Complex Systems with Patrick McKenzie (patio11) · Startups & Venture · October 2026
McKenzie reading aloud from his own 2022 essay, "Finality does not exist in payments". He has just described a 2016 Bitcoin transaction worth about $70 million that was partially voided in 2022, something no code base provides for. His argument is that finality is a social and legal construct, not a technical one.
Welcome to Complex Systems, where we discuss the technical, organizational, and human factors underpinning why the world works the way it does. Most people have an intuitive ranking of payment finality. Put a $20 burger on your credit card, and you know if something goes wrong that you can dispute it. But you send a wire, and you think the money is just gone because wires are final. That's what wires are for. In August 2020, Citibank accidentally wired nearly $900 million to a group of lenders. Some sent it back. Some said, wires are final. We're keeping it. A federal judge agreed with them. Two years and one appeal later, they gave it all back. I have a classic essay on this topic, and then I'd like to riff a little bit to apply it to the Citibank case, which I think a lot of people misunderstand a bit. Finality does not exist in payments, originally published in Bits About Money on February 15th, 2022. Children have a culture all of their own, and one sacred ritual of it, and sometimes in places, is no takes these backseats. Like much of child law, it both rhymes and is enforced by social sanction dictated by custom immemorial. It means transactions are absolutely final. Many adults believe final transactions to exist. They mostly don't, and that is a good thing, too. That might sound surprising. Finality is a techno-socio-legal construct. What does a transaction being final mean? In the layman's use of the term, it means that the transaction cannot be reversed. As a payments professional, finality can be thought of more of a probability distribution given the technical and organizational infrastructure which was used to make a payment. In the industry, we call this the rails. Finality also brings in the facts of the underlying transaction, the relationship of the parties, and the governing law or laws and regulatory regimes. We can confidently say things like, wire transfers are more final than credit card payments, but we generally don't say wire transfers are final. If they were really final, the world would break. An extreme example which proves the point. The cryptocurrency enthusiast community largely believes that code is law. Not your keys, not your coins, etc., etc. Many crypto enthusiasts would say that the Bitcoin protocol does not prohibit reversing transactions, but provides a security guarantee which suggests the likelihood of a reversal after an hour or so is infinitesimal. And yet, someone sent $70 million worth of Bitcoin in 2016, and that transaction was partially voided, with the reversal being worth slightly more than $70 million due to Bitcoin volatility. That didn't happen an hour later. It happened in 2022. How? The answer is nowhere in the Bitcoin white paper or any code base. A full recounting of it is outside the scope of this anecdote, but it rhymes with: if you and the United States federal government disagree whether a transaction is final, you are wrong. That is true for notorious Bitcoin thefts, but it's also true for wire transfers, conveyances of real estate, credit card payments, and grave robin. Possession is nine-tenths of the law, so the saying goes, but the state can conjure as many tenths are required if it is motivated to. The overwhelming majority of transactions do not go to the state for adjudication. In fact, English lacks a non-mathematical phrase in common use to describe how much of an understatement that is. Billions of transactions happen every year, on the order of hundreds of thousands get explicitly adjudicated. Non-state agreements for dispute resolution. If payment rails don't provide finality, what do they provide in its stead? Predictability. They publish rules, cast call them laws, and operate dispute resolution processes, definitely not courts, which provide for relatively efficient, relatively inexpensive, relatively fast decisions on transactions without needing to escalate past the payment rail to the state. These rules have a property in common with formal law. They are not fully descriptive of the system that is envisioned by them. For example, in credit card disputes, almost all decisions which matter are made by an entry-level employee of the card issuer, and those decisions vary wildly across issuers, even in circumstances which look very similar. As a simplified example, issuers who focus on premium card reusers frequently make a business decision to side with their customer more frequently than, say, mass market banks do. They would probably entirely automate chargeback sustained if the network rules allowed them to, but they don't. A side effect of formal rules is that they give soft security guarantees to an ecosystem, and those security guarantees allow people within an ecosystem to transact in something approaching mutual understanding of the degree of finality on offer. Additionally, they let ecosystems compete for users and for individual transactions, specifically on the basis of different rules for finality. Take wire transfers, please. We largely don't think of FedWire as being an agent in the same sense that American Express is an agent, but FedWire factually does have a marketing department and, believe it or not, is in vicious competition with Amex for at least some transactions. One important fact in the mind of both buyer and seller is that Amex charges more as the transaction gets larger, and Fedwire, in relative terms, basically doesn't. But another is that Fedwire has a relatively strong presumption of finality, and American Express very explicitly does not. Businesses who use American Express, or other credit card networks, to process payments often wonder why this is, particularly after they've been hit by a chargeback, which is industry jargon for a credit card payment reversal. The big strategic reason, unchanged in the decades we've had credit cards, is that card networks are a trusted overlay on economies with heavily heterogeneous trust relationships. Some credit card transactions are between a regular and the cafe they've gone to for 20 years, but some are between a business traveler and the hotel they'll never set foot in again. And credit cards guarantee to users that the risk of these two transactions is similar. They increase social trust between peers on the network by decreasing technical trust. This is akin to alchemy. Younger generations might not appreciate this, but there was a very real question in the late 1990s and across much of the world even today, whether transactions could ever take place over the internet without being able to look counterparties in the eye. Aren't hackers just going to steal all the money exposed to the internet? And lo and behold, they did not. But a necessary precondition for answering that question was there being money exposed to the internet. Credit card guarantees of reversibility substantially made that happen. I would be remiss if I didn't give regulations some of the credit here. Again, the payment rails could say in their rules that transactions are final, but private industry is not the court of final appeal. This is, incredibly to me, still an alive question for at least some financial institutions in the United States who believe Zell transfers are final because Zelle does not contemplate reversing transactions. Until the people with guns stop enforcing Regulation E, guidance to customer service representatives about finality is not actually controlling. And I'll say as an aside, years later, the CFPB did sue the large banks in the United States because they had told their customer service representatives to tell customers untrue things about the scope of Regulation E. That suit was then dismissed after politically motivated shake-ups in the CFPB in 2025. But just saying as an analyst and observer, it is still the case that Zell is an electronic payment method, and it is still a case that Regulation E says what it says with regards to customer liability for misused electronic payment methods. Wait, are you telling me that wires are reversible? Of course, wires are irreversible. They were not designed by children, but by professionals who live in a society which has systematically important institutions. And in the event of malfeasance or mistakes, society does not tolerate a bank failing or a state missing payroll simply because someone said, no, takes these back seas fast enough. Mistakes happen, by conservatively, the hundreds of thousands daily across all payment systems. Millions, depending on your definition of mistake. Wire transfers, like almost all payment systems, explicitly contemplate them and have a socio-legal ritual to quickly reverse them. The ritual is called hold harmless and comes from a soft guarantee about the wire transfer ecosystem, which is that transactions are largely between sophisticated counterparties acting in good faith, intermediated by institutions whose probity is almost sacrosanct. Importantly, wires are an expectation worth having a human in the loop for. This is very not true of most payments. A hold harmless is a very, very brief conversation between two peers at two different institutions, which is then memorialized on paper. The peers are generally operations professionals, one at the receiving institution and one at the sending financial institution, and sometimes even at its customers, since many serious users of financial infrastructure have operations teams to interact with their providers. The conversation is often shockingly informal, on the level of, yeah, we goofed, and we sent $1.2 billion to the wrong account Mondays. Am I right? And the operations professionals make a verbal agreement about the disposition of the transaction in minutes or less. The agreement is then solemnized in a brief document which gives Hold Harmless its name. The ops professionals are both taking a risk in voiding a transaction, and the party asking to avoid it, the sender, offers the party with the capability to void it, the receiver, a contractual indemnification should the state later come to the opinion that the ops professionals acted improperly. You can get a flavor of the language from NASA's model letter for ACH transactions. Hold harmlesses for wires look just a tiny bit different. How common are hold harmlesses? It took the combined forces of several agencies of the federal government more than five years to reverse $4.5 billion in Bitcoin transaction. That probably counts for a few days' worth of hold harmlessness executed after breezy telephone calls. It is worth noting that this is substantially more complicated internationally. You can still absolutely reverse a wire between an arbitrary bank in Japan and the United States in either direction, but the risk of unintentional fidelity. Goes up materially versus domestic wires. And while substantially all financial institutions in those two nations are de facto peers in a group of high trust counterparties, that is decidedly not true of all financial institutions in all nations. As an aside, how do you reverse a wire that is erroneously sent to Japan? Well, a funny anecdote for you. There happen to be two Japanese banks which have Swift codes, which is the thing that one uses for routing an international wire, that are one letter off of each other and approximately nine letters long. Once upon a time, a Japanese salaryman who happens to live in the United States instructed his American bank, by the way, when you wire the tax payment, please wire it to the correct bank because there are two Japanese banks that have Swift codes, which are one letter apart from each other, and occasionally miss wires get blown up by American bankers, so please be attentive here. And it turned out that that payment did not arrive in the ordinary course. So the salaryman called his bank in Japan, asking, hmm, what happened to the money? And the bank said very apologetically, well, you know how American bankers are. Sometimes they happen to make this particular genre of mistake. And the salaryman said, oh, well, you know how American bankers are, but you also know how Japanese salarymen are. I instructed them about that mistake before making this wire and then thoroughly checked the wire confirm, and it says the appropriate thing on it. And the Japanese bank said, well, we'll wait another day to see if it arrives, but it really should have arrived by now. Could you please ask the Americans one more time? So the salaryman got on the phone to the American bank and said, hey, since you sent a wire message, it probably went over Swift. Do you happen to have the actual Swift message available so that I could present it to the Japanese bank and have them follow up with their investigation? And the bank gave the salaryman a copy of the Swift message, and the Swift message had the wrong thing written on it, despite the wire confirm having the right thing written on it, due to infelicities in having to manually retype between applications, perhaps. So the salaryman sent his American bank a letter saying, well, it seems that I told you to wire money to this particular account in Japan, and in fact, told you to pay double plus attention to make sure that it was not sent to this other financial institution in Japan. And yet, the bank's money seems to have somehow ended up there anyhow. But clearly, my money is still at the bank, so send that to the bank that I told you to, please. And the bank said, well, we don't really agree with that theory of our operations here, but by total coincidence, money has arrived back from Japan today. So we will resend the wire. And they did so. Anyhow, a fun story about the joys of dealing with wires internationally. So why does this matter? Obviously, if you, or more to the point, your business interacts with the financial system, it is important to correctly model the sort of finality guarantees you get on transactions. For financial professionals, we likely haven't seen the final form of finality. There is still a rich design space there, and it appears underexplored over the last few decades. Some newer payment methods, including cryptocurrencies, are doing interesting tweaks, generally towards making payments substantially more final than credit cards. But you could imagine guarantees in the opposite direction working for at least some transactions among some group of users. Another very interesting axis is whether finality guarantees should be much more explicit than they are currently, and whether one should be allowed to pay for different finality guarantees. So that's the essay. Now, a bit of brief riffing on the Revlon situation, which many people misunderstood when it came out. So a brief riff on the Revlon situation from back in 2020 through 2022. Much of this was originally reported/slash commented on by Matt Levine, but well, he has funny and directionally accurate takes on it. I have my own takes/slash how to put this reflected PTSD about looking at applications facing operations professionals that would allow someone to make a $900 million mistake very easily and then have that mistake not get caught despite two other individuals taking an eyeball at the contemplated transaction. This isn't the most expensive software slash user experience bug in history, but goodness, it has got to be up there. So the situation that approaches the world in 2020. Revlon is a cosmetics company. It has fallen upon hard times, and it has arrived at a situation where it owes a lot of money to various lenders, a principal balance of approximately $900 million. So in somewhat better times, in 2016, Revlon had taken out a roughly $1.8 billion loan with Citibank as the administrative agent. And so we're going to be concentrating on the actions of Citibank employees for the next few minutes, because Citibank employees made a bit of a boo-boo with respect to an internal piece of software called FlexCube.
I think the acknowledgement of an ad read sounds cooler in Japanese.
Cool, right? So picture this. You've finally recruited that engineer you've been eyeing for months. The interview feedback was unanimous. Totally cracked. Their salary and equity grant were pricey, but worth it. You can't wait to get them to work. On filing expense reports? No, of course. You've never hired anyone just to have them do expense reports. But everyone you hire has to do expense reports because you're a grown-up company with stakeholders to satisfy. And perhaps you've even adopted one of the more modern expense report systems to be 50% less insultingly wasteful. Mercury, the banking provider I use for my own business, has an alternative, Mercury Spend. Your team's expense policies, approvals, limits, and reporting live in the same place with the rest of the business banking. So you spend less time asking an engineering lead to ask a senior engineer to fish out a SaaS invoice and more time actually doing things that matter. Have you ever really enjoyed a conversation with an accountant about expense substantiation? No, and the accountant didn't either. Just forward the SaaS receipt email to the usual alias and Mercury spend will save humans from thinking about the rest. When my assistant last told me a Mercury debit card charge was declined, I was able to approve a temporary increase in the cards limits in less taps than it took me to text them to try again, please. I also love being able to spin up cards trivially for a person, project, or expense category. A $1,000 a week limit on software. I'm a sassy guy. And like the rest of Mercury, it works regardless of whether you're a startup getting formal for the first time or a well-established company. Mercury has over 300,000 customers of all sizes. Fittingly, you don't need to talk to sales to liberate your team from expense report drudgery. Go to mercury.com to learn more and sign up in minutes. Mercury is a fintech company, not an FTIC insured bank. Banking services provided through Choice Financial Group and Column NA, Members FDIC. The IO card is issued by Patriot Bank, NA, member FDIC, pursuant to a license from MasterCard International Incorporated. Meetings get a bum wrap. This meeting could have been an email. But sometimes it is really useful to get everyone in a room so there are no misunderstandings. So do the notes for the meeting actually reflect what was decided in it? That is where Granola comes in. It is a modern notepad for meetings. You attend the meeting like you usually do, and Granola, running on your own device, securely transcribes it. You jot down notes as you usually do, and Granola enriches your version, tracking multiple speakers, the back and forth of the meeting, and final decisions. You can even chat with your notes, live or after the meeting. Why did this slip from Q3 again? Who is in charge of getting sign-off for marketing? Granola lets everyone be present in the meeting rather than having one person sidelined by being note-taker. It's your usual meetings, now with superpowers. Action items, actioned, owners, owned, synergies. Sorry, no amount of meetings will ever let me say synergies unironically. If meetings are eating up your day, Granola is a no-brainer. You can try it totally free. Just head to granola.ai/slash complex systems. That's granola.ai slash complex systems to get your time back. Try it for free at granola.ai slash complex systems. To make a long story short, if you want to make a approximately $8 million interest payment via FlexCube, you have to enter that fact in more form fields than is obviously sort of like naturally required. And if you don't hit all of those form fields, you will instead wire out the entire principle of the loan rather than simply an interest payment. And there will be a confirmation, but the confirmation won't exactly make it obvious that the entire principal of the loan is leaving the bank. And so, on August 11th, 2020, while attempting to make about an $8 million interest payment, one employee at a business outsourcing firm in a business process outsourcing firm in India attempts to key in that interest payment for $8 million and queues up Citi to send out $900 million or so. And then a second employee at the BPO also makes substantially the same mistake in checking it, and then it gets sent over to a city approver who actually works in Delaware, and that person also approves it, and so out $900 million goes. So, this hits the account of various lenders, and the lenders are largely surprised to get it. There is internal chatter. Was this a mistake? Did Citibank send us a notice that they were going to repay the Revlon thing early? And bluntly, if you think about it for a few seconds, this kind of stinks to high heaven because this debt is trading at like 20 to 30 cents on the dollar, and you don't expect to get 100 cents in full satisfaction out of the clear blue sky several years early. From, again, a party with extremely averse interest to yours, who you might be engaged in an act of litigation with. So, Citibank realizes its mistakes within a day and hits all of the lenders with a recall notice, saying essentially, hey guys, we goofed. You're going to do the thing that the culture that is. New York City strongly suggests you're going to do right now, right? And some lenders return the money, about $400 million worth. But about 10 managers representing various funds and similar and high-net worth individuals that were invested in this instrument continue to hold about $500 million. So who is out the $500 million? It is Citi. And Citi is pretty unhappy for a variety of reasons. $500 million operational mistakes are not exactly unknown in the financial industry, but they're pretty rare. Citi sues over this. Gets to the district court, and the district court says, well, there is this obscure thing in New York law called the discharge for value defense. This charge for value defense is basically like, in the case of an obvious error in a payment, we reverse the payment. No worries. But if the recipient of the payment has the like legitimate belief that, no, the payment is something that is actually owed to them in a way that a lender might assume that full repayment of a loan is actually owed and they haven't received notice of the error at the point the payment is made, payment is good. And so the judge says, nope. In this case, industry standard practice does not control New York law controls, and New York law says you can just keep the $500 million that you believe you are owed. This causes an absolute firestorm in the financial industry for so many ways and results in, oh boy, probably north of $500 million in legal spend as so many contracts get rewritten to say, despite what New York law says, if there is an erroneous payment, you absolutely do not do the thing that New York law suggests that you have the default right to, but instead will hew to what was previously industry-stranded practice, take the telephone call and return the money, you freaking idiots, sign on the dotted line, please. But it turns out that the non-final final payment is more final than was expected at the moment because it goes to the Court of Appeals. And the Court of Appeals says, among other things, you can read the entire opinion at your leisure. One, they think the district court judge erred in applying the discharge for value defense. And then two, it's just like monstrously perverse and disruptive that this transaction would get allowed to stand. That despite being a wire transfer, this should have been non-final from the jump. And I think that is very instructive in the way that the sort of technical reality of the wire and the social reality of the wire that, you know, we have this culture in the industry of doing hold harmless. And this should have been nothing more than like a single, not very stressful phone call between Citi and each lender. It resulted in a multi-year, multi-court battle. And then the legal reality trumped the legal reality, trumped the social reality, trumped the technical reality of the wire. And I find that to be just endlessly fascinating. But the international comparison here is also quite instructive. So in the United States, we've mentioned that subject to ongoing disputes or, well, they're not ongoing at the moment, but give it a minute. Subject to disputes between the regulators of United States banks and the banks with respect to Zelle. Zell payments are broadly thought to be like mostly final at the moment for one interesting class of payments. Zell, oh man, I should write an essay about this at some point, is a blocking play. It basically exists to give the banks a way to say, don't just take all your day-to-day activity to Cash App or Venmo. And it is broadly underbaked as a solution in a lot of ways. But it offers substantially instantaneous payments. And there are two competing standards for doing substantially instantaneous payments between bank accounts in the United States. But Zelle is the one that has most of the adoption right now. One is FedNow, which the payment wag joke for many, many years has been calling it Fed Later. And the other is RTP, which stands cleverly for real-time payments. You can make real-time payments right now, but the supported institution set for both sending and receiving is very far from full coverage. And Zell is much closer to full coverage. And so most people use Zell. The guarantees that different nations make with respect to whether consumers are at risk for their payments or not are very different from each other. The UK, for example, has substantially instantaneous bank account transactions between banks, requiring a two-factor authentication, typically through a mobile app. So the UK, as a broad feature of bank accounts, allows you to do instantaneous payments between bank accounts at almost any pound amount. And this has caused a lot of what's called. App fraud, APP, APP fraud, and it largely affected the usual suspects, largely consumers who might not be very sophisticated, older savers in particular, who responded to SMS messages or phone calls from scammers, et cetera, et cetera. So the UK said, okay, well, we're going to make the banks eat that one in the same way that Regulation E in the United States makes banks largely finally responsible for certain forms of fraud committed against users, and then the banks in the US offload it elsewhere. And there is a sort of cap on the amount that the payment standards body in the UK makes the bank eat, but it's very generous, 85,000 pounds or so reduced after pressure from more than 400,000 pounds. And the first year reimbursement was on the order of 173 million pounds out of banks. So not a small amount of money. Also, probably not full coverage for frauds committed in the United Kingdom, but it's just my finger-to-the-wing guess based on the size of the economy and typical fraud rates. So the PSR made an independent valuation and believes that app fraud was down by about 21%, which translates to about 70 million pounds of savings to consumers. And they thought, well, this is just that after this guarantee makes it possible to reverse these transactions, even with the bank being ultimately responsible for it, it's just a less attractive fraud surface. And that sort of whack-a-mole is quite common. Fraudsters go to whatever rail makes it most possible for them to successfully extract the money. India also historically had a similar problem with UPI. And India's solution was somewhat different. So rather than having the transaction be reversible and put it on the banks if there's no longer sufficient funds in the account to recover, in the case of a mule account, for those of you who don't know this lingo, mules are the individuals or companies that fraudsters with active knowing coordination or otherwise suborn to move money on their behalf. Frequently, just people responding to work-from-home scams. But some mules absolutely know what they're doing is too good to be true. You know, just receive money that is directed into your bank account and then forward it on to someone we nominate and keep 10% for your trouble. And then some people are a bit more naive about how the world works. And both people who are quite sophisticated about how the world works and quite naive about how the world works are allowed to get bank accounts. And that is broadly a just decision made by society and will not be reversed anytime soon. UPI exists, public-private partnership, wonderful, substantially instantaneous rail to make payments. UPI's fraud guarantee did not cover the case of a customer being induced to approve a payment on their cell phone or other device, even if they were induced fraudulently to make that payment. And this resulted in a politically unsustainable amount of fraud in India. And so it appears that the decision the RBI made was, okay, we will allow a one-time reversal of a payment made for in this common fraud modality where it is actually the user with their own hands on their own device making the fraudulent payment, but they've been induced to do so by lies being told by the fraudster. And so they shouldn't really be liable for it. So we will allow you to reverse that one time. In the case where we can't get it back from the fraudster's mule, rather than putting it to the bank, we will put it to a special fund stood up by the RBI/slash payment scheme. This is a once-in-a-lifetime opportunity. Please don't get frauded frequently. We would like to avoid the sort of moral hazard of you assuming that we will always cover for your mistakes. And then Japan decided to do this sort of differently. So although it is technically possible to reverse a furikomi, a bank-to-bank transfer in Japan, in practice, the reversal procedure, which is called kumimuvoshi, if you want some trivia night credit for Japanese payments professionals, in practice, the reversal procedure is so rare that most people, even in the Japanese financial industry, don't understand that that is literally a thing you can do. And what it does is the sender, similar to the case of Hold Harmless in the United States, but somewhat more regimented, the sender sends a request to the receiving institution. Hey, will you allow us to recall that? The receiving institution can't, at the level of the ops team, unilaterally recall the payment. They have to ask the account holder. And the account holder, in the case of them being a money mule, will typically say no or not respond to the request. And so it is. Is this poorly understood way to reverse the bank payments doesn't solve for the fraudulent use case or even the mistaken use case in Japan? So the Japanese government said, oh, well, typically elderly people are getting taken for just absurd amounts based on scams here. What can we do about it? What they largely settled on was user education and suasion against the financial industry to sort of do, let's say, harm mitigation approaches. So we're going to ratchet down the maximum amount of payments you can send today without actually coming into the bank. We're going to have bank tellers visit old people when they come up to the ATM and say, so what brings you up to the ATM today? Is it perhaps that you have received a telephone call? If so, let's talk a little bit before you push buttons on the ATM. Because unlike ATMs in the United States, the ATM in Japan can wire out close to $10,000 without any bank staff ever being involved. But the other thing they did was they made a sort of special legal procedure by which someone could file a complaint, and then the Japanese version of the Deposit Insurance Corporation could designate a mule's account as no longer being legally owned by the mule. And then the defrauded users could take pro-router shares of the amount of money that was left in the mule's account. The problem with this is that in Japan, since money movement is substantially instantaneous and since getting cash out of the financial system is still not all that weird of a thing to do, very frequently the amount of money that was in the mule's account at the point of the legal process being sent against it was nearly zero. And so this largely didn't solve for the redress to defrauded users. And so that's how various nations have differently approached this question of: okay, if the payment is final, if we say it is, when should we say it is? And even in light of concerted government action to make certain payments less final than they are otherwise believed to be, the social, technical, cultural substrate of those payments continues to make them final. Even when the state says, no, no, we think normatively that shouldn't be final. And this is part of the ongoing cat and mouse game between the good guys, all of us, inclusive of the financial industry, and the bad guys and their ravenous attempt to get at various people's owned assets. And that is, unfortunately, a recurring theme for complex systems and bits about money. We've covered it in the past. I will put some links in the show notes, and we are quite likely to cover it in the future. But hopefully, we'll have a happier topic to end on next week. See you then.
Thanks for tuning in to this week's episode of Complex Systems. If you have comments, drop me an email or hit me up at Patty11 on Twitter. Ratings and reviews are the lifeblood of new podcasts for SEO reasons, and also because they let me know what you like.