Hkchain

Case 3 — Public Reserve Verification

Scenario

Carol holds HKD 1,000 in hkd.hsbc on Hkchain. She wants to verify that her balance is genuinely backed by reserves at HSBC, without relying on a press release or an auditor's website.

This case demonstrates public verifiability of reserve backing — a direct mechanism for meeting HKMA's "public disclosure" requirement and, more importantly, for building end-user trust in licensed stablecoins.

Actors

ActorRole
CarolRetail L3 holder
HSBCLicensed issuer of hkd.hsbc
Auditor ARegistered auditor for HSBC attestations
Any member of the publicCan do this same verification for any address

Preconditions

  • Carol has been KYC'd by HSBC (L3) and holds HKD 1,000
  • HSBC has submitted a monthly attestation covering 2026-03 (period end 2026-03-31), with random-day snapshot on 2026-03-17
  • Auditor A has co-signed that attestation (AttestationFinalized)
  • HSBC's off-chain PDF attestation report is published at https://hsbc.com/.../attestations/2026-03.pdf; its SHA-256 hash is recorded on chain

Flow

Step 1 — Carol opens the Public Reserve Lookup page

https://hkchain.example/public/reserve-lookup

She enters her address (or it's auto-filled if her wallet is connected).

Step 2 — Lookup executes three queries

The page runs (in parallel):

  1. QueryBalance(address=carol, denom=hkd.hsbc) — returns 1000 hkd.hsbc
  2. QueryLatestAttestation(issuer=HSBC, denom=hkd.hsbc) — returns the attestation covering Carol's current holding
  3. QueryAttestationHistory(issuer=HSBC, limit=12) — returns the last 12 attestations for context

Step 3 — Results displayed

┌──────────────────────────────────────────────────────────────┐
│ Your balance:                                   HKD 1,000    │
│ Denom:                                          hkd.hsbc     │
│ Issuer:                                         HSBC         │
│                                                              │
│ Current backing attestation                                  │
│ ────────────────────────────                                 │
│ Period:            2026-03-01 – 2026-03-31                   │
│ Random-day snap:   2026-03-17                                │
│ Circulation:       HKD 1,247,392,150                         │
│ Reserve (market):  HKD 1,310,000,000                         │
│ Coverage ratio:    105.0%                                    │
│                                                              │
│ Signatures                                                   │
│ ─────────                                                    │
│ Issuer (HSBC):     0x… (verified)                            │
│ Auditor (Auditor A): 0x… (verified, registered)              │
│ Finalized at:      2026-04-05 block 382,991                  │
│                                                              │
│ Public attestation report                                    │
│ ─────────────────────────                                    │
│ PDF hash (on-chain): 0x7f3a1b9e…                             │
│ Public URL:          https://hsbc.com/…/2026-03.pdf          │
│ [Download and verify hash]  [View attestation on Explorer]   │
└──────────────────────────────────────────────────────────────┘
Live /dashboard/public/reserve-lookup against the seeded HKMA demo localnet. The retail-l3-1 address (hkchain10lrpc35y0j5drspryuwsfnheldt9z9sd84u3dt) returns one AddressReserveBinding{issuer, denom, balance, attestation} row: 10,000 HKD held against an ATTESTED 1.05× backed attestation, with attestation id, period, random-day snapshot 2025-12-15 (HKMA §5.7 requirement), reserve market value, auditor address, and the on-chain attestation_hash — every field surfaced from x/reserve.QueryReserveForAddress. Narrative actor "Carol" abstracts over this seed identity; the surface is identical.
Live /dashboard/public/reserve-lookup against the seeded HKMA demo localnet. The retail-l3-1 address (hkchain10lrpc35y0j5drspryuwsfnheldt9z9sd84u3dt) returns one AddressReserveBinding{issuer, denom, balance, attestation} row: 10,000 HKD held against an ATTESTED 1.05× backed attestation, with attestation id, period, random-day snapshot 2025-12-15 (HKMA §5.7 requirement), reserve market value, auditor address, and the on-chain attestation_hash — every field surfaced from x/reserve.QueryReserveForAddress. Narrative actor "Carol" abstracts over this seed identity; the surface is identical.

Step 4 — Carol (or anyone) can independently verify the hash

Download the PDF from HSBC's site. Compute the SHA-256. Compare to the on-chain hash 0x7f3a1b9e…. Match → the PDF Carol read is the exact PDF the auditor signed. No intermediary fabrication possible.

Step 5 — Carol can drill into past attestations

The history shows 12 months. For each, she can see period, circulation, coverage, and the corresponding PDF hash. Any consecutive pair lets her check: was the circulation monotone? Did coverage ever dip below 100%? Are attestation cadences consistent?

What this case demonstrates

  1. Public verifiability as a primitive, not a PR mechanism. The chain exposes the query; anyone can run it. No special access.
  2. Cryptographic binding between on-chain state and off-chain PDF. The PDF hash on chain is the attestation's fingerprint. Tampered PDFs fail hash comparison.
  3. Multi-sig attestation. The attestation carries both issuer and auditor signatures, verifiable on chain.
  4. HKMA's "public disclosure" requirement fulfilled end-to-end: prominent location on issuer website (the PDF), publicly queryable chain record (the hash + metadata), independent auditor sign.
  5. Random-day snapshot — per HKMA guideline, the attestation covers both period-end and a randomly selected business day. Both values are on chain and verifiable.

Edge case — attestation missing or stale

If Carol looks up her balance and no current attestation is found (or the latest attestation is older than the freshness parameter), the page displays a prominent notice:

⚠ No current attestation for this issuer.
  Latest attestation: 2026-02-28 (57 days ago)
  Issuer cannot mint additional HKD until a new attestation is finalized.

Carol can see exactly what is going on and contact HSBC (or the regulator) if needed. The chain does not hide the state.

Audience-specific value

  • For retail holders: direct trust primitive — "is my money real?" gets a clear, cryptographic answer
  • For institutional holders: due-diligence automation — treasury systems can programmatically verify reserve state before holding
  • For HKMA: demonstration of a chain's capacity to meet the "public disclosure" standard in a way that goes beyond website links
  • For auditors: their signatures become first-class chain citizens; reputation accrues
  • For journalists / civil society: the chain is the primary source, not an issuer's blog
Address detail at /explorer/address/<holder> — the same retail address from the lookup above, drilled into via the explorer. The page surfaces the Identity card (KYC level + VASP + IVMS101 off-chain ref + cross-checked SanctionsSet status), the Sub-role context card (delegated-by + delegated-from), Balances by denom, and the Recent transactions scan (bank-event filters + EVM-event filters merged client-side). The same surface is what any holder, auditor, or supervisor reaches.
Address detail at /explorer/address/<holder> — the same retail address from the lookup above, drilled into via the explorer. The page surfaces the Identity card (KYC level + VASP + IVMS101 off-chain ref + cross-checked SanctionsSet status), the Sub-role context card (delegated-by + delegated-from), Balances by denom, and the Recent transactions scan (bank-event filters + EVM-event filters merged client-side). The same surface is what any holder, auditor, or supervisor reaches.

Implementation notes (for engineering readers)

  • QueryReserveForAddress(address) returns one AddressReserveBinding{issuer, denom, balance, attestation} per registered denom the address currently holds. An empty list means the address holds no stablecoin-module denom. Public-facing UX is where the effort is.
  • Historical attestations per issuer are queryable efficiently via QueryAttestations{issuer, pagination}, which walks the per-issuer attestation-id index.
  • PDF hash verification is manual today (user downloads and computes). A browser extension that auto-verifies would be a natural future addition.

Counterpart surfaces — supervisor and auditor

The public-lookup surface is one of three views over the same chain state. The supervisor and auditor consume the same data through role-tailored dashboards:

Supervisor /dashboard/supervisor — four-card overview: Total circulation · Reserve coverage (with coverage ratio) · Compliance events (24h) · KYC level distribution. Click-through into the attestation calendar, per-issuer drill-down, and reports. Read-only by design — there is no supervisor-write tx type on chain.
Supervisor /dashboard/supervisor — four-card overview: Total circulation · Reserve coverage (with coverage ratio) · Compliance events (24h) · KYC level distribution. Click-through into the attestation calendar, per-issuer drill-down, and reports. Read-only by design — there is no supervisor-write tx type on chain.
Auditor /dashboard/auditor — pending co-sign queue + finalized-attestation history. Auditor signs MsgCoSignAttestation after off-chain audit work; the chain transitions the attestation from PENDING_AUDIT to ATTESTED, which unblocks the issuer's mint freshness gate. The auditor's authority is governance-registered via x/reserve.AuditorRegistry.
Auditor /dashboard/auditor — pending co-sign queue + finalized-attestation history. Auditor signs MsgCoSignAttestation after off-chain audit work; the chain transitions the attestation from PENDING_AUDIT to ATTESTED, which unblocks the issuer's mint freshness gate. The auditor's authority is governance-registered via x/reserve.AuditorRegistry.