Monument Bank cannot find a UK custodian.
That single operational failure—buried in a September 11 announcement about delaying retail tokenized deposits to November—matters more than the delay itself. A licensed British bank, backed by £2.5 billion in retail deposits and partnered with a Charles Hoskinson-funded privacy blockchain, has been stopped not by smart contract vulnerabilities, not by regulatory rejection, but by the absence of a single service provider capable of meeting two requirements simultaneously: FCA compliance and zero-knowledge proof handling.
The code compiles. The context reveals the exploit—and the exploit is not in the code at all.
The Middleware Bottleneck Nobody Modeled
The tokenized deposit narrative has been running for three years. Institutions parade proof-of-concepts, consultants publish bullish reports, and conference panels debate the merits of public versus permissioned chains. What gets almost no airtime is the unglamorous plumbing that determines whether any of it reaches production: custody infrastructure that can bridge traditional finance compliance with emerging cryptographic requirements.
Monument Bank's situation illustrates this gap with forensic clarity. The bank announced in March that it would tokenize retail deposits using Midnight, a privacy-focused Layer 1 built by Input Output Global. The architecture is straightforward on paper: customer data remains within the bank's systems, while zero-knowledge proofs validate compliance on-chain for regulatory audit purposes. Deposits continue earning interest, remain fully guaranteed by Monument, convert 1:1 to GBP, and carry FSCS protection up to £120,000.
What the architecture did not account for was the custodian layer. To hold the assets backing tokenized deposits, a custodian must satisfy FCA standards—a well-defined but demanding checklist covering capital requirements, operational controls, and client asset segregation. It must also handle zero-knowledge proofs—a capability that few traditional custodians possess and fewer still have integrated into production systems.
Based on my audit experience, most custodians fall into two categories: crypto-native firms with ZK expertise but limited regulatory credentials, or traditional financial institutions with FCA approval but no cryptographic proof processing capability. Monument needed both in a single provider. That provider does not exist in the United Kingdom.
When I reviewed similar integration challenges during the 2020 DeFi yield verification work, the pattern was consistent: projects would map their technical requirements, assume the service ecosystem would mature in parallel, and discover at launch that critical dependencies remained vaporware. Monument has now discovered this eighteen months into a flagship project.
The Midnight Question: Privacy Infrastructure Meets Institutional Reality
Midnight's positioning deserves separate scrutiny because it reveals the broader tension in institutional blockchain adoption.
Charles Hoskinson's involvement brings visibility—the Cardano founder commands attention from both retail and institutional audiences. His track record, however, includes a pattern of roadmap delays that should inform how observers assess Midnight's readiness for bank-grade deployment. Cardano's development history is one of ambitious timelines meeting extended delivery. Midnight appears to be following a similar trajectory, though whether the pause reflects genuine technical immaturity or merely the custodian bottleneck remains unclear from public disclosures.
The privacy architecture is genuinely novel for the banking sector. Zero-knowledge proofs solve a problem that has frustrated institutional adoption since the first enterprise blockchain experiments: how to achieve regulatory transparency without exposing customer data to public ledgers. Midnight's design keeps sensitive information within Monument's systems while generating cryptographic proofs that regulators can verify. This is the most compelling technical narrative in the project.
But novel architecture and production readiness are different variables. A single bank deploying with a single blockchain partner has no precedent to reference. The complexity compounds: Monument's core banking systems must integrate with Midnight's proof generation; the custodian must interface with both; FCA auditors must accept the ZK verification methodology. Consider the concentration of dependencies.
Based on my 2022 Frax Finance analysis, projects that depend on novel cryptographic primitives for security properties should be treated as higher-risk until they demonstrate at least one successful recovery from an adversarial condition.
The Custodian Gap Is an Industry Signal
Monument's failure to find a UK custodian is not merely a single bank's operational problem. It is a diagnostic signal that reveals where the RWA ecosystem actually stands versus where the narrative claims it is.
The tokenized deposit market has been described as "accelerating" for two years. Major banks have launched proof-of-concepts. Asset managers have tokenized money market funds. Consultancies have published enthusiastic reports. What has not accelerated is the supporting infrastructure—the custodians, auditors, and compliance service providers that turn concepts into production systems.
When I conducted the NFT floor price forensic analysis in 2021, the wash trading problem was largely invisible because the infrastructure to detect it did not exist. Exchanges reported volume without verification. Analytics firms lacked the tools to identify manipulation. Only after building custom on-chain forensic capabilities did the extent of the problem become measurable.
The custodian gap follows a similar pattern. The demand for FCA-compliant, ZK-capable custody exists—Monument is the proof. The supply does not. This creates both a market opportunity and a systemic risk.
The opportunity: A custodian that solves this dual requirement would capture not just Monument's business but potentially the entire UK tokenized deposit market as it develops. Based on my compliance audit work in 2025, the regulatory framework is sufficiently defined for a technically capable provider to pursue certification—assuming someone with the necessary cryptographic expertise decides the regulated custody market is worth entering.
The risk: Until this provider emerges, every UK bank pursuing tokenized deposits faces the same bottleneck. Monument chose the Canadian route, finding a custodian with FCA approval elsewhere. This introduces cross-border operational complexity, data sovereignty concerns, and potential regulatory friction that domestic custody would avoid. If other banks follow Monument's lead, the UK risks importing critical infrastructure rather than developing it domestically.
Tracing volume flows via on-chain intelligence reveals that offshore custodial arrangements can create reporting blind spots. Cross-jurisdictional data flows complicate AML monitoring and may introduce compliance gaps that FCA auditors have not yet fully mapped.
The institutional compliance framework work I led in 2025 emphasized the importance of end-to-end transaction visibility. When custody is fragmented across jurisdictions, achieving that visibility requires additional controls and potentially introduces latency that undermines the core value proposition of tokenized deposits—programmable, near-instant settlement.
The Broader RWA Context: Regulation Ahead, Infrastructure Behind
The Monument case crystallizes a pattern that has characterized the RWA sector since its inception: regulatory frameworks advance faster than the infrastructure required to implement them.
The FCA has established standards for tokenized deposit custody. The Digital Securities Sandbox provides a testing ground for novel structures. The regulatory intent is clear—Britain wants to lead in tokenized finance. What the regulator did not do, and arguably cannot do, is ensure that service providers capable of meeting those standards exist in the market.
This creates a peculiar dynamic. Projects like Monument proceed on the assumption that the infrastructure will be available when needed. When it is not, projects delay. Delays accumulate. The narrative of "institutional adoption accelerating" continues, but the actual deployment timeline extends.
My concern when analyzing Frax in 2022 was that reliance on market confidence rather than hard assets created systemic risk that would only manifest under stress. The custodian gap represents a similar structural vulnerability. The tokenized deposit system assumes custody infrastructure will be available. Under stress—whether regulatory pressure, operational failure, or market dislocation—that availability becomes the binding constraint.
The difference is that Frax's vulnerability was internal to the protocol. The custodian gap is external—a market structure problem. This makes it both harder to diagnose (projects do not routinely disclose infrastructure dependencies) and harder to fix (requires new entrants into regulated custody).
The Counter-Intuitive Angle: Why Monument's Delay Is Bullish for the Sector
The contrarian perspective that the bulls have not articulated: Monument's willingness to delay rather than compromise is a positive signal for institutional blockchain adoption.
Consider the alternative paths available. The bank could have proceeded with a non-FCA-compliant custodian, accepting regulatory risk. It could have used a crypto-native custodian without FCA approval, betting that regulators would not object. It could have simplified the architecture, dropping ZK proofs for standard transparency and losing the privacy differentiation.
Each of these would have allowed a launch announcement. Each would have created hidden liabilities. The bank chose to delay instead.
This is not the behavior of a project racing to capture narrative value. It is the behavior of an institution that understands regulatory compliance is not optional. A licensed bank cannot gamble on eventual regulatory acceptance the way a DeFi protocol can.
Based on my 2017 EtherGem experience, projects that release before addressing known vulnerabilities do not fail gracefully. The vulnerabilities eventually surface, often catastrophically. Monster Bank's vulnerabilities were identified before launch. The delay is the product of that identification.
The sector should want more failures like this—visible, pre-launch, and fixable.
What the Bulls Got Right
The tokenized deposit thesis remains sound. Banks need programmable money infrastructure for settlement efficiency. Private credit, structured products, and automated Lombard lending all require assets that exist natively on-chain. The demand for these capabilities has not diminished because one bank hit a custody bottleneck.
Monument's regulatory route is correct. Tokenized deposits have clear legal characterization as deposits rather than securities, reducing Howey test exposure. FSCS protection provides consumer confidence that stablecoin issuers cannot match. FCA oversight, while creating friction, also creates institutional legitimacy.
The architecture also appropriately addresses the privacy-compliance tension that has limited institutional adoption. Zero-knowledge proofs allow the bank to satisfy regulators without exposing customer data to public scrutiny. This is a genuine advance over the full-transparency models that most enterprise blockchains have attempted.
What the delay reveals is execution constraints beyond any single bank's control. The ecosystem of infrastructure providers has not kept pace with the ambitions of the banks they serve.
Monitoring the November launch date will be the next data point. For clients of Monument, the fear of losing access to new features and potential rewards is a legitimate concern. But the bigger structural challenge—that the infrastructure of financial plumbing is being pieced together on the fly—remains the ultimate test case. If November arrives and passes without a launch, it will not be because the regulation was too strict or the blockchain failed. It will be because the plumbing that connects them was never built at all.
The question for the sector is not whether tokenized deposits will exist. The question is whether the infrastructure required to support them will be ready before the market's attention shifts elsewhere. A bank that cannot find a custodian does not need a better blockchain. It needs a bridge—and someone has to build it on the other side.