## CENTRAL BANKERS’ NEW CYBERSECURITY CHALLENGE

## Source details

**Canonical URL:** [CENTRAL BANKERS’ NEW CYBERSECURITY CHALLENGE](https://www.imf.org/-/media/files/publications/fandd/article/2022/september/fanti.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/fandd/article/2022/september/fanti.pdf.md)
- [Structured JSON version](/-/media/files/publications/fandd/article/2022/september/fanti.pdf.json)

---

### Scope of CBDC adoption and concern
- 105 countries and currency unions are currently exploring the possibility of launching a CBDC.
- That’s up from an estimated 35 as recently as 2020.
- 19 Group of Twenty (G20) countries are considering issuing CBDCs, and the majority have already progressed beyond the research stage.
- Federal Reserve Chair Jerome Powell listed “cyber risk” as his number one worry relating to financial stability.
- A recent UK House of Lords report described cybersecurity and privacy risks as potential reasons not to develop a CBDC.

### Main cybersecurity and privacy risks identified
- Centralized data collection
  - Many proposed CBDC designs (particularly retail CBDCs) involve centralized collection of transaction data, posing privacy and security risks.
  - Centralized accumulation increases the payoff for intruders and enables potential surveillance of citizens’ payment activity.
- Third-party validator risk with distributed ledgers
  - Distributed ledger–based retail CBDCs (example: Nigeria’s eNaira, launched in October 2021) require third parties as validators.
  - Security guarantees depend on the integrity and availability of third-party validators, over which the central bank may not have direct control.
- Amplification of existing threats
  - If implemented without proper security protocols, a CBDC could substantially amplify the scope and scale of security and privacy threats already present in today’s financial system.
- Regulatory transparency vs. privacy trade-offs
  - Privacy-preserving designs may reduce transparency needed for regulators to detect money laundering, terrorism financing, and other illicit activities.

### Cryptographic and architectural mitigations
- Reduce or avoid centralized data collection
  - Mitigation options include not collecting transaction data or choosing validation architectures where each component sees only the amount of information needed for functionality.
- Use of cryptographic tools
  - Zero-knowledge proofs authenticate private information without revealing it.
  - Cryptographic hashing techniques can limit data exposure.
  - Examples: Project Hamilton (Boston Federal Reserve and MIT) separates transaction validation into phases, with each phase requiring access to different parts of transaction data.
  - Techniques can verify transaction validity with only encrypted access to sender, receiver, or amount; such tools have been tested in privacy-preserving cryptocurrencies such as Zcash.
- Threshold-based privacy designs
  - CBDCs can be designed to provide cash-like privacy up to a specific threshold (for example, $10,000) while allowing government authorities sufficient regulatory oversight.
  - The $10,000 threshold mirrors existing U.S. practice that allows reduced reporting for transactions under $10,000.

### Policy and regulatory recommendations
- Choose design based on country needs and policy priorities
  - Governments have many CBDC design options with different trade-offs in performance, security, and privacy.
  - CBDCs are not inherently more or less secure than existing systems; design choices determine risks.
- Regulatory mitigation for distributed-ledger designs
  - Potential mitigations include auditing requirements and stringent breach disclosure requirements for third-party validators.
  - There is currently no clear blueprint for devising these regulations for time-sensitive, closely interconnected distributed-ledger systems.
- International coordination and standard-setting
  - Fragmented international efforts risk interoperability challenges and cross-border cybersecurity risks.
  - The Federal Reserve, as issuer of a major world reserve currency, should help lead development of global CBDC regulations in standard-setting bodies.
  - International financial forums, including the Bank for International Settlements, IMF, and G20, have critical roles to play.
- Avoid premature abandonment
  - Some central banks have prematurely decided a CBDC poses too many cybersecurity and privacy risks.
  - Policymakers and technologists should develop and test solutions rather than preemptively deciding risks are too high.

### Key evaluative conclusions
- Technology enables central banks to embed cybersecurity and privacy protection in CBDC designs.
- Cryptographic advances make privacy-preserving validation feasible and have precedents in existing cryptocurrency implementations.
- Responsible CBDC design can turn cybersecurity and privacy challenges into opportunities to improve the security of the financial system.
- Greater international standard-setting and knowledge sharing among banks is critical at this moment of rapid development and adoption.

*Source: Article in Finance & Development, September 2022.*

---


_Source: https://www.imf.org/-/media/files/publications/fandd/article/2022/september/fanti.pdf_
