Central Bankers’ New Cybersecurity Challenge
Source details
- Canonical URL
- Central Bankers’ New Cybersecurity Challenge
Other formats
Bibliographic details
- Authors: GIULIA FANTI, OLE MOEHR
- Published: September 1, 2022
Overview
- Topic: cybersecurity and privacy implications of central bank digital currencies (CBDCs).
- Publication: F&D Magazine article by GIULIA FANTI and OLE MOEHR, September 2022.
- Contextual findings:
- "105 countries and currency unions are currently exploring the possibility of launching a CBDC."
- "That’s up from an estimated 35 as recently as 2020."
- "19 Group of Twenty (G20) countries are considering issuing CBDCs, and the majority have already progressed beyond the research stage."
- Example deployed retail CBDC: "Nigeria’s eNaira, launched in October 2021."
- Regulatory threshold example: "cash-like privacy up to a specific threshold (for example, $10,000)."
- Time reference on decision dynamics: "Over the past 18 months some central banks have prematurely decided that a CBDC poses too many cybersecurity and privacy risks."
Main cybersecurity and privacy risks identified
- Centralized data accumulation:
- CBDC designs (particularly retail CBDCs) often involve "the centralized collection of transaction data," increasing privacy and security risks.
- Risks include: surveillance of payment activity, accumulation of sensitive data in one place, use of data to spy on citizens, obtain security-sensitive details, and theft of funds.
- Distributed-ledger risks:
- Distributed ledger–based retail CBDCs may require third-party validators, introducing dependency on "the integrity and availability of third-party validators."
- Central bank control limitations: "the central bank may not have direct control" over third-party validators unless all validators are controlled by the central bank, which "largely defeats the purpose of using the technology."
- Regulatory-transparency trade-offs:
- Privacy-preserving designs can reduce regulator visibility needed to detect money laundering, terrorism financing, and other illicit activities.
- Amplification of existing threats:
- Without proper security protocols, a CBDC "could substantially amplify the scope and scale of many of the security and privacy threats that already exist in today’s financial system."
Mitigation strategies and design options
- Design variety:
- CBDC design variants include "centralized databases," "distributed ledgers," and "token-based systems"—each with different trade-offs for performance, security, and privacy.
- Data minimization and compartmentalization:
- Avoid collecting centralized transaction data where possible or use a "validation architecture in which each component sees only the amount of information needed for functionality."
- Example architecture: Project Hamilton separates "transaction validation into phases, and each phase requires access to different parts of the transaction data."
- Cryptographic techniques:
- Use of zero-knowledge proofs to "authenticate private information without revealing it" and cryptographic hashing techniques.
- Systems can be built that "verify transaction validity with only encrypted access to transaction details like sender, receiver, or amount."
- Precedents: privacy-preserving cryptocurrencies such as Zcash have tested these tools.
- Regulatory and auditing controls for distributed ledgers:
- Mitigation options include "auditing requirements and stringent breach disclosure requirements" for third-party validators.
- Balanced transparency:
- Cryptographic designs can enable "cash-like privacy up to a specific threshold (for example, $10,000) while allowing government authorities to exercise sufficient regulatory oversight."
- The article notes similarity to current U.S. reporting norms: "allows reduced reporting for transactions under $10,000."
Policy recommendations and governance priorities
- Do not preemptively reject CBDCs:
- "CBDCs are not inherently more or less secure than existing systems." Responsible design should be evaluated rather than abandoning CBDC exploration.
- Tailor design to national needs:
- "Governments should choose a design option based on a country’s needs and policy priorities."
- International coordination:
- Warns of "fragmented international efforts" leading to "interoperability challenges and cross-border cybersecurity risks."
- Recommends leadership and standard-setting by major actors: "the Federal Reserve should help lead the charge toward development of global CBDC regulations in standard-setting bodies."
- Calls for roles for international forums: "Bank for International Settlements, IMF, and G20 have a similarly critical role to play."
- Knowledge sharing:
- Emphasizes the need for "more knowledge sharing between banks" and international standard-setting given rapid development and adoption.
Key takeaways
- CBDC adoption is accelerating: "105 countries and currency unions" exploring CBDCs, up from "35" in 2020, including "19 Group of Twenty (G20) countries."
- Cybersecurity and privacy risks are real but addressable with careful design, cryptographic tools, and regulatory frameworks.
- Trade-offs exist across designs (centralized vs distributed vs token-based); no design is universally superior—choices depend on national priorities.
- International coordination, standard-setting, and oversight frameworks are essential to manage interoperability and cross-border cyber risks.
GIULIA FANTI and OLE MOEHR, F&D Magazine, September 2022.
Content in this bundle
- Central Bankers' New Cybersecurity Challenge