Security

Layered defense. Audit-ready foundations. Honest disclosure.

eUSD's confidentiality, the integrity of the reserve, and regulator-accessible disclosure all rest on well-studied cryptographic primitives, audit-ready program logic, and a multisig governance design with no single point of failure.

How it's secured

Six layers of defense.

Cryptographic primitives

Twisted ElGamal, bulletproofs, and Pedersen commitments on the Ristretto255 group. Standard hardness assumptions, no bespoke cryptography.

Multisig governance

2-of-3 Squads v4 multisig protects the mint, the IWR, the freeze authority, the reserve, and the Auditor Key’s on-chain registration and disclosure register — the decryption key itself is held off-chain, because a multisig cannot hold one. No single signer can act unilaterally. Until authorisation the Auditor Key has a single holder; moving it to 2-of-3 threshold key-sharing across separate hardware security modules is a Compliance Phase commitment.

24-hour time-lock

Every protocol upgrade affecting the mint, IWR, Auditor Key, or SLV is held for at least 24 hours before execution — visible to anyone in the meantime.

Public disclosure log

Every privileged operation — Auditor Key, freeze, Recovery Escrow Vault disposition, IWR modification — is recorded on-chain. Operator actions are published after 24 hours; disclosures made to a financial intelligence unit are held until anti-money-laundering law permits publication, with the unpublished count reported each quarter.

Token-2022 substrate

The protocol consumes the audited Token-2022 program as a standard library — no modified or forked token program with bespoke audit burden.

Wallet-native; no PII held by Softseco

Softseco holds no email addresses, no passwords, no customer databases; any KYC required at mint and redeem is performed by licensed ramp partners. Authentication is performed by the user's wallet — no central honeypot to breach.

Future commitments

Audits and licensing — what's planned.

The security and regulatory roadmap is sequenced across phases.

Development Phase · 2027

First security audit

Single firm engaged to review the initial Anchor program suite. Objective: identify structural issues, common vulnerability classes, and design-level concerns before further development.

Development Phase · 2027

MiCA EMI pre-application

Formal pre-application dialogue with the Polish Financial Supervision Authority (KNF). Submission of preliminary documentation. Engagement of EU-qualified legal counsel.

Compliance Phase · 2028

Comprehensive audits

Multiple firms in parallel review with non-overlapping methodologies. A third firm for the highest-risk components (Shielded Liquidity Vault, Auditor Key).

Compliance Phase · 2028

EMI authorization

Formal Electronic Money Institution authorization application submitted to KNF. Authorization, once granted, is passportable across the European Union under MiCA.

Mainnet Beta · 2029

Bug bounty program

Public program through Immunefi or equivalent, with rewards scaled to severity. Open to the entire program suite plus the SDK.

Ongoing

Continuous review

Ongoing audit relationship for incremental review of upgrades. Open-source publication of program source code for independent third-party review.

Known dependencies and risks.

We don't pretend they don't exist.

ZK ElGamal Proof Program

Disabled on Solana in June 2025 after a proof-verification vulnerability, then re-enabled on mainnet in June 2026 following independent security audits — confidential transfers run on mainnet today. The program is maintained outside Softseco's control and has been suspended once already, so both the Shielded Liquidity Vault and the token's confidential transfers carry that dependency. Contingency paths (Arcium's MPC-based Confidential SPL, or deferring the SLV) are set out in whitepaper §9.2.

Post-quantum cryptography

The confidentiality properties rest on the discrete logarithm assumption on Ristretto255. Not protected against a sufficiently capable future quantum adversary. Migration path under review.

USDC dependency on the on-chain rail

The 1:1 on-chain mint and redeem route, and the operational float that keeps it instant, are held in USDC, so a Circle-level event would affect on-chain convertibility. Fiat mint and redemption by bank transfer is available from launch and is unaffected; the reserve itself holds no USDC.