Essay · Market Structure

AMM, RFQ, or Order Book? A Market-Structure Test for Tokenized Assets

·14 min read·Andrew Nalichaev

A reusable five-part test for deciding which execution mechanism fits a tokenized instrument: price anchor, correctability, inventory economics, flow profile, and lifecycle discontinuities.

Asking whether a tokenized asset belongs on an AMM is like asking whether a bond belongs on a screen. The answer depends on who forms the price, who can correct it, what size is being traded, and whose balance sheet stands behind the quote.

The question is underspecified because the token is the wrong unit of analysis. Venue suitability is not a permanent property of a token: it depends on the instrument, the trading pair, the primary-market path, the eligible participant set, the characteristics of the order, and the state of the market at that moment. Change any one and the answer can change with it.

Current and announced market designs for tokenized assets already span RFQ routes, central-order-book venues, and permissioned AMM rails rather than converging on one mechanism. Dowgo, for instance, describes a planned venue built around a central order book with market makers; its authorization remains under review and the company states it is not yet authorized, making that an announced design rather than an observed production market. The plurality is the point: once several mechanisms coexist, something has to decide which handles a given order.

What follows is a way to decide — not a ranking of venues, but a diagnostic of five properties that determine what kind of liquidity is possible, and which mechanism should carry which order.

Three ways to commit a balance sheet

I think the useful distinction between execution mechanisms is not their interface but the moment at which a balance sheet commits, and what it knows when it does.

An AMM commits capital before the order exists. Prefunded liquidity becomes executable at a deterministic schedule of prices before the next order's attributes — size, direction, information content — are known. That is valuable when small trades must execute without waiting for a counterparty, and expensive when the arriving order is informed, large, one-sided, or hard to hedge.

Those costs get collapsed into one label and are worth separating. First, inventory funding and opportunity cost. Second, adverse selection from informed flow generally. Third, loss-versus-rebalancing — a narrower, precisely defined quantity: the loss created when arbitrageurs trade against an AMM price that has fallen behind an external reference. LVR is a component of the cost of prefunded commitment, not a synonym for it.

An RFQ participant commits after disclosure. It sees the instrument, side, size, and timing before pricing, so hedge cost, inventory, and eligibility enter that specific quote rather than a standing curve. This does not eliminate risk — the quoting party still bears information risk about why the order arrived and hedge risk on what it now holds — it relocates the decision to a point where more is known. The trade-off is weaker pre-trade transparency and dependence on participants actually responding.

Adjacent-market evidence is suggestive without being decisive. In a 2025 study of European ETFs, RFQ specialized in institutional-sized trades, showed lower measured price impact than matched lit executions, and was associated with primary-market flows. That is evidence from European ETFs, not a result about tokenized assets. Tokenized funds with functioning creation or redemption facilities may exhibit a similar inventory-correction link, but that remains a hypothesis until transaction data exist — and it does not apply to structures without a two-way primary facility.

The BUIDL route illustrates the distinction concretely. Uniswap Labs and Securitize describe Securitize Markets facilitating trading for pre-qualified investors, with whitelisted market participants known as subscribers — including Flowdesk, Tokka Labs, and Wintermute — competing to supply quotes, and the selected bilateral trade settling atomically onchain. Atomic onchain settlement does not turn the route into AMM price formation. The execution price is formed through order-specific quotes submitted after the request is known.

A limit order book sits between the two. Participants choose discrete prices and quantities and can normally revise or cancel before execution, so commitment is conditional on information yet visible in advance. Displayed orders can contribute to price discovery, but a book does not guarantee it: that depends on participant breadth, quote independence, and real executable interest behind the displayed size. A thin book supported by one market maker is one balance sheet presented through a different interface. Research on coexisting order books and AMMs models their interaction and identifies liquidity spillovers between the two. I take that as support for treating them as potentially complementary rather than as pure substitutes.

Two mechanisms belong here despite being missing from the title. Batch and call auctions delay execution to aggregate orders and information into one clearing event, the right structure when information arrives discontinuously. Primary issuance and redemption is not a secondary venue, but supplies the correction path that makes every secondary venue credible.

The point that ties them together: an algorithm does not eliminate market making. It standardizes how a prefunded balance sheet is exposed. Which is also why onchain settlement and onchain price formation must be kept separate. A contract can settle atomically on a public chain while its price originates from an external market, an oracle, or a quoting party's own book.

The five-part market-structure test

What follows is a diagnostic framework, not a score. Averaging these five would hide what matters most: some constraints are hard and cannot be offset by strength elsewhere.

Test 1 — Price anchor: what makes a quote economically defensible?

Ask where the economically authoritative price originates: a continuously observed external market, a periodically struck NAV, an appraisal, a model, or only the last transaction. Ask how often it changes, whether it stays meaningful outside the reference market's hours, and who is accountable when it is stale. The instrument's legal shape matters too, since a direct interest, a fund share, and a tracker certificate can reference the same underlying while diverging in unit value under stress.

Two products on the same tokenization infrastructure can sit at opposite ends of this test. Superstate documents USTB with a continuously updated NAV per share and market-day liquidity, while CUSHY uses periodic redemptions, with proceeds delivered on a dealing day for requests from the prior quarter. The wrapper does not determine the venue. The pricing clock does.

The claim to avoid is that AMMs cannot discover prices. They can participate in price discovery where informed and uninformed flow interact and the AMM market is economically significant. The narrower defensible claim is that a thin pool around an asset with an external or periodic valuation is unlikely to become the primary source of independent price discovery. Note too that Uniswap v4 hooks can implement custom pricing, dynamic fees, and bespoke swap logic, so a contract deployed in Uniswap is not automatically an AMM in the price-formation sense. Name the upstream price authority.

Test 2 — Correctability: who can close a deviation, and how fast?

A price anchor is only useful if someone can act on it. Ask who may mint or redeem, whether the path runs both ways, how long it takes, and what minimums, caps, and cutoffs apply. Ask whether participants eligible for the secondary venue are also eligible for the primary facility, and whether the mechanism still functions under stress.

Ondo's OUSG documentation is precise enough to make this measurable. Instant minting and instant redemption each carry a documented $5,000 minimum, and instant activity is bounded by published limits: a $50 million global and $25 million individual instant-mint limit per 24 hours, with a separate $50 million global and $25 million individual instant-redemption limit on the same basis. For separately requested non-instant transactions, the documented minimum subscription is $100,000 and the minimum redemption is $50,000 (investing, redeeming). Exceeding an instant limit does not route automatically — the investor must request non-instant processing. Eligible investors can mint from supported stablecoins, while the documented instant redemption path returns USDC and may be constrained by USDC availability.

The facility provides a two-way correction path with published transaction minimums and capacity limits. Capacity is the useful number. In each direction, immediate correction is bounded by the remaining global and individual limits; for instant redemption, deliverable USDC is an additional bottleneck. Published operational limits describe the capacity of a correction path; they are not evidence about secondary-market spreads, volume, or executable depth.

Redemption is not a boolean feature. It is a timed, sized, and permissioned trading path.

Correctability and price freshness are also independent variables. At its 2023 launch, Hamilton Lane and Securitize described the tokenized SCOPE feeder as offering on-demand redemption at the previous quarter's NAV per share; whether those terms remain current is not established here. As a configuration it is instructive: an exit path can exist while a fresh arbitrage anchor does not, and a curve trading around a quarter-old valuation can convert valuation delay into adverse selection.

Test 3 — Inventory economics: can anyone afford to warehouse both sides?

Ask whether the token or its underlying can be hedged, whether that hedge is available while the onchain venue is open, and what basis risk sits between the token, its claim, and the hedge. Ask whether inventory can be financed or posted as collateral, whether the asset generates carry, and whether that carry reaches the market maker. Then ask how concentrated the eligible balance sheets are, and what forced-unwind or revocation risk they carry.

This is where the AMM/RFQ distinction becomes economic rather than aesthetic: an AMM requires prefunding, so the cost of being wrong is priced into a curve, while RFQ lets the quoting party see the order before taking inventory risk.

Project Mariana is the most instructive case here, and its findings should be read narrowly. The documented result is technical feasibility: the BIS Innovation Hub, with the Bank of France, the Monetary Authority of Singapore, and the Swiss National Bank, built a proof of concept using an AMM to trade and settle three hypothetical wholesale CBDCs among allowlisted institutions. The documented limitation is equally explicit — liquidity must be prefunded, and the commercial viability of liquidity provision remained an open question outside the proof of concept's scope. The project is experimental and does not indicate an intent to issue CBDC.

My own inference is that this configuration is unusually AMM-compatible: wholesale FX has deep external price formation and standardized units, close to the most favorable conditions a prefunded curve can expect. That the balance-sheet question stays open even there is the point.

Test 4 — Flow profile: what kind of orders actually arrive?

Ask whether trades are frequent and small or rare and large, whether flow is balanced or structurally one-way during subscription and risk-off periods, and how information-sensitive the typical order is. Ask whether the user needs atomic execution or can wait for price improvement, and what the market is for: investment trading, treasury conversion, collateral rebalancing, or liquidation.

All else equal, small and frequent flow with low information content suits an AMM; large, irregular, directional flow suits RFQ, because the balance sheet can be priced after size is known; and a broad stream of heterogeneous orders can help sustain an order book. But size and frequency do not determine venue on their own. Quote competition, immediacy, information content, hedge access, eligibility, and market state all enter the decision, and any of them can override the size heuristic.

Test 5 — Lifecycle discontinuities: can the venue survive state changes?

Ask what happens at NAV cutoffs, market closes, and holidays; how dividends, coupons, splits, and maturities are processed; whether trading can be halted; and what happens after a default or appraisal revision. Ask whether eligibility can be revoked while orders or LP positions remain open, and whether a defined reopening mechanism exists.

Ondo Stocks total-return tracker tokens are the clearest current illustration, and the picture changed materially in 2026. On 25 June 2026, Ondo announced 24/7 instant minting and redemption for selected assets — initially SPYon, QQQon, CRCLon, NVDAon, TSLAon, and GOOGLon. This is not platform-wide: Off-Hours availability is enabled per asset, the supported list is dynamic, and normal operation remains session-structured with Off-Hours as a distinct session (market hours, off-hours trading).

The documented constraints matter as much as the capability. Quotes are priced by the platform rather than lifted from an exchange book (token and quote pricing). During Off-Hours, quotes, minting, and redemption can be instant, but spreads are typically wider and sizes are limited by separate dynamic per-asset limits; once a limit is reached a quote may be rejected and trading in that asset temporarily restricted. Trading can also halt around corporate actions, platform or asset risk controls, maintenance, and session transitions, and where the size of an ETF distribution is not yet known an asset may remain halted until sufficient information exists (investing and redeeming, corporate actions). Two steps are easy to merge and should not be: redemption into USDon may be instant, while conversion into USDC depends on stablecoin swapper liquidity.

Architecturally, the facility extends correctability across periods when the primary U.S. equity market is closed by requiring some intermediary to warehouse or hedge the resulting price risk under proprietary quoting, inventory limits, and halt rules. Public documentation does not establish which entity bears that risk, how it is hedged, or how much balance sheet is committed. My inference, stated as such: Ondo has not made the underlying equity market continuous; it has created a controlled quoting and correction bridge across some of the hours when that market is closed. So this test asks: when the reference market is closed, who intermediates the price risk, at what size, and under which halt conditions?

Hard constraints, soft constraints, and subsidies

The five tests do not average. Some findings are hard constraints that can make a continuously executable quote economically indefensible: no defensible current price, no executable correction path, a lifecycle event the venue cannot pause or settle correctly, a transfer rule that prevents inventory from reaching the participant who needs it, or no way to deliver the asset in the settlement window.

Others are soft — expensive funding, imperfect hedges, low trade frequency, one-sided flow, a small eligible participant set — and can be overcome at a price: wider spreads, higher fees, lower depth, issuer support, or incentives.

That last category deserves precision rather than dismissal. A 2025 BIS working paper, revised in 2026, studies US tokenized real-estate platforms and finds increased trading after natural-disaster declarations, attributing the liquidity advantage to platform buyback mechanisms and identifying a trade-off with higher platform insolvency risk — a finding of that paper's model and sample, not an assessment of any named company's financial condition. Read as market structure: buyback-supported liquidity can remain executable for a trader while the backstop is available, but its capacity and durability depend on the supporting balance sheet.

Which produces the organizing principle: credible continuous liquidity is bounded by the weakest non-substitutable capacity in the settlement and correction path. Not by TVL. What market makers can hedge, what they can redeem, what eligible counterparties can receive — economic reserves, displayed depth, and immediately executable liquidity are three different quantities.

One instrument, several execution paths

Take a hypothetical Treasury-like tokenized fund share with a frequently updated NAV, a two-way primary facility subject to size limits, and a cash-like settlement pair. Nothing about the token changes across the following three configurations, yet the appropriate execution path changes in all three. Sizes are illustrative, not thresholds.

Consider first a small, urgent conversion into the settlement asset — the kind a treasury operation raises without wanting to open a dialogue. Assume the order carries little information and values certainty of execution more than price improvement. An AMM may fit, provided the size sits inside verified executable depth and inside the remaining correction capacity the primary facility supplies. Neither condition is satisfied by pool TVL.

Now consider an institutional block. Pricing against the specific size rather than a standing curve favors competitive RFQ where the participant is eligible and quotes are responsive, or direct use of the primary redemption facility if the seller qualifies and the amount sits within remaining instant capacity. A sufficiently deep independent order book should not be excluded by definition either. Which path wins depends on eligibility, quote competition, and hedge access — Tests 2 and 3 — not on notional alone.

The third configuration is a collateral liquidation, where market state dominates. With a fresh price, an open hedge market, and sufficient guarded depth, deterministic atomic execution can be what the protocol needs. Under a stale valuation, a halted reference market, or an unresolved corporate action, that same curve can become vulnerable to informed flow, and an auction, wider protective parameters, or an explicit pause may be preferable — even though those are the least convenient options when they are needed.

Same token, three configurations, three answers. Routing belongs to the order and market state, not the asset class.

The hybrid execution stack

What follows is a design proposal rather than an existing standard, and it is not the published architecture of Uniswap, Securitize, Ondo, Dowgo, or any regulator. Applied honestly, the five tests usually output not a venue but a set of roles.

Layer 1, the economic anchor. The issuer, fund, or underlying venue supplies authoritative valuation and mint/redemption rules, defining when deviations are correctable at all. Its capacity — not its existence — is the number that matters.

Layer 2, block liquidity. Competitive RFQ lets participants quote institutional size after seeing the order, reducing the need to expose a large passive inventory schedule and connecting to primary creation and redemption.

Layer 3, displayed multilateral quoting and price discovery. An order book lets participants express distinct prices and quantities. It earns its place when the token market is expected to discover information rather than mirror an external value, and when enough independent participants exist to populate it. Such a book may itself be permissioned; displayed does not imply open.

Layer 4, atomic utility liquidity. An AMM can support smaller conversions, collateral operations, and liquidations, with the design objective of reliable execution within a bounded size rather than price discovery.

Layer 5, discontinuity management. Pauses, dynamic fees, auctions, position limits, and reopening rules handle closures, stale valuations, distributions, defaults, and eligibility changes. Specify this layer before offering continuous execution.

Layer 6, routing. Something must choose the path per order based on size, urgency, price confidence, eligibility, and market state — and, where rules allow, split one order across mechanisms.

The design claim: a plausible target architecture is not one venue per asset. It is one settlement graph with several execution mechanisms. Forcing blocks, small flow, price discovery, and discontinuity handling through one permanently executable curve does not remove the complexity — it relocates it into the spread, or onto whoever is funding the quote.

Continuous execution is not continuous liquidity

This article completes the market-structure taxonomy promised in the first article, while extending the architectural question raised by the second.

The method is deliberately not a scorecard. The framework produces five diagnostic answers and one routing decision: where the authoritative price originates; which participants can close deviations, at what size and speed; whose balance sheet supplies secondary liquidity and how it is financed and hedged; what orders actually arrive; when continuous execution must change mode or stop; and then, from those five, which roles belong to primary redemption, RFQ, order book, auction, and AMM. If a project cannot answer the first five, naming a venue is premature.

Which reduces to a better diligence question than the one this article started with: who forms the price, who can correct it, and whose balance sheet is executable when the trade arrives?

Tokenization can make a settlement rail continuously available. It cannot make information, hedging, or balance sheets continuous. The right execution design makes those discontinuities explicit instead of hiding them inside a permanently executable quote.

Disclosure and scope

This article is independent analytical commentary reflecting the author's personal views. No entity discussed commissioned, sponsored, paid for, reviewed, approved, or exercised editorial control over it. The author holds no financial interest in the instruments or entities discussed. It does not recommend buying, selling, or holding any financial instrument and is not investment, legal, or tax advice. Product mechanics and regulatory status are described from linked public sources as of 8 August 2026 and may change. The views expressed do not represent Haia, Haust Network, or Innowise.