The $100 trillion case against one smart contract
Every securities market on earth separates issuance from settlement. Ethereum and Solana merged them and called it elegance.

DTC custodies roughly $100 trillion in securities. It issues exactly none of them. That split, where one entity creates the claim and a different one settles its transfer, is not an accident of legacy plumbing. It is the design.
On Ethereum, the same machine does both. BlackRock issues BUIDL as a contract, the network settles every transfer of it, and the result is a token whose holders are visible to anyone with a browser. Issuance and settlement are not separate roles that happen to share a chain. They are one role. Etherscan is the proof.
Walk a regulator through a design that keeps the two apart and they follow it in minutes. It is the shape of every market they oversee. Walk a crypto founder through the same design and the first question is why it is not one smart contract. Same diagram. One room reads competent structure, the other reads wasted motion. Both are reasoning correctly, from different decades.
The separation is the system
Traditional markets do not run on one ledger. They run on a chain of distinct entities, kept separate by regulation.
The issuer creates the claim. The transfer agent keeps the register. The central securities depository, DTC or Euroclear, immobilises and settles. The central counterparty, NSCC or ICE Clear, novates and absorbs default risk.
Four jobs, four balance sheets, four points of failure that do not cascade into each other. When one breaks, the others contain it. Each sits inside its own regulatory perimeter.
That is not bureaucracy. It is the reason one firm blowing up does not take the settlement layer down with it.
Nominal separation versus functional separation
Here is the fair objection. Ethereum separates these too, since the contract deployer is not the validator set. True. But that separation is nominal.
The issuer can gate who holds the asset. Allowlists and freeze functions are routine, and BUIDL itself is whitelisted. What the issuer cannot do is choose who sees it. Every balance, every transfer, every counterparty is published to the whole world. The allowlist controls the guest list, not the one-way mirror. And the control is itself public: when an issuer freezes an address, the freeze is an on-chain event anyone can read.
Settlement is no different. Ordering and finality belong to a validator set the issuer never met, on a chain everyone can read.
Issuance, registry and settlement collapse into a single public machine. Separate on paper. Fused in fact. Solana is the same bargain with the dial turned toward throughput.
The founder's question, why not one contract, is that fusion restated as a feature. And it is not a stupid question. One global state is exactly what gives Ethereum its composability, and an asset that can touch every other asset on the same ledger is genuinely powerful. The model is not wrong. It is answering a different question from the one a depository of that size was built to answer.
What functional separation looks like on-chain
Canton keeps the split real. The issuing party's node controls the asset and its rules: who may hold it, and on what terms it moves. Ordering and settlement finality are a separate role, run by synchronizers operated by other parties, which sequence and finalise transactions without holding or reading their contents.
Selective disclosure means the register is not world-readable. Only the parties to a contract see their slice. And settlement is still atomic: the asset leg and the cash leg commit as one operation, across counterparties and across synchronizers.
Depository-style role separation, with programmable atomic settlement on top.
The production data tracks the thesis. Broadridge's DLR repo platform settled $368 billion in average daily volume on Canton in April 2026, close to $8 trillion for the month, up 268 percent year over year. DTCC will tokenize DTC-custodied US Treasuries on Canton, with an MVP in the first half of 2026. Goldman's Digital Asset Platform runs natively on it. Strategic investors closing in late 2025 included BNY, custodian for $57 trillion in client assets, along with Nasdaq, S&P Global and iCapital.
These are the institutions analysts have in mind when they say trillions are coming on-chain, and they are not deploying on rails that fuse the two jobs.
The tradeoff, stated honestly
This is not free. The price of functional separation and default privacy is the permissionless, fully public composability that powers the other model.
And yes, privacy can be retrofitted onto public chains. Zero-knowledge proofs, private rollups, encrypted mempools. It can be done. The question is what the default is.
On a transparent global chain, each of those is a bolt-on fighting the base layer's nature. On Canton, default-private with opt-in disclosure is the base layer. For a regulated claim, confidentiality you have to engineer back in, against the grain of the system, is not a posture a compliance committee signs.
Privacy as the default, transparency as the deliberate exception. That is the only shape that clears.
Which question is your asset asking?
Two questions resolve most of it.
Confidentiality. Does the asset need to control who can see positions, flows and counterparties? Gating who holds it is solved on both. Visibility is the real fork.
Composability. Does its value come from touching everything else on one open ledger?
The two rooms are not arguing about quality. They are arguing about which question the asset is asking. Pick the rail that answers it.
For a regulated claim, that means keeping the two jobs apart, the way every market that clears tens of trillions already does.


