This supplemental comment addresses the absence of technical standards for stablecoin wallet management, credential lifecycle, and state transitions. It recommends a formally defined wallet credential state machine with four states (UNBOUND, ACTIVE, REVOKED, EXPIRED), cryptographic wallet binding via Pedersen commitments, compliance-gated activation, lawful order cascading for freeze and seizure operations, and credential expiration with mandatory re-verification.
ZKProva Inc.
Compliance Technology & Infrastructure
April 8, 2026
National Credit Union Administration
1775 Duke Street
Alexandria, VA 22314
Re: Docket No. NCUA-2026-0265; RIN 3133-AF69 — Notice of Proposed Rulemaking: Investments in and Licensing of Permitted Payment Stablecoins Issuers (GENIUS Act PPSI Licensing Framework for Federally Insured Credit Unions), 91 FR 6531 — Supplemental Comment on Wallet Management and Credential State Machine Standards
Dear Members of the NCUA Board:
ZKProva Inc. previously submitted comments on this proposed rulemaking (Tracking IDs: mnk-icx3-0rd5, mno-0mc6-didw, mno-0qt5-kz5r, mnq-s497-hxgm, mnq-sqc4-isv8). We submit this supplemental comment to address a fundamental gap in the proposed rule: the absence of technical standards for stablecoin wallet management, credential lifecycle, and the state transitions that govern when a member can and cannot hold, transfer, or be issued stablecoins.
ZKProva has developed GeniusComply (deployed at ppsiready.com), a production compliance testing infrastructure platform purpose-built for credit unions preparing for PPSI licensure. As part of this platform, ZKProva has built and deployed a stablecoin wallet management system with a formally defined credential state machine, cryptographic wallet binding via Pedersen commitments, and compliance-gated state transitions. Our comments are informed by direct engineering experience with the technical challenges of wallet lifecycle management in a regulated stablecoin environment.
The proposed rule references wallet management as a compliance obligation (GENIUS Act Section 4(a); NCUA Q12(3)) but does not define what wallet management means technically. Without a defined wallet lifecycle, PPSIs will implement wallet systems with inconsistent security properties, varying levels of member protection, and incompatible approaches to credential issuance and revocation.
Key questions left unanswered by the proposed rule include: (a) what states can a stablecoin wallet occupy, and what transitions between states are permitted; (b) what compliance preconditions must be satisfied before a wallet can receive stablecoins; (c) how are wallet credentials cryptographically bound to the member's identity; (d) what happens to a wallet's credentials when the wallet is frozen or seized under lawful order; and (e) how are wallet credentials revoked, and what is the effect of revocation on the member's ability to transact.
We recommend that the final rule require PPSIs to implement a formally defined wallet credential state machine with the following states and transitions:
States:
UNBOUND. The initial state of a newly created wallet. The wallet has been associated with a member and assigned a blockchain address, but no compliance credentials have been issued. A wallet in the UNBOUND state cannot receive, hold, or transfer stablecoins.
ACTIVE. The wallet has been activated and compliance credentials have been issued. The member has completed all required preconditions — including consumer disclosure acknowledgment, OFAC screening, and AML risk tier assignment. A wallet in the ACTIVE state can receive, hold, and transfer stablecoins, subject to real-time AML threshold enforcement.
REVOKED. The wallet's credentials have been revoked — either by member request, by PPSI action (e.g., due to compliance failure), or by lawful order (freeze or seizure). A wallet in the REVOKED state cannot initiate new transactions. Depending on the reason for revocation, existing balances may be frozen in place or transferred under lawful authority.
EXPIRED. The wallet's credentials have reached their expiration date without renewal. A wallet in the EXPIRED state cannot initiate new transactions until credentials are renewed through the activation process.
Permitted transitions:
Prohibited transitions:
The state machine should be enforced programmatically — not as a policy that staff must follow, but as a technical control in the wallet management system that rejects invalid state transitions. Invalid transition attempts should be logged as compliance events.
The final rule should require that stablecoin wallets be cryptographically bound to the member's identity through a commitment scheme that prevents wallet reassignment and provides tamper-evidence.
We recommend Pedersen commitments for wallet binding. At wallet creation, the PPSI computes a commitment of the form:
C = r * G + H(wallet_address, credential_id, expiry) * H
where r is a random blinding factor, G and H are generator points on an elliptic curve, wallet_address is the member's blockchain address, credential_id is a unique identifier for the credential, and expiry is the credential expiration timestamp. The commitment C is stored on the wallet record; the blinding factor r and the private key material are encrypted (AES-256-GCM) and stored separately.
This binding ensures that: (a) the wallet address cannot be changed after binding without invalidating the commitment; (b) the credential expiration is cryptographically fixed at binding time; (c) the binding can be verified by any party with the public commitment and the opening values; and (d) the member's private key material is protected by authenticated encryption.
The final rule should specify the compliance preconditions that must be satisfied before a wallet can transition from UNBOUND to ACTIVE. We recommend the following preconditions, evaluated programmatically at activation time:
1. Consumer disclosure acknowledgment. All three mandatory GENIUS Act Section 6 disclosures (NOT_INSURED, NOT_LEGAL_TENDER, REDEMPTION_RIGHTS) must be delivered to and individually acknowledged by the member.
2. OFAC screening. The member must have a current (non-expired) OFAC screening with a CLEAR result. A screening that returned MATCH or ERROR should block activation until the match is resolved.
3. AML risk tier assignment. The member must be assigned an AML risk tier (low, medium, or high) based on initial risk assessment. The tier determines the monitoring intensity and threshold parameters that will apply to the wallet's transactions.
4. PPSI issuer status. The PPSI issuer associated with the wallet must be in ACTIVE status. Wallets associated with PENDING, SUSPENDED, or REVOKED issuers should not be activatable.
If any precondition is not met, the activation attempt should be rejected with a specific error identifying which preconditions are missing. This enables the member (or the member's credit union) to address the deficiency before retrying.
The final rule should specify the effect of lawful orders (freeze and seizure) on wallet credentials:
1. Freeze. When a wallet is frozen under lawful order (e.g., OFAC designation, court order, law enforcement request), the freeze should cascade to all active credentials on the wallet. Specifically: (a) the wallet's credential state should transition to REVOKED; (b) all active wallet credentials should be marked as revoked; (c) the freeze should be recorded with the order reference (case number, court order identifier, or OFAC designation reference) for audit trail purposes; and (d) the member should be unable to initiate any transactions from the wallet, including transfers, burns, or redemptions.
2. Seizure. When a wallet's funds are seized under court order, the seizure should: (a) execute a forced transfer of the specified amount from the member's wallet to a designated government or custodial wallet; (b) record the seizure with the order reference; (c) cascade credential revocation as with freeze; and (d) verify that the seizure amount does not exceed the wallet's balance.
3. Unfreeze. When a freeze order is lifted, the wallet should be unfrozen but credentials should not be automatically reissued. The member must go through the activation process again, ensuring that all compliance checks are current. This prevents a scenario where a previously frozen wallet is restored to active status with stale OFAC screening or expired AML risk assessment.
The final rule should address credential expiration. We recommend that wallet credentials have a maximum validity period (e.g., 365 days from issuance), after which the wallet transitions to EXPIRED status and the member must complete the activation process again — including fresh OFAC screening and AML risk tier assessment.
Automatic renewal should not be permitted. The purpose of credential expiration is to force periodic re-verification of the member's compliance status. If credentials renewed automatically, the re-verification would be bypassed, potentially allowing a member whose circumstances have changed (e.g., who has been added to the OFAC SDN list since the last screening) to continue transacting.
The PPSI should provide advance notice to members before credential expiration (e.g., 30 days before expiry), enabling proactive renewal and minimizing disruption to the member's stablecoin activities.
ZKProva has implemented the wallet credential state machine described above in production as part of the GeniusComply platform (ppsiready.com). Our implementation includes: four wallet states (UNBOUND, ACTIVE, REVOKED, EXPIRED) with programmatically enforced transitions and invalid transition rejection; Pedersen commitment binding using the secp256k1 curve with AES-256-GCM encrypted private key storage; compliance-gated activation requiring disclosure acknowledgment, OFAC screening, AML tier assignment, and issuer status verification; lawful order cascading with freeze, seizure, and unfreeze operations that automatically revoke credentials and record order references; credential expiration with 365-day default validity and advance renewal notification; and comprehensive audit logging of all state transitions and invalid transition attempts.
This implementation demonstrates that the standards recommended in this comment are technically achievable using standard cryptographic libraries and database infrastructure.
We respectfully request that the NCUA include the following wallet management standards in the final rule:
Wallet management is the operational layer of PPSI compliance — the mechanism through which compliance requirements are enforced in real time, at the point of transaction. The proposed rule establishes the obligation to manage wallets compliantly; the final rule should establish how. A formally defined state machine provides deterministic, auditable, and examiner-verifiable wallet behavior. The standards recommended in this comment are technically proven, operationally deployed, and designed to give NCUA examiners confidence that wallet operations are controlled, compliant, and consistent across all credit union PPSIs.
ZKProva Inc. welcomes the opportunity to provide technical demonstrations, implementation specifications, or testimony in support of these comments.
Respectfully submitted,
Viswanadha Pratap Kondoju
Founder & CEO
ZKProva Inc. (incorporation pending)
Disclaimer: This page is an informational archive of a public regulatory comment. It does not constitute legal advice. ZKProva Inc. is not a law firm and no attorney-client relationship is created. Not affiliated with, endorsed by, or sponsored by the NCUA, OCC, or U.S. Department of the Treasury.