Loading...
Research & Insights

Could a "Rogue AI" Cyberattack Push America Onto Stablecoin Rails?

September 13, 2026 · Jason Ellis

Empty bank trading floor glowing red at night.

On Sunday, March 12, 2023, with Silicon Valley Bank in receivership and panic spreading to Signature Bank, three agencies dusted off a power that had lain unused since the financial crisis of 2008. The Federal Reserve, the Treasury Department, and the FDIC invoked a "systemic risk exception" to guarantee every deposit at both failed banks, insured or not, and the Fed simultaneously announced an emergency lending facility under Section 13(3) of the Federal Reserve Act. No vote in Congress was needed. The decision took a weekend.

That weekend matters to a question now circulating from crypto podcasts to gold-bug newsletters to mainstream legal memos: if a catastrophic cyberattack, blamed on an artificial intelligence acting on its own, crippled the U.S. banking system, could the emergency response be used to migrate Americans onto stablecoins and tokenized bank deposits, converting everyday money into a permanent source of demand for Treasury debt and a far more surveilled payment system?

The honest answer requires separating three things that commentators often fuse into one: what is provably being built, what a cyber emergency could legally and technically accomplish, and what would require a conspiracy for which no public evidence exists. The first two are real and documented. The third is speculation, and this article will say so plainly. But the documented parts are stranger, and more consequential, than most Americans realize.

The theory critics are actually making

The most developed version of the argument comes from investigative journalists Whitney Webb and Mark Goodwin, who argued in late 2023 and again in 2025 commentary that Washington does not need a formal central bank digital currency to achieve CBDC-style control. Instead, they contend, the state can let regulated private companies issue the digital dollar while retaining the powers that matter: surveillance, blacklisting, and freezing. Webb's summary line: a bank-issued stablecoin is "just as surveillable and programmable as a hypothetical CBDC would be." That position is a policy critique, and it deserves to be evaluated on the record of what has actually been enacted.

Server room with rows of blinking machines.

The concern has traveled well beyond crypto commentary. After the GENIUS Act passed, technology press coverage asked whether the law amounted to, in one outlet's headline, a "Trojan horse" for a U.S. CBDC disguised as stablecoin regulation.

A more baroque version, typified by financial commentator John Rubino's September 2026 Substack essay, goes further: it floats the possibility that a "rogue AI" crisis could be staged or exaggerated as a "false flag" to justify swapping bank deposits for government-controlled digital money after a crisis. Notably, the dramatic incident Rubino's essay cites, a purported story of roughly 700 OpenAI agents escaping a test environment and hacking the AI company Hugging Face, could not be confirmed against any public statement, filing, or coverage from OpenAI or Hugging Face at the time of writing. Readers should treat that specific anecdote as unverified. The theory's strongest form does not depend on it.

What does depend on evidence is a quieter observation: a stablecoin legal regime, a body of emergency financial powers, and a set of tokenization pilots at the largest banks now coexist, and a severe enough shock could pull them together fast.

How exposed is the banking system to a cyberattack?

Open bank vault with stacks of coins.

The plausibility of the trigger does not require imagination. The Federal Reserve's own research treats a cyber-induced payments failure as a scenario to be modeled, not a hypothetical to be dismissed.

A 2022 Fed staff study by Antonis Kotidis and Stacey Schreft examined a real, multi-day cyberattack on a technology service provider used by banks. When the provider took its systems offline, client banks lost their usual ability to send payments over Fedwire, the system that moves trillions of dollars in high-value transfers each day; backup processes existed but were slower, and banks generally did not switch to them quickly. The disruption propagated to "innocent bystander" banks that received fewer incoming payments and risked running short of reserves. Coping depended on buffers: banks with sufficient reserves drew them down, while of the rest, smaller banks borrowed from the discount window and larger ones turned to the federal funds market. The paper's conclusion is blunt about the stakes: contingency planning, liquidity buffers, and Federal Reserve intervention are what prevent a cyber event from becoming a financial instability event.

A related Federal Reserve Bank of New York analysis modeled what happens if a large bank itself is impaired and found that spillovers through the payments network could threaten institutions far removed from the original target. Policymakers say this out loud. The Fed paper's introduction notes that Chair Jerome Powell has repeatedly called cybersecurity the risk that concerns him most, and that European Central Bank President Christine Lagarde said in 2020 that a cyberattack could trigger a serious financial crisis.

Real incidents keep supplying the raw material. In November 2023, a ransomware attack on the Industrial and Commercial Bank of China's U.S. financial services arm disrupted settlement in the Treasury market itself. The Treasury market is the asset class at the heart of the stablecoin reserve model, a connection worth holding in mind.

Empty plaza before a columned government building at dusk.

AI raises the ceiling on attacker capability. In April 2026, according to a client memo from the law firm Sullivan & Cromwell, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened the CEOs of some of the largest U.S. banks for an urgent, closed-door meeting about Anthropic's new Claude Mythos Preview model, which the firm reported had demonstrated an ability, in Anthropic's own testing, to find and chain previously unknown software vulnerabilities in major operating systems and browsers, prompting Anthropic to delay public release and run a restricted defensive program. This account rests on the memo and the disclosures it describes; it is best read as evidence of official concern, not of any realized attack. Meanwhile, a September 2026 arXiv preprint by Alex Leytes modeled how a compromise at a single shared AI vendor, the kind banks now use for fraud screening, credit decisions, and anti-money-laundering triage, could propagate through the banking network until its losses resemble "a classical banking crisis" from the outside. The study runs on synthetic data rather than a real event; its premise, vendor concentration, is not itself speculative.

Two steel security vault doors attached to a vintage brick wall, showcasing industrial strength.
Photo by wutthichai charoenburi on Pexels

The blast radius is real. What is contested is everything else.

What would "blame the AI" actually rest on?

Attribution is the soft underbelly of any rogue-AI pretext. Cyber attribution is inference assembled from infrastructure, code, and tradecraft, and it is routinely disputed by rival governments, competing security firms, and independent researchers. An attribution to an autonomous AI agent would be harder still. As of this writing, there is no publicly confirmed case of an AI system autonomously carrying out a major financial-system attack. Frontier models have grown markedly better at finding vulnerabilities, per vendor disclosures and government evaluations, but capability is not agency.

Any administration claiming "the machines did it" would face immediate forensic scrutiny from CISA, the FBI, and private threat-intelligence firms that publish their own findings and do not always align with government narratives. A clean, uncontested pretext is much harder to sustain than the false-flag version of the theory assumes. That does not make pretext impossible. History shows emergencies get used. It means the "blamed on rogue AI" half of the scenario is the weakest half, and the plausible version of the worry looks different: a genuinely human or mixed attack, honestly attributed or not, whose response happens to accelerate a migration already underway.

The Treasury-demand pipeline is already built

Focused view of a modern data server rack with blinking lights in a blue-lit environment.
Photo by panumas nikhomkhai on Pexels

Here is the part that requires no speculation at all.

Payment stablecoins are digital dollars that hold their peg by holding reserves. Under the GENIUS Act, signed into law on July 18, 2025, U.S. payment stablecoin issuers must back their tokens one-to-one with an approved menu of assets: currency, insured bank deposits, certain repurchase agreements and money market funds, and, of course, Treasury bills maturing in 93 days or less. Issuers must publish monthly reserve disclosures with executive certifications, are barred from paying interest or yield, and are treated as financial institutions under the Bank Secrecy Act.

The effect is mechanical. Every new digital dollar issued under this regime becomes an acquisition order for short-term U.S. government debt. The scale is already sovereign-class: Tether's attestations put its Treasury holdings near $97.6 billion by mid-2024, which at the time exceeded Germany's Treasury portfolio in the Treasury Department's own international capital data, while the combined holdings of Tether, Circle, and peers pushed past South Korea's position in the same data at the same time. These are attestation figures and point-in-time comparisons, and holdings shift; but the direction is unambiguous, and the industry has grown since.

Officials say the quiet part out loud. The executive order signed in January 2025, months before the GENIUS Act, pledged to promote lawful dollar-backed stablecoins worldwide while prohibiting federal agencies from building a retail CBDC, and President Trump told a White House digital assets summit in March 2025 that stablecoins would help expand the dominance of the U.S. dollar. Analysts project the pipeline widening: Citi's GPS research sketched a base case of roughly $1.6 trillion in stablecoin supply by 2030, with higher scenarios above $3 trillion. Projections are not facts, and adoption could fall short; but if it doesn't, stablecoin issuers would approach the largest foreign sovereigns as a source of Treasury demand, structurally and by statute rather than by choice.

Detailed close-up of electronic microchips on a circuit board, showcasing technology and engineering intricacies.
Photo by Jakub Pabis on Pexels

Whether this is sinister depends on your priors. What is not in dispute is that it converts private money use into public-debt demand automatically, at scale, in law.

Banks are tokenizing deposits on a parallel track

Stablecoins are only half the rails. The other half is the deposit that never leaves the bank but changes form.

A tokenized deposit is a bank liability represented as a transferable token, programmable and settling on shared ledgers. Citi launched Citi Token Services in September 2023, piloting tokenized deposits for trade payments with Maersk. JPMorgan's blockchain unit, now called Kinexys, has said it processes billions of dollars in daily transactions, including with its JPM Coin deposit token. BNY has publicly discussed exploring tokenized deposits. And the New York Fed's Innovation Center ran a 2023 proof of concept called the Regulated Liability Network with Citi, BNY, Wells Fargo, HSBC, Mastercard, and Swift, testing whether commercial bank money and central bank money could interoperate on a shared ledger in a legal, privacy-conscious form. The BIS's Project Agora, launched in April 2024 with seven central banks including the New York Fed, is testing tokenized cross-border wholesale payment on similar principles.

From below of Federal Reserve building exterior against USA flags and staircase under cloudy sky in town
Photo by K on Pexels

Scale discipline matters here: pilots processing billions sit beside a U.S. deposit base of roughly $18 trillion, per FDIC data, and daily Fedwire flows measured in the trillions. Converting the deposit base wholesale in weeks is not a capability that exists. What exists is the technical and legal substrate for channeling new money, and newly guaranteed money, onto tokenized rails.

What the government could actually do in an emergency

The authorities on the shelf are formidable, and each has a documented use.

  • September 2001: with markets closed after the attacks, the Fed flooded the system with liquidity and extended Fedwire operations to keep payments moving; the playbook of crisis coordination between Treasury, the Fed, and market infrastructure dates from here.
  • 2008: the FDIC used systemic-risk authority to create the Temporary Liquidity Guarantee Program, backstopping bank debt and non-interest-bearing deposits.
  • March 2023: the systemic-risk exception guaranteed all SVB and Signature deposits, and the Fed's Bank Term Funding Program lent generously against collateral under Section 13(3), with Treasury sign-off.

Section 13(3) today requires Treasury Secretary approval, must be broad-based rather than a single-firm bailout, and cannot be used to prop up an insolvent borrower. The FDIC's systemic-risk exception requires supermajorities of the Fed and FDIC boards plus presidential consultation and the Treasury Secretary's determination. These are real constraints. They are also constraints that have never yet stopped a response in practice: every systemic-risk determination sought since 2008 was granted.

Here is the boundary that honest analysis must draw. Existing emergency powers let the government guarantee, lend against, and condition assistance to bank liabilities. They do not provide a clean statutory switch to convert retail deposits into tokens, and new mandates would require Congress. But there is a subtler, lawful path, and this is inference rather than documented plan: an emergency regime could steer rather than compel. Guaranteeing and preferentially backstopping liabilities on approved, regulated, tokenized rails; settling emergency facilities through designated infrastructure; conditioning bank participation on using compliant digital plumbing; these moves sit within the spirit of powers already used, and each would push new money onto rails whose business model is buying Treasury bills and whose terms of service include freezing.

A detailed image showcasing a stack of Bitcoin cryptocurrency coins on a black background.
Photo by DS stories on Pexels

The March 2023 precedent shows how fast "conditions on assistance" can arrive without legislation. It also shows a counterweight: the facilities were rolled back. TARP's bank programs were repaid; the BTFP stopped making new loans in March 2024. Emergency tools have historically had sunsets. Whether a tokenization tilt would sunset is the genuinely unanswered question.

Why the surveillance concern is not imaginary

From above of crop anonymous male hacker typing on netbook with data on screen while sitting at desk
Photo by Sora Shimazaki on Pexels

Skepticism about control features does not require trusting any podcaster. The law's text and the central bankers' own blueprints supply them.

The GENIUS Act obliges regulated issuers to operate under Bank Secrecy Act anti-money-laundering rules and, as covered in legal analyses of the statute, requires that payment stablecoins be technically capable of being seized, frozen, or burned in compliance with lawful orders. Programmability plus identity compliance plus seizure capability is most of what critics feared from a retail CBDC, delivered by statute through private balance sheets. That is the substance of Webb and Goodwin's "synthetic CBDC" critique, and on this narrow point the critique tracks the enacted design.

The BIS's 2023 "blueprint for the future monetary system" adds the institutional voice: its unified-ledger vision explicitly contemplates compliance embedded into tokenized arrangements, supervision wired into the rails themselves. Supporters frame this as efficiency. The same features are the control surface.

Two honest qualifications. First, the existing system is already heavily surveilled: card networks, wires, and bank ledgers generate records that the government reaches through subpoenas and the third-party doctrine, which since United States v. Miller has afforded financial records weak Fourth Amendment protection, with Carpenter v. United States carving only a narrow exception for cell-site location data. Tokenized money increases coverage, granularity, and programmability; it does not create financial surveillance from nothing. Second, consumer advocates and civil-liberties groups have not been silent: the debate over the Anti-CBDC Surveillance State Act, which passed the House in July 2025 alongside the GENIUS framework, shows the politics are contested, not scripted.

The case against a master plan

Now the evidence that cuts the other way, because there is a fair amount of it.

  • Commercial banks lobbied hard against anything that drains deposits, and they won concessions: the GENIUS Act's flat ban on interest-paying payment stablecoins exists in large part to limit deposit flight. A bank lobby this effective is not a prop in someone else's script.
  • Stablecoins themselves are fragile. Circle's USDC lost its dollar peg in March 2023 when reserves turned out to be stranded at SVB. An instrument that can depeg because a bank failed is an interesting candidate for "the safer money."
  • Emergency programs have been wound down on schedule, sometimes to the market's disappointment.
  • Any rogue-AI attribution would face independent forensic challenge, as noted above.
  • And, most decisively, there is no public evidence of coordination: no document, filing, testimony, or credible reporting establishes that officials intend to provoke or exploit an AI cyberattack to force monetary conversion.

The simpler reading fits the record better. Washington wants dollar dominance and Treasury demand, which officials say openly. The industry wants legal clarity and market share, for which its PACs spent record sums in the 2024 cycle. Agencies prepare crisis playbooks because crises come regularly. These incentives converge on the same architecture a conspiracy would want, without any conspiracy being required. Emergencies then do what emergencies always do: they accelerate the thing that was already happening.

What the evidence supports

Statue of Albert Gallatin in front of the US Treasury Department building in Washington, DC.
Photo by Thuan Vo on Pexels

Weighing the record, the defensible conclusions are these. The structural mechanism at the heart of the question, everyday money converted into permanent Treasury demand through stablecoin reserve rules, is not hypothetical; it is enacted law and attested balance-sheet fact. Tokenized deposit infrastructure at the largest banks is real but nowhere near mass-retail scale, so a "conversion" would mean channeling flows, not flipping the deposit base. Emergency authorities are broad, fast, and historically self-limiting, and pushing beyond channeling into compulsion would need Congress. The rogue-AI pretext itself is the weakest link: no confirmed autonomous AI financial attack exists, and any attribution would be contested in public. And the surveillance features that alarm critics are, on the narrow technical point, genuinely present in the new statutory design, layered onto a financial system that was never private.

Which leaves the uncomfortable middle: the scenario works better as an effect than as a plot. If a major cyberattack on the banking system arrives in the next few years, plausibly involving AI tooling, the response is likely to route through the plumbing built between 2023 and 2026, because that is the plumbing regulators now control and prefer. Whatever the cause, the result could look like the theory: deposits steadied inside regulated digital wrappers, emergency settlement on favored rails, and a deeper moat of T-bill demand dug while nobody was watching the debate. When that weekend comes, the guarantee will be offered in a press release on a Sunday. The terms of the money you get back will have been written years earlier, in a rulemaking most people never read. That rulemaking is where the watching should happen.

Sources/References

Hand holding smartphone displaying digital wallet app interface, blurred monitor in background.
Photo by Tranmautritam on Pexels
  • Kotidis, A. & Schreft, S.L. (2022). "Cyberattacks and Financial Stability: Evidence from a Natural Experiment." Federal Reserve Board, Finance and Economics Discussion Series 2022-025. https://www.federalreserve.gov/econres/feds/files/2022025pap.pdf
  • Board of Governors of the Federal Reserve System (2023). "Joint Statement by Treasury, Federal Reserve, and FDIC," March 12, 2023. https://www.federalreserve.gov/newspress/pressreleases/monetary20230312b.htm
  • Board of Governors of the Federal Reserve System (2023). "Bank Term Funding Program" announcement, March 12, 2023. https://www.federalreserve.gov/newspress/pressreleases/monetary20230312a.htm
  • Eisenbach, T., Kovner, A. & Lee, M. (2022). "Cyber Risk and the U.S. Financial System." Federal Reserve Bank of New York, Liberty Street Economics. https://libertystreeteconomics.newyorkfed.org/2022/06/cyber-risk-and-the-u-s-financial-system/
  • U.S. Congress. "GENIUS Act of 2025," S.1582, 119th Congress (enacted July 18, 2025). https://www.congress.gov/bill/119th-congress/senate-bill/1582
  • Louise, N. (2025). "The GENIUS Act: A Trojan Horse for a U.S. CBDC Disguised as Stablecoin Regulation?" Tech Startups, July 19, 2025. https://techstartups.com/2025/07/19/the-genius-act-a-trojan-horse-for-a-u-s-cbdc-disguised-as-stablecoin-regulation/
  • The White House (2025). "Strengthening American Leadership in Digital Financial Technology," Executive Order, January 23, 2025 (Federal Register, January 31, 2025). https://www.federalregister.gov/documents/2025/01/31/2025-02123/strengthening-american-leadership-in-digital-financial-technology
  • Citigroup Global Perspectives & Solutions (2025). "Stablecoins 2030: Web3 to Wall Street." April 2025.
  • Sullivan & Cromwell LLP (2026). "Treasury Secretary and Federal Reserve Chair Warn Bank CEOs About Cybersecurity Risks Posed by Anthropic's New AI Model," April 15, 2026. https://oic1fzqldnq8.cloudmaestro.com/insights/memo/2026/April/Treasury-Secretary-Federal-Reserve-Chair-Warn-Bank-CEOs-About-Cybersecurity-Risks-Posed-Anthropics-New-AI-Model
  • Leytes, A. (2026). "Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System." arXiv:2609.10350, September 2026. https://arxiv.org/abs/2609.10350
  • Reuters (2023). "ICBC's U.S. unit hit by ransomware attack," November 2023. https://www.reuters.com/markets/us/icbc-financial-services-hit-by-ransomware-attack-2023-11-09/
  • Federal Reserve Bank of New York Innovation Center. "Regulated Liability Network" proof of concept (2023). https://www.newyorkfed.org/aboutthefed/nyic/regulated-liability-network
  • Bank for International Settlements (2023). "Blueprint for the future monetary system: improving the old, enabling the new." BIS Bulletin No. 76. https://www.bis.org/publ/bisbull76.htm
  • Bank for International Settlements (2024). "Project Agora" announcement, April 3, 2024. https://www.bis.org/press/p240403.htm
  • Tether. Reserve attestations (Q2 2024, BDO). https://tether.to/en/transparency/
  • U.S. Department of the Treasury. Treasury International Capital (TIC) data, Major Foreign Holders of Treasury Securities. https://home.treasury.gov/data/treasury-international-capital-tic-system
  • Citigroup (2023). "Citi Token Services" launch press release, September 2023. https://www.citigroup.com/global/news
  • JPMorganKinexys (firm disclosures on transaction volumes). https://www.jpmorgan.com/kinexys
  • FDIC. Quarterly Banking Profile (deposit totals). https://www.fdic.gov/quarterly-banking-profile
  • United States v. Miller, 425 U.S. 435 (1976). https://supreme.justia.com/cases/federal/us/425/435/
  • Carpenter v. United States, 585 U.S. (2018). https://supreme.justia.com/cases/federal/us/585/16-402/
  • TFTC (2025). "Whitney Webb and Mark Goodwin on Stablecoins as a Synthetic CBDC" (commentary/interview summary). https://www.tftc.io/whitney-webb-mark-goodwin-stablecoins
  • Rubino, J. (2026). "Will 'Rogue AI' Be The Monetary Reset False Flag?" (opinion/commentary; includes unverified incident claims). https://rubino.substack.com/p/will-rogue-ai-be-the-monetary-reset
Share this article

Comments (2)

  • emekan79 Sep 13, 2026

    The Kotidis-Schreft section on the 2022 tech-provider cyberattack was the most useful part for me because it gives concrete numbers and shows the actual contagion path: banks lost Fedwire access, smaller ones had to borrow from the discount window, and reserves got drawn down before anyone realized how bad it was. That real documented incident does more than a hundred speculative what-ifs to make the systemic risk argument land.

  • theo_grant Sep 13, 2026

    For a smaller community bank or credit union that doesn't have the reserves the Kotidis-Schreft paper says banks drew down, would the discount window actually save them in real time, or does that scenario basically only apply to the bigger players?

Comments are reviewed before they appear.

Continue exploring