on
But What Is the Digital Euro?
Money is digital. When you pay with a card, no physical object changes hands — a few databases update some numbers, and everyone agrees that wealth was transferred. So what exactly is the digital euro supposed to change?
To answer that, we need to understand how money works, how it moves, and where the current system falls short.
How Money Works
Money is a medium used to trade wealth; it is not equal to the total value of that wealth. For example, the value of all American stocks is ~70T USD, whereas the broad USD money supply is ~22T USD.
Historically, money was anchored to physical assets. Before 1971, the US dollar was exchangeable for gold at a fixed rate of $35 per troy ounce, a backing that stabilized most of the world’s currencies through the Bretton Woods system. When Nixon suspended convertibility in 1971, the world switched to fiat money. Today, money’s value comes from shared belief in the financial system — nothing more.
How then does this fiat money come into existence? The answer is: via credit. Economists distinguish three layers of money supply:
- M0 (narrow money or base money): Physical cash (coins and bills) plus the digital reserves that commercial banks and the government hold at the central bank. You and I cannot hold digital M0; only commercial banks and governments can.
- M1 (intermediate money): Highly liquid, “everyday” money. The physical cash from M0 plus all digital money in your checking accounts (demand deposits). Notice that M1 excludes the central bank reserves — it only measures money available to the public.
- M2 (broad money): M1 plus slightly less liquid assets like savings accounts or retail money market funds.
For reference, M0, M1, and M2 in the eurozone are roughly 4T, 11T, and 16T Euro respectively.
The money in your checking account is created by commercial banks through lending. When you take out a mortgage, the bank doesn’t reach into a vault and hand you someone else’s savings. It creates the money out of thin air by crediting your account — it generates a new entry in its database.1
Banks constantly exchange money with each other as their customers transact. At the end of each day, they must settle their net differences using M0 money — the reserves they hold at the central bank. While reserves don’t strictly limit how much a bank can lend, they must be sufficient to cover the daily flow of money between institutions. One reason banks offer interest on your deposits is a classic arbitrage play: by attracting deposits from competitors, they receive reserves that they can park at the central bank. If its interest rate is higher than what they pay depositors, they pocket the spread.
Ultimately, fiat money—whether a physical €50 bill or a digital balance—has no intrinsic value. A central bank reserve (M0) is essentially a tokenized slice of the state’s future taxation power. It holds value because millions of citizens will eventually work, earn M1, and pay taxes, allowing the government to settle its bond debts and keep the system afloat.
By extension, the money in your checking account is simply a database entry representing your bank’s promise to give you that value. This entire two-tiered system holds together because commercial banks are strictly regulated to manage risk, and governments promise to keep inflation in check.
But if money is simply a network of promises and regulated database entries, what actually happens when you buy a coffee? It moves through payment.
How Payment Works
Stripped down, payment is the act of synchronizing accounts across different institutions’ databases. When you transfer money to someone, your bank debits your account and the recipient’s bank credits theirs. SEPA (eurozone) and SWIFT (global) are one way to coordinate this distributed transaction (generally taking anywhere from seconds to days).
For instant payments, Visa and Mastercard immediately come to mind. A standard card transaction runs on the “four-party model”: the consumer, the merchant, the issuing bank (the consumer’s bank), and the acquiring bank (the merchant’s bank). A payment network (Visa or Mastercard) sits in the middle to route the transaction. Each payment passes through three stages2:
- Authorization: Check funds, lock the amount, perform fraud detection.
- Clearing: Both banks agree on the amount, currency, and fees.
- Settlement: The actual movement of funds between the banks.3
Each intermediary in this process takes a cut. The issuing bank charges an interchange fee (capped at 0.2% for debit and 0.3% for credit cards in the EU), the payment network charges coordination fees, and the acquiring bank or terminal provider takes their share, too. While large retailers can negotiate these rates, small businesses have little to no leverage and pay roughly 0.9% to 1.2% of every transaction.
Roughly a third of all consumer spending worldwide flows through Visa and Mastercard. In fiscal year 2025, Visa alone generated nearly $39B in revenue with an operating income of $24B — a 60% profit margin simply for being the API between banks.4
This setup has two fundamental issues:
First, sovereignty. Europe relies heavily on American card networks. If Visa and Mastercard were to restrict access — due to sanctions, trade disputes, or political pressure — European commerce would face serious disruption. This is not a theoretical scenario; similar measures are a proven instrument of geopolitical leverage.
Second, cost. Cash is free to use but inconvenient. Card payments are convenient but carry mandatory fees that disproportionately burden small businesses.
There is currently no free, convenient, digital alternative. Yet, a viable design for one has existed for decades.
True Digital Cash and GNU Taler
Alternatives to constantly routing data through rent-extracting corporate middlemen exist. GNU Taler constitutes one of multiple architectures for digital cash. It builds on David Chaum’s pioneering e-cash work from the 1980s.
At its core, GNU Taler replaces account-based tracking with digital tokens secured by a cryptographic primitive called a blind signature. The protocol separates the financial world into three parts: your local wallet app, your traditional commercial bank, and an independent cryptographic service provider called the Exchange.
The architecture is beautifully simple. When you want to withdraw digital cash, your wallet app generates a digital coin locally on your device and wraps it in a layer of mathematical “blinding” randomness. Your bank then transfers regular fiat money from your checking account into the Exchange’s escrow account. Once the funds clear, your wallet sends the blinded coin to the Exchange. The Exchange digitally signs the randomized package and returns it without ever seeing the actual coin serial number underneath.
Finally, your wallet app mathematically strips away the blinding layer, leaving you with a perfectly valid, cryptographically certified digital coin. Your bank knows that you withdrew money, but because only the Exchange signs the coin (and only while completely blinded), the system ensures strict payer privacy — no one can trace the final digital cash back to you.
Here’s how payment then works: When you buy groceries, your wallet hands the unblinded coin to the merchant, who forwards it to the Exchange to verify it hasn’t been spent before (preventing double-spending). The Exchange burns the coin by marking it as spent and instructs the banking system to credit the merchant’s commercial bank account with the coin’s face value. The merchant is identified, enabling taxation and anti-money laundering (AML) compliance. Because the Exchange only ever handled the blinded version during withdrawal, it has no mathematical way of linking the token to your identity.5
In your wallet, you directly hold cryptographically signed coins (like 5 Cent, 1 Euro, or 50 Euro). You pay with exact change and regularly rebalance your wallet by swapping fiat money for coins. It is an elegant, open-source architecture that the European Central Bank could easily adapt to serve as the structural framework for a sovereign digital euro.
What the ECB Is Actually Building
Sadly, the ECB’s digital euro abandons this elegance for complexity. Instead of a single, cryptographically secure digital cash system, the ECB has designed two largely separate architectures: an account-based one for online payments and a token-based one for offline payments.6
The Online Version
For online payments, there are no cryptographic coins. Instead, the ECB plans to operate a centralized ledger infrastructure recording all digital euro account balances. Pretty much what banks are doing right now, just centralized via the Eurosystem.
To interact with this system, you still need an intermediary. Participating Payment Service Providers (PSPs), like your current bank, will handle the digital euro accounts, enforce regulations and process transactions.
The ECB plans to introduce a proposed baseline holding limit of €3,000 for regular users and €0 for businesses (to not pull too much liquidity from commercial banks). You can choose to link your digital euro account to a commercial bank account. If you do, a “reverse waterfall” mechanism can automatically pull funds from your commercial bank if your digital balance is too low, and a “waterfall” can automatically sweep excess funds back to your bank if you exceed the limit.
While the design ensures that the central bank itself cannot see or match your real-world identity to individual transactions—leaving that data pseudonymized and siloed at the PSP level—the architecture has still raised alarms among privacy scholars. Centralizing the master settlement ledger creates an entirely new structural target. If a single payment profile is deanonymized or leaking data, it risks exposing a user’s entire transaction history across a unified timeline.
It’s complicated, the additional privacy gains are questionable, and the banks handle a lot of the complexity, justifying high fees.
The Offline Version
For offline payments, the ECB does indeed plan to use a token-based system. However, unlike GNU Taler, which uses coins for online payment, the ECB aims for purely offline peer-to-peer payments. This, however, introduces a deeply stubborn technical paradox.
If neither your phone nor the merchant’s terminal can talk to a live central validator, there is no immediate way to guarantee that you haven’t just spent the exact same digital token five minutes earlier at a different store. Completely preventing double-spending without an active data connection is impossible.
The ECB’s workaround is to rely on proprietary “secure hardware” (like the Secure Element in smartphones) to lock the tokens and physically prevent you from copying them. History strongly suggests this will fail.7 The crucial difference between securing a digital euro and securing a fingerprint is the threat model: with the digital euro, the device owner is the attacker. A hacker has full physical control over their own phone and unlimited time to break the hardware. Once a vulnerability is found, an attacker can duplicate a 500 Euro token and double-spend it infinitely until the merchant finally connects to the internet to clear the funds. The ECB has not clearly defined who is liable for this inevitable offline fraud.
The Potential of the Digital Euro
It’s still early days, and I really hope the EU gets the digital euro right. The potential is massive. The Eurozone could become a stronger, more sovereign and efficient currency zone that stimulates transfer of wealth and innovation across borders. An ideal system would be completely open, structurally simple (and thereby cheap), and reasonably anonymous.
The Banks’ Response
Unsurprisingly, the European banking sector is not waiting idly. A consortium of banks has launched Wero, a pan-European instant payment system backed by the European Payments Initiative (EPI). Wero enables instant account-to-account transfers and is expanding into e-commerce and point-of-sale payments across Europe.
Wero is a genuine improvement over the status quo. While it positions itself as a market alternative to make a central bank consumer wallet less urgent, its underlying technology is designed to ultimately play nice with the Eurosystem. The banks are setting the infrastructure up to serve as the front-end interface through which citizens will manage their digital euros once officially rolled out.
Even so, it remains a bank-owned initiative. The banks set the fees, control the software ecosystem, and decide who participates. It reduces Europe’s dependency on American card networks, but it does not fundamentally change the cost structure or introduce the structural privacy guarantees solutions like GNU Taler provide.
A simple and open digital cash system is the only mechanism that could force the payment industry into real competition. Whether European policymakers deliver on that depends on whether they recognize the difference between a system owned by private banks, a complicated platform hosted by a central bank, and an infrastructure genuinely built for the public.
The textbook “fractional-reserve” model suggests banks lend out a fraction of deposits. In practice, banks create deposits when they lend, and reserves serve primarily for interbank settlement. See the Bank of England’s Money creation in the modern economy (2014). ↩︎
See Understanding Payment Authorization, Clearing and Settlement. ↩︎
With debit cards, authorization and clearing happen nearly simultaneously, creating the illusion that money moves “immediately.” When you pay with a credit card, money is — you guessed it — created. When you settle your credit card bill at the end of the month, it is destroyed. ↩︎
This is a simplified explanation based on Chaumian e-cash as implemented in GNU Taler. ↩︎
See Cannataci et al., Digital Euro: Frequently Asked Questions Revisited (2026), arXiv:2601.18644. Licensed under CC BY 4.0. ↩︎
Consumer-grade hardware has a long history of being broken. Trusted Execution Environments (TEEs) have been compromised by software-only attacks; Secure Elements have been compromised by physical attacks. ↩︎
Loading comments...