i remember the first time i saw an identity check fail because the data was stale.

a friend's KYC got rejected—not because he was ineligible, but because the verification system was working off outdated info. he'd moved countries six months prior. his old status no longer applied. the system didn't know. the deal fell through. all because compliance couldn't keep up with life changes. 💀

that experience came flooding back reading about Citadel's on-chain licenses.

here's the pitch: NFT-based KYC licenses stored immutably on Dusk. no more multiple verifications. efficient. private. beautiful.

except there's a massive blind spot: blockchain is immutable. identity is not.

the article mentions "quarterly confirmation" as a recommendation. optional. unenforceable.

imagine this:

· user completes KYC. gets licensed as "accredited investor" and "EU resident"
· two years later, user moves to non-EU jurisdiction. status lapses.
· license doesn't update. stays valid in Merkle tree.
· user accesses regulated asset they're no longer eligible for.
· SP verifies proof. accepts license. trade settles.

who's liable? the SP accepted an outdated proof. the regulator fines them. the blockchain record shows a valid license—but the underlying reality was invalid.

immutability becomes evidence against you, not for you.

the fix? time-bound licenses with ZK-refresh proofs. license expires after 12 months. to refresh, user submits proof their data still matches—without re-sharing raw data. old license marked expired. compliance enforced.

$DUSK is building serious regulated infrastructure. but storing mutable identity data on immutable ledgers? that's a compliance bomb waiting to explode.

will Citadel solve data rot before the first failed audit? 🤔
#Dusk $DUSK @Dusk