Sealed as of August 9, 2026 · Stellae Liquiditas LLC · Division 03 · Digital Assets

This is a standalone position, not an amendment or continuation of any prior piece. It makes three separate, evidenced claims about the legacy card system: that its authorization architecture was built to fail in a specific, predictable way; that the institutions who built it profit from patching around the flaw rather than retiring it; and that when reform is proposed, from any direction, it is resisted, diluted, or reversed. Each claim is sourced independently. Together they describe a system performing exactly as designed.


I. The Architecture TradFi Built

A card transaction is authorized by matching a handful of static numbers — a sixteen-digit account number, an expiry date, a three-digit code — against a verification system with no shared, centralized memory of how many times those numbers have already been tested elsewhere. This was not always a hidden defect. It is the foundation the entire system was built on, and two independently documented attack classes exploit it directly.

In December 2016, researchers at Newcastle University published findings in IEEE Security & Privacy describing the Distributed Guessing Attack. Starting from a single known card number, an attacker can determine the expiry date in as few as 60 guesses and the CVV in fewer than 1,000 — individually enough to trip a fraud lockout, except the guesses are spread across hundreds of merchant websites simultaneously, so no single site sees enough failed attempts to raise an alarm. Full compromise takes about six seconds. Critically, the flaw was Visa-specific: Mastercard’s centralized network detected and shut down the same distributed attack in fewer than ten attempts. One network had a shared view of authorization attempts across the ecosystem. The other did not, and nothing in the underlying card-number format required it to.

A second, more fundamental exposure requires no stolen card at all. A card’s first six to eight digits — the Bank Identification Number — are public information, openly available through commercial lookup databases. The final digit is a checksum computed by the Luhn algorithm, a formula published in the open literature. An attacker can generate a plausible, correctly formatted card number from these two public facts alone and test it against lightly protected payment gateways until one returns a live response. The Federal Trade Commission’s Consumer Sentinel Network Data Book recorded 114,348 credit-card-fraud reports in 2023, responsible for approximately $246 million in losses — a meaningful share traceable to exactly this category, an attacker who never needed to breach anything, because the system generates its own attack surface in public, by design.


II. What TradFi Profits From

TradFi does not profit from fraud directly. No bank books a fraudulent charge as revenue and keeps it. The mechanism is indirect, and precisely for that reason it needs to be stated expressly rather than gestured at: card issuers and networks monetize the ecosystem that fraud generates — fees earned before losses are reversed, penalties charged to merchants after the fact, insurance products sold against the risk, interest exposure created by the confusion of being defrauded, and pricing that treats fraud as a permanent cost of doing business rather than a defect to be engineered out. Fraud losses are real and are absorbed somewhere in the system. But the architecture is structured so that revenue is collected at multiple points along the way, regardless of outcome, while the underlying flaw described in Section I remains unfixed. Five mechanisms, each independently documented:

1. Interchange revenue is earned before a transaction is ever known to be fraudulent. Interchange is assessed at authorization and settlement — the moment the card is charged. A chargeback, if one occurs at all, is a separate, later reversal process, and the interchange fee has typically already been earned and distributed before that reversal completes. Visa and Mastercard together control roughly 85 percent of the U.S. credit card network market, and card-issuing banks collected over $100 billion in swipe fees in 2023 alone — a toll on every transaction processed through the authorization model described in Section I, fraudulent or not, and earned regardless of whether that architecture is ever fixed.

2. Chargeback fees fall on the merchant, not the network or issuer. When a cardholder disputes an unauthorized charge, the network’s own operating rules impose a chargeback fee on the merchant handling the dispute — a cost layered on top of the fraud loss itself, collected by the same parties who designed the authorization system the fraud exploited. The merchant absorbs both the underlying loss exposure and the fee for the dispute process required to contest it.

3. Fraud-protection and identity-monitoring products are sold as recurring revenue — and the CFPB has repeatedly found the industry oversold them. This is not a theoretical incentive; it is a documented, adjudicated pattern. Between 2012 and 2016, the Consumer Financial Protection Bureau, often jointly with the Office of the Comptroller of the Currency or the FDIC, ordered five major card issuers to pay consumer relief and penalties for deceptively marketed credit-monitoring, identity-theft-protection, and payment-protection add-on products — many billed to cardholders for services that were never fully performed:

  • Bank of America — $727 million in consumer relief (2014), including $459 million to roughly 1.9 million accounts charged for credit-monitoring services that were not performed or only partially performed.
  • Citibank — $700 million in consumer relief to approximately 8.8 million accounts, plus a $35 million penalty, for deceptively marketed products including “IdentityMonitor,” “PrivacyGuard,” and wallet-protection services.
  • JPMorgan Chase — $309 million in refunds to over 2 million consumers, plus a $20 million CFPB penalty and a $60 million OCC penalty, for deceptive marketing of identity-protection and credit-monitoring add-ons.
  • Discover — $200 million in consumer refunds (FDIC and CFPB jointly) for deceptive telemarketing of payment protection, credit-score tracking, and identity-theft-protection products.
  • Capital One — approximately $140 million in refunds to 2 million customers plus a $25 million penalty, for deceptive marketing of payment-protection and credit-monitoring add-ons by its vendors.

The CFPB has described this as one of a dozen or more actions taken against the same category of practice industry-wide. The fear of fraud was the product being sold. In at least five documented cases, regulators found the service behind it was not being delivered as promised.

4. Interest exposure during a dispute is conditional, not automatic — but the condition is easy to miss. Under the Fair Credit Billing Act, a cardholder who files a proper written dispute to the address specified for billing inquiries is not required to pay the disputed amount, or interest on it, while the creditor investigates. That protection is real. But it applies only to open-end revolving credit, not installment obligations; it requires the consumer to follow a specific, formal notice procedure that many cardholders do not know exists and do not use, often disputing instead through a phone call or app that may not trigger the same formal protections; and if the investigation concludes against the consumer, the disputed amount becomes owed retroactively, “possibly with accrued interest.” The legal right exists. The practical gap between that right and what an average person actually does in the disorientation of discovering they have been defrauded is where exposure survives.

5. Risk is priced in, not engineered out. Merchant discount rates and consumer fee structures carry a fraud-risk component as a standing line item — a cost of doing business that is quoted, budgeted, and passed through rather than a defect the underlying authorization architecture is redesigned to eliminate. The same $100 billion in annual card fees cited above already prices this risk into every transaction, fraudulent or not.

None of these five mechanisms requires coordination or bad faith to operate. An architecture that earns revenue at the point of authorization, penalizes the merchant at the point of dispute, sells protection products against the risk it created, exposes the confused cardholder to conditional interest liability, and prices the whole cycle into a standing fee schedule does not need a conspiracy to persist. It only needs to keep working exactly as built.

The clearest evidence that even the “fixes” follow this same pattern came from a court, not a critic. When EMV chip technology rolled out in the United States in October 2015, it was implemented as a liability shift, not a security fix: whichever party — merchant or issuer — used the less-compliant technology at the point of sale would bear the cost of resulting fraud. On October 17, 2025, a federal court granted preliminary approval to a $231.7 million settlement resolving allegations brought against Visa, Mastercard, Discover, and American Express that they had improperly shifted EMV liability losses onto merchants — a legal finding that the mechanism sold to the industry as a fraud solution functioned in practice as a further cost-transfer instrument benefiting the networks that designed it.

EMV itself is not owned by any neutral standards body. It is owned and managed by EMVCo, a consortium whose members are Visa, Mastercard, JCB, American Express, China UnionPay, and Discover — the same networks whose base authorization architecture created the exposure the standard claims to address. The parties selling the patch are the parties who built the wound, and the patch generates a licensing and compliance cycle — new terminals, new certifications, new liability rules — that recurs every time the underlying flaw resurfaces in a new form. Tokenization vendors sell a further layer on top of this, marketing PCI DSS attestations as general security assurances when they verify only that stored data is handled correctly within a defined scope — saying nothing about the authorization architecture the card is subsequently checked against, because that architecture belongs to the networks, not the vendor.

MechanismWho CollectsWho Ultimately Bears the Cost
Interchange on the transaction itselfCard networks and issuing banksMerchants, via fee structure
Chargeback processing feesNetworks and issuersMerchants
Fraud-protection and identity-monitoring productsIssuing banks (subject to CFPB enforcement)Consumers
Conditional interest on disputed balancesIssuing banksConsumers who miss formal dispute procedure
Risk-adjusted merchant discount ratesNetworks and issuersMerchants and consumers, via pricing

III. Retrofits Instead of Retirement

When reform is proposed that would touch the architecture itself rather than add another patch on top of it, the pattern holds: resistance, dilution, or reversal.

The most prominent card legislation currently before Congress, the Credit Card Competition Act of 2026 (S. 3623 / H.R. 7035), illustrates the dilution path. Reintroduced January 13, 2026 with fresh political backing including a presidential endorsement, it would require large issuers to enable a second, non-Visa/Mastercard network per card. Versions of this bill have been introduced repeatedly since 2022 and stalled in committee every time. Even in its best-case form, the bill does not touch authorization architecture, fraud detection, or either attack class described in Section I — it proposes competition among toll collectors, not the removal of the toll.

The reversal path has already happened once, to a more ambitious reform than this one. In 2010, the Durbin Amendment to Dodd-Frank empowered the Federal Reserve to cap debit interchange fees for large issuers; the Fed implemented the cap via Regulation II in 2011. That price-cap regime held for fourteen years — until August 2025, when a federal district court, ruling in Corner Post v. Board of Governors on remand from the Supreme Court, vacated Regulation II’s fee-cap standard as contrary to the statute itself. A reform built through Congress, implemented by a federal regulator, and left standing for over a decade was unwound by a single district court ruling. This is not evidence that reform is impossible. It is evidence that reform aimed at the toll, rather than the architecture generating the toll’s justification, is provisional by nature — subject to the next lawsuit, the next administration, the next favorable court.

Nothing in this section required a plan or a conspiracy behind it. An industry earning $100 billion annually from an architecture it did not have to justify, selling the patches for that architecture’s known flaws as separate products, does not need to coordinate resistance to structural reform. The incentive not to do so is already built in.


IV. Signature-Based Settlement Retires the Architecture, Not the Toll

Digital-asset settlement does not patch the model described above. It removes the premise it depends on.

A card transaction is authorized by matching static, reusable numbers — some of them, as shown in Section I, publicly reconstructible — against a network with no shared record of prior attempts. A signature-based transaction on a network like the XRP Ledger is authorized by a cryptographic signature computed fresh for that specific transaction, using a private key that is never transmitted, never typed into a merchant’s form, and never exists as a small guessable number or a publicly derivable credential to begin with. There is no CVV-equivalent field to brute-force, and no BIN-equivalent public prefix from which the rest of a valid credential can be built, because authorization was never designed around a secret short enough to guess or a numbering scheme public enough to reconstruct. The structural gap that made both attacks in Section I possible — no shared visibility across independent verifiers — closes by design: the ledger is a single, shared, publicly verifiable record, not thousands of siloed authorization systems each blind to what happened everywhere else.

The same logic reaches Section II’s problem from underneath rather than around it. The Credit Card Competition Act’s best-case outcome is competition among intermediaries who each still take a cut, and the Durbin Amendment’s history shows even a successfully legislated cut can be litigated away. Peer-to-peer settlement has no intermediary in the authorization path to take a cut from, and no fee schedule for a future court to vacate, because there was never a toll booth to begin with. This is not a cheaper patch layered onto the existing structure. It is the absence of the structure that made the patches necessary.


V. What This Trades Away

None of this should be read as a claim that digital-asset settlement eliminates risk. It retires the specific architecture responsible for the fraud categories described above and trades it for a different one, and this firm has already published the fuller accounting of that trade elsewhere. In “The Bitcoin Abstention” and its Amendment No. 2 on the Coldcard entropy event and custody doctrine, Stellae Liquiditas documented in detail how a private key — unlike a CVV or a generated PAN — can be compromised by flawed generation, insider access, or memorization rather than brute-force guessing, and how the absence of a chargeback mechanism on most base-layer transactions removes a consumer protection the card system, for all its flaws, provides by design.

The honest claim is narrower than “blockchain ends fraud.” It is this: the specific architecture that made field guessing and BIN generation possible, and the fee structure that made patching more profitable than rebuilding, have no equivalent in signature-based settlement. Key-management risk is not eliminated by that fact. It is a different risk, on a different party, without a swipe fee attached to it either way.


VI. Bearing on the Firm’s Position

Stellae Liquiditas holds no legacy card-rail exposure as a treasury matter. This piece documents why that is a considered structural judgment rather than an absence of one. An industry that earns its revenue from an architecture it did not have to justify, sells the patches for that architecture’s own known flaws as separate products, and has demonstrated — through a stalled bill and a vacated regulation — that it will outlast reform aimed at the toll rather than the foundation, is not a system in the process of fixing itself. It is a system performing exactly as its incentives predict.

The vulnerability was not an accident TradFi failed to catch. It was the foundation TradFi built on, has profited from at every subsequent layer, and has no structural incentive to retire.


Sources

Consistent with the firm’s Public Content Sourcing Standard: peer-reviewed research, primary legislative and judicial text, government data, and first-party institutional filings only. No news-outlet coverage is cited as a final source.

  • Ali, M., Arief, B., Emms, M., & van Moorsel, A. — “Does the Online Card Payment Landscape Unwittingly Facilitate Fraud?” IEEE Security & Privacy, 2017 (Distributed Guessing Attack; peer-reviewed).
  • Newcastle University — first-party press release on the Distributed Guessing Attack research findings, 2016.
  • Association of Certified Fraud Examiners — “The Evolution of PAN Enumeration Attacks,” Fraud Magazine, 2025 (ACFE first-party institutional publication) — BIN attack mechanism and distinction from field guessing.
  • Federal Trade Commission — Consumer Sentinel Network Data Book 2023 (government primary source) — credit card fraud report volumes and losses.
  • EMVCo — standard governance and consortium membership (Visa, Mastercard, JCB, American Express, China UnionPay, Discover); first-party institutional documentation.
  • Fraud Liability Shift Settlement — preliminary court approval, October 17, 2025, resolving claims against Visa, Mastercard, Discover, and American Express regarding EMV liability-shift practices (primary judicial/settlement record).
  • Consumer Financial Protection Bureau — enforcement actions and consent orders against Bank of America (2014, $727M), Citibank ($700M), JPMorgan Chase ($309M plus penalties), Discover ($200M, joint with FDIC), and Capital One (~$140M plus penalty) for deceptive marketing of credit-monitoring, identity-theft-protection, and payment-protection add-on products (consumerfinance.gov; government primary source).
  • Fair Credit Billing Act (15 U.S.C. § 1666, amending the Truth in Lending Act) — billing-dispute procedure, interest-suspension conditions during investigation, and retroactive liability upon adverse resolution (primary federal statute).
  • Congressional Research Service — Report R41913, “Regulation of Debit Interchange Fees” (government primary source) — Durbin Amendment and Regulation II history.
  • U.S. District CourtCorner Post, Inc. v. Board of Governors of the Federal Reserve System, ruling vacating Regulation II’s fee-cap standard, August 2025 (primary judicial source).
  • S. 3623 / H.R. 7035, Credit Card Competition Act of 2026, 119th Congress — bill text, Congress.gov / GovTrack.
  • PCI Security Standards Council — PCI DSS attestation framework and scope definitions (pcisecuritystandards.org).
  • XRP Ledger documentation — transaction signing model and account key rotation.
  • Stellae Liquiditas LLC — “The Bitcoin Abstention” and Amendment No. 2 on the Coldcard entropy event and custody doctrine; self-citation for the firm’s key-management risk treatment.

Stellae Liquiditas LLC · Principal-only digital asset treasury · Stellae Group Division 03. Sealed August 9, 2026. This statement reflects the firm’s own treasury conviction and is not investment advice. Where the tokenization-vendor industry is discussed in Section II, the observations are structural and industry-wide, not an allegation against any named party. Claims regarding named card networks and issuers are limited strictly to what is documented in the cited primary and judicial sources.