Private, privacy-preserving transfers on-chain, built for regulatory approval. An open-source protocol that separates identity from redemption, so observers cannot link a deposit to its redemption while every transfer carries a signed, attributable statement of purpose.
Built by Soulbound Security. Reference implementation live at soulbound.finance on Arbitrum One since April 2026.
Depositors are identity-linked through a non-transferable Soulbound ID (the SoulBoundToken contract), which carries a zero-knowledge identity commitment. Recipients redeem to a fresh address using a one-time-use (OTU) redemption code. The protocol never records which deposit a redemption corresponds to.
This is not a mixer. Deposits are identity-gated (Soulbound ID plus optional Privado ID zero-knowledge verification), and every OTU generation requires a per-transaction EIP-712 signed attestation of purpose, recorded immutably on-chain. Compliance is structural, not bolted on.
Core properties:
- Compliant by design. KYC-linkable deposits via zero-knowledge commitment (Privado ID). EULA acceptance cryptographically recorded at mint. Per-transaction purpose attestation on every OTU. Regulators have an audit surface; counterparties do not.
- Private redemption. Recipient addresses are ephemeral. No recipient data is stored on-chain or off-chain beyond the redemption transaction itself.
- Multi-token. Native ETH plus controller-whitelisted ERC-20s. See Supported Tokens.
- Immutable contracts. No proxies, no
delegatecall. Upgrades require explicit member migration. Auditable by construction. - Unconditional exit.
emergencyWithdrawlets any Soulbound ID holder reclaim their full balance at any time, with no fee.
See §1 System Overview for the full contract dependency graph.
┌──────────────────────┐
│ SoulBoundToken │ Identity layer (Soulbound ID). Non-transferable.
│ │ ZK commitment. EULA gate on mint. Nonce tracks
│ │ OTU generation.
└──────────┬───────────┘
│
┌──────────▼───────────┐
│ DepositPool │ Inflow. Multi-token deposits. Per-tx EIP-712
│ │ purpose attestation. Splits fees on OTU generation:
│ │ Protocol fee → Treasury (direct)
│ │ OTU + gas fee → ClaimPool
└──────────┬───────────┘
│
┌──────────▼───────────┐
│ ClaimPool │ Outflow. Operator-processed redemptions.
│ │ Batch processing. Gas fund, deployable only to
│ │ whitelisted targets.
└──────────────────────┘
Deployment: SoulBoundDeployer, atomic deploy + link in a single tx.
One Soulbound ID per address. Non-transferable, non-burnable. Holds the member's encryptedAccountId, zkpCommitment (Privado ID) and EULA acceptance hash. The nonce increments on each OTU generation and provides replay protection for EIP-712 attestations.
ZK commitments can be set post-mint: mint first, verify later. See §2 SoulBoundToken.
Accepts ETH and whitelisted ERC-20s from Soulbound ID holders. No fees on deposit. OTU generation deducts the face value plus protocol and gas fees from the member's internal balance, sends the protocol fee directly to the treasury and forwards the remainder to the ClaimPool. The contract has zero knowledge of the OTU code itself.
See §3 DepositPool and §4 EIP-712 Fee Attestation.
Holds redemption funds and the gas reserve. Redemptions are processed by a privileged Operator role, the bridge between off-chain OTU validation and on-chain fund release. Supports single and batch redemptions. The gas fund is a separate balance for protocol operations and can be deployed only to Operator-approved targets.
See §5 ClaimPool and §7 Operator Trust Model.
Fees are bound to declared purpose. Every OTU generation requires an EIP-712 signed attestation, which the contract verifies and records on-chain before applying the matching fee tier. No OTU can be generated without one. Fees are charged on top of the OTU face value, not deducted from it. See §3 Fee Structure.
| Declared purpose | Protocol fee | Gas fee | Total | Status |
|---|---|---|---|---|
| Personal, non-commercial and charitable | 1.00% | 0.25% | 1.25% | Live |
| Commercial and enterprise | 2.00% | 0.25% | 2.25% | Disabled at deployment; enabled only upon regulatory approval |
The gas fee (0.25%) is a contract constant. Protocol fees are adjustable by the controller multisig and hard-capped at 5% per tier in the contract.
sbf-protocol/
├── src/
│ ├── SoulBoundToken.sol
│ ├── DepositPool.sol
│ ├── ClaimPool.sol
│ ├── SoulBoundDeployer.sol
│ └── interfaces/
│ └── ISoulBoundToken.sol
├── test/
├── scripts/
├── docs/
│ └── PROTOCOL_SPEC.md
├── audits/
├── CLAUDE.md
├── foundry.toml
├── LICENSE
└── README.md
Requires Foundry.
# Clone
git clone https://github.com/SoulboundSecurity/sbf-protocol.git
cd sbf-protocol
# Build
forge build
# Test
forge test
# Gas report
forge test --gas-reportTarget chain: Arbitrum One (mainnet) / Arbitrum Sepolia (testnet).
# Deploy full system atomically
forge script scripts/Deploy.s.sol --rpc-url $RPC_URL --broadcastSee TESTING.md for full test coverage documentation and contribution guidelines.
| Date | Review | Outcome |
|---|---|---|
| May 2026 | Independent third-party review by Gakarot, with mainnet-forked Foundry PoCs | Two findings, both fixed in c4d7787. Full record in audits/2026-05-28-gakarot-disclosure.md |
| June to August 2026 | Internal security review | Gas fund target whitelist added to ClaimPool (PR #7, merged in 38e250d) |
| September 2026 | Architecture-level protocol security review | Published as Where Privacy Actually Lives |
Gakarot subsequently joined Soulbound Security as Director of Blockchain Security; later reviews are internal. Further independent third-party assurance will follow alongside our wider certification programme.
To report a vulnerability: security@soulboundsecurity.io
Accepted vulnerability disclosures, and the changes shipped in response, are recorded in audits/. Operators deploying forks should review these entries to understand which findings apply to their architecture.
For platforms that want Soulbound Finance's off-chain mitigations on top of the on-chain protocol (address-bound identity verification at the auth boundary), see SBA-Auth.
- Website: soulboundsecurity.io
- App: soulbound.finance
- Research: soulboundsecurity.substack.com
- X: @soulboundsec
- Commercial, regulatory and legal: legal@soulboundsecurity.io
- Protocol security: security@soulboundsecurity.io
AGPL-3.0. See LICENSE. Commercial licences are available from Soulbound Security for integrations that cannot adopt AGPL-3.0 terms.
© Soulbound Security Ltd 2026