Hook
Is migrating from a public blockchain to a private permissioned network really the next logical step for institutional tokenization? Or is it a subtle admission that the ‘decentralized’ layer, when faced with real-world compliance and counterparty risk, buckles into a familiar pattern: centralized control wrapped in cryptographic jargon.
Franklin Templeton’s digital assets head, Roger Bayston, recently confirmed the firm’s move from Stellar to the Canton Network. The headline screams “adoption,” but beneath the surface, this shift raises questions that few are asking. Between the hype cycle and the blockchain reality, what does it mean when the world’s 6th largest asset manager opts for a DLT that is essentially a digital permissioned safe?
Context
Franklin Templeton manages over $1.5 trillion in assets. In 2021, it launched the ONCHAIN U.S. Government Money Market Fund on the Stellar network – a public, decentralized, open-source blockchain. That fund became the poster child for real-world asset (RWA) tokenization, proving that a regulated asset could live on a public chain, trade 24/7, and remain compliant.
Now, Bayston signals a partial or complete migration to Canton Network, a privacy-focused DLT developed by Digital Asset that is deliberately permissioned. Only vetted institutions can run nodes, view transaction details, or validate blocks. The tokenized fund is still alive and well, but the infrastructure is being swapped. The question isn’t whether Franklin Templeton can do it – they already have – but why the switch, and at what cost?
Core
Let’s break down the technical implications.
Stellar is a decentralized public blockchain. Anyone can run a node, submit transactions, and audit the ledger. Its consensus mechanism – the Stellar Consensus Protocol – relies on a quorum slice of trusted nodes, but entry is permissionless. That means anyone with a laptop can validate the state of the Franklin Templeton fund. Code is law, but on Stellar, the law is open source.
Canton Network is the opposite. It uses a “privacy-enhanced” DLT where nodes are operated only by authorized institutions. Transactions are not visible to the public; only to contractually bound participants. The network is designed for high-speed, private settlement among banks, asset managers, and insurers. There is no public validator set. There is no open mempool. There is no way to verify that a tokenized fund’s supply matches the underlying SEC filings without trusting the node operators.
Based on my auditing experience during DeFi Summer 2020, I have seen how permissioned layers often reintroduce single points of failure. When a yield aggregator I audited moved from a public testnet to a private mainnet, the team assured me it was for “regulatory reasons.” In reality, they wanted a kill switch. That kill switch exists in Canton by design: the node operators can halt the network, censor transactions, or even reverse settlements if the governance committee decides. Smart contracts don’t bluff, but the humans running them can.
So what does Franklin Templeton gain from this move?
- Data Privacy: On Stellar, every trade of the fund’s token is visible on-chain. On Canton, only the fund’s direct counter-parties and regulators see the transaction details. That’s a win for institutional clients who do not want their portfolio moves broadcast to the world.
- Settlement Finality: Permissioned DLTs can offer near-instant settlement with no fork risk. Public blockchains can have reorganizations. For a fund that manages billions, a six-block reorg is unacceptable.
- Compliance at the Networking Layer: Canton allows selective data sharing with regulators without exposing the entire ledger. This satisfies anti-money laundering and know-your-customer requirements without leaking proprietary trading data.
But the trade-offs are equally severe.
- Censorship Resistance: Zero. If a government orders the nodes to freeze the fund’s tokens, they can. Smart contracts on Stellar cannot be stopped by any single entity. On Canton, the governance committee is the sovereign.
- Auditability: Reduced. Only the node operators have full view of the ledger. External auditors must be granted special access. Compare this to Stellar where any independent forensic analyst (like yours truly) can verify the token supply and transaction history without asking permission.
- Network Effect: Lost. Stellar has a thriving DeFi ecosystem, DEXs, and lending protocols. The ONCHAIN fund tokens could be used as collateral. On Canton, the liquidity is isolated to the institution-run applications. The fund becomes a siloed asset rather than a composable piece of a global financial internet.
Contrarian
The contrarian take is uncomfortable: Franklin Templeton’s move from Stellar to Canton is not a step forward for cryptocurrency’s promise of an open, decentralized financial system. It is a retreat into a walled garden.
Is it progress, or just a liquidity trap in permissioned blocks?
We are seeing a pattern: BlackRock launched BUIDL on Ethereum (public), but also partners with private networks. JPMorgan keeps Onyx on a private Quorum chain. Now Franklin Templeton moves from a public chain to a private one. The narrative that institutions are “adopting blockchain” often conflates using a distributed ledger technology with embracing the ethos of decentralization.
But the ledger doesn’t lie, and neither does control over consensus. Canton Network’s validator set is currently composed of about 20 institutions, each hand-picked by Digital Asset and its governance board. That is not decentralized by any standard. It is a digital bookkeeping system with cryptography, but not a trustless one.
The most overlooked risk is regulatory creep. If a fund valued at $1B runs on a permissioned network where validators are all US regulated entities, what happens when the SEC decides that those validators should be treated as broker-dealers? Now the entire network is exposed to regulatory contagion. A public chain like Stellar would not have that vulnerability because there is no central entity to subpoena.
Franklin Templeton’s move is brilliant from a business perspective: it gives them control over the data, the governance, and the exit. But for those who bought the tokenization narrative as a path to a borderless, open financial system, this is a bitter pill. We are not witnessing a migration; we are witnessing a betrayal of the original vision.
Takeaway
If tokenization means moving from Stellar to Canton, are we simply recreating the legacy finance system on a blockchain facade? The ledger doesn’t lie, but the narrative might.
Watch for the next wave: will other RWA issuers follow Franklin Templeton into permissioned domains? If so, the public blockchain value proposition for institutional RWA dies – and we become paid operators of a very expensive, crypto- flavored database. Or, will a counter-movement emerge that proves compliance and decentralization can coexist? That is the story worth following.
- First published as deep analysis by Jacob Thompson, Crypto News Editor-in-Chief. Based on personal audit experience, institutional background, and on-chain forensic analysis.