Minted Protocol  /  Security & Compliance

Security and compliance posture

Minted Protocol's core codebase is built, audited, and validated. Compliance infrastructure is institutional-grade and structured for GENIUS Act compliance from architecture, not retrofitted.

99.3%
Overall test coverage
27/27
Five North sandbox phases passed
2
Independent Softstack audits completed
116+
Successful lifecycles exercised
72/72
Stability soak samples passed (6h)
0
Critical findings outstanding

Independent audits

Independently audited by Softstack GmbH (German Web3 audit firm, 1,200+ zero-exploit audits since 2017, institutional clients including Siemens AG). Two completed audit engagements, both dated 2026-02-28. All findings successfully addressed.

Softstack audit — Canton Protocol (DAML)

Softstack audit — DeFi Lending

Note on audit scope: The two Softstack audits cover Minted's prior cross-chain DAML+Solidity architecture, which has been fully deprecated. Current production architecture is 100% Canton-native with no bridges. Bridge-related findings in those audits are not applicable to the current architecture. A third audit on the Canton-native production architecture is in progress.

Five North 5N sandbox validation

Production validator infrastructure operated by Five North SV, LLC (Canton Super Validator) under a signed Validator/NaaS Hosting Services Agreement covering DevNet, TestNet, and MainNet validator nodes on Canton Network. Agreement executed March 23, 2026 (DocuSign Envelope ID 2A8720F7-6FBA-40C9-8936-8323231E31BC).

Separately, the protocol passed all 27 phases of Five North's 5N sandbox validation:

On-chain security architecture

LayerControl
Settlement atomicityDAML atomic commit on Canton — no partial execution
Validator consensus3-of-5 signing, sorted-address dedup
Replay protectionaddress(this) + block.chainid per attestation
Rate limitingNet mint/burn capped, 24-hour rolling window
Collateralization120% enforced on-chain before mint
Oracle stackChainlink + Tradecraft + API3 + TWAP
Key managementDedicated HSM-backed custody with attested enclave signing and dual-control authorization
Emergency controlsMulti-sig admin, 48-hour timelock

Compliance stack

FunctionProvider / status
Money services regulationFinCEN MSB registered
AML / BSAFull BSA/AML compliance program
OFAC screeningChainalysis + TRM Labs
FINRA-member broker-dealer / ATS / transfer agentTexture Capital (Canton-native) — non-binding LOI committed 2026-04-28; definitive agreement pending
Securities distribution structureReg D 506(b) / Reg S
Stablecoin regulatory frameworkdesigned for GENIUS Act alignment by architecture (mUSD non-yield-bearing; smUSD structurally separate)
Legal counselWallace Glausi (General Counsel, securities law specialist)
Regulatory advisorBob Feil (Chief Advisor; former VP, Federal Reserve Bank of Dallas, ~40-year Fed career)

Public artifacts