide a quantitative perspective for understanding the technological foundation of CBDC.
Patent Layout Analysis. Analysis of global blockchain patents reveals that technological innovation is highly concentrated in core areas closely related to CBDC [11]. Privacy protection and encryption technologies—zero-knowledge proofs, homomorphic encryption, secure multi-party computation—are hotspots for patent applications, directly addressing the need for “controlled anonymity.” Secondly, patents related to data sharing and access control mechanisms are numerous, reflecting that secure, efficient data sharing in distributed environments is key to blockchain empowering finance. Finally, patent activity for high-performance transaction systems—consensus algorithm optimization, sharding technology, state channels—is active, aiming to solve scalability bottlenecks to support retail-level transaction pressure [12].
Innovation Ecosystem. Blockchain technology innovation exhibits a clear enterprise-led pattern. Large technology companies, financial institutions, and specialized blockchain firms are the main contributors to patent applications and open-source projects [11]. These entities, leveraging market insights and engineering capabilities, tend to develop technological solutions close to commercial needs—enterprise-grade permissioned blockchain platforms (e.g., Hyperledger Fabric, Corda) and optimized privacy protection tools. In contrast, universities and research institutes focus more on basic theory and cryptographic primitives, providing theoretical support for long-term technological breakthroughs [32].
Regional Differences. From the perspective of patents and project deployments, significant regional differences exist in blockchain technology development. Major economies in North America, Europe, and Asia each have distinct characteristics. For example, innovation in some regions focuses more on underlying protocols and infrastructure, while others may be more rapid in application-layer integration and commercialization [11]. These differences partly stem from varying regulatory environments, industrial structures, and research investments. Research on institutional systems suggests that factors such as rule of law, citizen trust, and financial literacy profoundly shape how CBDCs should be designed across different jurisdictions [15].
However, CBDC, especially its cross-border applications, inherently requires coordination of technical standards and protocols. If CBDCs from different countries adopt incompatible underlying technologies or data standards, new digital silos will form, hindering cross-border payments and financial integration. Therefore, institutions like the BIS and International Organization for Standardization are actively promoting international standards development in digital payments and DLT [33].

2.5. Challenges in Technological Integration

Despite the numerous potentials blockchain technology brings to CBDC, it faces severe technical challenges during practical integration and application.
Performance Bottlenecks. This is the most frequently questioned aspect of applying blockchain to large-scale retail CBDC. Public blockchains constrained by their consensus mechanisms have limited transaction processing capacity. Although permissioned blockchains can significantly improve performance through optimized consensus algorithms, stably supporting peak transactions of tens or even hundreds of thousands per second for nations with hundreds of millions of users requires architectural innovations [10]. Comparative analysis of major CBDC implementations reveals significant performance variations. While China’s digital yuan demonstrates scalability achievable with hybrid architectures, Nigeria’s eNaira achieved only 0.8% adoption rate among banked users by end-2022, and the Eastern Caribbean’s DCash achieved 10% adoption, highlighting challenges of achieving scale in smaller economies [21]. Sharding technology, state channels, Layer 2 scaling solutions, and efficient hybrid architectures are possible directions, but they increase system complexity and security verification difficulty [22].
Security Risks. Security is the lifeline of a monetary system. Blockchain-based CBDC faces unique security challenges. First, post-quantum cryptographic threats: widely used asymmetric encryption algorithms may become vulnerable to future powerful quantum computers [29]. Developing and deploying post-quantum cryptographic algorithms has become urgent. Second, consensus mechanism attacks: even permissioned blockchains may suffer collusion attacks, Sybil attacks, etc., endangering ledger consistency. Third, smart contract vulnerabilities: flaws in code can be exploited, leading to fund loss or system failure [31]. Fourth, traditional cybersecurity risks: node servers, network communication, and key management still face threats such as hacking and DDoS attacks.
Interoperability. The future financial ecosystem will be a complex system with multiple currencies, platforms, and chains coexisting. CBDC needs to interface seamlessly with existing domestic payment systems and potentially interact with other CBDCs, private stablecoins, and traditional bank account systems [34]. This creates extremely high requirements for interoperability. Technically, it requires solving asset transfer, information verification, and state synchronization issues between different blockchains or databases. Interoperability challenges are compounded by fragmentation risk. As payment systems evolve toward regionalization, this increases risk of incompatible standards, duplicated liquidity pools, and rising transaction costs [35]. At business and regulatory levels, unified data standards (e.g., ISO 20022 [36]), legal frameworks, and governance models are needed to ensure legal finality and compliance for cross-jurisdiction transactions [33]. A summary of the key challenges and corresponding countermeasures is presented in Table 2.

3. Institutional Innovation: The Monetary System Under CBDC

The introduction of CBDC extends far beyond the digitization of monetary form. Its deeper significance lies in triggering profound evolution of monetary and financial institutions. This chapter systematically analyzes institutional innovations and challenges driven by CBDC from three dimensions: monetary attributes and legal status, monetary policy transmission mechanisms, and financial stability and risk prevention.

3.1. Monetary Attributes and Legal Status

The birth of CBDC first needs to address its positioning within the existing monetary and legal system, which forms the cornerstone of all institutional design.
From M0 to M2: Reconstruction of Monetary Aggregates. Traditionally, money supply is divided into currency in circulation (M0), narrow money (M1), and broad money (M2). Defining the attributes of CBDC, especially retail CBDC, as a digital form of direct central bank liability is crucial. The vast majority of designs explicitly categorize it into the M0 aggregate—digital cash. For example, the Central Bank of The Bahamas clearly positions the “Sand Dollar” as the digital equivalent of legal tender notes and coins, included in M0 [37]. This positioning has multiple institutional implications. First, it clarifies that CBDC is a direct liability of the central bank, backed by state credit, fundamentally different from commercial bank deposits, ensuring its safety [10]. Second, classifying it as M0 rather than bank deposits aims to minimize initial impact on the deposit base of the banking system, avoiding immediate triggering of severe financial disintermediation.
However, theoretical discussion does not stop there. Some scholars suggest that if CBDC bears interest, especially when negative interest rates become feasible, its monetary attributes may become blurred and pose challenges to monetary statistics and economic analysis frameworks [20]. For instance, if CBDC pays positive interest, it may possess dual functions as both medium of exchange and store of value, blurring traditional boundaries between M0 and M1/M2. If negative interest rates are implemented, it might trigger large-scale conversion of CBDC into cash, affecting monetary policy effectiveness.
From the perspective of the formal framework, the monetary attributes of CBDC can be expressed as:
V = i s s u e r , h o l d e r , v a l u e , Π , σ
where i s s u e r represents the issuing entity (central bank or protocol), h o l d e r represents the current holder, v a l u e represents the face value or current value, Π represents programmable constraints (such as purpose-binding, time restrictions, jurisdictional limits), and σ represents the state (active, locked, expired, redeemed). This formal expression enables precise description of institutional designs such as “controlled anonymity,” “tiered holding,” and “programmable money.” For example, anonymity for small transactions can be manifested by concealing h o l d e r information during transaction verification; tiered holding can be expressed as threshold restrictions on value; programmable money can be expressed as conditional rules preset in Π .
When designing CBDC, different countries exhibit differentiated choices in monetary aggregate positioning based on their respective economic and financial structures and policy objectives. Such differences reflect the trade-offs each country makes among monetary sovereignty, financial stability, and innovation efficiency.
Legal Framework Updates. The legal issuance and operation of CBDC must be premised on a clear and robust legal framework. This typically requires amending or enacting multiple laws. The primary task is clarifying the legal tender status of CBDC. Nigeria, when launching the eNaira, amended the Central Bank of Nigeria Act to explicitly state that “eNaira shall have equal legal tender status with the Naira” [38]. Similar legal confirmation is the basis for guaranteeing finality of CBDC payments, mandatory acceptance, and bankruptcy settlement priority. Without such legal confirmation, CBDC may not attain status equivalent to cash in legal disputes, undermining public confidence.
Secondly, the legal determination of payment finality needs addressing. Traditional payment systems have clear legal points defining irrevocability of payments. For CBDC systems based on DLT, it is necessary to legally confirm at which technical point—after a certain number of block confirmations—final settlement is constituted to eliminate legal uncertainty [39]. This issue is particularly complex in cross-border payment scenarios, as different jurisdictions’ laws may have varying standards for determining “finality.”
Furthermore, adaptations involving privacy and data protection laws, as well as AML/CFT laws, are needed to clarify authority and procedures for regulators to access transaction data under “controlled anonymity” architecture [11]. The EU’s General Data Protection Regulation (GDPR) sets high standards for personal data protection, imposing strict requirements on digital euro design. The European Central Bank’s emphasis on privacy protection in digital euro exploration is precisely to ensure design complies with EU legal framework requirements [22].
Interestingly, legislative approaches to CBDC are not uniform globally. Before 2025, legislative intervention focused predominantly on enabling issuance through legal tender designation. However, the U.S. Anti-CBDC Surveillance State Act (S. 1124) represents a paradigm shift toward prohibition rather than enablement [39]. This divergence reflects fundamentally different conceptions of monetary sovereignty—sovereignty as state capacity versus sovereignty as constitutional restraint—and illustrates how jurisdictions applying identical analytical criteria may rationally reach opposing conclusions [40].
Given the complexity of legal amendments, many jurisdictions have adopted “regulatory sandboxes” as transitional tools. These allow financial institutions to test innovative products based on CBDC or blockchain in controlled environments, while regulators may temporarily exempt certain requirements and closely observe risks [41]. This provides empirical evidence for improving legal frameworks and represents important institutional innovation balancing innovation incentives and risk prevention.

3.2. Transformation of Monetary Policy Transmission

CBDC provides central banks with unprecedented granular tools and potential new transmission channels for implementing monetary policy, potentially profoundly changing policy operation paradigms.
Precision Monetary Policy Tools. The programmability of CBDC allows distribution and use of money to be attached with precise conditions. This enables structural monetary policy and fiscal transfers to be executed with extremely high precision and efficiency. For example, central banks or fiscal authorities can distribute CBDC-form subsidies to specific target groups—SMEs, low-income households, workers in specific industries—and use smart contracts to set that these funds can only be used for designated consumption categories, even restricting geographical scope and time windows for use [30]. This concept of “Purpose Bound Money” has been deeply explored in Singapore’s Project Orchid, whose core idea is ensuring funds flow according to preset rules through programmable protocols [41].
The Bahamas, in designing the Sand Dollar, considered programming social welfare payments to automatically constrain fund use [36]. During crises, such “helicopter money” or targeted liquidity support can bypass financial intermediaries, reaching target entities directly, quickly, and without leakage, while allowing real-time monitoring of policy effects. However, this also sparks profound discussions about boundaries of central bank functions, data authority, and potential distortions in market resource allocation [20]. Critics worry excessive programmability might grant central banks excessive power to intervene in microeconomic activities. Finding balance between precise policy and market freedom constitutes important CBDC institutional design issue.
From the formal framework perspective, monetary policy dynamic adjustment can be expressed as:
R t + 1 = Φ ( R t , p o l i c y _ s h o c k )
where R t is the rule set at time t, p o l i c y _ s h o c k represents a policy shock (such as interest rate adjustments, targeted liquidity injections), and Φ is the rule-update function. This formulation frames CBDC as a rule-modifiable monetary policy instrument, rather than merely a payment innovation. For example, during a financial crisis, a central bank could modify the rule set R t to temporarily increase CBDC holding limits for specific sectors (such as SMEs) or provide incentives for CBDC circulation for specific purposes (such as wage payments). This dynamic rule adjustment capability enables more precise and timely monetary policy transmission.
Interest Rate Transmission and Liquidity Management. The possibility of paying interest on CBDC opens a new door to the monetary policy toolbox. The CBDC interest rate can become a new, direct monetary policy rate instrument. Theoretically, a central bank could influence the yield on risk-free assets held by the public by adjusting the CBDC rate, thereby transmitting more rapidly to bank deposit rates and broader financial markets [18]. This mechanism could enhance monetary policy transmission efficiency, particularly when traditional interest rate channels are obstructed.
In extreme circumstances—under Effective Lower Bound constraints—implementing negative interest rates on CBDC becomes technically more feasible because digital form reduces cost of holding large amounts of physical cash to avoid negative rates, potentially enhancing negative interest rate policy effectiveness [20]. Some scholars suggest CBDC introduction could eliminate the zero lower bound, providing greater operational space for monetary policy. However, negative interest rate policies may also bring side effects, such as encouraging public to convert CBDC into cash or other assets, potentially weakening policy effectiveness instead.
In liquidity management, wholesale CBDC can optimize interbank markets. For example, the European Central Bank’s explored “trigger solutions” envisage allowing commercial banks to automatically convert part of their reserves into wholesale CBDC when needed for instant large-value payment settlement, potentially enhancing payment system efficiency and resilience and changing banks’ liquidity management behavior [22]. Wholesale CBDC can also be used in cross-border payment scenarios, as demonstrated by mBridge project, achieving near-real-time cross-border synchronized settlement through multilateral CBDC platforms, significantly reducing liquidity needs [23].
These new tools and channels require central banks to re-evaluate their monetary policy frameworks and operational procedures. For instance, central banks may need to redesign liquidity management tools to adapt to new behavioral patterns in CBDC environment. Meanwhile, introduction of CBDC interest rates may affect commercial banks’ asset-liability management and credit supply behavior, requiring central banks to closely monitor these impacts and adjust policies promptly. A summary of the key policy tools and their transmission mechanisms is presented in Table 3.

3.3. Financial Stability and Risk Prevention

While improving efficiency, CBDC also introduces new financial stability risks. Its institutional design must incorporate forward-looking risk mitigation mechanisms.
Bank Disintermediation Risk and Tiered Holding Limit Design. This is the most prominent financial stability concern in retail CBDC design. If public can convert bank deposits into safer, central bank-backed CBDC without cost or limits, it could trigger large-scale deposit runs during stress periods, severely weakening commercial banks’ credit creation capacity. The speed of such “digital runs” could be far faster than traditional bank runs, as deposit transfers can be completed instantaneously through mobile phones, presenting new challenges to financial stability.
The transformations in the money ecosystem brought about by CBDCs create opportunities as well as new risks [42]. The need for risk mitigants and potential for risk amplification factors have split practitioners and academics around CBDCs. The endogenous mitigation of risks through improved bank competition often attributed to CBDCs is argued to be uncertain and may be insufficient from systemic risk perspective [42].
To mitigate this risk, mainstream proposals involve introducing tiered holding limits or graduated interest rate systems [20]. The core idea of tiered holding limits is to restrict amount of CBDC individual users can hold, thereby inhibiting large-scale deposit transfers. For example, Nigeria set transaction and balance caps for personal eNaira wallets [35]. This design is straightforward but may limit CBDC’s store of value function.
A more refined design involves applying tiered interest rates to CBDC accounts: paying zero or symbolic positive interest on balances within a certain limit to maintain cash-like attributes, while imposing penalizing negative interest on balances exceeding the limit to discourage use as large-scale store of value [20]. This design can meet daily payment needs while preventing CBDC from becoming a large-scale substitute for bank deposits.
The introduction of an exogenous mitigant in the form of a CBDC holding limit is already a recognized instrument to ensure consistency of a money ecosystem expanded with a CBDC [42]. The calibration of a holding limit on CBDCs leads to effective separation between CBDC and bank deposits, although an open-ended one that could strain bank engagement around expansion. This calls for a rule-based calibration methodology that mitigates time-inconsistency concerns but still addresses the evolving influence of frictions as an important driver of CBDC holding limits [42].
Different countries exhibit differentiated choices in designing tiered limits based on their respective financial structures and policy objectives. For instance, the European Central Bank’s proposed digital euro holding limit is approximately €3000, aiming to balance privacy protection and financial stability [22]. China’s e-CNY adopts a design combining anonymous wallets with real-name wallets, setting different transaction and balance limits according to varying identity verification levels [10]. These differences reflect distinct trade-offs each country makes among financial stability, privacy protection, and innovation efficiency. A comparative overview of CBDC design features across selected jurisdictions is provided in Table 4.
Anti-Money Laundering and Countering the Financing of Terrorism. The digitization and potential traceability of CBDC provide powerful tools for combating illicit financial activities, but design must balance with privacy protection. Systems based on blockchain inherently have auditable transaction records. This characteristic can serve both regulatory compliance and raise privacy concerns.
The “controlled anonymity” architecture institutionally requires establishing graded identity verification and transaction monitoring rules [11]. Small-value transactions may enjoy a high degree of anonymity, while large-value and suspicious transactions must adhere to strict Customer Due Diligence (CDD) and transaction reporting requirements. This graded design aims to balance individual privacy protection with AML/CFT compliance requirements. For example, China’s e-CNY adopts principle of “anonymity for small transactions, traceability for large transactions,” providing anonymous protection for transactions below certain amount while requiring identity verification and transaction tracing for large transactions exceeding thresholds [10].
This necessitates extending existing AML/CFT legal frameworks to CBDC domain and clarifying authority and procedures for regulators to trace and analyze transaction chains after obtaining legal authorization. Simultaneously, cross-border AML/CFT cooperation mechanisms need establishment, as CBDC could be used for cross-border illicit fund flows. The BIS’s Project Pyxtrial explores establishing secure data-sharing nodes between AML systems of different jurisdictions to collaboratively monitor cross-border CBDC flows [40].
In AML/CFT scenarios, the state transition σ of digital currency units needs to be traceable by regulators while protecting legitimate user privacy. Zero-knowledge proof technology can achieve “verifiable but invisible” compliance verification—proving to regulators that transactions satisfy preset conditions Π without exposing specific information about h o l d e r and v a l u e .

3.4. Institutional Environment as a Determinant of Architectural Choice

A persistent question in the comparative CBDC literature is whether the technological choice drives institutional outcomes or the reverse [15]. We take the second view in this section. The architectural choice is downstream of an institutional configuration that already fixes the admissible range of S, R, C, and I in our framework before any technology discussion takes place. Four jurisdictions illustrate this clearly—Singapore, the European Union, the United States, and China—and they cover most of the variation observed across active CBDC programs.
Singapore. The Monetary Authority of Singapore (MAS) operates Project Orchid and the Purpose Bound Money (PBM) protocol as design exercises in which the regulator participates inside the protocol-design loop, not merely as supervisor from outside [41]. PBM attaches conditions—payee, purpose, expiry—at the protocol layer, which maps to a maximally programmable Π in our V tuple. The corresponding I configuration is relatively permissive, with regulatory standing inside the consensus body. The institutional preconditions are high regulator capacity, strong public trust in the financial supervisor, and a small enough financial-sector ecosystem that protocol-level engagement is operationally feasible. None of these preconditions transfers mechanically to a larger or lower-trust setting.
European Union. The European Central Bank has pursued the digital euro since 2021 with privacy and data protection as governing constraints [22]. GDPR acts as a binding constraint on admissible Π, restricting retail programmability to narrow categories—the published preference for offline modes over conditional spending reflects this constraint directly. A proposed holding cap near €3000 sits well below the non-binding threshold κ* for any plausible parameter set in our Proposition A below. The architectural implication is intermediation-heavy: distribution through supervised intermediaries, deliberately limited programmability, and cross-border interoperability pursued through wholesale rails. The pattern is compliance-first.
United States. The Federal Reserve has not committed to a retail CBDC and has expressed preference for waiting on Congressional authorisation. The institutional configuration inverts that of Singapore: high private-sector innovation capacity, low regulatory disposition to participate in protocol design, and—distinctively—a strong constitutional concern about monetary surveillance, reflected in legislative proposals such as the Anti-CBDC Surveillance State Act [39]. In our framework this configuration tightens both R (rules cannot be programmed expansively without legislative authority) and I (no incentive structure can be specified for a program that does not yet exist). If a retail CBDC is eventually pursued in the United States, the architecture is biased toward minimal programmability and arm’s-length intermediation.
China. The institutional preconditions here are centralized governance, high state capacity, and a large domestic user base in which uniform technological roll-out is feasible. The e-CNY operates on these preconditions: a centralized two-tier ledger with the People’s Bank of China as sole issuer and authorized operators (commercial banks) handling distribution [10]. This configuration permits—and the documented design exploits—a broad Π (tiered identity-keyed limits, conditional vouchers in selected pilots) coupled to S issuance fully internal to the central bank. Cross-border functionality is layered onto the centralized retail ledger via separate wholesale rails (mBridge) [23]. The pattern is design- and capacity-driven.
Three points hold for the M framework. The four configurations occupy stable points in the design space rather than transient positions on a convergence path. Identical technological options—a €3000 cap, or its analogue elsewhere—produce different operational outcomes inside different (R, I) settings. The institutional configuration tends to fix the admissible region in M before the architectural choice is finalized; reversing that ordering, fixing the architecture and trusting the institutional environment to accommodate it, is the implicit cause of several stalled pilots that BIS surveys document. For a deeper comparison along these axes that includes operational data from a permissioned-consortium test bed, see Hu and Bogdanov (forthcoming) [43].

4. The AB2023 Model: A Formal Framework for CBDC Institutional Design

The preceding chapters have analyzed technological architectures and institutional innovations separately, but understanding their interaction requires a unified analytical framework. This chapter introduces the AB2023 tokenomic model as a formal tool for integrating technology and institution analyses, enabling parametric calibration of CBDC design. The three ledger architectures and how they map onto the M = (S, R, C, I) framework are illustrated in Figure 2.

4.1. Core Architecture of the AB2023 Model

Drawing on recent research in tokenomics, the AB2023 model reveals dynamic evolutionary patterns of digital financial systems through comprehensive analysis of multi-dimensional parameters [43]. The model comprises several core modules that correspond to the formal framework M = ( S t , R t , C t , I t ) introduced in Section 1.
The model’s core modules include:
  • Initial Parameters: Defines system initial state and boundary conditions—initial node count, user base, total token supply, etc.
  • Token Supply Model: Simulates token issuance dynamics and supply control mechanisms, including minting rules and burning mechanisms. This module corresponds to S t in the formal framework and is conceptually compatible with Kumhof & Noone’s analysis of CBDC balance sheet implications [16], as both focus on how digital currency issuance affects overall system equilibrium.
  • Node Growth Model: Characterizes expansion process of network participants (financial institutions, enterprise nodes) and its impact on network value.
  • User Growth Model: Tracks end-user adoption behavior, reflecting network externality effects. This corresponds to C t (circulation parameters) in the formal framework.
  • Token Price Simulation: Predicts dynamic changes in token prices based on supply–demand relationships and market sentiment.
  • Decentralization Measurement: Assesses power distribution and consensus security of the system—Gini coefficient, node concentration metrics.
  • Aggregated Metrics: Generates comprehensive evaluations of overall system performance, including derived indicators such as network entropy, liquidity, and stability. This corresponds to I t (incentive structure) in the formal framework.
The AB2023 model’s framework has profound theoretical connections with existing macroeconomic research on digital currencies. Kumhof & Noone’s analysis of CBDC balance sheet implications provides foundation for understanding macroeconomic effects of S t and C t [16]; Barrdear & Kumhof’s research on macroeconomic effects of CBDC reveals transmission mechanisms of C t and I t to the broader economy [18]; and Bindseil & Panetta’s discussion of CBDC as monetary policy instrument offers theoretical support for dynamic adjustment of R t [17]. The AB2023 model integrates these disparate theoretical elements into a unified analytical framework. The module structure and data flow of the AB2023 model are illustrated in Figure 3.

4.2. Comparison with Existing Tokenomic Models

To understand the distinctive contribution of the AB2023 model, it is useful to compare it with other mainstream tokenomic modeling approaches.
As Table 5 illustrates, the AB2023 model’s distinctive contribution lies in its multi-angle comprehensive analysis, integrating technological parameters (node growth, decentralization metrics) with economic variables (token supply, price dynamics). This integration makes it particularly suitable for analyzing CBDC systems, where technological choices and institutional outcomes are inextricably linked.

4.3. Implications for CBDC Institutional Design

The parametric analysis approach of the AB2023 model offers important insights for CBDC institutional design. Just as the model simulates network behavior by setting initial parameters and terminal conditions, CBDC institutional design requires calibrating various parameters according to specific economic and social environments to achieve optimal equilibrium under given policy objectives.
Parameterizing Institutional Design. The institutional arrangements discussed in Section 3—tiered holding limits, graduated interest rates, controlled anonymity—can be understood as parameters within the AB2023 framework:
  • Holding limits correspond to constraints on the v a l u e parameter in the digital currency unit representation V = ( i s s u e r , h o l d e r , v a l u e , Π , σ ) . By setting maximum thresholds on v a l u e for different holder types, the system can mitigate bank disintermediation risk while preserving payment functionality.
  • Graduated interest rates represent a dynamic element of the rule set R t , adjusting incentives for holding versus spending CBDC based on policy objectives.
  • Controlled anonymity is encoded in the Π (programmable constraints) and σ (state) parameters, enabling different privacy levels based on transaction characteristics.
  • Programmable money is directly represented by Π , which can specify purpose-binding, time restrictions, or jurisdictional limits.
Calibrating for Different Policy Objectives. Different national contexts require different parameter calibrations. For example:
  • Countries with higher financial stability concerns might set stricter holding limits to prevent deposit substitution.
  • Countries with stronger privacy protection requirements might adopt stronger anonymity protection technologies, reflected in more permissive Π constraints regarding information disclosure.
  • Economies heavily dependent on cross-border trade might prioritize wholesale CBDC and multilateral interoperability protocols, calibrating parameters to facilitate international transactions while managing capital flow risks.
Research on institutional systems suggests that factors such as rule of law, citizen trust, financial literacy, and internet connectivity profoundly influence how CBDCs should be designed across different jurisdictions [15]. This implies that no single parameter configuration is universally optimal—instead, CBDC implementation pathways must exhibit diversity, requiring adaptive adjustments according to different institutional contexts.
Stress Testing and Policy Simulation. Future research could leverage the simulation capabilities of the AB2023 model to conduct stress tests on system behavior under different combinations of institutional parameters. By systematically varying parameters such as holding limits, interest rate policies, and privacy protocols, policymakers could assess potential outcomes—adoption rates, disintermediation risks, transaction velocities—before committing to specific designs. This provides scientific evidence for policy formulation and enables evidence-based calibration of institutional parameters.
This parametric approach to institutional design unifies the technological and institutional analyses from preceding chapters into a single analytical framework, providing theoretical tools for understanding differences in CBDC design across countries and testing the proposition that different architectures exhibit systematic trade-offs between technical performance and institutional adaptability.

4.4. Two Analytical Propositions and Stylized Numerical Exercises

We develop M one step further with two propositions and an accompanying pair of stylized numerical exercises. The propositions state functional relationships and an equilibrium condition, not empirical predictions. Each is followed by an exercise that illustrates the proposition on a parameter grid. The exercises do not constitute empirical validation against any specific CBDC pilot, and we keep that distinction visible throughout.

4.4.1. Proposition A: Threshold Property of the Retail Holding Cap

Take a household with liquid wealth W. Two assets sit on the choice set: a bank deposit and the retail CBDC. A regulator-imposed cap κ ∈ [0, W] applies to the CBDC holding. Two parameters do the heavy lifting: α ∈ (0, 1), the household’s composite affinity for the CBDC (trust in the issuer, financial literacy, low cash habit), and ρ ∈ ℝ, the convenience-yield gap favoring deposits when positive. Both parameters absorb a substantial amount of unobserved heterogeneity; calibrating them against pilot data is left to Section 5.
Without the cap, a log-additive convenience-yield utility yields the unconstrained CBDC share s_uncon(α, ρ) = α/[α + (1 − α)e^ρ], a logistic share that recovers a closely related formulation in [49]. Imposing the cap gives s*(κ; α, ρ) = min{s_uncon(α, ρ), κ/W}.
Proposition A (non-binding threshold). Let κ*(α, ρ) = W · s_uncon(α, ρ) = W⋯α/[α + (1 − α)e^ρ]. The cap is binding for κ < κ* and non-binding for κ ≥ κ. In the binding region, s(κ) = κ/W and is institution-invariant. In the non-binding region, s*(κ) = s_uncon(α, ρ) and is institution-dependent.
Sketch. The above equations follow from the first-order condition of the household problem under the inequality constraint κ. The Karush–Kuhn–Tucker complementarity condition closes the equilibrium at κ = κ; for κ < κ the multiplier is strictly positive, for κ > κ* it is zero. The threshold κ* is the unique value at which the two branches of (2) coincide. Brunnermeier and Niepelt (2019) [20] provide the underlying neutrality argument: when the cap binds, CBDC substitution does not crowd out bank credit if the central bank recycles the inflow through refinancing at deposit-equivalent terms, so κ* is precisely the value at which that neutrality argument switches off. ■
Numerical Exercise 1. We solve (1)–(2) on a grid κ ∈ [0, 30,000] EUR under three illustrative institutional regimes: Strong CBDC affinity (α = 0.55, ρ = −0.10), Balanced (α = 0.40, ρ = +0.05), and Weak CBDC affinity (α = 0.25, ρ = +0.25). Liquid wealth W = 50,000 EUR; random seed 20260511. Figure 4 plots s(κ) for each regime; Table 6 records κ and the implied s* at three reference cap values. The ECB draft cap of €3000 is binding for all three regimes; the Bank of England candidate band 10,000–20,000 GBP enters the non-binding region only for the Weak CBDC affinity case. Below ~€10,000 the institutional differences are invisible: the three curves coincide on s* = κ/W. Past that threshold the differences become first-order—plateau values of 0.21, 0.39, and 0.57 separate the three regimes by roughly 0.18 share points each. The threshold κ* is therefore a useful operational parameter for distinguishing institutional regimes once the cap sits above the kink.

4.4.2. Proposition B: Fixed Point of the Rule-Update Map Φ

Let R_t ∈ [0, 1] be a one-dimensional rule parameter at time t—read as a normalized holding cap, or any other Π-encoded design parameter the central bank revises periodically. Let shock_t be an exogenous policy shock at t with E[shock_t] = 0, finite second moment, and support contained in [−M, M] for some bounded M > 0. The rule-update map is R_{t + 1} = Φ(R_t, shock_t) = clip((1 − λ)R_t + λ⋯R_target(shock_t), [0, 1]) with λ ∈ (0, 1) the adjustment speed and R_target(s) = R ¯ + θs the target rule level. R ¯ ∈ (0, 1) is the neutral target and θ ∈ (0, 1) the target sensitivity.
Proposition B (fixed point and convergence rate). Under the above with E[shock_t] = 0 and bounded support, Φ admits a unique fixed point in expectation, R* = R ¯ , and {R_t} converges in mean square to R* at geometric rate (1 − λ).
Sketch. Taking expectations on both sides of (3) gives the recursion E[R_{t + 1}] = (1 − λ)E[R_t] + λ R ¯ in the unsaturated region; the clipping is inactive when R ¯ ∈ (0, 1) and the shock support is bounded, so E[R_t] → R ¯ at geometric rate (1 − λ). The variance is finite and uniformly bounded under the second-moment condition. Heavy-tailed shocks violate the boundedness premise and sit outside the proposition; the numerical exercise below confirms that the long-run distribution of R_t still concentrates near R* under such shocks, with elevated variance. Structural breaks produce transient departures and re-convergence in the inter-break windows. ■
Numerical Exercise 2. We iterate (3) over T = 100 periods under three shock regimes: Bounded i.i.d. (Uniform[−1, 1]); Heavy-tailed (Student-t with df = 2.5, clipped at ±8 and rescaled); and Structural-break (piecewise large-step shocks at t ∈ [20, 35], [50, 65], [80, 95]). Parameters: λ = 0.25, R ¯ = 0.50, θ = 0.20, R0 = 0.10; random seed 20260511. Figure 5 plots R_t for each regime. Long-run means and standard deviations (computed over t ≥ 50) are 0.517/0.031 (bounded), 0.502/0.053 (heavy-tailed), and 0.457/0.156 (structural breaks). The bounded-shock run sits within one standard error of the analytical fixed point R* = 0.50. The proposition holds within its stated domain and degrades smoothly outside it.

4.4.3. What the Exercises Do and Do Not Establish

Each parameter is chosen for illustrative clarity, not calibrated against a CBDC pilot. The propositions are analytical results inside the model; the numerical exercises are stylized illustrations of those results on a parameter grid. Operational findings from a hybrid permissioned-consortium test bed—including throughput on the order of 28 to 68 confirmed transactions per second across regimes, and a hard ceiling on stake-slashing deterrence at the Byzantine fault-tolerance 1/3 threshold—are reported separately in Hu and Bogdanov (forthcoming) [43]; we cite that work for the operational backing of the incentive-structure claims about I_t without re-running those simulations here. Calibration of (α, ρ, R ¯ , θ) against pilot data remains the highest-priority continuation; Section 5 returns to this.

5. Conclusions

This paper started from a familiar observation in the CBDC literature—that architecture and institutions trade-off—and tried to write it down in a form that is comparable across jurisdictions and calibratable in future work. The vehicle is the tuple M = (S, R, C, I) together with V = (issuer, holder, value, Π, σ): one container in which technological choices and institutional choices both appear as parameters on the same object. The framework is not a new architecture. It is a vocabulary, and we have developed it just far enough to admit two closed-form propositions and a comparative exercise across four jurisdictions.
Proposition A locates a threshold κ* for the retail holding cap above which the cap ceases to bind. Below the threshold the equilibrium share s*(κ) is institution-invariant; above it, institutional differences re-emerge. Proposition B characterizes the fixed point of the rule-update map Φ under bounded policy shocks and reports its mean-square convergence rate. The two stylized numerical exercises in Section 4.4 illustrate the propositions on illustrative parameter grids. They are not validations against deployed CBDC pilots, and we have kept that distinction visible throughout.
The comparative Section 3.4 traces how the institutional environments of Singapore, the European Union, the United States, and China fix admissible regions in M before any architectural choice. Identical technological options yield different operational outcomes once placed inside different (R, I) settings. Reversing the ordering—fixing the architecture and hoping institutions accommodate it—is the implicit cause of several stalled pilots that BIS surveys document.

5.1. Policy Implications

Four points follow for jurisdictions actively designing CBDC programs. Articulate the (R, I) configuration before fixing the architecture; otherwise, the architecture imposes an institutional configuration the jurisdiction may not in fact want. Do not transplant a configuration that worked in a high-trust small jurisdiction (Singapore) to a larger jurisdiction without re-checking whether the underlying preconditions still hold. Treat the holding cap as a parameter rather than a doctrine: Proposition A makes the regime in which cap variation matters distinguishable from the regime in which it does not. Invest in cross-border interoperability before fragmentation locks in; the operational case for participation in shared rails such as mBridge strengthens faster than the case against, on the parameter ranges we have illustrated.

5.2. Limitations and Future Research

Three limitations qualify the conclusions. The analysis is conceptual and analytical; empirical validation against operational CBDC data lies outside the present scope. The M framework does not capture the political-economy dimensions of CBDC adoption—distributional consequences of monetary digitalization, redistribution of seigniorage, geopolitical implications of cross-border platforms—which sit outside the parameter space. The comparative section covers four high-income or middle-income jurisdictions; application to low-income or infrastructure-constrained settings, where financial inclusion matters most, would require re-specifying α and ρ in low-trust low-literacy contexts.
The most pressing continuation is empirical calibration of (α, ρ, R ¯ , θ) against pilot data from e-CNY, eNaira, the Sand Dollar, and—once available—the digital euro. The second is extension to strategic-interaction settings where the central bank anticipates counter-moves from private digital-money issuers. The third is integration with cross-cluster latency modeling along the lines of the virtual-blockchain work of Bogdanov, Khvatov, Uteshev and Shchegoleva (2024) [42], which would tighten the link between the technological architecture dimension of M and observed throughput. None of these continuations sits in the present manuscript; all three are within reach of the framework as set out here.

Author Contributions

Conceptualization, H.B. and A.V.B.; methodology, H.B., V.K. and A.V.B.; software, H.B. and E.S.; formal analysis, H.B.; investigation, H.B.; resources, A.V.B.; writing—original draft preparation, H.B.; writing—review and editing, H.B., V.K., E.S. and A.V.B.; visualization, H.B. and E.S.; supervision, A.V.B. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

The data presented in this study are available on request from the corresponding author. The numerical results are fully reproducible from the fixed random seed and parameter settings described in the manuscript. Code for Numerical Exercises 1 and 2 in Section 4.4 is available from the corresponding author upon request.

Acknowledgments

The authors are grateful to Valery Khvatov for his detailed and constructive comments, which greatly improved the quality of this work. Special thanks go to Aleksandr V. Bogdanov for his continuous guidance and support throughout this research. The authors acknowledge the use of generative AI-assisted technologies for language polishing and editing of the manuscript. The authors have reviewed, edited, and take full responsibility for all content. The scientific ideas, analytical derivations, numerical implementations, and conclusions presented in this paper are entirely the authors’ original work.

Conflicts of Interest

Author Valery Khvatov was employed by the company DGT Technologies AG. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

References

  1. World Bank. Global Payment Systems Survey (GPSS); World Bank: Washington, DC, USA, 2024. [Google Scholar]
  2. Atlantic Council. Central Bank Digital Currency Tracker. Available online: https://www.atlanticcouncil.org/cbdctracker (accessed on 24 April 2026).
  3. International Monetary Fund. Crypto-Assets and Financial Stability. In Global Financial Stability Report; International Monetary Fund: Washington, DC, USA, 2024; pp. 12–15. [Google Scholar]
  4. Chainalysis. The 2024 State of Crypto Crime; Chainalysis Inc.: New York, NY, USA, 2024. [Google Scholar]
  5. Bank for International Settlements. 2023 BIS Annual Economic Report; BIS: Basel, Switzerland, 2023. [Google Scholar]
  6. Frizzo-Barker, J.; Chow-White, P.A.; Adams, P.R.; Mentanko, J.; Ha, D.; Green, S. Blockchain as a disruptive technology for business: A systematic review. Int. J. Inf. Manag. 2020, 51, 102029. [Google Scholar] [CrossRef]
  7. Song, H.; Yang, Y.D.; Tao, Z. The application of blockchain in enterprise financing: A literature review and knowledge framework. Nankai Bus. Rev. 2022, 25, 34–48. [Google Scholar]
  8. Yu, D.J.; Sheng, L.B. Knowledge diffusion paths of blockchain domain: The main path analysis. Scientometrics 2020, 125, 471–497. [Google Scholar] [CrossRef]
  9. Auer, R.; Frost, J. Central bank digital currency and monetary sovereignty. J. Financ. Econ. 2024, 141, 511–523. [Google Scholar]
  10. People’s Bank of China. E-CNY White Paper (2024 Update); China Financial Publishing House: Beijing, China, 2024. [Google Scholar]
  11. Yao, Q. Controlled anonymity in CBDC system architecture. J. Digit. Curr. Res. 2024, 7, 513–529. [Google Scholar]
  12. Bank for International Settlements Innovation Hub. Annual Report 2023; BIS: Basel, Switzerland, 2023. [Google Scholar]
  13. Graduate School of Business, HSE University. Retail central bank digital currency design choices: Guide for policymakers. IEEE Access 2024, 12, 66129–66146. [Google Scholar] [CrossRef]
  14. International Monetary Fund. Conflict of Laws in Cross-Border CBDC Transactions; IMF Policy Paper 2025-003; International Monetary Fund: Washington, DC, USA, 2025. [Google Scholar]
  15. Grosman, A.; Sayyid, A.; Klarin, A. Central bank digital currencies and institutional systems: Design choices based on institutional characteristics. Eur. J. Int. Manag. 2024, 23, 245–271. [Google Scholar]
  16. Kumhof, M.; Noone, C. Central Bank Digital Currencies—Design Principles and Balance Sheet Implications; BIS Working Papers No. 725; Bank for International Settlements: Basel, Switzerland, 2018. [Google Scholar]
  17. Bindseil, U.; Panetta, F. Central Bank Digital Currency as a Monetary Policy Instrument; ECB Working Paper Series No. 2871; European Central Bank: Frankfurt, Germany, 2025. [Google Scholar]
  18. Barrdear, J.; Kumhof, M. The macroeconomics of central bank digital currencies. J. Econ. Dyn. Control 2022, 142, 104148. [Google Scholar] [CrossRef]
  19. Iyengar, G.; Saleh, F.; Sethuraman, J.; Sethuraman, J.; Wang, W. Economics of permissioned blockchain adoption. Manag. Sci. 2023, 69, 3415–3436. [Google Scholar] [CrossRef]
  20. Brunnermeier, M.K.; Niepelt, D. On the equivalence of private and public money. J. Monet. Econ. 2019, 106, 27–41. [Google Scholar] [CrossRef]
  21. Kumhof, M.; Noone, C. Payment Efficiency Gains from Central Bank Digital Currency. In BIS Quarterly Review; Bank for International Settlements, Monetary and Economic Department: Basel, Switzerland, 2024; pp. 22–35. [Google Scholar]
  22. Guliyev, B.; Bethlendi, A. Blockchain vs. centralized ledgers in CBDC: A comparative analysis of efficiency, scalability, and security. Sci. Cult. 2026, 12, 12–27. [Google Scholar]
  23. European Central Bank. Report on a Digital Euro; European Central Bank: Frankfurt, Germany, 2023. [Google Scholar]
  24. mBridge Project Consortium. Phase III Technical Implementation Report; Hong Kong Monetary Authority: Hong Kong, China, 2024.
  25. Panetta, F. Shaping Europe’s Digital Future: The Path towards a Digital Euro; European Central Bank: Frankfurt, Germany, 2023. [Google Scholar]
  26. National Institute of Standards and Technology. Post-Quantum Cryptography for Financial Networks; NIST Special Publication 800-208; U.S. Department of Commerce: Gaithersburg, MD, USA, 2024.
  27. Yaksetig, M.; Pereira, P.M.F.; Yang, S.; Nejadgholi, M.; Xu, J. Rayls II: Fast, Private, and Compliant CBDCs; Paper 2025/1638; IACR Cryptology ePrint Archive: Bellevue, WA, USA, 2025. [Google Scholar]
  28. Yaksetig, M.; Xu, J. Rayls: A Novel Design for CBDCs; Paper 2025/1639; IACR Cryptology ePrint Archive: Bellevue, WA, USA, 2025. [Google Scholar]
  29. National Institute of Standards and Technology. Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process; NIST IR 8413; U.S. Department of Commerce: Gaithersburg, MD, USA, 2022.
  30. Bernstein, D.J.; Lange, T. Post-quantum cryptography. Nature 2017, 549, 188–194. [Google Scholar] [CrossRef] [PubMed]
  31. Central Bank of The Bahamas. Sand Dollar Design Paper: Programmable Fiscal Rules; Central Bank of The Bahamas: Nassau, Bahamas, 2023. [Google Scholar]
  32. Liu, X.; Shan, X.G.; Jiang, N. Analysis of Sino-US blockchain technology competition situation based on patent information. Sci. Technol. Prog. Policy 2020, 37, 18. [Google Scholar]
  33. Committee on Payments and Market Infrastructures. Interlinking Payment Systems and the Role of Application Programming Interfaces; Bank for International Settlements: Basel, Switzerland, 2023. [Google Scholar]
  34. Financial Stability Board. FSB Report on the International Regulation of Crypto-Asset Activities; Financial Stability Board: Basel, Switzerland, 2023. [Google Scholar]
  35. Central Bank of Nigeria. Regulatory Guidelines on the eNaira (CBN Circular); Central Bank of Nigeria: Abuja, Nigeria, 2021.
  36. ISO 20022; Financial Services—Universal financial industry message scheme. International Organization for Standardization: Geneva, Switzerland, 2026.
  37. European Commission. Proposal for a Regulation of the European Parliament and of the Council on the Establishment of the Digital Euro; COM(2023) 369 final; European Commission: Brussels, Belgium, 2023. [Google Scholar]
  38. Zatti, F. From legal tender to prohibition: Competing paradigms in central bank digital currency law. Inst. ZA Uporedno Pravo 2025, 69, 561–575. [Google Scholar] [CrossRef]
  39. Bank for International Settlements Innovation Hub. Project Pyxtrial: Monitoring the Backing of Stablecoins; BIS: Basel, Switzerland, 2024. [Google Scholar]
  40. Monetary Authority of Singapore. Purpose Bound Money Whitepaper; Monetary Authority of Singapore: Singapore, 2023.
  41. Martinez Resano, J.R. CBDCs and the (Calibrated) Tiering of Money: The Financial Stability Arguments; SUERF Policy Note, No. 366; The European Money and Finance Forum: Vienna, Austria, 2025. [Google Scholar]
  42. Bogdanov, A.; Khvatov, V.; Uteshev, A.; Shchegoleva, N. Virtual Blockchain Network for Secure Financial and Industrial Applications. In Proceedings of the ICCSA 2024 Workshops, LNCS 14815, Hanoi, Vietnam, 1–4 July 2024; Springer: Cham, Switzerland, 2024; pp. 142–161. [Google Scholar]
  43. Hu, B.; Bogdanov, A.V. Blockchain as Infrastructure for CBDC: Technological Foundations and Challenges. In Proceedings of the ICCSA 2026 Workshops, Braga, Portugal, 30 June–3 July 2026; Springer: Cham, Switzerland, 2026. [Google Scholar]
  44. Cong, L.W.; Li, Y.; Wang, N. Tokenomics: Dynamic adoption and valuation. Rev. Financ. Stud. 2021, 34, 1105–1155. [Google Scholar] [CrossRef]
  45. Letychevsky, O.; Peschanenko, V.; Radchenko, V.; Poltoratzkyi, M.; Kovalenko, P.; Mogylko, S. Formal verification of token economy models. In Proceedings of the 2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC), Seoul, Republic of Korea, 14–17 May 2019; pp. 201–204. [Google Scholar]
  46. Jürjens, J.; Scheider, S.; Yildirim, F.; Henke, M. Tokenomics: Decentralized incentivization in the context of data spaces. In Designing Data Spaces; Otto, B., ten Hompel, M., Wrobel, S., Eds.; Springer: Cham, Switzerland, 2022; pp. 91–110. [Google Scholar]
  47. Lesavre, L.; Varin, P.; Yaga, D. Blockchain Networks: Token Design and Management Overview; NIST Interagency Report 8301; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2021.
  48. Khvatov, V.; Bogdanov, A. DGT Network Tokenomics—AB2023 Model Specification; DGT Network Technical Report; DGT Technologies AG: Toronto, ON, Canada, 2023. [Google Scholar]
  49. Mishra, B.; Prasad, E. A Simple Model of a Central Bank Digital Currency; Working paper; Cornell University: New York, NY, USA, 2023. [Google Scholar]
Figure 1. CBDC design triangle (privacy—compliance—performance).
Figure 1. CBDC design triangle (privacy—compliance—performance).
Blockchains 04 00012 g001
Figure 2. Three CBDC ledger architectures and the corresponding parameter signatures on the M = (S, R, C, I) framework. In all panels, filled circles represent end retail users; solid lines denote core structural or consensus links; dashed lines denote peripheral participation links.
Figure 2. Three CBDC ledger architectures and the corresponding parameter signatures on the M = (S, R, C, I) framework. In all panels, filled circles represent end retail users; solid lines denote core structural or consensus links; dashed lines denote peripheral participation links.
Blockchains 04 00012 g002
Figure 3. AB2023 tokenomic model scope. Orange boxes represent physical growth models; black boxes represent economic models; solid arrows denote core data flow and dependencies between modules; dashed outlines distinguish physical and economic model groups.
Figure 3. AB2023 tokenomic model scope. Orange boxes represent physical growth models; black boxes represent economic models; solid arrows denote core data flow and dependencies between modules; dashed outlines distinguish physical and economic model groups.
Blockchains 04 00012 g003
Figure 4. Equilibrium CBDC share s*(κ) under three illustrative institutional regimes.
Figure 4. Equilibrium CBDC share s*(κ) under three illustrative institutional regimes.
Blockchains 04 00012 g004
Figure 5. Convergence of R_{t + 1} = Φ(R_t, shock_t) under three shock regimes.
Figure 5. Convergence of R_{t + 1} = Φ(R_t, shock_t) under three shock regimes.
Blockchains 04 00012 g005
Table 1. Technological trade-off matrix for CBDC architectures.
Table 1. Technological trade-off matrix for CBDC architectures.
Design ParameterCentralized LedgerPermissioned DLTHybrid Architecture
ThroughputHighMediumHigh
TransparencyLowHighMedium
GovernanceStrong Central Bank ControlSharedMixed
Cyber RiskSingle-point failure riskByzantine fault toleranceMixed risk profile
Settlement FinalityInstantProgram-dependentTiered
InteroperabilityLimitedHighMedium
Table 2. Assessment of CBDC technical challenges and countermeasures.
Table 2. Assessment of CBDC technical challenges and countermeasures.
Challenge DimensionSpecific ManifestationsSeverityExisting SolutionsResearch Frontiers
Performance BottlenecksThroughput limits, latency, energy consumptionSignificantSharding, Layer 2 scaling, hybrid architecturesZK-Rollups, hardware acceleration
Quantum Computing ThreatsVulnerability of asymmetric encryption algorithmsLong-term high riskMigration to post-quantum cryptographyLattice-based cryptography, multivariate cryptography
Consensus Mechanism AttacksCollusion attacks, Sybil attacksModerateEconomic penalties, node authenticationVerifiable Random Functions
Smart Contract VulnerabilitiesCode defects, logical errorsSignificantFormal verification, security auditingZero-knowledge proof verification
Cross-chain InteroperabilityInconsistent standards, protocol differencesSignificantISO 20022, cross-chain protocolsUniversal cross-chain communication protocols
Traditional CybersecurityDDoS attacks, intrusions, key leakagePersistent threatDefense-in-depth, Hardware Security ModulesZero-trust architecture
Table 3. Assessment of CBDC monetary policy tools.
Table 3. Assessment of CBDC monetary policy tools.
Policy ToolTransmission ChannelPrimary ImpactPotential RiskPrecisionRepresentative Example
Interest-bearing CBDCInterest rate transmissionDirectly affects public risk-free yieldBank deposit substitution, digital runsHighSweden e-krona study [16]
Tiered Balance ToolTiered interest rate/limitsBuffers bank deposit outflowsThreshold calibration difficultyMediumECB €3000 limit [24]
Programmable TransfersTargeted paymentsPrecise fiscal transfers, consumption stimulusData privacy, market intervention concernsVery HighSingapore PBM protocol [41]
Liquidity TriggerAutomatic reserve conversionOptimizes interbank liquidity managementSystem complexityMediumECB trigger solution [21]
Table 4. Comparative analysis of CBDC design across jurisdictions.
Table 4. Comparative analysis of CBDC design across jurisdictions.
JurisdictionTypeArchitecturePrivacy ModelHolding LimitsProgrammabilityCross-Border Readiness
BahamasRetailCentralized + OfflineTiered KYCYes (undisclosed)Fiscal rules engineLimited
ChinaRetailHybrid ArchitectureSmall anonymous, large traceableTiered limitsPilot (vouchers)mBridge
NigeriaRetailCentralizedTiered KYCIndividual ₦500kNoneLimited
SingaporeWholesale + RetailDLT PlatformTiered privacyUnder studyHighly programmable (PBM)Strong
EURetailUnder studyStrong Privacy (GDPR compliant)€3k (proposed)RestrictedUnder study
Table 5. Comparison of AB2023 model with existing tokenomic models.
Table 5. Comparison of AB2023 model with existing tokenomic models.
Model/PaperMain FocusMethodologyKey Features/Findings
Tokenomics: Dynamic Adoption and Valuation [44]Pricing Model of TokensDynamic Asset Pricing Model
-
Equilibrium price determined by transactional demand from heterogeneous users
-
Investigates impacts of network externality, platform growth, and token supply on adoption and token price
Formalization and Algebraic Modeling of Tokenomics Projects [45]Verification and Simulation of TokenomicsAlgebraic Programming and Insertion Modeling
-
Focus on formalizing tokenomics model using algebraic structures
-
Utilizes Maple system for implementation
-
Example model: SKILLONOMY project
Tokenomics: Decentralized Incentivization in the Context of Data Spaces [46]Business Application of TokensComprehensive Guide and Case Studies
-
Outlines various aspects: token types, functions, valuation, distribution, governance, and regulation
-
Presents case studies of successful token projects and best practices
Blockchain Networks: Token Design and Management Overview [47]Token Design and ManagementOverview and Guidelines
-
Provides an overview and guidelines related to the design and management of tokens on blockchain networks
-
Emphasizes secure, reliable, and effective token management practices
-
Addresses technical, governance, and business considerations in token systems
AB2023 Model (Current Model) [48]Analyzing and Projecting Tokenomics BehaviorHybrid Blockchain Economy Modeling
-
Scrutinizes through diverse lenses, offering a multi-angular analysis navigating through network growth and economic dynamism
-
A conduit linking technological proficiency with economic impact, not as a future predictor but as a meticulous research tool
-
Reflects potential behavior and network performance through variable initial and terminal conditions
Table 6. Proposition A numerical summary across three institutional regimes. Liquid wealth W = 50,000 EUR. The non-binding threshold κ* is the cap value at which s_uncon(α, ρ) is just attained.
Table 6. Proposition A numerical summary across three institutional regimes. Liquid wealth W = 50,000 EUR. The non-binding threshold κ* is the cap value at which s_uncon(α, ρ) is just attained.
Regimeαρs_unconκ* (EUR)s* @ κ = 3000s* @ κ = 10,000
Strong CBDC affinity0.55−0.100.574628,7300.06000.2000
Balanced regime0.40+0.050.388119,4030.06000.2000
Weak CBDC affinity0.25+0.250.206110,3050.06000.2000
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Bitai, H.; Khvatov, V.; Savkov, E.; Bogdanov, A.V. Blockchain-Enabled Central Bank Digital Currency: Technological Architecture, Privacy, and Institutional Design. Blockchains 2026, 4, 12. https://doi.org/10.3390/blockchains4030012

AMA Style

Bitai H, Khvatov V, Savkov E, Bogdanov AV. Blockchain-Enabled Central Bank Digital Currency: Technological Architecture, Privacy, and Institutional Design. Blockchains. 2026; 4(3):12. https://doi.org/10.3390/blockchains4030012

Chicago/Turabian Style

Bitai, Hu, Valery Khvatov, Egor Savkov, and Aleksandr V. Bogdanov. 2026. "Blockchain-Enabled Central Bank Digital Currency: Technological Architecture, Privacy, and Institutional Design" Blockchains 4, no. 3: 12. https://doi.org/10.3390/blockchains4030012

APA Style

Bitai, H., Khvatov, V., Savkov, E., & Bogdanov, A. V. (2026). Blockchain-Enabled Central Bank Digital Currency: Technological Architecture, Privacy, and Institutional Design. Blockchains, 4(3), 12. https://doi.org/10.3390/blockchains4030012

Article Metrics

Back to TopTop