Pre-analysis commitment for a study of deposit rate sensitivity across U.S. bank size classes over the 2021 to 2024 tightening cycle, using FDIC Call Report data. The plan fixes the estimator, sample, comparison groups, controls, reported statistics, robustness variants, and the threshold for what counts as a finding. The file was written on August 25, 2026, before any data was retrieved. It was deposited here on August 27, 2026, after estimation had been carried out. This deposit therefore establishes the content and the deposit date. It does not independently verify that the file predates the estimation, and no claim to that effect is made. Departures from the plan are recorded in a deviation log accompanying the analysis. The work is funded by the Blockchain Association. The author retains the right to publish the findings regardless of what they show.
Baocheng Zeng, Jinhao Yang, Peilin Han, Kangnan He
Public cryptocurrency archives may appear usable when files exist, although factor research requires observations available and executable at each decision time. We audit public Binance BTCUSDT USD-M perpetual-futures data using event, publication, and availability times and separate proposal from deterministic auditing, evaluation, and holdout access. An initial gapless five-minute requirement for trade, mark, index, and open interest failed: the longest unrepaired intersection was 304.5729166666667 days. A disclosed revision made trade, mark, index, and realized funding the core streams and made open interest optional because its publication time was unverified. The revised mask retained 727 complete UTC days and supported a 436/145/146-day train, validation, and historical-holdout split. On 80 frozen known-rule templates, the auditor detected 40/40 violations and rejected 0/40 legal templates. Across ten null-signal paths, full auditing reduced mean false passes from 0.2910 to 0.0625. Under matched valid-candidate budgets, the audited adaptive agent tied random search and did not establish superiority. In the one-time historical holdout, all evaluated runs had positive IC but negative net Sharpe under primary costs. We therefore report a scoped negative result rather than a profitability or agent-superiority claim.
Abstract Dynamic exposure rules can appear effective simply because they reduce risky participation, not because they time exposure well. This study evaluates Pogi, a recursive FULL/PARTIAL/NONE controller that separates portfolio composition from total risky exposure and uses a non-executed shadow path to observe recovery during defensive states. Using daily cryptocurrency data from 2014–2026, eight chronological test folds, recursive transaction costs, and CRRA certainty-equivalent welfare, Pogi is compared with static scaling, volatility targeting, CPPI, drawdown throttling, moving-average control, fractional Kelly scaling, and an exact ex-post exposure-matched diagnostic. The analysis also tests initialization and memory sensitivity, timing nulls, search capacity, selection-aware inference, and external validation using U.S. industry portfolios and frozen cross-market transfer. The completed evaluation did not establish robust welfare superiority for Pogi or support a broader methodological contribution under the pre-specified evidence criteria. The results instead show why dynamic exposure rules should be judged against exposure-matched benchmarks, model-search controls, recursive-state diagnostics, and genuinely external validation.
Dwi Fitrizal Salim, Farida Titik Kristanti, Hosam Alden Riyadh, Mailinda Tri Wahyuni
Type of the article: Research ArticleAbstractThis study evaluates and compares risk measurement models for ten major cryptocurrencies: Bitcoin, Ethereum, Tether, Ripple, Dogecoin, Cardano, Binance Coin, Polkadot, Solana, and USD Coin. Using daily log-return data from January 2017 to October 2024, the analysis applies Modified Cornish-Fisher Value-at-Risk and standard, exponential, threshold, and Markov-switching generalized autoregressive conditional heteroskedasticity models. The main comparison is conducted at the 99% confidence level, while model reliability is assessed through out-of-sample backtesting using 500 observations and the Kupiec unconditional coverage and Christoffersen conditional coverage tests. The results reveal substantial heterogeneity in cryptocurrency risk. Modified Cornish-Fisher Value-at-Risk produces highly sensitive estimates for assets with extreme skewness and kurtosis, particularly Ripple, Cardano, and Dogecoin. However, no single model performs consistently better across all assets. Bitcoin is the only cryptocurrency for which all tested models pass both backtesting procedures. The Markov-switching specification provides acceptable coverage for Bitcoin, Ripple, and Dogecoin but does not consistently outperform conventional volatility models. Standard and asymmetric volatility models provide stronger support for Cardano, Binance Coin, and Polkadot, whereas Ethereum, Solana, and USD Coin remain difficult to model under the examined specifications. These findings demonstrate that cryptocurrency risk measurement requires asset-specific model selection based on both estimated loss magnitude and formal backtesting evidence.
The increasing demand for trustworthy and privacy-preserving credit reporting systems has exposed the limitations of both centralized and existing blockchain-based solutions, including scalability bottlenecks, weak privacy protection, and insufficient incentive mechanisms. To address these challenges, we propose LightCred, a novel consortium blockchain-based personal credit management framework that integrates lightweight nodes, Merkle proofs, multi-role smart contracts, and privacy-preserving cryptographic techniques. LightCred features a five-layer architecture that efficiently collects, verifies, stores, and serves credit data while ensuring data integrity, confidentiality, and regulatory compliance. Specifically, it (i) employs a low-cost and traceable data reduction mechanism through lightweight nodes and Merkle proofs to minimize storage and improve verifiability; (ii) introduces a multi-role smart contract model that enforces dynamic access control and fair incentive distribution based on participant reputations; and (iii) integrates zero-knowledge proofs and homomorphic encryption to support privacy-preserving credit scoring and querying. Experimental results demonstrate that LightCred achieves superior performance compared to five baseline methods, delivering up to 5% higher throughput, 3–5% lower privacy leakage, and 10–15% reduced storage costs, while maintaining competitive latency and auditability. These findings validate LightCred as a robust, scalable, and privacy-aware credit management solution, offering a viable alternative for modern credit reporting systems.
Michael Neubert, Wolfgang Rams, Patrick Gruhn, Marcel Lötscher
Perpetual futures (often called perpetual swaps) are the dominant crypto-derivatives instrument. They replicate the economic exposure of a futures contract without an expiry date. They replace maturity-based convergence with a funding mechanism that transfers cash flows between longs and shorts, typically every eight hours. This paper explains how perpetuals evolved from early proposals for non-maturing futures into a standardized crypto market instrument, and why key design choices changed over time. It synthesizes recent theoretical and empirical research on funding design, pricing, and arbitrage intuition, market microstructure, liquidation risk, and regulation. Finally, this study proposes a research agenda organized around funding design, constrained arbitrage, transparency, decentralized exchange design, policy, and legal classification, because recent U.S. and EU developments show that the same economic structure may be characterized as a futures contract, swap, CFD-type instrument, or other derivative depending on statutory definitions, venue design, and supervisory interpretation. This paper proposes the following definition: a cryptocurrency perpetual is an open-ended, margin-based derivative that gives synthetic long or short exposure to an underlying crypto asset and replaces expiry-based settlement with periodic funding payments that anchor the contract price to a reference spot price.
ABSTRACT The emergence of decentralized compute-sharing protocols—peer-to-peer GPU and specialized-hardware marketplaces enabling firms to provision machine learning training and inference capacity without direct capital expenditure or on-balance-sheet lease recognition—has introduced a structurally novel form of operational leverage that conventional credit analysis is ill-equipped to detect. This paper investigates whether such off-balance-sheet utilization systematically distorts a firm's True Free Cash Flow to Firm (FCFF), defined here as reported FCFF adjusted for the capitalized economic equivalent of decentralized compute obligations, and quantifies the implicit tail-risk premium that credit default swap (CDS) markets demand for this hidden leverage. We formalize the problem in three stages. First, we construct a Hidden Leverage Ratio (HLR) by reconstructing the present value of a firm's implicit compute-sharing commitments from on-chain settlement data, smart-contract escrow balances, and protocol-level utilization telemetry, applying an exposure-graph methodology to map indirect exposure routed through special-purpose vehicles (SPVs) and protocol intermediary nodes. Second, we develop a structural credit risk model extending the classical Merton framework with a compound jump-diffusion component calibrated to compute-price volatility, in which hidden leverage enters the firm's effective asset volatility and default boundary as an unobserved but inferable state variable, generating a model-implied default probability and credit spread. Third, we empirically estimate the market-implied tail-risk premium by regressing observed 5-year CDS spreads against the constructed HLR across a panel of 412 firm-quarters drawn from technology, fintech, and AI-infrastructure issuers with active CDS markets, controlling for conventional leverage, profitability, and macro-credit factors. We find that CDS markets demand a statistically and economically significant tail-risk premium for hidden compute leverage: a one-standard-deviation increase in HLR is associated with a 61–142 basis point widening in 5-year CDS spreads depending on cohort, an effect that persists after controlling for reported leverage ratios, implying that CDS markets partially but incompletely price this off-balance-sheet exposure ahead of formal disclosure. The structural model achieves an R² of 0.87 against observed CDS spreads and reveals a convex, threshold-like premium structure consistent with jump-risk pricing rather than continuous Merton-style diffusion risk alone. We critically examine the limits of on-chain data observability, the endogeneity risk in inferring "true" cash flow from a credit-market-implied proxy, the accounting standard-setting implications for emerging digital lease constructs, and the systemic stability concerns raised by undisclosed, correlated compute leverage across the AI infrastructure sector. This work establishes a rigorous, empirically grounded framework at the convergence of decentralized finance infrastructure, structural credit risk theory, and corporate financial reporting.
Sai Srikanth Madugula, Peplluis Esteva De La Rosa, Daya Shankar
Decentralized Finance (DeFi) lending protocols currently rely on heuristic, utilization-based bonding curves that mandate severe over-collateralization, systematically excluding under-collateralized assets like corporate invoices. This paper introduces a mathematically optimal pricing mechanism for decentralized credit: the Reverse Kelly Automated Market Maker (rkAMM), the core engine of our proposed lending framework. By inverting the Kelly Criterion, traditionally used for optimal bet sizing, we construct a dynamic interest rate discovery protocol that explicitly prices individual loan risk. The rkAMM ingests real-time Probability of Default (PD) streams from an off-chain Explainable AI oracle and dynamically calculates the exact interest rate required to sustain target liquidity provider (LP) yields. We mathematically derive the Reverse Kelly pricing function ($r = \frac{y + PD}{1 - PD}$), proving its strictly convex superiority over Aave and Compound's static utilization curves in managing capital efficiency. Furthermore, we deploy the rkAMM architecture via Solidity smart contracts, optimizing for gas-efficient 1e18 (WAD) floating-point arithmetic. To ensure decentralized transparency, our simulation infrastructure leverages MLflow for tracking yield hyperparameters, Data Version Control (DVC) linked to DagsHub for versioning Real-World Asset (RWA) data arrays, and localized edge-inference via Ollama (Llama-3) and Hugging Face (FinBERT) for zero-cost predictive modeling. Monte Carlo simulations across 10,000 macroeconomic stress scenarios confirm that the rkAMM maintains protocol solvency and stabilizes LP yields at 12-15\% net of expected credit losses. This work provides the foundational financial engineering required to bridge the \$2 trillion global supply chain finance gap using permissionless blockchain infrastructure.
Aktam U. Burkhanov, Abdul Jalil Mahama, Ilyоs Abdullaev, Nodira B. Abdusalomova · 6 authors
Type of the article: Research ArticleAbstractStablecoins serve as the primary liquidity and settlement platform for decentralized finance, yet recent market shocks and de-pegging events demonstrate systemic vulnerability regarding their stability. The purpose of this study is to quantify the tail risk of Tether (USDT) to determine the accuracy of different risk modeling frameworks during periods of extreme market stress. This study employs historical simulation, parametric Gaussian models, Monte Carlo simulation, and Extreme Value Theory using the Peaks-Over-Threshold approach on daily log returns from 2015 to 2025. Statistical diagnostics confirm high excess kurtosis of 24.3 and a negative skewness of –3.1 in the asset returns, which explicitly invalidates normal distribution assumptions. The empirical results reveal that Gaussian methods systematically underestimate extreme risk by 47% during high-volatility regimes. Extreme Value Theory models capture fat-tailed behavior with 50% higher precision than traditional models, identifying a maximum potential one-day loss of 1.50%. Backtesting parameters at the 95% and 99% confidence levels show that standard Value at Risk models fail to predict 14 out of 18 historical tail-risk anomalies. Expected Shortfall calculations under the generalized Pareto distribution successfully cover 99.8% of historical volatility spikes. This study concludes that Extreme Value Theory frameworks are essential for the robust design of decentralized finance protocols and the development of institutional risk management standards.AcknowledgmentsThe authors express gratitude to our respective university departments and institutional research groups for providing the technical infrastructure necessary to conduct this study. We also recognize the participants of internal research seminars whose early feedback helped refine the core empirical parameters of this stablecoin risk framework.
Daniel Pereira Alves de Abreu, Octávio Valente Campos, Aureliano Angel Bressan
Objective: This study aims to evaluate the performance of different ARMA-GARCH model specifications in the risk management of major cryptocurrencies, investigating whether the inclusion of exogenous variables improves the calibration of risk measures such as Value-at-Risk (VaR) and Expected Shortfall (ES). Methodology: To achieve this objective, 4,032 specifications of the ARMA-GARCH model applied to the ten main cryptocurrencies in trading were tested. The study incorporated the Fear and Greed Index and Bitcoin Trading Volume as exogenous variables in an ARMA-GARCH-X framework, comparing the performance of the different specifications against an ARMA(1,1)-GARCH(1,1) benchmark. Originality: Despite growing interest in crypto asset risk management, there are still gaps in the literature regarding the effectiveness of incorporating exogenous variables into forecasting models, as well as the increase in the quality of forecasts when using more complex models. Main results: The results indicate that the inclusion of external variables improves risk calibration in some assets, although the gains are marginal and heterogeneous. There is also no single optimal parameterization, requiring ARMA orders, GARCH specifications, and error distributions to be adjusted for each cryptocurrency. Theoretical/methodological contributions: From a methodological point of view, the study contributes by demonstrating the importance of specific calibration of ARMA-GARCH models for different cryptocurrencies in risk estimation. Furthermore, the results suggest that, although more complex models can improve tail risk estimation, the gains in predictive power over simpler models are limited. Keywords: Cryptocurrencies; Risk Management; ARMA-GARCH; Value-at-Risk; Expected Shortfall.
With the rapid development of digital finance, the mode of enterprise credit risk assessment has changed, and now also requires methods that can handle large-scale, diverse data and smart computation. The old system of credit rating has been based on the results of past financial reports and is no longer suitable for evaluating the changes and risks in modern corporate finance. This paper proposes a multi-dimensional model for mining credit reports of mining enterprises and combines structured financial data, transaction information, operating indicators, and other unstructured auxiliary data such as social media presence, online communication, supply chain dynamics, etc. By building a relatively detailed credit report, the bank can gain some information on the risk of a company's credit and its repayment ability for a loan. Algorithms that use machine learning, deep learning, ensemble models and predictive analysis are also known as intelligent default risk assessment algorithms that enhance the accuracy and flexibility of credit assessment. The following are ways to discover abnormal or complex patterns in a large amount of data early on for risk early warning, online credit assessment and dynamic portfolio management. Interoperability of digital finance platforms can support lifelong learning, automation and scalable high-frequency financial data, and maintain security, privacy and regulatory compliance. Although the above have been achieved, there are still deficiencies in the quality of data, interpretability of models, adherence to regulations, and sufficient computational resources, especially for small and medium-sized enterprises and new market institutions. Future research directions include building explainable AI systems, continuous learning, integrating multiple types of data (multimodality), and decentralized finance (DeFi) based on blockchains. At this point, the above technologies are expected to help enterprises strengthen credit risk management in the age of digital finance and provide more accurate and timely credit evaluations.
Sai Srikanth Madugula, Peplluis Esteva De La Rosa, Daya Shankar
The integration of machine learning into decentralized finance (DeFi) credit assessment is frequently undermined by opaque algorithms and severe methodological flaws regarding data leakage. This paper presents a rigorous, fully reproducible framework for explainable artificial intelligence (XAI) in invoice-backed default risk modeling. Utilizing a highly imbalanced dataset of 12,000 corporate loan originations, we engineer an XGBoost ensemble model that achieves an AUC-ROC of 0.89. We systematically eliminate the pervasive data leakage associated with the Synthetic Minority Over-sampling Technique (SMOTE) by implementing a dynamic crossvalidation pipeline, ensuring synthetic data generation is strictly isolated to training folds. To satisfy institutional accounting standards for expected loss (e.g., IFRS 9), we mathematically formulate and validate the Expected Calibration Error (ECE), achieving a highly calibrated probabilistic output of 0.08. Furthermore, we extract local explanations using SHAP (SHapley Additive exPlanations), imposing strict constraints on the background reference dataset to guarantee mathematical additivity and prevent stochastic approximation transitions. Our findings reveal that Days Payment Outstanding (DPO) and invoice age are primary default drivers, while on-chain reputation effectively mitigates perceived risk. Finally, we address critical privacy vulnerabilities, mathematically modeling Membership Inference Attacks (MIAs) on synthetic records. This work establishes a regulatory-compliant, structurally sound ML foundation for permissionless credit provision.
This paper estimates the carry embedded in listed IBIT options and compares it with the carry embedded in matched CME bitcoin futures. Put-call parity recovers an implied forward on the ETF; BlackRock's daily holdings file maps each ETF share into bitcoin units; and CME futures prices and BRRNY, a U.S. close bitcoin reference rate, provide the corresponding futures-market carry. The difference in carry implied by these two products is consistent with frictions that limit cross-margining between spot bitcoin or ETF exposure and CME futures. In the selected-strike IBIT sample of 386 date-bucket observations, the mean wedge is 2.58 percent and the median wedge is 2.52 percent, both measured in annual percentage points. The result is consistent with segmented collateral and margin systems limiting arbitrage between regulated bitcoin-exposure venues.
Modern banking systems simultaneously maintain monetary values across computation (8-10 decimal places), ledger posting ($\mathbf{4}-\mathbf{8}$decimal places), and customer presentation (2 decimal places) scales. In distributed microservice and event-driven architectures, unmanaged transitions between these scales introduce rounding drift, ledger divergence, reconciliation breaks, and non-deterministic replay risks that threaten audit compliance and regulatory reporting accuracy. This paper investigates how distributed banking systems can manage multi-scale monetary precision while preserving deterministic balances and auditability. The proposed Multi-Scale Monetary Precision Model (MSMP) defines three scale classes, three explicit precision boundaries, and four correctness invariants governing deterministic posting, ledger conservation, presentation consistency, and fractional carry forward. A taxonomy of three canonical failure modes, namely early rounding, boundary truncation, and nondeterministic aggregation, is presented together with four architectural patterns designed to ensure precision-safe monetary propagation. Evaluation on a synthetic bankingrealistic workload (106accounts over 365 days) demonstrates that MSMP reduces cumulative monetary drift by up to 99.9 %, eliminates reconciliation breaks entirely, and achieves 100 % replay determinism, with computational overhead of approximately 18 %. These results establish monetary precision governance as a first-class architectural control for audit-ready distributed financial systems.
Decentralized finance (DeFi) protocols now intermediate over USD 100 billion in value, including regulated stablecoins and tokenized assets deployed as collateral, yet no widely adopted framework operationalizes risk assessment at the rigor institutional adoption demands. Existing approaches emphasize protocol-specific parameter optimization or conceptual taxonomies without providing explainable, composability-aware, and structurally independent assessment methodologies. We propose a nine-dimension DeFi risk assessment framework extending the six-dimension taxonomy introduced by Moody's Analytics and Gauntlet with three novel dimensions: composability risk, comprehension debt, and temporal risk dynamics. We additionally introduce a transparency confidence modifier separating assessment reliability from risk severity. The framework is grounded in structural analysis of protocol dependencies conducted through an ontology-based protocol intelligence infrastructure covering more than 8,000 DeFi protocols. We retrospectively analyze 12 major DeFi-related incidents from 2024-2026 representing approximately USD 2.5 billion in direct losses. Five of the 12 incidents require at least one novel dimension for complete root-cause characterization, including the two highest-systemic-impact events in the dataset.
We study permissionless spot--perpetual basis trading in decentralized finance as a collateral control problem. The strategy holds spot inventory, hedges directional exposure with a short perpetual, and allocates capital between spot inventory and derivative margin under on-chain liquidity and execution frictions. The paper delivers three results. First, it solves a static control problem for the collateral share and shows that the risk-constrained formulation provides a more robust operating benchmark relative to the economic optimum. In comparative calibration, the required collateral rises monotonically under volatility stress. The collateral is the lowest for BTC and increases significantly for long tail assets such as LINK and DOGE. Second, the paper derives an asymmetric dynamic extension in which the lower boundary of intervention is solvency driven, and the upper boundary is determined by a trade-off between carry-loss and the cost of rebalancing. Monte Carlo simulation shows that the lower boundary remains structurally relevant, whereas meaningful interior upper triggers survive mainly in the regimes with high carry and low costs. Third, the paper validates an execution-aware implementation with live routed execution and historical backtests. The execution layer shows that the realized wedges are significant, but become worse in the case of selling the basis. This justifies a minimum effective rebalancing size and a positive execution buffer. The historical validation shows that in the case of a fixed control rule the realized performance is predominantly explained by the funding environment.
Rapid urbanization and the exponential growth of vehicles have led to severe traffic congestion, increased travel time, fuel consumption, and environmental pollution in metropolitan cities.Traditional traffic control systems, which rely on fixed-time signals and manual monitoring, are inadequate to handle dynamic and unpredictable traffic conditions.This project proposes a Smart Traffic Management System designed to optimize traffic flow and reduce congestion using advanced technologies such as Artificial Intelligence (AI), Internet of Things (IoT), and real-time data analytics.The system integrates smart sensors, cameras, and GPS-enabled devices to continuously monitor traffic density, vehicle movement, and road conditions.Data collected from these sources is processed using machine learning algorithms to predict traffic patterns and dynamically adjust traffic signal timings.Additionally, the system provides real-time route guidance to drivers through mobile applications and digital signboards, helping to distribute traffic evenly across the road network.Emergency vehicle prioritization and incident detection mechanisms are also incorporated to enhance response efficiency and safety.
We propose a framework for quantifying Credit Valuation Adjustment (CVA) in tokenized securities settled atomically via stablecoins on distributed ledger technology (DLT). We introduce the Settlement Currency Valuation Adjustment (SCVA), a new adjustment term inspired by the Collateral Cost Adjustment (CCA) of Fujii and Takahashi (2013). Using a two-state Markov depeg model, we derive a semi-analytical SCVA expression. Under USDC 2023 parameters, SCVA exceeds the settlement-period CVA reduction by a factor of approximately 3. Cross-stablecoin analysis reveals that the regulatory design of the settlement currency determines whether atomic settlement yields a net CVA benefit.
The next generation of financial and economic infrastructure has been realized by Real-World Asset (RWA) tokenization, which represents physical and regulated assets on distributed ledgers. Regardless of increased institutional interest, its large-scale adoption is limited by the scalability, regulatory compliance, governance, and finality of settlement issues intrinsic to traditional systems. This paper suggests a fractional asset tokenization model based on ERC-1155 on the Hedera blockchain using its Permissioned-public governance system, deterministic finality, and native token services. The proposed system will enhance the liquidity of assets, their accessibility to the market, and their efficiency and profitability by facilitating compliant fractional ownership, which is consistent with the changing regulatory processes. When compared to Ethereum and Bitcoin, it shows that Hedera would be more appropriate to the requirements of institutional grade RWA tokenization.
The strong interest in central bank digital currencies (CBDCs) arises in a context of increased digitization of payments and a growing search for more resilient and inclusive solutions. Among the desired features of CBDCs, offline payment constitutes a central challenge. It ensures the resilience of payment systems, promotes financial inclusion, and guarantees transaction continuity in the absence of network connectivity. However, unlikeonline payments, offline payments for CBDCs impose specific constraints and sometimes conflicting requirements in terms of security, privacy, fraud prevention, auditability, and integration with existing infrastructures. Consequently, this thesis focuses on the anal ysis and formalization of these offline payment requirements, as well as on the study of technical solutions capable of addressing them in a coherent manner. Accordingly, basedon this analysis leading to a structured taxonomy, the thesis introduces several original frameworks illustrating different strategies for satisfying these requirements. The first framework, PrivTEE-Pay, relies on a single-ledger architecture and exploits trusted execution environments combined with cryptographic primitives such as blind signatures and zero-knowledge proofs (zk-SNARKs). The second framework extends a conventionalpayment architecture through the integration of a secure smart card, the DigiVault card, coupled with a smartphone. This combined approach also relies on privacy-enhancing technologies and on the fraud detection model MarkoPayChain, based on Markov chains. A third framework, Block-PAD, proposes a hybrid architecture combining a central ledger for monetary issuance and a blockchain for delayed synchronization of offline transactions.Finally, the thesis complements these contributions with an advanced offline fraud detection framework, based on a combination of expert rules, explainable machine learning models, and hidden Markov chains. Moreover, these different frameworks are experimentally evaluated using simulators and synthetic datasets dedicated to offline CBDC payments. The results show that the proposed solutions make it possible to address the requirements identified in the taxonomy, each through explicit trade-offs. This thesis thus provides concrete contributions to the design of resilient, secure, performant, auditable, and privacy-preserving offline CBDC payment systems that can integrate into existing payment infrastructures.