🔥BTC/USDT

APAC group develops standards for permissionless blockchains

A coalition of blockchain risk specialists, industry associations and legal advisers has launched an Asia-Pacific working group to create governance and risk-management standards for public blockchain networks, targeting a gap that has complicated banks’ use of permissionless systems such as Ethereum.

The initiative, called “Project Pigeon: A Working Group for Permissionless Blockchain Governance in APAC,” is led by blockchain analytics firm Elliptic, the Digital Asset Association, the Responsible Fintech Institute, and law firm Baker McKenzie Wong & Leow. The group plans to publish an industry guide in the first quarter of 2027 and a separate briefing paper for regulators across the region.

Its work is designed to help financial institutions assess whether crypto assets operating on public networks can meet the conditions associated with “Group 1” prudential treatment. That classification generally depends on assets satisfying stringent requirements intended to distinguish lower-risk exposures from crypto holdings subject to more conservative capital treatment.

Project Pigeon follows the Monetary Authority of Singapore’s April 2026 consultation on the prudential treatment of crypto assets on permissionless blockchains. The consultation placed public blockchain governance, technological resilience, transaction finality and financial-crime controls near the center of the debate over how regulated institutions could use open networks.

The new group is attempting to translate those broad concerns into practical control frameworks that banks, supervisors and crypto service providers could apply consistently. Its output would not itself create a regulatory safe harbor or change capital requirements, but could give institutions a more detailed basis for documenting how they evaluate blockchain-related risks.

Four workstreams target public-chain risks

Project Pigeon has divided its work into four risk pillars: governance risk, technology risk, settlement finality risk, and anti-money laundering and counter-terrorist financing risk.

The Responsible Fintech Institute is leading the governance workstream, which will examine node concentration, transparency in protocol decision-making and accountability within decentralized systems. These questions go beyond whether a blockchain is marketed as decentralized. A network with a small number of entities able to influence validation, software upgrades or governance votes may present different operational and control risks from one with broader independent participation.

The Digital Asset Association will lead the technology-risk workstream. Its remit includes potential 51% attacks, in which an entity gains sufficient control of a blockchain’s validating power to interfere with transactions; protocol vulnerabilities; smart-contract exploits; and risks affecting the surrounding technical infrastructure.

Those issues are particularly relevant for financial institutions that may interact with public networks through wallets, custody arrangements, tokenized products or settlement systems. A bank’s risk assessment cannot rely solely on the market value or legal structure of a token if the underlying network can be disrupted, manipulated or exposed to a critical software failure.

Baker McKenzie Wong & Leow is overseeing settlement finality risk. The work will consider consensus mechanisms, the difference between probabilistic and deterministic finality, and the legal certainty of settlement.

Probabilistic finality means a transaction becomes increasingly difficult to reverse as more blocks are added after it, rather than becoming legally and technically irreversible at a single fixed moment. Deterministic finality provides a clearer point at which a transaction is final under the network’s rules. The distinction has direct consequences for institutions handling large-value transfers, collateral movements or transactions that need to align with established payment and securities-settlement processes.

Elliptic will lead the AML/CFT pillar, covering pseudonymous transactions, sanctions screening, blockchain analytics, Travel Rule compliance and the connection between financial-crime exposure and prudential risk. Public blockchains offer transparent transaction records, yet identifying the people or entities controlling an address often requires additional analytics, customer information and investigative processes. The group’s approach places these compliance controls alongside technology and governance tests rather than treating them as a separate operational concern.

A structured attempt to meet prudential expectations

The four-part model reflects a regulatory reality facing banks in APAC: access to a public blockchain does not automatically establish that the network meets institutional risk standards. Permissionless networks can allow anyone to participate in validation, transfer tokens or deploy applications, characteristics that can support open access but also create difficult questions around control, accountability and compliance.

Project Pigeon’s proposed industry guide, “Pigeon Permissionless Blockchains,” is expected to set out an end-to-end risk-management lifecycle. According to the consortium, the guide will include a risk taxonomy, catalogues of risk events, preventive and detective controls, governance mechanisms, methods for testing controls, and procedures for issue management and reporting.

That design suggests the group is focused on ongoing oversight rather than a one-time blockchain approval process. A network’s technical or governance profile can change through software upgrades, validator shifts, new applications, security incidents or changes in how intermediaries provide access. Institutions would need mechanisms to identify those changes and determine whether their risk assumptions remain valid.

The guide could also reduce fragmentation in how banks and crypto-native firms describe permissionless-network risk to supervisors. Without common language and testable controls, each institution may build its own framework for evaluating validator concentration, finality, smart-contract exposure or sanctions controls. That can make regulatory engagement slower and leave similar risks subject to sharply different interpretations.

Regulators will be included in the process

The consortium said the working group includes banks, crypto-native companies and legacy financial institutions active across APAC. It has also established observer and consulting roles for regulatory bodies, allowing supervisors to follow the work as it develops.

Baker McKenzie will act as the group’s secretariat. Its responsibilities include editorial oversight, support for regulator engagement and management of the governance process.

The group plans to hold plenary sessions every two weeks, alongside separate meetings for each of the four workstream sub-groups. A steering committee made up of the four co-convenors will conduct monthly reviews, while quarterly checkpoints are planned for regulatory engagement.

The timetable gives the project several months to develop technical standards before the planned Q1 2027 publication. Its usefulness will depend on whether the eventual framework produces specific, auditable controls rather than high-level principles that institutions already recognize. For banks considering public-blockchain activity, questions around who governs a network, how transactions become final, how code risks are controlled and how illicit activity is monitored are likely to determine whether permissionless infrastructure can fit within existing prudential systems.


For deeper context on regulation and institutional adoption in Asia, explore our insight on why stablecoins matter in Asia.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up