The Dial That Used to Be Fixed
What digital assets need from the economics of cash, finality, and the good-faith purchaser — and why the thing that started as cash is no longer cash
Keywords: digital assets; payment finality; identifiability; store-of-value; account-based payment; pseudonymity; double moral hazard; transferable debt; currency of money; bona fide purchase; nemo dat; distributed ledger
Abstract. Every money before the digital era inherited its place on one axis — the identifiability of the asset — as a fact of its material, and inherited with it a fixed bundle of trade-offs: finality against recourse, anonymity against traceability, cheap casual payment against permanent record. Cash sat at the low-identifiability endpoint and received finality; unique goods sat at the high end and received recovery. A digital asset is the first money-like instrument whose position on that axis is set by protocol rather than by physics. Drawing on the payments economics of Kahn and Roberds (2009), the legal history of money’s currency in Fox (1996), the peer-reviewed microeconomics of cryptocurrencies in Halaburda, Haeringer, Gans and Gandal (2022), and the good-faith-purchase literature of Crawford (2025), Schwartz and Scott (2011), and Levmore (1987), this essay shows that the proof-of-work token sits not at the cash endpoint it claims but in the contested interior of the axis: it is a pseudonymous ledger with probabilistic settlement and a permanent public history, securing neither the anonymity and finality of cash nor the recourse of account systems. The asset that launched at the cash endpoint was carried up the axis by the cost of its own use, shedding the small casual payment that defines that endpoint. What digital assets need from the framework is the discipline to name their coordinate, accept the bundle it carries, and stop claiming the properties of a place they do not occupy.
I. The dial that used to be fixed
Every earlier money inherited its place on one axis without anyone choosing it. Coin sat at one end because a coin is physically indistinguishable from every other coin of its denomination; a named painting sat at the other because it is physically unique and provably yours. The axis is identifiability — the feasibility of picking out a particular unit of an asset and proving who owned it — and for four thousand years it was a fact about the material, not a decision open to the designer. You could not make a shilling more traceable without stamping it into something that was no longer a shilling, and you could not make a Ferrari less traceable without cutting it into parts that were no longer a Ferrari. The law read the material and responded: where identifiability was low, it granted finality, the rule that an honest taker for value keeps what he receives and the former owner’s claim is extinguished; where identifiability was high, it granted recovery, the rule that the owner can trace and reclaim. Money got finality because money’s identifiability was zero as a physical fact.
A digital asset is the first money-like instrument for which that is no longer true. Its identifiability is not handed down by physics. It is written into a protocol, and a protocol is a choice. This essay is about what follows from that single change, and it reaches an unwelcome conclusion for most of the things now called digital money: that the properties they advertise and the properties they possess are not the same properties, and that the gap is exactly measured by where they sit on the axis that used to be fixed. In particular, the asset that launched at the cash end has been moved up the axis until it no longer performs the function — small, casual, final, hand-to-hand payment — that defined the cash end in the first place. The move was not a betrayal of a design. It was the design meeting the economics that govern every point on the axis, economics that were worked out for coins and paintings long before anyone built a ledger.
The framework I am drawing on is not native to digital assets and that is the point of using it. It comes from two literatures that never mention them: the property lawyers’ long quarrel over the good-faith purchaser of stolen goods, and the payments economists’ account of why anyone accepts anything in settlement of a debt. Read together, as I have argued elsewhere, they describe one axis with money at its vanishing point. Digital assets are the case that makes the axis visible, because they are the first assets whose position on it is set by hand.
II. What the two old literatures established
Start with the payments side, because it supplies the vocabulary that cuts. Kahn and Roberds (2009), in the standard economic introduction to the field, reduce every payment arrangement to a machine for overcoming two frictions: a time mismatch between production and consumption, and limited enforcement of promises. When enforcement is cheap and complete, pure credit suffices and nothing resembling money is needed; payment instruments earn their existence only where promises fail. Where they fail, exactly two architectures are available. A store-of-value system transfers an object — coin, note, token — and works if and only if the payee can verify one thing: the genuineness of the object. He need know nothing about the payer, not his name, not his history, not his solvency. An account-based system adjusts entries in a ledger and works if and only if two other things can be verified: the identity of the account holder, and the history of the account. The dichotomy turns on a single question — what must be verified for the payment to clear — and the answer is the object in one case and the identity in the other.
Kahn and Roberds add the result that gives the dichotomy its edge, drawing on a line of monetary theory: money and a complete public record of everyone’s transactions are, in a class of models, substitutes. Money is memory made portable. The balance in a pocket is a bearer-form summary of net past contribution, verifiable by inspection instead of by consulting a database, and this is why the store-of-value form dominates wherever record-keeping is expensive and recedes as record-keeping gets cheap. The store-of-value architecture is the payment system for strangers: no ledger, no identity, no recourse, finality at the moment the object changes hands.
Now the property side, which supplies the history of what happens when a legal system confronts an asset at the low-identifiability end. David Fox (1996) reconstructed how English law came to give money its defining legal attribute, currency: a recipient who takes money in good faith and for value acquires a fresh title, good against the whole world, that does not derive from the transferor’s title at all. The thief who steals your coins acquires nothing; the shopkeeper who innocently takes those coins from the thief acquires everything, and your title is gone at that instant. Currency is the exact opposite of the ordinary rule for property, which lets an owner reclaim from an innocent purchaser under the maxim that no one gives what he does not have. Fox shows the rule had two successive rationales, and the succession is the instructive part. The first was purely evidentiary: coin had, in the phrase of the cases, no earmark, one piece indistinguishable from another, so a former owner could never prove that these coins were his once they mixed with anyone else’s, and the courts held plainly that no action for the specific recovery of loose coin would lie. Identifiability was zero, proof was impossible, and recovery was abandoned not by policy but by necessity.
Then paper changed the physical fact, and the law’s response is the crucial datum. From the 1640s goldsmiths issued handwritten notes bearing dates and the names of payees. For the first time money had earmarks; a stolen note could be identified, advertised, and stopped. Under the evidentiary rationale, notes should have fallen under the ordinary tracing rule like any other identifiable chattel. In Miller v. Race (1758), reported by Fox, the courts refused. Lord Mansfield rejected the no-earmark reasoning as the ground of decision: “The true reason is on account of the currency of it” (as reported in Fox, 1996). Money passes in currency; once it reaches an honest taker for value the former owner’s title is extinguished, earmarks or not. Fox demonstrates Mansfield was ratifying sixty years of mercantile practice, because the alternative was intolerable: a note whose acceptability depended on investigating its provenance would circulate at a discount for title risk, transactions would slow while recipients checked, and the note system, whose whole purpose was to economize on the cost of moving coin, would forfeit its reason to exist.
Read as economics rather than doctrine, Fox’s history establishes something the digital-asset debate has not absorbed: finality for money is not the passive consequence of low identifiability but an active legal decision to treat identifiability as zero even when it is technically positive. The banknote had serial numbers; the law made them legally inert in an honest taker’s hands, because the exchange value of the instrument depended on their inertness. Identifiability is therefore two things at once — a property of the asset and a setting of the regime — and for money the regime deliberately drove it to zero at the point of honest receipt. That is precisely the dial a protocol now sets by hand.
Two features of Kahn and Roberds’ formulation matter for what follows. The first is that the time mismatch they require is weaker than the textbook double coincidence of wants; what is essential is not that no pair of counterparties ever wants what the other has, but that there is an inadequate supply of liquid assets to let exchange proceed as a sequence of spot trades. The second is that limited enforcement is not one friction but a family: it arises from geographical displacement, from an inadequate legal system, and — the strand that bears on digital assets — from informational limits, since an account-based system must incorporate one technology to track an individual’s actions over time and another to verify identities, and is only as good as those technologies. A payment system, on their broad definition, is any arrangement that overcomes the paired frictions of time mismatch and limited enforcement. And they close the point with a sentence that could serve as this essay’s epigraph: over the long run, changes in the underlying economic environment and the consequent structure of payments “will continue to redefine what may be considered ‘money’” (Kahn and Roberds, 2009). What may be considered money is not fixed; it moves as the technologies of tracking and verification move. A protocol is one such change in the underlying environment, and it redefines the boundary by letting a designer set, rather than inherit, the very informational parameters Kahn and Roberds name.
III. What a token actually is, on the record
The digital-asset debate runs on two claims about what a token is: that it is a bearer object like digital cash, and that its ledger makes it immutable and its settlement final. Both claims fail against the economics literature that studies these systems directly. The authority here is Halaburda, Haeringer, Gans, and Gandal (2022), the survey of the microeconomics of cryptocurrencies in the Journal of Economic Literature, read in full for what follows. It matters that the correction comes from inside the field’s own peer-reviewed survey, not from a critic outside it.
Take the bearer claim first. Halaburda et al. describe the mechanics precisely: a user holds not an account in the ordinary sense but a wallet, a pair consisting of a public address and a private key, and the blockchain, in the survey’s words, holds no coins and stores no balances but is “simply a ledger that records all transactions” ever made (Halaburda et al., 2022). The token is not an object that moves from hand to hand. It is an entry in a ledger of all historical transactions, reassigned from one address to another by a recorded operation. In the vocabulary of Kahn and Roberds, that is not the store-of-value architecture at all; it is the account-based architecture — a system of entries in a ledger — wearing the costume of a coin. Halaburda et al. make the identification explicit in a footnote that is worth its weight: the register aspect of the system, they observe, has been likened to the money-as-memory construct of Kocherlakota (Halaburda et al., 2022, citing Kocherlakota, 1998) — the same money-as-memory result that Kahn and Roberds place at the center of their survey. Two independent Tier-one sources thus converge on the same classification: the token is memory, a ledger record, an account entry. It is the thing the store-of-value form was built to avoid.
This is not a quibble about implementation. The whole economic advantage of the store-of-value architecture is that the payee verifies the object and nothing else — no identity, no history. A ledger of all past transactions is the opposite arrangement: history is the substance of the system, not a thing it dispenses with. Whatever else a token is, it is not the payment system for strangers that cash is, because cash carries no record and the token is nothing but record.
Now the identity question, where the literature is equally exact and equally contrary to the marketing. Halaburda et al. state that authentication with a private key, the survey states, proves only that the sender holds the private key for the address and does not prove who the sender is (Halaburda et al., 2022). An address is a pseudonym, not an anonym and not an identity. This is a genuinely intermediate position on the axis, and it is worth being precise about why. Cash is anonymous: the object carries no identifier at all, and its history is unrecoverable. A registered painting is identified: the asset is bound to a named owner in a database. A token is neither. It is pseudonymous: every transaction it was ever part of is permanently and publicly recorded against a persistent identifier, while the mapping from that identifier to a legal person is left outside the system, to be established or not by other means. The history is total; the identity is detachable. That is a point in the middle of the identifiability axis, and it is a point no physical asset could ever occupy, because no physical asset can carry a complete public transaction history while withholding the name of its holder. The protocol builds a location on the axis that physics does not offer.
IV. The finality that is not there
The second claim — immutability, final settlement — is the one the literature contradicts most sharply, and it is the claim on which the case for tokens as cash chiefly rests. Cash has finality in the strong sense Fox described: once the honest taker has the coin, no prior claim survives, full stop. Does a token have that? Halaburda et al. answer directly, and against the popular understanding. On immutability the survey is blunt: it calls the common conclusion that the record is immutable misleading, because electronic records can always be modified, and what consensus achieves is only that modification becomes hard to execute undetected (Halaburda et al., 2022). Consensus plus proof-of-work does not make the ledger unchangeable; it makes undetected change costly. Those are different properties, and only the first is finality.
On settlement specifically, the mechanism the survey describes is probabilistic, not final. Disagreement about the state of the ledger — a fork — is, in the authors’ account, an expected occurrence (Halaburda et al., 2022), and a token’s value in a given block, the survey notes, depends crucially on whether that block is recognized by other users once a fork is resolved (Halaburda et al., 2022). A payment recorded in a block that is later orphaned did not, in the end, happen. The survey documents that this is not hypothetical — it points to the hard fork of 1 August 2017 as a live instance of consensus splitting over the rules — and it catalogues, following the security literature it surveys, that an attacker with sufficient mining power can prevent transactions from confirming and can double-spend, even while noting the offsetting fact that an attacker cannot alter others’ transactions without their keys. The relevant conclusion for the present argument is narrow and firm: token settlement is a probability that rises toward one as confirmations accumulate, subject to reorganization and to fork, and it is never the categorical extinguishment of prior claims that the law grants to cash. On the axis, this is not the finality endpoint. It is somewhere short of it, and the distance is the reorganization risk the survey describes.
Put the two findings together and the standard picture inverts. A token is sold as anonymous bearer cash with instant final settlement. The peer-reviewed economics of the system says it is a pseudonymous ledger entry with probabilistic settlement and a public, permanent history. On identity it sits above cash, because it records a persistent identifier cash never carries. On finality it sits below cash, because its settlement can be undone by a reorganization cash is not subject to. It is not at the cash endpoint on either coordinate. It is in the interior of the axis on both, and the interior, as the older literatures show, is the contested, high-friction, recourse-bearing region — the region of goods, not of money.
V. The anonymity that cash has and tokens do not
One property is worth isolating because the digital-asset case most often claims it and the peer-reviewed literature most cleanly denies it: anonymity. Kahn and Roberds are precise about what anonymity does in a store-of-value system and what it costs. The store-of-value form requires the payee to verify the object and know nothing of the payer, and this informational parsimony is the source of both cash’s usefulness and its dangers. They note that the limited information associated with cash is what allows its use in payment for illegal activity, and that cash is correspondingly limited by its susceptibility to theft, so that account-based systems are the safer alternative on that particular margin (Kahn and Roberds, 2009, citing Camera, 2001, and He et al., 2005). Anonymity, in the payments literature, is a real and double-edged property: it frees exchange from surveillance and it removes the records that deter and unwind wrongdoing, and an instrument either has it or does not.
A proof-of-work token does not have it. The mechanics in Halaburda et al. are unambiguous on this: every transaction is recorded, permanently and publicly, against a persistent address, and the address proves key-possession while withholding legal identity. This is the reverse of cash’s informational profile. Cash keeps no record and reveals no identity; the token keeps a total record and merely detaches the identity, an attachment that other institutions routinely supply at the edges. The consequence is that the token secures neither of the things anonymity is wanted for. It does not deliver the surveillance-freedom of cash, because the ledger is a permanent public history that superior analysis can often de-pseudonymize; and it does not deliver the recourse-and-recovery of the account systems that Kahn and Roberds call the safer alternative, because its holders are, at the protocol level, nameless. It is exposed on both counts: recorded enough to be traced, nameless enough to be unrecoverable. The framework locates this as the worst of the interior for a party who wanted anonymity — a coordinate offering the traceability of the account world and the irrecoverability of the cash world at once, which is the opposite of what either endpoint offers. A holder seeking the actual anonymity of cash is, on the peer-reviewed evidence, not getting it from a public pseudonymous ledger, and the belief that he is is the single most consequential misreading of the coordinate these instruments occupy.
VI. The double moral hazard, ported to the ledger
There is a result in the good-faith-purchase literature that transfers onto digital assets with almost no modification, and because the source work is loaded and directly on point, it must be engaged rather than gestured at. Schwartz and Scott (2011) identified what they called the double moral hazard at the heart of the stolen-goods problem: an owner takes optimal precautions against theft only if she bears the loss when theft succeeds, and a buyer investigates his seller’s title optimally only if he bears the loss when the goods prove stolen, and both conditions cannot hold at once, because the loss can sit on only one side. Every categorical rule that assigns the loss fully to one party destroys the other party’s incentive to take care. This is not a friction that better drafting removes; it is a structural feature of any two-party arrangement in which a third party’s wrong must be absorbed.
The pseudonymous interior of a digital-asset ledger reproduces the structure exactly, and worse. At the cash endpoint the double moral hazard is dissolved, not solved, because there is no recovery: the honest taker keeps the value, the loss lies where it falls, and both parties, knowing this, price the irrecoverability into how they hold and handle the object. Finality resolves the incentive problem by refusing to reopen the transaction at all. At the recovery end the hazard is live but at least the parties are identifiable, so a legal system can, as Schwartz and Scott discuss, contemplate calibrated rules that condition recovery on the owner’s precautions. The interior-point token has neither escape. Its settlement is not final, so the irrecoverability that dissolves the hazard at the cash end is absent; a payment can, through reorganization or fork, fail to have happened. Yet its holders are pseudonymous, so the identifiability that lets the recovery regime assign precautions to a named party is also absent. The token occupies the one position where the double moral hazard is both live and unaddressable by the two mechanisms the older literature offers: it cannot be dissolved by finality, because settlement is probabilistic, and it cannot be managed by conditioned recovery, because the parties are detached from legal identity by design. The framework predicts that an instrument in this position will generate persistent, unresolved incentive failure around loss — theft, error, fraud — precisely because it sits where neither classical solution reaches, and it will keep generating it until identity is reattached at some institutional margin, which is the Coasean point developed in Section X.
VII. The hybrid layer, and where tokenized money really sits
Between the two pure architectures Kahn and Roberds place a third category, and it is the category into which most serious digital money actually falls, so the framework’s treatment of it matters more than its treatment of the pure token. The hybrid is transferable debt: an instrument privately issued, tied to an identifiable issuer, that circulates as a means of payment while remaining a claim to be redeemed. Kahn and Roberds analyze the historical form — the goldsmith’s note, the bank check, the bill of exchange — and identify its defining requirement: a payee must verify two things, that the instrument is what it claims to be, and that the issuer is good for it. Through transferable debt, one person’s credit becomes another’s means of payment. The instrument sits partway along the identifiability axis by construction: it carries more evidentiary traction than an anonymous object, because it is tied to a named issuer and, when endorsed, to a chain of named holders, and it carries less finality than cash, because it can be dishonored if the issuer fails. This is neither the money endpoint nor the goods interior; it is the engineered middle, and the law that governs it, the holder-in-due-course rules descended from Miller v. Race through the negotiable-instruments statutes, is a deliberate calibration that preserves circulation while retaining recourse against identified signatories.
A great deal of what is now called digital money is transferable debt in this exact sense, and the framework’s discipline applies to it more cleanly than to the pure token. An instrument redeemable against a named issuer — a claim on a reserve, a tokenized deposit, a liability of an identifiable institution — is a hybrid, and its coordinate on the axis is fixed by that fact whatever ledger technology carries it. It gets whatever finality the issuer’s solvency and the governing law provide, and no more; it gets whatever traceability the issuer’s records and the ledger’s history jointly produce, which is considerable; and its central verification burden is the one Kahn and Roberds name for all transferable debt, that the issuer is good for it. The instrument cannot be at the cash endpoint, because it is a claim on someone, and a claim is precisely what cash is not. This is not a defect. The hybrid is a genuinely useful location on the axis, the location that most of monetary history has actually occupied, and an honest tokenized instrument that presents itself as transferable debt — a recorded, redeemable, issuer-backed claim — is describing its coordinate correctly. The error is only in the instruments that carry the architecture of transferable debt while claiming the properties of cash, promising the finality and anonymity of the object while remaining, in substance, a traceable claim on a named party. The framework’s demand is the same one it makes everywhere: state the coordinate, and the coordinate for a redeemable issuer-backed token is the hybrid middle, with the recourse and the verification burden and the absence of true finality that the middle has always carried.
VIII. Why the cash function left BTC
If a token begins life aimed at the cash endpoint — small, casual, final, peer-to-peer payment — the framework predicts what will happen to it as it is used at scale, and the prediction is not a matter of anyone’s intentions. It is a matter of where the costs fall on the axis. The asset that most clearly illustrates the trajectory is BTC, and the trajectory is that the cash function departed it.
The mechanism is direct. A store-of-value instrument at the cash endpoint has one non-negotiable requirement: the cost of a single ordinary payment must be negligible, because that is the entire economic function of the cash end — small, casual transactions that no ledger and no verification burden could ever be worth carrying. The moment an individual payment carries a material cost, the low-value transactions that define the cash end become uneconomic first, because they are the ones for which any fixed cost is largest relative to the amount moved. This is the same logic Crawford (2025) applies to registration in the good-faith-purchase problem: a register is pointless for low-value goods because the fixed cost of consulting it does not scale down with the price of the thing, so, as Crawford puts it, no one buying a bottle of milk would “consult the register of milk owners” (Crawford, 2025). Whatever imposes a fixed per-transaction cost evicts the low-value use first. The point is general and does not depend on any particular fee mechanism or capacity figure, which is why I make no numerical claim about either: it is enough that some positive per-transaction cost exists and that it does not shrink in proportion to the value being moved, for then the smallest payments are always the first to be priced out, exactly as the milk-register fixed cost prices out the milk buyer regardless of how cheap the register becomes. On a settlement system whose per-transaction capacity is bounded and whose fees rise when demand presses against that bound, the fixed cost is the fee, and the eviction is automatic: as usage grows, the small casual payment — the defining cash use — is the first to become irrational, and the instrument migrates toward high-value, low-frequency transfers for which a material per-transaction cost is tolerable. The asset does not choose to leave the cash endpoint. The cost structure removes the cash use from it.
Notice what this does to the asset’s position on the axis, and why it compounds the findings of the previous section. High-value, low-frequency transfers are precisely the transactions for which recourse, identity, and record matter — the transactions that in the world of goods sit in the recovery regime, not the finality regime. An instrument that has shed its small-payment use and retained only its large-transfer use has moved, in function, from the money end of the axis toward the goods end, and it has done so while its underlying architecture was, as Section III established, an account-style ledger all along. The token did not descend from cash to something lesser. It surfaced as what it always was — a public historical ledger — once the one function that disguised it as cash, the cheap casual payment, was priced out. What started as cash stopped being cash, and the framework says this was the expected motion along the axis for any bearer-costumed ledger used at scale, not a peculiarity of one asset or one community’s decisions.
IX. Variety is the tell, again
Levmore (1987) observed, in the comparative study that anchors the good-faith-purchase literature, that legal systems display extraordinary variety in their treatment of the stolen-goods contest and almost none in their prohibition of theft itself, and he drew from this a functional inference: uniformity appears where a rule must control behavior that threatens the general welfare, while variety appears where either the rule does not much change behavior or reasonable lawmakers cannot tell which rule is best. Applied to the identifiability axis, Levmore’s inference becomes a diagnostic. At the endpoints, where the right rule is forced, legal systems converge: every monetized society gives money finality, and every developed society registers land, because at those coordinates the trade-offs resolve one way and disagreement is not reasonable. In the interior, where the trade-offs are balanced and the behavioral effect of any rule is weak, systems scatter, because there the choice genuinely does not much matter or genuinely cannot be settled.
The digital-asset field exhibits Levmore’s variety in its purest contemporary form, and the variety is itself evidence of where these instruments sit. If tokens occupied the cash endpoint, their treatment — legal, regulatory, commercial — would be converging the way the treatment of cash converged, because the endpoint forces the answer. Instead the treatment is a bewildering and unsettled diversity across jurisdictions and across instruments, which is exactly what Levmore’s thesis predicts for assets sitting in the contested interior rather than at a forced endpoint. The absence of convergence is not a sign that the law has not yet caught up; it is the signature of an interior-axis position, the same signature the stolen-goods contest has shown for four thousand years. When an asset’s legal treatment refuses to settle, the framework reads that refusal as a measurement: the asset is not at an endpoint, because endpoints settle. Digital assets, measured by the variety of their treatment, are reading as interior instruments, which is the same verdict the mechanics of Section III and IV return by a different route.
X. What digital assets actually need from this
The title of this essay promises what digital assets need from the framework, and the framework’s answer is a demand for honesty about coordinates, followed by a design discipline. Four things follow, and none is optional.
First: name the point on the axis, and accept its whole bundle. Fox’s history and Kahn and Roberds’ dichotomy together establish that each point on the identifiability axis carries a fixed bundle of consequences that cannot be unbundled by wish. The cash endpoint gives finality and anonymity and freedom from recourse, and pays for them with irrecoverability: value taken by fraud or error at that endpoint is gone, because the very rule that makes the object final for the honest taker makes it final for the thief. The recovery region gives traceability and recourse and error-correction, and pays for them with verification cost, discounts for title risk, and litigation. There is no point on the axis that gives finality and recourse together, because they are the two names for opposite answers to the one question of whether value received can be reclaimed. A digital asset that advertises the benefits of one end while promising the protections of the other is not describing a design; it is describing a location on the axis that does not exist. The first thing digital assets need is to state their coordinate and own the bundle that comes with it.
Second: stop claiming the endpoint the architecture does not occupy. The peer-reviewed mechanics say a proof-of-work token is a pseudonymous ledger with probabilistic settlement. That is a coherent and possibly useful location on the axis — a public-history instrument with detachable identity and confirmation-dependent settlement — but it is not the cash endpoint, and every claim that it is finality-equivalent to cash is falsified by the fork and reorganization results Halaburda et al. document. Digital assets need to sell the coordinate they occupy, whose properties are real, rather than the coordinate they do not, whose properties they lack. A pseudonymous auditable ledger is valuable for exactly the transactions where a permanent public record is an asset rather than a liability; it is the wrong instrument for the small anonymous final payment, and no amount of protocol description changes that, because the record is the substance of the system.
Third: read finality as a legal commitment, not a technical byproduct. The deepest lesson of Miller v. Race is that cash finality was never delivered by the physics of coin alone; it was delivered by a legal rule that chose to make identifiers inert at the point of honest receipt, because the exchange function demanded it. A digital asset that wants genuine finality — the categorical extinguishment of prior claims — cannot obtain it from consensus mechanics, which the survey shows deliver only costly-to-reverse probability. It can obtain it only the way money always has: from a legal regime that declares receipt final and binds the relevant parties to that declaration. This is why the payment systems that actually deliver hard finality at scale are the ones embedded in law and central-bank settlement, a point Kahn and Roberds develop for wholesale systems, where finality is a legal and institutional commitment purchased at the price of foreclosed recourse. Digital assets need to decide whether they want finality badly enough to accept the legal architecture that is the only thing that has ever produced it, and to stop expecting a protocol to manufacture, out of probability, a categorical rule that only law has ever supplied.
Fourth: locate the recourse, because the axis says where it must live. If a digital asset sits in the interior — pseudonymous, recorded, probabilistically settled — then it is in the region where, for every other asset, recourse and error-correction are indispensable and expensive. Coase (1937) established that a function migrates to the lowest-cost institutional margin: activity leaves the per-transaction market and enters an organization when the per-transaction cost of coordination becomes prohibitive. The interior of the identifiability axis is exactly where per-transaction recourse — each party policing each transaction alone — is most costly, and so recourse for an interior-point digital asset will not stay at the level of the individual transaction; it will migrate, Coase-fashion, to whatever institutions verify the identities the ledger deliberately leaves detached — the exchanges, the custodians, the on-ramps and off-ramps where pseudonym meets legal person. This is not a regulatory imposition external to the design; it is the axis asserting itself. An interior instrument generates a demand for identity-bearing institutions at its edges as surely as cash generates a demand for none, and a digital asset that refuses to plan for those institutions is not avoiding them but leaving their construction to others, on terms it did not set.
Each of these four demands has a concrete consequence, and stating them abstractly is not enough; the discipline the framework imposes is only real if it changes what a designer builds. Take the first, naming the coordinate, and follow it to its edge. An instrument that has chosen the cash endpoint has chosen irrecoverability, and irrecoverability at scale means that error and theft produce permanent, uncompensated loss. That is tolerable for the small casual payments the cash endpoint exists to serve, where the amount at risk in any one transaction is trivial; it is intolerable for large transfers, where a single mistaken or fraudulent transaction destroys a fortune with no recourse. So the coordinate choice is not free-standing: choosing the cash endpoint is choosing an instrument fit only for small stakes, and any attempt to run large value over a genuinely final, genuinely irrecoverable rail is a category error that the framework flags in advance. The endpoint and the use-case are not independently selectable.
The second demand, selling the coordinate occupied rather than the one coveted, has a consequence for how these instruments should be marketed and regulated, though I state it as the framework’s implication and not as a regulatory proposal I have tested. If the peer-reviewed mechanics say a proof-of-work token is a pseudonymous, probabilistically-settled, public-history ledger, then representations that it is anonymous final cash are, on the evidence assembled here, false as to every one of those coordinates. The framework does not itself carry legal force, but it identifies precisely which claims are contradicted by the mechanics: anonymity, finality, and bearer-object status. A representation that the instrument is an auditable pseudonymous ledger with confirmation-dependent settlement would be accurate. The gap between the two is not rhetorical; it is the gap between two different points on the axis, and it is measurable as such.
The third demand, reading finality as a legal commitment, has the consequence that hardens the whole argument. The wholesale payment systems that move the largest values in the world economy purchased finality deliberately and at a price. Kahn and Roberds document the migration of large-value interbank settlement to real-time gross settlement, an architecture in which each payment is an immediate and irrevocable transfer of central-bank funds, adopted precisely to insulate a payee from the risk that an earlier failure unwinds his receipt. What those systems bought, stated exactly, is the same commodity the currency rule gives the shopkeeper: the guarantee that value received is value kept, proof against later reversal, at the price of foreclosed recourse. They bought it with law and central-bank money, not with a consensus protocol, because a categorical guarantee against reversal is a legal object and consensus produces only a probability. A digital asset that wants that guarantee must acquire it where it has always come from. The consequence is stark: genuine finality and protocol-native decentralization, as the mechanics currently stand, are properties at different points on the axis, and an instrument cannot hold both at once any more than it can hold finality and recourse at once.
The fourth demand, locating the recourse, has the consequence that the institutional edges of a digital-asset system are not optional accessories but structural necessities dictated by the coordinate. An interior-point instrument — recorded, pseudonymous, probabilistically settled — generates a demand for identity-reattachment at its boundaries, because that is where the recourse the interior requires can be delivered, and Coase’s logic says the function will migrate to exactly those lowest-cost institutional margins. The exchanges, custodians, and on-ramps where pseudonym meets legal person are therefore not external impositions on an otherwise complete system; they are the system’s answer to the recourse problem its coordinate creates, and they will arise whether or not the designer plans for them. The only choice the designer has is whether to shape those institutions deliberately or to leave their construction to others on terms he did not set. The framework says the institutions are coming either way, because the axis position summons them, and a design that pretends they are unnecessary is not avoiding the recourse problem but exporting it.
XI. The coordinate worth building
The argument so far is corrective, and a purely corrective argument invites the reply that it condemns without constructing. So state the positive case the framework actually supports, because the framework does support one, and it is more interesting than either the boosters’ claims or the critics’ dismissals. The question is not whether digital assets can be money; it is which coordinate on the identifiability axis a protocol can occupy that no prior instrument could, and whether that coordinate is worth occupying. The answer is that the protocol’s genuine novelty is the ability to build a public, permanent, verifiable transaction history that is not held by any single institution — a ledger without a ledger-keeper — and that this is a real and previously unavailable coordinate, valuable for exactly the transactions where a permanent auditable record is the point rather than the problem.
Consider what the older literatures say such a coordinate is good for. Kahn and Roberds establish that account-based systems exist to supply what cash cannot: a record of history and a verification of identity, at the cost of requiring the institutions that keep the record and check the identity. The historical limit on these systems was always the institution — someone had to keep the ledger, and that someone was a point of cost, of control, and of failure. The protocol’s contribution, read through the payments framework rather than through its own rhetoric, is an account-based record whose keeping is distributed rather than institutional: the history is public and verifiable by anyone, and no single party owns the book. This does not move the instrument to the cash endpoint — it is still a record, still an account structure, still not a bearer object — but it occupies a position within the account region that was previously empty, the position of a recorded system without a recording monopolist. That is the coordinate worth building, and it is worth building precisely for the uses the account region has always served and the money endpoint never could: auditable settlement of consequential transactions, where the parties want a permanent verifiable record and are content to be identifiable at the institutional edges, and where the removal of a single controlling ledger-keeper is a genuine gain.
What the framework denies is only the claim that this coordinate is the cash endpoint in disguise. The distributed public ledger is an account instrument, and it inherits the account region’s properties: it is traceable, it requires identity-reattachment at its edges for recourse, and its settlement, until law supplies otherwise, is probabilistic rather than final. These are not the properties of cash, and the instrument is at its strongest when it stops pretending to be cash and presents itself as what it uniquely is: the first account-based record without an account-keeper, valuable for the permanence and verifiability and ownerless-ness of its history, and honest about the traceability and the institutional edges and the probabilistic settlement that the coordinate carries. An asset built for that coordinate, and marketed as occupying it, has something no prior money had. An asset built for that coordinate and marketed as cash has misdescribed itself into the one region — the interior — where, as this essay has shown across five loaded sources, it secures neither the finality of one endpoint nor the recourse of the other. The coordinate worth building is real. The only discipline the framework demands is that the builder say which coordinate it is, and the answer, for a distributed public ledger, is the ownerless middle of the account region, not the vanishing point where money lives.
XII. The axis does not negotiate
The unifying claim is that digital assets did not escape the old constraints; they made them legible. For every prior money the position on the identifiability axis was a fact of the material, and the trade-offs at that position — finality against recourse, anonymity against traceability, cheap casual payment against permanent record — were absorbed without anyone having to state them, because there was no dial to turn. A protocol is a dial. It lets a designer choose a coordinate, and the one thing it does not let the designer choose is the bundle that coordinate carries, because that bundle is fixed by the same economics Fox found in the coin cases, Kahn and Roberds found in the architecture of payment, Crawford found in the register, Schwartz and Scott found in the double moral hazard, and Levmore found in four thousand years of comparative variety.
Assemble the verdict from the sections that produced it. The mechanics, on the field’s own peer-reviewed survey, place the proof-of-work token in the account region, not the bearer region: it is a ledger of all history, likened by the survey itself to the money-as-memory construct that the payments literature puts at its core. Its settlement is probabilistic, subject to fork and reorganization, not the categorical extinguishment of prior claims that law grants to cash. Its holders are pseudonymous, recorded enough to be traced and nameless enough to be unrecoverable, which secures neither the anonymity of the cash endpoint nor the recourse of the account systems that the payments literature calls the safer alternative. It reproduces the double moral hazard in the one position where neither classical solution reaches, because finality cannot dissolve it and conditioned recovery cannot manage it. Its treatment across jurisdictions refuses to converge, which is the signature of an interior-axis position and not of a law still catching up. And the instrument that launched at the cash endpoint was carried up the axis by the cost of its own use, shedding the small casual payment that endpoint exists to serve, and revealing the ledger it had been from the start. Every one of these findings comes from a source read in full, and every one places the token in the interior, not at the endpoint it claims.
The positive coordinate remains, and it is genuinely new: an account-based record without an account-keeper, a public verifiable history owned by no one, valuable for exactly the consequential auditable transactions the account region has always served and honest about the traceability and institutional edges and probabilistic settlement that the region carries. What digital assets need from this framework is therefore not encouragement and not condemnation. It is the discipline to say where on the axis they stand, to accept the properties that come with standing there, and to stop claiming the properties of a place they are not. The axis was drawn for coins and paintings and stolen goods, and it does not negotiate with the fact that the asset is now digital. It only, for the first time, lets the asset’s designer see the coordinate he is choosing, and asks him to be honest about it. The dial that used to be fixed can now be set by hand. The bundle each setting carries cannot, and the pretense that it can is the whole of what has gone wrong.
References
Coase, R. H. (1937). The nature of the firm. Economica, 4(16), 386–405. https://onlinelibrary.wiley.com/doi/10.1111/j.1468-0335.1937.tb00002.x
Crawford, M. J. R. (2025). The riddle of the good faith purchaser. Oxford Journal of Legal Studies, 45(1), 167–192. https://academic.oup.com/ojls/article/45/1/167/7900629
Fox, D. (1996). Bona fide purchase and the currency of money. Cambridge Law Journal, 55(3), 547–565. https://www.cambridge.org/core/journals/cambridge-law-journal/article/abs/bona-fide-purchase-and-the-currency-of-money/86BB50EE4BCAC58064A13BA07C3F1969
Halaburda, H., Haeringer, G., Gans, J., & Gandal, N. (2022). The microeconomics of cryptocurrencies. Journal of Economic Literature, 60(3), 971–1013. https://www.aeaweb.org/articles?id=10.1257/jel.20201593
Kahn, C. M., & Roberds, W. (2009). Why pay? An introduction to payments economics. Journal of Financial Intermediation, 18(1), 1–23. https://www.sciencedirect.com/science/article/abs/pii/S1042957308000533
Levmore, S. (1987). Variety and uniformity in the treatment of the good-faith purchaser. Journal of Legal Studies, 16(1), 43–65. https://www.journals.uchicago.edu/doi/abs/10.1086/467823
Schwartz, A., & Scott, R. E. (2011). Rethinking the laws of good faith purchase. Columbia Law Review, 111(6), 1332. https://scholarship.law.columbia.edu/faculty_scholarship/187/