Skip to main content
Tokenized RWAs OFT shares the same security foundations as Stablecoin OFT — OpenZeppelin audited upgradeable libraries, EIP-7201 namespaced storage, two-step admin transfer, and push-based fee settlement. Tokenized RWAs OFT contracts are independently audited. This page focuses on threats and mitigations specific to the Tokenized RWAs OFT architecture.

Tokenized RWAs OFT Threat Model

Shared Threat Model

The following threats and mitigations are shared with Stablecoin OFT:
  • Pauser / Unpauser key compromise — Same split-role mitigation. See Stablecoin OFT Security.
  • Fee deposit address compromise — Same push-based model. Attacker controlling feeDeposit can only receive fees, not extract principal.
  • Supply inflation via misconfigured deployment — Ensure each NexusERC20 grants MINTER_ROLE/BURNER_ROLE only to the intended burner-minter address.
  • Fund recovery abuse — Same recoverFunds restriction: only from non-allowlisted addresses.
  • Non-atomic proxy deployment — Same risk. Deploy proxy and call initialize atomically.

Compliance Controls

Allowlist (via NexusERC20Guard)

The shared guard enforces allowlist checks on transfer, transferFrom, and burn for all registered NexusERC20 tokens. Mode switches (Open → Blacklist → Whitelist) are instant and do not clear existing lists.

Per-Token Pause (via NexusERC20Guard)

Each NexusERC20 can be paused independently using uint160(tokenAddress) as the pause ID. This allows freezing a specific token’s local transfers without affecting other tokens.

Per-Pathway Pause (via NexusPauseModule)

Cross-chain sends can be paused at four levels: globally, per destination, per token, or per (token, destination) pair. Priority resolution determines the effective state.

Fund Recovery

Same mechanism as Stablecoin OFT — admin can transfer tokens from non-allowlisted addresses for compliance seizures.

Monitoring

Events to monitor across the Tokenized RWAs OFT deployment:

Next Steps