





































Publicly traded companies held 1,264,867 BTC as of July 3, 2026, roughly 6.02% of Bitcoin's maximum supply and about $79 billion in value (Source: BitcoinTreasuries.net data reported by Wu Blockchain).
Hinkal provides privacy infrastructure for stablecoin payments and on-chain financial operations, letting businesses settle, pay out, and manage treasury across public chains while balances, counterparties, and amounts stay confidential, without changing wallets, chains, custody, or compliance controls.
Corporate treasury has moved on-chain faster than corporate disclosure practice has adapted, and the gap is now measurable: every balance, every rebalance, every payroll run, every vendor settlement, and every reserve drawdown is written to a permanent public ledger that competitors, counterparties, and attackers read for free.
The exposure is not limited to holdings, and extends to compensation structure, commercial relationships, burn rate, and runway.
This report maps the full exposure surface of a public corporate wallet in 2026, quantifies what each layer reveals, shows how an analyst reconstructs a treasury from public data, explains why the common workarounds fail, and sets out how to keep settlement verifiable and auditable without publishing the underlying business.
[[KEY_TAKEAWAYS]]
This report covers exposure created by corporate use of public blockchains, across four categories: balances, flows, payroll and vendor payouts, and liquidity or runway indicators.
It draws on 2026 holdings data from BitcoinTreasuries.net, The Block, DefiLlama, and the CEBE tracker, SEC filings from Strive and BitMine Immersion Technologies, on-chain attribution published by Arkham Intelligence, stablecoin payment research from McKinsey and Artemis, BCG, and Bessemer, and security incident reporting from CertiK.
Two boundaries are worth stating up front:
Where sources disagree on a figure, both are given. Where a number is derived rather than reported, the inputs are shown.
Corporate crypto treasury stopped being a curiosity and became a balance sheet category.

Every figure above describes capital sitting in wallets that publish their own activity. Filings report these positions quarterly. The chains report them continuously, and they report far more than the position.
The first thing a public wallet publishes is how much you have, and concentration makes that unusually legible.
Strategy holds between 843,775 and 847,363 BTC depending on the reporting date, roughly two thirds of all public company Bitcoin and about 4% of total supply, with an aggregate cost basis near $63.7 billion and an average purchase price around $75,500 (Source: Cryptobriefing, July 2026). Twenty One Capital holds approximately 43,514 BTC, Metaplanet approximately 43,000 BTC, and MARA Holdings approximately 36,303 BTC (Source: BitcoinTreasuries.net via Wu Blockchain).
The top 20 firms account for more than 90% of public corporate Bitcoin in most 2026 rankings.

Attribution turns that concentration into a live feed. Arkham Intelligence verified approximately 83% of Strategy's Bitcoin position directly on-chain in mid-July 2026, with roughly 184,000 BTC identified as sitting with a custodian (Source: Arkham Intelligence). That is the number that matters for this report. Attribution is not theoretical. It is a commercial product, and it works.
On-chain balance visibility differs from filed disclosure in three ways that matter operationally.

BitMine Immersion Technologies disclosed 5,777,468 ETH with approximately 85% staked, alongside $385 million in cash and marketable securities and 207 BTC (Source: BitMine 8-K, July 20, 2026). The staking position, the validator relationships, and the reward flows are all independently observable regardless of what the filing says.
For companies that are not treasury vehicles, and this is the larger group, balance exposure is pure downside. A payments company, an exchange, a fintech, or an iGaming operator gains nothing from publishing its float, and loses leverage in every negotiation where the counterparty can read it.
Balances are a photograph. Flows are the film, and they are more revealing.
Every acquisition publishes size, price band, timing, and often the venue. Digital asset treasury companies deployed at least $49.7 billion on crypto purchases in activity carrying into 2026 tracking, each creating a permanent record of when, how much, and through whom (Source: Hinkal, 2026 analysis). Q3 2025 alone accounted for roughly $25 billion of deployment, while early 2026 monthly inflows slowed sharply, to around $555 million in one reported low period.
Anyone tracking those wallets watched the slowdown in real time, before it appeared in commentary.
Sales are more sensitive still, because a sale by a self-described permanent holder is a signal about liquidity, not about price.

Read as a set, those events describe a sector rotating from accumulation to liquidity management. Each company published that rotation itself, in advance of explaining it. The timing gap between the on-chain movement and the press release is the exact window in which the information is worth the most to someone else.
Flow exposure also covers what a company never intends to announce: the treasury desk testing a new venue with a small transfer before a large one, the bridge route chosen for a cross-chain rebalance, the market maker whose address receives the block, and the pattern of splitting a large order across days. Execution strategy is a competitive asset. On a public chain it is a public document.
Payroll is the clearest illustration that exposure, not cost or speed, is the binding constraint on on-chain finance.
Fewer than 1% of businesses run payroll on public-chain crypto in 2026, and the reason cited consistently is that doing so permanently publishes every salary, every bonus, every contractor rate, and the treasury balance funding them (Source: Paxos Labs, 2026). The rails are not the problem. Stablecoin transfers settle in seconds at sub-cent cost across most networks, against two to five days and 2% to 5% for traditional cross-border rails (Source: Chainalysis, 2026). The disclosure model is the problem.
A single payroll batch publishes four things at once:

The market response in 2026 has been to build confidential payroll rails rather than accept the disclosure. Private stablecoin payroll deployments, including work by Toku with Aleo and Paxos Labs, exist specifically to process compensation without exposing salaries or treasury flows on-chain, and Toku alone has handled more than $1 billion in prior token payroll volume (Source: Paxos Labs, 2026). That volume is a useful measure of how much compensation data would otherwise have been public.
Business-to-business settlement is the largest genuine stablecoin payment category, at roughly $226 billion annually and close to 58% of real payment volume out of a $390 billion total (Source: McKinsey and Artemis Analytics, February 2026). B2B stablecoin payments grew 733% year over year in 2025, and real-world stablecoin payment volume doubled to around $400 billion (Source: Bessemer Venture Partners, April 2026).

Adoption at that scale is now visible in ordinary corporate operations. Ramp launched Solana-based stablecoin business accounts in July 2026, letting companies pay vendors and contractors in USDC and USDT across more than 140 countries, with over 1,000 organisations already using comparable Ramp stablecoin rails for international supplier payments (Source: Blockonomi, July 2026).
Tokyo-listed logistics firm AZ-COM Maruwa announced plans to pay approximately 2,300 business partners, including subcontractors and truck drivers, in the yen-pegged JPYC stablecoin, described as Japan's first large-scale corporate use of a local-currency stablecoin for contractor pay. Wirex pivoted toward stablecoin banking-as-a-service for corporate clients in July 2026, targeting B2B, e-commerce, and supply chain settlement.
Each of those flows writes a counterparty graph to a public ledger, and that graph is a commercially sensitive document.

The asymmetry is what makes this expensive. A competitor operating on traditional rails reads your entire counterparty graph while publishing none of their own. Institutional stablecoin playbooks acknowledge the tension directly, promoting on-chain B2B invoicing and settlement for speed and cost while noting that transmissions, balances, and counterparties are fully visible, and that transaction screening is required precisely because of that visibility.
The most sensitive number in any company is how long it can keep operating. On-chain, that number is derivable.
Strategy's USD reserve reached $3.225 billion as of July 19, 2026, built through equity sales, with holdings held steady at 843,775 BTC that week (Source: CoinDesk, July 2026). Earlier June 2026 figures put the reserve near $2.55 billion, providing roughly 17.4 months of coverage against approximately $1.76 billion in annual expected preferred dividends and interest, against a board minimum policy of 12 months.
Later July commentary referenced roughly 20 to 22 months of coverage, and combined with authorised Bitcoin monetisation capacity of up to $1.25 billion, total coverage approached 26 months under that framework.
Filing-verified cash runway across tracked treasury firms sits in a narrow, readable band as of July 23, 2026 (Source: CEBE tracker):

Average sector claims percentage, meaning senior claims diluting common equity exposure to the underlying Bitcoin, ran around 23%, rising to roughly 34% for Strategy and 45% for Strive (Source: CEBE tracker, July 23, 2026).
Filings supply part of this picture and wallets supply the rest, continuously. Strive disclosed cash and cash equivalents rising from $141.7 million to $153.4 million between June 26 and July 2, 2026 alongside a purchase of 17.76 BTC at approximately $59,850 (Source: Strive 8-K, July 6, 2026). For any company whose operating stablecoin balances sit in attributable wallets, the equivalent movement is visible daily rather than quarterly, and without the framing a filing provides.
For private companies the exposure is worse, because there is no filing to contextualise it. A venture-backed business paying its team and vendors from a public wallet publishes its burn rate and its runway to every competitor, every acquirer, and every prospective investor, continuously, on the worst possible schedule, which is the one where a bad month is visible before the recovery is.
The reconstruction is not exotic. It follows a repeatable sequence, and commercial tooling automates most of it.

The whole sequence is cheap, and that is the point. Financial intelligence that once required a subpoena, an insider, or an investigative team is now a subscription.
CertiK recorded 52 wrench attacks worldwide in H1 2026, meaning physical violence or robbery tied to crypto holdings, a 33% increase year over year, with $124.1 million in associated financial exposure (Source: CertiK H1 2026 report). Home invasions became the dominant vector, frequently enabled by leaked personal data that links an identity and a location to visible on-chain wealth.

For corporate treasuries the relevant risk is that a wallet identifies the people with access to it. Signers on a multisig, finance staff receiving payroll, and executives holding company tokens all become targets once holdings are visible and attribution is possible. Confidentiality at the settlement layer is a personnel safety control as much as a commercial one.
Most treasury teams have tried some version of the following, and none of them hold.
New addresses are linked by the transaction that funds them, and clustering heuristics resolve rotation in seconds. Rotation raises operational overhead and reconciliation burden while providing negligible privacy.
A centralized venue breaks the on-chain link but replaces it with counterparty and compliance risk, adds settlement delay, forfeits custody during transit, and creates a complete record with a third party. It also does not work for recurring payouts to counterparties who need to be paid directly.
Chunking a large movement into smaller ones creates a distinctive pattern that clustering tools flag rather than miss. It increases fee cost and reconciliation complexity while making the wallet set easier to identify, not harder.
Effective for entry and exit, useless for ongoing operations. Payroll, vendor settlement, and treasury rebalancing still have to touch the chain.
The most common proposal and the most expensive. It requires moving custody, integrations, liquidity, compliance tooling, and counterparties to a new environment, imposes a two-sided adoption problem because your vendors and clients must also migrate, and strands you on a network with thinner liquidity and fewer stablecoin options than the ones you left.
Non-starters for any regulated business. They provide no screening at the entry point, no selective disclosure for auditors, and they carry sanctions exposure that no treasury committee will accept.

The pattern across all six is the same. Each either fails technically or forces the business to change something it cannot change. What treasury teams need is confidentiality that fits into the stack that already exists.
Run this against your own operations before assuming your exposure is limited.
Any single yes on questions one through nine means the rest of the list applies.
Hinkal is a smart contract deployed on the public chains you already use, letting users hold private balances controlled by their existing wallet keys. It is not a mixer, not a private L1 or L2, and not a privacy rollup. There is no network to migrate to and no new custody model to approve.
Instead of a direct wallet-to-wallet transfer, funds are held in and moved from a private account inside the Hinkal smart contract. Zero-knowledge proofs, specifically zkSNARKs using Groth16, prove each transaction is valid without revealing its contents.
On-chain, an observer sees the Hinkal smart contract and the relayer address, and does not see sender, recipient, or amount.
There are four flows:

The Public to Public flow removes the two-sided adoption problem. Funds start in an ordinary wallet and arrive at an ordinary wallet, while the deposit into the contract and the withdrawal out of it are cryptographically unlinkable.
Your vendor, contractor, or client needs no shielded address, no new wallet, and no onboarding, and gets paid the way they always do.
Mapped back to the five exposure layers, balances are held privately and controlled by existing keys, flows stop publishing accumulation and rebalancing timing, payroll settles without publishing amounts or recipients, the vendor and B2B counterparty graph leaves the public ledger, and runway is no longer derivable from wallet activity.

Hinkal has operated in production for more than three and a half years, has completed 6 security audits, and has processed over $500 million in cumulative private volume across Ethereum, Polygon, Arbitrum, Optimism, Base, Solana, TRON, Arc, and Tempo (Source: Hinkal). Enterprise settlement is priced at 10 basis points, or 0.10% per transaction.
The company is backed by Draper Associates, SALT, SNZ Capital, and NGC Ventures, and was incubated at Stanford and through Binance MVB.
Privacy at the settlement layer means opacity to the public ledger, not opacity to your auditor, your regulator, or your compliance team. That distinction is structural, and it is what separates confidential settlement infrastructure from sanctioned obfuscation tools.
For a regulated institution the practical test is whether an examiner can be satisfied without a public disclosure. Scoped viewing keys plus pre-transaction screening plus exportable history is a stronger audit posture than a public explorer link, because it produces a complete, decrypted, attributable record rather than a set of addresses an examiner has to interpret.
End-to-end confidential settlements and payouts across Solana, TRON, Ethereum, and major EVM networks. Connect an existing wallet, move funds to a private balance, and settle privately or out to any public address. Suited to teams that need confidential settlement without an engineering project.
The enterprise control surface for confidential treasury and payouts, with permissioned multi-user access so a finance or treasury team operates together with defined roles, pending payouts queued and reviewed before execution, batch payouts that settle many recipients in one confidential operation for payroll, vendor, and contractor runs, and compliance controls on high-value transactions with viewing-key audit access.
The same protocol is exposed as an API and an SDK for products that want privacy embedded underneath their existing stack.
A multichain wallet that shields balances and transaction history while supporting swaps, transfers, and DeFi execution from a private account.
For custodians, institutional wallets, embedded wallet providers, payroll platforms, PSPs, merchants, exchanges, on-ramps, stablecoin card issuers, iGaming operators, and fintechs, the highest-leverage path is Hinkal Integrations: a private balance sitting next to the regular balance in your product, and a private send sitting next to the regular send.
Nothing in that sequence requires changing chains, wallets, stablecoins, custody arrangements, or compliance vendors. That is the design constraint the entire product is built around.
Hinkal is the privacy infrastructure that lets businesses run treasury, settlement, and payouts on public chains while balances, counterparties, and amounts stay confidential, with existing wallets, existing chains, and existing compliance controls fully intact.
The evidence in this report is consistent across every source: more than 1.26 million BTC and roughly $134 billion in corporate digital asset value now sit on ledgers that publish every balance change, every payout, every counterparty, and every reserve drawdown in real time.
That exposure compounds across five layers, from holdings to flows to compensation to vendor relationships to runway, and commercial attribution tooling has made reading it cheap enough that anyone can.
Migration to a private chain is not the answer, because the cost is the business itself. Adding a confidential settlement layer on the chains you already operate on, with Chainalysis KYT screening at the entry point and scoped viewing keys for auditors, closes the exposure without touching anything else.
Book a demo with the Hinkal team to map your treasury exposure and see a confidential batch payout run end to end.
Read Next:
Public corporate wallets reveal a company's treasury balances, accumulation and sale timing, rebalancing strategy, payout cadence, counterparty relationships, individual compensation, and derivable burn rate and runway. Because public blockchains record every transaction permanently, this information is available continuously rather than on the company's disclosure schedule, and commercial attribution platforms including Arkham, Chainalysis, and Elliptic cluster and label wallets so a single identified address expands into a full operational picture. Arkham verified approximately 83% of one public company's Bitcoin position directly on-chain in mid-July 2026, which illustrates how complete that picture can be.
The amount of corporate crypto publicly visible on-chain in 2026 exceeds 1.26 million BTC held by public companies, about 6.02% of Bitcoin's maximum supply and roughly $79 billion in value as of July 3, 2026, plus approximately 7.67 million ETH in tracked institutional and public company holdings and around 16.8 million SOL across about six public companies. Digital Asset Treasury Companies collectively held $134 billion in crypto as of January 1, 2026, up 137.2% year over year. Every one of those positions, and every movement in or out of them, is recorded on a public ledger.
Competitors can see corporate payroll and vendor payments on-chain whenever those payments settle on a transparent public network, because each transfer permanently records the recipient address, the amount, and the timestamp. Recurring transfers identify salaried staff, off-cycle transfers identify bonuses and severance, and outbound vendor payments reveal supplier identity, negotiated pricing, contract cadence, and client concentration. This is the primary reason fewer than 1% of businesses run payroll on public chains in 2026, despite stablecoin rails being faster and cheaper than correspondent banking.
A company can hide its treasury balance without breaking compliance by settling from a confidential balance on the chain it already uses, with screening at the entry point and selective disclosure for auditors. Hinkal holds private balances inside a smart contract on public chains, controlled by the company's existing wallet keys, and proves every transaction valid with zkSNARKs while keeping sender, recipient, and amount off the public ledger. Chainalysis KYT screens wallet addresses before execution, scoped and revocable viewing keys let auditors and regulators decrypt exactly what they need, and transaction history is downloadable out of the box, which is a stronger audit posture than a public explorer link.
The best way to prevent on-chain treasury exposure in 2026 is to add a confidential settlement layer to the chains, wallets, and stablecoins already in use rather than migrating to a private network. Hinkal Pay and Hinkal Prime execute treasury movements, batch payouts, and vendor settlements from private accounts controlled by existing wallet keys, with a relayer broadcasting so the company's wallet never appears as transaction origin. The Public to Public flow means recipients need no new wallet and no shielded address, which removes the two-sided adoption problem that makes migration-based privacy approaches fail in practice, and Hinkal Integrations lets wallets, PSPs, payroll platforms, and custodians embed the same privacy underneath their own product.






















