Nyquist Nyquist
CLOSED BETA · 2026 Start a 60-day pilot
Nyquist Research · No. 13 · Literature Review

Digital assets, DeFi & CBDCs: infrastructure outrunning its rails.

A systematic review of digital assets, DeFi, Web3 and central bank digital currencies, 2021–2026, across five domains — AMM market economics, DeFi ecosystem risk, real-world-asset tokenisation, CBDC design, and the regulatory architecture. The ecosystem has passed an inflection point from speculative experiment toward institutional infrastructure. The gap between the pace of technological innovation and the maturity of risk frameworks and regulation is the primary source of systemic instability on the 2026–2030 horizon.

Published
June 2026
Reading time
23 min
Author
Nyquist Research
Topic
DeFi · AMMs · RWA Tokenisation · CBDC · MiCA

Digital assets began as a niche phenomenon with Bitcoin in 2009 and, for most of their first decade, remained an object of speculation and academic curiosity. The 2020–2021 period was transformative: DeFi's Total Value Locked rose from roughly $1bn in mid-2020 to about $170bn at its November 2021 peak, NFTs emerged as a tokenised asset class, the first institutional crypto allocations appeared, and state CBDC programmes launched. By 2026 the landscape is defined by three structural shifts.

First, institutionalisation — BlackRock (BUIDL) and Franklin Templeton (BENJI) run regulated tokenised funds on public blockchains, and on-chain Treasuries are building durable infrastructure. Second, DeFi maturity — third-generation protocols integrate cross-chain interoperability, RWA tokenisation and AI components, creating new capability and new categories of vulnerability together. Third, regulatory coming-of-age — the EU's MiCA entered full force in 2024–2025, the first comprehensive crypto regime in a major jurisdiction, while more than 130 countries study or pilot CBDCs. Academic literature trails markets by 12–18 months; this review systematises five domains where the risk-analytical and regulatory relevance is direct.

01 — The inflection point

From speculation to infrastructure.

The review covers 2021–2026, with primary weight on the analytically mature 2023–2026 window, drawing on arXiv (cs.CR, q-fin, econ), SSRN, IEEE, ACM and official BIS, Federal Reserve, ECB and IMF publications. The inclusion bar was a formal economic or financial-mathematical problem statement — papers treating blockchain as a pure technical platform without financial-economic content were excluded. The five domains span positive research (models, empirics, risk measurement) and normative research (optimal protocol and CBDC design, regulation).

The central thesis is simple and uncomfortable: the digital asset ecosystem is no longer a question of whether it belongs in the financial system — it already does — but of whether its integration strengthens or undermines system resilience. The technological potential of tokenisation is real; the risk architecture of DeFi is different in kind, not merely scale; and the regulatory response is mature on stablecoins and wholesale settlement yet absent on DeFi proper.

02 — AMMs & markets

Automated market makers and depeg risk.

Automated market makers — protocols replacing the order book with an algorithmically maintained liquidity pool — are the central DeFi innovation. They solve liquidity bootstrapping without a traditional market-maker, but introduce impermanent loss (IL) for liquidity providers: value erosion relative to buy-and-hold, driven by arbitrage rebalancing. In the constant-product model (x·y = k), IL is analytically equivalent to a short-volatility position — LPs sell gamma to arbitrageurs for fee income, a bridge that lets the LP token be priced and delta-hedged like an option.

Concentrated liquidity (Uniswap v3) reshaped the LP profile: liquidity is allocated within a narrow range [pₐ, p_b], multiplying fees while the price stays in-range but bearing far greater IL on exit. ML-optimised concentrated strategies, trained on historical swap data, beat uniform allocation by 13–23% in fees at comparable risk. Whether LPs are net-profitable after IL and costs remains open — critically dependent on the pair, horizon and regime. For stablecoin pools, nested Ornstein–Uhlenbeck models with mean-reversion to parity are directly relevant to pricing CBDC liquidity pools where several forms of digital sovereign money coexist.

The Terra lesson

The May 2022 collapse of TerraUSD was formally characterised as a bank run on an algorithmic stablecoin — a Diamond–Dybvig coordination failure, where the UST/LUNA arbitrage created procyclical pressure on both legs. The implication: absent an exogenous value anchor or a lender of last resort, algorithmic stablecoins are structurally vulnerable to coordinated attack once market liquidity is sufficient.

Governance research on MakerDAO/DAI exposed the decentralisation illusion: a systematic gap between formal decentralisation claims and the actual concentration of voting power in a few whale wallets. Network analysis of Uniswap's topology found scale-free, core-periphery structure — liquidity clustered around a few hub tokens, so a shock to a key pool propagates faster than in a flatter network. Both findings carry direct regulatory weight: they complicate liability attribution when a protocol fails.

03 — Risk taxonomy

Twelve risk domains, three categories.

A systematic review of 43 sources (2021–2025) on DeFi 3.0 risk organises twelve risk domains into three categories. The taxonomy is the analytical backbone of the field — and the map against which any institutional risk framework for on-chain exposure should be checked.

CategoryRisk domains
Technology & data infrastructureSmart-contract bugs (reentrancy, overflow, flash-loan exploits) · oracle price manipulation · MEV · cross-chain bridges
Market & economicAMM liquidity risk (IL, fragmentation) · cascade liquidations (Aave, Compound) · stablecoin depeg & shared-collateral contagion · winner-takes-most concentration
Governance, legal & operationalPseudonymity & AML/CFT · DAO jurisdictional vacuum · voting-power concentration · developer key management & rug-pull

The structure matters: technology risk is endogenous to the protocol (a smart-contract bug is not a counterparty default), market risk has analogues in TradFi but realises atomically within a block, and governance risk is where the legal system has the least purchase. No single supervisory discipline covers all three.

04 — Bridges & MEV

The most dangerous attack surface.

Cross-chain bridges have accumulated more than $2.8bn in cumulative exploit losses since 2021. The fundamental flaw is a binary security model — a bridge is either fully operational or catastrophically compromised, with no intermediate state to contain partial failure. This is structurally unlike traditional finance, where circuit breakers and daily withdrawal limits provide buffers. The ASAS-BridgeAMM design (2026) proposes contained degradation — dynamically adjusting collateral haircuts, slippage bounds and withdrawal limits on adversarial signals; in 18-month retrospective testing it cut worst-case bridge-induced insolvency by 73% while preserving 104.5% of transaction volume under stress.

Maximal Extractable Value (MEV) — front-running, sandwich attacks, back-running, reordering — is an intrinsic property of permissioned transaction ordering and levies a persistent tax on ordinary users, redistributed to searchers and proposers. Theoretically it cannot be eliminated by fair-ordering or by purely economic mechanisms alone; a full solution must account for each application's payoff function. That makes MEV categorically harder than HFT front-running, which is regulated at the exchange level — MEV is embedded in the base consensus protocol.

Where the losses actually come from: aggregate blockchain exploit losses hit $2.36bn in 2024 and $2.47bn in H1 2025 alone, with more than 80% attributable to compromised private keys and signature vulnerabilities — not MEV. Infrastructure and key-management risk, not clever value extraction, remains the dominant loss vector.
05 — RWA tokenisation

Institutionalisation, on-chain.

Tokenisation — a digital on-chain representation of a claim over a physical or traditional financial asset — drew unprecedented institutional attention. The BIS calls it "the next logical step in the evolution of money and payments." Tokenised US Treasuries and government money-market funds were the first institutional wave at scale; BlackRock (BUIDL) and Franklin Templeton (BENJI) launched regulated funds on public networks, and BCG/McKinsey/BIS forecasts point to a $10–16tn tokenised market by 2030, contingent on resolving regulatory and infrastructure barriers.

ARCHThree tokenisation architectures.

  • Native — the full lifecycle (issuance, trading, redemption) is on-chain. Maximum efficiency, but needs the smart contract recognised as a legally valid registry.
  • Digital twin / wrapped — a custodian holds the traditional asset backing an on-chain token. Lower regulatory barrier, but retains custodian counterparty risk and a "reality gap".
  • Consortium blockchain — tokenisation within a permissioned network of intermediaries with a controlled gateway to public chains. Balances compatibility against liquidity access.

The economic value is real — programmable DvP eliminating settlement uncertainty, fractional ownership, 24/7 trading, native composability. But it materialises unevenly: standardised instruments (Treasuries, MMFs) tokenise far more successfully than idiosyncratic assets. Empirical work on 58 tokenised Detroit residential properties found extremely low liquidity, wide spreads and concentrated ownership. New risk categories follow the assets on-chain — oracle risk (an off-chain peg destabilises every contract using the token as collateral), uncertain cross-jurisdiction legal enforceability, liquidity fragmentation, and the privacy-versus-compliance conflict.

06 — CBDCs

Design, transmission & stability.

By 2025–2026 more than 130 countries research, pilot or run CBDCs — China's e-CNY, Nigeria's e-Naira, the Eastern Caribbean DCash, Jamaica's JAM-DEX, with the digital euro in implementation-prep after its 2024–2025 legislative framework. Project mBridge (BIS, HKMA, PBOC, CBUAE, BOT) demonstrated near-real-time wholesale cross-border settlement on DLT, bypassing correspondent banking — settlement collapsing from 2–5 days to seconds, materially significant for remittance-heavy emerging markets.

Among design parameters, remuneration is the most economically consequential variable. A non-remunerated CBDC with a holding limit (the digital euro's €3,000 model) is positioned as a payment instrument, not a store of value — a Romania dual-currency stress test found only moderate deposit outflows under that design. A remunerated CBDC opens a direct interest-rate channel to households but raises disintermediation risk: above a sufficient rate, households rationally shift from deposits into CBDC, contracting bank funding and expanding the central bank's balance sheet. Differentiated holding limits for domestic versus foreign digital currencies are critical to preventing uncontrolled euroisation and preserving monetary sovereignty.

Empirics from 23 pilots + 8 implementations

A synthetic-control and event-study analysis (2020–2025) found: interest-rate pass-through to deposit rates improved +12% in active-CBDC jurisdictions; formal account ownership among the previously unbanked rose +7.3pp in emerging economies; first-year deposit outflows averaged 3.2% — manageable but worth monitoring. Interest-bearing CBDCs with holding limits showed the best combination of transmission quality and disintermediation control.

07 — Regulation

MiCA, SupTech & the DeFi vacuum.

MiCA — adopted 2023, in full force 2024–2025 — is the world's first comprehensive crypto regime in a major jurisdiction: mandatory authorisation for stablecoin issuers and crypto-asset service providers, 1:1 reserves for e-money tokens and diversified reserves for asset-referenced tokens, volume limits for "significant" stablecoins, white-paper disclosure, and a crypto-adapted market-abuse regime. What it does not cover is equally consequential: DeFi protocols without an identifiable issuer fall outside the perimeter, creating an arbitrage space between centralised and decentralised finance.

The public nature of blockchain data is a unique supervisory opportunity — regulators gain a complete transaction history unavailable in TradFi. SupTech tools in development include on-chain AML/CFT graph analytics (mixing, structuring, chain-hopping detection beyond threshold rules), real-time DeFi systemic-risk monitoring (TVL, leverage, liquidation health factors), and MEV / market-manipulation surveillance. The countervailing force is privacy-enhancing technology (zero-knowledge proofs, ring signatures, stealth addresses) — a privacy–compliance duality with no clean technical resolution, only a normative choice.

The core normative challenge of DeFi is liability attribution in the absence of an identifiable legal subject.
A DAO is governed by code, but controlled by a few large holders

The debate on regulating DeFi spans from registering developers and governance participants as regulated entities to self-regulation via code audits and on-chain standards. The intermediate activity-based approach — regulating the activity and its risk profile rather than the legal subject — is viewed by the BIS and FSB as most likely to preserve DeFi's innovative potential while controlling systemic risk.

08 — Contagion

The CeFi–DeFi interconnection.

The 2022 collapse (LUNA/UST → Celsius → 3AC → FTX) exposed dense interdependence between centralised and decentralised segments that had been invisible in the growth phase. Contagion ran through shared collateral (LUNA used simultaneously across protocols), mirrored positions (CeFi-lender yield farming on DeFi), and information channels (panic propagating through social media faster than liquidity could adjust). Research on Web3 token price dynamics (2024) found price convergence between centralised and decentralised exchanges for liquid tokens, sustained by arbitrageurs — a de facto unified market.

The implication is sharp: a liquidity shock on a CEX transmits immediately to DeFi and back, which makes the distinction between "traditional-finance risk" and "DeFi risk" largely artificial for systemic purposes. As RWA tokenisation scales and traditional assets serve as on-chain collateral, these channels intensify — a "dual supervision" problem where TradFi regulators must understand on-chain risk and DeFi-oriented tools must account for the off-chain credit and market risk of the underlying collateral.

09 — The agenda

What to build next.

01
Markets

AMM economics under stochastic collateral. Beyond deterministic IL.

Embed jump-diffusion, regime-switching and extreme-value dynamics into IL and solvency assessment — critical when RWAs serve as collateral in concentrated-liquidity pools.

02
Measurement

Systemic risk in DeFi. CoVaR / SRISK, re-derived.

Adapt systemic measures to on-chain specifics: price endogeneity (prices are both oracle inputs and protocol outputs), atomic composability, and the instantaneous realisation of liquidation cascades.

03
Stability

Institutional tokenisation & feedback loops. When run dynamics amplify.

As BlackRock-scale tokenised funds become systemic, model the feedback between on-chain liquidity crises in RWA pools and off-chain markets — tokenised MMF runs could amplify, not dampen, funding-market stress.

Three further priorities: formal mechanism design for optimal wholesale CBDC architecture (permissioned vs permissionless, role models, consensus); the legal-economic nature of DAOs as regulated entities, including the design of voting, quadratic funding and conviction voting; and a systematic welfare analysis of MEV as a user tax — its redistributive consequences, optimal reduction mechanisms, and role in financing network security.

10 — The summary

Key takeaways.

Six sentences worth keeping
  1. The ecosystem crossed the inflection point from speculation to institutional infrastructure — BlackRock and Franklin Templeton are on-chain, MiCA is in force, 130+ CBDC programmes are live.
  2. In an AMM, impermanent loss is a short-volatility position; ML-optimised concentrated liquidity beats uniform allocation by 13–23% in fees — but net LP profitability remains an open question.
  3. Cross-chain bridges are the single most dangerous surface — $2.8bn in cumulative losses on a binary, all-or-nothing security model.
  4. RWA tokenisation creates real value but materialises unevenly — Treasuries tokenise well, idiosyncratic real estate does not.
  5. For CBDCs, remuneration is the master variable; interest-bearing-with-holding-limits best balances transmission against disintermediation.
  6. MiCA matures the stablecoin and wholesale regime, but DeFi remains a regulatory vacuum with growing systemic links to traditional finance.

The digital asset ecosystem in 2026 is a mature-but-still-forming infrastructure with high systemic potential and an incomplete risk profile. Its risk architecture differs from traditional finance not only in scale but in kind — atomic transactions, mempool transparency, governance concentration and MEV have no precise banking analogues. The pressing question is no longer whether digital assets belong in the financial system, but how to ensure their integration strengthens rather than undermines system resilience.

Risk taxonomy
IEEE (2025) — DeFi 3.0 Risk Taxonomy and Pathways to Financial Resilience; arXiv DeFi surveys (2021, 2023).
AMMs
Impermanent Loss in Uniswap v3 (2021); Strategic / Dynamic Liquidity Provision in CLMMs (2021–2025); Pegged-Asset AMMs (2024); Uniswap network analysis (2025).
Bridges & MEV
ASAS-BridgeAMM (2026); MEV Taxonomy, Detection & Mitigation (2024); Towards a Theory of MEV I–II (2023); MEV Sharing (2024).
Tokenisation
Exploration on RWAs (2025); Optimal Design of Tokenized Markets (2021); real-estate token liquidity (PMC); RWA security issues (ACM 2024).
CBDCs
Annual Reviews — Retail CBDC (2024); Fed FEDS — Macroeconomic Implications (2022); CBDC Stress Test in a Dual-Currency Setting (2025); global pilot evidence (2025).
Nyquist publishes literature reviews to keep our own engineering honest against the frontier. The most useful response is not agreement — it is a sharper disagreement on any single claim, with the citation attached.
  About Nyquist

On-chain risk needs the same rails — built in, not bolted on.

A bitemporal ontology and a real-time cross-asset state layer feed 36 named agents and a domain SLM — spanning tokenised RWAs, DeFi exposure, and CBDC scenarios alongside traditional books, with an interpretability and governance layer throughout. Built for decision-grade infrastructure, not leaderboard R².