Custody
Theo does not take direct custody of user assets. Custody sits with regulated institutional partners:
Standard Chartered Bank — Custodian of the ULTRA fund (thBILL).
Zodia Markets¹ — Institutional execution for thBILL minting/redemption.
FundBridge Capital — Operates the MG999 fund (thGOLD), with security over physical gold inventory.
Smart Contract Controls
Multisig — Sensitive operations (upgrades, role changes) require 3/5 multisig approval.
Emergency pause — A 2/4 multisig can pause minting and transfers during a security event.
Per-block limits — Minting and redemption capped per block to prevent exploitation.
Timelock — Administrative changes go through a delay window before execution.
External audits — Contracts have undergone independent security audits.
Access Control
All minting and redemption requires wallet whitelisting. Only verified participants interact with core contracts.
Operational Security
MPC (multi-party computation) wallets for key management. Role separation across minting, administration, and emergency response — no single party controls all operations.
All DeFi products carry inherent risks including smart contract, counterparty, and operational risk. Full disclosures at docs.theo.xyz.
¹ Zodia Markets is the trading name of Zodia Markets (Jersey) Limited.
