Guilherme Monteiro · São Paulo, SP
Pix por dentro: a infraestrutura de pagamentos que o Brasil documentou em público
SPI, DICT, Kafka e os contratos públicos por trás do Pix: arquitetura, segurança e os efeitos do pagamento instantâneo.
Uma coletiva em São Paulo
Em 19 de fevereiro de 2020, uma quarta-feira, o Banco Central apresentou numa coletiva em São Paulo o nome e a marca do sistema de pagamentos instantâneos que vinha construindo. O diretor João Manoel Pinho de Mello mostrou o logo e arriscou a frase que o país inteiro repetiria meses depois: "me passa um Pix". Ao lado dele, respondendo sobre tarifas, estava Carlos Eduardo Brandt, chefe-adjunto do departamento que tocava o projeto. Ele volta no fim deste texto.
O presidente do BC era Roberto Campos Neto, e o Pix virou a vitrine da gestão dele. Mas o Pix não nasceu naquela coletiva. Nasceu dois anos antes, num grupo de trabalho.
De 2018 a novembro de 2020
Em maio de 2018, o BC criou o Grupo de Trabalho de Pagamentos Instantâneos, aberto a qualquer instituição ou pessoa interessada. Foram mais de 130 participantes, com as opiniões de todos publicadas no site do BC. O resultado saiu em 21 de dezembro de 2018, no Comunicado 32.927: liquidação centralizada, governança das regras, formas de participação e provimento de liquidez.
Naquele comunicado, o BC tomou uma decisão que define o resto da história. Ele não seria só o regulador. Seria também o dono das regras e o operador da infraestrutura, e depois decidiu ser o desenvolvedor também. O BC pedia ao mercado uma solução aberta desde 2014, e nada tinha saído: o que existia eram carteiras fechadas, em que pagador e recebedor precisavam ser clientes da mesma instituição.
Em outubro de 2019, o BC começou a construir as duas peças que sustentam o Pix. O SPI, o Sistema de Pagamentos Instantâneos, liquida as transações entre instituições diferentes. O DICT, o Diretório de Identificadores de Contas Transacionais, guarda o vínculo entre cada chave e a conta dela.
Um ano depois, em 5 de outubro de 2020, abriu o cadastro de chaves. Foram 3,5 milhões no primeiro dia, com aplicativo de banco grande engasgando pela manhã. No fim do dia 13 de outubro, pouco mais de oito dias depois, eram 30 milhões. A operação restrita começou em 3 de novembro, com uma parte dos clientes de cada instituição. Em 16 de novembro de 2020, o Pix entrou em operação plena.
O que ele tirou do caminho
No mês de estreia, o Pix já teve mais transações que o DOC. Em janeiro de 2021 passou o TED. Em março, o boleto. No primeiro trimestre de 2022, tornou-se o meio de pagamento eletrônico mais usado do país, à frente dos cartões de crédito e de débito.
O DOC, criado pelo próprio BC em 1985, não sobreviveu à comparação. Tinha limite de R$ 4.999,99 e só caía na conta no dia útil seguinte. Os bancos da Febraban pararam de aceitar novas ordens às 22h de 15 de janeiro de 2024 e fecharam o sistema em 29 de fevereiro de 2024. A TEC foi junto.
A curva de volume é o que se espera de uma infraestrutura que virou hábito. Foram 9,4 bilhões de transações em 2021, 24 bilhões em 2022, 41,7 bilhões em 2023, 63,4 bilhões em 2024 e 79,8 bilhões em 2025. Em valor, 2025 passou de R$ 35 trilhões. Agosto de 2026 foi o primeiro mês acima de 8 bilhões de transações: 8,11 bilhões, somando R$ 3,73 trilhões.
Há um detalhe que o número de transações esconde. No mesmo agosto, o TED fez 67 milhões de operações e movimentou R$ 3,90 trilhões, mais que o Pix inteiro. O Pix ganhou a quantidade. Pagamento de valor alto entre empresas continua, em boa parte, no trilho antigo.
O perfil de uso também mudou. Em 2020, 85% das transações eram entre pessoas físicas, e 6% eram de pessoas para empresas. Em 2025, as duas fatias estavam praticamente empatadas: 44% e 43%. O QR Code dinâmico, que as lojas geram a cada venda, saiu de 5% das transações em 2021 para 40% em 2025. A mediana de um Pix em 2025 foi de R$ 36, contra uma média de cerca de R$ 440. Muita transação pequena, poucas grandes puxando a média. É o padrão de quem substituiu o dinheiro vivo.
No fim de 2025, eram 148 milhões de pessoas físicas usando Pix, cerca de 86% dos adultos, além de 12,8 milhões de empresas, 926 instituições participantes e mais de 920 milhões de chaves.
Kafka, OpenShift, Ansible
O BC não comprou um sistema de pagamentos pronto. O SPI e o DICT foram desenvolvidos pelo próprio BC, que também opera os dois. O que ele foi buscar fora foi a base. A licitação pediu uma arquitetura distribuída e altamente escalável, construída sobre Apache Kafka.
A escolha faz sentido para o problema. Kafka é um log distribuído: as mensagens ficam gravadas em partições replicadas entre vários brokers. Para aguentar mais carga, você acrescenta brokers e partições em vez de trocar a máquina por uma maior. Se um broker cai, uma réplica assume. Para um sistema que não pode fechar à noite, nem no domingo, nem no Natal, essas duas propriedades são o requisito.
Quem ganhou foi a Red Hat, com a versão empresarial de cada peça, segundo o estudo de caso publicado pela empresa em janeiro de 2021. O AMQ faz o streaming com Kafka, o OpenShift hospeda as aplicações de acesso e de lógica de negócio, e o Ansible Automation Platform automatiza a infraestrutura e a integração com a automação dos parceiros.
| Peça | Produto | Papel no Pix |
|---|---|---|
| Mensageria | Red Hat AMQ (Streams for Apache Kafka) | streaming distribuído entre os serviços |
| Orquestração | Red Hat OpenShift | aplicações de acesso e de lógica de negócio |
| Automação | Red Hat Ansible Automation Platform | automação da infraestrutura e integração com parceiros |
O número que costuma acompanhar essa história também vem dali. Na prova de conceito, com a carga esperada de 2 mil transações por segundo, 99% das transações internas do BC foram processadas em menos de quatro segundos. Vicente Fernandes, chefe da divisão de arquitetura de servidores do BC, disse que a Red Hat atendeu a todos os requisitos nessa etapa.
Vale ler com o ceticismo de sempre. É um teste de 2020, feito antes do lançamento e divulgado pelo fornecedor. A prova de conceito é a parte séria: é a etapa em que o fornecedor precisa mostrar a carga funcionando antes de levar o contrato. O estudo de caso é a parte de marketing.
Anatomia de um Pix
Um Pix entre dois bancos diferentes tem oito marcos de tempo definidos pelo BC, do momento em que você confirma até a notificação de que o dinheiro saiu. Estão no Manual de Tempos do Pix, que hoje está na versão 7.0. Antes disso, quando você digita a chave, o seu banco consulta o DICT e mostra o nome de quem vai receber.
pagador PSP pagador DICT / SPI (BC) PSP recebedor
| | | |
|--- chave ----->|---- consulta DICT ---->| |
|<-- nome -------|<--- vínculo -----------| |
|--- confirma -->| t0' | |
| | t1 monta pacs.008 | |
| |------ pacs.008 ------->| t1' |
| | | t2 disponibiliza ---->|
| | |<------ pacs.002 -------| t3'
| | | t4 débito e crédito |
| | | nas Contas PI |
| |<----- pacs.002 --------| t5a |
|<-- "pago" -----| t6a | |
O t0' é o instante em que o seu banco recebe a confirmação, e fica gravado no campo AcceptanceDateTime da mensagem. O t1 é quando o banco monta a pacs.008, a ordem de pagamento no padrão ISO 20022, medido antes da assinatura. O SPI recebe a mensagem por HTTP no t1' e a disponibiliza para o banco do recebedor no t2. O banco do recebedor responde com uma pacs.002 no t3'. No t4, o SPI troca os saldos nas Contas Pagamentos Instantâneos dos dois bancos, e esse é o momento da liquidação. A pacs.002 volta para o banco pagador no t5a, e você recebe o aviso no t6a.
Cada trecho tem meta própria:
| Trecho | Marcos | Meta do BC |
|---|---|---|
| Banco do pagador monta e envia a ordem | t1 − t0' | P50 0,9 s · P95 1,5 s |
| Banco do recebedor autoriza | t3' − t2 | P50 1,4 s · P95 2,3 s |
| Tempo gasto dentro do SPI | (t2 − t1') + (t5a − t3') | P50 2,8 s · P99 4,6 s |
| Experiência de quem paga | t6a − t0' | P50 6 s · P99 10 s |
| Consulta de chave no DICT (lado do BC) | — | P99 1 s |
| Consulta de chave (experiência do pagador) | — | P99 2 s |
| Limite duro no canal primário | t0' → t4 | 40 s, depois o SPI rejeita |
| Canal secundário (agendamentos) | t1' → t4 | 45 min |
O limite duro é de 40 segundos. Passou disso, o SPI rejeita a transação. Pix agendado vai por um canal secundário, com limite de 45 minutos, para não disputar recurso com quem está no caixa esperando. Transação com suspeita de fraude pode ficar retida pelo banco do pagador por até 30 minutos entre 8h e 20h em dia útil, e por até 60 minutos no resto do tempo.
Um detalhe de engenharia que vale o parágrafo: o manual proíbe usar relógios de instituições diferentes para medir os indicadores, porque qualquer diferença pequena distorceria o resultado. Cada instituição responde pela sincronia dos próprios servidores. Por isso, cada intervalo da tabela é medido de um lado só. Quem já tentou medir latência entre dois datacenters com NTP de terceiros entende a decisão.
A disponibilidade também tem meta. O SPI precisa ficar no ar 99,9% do tempo, numa janela de três meses, e conta como fora do ar qualquer período em que 80% ou mais das requisições falhem por culpa dele durante mais de 36 segundos. A consulta ao DICT tem meta de 99,9%, e as atualizações, de 99,8%. Os bancos são divididos em categorias pelo volume, e as metas deles vão de 99,5% para os maiores até 95% para os menores.
Quando pagador e recebedor estão no mesmo banco, o Pix nem passa pelo SPI. A especificação do DICT proíbe consultar a chave nesse caso. O banco liquida internamente e tem até 30 dias para informar a transação ao BC.
Por baixo de tudo, está a liquidez. Cada participante direto mantém uma Conta PI no BC, que desde agosto de 2022 é remunerada pela Selic. Fora do horário dos sistemas de liquidez, das 6h30 às 18h30 em dia útil, as fontes de dinheiro para abastecer essa conta ficam mais restritas. O Pix funciona 24 horas por dia, 7 dias por semana. O caixa dos bancos precisa acompanhar. Esse ponto volta na parte sobre pesquisa acadêmica.
O que a infraestrutura aguenta hoje
Em 6 de dezembro de 2024, uma sexta-feira de quinto dia útil, o Pix passou pela primeira vez de 250 milhões de transações num único dia: foram 250,5 milhões, somando R$ 124,3 bilhões. Um ano depois, em 5 de dezembro de 2025, foram 313,3 milhões. O recorde de valor é de 19 de dezembro de 2025, com R$ 193,5 bilhões num dia.
O recorde atual de quantidade é de 4 de setembro de 2026: 318.073.816 transações liquidadas no SPI, somando R$ 186,89 bilhões. Dividido pelos 86.400 segundos do dia, dá cerca de 3,7 mil transações por segundo de média. Em agosto de 2026 inteiro, a média foi de uns 3 mil por segundo. Em 2025, de uns 2,5 mil por segundo, o ano todo, de madrugada inclusive. A carga da prova de conceito de 2020 hoje é a média de um dia comum. E o pico de um sistema de pagamento fica sempre bem acima da média.
O código é fechado, o contrato é aberto
O código do SPI e do DICT não está publicado. O que está publicado, com licença Apache 2.0, é o contrato: como cada parte do sistema conversa com a outra. Qualquer pessoa lê. Não precisa ser banco, nem pedir credenciamento, nem assinar acordo de confidencialidade.
São duas APIs. A API Pix é a que cada banco ou fintech expõe para empresas: cobrança, QR Code, conciliação e devolução. A especificação é OpenAPI 3.0, está na release 2.10.0 e tem cerca de 3 mil estrelas e 303 forks no GitHub. O BC padronizou essa API de propósito, e é ela que permite ligar o sistema de uma loja ao Pix para gerar QR Code a cada venda. Se uma loja troca de banco, a integração continua a mesma, e o custo de sair de um banco cai junto.
A API do DICT é a que os participantes usam para falar com o diretório do BC. Também é OpenAPI 3.0, também Apache 2.0, mas fala XML. A autenticação é TLS mútuo. Toda requisição que grava algo vai assinada com XML Digital Signature, e toda resposta do DICT volta assinada.
Um detalhe muda a leitura: o repositório do DICT no GitHub foi marcado como obsoleto. A última versão publicada ali é a 1.8.0, de setembro de 2022. As atualizações passaram a sair só no site do BC. A especificação continua pública, só mudou de endereço.
Em volta das APIs ficam os manuais: o de Segurança, o de Padrões para Iniciação, o de Tempos e o Operacional do DICT, todos na página de regulamentação do Pix.
A especificação do DICT também escreve a própria política de versão. Mudança incompatível pode sair no máximo uma vez a cada seis meses, e a versão anterior fica no ar por pelo menos um mês. Não é o "we do not break userspace" do kernel. Mas é uma promessa escrita, datada e cobrável.
DICT: a defesa contra raspagem está na especificação
O DICT guarda o vínculo entre chave, conta e dono: CPF ou CNPJ, nome, banco, agência, conta. No fim de 2022, 77% da população adulta já tinha chave cadastrada. Quem conseguisse consultar esse diretório em massa montaria um cadastro de meio país com nome, documento e banco. A especificação trata isso como ameaça de primeira classe e descreve cada defesa em texto aberto.
Os números abaixo são da versão 1.8.0. A versão vigente, no site do BC, pode ter mudado os valores.
Token bucket por pessoa
Toda consulta de chave passa por limitação de requisições com o algoritmo token bucket. Cada política tem um balde de fichas, uma taxa de reposição e uma regra de contagem. Quando o balde zera, o DICT responde 429.
A política mais interessante é a que olha para o usuário final. O balde de uma pessoa física tem 100 fichas, o de uma empresa tem mil, e os dois repõem 2 fichas por minuto. São duas políticas com os mesmos números: uma para chaves de e-mail e celular, outra para CPF, CNPJ e chave aleatória. Consulta que encontra a chave custa 1 ficha. Consulta de chave que não existe custa 20. Pix efetivamente enviado depois da consulta devolve 1 ficha.
| Evento | Efeito no balde |
|---|---|
| consulta que encontra a chave | −1 ficha |
| consulta de chave que não existe (404) | −20 fichas |
| Pix efetivamente enviado depois da consulta | +1 ficha |
Quem usa o Pix normalmente consulta, paga e recupera a ficha. Quem tenta varrer números de celular erra quase sempre, e cada erro custa vinte vezes um acerto. Cinco chutes errados esvaziam o balde cheio de uma pessoa física. Depois disso, a reposição é de 2 fichas por minuto, e cada erro continua custando 20.
Existe uma segunda camada, no nível da instituição. Cada participante cai numa categoria de A a F, que vai de 12 mil fichas por minuto, com balde de 20 mil, até 2 fichas por minuto, com balde de mil. Nessa camada, a consulta que não encontra nada custa 3 fichas. Um banco que deixa cliente raspar o diretório começa a ser estrangulado junto.
O CPF do pagador em cada consulta
Para o limite por pessoa funcionar, o DICT precisa saber quem é a pessoa. Toda consulta leva o cabeçalho PI-PayerId. Desde a versão 1.5.0, ele carrega o CPF ou o CNPJ de quem vai pagar, e a especificação proíbe pseudonimizar esse valor, porque é por ele que o BC rastreia quem estoura limite. A consulta também leva o PI-EndToEndId, o identificador do pagamento que ela antecede.
Contadores quantizados
A consulta de uma chave devolve também dados antifraude sobre o recebedor: quantas transações ele teve, quantos relatos de fraude recebeu e quantos foram confirmados. Os contadores são agregados por chave, por titular e por conta, em três janelas: últimos 3 dias, últimos 30 dias e últimos 6 meses.
Os contadores de transações não vêm exatos. A escala é 0, 1, 5, 10, 50, 100, 500, 1.000, 5.000, sempre arredondando para cima. Três transações viram 5. Cento e noventa viram 500.
A especificação não explica o porquê. A leitura mais plausível é que o banco do pagador precisa de ordem de grandeza para medir risco, e só disso. Conta que nunca recebeu nada é uma coisa. Conta com milhares de recebimentos é outra. O número exato seria uma informação financeira sobre um terceiro, entregue a quem só vai mandar um Pix para ele.
Os contadores também não zeram quando a chave ou a conta é desativada, e passam para o novo registro em caso de portabilidade ou troca de titular. Apagar a chave não limpa o histórico.
Reconciliação com XOR
Cada banco mantém uma cópia dos vínculos dos seus clientes, e ela precisa bater com o DICT. Para isso, toda operação sobre um vínculo gera um CID: um HMAC-SHA256 dos atributos essenciais do vínculo, que usa como chave os 16 bytes aleatórios da requisição que o criou.
Para conferir a base inteira, o banco não manda milhões de registros. Calcula o VSync, que é o XOR de todos os CIDs de um tipo de chave, e compara com o do DICT. XOR é comutativo e é o próprio inverso. A ordem não importa, e incluir ou remover um vínculo custa um XOR só. Se os dois VSyncs batem, as bases são iguais com altíssima probabilidade. Se não batem, com certeza não são.
O que mudou depois da v1.8.0
Em novembro de 2023, as informações de segurança do DICT ganharam campos para o motivo da notificação e o tipo de fraude. Desde julho de 2025, os dados ligados às chaves precisam bater com o cadastro de CPF e CNPJ da Receita Federal. Desde outubro de 2025, o DICT deixa de devolver os dados da chave quando ela ou o titular foram marcados por fraude pelo próprio banco que receberia o Pix.
Quando o elo fraco está fora do BC
O Relatório de Gestão do Pix 2023–2025 afirma que os sistemas do BC nunca sofreram um ataque bem-sucedido. O mesmo relatório admite que fraudes, golpes e ataques a instituições participantes passaram a usar o Pix cada vez mais como meio de distribuição. As duas coisas são verdade ao mesmo tempo, e o caso mais caro mostra por quê.
Na noite de 1º de julho de 2025, um ataque aos sistemas da C&M Software desviou dinheiro das contas de reserva que bancos mantêm no BC. A C&M não movimenta dinheiro de ninguém: ela conecta instituições menores ao Sistema de Pagamentos Brasileiro. O dinheiro saiu por Pix e foi convertido em criptomoedas. A EBC confirmou pelo menos R$ 400 milhões desviados. A polícia prendeu um funcionário da C&M que recebeu R$ 15 mil, R$ 5 mil pela senha e mais R$ 10 mil para montar o acesso dos criminosos.
O SPI funcionou como especificado. O que falhou foi a credencial de um fornecedor, vendida por quem tinha acesso a ela. Nenhuma especificação pública resolve um insider com preço.
A resposta veio em camadas. Desde setembro de 2025, participantes que não são autorizados pelo BC, ou que se conectam à Rede do Sistema Financeiro Nacional por meio de um provedor de tecnologia, têm teto de R$ 15 mil por Pix, e o SPI rejeita automaticamente o que passar disso. Desde novembro de 2024, só instituições autorizadas pelo BC podem participar, e o prazo para as instituições de pagamento pedirem autorização foi antecipado para 1º de maio de 2026. Desde janeiro de 2026, todo participante, exceto cooperativa de crédito, precisa ter pelo menos R$ 5 milhões de capital social e de patrimônio líquido.
No lado de quem paga, desde novembro de 2024, Pix feito de um aparelho não cadastrado tem limite de R$ 200 por transação e R$ 1.000 por dia. Desde setembro de 2025, o bloqueio cautelar de até 72 horas também vale para contas de empresas.
O MED, o Mecanismo Especial de Devolução, existe desde 2021. Em outubro de 2025 ganhou o botão de contestação dentro do aplicativo do banco. A versão 2.0 ficou obrigatória em 2 de fevereiro de 2026. Ela segue o dinheiro pelas contas intermediárias, obriga o bloqueio dos valores suspeitos por até 11 dias durante a análise e dá 30 minutos para o banco da vítima avisar o banco que recebeu. Um algoritmo mapeia os caminhos de dispersão e envia as notificações automaticamente, mas a devolução só é pedida a quem teve fraude confirmada e está ligado à transação original por uma cadeia contínua de repasses. O desenho protege o vendedor de boa-fé que recebeu parte do dinheiro sem saber.
O próximo passo é o mais interessante para quem trabalha com modelo. O BC está desenvolvendo um indicador de probabilidade de fraude, calculado de forma centralizada e em tempo real para todas as transações, a partir de um modelo de machine learning. A decisão de autorizar continua com cada banco, e o próprio BC diz que só vai compartilhar o indicador se confiar no ajuste do modelo e se a análise jurídica permitir. Um score de risco central sobre cada Pix do país é uma ferramenta poderosa. A pergunta de projeto é quem vê esse número e sob quais regras.
O que a pesquisa acadêmica encontrou
O Pix virou objeto de estudo cedo, e os resultados vão além de "deu certo".
Em março de 2022, um boletim do Banco de Compensações Internacionais assinado por Angelo Duarte, Jon Frost, Leonardo Gambacorta, Priscilla Koo Wilkens e Hyun Song Shin registrou que o Pix tinha alcançado 67% dos adultos em pouco mais de um ano. Os autores apontam dois ingredientes: a participação obrigatória dos bancos grandes, para dar o empurrão inicial ao efeito de rede, e o papel duplo do BC como provedor da infraestrutura e dono das regras. A obrigação vale para instituições com 500 mil contas ativas ou mais.
Sergey Sarkisyan, hoje na Ohio State, estudou o efeito sobre a competição bancária. Os depósitos dos bancos pequenos cresceram em relação aos dos grandes, porque o Pix nivelou a conveniência de pagamento entre eles. Mais competitivos no serviço de pagamento, os pequenos passaram a pagar juros relativamente menores nos depósitos, e o modelo estimado por ele indica ganho de bem-estar para os depositantes. Antes, o banco pequeno compensava a desvantagem pagando mais juro. Com o Pix, deixou de precisar.
Os números do BC apontam na mesma direção. As instituições de pagamento eram 25,5% das transações do lado pagador em 2020 e chegaram a 50% em 2025. Os bancos múltiplos caíram de 55,8% para 35%. O índice de concentração, o Herfindahl-Hirschman, está abaixo de 10%, faixa considerada de baixa concentração.
O custo aparece num working paper do próprio BC. Rodrigo Gonzalez, do BC, Yiming Ma, de Columbia, e Yao Zeng, de Wharton, mostram que o pagamento instantâneo tirou dos bancos a capacidade de segurar pagamentos e compensar entradas e saídas no fim do dia. Para o banco mediano, entre 57% e 80% dos fluxos de Pix teriam sido compensáveis no modelo antigo. A resposta dos bancos foi guardar mais ativos líquidos: um desvio-padrão a mais de uso de Pix leva a 15,4 pontos percentuais a mais de ativos líquidos, principalmente títulos públicos, e a menos crédito na carteira. Nas palavras dos autores, os bancos ficam mais "estreitos".
O instrumento que eles usam para isolar causa e efeito é um detalhe técnico do próprio Pix: os timeouts. Se o banco do outro lado não processa a transação em 40 segundos, ela falha. Os autores medem só as falhas causadas pelos bancos da contraparte, que o banco estudado não controla. O limite de 40 segundos do Manual de Tempos virou variável instrumental num paper de finanças.
O mesmo trabalho cita outro, de Liang, Sampaio e Sarkisyan, segundo o qual a competição maior por depósitos amplifica a transmissão da política monetária. O Pix mexe na Selic por um caminho que ninguém desenhou em 2018.
Pix, UPI, FedNow e o resto do mundo
O primeiro sistema de pagamento instantâneo foi o da Coreia do Sul, em 2001, e em 2023 já eram mais de 60 jurisdições com algum sistema do tipo. O que separa o Pix não é a velocidade. É o uso.
Um estudo do BIS de 2024, citado pelo Fed de Richmond, mediu transações por habitante por mês em 2023: 35 no PromptPay da Tailândia, 27 no Pix, 13 no Swish da Suécia e 11 no UPI da Índia. Os Estados Unidos, somando RTP e FedNow, tinham 0,12 no primeiro trimestre de 2026. O valor médio também conta a história: cerca de US$ 92 no Pix, US$ 6 no UPI, US$ 3.750 no RTP e US$ 99.414 no FedNow.
| Sistema | País | Início | Operador | Volume recente | Valor médio |
|---|---|---|---|---|---|
| Pix | Brasil | nov/2020 | Banco Central | 8,11 bi transações em ago/2026 | ~US$ 92 |
| UPI | Índia | 2016 | NPCI | 24,51 bi transações em ago/2026 | ~US$ 6 |
| RTP | EUA | nov/2017 | The Clearing House | 128 mi por trimestre (1º tri/2026) | ~US$ 3.750 |
| FedNow | EUA | jul/2023 | Federal Reserve | 2,73 mi por trimestre (1º tri/2026) | ~US$ 99.414 |
Índia: mais volume, front-end concentrado
O UPI processou 24,51 bilhões de transações em agosto de 2026, média de 791 milhões por dia, com 752 bancos conectados. Em números absolutos, é três vezes o Pix. Por habitante, o Pix roda mais que o dobro.
A diferença de desenho está na ponta. No UPI, a maior parte do uso passa por aplicativos de terceiros. Em julho de 2026, o PhonePe, do Walmart, tinha 45,89% das transações, o Google Pay tinha 32,33% e o Paytm, 8,05%. Três aplicativos somam 86% do volume. No Pix, a ponta é o aplicativo do próprio banco ou de um iniciador regulado, e a concentração medida pelo BC fica abaixo de 10%. A infraestrutura é pública nos dois países. A porta de entrada, não.
Estados Unidos: trilho moderno, pouca gente passando
O FedNow entrou no ar em julho de 2023 e reunia 1.725 bancos e cooperativas de crédito no primeiro trimestre de 2026, 19,7% das instituições americanas. No trimestre, processou 2,73 milhões de transações, somando US$ 271 bilhões. No ritmo médio do dia recorde, o Pix faz 2,73 milhões de transações em uns 12 minutos.
A comparação é injusta, e a pesquisa explica por quê. Zhu Wang e Vinh Phan, do Fed de Richmond, lembram que os americanos já têm alternativas que parecem instantâneas, como Zelle, transferências para cartão e carteiras digitais, com liquidação depois. Países que dependiam de dinheiro vivo pulam etapas com mais facilidade que países com cartão e ACH em todo lugar. Por isso o FedNow ficou com pagamentos de valor alto: folha de pagamento, liberação de financiamento, liquidação imobiliária. Sarkisyan aponta a outra diferença: o Pix foi desenhado como sistema de varejo, com participação obrigatória dos bancos, e o FedNow chegou sem essa obrigação.
Europa: a conexão que começou agora
Em 24 de setembro de 2026, o BC e o Banco Central Europeu começaram a avaliar a viabilidade de ligar o Pix ao TIPS, a infraestrutura de liquidação instantânea do Eurosistema, que hoje opera euro, coroa sueca e coroa dinamarquesa. O BCE estuda conexões semelhantes com o UPI, com o sistema suíço e com o Nexus. Entre elas, a do Pix é a mais embrionária, e não há cronograma público.
Hoje, Pix fora do Brasil funciona por parceria entre empresas. O pagamento sai em reais, pela infraestrutura doméstica, para uma instituição brasileira, que depois faz a remessa ao exterior pelo caminho tradicional. O Pix em si só liquida transações domésticas. Uma ligação direta entre sistemas de bancos centrais seria outra coisa.
Carlos Eduardo Brandt
O técnico que respondia sobre tarifas naquela coletiva de 2020 entrou no Banco Central como analista, há mais de 23 anos. Brandt é formado em engenharia civil pela UnB e em direito pelo IESB, com especialização em finanças pela FGV. Chegou no início do período em que o BC reestruturava o Sistema de Pagamentos Brasileiro, em 2002.
No lançamento do Pix, ele era chefe-adjunto do Departamento de Competição e de Estrutura do Mercado Financeiro, o Decem, e era quem explicava o sistema nas lives do BC. Liderou o time que desenvolveu o Pix. Em 2021, quando o Pix fez um ano, foi o único brasileiro na lista da Bloomberg das 50 pessoas que definiram os rumos dos negócios naquele ano.
A imprensa o chama de "pai do Pix". O próprio BC prefere dizer, no Relatório de Gestão, que o Pix foi construído a múltiplas mãos, pelo corpo técnico do BC e pelas instituições que participaram da construção. As duas coisas são verdade ao mesmo tempo. Projeto desse tamanho precisa de muita gente e de alguém que responda por ele.
Em agosto de 2025, depois de 23 anos, Brandt deixou o BC e foi para o FMI, em Washington, como especialista sênior do setor financeiro. À BBC News Brasil, disse que achava que poderia contribuir com outros países numa escala global. O assunto dele agora é o problema que o Pix ainda não resolve: pagamento instantâneo entre países. Ele acompanha de perto o Nexus, do BIS, que começa por Índia, Malásia, Filipinas, Singapura e Tailândia, e a integração financeira dos 16 países da África Austral.
Um mês depois de o BC começar a estudar a ligação com a Europa, o problema que ele foi resolver fora bateu na porta do lugar de onde ele saiu.
O que o Pix abriu
O Pix não é open source no sentido estrito. O código do SPI e do DICT continua dentro do BC. A base é Kafka, projeto aberto, comprado com suporte de uma empresa. O que o BC abriu foi o resto: as APIs com licença Apache 2.0, os manuais, as metas de tempo com percentil, a política de versão e até a regra que decide quanto custa consultar uma chave que não existe.
Nada disso é de graça. Os bancos perderam a compensação de fim de dia e seguram mais título público no lugar de crédito. O perímetro virou o alvo, e o maior roubo da história do sistema passou por uma credencial vendida por R$ 15 mil. O dinheiro grande continua no TED.
Em 1883, Auguste Kerckhoffs escreveu sobre cifras militares que um sistema precisa continuar seguro mesmo se cair na mão do inimigo. O segredo fica na chave, não no mecanismo. O DICT segue a mesma lógica. Saber que o balde de uma pessoa física tem 100 fichas não dá ficha nenhuma a ninguém. Para passar do limite, o atacante precisa de mais CPFs e de mais contas, e cada um deles deixa rastro.
Esconder o desenho é apostar que ninguém vai procurar. Publicar é apostar que procurar não adianta.
Fontes
Documentos oficiais e especificações
- Relatório de Gestão do Pix 2020–2022, Banco Central do Brasil
- Relatório de Gestão do Pix 2023–2025, Banco Central do Brasil
- Manual de Tempos do Pix, versão 7.0, Banco Central do Brasil
- Comunicado 32.927, Banco Central do Brasil, 21/12/2018
- bacen/pix-api, especificação da API Pix
- bacen/pix-dict-api, repositório da API do DICT, marcado como obsoleto
- openapi.yaml da API do DICT, versão 1.8.0
Pesquisa
- Duarte, Frost, Gambacorta, Koo Wilkens e Shin, Central banks, the monetary system and public payment infrastructures: lessons from Brazil's Pix, BIS Bulletin 52, 2022
- Sarkisyan, Instant Payment Systems and Competition for Deposits, SSRN
- Gonzalez, Ma e Zeng, The Effect of Instant Payments on the Banking System, BCB Working Paper 619, 2025
- Wang e Phan, FedNow and the Development of U.S. Fast Payments, Richmond Fed Economic Brief 26-28, 2026
- Research Spotlight: Instant Payment Systems and Competition for Deposits, Wharton
Fornecedor
- Brazilian bank builds instant payment network with Red Hat, estudo de caso da Red Hat, 2021
Imprensa
- Banco Central apresenta logomarca do PIX, Teletime, 19/02/2020
- Mais de 3,5 milhões de chaves já foram cadastradas no Pix, Agência Brasil via Money Times, 05/10/2020
- PIX atinge 30 milhões de chaves cadastradas, FDR, 14/10/2020
- Fim do DOC? Febraban informa que bancos deixarão de oferecer tipo de transação, Suno, 04/05/2023
- Pix bate recorde de transações em um único dia: 250 milhões, InfoMoney, 10/12/2024
- BC suspende três instituições do Pix após ataque cibernético, Agência Brasil, 04/07/2025
- Líder do Pix está no FMI, Baguete, 17/11/2025
- Novas regras de segurança do Pix entram em vigor, Agência Brasil, 02/02/2026
- UPI hits new record with 24.51 Bn transactions in August, Entrackr, 01/09/2026
- Pix bate recorde diário de operação, Metrópoles, 05/09/2026
- Os meios de pagamento mais usados em agosto de 2026, Glin, 17/09/2026
- Bancos Centrais do Brasil e Europa iniciam avaliação para conectar Pix e Tips, DW via O Povo, 25/09/2026
A press conference in São Paulo
On Wednesday, February 19, 2020, Brazil's central bank held a press conference in São Paulo to unveil the name and brand of the instant payment system it had been building. Director João Manoel Pinho de Mello showed the logo and tried out the phrase the whole country would repeat months later: "send me a Pix". Beside him, answering questions about fees, was Carlos Eduardo Brandt, deputy head of the department running the project. He returns at the end of this text.
The central bank's president was Roberto Campos Neto, and Pix became the showcase of his administration. But Pix was not born at that press conference. It was born two years earlier, in a working group.
From 2018 to November 2020
In May 2018, the central bank created the Instant Payments Working Group, open to any interested institution or individual. More than 130 took part, with everyone's views published on the bank's website. The outcome appeared on December 21, 2018, in Communiqué 32,927: centralized settlement, governance of the rules, forms of participation and liquidity provision.
In that communiqué, the central bank made a decision that defines the rest of the story. It would not just be the regulator. It would also own the rules and operate the infrastructure, and later decided to be the developer too. The bank had been asking the market for an open solution since 2014, and nothing had emerged: what existed were closed wallets, where payer and recipient had to be customers of the same institution.
In October 2019, the central bank began building the two components that underpin Pix. SPI, the Instant Payments System, settles transactions between different institutions. DICT, the Transaction Account Identifier Directory, stores the link between each key and its account.
A year later, on October 5, 2020, key registration opened. There were 3.5 million on the first day, with major banks' apps struggling that morning. By the end of October 13, just over eight days later, there were 30 million. Restricted operation began on November 3, with a subset of each institution's customers. On November 16, 2020, Pix entered full operation.
What it cleared out of the way
In its debut month, Pix already processed more transactions than DOC. In January 2021 it passed TED. In March, bank payment slips, or boletos. In the first quarter of 2022, it became the country's most-used electronic payment method, ahead of credit and debit cards.
DOC, created by the central bank itself in 1985, did not survive the comparison. It had a limit of R$4,999.99 and only reached the account on the next business day. Febraban member banks stopped accepting new orders at 10 p.m. on January 15, 2024, and shut the system down on February 29, 2024. TEC went with it.
The volume curve is what you would expect from infrastructure that became a habit. There were 9.4 billion transactions in 2021, 24 billion in 2022, 41.7 billion in 2023, 63.4 billion in 2024 and 79.8 billion in 2025. By value, 2025 exceeded R$35 trillion. August 2026 was the first month above 8 billion transactions: 8.11 billion, totaling R$3.73 trillion.
There is a detail that the transaction count hides. In that same August, TED handled 67 million transactions and moved R$3.90 trillion, more than all of Pix. Pix won on quantity. High-value payments between companies still largely travel on the old rails.
The usage profile changed too. In 2020, 85% of transactions were between individuals, and 6% were from individuals to businesses. In 2025, the two shares were almost equal: 44% and 43%. Dynamic QR codes, which shops generate for each sale, grew from 5% of transactions in 2021 to 40% in 2025. The median Pix payment in 2025 was R$36, against an average of around R$440. Many small transactions, a few large ones pulling up the average. It is the pattern of something that replaced cash.
At the end of 2025, 148 million individuals used Pix, about 86% of adults, along with 12.8 million companies, 926 participating institutions and more than 920 million keys.
Kafka, OpenShift, Ansible
The central bank did not buy a ready-made payment system. SPI and DICT were developed by the bank itself, which also operates both. What it sought externally was the foundation. The tender called for a distributed, highly scalable architecture built on Apache Kafka.
The choice makes sense for the problem. Kafka is a distributed log: messages are stored in partitions replicated across multiple brokers. To handle more load, you add brokers and partitions rather than replace the machine with a bigger one. If a broker goes down, a replica takes over. For a system that cannot close at night, on Sundays or at Christmas, those two properties are the requirement.
Red Hat won, with the enterprise version of each component, according to the case study the company published in January 2021. AMQ handles streaming with Kafka, OpenShift hosts the access and business-logic applications, and Ansible Automation Platform automates the infrastructure and integration with partners' automation.
| Component | Product | Role in Pix |
|---|---|---|
| Messaging | Red Hat AMQ (Streams for Apache Kafka) | distributed streaming between services |
| Orchestration | Red Hat OpenShift | access and business-logic applications |
| Automation | Red Hat Ansible Automation Platform | infrastructure automation and partner integration |
The number usually quoted alongside this story comes from the same source. In the proof of concept, under the expected load of 2,000 transactions per second, 99% of the central bank's internal transactions were processed in under four seconds. Vicente Fernandes, head of the bank's server architecture division, said Red Hat met every requirement at that stage.
It is worth reading with the usual skepticism. This was a 2020 test, conducted before launch and publicized by the vendor. The proof of concept is the serious part: the stage where the vendor must demonstrate the load working before winning the contract. The case study is the marketing part.
Anatomy of a Pix payment
A Pix payment between two different banks has eight timestamps defined by the central bank, from the moment you confirm until you are notified that the money has left. They are in the Pix Timing Manual, now at version 7.0. Before that, when you enter the key, your bank queries DICT and shows you the recipient's name.
payer payer PSP DICT / SPI (BC) recipient PSP
| | | |
|--- key ------->|---- DICT query ------->| |
|<-- name -------|<--- link --------------| |
|--- confirm --->| t0' | |
| | t1 builds pacs.008 | |
| |------ pacs.008 ------->| t1' |
| | | t2 makes available --->|
| | |<------ pacs.002 -------| t3'
| | | t4 debit and credit |
| | | in PI Accounts |
| |<----- pacs.002 --------| t5a |
|<-- "paid" -----| t6a | |
The t0' timestamp is when your bank receives confirmation, recorded in the message's AcceptanceDateTime field. t1 is when the bank builds pacs.008, the payment order in the ISO 20022 standard, measured before signing. SPI receives the message over HTTP at t1' and makes it available to the recipient's bank at t2. The recipient's bank responds with a pacs.002 at t3'. At t4, SPI changes the balances in the two banks' Instant Payments Accounts, and that is the moment of settlement. The pacs.002 returns to the payer's bank at t5a, and you receive the notification at t6a.
Each segment has its own target:
| Segment | Timestamps | Central bank target |
|---|---|---|
| Payer's bank builds and sends the order | t1 − t0' | P50 0.9 s · P95 1.5 s |
| Recipient's bank authorizes | t3' − t2 | P50 1.4 s · P95 2.3 s |
| Time spent inside SPI | (t2 − t1') + (t5a − t3') | P50 2.8 s · P99 4.6 s |
| Payer's experience | t6a − t0' | P50 6 s · P99 10 s |
| DICT key lookup (central bank side) | — | P99 1 s |
| Key lookup (payer's experience) | — | P99 2 s |
| Hard limit on the primary channel | t0' → t4 | 40 s, then SPI rejects it |
| Secondary channel (scheduled payments) | t1' → t4 | 45 min |
The hard limit is 40 seconds. Beyond that, SPI rejects the transaction. Scheduled Pix payments use a secondary channel, with a 45-minute limit, so they do not compete for resources with someone waiting at the checkout. A transaction suspected of fraud may be held by the payer's bank for up to 30 minutes between 8 a.m. and 8 p.m. on business days, and up to 60 minutes at other times.
One engineering detail deserves a paragraph: the manual prohibits using clocks from different institutions to measure the indicators, because even a small discrepancy would distort the result. Each institution is responsible for synchronizing its own servers. That is why each interval in the table is measured on one side only. Anyone who has tried to measure latency between two data centers with third-party NTP understands the decision.
Availability has a target too. SPI must be up 99.9% of the time over a three-month window, and any period in which 80% or more of requests fail because of SPI for longer than 36 seconds counts as downtime. DICT lookups have a 99.9% target, and updates 99.8%. Banks are divided into categories by volume, with their targets ranging from 99.5% for the largest to 95% for the smallest.
When payer and recipient are at the same bank, the Pix payment does not go through SPI at all. The DICT specification prohibits looking up the key in that case. The bank settles internally and has up to 30 days to report the transaction to the central bank.
Beneath it all lies liquidity. Each direct participant holds a PI Account at the central bank, which has earned interest at the Selic rate since August 2022. Outside the liquidity systems' operating hours, from 6:30 a.m. to 6:30 p.m. on business days, the sources of money to fund that account become more restricted. Pix runs 24 hours a day, seven days a week. Banks' cash management has to keep up. This point returns in the section on academic research.
What the infrastructure can handle today
On Friday, December 6, 2024, the fifth business day of the month, Pix exceeded 250 million transactions in a single day for the first time: 250.5 million, totaling R$124.3 billion. A year later, on December 5, 2025, there were 313.3 million. The value record is from December 19, 2025, with R$193.5 billion in one day.
The current record by quantity is September 4, 2026: 318,073,816 transactions settled in SPI, totaling R$186.89 billion. Divided by the day's 86,400 seconds, that is an average of about 3,700 transactions per second. Across August 2026, the average was around 3,000 per second. In 2025, around 2,500 per second, all year, including the middle of the night. The load used in the 2020 proof of concept is now the average for an ordinary day. And a payment system's peak is always well above its average.
The code is closed; the contract is open
The source code of SPI and DICT is not published. What is published, under the Apache 2.0 license, is the contract: how each part of the system talks to the others. Anyone can read it. You do not have to be a bank, request accreditation or sign a nondisclosure agreement.
There are two APIs. The Pix API is the one each bank or fintech exposes to businesses: billing, QR codes, reconciliation and refunds. The specification is OpenAPI 3.0, is at release 2.10.0 and has around 3,000 stars and 303 forks on GitHub. The central bank deliberately standardized this API, and it is what connects a shop's system to Pix to generate a QR code for every sale. If a shop switches banks, the integration stays the same, and the cost of leaving a bank falls with it.
The DICT API is the one participants use to talk to the central bank's directory. It is also OpenAPI 3.0 and Apache 2.0, but speaks XML. Authentication uses mutual TLS. Every request that writes anything is signed with XML Digital Signature, and every DICT response comes back signed.
One detail changes how to read it: the DICT repository on GitHub has been marked obsolete. The last version published there is 1.8.0, from September 2022. Updates moved exclusively to the central bank's website. The specification is still public; only its address changed.
Around the APIs sit the manuals: Security, Initiation Standards, Timing and the DICT Operational Manual, all on the Pix regulation page.
The DICT specification also sets out its versioning policy. A breaking change may be released at most once every six months, and the previous version stays available for at least one month. It is not the kernel's "we do not break userspace". But it is a written, dated promise that can be enforced.
DICT: defenses against scraping are in the specification
DICT stores the link between key, account and owner: CPF or CNPJ tax identifier, name, bank, branch and account. By the end of 2022, 77% of the adult population already had a registered key. Anyone able to query this directory at scale could assemble a database of half the country, complete with names, tax IDs and banks. The specification treats this as a first-class threat and describes each defense in open text.
The numbers below come from version 1.8.0. The current version on the central bank's website may have changed the values.
A token bucket for each person
Every key lookup is rate-limited using the token bucket algorithm. Each policy has a bucket of tokens, a refill rate and a counting rule. When the bucket reaches zero, DICT returns 429.
The most interesting policy looks at the end user. An individual's bucket holds 100 tokens, a company's holds 1,000, and both refill at 2 tokens per minute. There are two policies with the same numbers: one for email and mobile phone keys, another for CPF, CNPJ and random keys. A successful key lookup costs 1 token. Looking up a key that does not exist costs 20. A Pix payment actually sent after the lookup returns 1 token.
| Event | Effect on the bucket |
|---|---|
| lookup that finds the key | −1 token |
| lookup of a nonexistent key (404) | −20 tokens |
| Pix payment actually sent after the lookup | +1 token |
A normal Pix user looks up, pays and recovers the token. Someone trying to sweep phone numbers almost always misses, and each miss costs twenty times as much as a hit. Five wrong guesses empty an individual's full bucket. After that, it refills at 2 tokens per minute, while each miss still costs 20.
There is a second layer at institution level. Each participant falls into a category from A to F, ranging from 12,000 tokens per minute with a 20,000-token bucket down to 2 tokens per minute with a 1,000-token bucket. At this layer, a lookup that finds nothing costs 3 tokens. A bank that lets a customer scrape the directory starts getting throttled along with them.
The payer's CPF in every lookup
For a per-person limit to work, DICT needs to know who the person is. Every lookup includes the PI-PayerId header. Since version 1.5.0, it carries the payer's CPF or CNPJ, and the specification prohibits pseudonymizing this value because it is how the central bank tracks those who exceed the limit. The lookup also includes PI-EndToEndId, the identifier of the payment it precedes.
Quantized counters
A key lookup also returns antifraud data about the recipient: how many transactions they have had, how many fraud reports they have received and how many were confirmed. The counters are aggregated by key, owner and account over three windows: the last 3 days, the last 30 days and the last 6 months.
Transaction counters are not exact. The scale is 0, 1, 5, 10, 50, 100, 500, 1,000, 5,000, always rounded up. Three transactions become 5. One hundred and ninety become 500.
The specification does not explain why. The most plausible reading is that the payer's bank needs an order of magnitude to measure risk, and nothing more. An account that has never received anything is one thing. An account with thousands of incoming payments is another. The exact count would be financial information about a third party, handed to someone who only intends to send them a Pix payment.
Nor do the counters reset when the key or account is deactivated: they carry over to the new record in cases of portability or change of ownership. Deleting a key does not erase the history.
Reconciliation with XOR
Each bank keeps a copy of its customers' links, and it has to match DICT. For that purpose, every operation on a link generates a CID: an HMAC-SHA256 of the link's essential attributes, using as its key the 16 random bytes from the request that created it.
To check the entire database, the bank does not send millions of records. It calculates VSync, the XOR of all CIDs for a key type, and compares it with DICT's. XOR is commutative and its own inverse. Order does not matter, and adding or removing a link costs just one XOR. If the two VSyncs match, the databases are identical with extremely high probability. If they do not, they are definitely different.
What changed after v1.8.0
In November 2023, DICT's security information gained fields for the reason for a notification and the type of fraud. Since July 2025, data linked to keys must match the Federal Revenue Service's CPF and CNPJ registers. Since October 2025, DICT no longer returns key data when the key or its owner has been flagged for fraud by the very bank that would receive the Pix payment.
When the weak link is outside the central bank
The Pix Management Report 2023–2025 states that the central bank's systems have never suffered a successful attack. The same report acknowledges that fraud, scams and attacks on participating institutions increasingly use Pix as a distribution channel. Both things are true at once, and the most expensive case shows why.
On the night of July 1, 2025, an attack on C&M Software's systems diverted money from the reserve accounts banks hold at the central bank. C&M does not move anyone's money: it connects smaller institutions to the Brazilian Payments System. The money left via Pix and was converted to cryptocurrency. EBC confirmed at least R$400 million stolen. Police arrested a C&M employee who received R$15,000: R$5,000 for the password and another R$10,000 to set up the criminals' access.
SPI worked as specified. What failed was a supplier's credential, sold by someone who had access to it. No public specification can solve an insider with a price.
The response came in layers. Since September 2025, participants not authorized by the central bank, or connecting to the National Financial System Network through a technology provider, have a R$15,000 cap per Pix payment, and SPI automatically rejects anything above it. Since November 2024, only institutions authorized by the central bank may participate, and the deadline for payment institutions to apply for authorization was brought forward to May 1, 2026. Since January 2026, every participant except credit cooperatives must have at least R$5 million in share capital and net equity.
On the payer's side, since November 2024 a Pix payment from an unregistered device is limited to R$200 per transaction and R$1,000 per day. Since September 2025, precautionary holds of up to 72 hours also apply to business accounts.
MED, the Special Refund Mechanism, has existed since 2021. In October 2025 it gained a dispute button inside banks' apps. Version 2.0 became mandatory on February 2, 2026. It follows the money through intermediary accounts, requires suspected funds to be blocked for up to 11 days during analysis and gives the victim's bank 30 minutes to notify the receiving bank. An algorithm maps the dispersal paths and sends notifications automatically, but refunds are requested only from those whose fraud has been confirmed and who are linked to the original transaction by a continuous chain of transfers. The design protects good-faith sellers who received part of the money unknowingly.
The next step is the most interesting for people who work with models. The central bank is developing a fraud-probability indicator, calculated centrally and in real time for all transactions using a machine-learning model. The decision to authorize stays with each bank, and the central bank itself says it will share the indicator only if it trusts the model's calibration and if legal analysis permits. A central risk score for every Pix payment in the country is a powerful tool. The design question is who gets to see that number, and under what rules.
What academic research found
Pix became a research subject early, and the findings go beyond "it worked".
In March 2022, a Bank for International Settlements bulletin by Angelo Duarte, Jon Frost, Leonardo Gambacorta, Priscilla Koo Wilkens and Hyun Song Shin reported that Pix had reached 67% of adults in just over a year. The authors identify two ingredients: mandatory participation by large banks, to give the network effect its initial push, and the central bank's dual role as infrastructure provider and rule owner. The requirement applies to institutions with 500,000 or more active accounts.
Sergey Sarkisyan, now at Ohio State, studied the effect on banking competition. Small banks' deposits grew relative to large banks', because Pix leveled payment convenience between them. More competitive in payment services, small banks began paying relatively lower deposit rates, and his estimated model indicates a welfare gain for depositors. Previously, small banks compensated for their disadvantage by paying more interest. With Pix, they no longer needed to.
The central bank's figures point in the same direction. Payment institutions accounted for 25.5% of payer-side transactions in 2020 and reached 50% in 2025. Multiple-service banks fell from 55.8% to 35%. The Herfindahl–Hirschman concentration index is below 10%, a range considered low concentration.
The cost appears in a working paper from the central bank itself. Rodrigo Gonzalez of the central bank, Yiming Ma of Columbia and Yao Zeng of Wharton show that instant payment took away banks' ability to hold payments and net inflows against outflows at the end of the day. For the median bank, between 57% and 80% of Pix flows could have been netted under the old model. Banks responded by holding more liquid assets: a one-standard-deviation increase in Pix use leads to 15.4 percentage points more liquid assets, mainly government bonds, and less lending in the portfolio. In the authors' words, banks become "narrower".
The instrument they use to isolate cause and effect is a technical detail of Pix itself: timeouts. If the bank on the other side does not process a transaction within 40 seconds, it fails. The authors measure only failures caused by counterparty banks, which the bank being studied does not control. The Timing Manual's 40-second limit became an instrumental variable in a finance paper.
The same paper cites another, by Liang, Sampaio and Sarkisyan, which finds that greater competition for deposits amplifies monetary policy transmission. Pix affects the Selic through a channel nobody designed in 2018.
Pix, UPI, FedNow and the rest of the world
The first instant payment system was South Korea's, in 2001, and by 2023 more than 60 jurisdictions had a system of this kind. What sets Pix apart is not speed. It is usage.
A 2024 BIS study, cited by the Richmond Fed, measured monthly transactions per person in 2023: 35 for Thailand's PromptPay, 27 for Pix, 13 for Sweden's Swish and 11 for India's UPI. The United States, combining RTP and FedNow, had 0.12 in the first quarter of 2026. Average value tells the story too: about US$92 for Pix, US$6 for UPI, US$3,750 for RTP and US$99,414 for FedNow.
| System | Country | Launch | Operator | Recent volume | Average value |
|---|---|---|---|---|---|
| Pix | Brazil | Nov/2020 | Central Bank | 8.11 bn transactions in Aug/2026 | ~US$92 |
| UPI | India | 2016 | NPCI | 24.51 bn transactions in Aug/2026 | ~US$6 |
| RTP | USA | Nov/2017 | The Clearing House | 128 mn per quarter (Q1/2026) | ~US$3,750 |
| FedNow | USA | Jul/2023 | Federal Reserve | 2.73 mn per quarter (Q1/2026) | ~US$99,414 |
India: more volume, a concentrated front end
UPI processed 24.51 billion transactions in August 2026, an average of 791 million per day, with 752 banks connected. In absolute numbers, that is three times Pix. Per person, Pix handles more than twice as much.
The design difference is at the customer-facing end. Most UPI use goes through third-party apps. In July 2026, Walmart's PhonePe held 45.89% of transactions, Google Pay 32.33% and Paytm 8.05%. Three apps account for 86% of volume. With Pix, the entry point is the bank's own app or a regulated payment initiator, and the concentration measured by the central bank is below 10%. Infrastructure is public in both countries. The front door is not.
United States: modern rails, few people using them
FedNow launched in July 2023 and had 1,725 banks and credit unions in the first quarter of 2026, 19.7% of American institutions. That quarter it processed 2.73 million transactions, totaling US$271 billion. At the average pace of its record day, Pix handles 2.73 million transactions in about 12 minutes.
The comparison is unfair, and the research explains why. Zhu Wang and Vinh Phan of the Richmond Fed point out that Americans already have alternatives that feel instant, such as Zelle, push-to-card transfers and digital wallets, with settlement later. Countries that depended on cash can leapfrog more easily than countries with cards and ACH everywhere. That is why FedNow ended up with high-value payments: payroll, loan disbursement and real-estate settlement. Sarkisyan identifies the other difference: Pix was designed as a retail system with mandatory bank participation, while FedNow arrived without that requirement.
Europe: a connection that is only just beginning
On September 24, 2026, the central bank and the European Central Bank began assessing the feasibility of linking Pix to TIPS, the Eurosystem's instant settlement infrastructure, which currently operates in euros, Swedish kronor and Danish kroner. The ECB is studying similar connections with UPI, the Swiss system and Nexus. Among them, the Pix connection is the most embryonic, and there is no public timetable.
Today, Pix outside Brazil operates through partnerships between companies. Payment leaves in reais over domestic infrastructure to a Brazilian institution, which then sends the money abroad through traditional channels. Pix itself only settles domestic transactions. A direct link between central bank systems would be something else.
Carlos Eduardo Brandt
The specialist answering fee questions at that 2020 press conference joined the central bank as an analyst more than 23 years ago. Brandt has degrees in civil engineering from UnB and law from IESB, with a specialization in finance from FGV. He arrived at the start of the period when the central bank was restructuring the Brazilian Payments System, in 2002.
At Pix's launch, he was deputy head of the Department of Competition and Financial Market Structure, Decem, and the person explaining the system on the central bank's live broadcasts. He led the team that developed Pix. In 2021, as Pix turned one, he was the only Brazilian on Bloomberg's list of the 50 people who shaped business that year.
The press calls him the "father of Pix". The central bank itself prefers to say, in the Management Report, that Pix was built by many hands: its technical staff and the institutions that took part in its creation. Both things are true at once. A project of this size needs many people and someone accountable for it.
In August 2025, after 23 years, Brandt left the central bank for the IMF in Washington as a senior financial-sector specialist. He told BBC News Brasil that he thought he could contribute to other countries on a global scale. His subject now is the problem Pix still does not solve: instant payments between countries. He closely follows BIS's Nexus, which starts with India, Malaysia, the Philippines, Singapore and Thailand, and the financial integration of 16 Southern African countries.
A month after the central bank began studying a connection with Europe, the problem he had gone abroad to solve knocked on the door of the place he had left.
What Pix opened up
Pix is not open source in the strict sense. SPI and DICT's code remains inside the central bank. Its foundation is Kafka, an open project bought with a company's support. What the bank opened up was the rest: Apache 2.0-licensed APIs, manuals, timing targets with percentiles, the versioning policy and even the rule deciding how much it costs to look up a nonexistent key.
None of it is free. Banks lost end-of-day netting and hold more government bonds instead of loans. The perimeter became the target, and the system's largest-ever theft went through a credential sold for R$15,000. The big money is still on TED.
In 1883, Auguste Kerckhoffs wrote about military ciphers that a system must remain secure even if it falls into enemy hands. The secret belongs in the key, not the mechanism. DICT follows the same logic. Knowing that an individual's bucket holds 100 tokens gives nobody any tokens. To exceed the limit, an attacker needs more CPFs and more accounts, and each leaves a trail.
Hiding the design is betting that nobody will look. Publishing it is betting that looking will not help.
Sources
Official documents and specifications
- Pix Management Report 2020–2022, Central Bank of Brazil
- Pix Management Report 2023–2025, Central Bank of Brazil
- Pix Timing Manual, version 7.0, Central Bank of Brazil
- Communiqué 32,927, Central Bank of Brazil, December 21, 2018
- bacen/pix-api, Pix API specification
- bacen/pix-dict-api, DICT API repository, marked obsolete
- DICT API openapi.yaml, version 1.8.0
Research
- Duarte, Frost, Gambacorta, Koo Wilkens and Shin, Central banks, the monetary system and public payment infrastructures: lessons from Brazil's Pix, BIS Bulletin 52, 2022
- Sarkisyan, Instant Payment Systems and Competition for Deposits, SSRN
- Gonzalez, Ma and Zeng, The Effect of Instant Payments on the Banking System, BCB Working Paper 619, 2025
- Wang and Phan, FedNow and the Development of U.S. Fast Payments, Richmond Fed Economic Brief 26-28, 2026
- Research Spotlight: Instant Payment Systems and Competition for Deposits, Wharton
Vendor
- Brazilian bank builds instant payment network with Red Hat, Red Hat case study, 2021
Press
- Central bank unveils the PIX logo, Teletime, February 19, 2020
- More than 3.5 million Pix keys already registered, Agência Brasil via Money Times, October 5, 2020
- PIX reaches 30 million registered keys, FDR, October 14, 2020
- The end of DOC? Febraban says banks will stop offering the transaction type, Suno, May 4, 2023
- Pix sets a single-day record: 250 million transactions, InfoMoney, December 10, 2024
- Central bank suspends three Pix institutions after cyberattack, Agência Brasil, July 4, 2025
- Pix leader is at the IMF, Baguete, November 17, 2025
- New Pix security rules take effect, Agência Brasil, February 2, 2026
- UPI hits new record with 24.51 Bn transactions in August, Entrackr, September 1, 2026
- Pix sets a daily transaction record, Metrópoles, September 5, 2026
- The most-used payment methods in August 2026, Glin, September 17, 2026
- Brazilian and European central banks begin assessing a Pix–TIPS connection, DW via O Povo, September 25, 2026
聖保羅的一場記者會
2020 年 2 月 19 日,星期三,巴西中央銀行在聖保羅的一場記者會上,公布了正在打造的即時支付系統的名稱與品牌。董事 João Manoel Pinho de Mello 展示標誌,並試著說出幾個月後全國都會掛在嘴上的那句話:「用 Pix 轉給我。」坐在他身旁回答手續費問題的,是負責此專案的部門副主管 Carlos Eduardo Brandt。本文結尾還會回到他身上。
當時央行總裁是 Roberto Campos Neto,Pix 成了他任內的招牌。但 Pix 並非誕生於這場記者會,而是兩年前的一個工作小組。
從 2018 年到 2020 年 11 月
2018 年 5 月,央行成立即時支付工作小組,向任何有興趣的機構或個人開放。參與者超過 130 名,所有人的意見都公布在央行網站上。成果於 2018 年 12 月 21 日,以第 32,927 號公報發布:集中清算、規則治理、參與方式與流動性供應。
在那份公報中,央行做出一個決定,定義了後續整個故事。它不僅要當監管者,還要制定規則、營運基礎設施,後來又決定親自開發。央行自 2014 年起就要求市場提供開放的解決方案,卻始終沒有結果。當時只有封閉錢包,付款人和收款人必須是同一家機構的客戶。
2019 年 10 月,央行開始打造支撐 Pix 的兩個核心元件。SPI,即時支付系統,負責不同機構之間的交易清算。DICT,交易帳戶識別碼目錄,則儲存每個識別碼與其帳戶之間的關聯。
一年後,2020 年 10 月 5 日,識別碼註冊開放。首日就有 350 萬個,大型銀行的應用程式在當天早上還一度卡住。到了 10 月 13 日晚間,僅八天多,就已有 3,000 萬個。11 月 3 日開始限量營運,各機構先開放部分客戶使用。2020 年 11 月 16 日,Pix 全面上線。
它清除了哪些障礙
上線首月,Pix 的交易筆數就超過 DOC。2021 年 1 月超越 TED,3 月超越 boleto 銀行付款單。到了 2022 年第一季,它成為全國最常用的電子支付方式,領先信用卡與金融卡。
由央行於 1985 年建立的 DOC,沒能在比較中存活。它的上限是 4,999.99 巴西雷亞爾,而且要到下一個工作天才入帳。Febraban 會員銀行於 2024 年 1 月 15 日晚間 10 點停止接受新指令,並在 2024 年 2 月 29 日關閉系統。TEC 也一併退場。
交易量曲線符合一項基礎設施成為日常習慣後的樣貌。2021 年有 94 億筆,2022 年 240 億筆,2023 年 417 億筆,2024 年 634 億筆,2025 年 798 億筆。金額方面,2025 年超過 35 兆雷亞爾。2026 年 8 月是首個突破 80 億筆的月份:81.1 億筆,合計 3.73 兆雷亞爾。
交易筆數掩蓋了一個細節。同樣在那個 8 月,TED 處理了 6,700 萬筆,轉移 3.90 兆雷亞爾,比整個 Pix 還多。Pix 贏的是數量。企業之間的大額支付,仍有很大一部分走舊軌道。
使用型態也變了。2020 年,85% 的交易發生在個人之間,6% 是個人付給企業。2025 年,兩者幾乎平分秋色:44% 與 43%。商店每筆銷售產生的動態 QR Code,從 2021 年的 5% 升至 2025 年的 40%。2025 年 Pix 的交易金額中位數是 36 雷亞爾,平均值則約為 440 雷亞爾。大量小額交易,少數大額交易拉高平均值。這正是取代現金的使用模式。
截至 2025 年底,已有 1.48 億名個人使用 Pix,約占成年人口的 86%,另有 1,280 萬家企業、926 家參與機構,以及超過 9.2 億個識別碼。
Kafka、OpenShift、Ansible
央行沒有購買現成的支付系統。SPI 與 DICT 都由央行自行開發,也由它營運。它向外部尋求的是底層基礎。招標要求採用 Apache Kafka,建立分散式且高度可擴展的架構。
這個選擇符合問題本身。Kafka 是分散式日誌:訊息儲存在分割區中,並複寫到多個 broker。要承受更大負載,就增加 broker 與分割區,而不是換成更大的機器。如果一個 broker 故障,就由副本接手。對於不能在夜晚、星期日或聖誕節停機的系統,這兩項特性就是基本要求。
根據 Red Hat 在 2021 年 1 月公布的案例研究,得標者是 Red Hat,提供各個元件的企業版本。AMQ 以 Kafka 處理串流,OpenShift 承載存取層與業務邏輯應用程式,Ansible Automation Platform 則自動化基礎設施,並整合合作夥伴的自動化流程。
| 元件 | 產品 | 在 Pix 中的角色 |
|---|---|---|
| 訊息傳遞 | Red Hat AMQ (Streams for Apache Kafka) | 服務之間的分散式串流 |
| 編排 | Red Hat OpenShift | 存取層與業務邏輯應用程式 |
| 自動化 | Red Hat Ansible Automation Platform | 基礎設施自動化與合作夥伴整合 |
伴隨這段故事經常出現的數字,也來自同一來源。在概念驗證中,以預期每秒 2,000 筆交易的負載測試,央行內部 99% 的交易在四秒內完成處理。央行伺服器架構部門主管 Vicente Fernandes 表示,Red Hat 在該階段滿足了所有要求。
閱讀時仍應保持一貫的懷疑態度。這是 2020 年、正式上線前進行的測試,由供應商公布。概念驗證是嚴肅的部分:供應商必須先證明系統能承受負載,才能拿到合約。案例研究則是行銷的部分。
一筆 Pix 的解剖
兩家不同銀行之間的一筆 Pix,從你確認付款到收到扣款通知,共有央行定義的八個時間節點。它們記載於目前為第 7.0 版的《Pix 時間手冊》。在此之前,當你輸入識別碼時,銀行會查詢 DICT,並顯示收款人的姓名。
payer payer PSP DICT / SPI (BC) recipient PSP
| | | |
|--- key ------->|---- DICT query ------->| |
|<-- name -------|<--- link --------------| |
|--- confirm --->| t0' | |
| | t1 builds pacs.008 | |
| |------ pacs.008 ------->| t1' |
| | | t2 makes available --->|
| | |<------ pacs.002 -------| t3'
| | | t4 debit and credit |
| | | in PI Accounts |
| |<----- pacs.002 --------| t5a |
|<-- "paid" -----| t6a | |
其中 t0' 是你的銀行收到付款確認的時刻,記錄在訊息的 AcceptanceDateTime 欄位。t1 是銀行組成 ISO 20022 標準付款指令 pacs.008 的時刻,在簽署之前量測。SPI 在 t1' 透過 HTTP 收到訊息,於 t2 提供給收款銀行。收款銀行在 t3' 回覆 pacs.002。到了 t4,SPI 調整兩家銀行即時支付帳戶的餘額,這就是清算完成的時刻。pacs.002 在 t5a 回到付款銀行,你在 t6a 收到通知。
每一段都有自己的目標:
| 區段 | 時間節點 | 央行目標 |
|---|---|---|
| 付款銀行組成並發送指令 | t1 − t0' | P50 0.9 秒 · P95 1.5 秒 |
| 收款銀行核准 | t3' − t2 | P50 1.4 秒 · P95 2.3 秒 |
| SPI 內部耗時 | (t2 − t1') + (t5a − t3') | P50 2.8 秒 · P99 4.6 秒 |
| 付款人體驗 | t6a − t0' | P50 6 秒 · P99 10 秒 |
| DICT 識別碼查詢(央行端) | — | P99 1 秒 |
| 識別碼查詢(付款人體驗) | — | P99 2 秒 |
| 主通道硬性上限 | t0' → t4 | 40 秒,逾時由 SPI 拒絕 |
| 次要通道(預約付款) | t1' → t4 | 45 分鐘 |
硬性上限是 40 秒。超過就由 SPI 拒絕交易。預約 Pix 走次要通道,上限為 45 分鐘,避免與正在收銀台等待的人搶資源。疑似詐欺的交易,付款銀行可在工作日上午 8 點至晚間 8 點之間暫留最多 30 分鐘,其他時段最多 60 分鐘。
有個工程細節值得單獨一段:手冊禁止用不同機構的時鐘量測指標,因為即使微小差異也會扭曲結果。各機構負責同步自己的伺服器。因此,表格中的每個區間都只在同一側量測。曾嘗試用第三方 NTP 量測兩座資料中心之間延遲的人,會理解這個決定。
可用性也有目標。SPI 在三個月視窗內必須達到 99.9% 的正常運作時間;若因 SPI 本身造成 80% 或以上的請求失敗,且持續超過 36 秒,就算停機。DICT 查詢的目標為 99.9%,更新為 99.8%。銀行依交易量分類,目標從最大銀行的 99.5%,到最小銀行的 95%。
當付款人與收款人在同一家銀行時,Pix 根本不經過 SPI。DICT 規格禁止在這種情況下查詢識別碼。銀行在內部清算,並有最多 30 天向央行申報交易。
一切的底層是流動性。每個直接參與者都在央行持有 PI 帳戶,自 2022 年 8 月起按 Selic 利率計息。在流動性系統工作日上午 6 點 30 分至下午 6 點 30 分的營業時間之外,為帳戶補充資金的來源更加受限。Pix 每天 24 小時、每週 7 天運作,銀行的資金管理必須跟上。學術研究部分還會回到這一點。
今天的基礎設施承受多少負載
2024 年 12 月 6 日,星期五,也是當月第五個工作天,Pix 首次在單日突破 2.5 億筆交易:共 2.505 億筆,合計 1,243 億雷亞爾。一年後,2025 年 12 月 5 日,達到 3.133 億筆。金額紀錄則是 2025 年 12 月 19 日,單日 1,935 億雷亞爾。
目前的筆數紀錄是 2026 年 9 月 4 日:SPI 清算 318,073,816 筆交易,合計 1,868.9 億雷亞爾。除以一天的 86,400 秒,平均每秒約 3,700 筆。整個 2026 年 8 月,平均每秒約 3,000 筆。2025 年則每秒約 2,500 筆,全年如此,連深夜也算在內。2020 年概念驗證的負載,如今已是普通一天的平均值。而支付系統的尖峰永遠遠高於平均。
程式碼封閉,介面契約開放
SPI 與 DICT 的程式碼沒有公開。以 Apache 2.0 授權公開的是契約:系統各部分如何彼此溝通。任何人都能閱讀,不必是銀行,不必申請資格,也不必簽署保密協議。
這裡有兩套 API。Pix API 是各銀行或金融科技公司向企業提供的介面,涵蓋收款、QR Code、對帳與退款。規格採 OpenAPI 3.0,目前為 2.10.0 版,在 GitHub 上約有 3,000 顆星與 303 個 fork。央行刻意將這套 API 標準化,正是它讓商店系統能接上 Pix,每筆銷售產生一個 QR Code。商店更換銀行時,整合方式保持相同,離開一家銀行的成本也隨之降低。
DICT API 則是參與者與央行目錄溝通的介面。同樣採 OpenAPI 3.0、Apache 2.0,但使用 XML。身分驗證採雙向 TLS。每個寫入請求都使用 XML Digital Signature 簽署,DICT 的每個回應也都有簽章。
有個細節會改變閱讀方式:GitHub 上的 DICT 儲存庫已標記為過時。那裡最後發布的是 2022 年 9 月的 1.8.0 版,後續更新只在央行網站發布。規格仍然公開,只是換了地址。
API 周圍還有各種手冊:安全、啟動標準、時間,以及 DICT 操作手冊,都在 Pix 的法規頁面上。
DICT 規格也寫明版本政策。不相容的變更最多每六個月發布一次,前一版本至少繼續提供一個月。這不是核心的「we do not break userspace」,但它是寫下來、有日期、能要求履行的承諾。
DICT:防止大量抓取的措施寫在規格裡
DICT 儲存識別碼、帳戶與持有人的關聯:CPF 或 CNPJ 稅籍編號、姓名、銀行、分行、帳號。2022 年底,77% 的成年人口已有註冊識別碼。誰若能大規模查詢這個目錄,就能建立包含半個國家姓名、證件號碼與銀行的資料庫。規格把這當成首要威脅,並以公開文字說明每一道防線。
以下數字來自 1.8.0 版。央行網站上的現行版本可能已更改數值。
每個人的權杖桶
每次識別碼查詢都受到 token bucket,也就是權杖桶演算法的速率限制。每個政策都有一個權杖桶、補充速率與計數規則。桶空了,DICT 就回覆 429。
最有意思的是針對最終使用者的政策。個人的桶有 100 個權杖,企業的桶有 1,000 個,兩者每分鐘都補充 2 個。共有兩套數值相同的政策:一套針對電子郵件與手機號碼,另一套針對 CPF、CNPJ 與隨機識別碼。查到識別碼扣 1 個權杖;查詢不存在的識別碼扣 20 個;查詢後實際送出 Pix,返還 1 個。
| 事件 | 對權杖桶的影響 |
|---|---|
| 查到識別碼 | −1 個權杖 |
| 查詢不存在的識別碼(404) | −20 個權杖 |
| 查詢後實際送出 Pix | +1 個權杖 |
正常使用 Pix 的人查詢、付款,便拿回權杖。試圖掃描手機號碼的人幾乎總是猜錯,每次猜錯的成本是命中的二十倍。五次錯誤猜測就能耗盡個人的滿桶。之後每分鐘只補 2 個,而每次錯誤仍要花 20 個。
機構層級還有第二道限制。每個參與者分為 A 到 F 類,從每分鐘 12,000 個權杖、桶容量 20,000 個,到每分鐘 2 個、桶容量 1,000 個。在這一層,查不到資料扣 3 個權杖。容許客戶抓取目錄的銀行,也會一起受到節流限制。
每次查詢都帶上付款人的 CPF
要讓個人層級的限制生效,DICT 就必須知道那個人是誰。每次查詢都帶有 PI-PayerId 標頭。從 1.5.0 版起,它包含付款人的 CPF 或 CNPJ,而且規格禁止將這個值假名化,因為央行正是用它追蹤超過限額的人。查詢還包含 PI-EndToEndId,也就是即將進行的付款識別碼。
量化計數器
查詢識別碼也會回傳收款人的反詐欺資料:有多少交易、收到多少詐欺通報,以及多少獲得確認。計數器依識別碼、持有人與帳戶彙總,分為最近 3 天、30 天與 6 個月三個時間視窗。
交易計數並非精確值。刻度是 0、1、5、10、50、100、500、1,000、5,000,一律向上取整。三筆交易變成 5,190 筆變成 500。
規格沒有解釋原因。最合理的解讀是,付款銀行只需要數量級來衡量風險,無須更多。從未收到款項的帳戶是一回事,收到數千筆款項的帳戶是另一回事。精確數字會成為第三方的金融資訊,交到一個只是想轉一筆 Pix 給他的人手上。
識別碼或帳戶停用時,計數器也不會歸零;攜碼或更換持有人時,會轉入新紀錄。刪除識別碼不能清除歷史。
使用 XOR 對帳
每家銀行都保有客戶關聯資料的副本,必須與 DICT 一致。因此,每次對關聯的操作都會產生 CID:對關聯的必要屬性計算 HMAC-SHA256,金鑰則是建立該關聯的請求中的 16 個隨機位元組。
檢查整個資料庫時,銀行不必傳送數百萬筆紀錄。它計算 VSync,也就是某一識別碼類型所有 CID 的 XOR,再與 DICT 的值比較。XOR 具有交換律,而且是自己的反運算。順序不重要,新增或刪除一個關聯只需一次 XOR。若兩個 VSync 相符,資料庫就以極高機率一致;若不相符,則肯定不同。
v1.8.0 之後的變更
2023 年 11 月,DICT 的安全資訊新增了通知原因與詐欺類型欄位。自 2025 年 7 月起,識別碼相關資料必須與聯邦稅務局的 CPF、CNPJ 登記一致。自 2025 年 10 月起,若識別碼或持有人被即將接收 Pix 的銀行本身標記為詐欺,DICT 就不再回傳該識別碼資料。
當薄弱環節在央行之外
《Pix 管理報告 2023–2025》指出,央行系統從未遭受成功的攻擊。同一份報告也承認,針對參與機構的詐欺、騙局與攻擊,越來越常把 Pix 當作資金分散管道。兩件事同時為真,而損失最大的案例說明了原因。
2025 年 7 月 1 日晚間,一場針對 C&M Software 系統的攻擊,從銀行存放在央行的準備金帳戶盜走資金。C&M 本身不替任何人移動資金,它負責將小型機構連接到巴西支付系統。款項透過 Pix 轉出,再換成加密貨幣。EBC 確認至少 4 億雷亞爾遭竊。警方逮捕了一名收取 15,000 雷亞爾的 C&M 員工,其中 5,000 是密碼的價錢,另 10,000 用來替犯罪者建立存取管道。
SPI 依照規格運作。失守的是供應商的憑證,由有權存取的人出售。沒有任何公開規格能解決一個願意開價的內部人員。
回應分層展開。自 2025 年 9 月起,未獲央行授權,或透過技術供應商連接國家金融系統網路的參與者,每筆 Pix 上限為 15,000 雷亞爾,超出即由 SPI 自動拒絕。自 2024 年 11 月起,只有央行授權的機構可參與,支付機構申請授權的期限則提前至 2026 年 5 月 1 日。自 2026 年 1 月起,除信用合作社外,每個參與者的股本與淨資產都必須至少達到 500 萬雷亞爾。
付款人方面,自 2024 年 11 月起,未登記裝置的 Pix 每筆限額 200 雷亞爾,每天 1,000 雷亞爾。自 2025 年 9 月起,最長 72 小時的預防性凍結也適用於企業帳戶。
MED,特別退款機制,自 2021 年就已存在。2025 年 10 月,銀行應用程式內新增了爭議申訴按鈕。2.0 版於 2026 年 2 月 2 日成為強制要求。它追蹤資金經過的中介帳戶,要求在調查期間凍結可疑款項最多 11 天,並給受害者銀行 30 分鐘通知收款銀行。演算法會繪製資金分散路徑,自動發送通知;但只有詐欺獲確認,且經由連續轉帳鏈與原始交易相連的對象,才會收到退款要求。這個設計保護了不知情收取部分款項的善意賣家。
對從事模型工作的人來說,下一步最值得關注。央行正在開發詐欺機率指標,利用機器學習模型,為所有交易集中、即時計算。是否核准仍由各銀行決定,央行自己也表示,只有信任模型校準結果、且法律分析允許,才會分享指標。為全國每筆 Pix 建立中央風險分數,是很強大的工具。設計上的問題是:誰能看到這個數字,又依循什麼規則?
學術研究發現了什麼
Pix 很早就成了研究對象,結果不只一句「成功了」。
2022 年 3 月,國際清算銀行由 Angelo Duarte、Jon Frost、Leonardo Gambacorta、Priscilla Koo Wilkens 與 Hyun Song Shin 署名的一份公報指出,Pix 在一年多內已觸及 67% 的成年人口。作者提出兩個要素:強制大型銀行參與,為網路效應提供最初推力;以及央行同時擔任基礎設施提供者與規則制定者。強制要求適用於擁有 50 萬個以上活躍帳戶的機構。
現於 Ohio State 任職的 Sergey Sarkisyan 研究了它對銀行競爭的影響。小型銀行的存款相對大型銀行增加,因為 Pix 讓兩者的付款便利性拉平。小銀行在支付服務上更具競爭力後,開始支付相對較低的存款利率;他的估計模型顯示,存款人福利有所提升。以前,小銀行靠較高利息補償劣勢。有了 Pix,就不再需要。
央行數據指向同一方向。支付機構在付款端交易的占比,從 2020 年的 25.5% 升至 2025 年的 50%。綜合銀行則從 55.8% 降至 35%。赫芬達爾—赫希曼集中度指數低於 10%,屬於低集中度區間。
代價則出現在央行自己的工作論文中。央行的 Rodrigo Gonzalez、Columbia 的 Yiming Ma 與 Wharton 的 Yao Zeng 指出,即時支付剝奪了銀行延後支付、在日終抵銷流入與流出的能力。對中位數銀行而言,57% 至 80% 的 Pix 資金流,在舊模式下原本可以互相抵銷。銀行的回應是持有更多流動資產:Pix 使用量每增加一個標準差,流動資產占比就增加 15.4 個百分點,主要是政府債券,而放款占比下降。用作者的話說,銀行變得更「狹窄」。
他們用來區分因果的工具,正是 Pix 的一個技術細節:逾時。若對方銀行未在 40 秒內處理交易,交易便失敗。作者只量測由交易對手銀行造成、受研究銀行無法控制的失敗。《時間手冊》的 40 秒上限,成了一篇金融論文中的工具變數。
同一篇論文還引用 Liang、Sampaio 與 Sarkisyan 的另一項研究,指出更激烈的存款競爭會放大貨幣政策傳導。Pix 透過一條 2018 年沒人設計過的路徑,影響了 Selic。
Pix、UPI、FedNow 與世界其他地方
第一個即時支付系統出現在 2001 年的南韓,到 2023 年,已有超過 60 個司法管轄區擁有類似系統。讓 Pix 不同的不是速度,而是使用程度。
Richmond Fed 引用的一項 2024 年 BIS 研究,量測了 2023 年每人每月的交易筆數:泰國 PromptPay 為 35,Pix 為 27,瑞典 Swish 為 13,印度 UPI 為 11。美國合計 RTP 與 FedNow,在 2026 年第一季只有 0.12。平均金額也訴說同樣的故事:Pix 約 92 美元、UPI 約 6 美元、RTP 約 3,750 美元、FedNow 約 99,414 美元。
| 系統 | 國家 | 上線時間 | 營運者 | 近期交易量 | 平均金額 |
|---|---|---|---|---|---|
| Pix | 巴西 | 2020 年 11 月 | 中央銀行 | 2026 年 8 月 81.1 億筆 | 約 92 美元 |
| UPI | 印度 | 2016 年 | NPCI | 2026 年 8 月 245.1 億筆 | 約 6 美元 |
| RTP | 美國 | 2017 年 11 月 | The Clearing House | 每季 1.28 億筆(2026 年第一季) | 約 3,750 美元 |
| FedNow | 美國 | 2023 年 7 月 | Federal Reserve | 每季 273 萬筆(2026 年第一季) | 約 99,414 美元 |
印度:交易量更大,前端更集中
UPI 在 2026 年 8 月處理 245.1 億筆交易,平均每天 7.91 億筆,連接 752 家銀行。絕對數字是 Pix 的三倍,但按人口計算,Pix 超過它的兩倍。
設計差異在使用者接觸的那一端。UPI 大部分使用量經過第三方應用程式。2026 年 7 月,Walmart 旗下 PhonePe 占交易的 45.89%,Google Pay 占 32.33%,Paytm 占 8.05%。三個應用程式合計 86%。Pix 的入口則是銀行自己的應用程式,或受監管的支付啟動服務商,央行量測的集中度低於 10%。兩國的基礎設施都是公共的,入口卻不是。
美國:現代軌道,使用者不多
FedNow 於 2023 年 7 月上線,到 2026 年第一季共有 1,725 家銀行與信用合作社,占美國機構的 19.7%。該季處理 273 萬筆交易,合計 2,710 億美元。依 Pix 紀錄日的平均速度,約 12 分鐘就能完成 273 萬筆。
這個比較並不公平,研究也解釋了原因。Richmond Fed 的 Zhu Wang 與 Vinh Phan 提醒,美國人早已有看似即時、稍後才清算的替代方案,例如 Zelle、轉入卡片的付款,以及數位錢包。依賴現金的國家,比起信用卡與 ACH 無所不在的國家,更容易跨越階段。因此,FedNow 留下的是高額支付:薪資發放、貸款撥款、不動產交割。Sarkisyan 指出另一個差異:Pix 一開始就是零售系統,要求銀行參與;FedNow 則沒有這項義務。
歐洲:才剛開始的連接
2026 年 9 月 24 日,巴西央行與歐洲中央銀行開始評估連接 Pix 與 TIPS 的可行性。TIPS 是歐元體系的即時清算基礎設施,目前處理歐元、瑞典克朗與丹麥克朗。ECB 也在研究與 UPI、瑞士系統及 Nexus 的類似連接。其中 Pix 的連接最處於早期階段,尚無公開時程。
目前,巴西境外的 Pix 透過企業合作運作。付款以雷亞爾經由國內基礎設施,先到一家巴西機構,再由它透過傳統管道匯往海外。Pix 本身只清算國內交易。央行系統之間的直接連接,會是另一回事。
Carlos Eduardo Brandt
那位在 2020 年記者會上回答手續費問題的技術人員,二十三年多前以分析師身分加入央行。Brandt 擁有 UnB 的土木工程學位、IESB 的法律學位,以及 FGV 的金融專業資格。他在 2002 年、央行開始重整巴西支付系統的時期加入。
Pix 推出時,他是競爭與金融市場結構部門 Decem 的副主管,也是央行直播中解說系統的人。他領導了開發 Pix 的團隊。2021 年 Pix 滿一歲時,他是 Bloomberg 當年「塑造商業走向的 50 人」名單中唯一的巴西人。
媒體稱他為「Pix 之父」。央行在管理報告中則更願意說,Pix 由許多雙手共同打造:央行技術團隊,以及參與建設的機構。兩件事同時為真。這種規模的專案,需要很多人,也需要有人負責。
2025 年 8 月,任職 23 年後,Brandt 離開央行,前往華盛頓的 IMF 擔任金融部門資深專家。他告訴 BBC News Brasil,認為自己能在全球範圍協助其他國家。他現在關注的是 Pix 尚未解決的問題:跨國即時支付。他密切追蹤 BIS 的 Nexus,首批涉及印度、馬來西亞、菲律賓、新加坡與泰國,也關注南部非洲 16 國的金融整合。
在央行開始研究連接歐洲的一個月後,他出國想解決的問題,敲響了他離開的那個地方的大門。
Pix 開放了什麼
嚴格來說,Pix 並不是開源系統。SPI 與 DICT 的程式碼仍留在央行內部。底層是 Kafka,一個搭配企業支援購買的開放專案。央行開放的是其他部分:採 Apache 2.0 授權的 API、手冊、帶百分位數的時間目標、版本政策,甚至查詢不存在識別碼要付出多少成本的規則。
這一切都有代價。銀行失去日終抵銷,改持更多政府債券而非放款。外圍成了攻擊目標,系統史上最大竊案經由一組以 15,000 雷亞爾出售的憑證發生。大額資金仍留在 TED。
1883 年,Auguste Kerckhoffs 談軍用密碼時寫道,即使系統落入敵手,也必須保持安全。秘密應該在金鑰,而不是機制。DICT 遵循同樣邏輯。知道個人的桶有 100 個權杖,並不會讓任何人多拿到一個。攻擊者要突破上限,就需要更多 CPF 與帳戶,而每一個都會留下痕跡。
隱藏設計,是賭沒人會去找。公開設計,是賭找了也沒有用。
來源
官方文件與規格
- Pix 管理報告 2020–2022,巴西中央銀行
- Pix 管理報告 2023–2025,巴西中央銀行
- Pix 時間手冊,第 7.0 版,巴西中央銀行
- 第 32,927 號公報,巴西中央銀行,2018 年 12 月 21 日
- bacen/pix-api,Pix API 規格
- bacen/pix-dict-api,已標記為過時的 DICT API 儲存庫
- DICT API 的 openapi.yaml,第 1.8.0 版
研究
- Duarte、Frost、Gambacorta、Koo Wilkens 與 Shin,Central banks, the monetary system and public payment infrastructures: lessons from Brazil's Pix,BIS Bulletin 52,2022 年
- Sarkisyan,Instant Payment Systems and Competition for Deposits,SSRN
- Gonzalez、Ma 與 Zeng,The Effect of Instant Payments on the Banking System,BCB Working Paper 619,2025 年
- Wang 與 Phan,FedNow and the Development of U.S. Fast Payments,Richmond Fed Economic Brief 26-28,2026 年
- Research Spotlight: Instant Payment Systems and Competition for Deposits,Wharton
供應商
- Brazilian bank builds instant payment network with Red Hat,Red Hat 案例研究,2021 年
新聞報導
- 央行公布 PIX 標誌,Teletime,2020 年 2 月 19 日
- Pix 已註冊超過 350 萬個識別碼,Agência Brasil,經 Money Times 刊載,2020 年 10 月 5 日
- PIX 達到 3,000 萬個註冊識別碼,FDR,2020 年 10 月 14 日
- DOC 結束?Febraban 表示銀行將停止提供此類交易,Suno,2023 年 5 月 4 日
- Pix 創單日 2.5 億筆交易紀錄,InfoMoney,2024 年 12 月 10 日
- 網路攻擊後,央行暫停三家機構的 Pix 資格,Agência Brasil,2025 年 7 月 4 日
- Pix 領導者已加入 IMF,Baguete,2025 年 11 月 17 日
- Pix 新安全規則生效,Agência Brasil,2026 年 2 月 2 日
- UPI hits new record with 24.51 Bn transactions in August,Entrackr,2026 年 9 月 1 日
- Pix 創下單日交易紀錄,Metrópoles,2026 年 9 月 5 日
- 2026 年 8 月最常用的支付方式,Glin,2026 年 9 月 17 日
- 巴西與歐洲央行開始評估連接 Pix 與 TIPS,DW,經 O Povo 刊載,2026 年 9 月 25 日