Key Takeaways
- In August 2020, Citibank accidentally wired $900 million of its own money to Revlon lenders due to a software interface error, triggering a court battle over New York's discharge-for-value defense when lenders refused to return the funds.
- Payment finality is a probability distribution based on technical rails, counterparty relationships, and regulatory jurisdiction, not an absolute technical property.
- Cryptographic networks like Bitcoin fail to achieve absolute finality in practice because sovereign governments possess the legal and coercive authority to compel asset recovery.
- Instant consumer rails such as Zelle, the UK's Faster Payments, and Japanese banking networks depend on administrative mechanisms like hold harmless letters to reverse mistaken or fraudulent transactions.
Settlement Is a Probability Curve, Not a Boolean
In August 2020, an operations team working for Citibank tried to process an interest payment on behalf of Revlon. Because of confusing software interfaces, the bank accidentally transmitted roughly $900 million of its own principal to Revlon creditors. Citibank demanded the money back the next morning. Several asset managers refused. That triggered a public legal fight in New York centered on the discharge-for-value defense, an old legal doctrine allowing creditors to keep mistaken payments if they were owed the money and had no reason to suspect an error.
Most engineers design fintech products under the assumption that an internal database flag marked settled represents an absolute end state. McKenzie argues this is a dangerous misunderstanding of how financial systems operate. “As a payments professional, finality can be thought of more of a probability distribution given the technical and organizational infrastructure which was used to make a payment,” he explains. A wire looks irreversible on a dashboard, but banking operations staff exchange hold harmless letters every day to pull funds back when an operator fat-fingers a routing number. “We can confidently say things like wire transfers are more final than credit card payments, but we generally don't say wire transfers are final. If they were really final, the world would break.”
The Sovereign State Overrides Cryptographic Code
Cryptocurrency advocates attempted to replace this messy human discretion with immutable ledger math. They designed systems meant to remove trusted intermediaries entirely. As McKenzie notes: “The cryptocurrency enthusiast community largely believes that code is law. Not your keys, not your coins, etc, etc.”
Yet cryptographic keys exist in the physical world, and the humans who hold them remain subject to legal courts and law enforcement. When governments decide an illicit transfer occurred, they do not bother arguing with consensus protocols. They seize physical devices, obtain court injunctions, and force asset recovery under threat of criminal penalty. As McKenzie observes: “Possession is nine-tenths of the law, so the saying goes, but the state can conjure as many tenths are required if it is motivated to.” In practice, “if you and the United States Federal Government disagree whether a transaction is final, you are wrong.”
Operational Realities on Fast Rails
The same principle governs modern consumer payment rails worldwide. Look at Zelle in the United States, Faster Payments in the United Kingdom, or the interbank network in Japan. Each platform markets immediate transfers to consumers, yet each must establish administrative and sociological procedures to handle fraud, extortion, and user mistakes. When payments go wrong, receiving banks face pressure from courts, regulators, and partner institutions to claw back funds.
If you build software that moves money, treating settlement as an irreversible event creates catastrophic financial liability. You risk advancing funds to users before a wire is legally safe from recall, leaving your own balance sheet exposed when a counterparty demands their money back.
What to Do With This
Audit your product's fund-availability logic this week. Map every deposit method where your system grants immediate spending privileges, and establish mandatory hold periods on transfers exceeding $5,000. Add explicit legal indemnity terms to your customer agreements that allow your system to freeze or claw back credited balances if an originating bank issues a recall notice.