Hkchain

Hkchain — MVP Scope and Roadmap

MVP target

A single-node testnet demonstrating end-to-end compliant HKD payment flow, ready for the HKMA technical readiness meeting on 2026-05-11.

This page records that MVP scope. Since then the same software has gained a five-validator permissioned test network with a public full node, a second test issuer denomination and a testnet onboarding portal. The current enforcement boundaries are stated in the technical report (Section 10.2).

What ships in MVP

Chain (Cosmos SDK + cosmos/evm v0.6.0, CometBFT single-node)

  • x/stablecoin — native HKD denom, mint/burn/redeem, pause, per-account freeze
  • x/compliance — AnteHandler decorators (KYC, sanctions, Travel Rule, threshold, velocity, role-gate, agent policy), audit log, reviewer/officer workflow, sub-role delegation, and a period report query over the audit log and flag queue
  • x/reserve — multi-sig attestation (issuer + auditor), daily par-value statements, public address-to-attestation lookup
  • x/kyc — six-level identity registry, VASP identifier binding, blacklisting
  • Extended ERC-20 precompile — Single Token Representation of HKD: standard transfer / transferFrom revert, and transferWithTravelRule / transferFromWithTravelRule run the same compliance decorators as the native path before the bank send, for dual-path parity
  • tx_trace — query returning per-decorator AnteHandler results from a node-local, non-consensus buffer, for demo visualization

Off-chain

  • Compliance Dashboard — Next.js app with read-only role views (supervisor, issuer operations, compliance, auditor, public reserve lookup)
  • Explorer — /explorer route in the hkchain web app: live block feed, block detail, compliance-annotated transaction detail (decorator trace, flags, Travel Rule payload, audit events, decoded messages, simulate-trace fallback), and address detail (KYC + sanctions, sub-role context in both directions, balances, recent transactions)
  • payx402 service — Go HTTP server implementing x402 pay-per-request, demo'd with good agent and blacklisted agent

Documentation

  • This docs/ tree (design, cases, references, future)
  • Demo walkthrough script
  • HKMA-targeted executive summary and slide deck

Demo contract (the nine must-show scenarios)

  1. Chain running, blocks producing
  2. HKD lifecycle: mint → transfer with Travel Rule → burn/redemption
  3. Transfer to blacklisted address rejected at AnteHandler
  4. Large transfer (≥ HKD 8,000) requires a full-tier Travel Rule payload; a minimal payload → rejected
  5. Proof of Reserve: issuer submits → auditor co-signs → finalized; mint gate unblocks
  6. Compliance report: period roll-up of the audit log and flag queue (export in HKMA's prescribed formats is roadmap)
  7. 402 agent payment: good agent succeeds; blacklisted agent rejected by chain, not by service
  8. Public reserve lookup: any address → attestation period → PDF hash
  9. Chain-enforced agent revocation: user-delegated agent sub-key spends within daily_cap / per_tx_cap; MsgRevokeSubRole lands and the next agent payment is rejected by AgentPolicyDecorator in the very next block

All scoping decisions preserve or support one of these nine.

Explicit non-goals for MVP

  • DEX / DeFi primitives
  • Multi-currency (HKD only — other fiat-referenced stablecoins are roadmap)
  • Production consensus (CometBFT only; Algorand PPoS documented as roadmap)
  • Mainnet deployment (single-node localnet for the MVP; a permissioned test network followed)
  • Real-time sanctions oracle (updates are authorised transactions signed by the compliance authority)
  • Velocity/threshold rules that block (flag-only, to avoid demo false-positives)
  • Mobile wallet SDK (MetaMask via the extended ERC-20 precompile is sufficient)
  • Cross-chain bridging / IBC
  • High-availability topology, formal security review, operational hardening
  • PDF and CSV rendering of reports (the MVP Report query returns structured sections only)

Roadmap

Near-term (post-MVP, pre-production)

  • Multi-issuer onboarding flow: governance proposals structured for HKMA observability, denom registration, audit trail of licensing events
  • Real-time sanctions oracle: oracle feed from canonical sources (UN, HKMA, OFAC) with governance fallback for dispute resolution
  • Threshold / velocity rules with blocking: governance-tunable mode (log | flag | block) per rule
  • Mobile wallet reference implementation: issuer-branded wallet SDK
  • PDF report rendering: formatted to match HKMA supervisory reporting templates

Medium-term (production-enabling)

  • Algorand Pure-PoS consensus migration: scalability path, open validator set, stronger decentralization narrative
  • Multi-validator operational topology: HA, region failover, validator set management for production
  • Formal security review: code audit, cryptographic review, operational security assessment
  • KYC provider standards: formal attestation schema, provider certification, cross-provider identity portability
  • IBC integration: cross-chain interoperability for HKD on Hkchain ↔ other Cosmos zones

Longer-term / exploratory

  • AI-assisted compliance triage: recommender for reviewers, eventually autonomous decisioner under officer supervision. See docs/future/ai-agent-compliance-review.md.
  • Cross-jurisdiction stablecoin fabric: interop with regulated stablecoin ecosystems in other jurisdictions (MiCA zones, GENIUS Act zones, etc.) under appropriate bilateral agreements
  • Advanced reserve composition analytics: on-chain or off-chain analytics surface for real-time reserve health signals

Dependencies and risks

  • Upstream version pin: github.com/cosmos/evm v0.6.0. Breaking changes in the upstream require re-validation.
  • HKMA guideline evolution: the Supervision and AML/CFT Guidelines may be updated; Hkchain docs and implementation will need to track material changes.
  • Regulatory engagement: productionization requires direct engagement with HKMA, including any pilot program arrangements.
  • Issuer onboarding: the first production issuer's readiness (legal, operational, technical) is on their critical path, not Hkchain's. MVP seeds a mock issuer to demonstrate the rail independently.

Success criteria for 2026-05-11

  • A 20-minute demo walks HKMA through all nine must-show scenarios
  • HKMA can independently query the chain and dashboard during and after the meeting
  • The technical document (this docs/ tree exported) is available for HKMA's internal review
  • At least one licensed issuer has seen the demo and provided structured feedback