diff --git a/CHANGELOG.md b/CHANGELOG.md index 09f86d8..77c34cd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,9 @@ All notable changes to the EthSystems Map are documented here. ## [Unreleased] +- fix(approach): [Private Money Market Funds](approaches/approach-private-money-market-funds.md): Phase 1 review for the MMF approach cycle. Stable- vs floating-NAV yield, aggregates at the fund's cadence, disclosure-key custody instead of threshold NAV opening, investor-side vs portfolio compliance, maturity corrected to `documented`, three new comparison rows, a conditional recommendation, and new open questions (collateral as a future extension). Links: `private-vaults` removed; `erc3643-rwa` and `private-mtp-auth` added. +- fix(use-case): [Private Money Market Funds](use-cases/private-money-market-funds.md): fills Additional Context, scopes Rule 2a-7 to registered funds, updates gates after the 2023 amendments, cross-links open questions to the approach card, and lists it in the [Funds & Assets](domains/funds-assets.md) domain. +- chore(pattern): re-review [Private Client Authentication for Institutional EOAs](patterns/pattern-private-mtp-auth.md) and [Compliance Monitoring](patterns/pattern-compliance-monitoring.md); no content change. - feat(pattern): [Selective Disclosure](patterns/pattern-regulatory-disclosure-keys-proofs.md) adds standing register disclosure, a second mode in which a register of record (such as a transfer agent) receives a continuous encrypted feed and rebuilds beneficial ownership for any point in time without holder cooperation. It covers the key, protocol steps, the in-circuit ciphertext constraint and the added threat-model entries, and flags feed granularity as an open trade-off. - feat(pattern): [ERC-3643 Tokenized RWAs](patterns/pattern-erc3643-rwa.md) adds a confidentiality-boundary section: the policy layer (claim topics, trusted issuers, ONCHAINID claims) is reusable, and the execution layer (`balanceOf`, `identity`, `isVerified`, `canTransfer`) is replaced. - chore(pattern): re-review [Shielding](patterns/pattern-shielding.md), [Private Shared State (FHE)](patterns/pattern-private-shared-state-fhe.md) and [TEE Key Manager](patterns/pattern-tee-key-manager.md) against the Private Money Market Funds approach; no content change. diff --git a/approaches/approach-private-money-market-funds.md b/approaches/approach-private-money-market-funds.md index 167a46a..ac9575c 100644 --- a/approaches/approach-private-money-market-funds.md +++ b/approaches/approach-private-money-market-funds.md @@ -1,26 +1,33 @@ --- title: "Approach: Private Money Market Funds" status: ready -last_reviewed: 2026-06-24 +last_reviewed: 2026-09-30 use_case: private-money-market-funds -related_use_cases: [private-stablecoins, private-treasuries, private-rwa-tokenization] +related_use_cases: [private-stablecoins, private-treasuries, private-rwa-tokenization, private-repo] primary_patterns: - pattern-shielding - pattern-regulatory-disclosure-keys-proofs supporting_patterns: - - pattern-private-vaults - pattern-compliance-monitoring - pattern-verifiable-attestation + - pattern-erc3643-rwa + - pattern-private-mtp-auth - pattern-private-shared-state-fhe - pattern-tee-based-privacy - pattern-tee-key-manager open_source_implementations: + - url: https://github.com/ethsystems/pocs/tree/master/pocs/private-payment/shielded-pool-compliance + description: "EthSystems PoC: KYC-gated shielded pool with in-circuit compliance" + language: "Noir, Solidity, Rust" - url: https://github.com/Railgun-Privacy/contract description: "Railgun shielded pool" language: Solidity + - url: https://github.com/OpenZeppelin/openzeppelin-confidential-contracts + description: "OpenZeppelin confidential contracts: ERC-7984 tokens on Zama's FHE" + language: Solidity --- # Approach: Private Money Market Funds @@ -29,72 +36,76 @@ open_source_implementations: ### Scenario -A treasurer subscribes USD 50M USDC to a tokenized T-bill money market fund. Position size, redemption timing, and yield attribution must be hidden from competitors and other fund participants. Fund NAV must be publicly verifiable on a daily or intraday cadence and must remain verifiable even if the fund operator goes offline; redemptions must continue without interruption under stress. +A treasurer subscribes USD 50M USDC to a tokenized T-bill money market fund. Position size, redemption timing, and yield attribution must be hidden from competitors and other fund participants. Fund NAV and total shares outstanding stay public at the fund's publication cadence; redemptions must continue without interruption under stress. Tokenized MMFs on Ethereum today mostly keep a stable USD 1 NAV and pay yield as new shares; floating-NAV funds pay it through the share price instead. ### Requirements -- Daily or intraday NAV computation with verifiable correctness -- SEC Rule 2a-7 (US) and ESMA MMFR (EU) compliance: gates, liquidity fees, concentration limits -- Atomic subscription and redemption settlement (no partial fills) +- Daily or intraday NAV computation with verifiable correctness (total shares outstanding stays public) +- Aggregate figures are published at the fund's cadence, not per transaction, so totals don't reveal individual flows +- SEC Rule 2a-7 (US) and ESMA MMFR (EU) compliance: liquidity fees, concentration limits, and MMFR liquidity gates. Private funds instead follow offering requirements such as investor eligibility and investor-count limits. +- Atomic subscription and redemption settlement (no partial fills: shares and cash move together or not at all). Where the cash leg settles off-chain, the transfer agent reconciles. - Yield attribution provably correct per investor without revealing positions -- Operator-independent solvency: NAV verifiable by a threshold subset, not the operator +- The transfer agent can rebuild the full register of record for any point in time (eligibility, holder counts, sanctions screening, tax) without holder cooperation +- Per-holder choice: confidential by default, with opt-out for holders that must stay public +- Eligibility (KYC, accreditation, jurisdiction) is proven without a public wallet-to-investor mapping ### Constraints -- Threshold opening (t-of-n) by independent custodians or auditors must be administratively feasible +- Custody of disclosure keys must be administratively feasible for the transfer agent and regulators - Periodic full-audit checkpoints must run off the critical path of subscription/redemption - Fund-circuit hash registered immutably at deployment; circuit upgrades imply migration -- Compliance gates (Rule 2a-7 liquidity ratio, concentration limits) must be enforceable without revealing individual positions +- No personal data on-chain, even encrypted, because data-protection rules such as GDPR conflict with an immutable ledger: the register feed carries pseudonymous investor IDs, and personal data stays off-chain with the transfer agent +- Compliance gates (Rule 2a-7 liquidity ratio, concentration limits) must be enforceable without revealing individual positions. These portfolio rules apply to the fund's assets, so investor privacy doesn't affect them; investor-side rules such as liquidity fees depend only on aggregate flows. ## Approaches ### ZK Shielded Commitments ```yaml -maturity: prototyped +maturity: documented context: i2i crops: { cr: high, o: yes, p: full, s: high } -uses_patterns: [pattern-shielding, pattern-regulatory-disclosure-keys-proofs, pattern-verifiable-attestation, pattern-compliance-monitoring] +uses_patterns: [pattern-shielding, pattern-regulatory-disclosure-keys-proofs, pattern-verifiable-attestation, pattern-compliance-monitoring, pattern-erc3643-rwa, pattern-private-mtp-auth] example_vendors: [paladin, railgun, privacypools] ``` -**Summary:** Share positions are shielded UTXO commitments; a running `total_shares` commitment is updated per transaction; NAV opens via threshold key holders independent of the operator. +**Summary:** Share positions are shielded UTXO commitments; a running `total_shares` commitment is updated per transaction; the running total is opened at the fund's publication cadence by the transfer agent, and anyone can check the opening against the on-chain commitment. -**How it works:** Each position is a commitment to (attestation hash, share count, entry NAV). Subscription mints a position commitment and increments a running Pedersen commitment to `total_shares`; redemption nullifies the position and decrements the running total. ZK circuits enforce conservation, gate logic (Rule 2a-7 liquidity ratio, concentration), and yield-attribution constraints. NAV is computed by any t-of-n threshold key holders opening `total_shares` and multiplying by an oracle price-per-share; a periodic full-audit checkpoint verifies the running total against all active positions, off the redemption critical path. +**How it works:** Each position is a commitment to (attestation hash, share count, and entry NAV for floating-NAV funds). Subscription mints a position commitment and increments a running Pedersen commitment to `total_shares`; redemption nullifies the position and decrements the running total. ZK circuits enforce conservation, gate logic (investor-side: eligibility, jurisdiction caps, investor counters; the Rule 2a-7 liquidity ratio and concentration limits are portfolio rules, enforced outside the pool), and yield-attribution constraints. At the fund's publication cadence, the transfer agent, which receives each transaction's opening through the register feed, opens `total_shares` and publishes the total, which anyone can check against the on-chain commitment; the fund publishes NAV per share; a periodic full-audit checkpoint verifies the running total against all active positions, off the redemption critical path. **Trust assumptions:** - L1 / L2 consensus and verifier contract correctness -- Threshold custodian / auditor set (t-of-n) for NAV opening; operator does not participate in the threshold -- Oracle integrity for per-share price (single oracle or quorum) +- Transfer agent for opening and publishing the running total (it already holds the full register); the register key can be threshold-held with independent co-holders +- Oracle integrity for per-share price (floating-NAV funds; single oracle or quorum) **Threat model:** - Adversary observes L1 / L2; cannot break ZK soundness -- Threshold compromise (t collusions) reveals NAV but not individual positions -- Oracle compromise distorts NAV; mitigated by quorum +- Register-key compromise reveals positions to the attacker; the published total reveals only aggregates at the fund's cadence +- Oracle compromise distorts NAV (floating-NAV funds); mitigated by quorum - Periodic full-audit catches running-total drift from circuit bugs **Works best when:** -- Operator independence is a hard requirement (regulator, donor policy, internal governance) +- Investor positions must be hidden from the public while the transfer agent keeps the full register - Daily or intraday NAV cadence matches the proving budget -- Threshold custodian / auditor administration is feasible +- Disclosure-key custody (register key, regulator viewing keys) is administratively feasible **Avoid when:** - Yield logic is complex enough that circuit complexity exceeds practical bounds -- Threshold administration overhead (key rotation, custodian onboarding) is unacceptable +- The confidential set is small and concentrated, so unlinkability gains are limited -**Implementation notes:** PoC uses Railgun-class shielded pool primitives. Compliance gates encoded as ZK public outputs (e.g., post-redemption weekly liquid assets ≥ 50%, the SEC Rule 2a-7 minimum since the 2023 amendments); regulator scope via per-position view keys logged through EAS. Yield attribution uses pro-rata share-of-total computation: each redeemer proves `my_shares / total_shares * total_yield = entitled_amount`. +**Implementation notes:** The PoC uses the shielded pool in [2/SHIELDED-POOL](https://specs.ethsystems.org/2/) with attestation-gated entry ([3/ATTESTED-POOL](https://specs.ethsystems.org/3/)), as implemented in EthSystems' [shielded-pool-compliance](https://github.com/ethsystems/pocs/tree/master/pocs/private-payment/shielded-pool-compliance): KYC-gated entry, attestation expiry, circuit-level compliance checks, and an encrypted audit channel. The MMF variant adds investor positions, yield distribution, investor counters, ZK compliance outputs, per-position regulator view keys, and yield as new shares (a periodic mint or a multiplier; pro-rata attribution applies only to floating-NAV funds), with fund-level portfolio rules measured outside the pool. ### FHE Encrypted Balances ```yaml -maturity: prototyped +maturity: documented context: i2i crops: { cr: medium, o: partial, p: partial, s: medium } -uses_patterns: [pattern-private-shared-state-fhe, pattern-compliance-monitoring] +uses_patterns: [pattern-private-shared-state-fhe, pattern-compliance-monitoring, pattern-erc3643-rwa] example_vendors: [zama, fhenix, orion-finance] ``` -**Summary:** Balances are FHE ciphertexts on an FHE-enabled L2; NAV is computed homomorphically; threshold key holders decrypt for publication. +**Summary:** Balances are FHE ciphertexts handled by an FHE network over the host chain (for example, Zama on Ethereum mainnet); NAV is computed homomorphically; threshold key holders decrypt for publication. **How it works:** Subscriptions encrypt the share count under the FHE network's keys; balances are stored as ciphertexts with ACL-based read access. NAV is computed under encryption (sum of ciphertexts × per-share price); a t-of-n threshold network decrypts the result for posting on chain. Yield attribution runs as homomorphic arithmetic; gate logic uses encrypted comparisons. @@ -109,6 +120,7 @@ example_vendors: [zama, fhenix, orion-finance] - Shared throughput across all FHE applications on the network is a bottleneck **Works best when:** +- Existing integrators and contract holders must keep operating on balances (account model), and amount-only confidentiality is acceptable - Yield logic is complex (path-dependent strategies) and benefits from homomorphic arithmetic - Per-balance ACL granularity matches the disclosure model - Threshold-network trust is acceptable to all custodians @@ -120,11 +132,11 @@ example_vendors: [zama, fhenix, orion-finance] ### TEE Enclave ```yaml -maturity: prototyped +maturity: documented context: i2i crops: { cr: medium, o: no, p: full, s: low } uses_patterns: [pattern-tee-based-privacy, pattern-tee-key-manager, pattern-compliance-monitoring] -example_vendors: [] +example_vendors: [inco, iexec] ``` **Summary:** Positions sealed inside a TEE enclave; NAV computed in the clear internally; remote-attested results posted on chain. @@ -154,51 +166,61 @@ example_vendors: [] | Axis | ZK Shielded Commitments | FHE Encrypted Balances | TEE Enclave | |---|---|---|---| -| **Maturity** | prototyped | prototyped | prototyped | +| **Maturity** | documented | documented | documented | | **Context** | i2i | i2i | i2i | | **CROPS** | CR:hi O:y P:full S:hi | CR:med O:part P:part S:med | CR:med O:no P:full S:lo | -| **Trust model** | Math + threshold (t-of-n) for NAV opening | Threshold (t-of-n) decryption | Hardware vendor + supply chain | -| **Privacy scope** | Amounts + addresses | Amounts only; addresses public | Amounts + addresses (inside enclave) | +| **Trust model** | Math + transfer agent for publishing aggregates | Threshold (t-of-n) decryption | Hardware vendor + supply chain | +| **Privacy scope** | Amounts + addresses (bounded by anonymity set) | Amounts only; addresses public | Amounts + addresses (inside enclave) | | **Performance** | Constant per tx; periodic full-audit scales with positions | Heaviest compute; shared throughput | Cheapest; near-instant | -| **Operator req.** | None (relayer optional) | Yes (threshold network) | Yes (enclave host) | +| **Operator req.** | None beyond the transfer agent (relayer optional) | Yes, beyond the transfer agent (threshold network) | Yes, beyond the transfer agent (enclave host) | +| **Interop with integrators and contract holders** | Low: replaces the token's execution layer, and contracts can't hold note secrets | Medium: address-based, and contracts can hold and move encrypted balances | Medium: through the enclave's attested interface | | **Cost class** | Medium-high | Medium | Low | +| **Yield distribution cost** | Per position per period (mint), or one update (multiplier) | Per balance per period (homomorphic add), or multiplier | Low: computed inside the enclave | | **Regulatory fit** | Strong (per-position view keys, EAS-logged) | Strong (per-balance ACL, no revocation) | Conditional (vendor attestation) | -| **Failure modes** | Threshold compromise; circuit bugs; oracle compromise | Threshold compromise; no revocation; throughput | Side-channel; vendor compromise; enclave outage | +| **Failure modes** | Register-key compromise; circuit bugs; oracle compromise (floating-NAV funds) | Threshold compromise; no revocation; throughput | Side-channel; vendor compromise; enclave outage | ## Persona perspectives ### Business perspective -For a yield-bearing tokenized treasury product where operator-independent NAV verification is the load-bearing property, ZK Shielded Commitments is the default: positions and redemptions are private, the running-total commitment is opened by a threshold subset of custodians and auditors who do not include the operator, and the fund continues to function under operator outage. FHE suits funds with complex yield logic (multi-strategy MMFs, dynamic allocation) where homomorphic arithmetic removes circuit-design overhead; the trade-off is reliance on the FHE network for both decryption and throughput. TEE is a viable PoC starting point and a near-term production option for funds whose custodians already accept hardware-rooted trust. +For a yield-bearing tokenized treasury product where confidential investor positions and a complete transfer-agent register are the load-bearing properties, ZK Shielded Commitments is the default: positions and redemptions are private, and aggregates are published at the fund's cadence rather than per transaction. FHE suits funds whose existing integrators and contract holders must keep operating on balances, since its account model keeps addresses and hides amounts only; the trade-off is reliance on the FHE network for both decryption and throughput. TEE is a viable PoC starting point and a near-term production option for funds whose custodians already accept hardware-rooted trust. ### Technical perspective -The dominant engineering question is the NAV-proof model. ZK with a running `total_shares` commitment keeps per-transaction proving constant and pushes full-audit cost off the critical path; circuit complexity for gate enforcement and yield attribution is the ceiling. FHE simplifies the programming model but inherits shared-throughput limits and per-ciphertext revocation gaps. TEE eliminates both proving cost and revocation issues but introduces a hardware trust chain and side-channel surface that auditors must accept. Threshold custody administration (key rotation, custodian onboarding, t parameter selection) is non-trivial across all three. +The dominant engineering questions are yield distribution into hidden positions and the size of the anonymity set. ZK with a running `total_shares` commitment keeps per-transaction proving constant and pushes full-audit cost off the critical path; circuit complexity for gate enforcement and yield attribution is the ceiling. FHE simplifies the programming model but inherits shared-throughput limits and per-ciphertext revocation gaps. TEE eliminates both proving cost and revocation issues but introduces a hardware trust chain and side-channel surface that auditors must accept. Threshold custody administration (key rotation, custodian onboarding, threshold parameter selection) is non-trivial across all three. ### Legal & risk perspective -This is a perspective for legal review by the deploying fund operator, not legal advice. The three options expose distinct evidence patterns: ZK Shielded Commitments via per-position view keys plus ZK public outputs proving gate compliance (liquidity ratio, concentration) without revealing positions, with EAS-logged disclosures as the trail; FHE via per-balance ACL granularity with no per-ciphertext revocation (revocation depends on subsequent balance updates triggering re-grants, or the disclosure model has to rely on append-only audit logs); TEE via enclave-mediated disclosure that depends on enclave-code reproducibility, multi-party signing, and the vendor governance model. Whether any of these patterns satisfies SEC Rule 2a-7 or ESMA MMFR auditor expectations is a question for jurisdictional review. Threshold custodian composition (independence from the operator, jurisdictional diversity) is a structural-risk parameter that legal review would weigh in any of the three. +This is a perspective for legal review by the deploying fund operator, not legal advice. The three options expose distinct evidence patterns: ZK Shielded Commitments via per-position view keys plus ZK public outputs proving investor-side gate compliance (eligibility, jurisdiction caps; portfolio rules are measured on the fund's assets) without revealing positions, with EAS-logged disclosures as the trail; FHE via per-balance ACL granularity with no per-ciphertext revocation (revocation depends on subsequent balance updates triggering re-grants, or the disclosure model has to rely on append-only audit logs); TEE via enclave-mediated disclosure that depends on enclave-code reproducibility, multi-party signing, and the vendor governance model. Whether any of these patterns satisfies SEC Rule 2a-7 or ESMA MMFR auditor expectations is a question for jurisdictional review. Custody of disclosure keys (the transfer agent's register key, regulator viewing keys; independence and jurisdictional diversity where threshold-held) is a structural-risk parameter that legal review would weigh in any of the three. ## Recommendation ### Default -For institutional-grade private money market funds where operator-independent NAV is required, default to ZK Shielded Commitments with a Pedersen running-total opened by a t-of-n threshold of custodians and auditors who do not include the fund operator. Periodic full-audit checkpoints run off the redemption critical path. Selective disclosure runs through per-position view keys logged via EAS; gate compliance is encoded as ZK public outputs. +For institutional-grade private money market funds, default to ZK Shielded Commitments, with privacy by default and opt-out for holders that must stay public (reserve holders, autonomous contracts). Publish aggregates at the fund's cadence rather than per transaction, and give the transfer agent a standing register feed. Unlinkability is bounded by the confidential set: in a single-fund pool with concentrated holders it is limited, and a pool shared across funds or with the cash leg widens it. Periodic full-audit checkpoints run off the redemption critical path. Selective disclosure runs through per-position view keys logged via EAS; investor-side gate compliance is encoded as ZK public outputs. Choose FHE Encrypted Balances when existing integrators and contract holders must keep operating on balances and amount-only confidentiality is acceptable. ### Decision factors -- If yield logic is complex (multi-strategy, path-dependent) and per-balance ACL granularity is required, choose FHE Encrypted Balances. +- If existing integrators and contract holders must keep operating on balances, or per-balance ACL granularity is required, and amount-only confidentiality is acceptable, choose FHE Encrypted Balances. - If near-term deployment is required and custodians already accept hardware-rooted trust, choose TEE Enclave as a PoC or transitional path. -- If operator independence cannot be administered through threshold custody, none of the three approaches removes the trust assumption, re-scope the requirement. +- If the confidential set stays small and concentrated (single fund, few large holders), none of the three approaches delivers meaningful unlinkability; widen the set (shared pool, cash leg) or re-scope to amount confidentiality. ### Hybrid -Run primary NAV through ZK Shielded Commitments; use TEE for high-frequency intraday yield strategies that exceed practical proving budgets, with the TEE output committed back into the ZK running total at the next checkpoint. FHE handles complex strategy attribution where the dominant operation is homomorphic arithmetic. Compliance gating runs uniformly through the regulator-disclosure-keys pattern across all rails. +Hold confidential positions in ZK Shielded Commitments and keep opted-out holders on the public token, with conservation spanning both. Use TEE to compute per-period yield distribution across hidden positions when it exceeds practical proving budgets, with the TEE output committed back into the ZK state at the next checkpoint. FHE Encrypted Balances serve integrator and contract-holder positions that must stay operable where amount-only confidentiality is acceptable. Compliance gating runs uniformly through the regulator-disclosure-keys pattern across all rails. ## Open questions -1. **Yield-cohort attribution.** Balancing fungible-share privacy against the complexity of attributing yield across different entry-NAV cohorts; pro-rata is the working assumption but other models may better serve specific products. +1. **Yield-cohort attribution (floating-NAV funds).** Balancing fungible-share privacy against the complexity of attributing yield across different entry-NAV cohorts; pro-rata is the working assumption but other models may better serve specific products. Stable-NAV funds avoid cohorts by paying yield as new shares. 2. **Peer-to-peer share trading.** Shielded MMF shares traded peer-to-peer with privately enforced NAV-based pricing; integration with shielded DvP is unresolved. 3. **Mixed-currency underlying.** Hiding currency exposure when the underlying basket spans multiple currencies; oracle and ACL design are unresolved. 4. **MMF-as-cash-equivalent.** Whether shielded MMF shares can serve as the cash leg in DvP for other instruments. - +5. **Anonymity-set source.** Single fund, pool shared across funds, or shared with the cash leg, and how per-fund rules are enforced in a shared pool. +6. **Account vs note.** Amount-only confidentiality with interop, vs unlinkability with a replaced execution layer. +7. **Participation.** Privacy by default with opt-out; what each public ↔ confidential crossing leaks; a minimum confidential-set size. +8. **Transfer-agent visibility.** The minimum the register feed must carry (ownership vs flows), and constraining the ciphertext in-circuit. +9. **Yield into hidden positions.** Periodic mint vs multiplier, and whether a multiplier counts as reinvestment for reporting and tax. +10. **Custody.** Multisigs, smart accounts and contract holders; client-side vs delegated proving. +11. **Migration from deployed tokens.** In-place upgrade vs reissuance, and interop cost per integrator. Several deployed tokenized MMFs run Securitize's DS Protocol, with two generations in production (omnibus removed in the newer one); in-place upgrades must fit each generation's storage layout. Locking the deployed token and mirroring positions on a confidential ledger ([origin-locked pattern](../patterns/pattern-origin-locked-confidential-ledger.md)) makes the lock contract a nominee holder: investor counters go wrong, or the reporting that fixes them is public. +12. **Liveness under stress.** The holder's path to cash when an operator or cash venue is unavailable. +13. **Collateral (future extension).** Locking a hidden position in favour of a lender, the lender's claim on default without the borrower's secret, a confidential cash leg, and keeping the register of record accurate while shares sit in a lending pool. \ No newline at end of file diff --git a/domains/funds-assets.md b/domains/funds-assets.md index fde67d2..01b4352 100644 --- a/domains/funds-assets.md +++ b/domains/funds-assets.md @@ -13,6 +13,7 @@ description: "Hold and transfer claims with hidden positions and verifiable audi ## Primary use cases - [Private Bonds](../use-cases/private-bonds.md) +- [Private Money Market Funds](../use-cases/private-money-market-funds.md) - [Private RWA Tokenization](../use-cases/private-rwa-tokenization.md) - [Private Smart Derivatives (ERC-6123)](../use-cases/private-derivatives.md) diff --git a/patterns/pattern-compliance-monitoring.md b/patterns/pattern-compliance-monitoring.md index 1df72ba..b7aec12 100644 --- a/patterns/pattern-compliance-monitoring.md +++ b/patterns/pattern-compliance-monitoring.md @@ -4,7 +4,7 @@ status: ready maturity: concept type: standard layer: hybrid -last_reviewed: 2026-06-18 +last_reviewed: 2026-09-30 works-best-when: - Institution must monitor transactions for AML or sanctions compliance. diff --git a/patterns/pattern-private-mtp-auth.md b/patterns/pattern-private-mtp-auth.md index 756cce8..a2cf78b 100644 --- a/patterns/pattern-private-mtp-auth.md +++ b/patterns/pattern-private-mtp-auth.md @@ -4,7 +4,7 @@ status: ready maturity: testnet type: standard layer: hybrid -last_reviewed: 2026-06-18 +last_reviewed: 2026-09-30 works-best-when: - Institutions must comply with KYC/AML but want to protect client privacy on-chain. diff --git a/use-cases/private-money-market-funds.md b/use-cases/private-money-market-funds.md index ddb1805..26f6602 100644 --- a/use-cases/private-money-market-funds.md +++ b/use-cases/private-money-market-funds.md @@ -11,6 +11,11 @@ Tokenized money market funds providing yield-bearing treasury management for ins ## 2) Additional Context +- **Holders differ in what they want disclosed.** Reserve holders (for example, stablecoin issuers backing their token) publish positions on purpose; trading firms want the opposite. Confidentiality needs a per-holder choice. +- **The transfer agent keeps the register of record** and must be able to rebuild it in full: eligibility, holder counts, sanctions screening, tax. +- **Most tokenized MMFs on Ethereum today keep a stable USD 1 NAV** and pay yield as new shares; floating-NAV funds pay it through the share price. +- **Collateral use is the likely next step.** Tokenized MMF shares already serve as collateral and as stablecoin reserves in the clear. Using them as collateral confidentially is a future extension (see [Private Repo](private-repo.md) and the approach card's open question 13). + ## 3) Actors Asset Managers · Institutional Investors · Banks · Custodians · Regulators · NAV Calculation Agents @@ -30,7 +35,7 @@ Large MMF positions reveal treasury management strategies and cash reserves. Com **Constraints:** - Daily NAV calculations -- SEC Rule 2a-7 compliance (for US funds) +- SEC Rule 2a-7 compliance (for registered US funds); offering rules such as eligibility and investor-count limits for private funds - Liquidity requirements for redemptions ### Problem 2: Redemption Pattern Privacy @@ -46,7 +51,7 @@ Redemption patterns signal liquidity needs or market views. Large redemptions ca **Constraints:** - Same-day or T+1 redemption requirements -- Gate and fee provisions +- Fee provisions, and gates where the regime has them (ESMA MMFR; removed from Rule 2a-7 in 2023) - Systemic risk monitoring obligations ## 5) Recommended Approaches @@ -59,9 +64,9 @@ See detailed solution architecture and trade-offs in [**Approach: Private Money ## 6) Open Questions -- How does yield attribution work with position privacy? -- What's the relationship to stablecoin privacy patterns? -- How to handle fund gates/fees with position privacy? +- How is yield attributed across entry-NAV cohorts in floating-NAV funds without revealing positions? +- Can the confidential set be shared with stablecoins used as the cash leg, and how are per-asset rules enforced then? +- What does each crossing between public and confidential holdings leak, and how large must the confidential set be? ## 7) Notes And Links