Institutional digital finance has grown by more than 100% in the past 18 months, yet it still represents less than 0.02% of traditional clearing volumes. That gap framed a Consensus Miami panel this week where executives from Moody’s Ratings and the non-custodial exchange ChangeNOW argued that blockchain systems can satisfy compliance demands without forcing every user to surrender their identity.
The panel, focused on what speakers called the onchain “intelligence layer,” tackled a tension that has followed crypto since its earliest days: public blockchains make transactions traceable enough to audit and police, but that same transparency can expose personal financial activity to anyone with a block explorer. Traditional finance solves accountability by knowing who you are. Crypto, at least in its original vision, promised you could transact without that exposure.
The $35 Billion Question
Rajeev Bamra, global head of strategy for digital economy at Moody’s Ratings, put some numbers on the scale of the problem. He estimated the institutional digital-finance market at roughly $35 billion today. Compare that to more than $200 trillion in annual clearing-house flows in conventional finance, and you see why traditional institutions still view crypto as a rounding error.
But that rounding error is growing fast. Bamra cited growth of “over 100 or 150%” in the past 18 months, a pace that suggests institutional players are finding ways to participate even without the identity infrastructure they’re accustomed to. The Bitcoin treasury ecosystem alone has expanded dramatically, with executives at Consensus projecting a $3 trillion digital credit market built on Bitcoin-backed instruments.
Bamra framed the conventional intelligence layer around three questions: “Who is it? What are they doing? And can I trust the record?” In traditional finance, banks, custodians, clearinghouses, and credit-rating agencies have answered those questions for decades. The challenge is building equivalent trust on rails that were explicitly designed to function without central gatekeepers.
Hybrid Architecture as the Middle Path
The solution Bamra outlined is architectural rather than philosophical. Instead of picking between fully public or fully private blockchains, institutions will increasingly build hybrid systems that split the work.
“Private permission networks are going to offer the accountability, the credibility aspect,” he said, while “the public permissionless brings the liquidity which the private permissions don’t.”
Think of it like a corporate intranet connected to the public internet. The intranet handles sensitive internal operations with known participants and controlled access. The internet provides reach, liquidity, and interoperability. Neither alone does everything you need.
For Ethereum and other public chains, this framing matters because it suggests institutional adoption doesn’t require those networks to become permissioned. They serve as liquidity venues and settlement layers while permissioned sidechains or private networks handle the identity and credentialing functions institutions require. You can track real-world assets and tokenized credit instruments through our sectors dashboard to see how this hybrid approach is playing out in practice.
ChangeNOW’s Address-Level Compromise
Pauline Shangett, chief strategy officer at ChangeNOW, approached the same problem from the user side. Her platform operates as a non-custodial exchange that does not enforce KYC by default. That design choice puts ChangeNOW closer to crypto’s original ethos, but it also raises obvious questions about how the company handles compliance and law enforcement requests.
Shangett’s answer: map wallet addresses, not people.
“Bitcoin at its core, at its origin was a semi-anonymous digital cash,” she said. ChangeNOW works with AML providers and blockchain forensics firms to monitor transaction flows at the wallet level. “All of this blockchain forensics infrastructure allows us to not map people who are passing funds through our system, but instead map their addresses.”
When law enforcement agencies contact ChangeNOW, the company provides transaction data without doxing the person behind the transaction. The wallet address itself becomes the accountability unit. Investigators can trace funds through the blockchain’s public ledger without the platform having to know (or store) the real-world identity of every user who touches it.
This is a meaningful distinction. Traditional AML frameworks assume you identify the customer at onboarding and monitor their activity going forward. ChangeNOW’s model flips the sequence: monitor the activity first, investigate specific addresses when red flags appear, and only pursue identity when there’s a concrete reason to do so.

Where Regulatory Intentions Collide with Execution
Bamra offered a nuanced take on the regulatory landscape. The European Union’s Markets in Crypto-Assets Regulation (MiCA) and the U.S. GENIUS Act both ask fundamental questions about asset quality, segregation, and liability. In that sense, regulators on both sides of the Atlantic are trying to solve the same problems.
“We think there is regulatory convergence in intention, but there’s fragmentation in reality or in execution,” he said.
The specifications layer is where the divergence becomes painful. MiCA imposes detailed requirements on stablecoin reserve composition, liquidity buffers, and redemption rights. The GENIUS Act, still working through Congress, takes a different structural approach focused on issuer licensing and prudential oversight. Entities operating across jurisdictions face the challenge of building compliance systems that satisfy both frameworks without duplicating costs.
For privacy-preserving designs, this fragmentation creates additional uncertainty. An address-level monitoring approach that satisfies one regulator might not satisfy another. A hybrid architecture that works for European institutional clients might need different configurations for U.S. operations. The policy debates that opened Consensus touched on these tensions, with eight hours of regulatory discussion covering everything from DeFi oversight to IRS reporting requirements.
The Liability Framing
Shangett ended with a regulatory-liability argument that cuts to the heart of where responsibility should actually sit in crypto’s value chain.
“The agents who should be held liable for the regulatory frameworks and the adoption thereof are agents who are dealing with emission and not transmission,” she said.
Translated: if you’re issuing tokens, you bear the regulatory burden. If you’re just facilitating their movement, your obligations should be lighter. This framing has obvious appeal for exchanges and infrastructure providers, but it also reflects a genuine functional distinction. The entity that creates an asset and brings it to market has control over its structure, disclosure, and initial distribution. An exchange that lists it afterward is more like a highway than a car manufacturer.
Regulators haven’t fully embraced this distinction. MiCA, for instance, places substantial obligations on crypto-asset service providers regardless of whether they issued the assets they’re facilitating. But Shangett’s argument points toward a principle that could shape future regulatory design: match liability to control.
What This Means for the Market
The practical implication of the panel’s discussion is that privacy and accountability exist on a spectrum, not as binary alternatives. The question isn’t whether to sacrifice one for the other but how to build systems that deliver appropriate amounts of each at different layers.
For retail users who want to swap tokens without creating an identity record, wallet-level monitoring offers a compromise. The blockchain’s public ledger provides auditability. Forensics tools flag suspicious patterns. But the user’s personal information doesn’t automatically enter a centralized database with every transaction.
For institutions that need counterparty credibility and regulatory sign-off, private permissioned networks offer those assurances without requiring the entire public chain to adopt the same restrictions. The liquidity advantage of permissionless DeFi remains accessible while the credentialing happens in a controlled environment.
The hybrid approach also explains why institutional adoption has accelerated despite the absence of a unified global regulatory framework. Institutions aren’t waiting for regulators to solve the identity problem. They’re building layered systems that handle compliance internally while tapping public networks for what those networks do best: liquidity, composability, and always-on settlement.
Moody’s presence on the panel itself signals something about where traditional finance sees this heading. Credit-rating agencies don’t typically show up to discuss theoretical frameworks. They show up when there’s business to rate. Bamra’s estimate of 100-150% growth in 18 months suggests the rated-instrument pipeline is expanding faster than public attention has recognized.
The gap between $35 billion and $200 trillion remains enormous. But the growth trajectory, combined with architectural approaches that address compliance without abandoning privacy, suggests the gap is closable. Not by making public blockchains private, and not by making private blockchains public, but by building systems that know when to use each.




