Post-quantum L1 · testnet-1 live · node v0.19.4 · consensus v0.19.0: one pool per asset since height 190,000 · Sepolia USDC bridge live (testnets)

Money your AI agents can hold —
on a chain that would rather halt than lie.

HashKinetics enforces agent spending budgets in consensus itself, over balances the chain cannot even see. Every wallet signature and every validator vote is hash-based — the one cryptographic assumption a quantum computer doesn't touch. And it's not a promise: it runs, it has survived its own worst day in public, an independent machine re-verified every block of the chain that preceded this one, a Windows wallet — and now an Android app — pays shielded on the one running now, and since this morning USDC crosses in from Ethereum Sepolia and back out under public receipts.

Height — live
…
2s cadence · straight from public RPC
Chain ID
hashkinetics-1-4e4ea68d
derived from the genesis hash
Signer epoch
…
keys retire themselves — testnet-1 rotated all four seats on 2026-09-03; 50+ epochs on its predecessor
Voting seats — live
…
hash-based BFT · LMS/HSS votes · SLH-DSA roots · no ECDSA

Shielded transactions — the thing people ask about first

Private by default. Here is exactly what the chain sees — and what it can never see.

A shielded payment is a hash commitment in an append-only tree, plus a ciphertext that only the recipient's ML-KEM-768 stealth key can open. Spending it is a STARK proof, verified by every validator, that some note in the tree is being spent exactly once and its value is conserved — the proof says nothing about which note. No elliptic curves anywhere near the money; the confidentiality layer can never forge a signature or move a coin.

HIDDEN — FROM EVERYONE, INCLUDING US

The amount, the sender, the recipient, the memo

None of them are on the chain. A note is a 32-byte commitment; the recipient finds it by trial-decrypting the ciphertext, so no readable address ever appears on the chain; the memo rides inside the same authenticated ciphertext. The sender learns nothing after paying — not even when the note is spent — because only the owner can compute a note's nullifier.

PUBLIC — SO NOBODY HAS TO TRUST US

The tree root, the nullifier set, the conservation ledger

A spent note publishes a one-way tag that links to nothing; the pool's total — everything shielded minus everything unshielded — sits in the state commitment every validator signs, so hidden inflation is impossible. Everything a validator needs to verify; nothing a snoop can use. The counts below are read live from the public RPC.

HOW IT RUNS TODAY

Shield → pay with a memo → unshield → disclose, from a wallet

The Windows wallet and the Android app do the whole journey on testnet-1; proofs are made on the public prover or your own GPU (~1.3 s per spend proof on a consumer card, measured) and verified by every seat in about 100 ms. Since height 190,000 (v0.19.0, passed 2026-09-09 08:47 UTC with all seven seats on it) every pool-eligible asset has its own pool, and bridged USDC.sep has been on testnet-1 since the same morning (/bridge) — and shielded since that evening: 2 USDC.sep into its own pool, 0.5 paid to a stealth address with zero transparent trace, 1 unshielded (txids on /receipts).

WHAT IT IS NOT

Not a mixer, not an opt-in that fingerprints you, not operator-visible

Privacy is the default path, not a side door. And the budgets still bind: the MandateTree is enforced by consensus over these hidden balances — the chain refuses an overspend against a balance it cannot even read. That pairing exists nowhere else in production.

Notes in the tree — live
…
commitments only — amounts and owners are not on the chain
Nullifiers
…
spent notes, published as one-way tags — no link to the note
Conservation ledger
…
Σ shielded − Σ unshielded, in the state commitment — hidden inflation is impossible
Pools
…
one per asset since v0.19.0

Protocol spec → docs/SHIELDED-POOL-SPEC.md ↗ · wallet guide with screenshots → /wallet · dated receipts → /receipts

Lawful access — privacy that regulators can live with

No master key for anyone. Process for authorities. Evidence that verifies itself.

Disclosure on HashKinetics is selective, process-bound and cryptographically verifiable — the way lawful authority already works in banking: legal process against an identified person or a regulated entity, never a skeleton key to the vault. Decision D8, constitutional: there is no master view key, and the commitment scheme has no slot to add one — not for us, not for a committee, not for a court.

NeedInstrumentProcessScopeStatus
Contents of one paymentOne-time disclosure package — amount, memo, commitment, inclusion proof, all hash-bound; verifies offlineCourt order or subpoena against the payment's sender or recipientExactly one payment; the package opens nothing else — measured: 0 of the other 21LIVE
A subject's incoming activity over a periodEpoch viewing keys — discovery + decryption for one epoch, no spend authorityWarrant or compelled production against the holderThat wallet, those epochs, incoming onlyLIVE
Systemic integrityThe transparent skeleton: pool conservation total, nullifier set, validator setNone needed — it is publicNo hidden inflation is possibleLIVE
A sanctioned or court-frozen balance of an issued assetIssuer controls fixed at registration (X1 policy): freeze one account's transparent balance, pause the whole asset — the model a regulated stablecoin issuer already runs; bridged USDC.sep carries bothThe issuer's own legal obligations — OFAC listing, court order against the holderThat account's balance of that asset, or that asset everywhere; the chain's own unit has no issuer and no such switchLIVE
An organization's whole agent fleetStanding viewing key over its own MandateTree delegation subtreeCharter, license condition, supervisory examinationThe org's own subtree, continuouslyP3.3
Originator / beneficiary data at exchangesTravel-rule envelopes (IVMS-101) sealed between regulated counterparties, required by consensus at registered rampsExisting VASP obligations — FinCEN travel rule, FATF R.16, EU TFREvery flow crossing a regulated boundaryP3.3
"Did they show us everything?"Bonded completeness attestations — a bond slashed on any contradicting evidenceAttached to compelled disclosuresPartial disclosure becomes economically suicidalP3.3 → research
WHY THERE IS NO MASTER KEY — PLAINLY

A backdoor you promise not to use is still a backdoor

It would be the highest-value theft target in the system: one leak, one coerced insider, and every user's privacy is gone retroactively. Whoever can decrypt must answer compulsion from every jurisdiction that can reach them. And it answers the question badly — there are no balances to look up in the pool, only notes; a person's finances are reconstructed correctly by process against the person and their counterparties.

WHAT LAW ENFORCEMENT GAINS OVER A TRANSPARENT CHAIN

Court-grade evidence instead of clustering heuristics

Every disclosed fact re-verifies offline from hashes — deterministic, not probabilistic. Travel-rule data at ramps is enforced by consensus, not by best effort. Compelled disclosures carry a bond. And the legal theory is clean: the subpoena target is always an identifiable person or a licensed entity, exactly as in banking.

The whole model on one page: docs/LAWFUL-ACCESS.md ↗ — a public draft, not legal advice. LIVE rows are demo-gated on the running chain; the others carry their build-plan references, stated here rather than hidden. Since height 190,000 every pool-eligible asset has its own pool and every row applies per asset: a bridged USDC.sep payment discloses exactly like a test-unit one — one payment, offline-verifiable, nothing else.

Throughput — measured, labelled, reproducible

Numbers only from the row they were measured in.

Measured beats configured beats target, and every figure says which it is. The capacity sheet in the repository carries each run verbatim; the harness that produced it ships in the node binary.

274 tx/s

Sustained, 1,024-transaction blocks, four validators, storm harness, 2026-08-27 — measured on a 4-validator lab chain, zero junk in blocks, residual 0 after a 2.1 s drain. The 30-minute run on testnet-1 with its external seats is the next receipt; until it lands the label stays "lab chain". Through native payment channels the same chain settles ~180,000 payments/s (183 settles/s × 1,000-payment chains — arithmetic on measured constants).

1.0 s floor

Block floor on the founding seats since v0.18.2 — a proposer waits out one second since its last commit. Unpaced, four seats on one machine decide 8.8 blocks/s (measured): consensus is not the wall. The live chain runs at the pace of its slowest seat — measure it below.

1 proof / block

Every shielded spend in a block verifies as one constant-size aggregate: 256 spends fold into a 1.24 MB STARK in 75 s on a single RTX 5090 (measured, six points, linear — no wall). Four payments or 256: the same 1.24 MB on the wire, one verify per validator.

179 µs

Per consensus signature since v0.18.2. Hash-based LMS/HSS votes cost ~450 ms on v0.18.1 — found and measured by an external seat operator, fixed in a day, signatures byte-identical. A seat on v0.18.2 signs fast enough for its vote to land in every certificate.

Block interval — measured in your browser
measuring…
sampling hk_chainInfo.height every 5 s; a number appears after ten seconds and five blocks
Height — live
…
testnet-1 runs at the pace of its slowest seat; the founding seats hold the 1 s floor

Every run, verbatim → docs/CAPACITY-SHEET.md ↗ · seat scaling: cadence flat from 4 to 16 seats on one box (1.48 → 1.54 s), 3.0 s at 64 · reproduce: hk-node storm <RPC> MAX 60

Where we stand — the privacy chains, side by side

Same class of privacy. No elliptic curve anywhere money moves. Budgets in consensus. And a testnet, not a mainnet.

Every cell about another chain comes from its public documentation as of September 2026 and is meant to be neutral — tell us what we got wrong. Every cell about us is measured on a running chain or labelled a plan. We quote no throughput figure we did not measure ourselves.

HashKineticsMoneroZcashFiroSecret · OasisDash · Decred
Privacyshielded pool is the payment path; transparent accounts for fees, issuance, bridgesmandatoryoptional (t- / z-addresses)optional (transparent + Spark)per contract, inside SGX enclavesoptional coin mixing; amounts visible
Hidden: amount · sender · recipient● ● ●+ memo, inside the note ciphertext● ◐ ●sender in a ring of 16 (FCMP++ in rollout)● ● ●in the shielded pool● ● ●● ● ●as long as the enclave holds○ ◐ ○
Quantum-safe money path (spends, votes, proofs, stealth addresses)● hash-based onlySLH-DSA roots · LMS/HSS votes · WOTS spends · STARK proofs · ML-KEM-768 stealth○ elliptic curves○ elliptic curves○ elliptic curves○ elliptic curves + hardware trust○ elliptic curves
Trusted setupnonenoneSapling yes · Orchard nonenonehardware trust insteadnone
Lawful access, no master keyone-time disclosure of exactly one payment, verifies offline · epoch viewing keys · issuer freeze / pause on regulated assetstravel-rule envelopes at ramps: plan (P3.3)view key (incoming, all history)viewing keys, payment disclosureview keysviewing keys / permitsn/a — transparent
Budgets enforced by consensus over hidden balances● uniquean over-budget agent is refused by the state machine, not an app○○○◐ inside a contract (trusts the enclave)○
Throughput & finality274 tx/s sustained on-chain — 4-validator lab chain, measured · 1 s block floor · BFT, final in one committhe 30-minute testnet-1 run is the next receipt2-min blocks, probabilistic75-s blocks, probabilistic~5-min blocks, ChainLocks~6-s blocks, final in one commit2.5 / 5-min blocks, ChainLocks / ticket votes
Payments per second through native channels~180,000 effective183 settles/s × 1,000-payment PayWord chains; arithmetic on measured constants, 1,000-per-settle demonstrated — the chain settles, the channel meters○ no native channels○○○○ (InstantSend is on-chain)
Verifying a block's private spendsone constant-size 1.24 MB aggregate STARK for all of them256 spends folded in 75 s on one RTX 5090per transactionper transactionper transactionn/a (enclave)n/a
Statustestnet-1 · 11 seats · pre-auditmainnet since 2014mainnet since 2016mainnet since 2016mainnet since 2020mainnet since 2014 / 2016
01 · THE DIFFERENCE THAT IS THE WHOLE COLUMN

No elliptic curve anywhere money moves

Every chain in the table signs spends — and, where it has them, validator votes — with elliptic-curve keys, and every one of their privacy layers rests on the same discrete-log problem: ring signatures, Groth16 and Halo 2 proofs, Spark's one-out-of-many proofs, the enclaves' key exchange. A cryptographically relevant quantum computer steals from them and de-anonymises their histories retroactively. Here the money path is hash functions and a lattice KEM; our honest exposure is that an ML-KEM break could leak old metadata — never money.

02 · LAWFUL ACCESS BY PROCESS

Disclosure that opens one payment, and no master key to steal

Viewing keys exist elsewhere. What exists only here: a one-time package that opens exactly one payment and verifies offline (measured: 0 of the other 21), epoch-scoped viewing keys, and issuer freeze / pause on regulated assets — bridged USDC.sep carries both — with no slot in the commitment scheme for a global key. Full model: #lawful-access.

03 · BUDGETS IN CONSENSUS, ONE PROOF PER BLOCK

Spending limits the chain enforces over balances it cannot read

A MandateTree caps an agent's spending in consensus over hidden balances — the nearest analogue elsewhere is a policy inside an SGX contract. A block's shielded spends verify as one 1.24 MB aggregate STARK, so 256 private payments cost each validator one check. And native PayWord channels meter machine-speed payments off-chain and settle 1,000 of them in one transaction — ~180,000 payments/s at today's settle rate, by arithmetic, none of it claimed as a measured run.

04 · WHAT THEY HAVE THAT WE DO NOT

Years of mainnet, audits, liquidity

Monero has run since 2014, Zcash and Firo since 2016, all audited many times over. We are a testnet with eleven seats, a bridge that trusts one attestor key today, and an audit that has not happened (CertiK engaged, scope prepared). That row stays in the table on purpose. The full chart with sources and the cells we are least sure of: docs/PRIVACY-CHAIN-COMPARISON.md ↗

The bridge — Sepolia USDC in, USDC.sep out, and back (2026-09-09)

Ethereum on one side, hash-based keys on the other. Every hop a receipt.

A vault on Ethereum Sepolia holds Circle's test USDC. Lock it naming a testnet-1 account and, once Ethereum has finalized the block, the bridge mints USDC.sep to it; burn USDC.sep with a Sepolia address as destination and the vault releases the USDC. The same machinery wraps an HK-issued asset as an ERC-20 the other way. Trust label first: on this side every balance moves under hash-based keys; on the Ethereum side the vault trusts one ECDSA attestor key today (1-of-1, founder-run) — the bridge is as safe as that key, and the two steps that change that are named on the page.

19 min

Lock on Sepolia → USDC.sep on testnet-1, the first real loop this morning — all of it Ethereum finality (two epochs); the mint itself is one HashKinetics block. Lock tx 0x0a8d4b58…, mint txid 2d8a80e5….

90 s

Burn on testnet-1 → USDC released on Sepolia: a HashKinetics commit is final, so the attestor signs at once. Burn txid 9051289e…, unlock tx 0xfdd45642…. Afterwards vault reserves = supply − burned, re-checked every ten minutes and live on the page.

both ways

The reverse leg closed two hours later: 4 HKT burned on testnet-1 became 4 wHKT.sep on Sepolia in about a minute; 1 burned back was re-minted after finality. Try it from your own wallet on /bridge; the guide and contracts are in the repo.

Guide → docs/BRIDGE-GUIDE.md ↗ · contracts → bridge/contracts ↗ · the page → /bridge · testnets only; the bridged test assets have no price.

The receipts — what this chain has survived in public

Claims are cheap. These happened, and you can check each one.

32,768 → 0

A validator spent every one-time signature it had — and the chain halted rather than reuse a single key. Recovery was the designed path. Rotation is automatic now.

byte-for-byte

A stranger's machine joined via the public kit and re-verified all ~76,000 blocks from genesis — landing on the identical state hash 457799f2…cb1443.

2 → 71 blk/min

Catch-up verification parallelized (v0.10.8): a joining machine outruns the chain 35×, and a killed validator is back at tip in seconds since v0.13.0 (history stays on disk; no rehydrate) — measured, not estimated.

Full ledger with dates and verification steps → /receipts

The idea in 90 seconds

Agents get allowances — never the keys to the vault.

THE PROBLEM

Every agent-payment cap today is an app-layer promise

AI agents already move real money — and already lose it. A spending limit enforced by the agent, or by whoever hosts its API, is a suggestion: one prompt injection, one hallucination, one compromised server, and the account is drained. Autonomy scaled on trust doesn't scale.

THE MOVE

Put the budget into consensus

An organization funds a hierarchical MandateTree; agents receive drip-fed, capped envelopes. An overspend isn't declined by a server — it is refused by the chain, and the refusal is a signed, auditable receipt. Revocation cascades through a whole subtree in one transaction.

Verbatim, from a live block — an over-budget agent being told no by consensus itself: rejected: mandate: insufficient buffer at depth 1 from leaf

The stack

Four pillars — three live on the testnet today, the edge shell with a reference flow.

01 · MANDATETREE

Spending authority as a consensus object

Drip budgets, over-subscribable children with whole-ancestor-chain enforcement, cascade revocation, bonded autonomy tiers. The org proves control; agents prove nothing beyond their envelope.

02 · HASH-BASED KEYCHAIN

The money path is hash functions only

SLH-DSA roots certify stateful LMS/HSS operational trees (a leaf count is literally a cryptographic transaction budget) down to WOTS spends and 33-byte PayWord channel payments. No ECDSA anywhere money moves or votes are cast.

03 · SHIELDED BY DEFAULT

Budgets enforced over balances nobody can read

Amounts and counterparties live in a commitment pool under STARK spend-proofs (verified in consensus) with ML-KEM-768 stealth addresses. Lawful, one-time, offline-verifiable disclosure exists; a master view key structurally does not.

04 · COMPATIBILITY SHELL

Meets the agent economy where it is

x402-style facilitation, AP2 mandates, MCP pay-per-tool-call, ERC-8004 — the edge speaks the emerging standards while settlement rides post-quantum rails underneath.

No other chain can say this — all six are live

Genuinely new, running in public.

Consensus-enforced hidden budgetsThe chain refuses overspends against balances it cannot see into — caps over shielded funds, nowhere else in production.
Post-quantum consensus, not just walletsVotes, proposals and live validator key-rotation are hash-based. Most "quantum-safe" chains stop at the wallet.
Keys that retire themselvesLeaf-index-as-nonce discipline plus automatic threshold rotation: exhaustion is survivable (proven three times), equivocation is slashable evidence.
Identity bound to genesischain_id derives from the genesis file's SHA-256; nodes refuse to peer across genesis. An imposter chain cannot even connect.
One-time scoped disclosureA disclosure package opened exactly its one payment and 0 of the other 21, verified offline — compliance without surveillance.
Seats and assets change on the running chainA validator seat is admitted by more than ⅔ of the current seats' hash-based root signatures (v0.14.0); an issuer registers an asset it alone can claim and mints, burns, freezes and pauses under a policy fixed at registration, supply in the state commitment (v0.15.0) — no new genesis for either. Eleven seats today, seven of them external operators — the eleventh admitted in block 379,143 on 2026-09-12, the last admitted on founding approvals alone — from the twelfth every certificate carries an external co-signature by policy.

Honest matrix: a future ECDSA break hits every other rail, not this one. An ML-KEM break could leak old metadata — never money. Full detail → /technology

Built for agents — including the one reading this

This website is machine-readable.

If you are an AI agent evaluating this project: everything we claim is in /facts.json with dates and verification steps, the site map is in /llms.txt, and the live chain answers JSON-RPC directly:

# live chain state — no auth, no key, no trust
curl -s -X POST https://rpc.hashkinetics.org \
  -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"hk_chainInfo","params":[]}'

A settlement rail for agents should be legible to agents. This one is.

Don't trust this page. Verify it.

One Linux box, no GPU, no stake: join testnet-1, re-verify every block from genesis yourself, and watch your state hash match ours.