In the past twelve months, central banks from London to Beijing have picked the deposit token, not the stablecoin, as their preferred form of on-chain money. The pilots share three needs: ledgers that talk to each other, confidentiality for bank data, and ISO 20022 messaging. XDC's enterprise stack was designed around those same three.
What a deposit token is
A deposit token is an ordinary commercial bank deposit recorded on a distributed ledger instead of the bank's internal books. The holder keeps the same claim on the bank, the same deposit protection and the same regulator. What changes is the rail: the money can settle around the clock and move only when a programmed condition is met.
The name comes from a 2023 paper by Oliver Wyman and J.P. Morgan's Onyx unit. Central banks usually say "tokenised deposit". Both terms describe the same instrument.
| Deposit token | Stablecoin | Wholesale CBDC | |
|---|---|---|---|
| Issuer | Licensed commercial bank | Private issuer, often a non-bank | Central bank |
| What the holder owns | A claim on the bank, like any deposit | A claim on the issuer's reserve pool | A claim on the central bank |
| Fits existing bank regulation | Yes, it stays a deposit | Needs its own regime | Yes, it is central bank money |
| Typical user | Bank customers and corporates | Anyone with a wallet | Banks settling with each other |
The three are complementary. In most designs now being tested, banks issue deposit tokens to customers and settle between themselves in central bank money.
What governments and central banks have done in the last 12 months
Six public authorities moved deposit tokens from theory to real money between October 2025 and September 2026. The pattern is consistent: banks issue the token, the central bank supplies the settlement asset.
| Date | Authority | What happened |
|---|---|---|
| 24 Sep 2026 | United Kingdom: UK Finance, backed by the Bank of England | Lloyds, NatWest and Barclays completed two remortgage transactions in tokenised sterling deposits. A second group including HSBC ran a marketplace payment released on delivery. Seven banks are in the Great British Tokenised Deposit project, which plans a rulebook and three digital bonds in Q1 2027. |
| 21 Sep 2026 | Eurosystem: ECB Pontes | Pontes went live so banks can settle tokenised asset trades in central bank money. Thirteen institutions were ready on day one. |
| May to Jul 2026 | BIS Project Agorá with seven central banks | The prototype settled cross-border payments atomically using tokenised deposits and tokenised reserves. In the real-value phase, 22 institutions and five central banks completed 30 transactions worth about CHF 800,000 in six currencies. |
| 1 Jan 2026 | China: People's Bank of China | The e-CNY was reclassified from digital cash to an interest-bearing deposit. Balances became commercial bank liabilities, covered by deposit insurance and reserve requirements. |
| 13 Nov 2025 | Hong Kong: HKMA EnsembleTX | Project Ensemble moved from sandbox to real-value pilot. Banks use tokenised deposits to settle tokenised money market fund trades through 2026, with 24/7 settlement in tokenised central bank money planned. |
| 8 Oct 2025 | India: Reserve Bank of India | RBI began a deposit tokenisation pilot with a few banks, using the wholesale e-rupee as the settlement layer. Its FY26 annual report adds a pilot for tokenised certificates of deposit. |
The policy signal is as important as the transactions. The Bank of England has said it would rather see banks innovate with tokenised deposits than with stablecoins. China, the country with the most advanced retail CBDC, chose to route digital money through bank balance sheets instead of around them.
Three requirements every pilot ran into
Read the pilot reports side by side and the same three engineering problems appear in each.
Ledgers must talk to each other. Banks have run private blockchains for a decade, but each built its own, so tokens could not leave the issuing bank. The UK project matters because it is interbank. Agorá needed one shared ledger for deposits plus a separate ledger per central bank. No single chain will hold every bank and every currency.
Bank data must stay confidential. A bank cannot publish customer balances and payment flows on a public ledger. The Agorá findings state that privacy has to hold at both balance and transaction level, while regulators keep the access they need.
Payments must speak ISO 20022. Swift completed the bulk of its cross-border ISO 20022 migration in November 2025, and the standard now carries the compliance and remittance data banks rely on. Swift's own blockchain ledger, ready for use since 9 July 2026 with 17 banks, keeps that format. On 24 September, IBM released an adapter that lets banks instruct tokenised deposit transfers with standard ISO 20022 messages.
A platform that solves only one of the three cannot carry deposit tokens at scale.
Why XDC's enterprise stack fits
XDC answers each of the three requirements with a dedicated component, on a public Layer 1 that is EVM-compatible and secured by validators that have passed KYC.
Interledger: XIM connects the ledgers banks already use
The XDC Interledger Messaging Protocol (XIM), published in September 2026, is a chain-agnostic protocol for carrying one canonical message across different networks. It targets public chains, permissioned ledgers, institutional networks and authenticated gateways into existing financial systems.
Its key design choice is that verification is set per lane, not once for the whole network. A corridor into a central bank ledger can demand stronger proof than a low-value corridor between two subnets. That matches how deposit tokens will work in practice: bank ledgers, central bank ledgers such as Pontes or the wholesale e-rupee, and Swift will coexist, each with its own trust model.
Privacy layer: transactions stay inside the bank's network
XDC Subnets give a bank or consortium a permissioned chain of its own. Subnet transactions are not visible on the XDC mainnet. A relayer checkpoints the subnet's consensus data to a mainnet smart contract, so the record is tamper-evident without exposing its contents.
XIM extends the same principle across ledgers. Its privacy model is commitment-based: a message carries hashes of the payload, the compliance metadata and the privacy policy, while the underlying data moves only through authorised channels. Counterparties and supervisors see the details. The public network sees a proof.
ISO 20022: the token carries the data banks already produce
XDC's architecture lists ISO 20022 messaging systems as a designed integration point, and XIM names ISO 20022-compatible payment workflows as a target use. The paper describes gateways that take an instruction from an existing financial rail, commit to it without publishing its contents, and route it to XDC or another ledger.
For a bank this means no parallel data model. The payment instruction its systems generate today can drive the token movement, and screening and reconciliation keep working on the same fields.
How the pieces fit
Each bank keeps its ledger private. XIM moves the payment message between banks and into the central bank's ledger, and the mainnet records only checkpoints.
A deposit token payment on XDC, step by step
This is an illustrative flow for a payment from a customer of Bank A to a customer of Bank B, built from the components above.
- Issue. Bank A records the customer's deposit as tokens on its own XDC subnet. The money remains a deposit on Bank A's balance sheet.
- Instruct. The customer orders a payment. Bank A's payment system produces the same ISO 20022 instruction it would send today.
- Commit. Bank A's subnet debits the tokens and emits a XIM message. Only hashed commitments leave the subnet.
- Route. XIM delivers the message to Bank B's ledger under the verification policy set for that lane.
- Credit. Bank B credits its customer with its own deposit tokens, so each customer always holds a claim on their own bank.
- Settle. The two banks settle the interbank position in central bank money, through the RTGS system or a wholesale CBDC.
- Anchor. Both subnets checkpoint to the XDC mainnet, which gives auditors and supervisors one tamper-evident record.
The customer sees a payment that completes in seconds at any hour. The banks keep their data, their compliance process and their message format.
What still has to be proven
The case for XDC is architectural today, and three things have to follow before it is proven in production.
- A live bank pilot. None of the programmes listed above has named XDC as its platform. XIM is a published protocol design, and it needs a regulated institution to run real value across it.
- Central bank connectivity. A deposit token is only as good as its settlement leg. Lanes into systems such as Pontes, the wholesale e-rupee or Hong Kong's tokenised central bank money have to be built and accepted by those operators.
- Legal certainty per jurisdiction. Agorá found settlement finality achievable in all seven participating jurisdictions, but said further work is needed on operational and contractual requirements. The same applies to any new rail.
The direction of travel is settled: regulators want on-chain money to be bank money. The open question is which infrastructure carries it between banks, privately and in a language banks already speak. That is the problem XDC's interledger, privacy layer and ISO 20022 support were built to solve.
Discussion (0)