Skip to content

OpenZeppelin publishes CACEIS EURXT audit: zero critical, three low-severity findings

The MiCA-licensed euro EMT from Crédit Agricole's custodian cleared OpenZeppelin's May 20–21 audit with no high- or medium-severity issues.

by 3 min read

OpenZeppelin published its security audit of CACEIS's EURXT — the MiCA-regulated euro e-money token (EMT) issued by Crédit Agricole's custodian — on October 2, 2026, per OpenZeppelin's news page. The review ran May 20–21, 2026 against the Solidity contract set. Result: zero critical, high or medium findings, and three low-severity operational refinements, all acknowledged by CACEIS for the next contract revision ahead of launch.

Why this audit matters

MiCA's EMT regime, in force since June 30, 2024, lets authorised credit and e-money institutions issue single-fiat-pegged stablecoins across the EU under a passported license. The regime is now populated — Circle (EURC), SG-FORGE (EURCV), Membrane (EURØP), Monerium (EURe) and others — but the next wave is custodian-issued EMTs from universal banks. CACEIS, the custody arm of Crédit Agricole, is one of the first large bank custodians to publish an audit on a MiCA-track euro EMT.

The three low-severity items published by OpenZeppelin are specific and operationally material:

  • Admin role overuse. DEFAULT_ADMIN_ROLE gates both high-privilege role administration and routine maintenance (setRedemptionAddress, setContractURI). A compromise of that key is a maximal-blast-radius event. OpenZeppelin recommends splitting routine maintenance into a lower-privileged role.
  • Premature minting. The contract allows token minting before setRedemptionAddress is configured. In that window, EURXT would exist on-chain with no on-chain redemption path pointing anywhere — a mismatch between the on-chain state and the off-chain redemption pipe MiCA presumes.
  • Seizure routing. seizeBlacklistedFunds can direct seized assets to the redemption address, which under certain operational flows would contaminate the off-chain settlement pipeline. OpenZeppelin recommends a dedicated holding account for seized balances.

Fifteen informational items — storage layout inefficiencies, redundant code patterns, style deviations — were flagged separately. None affect the contract's core security guarantees.

What the shape of this audit tells you

Three operational-tier low findings and no higher-severity items is the kind of result you expect on a contract designed by a bank's legal and ops teams first, with the smart-contract surface pared back to transfer, mint, burn, pause and seize primitives. The failure modes OpenZeppelin flagged are classic bank-custody oversights ported into Solidity: role hierarchies that mirror the org chart rather than the attack surface, state transitions that assume the off-chain integration is already live, and seizure plumbing wired for operational convenience rather than isolation.

For builders integrating EURXT once it launches, the three items are useful inputs: expect CACEIS to split roles before mainnet, confirm the redemption-address configuration is live before accepting EURXT in a vault contract, and treat the seizure flow as potentially aliased with normal redemption traffic until the next audit confirms the fix.

Context

The EU is the first jurisdiction with a working, actively used, licensed stablecoin regime. Audit scrutiny on bank-issued EMTs is one of the few places a reader can see what a European universal bank's smart-contract practice actually looks like under third-party review — against which the many "institutional-grade" claims in retail-oriented stablecoin marketing can be benchmarked.

What to read

  • The full audit PDF on OpenZeppelin's site, linked from the news page above.
  • The CACEIS announcement when EURXT formally launches (the audit is pre-launch).
  • ESMA's EMT register entries, for the final license scope and reserve-asset mix once the token is public.

Related stories