A treasury team asked to "put some collateral on a public chain" is being asked to sign off on a settlement system, a governance process and a set of legal exposures it did not choose and cannot fully see. A chain's marketing answers a different question from the one a mandate requires. This is a framework for the question that matters: what does a specific chain, as it exists today, actually give an institution, and where does the documentation stop and the assumption begin. The subject ran through two sessions on Proof of Talk's archived Paris 2026 programme at the Louvre Palace: "What Institutions Need From Blockchain Infrastructure", with Evan Cheng and Ronit Ghose speaking and Frank Chaparro moderating, and "From Enterprise Blockchain to Tokenised Markets: The Next Chapter of Institutional Finance", with David Rutter, Tim Grant and Ben Nadareski. This piece does not rank chains or recommend one, and it is not investment, legal, tax or accounting advice.

Settlement finality, and which kind

The Principles for Financial Market Infrastructures, published by CPSS (now the Committee on Payments and Market Infrastructures) and IOSCO in April 2012, state in Principle 8 that "an FMI should provide clear and certain final settlement, at a minimum by the end of the value date." Its key considerations add that an FMI "should clearly define the point after which unsettled payments, transfer instructions, or other obligations may not be revoked by a participant." That defined, irrevocable point is the one most public chains find hardest to state precisely.

Chains broadly split into two families. Probabilistic-finality chains, the Bitcoin model, never declare a transaction irreversible; confidence rises with each additional block. Chains with explicit finality declare a finality event. On Ethereum, ethereum.org explains that a checkpoint is finalised once a pair of checkpoints attracts votes representing at least two-thirds of total staked ETH, a process that spans at least two epochs of 32 twelve-second slots, so roughly 13 minutes, and that reverting a finalised block would cost an attacker at least one-third of all staked ETH. The Canton Network's Global Synchronizer, a public permissioned network rather than a permissionless one, orders transactions under a Byzantine fault-tolerant protocol that needs more than two-thirds of its Super Validators, as set out in our explainer on the Canton Network.

The diligence question is not "is this chain fast" but "what event does this chain call final, what share of stake or operators would have to collude or fail to reverse it, and does that event happen before or after the point at which our own booking system marks the trade as settled." When those diverge, the institution carries finality risk its own ledger does not show.

Validator set size and concentration

A large validator count is not the same as a decentralised one. The Nakamoto coefficient, the smallest number of independent entities that could together halt or corrupt a chain, is more useful, though it depends on assumptions about which operators are genuinely independent and which threshold is chosen. A Gate Learn article dated 24 March 2026, using epoch 685 data, counted 1,414 Solana validators across 37 countries and territories and gave a Nakamoto coefficient of 19, while noting the figure may be understated because one entity can run several validators anonymously. That is an exchange's educational material, not an audited figure.

Ethereum's number looks different by stake. A joint ARK Invest and Glassnode report published on 1 September 2026, as reported by The Crypto Times, found Lido, Binance and Kraken accounting for roughly 39% of staked ETH and gave Ethereum a coefficient of 3 under the report's selected threshold, against 19 for Solana using a 33% threshold. These numbers come from analytics firms; no supervisor has set a concentration level at which reliance on a chain becomes a supervisory concern.

The step itself is mechanical: pull a snapshot from a named tracker, record its date and threshold, and compare the result with the institution's own appetite for single-point-of-failure exposure, rather than accepting "thousands of validators" as proof of resilience.

Client diversity is a separate number

A chain can have thousands of independent validators and still be fragile if nearly all of them run the same software. Ethereum.org warns that "a bug in a consensus client with over 33% of the Ethereum nodes could prevent the consensus layer from finalizing," and that a bug in a client with a two-thirds majority could cause the chain to split and finalise incorrectly. The dashboard at clientdiversity.org, accessed on 16 September 2026, showed Ethernodes data with Geth at 50.13% and Nethermind at 25.46% of execution clients, though it marked that data as stale. For consensus clients, it showed Miga Labs putting Lighthouse at 51.32% and Prysm at 20.07%, while Rated.Network put Teku at 53.86%. Trackers that disagree this much are a finding in their own right. On Solana, a bex.co analysis dated 16 March 2026 put Jito-Solana, a fork of the Agave client, at about 72–88% of staked SOL and Frankendancer, the hybrid form of Jump's independently written Firedancer client, at about 20.9% across 207 validators, with full Firedancer reaching mainnet in December 2025. The figure to file is the dominant client's current share, dated, with its source.

Outage history, with dates

Primary post-incident reports are worth reading directly. Solana's report on 6 February 2024 records that block finalisation halted at 09:53 UTC after a legacy loader program triggered "an infinite recompile loop in the JIT cache"; more than 95% of cluster stake was running the affected release, and because stalled validators stopped voting, "consensus halted irrecoverably." Consensus resumed at 14:55 UTC after validators upgraded, about five hours later. Solana's overview of its 14 September 2021 outage describes bot-generated transactions during a token offering flooding the network, validators crashing, and a stall of about 17 hours, ended by a coordinated upgrade and restart from the last confirmed slot. Both recoveries depended on human coordination among validator operators, which is itself a governance fact.

Ethereum has not suffered a comparable full halt since the Merge, but on 11 and 12 May 2023 mainnet twice lost finality when the Prysm and Teku clients struggled to process attestations with old target checkpoints. Post-incident analysis reports that the network recovered without manual intervention or an emergency release, helped by clients that were unaffected. The useful comparison is not which chain has never gone down, but which publishes a dated technical post-mortem naming the defect, and whether that class of defect has recurred.

Upgrade governance: who can change the rules

Ethereum protocol changes move through Ethereum Improvement Proposals and rough consensus among independently maintained client teams, with no on-chain vote that binds anyone to ship a change. Solana changes are proposed as Solana Improvement Documents and depend on validators adopting the client releases that implement them. Applications built on these chains often use a different model again, typically a multisig with a timelock; a fuller diligence checklist covers who holds those keys and how long a change can be delayed. The PFMI expect an FMI to have clear, documented governance arrangements. An institution using a public chain for settlement is relying on a change process it does not sit inside, and the file should say so.

Privacy is a set of requirements, not a switch

"Privacy" on a public chain bundles several separate needs: confidentiality of transaction data, data-protection compliance, selective disclosure to counterparties and auditability for supervisors. These pull against each other. A base layer that is transparent by design pushes confidentiality into a separate layer with its own trust assumptions and regulatory exposure; our framework on blockchain privacy in regulated finance sets this out.

What the token exposes the holder to

Holding or staking a chain's native token is a different risk from using the chain for settlement, though the two are often bundled because validating or paying fees requires the asset. The exposures include price volatility unrelated to the activity being settled, slashing risk on staked positions where the protocol slashes, and governance influence over fee and issuance parameters that a passive holder does not control. Our piece on institutional staking covers the staking side.

Legal characterisation: in force, stalled or litigated

Commentary routinely turns "proposed" into "the rule", so status matters here. Three examples, as of 16 September 2026, show three different positions.

  • European Union, in force. The Markets in Crypto-Assets Regulation applied to asset-referenced and e-money tokens from 30 June 2024 and became applicable in its entirety on 30 December 2024. Existing providers could use a transitional period of at most 18 months, ending 1 July 2026, and many member states chose shorter periods.
  • United States, a bill that stalled. The Digital Asset Market Clarity Act failed a Senate cloture vote on 15 September 2026, with more than 40 senators voting against. It is not law. CoinDesk's own assessment was that the failure "essentially ends market structure legislative work in the Senate for 2026."
  • United States, litigation. In SEC v. Ripple Labs, the Southern District of New York held in July 2023 that XRP was sold as a security in Ripple's institutional sales but not in its exchange sales to retail buyers, and later imposed a $125 million civil penalty. After the court declined in 2025 to reduce the penalty or lift the injunction as part of a settlement, both sides dropped their appeals, and the Second Circuit approved the dismissal on 22 August 2025. The penalty and injunction stand, and no appellate ruling was issued on the underlying question.

None of this settles how a given chain's native token, or an instrument issued on it, will be characterised in a given jurisdiction. The honest diligence note is a status rather than a conclusion, and it needs jurisdiction-specific legal advice, which this is not.

Assembling the file

None of the eight items substitutes for another. A chain with a healthy Nakamoto coefficient but a dominant client carries bug risk the validator count does not show. A chain with clean finality mechanics but an unsettled legal characterisation carries booking risk the engineering does not show. The file an institution should be able to produce for any chain it relies on is a dated, sourced snapshot against each question, not the chain's own claim to have answered them. Proof of Talk's next edition is at Louvre Abu Dhabi on 3–4 December 2026, with admission by application; details are on the Abu Dhabi page.