Research

How Safe Is Safe?

Blockchain security is only one part of the story. For banks entering the world of digital money, the more important question is: who actually controls the asset?

QNTM

2 min read

A bank-grade framework mapping control layers, exposures and risks defining digital asset security.

For years, digital asset security has centred on a simple idea: protect the private key, and you protect the money.

That principle still matters. But for banks and regulated financial institutions, it is no longer enough.

A blockchain can remain cryptographically intact while an asset sitting on it becomes frozen, seized, restricted or operationally unusable. The private key may remain secure while an issuer, custodian, smart contract or legal authority exercises control somewhere else in the system.

The question is therefore shifting.

Not simply: Can the blockchain be hacked?

But: Where does control over the asset actually sit?

The control points institutions need to understand

Different digital assets can sit inside the same wallet while operating under fundamentally different control models.

With Bitcoin, control may sit primarily with the private key and the network. With fiat-backed stablecoins such as USDT or USDC, the issuer introduces another control point. Assets held through exchanges, brokers or custodians introduce additional intermediaries. Above them sit sanctions regimes, courts, regulators and jurisdictions capable of compelling action.

Recent enforcement actions have made that distinction increasingly visible. In April 2026, Tether froze more than $344 million in USDT across two addresses on the Tron network in coordination with OFAC and US law enforcement. Further action followed in July.

The blockchain wasn't broken. The cryptography wasn't cracked.

The control existed somewhere else.

From key security to control architecture

This is the central argument of How Safe Is Safe?, a new QNTM Strategic Research Note.

The paper argues that financial institutions need to move beyond conventional definitions of wallet security and instead evaluate the complete control architecture surrounding an asset.

That means understanding not only who holds the keys, but who can move an asset, freeze it, refuse redemption, expose its flows, compel a transfer, interrupt custody, change a smart contract—or eventually render its underlying cryptography obsolete.

The full paper introduces a bank-grade framework for doing exactly that: three control exposures, five control layers, eight institutional wallet security standards and a ten-category risk taxonomy. It also examines stablecoin issuer risk, Basel disclosure, sanctions, operational resilience, cryptographic lifecycle management and quantum readiness.

The conclusion is straightforward:

A wallet is safe only when the institution understands and governs every control point that can affect the asset.

Read the full position paper

How Safe Is Safe? — Wallet security, digital money, and the new control points in banking explores what security should mean as digital assets move deeper into regulated financial infrastructure.

For banks, regulators, policymakers and institutions building the next generation of digital money, the question is no longer simply whether digital assets are safe.

It is whether we are measuring safety in the right way.

Download the full QNTM position paper

Download the full QNTM position paper