The Stablecoin Stack
A stablecoin is sovereign at every layer or at none.
Europe is building its escape from American financial infrastructure on American financial infrastructure. The euro stablecoins designed to give Europe a sovereign digital instrument are being built on US-jurisdiction blockchains, run on US-controlled cloud infrastructure and custodied through US technology providers.
In April 2026, Qivalis, the consortium of twelve European banks designing the European stablecoin response, announced it would use Fireblocks (US technology provider with Israeli founders) for its custody layer. Jan-Oliver Sell, the chief executive of Qivalis, told CoinDesk in March 2026 that operating onchain effectively forces issuers into dollar infrastructure. Two routes to the same destination: procurement (Qivalis) and acquisition (SG-FORGE’s custody provider Metaco bought by Ripple in May 2023, taking SG-FORGE’s European-chosen infrastructure under US jurisdiction).
A stack-contamination test for stablecoins runs five layers, each requiring sovereign verification. The European stack to pass it already exists. European stablecoin sovereignty is a procurement decision Europe is currently making in the wrong direction.
The Escape Vehicle Carries the Dependency
Consider the architectural irony at the centre of Europe’s stablecoin programme. The euro is designed to be a sovereign instrument. The blockchains the euro now needs to live on were designed for the dollar. The custody providers that operate at institutional scale are headquartered in Delaware, New York, or San Francisco. The cloud infrastructure underneath them is American.
The compliance pipelines that determine whose transactions clear are governed by US executive orders that did not exist when MiCA was drafted. Europe is, layer by layer, choosing the operational stack on which its monetary escape vehicle will run. Each individual choice is defensible by ordinary procurement criteria.
The aggregate is a euro stablecoin programme whose operational sovereignty resolves to the same jurisdiction as the dollar systems it is meant to compete with. Everything else in the paper is mechanism, evidence, and remedy.
The pattern is current and named. In April 2026, Qivalis (the consortium of twelve European banks building the most ambitious euro stablecoin Europe has ever attempted) announced that its operational infrastructure partner would be Fireblocks.[1]
The wallet infrastructure, custody, tokenisation engine, identity verification, and sanctions screening for Europe’s flagship euro stablecoin will be provided by Fireblocks Inc., incorporated in the United States, headquartered at 500 Fashion Avenue, New York.
Its custody subsidiary, Fireblocks Trust Company LLC, is chartered as a limited-purpose trust company by the New York Department of Financial Services, regulated under New York Banking Law and the SEC’s Custody Rule.[2] Its Israeli affiliate, Fireblocks Ltd., contracts with non-US customers from Tel Aviv.
Its own published compliance materials list OFAC as the first sanctions list it screens against.[3]
Qivalis is due to launch in the second half of 2026 under Dutch supervision and MiCA authorisation. Its purpose, according to its founders’ joint declaration, is to provide “a genuine European alternative to the US-dominated stablecoin market” and to “contribute to Europe’s strategic autonomy in payments.”[4]
The diagnosis comes from inside the project.
Jan-Oliver Sell, the Chief Executive of Qivalis, told CoinDesk in March 2026: “if you want to operate onchain, you’re effectively forced into the dollar.”[5] He said it as a warning.
He is right that the on-chain euro market is dominated by dollar-denominated tokens, that the rails the euro must use to operate on-chain were built for dollar use cases first, and that the structural pull of those rails is toward the dollar. He is wrong that European banks are forced to use US-jurisdictional infrastructure to participate in this market.
Société Générale’s digital subsidiary, SG-FORGE, has been issuing a MiCA-compliant euro stablecoin since April 2023, on Ethereum, then Solana, then Stellar, then XRP Ledger.[6]
It is in production.
It has approximately five hundred holders. It is the second-largest euro stablecoin globally after Circle’s EURC.[7]
It is small, but it exists.
Sell’s claim that the on-chain euro is technically impossible is empirically false. What is true is that nobody has scaled it, and the architecture being built to scale it reproduces the dependency Sell is warning about, one layer down.
What is also true (and this is the second mode of failure the paper is about) is that even when a European bank does make the European procurement choice, the choice does not stay European. SG-FORGE selected Metaco for its custody and on-chain lifecycle infrastructure in 2022. Metaco was Swiss, headquartered in Lausanne. It was a credible Position 1-equivalent choice at the time.
In May 2023, Ripple (a US company headquartered in San Francisco, incorporated in Delaware, subject to US securities law and OFAC jurisdiction) acquired Metaco for approximately two hundred and fifty million dollars and renamed it Ripple Custody.[8] SG-FORGE now operates EURCV’s reserves, minting, burning, and on-chain lifecycle through Ripple Custody.
The bank did not change its procurement decision. The procurement decision changed underneath it. The acquisition pattern documented in Paper 9 (Solvinity bought by Kyndryl in November 2025, removing the Dutch government’s chosen sovereign cloud provider from European jurisdiction) operated identically here, at the operational layer of the European stablecoin stack.
Two routes to the same destination: procurement (Qivalis) and acquisition (SG-FORGE). The currency is European. The wrapper is European. The reserves are European. The supervision is European. The control is American.
The mechanism by which this happens is stack contamination, applied to monetary infrastructure: a Position 2 wrapper on Position 4 operational infrastructure is Position 4, by the principle Paper 1 introduces and Paper 2 generalises across the stack. The regulatory gap that allows it to happen is that MiCA defends the euro as a currency but does not defend the rails the euro runs on.
The case studies that prove it is happening are Qivalis and SG-FORGE. The remedy that closes the gap is a procurement mandate at the regulated demand layer combined with acquisition protection at the ownership layer, with comprehensive scope across financial services, public sector procurement, and critical infrastructure.
The political coalition that supports the remedy includes the European Central Bank, the European supply-side providers, and, on rational analysis, Qivalis and SG-FORGE themselves. All of that is what follows.
But the first principle, the sentence the reader is meant to carry away, is the architectural irony at the top: the escape vehicle Europe is building reproduces the dependency the escape is meant to remove, and it does so by choice, not by necessity.
The Stack-Contamination Test for Stablecoins
Paper 1 of this series introduced a five-position framework for data sovereignty.[9] Position 1 is national sovereignty: a single member state controls the data and the infrastructure, with no foreign jurisdiction reaching the chain of custody. Position 2 is EU sovereignty: European infrastructure operated by European providers, no entity in the chain subject to non-EU jurisdiction.
Position 3 is distributed sovereignty: no single entity controls the system, mathematical guarantees replace institutional ones, and no foreign state can compel disclosure because there is no single point to compel. Position 4 is shared sovereignty with a foreign state: the appearance of European control over infrastructure that remains subject to foreign jurisdiction.
Position 5 is decentralisation theatre: foreign control delivered through nominally distributed systems whose consensus, governance, or development authority sits under foreign jurisdiction.
The framework introduces a critical principle. Stack contamination operates vertically as well as horizontally. Each layer of a system carries its own position. If any single layer sits at Position 4, the entire stack is contaminated. The effective position is determined by the least sovereign component.[10]
The framework applies here to euro stablecoins. The stablecoin stack has at least seven layers. The issuer entity: who incorporates it, who supervises it, who owns the equity. The reserves: where the backing assets are held, in what jurisdiction, by what custodian. The wrapper regulation: under what regulatory framework the token is issued and supervised.
The tokenisation engine: what software mints, burns, and modifies the smart contract that represents the token. The wallet infrastructure: how end-user and institutional wallets are provisioned, secured, and managed. The sanctions screening: what compliance pipeline screens transactions against which sanctions lists. The public chain: what blockchain network the token is issued on.
MiCA, the European regulation under which Qivalis is being authorised and SG-FORGE has been authorised, addresses the first three of these layers.
It assesses the issuer (incorporation, governance, capital, fit-and-proper criteria), the reserves (1:1 backing, eligible asset classes, custody at regulated credit institutions, segregation), and the wrapper (white paper, conduct, redemption rights, customer protection, ECB consultation for systemic stablecoins).
The regulation has real and important monetary-sovereignty objectives: Articles 23 and 24 give national competent authorities and central banks powers to restrict or prohibit issuance that threatens “financial stability or the EU’s monetary sovereignty.”
Transaction caps on non-euro stablecoins (one million transactions per day, two hundred million euro in payment value) exist specifically to defend the euro’s prominence in everyday payments.[11]
MiCA is not toothless on sovereignty.
But MiCA’s sovereignty toolkit is one-dimensional. It addresses the currency-denomination dimension of monetary sovereignty: keeping euro use euro-denominated, preventing structural dependencies on foreign currencies from emerging in everyday payments. It does not address the operational-jurisdiction dimension: whether the rails the euro runs on are reachable by European law alone.
MiCA assesses the wrapper layers. It does not assess the operational layers or the chain layer. The operational stack underneath a MiCA-compliant euro stablecoin is invisible to the regulator that is supposed to be defending European monetary sovereignty.
The consequence is structural. A euro stablecoin can be Position 1 or 2 at every layer MiCA assesses and Position 4 at every layer MiCA does not. By Paper 1’s stack-contamination principle, the effective position is determined by the least sovereign component. A Position 2 wrapper on Position 4 operational infrastructure is, in effect, Position 4. The wrapper does not save you.
The euro is European. The control is not.
Qivalis demonstrates this. SG-FORGE demonstrates it. Circle’s EURC has always demonstrated it openly, simply by being incorporated in Delaware. The pattern is not exceptional. It is the default outcome of a regulatory framework that does not require Position 1, 2, or 3 at every layer of the stack. MiCA’s sovereignty defence is real but partial.
The unguarded layer is the operational stack, and the operational stack is where the freeze function lives.
The Layer MiCA Cannot See
Where MiCA earns its sovereignty claim is real and worth stating. The euro stablecoin transaction caps are not symbolic. Under Article 24, if a non-euro asset-referenced token is widely used as a means of exchange in the EU, supervisors can require the issuer to limit issuance, restrict use, or cease activity in the EU entirely.
The European Banking Authority, in coordination with the European Central Bank, has direct supervisory powers over significant stablecoin issuers. National competent authorities can require enhanced reporting, stress tests, and corrective measures.
In severe cases, the authority can recommend suspending or revoking an issuer’s licence if it identifies risks to financial stability or monetary sovereignty.[12]
These provisions have teeth. The ECB lobbied throughout the MiCA legislative process to keep them. They are why Tether’s USDT was delisted from major European exchanges in late 2024. The issuer did not comply with MiCA, and the regulation does not permit unauthorised stablecoins to be widely traded for European users.[13]
They are also why Bank of France First Deputy Governor Denis Beau called for further restrictions on non-euro stablecoin use in everyday payments in March 2026 because MiCA’s existing provisions create a foundation that can be tightened further. MiCA did not fail.[14]
What MiCA does not assess is what happens beneath the issuer. When the European Banking Authority and DNB review Qivalis’s licence application, they will examine Qivalis B.V. as a corporate entity. They will assess governance, capital adequacy, reserve composition, redemption terms, and the fit-and-proper status of directors. They will not assess Fireblocks.
There is no requirement, anywhere in MiCA, that the wallet infrastructure provider supplying tokenisation, custody, and sanctions screening to a MiCA-licensed EMT issuer be European-incorporated, European-jurisdictional, or even European-resident. The regulation assumes the issuer is the relevant supervised entity.
The operational stack is treated as a vendor relationship that the issuer manages under its own governance.
This is a structural choice that reflects MiCA’s drafting context. The regulation was written between 2020 and 2023, when the operational stack of digital asset infrastructure was treated as a technical layer comparable to cloud hosting or core banking software.
MiCA’s regulatory cousins (DORA for operational resilience and NIS2 for critical infrastructure) were the instruments expected to handle the supply-chain and ICT-third-party dimensions.
The result is that DORA assesses the operational resilience of stablecoin infrastructure, NIS2 assesses cybersecurity, and MiCA assesses the wrapper, but no instrument explicitly assesses jurisdictional sovereignty of the operational stack. DORA requires concentration risk analysis of ICT third parties; it does not require those third parties to be European.
NIS2 requires supply-chain security; it does not require supply-chain sovereignty.
The gap is precise and consequential. A Qivalis stablecoin running on Fireblocks is fully compliant with MiCA at the wrapper layer, fully compliant with DORA at the operational resilience layer, and fully compliant with NIS2 at the cybersecurity layer.
It can pass three regulatory frameworks designed to defend different dimensions of European resilience and remain Position 4 at the layer where the freeze function lives. This is the regulatory architecture the United States built the GENIUS Act to exploit, and the architecture the Bank for International Settlements has been signalling as inadequate since 2025.
BIS general manager Pablo Hernández de Cos repeated his warning in early 2026 that some dollar stablecoins function more like investment vehicles than money, and called for greater global coordination on stablecoin regulation to address cross-border risks.[15] The cross-border risk MiCA misses is the cross-border control of the operational stack underneath the European wrapper.
Articles 23 and 24 in theory could be used to address this. The provisions empowering NCAs and central banks to act when financial stability or monetary sovereignty is threatened are, in their wording, broad enough to encompass operational-stack vulnerabilities. In practice, they have never been so used. The transaction caps target currency denomination.
The supervisory powers target issuer behaviour. Neither has been deployed against an issuer’s choice of operational vendor.
To extend MiCA’s sovereignty toolkit to the operational stack, either Articles 23 and 24 must be interpreted more expansively than they have been to date, or the regulation must be amended to explicitly require Position 1, 2, or 3 at every layer for euro stablecoins used in defined regulated contexts. The second is cleaner.
The first invites the same regulatory paralysis that has plagued the multi-issuance question for two years.[16]
The European Stack Exists
The argument that Qivalis “had no choice” is empirically wrong. Three production-grade European wallet, custody, and tokenisation infrastructure providers exist today, are used by major European financial institutions, and would have qualified for the role Fireblocks has been awarded.
Dfns is a French company, incorporated in Paris, founded in 2020 by Clarisse Hagège.[17] It is SOC 2 Type II certified and ISO 27001 certified, the standard regulated-institution certifications for digital asset infrastructure.
Its current customer list includes ABN AMRO, Banca Sella, Société Générale, Fidelity, Stripe (via Bridge), Circle, IBM (which selected Dfns as its partner for the Digital Asset Haven enterprise platform launched in late 2025), Deblock (the first MiCA-licensed financial institution in France), Republic, Gemini, and over three hundred other financial institutions.[18]
It secures over five billion dollars in monthly transactions across more than one hundred blockchains. It offers cloud, hybrid, and on-premise deployment models specifically designed for institutions with strict data-residency or compliance requirements, including DORA.
In January 2025 it raised a sixteen-million-dollar Series A from Further Ventures (the venture arm of Abu Dhabi’s ADQ sovereign wealth fund), with participation from Bpifrance (the French public investment bank) and prior investors. It is, by any reasonable measure, productionised European wallet infrastructure that meets institutional regulated requirements.
Taurus is a Swiss company, incorporated in Geneva, founded in 2018, with a banking-grade custody platform used by Deutsche Bank, Santander, Crédit Agricole, State Street, and over thirty-five other major banks and institutions.[19] It is regulated by the Swiss Financial Market Supervisory Authority. Its product covers custody, tokenisation, and trading infrastructure for institutional clients.
Ledger Enterprise is the institutional arm of Ledger, a French company founded in 2014, headquartered in Paris.[20] It provides hardware-rooted custody for institutions, a product line distinct from but related to Ledger’s consumer hardware wallet business. It is used by major European banks, asset managers, and tokenisation platforms.
Three companies. Three European jurisdictions. All productionised, all in active use by major European banks, all meeting the relevant institutional certifications. Qivalis selected none of them.
The most ambitious euro stablecoin project the European banking sector has ever attempted, with twelve major European banks as members and combined balance sheets in the trillions, ran a wallet infrastructure procurement and selected an American company.
It is important to be precise about who made this decision. Qivalis is not a coalition of twelve banks each running a parallel RFP. Qivalis is a single Dutch entity (a B.V. registered in Amsterdam) operating under the executive leadership of Jan-Oliver Sell. The Fireblocks selection was a single procurement decision made by Qivalis B.V., not twelve correlated decisions made by twelve banks.
The member banks endorsed the choice by joining the consortium and continuing to participate; they did not each independently arrive at it. The diagnosis therefore is not “twelve banks converging on the same answer.”
It is that the institutional procurement standards a single decision-maker would apply to wallet infrastructure for an institutional-scale euro stablecoin produce Fireblocks as the answer,
and that the twelve member banks’ risk and procurement committees, asked to review and ratify that answer, would also produce Fireblocks as the answer if they ran the same evaluation against the same matrix.
Why?
The evaluation matrix for institutional wallet infrastructure has the columns it always has: security architecture, MPC sophistication, certifications, insurance limits, blockchain coverage, integration breadth, customer reference list at institutional scale, throughput, uptime, support response times, on-prem deployment options, regulatory track record across jurisdictions, financial stability of the provider.
Fireblocks scores higher on most of those columns than Dfns, Taurus, or Ledger Enterprise. Its valuation is eight billion dollars to Dfns’s order of magnitude lower.[21] Its workforce is more than nine hundred and fifty to Dfns’s roughly eighty. It has integrations with virtually every blockchain that matters to institutional clients.
Its customer list includes the largest exchanges and fintechs globally. Its NYDFS-chartered trust subsidiary provides a regulated custody option at a level of regulatory recognition no European provider can yet match. Its insurance limits, audit history, and incident response capabilities are deeper. On the matrix the procurement officer runs, Fireblocks wins.
This is what Paper 6 calls the rational trap, operating at the level of a single institutional decision. The decision-maker is not biased against the European stack; the decision-maker is applying the institutional procurement standards every regulated bank applies to ICT third parties, against the criteria those standards measure, and the criteria produce Fireblocks.
There is no bad faith in this. There is no European builder being deselected because of prejudice. There is the matrix producing the answer the matrix was built to produce, in a regulatory environment where the matrix does not include “Position 1, 2, or 3 at every layer of the stack” as a column. Add that column, and the matrix produces a different answer.
Without it, the matrix produces structural dependency on the very infrastructure the project exists to replace.
The detail that makes the diagnosis sharp is Banca Sella. Banca Sella is one of the twelve Qivalis member banks. Banca Sella is also a current Dfns customer. Its name appears publicly on Dfns’s institutional client list.
The Italian bank is using French wallet infrastructure for one set of digital asset operations and is part of a consortium that has selected American wallet infrastructure for the most strategically important set of digital asset operations the consortium has ever undertaken.[22]
The decision is not about whether the European stack works. Banca Sella’s own production environment proves that it does.
The decision is about which stack wins on the matrix for this particular use case at this particular scale, and the matrix produces Fireblocks.
This is the rational trap reaching the operational layer of European stablecoin sovereignty in real time, against a European alternative that one of the consortium’s own banks is already a customer of. The European stack was not absent from the decision. It was deselected.
Sovereignty That Can Be Sold
If Qivalis is the procurement problem, SG-FORGE is the second mode of failure: the acquisition problem.
SG-FORGE is the digital-asset subsidiary of Société Générale, the French banking group with roughly 1.7 trillion euro in assets, headquartered in Paris and supervised by the Autorité de Contrôle Prudentiel et de Résolution and the Autorité des Marchés Financiers.
SG-FORGE itself is licensed as an investment firm under MiFID II, authorised as an electronic money institution by ACPR, and registered as a digital asset service provider by AMF.[23] By every visible measure, SG-FORGE is Position 1 at the issuer layer: French entity, French supervision, French parent.
The stablecoin it issues, EURCV, was launched in April 2023 and is one of the first MiCA-compliant euro stablecoins to reach production.
In 2022, when SG-FORGE selected its custody and on-chain lifecycle technology partner, it chose Metaco. Metaco was a Swiss company, headquartered in Lausanne, founded in 2015.
Switzerland is not in the EU but is a credible Position 1-equivalent for sovereignty purposes from a French perspective: bilateral relationships, no Schrems-style legal regime governing the transatlantic data flow, no extraterritorial sanctions reach comparable to OFAC. Metaco was a defensible procurement choice.
SG-FORGE’s chief technology officer, the Société Générale board, and ACPR all signed off on it.
In May 2023, Ripple Labs (a US company headquartered in San Francisco, incorporated in Delaware, subject to US securities law and OFAC jurisdiction) acquired Metaco for approximately two hundred and fifty million dollars. The Swiss provider became a US subsidiary. The product was rebranded Ripple Custody.
SG-FORGE’s custody and on-chain lifecycle infrastructure became operationally American by acquisition. The bank did not change its procurement decision. The procurement decision changed underneath it. SG-FORGE today operates EURCV’s reserves, minting, burning, and on-chain lifecycle through Ripple Custody.[24]
The February 2026 expansion to XRP Ledger, announced one day after the deployment went live, deepens the integration.[25] The Position 1 wrapper now sits on Position 4 infrastructure, contaminated by acquisition.
This pattern is not unique to SG-FORGE. Paper 9 of this series documents the Solvinity case: the Dutch IT services company chosen by Amsterdam municipality and the Dutch Ministry of Justice precisely because it was a Dutch entity outside the reach of the CLOUD Act, acquired by Kyndryl (an American company spun out of IBM) in November 2025.
The Dutch government’s sovereign cloud arrangement became Position 4 by acquisition, with no decision the Dutch government had made. The procurement test had been run. The procurement test had been passed. The acquisition test had not been written.
The implication is uncomfortable. Procurement-only solutions to the operational-stack sovereignty problem are insufficient. Even if a European bank does what SG-FORGE did in 2022 (make the right call at the time of vendor selection) the resulting Position 1 or Position 2 outcome is not stable.
Sovereignty that depends on the European jurisdiction of a private vendor is sovereignty that can be sold. The acquirer pays a premium; the European customer keeps their contract; the contract now runs through US jurisdiction. Nothing in the procurement framework prevents this.
A complete policy response therefore requires two instruments operating together. First, a procurement standard requiring Position 1, 2, or 3 at every layer of the stack for euro stablecoins used in defined regulated contexts: this addresses the Qivalis problem.
Second, an acquisition-protection framework for designated critical infrastructure providers in the European digital asset stack: this addresses the SG-FORGE problem.
The second instrument either requires foreign direct investment screening of acquisitions of designated providers (analogous to FDI screening for defence or telecoms), or contractual fallback rights ensuring European customers can exit a vendor relationship without penalty if the vendor is acquired into non-EU jurisdiction.
Neither instrument exists today. Without both, the SG-FORGE pattern reproduces and the Qivalis pattern is not protected against future SG-FORGE-style outcomes once Qivalis migrates its stack.
The Mechanism Is Already Documented
Paper 27 of this series documents what the United States executive branch did to the International Criminal Court between February 2025 and the present. President Donald Trump signed Executive Order 14203 on 6 February 2025, authorising sanctions against ICC officials investigating US persons or allies.[26]
The chief prosecutor, Karim Khan, a British national working in the Netherlands, had his Microsoft email account cancelled. The ICC ran on Microsoft 365, and when the American government sanctioned an ICC official, the American company complied. Khan’s UK bank accounts were frozen. All nine hundred ICC staff were banned from entering the United States.
By December 2025, the sanctions had expanded in waves to four judges, two deputy prosecutors, and a UN Special Rapporteur, with citizens of the United Kingdom, Canada, France, Slovenia, Italy, Georgia, and Mongolia among the targets.[27]
The financial consequences reached them through private US-incorporated infrastructure providers (Microsoft, Visa, Mastercard, Amazon) that were required to comply with OFAC regardless of where their customers were located or what European law might say.
Canadian judge Kimberly Prost’s credit cards stopped working, her Amazon account was cancelled, a purchased e-book disappeared from her device, her Alexa stopped responding, her daughter could no longer attend professional conferences in the United States.
Francesca Albanese, the Italian citizen and UN Special Rapporteur on the Palestinian territories, sanctioned on 9 July 2025, could not open a bank account in Italy. Italian banks examined the legal position and concluded they could not serve her without risking exclusion from dollar clearing.
This is the precedent. Now apply Paper 13’s “subject swap” move to the operational stack of a Qivalis euro stablecoin.[28]
Imagine, in 2027 or 2028, an ICC official (perhaps a prosecutor investigating a sanctioned ally of the United States, perhaps a judge ruling in a politically sensitive case) is OFAC-designated under whatever the successor framework to EO 14203 then is.
The official’s European bank, somewhere in the eurozone, holds Qivalis euro stablecoins as part of its institutional treasury operations or processes a payroll transaction for the official’s salary. The bank’s compliance system, integrated with Fireblocks’s sanctions-screening pipeline, runs the OFAC list against the transaction.
Fireblocks Inc., as a US person, is required by US law to enforce the OFAC designation. The transaction is blocked. The official is unable to receive their salary in Qivalis euros. The European bank is told the transaction was blocked; it is not told why; the OFAC designation reaches the European bank’s euro stablecoin transactions before any European supervisor sees the transaction.
The ECB is not consulted. The DNB is not consulted. The European judicial process that would ordinarily protect a European citizen (or a non-European individual operating under European supervision) from foreign executive action against their access to a regulated European financial product is bypassed. The screening happened at the operational layer. The operational layer is American.
The wrapper is European, but the wrapper does not see the screening because the screening happens before the wrapper does.
This is the same mechanism applied to a different layer, that has already operated against Karim Khan’s email, against Kimberly Prost’s credit cards, and against Francesca Albanese’s ability to open a bank account in her own country. The architecture admits the possibility. The precedent is documented, recent, and applicable.
The only barrier to its repetition at the Qivalis layer is the political question of whether the US executive branch chooses to extend an existing tool to a new domain.
The dual-jurisdiction exposure makes the risk worse, not better. Fireblocks Ltd. is incorporated in Tel Aviv. Israeli export control law and counter-terrorism financing regimes reach the operational entity through a different door.
The 2025 to 2026 ICC sanctions environment was politically aligned with Israeli policy interests against the ongoing Gaza investigation, and the ICC officials most likely to face designation in any successor framework are precisely the prosecutors and judges working on that investigation.
A European bank holding Qivalis euros on Fireblocks infrastructure is exposed to two foreign jurisdictions simultaneously, both of which have demonstrated, in the past eighteen months, a willingness to use private infrastructure as a policy instrument against European-aligned institutions.
The euro stablecoin Europe is building to escape Washington’s reach is being built with an architecture that admits Washington’s reach at the layer that matters. The architecture also admits Tel Aviv’s. The dependency is not theoretical, the precedent exists, and the mechanism is already operational in the closest analogous infrastructure we have.
What the Architecture Reveals
Qivalis and SG-FORGE both occupy Position 4 at the operational stack layer.
Both are euro stablecoins.
Both are MiCA-compliant or seeking MiCA compliance. Both have made architectural choices that subordinate operational-jurisdiction sovereignty to commercial considerations.
The architectures are similar. The stated reasons for the architectures diverge in revealing ways, and the divergence matters because it tells us which forms of intervention each entity will rationally support.
Qivalis’s stated goals (drawn from its founders’ joint declaration, Sell’s public statements, and the consortium banks’ communications) frame the project around European strategic autonomy.
The September 2025 founders’ declaration described the project as offering “a genuine European alternative to the US-dominated stablecoin market” and “contributing to Europe’s strategic autonomy in payments.”
Sell told CoinDesk that “we want to be the main issuer of euro stablecoins globally” and that the consortium is “building the interface between blockchain and the euro.”
The framing is sovereignty. The political legitimacy of the consortium with the European Central Bank, with the Bank of France calling for further restrictions on non-euro stablecoins, with the European Commission’s CADA drafting bodies, all rests on this framing.
Qivalis is positioned as the institutional answer to dollar dominance.
Qivalis’s revealed goals (what its architecture, timing, and procurement choices show it actually optimising for) are different.
The H2 2026 launch timing is racing against EURC’s market growth: Circle’s euro stablecoin has gone from 17% to 41% of euro stablecoin market capitalisation in twelve months, and Qivalis’s window to compete shrinks every month it is not in market.[29]
The Fireblocks selection reveals that, given the choice between “build on European stack and ship slower” and “build on Fireblocks and ship by H2 2026,” the consortium chose ship-by-H2-2026. The goal was speed-to-market and institutional scale.
Sovereignty was the political wrapper that made the ambition palatable to European policymakers and gave the consortium cover for what is a commercial play.
The participating banks each get a share of reserve yield on euro-area sovereign bonds at scale, the ability to charge transaction fees, the strategic position of having captured institutional settlement before the digital euro lands in 2028 to 2029, and a regulated moat against the next Circle-equivalent. The contradiction between stated and revealed goals is real, current, and writable.
SG-FORGE’s stated goals are different.
Stenger, the SG-FORGE CEO, has been explicit that the project is “an open, secure and institutional-grade platform for digital asset trading.”[30]
The June 2025 USDCV launch with BNY as reserve custodian acknowledged openly that “the stablecoin market remains largely US Dollar denominated” and described USDCV as the “obvious next step” for serving institutional and corporate clients.[31]
SG-FORGE positions itself as institutional plumbing for the on-chain stablecoin market in whatever currency clients need, with a regulated bank as the issuer and a European supervisor as the regulator. Stenger has not claimed the project is about European sovereignty. He has claimed it is about being institutional-grade, regulated, and multi-chain.
SG-FORGE’s revealed goals are consistent with its stated ones. The product is institutional plumbing for a dollar-dominated market. The Ripple Custody dependency, the BNY custody for USDCV, the deployments on Solana and Stellar and XRP Ledger: all are commercial choices made on commercial criteria.
SG-FORGE is honest about being institutional infrastructure for a market that runs on US-jurisdictional rails. There is no contradiction between what SG-FORGE says and what SG-FORGE does. There is, however, a contradiction between SG-FORGE’s actual operations and any claim that SG-FORGE constitutes European stablecoin sovereignty. SG-FORGE does not make that claim.
The claim is made on its behalf by other parties: sometimes by analysts contrasting it with EURC, sometimes by European policymakers seeking proof points that European banks are participating in the stablecoin market.
This asymmetry has policy implications. Qivalis, whose stated and revealed goals diverge, can be moved toward Position 1, 2, or 3 alignment by an intervention that closes the gap between what it says and what it does. The intervention has to make Position 4 architecturally disqualifying for the regulated demand layer Qivalis depends on for institutional scale.
SG-FORGE, whose stated and revealed goals are consistent and inconsistent with sovereignty, can only be moved by an intervention that changes the commercial logic of the on-chain stablecoin market: by creating regulated demand for Position 1, 2, or 3 architecture that exceeds the regulated demand for Position 4 architecture, on commercial terms.
Both interventions are the same instrument. A procurement mandate at the regulated demand layer disqualifies Position 4 for both Qivalis and SG-FORGE on the only criterion where the European challengers can win against the American incumbent (Circle’s EURC, Position 4 at the wrapper by virtue of Delaware incorporation).
For Qivalis, the mandate becomes the regulated moat that justifies the migration cost. For SG-FORGE, the mandate becomes the regulated demand that makes Position 1, 2, or 3 commercially viable. Both issuers, doing the maths, support the mandate.
The proof of this (and the key political fact) is that there is no commercial argument against the mandate that the issuers can make without admitting that their current architecture is structurally subordinate to an American incumbent at the layer that matters. The mandate is the only competitive move European challengers have.
This is also why the market correction has to be regulatory, not voluntary. Voluntary procurement on commercial criteria produces Position 4 by default. SG-FORGE proves that. The market produces Position 4 because Position 4 wins on the commercial matrix. To produce Position 1, 2, or 3 architecture, the matrix has to be changed.
The instrument that changes the matrix is regulation that disqualifies Position 4 for defined use cases. There is no other instrument that produces the outcome.
What the Mandate Looks Like
The structural ask is a single instrument with comprehensive scope across European institutional demand for euro stablecoins.
The instrument is a procurement standard requiring Position 1, 2, or 3 at every layer of the stablecoin stack (issuer, reserves, wrapper regulation, tokenisation engine, wallet infrastructure, sanctions screening, and chain).
The standard applies to any euro stablecoin used in four institutional contexts: financial services regulated under MiCA, DORA, or NIS2; European public sector procurement and payments; CADA-designated critical infrastructure; and Eurosystem operations.
Single instrument.
Wide scope.
Four enforcement vehicles, not four implementation tiers.
The mandate covers comprehensive scope. The mandate generates the demand signal that funds European supply-side scaling only if it spans all institutional euro stablecoin use.
A mandate applied to financial services alone, with public sector procurement and critical infrastructure left for later, produces a demand signal too narrow to fund the supply-side scaling required, and creates immediate political pressure to weaken the financial-services scope to match the smaller demand.
The mandate has to sweep across all institutional contexts in which euro stablecoins are used or could be used, because anything narrower will not generate the volume that makes Position 1, 2, or 3 architecture commercially viable at the scale Qivalis is targeting.
Financial services. The Digital Operational Resilience Act, in force since January 2025, applies to financial services entities and the ICT third parties that serve them. It already requires concentration risk analysis, exit strategies, and continuity planning for ICT third parties supporting critical or important functions.[32]
Extending DORA to require that euro stablecoins used by DORA-scope entities (banks, investment firms, payment service providers, MiCA-licensed CASPs, asset managers, insurers, and others) be Position 1, 2, or 3 at every layer is the cheapest enforcement vehicle to write. The infrastructure for compliance already exists.
Entities are already producing third-party register documentation, dependency maps, and concentration risk assessments. The amendment is to add operational-stack sovereignty as an assessment dimension. The hundreds of thousands of entities within DORA’s scope become anchor customers by construction, and the supervisory machinery to enforce the mandate is already in place.
Public sector procurement and payments.
European governments at the EU, member state, and municipal level (and the public-sector entities that operate under their procurement frameworks, including universities, hospitals, public broadcasters, regulated utilities, and public-sector contractors) are increasingly considering stablecoin rails for specific use cases.
Cross-border treasury operations, public procurement payments, social transfer pilot programmes, and salary disbursement experiments.
Mandating that any stablecoin used in any of these contexts be Position 1, 2, or 3 at every layer creates demand at the public-sector layer to match the demand created at the financial-services layer.
EU public procurement law and member state procurement codes are the existing vehicles. The amendment is to add stack-sovereignty criteria to the existing tender requirements for digital payment rails.
Critical infrastructure under CADA and NIS2. The forthcoming EU Cloud and AI Development Act defines categories of “European data” and “critical infrastructure” subject to enhanced sovereignty requirements. Monetary infrastructure including stablecoins should be explicitly included in the CADA scope, alongside the cloud and AI categories CADA already addresses.
The Policy Brief of this series argues this position. The NIS2 Directive, in force since October 2024, designates critical and important entities across energy, transport, healthcare, water, telecommunications, and other sectors.
Mandating that euro stablecoins used by NIS2-designated entities meet the same Position 1, 2, or 3 standard extends the procurement principle to every domain where European critical infrastructure operators might use stablecoin rails for treasury, settlement, or payment functions.
Naming euro stablecoins as critical infrastructure under CADA and NIS2 gives the mandate a single legislative home and integrates it with the broader sovereignty agenda.
Eurosystem operations. The European Central Bank, as the supervisor of monetary policy and the operator of TARGET, is the highest-stakes institutional customer for euro stablecoins running on European-jurisdiction infrastructure.
The wholesale digital euro project (Appia for cross-currency interoperability and Pontes for connecting the wholesale digital euro to traditional infrastructure) is being built with European-sovereign architecture as a design assumption.[33]
Mandating that any private-issuer stablecoin used in Eurosystem operations or interfacing with Eurosystem settlement be Position 1, 2, or 3 at every layer is the natural extension of this design assumption to the private-issuer layer. The political legitimacy is unambiguous: the ECB has been explicit since its founding that monetary sovereignty is its purpose.
The mandate fits inside the ECB’s existing remit.
The four enforcement vehicles operate together. They are not phased; they are simultaneous. The political case for any one of them is the political case for the others, because the demand-signal argument requires comprehensive scope.
A mandate that applies only to financial services entities will be lobbied down by the financial sector arguing it is at a competitive disadvantage relative to public-sector and critical-infrastructure stablecoin use that is not similarly regulated.
A mandate that applies to all four scopes simultaneously creates a uniform regulatory standard that no individual sector can credibly argue against. This is also the pattern Paper 25 documents in every successful European sovereignty programme: the mandate that worked was the one that swept across all the relevant demand at once.
The coalition that rationally supports this mandate is wider than it might initially appear.
The European Central Bank supports the mandate because the mandate extends ECB monetary sovereignty objectives into the operational stack: a domain the ECB has been signalling concern about since 2024 but has lacked direct regulatory tools to address.
The Bank of France’s March 2026 call for further restrictions on non-euro stablecoins is the public surface of a deeper supervisory discomfort about the operational-stack question. The mandate gives the ECB a tool.
The European supply-side providers (Dfns, Taurus, Ledger Enterprise, and the smaller European wallet, custody, and tokenisation infrastructure firms behind them) support the mandate because the mandate converts their commercial position from competing against Fireblocks on features (which they lose) to being the qualifying European alternative under regulated demand (which they win).
Regulated demand at scale also makes them investable: the Bpifrance, EIF, and member state development bank capital that can fund the supply-side scaling is currently constrained by the absence of guaranteed institutional demand. The mandate creates the demand. The capital follows.
Qivalis supports the mandate, on rational analysis, because the mandate disqualifies its largest competitor on the only criterion where Qivalis can win, and gives Qivalis eighteen to twenty-four months to migrate operational infrastructure in exchange for a regulated moat. The migration cost is real but recoverable. The competitive advantage is structural and durable.
The consortium’s banks, doing the institutional maths, prefer regulated moat with migration cost over no-moat-and-no-migration.
SG-FORGE supports the mandate, on the same rational analysis. The mandate creates regulated demand for Position 1, 2, or 3 architecture at exactly the institutional layer SG-FORGE is positioning to serve.
SG-FORGE’s commercial position is “regulated bank that builds rails for institutional clients in whatever currency the market needs.” The mandate makes Position 1, 2, or 3 the only institutional rail for the regulated euro-denominated demand layer. SG-FORGE’s existing investment in regulatory compliance becomes a moat against unregulated competition.
The coalition is not unanimous (Circle, Tether, and the US-jurisdictional infrastructure providers will oppose) but the European coalition that benefits is broader than the European coalition that loses.
The mandate is the rare regulatory instrument where the European incumbents and the European challengers and the European supply-side and the European supervisors all benefit, and only the foreign incumbents lose. This is the pattern Paper 25 documents in every successful European sovereignty programme. The political alignment exists. The instrument is the missing piece.
The Clock
The clock is not the GENIUS Act. The GENIUS Act is the strategic context: the architecture the United States built to entrench dollar stablecoin dominance globally and to convert every dollar of stablecoin issuance into a dollar of US Treasury demand.[34] Each month that the European mandate does not exist, EURC’s market share grows and the global dollar stablecoin architecture deepens.
But the strategic contest is multi-year, the demand-signal argument is multi-year, and the GENIUS Act is the backdrop.
The clock is that the freeze function is operational today. The mechanism at issue (that the operational layer of a euro stablecoin built on Fireblocks can be reached by US legal process and the consequences will fall on European holders without any European institution being consulted or able to prevent it) is not theoretical.
It has already operated, repeatedly, in the past twelve months, in identical infrastructure. The chief prosecutor of the International Criminal Court, Karim Khan (a British national working in the Netherlands for an institution to which 123 nations are signatories) had his Microsoft email cancelled and his UK bank accounts frozen because the ICC ran on Microsoft 365 and Microsoft is American.
Canadian judge Kimberly Prost found that her credit cards stopped working, her Amazon account was cancelled, an e-book she had purchased disappeared from her device, and her Alexa stopped responding to her voice. Francesca Albanese, the Italian UN Special Rapporteur on the Palestinian territories, could not open a bank account in Italy.
Banca Etica, an Italian ethical bank that wanted to serve her, examined the legal position and concluded that doing so would risk exclusion from dollar clearing. By the end of 2025, four judges, two deputy prosecutors, and a UN Special Rapporteur had been sanctioned, including citizens of the United Kingdom, Canada, France, Slovenia, Italy, Georgia, and Mongolia.
The infrastructure consequences reached them through private American companies (Microsoft, Visa, Mastercard, Amazon) complying with their home jurisdiction’s law because that is what the architecture is designed to do. Their own governments were not the route.
These are precedents in identical infrastructure: private US-incorporated financial-service providers, complying with OFAC designations, applying the freeze function to European-based individuals and institutions, with no European judicial or supervisory process in the loop. Fireblocks is the same kind of provider. The Qivalis architecture being built is the next venue.
The technical mechanism (sanctions screening at the operational layer, executed by a US person before any European supervisor sees the transaction) is identical. The regulatory environment that would have stopped it does not exist.
The political environment that would have made the United States executive branch hesitant to use it does not exist either; if anything, the trajectory of the past twelve months has been toward more aggressive use, not less.
This is the clock. The freeze function works. The precedent is twelve months old. The architecture being built admits the same mechanism. The European mandate that would close the gap does not yet exist.
Every month that passes ships more European money onto the rails, deepens the supply-side dependency, and adds more European institutions to the population whose access to European money runs through American jurisdiction.
The Qivalis launch in the second half of 2026 will be the largest deposit of European institutional money onto US-jurisdictional operational rails in the history of the European stablecoin market. After it ships, migration becomes harder. Before it ships, the architecture is still negotiable.
The instrument is procurement. The political coalition exists. The European stack exists. The freeze function exists too, today, and the precedent for its use is documented and recent. The escape vehicle Europe is building to reduce dollar dependency does not have to carry the dependency. The architecture admits a different choice.
What is required is the will to make it before the architecture is shipped.
[1] Fireblocks announcement of Qivalis partnership, April 2026, reported by Cointelegraph and CoinMarketCap.
[2] Fireblocks Trust Company LLC charter, NYDFS, available via Fireblocks Custody Network public documentation.
[3] Fireblocks compliance documentation, “How to Navigate Stablecoin Compliance: KYC, Travel Rule, Transaction Monitoring.”
[4] Joint declaration of founding banks, 25 September 2025, published via Danske Bank and other consortium members. Qivalis member banks confirmed across multiple sources including BBVA’s announcement of consortium membership and CCN reporting (March 2026).
[5] Jan-Oliver Sell, interview with CoinDesk, 31 March 2026.
[6] SG-FORGE announcements, 2023 to 2026, including initial Ethereum launch (April 2023), Solana deployment (June 2025), Stellar deployment (February 2025), and XRP Ledger deployment (February 2026).
[7] Ledger Insights, “SocGen FORGE goes live with EURCV stablecoin on XRP Ledger,” February 2026, reporting approximately 65.8 million euro circulation and 500-plus holders.
[8] Ripple acquisition of Metaco, May 2023, public reporting.
[9] Paper 1, “The Sovereignty Illusion,” in this series.
[10] Paper 1, “The Five-Position Framework.”
[11] MiCA Regulation, Articles 23 and 24; transaction caps detailed in Title III provisions on asset-referenced tokens.
[12] MiCA implementing measures, ESMA and EBA technical standards.
[13] USDT delistings from major European exchanges, late 2024, following Tether’s confirmation of MiCA non-compliance.
[14] Denis Beau, public remarks, March 2026.
[15] Pablo Hernández de Cos, BIS General Manager, speech at Bank of Japan seminar, Tokyo, 20 April 2026.
[16] Judith Arnal, “Multi-issuance stablecoins and MiCA’s first real credibility test,” CEPS, July 2025.
[17] Dfns corporate registration: SIREN 88817657500056, 142 rue de Rivoli, Paris 1st arrondissement.
[18] Dfns customer disclosures via Crunchbase, Circle Alliance Directory, and corporate communications.
[19] Taurus public corporate information, FINMA registration.
[20] Ledger Enterprise public corporate information.
[21] Fireblocks Series E valuation, January 2022; subsequent reporting confirms continued institutional positioning.
[22] Banca Sella appears on Dfns’s institutional client list (Dfns corporate website, 2026); Banca Sella is also a Qivalis consortium member per BBVA and other consortium communications.
[23] SG-FORGE corporate registration and licences via ACPR and AMF public registers.
[24] SG-FORGE deployment to XRP Ledger reporting, February 2026, including Ledger Insights and SG-FORGE official communications.
[25] SG-FORGE official press release, 19 February 2026.
[26] Executive Order 14203, “Imposing Sanctions on the International Criminal Court,” 6 February 2025.
[27] OFAC designations, June 2025; Paper 30 of this series provides full case-by-case documentation.
[28] Paper 12 of this series, “The Decentralisation Illusion,” develops the “subject swap” methodology in detail.
[29] Circle EURC market share growth, 2024 to 2025; reported across multiple stablecoin market trackers.
[30] Jean-Marc Stenger, public statements via SG-FORGE corporate communications.
[31] SG-FORGE press release, USDCV launch, June 2025.
[32] DORA Regulation (EU) 2022/2554, in force 17 January 2025.
[33] Paper 14 of this series, “The Wholesale Digital Euro,” provides full architectural detail.
[34] GENIUS Act, signed 18 July 2025, US Public Law 119-XX.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →