Skip to content
Mailing Lists/CIP-TBD: Add Halborn as a Weight 4 Super Validator - Edgar CepinSource on lists.sync.global ↗

CIP-TBD: Add Halborn as a Weight 4 Super Validator - Edgar Cepin

cip-discuss1 messagesstarted 09-07-2026
Also mentions:CIP-0105
  1. #1Edgar Cepin09-07-2026source ↗

    CIP: CIP XXXX (to be assigned)

    Title: Add Halborn as a Weight 4 Super Validator

    Author: Edgar Cepin

    Status: Draft

    Type: Governance

    Created: 2026-07-02

    License: CC0-1.0

    Abstract

    • Add Halborn Inc. as a Weight 4 Super Validator

    • Halborn agrees to a multi-year basket of security-focused contributions to the Canton ecosystem, including infrastructure and custody security audits, a public security standards publication, EU regulatory readiness advisory, a subsidized security-testing tier, and a Daml package audit pathway

    • Halborn agrees to earn its full Weight 4 progressively as these commitments are completed.

    • Halborn can operate its own Super Validator node on behalf of the Canton network.

    Specification

    • Add up to 4 SV Weight for Halborn, earned progressively as commitments below are completed

    • Halborn onboards with an SV Weight of zero and is free to operate a Super Validator node at their discretion

    • Halborn will operate its Super Validator node.

    Motivation

    • The infrastructure components Halborn proposes to audit (Splice validator/SV software, custody and key management integrations, cross-chain bridge implementations) are critical to the proper functioning and safety of the Canton Network, since they govern how assets, keys, and cross-application transactions are secured across the ecosystem.

    • It is critically important that these components are independently and regularly assessed for vulnerabilities, both to protect network participants from exploitation and to solidify the legitimacy of the Canton Network among the regulated financial institutions it targets

    • The codebase and configuration underlying this infrastructure is subject to change over time through upgrades and other maintenance-related activities. It is therefore important to revisit these audits periodically, and specifically after major upgrades, to ensure that changes do not introduce new vulnerabilities or undermine the security properties the network depends on

    Rationale

    • Halborn is an award-winning security solutions firm, founded in 2019, that has completed 3,000+ engagements amounting to $1 trillion in value protected

    • Halborn's governance framework is validated by SOC 2 Type 2, ISO 27001, and NIST certifications

    • Halborn already maintains a public Daml/Canton whitepaper positioning Canton as the trust layer for regulated financial infrastructure

    • Halborn commits to the following:

      • Complete a recurring independent security audit of a Canton infrastructure component (Splice validator/SV software or a designated cross-chain bridge implementation) once per year for 3 years, plus an additional review after any major Mainnet version change, excluding the Canton Coin Daml model.

      • Complete a recurring Canton-native custody security review series, covering SV/validator key management, institutional custody integrations, wallet software, and signing infrastructure, beginning within 12 months and continuing annually

      • Publish and maintain a Canton Security Standards Publication Track, combining an institutional security framework and threat model, with an initial publication within 12 months and one substantive revision per year thereafter

      • Publish quarterly EU regulatory readiness briefs (MiCA/DORA/VARA) beginning within 6 months, and deliver at least one subsidized regulatory advisory engagement to a Canton ecosystem participant annually

      • Extend a 10% subsidized tier of its Bastion offering to qualifying Canton ecosystem participants, beginning within 18 months and continuing on an ongoing basis with annual reporting, with eligibility defined jointly with the Foundation

      • Establish an official security review pathway for the Daml package registry, coordinated with Digital Asset, within 12 months

      • Actively and continuously participate in Canton Foundation working groups relevant to its contribution areas, including the Tokenomics Working Group

      • Participate in the CIP-0105 locking framework at the highest tier practical for a Weight 4 SV within 3 months of onboarding

      • Bear all costs of operating its Super Validator node, at no cost to the Foundation or the network

    • Why Halborn

      • Founded in 2019, Halborn is an award-winning, industry-leading security solutions firm, trusted by the world's largest banks and financial institutions

      • Halborn has discovered several zero-days and completed 3,000+ security engagements, amounting to $1 trillion in value protected

      • Halborn acts as a strategic security advisor across the engagement lifecycle, guiding architecture and design decisions, technical due diligence, custody and key management, and AI security strategy, while upskilling teams through technical training and backing it with hands-on smart contract, code, and web/mobile/cloud assessments

      • Halborn's governance framework, covering data protection, access controls, personnel screening, and incident response, is independently validated by SOC 2 Type 2, ISO 27001, and NIST certifications

      • Halborn has already published a public Daml/Canton whitepaper positioning Canton as the trust layer for regulated financial infrastructure, reflecting direct, existing familiarity with the network ahead of this proposal

      • Because Canton bridges regulated institutional finance and on-chain infrastructure, Halborn is one of the few firms fluent in both, letting a single team assess the full trust surface rather than splitting the work across separate Web2 and Web3 specialists

    SV Mechanics

    An extraBeneficiary PartyID associated with the ‘escrowed’ Super Validator will be setup by the Foundation, or another SV node operator approved to provide SV rewards escrow services, with an SV Weight at the maximum earnable weight.

    The Applicant is responsible for coordinating the process of setting up the escrowed weights with the GSF and the operator of the SV node.

    The Applicant is responsible for all costs associated with the operation of the representative SV

    The representative SV will NOT mint rewards on a block by block basis

    All representative SV rewards will go to the Unclaimed Rewards pool

    Applicant is required to present proof of successful completed milestones to the Tokenomics Working Group

    Applicant is required to present a calculation for number of Canton Coin it should earn for meeting the requirements of the milestone

    If the Tokenomics Working Group agrees the milestone has been met and agrees with the calculation, an announcement will be sent via the Tokenomics-Announce mailing List

    ⅔ of Super Validator Operators will then assign a portion of the Unclaimed Rewards to be minted by the Applicant’s Validator

    ⅔ of the Super Validator Operators will update their configurations to allow Applicant to takeover a portion of their SV Weight on a go-forward basis

    If any milestones and associated rewards are not achieved by the deadline

    Applicant will be notified they have not met a deliverable by the Foundation

    Remaining SV Weight on the representative SV will be removed from the SV Operator configs

    The Tokenomics Working Group will make a recommendation to the SVs on what to do with the Unclaimed Rewards

    Copyright

    This CIP is licensed under CC0-1.0.

    Changelog

    • 2026-07-02: Initial draft prepared from Halborn's Canton Foundation Membership Application.