Launched by @WillMorales_SF, this is a community for the next generation of builders in FinTech, Banking, Blockchain, Crypto. Sign up for our weekly newsletter!
Given the level of bad information going around on Twitter about this, I wanted to dig in briefly on the Prime Trust situation and regulation.
First, to refresh everyone, on regulatory frameworks:
1 - Your primary rules come from your charter and your regulator. Regardless of what you put in documents elsewhere, these govern the existence of your bank or trust and are the source of truth.
For example, with the NYDFS, if I am a stablecoin issuer, and I say in my T&Cs with users that I can buy Dogecoin for the reserve, that's one thing. However, the NYDFS guidelines for stablecoin issuers do not allow Doge. They only allow bank deposits, t-bills, ON reverse repo, and TMM funds. That's it. What happens if you go buy Doge?
Fines, loss of license, jail are all possible. You can't just override the regulators with your customer-facing docs.
Also: your T&C's not matching your regulatory authority itself should be a red flag that you are sloppy.
2 - Regulators have two different kinds of authority. One is what I just said, which is setting the rules. The other, which some people like to pretend don't exist or ignore, is that they have supervision and ongoing conduct authority. That is to say, they are going to show up in your office, conduct audits, supervise actions, and generally make sure you are neither a bunch of clowns nor a bunch of criminals. This isn't just about what the rules are, but also HOW you obey the rules and if you are reasonable and safe about them.
Okay, with that out of the way, let's address two questions that seem to be flying around:
First, what happened with Prime Trust? Here, it appears the core problem was that they lost the keys. Literally. They lost the private keys. This is the old school equivalent of "we put all your money in a vault, but then we forgot the combination to the vault, so we can't get it out". In that case, they owe you money, but they can't get to it, so... bankruptcy. As an additional factor, it appears that (in a well thought out plan) Prime Trust covered this up and was paying out customers with other funds to try to keep this going while they fumbled around like idiots trying to figure out how to fix this. To be clear: don't do this. You have an error of that magnitude, you have to self-identify and let the regulator know. Secondarily, their regulator should have figured this out somehow, as should their auditor have. Lots of failures here, but important detail, this is not a failure of rules. This is a failure of conduct and supervision. "Hey it's totally cool if you lose the keys and then lie about it" is not part of the Nevada trust statutes.
Second, is a state-level trust, an SPDI, or a state or national level bank safer? The answer to this, as it turns out, extremely complicated and not subject to a simple "yes" or "no".
On trusts vs. SPDIs: they are very similar entities. Despite a certain person blasting around the customer-facing T&Cs, I've spoken to a regulator and confirmed Prime Trust did not have the authority to lend out customer assets or rehypothecate them. They did have the authority to place cash in normal cash management vehicles (bank deposits, t-bills, mmfs, etc.), which would have been covered under the T&Cs we have seen, but they did not have the authority to lend them out for, say, mortgages. Both entities have pretty much the same legal authority: you hold assets and you don't lend them out in risky fashion, and you don't use leverage.
So what's the big difference among all these things? A lot of people will not like this answer, but to me, it's the quality of the regulator. Trusts are largely going to be an issue of oversight, and making sure they obey the rules they are ostensibly governed by. Nothing in the SPDI rules vs. a Nevada trust vs. a NY trust is going to cover losing the private keys. None of them are "allowed" to do that. But if I'm picking among those three regulators purely for customer safety, based on conduct I have seen so far, here is my personal stack ranking:
Nevada Trust < Wyoming SPDI < NYDFS Trust
Note that the order is not based on the legal form factor; the SPDI is between two trusts! It's based on how much I trust each regulator to successfully supervise the entity and enforce the rules.
Second, the regulator isn't even the first thing I would look to, and here is where we are going to get absolutely wild when it comes to supervision. Do you know who I would trust more than all three of those things and literally anyone in the crypto ecosystem?
JP Morgan.
Funny. That's a global bank, allegedly the thing we are all railing against, which does engage in risky lending, and yet I'm telling you, publicly, that I trust them more than any crypto trust. Why?
They are maniacal. I worked there. The risk teams, controls, and even front office people at JPM are a different caliber than the people I encounter in crypto (who are, if we are being brutally honest, pretty bush league when it comes to actual risk management). The level of focus on controlling risk is far higher, and the best two determinants historically of ongoing good risk management is the history of the institution (e.g. it's better to have been around for 100 years than 1 year) and the quality of the people. JPM has great people. I've worked with a lot of them.
Why is this? These people are crunchy, grumpy, asshole risk professionals with a long track record of doing it right. That's your number one factor, because the best thing to prevent Prime Trust? Don't lose the keys in the first place. And don't trust you didn't lose them, have six different layers of people, all of whom hate each other and would love to get the others fired for a mistake, all checking each other to make sure the keys are there.
Oh, and if they do fuck up? They have a giant balance sheet and tons of capital, so if they lose my private keys or the money in my bank account, they are 100% going to be paying me back.
This relates to the actual objections banking regulators have to crypto companies, when you get inside the rope and talk to them. Things being "crypto" in ideology are usually number three on the list when they talk to me about this. Number one is "this stuff is really new, are we sure it works, what are the procedures, how do we have good rules"; there are some good answers to this (see: @fsa_JAPAN), but I think that's a totally legitimate question. Number two, to paraphrase, is "what the fuck is with these people". I've gotten more than one extremely angry or confused phone call from a regulator asking to sanity check things they just heard from crypto companies with me, and most of the time I'm like yeah, no, that is as insane as it sounds and I would not let them do that (for instance: massive payments processing with $150k of capital). So real talk for the space: you need to start taking risk management way more seriously.
How many crypto firms that wanted to do bank like activities had top tier credit risk management teams? Counterparty credit? Market risk? Capital planning? Liquidity management? KYC/AML? Trade surveillance? How many of them held appropriate capital under B3, even if you ignore the extremely punitive treatment for crypto and just benchmarked assets by vol (leaving you more in the neighborhood of EM or equities)?
It's basically zero.
The over-preference for fighting weird-ass ideological battles about specific phrasing around rehypothecation (of cash!) while completely neglecting building out a truly institutional framework is part of why we are facing Operation Chokepoint 2.0 in America. And while I've obviously spoken out about it and think maybe things have gone too far, I 100% see where regulators are coming from and the continued failure of the industry to bring in people with a comprehensive understanding of these issues and manage risk in a reasonable way are real issues that need to be resolved before any normal two-legged person should trust crypto more.
TL;DR - actually, yeah, I trust banks way more right now until crypto gets its shit together. Not because they are better in theory, but because they are better in practice.
@FinTechtris Weekly is out now!
🚨 Topic:
Differentiation needed in #FinTech — now more than ever:
- differentiation leads to competitive advantage;
- paths to gaining differentiation;
📰 Plus top headlines!
Hit the link below & subscribe today 📩!
https://t.co/uBk621IIft
#Embeddedfinance gains momentum as non-banking firms integrate #financialservices (payments, cards, accounts, open banking).
🚕Uber, Starbucks ☕️, Doordash 🛍, and other top brands are using it build new revenue streams with new & existing customers.
Here’s a 🧵 on the topic —>
My topic of the week focused on user onboarding in everyday #fintech & #banking apps.
Covers key points:
- regulation in validating users
- obligations for banks & fintechs
- list of #compliance vendors
- best practices
Check it out: https://t.co/M2wzjBMqj7
@FinTechtris
A new year brings new perspective.
For #FinTech builders, this means the same offerings from 2021 - 2022 won’t cut it in 2023.
To make it thru the turbulence, a differentiated #MVP (minimum viable product) is critical. Check out my deep dive post:
https://t.co/nNbswRsr0p
Coinbase to fire nearly 1,000 employees as it seeks to get costs under control amid cratering crypto trading volume.
Also, when did it become normal to fire employees by sending an email to their *personal* address?
https://t.co/Gf7H8VyYBj
I took a different take on the outlook for #fintech in 2023.
By diving into top sectors -- #payments, #banking, #crypto, #lending, #investments -- we identify key opportunities to explore, where to hold back.
Give it read and let me know what's missing.
https://t.co/v1EaH9DWKX
Super excited for @TechCrunch#Disrupt2022 next week! If you’re attending (or happen to be in San Francisco 🌁), let’s meet up! Hyped to discuss what’s going on in #fintech and #banking 🏦 — send me DM 📩