BIS lays out steps for ‘secure and resilient’ CBDC systems

BIS says a cyber attack on “critical infrastructure” could threaten potential CBDC framework

article-image

Proxima Studio/Shutterstock modified by Blockworks

share

Research into safe and sustainable CBDC systems has continued apace, with the Bank of International Settlements on Friday outlining the agency’s latest steps to provide a “security and resilience framework” for them.

The idea behind the Bank of International Settlements’ paper, published on Friday, was to help banks safeguard against risks when it comes to CBDC implementation. 

The paper, dubbed Project Polaris, is designed to get ahead of CBDC launches and protect “critical infrastructure.”

While some central banks — such as Kenya — have said the once-promising allure of CBDCs has faded, other financial institutions, like the IMF, are receptive to possible adaptation.

While central banks largely have cyber security measures in place, the introduction and rollout of CBDCs could lead to new risks. While over 100 countries — including the UK and US — are currently exploring a potential CBDC, few have moved beyond small-stage, pilot projects and into actual implementation. 

“CBDC systems will need to remain highly resilient in a broad range of scenarios, including short-term (such as temporary system outages), ongoing situations (such as in areas without reliable internet, telecommunications connectivity or power), or civil contingency conditions (such as natural disasters or war), 9 besides being highly responsive in normal operations,” the BIS wrote.

Successful and safe implementation requires modernized technology to not only support a CBDC, but also to protect it, the agency found — echoed by other central banks.

Among the suggestions, Project Polaris pushed for central banks to hire a chief security officer (CSO). 

The CSO would then be able to have “regular” communication with counterparts across the globe, since CBDCs will require an international framework. There would also be an “incident response team” who could respond to a variety of potential scenarios.

It also urges central banks to consider other operators needed in a CBDC ecosystem, from commercial banks to merchant partners. This would lead up to the fulfillment of a resilience requirement — similar to a stress test — depending on the CBDCs “weakest link.”

Overall, frequent check-ups and assurances of secure technology are said to be key for any CBDC if central banks decide to deploy them.

“The framework could also help central banks assess their cyber security and resilience maturity level as it stands today as compared with what could be required when operating a CBDC system, by assessing and ranking how the organization adheres to the practices outlined in this framework,” the BIS wrote.

Project Polaris is not the first foray into CBDC research that the BIS has conducted. It put out another report in late June focused on how commercial banks could tokenize customer deposits.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (8).png

Research

Kinetiq has established itself as Hyperliquid's dominant liquid staking protocol, holding 82.5% of LST market share with $610M in TVL. The protocol is now expanding beyond its kHYPE staking core into higher take-rate verticals: iHYPE for institutional custody rails, Launch for HIP-3 capital formation, and Markets for builder-deployed perpetuals. We view Markets, launching Jan. 12, as the highest-potential product line given its mechanically scalable, activity-linked unit economics. Near-term revenue remains anchored by kHYPE's KIP-2 fee schedule (~$1.6M annualized), while Markets provides embedded optionality if HIP-3 economics normalize post-Growth Mode. KNTQ's setup is relatively clean: zero insider unlocks until November 2026, 6.2% buyback yield from staking revenue, and cleared airdrop overhang. Risks center on unproven Markets execution, declining kHYPE TVL despite ongoing incentives, and competition from Hyperliquid's native initiatives.

article-image

BTC finished the week up 1.6%, while L2s, RWAs and the treasury trade continued to grind lower

article-image

DTCC moves DTC-custodied Treasuries onchain via Canton, while Lighter’s LIT launches trading at a fees multiple in Hyperliquid territory

article-image

In the 90s, rapt audiences worldwide watched a coffee pot — will that fascination ever turn to crypto?

article-image

Some systems improve by failing — and crypto has no choice

article-image

Yield Basis introduces an IL-free AMM design that already dominates BTC DEX liquidity

article-image

Maybe tokenholders don’t need the rights that corporate shareholders have come to expect

Newsletter

The Breakdown

Decoding crypto and the markets. Daily, with Byron Gilliam.

Blockworks Research

Unlock crypto's most powerful research platform.

Our research packs a punch and gives you actionable takeaways for each topic.

SubscribeGet in touch

Blockworks Inc.

133 W 19th St., New York, NY 10011

Blockworks Network

NewsPodcastsNewslettersEventsRoundtablesAnalytics