
This paper presents the Osnias Clearing end-user security architecture across the complete participant identitylifecycle: onboarding, dual-domain authorization, secure fund release, cryptographic renewal and off-boarding.Its objective is to reduce the risk that compromise of a single operational ECDSA key could result in diversionof escrowed funds.The architecture uses existing chains as they are. It separates the operational EVM signing address, anindependent Sei authorization domain, and a cold EVM release destination generated from a separate seedand pre-committed in the smart contract. The release destination is intended to remain non-signing during itsdesignated receiving phase and to serve as a pre-committed beneficiary rather than an operationalauthorization key, so compromise of the operational signer does not, by itself, confer control over thedestination of released funds.A future Shor-enabled attack against exposed ECDSA public keys is treated as a prospective cryptographicrisk, not as an asserted present operational threat. The design philosophy is long-horizon security engineering:use mechanisms available on current chains to reduce a plausible risk class extending across a longoperational and cryptographic horizon, without claiming that ECDSA itself has become post-quantum secure.Document level: internal technical assessment and audit-readiness review. Controls are classified by evidencestatus; this document is not an independent audit, formal verification, penetration-test report or production-security certification.
