Canary Protocol Logo
RWA security, end to end

The Assurance Layerfor tokenised capital.

Canary secures every mint, cross-chain transfer and redemption through Cipher, which verifies collateral, detects anomalies and enforces issuer rules inside hardware enclaves.

See how it works
Total value secured
$45B
$45,000,000,000Verify Metrics

Real-world assets protected across mint, redeem and cross-chain transfer.

Securing leading protocols
Canary DVN
The assurance layer
Verification
Hardware-isolated enclaves
Consensus
K-of-N independent quorum
Data
Certificate-pinned sources
Coverage
150+ chains
Why Canary DVN

Cryptographic trust. Operational security.

Old modelCanary DVN
01Private key in enclaveIsolated

The key never leaves hardware. Operators can't read it.

02CIPHER verificationAttested

The enclave proves which code ran before it signs.

03Independent checksK-of-N

Multiple operators must agree. One bad actor is outvoted.

04ProofGenerated
05Canary DVNQuorum
06SettlementProven

No proof, no settlement. Failure is refused, not retried.

No single party can move funds. If the quorum can't prove the message, settlement is refused — not retried, not queued.

How Canary secures value
across 150+ chains

Ingest

Data and instructions from institutional curators and market venues.

Verify in TEE

Inputs validated inside trusted execution environments with SSL pinning.

Attest & Sign

Hardware-level attestation, k-of-n sourcing, and replay protection.

Transport

Messages delivered via LayerZero rails with Canary DVN validations.

Settle & Observe

On-chain and off-chain states updated. Observability and audit logs captured.

$B+
secured volume
+
live partners
+
chain integrations
k+
cross chain messages
Verify Metrics
How a message is verified

Four layers. An attacker must defeat every one, at once.

Checks cleared0 / 10
01Distributed trust
No single key or operator decides.
Checking
K-of-N quorum
Multiple independent operators must agree.
Checking
Multiple signing keys
No one can authorize a message alone.
—
HSMs
Keys held in hardware security modules, never exposed.
—
02Delivery infrastructure
No single supply chain to compromise.
Waiting
3 cloud providers
Three independent providers, zero shared control plane.
AWS | GCP* | Azure*
—
3 hardware architectures
Three distinct silicon roots of trust.
AWS Nitro | Intel TDX | AMD SEV-SNP
—
TEEs
Every check runs inside hardware-isolated Trusted Execution Environments.
—
03Prove it cryptographically
Don’t trust that the right code ran – verify it.
Waiting
ZK proof, verified on-chain
Cryptographic proof that the correct verification code executed – checked by the chain itself.
—
04Check the meaning
Reject valid-looking but invalid actions.
Waiting
Anomaly detection
Messages outside historical patterns are flagged before signing.
—
Collateral Proofs
Minted value is checked against attested collateral.
—
Value-scaled thresholds
Larger transfers demand a larger quorum.
—
All layers pass
Sign
Any layer fails
Refuse
An attacker must defeat every layer simultaneously.
Awaiting all four layers
What partners say

Trusted by the teams moving the most value.

Canary is building a security solution trusted by some of the largest applications in the space, including EtherFi. They’ve already attested to more than a billion dollars in volume moving between blockchains. As LayerZero expands across more chains and assets, Canary’s role becomes critical as a client-diverse, fast, and secure DVN assets and applications can build with at scale, with speed.
LayerZero
Bryan Pellegrino
Co-founder, LayerZero
01 / 04
Backed by
From @canary_proto on X

Latest from Canary

Follow on X