eUSD's confidentiality, the integrity of the reserve, and regulator-accessible disclosure all rest on well-studied cryptographic primitives, audit-ready program logic, and a multisig governance design with no single point of failure.
Twisted ElGamal, bulletproofs, and Pedersen commitments on the Ristretto255 group. Standard hardness assumptions, no bespoke cryptography.
2-of-3 Squads v4 multisig protects the mint, the IWR, the freeze authority, the reserve, and the Auditor Key’s on-chain registration and disclosure register — the decryption key itself is held off-chain, because a multisig cannot hold one. No single signer can act unilaterally. Until authorisation the Auditor Key has a single holder; moving it to 2-of-3 threshold key-sharing across separate hardware security modules is a Compliance Phase commitment.
Every protocol upgrade affecting the mint, IWR, Auditor Key, or SLV is held for at least 24 hours before execution — visible to anyone in the meantime.
Every privileged operation — Auditor Key, freeze, Recovery Escrow Vault disposition, IWR modification — is recorded on-chain. Operator actions are published after 24 hours; disclosures made to a financial intelligence unit are held until anti-money-laundering law permits publication, with the unpublished count reported each quarter.
The protocol consumes the audited Token-2022 program as a standard library — no modified or forked token program with bespoke audit burden.
Softseco holds no email addresses, no passwords, no customer databases; any KYC required at mint and redeem is performed by licensed ramp partners. Authentication is performed by the user's wallet — no central honeypot to breach.
The security and regulatory roadmap is sequenced across phases.
Single firm engaged to review the initial Anchor program suite. Objective: identify structural issues, common vulnerability classes, and design-level concerns before further development.
Formal pre-application dialogue with the Polish Financial Supervision Authority (KNF). Submission of preliminary documentation. Engagement of EU-qualified legal counsel.
Multiple firms in parallel review with non-overlapping methodologies. A third firm for the highest-risk components (Shielded Liquidity Vault, Auditor Key).
Formal Electronic Money Institution authorization application submitted to KNF. Authorization, once granted, is passportable across the European Union under MiCA.
Public program through Immunefi or equivalent, with rewards scaled to severity. Open to the entire program suite plus the SDK.
Ongoing audit relationship for incremental review of upgrades. Open-source publication of program source code for independent third-party review.
We don't pretend they don't exist.
Disabled on Solana in June 2025 after a proof-verification vulnerability, then re-enabled on mainnet in June 2026 following independent security audits — confidential transfers run on mainnet today. The program is maintained outside Softseco's control and has been suspended once already, so both the Shielded Liquidity Vault and the token's confidential transfers carry that dependency. Contingency paths (Arcium's MPC-based Confidential SPL, or deferring the SLV) are set out in whitepaper §9.2.
The confidentiality properties rest on the discrete logarithm assumption on Ristretto255. Not protected against a sufficiently capable future quantum adversary. Migration path under review.
The 1:1 on-chain mint and redeem route, and the operational float that keeps it instant, are held in USDC, so a Circle-level event would affect on-chain convertibility. Fiat mint and redemption by bank transfer is available from launch and is unaffected; the reserve itself holds no USDC.