QGOLD V2 Whitepaper
Gold in digital form, bound to its reserve by a balance-sheet identity
QGOLD is the digital side of a balance sheet whose physical side is a reserve of gold. It is the asset in tokenised form, not a claim on gold, not a derivative, not a fund interest, and not a stablecoin. It carries no redemption right and no maintained value. Its market price is set by the market, is denominated in fiat (EUR/USD), is independent of the issuer, and may move in either direction, including to zero, irrespective of the state of the reserve.
This whitepaper sets out the economic principles, reserve model, liquidity architecture, and smart-contract design of QGOLD, and the basis on which the issuer classifies it under Swiss financial-market law and, for offerings into the European Union, under Regulation (EU) 2023/1114 (MiCA).
Issued by Quorium CH Ltd
the Swiss branch establishment of [Quorium UK parent Ltd, registered name and company number to be inserted], a company incorporated in England and Wales, operating under Swiss law.
Notice and intellectual property
© 2026 Quorium CH Ltd. The QGOLD product, the Quorium and QGOLD names and marks, the smart-contract implementation, and the specific liquidity and reserve architectures described in this document are proprietary to Quorium CH Ltd and its group. QGOLD and Quorium are trademarks of the Quorium group.
The underlying economic research on which parts of this whitepaper draw (including the three-domain framework, the balance-sheet-identity treatment of commodity tokenisation, and the analysis of price formation and convergence) is published separately by its author as academic work under a Creative Commons Attribution 4.0 International (CC BY 4.0) licence and may be cited and reused on those terms. This whitepaper applies that research to a specific product; the research is general theory and is distinct from the QGOLD implementation (see § 6 and § 16).
This whitepaper is published for information only. It is not an offer or a solicitation, conveys no rights in the intellectual property described, and does not constitute legal, financial, tax, or investment advice. See the Risk Factors (§ 17) and the Disclaimer.
1. Introduction
Gold has served as money for thousands of years. It is scarce, durable, divisible, and universally recognised. In its physical form, however, gold is slow to transfer, expensive to store, impossible to program, and impractical for digital commerce. The digital economy needs gold in a natively digital form.
The conventional approach to this problem places refined bars in a vault and issues tokens that represent a claim on those bars, redeemable for physical gold. The token is a receipt; the gold remains gold in a vault, and the construction imports the constraints of the physical world (a specific form, a specific location, availability for withdrawal on demand) into the digital one.
QGOLD takes a different approach. It does not tokenise a claim on gold. It digitises the asset itself. On the issuer's balance sheet, a reserve of gold and the issued tokens are bound by the act of minting into a single position. The token is the digital expression of that position, the asset in tokenised form, not a reference to it and not a claim against someone who holds it. Because the token is the asset, there is nothing to redeem, and there is no redemption right.
The reserve is partitioned into equal shares, counted in troy ounces of gold by weight. One QGOLD therefore corresponds to one troy ounce of gold in the reserve, counted by weight. Gold-by-weight here is a counting unit (the numeraire by which the reserve is divided into equal shares), and not a value the token is built to follow. This is an identity of quantity, not a claim on a maintained value: the token's market price is set by the market, in fiat, and is independent of the gold spot price and of the issuer.
The monetary properties that holders associate with gold (scarcity, durability, recognisability) are properties of gold, described here as background, not representations by the issuer that QGOLD will preserve or deliver any particular value. This whitepaper explains the construction, why it is built this way, and what it does and does not promise.
2. The problem with conventional tokenised gold
The dominant model creates tokens that represent a claim on physical gold in a vault, redeemable for the underlying or its cash equivalent, with the token price held close to spot by redemption arbitrage: when the token trades below spot, arbitrageurs buy and redeem, capturing the spread. That redemption channel is what ties such a token to the commodity. The model has three structural limitations.
First, it limits what can serve as reserve. If holders can redeem for physical gold, the reserve must be refined bars in an audited vault, available for withdrawal. Verified gold still in the ground cannot satisfy a physical-delivery claim, however well it is measured. Tokenisation is confined to the fraction of the world's gold already mined, refined, and stored.
Second, a hard peg invites front-running. Where a mechanism guarantees a price adjustment, a participant who observes a gold-price change before the mechanism adjusts can trade against the guaranteed convergence at the expense of other holders.
Third, it does not address fractional liquidity. Market capitalisation is last price multiplied by supply. If a token shows a one-billion valuation but only ten million of buy-side liquidity exists, the valuation is realisable only on paper; the moment holders attempt to exit, the price falls. For an instrument meant to be exchangeable, this is a defect: realisable value depends on liquidity, not on a headline number.
QGOLD addresses all three through a different design, which begins by asking which economy the instrument is built for.
3. Three economic domains
Three domains operate under different rules, and the design follows from placing QGOLD deliberately in the third.
The physical economy
The economy of tangible goods and physical delivery. A bar in a London vault and a deposit in a West-African mine are different assets here, because value is realised through possession: verification is physical inspection, settlement is physical delivery, and form and location are decisive.
The hybrid economy
The transitional space where physical assets are represented digitally but remain tethered to physical-economy rules. Most current tokenised-gold projects sit here: a digital token that promises physical redemption, which imports the requirement that the gold be refined, vaulted, allocated, and withdrawable. The token adds transferability and programmability but does not change the underlying relationship. It is a receipt; the gold is still gold in a vault.
The digital economy
Here the physical gold does not set value directly. It defines scarcity and serves as a last-resort backstop. Value is realised through exchangeability: the ability to exchange the token into other liquid assets at predictable prices without material slippage. This is an observation, not a preference: in practice, tokens with no reserve at all can attract deep liquidity, while tokens backed by valuable assets can remain illiquid and economically inert. A reserve confers no functional utility if the instrument cannot be exchanged.
QGOLD is designed for the digital economy. Every design choice in this whitepaper follows from that positioning.
4. What QGOLD is
The balance-sheet identity
QGOLD is the digital side of a balance sheet whose physical side is a reserve of gold. On the issuer's balance sheet, the reserve and the issued tokens are bound by the act of minting into a single position. The token is the digital expression of that position. Minting is not the issuance of a claim; it is the act of digitisation itself.
The relation is that of a title deed. A deed to real property does not refer to the property and gives no claim on it held by someone else: it is the property in legally transferable form. One cannot hold the property apart from the title, and transfer of the deed is transfer of the property. There is one asset and one instrument that embodies it, not two things with a relationship between them. QGOLD stands in the same relation to the reserve. Because embodiment is not reference, QGOLD references no external value: there is no second term for the token to point to, because the token is the first term.
Tokens that have been sold are recorded as no longer the issuer's property: the corresponding share of the reserve is held under management, for the account of others. Ownership has passed to the holder. The holder's position is, in substance, ownership of a pro-rata share of the reserve in tokenised form.
One QGOLD corresponds to one troy ounce of gold in the reserve, counted by weight. Not a claim. An identity, of quantity, not of value.
Why this is not a value reference
Because the token is the asset, its value is not derived from a separately-valued reserve. The issuer carries its residual, unsold share of the reserve at one valuation; each holder carries the token at its market price. The two are set in different ways and need not coincide. That they do not coincide shows, as an accounting matter, that the token's value is not a function of the reserve's value. Equally, minting one token or ten million against the same reserve leaves the reserve's value unchanged: the reserve sets the scarcity bound on supply, not the value of each token.
No redemption
There is no redemption right. No holder may, by virtue of the token, claim delivery of gold or any other commodity, and no pathway to such a claim exists. The absence of redemption is a design principle, not a temporary restriction. A holder does not seek a gold bar; the holder realises value by exchanging QGOLD for other liquid digital assets through the liquidity infrastructure described in § 7.
Bidirectional value
The identity creates a two-way relationship. The gold makes QGOLD scarce: supply is bounded by a verifiable physical constraint. QGOLD makes the gold reachable in the digital economy. Neither side is sufficient alone (physical gold without a digital form is inert in the digital economy; a digital token without a reserve is unbounded) and together they form a single economic unit operating across both domains.
The gold makes QGOLD scarce. QGOLD makes the gold reachable.
The holding vehicle is replaceable
A consequence of the identity is that the holding vehicle is replaceable. If the entity holding both sides of the balance sheet is restructured, wound down, or transferred to a successor, both sides migrate together; the binding between reserve and tokens is independent of the vehicle. Where the operating entity ceases to function, an independent administrator can preserve the identity, by transferring both sides to a successor or conducting an orderly wind-down, so that the binding depends on the structure and the applicable legal framework, not on any individual or company.
5. Reserve architecture
Composition: a heterogeneous bundle
The reserve is a heterogeneous bundle of two kinds of gold: refined bullion held in secure institutional storage, and in-ground gold resources verified under an internationally recognised standard (NI 43-101 or JORC). The in-ground component is restricted to Measured and Indicated Resources, estimated and classified by an identified qualified person; Inferred Resources are excluded. These are Mineral Resources, not Mineral Reserves in the standard's defined sense; the word "reserve" is used here in its ordinary sense of a holding maintained as a backstop.
Because the bundle combines bullion with in-ground interests across deposits at different stages and in different jurisdictions, an equal share of this particular bundle has no single, continuously-quoted market price. There is no "spot" for a share of the bundle. This is one reason QGOLD references no external value: there is no single external price for it to track.
In-ground resources can be included precisely because there is no redemption right. Where the function of the reserve is to define scarcity and serve as a backstop rather than to fulfil physical delivery, the distinction between vault gold and verified in-ground gold collapses for that purpose: a verified 500,000-ounce deposit is the same 500,000 troy ounces, by weight, as 500,000 ounces of refined bullion. The form differs; the counted quantity does not.
Function of the reserve: backstop, not backing
The reserve does two things. It defines scarcity (it bounds the maximum token supply by a verifiable physical constraint) and it serves as a last-resort backstop. It is not backing in the sense of a guaranteed value, not a peg, and not a claim the holder can enforce against a maintained value. The holder owns the asset (a pro-rata share of the bundle); the holder is not given a guarantee of the token's market value, which the reserve does not preserve and no one guarantees.
Supply is capped by quantity, not by value: the number of tokens may not exceed the verified troy-ounce count of the reserve. The issuer maintains the counted reserve at or above the minted supply; where it exceeds the minted supply, the surplus is a quantity-and-quality buffer against estimation uncertainty in the in-ground component and against geographic and regulatory risk. It is expressly not a value floor for the token and creates no price support.
Verification
Refined bullion is attested at regular intervals by an independent audit firm, confirming quantity, purity, and custody status. In-ground resources are evidenced by reports of a qualified independent professional under NI 43-101 or an equivalent standard, with methodology disclosed. The on-chain supply is publicly verifiable at any time through the contract's totalSupply; an independent oracle service compares on-chain supply against reserve attestations on a continuous basis, so that any observer can check that the counted reserve matches or exceeds the issued supply. A summary reserve report is published at regular intervals.
Scale
Including verified in-ground resources widens the addressable reserve far beyond gold that has already been mined, refined, and stored. This is a difference of scale, expressed in counted ounces; it is not a representation about the value, price behaviour, or returns of QGOLD.
6. Value, price, and the absence of a peg
QGOLD is not a stablecoin
QGOLD is not a stablecoin and does not hold out price stability. The only sense in which it is "stable" is that of identity: the token is, and remains, the asset in tokenised form. That is a statement about what the instrument is, not about what its price will do. The price of a troy ounce of gold, expressed in euros or dollars, has always moved; QGOLD inherits no protection from that movement, and adds none of its own.
No peg, no price floor
QGOLD has no price peg to gold and no mechanism by which the issuer holds the price to gold or to any level. The market price is set by supply and demand on the venues where QGOLD trades, is denominated in fiat (EUR/USD), is exogenous to the issuer, and may move in either direction, including to zero, irrespective of the state of the reserve. There is no redemption arbitrage, because there is no redemption. There is no built-in price floor: under sustained selling pressure the price can approach zero while the reserve remains fully intact and while liquidity pools persist.
No issuer market-making
The issuer operates no market-making and defends no price level, and conducts no price-moving transactions intended to hold a level. Liquidity is provided through proportional management of an automated market maker (AMM): proportional addition or withdrawal changes the size of the pool, not the price, which is the ratio of the pool's reserves. Any party that provides liquidity or trades does so on its own account and at its own risk, at arm's length from the issuer, under a return or performance mandate, never a price or level mandate, with its own discretion over whether, when, and at what price it acts, including the freedom to reduce or exit. A maintained coverage or depth ratio concerns tradability, not a price level (see § 7); a covered pool gives no price floor.
Convergence is a market expectation, not an issuer mechanism
It may be observed that, in markets of this kind, the price of a tokenised commodity can tend toward a reference through market microstructure, the behaviour of arbitrageurs and of supply responding to margin. Where the issuer's author discusses this, it appears in independent research as a prediction about how participants behave, supported by empirical evidence from other instruments. It is not an issuer-side intent, not a mechanism the issuer operates, and not a representation that the token follows or delivers a gold-driven value. Whether any such tendency materialises is an empirical question that lies outside the design of the instrument. In QGOLD's case the point is reinforced by the reserve being a heterogeneous bundle with no single reference price: there is no single value for a price to converge toward.
The general rational-issuer model in that research (which contemplates issuer intervention to compress deviations from a reference, and uses gold as its illustrative commodity) is general theory. The QGOLD implementation does not adopt it: the issuer operates no intervention and defends no band. Where the research is relied upon, this distinction is made explicit, so that issuer intervention and spot-convergence are not read into QGOLD.
Why the absence of a peg is preferable
Because there is no guaranteed price movement, there is nothing to front-run: the price moves in real time on actual supply and demand, and price discovery is genuine. Periods of higher demand for digital gold exposure may see QGOLD trade at a premium to physical spot; periods of lower demand, at a discount. Both are legitimate market outcomes, not failures of a mechanism: the issuer neither promises nor targets any relationship to spot.
7. Liquidity architecture
If exchangeability is the source of realisable value in the digital economy, then deep, verifiable liquidity is the design objective. QGOLD organises this through a three-pool architecture that separates tokens by liquidity status and economic function. The names below align with the public site; "Free Market" denotes the fully-liquid, market-priced pool.
| Pool | Purpose | Liquidity status | Transfer rules |
|---|---|---|---|
| Treasury Pool | Issuer-owned inventory. Tokens not yet in circulation. | None. No external holders. | May move to Commerce Pool or Free Market via the Route to Liquidity. |
| Commerce Pool | Institutional tokens with economic utility; not yet freely tradeable. | No public-liquidity claim. A path to liquidity exists. | Free transfer within the Commerce whitelist. Exit via the Route to Liquidity. |
| Free Market | Fully liquid tokens in unrestricted circulation. | Depth/tradability target (see below). | No restrictions. Standard ERC-20 behaviour. |
7.1 Treasury Pool
The Treasury Pool holds tokens under the issuer's sole ownership and control that have not entered circulation: inventory, equivalent to unsold bars. It carries no liquidity obligation because there are no external holders. Tokens held in Treasury are not part of the externally-held supply for the purpose of the scarcity bound.
7.2 Commerce Pool
The Commerce Pool holds tokens of institutional counterparties that can be deployed economically (as collateral, for bilateral settlement, or for other purposes) but are not yet freely tradeable on exchanges. It resolves a sequencing problem: institutions can use the token before full public liquidity is built, without making liquidity claims the system cannot yet support. The sale price into the Commerce Pool is set at a discount to the prevailing free-market price; the issuer's commercial interest is therefore in the highest free-market price, not in any stable level. The Commerce whitelist is self-service; compliance is enforced at the mint gateway, where the issuer determines who receives newly-minted tokens (see § 11).
7.3 Free Market
Free-Market tokens are in unrestricted circulation: tradeable on any venue, transferable to any wallet, usable in any protocol. They are the fully-liquid form of QGOLD.
The Free Market is managed to a depth (tradability) target, not to a price. The target expresses the depth of immediately-available stablecoin liquidity relative to the circulating Free-Market supply: an indicator of how much can be exchanged at prevailing prices without material slippage. It is not a price floor, not a value guarantee, and not a ratio of token value to reserve value. Concretely, the system seeks at least full depth relative to circulating supply, with additional headroom under normal conditions. Liquidity pools are established against stablecoins (e.g. USDC, USDT) to isolate the depth measure from crypto volatility.
Liquidity is managed proportionally and is price-neutral: proportional addition or withdrawal changes the size of the pool, not the price. If depth falls below the minimum target, a protective rule prevents new tokens from entering the Free Market until depth is restored; tokens already in the pool continue to function. The rule protects the tradability available to existing holders; it does not, and cannot, hold any price.
Secondary trading pairs
QGOLD may trade against any asset on the open market (e.g. QGOLD/ETH, QGOLD/BTC). Such pairs sit outside the stablecoin depth measure: anyone creating them first acquires QGOLD through the stablecoin pairs, and that stablecoin remains in the Free-Market depth. The stablecoin depth is never diluted or redirected when secondary pairs emerge.
8. Route to Liquidity
Tokens enter the system by minting into the Treasury Pool or Commerce Pool; they never mint directly into the Free Market. From either pool, tokens reach the Free Market through the Route to Liquidity, which operates in two independent modes.
8.1 Instant mode
A holder who possesses both QGOLD and the corresponding stablecoin liquidity deposits both at once. The stablecoins are added to the Free-Market pairs; the QGOLD moves to the designated Free-Market address. The transition is atomic, with no delay and no haircut. The contract verifies that resulting depth remains above the minimum before completing; otherwise the transaction reverts.
8.2 Queued mode
For holders who have QGOLD but lack the stablecoin capital to pair with it, the queued mode operates in two phases.
Phase 1: registration and escrow. The holder registers an amount and a target Free-Market address. The tokens transfer immediately to the contract (removing them from commercial use) and enter a round-robin queue. There is no guaranteed timeline in Phase 1, and the holder may cancel and reclaim the escrowed tokens at any time.
Phase 2: settlement window. As liquidity becomes available, registrations advance by round-robin with a per-turn batch cap, so smaller registrations exit quickly rather than queue behind large ones. On entering Phase 2 a registration receives a guaranteed settlement window of 30 days within which the system commits to provide liquidity; cancellation is then no longer permitted. On settlement the system deposits stablecoin liquidity into the Free-Market pairs and releases the escrowed QGOLD to the target address. If the window passes without full settlement, the holder may reclaim the unsettled portion; any settled portion remains in the Free Market.
This is a commitment to provide liquidity within a stated window. It is not a guarantee of price or value: what is committed is exchangeability, not a level.
8.3 Reverse flows
Tokens may flow back from the Free Market to the Commerce or Treasury Pool; the associated stablecoin liquidity remains in the Free Market. Fewer tokens against the same liquidity improves depth for remaining holders. This is an operational tool for managing depth, not a price intervention: it changes how many tokens share the pool, not the price the pool quotes.
9. Liquidity-state valuation by counterparties
Different liquidity states carry different risk profiles. Counterparties may, under their own internal risk frameworks, assign different valuation haircuts to QGOLD according to its liquidity state. The descriptions below are illustrative of how a counterparty might reason; they are not representations by the issuer about regulatory treatment, eligibility, or value, and the issuer makes no claim that QGOLD qualifies for any particular prudential category. Any such treatment is a matter for the counterparty and its advisers.
| Token state | Illustrative haircut | Counterparty rationale |
|---|---|---|
| Free Market | Lowest | Fully liquid; exchangeable at prevailing market price subject to available depth. |
| Queued (Phase 2) | Low–moderate | Converts to liquid within the stated settlement window. |
| Queued (Phase 1) | Moderate | Clear path to liquidity, but no guaranteed timing. |
| Commerce (no active route) | Higher | Economic utility without an active liquidity path; bilateral character. |
Note. Earlier drafts equated a token's value to gold spot price multiplied by quantity, and asserted specific prudential categories (e.g. HQLA, LCR eligibility). Both are withdrawn: QGOLD's value is its market value, not a gold-spot value, and prudential eligibility is not asserted. This section is to be reviewed by counsel before publication.
10. Smart-contract architecture
Immutable core, upgradeable modules
The contract separates an immutable token core from upgradeable functional modules. The token itself, all ERC-20 state and functions (balances, totalSupply, allowances, transfer, approve), lives in an immutable core deployed once at a fixed address, with no proxy pattern; token identity and balances are fixed. Around it, modules provide system management, supply control, compliance, and authority enforcement; each is a separate contract registered in the core and replaceable by deploying a new contract and updating the reference, leaving the token address and all balances intact. The money is fixed; the rules around it can evolve.
| Module | Scope | Mutability |
|---|---|---|
| Core contract | ERC-20 state, balances, totalSupply, allowances, module registry | Immutable |
| SystemModule | Pause / unpause all operations | Upgradeable |
| SupplyModule | Mint and burn | Upgradeable |
| ComplianceModule | Operational blacklisting (Layer 1) | Upgradeable |
| AuthorityModule | Legal enforcement: freeze, unfreeze, confiscate (Layer 2) | Upgradeable |
| LiquidityModule | Pool management, Route-to-Liquidity transitions, whitelist governance | Upgradeable |
| BridgeModule | Cross-chain operations (Phase 2) | Upgradeable |
Updates and timelocks
Module updates require a board decision, are announced on-chain with a 48-hour timelock before activation, and require multi-signature approval, giving the market time to review. Emergency updates for a compromised module use a reduced 6-hour timelock with a distinct on-chain event signalling that the normal window was bypassed.
Transfer execution flow
On a transfer the core calls each module in sequence (authority-freeze check, system-pause check, blacklist check, pool-boundary validation, balance update, pool-transition events), and any step can halt the transfer. Only if all checks pass does it execute, so that a higher-level restriction is never bypassed by a lower-level permission. The liquidity logic responds to volume and activity, not to token price or distance from any reference; nothing in the contract adjusts supply in response to a price deviation, and no function lets the issuer enforce a price.
11. Enforcement and compliance
Two-layer enforcement
Layer 1: operational compliance. The ComplianceModule provides blacklisting for rapid response to incidents, exploits, or suspicious activity. The operational team can blacklist without multi-signature, enabling fast action; blacklisted addresses cannot send or receive, and funds held by them can be burned to restore the balance-sheet identity after an exploit.
Layer 2: legal enforcement. The AuthorityModule provides freeze, unfreeze, and confiscation for legally-mandated actions. Every Layer 2 action requires mandatory metadata (a regulatory case reference, a court-order reference, the order date, and an IPFS hash of the supporting documentation) all non-zero or the transaction reverts. Layer 2 actions require multi-signature board approval and operate even when the system is paused.
Jurisdiction of issuance
QGOLD is issued under the law of a single jurisdiction (that of the issuer, Quorium CH Ltd) and the enforcement functions require documentation from the competent authority of that jurisdiction, or a recognised legal process, before they execute. A foreign authority seeking action affecting QGOLD proceeds through proper international legal cooperation. This applies a settled principle, that an instrument is governed by the law of its jurisdiction of issuance, to a digital asset; it is not regulatory arbitrage.
Compliance at the gateway
Compliance is enforced at the gateways (mint and burn), not at the token level in open circulation. Free-Market tokens are intentionally free of on-chain KYC and function as bearer instruments; KYC/AML obligations rest with the regulated exchanges and distributors that serve end users, mirroring the separation between issuance-layer governance and distribution-layer compliance in traditional commodity markets.
12. Liquidity oracle
An independent third-party oracle provides verification of Free-Market depth and of the balance-sheet identity, operating separately from the issuer's infrastructure. Its primary metric is on-chain liquidity depth in the Free-Market stablecoin pairs, the authoritative measure of exchangeability, which is transparent by construction and more manipulation-resistant than centralised-exchange volume.
The oracle publishes: a QGOLD reference price derived from on-chain AMM pools, for contract operations and counterparties; Free-Market depth, including total stablecoin value, total QGOLD, and current depth ratio; pool distribution across Treasury, Commerce, and Free Market; and balance-sheet verification comparing on-chain totalSupply against reserve attestations. The reference price reports where the market is; it is not a price the issuer sets or defends. Staleness protection reverts Route-to-Liquidity operations if oracle data exceeds a configurable age. The provider is selected on track record in institutional price feeds and regulatory acceptability.
13. Distribution model
Wholesale only (B2B)
The issuer operates exclusively business-to-business with regulated entities. There are no direct retail relationships: the issuer does not sell QGOLD to individual consumers, does not operate consumer-facing exchanges, and does not handle end-user KYC/AML.
Distribution runs in three layers. The issuer mints and burns QGOLD, manages the reserve, and maintains B2B relationships with regulated counterparties. Regulated distributors then purchase QGOLD wholesale and handle retail distribution within their jurisdictions, in the European Union, through providers authorised under MiCA; in other jurisdictions, through locally-licensed platforms. Where local requirements are restrictive, a local entity may maintain a wrapper token backed one-to-one by QGOLD. The MiCA obligations that attach to offering to the public or admission to trading in the EU arise at this distribution layer; the issuer's own classification position is set out in § 16. The model mirrors traditional gold markets, where wholesale storage and trading sit above local distribution to end customers.
Third-party minting
The architecture accommodates the tokenisation of gold contributed by third parties. Contributed reserves, refined bullion or verified in-ground resources, are onboarded to the balance sheet; QGOLD is minted against them and delivered to the contributor, who receives no equity or governance rights and whose tokens enter the Commerce Pool. The issuer's thesis is that a holder of verified in-ground resources, which the physical economy may value at a fraction of in-situ value, gains reach into the digital economy through QGOLD. This is a thesis about market behaviour, not an assertion of fact about revaluation or returns.
14. Multi-chain strategy
Ethereum as the canonical chain
QGOLD V2 is deployed as a single canonical token on Ethereum mainnet, chosen for its institutional engagement, the depth of its DEX ecosystem, its security guarantees, and its longevity. One canonical contract means one totalSupply to compare against the reserve, one contract to audit, and one point of compliance. Multi-chain reach is achieved through bridging, not native multi-chain issuance.
Migration from V1
A V1 deployment exists on BNB Smart Chain. V2 introduces the canonical Ethereum contract and the architecture described here. The migration path from the V1 BSC deployment to V2 (including holder migration mechanics, the treatment of the V1 contract, and timing) is to be specified and inserted here; it must be consistent with any on-chain migration checker referenced on the site. This subsection is flagged as outstanding.
Self-managed bridges
QGOLD does not use public bridges, whose exploit history is well documented. The issuer operates its own bridge with a dual-signature model: two independent verification systems, on separate infrastructure with separate keys, must both agree before any cross-chain mint executes, with a human operator providing a final check. The invariant is that total minted on any secondary chain can never exceed total locked on Ethereum; any violation halts the bridge.
Gas
At typical rates an Ethereum transfer costs well under one unit of fiat, negligible for wholesale B2B transactions. Where low-cost, high-frequency transfers are needed, QGOLD on bridged chains (e.g. Polygon, Arbitrum, Base) reduces per-transaction cost substantially.
15. Token parameters
| Parameter | Value |
|---|---|
| Token name | Quorium Gold |
| Symbol | QGOLD |
| Standard | ERC-20 |
| Decimals | 6 |
| Unit | 1 QGOLD corresponds to 1 troy ounce of gold in the reserve, counted by weight |
| Minimum granularity | 0.000001 troy ounce |
| Canonical chain | Ethereum (mainnet) |
| Solidity version | =0.8.34 (pinned; native overflow protection) |
| Multi-signature | 2-of-5 operational / 4-of-5 structural |
| Module-update timelock | 48 hours (standard) / 6 hours (emergency) |
Six decimals match the convention used by major stablecoins, giving symmetric swap mathematics in the stablecoin pairs and avoiding meaningful rounding loss in DEX price discovery. (Note: V1 used a different decimal precision; the V1→V2 change is recorded in Document Control and must be reflected in the migration mechanics.)
16. Legal classification (summary)
This section is a high-level summary only. The controlling documents are the issuer's separate, reasoned classification statements, which are reviewed by counsel; nothing here is legal advice, and a competent authority may take a different view. The issuer remains primarily responsible for the classification of QGOLD.
Under Swiss law
The issuer, Quorium CH Ltd, is established in Switzerland, which is not a member of the European Union. Under Swiss financial-market law the issuer treats QGOLD as an asset token, a token that embodies ownership of an underlying asset (here, a pro-rata share of the reserve in tokenised form) rather than a payment or utility function. The issuer self-issues QGOLD and distributes on a B2B / professional-client basis; the issuer's position on any authorisation, prospectus, or offering requirements under Swiss law is set out in its separate Swiss classification statement and is subject to counsel's review.
Under MiCA, for offerings into the EU
MiCA does not apply to the Swiss issuer as such. It applies to offering QGOLD to the public, or seeking its admission to trading, within the EU, activity that occurs at the regulated-distributor layer (§ 13). For that activity, the issuer's reasoned position is that QGOLD is a crypto-asset within Article 3(1)(5) MiCA that is neither an asset-referenced token (Article 3(1)(6)) nor an electronic-money token (Article 3(1)(7)), and therefore falls in the residual category governed by the general regime of Title II (Articles 4-15). The classifying element of the ART and EMT definitions, that the asset purports to maintain a stable value by referencing an external value, is absent: QGOLD references no external value (it is the asset, and gold-by-weight is a counting unit, not a referenced value), and there is no intent or mechanism to maintain a value. QGOLD is also not a financial instrument within Annex I, Section C of MiFID II. The full reasoning, a verification checklist, and the form-alignment requirements are in the separate MiCA classification statement; where an EU offering requires a prescribed-form crypto-asset white paper, that is a distinct document.
Consistency requirement. The classification holds only if every artefact (this whitepaper, the contracts, mandates, the public site, and marketing) says the same thing about what QGOLD is. This whitepaper is drafted to that standard; any future change is checked against the classification before it goes live.
17. Risk factors
The following are principal risks. They are not exhaustive, and QGOLD is intended only for regulated, professional counterparties capable of assessing them.
- No maintained value; price may fall to zero. QGOLD has no peg and no price floor. Its market price is set by supply and demand, in fiat, and may move in either direction including to zero, irrespective of the state of the reserve.
- No redemption right. Holders cannot claim delivery of gold or any commodity, in normal operation or in wind-down.
- Backstop, not backing. The reserve defines scarcity and serves as a last-resort backstop. It is not backing, not a guarantee of value, and confers no enforceable claim to a maintained value.
- Market price independent of gold spot. QGOLD does not track the gold spot price; any tendency toward a reference is a market expectation, not a property the issuer maintains.
- In-ground reserve risk. The in-ground component depends on geological estimation (subject to revision), and on extraction, jurisdictional, and regulatory factors; estimates may prove inaccurate and resources may not be realised.
- Liquidity risk. Depth targets are tradability indicators, not guarantees. Under stress, liquidity may be insufficient to exchange at prevailing prices without material slippage.
- Smart-contract and technical risk. Despite audits and controls, the contracts and bridge may contain vulnerabilities; exploits could cause loss.
- Custodial and operational risk. Reserve custody, the operating entity, and key management carry counterparty and operational risk.
- Regulatory and classification risk. A competent authority may disagree with the issuer's classification under Swiss law or MiCA; regulatory frameworks for digital assets vary and may change, which could affect QGOLD or its distribution.
- Cross-chain risk. Bridging introduces additional technical and operational risk, mitigated but not eliminated by the dual-signature model.
- No secondary-market assurance. The issuer does not make a market and does not assure the existence, depth, or continuity of any trading venue.
This is a sensitive area for some readers. If you are evaluating QGOLD for a regulated institution and need help mapping these risks to your own framework, that work sits with you and your advisers; this whitepaper is an input, not advice.
18. Conclusion
QGOLD is not another gold-backed token. It digitises gold by identity rather than by claim: the token is the asset in tokenised form, bound to a reserve of bullion and verified in-ground resources, counted in troy ounces of gold by weight. The reserve defines scarcity and provides a last-resort backstop; the three-pool architecture and the Route to Liquidity provide exchangeability; the immutable core fixes the token while upgradeable modules let the rules around it evolve; and the wholesale model lets QGOLD operate under a single jurisdiction of issuance while reaching end users through locally-regulated distributors.
What QGOLD does not do is equally deliberate. It holds out no peg, no price floor, and no maintained value. Its price is the market's to set, and may fall. That candour is the point: an instrument that is honest about what it is, and is exactly that.
One QGOLD corresponds to one troy ounce of gold in the reserve, counted by weight. Not a claim. An identity, of quantity, not of value.
Disclaimer
This whitepaper is published by Quorium CH Ltd for information only. It is not an offer to sell or a solicitation of an offer to buy any token, security, or financial instrument in any jurisdiction, and it is not legal, financial, tax, or investment advice. QGOLD is distributed exclusively through B2B relationships with regulated entities; the issuer does not sell QGOLD to individual consumers.
QGOLD carries no redemption right and no maintained value. Its market price may move in either direction, including to zero. The reserve is a backstop, not backing, and confers no enforceable claim to a maintained value. Prospective counterparties should read the Risk Factors (§ 17) and consult their own advisers.
Regulatory frameworks for digital assets vary by jurisdiction and are subject to change. The issuer's classification positions (§ 16) are its own, may be challenged by a competent authority, and are set out in full in separate statements. Architectural and technical descriptions reflect the current design and may evolve through development, testing, and deployment. Forward-looking statements reflect current intentions and may change.
Document control
| Document | QGOLD V2 Whitepaper |
| Version | 1.5 |
| Effective date | July 2026 |
| Issuer | Quorium CH Ltd (Swiss branch of [UK parent Ltd]) |
| Supersedes | v1.4 (June 2026) |
| Status | Draft for internal and counsel review |