Stablecoin Distribution and Operational Risk Report 2026

Independent analysis of $180B in USDT, USDC, USDe, PYUSD, and USDG, with concentration risks and an operating framework for wallets and payments.

BroLabel Team55 min readStablecoinsMarket StructureRiskWallet Infrastructure

Independent BroLabel field report · 56 HTML sections

Source: Dollar Supremacy, Range, in partnership with Utila

On-chain holder snapshot indexed on March 9, 2026

BroLabel independently summarized and interpreted the source. Figures below should be read as a point-in-time view, not as current balances or transaction-flow data.

Core Thesis

Price parity hides divergent infrastructure roles. The ownership data suggests that USDT supplies liquidity to centralized trading venues, USDC reaches the widest mix of institutional and on-chain users, USDe packages a return-generating strategy, PYUSD gains utility through credit markets, and USDG builds distribution around Solana.

The most important risk is not market share alone but where control accumulates. Binance, OKX, and Coinbase together held roughly 36% of the five tokens' analyzed supply, while individual assets also depended on a dominant exchange, smart contract, lending venue, or chain.

For payment and wallet operators, stablecoin selection is therefore an architecture decision. Liquidity, issuer model, chain availability, policy controls, counterparty exposure, event visibility, and reconciliation should be assessed together rather than reduced to the peg.

$180B
analyzed supply
5
dollar stablecoins
36%
held by three leading CEXs
2 chains
Ethereum and Solana

56 editorial sections

Report contents

Market snapshot: five operating profiles

The figures below restate only the Range and Utila evidence snapshot dated March 9, 2026. They are neither live market data nor an asset ranking.

AssetObserved roleDistribution evidencePrimary dependency
USDTLiquidity rail for centralized trading venues57.1% on CEXs; 8.9M holders; $107.1B analyzedBinance held 39.6%; 96.5% of analyzed supply was on Ethereum
USDCWidely distributed dollar for institutions, DeFi, and on-chain marketsFlattest holder concentration; $9.1B on Solana; 7.6M holdersCoinbase group exposure and a 38% Ethereum attribution gap
USDeSynthetic dollar embedded in a return-generating strategy69.5% in DeFi; 59.8% in sUSDe stakingSingle-contract, funding-rate, and Ethereum dependencies
PYUSDLending-led stablecoin with regulated issuance34% in lending protocols; Solana share reached 28.1%Protocol incentives, concentrated custody, and limited retail distribution
USDGDistribution and payments strategy anchored in Solana71.5% on Solana; issuance expanded beyond twice its earlier level, reaching $1.29BTop-three holder concentration and a small 6,336-address holder base

Part I — Reading the market · 01

The peg is a price property, not an operating model

Five tokens can trade near one dollar while exposing an operator to entirely different issuers, venues, contracts, chains, redemption paths, and failure modes.

A stablecoin is often selected as if the ticker were the product. In practice, the product is the complete route from fiat or collateral into issuance, through a chain and a wallet, to a counterparty, and eventually back through redemption. Every link adds a control boundary. The useful comparison is therefore not simply USDT versus USDC versus another token; it is one end-to-end operating system versus another.

The March 2026 snapshot makes this visible. USDT behaved primarily as centralized-market liquidity; USDC showed the broadest institutional and onchain distribution; USDe concentrated inside a return-bearing protocol loop; PYUSD gathered utility in lending; and USDG leaned into Solana-led distribution. Treating these roles as interchangeable can produce the wrong liquidity assumptions, the wrong policy limits, and the wrong incident plan.

Analyzed supply by asset

Linear scale of balances observed on Ethereum and Solana in the source snapshot.

USDT$107.1B
USDC$62.1B
USDe$6.48B
PYUSD$3.76B
USDG$1.29B

Data source: Range and Utila, Dollar Supremacy, snapshot dated March 9, 2026.

Evidence and risk map

$180B
analyzed supply
5
distinct operating archetypes
2
chains in the source snapshot
  1. Selecting by market capitalization while ignoring the actual corridor and exit route.

  2. Applying one global exposure limit to assets with different counterparties and control surfaces.

  3. Assuming a stable price implies stable access to minting, liquidity, or redemption.

Operator control sheet

  1. Document the full asset-chain-venue-redemption route for every supported workflow.

  2. Approve assets per use case rather than maintaining an undifferentiated token allowlist.

  3. Assign an accountable owner for liquidity, issuer, chain, and operational risk.

  4. Review the route whenever a provider, contract, or network implementation changes.

Part I — Reading the market · 02

What a balance snapshot can — and cannot — prove

The dataset is powerful for locating dependencies at rest, but it does not measure payment velocity, offchain obligations, or the current market state.

The source indexed non-zero token holders on Ethereum and Solana and enriched addresses with entity labels and behavioral heuristics. That approach can reveal whether balances cluster at exchanges, custodians, protocol contracts, or unattributed wallets. It is especially useful for forming hypotheses about counterparty concentration and technical dependency.

A holder snapshot does not tell us how often funds move, which balances are operational versus customer-owned, what sits on other chains, or which offchain liabilities offset an onchain position. Attribution can also vary by token and network. We therefore use the figures as directional evidence, never as a live exposure report. Any production decision should be refreshed with current balances, issuer disclosures, contractual terms, and the operator's own ledger.

Holder addresses by asset

Logarithmic scale keeps million-address and thousand-address assets legible. Addresses are not the same as users.

Log scale
USDT8.9M
USDC7.6M
PYUSD73.7K
USDe13.2K
USDG6,336

Data source: Range and Utila, Dollar Supremacy, snapshot dated March 9, 2026.

Evidence and risk map

2026-03-09
snapshot date
ETH + SOL
networks analyzed
57–98%
approximate attribution range
  1. Presenting point-in-time balances as current market facts.

  2. Confusing address count with users or beneficial owners.

  3. Treating an unattributed address as proof of retail ownership.

Operator control sheet

  1. Stamp every dashboard and decision memo with the data timestamp and chain scope.

  2. Separate observed facts, attribution inferences, and BroLabel interpretations.

  3. Reconcile onchain positions to internal customer and treasury liabilities.

  4. Use multiple sources before changing asset or counterparty limits.

Part I — Reading the market · 03

Concentration is a stack, not a single percentage

Issuer, entity, venue, contract, chain, bridge, and operational concentration can overlap and amplify one another.

A token can look distributed across thousands of addresses while remaining dependent on one issuer, one redemption channel, or one exchange cluster. It can also be broadly distributed by entity yet technically concentrated in a chain or a contract. Concentration must therefore be decomposed into layers before it can be governed.

Our operating map uses seven layers: reserve and issuer, direct redemption, named entity, venue and protocol, smart contract, blockchain and bridge, and the operator's own signing and ledger stack. The relevant risk is usually the combination. A large exchange balance becomes more material when the same exchange is also the primary liquidity route and the only tested off-ramp.

Largest attributed holder share

The largest entity or contract attributed to each asset in the source concentration analysis.

USDesUSDe59.8%
USDTBinance39.6%
USDGOKX24.8%
PYUSDCopper16.3%
USDCCoinbase11.2%

Data source: Range and Utila, Dollar Supremacy, snapshot dated March 9, 2026.

Evidence and risk map

36%
held by Binance, OKX, and Coinbase in the snapshot
7
layers in the BroLabel concentration map
1 route
can still be a single point of failure
  1. Address diversification that leaves the same beneficial counterparty underneath.

  2. A fallback chain that still depends on the same bridge or issuer action.

  3. Independent limits that fail to capture correlated exposures.

Operator control sheet

  1. Maintain a dependency graph, not only a wallet inventory.

  2. Aggregate addresses to legal entities and service providers.

  3. Set both per-layer limits and a correlated exposure ceiling.

  4. Test whether the fallback route removes or merely renames the dependency.

Part II — Five operating archetypes · 04

USDT: centralized-market liquidity at global scale

USDT's breadth is a liquidity advantage, but the snapshot shows that a large share of the analyzed supply depended on exchange distribution and one dominant venue.

The analyzed USDT supply was the largest in the dataset at $107.1 billion. Approximately 57.1% sat at centralized exchanges, and Binance alone accounted for 39.6%. That pattern is consistent with an asset used extensively for trading liquidity, collateral movement, and fast transfers between market participants.

For an operator, deep venue liquidity can reduce conversion friction while increasing dependence on exchange access and issuer terms. The observed 96.5% Ethereum share within the two-chain sample should not be generalized to all USDT networks; it simply means that Ethereum dominated the specific ETH/SOL comparison. A corridor decision must use the chain actually available to customers and counterparties.

Evidence and risk map

$107.1B
analyzed on Ethereum and Solana
57.1%
at centralized exchanges
39.6%
at Binance
  1. Exchange access becomes part of the practical liquidity guarantee.

  2. A venue incident can affect price execution even without an issuer or chain failure.

  3. Network support can be mistaken for corridor liquidity.

Operator control sheet

  1. Cap exposure by exchange and beneficial entity, not only by wallet address.

  2. Maintain at least two tested liquidity routes for material corridors.

  3. Monitor issuer terms, reserve reporting, and redemption eligibility separately.

  4. Measure slippage and time-to-cash during stress, not only normal markets.

Part II — Five operating archetypes · 05

USDC: broad distribution with an attribution blind spot

USDC showed the most even holder distribution in the sample and the largest Solana balance in absolute dollars, while a material share of Ethereum supply remained unattributed.

The snapshot covered $62.1 billion in USDC and 7.6 million holders. Of the two observed networks, 85.3% was on Ethereum and 14.7% on Solana, equal to roughly $9.1 billion on Solana. Coinbase represented the largest named entity at 11.2%, far below USDT's dominant venue share, which supports the view of broader distribution.

Distribution does not eliminate issuer, banking, or attribution risk. Approximately 38% of Ethereum USDC in the analysis was not assigned to known entities. Some of that may reflect genuine long-tail ownership; some may be infrastructure that labeling has not yet resolved. Operators should combine Circle's reserve and redemption disclosures with entity-level monitoring and a chain-specific liquidity plan.

Evidence and risk map

$62.1B
analyzed supply
$9.1B
on Solana in the sample
38%
of Ethereum supply unattributed
  1. Broad address distribution can mask unknown institutional clusters.

  2. Native and bridged representations may be confused across networks.

  3. Direct redemption rights may differ from secondary-market access.

Operator control sheet

  1. Verify the exact mint or token contract for every supported network.

  2. Track native issuance separately from bridged exposure.

  3. Refresh unattributed clusters before major treasury moves.

  4. Rehearse cash redemption and market conversion as distinct exit paths.

Part II — Five operating archetypes · 06

USDe: a synthetic dollar inside a return engine

USDe is not operationally equivalent to a fiat-reserve stablecoin: its peg mechanism connects crypto backing, derivatives hedges, off-exchange providers, and protocol contracts.

The analyzed $6.48 billion supply was almost entirely on Ethereum, and 69.5% sat in DeFi. The sUSDe staking contract alone represented 59.8%. This is not merely holder concentration; it is evidence that the asset's primary utility was closely tied to a reward-accruing protocol workflow.

Ethena documents a delta-neutral model using spot backing and offsetting derivatives, together with funding, custody, exchange, liquidity, and smart-contract risks. That means an operator must evaluate both token transfer risk and the health of the mechanism supporting the synthetic dollar. A $1 screen price does not show hedge quality, funding pressure, or redemption capacity.

Evidence and risk map

$6.48B
analyzed supply
69.5%
in DeFi
59.8%
in the sUSDe contract
  1. Persistent negative funding can pressure protocol economics.

  2. Contract and off-exchange provider dependencies can interact.

  3. Staking liquidity may differ from spot-token liquidity during stress.

Operator control sheet

  1. Classify USDe separately from fiat-reserve payment stablecoins.

  2. Set independent limits for USDe and sUSDe positions.

  3. Monitor backing, reserve fund, funding, and redemption indicators.

  4. Test unstaking and liquidation paths before treating yield as cash-like.

Part II — Five operating archetypes · 07

PYUSD: payments branding, lending-led distribution

The snapshot found a regulated-issuer asset whose onchain adoption was materially shaped by lending venues and institutional positions.

PYUSD accounted for $3.76 billion across the two observed chains, with 71.9% on Ethereum and 28.1% on Solana. Around 34% was located in lending protocols. Copper, a combined PayPal and USDtb grouping, and Spark were among the largest named positions in the source analysis.

A payment narrative and a lending distribution channel can coexist, but they create different operating assumptions. Incentive changes can move deposits rapidly; protocol health can matter as much as issuer quality; and the same token may have very different liquidity by chain. The operator should measure organic payment demand separately from balance growth created by yield or collateral incentives.

Evidence and risk map

$3.76B
analyzed supply
34%
in lending protocols
28.1%
on Solana
  1. Liquidity may decline when lending incentives change.

  2. Protocol exposure can be mistaken for issuer exposure only.

  3. Chain-level adoption may not translate into merchant acceptance.

Operator control sheet

  1. Separate wallet balances, protocol deposits, and collateral positions in reporting.

  2. Monitor utilization, withdrawal liquidity, and incentive expiry by protocol.

  3. Validate each chain's fiat and secondary-market exit route.

  4. Tie payment-support decisions to actual counterparty acceptance data.

Part II — Five operating archetypes · 08

USDG: network-led distribution with a small holder base

USDG stood apart through its Solana weight and concentrated exchange distribution, illustrating how a go-to-market network can become an operational dependency.

The sample covered $1.29 billion in USDG and 6,336 holder addresses. Solana represented 71.5% of the observed supply, while 47.2% sat at centralized exchanges. OKX held 24.8%, Kraken 14.1%, and Robinhood 11.6%, producing a concentrated distribution profile despite the asset's cross-platform ambitions.

A smaller holder base is not automatically a weakness if the asset serves wholesale or platform distribution. It does, however, make named partnerships, market-making capacity, and chain operations more important. Teams should distinguish strategic ecosystem adoption from resilient two-sided liquidity available to their own customers.

Evidence and risk map

$1.29B
analyzed supply
71.5%
on Solana
6,336
holder addresses
  1. A concentrated venue set can define price discovery and access.

  2. Network incidents can affect most observed supply at once.

  3. Partnership announcements may overstate usable corridor liquidity.

Operator control sheet

  1. Set a tighter initial limit until independent liquidity routes are demonstrated.

  2. Monitor market depth at the actual venues used by the product.

  3. Test Solana account creation, fee funding, and token-account validation.

  4. Maintain an alternative settlement asset for each customer corridor.

Part III — Dependencies beneath the ticker · 09

Entity concentration: many addresses, one counterparty

Wallet-level diversification is misleading when cold wallets, omnibus accounts, and operational clusters belong to the same legal or economic entity.

Binance, OKX, and Coinbase together represented roughly 36% of the combined analyzed supply. That cross-token concentration is more important than any single address because the same entity can sit beneath several wallets, assets, and service relationships. An operator may therefore diversify tickers yet retain a common exchange, custodian, or fiat gateway dependency.

Entity aggregation should connect onchain attribution to contracts and internal vendor records. A label is not enough: teams need the legal entity, service function, jurisdiction, account ownership model, and exit dependency. The goal is not perfect attribution; it is a defensible exposure view that improves as evidence changes.

Evidence and risk map

~36%
combined share of three leading CEX groups
1:N
one entity can control many addresses
24/7
exposure changes beyond reporting hours
  1. The same entity appears under several labels or subsidiaries.

  2. Customer assets and treasury assets are mixed in an omnibus view.

  3. A counterparty limit is calculated after, rather than before, signing.

Operator control sheet

  1. Create a canonical entity ID across wallets, accounts, vendors, and contracts.

  2. Apply pre-signing limits to the aggregated entity exposure.

  3. Record attribution confidence and the evidence date.

  4. Escalate when a new address maps to an already concentrated entity.

Part III — Dependencies beneath the ticker · 10

Chain concentration: availability and account models matter

The same stablecoin ticker can require different validation, fee funding, confirmation, and incident logic on Ethereum and Solana.

Chain share affects more than transaction fees. It determines which account model the product must understand, how token identity is verified, which events indicate finality, how fees are funded, and what failure states operations must distinguish. A second chain is only a real fallback if the application, policy engine, liquidity route, and reconciliation process all support it.

On Solana, token balances live in token accounts associated with a mint and an authority; a wallet may have several token accounts for the same mint. On Ethereum, balances are normally read from a token contract against an account address. These differences affect deposit detection, address validation, rent or fee handling, and attribution. Cross-chain totals should not be merged before token provenance is verified.

Ethereum and Solana share of analyzed supply

A 100% comparison of the two networks covered by the source snapshot.

USDT96.5% / 3.5%
USDC85.3% / 14.7%
USDe99.9% / 0.1%
PYUSD71.9% / 28.1%
USDG28.5% / 71.5%

Data source: Range and Utila, Dollar Supremacy, snapshot dated March 9, 2026.

Evidence and risk map

99.9%
USDe on Ethereum in the sample
71.5%
USDG on Solana in the sample
2 models
different account and event semantics
  1. The wrong mint or bridged representation is accepted.

  2. A nominal fallback chain lacks operational readiness.

  3. Confirmation logic marks a deposit final too early or too late.

Operator control sheet

  1. Allowlist exact chain and token identifiers, never ticker alone.

  2. Use chain-specific address and destination validation.

  3. Define finality, retry, and duplicate-event rules per network.

  4. Run quarterly failover tests with real low-value transfers.

Part III — Dependencies beneath the ticker · 11

Protocol and contract concentration: composability creates coupling

A stablecoin held inside lending, staking, bridge, or liquidity contracts inherits the operational behavior of those contracts.

The source data makes contract concentration visible in USDe's sUSDe position and PYUSD's lending exposure. Once a token enters a protocol, the operator is no longer exposed only to the token. Withdrawal queues, oracle behavior, collateral parameters, governance changes, contract upgrades, and emergency pauses become part of the position.

The internal ledger should preserve the difference between an available wallet balance, a supplied lending balance, a collateral position, a claim token, and an amount pending withdrawal. Collapsing them into one USD total overstates immediately available liquidity and prevents policy from acting on the real control boundary.

CEX and DeFi distribution by asset

CEX and DeFi shares do not total 100% because issuer, custody, multisig, bridge, and other categories remain outside both series.

USDT
CEX57.2%DeFi2.9%
USDG
CEX47.2%DeFi5.2%
USDC
CEX34.3%DeFi6.4%
PYUSD
CEX19%DeFi34%
USDe
CEX6.4%DeFi69.5%

Data source: Range and Utila, Dollar Supremacy, snapshot dated March 9, 2026.

Evidence and risk map

59.8%
USDe in one staking contract
34%
PYUSD in lending protocols
5 states
minimum ledger distinction
  1. A token remains at $1 while a protocol claim becomes illiquid.

  2. An upgrade changes permissions or withdrawal behavior.

  3. Recursive collateral links several positions to one liquidation event.

Operator control sheet

  1. Allowlist contracts by verified address, function, and intended workflow.

  2. Represent protocol positions as separate ledger instruments.

  3. Monitor upgrades, governance proposals, pauses, and withdrawal conditions.

  4. Stress available liquidity after protocol haircuts and exit delays.

Part III — Dependencies beneath the ticker · 12

Attribution is an operating capability, not a static label

Entity mapping should carry evidence, confidence, ownership, and review dates so that it can support policy without pretending to certainty.

Exchange cold wallets often reveal patterns such as round balances, recurring counterparties, synchronized transfers, and address clusters. These signals can improve attribution beyond public labels, but they remain inferences until corroborated. A production system should store the reasoning and confidence behind each mapping.

Attribution also decays. Providers rotate wallets, custodians change structures, contracts migrate, and ownership relationships evolve. The control is therefore a lifecycle: observe, classify, review, apply policy, monitor for contradiction, and retire stale mappings. Low-confidence attribution should trigger more conservative routing, not an arbitrary definitive label.

Evidence and risk map

4 fields
evidence, confidence, owner, review date
3 tiers
verified, probable, unknown
0
labels that should live forever without review
  1. Stale labels route funds to a changed owner or service.

  2. A false positive blocks a legitimate counterparty.

  3. A false negative hides aggregate exposure.

Operator control sheet

  1. Store provenance and confidence with every entity mapping.

  2. Require a second source for high-value or high-risk destinations.

  3. Expire inferred labels unless they are reviewed.

  4. Log manual overrides and feed outcomes back into the model.

Part IV — The operator control plane · 13

Select a route, not a ticker

A defensible stablecoin decision scores the complete business route across liquidity, control, redemption, technical fit, and recovery.

The correct unit of approval is an asset on a specific chain, for a defined customer and counterparty workflow, using named providers and an explicit exit. A token may be approved for treasury conversion on one network but not for automated customer payouts on another. This precision prevents product convenience from silently becoming balance-sheet risk.

We recommend a five-axis scorecard: corridor liquidity, issuer and redemption quality, chain and contract readiness, policy and observability, and fallback independence. A high average score should not compensate for a zero in redemption or control. Some requirements are gates, not weights.

Evidence and risk map

5 axes
minimum route scorecard
3 levels
approved, restricted, prohibited
1 owner
accountable for each route
  1. A product team expands a token to a new chain without risk approval.

  2. A weighted score hides a fatal control gap.

  3. A corridor remains approved after its liquidity provider changes.

Operator control sheet

  1. Create route IDs combining asset, chain, workflow, counterparties, and exit.

  2. Make redemption, signing control, and reconciliation mandatory gates.

  3. Attach volume limits and review dates to every approval.

  4. Trigger reassessment on provider, contract, chain, or regulatory change.

Part IV — The operator control plane · 14

Policy must act before signing

Monitoring can explain a bad transfer; pre-signing policy can prevent it. The control boundary belongs between transaction intent and signature creation.

A wallet API should not turn an application request directly into an irreversible signature. The request needs an authenticated identity, a unique idempotency key, validated asset and network identifiers, destination screening, exposure checks, velocity limits, and an approval path. Only the approved payload should reach the signing quorum.

MPC and DKG can split signing authority so that no single system reconstructs a complete private key. A client-controlled Co-Signer adds a policy enforcement point under the operator's control. This architecture is valuable only when the policy decision, approver identity, exact transaction payload, and resulting signature are tied together in an auditable record.

Evidence and risk map

Before
the only safe time for a blocking policy
MPC
distributed signing authority
1 intent
one idempotent transaction lifecycle
  1. Duplicate requests produce two valid transfers.

  2. Policy checks a human-readable summary but signs a different payload.

  3. An emergency override becomes an ungoverned routine path.

Operator control sheet

  1. Bind policy approval cryptographically to the final transaction payload.

  2. Require idempotency for every value-moving request.

  3. Scope rules by asset, chain, destination, amount, entity, and environment.

  4. Use time-bound, dual-approved, fully logged emergency overrides.

Part IV — The operator control plane · 15

Events and ledger records turn chain activity into operations

A block explorer is evidence, not an operating ledger. Teams need deterministic events and double-entry-style records tied to business intent.

A production workflow spans requested, policy-approved, signed, submitted, observed, confirmed, credited, reversed, and failed states. WebSocket or equivalent event delivery reduces detection delay, but events may arrive late, twice, or out of order. The consumer must deduplicate, persist offsets, and reconcile against authoritative API and chain state.

The ledger should connect customer obligation, treasury position, network fee, provider fee, transaction hash, chain, asset representation, destination entity, and finality status. Reconciliation then becomes a controlled comparison among expected business state, internal records, wallet balances, and onchain evidence rather than a manual reconstruction after month-end.

Evidence and risk map

9 states
minimum transaction lifecycle
At least once
safe assumption for event delivery
4-way
business, ledger, wallet, chain reconciliation
  1. Duplicate events create duplicate customer credits.

  2. A confirmed transfer is booked to the wrong asset representation.

  3. Fees and reversals remain outside the financial record.

Operator control sheet

  1. Use stable event IDs and idempotent state transitions.

  2. Requery authoritative state after gaps, reconnects, or contradictions.

  3. Record asset, chain, contract or mint, and decimals in every ledger entry.

  4. Run daily exception reconciliation and periodic full-balance proof.

Part IV — The operator control plane · 16

Fallbacks must remove dependencies, not rename them

A credible continuity plan maps trigger, authority, customer state, liquidity source, communication, and reconciliation for each failure layer.

Stablecoin incidents rarely stay within one technical boundary. An issuer pause affects redemption assumptions; a chain incident affects confirmation and fee markets; an exchange restriction affects liquidity; a contract pause affects position exit; a Co-Signer outage affects signing; and a ledger incident affects the operator's ability to prove customer balances.

A runbook should specify the first safe action: pause new deposits, stop withdrawals, lower limits, switch routes, or continue under observation. It should also state who can make that decision and what evidence ends the incident. Recovery is incomplete until every in-flight transaction and ledger exception is reconciled.

Evidence and risk map

6 layers
issuer, chain, venue, contract, signing, ledger
1 owner
incident commander with explicit authority
100%
in-flight items reconciled before closure
  1. The fallback uses the same issuer, venue, or signing dependency.

  2. Customer balances change while communications lag.

  3. Operations resume before transaction state is reconciled.

Operator control sheet

  1. Write runbooks per failure layer with explicit pause and resume criteria.

  2. Test alternative assets, chains, liquidity venues, and signing paths.

  3. Preapprove customer and counterparty communication templates.

  4. Keep an immutable incident timeline linked to ledger exceptions.

Part V — Implementation and governance · 17

A 90-day path from token support to controlled operations

The fastest safe implementation starts with route inventory and ledger truth, then adds pre-signing policy, event resilience, tested fallbacks, and governance evidence.

Days 0–30 establish scope: inventory every asset-chain-contract route, map entities and providers, define authoritative ledger states, and stop unsupported combinations from entering production. Days 31–60 implement controls: authenticated requests, idempotency, pre-signing limits, destination policy, event deduplication, and daily reconciliation. Days 61–90 prove resilience through failover tests, incident exercises, access review, and governance sign-off.

Regulation changes the evidence expected from operators, but not the core engineering discipline. MiCA treats qualifying single-currency tokens as e-money tokens with issuer and redemption requirements in the EU. The U.S. GENIUS Act establishes a framework for permitted payment stablecoin issuers, one-to-one reserves, redemption disclosures, and AML obligations. Product availability and responsibilities still depend on jurisdiction, role, contracts, and implementation, so counsel must validate the final model.

Evidence and risk map

90 days
three implementation waves
30/60/90
scope, control, prove
Quarterly
minimum route and access review
  1. The program starts with automation before establishing ledger truth.

  2. Policies exist in documents but not in the signing path.

  3. A regulatory label is applied without role- and jurisdiction-specific analysis.

Operator control sheet

  1. Name executive, product, engineering, risk, finance, and legal owners.

  2. Require measurable exit criteria for every implementation wave.

  3. Retain evidence for approvals, policy decisions, signatures, and reconciliation.

  4. Review routes quarterly and after material issuer, chain, provider, or legal change.

Applying the framework in infrastructure

This framework becomes practical when asset, chain, amount, destination, and counterparty rules execute before signing, while every event reaches the operating ledger and reconciliation process. That is the control layer implemented by BroSettlement.

Frequently asked questions

Are stablecoins with the same one-dollar target interchangeable?

No. Their issuers, reserves, redemption rights, chains, contracts, liquidity venues, and concentration patterns differ. Interchangeability must be tested for a specific route and use case.

Does a large holder count prove broad ownership?

Not by itself. One entity may control many addresses, while one omnibus address may represent many customers. Entity attribution and account structure are required.

What is the minimum safe unit of stablecoin approval?

An asset on a specific chain for a defined workflow, with named counterparties, explicit limits, verified token identity, and a tested exit route.

Why is pre-signing policy essential?

Because a valid blockchain signature is normally irreversible. Screening after broadcast can detect a problem but cannot prevent the transfer.

Is a second blockchain automatically a fallback?

No. The application, signing policy, liquidity venue, fee funding, monitoring, customer support, and reconciliation must all work independently on that chain.

How often should route approvals be reviewed?

At least quarterly and immediately after a material issuer, contract, chain, provider, liquidity, or regulatory change.

Sources and use limits

This is an independent BroLabel report. It uses the March 9, 2026 Ethereum and Solana holder snapshot published by Range and Utila as an evidence base, then develops a new operating framework for treasury, wallet, payments, risk, and finance teams. It is not a reproduction or substitute for the source report, and it is not legal, investment, or accounting advice.

  1. Dollar Supremacy: A Deep Dive into the Distribution of the Leading Stablecoins — Range and Utila
  2. Dollar Supremacy: What $180B in Stablecoin Data Reveals About Market Concentration — Utila
  3. USDC Transparency and Stability — Circle
  4. Tether Transparency — Tether
  5. USDe Overview and Risks — Ethena
  6. PayPal USD Transparency Reports — Paxos
  7. Tokens and Token Accounts — Solana
  8. Regulation (EU) 2023/1114 on Markets in Crypto-assets — EUR-Lex
  9. S.1582 — GENIUS Act — Congress.gov