Institutional Custody Risk Research
Independent analysis from the Linkmerica Research Team. All briefs are versioned, dated, and produced under the LISR framework. Suitable for institutional reference and compliance documentation.
A Moving Target: Hardware Custody and the Post-Quantum Migration Problem
Hardware custody commits to cryptographic primitives for years through immutable bootloaders that cannot be patched. Algorithm confidence has just demonstrated it can change in sixty hours. Two findings published three months apart read very differently together than apart.
Tempo MPP: Permissioned Validators and the Session-Escrow Custody Surface
Visa operates a production validator node on Tempo — a materially different commitment from joining a consortium. The validator set is a permissioned institutional group, not a decentralised network. Where the Tier 1 cohort raised questions about undisclosed controls, Tempo's institutional backing is unusually concrete, and that concreteness is itself the custody question.
Five Ways an Agentic Protocol Fails Custody: Opacity, Documentation, Architecture, Delegation, and Immaturity
All five Tier 1 agentic payment protocols now carry independent custody scores, completed within 90 days of the framework's founding. Four HIGH, one MODERATE, spanning 6.0 to 7.2 — and each fails for a structurally different reason.
Coinbase AgentKit and x402: From Single-Vendor Standard to Neutral Infrastructure — An Independent Custody Risk Assessment
On July 14, 2026, Coinbase transferred x402 to Linux Foundation governance — 40+ Premier Members now include direct competitors Visa, Mastercard, and Google. Official documentation cautions against using the public facilitator for production mainnet EVM routes.
Visa TAP: The Authentication Layer for Agentic Commerce — An Independent Custody Risk Assessment
Visa's Trusted Agent Protocol has moved from pilot to production with 100+ partners and tier-1 processors. Core finding: every TAP-authenticated transaction depends on a single Visa-operated key directory. The federated model described in the original specification remains unimplemented with no published timeline.
Google AP2 v0.2.0: The Custody Risk Surface of Cryptographic Mandate Infrastructure
Nine months of adoption data on Google's Agent Payments Protocol. The three-mandate cryptographic architecture introduces a custody risk category existing frameworks do not address — authorization custody, not asset custody.
AP4M: 30 Days After Launch — What the Intelligence Record Shows
Built entirely from Linkmerica's own dated agentic monitoring record — June 11 through June 16, 2026. The first institutional research document demonstrating the value of continuous infrastructure surveillance over point-in-time analysis.
Trump's Quantum EOs and Self-Custody: What the 2030 Deadline Means for Hardware Wallet Holders
On June 22, 2026, President Trump signed two executive orders mandating federal PQC migration by 2030–2031. Linkmerica published its quantum readiness assessment one week earlier. This brief maps the federal compliance timeline against the four LISR-scored wallets and the harvest-now-decrypt-later threat vector.
The Quantum Readiness Gap: Rating the Self-Custody Stack Against Q-Day
March 2026 research compressed the Q-Day risk window to 2029–2035. Hardware wallet manufacturers are responding unevenly. This brief maps the four currently-scored LISR wallets against the post-quantum transition — the first independent institutional quantum readiness assessment of hardware wallet custody infrastructure.
Agent Pay for Machines: The Custody Risk Surface of Machine-to-Machine Payments
Mastercard's AP4M introduces a parallel payment infrastructure where autonomous agents authorize and settle transactions across card rails, bank accounts, and stablecoin networks. The first independent institutional custody risk analysis of AP4M — published the day after launch.
Research inquiries: research@linkmerica.com · All briefs are informational only and do not constitute financial or investment advice.