Tuesday, August 4, 2026

The Zombie and the Fire Extinguisher

What I found when I set out to understand the digital euro

So I set out to understand what exactly the digital euro is.

It started with a single claim that I refused to believe. The European Central Bank says the digital euro will work offline. No signal, no servers, no bank in the loop: money passing from one phone to another in a dead zone, the way a banknote passes between hands.

My first reaction was: that has to be false. Or at least carefully misleading. Because I know what digital money is. It's an entry in someone's ledger. Every payment is a request to a server, every balance a row in a database, every transaction a conversation with a machine that keeps score. Take away the network and you should, by all rights, take away the money.

So I started pulling on that thread. And I want to tell you what happened, because it did not go the way I expected. Every answer I got was honest. And almost every honest answer opened a worse question. By the end, I wasn't asking whether the offline claim was true anymore. I was asking which of two objects Europe is actually building. Both are maintained at public expense and used by almost nobody. One is a fire extinguisher. The other is a zombie.

And the conclusion I eventually reached is not that Europe shouldn't build it. It's something more specific, and harder to dismiss.

Here's the journey.


The claim I didn't believe

Digital cash has one canonical problem, and it's the problem of the copy. A file can be duplicated. A balance, if nothing stops you, can be spent twice. The entire architecture of online payments (the ledgers, the clearing houses, the blockchains) exists to solve this one embarrassment: making sure that when money leaves you, it is actually gone.

Remove the network, and you appear to remove the referee.

The answer, it turns out, is that the digital euro moves the referee from the server into the silicon. The value lives as cryptographically signed tokens inside a secure element, the same class of tamper-resistant chip that already runs tap-to-pay and sits inside every SIM card. You load the wallet during an online session, or at an ATM. After that, value moves phone-to-phone over NFC with no network involved at all. The chip itself enforces the rules: it won't sign away a balance it doesn't hold, it won't release the same token twice, and the tokens can't be forged without keys buried in hardware engineered to destroy itself under probing. The transaction leaves no record with any bank or any central bank. Only the changed balance becomes visible later, when the device reconnects.

So, fine. Not false. Not even misleading, really. Point conceded.

But while I was reading about it, something nagged at me. This felt familiar. And then it clicked: I'd seen this before. In the nineties, Europe built exactly this, several times over. Mondex in Britain. The GeldKarte in Germany. The Chipknip in the Netherlands. And in Portugal, the Porta-Moedas Multibanco, a chip you loaded with value at the ATM and spent offline at terminals. A bearer instrument in plastic. Lose the card, lose the money, exactly like a wallet of notes.

The technology I'd just refused to believe in wasn't an invention. It was a revival.

And every single product on that list is dead.

That was the first worse question. But before I got to the graveyard, I had a more obvious objection to get out of the way.


Why not just extend IBAN?

Because here's the thing: if the goal is modern European payments, we already have an addressing system that works everywhere. It's called the IBAN. Make transfers instant, make them free, put a decent app on top, done. Why build a whole new form of money?

And when I dug into this, I found something almost funny: for online payments, that is exactly the right answer, and Europe is already doing it. Instant euro transfers over the existing SEPA rails are now mandated by regulation across the euro area. Wero, the wallet built by a coalition of European banks, is putting person-to-person and merchant payments directly on top of those rails. And the banking industry's loudest criticism of the digital euro is the same as mine: the online version duplicates infrastructure that already exists, paid for by the same institutions being ordered to build the duplicate.

So why does the digital euro exist at all? Because there are three things no extension of an account number can ever provide. Not because the rails are bad, but because these aren't features of the rails. They're features of what the money is.

First: who owes you. Money in a bank account is a promise from a commercial bank. Good money, insured, regulated, but a liability of a private company all the same. A digital euro would be a claim on the central bank itself, the digital sibling of the banknote. No redesign of the addressing scheme changes who owes you the money. Only the issuer does.

Second: offline. An account is a row on a server. Every account payment, by definition, has to reach that server. Account systems cannot work offline even in principle. If you want offline, you're forced into tokens in hardware, the thing from the previous section.

Third: privacy. Every hop through an account is visible to the institution hosting the account, because in a ledger system the record is the payment. The offline token changes hands with nobody watching.

So the honest scorecard: where accounts suffice, Europe is extending accounts. The digital euro exists for the three things accounts structurally can't do.

But look at what that means. I stepped back and considered the shape of the whole project, and it fights on two fronts. The first front is online, where it marches into territory that's already occupied. Redundant. The second front is offline, where it revives a product category with an unbroken, decades-long record of failure. Every electronic purse Europe ever launched is in the ground.

And here's the strange part. Each front is defended by pointing at the other one. Challenge the online leg as redundant, and the answer is: but the offline leg is unique, nothing else can do it. Challenge the offline leg as a proven failure, and the answer is: but this time it ships inside a modern online system with legal backing and universal reach. The project justifies itself in the crossfire between its own two halves.

That's not automatically wrong. Combined systems sometimes succeed where their parts failed separately. But it sharpened my attention considerably. A plan whose every part is excused by a different part deserves a proper walk through the graveyard.

So I took one.


The graveyard

The cleanest specimen is the Portuguese one, the Porta-Moedas Multibanco, because it did everything right and died anyway. It launched in the early nineties on the back of Multibanco, at the time one of the most advanced ATM networks in the world. You loaded value from your bank account onto the chip, you spent it offline at terminals across the country. The chips worked. The cryptography held. Fraud did not kill it.

Irrelevance did. Multibanco's online debit network was so good, so fast, so universally accepted, that nobody could be bothered to preload a purse. Why fill a chip with money in advance when the card connected to your account works instantly, everywhere, every time? By the mid-2000s the purse was gone. The Dutch Chipknip followed in 2015. The German GeldKarte faded for years before being formally switched off. Mondex never escaped its pilots.



Read that epitaph carefully, because it turned out to be the most important sentence of my whole investigation: the electronic purses were not killed by their weaknesses. They were killed by the strength of the online alternative. The redundancy killed the resilience.

Which is exactly the collision the digital euro is choosing to rebuild. Deliberately. At continental scale.

The modern graveyard didn't cheer me up either. Nigeria launched the eNaira into near-total public indifference; adoption is a rounding error. The Bahamian Sand Dollar circulates in amounts that would embarrass a mid-sized credit union. Both are, officially, thriving. Meanwhile, the central banks that could still walk away quietly did: Denmark declined early, Sweden let its e-krona pilot lapse without ever deciding to launch, Canada shelved its retail project in 2024. I noticed a pattern in that list and filed it away: before launch, central banks can retreat. After launch, they never do. That pattern comes back later, and when it does, it's ugly.

And the winners? The public payment systems that actually conquered their markets, Brazil's Pix and India's UPI, are, architecturally, my proposal. Online, account-based, instant, nearly free. Extended IBAN, in spirit.

At this point I was feeling fairly smug. The scoreboard agreed with me. Then I started asking about risk, and the smugness began to leak.


But isn't offline a huge risk?

This was my next objection, and I expected it to be the knockout. If value lives in chips and moves with no server watching, then the nightmare writes itself: someone fully compromises a secure element and starts minting money. Because offline transactions touch nothing central, the counterfeit circulates invisibly, phone to phone, until it tries to cross back into the online world - the funding and defunding boundary, where forgery and double-spending checks finally run. And this isn't ordinary payment fraud, which steals from a bank or a cardholder. Counterfeit central-bank money attacks something categorically worse: trust in the currency itself.

What I found is that the designers agree (offline is openly the riskiest component of the whole project) and that the risk is managed rather than eliminated. The blast radius is capped by architecture. Every chip carries its own diversified keys, so cracking one device compromises one wallet; there is no master key anywhere that mints unlimited euros. Per-wallet exposure is bounded by holding limits. Forged tokens die at the online boundary the moment they fail verification. So the attack economics read: defeat certified tamper-resistant hardware, one device at a time, for a small and bounded payoff. Not an attractive business.

Not an impossible one, either. The history of "tamper-resistant" is a history of eventual embarrassment. The Mifare Classic transit chip was famously broken, and pay-TV smartcards fell one after another. Hardware trust erodes. It always has.

But then I ran into the question that cracked my skepticism for the first time: risky compared to what? The fair benchmark isn't perfection. It's cash, which is counterfeited, stolen, and laundered every single day, and which society tolerates gladly because it buys two things nothing else provides: privacy, and resilience.

And resilience stopped being theoretical on the 28th of April, 2025, when the Iberian Peninsula went dark and card payments died across two countries in the space of seconds. That afternoon, the only payment technology still working was three thousand years old. The Dutch central bank now formally advises every adult to keep roughly seventy euros in cash at home. Nordic civil-defense guidance suggests a week's worth of expenses. When governments start printing brochures telling citizens to stockpile banknotes, the failure mode this thing targets is no longer a slide in a consultant's deck.



So: yes, a huge risk. Deliberately taken, carefully bounded, aimed at a failure mode that has already happened. I moved on to my darker hypothesis.


Resilience, or control?

Because that's where my head went next. Strategic infrastructure, issued by the central bank, sitting on everyone's phone. Is the real product resilience, or control?

The evidence surprised me, at least for the present tense: the offline component is the most control-hostile piece of the entire design. Think it through. If surveillance were the goal, you would build the exact opposite of offline tokens: an online-only, account-based system where every transaction lands on a central ledger by construction. Extended IBAN, my own proposal, is the ideal surveillance architecture; every payment is visible to an intermediary, because visibility is how accounts work. Offline bearer tokens that leave no record anywhere, where only payer and payee ever know a transaction occurred, are the one element that structurally resists observation. The ECB added offline capability largely to answer the control criticism. The draft regulation explicitly prohibits making the digital euro programmable money: no expiry dates, no spending restrictions. And the one feature that genuinely looks coercive, the holding limit, turns out to exist to protect commercial banks, not to discipline citizens. More on that in a moment.

But my suspicion survived in one precise, irreducible form, and I'm not going to cosmetic it away. Cash's privacy is physics. Paper does not remember. The offline euro's privacy is policy plus firmware. A secure element that records nothing today could, after one legislative amendment and one software update, record everything. Capability outlives intent. Institutions change, majorities change, emergencies arrive, and the infrastructure will still be sitting there, one update away from a different personality.




So the answer I landed on: resilience by design, control as latent possibility. The thing deserving permanent vigilance was never the chip. It's the text of the regulation, and how easily some future majority can rewrite it.

There's also a slower version of the control scenario that needs no villain at all, and it worried me more than the deliberate one. Cash's privacy and its exit-value depend on a physical logistics chain (ATMs, armored transport, branches, merchant acceptance) and that chain is decaying on its own, closure by closure. If it withers far enough, the capped digital wallet becomes the only central-bank money ordinary people can hold, and the exit option shrinks without anyone ever having voted to close it. Nobody decides. It just happens. Deliberate plans can be opposed. Drift can't.


The three-thousand-euro paradox

Then I hit the objection that felt like plain common sense. We're telling citizens to choose between unlimited cash under the mattress and a wallet capped at around three thousand euros. As a safeguard, the capped wallet seems designed to lose. Who picks the smaller lifeboat?

The resolution turned my objection inside out: the cap isn't a flaw in the safeguard. The cap is what allows the thing to exist at all.

Because an unlimited digital claim on the central bank would be the perfect safe asset. Safer than any deposit, instantly accessible, zero bank risk. And for that exact reason, it would be the perfect bank-run machine. Cash runs are throttled by physics: ATM limits, branch queues, vault logistics. Those frictions buy the authorities days. A digital run has no physics. Every deposit in the euro area could attempt the jump to central-bank money in a single afternoon, at tap speed, from the beach. The holding limit is the firewall between "useful public money" and "doomsday device for the banking system". It isn't timidity. It's load-bearing.



Which clarified for me what kind of safeguard this was ever supposed to be. Not "store your wealth here". The design deliberately loses that contest, capped and paying no interest. The promise is narrower: keep transacting when the networks fail. And for that job, the cap barely binds. Remember the official guidance: seventy euros per adult in the Netherlands, a week of expenses in the Nordics. Almost nobody pre-positions three thousand euros in banknotes either. In an actual blackout, cash and the offline wallet are both limited to whatever you set aside beforehand. The ATMs are down for everyone.

But I want to be clear about what the wallet can never be, because it's by explicit design: an exit. A hedge against the banking system, against bail-ins, against the state itself. For that, cash remains the only instrument. That's tolerable exactly as long as cash genuinely coexists, which loops straight back to the slow drift I just described. And it explains a detail I found telling: the same legislative package that creates the digital euro also forces merchants to keep accepting cash. Even the ECB, apparently, does not trust its own creation to be the only fallback.


Nobody wants to sell this

Then I looked at who's supposed to hand this thing to the public, and found a structural fact I've never seen in any consumer product: the digital euro will be distributed by institutions that lose when it succeeds.

Count the ways. Every euro that moves into a digital wallet leaves a commercial bank's balance sheet; that's the deposit-flight problem the holding limit only softens. Basic use must be free to citizens, by law. The fees banks can charge merchants are capped, by the same law. The integration bill lands on the banks. The ECB's own development budget runs north of a billion euros, and studies commissioned by the banking industry claim tens of billions across the sector. And the finished product will compete head-on with Wero, the wallet those very same banks are building with their own money.

No rational retailer stocks that product. Which is why, I learned, the model was never retail. The regulation mandates that banks distribute the digital euro, with an interchange-style fee as compensation for their trouble. The correct mental model is not "company launches product". It's "building code requires fire extinguisher". The shopkeeper does not believe in the extinguisher. The shopkeeper installs it because the inspector is coming.

Before I dismissed that as doomed, I remembered how resilience infrastructure has always actually arrived. Nobody demanded chip-and-PIN cards; issuers put them in our wallets. Nobody petitioned for instant SEPA transfers; a regulation forced every bank to offer them, and now they're simply how money moves. Enthusiasm was never the distribution mechanism for plumbing. Mandates and defaults were. And the design leans into it: an automatic top-up from your bank account means the wallet can stay provisioned without you ever thinking about it. Insurance by default, rather than by discipline.

Whether defaults can fully substitute for demand - that's the open question everything else hangs on. But at least the strategy is coherent: if the product's value is systemic, make its presence systemic, and stop waiting for love.


The zombie

And then I arrived at the fear that had been building the whole time, the one that survives every rebuttal above. Suppose it launches and nobody comes. Products die of that. But this isn't a product. It's a project of an institution that cannot run out of money, and that has never once, anywhere on Earth, admitted a launched digital currency failed.

I traced the mechanics, and they're worse than the caricature. My first assumption was crude: the ECB will just print money to keep it alive. The reality is subtler and, for my purposes, worse. The costs come out of Eurosystem income, which means they surface as reduced profit remittances to national treasuries. Think about what that implies. An inflationary cost would provoke outrage. A remittance shortfall is invisible. No finance ministry defends that line item. No parliament votes on the ECB's budget. The European Court of Auditors holds only a narrow mandate over the ECB. And several euro-area central banks are currently posting losses and skipping remittances anyway, so the cost of a walking-dead project vanishes into statistical noise. The one mechanism known to kill failed public IT projects, a budget committee with the power to say enough, structurally does not exist here.

And it gets worse after launch, because launch is preceded by legislation. Once the regulation passes, the digital euro is not an ECB initiative anymore. It's law. Killing it would require the Commission, the Parliament, and the Council to jointly repeal it. Not a quiet decision in Frankfurt. Statutory entrenchment, plus institutional pride, plus no budget constraint. That's the complete recipe for an immortal failure.



Remember the pattern I filed away in the graveyard? Before launch, central banks retreat: Denmark, Sweden, Canada. After launch, never. The eNaira and the Sand Dollar shuffle on at rounding-error adoption, officially in excellent health. And the most instructive corpse of all turned out to be Finland's Avant, the Bank of Finland's own 1990s card money, arguably the world's first central bank digital currency. It died. But look at how. It died only after the central bank sold it to commercial banks, entities with a profit-and-loss statement. Death required transferring the project to someone with a budget constraint. The digital euro is being built in the one institutional location where that transfer can never happen.

So my darkest forecast, a too-big-to-die zombie, isn't paranoia. It's a straight reading of the incentive architecture.

And yet. Right at the bottom of this hole, I found the twist that reorganized everything I'd learned. A zombie and a fire extinguisher are physically identical. Both are maintained infrastructure that almost nobody uses. From the outside, from the transaction statistics, from the annual reports, you cannot tell them apart. The only difference between them is whether the thing works on the day it's finally needed. And the ECB will never voluntarily report that answer, because no institution self-certifies its own failure.

I sat with that for a while: a likely failure, running on money nobody will ever see leave, protected by law, operated by an institution that will never test itself. Somewhere in there, I realized, was my actual conclusion. But before writing it down, I owed the project a fair hearing on the remaining questions, including the one where it might genuinely win.


What's actually in it for me?

After all the system-level argument, I made myself answer the question a normal person asks first: forget Europe, what do I get at the till?

Start by deleting the answer I'd assumed. I will not personally save the Visa fee, because I never personally paid it. The merchant does, and it reaches me only as slightly higher prices. In the EU, interchange fees are already capped by regulation at a fraction of a percent, so the honest per-basket saving is measured in cents. The fuller story is that the card networks' scheme fees have been climbing steeply for years, merchants are furious, and the digital euro's legally capped merchant costs are aimed straight at that. But the beneficiary at the checkout is the shop, and only eventually, diffusely, me.

The real benefits are quieter and different in kind. One payment method with guaranteed acceptance across the entire euro area, where today every national darling dies at the border: MB Way useless in Berlin, Girocard useless in Lisbon. Basic use free by law. Paying any person in the zone without caring which bank or app they use. A payment that survives a blackout. And offline, the only digital payment in existence with cash-grade privacy.

Read that list coldly and the marketing problem diagnoses itself. Every item is systemic, insurance-like, invisible at any individual checkout where my current card already works fine. The digital euro's consumer pitch is the pitch of the smoke detector. And nobody has ever fallen in love with a smoke detector.


So, would I use it?

Honest answer: yes, but in exactly the limited way this whole investigation implies. As insurance, not as a habit.

Concretely: I'd load the offline wallet with a hundred, maybe two hundred euros, and mostly forget about it. The same logic as the Dutch emergency-cash advice, because it's the one scenario where it beats everything else in my pocket, and holding it costs me nothing at amounts where foregone interest is pennies. I'd use the online version opportunistically where it's genuinely better: across a border, paying a person instead of a shop. I would not migrate my daily spending away from things that already work, because the benefit at any single checkout is, as established, nearly invisible. I'd keep physical cash, because the exit-option argument was mine and I meant it. And I'd attach one condition: before loading a cent, I'd read what the final regulation actually says about offline privacy, and how easily it can be amended. Vigilance, applied.

But look at what happens if millions of people do exactly what I just described. The usage statistics will call it a flop. The resilience case will quietly call it mission accomplished. My honest yes is the weak, watchful yes, and it's probably the only kind of yes this project was ever going to get.


Different weather

So that's where the investigation left me: a project that's redundant on one front, reviving a graveyard on the other, sold by unwilling banks, structurally unkillable, and useful to me personally on maybe three days a decade. If the world of 1995, or even 2015, were the world of today, my forecast would be easy: a quiet, expensive failure, preserved indefinitely by the one institution that can't admit it.

But here's where I want to slow down, because it's the part that genuinely moved me a few degrees. Instruments aren't doomed by their ancestry. They're doomed by their circumstances. And the circumstances have changed, in ways that cut, for once, in the digital euro's favor.

The purses died because the networks got too good. The founding assumption of this decade is that networks fail. An entire peninsula lost its payment system in an afternoon in 2025. Undersea cables in the Baltic get cut often enough that navies now patrol them. Governments that spent thirty years celebrating the cashless society are printing brochures telling citizens to keep banknotes in a drawer. Resilience, which in the nineties had no constituency at all, now has civil-defense planners, security strategists, and a public that has personally stood in a dark supermarket. The exact force that killed the Porta-Moedas Multibanco, the flawless ever-present network, is no longer assumed by anyone serious.

Autonomy stopped being an abstraction, too. In 2022, the world watched payment networks switched off over a weekend, country-scale. Two American companies control the tap-to-pay interface of nearly every phone in Europe; two others carry about two-thirds of euro-area card payments; dollar stablecoins are scaling under enthusiastic American legislation. When Europe built Galileo, the objection was word-for-word the one I started with (GPS is free and works, why duplicate it?) and the answer aged well: because it belonged to someone else, and things that belong to someone else can be priced, degraded, or aimed. Redundancy, I've come to think, was never a fallacy in strategy. Only in accounting.

The hardware problem that strangled the purses has quietly solved itself. They needed special cards, special readers, special habits. The secure element now ships in every phone by default; distribution rides inside banking apps people already have; provisioning can happen by automatic top-up while the user thinks about nothing at all. The purses demanded enthusiasm. This thing is engineered to survive on indifference, which, after everything above, I've concluded is exactly the correct engineering assumption.

The law has changed sides as well. The purses were optional products competing on a shelf. The digital euro would be legal tender, acceptance mandated, distribution mandated. Yes, that's the same entrenchment that makes my zombie scenario possible. The sword has two edges. But one of those edges faces the graveyard: death by indifference, the thing that actually killed every predecessor, becomes nearly impossible.

And the stakes have inverted. In 1995, if the purse died, cash remained, and nothing important was lost. Today, cash is being displaced regardless, by cards and by apps, at whatever pace habits drift, and the digital euro barely moves that trend either way. What it decides is not whether the role of cash gets digitized, but what inherits it: something public, capped, privacy-bounded by law and audit, or something private, unaccountable, and mostly foreign. The alternative to trying is not the status quo. There is no status quo on offer.

None of this guarantees anything. But the public scoreboard is not all graves, either. Pix and UPI were public infrastructure launched into crowded, satisfied markets, and within five years each was simply how a subcontinent pays. Different architecture, sure. But proof that "state payment project" and "thing people actually use" are not natural enemies.



The graveyard is real. I walked it. But graveyards are records of old weather, and the weather has changed. By the end of this part of the investigation, my forecast had honestly shifted, from doomed to genuinely uncertain. And it was that shift that crystallized the conclusion I'd been circling ever since the zombie. Because an uncertain bet is only acceptable when someone is allowed to check the result.


The risk that should not be acceptable

So let me say clearly where I landed, because after this many objections it would be easy to mistake me for an opponent.

I am not against the digital euro.

Everything we know says it will probably fail. The purses failed. The launched CBDCs failed. The banks distributing it want it dead, and its benefits are invisible at every individual checkout. And everything that has changed says it genuinely might not; the weather argument is real, and I meant it. Probable failure with a real chance of mattering: that is a perfectly ordinary profile for public infrastructure. Most insurance is never used. Most resilience looks like waste right up until the day it doesn't. If likely failure were disqualifying, we would have no fire brigades. Failure is not the unacceptable part.

Here is the unacceptable part. As currently constructed, if the digital euro fails, no one will ever know, and nothing will ever stop it.

Run the checklist from my investigation one last time. The metric that would actually reveal failure (loaded wallets, not transaction counts) is not required to be published anywhere. The institution operating it will never self-report; no central bank on Earth has ever declared its own launched digital currency dead. The external auditors' mandate is narrow. The costs appear in no budget that anyone votes on; they vanish silently as reduced remittances into treasuries already accustomed to shortfalls. And the moment the regulation passes, ending the project stops being a decision and becomes a repeal that three institutions would have to want simultaneously, while none of them retains any incentive to even look.

And remember what success is supposed to look like. Nothing at all. A dull line item. A setting configured once in a banking app. A small balance riding in my phone's silicon, forgotten like the emergency banknotes in the kitchen drawer, waiting for the afternoon the terminals go dark. That is the design goal, and it's a legitimate one.

But failure will look exactly the same. Same line item. Same silence. Same annual report. An empty extinguisher rusting on the wall is indistinguishable from a full one - until the fire. We are on the verge of building the one kind of project that no engineering culture, no market, and no honest government should ever permit: one whose failure cannot be observed, and whose waste cannot be stopped.



A likely failure with a failure detector and a kill switch is a reasonable bet. That's just called trying something, and trying things is how Pix happened, how Galileo happened, how every piece of infrastructure we now take for granted happened. A likely failure with neither is not a bet at all. It is a blank check made out to institutional pride, drawn on money nobody will miss because nobody will ever see it leave.

What makes the omission indefensible is how cheap the fix is. Three clauses, in a regulation that is still being written. Mandatory publication of loaded-wallet counts, the one number that separates the extinguisher from the zombie. Independent audit rights over what the offline system actually records, so the privacy promise is verified rather than trusted. And a genuine review-and-sunset mechanism whose default is termination, so that continuation has to be argued for by someone, on the record, ever. All of it decided now, while legislators still hold the pen, because everything I learned says that afterward, no one holding the power will keep the motive.

Build it with those instruments, and I will load my hundred euros on launch day and hope to never think about them again. Build it without them, and it almost doesn't matter whether it succeeds, because we will have accepted the principle that public infrastructure never has to answer for itself. And that principle will outlive any wallet.

I set out to check whether one claim was false or misleading. The claim was fine. What I found instead was a project that might work, will probably fail, and is currently being insulated from anyone ever finding out which.

The chip was never the risk. The text is.

And the text is still open.

No comments:

Post a Comment