For years, the usual banking answer to which blockchain to use was a private network, controlled by the institution itself or by a consortium. Public networks were seen as a foreign environment, with no clear party in charge and risks that were hard to explain to the supervisor. That view has changed. Today some of the largest institutions in the world operate on public networks, others keep private networks and many combine both.
This article explains the differences between the two types of network, what leading institutions are doing and the criteria that usually decide the choice.
What separates a public network from a private one
On a public network, such as Ethereum, Solana or Polygon, anyone can run a node and validate transactions under the protocol’s rules. Transactions are visible to everyone, assets can move between any participants on the network and no single entity controls how it runs.
On a private or permissioned network, such as those built on Hyperledger Besu in a private configuration, only nodes authorised by whoever governs the network take part. The institution or consortium decides who validates, who reads and who transacts. Privacy and control are greater, but assets only move between admitted participants.
Between the two sits an increasingly common option: permissioned assets on public networks. The token lives on a public network, but its contract only allows verified wallets to hold or transfer it. The network is open; the asset is not.
What leading institutions are doing
Recent decisions by several institutions show there is no single answer:
- JPMorgan has run its own private network through Kinexys since 2015, on which it launched JPM Coin in 2019. In November 2025 it made JPMD available to institutional clients, a USD deposit token deployed on Base, a public network, that can only be transferred between authorised wallets.
- Société Générale, through SG-FORGE, launched its EURCV euro stablecoin on Ethereum in 2023 and has since extended it to Solana, XRP Ledger and Stellar, all public networks.
- DTCC uses two networks at once for its tokenisation service: Hyperledger Besu for cases that require a private network and Canton Network for interoperability between institutions.
- 21X, the first infrastructure authorised in the European Union to trade and settle tokenised securities under the DLT Pilot Regime, runs on Polygon, a public network, with access limited to verified wallets.
The direction is clear: public networks have become part of banking infrastructure, usually with access controls built into the asset itself.
Comparing the models
| Criterion | Private network | Public network | Permissioned asset on a public network |
|---|---|---|---|
| Who validates | Authorised nodes | Any participant | Any participant |
| Who can hold the asset | Network participants only | Anyone | Verified wallets only |
| Visibility of transactions | Limited to participants | Public | Public |
| Interoperability and liquidity | Limited to the network | Wide | Wide, within the permissions |
| Network governance | The institution or consortium | The protocol | The protocol, with issuer rules in the asset |
| Cost of running the network | Borne by the institution | Transaction fees | Transaction fees |
Privacy: the most common objection
The main objection to public networks is visibility. Anyone can look up the balances and movements of an address. For a bank, the possibility of linking an address to a specific client is a confidentiality issue and, in some cases, a data protection issue.
There are ways to mitigate it. In an omnibus wallet model, the positions of many clients are pooled in a few addresses and individual attribution lives in the bank’s internal record, not on the network. Transfers between clients of the same institution can be reflected only in that record, without creating a visible transaction. And movements that do reach the network are identified by address, not by client.
How to decide
A few questions help guide the choice:
- Who does the asset need to move between? If it must reach other institutions, exchanges or applications, a private network limits its reach.
- Which assets will be offered? Stablecoins and many tokenised stocks exist on specific public networks, and the bank will need to operate on them to hold them in custody.
- What level of confidentiality does the product require? The wallet model and permissions on the asset cover most cases.
- Who bears the cost and the governance? A private network requires maintaining nodes, upgrades and agreements with the other participants.
In practice, many institutions will end up operating on several networks at once, as DTCC and Société Générale already do. That is why the infrastructure should not be tied to a single network: it should be able to hold assets on different chains with the same keys in the bank’s HSMs, the same controls and the same internal record.
At Finhattan we deploy inside each bank an infrastructure that operates on the networks the institution chooses, public or private, with keys in its HSMs and its internal record integrated with the core. It is described in how we work and security and control.
For an institution weighing which networks to use, the starting point is contact.