General

What OpenAI's cyber defense call means for stablecoin infrastructure

The cyber defense problem becomes a financial control problem when money moves in seconds and the checks around it do not.

Ivan SzeftelMarketing Manager · September 2, 2026
What OpenAI's cyber defense call means for stablecoin infrastructure

What 116 organizations actually diagnosed

On 27 August 2026, 116 organizations signed an open letter calling for a global surge in cyber defense. CNBC names OpenAI, Anthropic, Microsoft and AMD among the signatories, TechCrunch adds Google, and both report that financial institutions signed it too.

The central line is: "We have a limited window to strengthen cyber defenses." Status quo security "won't be enough", it argues, because "technical debt in legacy systems" has left systems exposed, and the security teams defending them have been "historically under-resourced". The letter also forecasts that AI-enabled attacks "will become far more widespread and sophisticated as models around the world become increasingly capable".

The letter names hospitals, water treatment plants and internet infrastructure, not payment rails. Applying its diagnosis to money movement is Range’s compliance reading, not the letter’s. But we think the comparison matters because financial infrastructure touches nearly every part of modern life, and disruption to payment rails can cascade just as quickly through the systems people depend on.

What that diagnosis looks like in stablecoin controls

Two parts of that diagnosis map directly onto how compliance and risk functions operate.

The problem with control cadence

In the control stacks companies describe to us, identity is verified once, at onboarding. Counterparty risk is reviewed on a calendar basis, quarterly when the calendar allows. Sanctions screening runs when a payment is released. The debt here is not legacy code, it is cadence.

Those review cycles were designed around slower financial processes, not a payment rail that can settle in seconds.

A payment released the day before a quarterly review may still be based on a risk decision made nearly 90 days earlier. The same principle applies to identity verification: a counterparty that was verified at onboarding can still be marked as “verified” in the system, even if its ownership, sanctions status, wallet exposure, or risk profile has changed since then.

This creates a period of exposure between when a change occurs and when the control is re-evaluated. A new screening helps close that exposure window, but when the verification process must be repeated manually, the associated cost influences how often it occurs. Quarterly reviews do not necessarily indicate how quickly risks can change; rather, they often reflect how frequently a team can afford to conduct the required work.

Knowing your own position after the money has moved is a separate problem, and we made that case in Why stablecoin instant settlement rarely lands instantly, and how to fix it.

Compliance capacity does not scale with volume

Companies describe the same operating problem: transaction volume grows faster than compliance and risk headcount. More payments mean more counterparties, more wallets, more chains and more decisions that have to be made before money moves. The team may grow too, but rarely at the same rate.

For each payment, the company still needs answers to a basic set of questions. Is this address associated with malicious activity? Is there sanctions, fraud or illicit-finance exposure in the source of funds? Does the wallet actually belong to the intended counterparty? Is the risk consistent with the company’s policy for releasing the payment?

Obtaining these answers often requires several manual steps. An analyst screens the wallet, traces relevant transaction history, reviews the source of funds, checks the findings against the intended recipient, and records the reasoning behind the final decision to release or escalate the payment. If the same counterparty uses a different wallet or if the company adds another chain, much of this work needs to be repeated. The tools currently in use are often designed for investigations, allowing an analyst to explore a case in depth, rather than facilitating high-volume payment operations where consistent controls must be applied to every transaction.

That creates a scaling problem. The workload grows with transaction count, number of counterparties, number of wallets and number of chains. Hiring another analyst adds capacity one person at a time, but it does not remove the repeated screening, matching and documentation underneath each decision.

Eventually, the queue of transactions grows faster than the team can handle. Review times extend, and teams must prioritize which transactions require more thorough attention. Furthermore, demonstrating that the same controls were applied consistently across all payments becomes more challenging. The limiting factor shifts from access to risk data to the amount of manual work necessary to convert that data into a documented decision prior to releasing the payment.

AI is already testing identity and payment authorization

On money movement, FinCEN and FATF have already documented the mechanisms, though neither measures the forecast's rate.

In November 2024, FinCEN told financial institutions it had observed an increase in suspicious activity reporting describing suspected deepfake media, in schemes that "often involve criminals altering or creating fraudulent identity documents to circumvent identity verification and authentication methods". The same alert records criminals using GenAI tools to impersonate "an executive or other trusted employee" and then instruct victims to transfer large sums. Those two typologies map to two attack surfaces: identity at onboarding and authorization at payment. The first of those is the control companies describe running exactly once.

In July 2026, FATF connected it to stablecoin movement. Its Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs records that the abuse of AI "is emerging as a risk factor across the lifecycle of fraud, hacking and money laundering", and that stolen assets "can be rapidly moved and fragmented through stablecoins, DEXs, bridges and multiple VASPs, making tracing and freezing more difficult". FATF is describing VASPs, DeFi and unhosted wallets, not corporate treasury operations. The step from there to a company's own controls is ours.

Neither FinCEN nor FATF quantifies the speed at which AI-enabled financial crime is increasing. However, they both acknowledge that synthetic identities, executive impersonation, and AI-assisted money laundering are already present in the threat landscape. The argument regarding the pace of these threats does not rely on predicting their growth; a 90-day review period remains consistently 90 days long.

Four controls worth reviewing now

FATF directs its recommendations to authorities rather than individual firms. But several of the risks it highlights translate directly into operational questions for companies moving money: how identities are verified as synthetic identity techniques improve, whether investigators can keep pace with AI-enabled activity and how quickly new risk information reaches the controls that govern a payment.

For a compliance function, that turns into a more practical question: how much can change between when a control last ran and when money is released? Four tests help make that visible:

  • Map control cadence. Record which checks run continuously, per transaction or on a schedule. The gap between reruns is your exposure window.
  • Set identity expiry rules. Define how long KYC or KYB remains valid and which changes trigger re-verification.
  • Test for impersonation. Run payment approvals against a realistic deepfake or synthetic-identity scenario where the request appears to come from someone trusted.
  • Keep the evidence. Record what was screened, when, against which source and who approved the payment.

None of this requires buying another vendor. It requires making the operating model explicit. The important step is deliberately deciding those intervals, measuring the exposure they create, and shortening them where the business can no longer justify the gap.

Where Range sits

Range turns those requirements into controls that run with the transaction.

Protect screens payments before execution and continuously monitors counterparty exposure against a matched entity record, while the risk and compliance providers a company already uses continue supplying their signals.

The result is a record of what was screened, when the control ran and what decision followed. Range does not make a company compliant. It gives compliance teams the evidence behind each control and decision.

To see how your control cadence compares to your transaction volume, get in touch.

Protect your time and money

Get your unified treasury dashboard in 30 minutes.