PARAMETA

Why Wallet Allow Lists Only Block Half the Problem

2026.09.16Insight
Blog — ArticleScroll

A November 2025 report from the Bank for International Settlements (BIS) contains a striking figure.

Bank for International Settlements headquarters building in Basel, Switzerland

Assets held in tokenized money market funds grew from roughly USD 770 million at the end of 2023 to about USD 9 billion by the end of October 2025 — more than tenfold in under two years.

Line chart of total assets held in tokenized money market funds, 2023 to 2025

Money market funds themselves are nothing new. They're a decades-old product that parks money briefly in short-maturity assets like short-term government bonds or repurchase agreements. A tokenized money market fund simply represents that fund's shares as tokens on a blockchain. The product hasn't changed — how you carry the shares has.

This piece looks at how that actually works, and where BIS says the gap is. It isn't about any specific fund or investment decision.

This Fund Can't Be Sent to Just Any Wallet

An ordinary token can go to anyone once you know the address. A tokenized money market fund can't work that way. Legally, it's a security, so the recipient has to be a verified party.

So these tokens use an allow list. The fund vets investors, adds their wallet addresses to a list, and lets the token move only within that list.

Recent token standards such as ERC-3643 build this check straight into the code. isVerified confirms the receiving wallet is on the list, and canTransfer checks whatever other conditions apply. If either fails, the transfer simply doesn't execute. Nobody filters it out after the fact — the transaction itself can't go through.

On the face of it, that looks pretty solid.

BIS Says the List Only Blocks 'Direct' Holding

The report's most striking point is this: an allow list only restricts direct holding of the token.

Someone who isn't on the list can still reach the fund through other routes. The report names three.

One is wrapping it in another token. If shares of a tokenized money market fund become part of a stablecoin's reserve assets, then anyone holding that stablecoin is tied to the fund's performance regardless of whether they're on the allow list.

Second is a fund of funds. OUSG, the example the report cites, invests only in other tokenized money market funds. The issuer can put out its own branded token and reset fees or minimum investment amounts to suit its own investors.

Third is platforms. Some let users they've onboarded trade the token among themselves, which widens access to wallets the fund never put on its own list.

In other words, the door is locked — it's just that only that one door is locked.

Four Wallets Hold 90% of the Fund

The same report gets more specific. For BUIDL, currently the largest tokenized money market fund, and for WTGXX, another large fund, the top four wallet addresses hold about 90% of all outstanding shares.

Bar chart showing the top four wallet addresses' share of total fund holdings

That's less a red flag than a picture of who this market currently serves. The report identifies the main investors as companies that run decentralized finance protocols. They buy the fund not to save, but for collateral — they needed a yield-bearing asset they could post when borrowing stablecoins.

So trading is thin. A small number of holders sit on it for a long time. The report flags this as a liquidity weakness.

BIS's Proposed Fix: Stop Building a Separate List for Every Fund

The report also lists the practical problems with the allow list approach itself. Every fund maintaining its own list duplicates the same work, it doesn't scale well as investor counts grow, and because tokens can't leave the list, the design is awkward for uses that need to move fast, such as posting collateral for a margin call. It also flags how this splits the blockchain into zones that are controlled and zones that aren't.

The phrase the report reaches for is "a trusted wallet ID scheme shared across funds." It adds the caveat that this would need to be backed by anti-money-laundering checks and ongoing compliance monitoring.

Instead of duplicating a list for every fund, verify identity properly once and reuse the result wherever it's needed. This is exactly the problem PARAMETA is working on with DID/MyID and on-chain KYC. Selective disclosure passes along only the fact that "this wallet passed screening," not who the person is. Verification history stays in an audit log so it can be traced back later.

That said, BIS doesn't point to a specific approach. The report goes only as far as saying an alternative "may be needed."

To Be Honest, This Story Isn't Over

Even the shared-ID direction leaves questions unanswered.

Who would run it? Consolidating lists that were once scattered across funds into one place is convenient, but it also raises the stakes if that one place goes down. Cross-border, whose standard applies hasn't been settled either. The report itself leaves this as a problem that needs international coordination.

And the allow list is just one of the risks BIS raises. The more fundamental one is a liquidity mismatch: the token promises daily redemption, but the underlying assets can't be sold that fast. There are separate technology risks too, like smart contract vulnerabilities or service outages.

Still, the allow list finding stands out because public blockchain data confirmed that what everyone assumed was blocked by technology was, in fact, only half-blocked. Putting a control into code doesn't mean the control is complete.

Whether a token can be issued is a question that's already been answered. The next one seems to be this: when that token moves beyond the list, will we even know it happened?


Back to list