SSS DeFiβ2.0
Open App
Security updateJuly 28 incident · dialogue and asset recovery noticeView notice →
Target previewThe information architecture is near-final; production evidence remains rolling while the main system continues to evolve.
SSS · TRUST CENTER

Trust should be inspectable, not implied.

This surface brings together SSS claims, system components, funding routes, authority boundaries, release evidence, risks, incidents, and governance. Unknown, stale, or unverified information stays visible as such.

16Production canistersconfigured ID baseline
21Funding routes7 Canonical Assets
13Canonical claims10 currently expressible
1Financial coresingle-authority requirement
16Registered risks12 high severity
System boundaries

One system, bounded planes, one financial judge.

The Trust Center is not a new business authority. It explains who owns each responsibility and what each plane must never do.

01

User intent

WWW

Expresses actions; never judges financial success.

02

Financial kernel

Core

Balances, reservations, trades, liquidity, and final receipts.

03

External execution

Asset Hub + Gateways

Routes, signing, broadcast, and finality evidence.

04

Read & evidence

Data API + Portal

Rebuildable views and public evidence; never rewrites finance.

PUBLIC CANISTER REGISTRY

Production components and public IDs

IDs are the stable baseline. Module hashes, controllers, and observation times are rolling evidence and remain Pending until collected.

Registry available; public-chain observation pending.This does not imply a canister outage or controller anomaly.
ComponentCanister IDAuthorityEvidence
CoreCanonical internal balances, reservations, trades, orders, liquidity, fees, and authoritative financial receipts.dlhkk-raaaa-…yl5a-caiFINANCIAL COREObservation pendingModule Hash / Controllers
WWWApplication frontend and user interaction surface.dmgm6-4yaaa-…yl5q-caiUSER INTERACTIONObservation pendingModule Hash / Controllers
PortalBrand and public positioning surface.bpfil-eiaaa-…lkrq-caiCONTENTObservation pendingModule Hash / Controllers
DocsTechnical and product documentation surface.rmlok-daaaa-…lrea-caiCONTENTObservation pendingModule Hash / Controllers
Data APIRebuildable market, history, reporting, daily-close, and public-safe projections.xobtb-pyaaa-…lrsq-caiDATA PROJECTIONObservation pendingModule Hash / Controllers
Agent GatewayIntent interpretation, draft, preview, confirmation, callback, and nonfinancial orchestration.yq5eu-qqaaa-…zaga-caiAGENT INTENTObservation pendingModule Hash / Controllers
Dataroom / GrowthContribution records, Growth programs, and nonfinancial operational records.5jtld-gaaaa-…eekq-caiNONFINANCIAL PROGRAMObservation pendingModule Hash / Controllers
Asset HubAsset-route registry, external funding evidence, route coordination, and supported external execution state.7uamq-xiaaa-…grha-caiEXTERNAL EXECUTIONObservation pendingModule Hash / Controllers
EVM GatewayEVM signing, broadcast, submission journal, finality observation, and bounded recovery.7tbke-2qaaa-…grhq-caiEXTERNAL EXECUTIONObservation pendingModule Hash / Controllers
Solana GatewaySolana evidence, signing, broadcast, finality observation, and bounded recovery.za2zu-caaaa-…gwpa-caiEXTERNAL EXECUTIONObservation pendingModule Hash / Controllers
ETH Bridge LedgerDefined Ethereum-side bridge or route ledger support; exact authority requires production review.5o4em-jyaaa-…gria-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
BNB Bridge LedgerBNB-route bridge-ledger support.zoyu4-zqaaa-…gwoa-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
BTC Bridge LedgerBTC-route bridge-ledger support.43aff-eqaaa-…gwqa-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
SOL Bridge LedgerSolana-route bridge-ledger support.zjzsi-uiaaa-…gwoq-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
USDC Bridge LedgerProduction USDC bridge-ledger support across configured routes.5j5cy-eaaaa-…griq-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
USDT Bridge LedgerProduction USDT bridge-ledger support across configured routes.5a6je-siaaa-…grja-caiFINANCIAL SUPPORTObservation pendingModule Hash / Controllers
FUNDING ROUTES

Configured does not mean currently healthy.

The current preview exposes the stable route catalog. Fees, finality, gateway health, canary, reconciliation, and freshness will be attached as rolling evidence.

21Configured routeslive evidence pending
7Canonical AssetsICP · BTC · ETH · BNB · SOL · USDC · USDT

EVM · Arbitrum

3
arbitrum:ethETH → ETH
Evidence pending
arbitrum:usdcUSDC → USDC
Evidence pending
arbitrum:usdtUSDT → USDT
Evidence pending

EVM · Base

3
base:ethETH → ETH
Evidence pending
base:usdcUSDC → USDC
Evidence pending
base:usdtUSDT → USDT
Evidence pending

EVM · BNB Smart Chain

4
bsc:bnbBNB → BNB
Evidence pending
bsc:btcBTC → BTC
Evidence pending
bsc:usdcUSDC → USDC
Evidence pending
bsc:usdtUSDT → USDT
Evidence pending

EVM · Ethereum Mainnet

3
ethereum:ethETH → ETH
Evidence pending
ethereum:usdcUSDC → USDC
Evidence pending
ethereum:usdtUSDT → USDT
Evidence pending

ICP_ICRC · ICP

5
icp:ckbtcCKBTC → BTC
Evidence pending
icp:ckethCKETH → ETH
Evidence pending
icp:ckusdcCKUSDC → USDC
Evidence pending
icp:ckusdtCKUSDT → USDT
Evidence pending
icp:icpICP → ICP
Evidence pending

SOLANA · Solana Mainnet

3
solana-mainnet:solSOL → SOL
Evidence pending
solana-mainnet:usdcUSDC → USDC
Evidence pending
solana-mainnet:usdtUSDT → USDT
Evidence pending
CLAIM REGISTRY

Every public promise has an ID, status, and boundary.

LIVE, BETA, PARTIAL, TARGET, and RESEARCH are not interchangeable. Missing evidence can only downgrade a claim, never strengthen it.

CLAIM-PRIVATE-001PARTIAL

Private Trading System for the AI Era

SSS is building a Private Trading System for the AI Era.

BoundaryPublic Beta provides an application-level private-account foundation; public-detail, administrator, telemetry, support, governance, and cryptographic-privacy gaps remain.
TARGET2 Evidence
CLAIM-EXPERIENCE-002BETA

CEX Experience

SSS is pursuing a CEX-style account experience with DEX trust boundaries.

BoundaryThe phrase describes product architecture and does not claim parity with leading centralized exchanges in liquidity, market breadth, institutional tooling, or service capacity.
LIVE1 Evidence
CLAIM-TRUST-003PARTIAL

DEX Trust

DEX Trust means explicit financial authority, inspectable rules, production verification, visible dependencies, and governed upgrades.

BoundaryReproducibility, controller minimization, and SNS governance remain incomplete targets.
LIVE2 Evidence
CLAIM-CROSSCHAIN-004BETA

Supported multichain funding

SSS supports published, allowlisted multichain funding routes.

BoundaryDeposits and withdrawals remain subject to chain, token, gateway, RPC, fee, evidence, and finality conditions.
LIVE2 Evidence
CLAIM-SETTLEMENT-005LIVE

Internal onchain settlement

Internal financial outcomes settle on ICP canisters.

BoundaryExternal deposits and withdrawals remain outside the internal-settlement scope until their evidence and finality conditions are accepted.
LIVE2 Evidence
CLAIM-GASLESS-006LIVE

Gas-token abstraction for internal actions

Users do not need to prepare a gas token for every internal SSS trade or liquidity action.

BoundaryThe user-facing gas-token requirement is abstracted for internal actions; economic and external-chain costs may still apply.
LIVE1 Evidence
CLAIM-BALANCE-007BETA

Canonical Balance

Supported funding routes feed canonical balances.

BoundaryCanonical balance is the internal financial identity used by trading, orders, liquidity, history, receipts, and permissions; route provenance and external risk remain.
LIVE2 Evidence
CLAIM-VERIFY-008PARTIAL

Privacy-preserving verification

SSS has foundations for separating public market information from owner records.

BoundaryComplete selective disclosure, institution viewer roles, operator restriction, and cryptographic verification remain target or research capabilities.
LIVE1 Evidence
CLAIM-AGENT-009BETA

Permissioned AI-agent intents

The Agent may interpret and prepare supported actions.

BoundaryThe Financial Core independently verifies permissions, balances, limits, and final financial state; the Agent has no independent financial authority.
LIVE1 Evidence
CLAIM-THESIS-010LIVE

You should trade crypto on a blockchain.

You should trade crypto on a blockchain.

BoundaryThis is a product and market thesis, not an investment, security, or universal protocol guarantee.
LIVE1 Evidence
CLAIM-INSTITUTION-011TARGET

Private Trading for Institutions

SSS is designing Private Trading for Institutions.

BoundaryCurrent foundations support account, settlement, receipts, funding, and scoped Agent work; the complete institution product is not live.
LIVE1 Evidence
CLAIM-GOVERNANCE-012TARGET

SNS governance

SNS-governed financial and privacy rules are a target architecture.

BoundarySSS remains in a pre-SNS team/controller phase; launch depends on product, privacy, reproducibility, operational, governance, and distribution readiness.
LIVE1 Evidence
CLAIM-CRYPTO-013RESEARCH

Cryptographic confidentiality

SSS is researching cryptographic confidentiality.

BoundaryResearch does not represent a current product capability or fixed delivery commitment.
TARGET1 Evidence
RELEASE EVIDENCE

Observe facts during iteration; attest versions at release.

The main development line is still moving, so this page does not present an interim commit as the final production release. Full source, Wasm, and deployed-module binding happens at an explicit release point.

1
READY

Source-controlled registries and evidence contracts

2
PENDING

Anonymous module-hash and controller observation

3
DEFERRED

Local Wasm and production module-hash comparison

4
DEFERRED

Release attestation and reproducible-build evidence

RISK REGISTER

A public risk register is a trust surface.

This view exposes structural risks, current controls, and target controls. A risk remains OPEN until closure evidence exists.

RISK-CONTROLLER-001
HIGHOPEN

Pre-SNS controller authority

Critical canisters remain upgradeable by current controllers before the SNS transition.

Current controls
  • explicit production identities
  • manual release review
  • source and deployment records
Target controls
  • public controller manifests
  • reproducible builds
  • proposal-based upgrades
governancePENDING PRODUCTION REVIEW
RISK-REPRO-002
HIGHOPEN

Incomplete reproducible production builds

Published source is not yet independently linked to every deployed critical Wasm.

Current controls
  • source-controlled release records
Target controls
  • pinned build environment
  • deterministic builds
  • public build manifests
releasePENDING PRODUCTION REVIEW
RISK-PRIVACY-PUBLIC-003
HIGHOPEN

Remaining public-detail privacy gaps

Some public transaction-detail or recent-trade paths may expose exact or fingerprintable information.

Current controls
  • owner-oriented major read paths
  • existing source audits
Target controls
  • owner scoping
  • public aggregate contract
  • recent-trade minimization
privacyPENDING PRODUCTION REVIEW
RISK-PRIVACY-OPERATOR-004
HIGHOPEN

Broad operator or administrator data access

Early-beta operational paths may expose more user-level information than the target model permits.

Current controls
  • admin authentication
  • manual operational controls
Target controls
  • access inventory
  • aggregate health
  • user-authorized support
privacyPENDING PRODUCTION REVIEW
RISK-CROSSCHAIN-005
HIGHOPEN

External-chain and gateway risk

Deposits and withdrawals depend on external chains, contracts, gateways, RPCs, signatures, fees, evidence, and finality.

Current controls
  • route allowlists
  • evidence
  • finality thresholds
Target controls
  • fresh route registry
  • bounded execution
  • stronger canary evidence
fundingPENDING PRODUCTION REVIEW
RISK-KEY-006
HIGHOPEN

Signing and key-management risk

External execution depends on signing authority and key-management systems.

Current controls
  • narrow operational procedures
  • restricted identities
Target controls
  • narrow signing scope
  • rotation
  • minimum-authority keepers
securityPENDING PRODUCTION REVIEW
RISK-LIQUIDITY-007
HIGHOPEN

Limited liquidity and execution quality

Public Beta liquidity does not yet match mature CEX or leading DEX markets.

Current controls
  • current pools and market workflows
Target controls
  • core-market depth
  • measured spread and slippage
  • market-maker program
marketPENDING PRODUCTION REVIEW
RISK-STABLE-008
HIGHOPEN

Upgrade and stable-state compatibility

Critical financial upgrades may create stable-state compatibility risk.

Current controls
  • stable-state inventories
  • targeted audits
  • post-upgrade checks
Target controls
  • versioned migrations
  • upgrade simulations
  • rollback boundaries
corePENDING PRODUCTION REVIEW
RISK-PROJECTION-009
MEDIUMOPEN

Data freshness and projection mismatch

Projection lag may cause stale or contradictory displays relative to Core.

Current controls
  • source cursors
  • rebuildable projections
  • existing freshness checks
Target controls
  • visible freshness
  • automatic refresh after recovery
  • mismatch alerts
data_apiPENDING PRODUCTION REVIEW
RISK-FRONTEND-010
HIGHOPEN

Frontend, domain, and delivery risk

A compromised frontend or domain can mislead users even when canisters remain correct.

Current controls
  • frontend security audits
  • controlled domains
Target controls
  • bundle hashes
  • release manifests
  • independent verification links
wwwPENDING PRODUCTION REVIEW
RISK-AGENT-011
HIGHOPEN

Agent permission expansion

An Agent or integration may receive broader read or execution authority than intended.

Current controls
  • confirmation flows
  • current grant foundations
  • Core execution
Target controls
  • scopes
  • limits
  • nonce
agentPENDING PRODUCTION REVIEW
RISK-TELEMETRY-012
MEDIUMOPEN

Telemetry and browser-storage privacy

Telemetry, receipt caches, sessions, addresses, or device context may create user-data exposure.

Current controls
  • current client isolation and diagnostics
Target controls
  • data minimization
  • purpose and retention
  • expiry
privacyPENDING PRODUCTION REVIEW
RISK-INCIDENT-013
MEDIUMOPEN

Incomplete public incident process

Operational events can be fragmented or underexplained without one versioned incident registry.

Current controls
  • development and deployment records
Target controls
  • severity model
  • incident IDs
  • timelines
operationsPENDING PRODUCTION REVIEW
RISK-ISSUER-014
HIGHOPEN

Token issuer and contract risk

Stablecoins and wrapped assets depend on issuers, contracts, mints, bridges, or chain-key systems.

Current controls
  • canonical route controls
  • asset registry
Target controls
  • contract disclosure
  • route provenance
  • pause and retirement process
assetsPENDING PRODUCTION REVIEW
RISK-CYCLES-015
MEDIUMOPEN

Canister resource and availability risk

Cycles, memory, or operational health can affect availability.

Current controls
  • cycles monitoring
  • manual replenishment
Target controls
  • public-safe health
  • threshold alerts
  • funding policy
operationsPENDING PRODUCTION REVIEW
RISK-GOVERNANCE-016
HIGHOPEN

Premature or concentrated governance

Launching SNS before product, privacy, reproducibility, and distribution readiness may formalize weak or concentrated control.

Current controls
  • pre-SNS controller phase
  • readiness planning
Target controls
  • launch gates
  • public threat model
  • distribution analysis
governancePENDING PRODUCTION REVIEW
PUBLIC INCIDENTS

Incidents should be permanent, traceable, and correctable.

SSS has opened its first formal incident record. Facts, user protection, recovery status and unresolved boundaries remain visible while the audit continues.

SSS-INC-20260728
CONTAINEDRECOVERY OPEN

July 28, 2026 CLMM exploit

The known exploit path has been contained. Seven affected assets were reconciled to atomic units, user liabilities remain fully covered, and the external proceeds are under continuing multi-chain monitoring.

7/7assets reconciled58external payouts matched≈95%team-owned impact0user haircut planned
Read dialogue and recovery noticeFull technical post-mortem pending audit closeout
AUTHORITY & GOVERNANCE

Who may do what—and what they must never do.

Governance is not an SNS badge. It is the verifiable combination of controllers, upgrade rights, financial authority, operational permissions, and emergency boundaries.

Current governance state: Pre-SNS.Controllers still require public observation. SNS control is a target, not a current fact.
financial_coreFINANCIAL CORE

core

May write
  • canonical balances
  • reservations
  • trades
  • orders
  • liquidity
  • fees
  • authoritative receipts
Must not do
  • external signing-key custody
  • long-term analytics authority
  • arbitrary support browsing
asset_hubEXTERNAL EXECUTION

asset_hub

May write
  • documented route and evidence state
Must not do
  • own canonical SSS user balance
  • finalize internal financial success independently
evm_executionEXTERNAL EXECUTION

evm_gateway

May write
  • external EVM execution state
Must not do
  • change Core balances
  • invent external finality
solana_executionEXTERNAL EXECUTION

sol_gateway

May write
  • external Solana execution state
Must not do
  • change Core balances
  • invent external finality
bridge_financial_supportFINANCIAL SUPPORT

eth_bridge_ledger · bnb_bridge_ledger · btc_bridge_ledger · sol_bridge_ledger · usdc_bridge_ledger_prod · usdt_bridge_ledger_prod

May write
  • only documented bridge-ledger semantics
Must not do
  • become an undocumented duplicate SSS balance
  • claim general SSS settlement authority
  • own Route Policy
data_projectionDATA PROJECTION

data_api

May write
  • rebuildable projections
  • daily closes
  • read models
Must not do
  • financial mutation
  • balance correction
  • final success authority
user_interactionUSER INTERACTION

www

May write
  • browser and user-interaction state only
Must not do
  • financial success authority
  • hidden balance edits
agent_intentAGENT INTENT

agent_gateway

May write
  • intent and nonfinancial orchestration state
Must not do
  • arbitrary account reads
  • financial mutation
  • unsupported execution
  • final success authority
operationsOFFCHAIN OPERATIONAL ACTOR

keepers

May write
  • bounded, explicit, idempotent progress calls permitted by canister interfaces
Must not do
  • universal account access
  • discretionary balance changes
  • Route Policy mutation
  • hold unattended privileged controller identity
contentCONTENT

portal · docs

May write
  • content assets only
Must not do
  • financial mutation
  • trade settlement
  • withdrawal authority
  • nonfinancial program authority
nonfinancial_programNONFINANCIAL PROGRAM

dataroom

May write
  • nonfinancial program records only
Must not do
  • trading balance mutation
  • trade settlement
  • withdrawal authority
  • general content authority