What a whitelisted token on a public chain gives a bank, and which risks it keeps
A whitelist in the token contract lets an issuer use a ledger that other firms' platforms already connect to, while keeping control over who holds the token and the power to freeze or reverse transfers. It does not touch the chain underneath: validator governance, forks, finality and fees stay outside the issuer's control, which is why Singapore caps the exposure and Hong Kong asks banks for extra caution.
- Problem
- Banks and fund managers in Singapore and Hong Kong issue tokens on Ethereum but limit who can hold them. What does a permissioned token on a public chain give them that a private ledger does not, and what risk remains?
A whitelisted token splits control in two. The issuer controls the token: a list in the token’s code decides which wallets may hold it, and the issuer can freeze, reverse or destroy holdings. Nobody controls the chain: independent validators run it, and the issuer cannot choose them, audit them or stop a fork. What the issuer gets for accepting that is a ledger that distributors, custodians and other banks already connect to. Regulators in Singapore and Hong Kong now accept the design on condition that the issuer keeps the controls, and treat the chain itself as a risk to be capped and watched.
The problem
Singapore and Hong Kong institutions have put tokens on public chains while limiting who can hold them. DBS tokenises structured notes on Ethereum for accredited and institutional investors, sold through three third-party platforms (pilot entry). UBS Asset Management’s tokenised money market fund, uMINT, runs on Ethereum and is sold through authorised distributors (pilot entry). Anchorpoint, a Standard Chartered subsidiary licensed by the Hong Kong Monetary Authority (HKMA), issues its Hong Kong dollar stablecoin HKDAP on Ethereum mainnet to whitelisted wallets only (pilot entry).
The same banks also run private ledgers. DBS’s own tokenised deposits, DBS Token Services, run on a permissioned chain that DBS controls (pilot entry). J.P. Morgan offers deposit accounts on its private permissioned blockchain and, since November 2025, a deposit token for institutional clients on Base, a public network built on Ethereum (J.P. Morgan release, 12 November 2025).
The question is now a capital and custody question. Under the Basel standard as Singapore drafted it in 2025, banks would have had to put every token on a permissionless chain in Group 2, the costly capital treatment (MAS consultation paper, April 2026, para 2.2). On 17 April 2026 the Monetary Authority of Singapore (MAS) proposed that banks may use the lower Group 1 treatment for such tokens if the issuer keeps specific controls, including a holder whitelist (Wire). On 27 May 2026 the HKMA told banks to take extra caution with tokens that have no such controls (Wire).
How it works
Some terms first. A ledger is a record of who holds what. A public permissionless chain, such as Ethereum, is a ledger that anyone can read and anyone can help run by operating a validator, a computer that checks transactions and adds them to the ledger. A private permissioned ledger is run by a set of institutions that decide who may take part. A token is an entry on a ledger representing one unit of an asset. A smart contract is a program on the ledger; each token is governed by one. A wallet is an address on the ledger, controlled by a cryptographic key. A whitelist is a list of wallets the token’s contract allows to hold or receive it.
The whitelist lives in the token, not in the chain. Anyone can send a transaction on Ethereum. The token contract decides whether a transfer of that particular token succeeds.
A transfer that succeeds
Follow HKDAP, the only Singapore or Hong Kong token above with a published contract address.
1. Onboarding. A corporate client opens an account with an authorised distributor, such as the licensed trading platform OSL or Standard Chartered (pilot entry). The distributor checks the client’s identity and registers the client’s wallet. Anchorpoint says each holder’s wallet must be whitelisted by at least one authorised distributor “to enable any transaction of HKDAP” (Anchorpoint user alert).
2. The instruction. The client’s wallet sends a transaction to the HKDAP contract on Ethereum, asking it to move HKDAP to a supplier’s wallet. The supplier has been onboarded by a distributor too. Ethereum validators include the transaction in a block like any other and collect a fee, paid in ether, for doing so (ethereum.org: gas and fees).
3. The checks. The HKDAP contract is an upgradeable proxy whose current logic contract, verified on Etherscan, is named ControllableAHKD (Etherscan). Its published interface points to separate contracts for a blacklist, for frozen holdings and for activating token holders, and includes a switch that pauses all transfers. These are how Anchorpoint’s whitelist rule is enforced on-chain. Both wallets are registered and neither is blacklisted or frozen, so the contract debits the client and credits the supplier.
4. Finality. The transfer is final when the block containing it is finalised by Ethereum’s validators (ethereum.org: proof of stake). Anchorpoint’s reserves and books are unchanged. The only record of the transfer is on the public chain, visible to anyone.
A transfer that the contract blocks
Now the client sends HKDAP to a wallet no distributor has registered, perhaps an address copied wrongly, or a wallet belonging to someone who has not been checked. Ethereum still includes the transaction in a block and the sender still pays the fee (ethereum.org: gas and fees). Under Anchorpoint’s rule that a wallet must be whitelisted to enable any transaction, the token contract rejects the transfer and no HKDAP moves. The chain records a failed transaction.
If HKDAP has already reached a wallet that should not hold it, the issuer can act after the fact. The contract’s interface includes functions to freeze holdings, to destroy the balance of a blacklisted address, and to pause every transfer (Etherscan). None of these needs the cooperation of the chain’s validators: the issuer changes its own token’s records.
The standard form of the same design
HKDAP uses its own contract design. ERC-3643, a finalised Ethereum standard for tokens that represent regulated securities, specifies the same checks in a common form (ERC-3643). Before each transfer the token asks an identity registry whether the receiving wallet belongs to a verified investor who holds the required attestations from trusted issuers, then asks a compliance contract whether the transfer breaks any offering rule, such as a cap on the number of holders. It also checks that neither wallet is frozen and the token is not paused. An agent appointed by the issuer can force a transfer, freeze a wallet or part of a balance, and move tokens to a new wallet when an investor loses the key.
A third form puts the check on the venue rather than the token. In Project Guardian’s first pilot in 2022, DBS, J.P. Morgan and SBI Digital Asset Holdings traded tokenised deposits and bonds through adapted versions of the Aave and Uniswap protocols on Polygon, a public chain, where each trade was checked against a digital credential that a regulated institution had issued to the trader (pilot entry).
On a private ledger
On DBS’s permissioned chain the check happens one level down. Only parties DBS admits can reach the network at all, so the token needs no list of its own to keep out strangers. DBS says the permissioned design gives it full control over the services (pilot entry). The code can be the same: DBS’s chain runs the Ethereum Virtual Machine (EVM), the same execution environment as Ethereum (pilot entry).
| Whitelisted token on a public chain | Token on a private permissioned ledger | |
|---|---|---|
| Who can read the ledger | Anyone | Participants |
| Who runs it | Independent validators, unknown to the issuer | The operator and admitted institutions |
| Where holders are checked | In the token contract, or at the venue | At network access |
| Correcting a wrong transfer | Issuer’s contract functions | Operator changes the ledger |
| Who else can connect | Any platform or custodian that supports the chain | Only those the operator admits |
| Basel default for a bank | Group 2 | Can qualify for Group 1 |
Why it is built this way
The design lets the issuer keep the legal and compliance duties it cannot hand to a public network, while using that network as shared plumbing.
The issuer’s duties do not change with the ledger. An issuer of a security or a stablecoin must know its holders, meet anti-money laundering rules and be able to fix errors. The Basel Committee’s research group lists the controls a token contract can carry for this purpose: a denylist of barred addresses, an allowlist of approved addresses, and a controller that can block and reverse fraudulent transactions and amend the token’s code. It notes that the controller governs “the specific tokens of a specific issuance”, not the network (BCBS Working Paper 44, August 2024, section 3.2).
The regulators have written those controls into their rules. MAS’s deeming provisions, which give a bank a safe route to Group 1, include issuer functions to correct or freeze transactions under governance controls and with the legal right to do so, and permissioning so that “only whitelisted entities or whitelisted wallets that have been pre-screened and verified can hold and perform transactions” (MAS consultation paper, April 2026, Annex D paras 2(a) and 3(a)). The HKMA’s custody guidance says that permissioned tokens with access controls in the smart contract “may enable recovery of lost assets”, unlike permissionless tokens on a public chain (HKMA guidance, 27 May 2026, para 9). Hong Kong’s Securities and Futures Commission (SFC) lets tokenised funds use public permissionless networks only with “additional and proper controls”, with a permissioned token as the example (Wire).
What the public chain adds is reach. The institutions’ own statements put it in terms of connections to other firms. DBS sells its Ethereum notes through ADDX, DigiFT and HydraX to investors who need not be DBS clients (pilot entry). UBS reported its first on-chain subscription and redemption for uMINT through DigiFT as distributor (pilot entry). J.P. Morgan says its clients want “faster and easier money movement on public blockchains” (J.P. Morgan release).
Of these, distribution carries the most weight. A public chain is the one ledger that distributors, custodians and platforms can all connect to without joining a bank’s own network. That is why DBS keeps its tokenised deposits on its private chain but puts notes it wants other platforms to sell on Ethereum. None of these institutions has published volumes, so whether the reach produces buyers is not yet shown.
There is also a positioning reason. MAS’s interim caps on exposure and issuance, set out below, keep the business small by design. A small issue on a public chain buys a bank operating experience and standing with its regulator while the capital rules are being written, at a cost the caps limit. No institution gives this as its reason; it is an inference from the caps and from how small the published activity remains.
In our markets
Singapore has moved first on capital. MAS’s April 2026 proposal disapplies the Basel conditions on validators that a permissionless chain cannot meet, provided the bank meets principle-based requirements on governance, technology, settlement finality and anti-money laundering (para 2.4 and Annex C). The deeming provisions add conditions on the chain as well as the token: a large or unconcentrated validator set, documented governance, a defined point of finality, independent audits of smart contracts, and a business continuity plan with an off-chain “golden source” of records (Annex D paras 1 and 2). During the interim period a locally incorporated bank’s Group 1 exposure to such tokens is capped at 2% of Tier 1 capital and its issuance at 5% (para 2.8); for foreign bank branches the caps are 0.2% and 1% of branch assets (para 2.9). MAS lists “Trust Anchors” as an example of a permissioning control (Annex D, footnote 8), the credential model tested in Project Guardian.
Hong Kong has moved on custody and product rules rather than capital. The HKMA’s guidance lets banks scale custody controls to the network type (private permissioned, public permissioned, public permissionless) and asks for extra caution before relaxing controls, or outsourcing custody, for permissionless tokens on public permissionless networks (HKMA guidance, paras 9, 11 and 14). The SFC’s tokenisation circular requires added controls for funds on public chains (Wire). HKDAP is the one Hong Kong case with a published contract. ChinaAMC (HK) calls the chain for its tokenised money market fund a “public permissioned blockchain” without naming it; third-party trackers list the Hong Kong dollar class as an Ethereum token, but ChinaAMC has published no address (pilot entry).
The HKMA calls a token “permissioned” when its contract has access controls; MAS asks whether the token has whitelisting. Both describe the same design: an open chain and a closed token.
The case against
The whitelist does nothing about the chain. The Basel Committee’s research group lists risks a bank takes on a permissionless chain that sit below the token (BCBS Working Paper 44, section 2):
- Governance: upgrades are decided by participants the bank cannot hold accountable, often off-chain, and a disagreement can split the chain in two, leaving two tokens for one underlying asset (section 2.1).
- Attacks: a party controlling a majority of validation could choose which transactions are recorded (section 2.2).
- Fees: validators collect transaction fees and may be illicit parties operating under pseudonyms (section 2.3.1).
- Finality: on many permissionless chains settlement is probabilistic, and legal finality and technical finality may not line up (section 2.3.2).
- Liquidity: every transfer is visible, which can speed a run, and fees can rise and blocks fill up exactly when holders most need to move (section 2.4.1).
The paper’s main mitigant for chain failure is the issuer’s business continuity plan, such as an off-chain register that identifies the rightful owner after a fork or attack. It says the efficacy of such plans “remains an open question” and that moving an asset off a failed chain “could prove complex and expensive” (section 3.1). It concludes that current mitigants “have not been tested under stress” (executive summary). Singapore’s caps and Hong Kong’s “extra caution” are the regulators’ answer to that gap.
A whitelisted token keeps little of what makes the chain open. A critic would ask what is left of a public chain once the token restricts every holder, the issuer can reverse any transfer and trading happens on a licensed platform’s order book rather than on-chain, as the SFC’s rules for tokenised funds provide (Wire). On that view the institution takes on the chain’s operational risks and gets a shared database. A private ledger such as DBS’s, running the same EVM code, gives the same programmability without the public exposure. The Bank for International Settlements proposes a different shared ledger altogether: a unified ledger run under public-sector governance, holding tokenised central bank money, deposits and bonds together (BIS Annual Economic Report 2025, chapter III).
The non-ledger alternative is the existing register. A fund or note can keep its register with a transfer agent or depository and sell through the same platforms by conventional connections. DBS has not said whether the token or a separate register is the legal record of its notes, and UBS has not said so for uMINT (pilot entries). Where the register lives elsewhere, the chain carries a copy.
The answer depends on the asset. For cash-like tokens, such as a stablecoin or a deposit token, the trade is worth making. They gain from being usable at any whitelisted counterparty on any platform, and on Ethereum the chain-level risks listed above have been small in practice: the BCBS paper notes that no proof-of-stake chain had suffered a majority attack when it was written (section 2.2), and the issuer’s freeze and correction functions cover errors in the token itself (MAS Annex D para 2(a)). For a note sold through a few platforms and held to maturity, the case is weaker. The reach adds little once the note is placed, and the chain-level risks stay for its whole life.
Both judgements rest on the issuer’s off-chain fallback working if Ethereum has a serious incident, and, as above, no one has yet tested one under stress.
For Ethereum
This is the route regulators in Singapore and Hong Kong have opened for regulated assets on Ethereum: an ERC-20 compatible token with an allowlist, a freeze and correction function held by the issuer, and an off-chain register as backup. ERC-3643 is the finalised standard for it; HKDAP uses a custom contract with the same kinds of controls. Respondents to MAS’s 2025 consultation called the Group 2 default “not technology neutral and punitive”, citing safeguards built on layer 2 networks (para 1.2), and J.P. Morgan chose Base, a layer 2 network, for its deposit token.
Ether itself cannot use this route. It has no issuer to freeze, correct or whitelist, so it stays in Group 2 under the MAS proposal (Wire). What moves into Group 1 is bank-issued tokens that use Ethereum as settlement infrastructure. Each whitelisted transfer still pays fees to Ethereum’s validators, so the chain earns from these tokens. The tokens cannot flow into open DeFi protocols unless every counterparty wallet and pool contract is on the list, because an address not on the allowlist can neither send nor receive the token (BCBS WP44, section 3.2).
What to watch
- MAS’s response to feedback on the April 2026 consultation, and whether the 2% and 5% caps survive in the final rules.
- A Singapore bank notifying MAS and using the Group 1 route for a token it issues on a public chain.
- Published contract addresses for DBS’s structured notes, uMINT or ChinaAMC’s fund, which would show whether each uses ERC-3643, a custom whitelist, or no on-chain control.
- The first tokenised fund listed for secondary trading on a Hong Kong platform under the April 2026 circulars, and whether its tokens move on-chain between platforms.
- Any Basel Committee revision of the Group 2 default for permissionless chains.