Security that rests on hardware, not trust
Every stablecoin in operation today carries the same structural weaknesses: a master key that exists, an administrator who can change the rules, audits that are snapshots, and bridges that get robbed. AUD AER was engineered to remove each one — not mitigate them by policy, but make them mechanically impossible.
The AEREDIUM platform at a glance
The platform is developed by Aeredium — learn more at aeredium.io.
The four technologies
Iridium — the settlement chain
Aeredium's high-performance blockchain: a new block every 30 milliseconds and sustained throughput of 250,000 transactions per second. Fully compatible with the Ethereum programming model. Iridium is where AUD AER is minted and where its canonical ledger lives.
Sealed execution — contracts inside enclaves
Critical contracts, including the AUD AER issuance contract, execute inside Trusted Execution Environments — hardware-isolated compartments whose code cannot be read or altered even by the machine's operator. If anyone modifies the code by a single byte, its hardware fingerprint changes and the system refuses to operate. Tampering is not detected after the fact; it is refused by the silicon.
AERKey — the key that never exists
Issuance is controlled by a threshold signature system. Three enclaves each hold one mathematical share of the signing key; the complete private key is never constructed — not during generation, not during signing, not ever. Two of three must cooperate to sign. There is no master key to steal, because no key exists in any one place.
USIG — signatures that cannot be double-spoken
Every enclave carries a hardware-enforced monotonic counter. Every signed statement carries the next counter value, which can never repeat or go backwards. Signing two contradictory statements — the root of most sophisticated attacks on distributed systems — becomes mechanically detectable, publishable proof of compromise.
The observer layer
Aeredium's observer service runs inside the same attested enclaves and watches external systems directly — Ethereum-family chains, Bitcoin, Solana, Tron, and, significantly for a fiat-backed instrument, the banking rails. Observations take effect only when at least two of three independent observer nodes attest byte-identical reports. It is not a third-party oracle; it is the issuer's own attested hardware reading primary sources under quorum.
Multi-chain without bridges
AUD AER travels to external networks such as Ethereum and Arbitrum by burn-and-mint: tokens are burnt on one chain, the burn is quorum-observed, and the same hardware quorum signs the mint on the destination chain. No third-party bridge operator, no pooled collateral waiting in a lockbox, no wrapped intermediary token. At every instant the sum of AUD AER across all chains equals net issuance on Iridium.
Governance without an administrator key
The AUD AER contracts contain no owner and no administrator. Every change — registering an enclave, approving a code upgrade, adjusting issuance caps — follows one path: a directive signed by a threshold of governance keys, published on-chain, and executable only after a 48-hour public timelock. Counterparties and regulators see every pending change before it takes effect, with time to object. Aeredium itself cannot secretly modify AUD AER.
Compliance enforced in silicon
Sanctions screening, blocklists, transaction limits and freeze orders execute inside the enclaves, within the sealed contract logic itself. No operator, employee or attacker can bypass or quietly disable them — the attestation proves the exact code that ran. When a regulator or court requires an account frozen, the freeze is enforced by hardware on every chain AUD AER touches.
Honest limits
No system is riskless. Hardware enclaves have had disclosed vulnerabilities historically — which is why the quorum spans three different enclave technologies on separate cloud providers, so no single vendor's flaw can yield control. Reserves face the same credit and operational risks as any safeguarded client money — hardware cannot remove bank risk; it makes the position continuously visible. A fuller, franker risk discussion is available to regulators and institutional counterparties on request.