The EU Parliament’s economic committee just reached a compromise on the digital euro, and the part that matters got almost none of the coverage. Fees and offline payments took the headlines. Underneath them, the French and German data authorities had forced privacy up the agenda, insisting the digital euro behave like cash. They are right to fight that. They are fighting it on far too small a field.

Because the digital euro the ECB is actually building is a capped, intermediated, offchain instrument that arrives around 2029. By then the question won’t be whether Europe has a digital euro. It’ll be whether anyone still needs one. The opportunity in front of the ECB right now is larger than the one it is planning for, it is buildable with technology that already exists, and everything standing in the way is a policy choice. None of it is cryptographic.

There are three doors here, and each is a model for digital money. Two have already been opened, by the two largest economies on earth, and neither leads anywhere Europe would want to go. The third is still shut, and the rest of this is about what is behind it.

The doors the others closed

The United States opened its door in July 2025 with the GENIUS Act. The law did two things at once. It gave private dollar stablecoins a real legal framework, and it barred the Federal Reserve from issuing a retail digital dollar. America chose private money over public money on rails. The dollar you hold on a public chain today is a liability of Circle or Tether, never of the Fed. And under that same law, the issuers must be able to freeze and block transactions, which they do, on request. Tether has frozen billions. So the American digital dollar is private, and it carries a kill switch written into the statute.

China opened the opposite door and found the same compromise waiting behind it. Its e-CNY (the digital yuan) is genuine central bank money, but it is surveilled by design and ringed with capital controls. Beijing recently made it interest-bearing to coax adoption along. It works well enough if you are inside the system and untroubled by being watched. Nobody outside China wants it as neutral settlement money, and that is the whole point.

Door one is private money with a freeze switch. Door two is public money under surveillance. Both are live, both work, and neither manages to be neutral and private at the same time.

That combination, public central bank money that behaves like cash on rails nobody controls, is the third door. It stands open, and nobody has walked through it.

Real money, not a wrapper

The biggest thing a digital euro has going for it is so obvious it tends to get skipped. It would be real euro.

A stablecoin is a claim. USDC is a promise from Circle that somewhere there is a dollar, or a Treasury bill, standing behind the token in your wallet. Usually the promise holds. In March 2023 it briefly didn’t, when a slice of Circle’s reserves was trapped in a failing bank and USDC traded down to 87 cents. The token was never worth more than the issuer and the issuer’s bank. (This is the distinction I’ve made before about stablecoins. A tokenised claim on money is not money.)

A digital euro issued directly by the ECB is not a claim on euro. It is euro. Central bank money, the risk-free asset, the thing every other euro instrument is ultimately a promise to deliver.

It can’t depeg. It is the peg.

Put that token on a public chain, and you have what no stablecoin can offer: the composability and reach of onchain money with the counterparty risk removed completely. Same programmability, none of the issuer risk. For anyone building onchain settlement that is not a refinement on the stablecoin. It is a different instrument. The ECB makes a version of this case in its own papers, in the gray language of a “monetary anchor,” without ever quite saying the plain thing aloud: a real onchain euro beats every dollar stablecoin on the one axis that finally settles the matter, which is whether the money is actually money.

Sovereignty is in the contract, not the validators

Here is where the objections begin and where I lose half the room.

“You can’t put central bank money on a public blockchain. You would be handing European monetary sovereignty to a crowd of anonymous validators, half of them sitting in places you don’t control.”

I understand the fear. I think it runs backwards.

Pull “sovereignty” apart, because it is two different things wearing one word. There is issuer control, meaning who can mint, who can freeze, what the rules are. And there is infrastructure control, meaning who runs the machines that order the transactions. The instinct says you need both. You need the first. The second is a trap.

Look at how the dollar actually took onchain money. Circle does not own Ethereum and never has. It controls the contract, it can mint and it can freeze, it arrived with the liquidity, and that was enough to make USDC the default dollar on every public chain. Issuer control plus reach. The validators were someone else’s concern, and it changed nothing. The dollar won the onchain frontier without owning a single block producer.

Now follow the European instinct to its conclusion. To secure “infrastructure control” you build a European chain with a European validator set, and you have made the problem worse rather than better. A small, jurisdictionally concentrated validator set is easier to coerce, easier to halt, and less credibly neutral than a large global one. You want the validator set as wide as possible, not walled off. The neutrality of a base layer is a function of how many independent parties run it and how hard they are to pressure together. A national chain discards exactly that property and calls the result sovereignty.

So the move is not to own the base layer. It is to issue on the most neutral, most decentralized base layer there is, write every sovereign power you genuinely need into the contract and into law, and (this part Europe does well) extend regulatory reach over the on-ramps and off-ramps. Where you want a say over the base layer itself, you earn it the way everyone else does, by taking part. European staking. European block builders. Client diversity. Influence in proportion to participation, rather than total control of an island nobody visits.

(If you read my piece on bridges being an anti-pattern, you already know I don’t think you cure fragmentation by adding chains. The same logic holds here. The euro does not need an island of its own.)

The things that scare a settlement engineer

The next objection is finality, because a settlement system that is not final is not a settlement system at all.

The standard objection is that public blockchains offer only probabilistic finality. You wait, you watch the confirmations stack up, and at some depth a reversal becomes unlikely. That hold for proof-of-work. It does not hold for Ethereum now. Ethereum has economic finality: once a block is finalized, reversing it would require an attacker to destroy at least a third of all staked ether, tens of billions of dollars, on purpose. That’s not “probably won’t reverse.” It’s “won’t reverse unless someone is willing to torch a fortune to force it.” Finality is slow today, around fifteen minutes, but the work to bring it down to seconds is well advanced.

Note that economic finality is a different thing to the legal settlement finality a central bank is built around. It is a guarantee backed by the cost of attack, not by statute. But it is deterministic, it is getting faster, and for the worst day there is a backstop I will come to.

The cousin of the finality fear is forks. “What happens when the chain splits, and which euro is the real one?” That is already solved, and a private company solved it years ago. When a chain forks, the issuer declares which side it honors, and the duplicated tokens on the orphan fork are worth nothing the moment the issuer refuses to redeem them. Circle does this routinely. The ECB, as direct issuer, holds the same lever, only stronger, because it is the central bank.

And if the chain halts outright, that is what the centralized core is for. The onchain euro does not replace the ECB’s own settlement system. It sits above it as the composable, public-facing layer, redeemable back into the core. If the base layer has its worst day, redemption into the core is the circuit breaker, and the central bank never has its final settlement held hostage by a network it does not run. Composability in normal times, sovereignty in a crisis.

The best of offline, onchain

Everyone treats privacy as the hard, dangerous part of a digital euro. It is the opposite. The cryptography that solves it already exists, developed by others over years. What the French and Germans did was keep it on the table, refusing to let the offline mode be quietly dropped.

Cash-like privacy means money that can pass from phone to phone with no network, no intermediary, no record. The hard problem there is stopping people spending the same coin twice when there is no shared ledger to check against. The working answer pairs two mechanisms. A secure element in the device (tamper-resistant hardware) stops the obvious copy-and-respend attack. Zero-knowledge proofs let a payment be validated while hiding who paid whom, and let a cheat, if one ever slips through, be traced back to that single spender when the coins are later banked, without exposing anyone else. Prevention in the hardware, detection in the cryptography. It is real, and most of it has been built.

Now take that same zero-knowledge machinery and put it onchain. The double-spending problem does not just stay solved, it gets easier because the thing that made it hard offline was the absence of a shared ledger. Onchain there is one. The same proof that hides who paid whom also publishes a one-time marker, and the chain checks that marker against everything spent before and rejects a second spend on the spot. No secure element is needed, no detecting fraud after the fact, no open question about who eats the loss. The ledger does the preventing. (This is shielded-pool cryptography, the Zcash lineage, with a central bank as the issuer and a narrow, court-gated way to unmask a proven cheat.) So onchain you get both at once: the cash-like privacy the French and Germans fought for, and double-spend prevention stronger than the offline mode can offer.

I am not arguing for dropping offline payments. You keep them, for the genuine no-signal moments. Offline is the one place the old trade-off survives, where you can detect double-spending but not fully prevent it, and a broken secure element is a bounded risk capped by holding limits on the offline balance. Cash has counterfeiting too, and it works anyway. But that residual lives in the fallback, not in the thing you use every day.

Here is the part that keeps getting missed. The offline privacy and the onchain settlement are not two features, they are two halves of one thing. Together they make the only digital money that is public, neutral, and private at once. That combination is the third door, and it is the whole reason to build any of this.

The surveillance inversion

The usual fear about any central bank digital currency (CBDC) is surveillance, the state watching every coffee you buy. For most designs that is a reasonable fear. For the e-CNY it is the design.

But the two open doors tell the opposite story. The private dollar is the one that can freeze you. The public yuan is the one that watches. The option everyone fears as the surveillance threat, public central bank money, is the only one of the three that does neither.

On privacy, the public euro is the private option.

Sit with that inversion. Europe’s privacy fight is not a civil-liberties nicety bolted onto a payments project. It is the differentiation itself. It is the moat.

The strongest case is wholesale

Why put any of this on a chain at all? If the use is buying lunch or a tram ticket, offline already covers it, and you could drop the chain entirely. For retail alone, that objection is correct.

The chain is not for retail. It is for the money already moving onto it: tokenized bonds and funds, collateral, institutional settlement, the slow migration of capital markets onto programmable rails. That is where the value is, and it is the part of finance with the least tolerance for a transparent ledger. No desk will settle onchain if its positions, counterparties, and timing are visible to every competitor as they happen. Public blockchains are commercially unusable for serious finance for a reason that has nothing to do with speed. They show everyone everything.

That is the same privacy that was fought for on the cash side, needed again on the wholesale side. What a citizen wants at the shop and what a bank needs on a billion-euro settlement is the same cryptographic mechanism. Build it once and both are served.

Privacy is only half of what they need. No bank will settle in another bank’s stablecoin, for the same reason banks have never chosen to hold each other’s deposits: nobody wants a competitor’s credit risk on their books. Interbank settlement runs on central bank money for exactly that reason, and going onchain changes none of it. A stablecoin cannot be neutral between the firms competing to issue it. A central bank euro can.

Give them that asset on a programmable chain and the upside is not marginal. Settlement that takes days collapses toward zero, delivery and payment clear in a single atomic step with nobody left exposed mid-trade, and the composability decentralised finance already runs onchain becomes available to regulated balance sheets. They would gain a single verified record of who owns what, the operational transparency they have always lacked, while the zero-knowledge layer keeps the competitive detail hidden. Instant, final, auditable, and private at once, which is not a trade anyone has offered them before.

So the strongest case for the third door was never retail. It is that finance is moving onchain, it will need private settlement in real money when it arrives, and whoever supplies that owns the rail the next era runs on. If Europe does not, a dollar stablecoin will, and the wholesale layer goes the way the retail one already did.

The only wall that’s real

So if the cryptography works, the finality holds, the forks are handled, the sovereignty argument runs backwards, the privacy is a feature nobody else can offer, and the institutions that would use it are already moving onchain, what is actually stopping this?

Banks. Or more precisely, the fear of what a good digital euro would do to them.

A real, risk-free, programmable euro that anyone can hold is the most attractive deposit substitute ever designed. Why leave money in a commercial bank, with its credit risk, when you can hold the risk-free asset directly and still spend it? At scale, deposits drain; banks lose their funding, lending contracts. That is not a paranoid worry. It is the actual reason the ECB’s digital euro comes hobbled. The holding caps of a few thousand euros, the absence of interest, the deliberate friction. Each of those choices exists to stop the instrument competing too well. They are engineering a digital euro that is safe precisely because it is too weak to be widely held.

A capped, non-interest, intermediated, offchain euro will not take the third door. It can’t. It has been designed not to.

The answer is not to ignore the disintermediation risk, which is real. It is to manage it with a sharper tool than a flat cap. Tiered remuneration is that tool: let people hold and spend freely for the purpose of actually paying for things, but make balances above a threshold unrewarding to sit on, either unremunerated or gently penalized. The money stays useful as money and stops being an enormous risk-free savings account. China just turned the same dial the other way, making the e-CNY interest-bearing to draw holdings in. Europe could turn it in reverse, winning scale in payments without setting off the run on banks. The tool exists. It is a policy choice, not a technical limit.

And the fear is only one side of the ledger. The institutions most afraid of losing retail deposits are the same ones with the most to gain on the wholesale side, where instant settlement in programmable central bank money is a straight upgrade on what they do today. Weaken the euro to shield them from the first risk, and you withhold the second prize. Built right, this is not something banks need protecting from. It is something they would help build.

That is the pattern under all of it. Every step relocates trust, it never removes it, and once the whole thing is stacked up, the only trust left to supply is the kind no protocol can manufacture.

Which brings me back to the three doors. The third is not open because someone left a prize behind it. It is open only because Washington and Beijing each walked through a worse one, and there is nothing waiting on the other side. Whatever goes there, Europe has to build, against the clock, and the player most likely to fumble that is Europe itself.

The door will not stay open. The cryptography is ready. The institution is the question.