Kinexys and MIT DCI Map the Unresolved Risks of Public Blockchains for Regulated Firms
Key points
- Kinexys by J.P. Morgan and MIT Digital Currency Initiative co-published a 37-page paper on 20 July 2026, the third in a joint series, identifying four primary challenges for regulated financial institutions on public blockchains: front-running, transaction omission or censorship, unsolicited token receipt, and gas fees paid to sanctioned entities.
- The paper's six-layer framework concludes that application and smart contract layer mitigations address symptoms only, while durable fixes require protocol and governance layer changes that financial institutions cannot directly control.
- MEV-Boost was adopted in over 90 percent of recent Ethereum blocks, and in January 2026 a single builder, Titan Builder, constructed 45 percent of MEV-Boost blocks, illustrating concentration risk in transaction ordering infrastructure.
- Private order flow, cited as representing 30 to 40 percent of Ethereum transactions, is identified as a partial mitigation for front-running, alongside EIP-7805 (FOCIL) for guaranteed inclusion and encrypted mempools via threshold decryption or trusted execution environments.
- The paper calls for regulatory safe harbour provisions for institutions that take demonstrable reasonable steps to avoid sanctioned counterparties but are nonetheless exposed by the inherent design of public blockchains, and for front-running of financial transactions to be classified as market manipulation.
Kinexys by J.P. Morgan and the MIT Digital Currency Initiative have jointly published a 37-page paper identifying four structural problems that regulated financial institutions face when operating on public blockchains, with Ethereum L1 as the primary worked example. The four issues are transaction front-running, transaction omission or censorship, receipt of unsolicited tokens, and gas fees flowing to sanctioned entities. The paper is the third in a co-published series, following earlier work on payment token programmability and token standards.
The front-running analysis is the most operationally pointed section. Because unconfirmed transactions sit in a transparent mempool and block proposers are free to reorder by extractable value rather than arrival time, an institution’s administrative actions, such as adding an address to a deny-list, are visible before execution. The paper notes that a profit-maximising block builder would legally sequence the target’s escape transaction ahead of the freeze without the target needing to outbid, simply because profitability-based ordering favours whichever transaction the builder encounters first. A related scenario describes a surge of token holders racing to exit ahead of a global pause driving gas fees high enough to delay the pause transaction itself; a proposed mitigation is a “dead man’s switch” design where a contract lapses into a paused state unless the issuer submits periodic heartbeat transactions, though this requires the institution to remain continuously online.
The paper organises potential responses across a six-layer framework spanning application, smart contract, token standard, blockchain network, network governance, and regulation. Its central finding is that the mitigations most accessible to financial institutions sit at the application and smart contract layers, where they address symptoms rather than causes; durable fixes require changes at the protocol and governance layers, where institutions hold little direct influence. Specific mechanisms surveyed include private order flow, which the paper states accounts for 30 to 40 percent of Ethereum transactions, EIP-7805 (Fork-choice enforced Inclusion Lists) for guaranteed transaction inclusion, EIP-7732 (enshrined Proposer-Builder Separation), and encrypted mempools via threshold decryption or trusted execution environments. The paper also notes that MEV-Boost was adopted in above 90 percent of recent blocks, and that in January 2026, 45 percent of MEV-Boost blocks were built by a single entity, Titan Builder.
On Layer 2 networks, the paper argues that a known, centralised operator gives institutions a recognisable counterparty for legal and commercial arrangements, though it flags that reliance on L1 for settlement reintroduces the same underlying risks. The regulatory section calls for front-running of financial transactions on public blockchains to be treated as market manipulation under existing or new legal frameworks, for clarity on institutional obligations when unsolicited tokens arrive, referencing the Tornado Cash sanctions and subsequent dusting of unrelated addresses, and for safe harbour provisions for firms that take demonstrable reasonable steps but are nonetheless exposed by public blockchain design. The paper closes by stating meaningful progress requires coordinated action across financial institutions, protocol developers, and regulators.
More on the wire
- Eight more banks join China's e-CNY network as 2026 roster triples
- HSBC and Standard Chartered complete first live tokenised deposit transfer over Swift blockchain
- Citi Plans Bitcoin Custody Service for Institutional Clients Later This Year
- Citi Plans Crypto Custody Launch This Year, Starting With Bitcoin