Tokenized RWAs Hit $30B—But Are Banks Building Parallel 'Institutional DeFi' That Competes With Us?

Real talk from someone who’s been building in DeFi since 2020: I’m watching something both exciting and unsettling unfold.

Tokenized real-world assets (RWAs) just crossed $30 billion in Q3 2025. To put that in perspective, this market barely existed three years ago. Now we’re seeing projections from McKinsey and others putting RWAs at $2-4 trillion by 2030, with some bullish scenarios hitting $30 trillion by 2034.

Here’s what’s keeping me up at night: 11% of institutions already hold tokenized assets, and 61% are planning to invest soon. But they’re not coming to public DeFi—they’re building something parallel.

The Permissioned Takeover

JPMorgan’s Onyx platform is testing on-chain settlement of tokenized assets. Société Générale issued tokenized bonds on Ethereum. BlackRock’s BUIDL fund has distributed over $100M in dividends. Aave Arc created KYC-only lending pools.

All of these use blockchain technology. None of them embrace the permissionless, censorship-resistant ethos that made DeFi revolutionary.

Instead, we’re seeing:

  • KYC-gated liquidity pools
  • Verified identities required
  • Permissioned access controls
  • Compliance-first protocols
  • Tokenized repo, collateral, FX with institutional intermediaries intact

The Math That Worries Me

Current DeFi TVL: ~$100 billion
Projected RWA market by 2030: $2-4 trillion
That’s 20-40x larger.

If institutional tokenization becomes 20-40x bigger than public DeFi, what does that mean for protocols like mine? Are we building in a niche market while the real value flows through permissioned rails?

Did TradFi Absorb Blockchain Without the Revolution?

Here’s my question to this community: Did traditional finance just absorb blockchain technology while rejecting everything that made crypto meaningful?

They’re using our infrastructure (Ethereum, L2s, smart contracts) but imposing the same gatekeepers, KYC requirements, and centralized control that we were trying to escape. They get 24/7 settlement and atomic swaps, but users still need permission to participate.

Is this:

  • :white_check_mark: Legitimization that brings trillions in capital and validates blockchain tech?
  • :cross_mark: Absorption that creates “institutional DeFi” competing with public DeFi for liquidity and mindshare?
  • :person_shrugging: Both—and we need to adapt or become irrelevant?

As someone running a DeFi protocol, I’m genuinely conflicted. Part of me celebrates the validation (“We were right about blockchain!”). Part of me worries we’re building for a market that’s about to be dwarfed by permissioned alternatives.

For founders and builders here: Are you adapting your protocols to support RWAs? Adding permissioned modes? Or doubling down on permissionless values?

For the technically minded: Can public DeFi and institutional RWAs coexist, or are we headed for a liquidity war?

I’d love to hear how others are thinking about this inflection point.


Sources: Market data from BCG RWA Tokenization Analysis, Coindesk RWA Coverage, institutional adoption stats from TreasuryXL TradFi-DeFi Convergence Report

Diana, this resonates with a lot of what I’m seeing from the regulatory side, but I’d push back on the “absorption” framing. What we’re witnessing is legitimization, not co-option.

Why Permissioned Pools Exist: Legal Reality

Here’s the uncomfortable truth: Banks cannot legally participate in permissionless DeFi. Full stop.

They’re bound by:

  • AML/KYC requirements – Know Your Customer isn’t optional
  • Sanctions screening – OFAC violations carry criminal penalties
  • Accredited investor rules – Can’t offer certain products to retail
  • Suitability obligations – Must ensure products fit client risk profiles

When JPMorgan or BlackRock touches blockchain, they’re not doing it to avoid regulation—they’re doing it within regulation. Permissioned pools aren’t a bug; they’re the feature that makes institutional participation possible.

Compliance Enables Innovation

I’ve spent the last 5 years helping crypto companies navigate compliance, and here’s what I’ve learned: regulatory clarity unlocks capital.

Look at the trajectory:

  • 2021: Institutions curious but scared (regulatory uncertainty)
  • 2023: Some pilots, mostly private chains (MiCA drafts emerging)
  • 2025: $30B in tokenized assets (clearer frameworks, permissioned infrastructure)
  • 2030 projection: $2-4T (mature compliance standards)

The market isn’t growing despite KYC and permissions—it’s growing because of them. Institutions need regulatory cover to deploy capital at scale.

Can Both Ecosystems Coexist?

Short answer: Yes, but they serve different purposes.

Public DeFi:

  • Permissionless innovation
  • Pseudonymous participation
  • Censorship resistance
  • Composability without gatekeepers
  • Crypto-native users and use cases

Institutional RWAs:

  • Regulatory compliance
  • Verified participants
  • Legal recourse and consumer protection
  • Integration with TradFi systems
  • Institutional capital and treasury management

These aren’t competing—they’re complementary. Public DeFi is the innovation layer; institutional RWAs are the capital layer.

The Bridge We Need

Here’s where it gets interesting: We need bridges between these worlds.

Some protocols are already doing this:

  • Liquidity routing that maintains compliance boundaries
  • Tokenized treasuries that can serve as DeFi collateral
  • Hybrid custody models (institutional grade with DeFi composability)
  • Zero-knowledge compliance tech (prove accreditation without revealing identity)

The future isn’t either/or. It’s layered:

  1. Settlement layer (Ethereum, public L1s)
  2. Compliance layer (KYC, permissioned pools, regulatory rails)
  3. Innovation layer (Public DeFi, permissionless composition)

Liquidity Fragmentation Is Real But Manageable

You’re right to worry about liquidity splitting between open and permissioned pools. This is a genuine concern.

But consider: MakerDAO’s RWA vaults brought U.S. treasuries and bank loans on-chain to back DAI. That’s institutional capital supporting public DeFi, not competing with it.

If we design protocols correctly, institutional RWAs can provide stable collateral and liquidity into public DeFi, while public DeFi provides innovation and composability on top of institutional rails.

Your Protocol’s Path Forward

For YieldMax specifically, I’d explore:

  • Accepting tokenized treasuries as collateral – Institutions provide stable base yield
  • Offering compliant “institutional tier” – Separate pool, same underlying protocol
  • Building privacy-preserving compliance – ZK proofs of accreditation

Better to be proactive than reactive. The regulatory train is coming—you can build the tracks or get run over by them.

Bottom line: This isn’t TradFi absorbing DeFi. This is blockchain technology winning—institutions are coming to us, adopting our infrastructure, just with the compliance guardrails their legal teams require.

:balance_scale: Compliance enables innovation. Both ecosystems can thrive.


For context: Finextra on TradFi-DeFi Bridging 2026, Conduit Permissioned DeFi Guide

Diana, I feel this in my bones. Running a pre-seed Web3 startup, I’ve lived both sides of this conversation.

The Investor Reality Check

Here’s what happened when I pitched our protocol to VCs last year:

My pitch: “We’re building permissionless DeFi infrastructure for…”
VC response: “Cool tech, but what’s your path to institutional adoption?”

My revised pitch: “We’re enabling tokenization of real-world assets with compliant…”
VC response: “Tell me more. Who are your enterprise customers?”

That’s when it hit me: The market that VCs want to fund isn’t the same as the market that made us fall in love with crypto.

Product-Market Fit for Institutional Capital

Rachel’s right about regulatory necessity, but let me add the business lens:

Institutions have different needs:

  • Predictable yields (not “up to 8000% APY!!1!”)
  • Legal recourse (if something breaks, they can sue)
  • Custody standards (can’t explain “not your keys, not your coins” to the CFO)
  • Audit trails (need to show regulators where every dollar went)
  • Counterparty verification (can’t lend to anonymous wallets)

Public DeFi optimized for crypto-natives. RWAs are optimizing for institutions. These are different products for different customers.

Can Public DeFi Compete on PMF?

Here’s the uncomfortable question: If institutions want KYC and compliance, can permissionless DeFi compete for their capital?

I don’t think so. Not directly.

But that doesn’t mean we lose. It means we need a different strategy:

The Two-Tier Approach

We’re building our protocol with dual modes:

  1. Open pool – Permissionless, crypto-native, innovation playground
  2. Institutional tier – KYC-gated, compliant, enterprise sales

Yeah, it doubles engineering complexity. Yeah, it feels like compromise. But it’s the path to sustainability.

Our open pool drives innovation and community. Our institutional tier drives revenue and runway.

Sustainable Business Models

Diana, you asked about adapting protocols. Here’s my take:

Token incentives are not sustainable business models.

Every DeFi protocol that relies purely on token emissions for yields is playing a game of musical chairs. When the music stops (token value crashes), liquidity evaporates.

RWAs bring real yield—actual cash flows from treasuries, real estate, corporate credit. That’s a business model VCs understand and can underwrite.

If public DeFi wants to compete long-term, we need sustainable yields that don’t depend on speculation.

The Opportunity: Hybrid Protocols

I’m actually bullish on this convergence. Here’s why:

Public DeFi gets:

  • Stable collateral (tokenized treasuries)
  • Real yield (not just token emissions)
  • More developer talent (institutional projects hire devs)
  • Better infrastructure (institutions fund scaling solutions)

Institutions get:

  • Innovation (public DeFi builds stuff fast)
  • Composability (plug into existing protocols)
  • Global liquidity (24/7 markets)
  • Atomic settlement (no correspondent banking delays)

The winners will be protocols that bridge both worlds.

My Advice for Founders

If you’re building in this space:

  1. Accept both markets exist – Don’t pick sides, build bridges
  2. Start permissionless, add compliant tier – Easier than going reverse
  3. Find institutional partners early – They’ll tell you what compliance features matter
  4. Build sustainable unit economics – Token incentives are marketing, not business models
  5. Hire someone who speaks TradFi – You need a translator for enterprise sales

Austin Startup Scene Perspective

In Austin, we’re seeing a shift. The Web3 founders who are raising capital in 2026 aren’t pitching “permissionless revolution.” They’re pitching “blockchain efficiency for institutional workflows with optional compliance layers.”

It’s less sexy. But it’s what gets funded.

My hot take: By 2028, the biggest “DeFi” protocols will have institutional customers contributing 60%+ of TVL, even if retail users are 90%+ of addresses.

The revolution won’t be decentralized—it’ll be layered. And that’s okay.


Context: Yahoo Finance RWA Predictions 2026, AurPay RWA Tokenization Convergence

Jumping in from the developer trenches here. I work on a mid-size DeFi protocol, and this conversation is basically every standup meeting for the last 6 months.

Developer Experience Fragmentation

Diana, you asked if we’re adapting our protocols. The answer is yes, but it’s… complicated.

What we’re hearing from users:

  • “Can you add a permissioned mode for our corporate treasury?”
  • “Our investors need KYC before they’ll provide liquidity.”
  • “We want to use your protocol but need audit-compliant transaction logs.”
  • “Can you integrate tokenized treasuries as collateral?”

What that means for dev teams:

  • Building two separate UIs (open vs KYC-gated)
  • Maintaining separate smart contract modules (permissionless core + compliance wrapper)
  • Different testing suites (public pool scenarios vs institutional compliance)
  • Split documentation (DeFi-native users vs TradFi customers)

It’s like maintaining two products in one codebase. Our complexity has doubled.

User Confusion Is Real

From the frontend perspective, this is a UX nightmare:

User signs in:

  • “Why do some pools require KYC and others don’t?”
  • “What’s the difference between ‘Open APY’ and ‘Verified APY’?”
  • “I passed KYC on Aave Arc, why do I need to do it again here?”
  • “If I use the permissioned pool, what data are you collecting?”

We’re trying to explain permissioned vs permissionless to people who just want to earn yield on their stablecoins. It’s hard.

Privacy Concerns

Here’s something that keeps me up at night: KYC on blockchain creates permanent identity records.

In traditional banking:

  • Bank gets hacked → data breach, identity theft risk
  • But transaction history stays with the bank

In permissioned DeFi:

  • KYC provider gets hacked → data breach
  • But your identity is now linked to on-chain addresses
  • Those addresses have immutable transaction history
  • Anyone can see what you traded, when, and for how much

We’re creating permanent surveillance infrastructure and calling it progress.

What Developers Are Saying

In our Discord and GitHub:

The pragmatists: “We have to build this. Institutions won’t use pure DeFi.”
The purists: “We’re betraying everything crypto stood for.”
The realists: “Both are true. So what do we do?”

Most of us land somewhere in the middle—reluctantly building permissioned features while trying to preserve the open core.

Skill Set Evolution

Rachel and Steve talked about institutional adoption. From a dev perspective, that means:

Skills I learned for DeFi:

  • Solidity
  • Web3.js/Ethers
  • MEV protection
  • AMM math
  • Flash loan patterns

Skills I now need for “institutional DeFi”:

  • Compliance frameworks (MiCA, potential US regs)
  • Enterprise authentication (OAuth, SAML for institutional wallets)
  • Audit trail design
  • KYC/AML integration APIs
  • Multi-sig approval flows for corporate treasuries

It’s like being asked to build a sports car but with enterprise fleet management features. The elegance suffers.

But Maybe There’s Hope?

Zero-knowledge proofs could solve some of this. Imagine:

  • Prove you’re an accredited investor without revealing identity
  • Prove you passed sanctions screening without linking to on-chain address
  • Prove you have adequate collateral without showing wallet contents

Protocols like Aztec and zkSync are working on this. If zkKYC becomes real, we could have compliance and privacy.

My Honest Take

As someone who came into crypto because I was excited about accessible, open finance—this whole situation feels like a compromise.

But Rachel’s right that institutions need compliance. And Steve’s right that sustainable business models matter.

I guess I just hope that as we build these bridges between DeFi and TradFi, we don’t lose what made this space special: the ability for anyone, anywhere, to access financial tools without asking permission.

If “institutional DeFi” means my daughter’s generation still needs a bank account and credit score to access global finance… what did we even build this for?

Maybe I’m being too idealistic. But that’s why I got into this space in the first place.

Question for the architects here (looking at you, @blockchain_brian): Are zero-knowledge compliance solutions mature enough yet to give us both privacy AND regulatory compliance? Or is that still science fiction?


Related reading: Biconomy Native Account Abstraction Q1 2026, Circle on EIP-7702 and Pectra Upgrade

Diana, you’re asking the right questions. Emma’s concerns about idealism vs pragmatism cut to the heart of this. Let me offer the architectural perspective.

The Decentralization Maximalist’s Concern

I’ve been in this space since mining Bitcoin in 2013. I’ve watched:

  • Big Blocks vs Small Blocks
  • Proof of Work vs Proof of Stake
  • On-chain vs Off-chain scaling
  • And now: Permissionless vs Permissioned

Each time, the narrative is the same: “We need to compromise on decentralization for [scalability/regulatory compliance/institutional adoption].”

And each time, I worry we’re building a slightly better version of the system we were trying to replace.

If You Need Permission, Why Use Blockchain?

This is the question that haunts me about permissioned RWAs:

What’s the value proposition of blockchain when:

  • You need KYC to participate
  • Transactions can be reversed by admins
  • Contract upgrades controlled by multisig
  • Regulatory bodies can freeze assets
  • Identity providers act as gatekeepers

At that point, you’re using blockchain as a database with extra steps.

The answer institutions give: “24/7 settlement, atomic swaps, programmable logic, global interoperability.”

Fine. But you could get most of that with AWS, Kafka, and a well-designed API layer. Without the gas costs and complexity.

The only thing blockchain gives you that centralized systems don’t: censorship resistance and permissionless composition.

If you throw those away, what’s left?

Historical Parallel: Intranets vs Internet

Emma and Steve mentioned dual-mode protocols. Let me offer a historical analogy:

1990s: Rise of Intranets

  • Companies wanted internet technology but “secure and controlled”
  • Built internal intranets with firewalls
  • Promised “all the benefits of internet, none of the risks”

What happened:

  • Intranets became essential for internal workflows
  • But the open internet is what created trillion-dollar companies
  • Google, Amazon, Facebook didn’t build on intranets—they built on the open web

Today: Permissioned DeFi vs Public DeFi

  • Institutions want blockchain technology but “compliant and controlled”
  • Building permissioned pools with identity gates
  • Promising “all the benefits of DeFi, none of the regulatory risk”

My prediction:

  • Institutional RWAs will become essential for corporate treasury operations
  • But the real innovation will still happen on permissionless rails
  • The next Uniswap, the next Aave—they won’t start in permissioned pools

Maybe There’s a Settlement Layer Thesis

Here’s where I’m cautiously optimistic:

Ethereum (and other L1s) could become the settlement layer regardless of permission model.

Even if most transactions happen in permissioned L2s or private pools:

  • They still settle on public L1 for finality
  • They still use ETH for gas and security
  • They still leverage Ethereum’s validator set for censorship resistance

It’s like TCP/IP: some networks are private (corporate VPNs), some are public (internet), but they all use the same base protocol.

If this thesis is right, then:

  • Public DeFi = Innovation layer (permissionless experimentation)
  • Institutional RWAs = Application layer (compliant workflows)
  • Ethereum L1 = Settlement layer (shared truth)

And rising institutional adoption drives L1 value even if most users never directly touch it.

The Trust Assumptions Problem

But here’s where I get nervous again:

Permissioned systems have fundamentally different trust assumptions.

In public DeFi:

  • Trust the code (audited smart contracts)
  • Trust the validators (economic incentives)
  • Don’t trust any individual party

In permissioned RWAs:

  • Trust the KYC provider (doesn’t leak your data)
  • Trust the admin multisig (doesn’t rug)
  • Trust the regulatory framework (doesn’t change arbitrarily)
  • Trust the institution (honors contracts even when inconvenient)

These aren’t just different—they’re incompatible in many ways.

And if the most valuable transactions (trillions in RWAs) happen in trusted, permissioned systems… does that undermine the security model of the base layer?

Example concern: If most Ethereum value is in permissioned L2s, what happens when a government demands transaction censorship? Do validators comply? Do they fork?

Answering Emma’s Question on zkKYC

@ethereum_emma asked about zero-knowledge compliance solutions. Short answer: They’re maturing but not there yet.

What’s possible today:

  • zkKYC: Prove you passed KYC without revealing identity
  • Proof of solvency: Prove you have X collateral without revealing wallet
  • Selective disclosure: Share only necessary info (e.g., “over 18” without birthdate)

Current projects working on this:

  • Aztec Network (zkSNARKs for private DeFi)
  • Polygon zkEVM (zero-knowledge rollups with privacy)
  • Tornado Cash spiritual successors (controversial but technically sound)

What’s NOT solved yet:

  • Real-time sanctions screening (need to check against OFAC list somehow)
  • Compliance audits (how do you audit what you can’t see?)
  • Legal acceptance (regulators skeptical of “trust the math”)

My take: zkCompliance is the path forward, but it’s 2-3 years from institutional readiness.

What Public DeFi Should Do

For protocols like Diana’s YieldMax:

  1. Stay permissionless at the core – This is your moat
  2. Build optional compliance layers – For institutions who need them
  3. Invest in zkTech – The future is private but compliant
  4. Collaborate with traditional finance – But on your terms
  5. Remember why we’re here – Financial access for everyone, not just everyone who passes KYC

If we’re going to build bridges between DeFi and TradFi, let’s make sure those bridges have on-ramps for ordinary people, not just institutions.

The moment “decentralized finance” means “finance that requires institutional intermediaries and permission,” we’ve lost the plot.


Technical context: A16z Blockchains for TradFi Guide, Chainlink Data Privacy in Banking 2026