Government debt issued, serviced, and redeemed as native ledger objects — where the issuer holds the keys and every coupon is a deterministic, auditable event. The primary market and the register become the same system of record.
The bond exists on the sovereign's own ledger from the moment of authorization, with the treasury holding signing authority end to end.
Issuance is authorized by the debt-management office holding its own ML-DSA-65 keys, so the act of creating the security and the legal authority to create it are the same cryptographic event. No external registrar mints on the sovereign's behalf.
Face value, currency, coupon schedule, day-count convention, and maturity are written into the instrument as executable terms rather than a prospectus PDF referenced elsewhere. Servicing reads the same fields the issuer signed.
Primary auctions, reopenings, and taps are recorded as ordered entries in the hash-chained ledger, giving a tamper-evident record of price, size, and allotment. The auction result and the resulting register are one artifact.
Reopened tranches collapse into a single fungible ISIN-equivalent line where economically identical, so secondary liquidity is not fragmented across microscopically different series. The ledger tracks outstanding notional per line without a separate reconciliation.
Debt service becomes a function the ledger executes against a defined record date, not a chain of instructions across correspondent banks.
Each coupon is computed from the encoded schedule and day-count against the holder register snapshot at record date, producing an identical result for every party that verifies it. There is no discretionary interpretation of accrual.
At maturity, redemption of principal and retirement of the security settle in a single atomic operation, so a holder is never left extinguished-but-unpaid or paid-but-still-outstanding. Partial calls and amortizing structures follow the same atomicity.
Tax withholding, gross-up clauses, and jurisdiction-specific treatment can be expressed as servicing logic tied to holder attributes rather than handled off-ledger after payment. The net and gross amounts are both on the record.
The register snapshot that entitles a holder to a coupon is taken at a ledger height, making the ex-date boundary exact and non-repudiable. Late-settling secondary trades cannot silently reassign an entitlement already fixed.
Secondary transfers move the bond and the cash in one indivisible step, eliminating the window where one leg has moved and the other has not.
The security leg and the sovereign-CBDC cash leg either both settle or neither does, so principal risk between counterparties is structurally removed rather than mitigated by timing. There is no free-delivery exposure to manage.
Settlement can be immediate because there is no separate clearing layer to net across; finality is the confirmation of the atomic operation. Longer cycles become a policy choice, not a technical constraint.
Repo, reverse repo, and collateral pledges are modeled as conditional transfers with defined unwind terms, so the encumbrance and its release are both native ledger states. Rehypothecation chains remain visible to the issuer.
Because the register, the settlement engine, and the payment rail share one ledger, a trade cannot be confirmed in one system and unknown in another. Reconciliation between custody and cash disappears as a category of work.
Ownership is a current ledger state the issuer can read directly, with a complete tamper-evident history behind every position.
Holders control their positions with their own keys, so the register reflects genuine control rather than an entry in a custodian's internal books. The sovereign is not dependent on a custodian's solvency to know who owns its debt.
Every transfer since issuance is chained, letting the issuer or an auditor reconstruct the full ownership history of any bond without requesting files from intermediaries. Chain-of-title for debt is verifiable, not asserted.
Holding restrictions — investor class, jurisdiction, sanctions status, lock-up windows — are enforced at transfer time as conditions on the object rather than policed after the fact. Ineligible transfers fail rather than settle-and-remediate.
The issuer can see aggregate exposures across its whole outstanding stock in real time, supporting debt-management decisions that today rely on lagged, stitched-together data. Positions are a query, not a data request.
Keys, ledger, and data residency are arranged so that no external party can freeze, censor, or read the sovereign's own debt operations.
Signing authority for issuance and servicing lives with the sovereign, so debt operations cannot be suspended by a vendor or a foreign settlement venue. Operational continuity is a property of the design, not a contractual promise.
Long-dated bonds outlive the security assumptions of classical signatures, so instruments are signed with ML-DSA-65 under FIPS 204 to keep authenticity verifiable across the instrument's full life. A thirty-year bond is protected on a thirty-year horizon.
The register and servicing history reside within national infrastructure, keeping sensitive sovereign-debt data under domestic legal jurisdiction. Cross-border replication is a deliberate policy act, not an operational default.
The hash-chained ledger gives supreme audit institutions and external auditors a mathematically verifiable record without granting write access. Oversight reads the same truth the issuer relies on.
Talk to us about sovereign bonds and treasuries in a sovereign deployment.