#dusk $DUSK @Dusk
An investor’s eligibility should not become a permanent label attached to a wallet.
Accreditation can expire. Residency can change. Control of a wallet can also change. Relying on an old approval may leave a transfer looking compliant without checking who is receiving the asset now.
Citadel 2 offers an interesting design path. An investor can generate a zero knowledge proof from a registered, LP signed credential. The Citadel contract verifies that proof and records a public session without exposing the underlying identity, credential or wallet key onchain.
For a regulated transfer, a service provider could require a fresh Citadel session, use a transfer-specific challenge, and bind the resulting cookie or authenticated request to the receiving account. With a selective disclosure profile, only the required facts such as eligible residency or accreditation would need to be disclosed or proven.
Citadel confirms that the session is cryptographically valid. It does not decide which license providers are trusted, how long approval lasts, whether it may be reused, or how revocation is checked. The service provider potentially the issuer or venue must define those rules.
Citadel 2’s current specification is marked Draft, and its repository says the implementation is not intended for production use. This remains a design path, not proof of a live eligibility gate on Dusk.
Should every regulated transfer require a new eligibility proof?
$DUSK
An investor’s eligibility should not become a permanent label attached to a wallet.
Accreditation can expire. Residency can change. Control of a wallet can also change. Relying on an old approval may leave a transfer looking compliant without checking who is receiving the asset now.
Citadel 2 offers an interesting design path. An investor can generate a zero knowledge proof from a registered, LP signed credential. The Citadel contract verifies that proof and records a public session without exposing the underlying identity, credential or wallet key onchain.
For a regulated transfer, a service provider could require a fresh Citadel session, use a transfer-specific challenge, and bind the resulting cookie or authenticated request to the receiving account. With a selective disclosure profile, only the required facts such as eligible residency or accreditation would need to be disclosed or proven.
Citadel confirms that the session is cryptographically valid. It does not decide which license providers are trusted, how long approval lasts, whether it may be reused, or how revocation is checked. The service provider potentially the issuer or venue must define those rules.
Citadel 2’s current specification is marked Draft, and its repository says the implementation is not intended for production use. This remains a design path, not proof of a live eligibility gate on Dusk.
Should every regulated transfer require a new eligibility proof?
$DUSK

