blockchainsv
News

CertiK Validates Smart Contract Security for DACC ChainFusion Platform

CertiK has completed a security audit of the in-scope smart-contract code behind Digital Asset Clearing Center's DACC ChainFusion™ platform, per a Manila Times report dated August 17, 2026.

Caleb North·updated August 18, 2026

CertiK Validates Smart Contract Security for DACC ChainFusion Platform

The review examined privileged functions, role-based permissions, and access-control logic — the exact surfaces where tokenised-asset code tends to fail silently. The engagement lands as Hong Kong pushes to scale its digital-bond market through tokenisation.

Audit scope

The review examined smart contracts supporting defined on-chain asset-issuance and lifecycle processes. CertiK documented findings and recommendations in a final report. Privileged-function review is the right starting point. Bond tokenisation depends on role-gated mint, burn, freeze, and settlement paths. Role-based permission review comes next. Access-control logic closes the loop. Together, the three categories cover the common attack surface for any issuance and lifecycle contract.

Why the surface area matters

Tokenised bonds run through smart contracts at every step — issuance, ownership records, programmed events, settlement workflows. One misconfigured role can mint new supply, freeze investor balances, or reroute settlement funds. For a system pitched as the direct regulatory interface from inception to distribution, those primitives are the entire product surface.

DACC ChainFusion™ is described as featuring bank-grade hot-cold wallet segregation and real-time KYT/AML transaction screening. The CertiK audit does not validate those operational claims. Operational controls live outside the in-scope contracts. Read the final report to see what was actually tested versus what the announcement copy asserts.

In the release, Serra Wei, co-founder and Chairwoman of the Digital Asset Clearing Center, framed the audit as a foundation for tokenised markets. Yuannan Yang, Director of Security Engineering at CertiK, positioned the work as preparation for mainstream integration of tokenised assets. Both statements are positioning. Neither replaces independent code review by integrators.

Verification checklist

Three signals will tell you whether the audit translated into shipped security, not just shipped marketing.

  • Published report. Demand the full CertiK report, not the announcement summary. Look for the exact contracts audited, the commit hash, and the diff scope. No commit hash, no audit.
  • Findings resolution. High and medium severity issues need public disclosure of remediation before any mainnet exposure. A clean summary with no listed findings is a red flag, not reassurance.
  • Operational separation. Hot-cold wallet segregation and KYT/AML are off-chain claims. Confirm the signer keys, key-rotation policy, and screening vendor integration independently. Smart-contract audit scope does not cover these surfaces.

The platform also picked up Gold in Banking-as-a-Service Innovation at the Juniper Research Fintech Payments Awards 2026. Awards are not audits. Track the report, not the trophy.