Ecosystem

No one to call

Author

Denelle Dixon

Publishing date

For institutions looking for ways into onchain finance, a corporate-controlled blockchain often looks like the safe option.

One party makes the rules. One party answers the phone. One party can be sued.

That option is procurable. It has the shape a vendor relationship is supposed to have: a contract, a service level, a named counterparty your legal team can evaluate.

It's also exactly the pitch to be suspicious of.

The party you can point to is the party that can change the terms on you. Fees can rise when returns soften. Access can be revoked or restricted.

What makes the closed option feel safe is the fact that someone is in charge. That is the very thing that should give a careful institution pause.

The counterparty reflex

Ask why open networks are hard for an enterprise to adopt and you'll hear answers about technology. The honest answer is older than the technology. Corporations and governments are built for a world where there is a counterparty on the other side: someone to sign the contract, commit to the uptime, tell you what will be done for you, and take the blame if things go wrong.

An open network has no counterparty. The software runs on machines that thousands of unrelated parties operate, and none of them can unilaterally change the terms for the rest.

No one picks up the phone because there is no one to call.

I understand why that feels risky. But risk does not go away when someone is accountable to you; it just moves.

So the choice is not between risk and safety. It is a choice about which risk you would rather hold: that no one is answerable to you, or that the party answerable to you is also the one capable of renegotiating terms.

Closed software already taught this lesson

Enterprises paid for this lesson once already. You buy the contract and the service level, and year by year you find out what came with them. You don't own or control your data. You can't move it. Fee structures change when the vendor's margins tighten. What the system will do for you is decided by the entity that builds it, and the exit costs more every year you stay.

This isn't hypothetical. Enterprises watched entire business layers get repriced after Broadcom acquired VMware. Cloud providers stopped charging customers to remove their own data only after regulators moved on it. The enterprise blockchain consortia of the last decade didn't fail on the technology either. They shut down because the parties operating them decided to stop, and every participant's integration work went with them.

Permissioned blockchains reproduce the same dependency. The operator defines the product, so the operator defines your ceiling. Even the transparency runs one way: what you can see is whatever the operator chooses to publish.

An open public network inverts the parts that matter most. The ledger is public and yours to view at any time. Nothing about your business waits on someone else's permission.

The right to leave

One difference a vendor relationship can't reproduce is the right to leave. On an open network, the state of the ledger belongs to everyone who uses it. If governance ever drifts away from what you signed up for, you, and everyone who agrees with you, can carry the entire state of the network into a new instance and keep going.

In practice this is hard and virtually nobody ever actually does it, so I won't oversell here, but what the option does, even without being exercised, is set a ceiling on how far governance can drift before participants start leaving. That ceiling binds us the same way it binds everyone else.

Now, try to leave a closed network. You never held the whole ledger to begin with. Permissioned designs show each participant only the slice it is party to, which is the privacy feature institutions are sold on, so there is no complete state for you to carry anywhere. You can leave with your own records. You cannot leave with the network, and whether you keep your access at all is the landlord's call.

What an open network costs you

None of this makes an open network the easy choice, and I won't pretend otherwise:

  • There is no counterparty, so no one to sue.
  • Reversals don't happen, and while clawbacks can happen, value sent to the wrong place may be gone.
  • Key management is your responsibility. You can staff it internally or hire a qualified custodian, but it is not something the network guarantees on your behalf.
  • You get the network's real uptime instead of a contractual number. (Stellar's is 99.998% since 2014, which I'd rather be judged on than a promise anyway.)
  • Protocol changes arrive through validator consensus, so governance requires participation; if you don't show up, you accept what the people who did show up decided.

And when something breaks at two in the morning, there is no vendor at the other end of the escalation path, because there is no vendor. There is your own team, a ledger whose full state you can read without anyone's permission, entities who care about the continuity of the network and about fixing what breaks quickly, and whatever operational relationships you build. Those relationships can be bought: custodians, response retainers, managed key operations. What you cannot buy is a counterparty who can reach into the network and fix it for you. That is a real cost, and it has to be planned for rather than contracted around.

The constraints run in our direction too. The Stellar Development Foundation funds development, runs validators, and advocates for the protocol changes we believe are right. What we cannot do is unilaterally alter the ledger, revoke your access to the network, or change what a transaction costs. These are not promises. They are properties of the protocol, and they bind every operator, including us.

Which points at what I think actually explains the hesitation, and it isn't risk tolerance. Institutions have decades of muscle for vendor risk: procurement teams, master agreements, vendor management functions, lawyers who do nothing else. For protocol risk (key operations, validator participation, governance engagement, incident response that doesn't route through a support ticket) there's almost nothing. The barrier isn't that open networks carry more risk. It's that their risks land in departments that don't exist yet. That's a capability problem, and capability problems get solved.

What a regulated fund actually runs on

Franklin Templeton's BENJI is a money market fund registered under the Investment Company Act of 1940. That registration means the fund operates under the same public, binding rules as any traditional money market fund. Those rules are what give institutional holders the confidence to hold it, onchain or off.

Look at where a fund like that can operate. An entity answering to the SEC, to auditors, and to every shareholder who redeems does not experiment with its infrastructure. BENJI has run on public networks since 2021, alongside comparable funds Franklin Templeton still offers on traditional rails. Five years of continuous supervision, and the absence of a counterparty has never been the thing that broke. Institutions under that much scrutiny don't take leaps. They do arithmetic.

The "safe" option binds you

The "safe" option isn't, in fact, safe. It is the one that binds you.

The early internet ran on protocols nobody owned. You didn't need permission to build on them, and there was no one to call about it. Plenty of people have built walled gardens on top since. But nobody has replaced the protocols underneath. The open layer is still the layer everything else has to reach through.

Open networks are the same bet, applied to value. The closed option is familiar and will therefore seem safer, simpler, and easier to procure. But it will always be the one that binds you: rules you didn't write, data you can't move, an exit you don't control.

Having no one to call is a real cost. So is building the capability to operate without that person to call. What you get for both is a network where no single party can change the terms on you. Not when the market turns, not when returns soften, not ever. For institutions putting long-duration capital onchain, that's the trade worth making.

This article is for informational purposes only and is not investment, legal, or tax advice. We do not warrant the accuracy, usefulness, or completeness of any content provided. Any reliance you place on such content is strictly at your own risk. Third-party projects referenced herein are independent parties building on the decentralized and permissionless Stellar network. SDF does not control or endorse any third-party services referenced and is not liable to you for such services in any way. Digital asset and cryptocurrency regulations vary by jurisdiction; consult qualified professionals to understand specific laws and regulations that may apply to your activities. Investment products are not FDIC insured, have no bank guarantee, and may lose value.