Revolution V2 is coming. A new chain, real proofs, and a verified identity stack. See what's changing

Ecosystem

Compliance-Grade Identity for Real-World Assets

Issuing a token is easy. Deciding who may hold it is hard.

Tokenized real-world assets have moved from pilots to a visible market. The open question is no longer whether a fund share or a Treasury bill can live on a public chain. It can. The question is how every transfer proves that the receiving party is eligible, without copying that party’s personal data into every system it touches.

This post looks at where the market stands, what the rules ask for, and how Revolution V2 specifies an answer: Sigillum (verified identity) with facets proven in zero knowledge.

The market is real, and it is gated

RWA.xyz reports a distributed real-world asset value of $38.54B and 4,831,500 total asset holders. Tokenized U.S. Treasury funds alone show $14.96B in distributed value across 83,706 holders as of 25 September 2026. In May, CoinDesk reported that the tokenized RWA market had “grown more than 200% over the past year”, citing rwa.xyz data.

The largest managers are building here. In the same report, BlackRock filed for two new onchain fund offerings, one with a $3 million minimum. Its BUIDL fund, launched in March 2024, requires “U.S. Qualified Purchaser” status and completion of AML and KYC requirements before a subscription. In August 2026 the SEC’s Division of Investment Management issued a no-action letter that lets Franklin Templeton’s registered funds hold shares of its onchain government money fund.

Look at the holder counts. The BUIDL page lists 107 holders. The asset is on public chains. The investor base is small and screened. That is not a flaw in the product. It is the law working as designed. It also shows where the friction sits.

The rules all ask the same question

Different regimes use different words. They converge on one requirement: know that the counterparty is allowed to be there.

Investor eligibility. The SEC notes that “many of the offering exemptions under the federal securities laws limit participation to accredited investors”. An individual qualifies with, for example, “Net worth over $1 million, excluding primary residence” or income above set thresholds.

Sanctions. OFAC states that “sanctions compliance obligations apply equally to transactions involving virtual currencies” and fiat. Its guidance says screening “may include geolocation, customer identification, transaction screening, and more.”

Stablecoins. The GENIUS Act was signed on 18 July 2025. It subjects stablecoin issuers to the Bank Secrecy Act and requires them to be able to “seize, freeze, or burn payment stablecoins when legally required.” Implementation is under way. In April 2026, Treasury proposed a rule that would require permitted issuers to “adopt and maintain an effective sanctions compliance program.” In August 2026, Treasury proposed rules on stablecoin issuance, offer and sale, with comments due 19 October 2026. The same notice states that the Act’s restrictions on digital asset service providers begin on 18 July 2028.

Europe. ESMA confirmed that “The MiCA transitional period will officially expire across the EU on 1 July 2026.” After that date, an entity serving EU clients without a MiCA licence “must cease offering such services.” Jurisdiction is now a hard boundary for crypto services in the EU.

Tokenized securities trading. On 17 September 2026 the SEC issued an “Innovation Exemption” for venues that trade tokenized NMS stock. It requires smart contracts that are “auditable, public, and deployed on a public, permissionless distributed ledger.” Chairman Atkins’ statement adds that a venue “must set standards of access to allow only certain participants to trade.”

Read those last two together. Public, permissionless rails. Restricted participants. The chain is open. The access check is not.

The bottleneck is the eligibility check

A common approach to access is an allowlist. A transfer agent or issuer runs KYC off chain and adds approved wallets to a list. The token contract checks the list.

That works for a hundred holders. It strains at scale for three reasons.

  1. Data spreads. Each issuer, venue and service provider collects the same documents again. Each copy is a liability.
  2. Checks do not travel. Eligibility proven to one issuer means nothing to the next contract. The investor starts over.
  3. Lists leak. An onchain allowlist tells observers which addresses passed which check.

SEC Commissioner Hester Peirce described the cost of the current model on 23 September 2026: “We build ever bigger data haystacks on the theory that we will find a needle or two inside.” She pointed to a different tool: “A zero-knowledge proof can tell a counterparty ‘Yes, this person meets your requirement’ without that counterparty knowing your name, income, or address.” She listed the kinds of facts such credentials could attest to, including “accredited investor status, absence from sanctions lists.” She noted that her views are her own and not necessarily those of the SEC. In December 2025 she made a similar point: “Zero-knowledge proofs shield private information while proving, for example, that someone is permitted to conduct a given transaction.”

These remarks do not change any rule. KYC and AML obligations remain. What changes is the architecture question. The check still happens. The data does not have to follow the token.

How a zero-knowledge eligibility check works

The pattern has three parts.

  • An issuer verifies once. A regulated party checks documents off chain and issues a credential that states facts, for example “accredited” or “resident in an allowed set”.
  • The holder proves a predicate. When a transfer needs a fact, the holder generates a proof that its credential satisfies the rule and has not been revoked.
  • The contract verifies the proof. The contract learns one bit: the rule is met. It never learns the name, the income or the passport number.

The hard engineering sits in revocation, replay protection and audited circuits. A proof must fail if the credential was revoked. A proof used for one transfer must not be reusable for another.

What Revolution V2 specifies

Revolution V2 builds identity on this pattern. The components have names. Each carries its plain-English meaning.

Sigillum (verified identity) is the verified identity behind a Nomen (name), a human-readable .revo name. The Revolution Name Service verifies the holder off chain with identity data partners and KYC modules. It writes commitments to the chain. It never writes attributes.

Sigillum (verified identity) has levels. Two matter for real-world assets:

LevelMeaningPotestas (permissions) unlocked
L3 EnhancedKYC and AML screening completedAccredited-investor facets, RWA-linked settlement
L3 EntityLegal entity verified with an authorized signatoryMerchant agents, bonded reputation pools

Levels are governance-set. Potestas (permissions) comes from the Sigillum (verified identity) level and the account class. V2 defines Business and Institutional account classes with multisig, policy quorum, hardware or MPC signers and multi-role approvals.

Facets are single provable attributes of a Sigillum (verified identity). The facets relevant to regulated assets are:

  • investor.accredited: the holder is accredited.
  • jurisdiction.in: residence is in an allowed set.
  • jurisdiction.not.in: residence is outside a blocked set.
  • sanctions.clear: the holder has cleared sanctions screening.

The mechanism is specified in the whitepaper. The name service commits each credential as a leaf in a Merkle tree. The root is stored as the identity’s facet root. To prove a facet, the holder generates a zero-knowledge proof that a leaf under the root satisfies the predicate and is not in the issuer’s revocation set. A Proof Verifier contract checks it. Each proof carries a nullifier bound to the settlement it is used for, so it cannot be replayed.

Per identity, the chain stores one facet root, one reputation pointer and per-settlement nullifiers. Nothing else. The design principle is “prove, do not store.”

Data on Ethereum. Revolution V2 is a rollup that publishes its data to Ethereum in blobs. Validium was considered and not chosen. The whitepaper states the reason directly: data on Ethereum is the strongest assurance for RWA, custody and commerce counterparties. A custodian or issuer can recover and verify the chain’s state from Ethereum without relying on a separate data availability vendor.

Roles stay separate. Revolution does not custody assets and does not act as a broker-dealer. Issuers and custodians remain responsible for issuance and custody. Revolution supplies the identity and verification layer those parties can call.

Built versus specified

Precision matters here, so here is the status.

Built and tested in the V2 repository: a ZKsync OS devnet, the staking system, the canonical ERC-4337 EntryPoint v0.8, ERC-7579 modular accounts, a network-run paymaster and its budget.

Specified, not built: the identity layer. Phase 2 of the roadmap delivers the name service on V2 with .revo names, the Facet Registry and Proof Verifier, and audited circuits for human.verified, entity.verified, age.over.18, age.over.21, jurisdiction.in and jurisdiction.not.in. The Phase 2 exit test requires facet proofs to verify on chain with published circuit audits.

investor.accredited and sanctions.clear are in the initial facet list. Facets are governance-set and are added when a transaction type needs them. They are not in the first Phase 2 circuit set.

Not live: Virtus (V2 testnet) launches in Phase 1. There are no users, assets or volumes on V2 today.

Open items: the credential format for circuits must be confirmed with issuers. Data protection treatment of verification data is flagged for legal review, with obligations sitting with the name service as issuer. Every contract and circuit receives an independent audit before mainnet.

What this means for you

For issuers and transfer agents. A transfer rule can ask for a proof instead of a list lookup. “Accredited, and not resident in a blocked jurisdiction, and sanctions-cleared” becomes a set of facet checks. Your KYC process stays yours. The chain holds no personal data from it.

For custodians. State is recoverable from Ethereum. Entity accounts can require multiple signers and role-based approvals.

For investors. Verify once with a regulated party. Prove eligibility to many contracts. Reveal only the fact each contract needs.

For builders. Facets are contract-callable checks. An Agens (agent) acting for a verified holder carries a Mandatum (delegated authority) that never exceeds the holder’s Potestas (permissions), and every action traces back to a Sigillum (verified identity).

This post describes design and regulation. It is not legal advice. Each issuer remains responsible for its own obligations.

What is next

Phase 1 brings Virtus (V2 testnet) online with real proofs settling to Sepolia, the Ethereum test network. Phase 2 ships identity: .revo names, the Facet Registry, the Proof Verifier and the first audited circuits. Accredited-investor and sanctions facets follow when a transaction type needs them, through governance.

The market has shown that assets can move on chain. The next step is proving who may hold them, privately, at every transfer.

Sources

Build on V2.

Virtus (V2 testnet) opens in Phase 1. The SDK and APIs are in the developer docs.