I attended Stablecon this week in DC, and on Thursday I got to be in a simulation. This was a group of industry folks running a crisis exercise. The scenario was a fictional $50 billion offshore dollar coin called USDQ, and the panel was made up of industry operators playing an issuer, a custodian, an infrastructure provider, a bank, a senator, the Treasury and a prudential regulator. Before it started, the moderator put a poll on the screen asking whether the industry was prepared for stablecoin contagion. 90% of the room said no.
Sheila Bair gave the opening remarks. She ran the FDIC through 2008 and was at Treasury on 9/11, and while she was generally warm about the GENIUS Act, she was clear about something the Act doesn’t cover. That is, good reserves don’t stop a run on their own. What stops a run is the holder’s confidence that the money will be there the moment they ask for it, and that confidence depends on the intermediaries, the custodians and the service providers as much as on the assets. She also asked the room not to plan around a government bailout!
So yeah, I went in expecting it all to be a lesson about reserves. I came out thinking the exercise had actually shown something more specific, and maybe just a little bit uncomfortable. Nobody in the scenario lost money because the reserves were bad. They lost it because the settlement layer worked exactly as designed, and nothing sat in front of it to check whether it should.
What broke
In the scenario, shortly after 3 am GMT, about $5 billion of USDQ appeared on chain with no reserve deposit behind it. Attackers had compromised the validator side of a cross chain bridge. They didn’t take existing coins. What they did was convince the bridge’s minting contract that collateral had been locked on the source chain when it had not, and so the bridge issued new coins on the strength of that. That meant the unbacked coins moved into exchange wallets and OTC desks before anyone noticed. By the time the issuer’s regulator in Abu Dhabi opened an investigation into the reserve ledger, the peg was already gone.
Now to be clear, this isn’t some hypothetical, the designers had actually modeled this on something that happened in April. On 18th April, Kelp DAO’s bridge released 116,500 rsETH, worth about $292 million and roughly 18% of the token’s circulating supply, to an attacker who had never locked anything. The bridge relied on a single verifier. The attackers compromised two RPC nodes, used a denial of service attack to knock the competing nodes offline, and fed the verifier a fabricated message saying the tokens had been burned on the source chain. The verifier accepted the message and the chain settled the release. The drain ran at 17:35 UTC on a Saturday. The emergency pause came 46 minutes later. Aave, Spark and Fluid froze their rsETH markets within hours, and by one count more than $13 billion left DeFi platforms over the following two days. Investigators have attributed that attack to North Korea’s Lazarus Group. Four years earlier, the Wormhole bridge had minted 120,000 ETH of wrapped ether on Solana against collateral that didn’t exist, about $320 million at the time, and Jump Crypto replaced the ETH from its own balance sheet to keep Solana’s lending markets solvent.
When you look at these cases, none of them are problems with the reserves. The collateral was in fact where it was supposed to be. The way I look at it is what failed is the check that sits between an instruction and an irreversible settlement. The settlement layer had no way to know the check had been corrupted, so it did its job and finalized. In the simulation that turned $5 billion of phantom money into real money in under an hour.
I’ve written before that par value is really a property of the whole stack rather than just the token, and that we’ve spent a lot of regulatory effort on the train while the risk moved to the tracks. The way I think about the GENIUS Act is its basically a balance sheet law. It covers reserves, monthly disclosure, redemption at par and a comparability test for foreign issuers. It really has nothing to say about bridges, and when you look at it, a bridge is the one place where a coins supply gets created outside the issuers ledger. Its worth noting that every major stablecoin that runs on more than one chain depends on one.
What the room did about it
Ok, so now the fun! The peg broke, and the responses came quickly, and they were all responses you’d expect from a set of competent people.
The largest exchange by USDQ volume suspended redemptions and told customers their balances were secure. The bank stopped processing fiat withdrawals against the coin while its board met. The infrastructure provider blocked wallets and started a seven, thirty and ninety day look back for any tainted flows. Abu Dhabi restricted the token inside its jurisdiction. The Justice Department and OFAC froze close to a billion dollars in wallets tied to the exploit. The infrastructure provider pointed out that regulated issuers can enforce a freeze on chain, and said this was the system working as intended.
So super interesting, because that feels like the right thing, but I also think its the problem. What we saw is everyone using tools at their disposable to take finality back out of a system. Remember, this is a system whose main selling point is that finality can’t be taken back. Halting, freezing, restricting, looking back, clawing back. The inherent value of these rails is that they’re irreversible, and when it comes down to it, the only thing the crisis desk can do with them is reverse.
In a lot of ways the law anticipates this. GENIUS requires permitted issuers to have the technical ability to seize, freeze, burn or block the transfer of outstanding stablecoins on a lawful order, and it requires the same of any foreign issuer that wants access to US customers. So Congress did write a brake into the statute. But it put it behind the settlement rather than in front of it, and I suspect thats because the drafters were thinking about sanctions and law enforcement, and not about stability. A freeze is a good tool for stopping a sanctioned wallet. But I think its probably a poor tool for a run, because by the time it fires the money has moved, the attacker has swapped into something else, and the exchange has already decided which of its customers get to leave.
It feels to me like atomic settlement only works as a trust anchor if verification happens before the act. Instant finality with no deterministic check in front of it doesn’t make the system safer, what it does is make errors permanent. I’ve been thinking about this in terms of an agent mistake becoming final, but the simulation showed the same failure with no agent involved. The bridge’s verifier was the unreliable component, the chain treated its assertion as fact, and then finality did the rest.
Where the damage goes
I think the other interesting part of this exercise was the contagion path.
The person playing the prudential regulator laid it out, and I’m sure it was familiar to people who were in the market in March 2023. The unbacked coin is sitting as collateral in DeFi lending markets. Those positions get liquidated. Now liquidations need something liquid to sell, and theres only one crypto asset that trades in size at 3 am on a Saturday and its Bitcoin, so Bitcoin falls. The regulated firms with Bitcoin exposure, so think about the ETF sponsors and prime brokers with VaR limits and compliance departments, are the ones who have to sell into that, and of course they do. An exploit in a corner of DeFi that most bankers have never heard of ends up as a drawdown at the most conservative institutions in the system, over a weekend, faster than any human process can respond.
The chap playing the Treasury was concerned about something different. His concern was the roughly $40 billion of short dated Treasuries backing the coin, who held them, and whether they could be sold into a redemption wave without moving the bill market. The reserve was sound. But the reserve being sound is what made it a channel for contagion, because a large, high quality reserve is really a large forced seller just waiting for a reason to sell.
And of course liquidity went where it always goes under stress, to the venue with the fewest rules. The exit of last resort became the largest global exchange, still quoting USDQ at 80 cents after every regulated venue had restricted it. When the moderator asked whether Treasury would sanction that exchange, the answer was actually very careful. Go after the illicit finance angle surgically, because the same venue was actually now the only place many holders could get out, and shutting it would hurt the people the government was trying to protect. Again, this isn’t hypothetical. When USDC traded down to 87 cents in March 2023, Coinbase and Binance suspended conversions, and the discount reflected which doors were open more than it reflected the reserves.
Who backstops it
Bair told the room not to plan for a bailout. The rest of the afternoon played out what the alternative may look like in practice.
The regulated issuer on the panel offered to backstop USDQ, buying it at 75 cents and then at 65, on condition that the Abu Dhabi government put up collateral alongside. The custodian, who had refused to onboard the coin in the first place, talked about watching the bodies float past on the river and started asking how to pick up the distressed clients. One of the industry players then said what I guess the others were thinking. This is the moment we’ve been waiting for, which institutions are in trouble, is there a Jamie Dimon opportunity here?
Actually I don’t think that’s cynical. I think it’s more like a private lender of last resort, and in a world without a public one it’s the only lender on offer. Jump replaced 120,000 ETH for Wormhole because a Solana insolvency would have cost Jump more than $320 million. What normally happens is the bid comes from whoever has the balance sheet and the most to lose from contagion. Generally it comes at a price that moves market share along with the risk. If you think about it, the free banking era ended the same way, with the banks that ran the clearing system setting the terms for everyone else. If the industry doesn’t want the Fed inside the perimeter, then this is what the perimeter looks like with the largest regulated issuer buying its competitor’s liabilities at 65 cents.
The bid is also a tool applied after the fact. Like the freeze and the halt, it arrives once the money has moved, and its price ends up being set in the middle of the run by whoever happens to have cash that afternoon.
Putting the check in front of the settlement
Reflecting on this exercise, it feels like the crisis playbook the industry is writing is aimed at the wrong end of the transaction. We are getting reasonably good at reversing settlements. We have barely started on the harder problem, which is not finalizing a bad one in the first place.
I think the most direct fix is likely so sort of verification before finality. A mint on one chain should not be final until the lock on the other chain has been proven, and that proof should never rest on a single verifier that two poisoned RPC nodes can capture. This is the same idea that makes atomic settlement valuable everywhere else in finance. In delivery versus payment, the payment leg doesn’t settle unless the delivery leg does. Cross chain issuance today mostly runs on an assertion, and in April an assertion released $292 million. I suspect the reason nobody has built the proof is not that it’s hard to imagine. It’s more like that verification costs time and money, and bridges compete on speed, and of course the issuer usually doesn’t control the bridge its coin travels over. In my mind, that’s a market structure problem before it’s an engineering one.
A second fix is to make halts a designed feature rather than just a judgment call. It was interesting that every pause in the simulation was a decision taken under pressure with partial information, by an exchange, a bank board or a foreign regulator, and each one changed who could get out. Equity markets learned after 1987 to pre-commit to circuit breakers with known triggers and known durations that everyone can see in advance. I wonder if a supply side version, like a cap on how fast a bridge can mint relative to attested reserves, would have stopped Kelp’s drain in the first block instead of the 46th minute. I’m sure it would also occasionally block a legitimate large mint, and that would have to be the trade the industry is willing to make.
The third is an exit that isn’t the least regulated venue in the world. As long as the only open door in a crisis belongs to whoever ignores the restrictions, restrictions concentrate the run rather than contain it. It feels to me that somebody regulated has to be willing to make a market in a broken coin, at a price, on a weekend. The issuer’s 65 cent bid was the right idea, but probably too late in the game. The terms of that bid, who stands behind it and what they get paid for the risk, should be agreed before the event. In the free banking era that role fell to the Suffolk Bank, and it was paid for it, in the deposits member banks had to keep with it.
The settlement layer is valuable because it gives the same answer every time. The simulation showed what that looks like when its asked the wrong question.
References
The simulation
Stablecoin Crisis Simulation, Stablecon, September 10, 2026. Panelists appeared in their individual capacities and in character; roles, not people or employers, are described here. The scenario, coin, venues and news bulletins were all fictional.
The real-world analogs
The statute

