One Block, Two Nodes, the Same Number: Reproducible Supply Evidence for Euro E-Money Tokens
Every issuer of a euro e-money token publishes a number called "tokens in circulation". The reserve has to cover it, the auditor compares it to the bank statements, and the supervisor receives it in a template. Ask where the number came from and the honest answer, more often than not, is a block explorer screenshot taken by the issuer about the issuer.
That was fine while nobody asked. Two documents now ask. The EBA's reporting instructions for MiCA issuers (template S 02.00, "Value of the token issued") want the value at the reference date and the maximum, minimum and average of the values at the end of each calendar day of the period. The AICPA's 2025 stablecoin criteria, which the AICPA is pushing as the standard under the US GENIUS Act, want natively minted tokens disclosed per blockchain and per smart contract, reconciled to the redeemable amount. Both need a figure pinned to a moment, from a source that is not the issuer, that someone else can reproduce.
So I built the boring version of that and ran it against every euro e-money token I could source a contract for. What follows is what the packs look like, what the runs found, and where the approach breaks.
What a pack contains
The input is a registry: one entry per deployment, keyed by chain and contract address, with the issuer, the decimals and a URL to the issuer's own page that publishes that address. Tickers are labels, never identity. This matters more than it sounds: since 26 August 2026 there are two unrelated tokens called EURR, one from StablR in Malta and one from Bridge Building S.A. in Luxembourg offered through Revolut. A registry keyed by ticker would have silently merged them.
A run pins a block, either by number or as the last block at or before a UTC timestamp, and
reads totalSupply for every contract at that block through at least two RPC
endpoints run by different operators. The endpoints have to agree. If they do not, the run
fails and records both answers; it never picks one. Every call is pinned to the block hash rather than the block number, so a reorg makes the
call fail instead of returning the wrong state.
The output is a directory: result.json and result.csv with the
figures, inputs.json with the registry subset and the pinned block actually used,
rpc-log.jsonl with every request and raw response, and MANIFEST.json
with a SHA-256 per file. The JSON is canonical (sorted keys, no whitespace, integers as decimal
strings), so the content hash of result.json is stable across machines. The
manifest can be signed with an Ed25519 key, and a single-file verifier written against the
standard library only checks the hashes, the canonical form, the arithmetic and the signature,
then optionally re-reads the chain at the pinned block through an RPC of the verifier's
choosing and prints identical or a diff.
The runs of 13 September
Eight tokens, nine deployments, three chains, three packs. Ethereum at block 25,969,531 (15:52:11 UTC, three endpoints agreeing), Base at 51,262,772 and Polygon at 93,739,911 a few minutes later, two endpoints each. Each pack was re-derived with the verifier within minutes: identical.
- EURC (Circle): 301,722,064.14 on Ethereum and 48,874,867.12 on Base
- EURCV (Societe Generale-FORGE): 136,859,562.58 on Ethereum
- EURR (StablR): 17,143,032.56 on Ethereum
- EURØP (Schuman Financial): 7,743,136.33 on Ethereum
- EURQ (Quantoz): 6,000,000.00 on Ethereum
- EUROD (Oddo BHF): 5,100,000.00 on Polygon
- EURe (Monerium): 2,566,581.02 on Ethereum
- EURAU (AllUnity): 256,680.64 on Ethereum
These are gross totalSupply figures. Nothing above is presented as "in
circulation", and the reason is the first finding.
Finding 1: nobody publishes the exclusions
Circulating supply is total supply minus whatever the issuer holds in treasury, minter or bridge-lock addresses, minus tokens that are blocked or test balances. The AICPA criteria call this the minted-versus-redeemable reconciliation. To subtract an address you need the issuer to publish it. I read the public pages, white papers and audit reports of Circle, Monerium and Schuman looking for such addresses. Token contracts, yes. Blocklist policies, yes. A concrete treasury or bridge holder address suitable for exclusion, no. The registry records that as pending with the URLs checked rather than guessing, and the packs carry an empty exclusion list. If an issuer wants an independent circulating figure, publishing those addresses is the one thing only they can do.
Finding 2: the register is not the market
The ESMA interim register lists 24 authorised EMT issuers. Reading every issuer's own material to find a deployed contract for the euro tokens produced eight admissions and a ledger of what stopped the rest. Paxos Issuance Europe's EUROe page now redirects to a redemption notice. Newrails' EURW white paper carries a different LEI from the register entry. Banking Circle's EURI white paper and audit report describe the product without a mainnet address. Bridge's EURR transparency link, as published in the register, returns 404. An active row in the register is not evidence of active minting, and a ticker match on an explorer is not an issuer source.
Finding 3: yesterday's evidence has a shelf life on free nodes
The packs from 13 September verified minutes after they were written. The same verify command against packs from the previous evening failed the next morning: the free endpoints could not serve state for blocks between twelve and twenty hours old, with errors such as "historical state is not available" and "state at block is pruned". A period report over September, one end-of-day snapshot per calendar day, came back zero for twelve out of twelve completed days for the same reason. The report marks itself incomplete and refuses to treat a missing day as zero, which is the right behaviour, but the lesson is operational: reproducing a quarter of end-of-day figures needs an archive endpoint, or a job that takes the snapshot minutes after midnight while the state still exists. The S 02.00 maximum, minimum and average cannot be computed after the fact from public infrastructure.
What the pack does not prove
- Anything about reserves. It reads the liability side only.
- Circulating supply, until exclusions exist with a source.
- Coverage of chains it does not read. EURC alone is deployed on eight networks; the packs cover two of them.
- Authorship or date. The signature binds the files to a key. Who holds the key, and an external anchor for the manifest hash, are procedures, not code.
None of this is clever. It is a pinned block, a quorum, a canonical file and a hash, done the same way every day so an auditor can stop trusting the screenshot and start re-deriving. The interesting work sits on the other side: issuers publishing their exclusion addresses, and reporting templates that ask for the end of each calendar day being fed by something that actually ran at the end of each calendar day.
The daily totalSupply figures for the Ethereum deployments continue to be
published on the euro stablecoin supply page. The evidence
packs behind the runs above, with their manifests and signatures, are available on request.