Digital ruble launched | Bank of Russia

xxx

Major banks and retail companies will make their infrastructure available for processing digital rubles on 1 September 2026.

Starting from this date, individuals will be able to use the new form of the national currency, if they wish. To do so, they will need to open an account on the Bank of Russia’s platform. This can be done in the Digital Ruble section that will appear in the mobile applications of banks connected to the platform. An individual or a company may have only one account while individual entrepreneurs are permitted to have two accounts for personal use and for business purposes.

Individuals will be able to top up digital ruble accounts from their bank accounts by up to ₽300,000 per month. Businesses will have no top-up limit. Both individuals and businesses will be able to use all funds in their digital wallets without any restrictions. Available operations will include customer-to-customer and business-to-business transfers, as well as transfers to/from government, purchases, and refunds.

Additionally, certain banks wish to provide digital ruble services now, though they are not legally obliged to make their infrastructure available this autumn. The regulator has given them this opportunity.

For individuals, all payments and transfers in digital rubles will be free of charge. Businesses will be granted a grace period until the end of 2026, when no fees will be charged for payments and transfers. From 2027, individual entrepreneurs and businesses will have to pay fees that will be the lowest in the payment market.

From: Digital ruble launched | Bank of Russia.

xxx

POST Stable Connections

The lovely people at Currency Research invited me to host a roundtable at the Central Bank Payments Conference (CPBC) in Istanbul. The rountable was about quantum computing or, more precisely, about quantum readiness: that is, how does a financial institution go about preparing for “Y2Q”, which is the time at which a quantum computer becomes capable of breaking the asymmetric cryptogtaphy used by banks, governments and others to protect data around the world. A working quantum computer capable of making off with everyone’s money (and worse) may not be that far off. Banks and others are already planning for Y2Q and working out how and when to migrate to post-quantum cryptography (PQC).

Google think we are getting ever nearer to Y2Q. Given the progress they see in quantum computing hardware development, quantum error correction and quantum factoring resource estimates, they have adjusted their quantum era timeline to 2029 and are taking action. They are prioritising PQC migration for authentication services and recommend that others do the same. Android 17 is integrating PQC digital signature protection using ML-DSA in alignment with the National Institute of Standards and Technology (NIST), building on Google Chrome support for PQC.

Whether working quantum computers capable of breaking today’s security are a few years away or a few decade away, they will undoubtedly be here one day so prudcent organisations are building their defences. Bruce Schneier, a leading expert in computer security (and someone who I always listen to on such matters) says that now is probably the right time to worry about, and defend against, attackers who are storing encrypted messages in hopes of breaking them later on future quantum computers.

(Your enemy could harvest your data and then tuck it away safely until a quantum computer comes out a decade from now, when they can then get access to your data.)

Unlike Y2K, where we knew exactly when we might get into trouble and could take (as it turned out, very successful) action to mitigate any problems, we do not know when we will reach Y2Q. But that’s no excuse for lack of preparation, and at the roundtable we discussed the first step, the quantum audit needed to findout which systems needs updating and prioritising the roll-out of PQC.

Quantum audits to one side, I must say it was an enjoybable and informative event. I found the discussions around tokenisation and stablecoins particularly useful in the context of other work right now. It was also an opportunity to catch up with old friends, one of them being Kosta Peric from the Gates Foundation. Kota took part in a fireside on inclusion that I found especially interesting.

As the picture shows, when the audience were asked what might make the biggest difference to cross-border payments in Africa, the overwhelming sentiment was in favour of interconnecting instant payment systems rather than, for example, using stablecoins or central bank digital currencies. This caught my eye because my Fime colleague Arnaud Crouzet and I have just published a paper on “Cross-border payments as a key opportunity for dometic schemes” in the Journal of Payment Strategy and Systems (Vol. 20, No. 3, Fall 2026) in which we use Africa as one of the case studies to illustrate the benefits of precisely this approach. We looked at the issues around the interconnection of domestic schems and concluded that:

  • Interconnecting domestic payment schemes is no longer a purely theoretical idea. In several regions, it is already taking shape.
  • It offers a realistic and practical path toward cross-border payments that are cheaper, faster and more transparent by leveraging assets that already exist.
  • For domestic schemes, the opportunity is to move beyond a purely national utility role and become a meaningful participant in regional cross-border networks.

For central banks, regulators and schemes who are looking to exploit the possibilites here, all I will say is that I am sure that Fime’s expertise and experience can support management decisiom-making very effectively!

AI for Retail Card, leaders can’t fully leverage their data advantage

The always interesting Andrew Dresner writes about a colleague using an AI-enabled App to recommend which payment card to use for each specific purchase based on rewards and notes that “this kind of AI optimization ruins spend economics if widely adopted”. Indeed it does, so in a way I wasn’t surprise by his comment about a couple of big issuers (eg, Chase) blocking the app. But in a world of open banking, AI-turbocharged switching and competition for spend data, how long can even the biggest issuers hold out? Given the fact that premium cards with rewards may not be good value for money for many consumers, where is the sector headed?

You might be able to persuade me that I’ll look cool taking out a metal card (which, of course, I never actually do because I use my phone and the expensively-engineered metal card is at home in a draw) but how will you persuade my AI agent to spend $1,000 on a premium card that only delivers $300 worth of value over the year? I’m pretty sure that any half-decent agent would stop me from using my British Airways card right away given that Avios are next to worthless these days.

By the way, if you think I’m being a bit hard on Avios, I have twice this week tried to use Avios for flights to the US later this only to see no seats or upgradde available. There seem to be plenty of Avios seats for Dusseldorf next week though. I’m not joking. See the screenshots.)

153M driver’s licenses for sale after alleged leak from IDScan | Cybernews

xxx

A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan.net. This platform specializes in in-person identity (ID) verification and serves businesses such as Hertz, FedEx, Target, marijuana dispensaries, and many more.

From: 153M driver’s licenses for sale after alleged leak from IDScan | Cybernews.

xxx

Liminal 

The breach illustrates why identity documents are a higher-value and more permanent target than credentials like passwords, and how age-verification mandates are expanding the pool of exposed data.
A driver’s license is far more useful to an identity thief than a password, because a password can be reset while a face, date of birth, address, and license number cannot easily be replaced, especially when paired with high-resolution images of a government ID. The presence of front-and-back images plus infrared and ultraviolet scans means the exposed records include the security features used to validate authenticity, which raises the risk that the data could be used to pass identity checks or produce convincing forgeries.
Malwarebytes ties the incident directly to the growth of age verification, noting that requiring users to upload an ID or selfie to a third-party provider turns a simple website visit into a decision to share an enduring identity document with a company the user may never have heard of. This connects the breach to the wave of age-assurance mandates advancing across U.S. states, the UK, the EU, and Australia, each of which expands the number of organizations, contractors, and cloud platforms holding copies of government IDs.
The incident fits a broader pattern of identity data concentrating in verification vendors that become single points of failure. Facial images and ID copies can be reused to make scams more convincing, pass weak checks, or assemble victim profiles by combining records from separate breaches. The episode strengthens the case for privacy-preserving age and identity checks, such as zero-knowledge or on-device verification, that confirm an attribute without transmitting or storing the underlying document, an approach that vendors and regulators have increasingly promoted.

These Banks Are Banding Together to Launch a Stablecoin – WSJ

xxx

Bank of America, Citigroup and Goldman Sachs are among a group of nearly two dozen firms teaming up to jump into the world of stablecoins, or digital tokens that can be used for cross-border transactions. On Tuesday, the consortium said it would move to launch the stablecoin venture in the first half of 2027.

JPMorgan Chase has separately evaluated whether it could launch its own stablecoin, though those discussions have been preliminary, with no active product underway.

From: These Banks Are Banding Together to Launch a Stablecoin – WSJ.

xxx

Stablecoin Payment Statistics 2026: Volume, Adoption, and the Real-Payment Gap – Axis Intelligence

xxx

Only $390 billion of the $35 trillion that moved across stablecoin networks in 2025 was a genuine economic payment. The rest was trading, internal shuffling, and automated contract loops. That 1.11% figure — which Axis Intelligence Research calls the Real-Payment Penetration Rate (RPPR) — is the single most important number in this entire dataset: it tells you both how small the real market is today and how large the runway ahead actually is

From: Stablecoin Payment Statistics 2026: Volume, Adoption, and the Real-Payment Gap – Axis Intelligence.

xxx

how can we stop rogue AIs from using Anthropic’s MHS to control devices, including humanoid robots? What security model does MHS use?

Just as agentic commerce needs some kind of security gate between transaction enbaling and transactions, so agentic action needs a similar deterministic, non-AI policeman sitting between the MHS gateway and teh real world devices.

The policeman should, as you might expect:

Reject commands outside certified position, speed, acceleration, force and workspace envelopes.

Check complete trajectories, not merely individual commands.

Prevent disabling sensors, interlocks, watchdogs or emergency stops.

Remain safe if the AI, MHS driver, operating system or network is compromised.

Be incapable of receiving software-policy changes from the controlling AI.

Simple, right?

Quantum Computers Will Never Break RSA, Says Oxford Physicist. But I Say Migrate Anyway

xxx

Migration cost is bounded and knowable. The cost of the others is unbounded and, thanks to harvest-now-decrypt-later, partly already incurred ie data intercepted this morning with a twenty-year confidentiality requirement has to survive every future in which a capable machine exists.

From: Quantum Computers Will Never Break RSA, Says Oxford Physicist. But I Say Migrate Anyway.

xxx

Design a site like this with WordPress.com
Get started