The Plant · Essay 01 of 04 · 7 October 2026
The rooms and the watts.
A token is an entry in a machine. The machine sits in a building. The building needs power, water, cooling and a fence.
None of this is controversial, and almost none of it appears in the way tokenised money is discussed. The prevailing vocabulary is one of abstraction: ledgers, networks, rails, layers, protocols. These words describe the logic of the system correctly. They also relocate it, so that the reader comes away with the impression that a token exists somewhere other than a place. It does not. Every token that has ever settled a payment or recorded a transfer of title was, at the moment of settlement, a change in the state of memory inside a machine, and that machine was in a room with a postal address.
Cash Leg asked whether the token still substitutes for its twin. The test sat on eight fields: twin, title, cash leg, clock, pledge, exit, crowd, basis. Those fields assume a plant. If the plant is dark, exit, clock and cash leg are not market variables. They are unavailable. This series asks what has to exist in the world before that test can even be run. The method is the same. Sit with a real plant, then write the shape. One object a week. No product tours, no protocol wars, no valuations.
The first object is the simplest and the least discussed. It is the hall.
The word is chosen deliberately. A hall is a large enclosed room that people do not usually enter. In the data-centre trade it is the data hall: the white-floored, windowless space where the racks stand in rows. The essay visits three kinds of hall. The first belongs to a bank or a financial market infrastructure, where a tokenised deposit or a settlement asset is, in the strict sense, a managed database inside an estate the regulator already knows. The second belongs to a public chain, where the claim of decentralisation meets the question of who owns the building. The third is industrial: the warehouse beside a substation that began life hosting a proof-of-work network and is now being reconsidered as something else. That third hall is the most instructive, because its conversion shows what the asset actually was all along.
The essay is not an energy-moral argument. It does not ask whether a given network uses too much electricity, or whether the electricity is clean. Those are legitimate questions and they belong to other essays. The question here is narrower and more structural: what must be physically true, continuously, for the entry in the machine to mean something?
A reader who has followed tokenised markets through 2025 and 2026 has been offered a sequence of abstractions, each of them accurate and each of them incomplete.
A ledger is a rule for ordering entries. A network is a set of machines that apply the rule. A rail is a path by which value is supposed to move. A layer is a place in a stack diagram. A protocol is the text that tells the machines what to do. None of these words has a postcode. That is their use, and it is also their defect. They let a discussion of substitution proceed as if the only things that can fail are legal things: a statute, a cap, a redemption window, a pledge eligibility list. Cash Leg showed that those failures are real. They are not the first failures.
The first failure is older. It is the failure of a feed, a generator, a chiller, a landlord, or a region. The abstraction does not deny this. It files it under "operations" and moves on. Operations is where the token lives.
There is a second hiding, and it is more precise. Public-chain writing treats "the network" as if it were one object. It is at least two. On Ethereum after the Merge, the economic security is a validator set: on the order of 890,000 validators, each a stake and a key, not a building. The physical continuity is a node set: the machines that actually store the chain, gossip blocks and serve the applications. Cambridge's Centre for Alternative Finance, in a bottom-up audit published in July 2026, counted about 8,522 discoverable full nodes, against roughly 894,000 validators.1 A validator can be one process among many on a hosted machine. A node is the machine. When this essay says "the hall," it means the second object. Confusing the two is how a large validator count is made to stand in for a large number of buildings. It does not.

| Layer | What it is | What fails it |
|---|---|---|
| Claim | The token, as a balance or a title the holder believes they have | A redemption window, a cap, a freeze |
| Record | The ledger entry that says so | A client bug, a fork, a gateway that cannot see the chain |
| Machine | CPU, memory, disk, NIC, signing box | A rack, a failed PSU, a full disk |
| Hall | Cage, cooling, UPS, generators, fence | A bad transfer switch, a fuel batch, a landlord |
| Outside the fence | Grid, water main, fibre, jurisdiction | A feeder trip, a curtailment order, a seizure |
The rest of the essay walks the bottom three rows. The top two are Cash Leg's subject. They are not independent of the bottom three.
Start with the room that most closely resembles what people imagine when they say "the system": the hall in which a regulated institution runs the infrastructure for settlement.
Approach it the way a visitor would. There is a perimeter first. In a facility of the Equinix NY4 or LD4 type, the first thing is not a door but a boundary: fencing, bollards rated to stop a vehicle, a gatehouse, cameras with overlapping fields of view. NY4 sits at 755 Secaucus Road, in a flat industrial district a short distance across the Hudson from Manhattan, in the same cluster of buildings that has long served as the physical home of American electronic trading. Public facility directories put the building in the range of roughly 150,000 square feet of colocation space and an IT load in the tens of megawatts; one directory prints 31 MW and another prints 18 MW, which is a reminder that landlord figures are marketing until they are metered.2 LD4 is at 2 Buckingham Avenue, Slough, west of London, in a belt of business parks that sits near major fibre routes. One directory prints about 21 MW and about 145,000 square feet.3 Neither address would appear on a tourist map. Both are, for the purposes of modern financial markets, central.
Inside the perimeter, the visitor passes through a sequence of controlled spaces: reception, an identity check against a pre-registered list, a mantrap in which only one door can be open at a time, and then the corridor to a specific cage or suite. A cage is a literal one, a mesh enclosure bolted to the floor, and it is the unit of tenancy. The institution's machines are in the cage. The building, the power and the cooling belong to the landlord.
Then the hall itself. It is cold, loud, and surprisingly empty of people. Racks stand in rows with the fronts facing each other across a cold aisle, where conditioned air is delivered at floor level, while the backs face a hot aisle, where the exhaust is captured and returned. A rack in an ordinary enterprise installation might draw somewhere between five and fifteen kilowatts. A rack built for current accelerated computing draws several times that, often forty to more than a hundred kilowatts, which is why the conversion discussed in section V is a rebuild and not a relabelling. Multiply by the number of racks in a hall, and a single room can draw several megawatts. A continuous megawatt is, roughly, the average demand of on the order of a thousand households. The comparison is only a scale. The hall is not a household. It cannot shrug.
The electricity does not simply arrive. It comes from a utility substation on a primary feed, ideally two feeds from two separate substations, so that the failure of one is not the failure of the building. Inside the facility it passes through transformers and switchgear, then to uninterruptible power supplies: banks of batteries, or in some designs flywheels, whose job is not to run the hall but to carry it for the minutes between a grid failure and the moment the generators take over. The generators stand outside, in a row, each the size of a shipping container, each fed from a day tank and a larger bulk store of diesel. Facilities of this class typically hold enough fuel for a day or two of full load, and hold contracts with fuel suppliers for resupply during a prolonged outage. The existence of those contracts is as much a part of the plant as the tanks.

Power is only half the problem. Almost every watt delivered to a server becomes a watt of heat that must be removed. The cooling plant, usually on the roof or beside the building, consists of chillers, pumps and, in many designs, cooling towers that evaporate water to reject heat. Where the design is evaporative, the hall has a second utility and a second contract. That water arrives by a municipal main, which is another feed, another point of dependency, and another entity whose outage is the hall's outage.
Power distribution is described as A/B or 2N: each rack receives two independent power paths, so that servers with dual power supplies survive the loss of either. The industry grades this resilience in tiers. A financial tenant will usually insist on the upper end. But resilience is a gradient, not a state. A facility designed for concurrent maintainability can still lose power through a coincident failure, a bad automatic transfer switch, a contaminated fuel batch, or a human error during maintenance. The history of the industry is a library of post-incident reports written in the same dry vocabulary: a breaker that did not open, a generator that did not start, a control system that did what it was told.
What, then, is in the cage? In a conventional institution, the machines run the institution's own ledger, the system of record for balances. When a bank speaks of a tokenised deposit, or a deposit token, the object is, in the first instance, a representation of a liability that already lives in this ledger, issued in a form that can move on a shared, programmable platform. JPMorgan's Kinexys is the best-known example: a permissioned system through which the bank's institutional clients move value that corresponds to deposits at the bank. Company-attributed figures put cumulative volume above $3 trillion and average daily volume above $5 billion as of December 2025; later prints in 2026 have put the cumulative above $4 trillion and the daily run-rate nearer $7 billion, including after the addition of Asia-Pacific currencies to the deposit-account set.4 This essay treats those as company figures, not as a census, and notes that they move. JPMD, the dollar deposit token, reached institutional clients on Coinbase's Base network in November 2025 and was announced for native issuance on Canton through 2026. The bank has described the platform and its volumes at length. It has not, as far as the public record shows, published a gazetteer of the buildings that host its nodes. It would be odd if it had. Location is a security matter.
What can be said, without guessing at addresses, is narrower and sufficient. A permissioned network is a set of machines operated by named institutions, in named jurisdictions, in buildings of the kind just described, under contracts with landlords of the kind just described. Its resilience is bounded by that of the least resilient site it depends upon for finality. The token does not know this. The holder finds out when the site is the one that failed.
The same applies, with variations, to the market infrastructures. Securities depositories and clearing houses such as SIX in Switzerland or DTCC in the United States operate their own primary and secondary sites, often in separate regions, with replication between them. They are among the most carefully engineered facilities in finance, because the regulatory expectation is explicit. Principle 17 of the CPMI-IOSCO Principles for Financial Market Infrastructures requires a business-continuity plan designed so that critical IT systems can resume operations within two hours following disruptive events, and so that the FMI can complete settlement by the end of the day even in extreme circumstances. The secondary site is supposed to sit at a geographical distance sufficient to give it a distinct risk profile.5 When such an institution launches a tokenised or digital-asset service, as SIX has done through SDX, the new service inherits this regime. It runs in the same estate, under the same continuity obligations. It does not inherit a new physics.
This is the first and most important observation about the bank hall. Tokenisation within a regulated institution does not remove the building from the picture. It adds a layer of software on top of a building that was already doing a hard job, and it takes on the building's obligations and its failure modes. The dual feed, the diesel, the chillers and the fence were there before the token. The token's availability is their availability.
There is a second observation, and Cash Leg already prepared it. A deposit token is not a public cash token and it is not a note in a drawer. It is a liability of a named bank, written so that it can move among approved clients. When the hall is dark, the liability has not been extinguished. It has become unusable for the interval of the outage, on the same terms as the deposit it represents. The token does not improve on the deposit's continuity. It copies it.
The second hall is harder to find, because the claim made on its behalf is that it does not exist.
A public blockchain such as Ethereum is described as decentralised: no single party operates it, and no single failure can stop it. That description is a statement about governance and protocol design, and at that level it is substantially true. The software specifies how independent nodes agree on a shared state. No central operator holds the key. If one node vanishes, the others continue.
But a node is a computer, and a computer is somewhere. The question the essay puts is not whether the protocol is decentralised. It is where the machines are, and whether their failures are independent.
Crawls of the Ethereum peer-to-peer network have repeatedly produced an uncomfortable answer. The Cambridge audit, using a bottom-up count of discoverable full nodes as of its 2026 fieldwork, is the cleanest recent one. Of about 8,522 nodes, roughly 64 per cent sit in cloud or enterprise hosting. About 36 per cent run on residential connections. The home nodes are the ones the decentralisation story would have predicted would be the majority. They are the minority. The three largest named landlords (Hetzner, Amazon Web Services and OVH) together host about 40 per cent of the total node count, on the order of 15, 13 and 12 per cent respectively. The country map is the cloud map: the United States 31 per cent, Germany 16, Finland 8, France 6. Those four countries hold about 62 per cent of discoverable full nodes.1

| Cut | Share | What it is |
|---|---|---|
| Discoverable full nodes | ~8,522 | Machines that store and serve the chain |
| Validators | ~894,000 | Stakes and keys; many per machine |
| Cloud or enterprise hosting | ~64% | A landlord, a contract, a region |
| Residential | ~36% | The minority the story assumes is the majority |
| Hetzner | ~15% | German host; Falkenstein, Nuremberg, Helsinki |
| Amazon Web Services | ~13% | Largest cloud; terms and regions are policy |
| OVH | ~12% | French host; Roubaix and elsewhere |
| United States | 31% | Largest single jurisdiction |
| Germany | 16% | Second |
| Finland | 8% | Third |
| France | 6% | Fourth |
| Those four countries | ~62% | The actual map |
| Continuous power, post-Merge | ~0.90 MW | About 7.87 GWh a year; ~105 W per node |
Two cautions belong next to the table, because the wrong reading is easy.
The first is methodological. A crawl sees the nodes that answer. It does not see every validator, and it does not see stake. Thirty-one per cent of discoverable nodes in the United States is not thirty-one per cent of economic security. Hosting concentration and stake concentration are related and they are not the same number. The essay uses the node map as a map of buildings, not as a map of voting power.
The second is about finality, and it is the reason the buildings still matter. Ethereum finalises a checkpoint when votes representing at least two-thirds of stake have been collected, twice, under Casper FFG. If participation falls below that line, checkpoints stop finalising. If the failure to finalise persists beyond a set number of epochs, an inactivity leak begins to bleed the stake of validators who are not attesting, until the active set again holds two-thirds of what remains.6 A correlated outage does not have to be a majority of stake to change the market. It has to be large enough, and simultaneous enough, to push the chain off the finality line, or to push the doors to the chain shut while the chain continues. Both have happened. Neither required a cryptographic break.
Why the concentration matters, if the protocol tolerates the loss of individual nodes, is three forms of correlation.
The first is landlord correlation. If a large share of nodes depends on the same provider, then the provider's decisions and failures are shared across them. Providers have terms of service, and terms of service are enforceable. Hetzner is the clean case. On 23 August 2022 the company stated, in a public support thread, that using its products for any application related to mining was not permitted, "even remotely related," and that this included Ethereum, proof of stake, proof of work, and trading. On 2 November 2022 it blocked Solana activity on its servers. More than a thousand Solana validators went offline. Delinquent stake was reported around a fifth to 22 per cent of the network, the highest since May of that year. The chain did not halt. The Solana Foundation began unstaking 28.5 million SOL that its delegation programme had placed with the affected validators.7 The mechanism is the point, not the chain. A policy decision by a landlord removed a slice of capacity at once, regardless of the protocol's design. Hetzner's share of Ethereum hosting has since fallen from the levels discussed in 2022, and by the 2026 Cambridge cut it is about 15 per cent of nodes rather than a dominant share. The fall is itself evidence. Operators moved because a landlord had demonstrated that it could make them move.
The second is technical correlation, and it sits one step in front of the hall. Many applications, and many institutions, do not run their own nodes at all. They reach the chain through a small number of managed gateways, and those gateways run on the same clouds. On 11 November 2020, Infura's Ethereum mainnet API failed at 08:12 UTC. The root cause was not an outage of the chain. Components inside Infura were pinned to older versions of the Go-Ethereum client, including 1.9.9 and 1.9.13, which hit a consensus bug at block 11,234,873. Newer builds, 1.9.19 and later, were unaffected and kept producing blocks. Infura could no longer see the chain its customers were paying it to see. Binance, Bithumb and others halted ether and ERC-20 withdrawals. MetaMask, which defaulted to Infura, failed for a large share of its users. Withdrawals at Binance were restored at about 10:28 UTC. The chain had been healthy throughout.8
The more recent case is the landlord's own region. On 20 October 2025, an AWS us-east-1 failure, beginning in DNS resolution for DynamoDB API endpoints at about 02:51 ET, took down a wide set of customer control planes. Coinbase later wrote that users experienced degraded performance for 3 hours and 17 minutes, with trading unavailable in intervals and transfers, withdrawals and deposits delayed or failed. Robinhood was down for hours. The chain those venues intermediate was not the thing that failed. The doors were.9 A holder that morning had a claim that was intact on a ledger and unusable at the only counter they had.
The third is geographic and grid correlation. A region has a grid. A grid has weather, regulation and, now and then, a bad day. The same is true of the fibre, which the next essay follows out of the building. Subsea and terrestrial routes concentrate in particular corridors. A network that is institutionally borderless turns out, at the level of power and cables, to be anchored in a handful of jurisdictions with cheap or reliable electricity, good fibre and permissive hosting terms. The notion that the network survives anything does not survive a coincident disturbance in a corridor where a large fraction of its capacity happens to live.
Be exact about what this does and does not show. It does not show that the chain is insecure in the cryptographic sense. A transaction, once finalised under the protocol's rules, is not made less final by a data-centre outage. It also does not show that the decentralisation claim is false. The validator set is large, and the protocol has a long record of continuity. The claim is narrower. The physical substrate of a public chain is concentrated, commercial and located, and the properties attributed to "the network" are properties of a protocol running on top of that substrate. Where the substrate is correlated, the protocol's guarantees are conditional on it.
For the purposes of the series, this has a consequence. The usual argument for a token as a substitute for a conventional claim is that it can move without the permission or the presence of the incumbent institutions. That is true at the level of authorisation. At the level of operation, the token's movement depends on a different set of incumbents: hosting companies, utilities and carriers. They are not banks, and they do not hold the asset. They do hold the building in which it is processed. Cash Leg called the American design a wager that dollar dominance could climb onto a ledger through private issuers. The public-chain hall is a different wager: that a protocol can remain a substitute even though its buildings are rented from a short list of firms that can change their terms.
The third hall was not built for finance at all, and it has the clearest lesson to teach.
Consider the class of sites that grew up around proof-of-work mining: very large buildings, often in remote or secondary locations, defined by access to inexpensive electricity. The campus at Rockdale, Texas, is the example with a public footprint. It sits on the former Alcoa aluminium-smelter estate in Milam County, where a power plant and an industrial footprint had left generating and transmission capacity in place. Bitdeer's filings put energised electrical capacity at Rockdale at 563 MW as of 31 March 2026, inside a company-wide fleet of about 1,744 MW across the United States, Norway, Bhutan, Ethiopia and Malaysia. In September 2026 the company acquired about 200 acres adjacent to that site, taking the Rockdale footprint to roughly 255 acres, and described the interconnection as the thing that made further allocation plausible.10
The Nordic and Himalayan sites belong to the same family, and they should not be collapsed into one story. Molde, on the Norwegian coast, was listed at 84 MW and online for crypto, with an early assessment of conversion. Tydal, inland in Norway, is the conversion that has actually been signed: on 4 August 2026 Bitdeer's subsidiary agreed a 16-year colocation lease with Volta covering 121 MW of IT capacity, about 133 MW gross, at an average of about $202 per kilowatt per month, electricity reimbursed, 3 per cent annual escalators. The base term is valued at about $4.7 billion, with an eight-year extension that could take it toward $8 billion. The planned facility is specified for NVIDIA GPUs, with Dell as technology provider, for an unnamed AI laboratory. Operations are targeted in two phases, 31 December 2026 and 31 March 2027, with about $500 million of remaining capital expenditure. Jigmeling in Bhutan was listed at 500 MW and online for crypto in the March filing; a separate letter of intent, not a signed conversion, targets an initial 30 MW AI campus at Gelephu with a pathway that has been described toward 500 MW.11 The names differ. The pattern does not. The asset is the interconnection.
What does one see at such a site? A mining hall is, in physical terms, a more primitive version of the bank hall. The racks are shelves of purpose-built machines, air-cooled with high-volume fans, often in buildings that look more like industrial sheds than data centres. There is little redundancy, because the workload tolerates interruption: if a section goes down, the machines simply do not hash for a while. What the site does have, in quantity, is the thing that is hardest to obtain. A large, firm, grid-connected supply, sitting behind a substation, with the permits and the right to draw it.
Over the past several years a number of these operators have recognised that this is the valuable thing. A graphics-processing cluster for artificial intelligence draws power on the same order as, or well above, a mining hall of the same footprint, and it needs the same two things: power, and somewhere to put it. The conversion is not trivial. The cooling must change, from air to liquid in many designs. The power distribution must be redesigned for far higher density. The resilience expectations are different, because an AI tenant does not accept the interruptions a miner tolerates. But the fundamental asset moves across the boundary intact. It is the interconnection, the substation and the land.
This is why the conversion is evidence and not merely news. It shows what the thing called "the network" consisted of, at least in its proof-of-work form: a warehouse with a substation. The protocol, the hash function and the incentive design were real, and they mattered for what the network could do. The physical asset that gave the network its capacity was an entitlement to draw megawatts at a place, and that entitlement turned out to be fungible with an entirely different use. When the economics of one use deteriorate relative to another, the building does not care which workload it hosts. It hosts whichever pays. A 16-year lease at $202 per kilowatt per month is a price for the entitlement. It is not a price for the hash function.
Two implications follow, and they are the point of the section.
The first is that the security of a proof-of-work chain is, in the end, a function of how much of a scarce physical capacity is committed to it, and that commitment is reversible by the owner of the capacity. Hashrate is not a law of nature. It is a tenancy. When the tenancy is re-let, the chain does not get a vote.
The second is more general, and it binds the industrial hall back to the bank hall and the public-chain hall. The hall is the scarce thing. Algorithms can be copied without limit. Transformer capacity and grid interconnection queues cannot. Anyone who has tried to connect a large new load to a transmission system in recent years knows that the wait is measured in years, and that the queue itself has become a form of property. The campus that already stands behind a live substation holds a position that cannot be quickly replicated. A protocol that assumes it can always rent more buildings is assuming a market in buildings that, at the scale that matters, clears slowly and often does not clear at all.
Set the three side by side and the shared elements are plain.
Figure 3. Three halls, one plant.
| Bank or FMI hall | Public-chain hall | Industrial hall | |
|---|---|---|---|
| What the token is | A liability or a register entry, written so it can move | A state change under a protocol | Capacity first; the workload is reversible |
| Landlord | Colocation operator, or the FMI's own estate | AWS, Hetzner, OVH, and a long tail | The operating company that owns the interconnection |
| What is scarce | Dual feed, recovery site, the two-hour clock | Uncorrelated buildings | Megawatts already energised |
| What the tenant tolerates | Almost nothing; PFMI sets two hours | Single-node loss; not correlated loss | Miner: interruption. AI tenant: not interruption |
| Public map | Addresses of the buildings; not of the nodes | Node crawl; not a stake map | Filings, leases, MW |
| Failure the holder feels | Books unavailable until failover | Chain up, doors shut; or finality stalled | Capacity leaves; difficulty and security follow |
| What tokenisation changed | A software layer on an estate that already existed | The workload, not the landlord | Nothing structural; the lease can change |
Each has a landlord, whether that is a colocation operator, a cloud provider, or the operating company that owns the site. The landlord is a legal person with a contract, an insurer, creditors, and a set of terms that can change. Hetzner changed its terms and then enforced them. Equinix does not need to do anything so dramatic. Its contract already allocates the building, the power and the cooling to itself, and the machines to the tenant.
Each has a grid connection. Beyond the building there is a utility, a feeder, a substation, and a transmission operator whose decisions about curtailment, tariffs and priority apply to the facility like any other large load. In some systems, large flexible loads are paid to switch off when the grid is stressed. That is a sensible arrangement for the grid. It is also a reminder that the hall's operation is subject to a higher claim than its own. A token that presents itself as available at all hours is presenting a property of the protocol, not a property of the feeder.
Each has a postcode, and therefore a jurisdiction. The building sits within a legal order that can inspect it, tax it, license it, seize equipment from it, or order it closed. The decentralisation of a protocol is no immunity against the territorial authority of the place where its machines stand. Cash Leg's map of statutes (GENIUS, the ROAD to Housing bar on a retail public token, Beijing's nationalisation of the primitive) is a map of law. This is the map of where the machines those statutes care about actually sit. The two maps are not the same, and a serious account of substitution has to hold both.
And each has a fence. The fence is not rhetorical. It is the point at which someone decides who may touch the machine, and that decision is made by a person or a company, under law. Inside the fence, the integrity of the entries depends on the integrity of the physical access regime. Outside it, the continuity of the entries depends on the continuity of everything the fence encloses.
These shared elements are not an argument against tokenisation. They are the answer to a question that the abstract vocabulary tends to suppress: what, in the physical world, must remain true for the token to remain a working claim? The answer is a list, and the list is long.
Figure 4. What must remain true, continuously.
| Dependency | Where it sits | What "true" means | How it fails |
|---|---|---|---|
| Two power paths | Inside the fence | A/B or 2N to the rack | One path plus a maintenance error |
| Bridge power | UPS, batteries, flywheel | Minutes, not hours | A string that was not tested |
| Fuel | Day tank, bulk tank, supply contract | A day or two, then resupply | A bad batch; a contract that is paper |
| Heat rejection | Chillers, towers, liquid loop | Every watt in becomes a watt out | A pump, a water main, a design built for air |
| Paths out | Fibre, diverse conduits | Two ways that do not share a trench | The next essay |
| Occupancy | Lease, licence, title | A right to be there | Landlord insolvency, a term, a ban |
| People | The roster | Someone who can reach the site | The fourth essay |
| Law | The postcode | Permission to operate | Inspection, seizure, a closure order |
Each item can be engineered, contracted and insured, and each costs money. The cost of the token's availability is the cost of the hall.
It is worth being precise about what this implies for the claim that tokenisation reduces cost. Settlement can certainly become faster and operationally simpler at the level of messaging and reconciliation. Cash Leg's account of deposit tokens and of capped instant exit is an account of that simplification. The saving at that level does not eliminate the underlying plant. It moves the plant, concentrates it, or duplicates it, since a hybrid world requires both the legacy halls and the new ones to remain live while the transition is under way. A bank that runs a tokenised deposit platform has not retired the ledger it already ran. It runs both. The second set of machines is a cost centre with a postcode, not a saving that appears by calling the balance a token.
Cash Leg uses a single test for any proposed substitution, and it applies here without modification. If the hall goes dark, does the token still do what the thing it replaces would have done?
The status language does not need to be reinvented. Substitutes, when ordinary conditions hold. Watch, when one field is already the weak channel. Does not substitute under stress, when exit, cash, crowd or basis would not survive the stated shock. The shock here is physical. The fields that fail are clock and exit.
Figure 5. The same test, three halls.
| Shock | What still works | What the holder can do | Status |
|---|---|---|---|
| Bank hall dark; generators do not start; secondary site not yet live | The liability still exists on the bank's books | Nothing, until failover. Same as the deposit | Does not substitute for cash in hand. Copies the deposit's outage |
| Bank hall dark; secondary site takes over inside the two-hour window | The FMI or bank design, not the token | Wait, then resume | Watch. The token is a passenger on the recovery plan |
| Cloud region fails; chain keeps finalising | Protocol continuity | Cannot pass the gateway, the exchange, the wallet default | Does not substitute at the counter. The claim is intact and unusable |
| Landlord changes terms and removes a slice of nodes | The chain, if remaining stake can still finalise | Capacity migrates, with a gap | Watch. Correlation is the weak channel |
| Participation falls below two-thirds | The ledger, unfinalised | Wait through an inactivity leak, or do not wait | Does not substitute under stress for anything that needed finality that day |
| Substation behind a mining campus trips, or the lease is re-let | The protocol's adjustment | Wait; security margin is temporarily elsewhere | The workload was a tenancy. The tenancy moved |
Run the cases in prose, because a table can make them look cleaner than they are.
Suppose the bank hall loses power and the generators fail to start. The institution's own ledger is unavailable. Depending on the design, a replica in the secondary site may take over, within the recovery window the regulator requires. That is the point of the secondary site, and Principle 17 is unusually clear about the number: two hours to resume critical IT, and settlement completed by the end of the day even in extreme circumstances.5 Note what substitution means here. The token does not replace the failover. The token depends on it. A deposit token has no existence independent of the bank's books, and the books are in the hall. When the hall is dark and the failover has not yet engaged, the token is as unavailable as the deposit it represents. It does not substitute for cash, which would continue to exist as a note in a wallet, a till or a vault with no electrical dependency. It substitutes, at best, for the deposit, and only on the deposit's terms.
Suppose a major cloud region fails, as us-east-1 did on 20 October 2025. Public-chain nodes in that region drop off. The protocol continues, if enough nodes elsewhere keep producing and validating blocks. The applications that depend on the failed region's gateways cannot reach the chain, and the exchanges and custody providers whose infrastructure lives there cannot process withdrawals. Coinbase's own account of that day is the cleanest: transfers failed or were delayed, and the degraded interval was measured in hours, not in epochs.9 A holder of a token on that day has a claim that is intact on the ledger and unusable in practice. Whether the holder thinks of this as an inconvenience or a failure depends on what the token was meant to replace. If it was meant to replace a cash payment at a counter, the answer is plain. The status is the one Cash Leg already uses for a capped instant exit that is not, on the day, instant. Watch in ordinary weather. Does not substitute under the stated shock.
Suppose a grid event takes down the substation behind a large mining or compute campus, or the owner re-lets the interconnection, as at Tydal. The network that depended on it loses a share of its capacity. In a proof-of-work chain the effect is a drop in the rate at which blocks are produced, a temporary reduction in security margin, and a shift of revenue to the sites that remain. The protocol adjusts. The users, for a time, wait. The conversion case is sterner than the outage case. An outage is temporary. A 16-year lease is a decision that the megawatts have a better tenant. The chain is not consulted.
Across all three cases the structure is the same. The token does not substitute for the thing in the world that requires no hall. It substitutes, at best, for the thing that already required one. Cash in a drawer and a deposit at a bank are not the same in this respect. The former has a continuity that depends on the physical object and on nothing else. The latter depends on a plant whose continuity must be continuously purchased. A token is of the second kind. It lives on the same side of the line as the deposit.
That is not a defect. It is a classification. The tokens under discussion are a new way of recording and moving claims that were already institutional. What the hall teaches is that the place to look for what the token can and cannot replace is in the cost, redundancy and jurisdiction of the building. That is a place the abstraction hides.
The eight fields do not need to be rewritten. They need a floor.
Twin: the token still says it is a deposit, a fund share, a Treasury bill. The twin relationship is a legal and accounting fact. It is also a fact about two halls, or about one hall wearing two interfaces. If the register and the token are in the same estate, a dark hall darkens both. If they are in different estates, a dark hall darkens one, and the basis opens for the interval.
Title: token equals register, or token equals receipt. Either way, the title is an entry. An entry that cannot be read is not, for the holder, a title that day.
Cash leg: unchanged in law, conditional in operation. A deposit token's cash leg is the bank. The bank's cash leg, on the day, is the feed.
Clock: this is the field the hall injures first. Hours, finality, weekend. A chain that keeps producing blocks has not kept the holder's clock. The holder's clock stopped at the gateway. An FMI that resumes in two hours has kept its regulatory clock and missed any use that needed the first hour.
Pledge: a pledge against a token in a dark hall is a pledge against an unavailable object. Eligibility does not survive the outage just because the eligibility list was published.
Exit: the field Cash Leg watches. Primary redemption plus a capped instant path. Both paths are processes in a hall. A cap is a rule. A dark hall is a cap of zero.
Crowd: holder concentration was the September subject. Landlord concentration is the October subject. They compound. A tight holder set, served by a tight gateway set, in a tight region, is one crowd.
Basis: the gap between token and twin. A physical outage opens a basis even when nothing in the terms has changed, because one side of the pair can be touched and the other cannot.
None of this is a reason to abandon the fields. It is a reason to read a print that says "substitutes" as a statement about ordinary conditions in the hall, not as a statement about the token in the abstract.
The hall is the first object because it is the outermost: the shell inside which everything else sits. The walk through it has found a fence, a feed, a generator, a chiller, a cage, a landlord and a postcode.
Inside the hall are the machines, and inside the machines are the entries. Between the building and the entry there is another layer, also physical and also routinely forgotten: the wires, the carriers and the exchange points through which one hall talks to another. A token that cannot reach its counterparty has not settled anything, however well the hall is powered.
The next essay leaves the building and follows the cable.
Next week: Essay 02, The Cable.
Cambridge Centre for Alternative Finance, Ethereum After the Merge: A Change in Power, Cambridge Judge Business School, published 10 July 2026. Bottom-up audit of about 8,522 discoverable full nodes, distinct from about 894,000 validators. Hosting split about 64 per cent cloud or enterprise and 36 per cent residential. Hetzner, AWS and OVH together about 40 per cent of nodes (about 15, 13 and 12 per cent). Country shares: United States 31, Germany 16, Finland 8, France 6, together about 62 per cent. Continuous demand about 0.90 MW; annual consumption about 7.87 GWh; network-weighted average about 105 watts per node. A crawl sees nodes that answer. It is not a census of stake.
Equinix NY4, 755 Secaucus Road, Secaucus, New Jersey. Public facility directories differ on IT load (figures of 18 MW and 31 MW both circulate) and agree on the order of magnitude, the financial-tenant mix, and the campus relationship with NY2, NY3, NY5 and NY6. Treat megawatt prints as directory figures, not as metered load.
Equinix LD4, 2 Buckingham Avenue, Slough. Directory figures of about 21 MW and about 145,000 square feet are used as scale, not as an audited capacity.
Kinexys by J.P. Morgan, company-attributed volume. December 2025 prints: cumulative above $3 trillion, average daily above $5 billion. Later 2026 prints, after further currency additions to the Blockchain Deposit Account set, have put cumulative volume above $4 trillion and average daily volume nearer $7 billion. Gross value processed, not assets under management. JPMD on Base from November 2025; native issuance on Canton announced for a phased 2026 rollout. No public node gazetteer.
CPSS-IOSCO, Principles for Financial Market Infrastructures, April 2012, Principle 17, key consideration 17.6. The business-continuity plan should incorporate a secondary site and should be designed to ensure that critical IT systems can resume operations within two hours following disruptive events, and to enable the FMI to complete settlement by the end of the day even in extreme circumstances. The secondary site should have a distinct risk profile, which in practice means geographical distance. The two-hour figure is an objective for critical IT resumption, not a guarantee that a tokenised service meets it.
Ethereum finality under Gasper / Casper FFG requires two rounds of votes representing at least two-thirds of stake. Failure to finalise beyond the inactivity-leak threshold (on the order of four epochs, about 25 minutes) bleeds non-participating stake until the active set again holds two-thirds of remaining stake. See Ethereum Foundation consensus documentation. Node geography is not stake geography; the threshold is cited so the building correlation has a protocol consequence, not so that 31 per cent of nodes can be read as 31 per cent of stake.
Hetzner Online GmbH, public support statement, 23 August 2022, barring mining "even remotely related," including Ethereum, proof of stake, proof of work, and trading. Enforcement against Solana validators, 2 November 2022: more than 1,000 validators offline; delinquent stake reported around 20 to 22 per cent (RockawayX dashboard, via The Block); Solana Foundation, 9 November 2022, began unstaking 28.5 million SOL from its delegation programme that had been placed with affected validators. The chain did not halt.
Infura status and post-mortem, 11 November 2020. Mainnet API failed at 08:12 UTC. Root cause: components pinned to Geth 1.9.9 and 1.9.13, consensus bug at block 11,234,873. Builds 1.9.19 and later unaffected. Binance restored withdrawals at about 10:28 UTC. MetaMask, Bithumb and others affected. The chain continued.
Amazon Web Services, us-east-1 event, 20 October 2025, beginning about 02:51 ET in DNS resolution for DynamoDB endpoints. Coinbase engineering retrospective, 13 November 2025: degraded customer performance for 3 hours 17 minutes; trading intervals unavailable; transfers, withdrawals and deposits delayed or failed. Robinhood reported a multi-hour outage the same morning. The incident is a door failure, not a chain failure.
Bitdeer Technologies Group, filings and operations updates. Energised capacity at Rockdale 563 MW as of 31 March 2026, inside about 1,744 MW company-wide. September 2026: acquisition of about 200 acres adjacent to the Rockdale site. The site is the former Alcoa smelter estate, Milam County, Texas.
Bitdeer, Tydal Data Center AS lease with Volta Tydal AS, announced 4 August 2026: 121 MW IT, about 133 MW gross, 16-year base term valued at about $4.7 billion, optional eight-year extension toward $8 billion, about $202 per kW per month, 3 per cent escalators, electricity reimbursed. NVIDIA GPUs, Dell as technology provider, unnamed AI laboratory tenant. Target operations 31 December 2026 and 31 March 2027. Molde remains an operating crypto site at 84 MW in the March 2026 footprint. Jigmeling, Bhutan, 500 MW, listed online for crypto in that footprint; the Gelephu AI letter of intent is a separate and non-binding 30 MW starting point. Do not describe Jigmeling as converted.