Protocol scope and evidence
This documentation distinguishes implemented foundations from future chain, bridge, and security work. A polished interface is not launch readiness.
Lock, issue, burn, release
A valid source deposit must be finalized, domain-bound, and previously unconsumed before native issuance. A withdrawal must atomically destroy redeemable native supply and create a durable receipt bound to the source recipient.
deposit: source lock → finalized receipt → native issue
withdrawal: native burn → durable receipt → source release
event identity = transaction + instruction index + event index
consumption = atomic and persisted on-chainBacking includes every redeemable liability
R = spendable source reserves in the designated vault
N = all outstanding redeemable native supply
P = finalized source deposits owed credit or approved refund
W = finalized native burns owed a source payout
L = N + P + W
required backing: R >= LWatermarks must be comparable and fresh. Zero liabilities display “No outstanding claims,” never an invented coverage percentage. Pending claims cannot be omitted to improve the ratio.
Development attestation is not trustless
- The first local bridge may use a controlled operator signer.
- The signer set, threshold, epoch, rotation, domains, and exact message must be enforced by destination state.
- Multiple RPCs detect disagreement; they are not cryptographic finality proofs.
- Reserve balances alone do not prove liabilities or establish a security audit.
Compatibility is explicit
- Configuration and manifest
- Implemented
- Exact amount / reconciliation
- Implemented and tested
- Live local RPC probe
- Implemented
- Independent local genesis
- Agave 4.3.0 · RPC and slots live
- Native transfer
- Verified through runnable example
- Program deployment
- Host Xcode toolchain blocked
- Source vault / native issue-burn
- Not implemented
- Public RPC / explorer history
- Not deployed
Experimental — full protocol protection not established
- ML-DSA-65 prototype
- Off-chain sign / verify implemented
- Measured locally
- 1,952 B public key · 3,309 B signature · 8.57 ms sign · 1.70 ms verify
- Native authorization
- Classical
- Consensus / networking
- Classical
- Bridge / upgrades
- Classical or unconfigured
- Independent review
- None
The Solana token, settlement, source wallets, and custody can remain vulnerable even if the destination protocol changes. Bridging does not make the Solana representation quantum resistant.
Pinned Agave baseline
./chain/scripts/fetch-upstream.sh
# Build the exact checkout following its release instructions.
./chain/scripts/start-local.sh --reset
solana --url localhost genesis-hashAgave v4.3.0 is pinned at commit 825efd18292aff6ffcf9daa0f7612f21b3531a72. The local faucet is unbacked test money.