Stablecoin Risks and Regulation: The Six-Risk Checklist Every Payments Architect Must Run Before Building (Part 4 of 5)

Part 4 of the PaymentTalks Stablecoin Masterclass. Read Part 1: What Is a Stablecoin?, Part 2: How Stablecoins Are Created and Destroyed, and Part 3: Stablecoins vs Traditional Payment Rails first if you’re joining mid-series.

What Questions Must You Answer Before Recommending Stablecoin Rails?

A client walks into the room with a brief that sounds too good to argue with: cut cross-border payment costs by 95%, settle same-day across a dozen currency corridors, and stop pre-funding nostro accounts. Stablecoin rails answer that brief on paper. I’ve built payment architecture on ISO 20022 and SWIFT MT for long enough to know that “answers the brief on paper” and “is safe to put in front of a client” are two different sentences.

Before you present the recommendation, you need a straight answer to four questions:

  • Is using stablecoins for payment even legal in both the originating and receiving jurisdiction?
  • If the stablecoin de-pegs by 5% overnight, what happens to the client’s payment obligation?
  • If the smart contract is exploited and the funds move, who is liable, and what does recovery actually look like?
  • Are both parties classified as Virtual Asset Service Providers (VASPs), and are they compliant with the FATF Travel Rule?

If you can’t answer all four with confidence, you’re not ready to recommend stablecoin rails. Not because stablecoins are inherently unsafe. They’re maturing fast, and regulators are catching up. But the risk and regulatory landscape underneath them is uneven, moves quarter to quarter, and carries consequences traditional payments architects have never had to price in. A recalled MT103 or a returned SEPA transaction has a known process. A stablecoin sent to the wrong wallet does not.

This article gives you the full landscape: the six risks you assess on every stablecoin payment design, and the regulatory frameworks now reshaping what’s legally usable in the world’s largest payments jurisdictions.

What Are the Six Risks Every Stablecoin Payment Architecture Must Assess?

None of these are hypothetical. Each one has already produced real financial loss or forced regulatory intervention. Treat them as a pre-build checklist, not background reading.

Risk 1: De-Pegging Risk

What it is: the stablecoin breaks its 1:1 promise against its reference currency. A token meant to trade at $1.00 trades at $0.90, or at $0.00.

Why it happens: de-pegging starts as a confidence problem, not a technical one, and the trigger differs by design.

  • Fiat-backed (USDC, USDT): reserve inadequacy or opacity. If the market doubts the reserve covers the supply, you get a bank run: everyone redeems at once, and if reserves are illiquid or short, the peg snaps.
  • Crypto-backed (DAI): if the underlying collateral (typically ETH) falls faster than the smart contract’s liquidation logic can react, the stablecoin goes under-collateralised and the peg comes under threat.
  • Algorithmic (TerraUST): confidence failure turns into a death spiral. The algorithm mints more tokens to defend the peg, the extra supply floods the market, confidence drops further, and selling accelerates.

TerraUST, in detail: by early May 2022, UST was the third-largest stablecoin by market cap, with roughly $18.7 billion in circulation. On 7 May, large withdrawals from the Anchor Protocol created selling pressure. The algorithm minted LUNA to defend the peg. LUNA went from around $80 to $0.0001 in four days. UST followed it to near zero. Somewhere between $40 and $45 billion in combined value was wiped out, and a large number of individual holders lost their savings.

USDC and the SVB moment: fiat-backed doesn’t mean immune. When Silicon Valley Bank failed in March 2023, Circle disclosed that about $3.3 billion of USDC reserves sat at SVB. That single disclosure was enough to trigger panic. USDC traded as low as $0.87 for roughly 48 hours before the peg recovered, once the US deposit guarantee and Circle’s own clarification landed.

How an architect responds:

  • Build real-time peg monitoring into the design, tracking the stablecoin’s market price against its reference currency.
  • Set an automatic fallback threshold. If the peg drifts past a defined percentage (0.5% is a reasonable start), route the payment through traditional rails instead.
  • Never carry material stablecoin balances overnight without checking issuer and reserve health first.
  • Diversify issuers if the treasury is holding meaningful stablecoin balances.
  • Use only fiat-backed stablecoins with transparent, attested reserves for payment applications. Algorithmic stablecoins have no place in a payment architecture.

Risk 2: Smart Contract Risk

What it is: a bug or vulnerability in the stablecoin’s governing smart contract gets exploited, and funds are stolen or permanently lost.

Smart contracts are software, and software has bugs. The difference from a core banking system is finality. A banking vulnerability can be patched, an error corrected, and fraud investigated with a regulatory backstop behind it. A smart contract exploit on-chain is usually irreversible the moment it executes. There’s no chargeback equivalent, no recall message, no court-ordered freeze in most cases.

  • Poly Network (August 2021): an attacker exploited a cross-chain bridge contract and moved $611 million in assets, including stablecoins. In this unusual case the attacker gave the funds back, but had no legal obligation to.
  • Wormhole Bridge (February 2022): $320 million stolen through a bridge contract vulnerability. Jump Crypto covered the losses, but only because they could afford to. A smaller platform would not have survived it.
  • Ronin Bridge (March 2022): $620 million stolen from the bridge behind the Axie Infinity game. Circle froze $750,000 in USDC tied to the attacker, but the remainder, held in ETH and other assets, was gone.

How an architect responds:

  • Build only on battle-tested, heavily audited contracts. USDC and USDT have years of deployment history, billions in value secured, and repeated audits behind them. Don’t build payment applications on experimental contracts.
  • Keep custom smart contract logic to a minimum. Every extra line is another attack surface, and a payment use case rarely needs complex on-chain logic.
  • Treat bridge risk as its own category. Cross-chain bridges have been responsible for more than $2 billion in losses. Use only the most established bridges and track their audit status separately.
  • Factor in on-chain insurance (Nexus Mutual, Sherlock, and similar) for institutional deployments as part of the risk framework, not an afterthought.

Risk 3: Custodian and Counterparty Risk

What it is: the entity holding the stablecoin assets on your client’s behalf, whether custodian, exchange, or wallet provider, becomes insolvent, gets hacked, or misappropriates funds.

FTX, November 2022: FTX was the world’s second-largest crypto exchange. Investigative reporting showed customer funds, supposedly held in segregated custody, were being used to prop up its affiliated trading firm, Alameda Research. When Alameda’s losses surfaced, a bank run followed, withdrawals froze, and FTX filed for bankruptcy within days. Roughly $8 billion in customer funds went unaccounted for. Stablecoin holders at FTX recovered cents on the dollar, or nothing.

This wasn’t a blockchain failure. It was a custodian failure, a traditional fraud wearing the opacity of an unregulated exchange.

The question that actually matters: when your client holds USDC at a custodian, what legal protection kicks in if that custodian fails?

  • Regulated custodians with segregated accounts: client funds are legally separate from the custodian’s own book. In insolvency, clients hold a priority claim. This is the floor for enterprise use, not the ceiling.
  • Unregulated exchanges: your “balance” is often just a line in the exchange’s internal ledger. The exchange holds the actual USDC. If it fails, you’re an unsecured creditor, exactly what happened at FTX.

How an architect responds:

  • Use only regulated, licensed custodians, for example Fireblocks, BitGo, Anchorage Digital, Copper, or an OCC / state-licensed qualified custodian.
  • Confirm client funds sit in legally segregated custodial accounts, not commingled with the custodian’s operating funds.
  • For large balances, insist on institutional-grade custody with multi-signature controls, so no single individual can move large sums unilaterally.
  • Run periodic proof-of-reserves checks where the custodian supports on-chain verification.
  • Never confuse a trading exchange’s balance display with actual custody. It isn’t the same thing.

Risk 4: Regulatory and Compliance Risk

What it is: the stablecoin activity is unlicensed, falls short of AML/KYC obligations, or breaches the FATF Travel Rule, exposing the firm and the client to fines, blocked transactions, or regulatory action.

The FATF Travel Rule: the Financial Action Task Force is the international standard-setter for anti-money-laundering and counter-terrorist-financing rules. In 2019 it extended Recommendation 16, the Travel Rule, to cover Virtual Asset Service Providers.

When a VASP moves virtual assets, stablecoins included, on a customer’s behalf, this data has to travel with the transaction:

  • Originator: full name, account or wallet address, and physical address, national ID, or date and place of birth.
  • Beneficiary: full name and account or wallet address.

If that reads like the Debtor and Creditor party data every PACS.008 or MT103 carries under correspondent banking rules, that’s because it’s structurally the same obligation, just applied to a blockchain rail instead of SWIFT. The catch: a blockchain transaction natively carries only a wallet address, no name, no ID. VASPs have to push that data through a separate channel and retain it for AML purposes.

The tooling that has grown up around this:

Standard / ToolPurposeWhat it does
IVMS 101Travel Rule data formatThe structured Inter-VASP Messaging Standard for originator/beneficiary data between VASPs.
NotabeneTravel Rule compliance platformLets VASPs exchange IVMS 101 data and verify counterparty compliance.
VeriscopeTravel Rule networkShyft Network’s VASP-to-VASP protocol for Travel Rule data.
Sygna BridgeTravel Rule platformWidely used across Asia-Pacific.
ChainalysisOn-chain analyticsScreens wallet addresses against sanctions lists, flags suspicious patterns.
TRM LabsTransaction monitoringRisk-scores blockchain addresses and transaction flows.
EllipticBlockchain analyticsSanctions screening and AML monitoring.

How an architect responds:

  • Wire IVMS 101-compliant Travel Rule tooling (Notabene, Veriscope, or equivalent) into any VASP-to-VASP design from day one, not as a bolt-on.
  • Run sanctions screening against on-chain analytics before a transaction ever sends. Wallet addresses do show up on OFAC SDN lists.
  • Confirm both the sending and receiving party hold the right VASP licence in their own jurisdiction.
  • Build stablecoin KYC onboarding to match or exceed traditional banking KYC. Regulators are converging on that expectation fast.

Risk 5: Finality and Irreversibility Risk

What it is: a transaction sent to the wrong address, or under fraudulent or mistaken instructions, can’t be pulled back, and the funds are gone.

Traditional payments have imperfect but real recall paths: an MT199 recall, a SEPA R-transaction, a card chargeback. A blockchain transaction has none of that once confirmed. There’s no system message to reverse it, no return code, no court order that gets the funds back if the receiving wallet owner won’t cooperate.

  • Wrong address: a treasury operator reuses a wallet address from a prior transaction that has since changed, and sends $150,000 to a defunct exchange address. Unrecoverable.
  • Address poisoning: an attacker generates a wallet address that visually matches a known counterparty’s, same first and last characters, banking on a copy-paste mistake from transaction history.
  • Social engineering: an attacker compromises an email thread and swaps in a fraudulent wallet address during a confirmation exchange.

How an architect responds:

  • Whitelist destination addresses. Only pre-approved, verified wallets should be valid payment destinations in an institutional system.
  • Require second-factor confirmation, through a separate channel, above a defined transaction threshold (say $10,000).
  • Force character-by-character visual confirmation for any new address before it’s approved.
  • Send a small test transaction ahead of a large payment to a new counterparty, and confirm receipt before sending the rest.
  • Where the platform supports it, run a transaction simulation before execution on new addresses.

Risk 6: Liquidity Risk

What it is: the on/off-ramp exchange doesn’t have enough market depth to convert a large stablecoin position to fiat without moving the rate against you, or without delaying settlement.

Stablecoin exchanges aren’t central banks. They run liquidity pools, and for everyday payment sizes that’s rarely a problem. Convert $5 million from USDC to PHP in one instruction, though, and the exchange may not have enough PHP depth to fill it at the quoted rate. What you get is slippage: the effective rate degrades as the size of the transaction grows. Major corridors (USD/EUR, USD/MXN) are deep. Emerging-market corridors (USD/NGN, USD/PKR) can be thin on stablecoin rails specifically.

How an architect responds:

  • Get real liquidity data from the exchange partner for the specific currency pair and transaction sizes you expect, before you commit the architecture.
  • Design for payment splitting on large transfers, executed across a time window to reduce market impact.
  • Use two or three exchange relationships in a corridor to aggregate liquidity rather than depending on one.
  • Pre-position a small USDC float for time-critical corridors so you’re not waiting on an on-ramp conversion under pressure.

How Do Major Jurisdictions Regulate Stablecoins Right Now?

Stablecoin regulation is moving faster than almost any other area of financial policy. Here’s where the major jurisdictions stand as of 2025 to 2026.

European Union: MiCA (Markets in Crypto-Assets Regulation)

Status: in full effect since June 2024. The most comprehensive crypto regulatory framework anywhere.

MiCA gives all 27 EU member states one framework, and splits stablecoins into two buckets:

  • E-Money Tokens (EMTs): pegged to a single official currency (USDC to USD, EURC to EUR). Regulated like e-money: issuers need Electronic Money Institution (EMI) authorisation and 1:1 reserves in low-risk, liquid assets.
  • Asset-Referenced Tokens (ARTs): backed by a basket of currencies, commodities, or other assets. Stricter rules, including a dedicated reserve fund and governance requirements. Most major stablecoins don’t fall here.

EMT issuers must hold EMI authorisation in at least one member state, keep reserves in segregated accounts at regulated credit institutions, honour redemption at par on demand, publish a white paper disclosing material information, and stay under supervisory scrutiny once daily volume passes €200 million.

Real-world impact: in late 2024, major European exchanges including Coinbase Europe, Kraken, and Bitstamp delisted USDT for EU residents because Tether hadn’t obtained EMI authorisation. That’s the clearest signal so far that non-compliance under MiCA means actual market exclusion, not a warning letter.

For architects building for EU clients: use only EMT-licensed stablecoins, which in practice today means USDC from Circle.

United States: The GENIUS Act (2025)

Status: passed the US Senate in 2025. The first federal stablecoin framework in the US.

Before this, US stablecoin regulation was a patchwork of state money-transmitter licences and OCC trust-bank charters with no federal baseline. The GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act) fixes that.

  • Issuer licensing: federal licensing through the OCC, or a qualifying state licence. Non-bank issuers are allowed if they clear capital and reserve requirements.
  • Reserves: 100% backing in US dollars, Treasuries with 93-day or shorter maturities, or other regulator-approved liquid assets.
  • Disclosure: monthly public reserve-composition disclosure, and independent annual audits above a size threshold.
  • Algorithmic moratorium: a two-year study period before any new algorithmic stablecoin can launch for payment use. Existing ones face review.
  • FDIC insurance: stablecoin holders don’t get it. That distinction from bank deposits doesn’t go away.

For architects, this finally gives US clients a federal framework to point to instead of a state-by-state patchwork. USDC (Circle) and PYUSD (PayPal/Paxos) are best positioned for GENIUS Act compliance today.

United Kingdom: FCA / Bank of England Framework

Status: under the Financial Services and Markets Act 2023, with the FCA regime expected operational through 2025 to 2026.

The UK splits oversight: the FCA authorises and supervises fiat-backed stablecoin issuers for reserve, redemption, and disclosure standards, while the Bank of England takes systemic oversight of any stablecoin arrangement large enough to threaten financial stability if it failed.

Proposed requirements mirror MiCA in spirit: FCA-authorised issuance for retail stablecoins, reserves at the Bank of England or in approved liquid assets, prompt redemption at par, and capital requirements on issuers. USDC is expected to secure FCA authorisation and become the default choice for UK enterprise payment applications.

UAE: CBUAE Payment Token Services Regulation (2024)

Status: issued by the Central Bank of the UAE in 2024, and active.

  • AED-pegged stablecoins (AETokens): fully permitted, with CBUAE-licensed issuers and AED reserves held at UAE banks. This opens a regulated path for a Dirham stablecoin, which matters for the GCC’s digital economy.
  • Foreign fiat-referenced tokens: USDC, USDT, and similar remain usable for international payments but are restricted for domestic retail use inside the UAE, where AED itself is required for goods and services.
  • Crypto-backed and algorithmic stablecoins: prohibited for payment use outright.
  • VASP licensing is mandatory for any entity offering stablecoin payment services.

For architects working UAE or GCC corridors: USDC and USDT still work for cross-border B2B. For anything domestic inside the UAE, the design needs an AED-pegged, CBUAE-licensed token. Several UAE banks and fintechs were building AED stablecoins as of 2025. If the corridor touches the UAE’s mBridge participation, CBDC-based settlement is a parallel track worth knowing alongside the stablecoin one.

Where Does Saudi Arabia Stand on Stablecoin Regulation?

This one is worth its own section, given how much GCC cross-border volume runs through Riyadh.

There is no dedicated Saudi stablecoin framework in force today. SAMA’s historical position, dating to a 2018 standing-committee declaration, treats virtual currencies as unlicensed and unrecognised, and banks are barred from crypto-related activity without explicit SAMA approval, a process that has run up to nine months in practice.

That said, the posture is visibly shifting. In late 2025, Minister Majed Al-Hogail announced that Saudi Arabia is developing a nationally regulated stablecoin framework under joint SAMA and Capital Market Authority (CMA) oversight, aligned with Vision 2030’s push to modernise cross-border payments. As of mid-2026, this sits at the policy-design stage: no published rules yet on issuer licensing, reserve backing, or redemption rights. Separately, SAMA has been piloting a Central Bank Digital Currency and has participated in the BIS mBridge multi-CBDC project since 2024, which has already reached minimum-viable-product stage for cross-border settlement between commercial banks.

For architects scoping a Saudi corridor today: treat stablecoin rails into or out of KSA as not yet licensable for domestic use, and design around traditional rails or the CBUAE / mBridge path for GCC settlement until SAMA and CMA publish the actual rulebook. Shariah-compliance requirements are also expected to shape the eventual framework, likely favouring asset-backed structures over algorithmic ones.

The Common Thread Across Every Jurisdiction

Different regulators, same direction. Five themes hold everywhere:

  • Fiat-backed only for payments. Regulators globally are converging on fiat-backed, not algorithmic, not purely crypto-backed, as the only acceptable model for regulated payment use.
  • Reserve quality and transparency aren’t optional. 1:1 backing in cash and high-quality government securities is becoming the floor, and opaque or mixed reserves are drawing regulatory pressure.
  • Issuer licensing is required. Unregulated issuers are being pushed out of major markets. Only licensed issuers get to serve regulated payment flows.
  • The Travel Rule applies. FATF’s VASP Travel Rule is landing at national level across every G7 jurisdiction. Originator and beneficiary data travels with the payment, full stop.
  • Consumer protection is a floor, not a feature. Par-value redemption rights, clear disclosure, and segregated reserves are becoming baseline requirements everywhere.

How Do You Turn Risk and Regulation Into One Pre-Build Checklist?

Work through this before you recommend stablecoin rails in any client engagement:

CheckQuestionAcceptable Answer
Stablecoin selectionIs it licensed/compliant in every relevant jurisdiction?Yes, e.g. USDC holds MiCA-compliant status in the EU
Reserve qualityWhat backs it, and is that publicly attested?Cash + T-Bills, monthly attestations minimum
CustodianIs custody regulated, with funds legally segregated?Licensed custodian, bankruptcy-remote segregation
De-peg monitoringIs there a peg monitor and fallback in the design?Real-time monitoring + automatic fallback threshold
Travel RuleIs IVMS 101-compliant tooling integrated?Yes, for any VASP-to-VASP transfer
Sanctions screeningAre destination addresses screened pre-send?Yes, mandatory before every send
Address validationWhitelist plus second-approval for new addresses?Yes, especially above a defined value threshold
Finality designAre users told transactions are irreversible?Yes, with confirmation workflows
Corridor liquidityHas liquidity been checked for the pair and size?Yes, capacity confirmed for expected volumes

Key Takeaways

  • De-pegging, smart contract failure, custodian collapse, compliance gaps, irreversibility, and liquidity constraints are the six categories every stablecoin architecture has to address explicitly. None of them can be assumed away.
  • TerraUST and FTX aren’t crypto horror stories. They’re architectural-failure case studies every payments professional should be able to explain in plain terms.
  • MiCA, the GENIUS Act, the FCA framework, and CBUAE regulation are converging on the same principles: licensed issuers, transparent fiat reserves, VASP compliance, and Travel Rule implementation. Saudi Arabia is heading the same direction, just earlier in the process.
  • USDC is currently the most regulatory-compliant stablecoin globally, and the practical benchmark for enterprise payment applications.
  • The FATF Travel Rule is not optional for institutional stablecoin flows. IVMS 101 integration belongs in the design phase, not the punch list.

What’s Next

You now have the risk map and the regulatory landscape. What can go wrong, and what the rulebook says in each major jurisdiction.

The harder, more valuable piece is next: turning all of this into an actual system. Part 5 of this series walks through three architectural patterns, ISO 20022 integration design, compliance architecture, and a decision framework for matching the right rail to the right payment. If you want the mechanics of how stablecoins get minted and redeemed before you get there, Part 2 on stablecoin creation and destruction and how stablecoins map onto ISO 20022 messaging are worth a pass first.

This is architect-level work. Ready for it?

Frequently Asked Questions

What is de-pegging risk in a stablecoin payment system?

De-pegging is when a stablecoin trades away from its intended 1:1 value against its reference currency, usually the US dollar. It happens when confidence in the backing mechanism breaks down, whether that’s reserve doubts for fiat-backed coins, collateral collapse for crypto-backed coins, or an algorithmic death spiral like TerraUST in May 2022.

Which stablecoins are compliant with MiCA in the European Union?

USDC, issued by Circle, currently holds EMI authorisation and is treated as MiCA-compliant. USDT (Tether) has not obtained the required authorisation and was delisted from EU-facing exchanges in late 2024 for EU residents.

What does the FATF Travel Rule require for stablecoin transfers?

It requires Virtual Asset Service Providers to transmit originator and beneficiary information, name, wallet address, and identifying details for the sender, alongside any stablecoin transfer, using a format like IVMS 101. It’s the crypto-native equivalent of the Debtor/Creditor data every PACS.008 or MT103 message already carries in correspondent banking.

Is USDC legal to use for payments in Saudi Arabia?

There’s no published Saudi rulebook yet that licenses stablecoins for domestic payment use. SAMA and the CMA announced plans in late 2025 for a national stablecoin framework, but as of mid-2026 it remains at the policy-design stage. Cross-border B2B use is a different conversation than domestic retail payment, and both need SAMA guidance confirmed before you build.

What is the GENIUS Act and how does it regulate US stablecoins?

The GENIUS Act is the first federal US framework for payment stablecoins, requiring OCC or qualifying state licensing, 100% reserve backing in cash or short-dated Treasuries, monthly disclosure, and a moratorium on new algorithmic stablecoins pending further study.

How is smart contract risk different from de-pegging risk?

De-pegging is a confidence and reserve problem: the stablecoin’s value itself breaks. Smart contract risk is a code and security problem: the mechanism holding or moving the stablecoin gets exploited, as in the Poly Network, Wormhole, and Ronin bridge hacks, regardless of whether the peg itself is intact.

Can a stablecoin payment be reversed if it’s sent to the wrong address?

No. Blockchain finality is absolute once a transaction confirms. There’s no recall message equivalent to an MT199, no return code, and no court-ordered freeze in most cases. The only fix is voluntary return by the receiving wallet’s owner, which is why address whitelisting and second-factor confirmation matter so much operationally.

Which custodians are considered safe for institutional stablecoin holdings?

Regulated, licensed custodians with legally segregated client accounts, such as Fireblocks, BitGo, Anchorage Digital, or Copper, are the accepted floor for enterprise use. A trading exchange balance is not the same as custody and shouldn’t be treated as one for institutional holdings.

Scroll to Top