As both a #security #researcher and #OpenSource advocate, I say forget the secure element.
I'm not sure exactly how cashu fits in here, but if it's just a matter of storing the tokens you get from the eCash server: require a PGP pubkey and encrypt the tokens with that. Simple, effective, and easy to audit.
Or ECC encryption, if you prefer that. 
ECC Encryption / Decryption | Practical Cryptography for Developers