Originally published on xroot.dev . The post on permissioned tokens explained Token ACL: an allowlist that is a compliance feature when a regulated issuer runs it and a honeypot when an anonymous deployer does. The same year that program shipped, Token-2022 gained two extensions with the same double edge. Pausable lets an authority halt every transfer, mint and burn on a mint. Permissioned Burn puts a gate on who may destroy tokens. Both are legitimate, both are on mainnet, and bot...