The $30 trillion that will not tokenize on public chains
Why some assets live on-chain in public, and others structurally cannot.

Etherscan currently displays 54 holders of BlackRock's BUIDL token on Ethereum mainnet. Anyone with a browser can see them. Tether's hot wallets are tracked in real time. Every USDC transfer above $1 million is flagged within seconds.
Now consider what is not on-chain. Goldman's repo book. Apollo's loan-level allocations. Citadel's market-making inventory. The cross-currency basis swaps that move trillions overnight.
Both lists are growing. Neither is converging on the other.
There is a sorting principle nobody states explicitly, and every issuer eventually discovers it: information sensitivity dictates infrastructure.
The scale of what is being left out
Add up the asset classes that cannot live on a transparent public ledger. Global OTC derivatives, more than $600 trillion in gross notional. Bilateral repo, around $5 trillion in daily flows. Securities lending, around $2 trillion. Private credit, more than $1.7 trillion. Active institutional balance sheet positions on top of that.
The total runs to tens of trillions. All of it will tokenize somewhere. None of it will tokenize anywhere a competitor can read it.
What is actually on public chains today
Roughly $30 billion in real-world assets sits on public blockchains, excluding stablecoins, according to RWA.xyz as of May 2026. The mix is dominated by stablecoins themselves at around $300 billion separately, tokenized money market funds such as BUIDL, BENJI and OUSG, tokenized Treasuries, and fund-level wrappers around private credit.
These work in public because the information being exposed is not strategic. A Treasury bill is the same instrument in every account. A money market fund rebalances by formula. There is nothing competitively sensitive to conceal.
Contrast that with what has not moved on-chain at scale, despite years of pilots and billions in invested capital. Active hedge fund positions. Bilateral repo at the trade level. Securities lending inventory. Prime brokerage relationships. Loan-level private credit data. OTC derivatives books. Active market-making inventory. Bank balance sheets.
The reason is the same in every case. Exposing these on a public chain, even with KYC whitelists, multiple addresses or custody-layer pseudonymity, leaks intelligence that competitors will harvest.
When the Federal Reserve studied two tokenized bonds issued on public Ethereum, Santander in 2019 and the EIB in 2021, it found that issuers had to push almost everything operationally meaningful off-chain in order to maintain confidentiality. The blockchain became a thin pointer system.
Privacy is coming, but on whose timeline
The standard response is that public-chain privacy primitives are being built, and that once they ship, the rest of institutional finance will migrate. The list of technologies people cite is familiar, and it is worth examining honestly.
Stealth addresses, proposed as ERC-5564 in August 2022, have been available for nearly four years. No major institutional wallet supports them in production.
Fully homomorphic encryption, championed by Zama and others, is genuinely promising research. Recent academic benchmarks still put it three to six orders of magnitude slower than plaintext computation. That is not production-ready for institutional throughput.
Anonymised RPC endpoints exist in research papers but are not the default in any institutional wallet. Built-in wallet privacy remains unshipped as of 2026.
Each of these is real engineering work and none of it is wasted. But the institutional question is not whether these primitives will exist eventually. It is whether an issuer launching this year should defer for three to five years while waiting for them.
For most, the answer is no. Which is why sensitive asset classes either do not tokenize at all, or tokenize on rails that already provide the privacy properties they need.
Privacy as architecture, not as a feature
Public chains optimise for trustless settlement between unknown, potentially adversarial parties, with global verifiability. Privacy in that model is genuinely hard, because the goal is to give participants confidentiality from observers who hold every byte of state.
For regulated entities the threat model is different. Counterparties are known, KYC'd and legally bound. The parties you need confidentiality from are competitors and the broader market, not anonymous attackers.
You do not need cryptographic guarantees against Byzantine adversaries. You need architectural guarantees that information flows only to entitled parties.
That is the design choice the Canton Network made at the outset. Privacy is not a layer added on top. It is the default.
Whether that is the right answer in every case is a separate question. But the data on what is actually being tokenized is becoming difficult to ignore.
Broadridge's DLR repo platform on Canton settled $368 billion in average daily volume in April 2026, close to $8 trillion for the month, a 268 percent increase year over year. DTCC announced it would tokenize DTC-custodied US Treasuries on Canton, with an MVP in the first half of 2026. Goldman Sachs' Digital Asset Platform runs natively on Canton. Strategic investors closing in late 2025 included BNY, custodian for $57 trillion in client assets, along with Nasdaq, S&P Global and iCapital.
These are the institutions that industry analysts have in mind when they say trillions are coming on-chain. Their actual production volume is running on rails built for their actual privacy requirements.
A practical framework
Two questions resolve most of the public versus private chain decision.
Position-strategic risk. If a competitor sees my position, do I lose alpha?
Counterparty-confidential risk. If the public sees who I am transacting with, am I exposing relationship intelligence?
Issuers who push assets onto rails that do not match their information profile tend to end up in one of three places. They accept the leakage and lose competitive position. They push the meaningful state off-chain and end up with a blockchain that is really an expensive pointer system. Or they delay the launch indefinitely, waiting for primitives that may not arrive on their timeline.
There is a fourth option, which is to choose the rail that matches the asset in the first place. That is increasingly the one institutions are quietly choosing.


