Skip to whitepaper
City Protocol

City Protocol / Whitepaper

Infrastructure for Onchain Structured Products

Version 2.125 September 2026
Start reading

Abstract

City Protocol is building a universal infrastructure and marketplace for structured products that align with different risk profiles and investment goals. The protocol is a structured-product infrastructure that enables users to enter a variety of structured products across decentralized finance (DeFi) and real-world assets (RWA), built on existing blockchains. Curator Vaults provide access to institutional yield strategies: in each vault, an independent third-party institutional curator executes a strategy inside a mandate that the contracts enforce, and participants hold Receipt Tokens valued at net asset value (NAV) per share and bear the full risk of loss. Onchain Token Portfolios (OTPs) are rules-based baskets of tokenized equities that one transaction buys into the participant’s own onchain account; past performance is no indication of future results. Venzo is the flagship application for both. $CIT launches on Ethereum mainnet at the token generation event (TGE) with a fixed supply of 10,000,000,000 and will be bridged to Arbitrum, Base and BNB Smart Chain ahead of listing. It provides governance, product benefits, service payments and ecosystem incentives, and it confers no claim on product assets or protocol revenue.

Keywords: structured products; tokenization; vault infrastructure; model portfolios; decentralized finance

1 Introduction

1.1 What City Protocol is

City Protocol is building a universal marketplace for structured products that align with different risk profiles and investment goals. The protocol is a structured-product infrastructure that enables users to enter a variety of structured products across DeFi and RWA (issuance and operation, tokenization, vault infrastructure), built on existing blockchains, and it packages third-party strategies into products that eligible users, subject to KYC/KYB checks, jurisdictional restrictions and product-specific eligibility, can access from a self-custodied wallet.

City Protocol offers two products. Curator Vaults provide access to institutional yield strategies. Onchain Token Portfolios (OTPs) are rules-based baskets of tokenized equities that one transaction buys into the participant's own onchain account; past performance is no indication of future results. Venzo (app.venzofinance.com) is the flagship application through which users subscribe to both. As at September 2026, five Curator Vaults are live and accepting deposits, three Index OTPs are live, on BNB Chain powered by bStocks and on Base powered by Coinbase Tokenized Stocks, and Venzo has reached considerable total value locked (TVL).1

1.2 The problem

Structured products and exchange-traded funds (ETFs) are two of the largest packaged-investment categories in traditional finance. Structured products carried an estimated US$2.55 trillion of outstanding notional in 2026 [1], and global ETF assets reached a record US$23.11 trillion at the end of July 2026 [2]. Access to both is gated by high minimum investments, private-banking and brokerage relationships, and distribution rules that differ by jurisdiction. Onchain capital is global and settles continuously in stablecoins, yet each issuer that brings a strategy onchain rebuilds the same stack: investor eligibility, subscription and redemption workflows, NAV calculation and oracle controls, audited contracts with role-based permissions and emergency pauses, methodology and lifecycle controls, and the reporting that shows users what a product holds, how it is valued and when it can be exited. When each issuer builds this stack alone, launches are slow, security work is duplicated, reporting is inconsistent and the range of products available to users stays narrow.

1.3 Existing onchain infrastructure

City Protocol builds on an asset and settlement layer that is already in production. Four developments make onchain structured products practical in 2026.

  • Real-world assets: Tokenized real-world assets reached US$38.4 billion at 1 September 2026, and tokenized equities US$2.53 billion across 3,906 products, with US$26.8 billion of monthly transfer volume [3]. Treasury funds, private credit and listed shares now exist as tokens that settle onchain around the clock.

  • Stablecoin settlement: A stablecoin supply above US$300 billion gives every subscription a global settlement asset [3], and the Federal Reserve Bank of Kansas City estimates that roughly a fifth of stablecoins sit idle in wallets [4].

  • DeFi primitives: Tokenized-vault standards define shares and asynchronous requests [5, 6, 7], account abstraction lets a portfolio sit in a programmable account that its owner controls [8], and onchain lending, trading and price-feed infrastructure supplies the building blocks of each strategy.

  • Regulation: MiCA sets an EU framework for crypto-assets [9], and on 17 September 2026 the US Securities and Exchange Commission issued an innovation exemption under which qualifying venues may trade tokenized US-listed stocks onchain for five years, provided each token carries the same rights as the underlying share [10].

What remains missing is the product layer that packages these assets with mandates, methodologies, valuation, eligibility and lifecycle controls, and City Protocol supplies it.

1.4 How City Protocol differs

City Protocol turns the manufacturing of structured products into shared infrastructure: issuers define the mandate or methodology, and the protocol supplies the machinery that makes it verifiable, governable and distributable. Lower manufacturing cost brings more issuers, and more issuers widen the range of products a user can reach from one wallet.

  • Two architectures under one layer: For vault infrastructure, an operator publishes a vault such as market-neutral trading strategy, credit or lending, run in Curator Vaults under contract-enforced mandates. For OTP, exposures that consist of holding a defined basket run as OTPs in the participant’s own wallet account.

  • Curator-bound execution: The curator or issuer defines the mandate, and strategy managers act only within the allowlisted assets, venues, actions and caps that the contracts enforce.

  • Verifiable valuation and state: A NAV update takes effect only after an authorized reporter quorum signs it and it passes freshness and deviation checks. Deposits, redemptions, fees, NAV reports and strategy debt are recorded onchain and indexed.

Table 1: Two routes to a packaged strategy.

Offchain structured products and ETFs

City Protocol

Access

Brokerage or private-banking relationship, minimum tickets and local distribution rules

A wallet; many products through Venzo, with eligibility applied at subscription

Manufacturing

An issuer-specific legal and operational stack

A shared Issuance & Operation Layer over tokenization and vault infrastructure

Product forms

Notes, funds and exchange-traded products

Pooled Curator Vaults and self-custodied OTPs

Exit

Issuer or market-maker liquidity in market hours

Liquid or epoch-based settlement for vaults; single-transaction exit for OTPs

2 Products

2.1 Curator Vaults

Curator Vaults provide access to institutional yield strategies. A Curator Vault pools participant deposits in a vault contract, and a named, independent curator runs one strategy inside an approved mandate that the contracts enforce. The curator is responsible for the vault’s mandate, disclosures and compliance, and the display of a vault on Venzo is not an offer, solicitation or recommendation. Residents of the Republic of Korea can access only crypto-only Curator Vaults, as defined and marked in Table 2. Curator Vaults with exposure to private credit or other real-world assets are not available to them, and access to those vaults from Korea is blocked at the interface. The participant deposits stablecoins, receives Receipt Tokens priced at NAV per share and redeems through the vault’s liquid or epoch-based settlement window. The return comes from the strategy, such as lending interest, funding income, credit spreads or arbitrage spreads. Each vault carries a risk of partial or total loss, and participants must review the mandate, fees, redemption terms and risk disclosures before committing capital.

Table 2: Curator Vaults live and accepting deposits, September 2026.

Curator Vault (curator)

Strategy type

Available in Korea

Delta-Neutral Prime USD (Liquid Alpha)

Market-neutral DeFi strategies

Yes

Credit Strategy (JPEG Trading)

Credit strategy that lends at contractual rates to underlying borrowers; returns to participants are variable, are not guaranteed and may be negative

No

AFUSD Private Credit (Affinity)

Private credit

No

Pro Lend PLUS (Bitlend Pro)

Lending

No

Ergodic Cross-Exchange Arbitrage (Ergodic Trading)

Cross-exchange arbitrage

No

Each vault sets and discloses its own economics.

A crypto-only Curator Vault holds, lends against and earns from crypto-assets only, with no exposure to real-world loans, receivables, securities or tokenized securities. Only crypto-only vaults are available to residents of the Republic of Korea. If a vault’s mandate changes to add real-world exposure, access from Korea is blocked before the change takes effect.

2.2 Onchain Token Portfolios

Onchain Token Portfolios (OTPs) are rules-based baskets of tokenized equities that one transaction buys into the participant's own onchain account; past performance is no indication of future results. An OTP is a published, rules-based model portfolio. At subscription, one transaction buys the constituents at the weights the methodology sets and delivers them into the participant’s own onchain account, where City Protocol holds no assets, keys or permissions, it is completely non-custodial. Exit takes one transaction, and any constituent can be sold, transferred or pledged on its own. The return is the market performance of the constituents.

OTPs come in three types (Table 3). The constituents of the live range are tokenized equities.

Table 3: OTP types.

Type

What it holds

Status

Index OTP

A defined index basket, bought at the weights the methodology sets; the list changes only when the published constituent rule adds or drops a name, and the live Index OTPs hold fixed lists. On BNB Chain, powered by bStocks, the Magnificent Seven Index OTP buys Alphabet, Amazon, Apple, Meta, Microsoft, Nvidia and Tesla at one seventh each. On Base, powered by Coinbase Tokenized Stocks, the Fantastic Four Index OTP buys Alphabet, Apple, Meta and Nvidia at one quarter each, and the Tesla–SpaceX Index OTP buys Tesla andSpaceXat one half each.

Three live since September 2026

Guru OTP

The disclosed positions of well-known managers, tracked from third-party public sources such as quarterly Form 13F filings; the list will change only when a new filing or a disclosed trade is published, and each change will mirror that disclosure.

Go live in Q4 2026

Thematic OTP

The names that meet a published theme rule; the list will change when a name enters or leaves the rule.

Go live in Q4 2026

The Index OTP names describe the companies each basket holds, and Magnificent Seven is a market term for seven large US technology companies. No OTP carries any affiliation with, or endorsement from, a person, company or manager that its name or methodology refers to. Each OTP inherits the eligibility restrictions of its constituents. The live Index OTPs are available only to eligible participants outside the United States and the other restricted jurisdictions listed in the Terms & Conditions [13]. OTPs are not offered to residents of the Republic of Korea unless the OTP and its distribution are authorised as required under Korean law; until then, access from Korea is blocked at the interface.

2.3 How the two products compare

A Curator Vault suits a return that an operator must produce and exposures that need pooling to work, such as capacity-limited strategies. An OTP suits a defined basket held directly, where ownership, per-asset control and transparency matter most. Both architectures are non-custodial, both enforce a published rule set, and both publish their operating history (Table 4).

Table 4: Curator Vaults and OTPs compared.

Curator Vault

Onchain Token Portfolio

Participant holds

Receipt Tokens, a claim on a pooled vault

The constituent assets, in the participant’s own account

Holdings decided by

The curator, within the approved mandate

The published methodology; the list changes only on the source or rule it names

Source of return

Strategy income: lending interest, funding, credit spreads and fees

Market prices of the constituents

Accounting

NAV per share, struck at each settlement

Token balances, readable onchain

Exit

Liquid or epoch-based redemption

One transaction back to one asset, or any constituent sold on its own

Dominant risk

Strategy loss, or a contract failure affecting the pool

Constituent prices falling; onchain execution risk; liquidity risk

2.4 Venzo

Venzo is the flagship application where users access Curator Vaults and OTPs by strategy type and liquidity terms, review each product’s mandate or methodology, fees and risk disclosures, subscribe from a self-custodied wallet, monitor positions and exit. Venzo also runs the Polis Points seasons, which include a single-layer referral component. Polis Points are loyalty points that record participation: they have no cash value, cannot be sold, transferred or exchanged for cash, and carry no entitlement or promise to receive $CIT or any other asset. Participants earn points only on products available in their jurisdiction. Residents of the Republic of Korea earn points only for their own eligible positions: referral and promotional quest points are not available to them.

3 Product mechanics

3.1 System architecture

City Protocol connects a yield source to a user through four layers (Figure 1). Tokenization as a Service (TaaS) turns a fund, strategy, credit book or managed account into an onchain product with a defined token representation, investor eligibility, NAV monitoring and attestations. Vault as a Service (VaaS) provides audited vault contracts, including white-label vaults for partners, that hold participant capital, enforce the mandate, track NAV and handle redemption. The Issuance & Operation Layer packages vault exposures and tokenized assets into products with a methodology, reporting, fees, rebalancing and a lifecycle state, through either the Curator-Vault Architecture or the OTP Architecture. Venzo delivers each product to users.

The modules exchange state as well as capital. When a component is paused, impaired, stale or ineligible, every product that holds it updates its status, and the affected subscriptions, redemptions or rebalancing pause until the component recovers; OTP participants keep the ability to exit throughout.

City Protocol system architecture showing participants, Venzo, the issuance layer, vaults, tokenization, and yield sources

Figure 1: The City Protocol stack, from yield source to user.

3.2 Curator Vaults

3.2.1 Contract design

The Curator Vault contracts implement tokenized-vault share accounting with asynchronous request flows, following the ERC-4626, ERC-7540 and ERC-7575 interface standards [5, 6, 7]. Each vault is its own set of contracts with its own mandate, and every action executes atomically: a deposit, redemption, settlement or strategy execution either passes every check or reverts as a whole (Table 5).

Table 5: Curator Vault modules.

Module

Function

Vault contract

Accepts deposits and redemption requests, issues and burns Receipt Tokens and enforces the core vault rules, in one of four liquidity configurations.

Access policy

Runs in open mode or policy mode, with allowlists, denylists or signed authorizations bound to the account, the vault, the network and an expiry.

Limit module

Enforces the configured caps on total assets and pending deposits, and any configured minimum deposit or redemption size.

Report oracle

Accepts NAV reports only from authorized reporters under a configurable quorum, with freshness, epoch-timing and price-deviation checks.

Settlement module

Prices each epoch against an eligible NAV report, snapshots the price, fees and protocol split, and makes settled amounts claimable.

Fee manager

Accrues fees within hard caps and mints them as vault shares to the fee receiver.

Strategy manager

Allocates idle assets to allowlisted strategies within per-strategy and total debt caps, executing only approved actions on approved targets.

Vault registry

Records each vault’s address, asset, strategy manager, oracle, type and status as the canonical discovery source.

3.2.2 Subscription, settlement and redemption

Subscriptions and redemptions run in epochs (Figure 2), so every request in an epoch settles at one valuation point on the same terms.

  1. Request: The participant deposits an accepted asset or transfers Receipt Tokens for redemption, and the vault checks access, limits, product status and pause state.

  2. Epoch close: At the end of the window, the epoch closes to new requests.

  3. Valuation: The valuation provider proposes the NAV and authorized reporters sign it; the report takes effect only when it meets quorum and passes the freshness, timing and deviation checks.

  4. Settlement: The settlement module prices the epoch and snapshots the report identifier, price, fees, protocol split and timestamp. Deposits mint Receipt Tokens, and redemptions fix the settlement assets owed.

  5. Claim: Once idle settlement assets cover the whole epoch, participants claim, and redeemed Receipt Tokens are burned.

Curator Vault deposit and redemption requests passing through valuation and settlement

Figure 2: Epoch-based subscription and redemption in a Curator Vault.

Deposit requests can be cancelled before settlement where the configuration allows it, and redemption requests are final once submitted. Vaults with highly liquid assets also offer liquid redemption from idle liquidity. At a valuation point t, NAV and the share price are

Net asset value equals assets minus liabilities and fees; share price equals net asset value divided by receipt tokens outstanding (1)

where At is the verified value of the vault’s assets, Lt its liabilities, Ft its accrued fees and Nt the Receipt Tokens outstanding. Liquid onchain strategies derive NAV from onchain positions and price feeds; RWA-backed and offchain strategies draw on administrator reports, reserve data, collateral values and third-party verification. Two properties of settlement protect every participant in an epoch.

Proposition 1 (Settlement finality). Once an epoch has settled, no later NAV report, fee change or strategy event alters the Receipt Tokens minted or the settlement assets owed for that epoch.

Proof. Every claim on the epoch derives from the settlement snapshot of report identifier, price, fees, protocol split and timestamp. Later reports, fee changes and strategy events update state that settled claims do not read.

Proposition 2 (Funded claims). A redemption claim becomes payable only when the vault holds idle settlement assets for the entire settled epoch, and assets reserved for claims cannot be allocated to a strategy.

Proof. The settlement module marks an epoch fulfilled only after verifying that idle settlement assets cover it. Claimable redemption assets are excluded from the assets available to the strategy manager, so no allocation can draw on them.

3.2.3 Strategy execution

The curator defines the mandate: allowed assets, venues and strategies, allocation limits, drawdown threshold, leverage limit, liquidity requirement, minimum collateralization and redemption period. The strategy manager makes tactical decisions inside that envelope, while structural changes stay with governance roles. Execution is bounded at contract level through strategy allowlists, debt caps, approved targets and actions, and balance-delta verification after every action; the whitelist confers execution rights only.

When a mandate is executed on a centralized trading venue, we use an independent attestation provider to verify the assets through a read-only API and present the results in a user-accessible dashboard. Exposure to each venue is capped at the vault level and continuously monitored against the mandate. Proof-of-deployment records and independent reserve verification provide additional assurance over assets held at the venue.

3.2.4 Fees

Fees are encoded in each vault’s contracts and disclosed before subscription. At each settlement, the vault mints new shares for the fees owed to the fee receiver, so fees are paid in shares. Each curator will set its own fees for each vault. City Protocol only acts as the infrastructure provider for vault and will support curators to publish strategies with its vault infrastructure.

3.3 Onchain Token Portfolios

3.3.1 Contract design

An OTP applies token balances to onchain portfolios. Each methodology as a rules-based, non-personalised rule set is published. It provides no individual investment advice or discretionary management, and OTPs are not offered to residents of the Republic of Korea unless authorised as required under Korean law. Three properties define the structure.

  • Direct ownership: Each participant’s constituents sit in a smart account that the participant owns, never commingled with other participants’ assets.

  • Rules-based lists: The methodology names the constituents, the weights at purchase and the third-party public source or published rule that can change the list. It is published and versioned before the product opens.

  • Single-transaction entry and exit: One transaction converts stablecoins into the full basket at the methodology’s weights, and one transaction reverses it.

A participant’s position rests on two layers. At sign-in, the participant receives a self-custodial embedded wallet whose private key is split into two encrypted shares that combine only at the moment of signing, so neither City Protocol nor its wallet-infrastructure provider holds the key. At first purchase, a smart account following the ERC-4337 standard [8] is deployed for the participant and owned by that wallet, and every constituent sits in that account (Table 6).

Table 6: OTP modules.

Module

Function

Status

Portfolio registry

Records live portfolios, constituent lists, methodology versions, fee schedules, eligibility policies and lifecycle status.

In operation

Methodology

Holds the published rule set: the constituents, the weights at purchase and the source or rule that can change the list.

In operation

Account factory

Deploys each participant’s smart account, owned by the participant’s wallet from creation.

In operation

Eligibility policy

Applies jurisdictional rules, allowlists and product-specific access requirements at subscription.

In operation

Exit router

Converts the basket back to one asset in one transaction, or exits part of the portfolio down to a single constituent.

In operation

Disclosure and lifecycle

Publishes the methodology, constituents, list changes, fees and risk disclosures, and manages launch, pauses and retirement.

In operation

Delegation module

Will record the policy that scopes each signer a participant adds to their account.

In operation

Rebalancing Executor

Will apply each published list change inside every enrolled account as a session signer bound to that policy.

Next phase

Basket Execution Router

Will settle the legs of each list change as one price-checked atomic batch.

Next phase

3.3.2 Subscription and exit

At subscription, the eligibility policy is checked and one transaction acquires every constituent at the methodology’s weights, delivering the assets into the participant’s smart account (Figure 3). Subscription settles within that transaction. To exit, the participant converts the basket back to one asset in one transaction or sells any constituent on its own. Exit draws on holdings the participant already owns, so it is available at any time, including while a product is paused.

Proposition 3 (Participant custody). Under the OTP Architecture, every constituent of a portfolio sits in the participant’s own smart account from subscription to exit, and only a transaction authorized by the participant can move an asset out of that account.

Proof. The account factory deploys each smart account with the participant’s wallet as its owner, and the subscription transaction delivers every constituent to that account. City Protocol holds no key and no signing permission over the account, so the account executes only the transactions that its owner authorizes, including exits and single-constituent sales.

The next phase will preserve this property. A participant will be able to add the Rebalancing Executor to the account as a session signer, a limited signing key bound to a policy, through a one-time consent. The policy will allowlist the constituent contracts and the Basket Execution Router, permit only the swap and approval functions that the router needs, and deny every other request by default, including any transfer to another address and any key export. The policy will be enforced inside a trusted execution environment before any signature is produced, and the participant will be able to remove the signer at any time, which will stop automation immediately and leave every token in the account.

Onchain Token Portfolio purchase, participant account, methodology, and list change flow

Figure 3: The OTP account model. Constituents stay in the participant’s own smart account, and the list changes only on the source or rule that the methodology names. Components drawn dashed arrive with the next phase.

3.3.3 Weights and list changes

An OTP position is the set of token balances in the participant’s account, so the portfolio reports its composition directly. For constituent i with balance bi and price pi(t) at time t, the current weight is

Constituent weight equals its balance times its price divided by the total value of all constituents (2)

The methodology sets the weights at purchase, for example one seventh each for the Magnificent Seven Index OTP. Between list changes, the balances bi change only through the participant’s own transactions, so the weights otherwise move with prices alone. After purchase, the weights follow the market and are left to follow it: nothing is sold because a name grew, and nothing is bought because a name lagged.

The constituent list changes only on the third-party public source or the published rule that the methodology names. An Index OTP changes when its published constituent rule adds or drops a name. A Guru OTP will track a third-party public source, such as a manager’s quarterly Form 13F filing, and will change when a new filing or a disclosed trade is published; each change will mirror that disclosure, and every other position will stay as it is. A Thematic OTP will change when a name enters or leaves the theme’s published rule. Every change is published on the product page before it executes and recorded on the portfolio’s Rebalances tab. Changes are infrequent by design: quarterly for a portfolio that tracks Form 13F filings, and rarer for an index.

The live Index OTPs hold fixed lists, so there is nothing to apply before the next phase. In the next phase, the Rebalancing Executor will apply each published change inside every enrolled account, and the Basket Execution Router will settle the legs as one atomic batch: each leg’s quote will be checked against a reference market and held within a slippage cap, and the batch will settle in full or not at all. Execution will halt when a price feed is stale or a constituent is paused, impaired or unbacked. The Guru OTP and Thematic OTP types arrive with that phase.

3.3.4 Retirement and fees

When an OTP is retired, subscriptions and published list changes stop, and each participant keeps every asset held in their own account; City Protocol publishes notice before a portfolio is retired. The OTP fee is 0.1% of buy and sell volume, and the full fee schedule is disclosed before subscription.

3.4 Issuance & Operation Layer

The Issuance & Operation Layer standardizes the lifecycle of both product types through seven stages: mandate, validation, issuance, reporting, subscription, rebalancing and exit. Issuers define the mandate or methodology, and the layer supplies the registry, component validation, issuance, methodology enforcement, reporting, primary-market handling, eligibility, disclosure and lifecycle management around it. Curator-Vault products report product-level NAV. For an OTP, the layer reports onchain composition, rebalancing means a list change on the named source or rule, and exit leaves the holdings with participants. Component whitelisting restricts every product to approved components, and status propagation updates a product automatically when a component is paused, impaired, expired or ineligible.

3.5 Tokenization and verification

TaaS defines what a token represents, such as a vault share, a fund share class or an RWA-backed yield position, and sets its transferability by asset, jurisdiction and distribution channel. The NAV monitoring oracle validates pricing inputs and reserve data, checks deviation thresholds and publishes the validated value onchain. The attestation engine links product claims to proof of reserves, proof of deployment, NAV report hashes and settlement records, publishing verification results while keeping confidential account data private.

4 Role of the token

4.1 Token overview

$CIT is the native token of City Protocol. $CIT launches on Ethereum mainnet. The full supply of 10,000,000,000 $CIT was minted once on the canonical Ethereum mainnet contract before TGE, and the token will be bridged to Arbitrum, Base and BNB Smart Chain ahead of listing; bridging moves existing tokens between networks while the combined supply stays fixed (Section 8).

Table 7: $CIT at a glance.

Item

Detail

Name and ticker

City Protocol, $CIT

Token standard

ERC-20, 18 decimals

Total supply

10,000,000,000 $CIT, minted in full before TGE

Canonical contract

0xfdB0f0962C3dB4664a5eadE96999C7d4F0f53d89 (Ethereum mainnet)

Bridged networks

Arbitrum One, Base and BNB Smart Chain;

TGE

Q4 2026, by direct listing with no public sale

Issuer

Primary Creative Limited, British Virgin Islands

4.2 Where the token sits

City Protocol’s products run on stablecoins and their own underlying assets: a Curator Vault participant holds Receipt Tokens, and an OTP participant holds the constituents directly. $CIT sits one level above, at the protocol that issues, operates and distributes the products, and connects to them through governance, product benefits for holders, service payments, ecosystem incentives (Section 5). Every Curator Vault and OTP accepts eligible participants on the same terms whether or not they hold $CIT.

4.3 Allocation

All allocations will be public and will be shared in the separate link by the foundation.

5 Token utility

5.1 Utilities and access

Table 8 lists what $CIT is used for and how holders access each utility. Governance and the interface fee discount activate three months after TGE.

Table 8: $CIT utilities.

Utility

What it provides

How holders access it

Governance

Proposals and token-weighted votes on protocol parameters, fee structures and the product roadmap (Section 6)

Holding $CIT in a self-custodied wallet on a supported network; voting instructions are published when governance activates

Interface fee discount

A discount on Venzo interface fees for holders, with no effect on any product's yield, NAV or returns

Holding $CIT under the eligibility terms published at activation

Service payments

Payment for eligible services across the stack, with partial fee discounts

Payment for eligible services in $CIT

Ecosystem incentives

Ecosystem grants, liquidity programmes and growth campaigns under terms published before each programme. Rewards distributed solely on ecosystem participation.

Participation in an eligible programme and a claim through the official website

5.2 What $CIT does not provide

$CIT is a utility and governance token. Holding or using $CIT provides none of the following rights or protections.

  • Ownership or control: $CIT confers no share, equity, membership or other ownership interest in Primary Creative Limited or any affiliate, and no right to take part in their management.

  • A claim on product assets: $CIT gives no claim on, and no decision rights over, the assets held in any Curator Vault, OTP account or other City Protocol-powered product.

  • Revenue, profit or income: Holders have no entitlement to protocol revenue, fees, profits, dividends, interest or any other distribution.

  • Redemption or repurchase: No party undertakes to redeem, repurchase, buy back or burn $CIT using protocol revenue, or to support its market price or liquidity. Governance cannot direct protocol revenue, fees or treasury assets to $CIT holders or to buybacks or burns, and no reserve of assets backs the token.

  • A guaranteed return: $CIT confers no guaranteed return.

  • Investor protection: $CIT is not covered by any investor compensation scheme or deposit guarantee scheme.

6 Governance

6.1 Who makes decisions

Decisions in City Protocol sit at four levels, each with its own scope and execution path (Table 9).

Table 9: Decision levels in City Protocol.

Level

Who decides

Scope

How decisions take effect

Protocol

$CIT holders, by token-weighted vote

Protocol parameters, fee structures within the contract caps and the product roadmap

Passed proposals are executed through the multisig and timelock controls that hold protocol roles. The multisig executes every passed proposal unless execution would breach applicable law, the bounds written into the contracts or an active security response, and it publishes its reasons whenever it does not execute.

Operations

The developer of City Protocol

Contract deployment, role assignment, registry records, oracle and strategy policy, emergency response

Multisig approval, with high-impact changes passing through the timelock

Product

Curators and issuers

Mandates, component universes, methodologies, fees within the caps and liquidity terms

Product configuration; methodology changes are versioned and published before they take effect

Account

Each OTP participant

Every transaction from the participant’s own smart account and, from the next phase, whether to add the Rebalancing Executor as a signer

Owner signature; from the next phase, removal of a signer will take effect immediately

6.2 What governance covers

$CIT governance covers the protocol: its parameters, its fee structures within the caps set in the contracts and its product roadmap. Three things stay outside the reach of a governance vote: the assets inside each product, which remain under the product’s mandate or methodology and belong to its participants; settled economics (Proposition 1); and each OTP participant’s account (Proposition 3). Governance activates three months after TGE. Any holder can open a proposal for discussion on the governance forum. A proposal moves to a vote after a discussion period of at least 5 days, followed by a 7-day token-weighted vote and execution through the timelock described in Section 6.3. Submitting a proposal to a vote requires 1,000,000 $CIT (0.01% of total supply), held directly or delegated to the proposer. A vote requires a quorum of 100,000,000 $CIT (1% of total supply) and passes by a simple majority of votes cast. Unvested tokens and tokens held by Primary Creative Limited and City Foundation do not vote. Governance may change these parameters only by a vote under the same rules.

6.3 How upgrades are executed

City Protocol changes its system through controlled configuration and new deployments, each bounded by rules that the contracts enforce.

  • Immutable vault code: The Curator Vault contracts are deployed as immutable contracts. Change runs through role-governed configuration within hard-coded bounds, and a new contract version is deployed as a new vault, leaving existing positions under their original code.

  • Multisig and timelock: Before a product goes live, sensitive roles move to multisig wallets or the onchain timelock, and sensitive governance actions on the vault infrastructure require a three-of-five multisig. The default timelock delay is 24 hours, with longer delays for high-impact actions, so participants can observe a queued change before it takes effect.

  • Hard-coded bounds: Fee caps are written into the fee manager, and entry and exit fees can only decrease once a vault is initialized.

  • Versioned methodologies: Each new OTP methodology version and each list change is published before it takes effect, and City Protocol gives notice before retiring a portfolio.

  • Separated roles: Settlement, pricing, access policy, fee management, strategy configuration, strategy execution, oracle membership, pause and unpause are separate roles, so a settlement operator cannot change access policy and a pricing operator cannot allocate capital.

7 Security and risk

7.1 Audits and monitoring

Zenith audited the Issuance & Operation Layer, Vault as a Service and Tokenization as a Service (June 25th, 2026, Full Report, Public Verification). All critical and high findings are resolved.. At product level, Delta-Neutral Prime USD has been audited by 0x Macro, Pashov and Spearbit, and the reports are published in the City Protocol documentation [12]. Each deployment is checked before launch for role transfer, oracle quorum, deviation tolerance, fee disclosures, strategy caps and source verification. Role, oracle, NAV, settlement, pause and fee changes emit indexed events, and a master proof-of-solvency dashboard from an independent provider lets anyone verify Curator Vault TVL in real time.

7.2 Oracle and NAV design

The report oracle accepts a NAV report only from authorized reporters under a configurable quorum, with protection against duplicate approvals, a freshness bound, binding to the network and the contract, and epoch-timing checks. Settlement rejects a price that moves beyond the vault’s deviation tolerance, and a vault can require several independent signers, for example a three-of-three quorum. When an update fails verification, lacks signer approval, uses incomplete data or breaches the deviation limit, the product pauses subscriptions, redemptions or both until the issue is resolved. For OTPs, each constituent’s price source is validated at admission (Section 3.3.3).

7.3 Risk isolation

Each part of the system is isolated so that a failure stays within the unit where it occurs.

  • Per-vault isolation: Each Curator Vault is a separate set of contracts with its own mandate, access policy, limits, strategy manager, debt caps and oracle.

  • Bounded strategies: Strategy execution is restricted to allowlisted strategies, approved targets and approved actions, with debt caps and balance-delta verification; a failed check reverts the whole transaction.

  • Protected balances: Unsettled deposits and assets reserved for redemption claims are excluded from strategy allocation (Proposition 2).

  • Per-account portfolios: OTP assets sit in each participant’s own smart account, so every portfolio is isolated from every other (Proposition 3).

  • Controlled composition: Products hold only whitelisted components, and component status propagates to every product that holds it.

  • Role separation: Operating duties are split across vault creators, strategy managers, NAV signers, guardians and operators, so moving user assets requires approval from more than one role.

7.4 Liquidation and unwind logic

Participant positions in Curator Vaults and OTPs carry no margin requirement, so the protocol has no liquidation path for a participant’s position. Liquidation and unwinding occur at three other points, each governed by rules set in advance.

  • Collateral inside credit strategies: A vault that finances loans or receivables sets a target and a minimum collateralization ratio in its mandate, such as the 150% target and 120% minimum of the RWA-backed lending template; coverage below the minimum triggers the vault’s circuit breakers and the mandate’s liquidation policy.

  • Leverage and drawdown inside trading strategies: Mandates cap leverage and set a drawdown threshold, and a breach triggers circuit breakers that can pause deposits, withdrawals, allocation or strategy execution.

  • Redemptions and wind-down: An epoch redemption locks its price at epoch close, the strategy manager returns the required capital on the redemption schedule, and claims become payable only when the settlement assets are present (Proposition 2). A vault wind-down strikes a final NAV, liquidates components and opens claims. A retired OTP leaves every asset with its participants.

7.5 Emergency controls

Pause controls are layered across the vault, deposits, redemptions, share transfers, strategy allocation and strategy execution, and pause and unpause are separate roles, so emergency response is fast and resumption requires review. Automated circuit breakers pause the affected functions on NAV deviation beyond policy, collateralization below the minimum, stale oracle data, unauthorized strategy debt, allocation above quota, abnormal withdrawal pressure, signer quorum failure or suspicious transaction patterns. On the OTP side, a pause halts new subscriptions and published list changes, while participant exit stays open because the participant alone executes it.

7.6 Principal risks

Table 10 summarizes the principal risks and the controls that address them. Controls reduce these risks, and none of them removes risk entirely: markets can move against any strategy, so participants can lose part or all of the value they commit.

Table 10: Principal risks and controls.

Risk

How it arises

Principal controls

Smart contract

A defect, misconfiguration or exploit in the vault contracts, the OTP modules or a smart account

Independent audits, test coverage, atomic transactions, bounded execution, layered pauses and pre-launch checks

Oracle and valuation

An incorrect, stale or manipulated NAV or price input

Reporter quorum, freshness and deviation checks, snapshot settlement and pauses on failed updates

Strategy and curator

Strategy losses, mandate breaches or curator failure

Creator-bound execution, allowlists and debt caps, drawdown and leverage limits, circuit breakers and disclosure

Counterparty and custody

Failure of a trading venue, custodian, tokenized-asset issuer or service provider

Dedicated venue sub-accounts, proof of deployment, reserve verification and constituent validation

Liquidity and timing

Redemption windows, epoch settlement or thin markets delay an exit

Disclosed liquidity terms, the funded-claim rule and single-transaction OTP exit

Governance and keys

Capture of governance or compromise of an administrative key

Multisig custody of roles, timelocks, role separation and separate pause and unpause

Regulatory

A change in law restricts products or the token

Eligibility controls at subscription, interface geofencing and product-level restrictions

8 Cross-chain architecture

8.1 Networks and their roles

City Protocol runs across several EVM networks (Table 11). The token has one canonical home, each product sits on the network where its strategy or constituents operate, and Venzo presents products from every supported network in one interface.

Table 11: Networks in City Protocol.

Network

$CIT

Products

Ethereum mainnet

Canonical contract, with the full supply minted

Curator Vault deployments

Arbitrum One

Bridged ahead of listing

Curator Vault deployments

BNB Smart Chain

Bridged ahead of listing

Magnificent Seven Index OTP, powered by bStocks; planned vault integration

Base

Bridged ahead of listing

Fantastic Four Index OTP and Tesla–SpaceX Index OTP, powered by Coinbase Tokenized Stocks

8.2 Token bridging

$CIT follows a canonical-supply model. The full supply of 10,000,000,000 $CIT was minted once on Ethereum mainnet, and the $CIT tokens on Arbitrum, Base and BNB Smart Chain will be bridged representations, created ahead of listing: a transfer takes tokens out of circulation on the source network, by locking or burning them, before the bridge releases the same amount on the destination network. Let Sk denote the circulating supply of $CIT on network k, outside the bridge’s escrow. Then

SEthereum + SArbitrum + SBNB + SBase ≤ 1010 (3)

Proposition 4 (Supply conservation). The combined circulating supply of $CIT on Ethereum mainnet, Arbitrum One, Base and BNB Smart Chain never exceeds 10,000,000,000, provided the bridge releases tokens on a destination network only against an equal amount locked or burned on the source network.

Proof. The full supply was minted once on Ethereum mainnet, and the bridged contracts issue tokens only through the bridge. Each transfer removes an amount from circulation on the source network before releasing the same amount on the destination network, so every transfer preserves the combined total, which starts at 10,000,000,000.

The bridged and bridge contract addresses are published through City Protocol’s official channels before listing, and holders should use only those addresses.

8.3 Products across networks

Curator Vault TVL is multichain, with the majority currently on Arbitrum and Ethereum. Curator Vaults apply chain abstraction: a participant deposits from a supported EVM network and receives vault shares, while strategy execution and NAV settlement stay on the vault’s execution network. OTP constituents are held on the network where they are issued, in the participant’s own smart account. Full chain abstraction across supported networks is planned for 2027 (Section 9).

8.4 Cross-chain risks

Operating across several networks adds bridge, messaging, liquidity and network risks (Table 12).

Table 12: Cross-chain risks and controls.

Risk

Effect

Controls

Bridge failure or exploit

Bridged $CIT can lose its backing, and tokens in transit can be lost or delayed

Canonical supply on Ethereum mainnet; addresses published before listing; supply on each network reconcilable onchain

Message relay failure

A cross-chain deposit or withdrawal is delayed or fails to complete

A cross-chain request settles only once its message is delivered, with request status visible per deployment

Liquidity fragmentation

$CIT trades at different depth or price across networks

DEX and CEX liquidity; bridging between networks

Network outage

Downtime, congestion or a reorganization delays settlement

Layered pause controls per deployment; settlement at the next valuation point

Address spoofing

Users interact with counterfeit contracts or phishing interfaces

Official addresses and domains published through official channels

9 Roadmap

Each roadmap item depends on technical, security, commercial, legal and regulatory conditions, so timing and scope can change.

Table 13: Delivered milestones.

Period

Delivered

Q1 2026

First Issuance & Operation Layer workflows and Venzo vault launches, with admin and consumer interfaces

Q2 2026

Asynchronous vault architecture completed (ERC-7540, ERC-4626 and ERC-7575, with deterministic epoch settlement); Venzo public launch with full participation flows

Q3 2026 to date

Distribution live on Venzo from July 2026; five Curator Vaults live and accepting deposits; Polis Points Season 1 (21 July to 31 August 2026) and Season 2 (3 September to 30 October 2026); Magnificent Seven Index OTP live on BNB Chain, powered by bStocks, Fantastic 4 (FAN4) Portfolio and Tesla–SpaceX Portfolio on Base chain, powered by Coinbase Tokenzied Stocks in September 2026

Table 14: Planned development.

Period

Planned

Q4 2026

TGE and direct listing in Q4 2026, with $CIT live on Ethereum mainnet

Cross-chain vault expansion, multi-chain OTP integrations

2027

Full chain abstraction across supported layer-1 and layer-2 networks; mobile app

City Protocol also plans to add more structured products to the platform, such as fixed coupon notes, options products and equity-linked notes. Any such product will be issued and distributed only by appropriately licensed entities where permitted by law, and will not be offered to residents of the Republic of Korea unless authorised as required under Korean law.

10 Legal disclaimer

10.1 Issuer and status of this paper

This whitepaper is issued by Primary Creative Limited, a company limited by shares incorporated in the British Virgin Islands, with its registered office at Intershore Chambers, P.O. Box 4342, Road Town, Tortola, VG1110, British Virgin Islands. Primary Creative Limited is the issuer of $CIT City Protocol, and it is owned by City Foundation (Cayman Islands, registration number CR-427284). This is version 2.1, dated 25 September 2026. Every amendment is published with a version history. Material amendments are notified to trading platforms on which $CIT is admitted, through the disclosure channels those platforms designate, before they take effect.

10.2 Regulatory positioning of $CIT

$CIT is a utility and governance token that provides governance participation, product benefits, payment for protocol services and ecosystem incentives (Section 5). For the purposes of Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) [9], $CIT is a crypto-asset other than an asset-referenced token or an e-money token, and it is not intended to constitute a financial instrument, a transferable security or any other regulated investment. For the Republic of Korea, Primary Creative Limited will obtain a Korean legal opinion before TGE. It will share that opinion with the relevant parties, including each Korean virtual asset trading platform that lists $CIT. A crypto-asset white paper prepared under Title II of MiCA is published at cityprotocol.co/mica_whitepaper [11]; no competent authority in any Member State of the European Union has approved it.

$CIT reaches holders through ecosystem programmes and admission to trading on crypto-asset trading platforms, and no public sale of $CIT takes place. Each City Protocol product carries its own eligibility requirements, which can include KYC or KYB verification and restrictions inherited from constituent issuers. Access to the interfaces that City Protocol operates, including Venzo, is blocked by geofencing for the restricted and sanctioned jurisdictions in the City Protocol Terms & Conditions [13]. For residents of the Republic of Korea, the following are not available and are blocked at the interface: all OTPs; the structured products described in Section 9; Curator Vaults with exposure to private credit or other real-world assets; the referral and promotional quest components of Polis Points Crypto-only Curator Vaults and Polis Points remain available to Korean residents. Primary Creative Limited does not market City Protocol products in Korea: Venzo and its product materials have no Korean-language interface or content, no KRW pricing or payment, and no Korean assets such as tokenized Korean shares or loans to Korean borrowers, and there are no Korea-specific campaigns, or rewards. Korean-language disclosures about $CIT that a trading platform requires do not promote Venzo products. Onchain transfers of $CIT remain permissionless at the contract level.

10.3 No offer and no advice

This whitepaper is provided for information only. It is not a prospectus, an offer document, an offer to sell or a solicitation of an offer to buy $CIT, any product or any other asset, and no part of it forms the basis of any contract or investment decision. Nothing in this paper constitutes investment, financial, legal, tax or accounting advice, and readers should consult their own professional advisers.

10.4 Risks users assume

Acquiring, holding or using $CIT, and participating in City Protocol products, involves significant risk, including the loss of all value committed. Users assume, among others, the following risks.

  • Loss of value and volatility: $CIT and product positions can lose value in part or in full, the market price of $CIT can be highly volatile, and past performance of any strategy is no guide to future results.

  • Liquidity and transferability: An active market for $CIT may not develop or continue on any network, and positions may not be transferable or liquid during pauses, outages or settlement windows.

  • Technology and third parties: Contracts can contain defects despite audits, networks can suffer outages and reorganizations, price inputs can be wrong or manipulated, and curators, custodians, venues, tokenized-asset issuers, bridges and data providers can fail to perform.

  • Cross-chain operations: Bridged $CIT depends on the integrity of the bridge, and City Protocol does not guarantee the completion of any cross-chain transaction.

  • Regulation and governance: Changes in law can restrict products or $CIT, and token-weighted voting can concentrate influence among large holders.

  • Keys and irreversibility: Onchain transactions are irreversible, and the loss or compromise of a wallet’s keys can mean the permanent loss of its assets.

10.5 Forward-looking statements and governing law

Statements about planned features, timelines and the roadmap are forward-looking and can differ materially from actual outcomes. Terms such as deposit, redemption, yield, NAV and vault describe the behaviour of smart contracts and imply no banking, custodial, fiduciary or deposit-taking relationship. This whitepaper is governed by the laws of the British Virgin Islands.

References

[1] Numerix. Structured Products: Global Trends, Market Forces, and What Comes Next, 6 May 2026, citing Structured Retail Products (SRP). numerix.com

[2] ETFGI. ETFGI reports Global ETF Industry Assets Reach Record US$23.11 Trillion at the end of July and YTD Inflows Hit All-Time High US$1.71 Trillion, 19 August 2026. etfgi.com

[3] RWA.xyz. Analytics on Tokenized Real-World Assets, data as at 1 and 24 September 2026. app.rwa.xyz

[4] Federal Reserve Bank of Kansas City. What Are Stablecoins Used for Today? Estimating the Distribution of Stablecoins, Payments System Research Briefing. kansascityfed.org

[5] ERC-4626: Tokenized Vaults. Ethereum Improvement Proposals. eips.ethereum.org

[6] ERC-7540: Asynchronous ERC-4626 Tokenized Vaults. Ethereum Improvement Proposals. eips.ethereum.org

[7] ERC-7575: Multi-Asset ERC-4626 Vaults. Ethereum Improvement Proposals. eips.ethereum.org

[8] ERC-4337: Account Abstraction Using Alt Mempool. Ethereum Improvement Proposals. eips.ethereum.org

[9] Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets. Official Journal of the European Union, L 150, 9 June 2023. eur-lex.europa.eu

[10] U.S. Securities and Exchange Commission. SEC Issues “Innovation Exemption” to Facilitate the Trading of Tokenized NMS Stock and Request for Comment, press release 2026-90, 17 September 2026. sec.gov

[11] Primary Creative Limited. City Protocol crypto-asset white paper (MiCA, Title II), notified 26 August 2026. cityprotocol.co/mica_whitepaper

[12] City Protocol. City Protocol Documentation, including audit reports. city-protocol.gitbook.io/docs

[13] City Protocol. Terms & Conditions, last updated 15 April 2026. city-protocol.gitbook.io

1Live Venzo vault data is published at dune.com/cityprotocol/venzo-vaults.