Paper: Privacy is Fungibility: Why Endogenous Tokens Are Not Money
Authors: Alex Lynham, Geoffrey Goodell
Date: 15 May 2026
Estimated Reading Time: 18 minutes

The paper argues that endogenous blockchain tokens should not be considered money and are better understood as a form of credit. Building on the framework from Kahn et al.'s Money is Privacy, the authors define money primarily through privacy and fungibility rather than through transferability or scarcity. They classify blockchain assets according to trust locus and security locus, distinguishing endogenous cryptoassets from stablecoins, CBDCs, and cash-like instruments. The paper contends that public ledgers with account-based state expose identities, balances, and transaction histories, making them structurally incompatible with cash-like privacy. The authors extend existing economic models of theft and opportunistic behavior to blockchain environments, arguing that public visibility creates conditions resembling credit systems rather than anonymous cash systems. They further claim that stablecoins on public blockchains inherit many of the same limitations because they depend on the security and governance of the underlying ledger. The paper concludes that privacy, or what the authors term "obliviousness," is a necessary condition for fungibility and therefore for money itself.

Core insights

The paper is not a tokenomics study in the traditional sense of emissions, staking, inflation, or treasury design. Instead, it examines the institutional foundations that determine whether a token can function as money. The authors argue that endogenous blockchain tokens derive both security and governance from the same system in which they circulate. This creates a structure where token value and network integrity are mutually dependent. If token value falls sufficiently, what mechanism remains available to secure the ledger? The paper suggests that this dependency makes endogenous tokens fundamentally different from monetary instruments backed by external institutions. A notable contribution is the classification framework based on trust locus and security locus. Under this framework, many proof-of-stake assets occupy the fully endogenous category, while cash-like CBDCs occupy the fully exogenous category. This distinction has direct implications for token demand. Demand for an endogenous token is not solely demand for a medium of exchange or store of value; it is simultaneously demand for the security assumptions of the network itself. The paper therefore treats token valuation and network security as inseparable variables. The discussion of fungibility introduces an alternative lens for evaluating cryptoasset demand. In conventional tokenomics, fungibility is often assumed. Here, the authors argue that fungibility depends on privacy because identifiable holdings create differentiated risk profiles. Large holders may face greater physical, social, or governance risks than smaller holders. If market participants recognize these asymmetries, can two units of the same token truly be considered economically equivalent? The paper implicitly challenges the assumption that ledger-based assets are perfectly fungible merely because they are technically interchangeable. The paper also reframes stablecoins within this framework. Stablecoins may possess exogenous value backing, but they often rely on ledgers secured by endogenous tokens. As a result, stablecoin holders inherit some portion of the underlying network risk. This argument extends beyond price stability and focuses on transaction integrity, censorship resistance, and governance. The authors therefore reject the view that a stablecoin automatically serves as a cash equivalent simply because its price is stable. A substantial portion of the paper analyzes theft incentives and information visibility. The authors adapt economic models of theft to public ledger environments and argue that complete visibility of balances changes the incentive structure facing attackers. While technical barriers reduce the practical frequency of attacks, the theoretical conditions remain closer to credit systems than cash systems. The discussion of MEV further illustrates how publicly observable transaction information can be monetized by other actors. These examples are used to support the broader claim that information exposure creates economic behaviors inconsistent with the authors' definition of money. The conclusion is that endogenous blockchain economies lack a native cash-like primitive. The authors argue that privacy is not merely a desirable feature but a prerequisite for fungibility, and fungibility is a prerequisite for money. Even if a confidential asset were introduced, reliance on a shared ledger and its endogenous security model could still create a common point of failure. Under this framework, the key challenge for future token systems is not only maintaining value stability but also separating transactional privacy and monetary function from the governance and security dependencies of the underlying network.