Skip to content
FREEZESCOPE
EVIDENCE-OF-RECORD FOR STABLECOIN FREEZES

Every stablecoin freeze is a lawsuit and a federal filing waiting to happen.

Not “trust us.” Here’s how to check us.

When a U.S. issuer freezes an address, it faces a court on one side and OFAC on the other — under strict liability, on a 10-business-day clock. FreezeScope turns that moment into a signed, hash-chained evidence record that a skeptical third party — opposing counsel, an examiner — can re-verify offline, byte by byte, without trusting us, our operator, or the data provider it came from.

Built for the compliance and legal teams who own the freeze — and have to defend it.

VERIFICATION READOUTOFFLINE · REPRODUCIBLE
header_verified✓ keccak(rlp(header)) == reported
tx_inclusion_verified✓ recomputed root == header root
storage_proof_verified✓ MPT proof vs verified stateRoot
not_determinable— state-proof capture unsupported on this chain
PRODUCES
A signed, hash-chained evidence pack for each freeze: what was ordered, what was done, what was proven, and what couldn't be.
READ BY
The examiner reviewing your program, and opposing counsel in discovery.
VERIFIED BY
Them, offline, from the files alone — without trusting us.
THE PROBLEM · NO SAFE DIRECTION

There is no careful-enough freeze.

Freezing isn't a "do it carefully and you're fine" decision. Both directions lead to a monster.

OVER-FREEZE

Freeze a pool or the wrong excess and you're sued for wrongful freeze.

Zama's contract-level cUSDC freeze was reversed by a court as "unwarranted" — the first court-unwound contract-level freeze, immobilizing innocent holders caught in the pool.

UNDER-FREEZE

Freeze too slowly or too narrowly and you're sued for negligence — or held in contempt.

Drift faces a "froze-too-slow" class action after funds bridged out before the freeze landed.

Under strict liability, intent is no defense — "I didn't mean to" is worth nothing. A documented, defensible decision is the only shield. That record is the entire product.

CASE · APRIL 2026 · UNRESOLVEDCOLLISION
$344M
BLOCKED · CONTESTED

OFAC's designation made the USDT blocked property; private terrorism creditors are using New York turnover law to seize the same property. OFAC forbids release without a license; a court may order it turned over. Contradictory commands, no safe move — the largest stablecoin freeze ever recorded.

WHY NOW · THE WINDOW IS OPEN

A mandate, a clock, and live pain — converging in 2026.

  1. JUL 18 2025

    The mandate.

    The GENIUS Act (Pub. L. 119-27) makes freeze capability a condition of every U.S. payment-stablecoin license and codifies a "reasonable particularity" standard for lawful orders. Demand by statute, not by sales.

  2. APR 10 2026

    The rules.

    FinCEN and OFAC jointly propose implementing rules (91 Fed. Reg. 18,582) — proposed OFAC Part 502 and FinCEN Part 1033. A material compliance-program failure is priced at up to $100,000/day (doubling to $200,000 for knowing violations).

  3. JUN 9 2026

    Comments close.

    The shape of the obligation is now visible — and every issuer is sizing the build.

  4. BY JAN 2027

    It takes effect.

    The forced-adoption window is open now — which is exactly when the standard-of-record gets set.

$0M
largest freeze
0
business-day OFAC clock
$0K/day
proposed penalty
0-year
records
THE RECORD · ONE SPINE, TWO AUDIENCES

One verified evidence spine. Two records that answer to different rooms.

FreezeScope never touches the freeze button — no keys, no token-path code, never in the money-movement path. Chain access is read-only; there is no transaction-signing code in the system at all. The only keys it holds sign evidence.

THE FIVE BEATSRECORDED · SEQUENTIAL
  1. 01ORDER
  2. 02DETERMINATION & BLAST RADIUS
  3. 03CAPTURE
  4. 04NOTICE & FILING CLOCK
  5. 05UNWIND

Every beat is a recorded event. Every gap in a beat is recorded data.

LENS · FILING

The regulatory record

Blocked-property reports shaped after 31 CFR 501.603, valuation at the freeze block, notice and unwind status, and a verifiable filing-deadline clock: business-day math against a versioned, source-cited federal holiday calendar, with the consulted calendar slice embedded in the record so a verifier recomputes the due date from its own bytes.

For the CCO.

LENS · DEFENSE

The litigation record

The order, the recorded reasonable-particularity determination with its quoted basis, the blast radius, and a decision overlay: privileged narrative on a second, separate chain.

For the GC.

LENS · REGISTER

The standing view

The record read as an inventory across scenarios rather than as a single case.

For the standing blocked-property register.

ARTIFACT · RUN OUTPUTSELF-CONTAINED · SIGNED

A run emits a small, self-contained set of files — the signed evidence pack, the append-only event log, and the checkpoint receipts. The pack embeds the entire event log verbatim, so the report is a view over the log and can never say anything the log doesn't.

THE APPROACH · WHY ISSUER-OWNED

The freeze duty is yours — and it's non-delegable.

In a courtroom it's your reasonableness on trial. So the most credible record is your own — and, better, one whose truth doesn't rest on anyone's word, including ours. A record rented from the screening vendor sitting inside your freeze chain reads as outsourced compliance, and that vendor could be a co-defendant. The intelligence vendors tell you who to freeze. The record of what you did, and why, has to belong to you and survive a hostile reading. That is the product.

VERIFICATION · THE POINT OF THE WHOLE THING

Every claim cites its evidence. Anyone can re-walk it.

Most compliance tooling asks you to trust its output. This is built the other way around: the verifier shares no trust with the producer, and runs offline from the committed bytes.

HASH-CHAINED · SIGNED

Every event is chained to its predecessor and Ed25519-signed. The genesis event commits the signing key into the chain, so a log verifies offline from its own bytes.

CITED, WITH PROOFS

Every figure in the report carries the sequence number and hash of the event it restates, plus a Merkle inclusion proof tying that event to a signed checkpoint.

PROOFS, NOT PROVIDER VALUES

Balances are Merkle-Patricia state proofs re-walked against independently verified block headers — never a bare value an API returned. A failed proof is recorded as a rejection, not discarded.

REFUSE-TO-EMIT

Before writing anything, the assembler hands its own exact output bytes to the independent verifier. Any finding aborts the run. A producer bug cannot vouch for itself.

INDEPENDENT VERIFIER

The verifier is structurally prevented from sharing the producer's code — enforced by a test that parses the package and fails on any disallowed import.

DETERMINISTIC

Same inputs produce a byte-identical record. Reference runs are byte-compared on every build, so drift is a failed build, not a discovery.

INVARIANTSLOAD-BEARING

Corrections never rewrite history. An amendment is a new event pointing back at what it supersedes, and supersession is disclosed on the face of the report.

"Final" is never a single checkbox. Finality is typed per chain — what finality means on one chain is a different value from what it means on another, and the system will not silently conflate them.

DISCIPLINE

The two things that are hard to fake.

PRIVILEGE, PROVABLY
FACTUAL LOGDECISION OVERLAY · PRIVILEGEDevt_00evt_01evt_02evt_03dec_00dec_01dec_02dec_03

references flow one way only

Privileged deliberation, structurally separated.

Privileged deliberation doesn't live in a "restricted field." It lives on a second, separate append-only chain with its own signing key. The privileged chain references factual events; the factual log records nothing about the privileged one — not its contents, not its existence. So a discovery production is simply the factual artifacts, untouched. And it's checkable: a production audit proves the produced set contains zero privileged material, by exact file census plus a structural scan. Not privilege by filtering. Privilege by structure.

REFUSALS ARE EVIDENCE
PROVENATTESTEDNOT DETERMINABLE

An honest absence, recorded.

When the system can't verify something, it records that it couldn't — as structured data, with a reason, committed to the same Merkle checkpoint as everything else. Never fabricated, never silently skipped. It goes further: where a chain makes a proof possible but unimplemented, the record says so; where the chain makes it impossible, the record says that instead. Labelling both the same would misstate what was and wasn't done. An honest record of an absence is itself defensible.

EXERCISED AGAINST REALITY

Three freezes, three different shapes of hard.

The record has been built against three real, public freeze events — chosen because each breaks something the others don't.

PROVEN
ETHEREUM · USDC · 2022

Tornado Cash designation

The full proof gauntlet: verified headers, transaction and receipt inclusion rebuilt locally, and balances cryptographically proven with Merkle-Patricia state proofs — including proving the blacklist flag flipped in state at the freeze block and not at its parent.

The freeze, proven in state.

ATTESTED
TRON · USDT · 2026

OFAC designation

State-proof capture isn't supported on this chain, so nothing is dressed up as proof: every claim is recorded as an explicit, checkpoint-committed refusal, and the balances enter the record as clearly labeled attested facts.

The scenario where the record's job is to say what it did not do.

NOT DETERMINABLE
CONFIDENTIAL-TOKEN WRAPPER · COURT-ORDERED · 2026

Structural refusal, and an unwind

A court order rather than a designation. The only freezable unit was the entire pooled contract, so the blast radius is structural; per-holder balances are encrypted and therefore structurally unknowable, recorded as a refusal. Its court-ordered reversal two days later was captured at equal rigor — the record's first observed unwind.

The scenario that is mostly about what can't be known.

SCOPE · DISCLOSED

The limits, stated plainly.

FreezeScope is an evidence-of-record system in active development, and some of what production will require isn't built yet. These are disclosed properties of the design — recorded in the specs and in the records themselves — not omissions.

  1. 01

    The signing keys in published reference runs are committed test vectors. Signatures prove integrity, not identity. Production key custody plugs in behind a named seam, and the record discloses which trust model produced it.

  2. 02

    Checkpoint anchoring is a local stub — there is no external witness yet. The production implementation refuses to construct rather than pretend to be real.

  3. 03

    Official filing artifacts are not generated. The deadline clock is real and independently verifiable; producing the official workbook or package is gated until authoritative schemas are vendored, because legal formats are never inferred.

  4. 04

    Where a chain doesn't support state proofs, balances are attested rather than proven — and the record says so, per claim.

If any of those four is the thing you'd press on, that's the conversation we want to have.

QUESTIONS

Straight answers.

That's the design goal: no. Every figure in the report cites a hash-chained, signed event with an inclusion proof, and the verification runs offline from the committed bytes — independently of us, our infrastructure, and our data provider.

The freeze is coming. The record shouldn't be improvised.

If you live in this problem — in compliance, in the legal seat, or anywhere close to it — we'd like to talk.

No deck. We’d rather walk you through the record itself — including the four limits above.