Original Title: "Asset Risk Assessment - Membrane Finance (EUROe)"
Original Authors: LLAMARISK, EVMKNOWS
Original Translation: Kxp, BlockBeats
EUROe is a custody stablecoin that complies with the MiCA standard, issued by Membrane Finance, a subsidiary of the blockchain development organization Equilibrium Group. It was officially launched on the Ethereum mainnet on February 1, 2023, and has been deployed on Polygon, Arbitrum, Avalanche, and some testnets. As of now, approximately 1.64 million EUROe have been issued, distributed across four chains: Ethereum mainnet (982,777 EUROe), Arbitrum (96,873 EUROe), Polygon (560,235 EUROe), and Avalanche (25 EUROe).

EUROe On-Chain Supply Status - May 26, 2023 EUROe is an electronic currency issued under the regulatory framework recognized by the European Union. It is regulated by the Finnish Financial Supervisory Authority (FIN-FSA) and can be confirmed by verifying the status of Membrane Finance Oy. In addition, EUROe is fully compliant with the MiCA standard to address new regulations that will take effect in the summer of 2024.
Currently, Membrane Finance only provides direct issuance and redemption services for EUROe to institutions, but anyone can obtain and use EUROe on the secondary market without permission. These channels include DeFi, brokers, OTC trading, or centralized exchanges. This decision aims to reduce the cost and security risks of storing large amounts of customer KYC data, as well as the cost of processing issuance/redemption requests.
Membrane is the sole distributor of EUROe. Membrane's "clients" are institutions that have accounts with Membrane and have undergone due diligence processes, including KYB, AML, CTF, and KYC audits. "End users" refer to anyone who uses EUROe without an account. The following diagram illustrates the issuance/destruction process for white-listed clients applicable to Membrane:

The issuance/destruction operations are handled by EUROe's MINTER_ROLE and BURNER_ROLE, and can be monitored through designated addresses on each chain (Ethereum, Polygon, Arbitrum, and Avalanche). The following chart displays the issuance/destruction events on all chains over time:

Several Ethereum-based destruction events and equivalent issuance events occurred simultaneously, which is likely due to cross-chain operations facilitated by Membrane (for example, 60,000 EUROe were issued to Polygon on March 20, 60,000 EUROe were issued to Arbitrum on April 14, and 10,848 EUROe were issued to Arbitrum on April 25). According to the pricing page, cross-chain operations (excluding issuance/destruction operations) are a free service provided by Membrane.
A few addresses have been responsible for the majority of EUROe issuance to date. Approximately 95% of circulating EUROe is issued by three addresses. The following chart is color-coded based on the different chains (gray=Ethereum, purple=Polygon, blue=Arbitrum).

According to the requirements of the European electronic currency regulations, the reserves supporting electronic currency must be carefully managed by electronic money institutions (EMIs). Key requirements include maintaining a minimum capital of 350,000 euros or a 2% buffer fund based on the average outstanding electronic currency (whichever is higher), separating EMI's own funds from reserves, and protecting reserves through investment in safe and low-risk assets.
Reserves can be held in dedicated bank accounts or invested in safe, low-risk debt securities issued or guaranteed by central governments, central banks, international organizations, multilateral development banks, or regional or local authorities within member countries. In addition, reserves can be invested in debt securities issued by financial institutions or corporations rated AAA to A. Additionally, reserves can be covered by insurance policies or other comparable guarantees to provide an additional layer of security.
As an alternative, EMI can invest in collective investment transfer securities (UCITS) funds that specialize in the aforementioned assets. These funds, managed by institutions such as BlackRock, provide a way to "outsource" reserve management operations. For a more detailed overview of the reserve requirements faced by electronic currency issuers, please refer to the electronic currency section in our Monerium EURe assessment.
Membrane publishes its reserve support status on its website every month and promises to undergo third-party audits every quarter. According to their documentation, they plan to implement "public on-chain reserve proof data" as soon as possible. According to the latest reserve inspection report, the reserves are held in cash in two different banks within the European Economic Area, namely Bank Frick (Liechtenstein) and Osuuspankki (Finland).
Membrane Finance is an authorized electronic currency institution that has been granted the authorization to issue electronic currency under Finnish legislation implementing Directive 2009/110/EC. Membrane Finance Oy is registered in Finland with a registered office address at Meritullinkatu 1, 00170 Helsinki, Finland (trade register number 3236886-2). The company is supervised by the Finnish Financial Supervisory Authority (FIN-FSA).
According to the "Legal Framework for Customer Fund Security" document provided by Membrane, customers are protected by Finnish law in the following areas:
1. EUROe reserves are legally considered as customer funds - Section 26 of the Finnish Payment Institutions Act (297/2010).
2. Customer funds must not be mixed and must be protected in accordance with applicable law - Section 26 of the Finnish Payment Institutions Act (297/2010).
3. Customer funds are protected in the event of Membrane bankruptcy - Chapter 5, Section 6 (120/2004) of the Finnish Bankruptcy Act and Chapter 4, Section 9 (705/2007) of the Finnish Enforcement Code.
4. Customer funds are protected in the event of bankruptcy of the custodial bank in Membrane - Chapter 5, Section 6 (120/2004) of the Finnish Bankruptcy Act and Chapter 4, Section 9 (705/2007) of the Finnish Enforcement Code.
5. Investments in low-risk and liquid securities should be considered as the property of the client in the event of bankruptcy - a general provision related to the aforementioned regulations.
6. Each Membrane client enjoys a maximum deposit guarantee of 100,000 euros in terms of custodian banks - managed by the EU Deposit Guarantee Scheme Directive.
It is worth noting that customer funds are only not protected by the aforementioned regulations in the event of criminal activity or intentional negligence in protecting customer funds by Membrane or its custodian banks, or if regulatory authorities in the relevant jurisdiction suddenly and unpredictably change regulations and established practices.
Currently, more regulatory requirements (Crypto Asset Market Regulations - MiCA) are being developed, which will impose further obligations on tokens (electronic currency tokens) based on legal tender. According to MiCA regulations, these tokens must not only comply with the Electronic Money Directive, but also with requirements such as prudent marketing, risk disclosure, and interest prohibition. Currently, MiCA has not yet come into effect and is expected to be implemented by EU member states in mid-2024. In this regard, Membrane is preparing to comply with future regulatory requirements by issuing their Euro stablecoin under electronic currency tokens.
Like other stablecoins, Membrane Finance must comply with legal and regulatory requirements, and therefore reserves the right to block individual EOA or contracts. According to its access denial policy, Membrane will not deny account access unless for the following reasons:
· Received requests from authorized government agencies, authorities, or regulatory bodies;
· Fulfill the requests of the owners and controllers of the received addresses, and provide sufficient evidence; or
· Membrane believes that denying access is necessary to comply with recognized Finnish or EU laws, regulations, or legal orders.
Membrane uses a series of control mechanisms to maintain its operation, enhance security, and respond to emergencies. These mechanisms are determined by a series of defined roles, with each role being granted different levels of access to the EUROe stablecoin smart contract. Key roles include the PROXYOWNER_ROLE (responsible for contract upgrades), BLOCKLISTER_ROLE (able to assign and remove BLOCKED_ROLE, equivalent to a blacklist), and MINTER_ROLE (the only role with minting permissions). Emergency roles such as PAUSER_ROLE and UNPAUSER_ROLE are also established for emergency situations, while the DEFAULT_ADMIN_ROLE is responsible for overseeing all other roles.

The addresses of role holders on each chain can be found here.
EUROe's smart contracts are managed internally and use security protocols to restrict unauthorized access to key roles. As part of these security measures, Membrane utilizes multi-party computation (MPC) technology provided by Fireblocks. Therefore, privileged roles are displayed on the chain as EOA accounts.
The contract design is upgradable for potential improvements and modifications. Although there is no time lock at the smart contract level for fast adaptability, EUROe may use time locks in its internal operations to increase security (which we cannot verify).
An emergency procedure has been developed, in which BLOCKED_ROLE is assigned as the most common response measure for emergencies or black swan events. Suspending the EUROe stablecoin is an extreme measure to deal with the imminent threat. The governance of EUROe is completely controlled by Membrane Finance, and there is currently no on-chain governance or voting mechanism.
In order to improve operational efficiency, Membrane uses MPC for contract interaction. As this service is provided by an external party and MP computation is done off-chain, the robustness of the system cannot be publicly verified and evaluated. However, it is well known that Fireblocks is one of the largest infrastructure providers in the crypto industry. Fireblocks employs multiple layers of security measures and regularly undergoes penetration testing by third-party companies ComSec and NCC Group to identify and eliminate vulnerabilities. Additionally, Fireblocks has also been awarded SOC 2 Type II certification by Ernst & Young.
The complete audit report can be found on PeckShield's GitHub and Runtime Verification's GitHub. For detailed information on submissions and resolved findings, please refer to this link.
In short, Membrane Finance operates within a sound regulatory framework, complies with Finnish law, and is prepared for the upcoming MiCA requirements. The company demonstrates transparency in reserve management, with reserves held in two well-known banks within the European Economic Area. Operational security measures are also on par with current industry leaders.
Currently, EUROe is not open to retail customers and does not pose a significant problem for the assessment of pool occupancy risk. As long as EUROe is paired with another freely available asset with sufficient liquidity and balance, the risk of occupancy is almost impossible. In addition, it can be assumed that the presence of multiple market makers recruited by Membrane, or more precisely competition, will naturally prevent this from happening.
From a more general perspective, we believe that incentivizing the EUROe pool may be a good step towards enriching and diversifying euro liquidity in DeFi.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia