> For the complete documentation index, see [llms.txt](https://docs.valuechain.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.valuechain.xyz/5.-mirror-protocol.md).

# 5. Mirror Protocol

#### 5.1 Role

Mirror Protocol is ValueChain's interoperability layer. It brings assets from external networks onto ValueChain and sends them back.

* **Deposit.** When a deposit on an external network is detected and verified, Mirror Protocol mints an equal amount of the corresponding token on ValueChain.
* **Withdrawal.** Mirror Protocol burns the ValueChain token and releases the native asset on the destination network.

Liquidity from several external networks is thus pooled into one trading and settlement environment. The supported assets, networks, limits and fees are published by the Mirror API at runtime rather than fixed in the protocol.

#### 5.2 Two kinds of route

|                               | Custody route                                                   | Bridge route                                                           |
| ----------------------------- | --------------------------------------------------------------- | ---------------------------------------------------------------------- |
| Networks today                | Non-EVM or custodial networks (e.g. BTC, SOL, XRP, TON)         | Base only                                                              |
| How the user deposits         | Sends to a deposit address assigned to their ValueChain account | Calls the bridge contract on Base                                      |
| Where the asset is held       | Segregated accounts at institutional custodians                 | The bridge contract on Base                                            |
| Where the deposit is credited | The user's Spot account, directly                               | Spot account (toClob = true) or ValueChain EVM wallet (toClob = false) |

Each custody deposit address is assigned to one ValueChain account on one external network. It is recorded on chain in the `SoDexTokenCustody` contract. Before sending funds to an address, the address should be checked against this on-chain record.

#### 5.3 Security model

**Validation.** Mirror Protocol uses an **MPC + TEE validator architecture**. A set of distributed nodes running inside trusted execution environments independently validates each deposit and withdrawal event. The nodes must reach consensus before any mint or redemption happens, so no single node can compromise the bridge.**Custody.** Assets on custody routes are held by institutional-grade custodians, currently **Cobo, Ceffu and Coinbase**, in segregated accounts.

* These custodians are recognised worldwide for their regulatory standing and security infrastructure, and safeguard client assets to institutional standards.
* Assets are spread across several custodians, so no single institution is a point of failure.
* Every custodied asset is mirrored 1:1 on ValueChain, so the supply of a mirrored asset is backed by the same amount held in custody.

**Compliance.** ValueChain integrates on-chain compliance tooling from **Elliptic** and **Chainalysis**. KYT (Know Your Transaction) screening monitors transaction flows and flags high-risk activity in real time, and KYA (Know Your Address) screening assesses the risk of counterparties and addresses before assets are accepted. Together they keep assets on the network secure and compliant while preserving the open, permissionless character of the chain.

#### 5.4 Withdrawal flow

A withdrawal is paid from the user's ValueChain EVM balance. Funds held on the trading appchains are first moved back to the EVM: Perps → Spot → EVM. The withdrawal then works as follows:

1. The user signs a `WithdrawToken` permit specifying the asset, destination network, receiver, amount and route type.
2. The permit is submitted through the sponsored-withdrawal gateway, which pays the ValueChain gas.
3. Mirror Protocol burns the token on ValueChain and releases the asset on the destination network.
4. The withdrawal is tracked by its ValueChain request hash and, once assigned, its withdrawal ID.

The user only signs. They do not need SOSO for gas.

#### 5.5 Protocol contracts

| Contract                | Role                                          |
| ----------------------- | --------------------------------------------- |
| SoDexTokenPortal        | Entry point for mirrored-asset operations     |
| SoDexTokenCustody       | On-chain record of custody deposit addresses  |
| SoDexTokenWithdrawer    | Withdrawal execution                          |
| SoDexTokenCallForPermit | Permit verification for sponsored withdrawals |
| SoDexTokenCaller        | Protocol call routing                         |
| SoDexTokenOracle        | Validation and oracle data                    |
| SoDexTokenQuery         | Read-only configuration                       |

Addresses are in Appendix B.
