BriefingThesis
PaymentLeaks
BriefingThesis
0:00 on page
ES|EN
IN
IGNACIO DE NAVASCUÉS
EDITOR · 12Y IN PAYMENTS
Today2026-03-29

Today's briefing, and why it matters to you.

2026-03-29
Yesterday's data2026-03-29

Top 3 · Systemic Impact

TODAY
1Systemic

Anthropic Mythos AI leak — Chinese group uses Claude to infiltrate ~30 financial institutions

A Chinese state group was discovered using Claude Code to infiltrate ~30 organizations, including financial institutions. Anthropic accidentally leaked details of "Claude Mythos", an unpublished model with capabilities to discover zero-day vulnerabilities in production code. Cybersecurity stocks fell sharply. This is not a theoretical risk — it's an operational weapon in the hands of state actors. Every PSP and acquirer with legacy code (i.e., all of them) needs to reevaluate their attack surface assuming that the adversary has foundation model-level code analysis tools. - [Fortune](https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/) - [CoinDesk](https://www.coindesk.com/tech/2026/03/28/here-s-what-next-as-anthropic-s-most-powerful-ai-model-leaked-via-unsecured-data-cache)

SourcesFortune↗·CoinDesk↗
2Systemic

USDC surpasses USDT in volume for the first time — $2.55T vs $1.49T in Q1 2026

Structural shift in stablecoins. Circle won the institutional volume battle while Tether retains market cap dominance ($184B). The catalyst: GENIUS Act + Circle's compliance-first stance. Simultaneously, Fiserv launched FIUSD with distribution to 10,000 FIs and 6M merchants. The question for PSPs and acquirers is no longer "do we adopt stablecoins?" but "which one, and when do we get left out if we don't?" - [Motley Fool](https://www.fool.com/investing/2026/03/27/usdt-vs-usdc-which-will-win-the-stablecoin-race/)

SourcesMotley Fool↗
3Systemic

Weekend of deadlines: 4 regulations in effect in 48 hours

Unprecedented confluence: DORA Register of Information (Monday, only 6.5% passed quality checks), Indonesia TIKMI (new payments architecture), PayPay absorbs LINE Pay (near-monopoly Japanese QR, 67M+ users), and RBI mandatory 2FA for ALL digital payments in India (Tuesday, 1.4B people). Four markets representing >2B people change regimes simultaneously. Whoever isn't ready Monday morning is already too late. - [CSSF DORA](https://www.cssf.lu/en/2026/03/dora-register-of-information-collection/)

---

SourcesCSSF DORA↗

News by Impact

24 STORIES
ALTA

OpenAI launches Agentic Commerce Protocol with Walmart, Target, Best Buy, Sephora — Morgan Stanley projects $385B in agentic commerce by 2030. The battle to be the AI agent checkout is open and card schemes aren't the only possible rail.

CNBC
ALTA

Mastercard LTM — foundation model for transactional data with 300% fraud detection improvement.

MC builds 3-layer stack (LTM + behavioral biometrics + Decision Intelligence) with no public Visa equivalent.

DevX
ALTA

Wero: Trump fears accelerate European sovereignty — 52.5M users.

The adoption argument shifted from cost/UX to geopolitical sovereignty.

Reuters
ALTA

Fed vs Wall Street

market pricing 3 cuts, Fed says 1 — biggest disconnect in years. If the Fed is right, BNPL, auto loans and mortgage rates get more expensive than expected.

MarketMinute
ALTA

SEC publishes Post-Quantum Financial Infrastructure Framework.

Google shortened PQC timeline to 2029. 16 global banks already have quantum programs. Migration is no longer optional.

SEC
ALTA

LankaPay + WeChat Pay

cross-border QR in Sri Lanka, 400K merchants, MDR capped at 1.8%. China weaves QR network that completely bypasses Visa/MC in Asia. Fintech Singapore | Daily FT

No source
ALTA

Brazil: 3 new PIX measures in effect — MED 2.0, self-service fraud, new limits.

Brazilian BC executed 3 regulatory actions in one week.

Estado de Minas
ALTA

80% of acquirers say they're ready for agentic commerce, but merchants aren't — gap creates opportunity for intermediaries.

PYMNTS
ALTA

Palo Alto Unit 42: Iran cyber threat against financial sector escalating.

FIs with US/Israel ties are priority targets.

Unit 42
MEDIA

PayPay +24.6% after NASDAQ Composite inclusion — Japan's most valuable fintech.

Monday closes LINE Pay absorption. SoftBank retains 92% vote.

Simply Wall St
MEDIA

Indonesia PP Tunas forces payment apps to block under-16s.

Impacts wallet onboarding in country with high youth mobile penetration.

MataMata
MEDIA

Mexico: 86M digital users projected, 795 active fintechs, but 85% of <500 peso payments still cash.

Fintech Law 2.0 on horizon.

EbankingNews
MEDIA

Africa mobile money exceeds $2T — MTN MoMo processes $500B alone.

PayPal announces cross-border wallet for Africa in 2026.

Technext
MEDIA

Zepz (WorldRemit/Sendwave) — CEO resigns. Signal of remittance consolidation

pure-play loses to super-apps.

Fintech Futures
MEDIA

Credit Agricole JV with Worldline + Barclays explores options for Barclaycard.

European acquiring map redrawn while Adyen leads in revenue.

Business of Payments
MEDIA

Nacha deadline forces proactive ACH fraud detection.

Sub-100ms latency is the new standard.

Sardine.ai
MEDIA

ECB DLT collateral — tokenized assets accepted as collateral from tomorrow March 30.

Milestone for European institutional tokenization.

ECB
MEDIA

MercadoLibre increases Argentina investment 30% to $3.4B — Mercado Pago 78M MAUs with super-app ambition.

Simply Wall St
MEDIA

Bre-B Colombia +29% growth, QR for individuals in H1 2026.

Colombia Fintech
MEDIA

Recorded Future: payment fraud increasingly automated — Mastercard defines future as "AI vs AI".

Mastercard
MEDIA

SAMA updates Saudi payment oversight framework — applies to all Kingdom payment system operators.

Lexis.ae
MEDIA

Fiserv FIUSD — first banking stablecoin with scale distribution (10K FIs, 6M merchants).

Forbes
MEDIA

MENA fintech: tokenized wallets and GCC-Africa corridors dominate.

UAE $212.4B in digital payments.

GlobeNewswire
MEDIA

BCG: "Beyond Payments" — Africa needs to move from payments to credit and interoperability.

Nigeria captures 35% of African tech investment.

BCG

Exposure Check

  • Anthropic/Claude exposure: Any FI using Claude Code or Anthropic APIs in production should audit access immediately. The Chinese group exploited model capabilities to find vulnerabilities — if your code goes through these models, review what data is exposed.
  • DORA non-compliance: Only 6.5% of ROIs passed quality checks. If you have European counterparties who didn't deliver, Q2 enforcement actions may impact operations.
  • Circle: -20% last week due to CLARITY Act + wallet freezing. Direct exposure for those with USDC in treasury or settlement flows.
  • Iran — cyber escalation: Unit 42 confirms active escalation against FIs with US/Israel ties. If you process payments in those corridors, reinforce SOC now.

Connect the Dots

[Anthropic Mythos leak] + [LiteLLM supply chain attack March 26] + [97% US banks compromised via thirds] → Triple convergence of AI+supply chain risk. State actors now have foundation model-level code analysis tools, AI supply chains (LiteLLM, 95M downloads/month) are compromised, and 97% of US banks already have breaches via third parties. Most likely Q2 attack vector: compromised AI agent operating within financial infrastructure with legitimate permissions.

[USDC flips USDT in volume] + [Fiserv FIUSD launch] + [MC acquires BVNK for $1.8B March 24] → Incumbents already chose regulated stablecoins as settlement rail. This isn't experimentation — it's infrastructure. BVNK gives MC native stablecoin capability, Fiserv distributes to 10K FIs, and institutional volume confirms USDC as standard. The GENIUS Act is the missing legislative catalyst.

[OpenAI ACP + Shopify Agentic Plan] + [80% acquirers ready, merchants not] + [Stripe enables agentic payments on Facebook March 28] → The future checkout isn't a webpage. Stripe, OpenAI and Shopify build the new purchase funnel where the AI agent is the intermediary. Acquirers have the pipeline ready but merchants don't know how to connect it. The middleware that solves that gap in the next 12 months captures a $385B market.


Active Follow-ups

  • DORA ROI (since March 24): Went from "imminent deadline" to "compliance crisis". Only 6.5% passed quality checks. Luxembourg only 40% delivered. Q2 enforcement actions expected.
  • PIX MED 2.0 (since March 24): Already operational. Cascading fraud recovery active. Brazilian BC executed 3 actions in one week (eFX + Entrepay liquidation + MED 2.0).
  • ECB DLT Collateral (since March 25): Operational tomorrow. From announcement to execution in 5 days.
  • Iran cyber threat (since March 24): Escalation confirmed by Unit 42, FINRA and NYDFS. Oil $112.57, Iran charges toll in yuan at Hormuz.
  • Fed crisis (since March 27): Powell threatened by DOJ, Warsh blocked in Senate, mandate expires May 15. Gold fell -23% from ATH. US monetary uncertainty is the biggest macro risk for global payments.
  • Wero (since March 24): From 50M to 52.5M users in 5 days. Narrative shifted from "A2A alternative" to "European sovereignty against Trump". Worldpay joined as Principal Member.
  • PayPay-LINE merger (since March 26): Closes Monday. +24.6% on stock market post-NASDAQ inclusion. Japanese QR near-monopoly confirmed.

Notable Silence

  • Stripe-PayPal acquisition: Bloomberg reported acquisition evaluation March 24 ($159B vs PayPal in free fall post-CEO ousted). Total silence since. With PayPal bleeding (-$10B market cap, class action, CEO dismissed), optimal buy moment is now. If Stripe hasn't made public move, either due diligence revealed serious problems or they're negotiating in silence.
  • GENIUS Act vote: The law that would catalyze institutional stablecoin adoption in US has no confirmed vote date. The entire market (USDC flip, Fiserv FIUSD, MC BVNK) bets it passes, but Congress hasn't scheduled.
  • Visa response to MC LTM: Mastercard has spent two weeks announcing AI capabilities (LTM, behavioral biometrics, agentic live) without public Visa response. Either Visa is preparing something big or losing the innovation narrative.
  • China retaliation post-Anthropic leak: A Chinese state group was exposed using US AI to infiltrate FIs. Beijing's diplomatic and technical response hasn't appeared. Historically, public exposure of Chinese cyber operations generates asymmetric retaliation in 30-60 days.

Weak Signals

  • Indonesia PP Tunas (minor protection in payment apps): Regulation forcing blocking of under-16s in payment apps. Early signal that digital wallet onboarding regulation will expand to other markets with young demographics. If this replicates in India, Africa or LATAM, the addressable mobile money base contracts significantly. At 3-6 months: expect similar legislation in Philippines, Vietnam.

  • Riksbank requires crisis/war-proof payments infrastructure + mandatory cash: Sweden, the world's most cashless country, reverses course. SEK 10K cash mandatory, offline cards mandatory July 2026. The war in Ukraine and tension with Iran make Nordic central banks reconsider total digital dependency. In 3-6 months: other Nordic and Baltic countries will follow. Implication for payments: all infrastructure must have offline fallback.

  • Turkey: TCMB suspends 9 payment entities (Sipay, Vepara, Fzypay, Papara, Ininal): The Turkish crackdown is the biggest fintech purge in an emerging market in 2026. Coincides with EU proposal for Turkey to join SEPA (85M people). Turkish regulatory cleanup prepares ground for European infrastructure integration. In 6 months: Turkey as EU-MENA payments bridge.

  • France: payment fraud +23% since January, 30K cards on dark web, QR fraud x4: France emerges as Europe's payments fraud epicenter. The QR fraud x4 data is especially relevant given Wero's push towards QR payments. If Wero scales e-commerce and POS without solving the QR vector, fraud rate could damage adoption.

Convergence — 6-12 Month Thesis

This week's most dangerous convergence:

Tokenization + Agentic Payments + AI = new systemic attack vector.

ECB accepts DLT collateral tomorrow (tokenization operational). OpenAI launches ACP for AI agents to buy for you (agentic payments operational). Anthropic Mythos demonstrates that a foundation model can find zero-days in financial code (offensive AI operational). SEC publishes post-quantum framework (recognition that current encryption has expiration date).

Convergence: when an AI agent has permissions to execute tokenized payments, and the adversary has a foundation model that finds vulnerabilities in the code managing those payments, systemic risk multiplies. It's not each individual piece — it's the combination.

CBDCs + Stablecoins = regulated coexistence, not competition. Digital Dirham uses mBridge (CBDC), while USDC dominates institutional volume in the West. Fiserv FIUSD distributes to banks. Rails don't compete — they coexist by jurisdiction. Regulation (GENIUS Act, MiCA, CLARITY Act) defines which rail operates where.

Regulation + Fragmentation = compliance as entry barrier. DORA, TIKMI, RBI 2FA, SAMA, FATF Travel Rule — regulatory density is such that only players with compliance-as-infrastructure survive. Those treating compliance as cost will be acquired or liquidated (like Entrepay in Brazil).

Parallel sovereign rails

· position, not only news4 RAILS

Fragmentation advances steadily:

  • CIPS (China): First renewal in 8 years — dual settlement, multi-currency. Processed $26.4T, direct participants +40% to 193. Standard Bank (Africa) joins. Key data: mBridge registered 95.3% of volume in digital yuan (387.2B CNY). CIPS is no longer alternative — it's operational parallel infrastructure.

  • WeChat Pay / QR network (China): Sri Lanka (400K merchants) joins the network. MDR capped at 1.8% by central bank — direct undercut to Visa/MC. With Thailand, Malaysia, Singapore and Indonesia already connected, China has a cross-border QR network covering >2B people without touching Western infrastructure.

  • UPI (India): 240B transactions projected FY26, >800M daily. Expansion to Sri Lanka via LankaQR. RBI in talks with 4-5 central banks about cross-border CBDC. On April 1, mandatory 2FA changes rules for the entire ecosystem.

  • PIX (Brazil): MED 2.0 operational — real-time cascading fraud recovery. BCB executed 3 regulatory actions in one week. Liquidated Entrepay/Acqio/Octa (first 2026 shutdown). PIX doesn't just scale — it aggressively regulates its ecosystem.

  • Digital Dirham (UAE): Launched with mBridge cross-border. UAE positions as Gulf CBDC hub connecting with Chinese system.

Verdict: Fragmentation is no longer trend — it's operational reality. Each system has its own scale, own regulation, and zero dependence on US infrastructure. The only real bridges between these systems are regulated stablecoins (USDC) and bilateral QR agreements.

Archive · Past coverage

3 RELATED
2026-03-28
Mastercard sells Nets (RTP) and bets everything on on-chain stablecoins
CircleTether
2026-03-27
FTC threatens Visa, Mastercard, PayPal and Stripe over "debanking"
CircleTether
2026-03-26
CLARITY Act bans yield on stablecoins — Circle -15%
Circle
← 2026-03-282026-03-30 →

Never miss a briefing

Get notified every morning when the briefing is ready.

Anything to improve? Tell me.

I read everything. If anything's missing, extra, or broken in the briefing, I'd love to hear it.

PaymentLeaks

PaymentLeaks is built by Ignacio De Navascués — 12 years in the payments industry. Daily intelligence on global payments, fintech and sovereign rails, hand-curated and analyzed every morning.

Content
  • Today's briefing
  • Glossary
  • See sample
  • FAQ
About
  • About PaymentLeaks
  • Privacy
  • Terms
© 2026 PaymentLeaks · MadridIndependent analysis. Not financial advice.