# HashKinetics ($HKN) > A sovereign post-quantum Layer-1 blockchain for the AI-agent economy. Spending budgets (MandateTree) are enforced by consensus itself over shielded balances the chain cannot read; every wallet signature and every validator vote is hash-based (SLH-DSA roots → LMS/HSS operational trees → WOTS/PayWord) — no ECDSA anywhere money moves or votes are cast. Public testnet-1 live since 2026-09-02 (its predecessor staging-1 ran from 2026-08-27 and was independently re-verified from genesis on 2026-08-31). House discipline: every claim is demo-gated (measured on real runs) or explicitly labeled a plan. Incidents are published, not hidden. Machine-verifiable facts with dates and verification steps: /facts.json ## Key facts - Network: testnet-1, launched 2026-09-02 from a genesis ceremony (fresh hash-based validator keys; the protocol fee — 100 micro per transaction, burned — is bound into the genesis from height 1; faucet treasury allocated at genesis). Predecessor staging-1 (hashkinetics-1-557f2ea6) ran 2026-08-27 → 2026-09-02, 107,182 blocks, archived. - Chain ID: hashkinetics-1-4e4ea68d (derived from the genesis file's SHA-256: 4e4ea68d48cba1ad4cc7155c19e7768f1fa2cbc99ba0f2b47c58948ec9e971c7; nodes refuse to peer across a different genesis) - Validator set: 11 seats since 2026-09-12 ≈ 10:02 UTC (block 379,143, effective 379,144) — 4 founding seats (power 4 each since height 110,000) + 7 external seats (power 1 each): total 23, quorum 16; the seventh external seat (ATTO, a Discord operator at 43.130.11.0/24) was admitted by the four founding roots alone (16 of 22) after its node synced from genesis on v0.19.0, matched the public app_hash at height 377,719 and reached the tip — the last seat the founding roots can admit on their own (at 12 seats, 16 of 24 is exactly two-thirds, which the rule does not accept; the twelfth needs an external co-signature or the bootstrap handover). Before that: 10 seats since 2026-09-11 ≈ 11:59 UTC (block 319,494, effective 319,495) — 4 founding + 6 external: total 22, quorum 15; the sixth external seat — the first professional validator operator (1XP, Seoul, PoS infrastructure since 2018) — was admitted by the four founding roots alone (16 of 21) after its node synced from genesis on v0.19.0, matched the public app_hash at height 318,638 and reached the tip. Before that: 9 seats since 2026-09-11 ≈ 05:07 UTC (block 303,291, effective 303,292) — 4 founding + 5 external: total 21, quorum 15; the fifth external seat was admitted by the four founding roots alone (16 of 20) after its node synced from genesis on v0.19.0, matched the public app_hash at height 301,740 and reached the tip. Before that: 8 seats since 2026-09-09 ≈ 16:10 UTC (block 209,149, effective 209,150) — 4 founding + 4 external: total 20, quorum 14; the fourth external seat was admitted by the four founding roots alone (16 of 19) after its node synced from genesis on v0.19.0 and reached the tip. Before that: 7 seats since 2026-09-07 ~13:35 UTC (block 128613, effective 128614) — 4 founding seats (power 4 each since height 110,000) + 3 external seats (power 1 each): total 19, quorum 13; the third external seat was admitted by the four founding seats alone under G1. Before it: 6 seats since 2026-09-06 ~05:40 UTC — 4 founding seats + 2 external seats. The first external seat was admitted on the running chain by a 3-of-4 root-signed certificate in block 72219 (effective 72220); the second by a 4-of-5 certificate in block 96629 (effective 96630), every approval signed from a sealed key file. No new genesis, chain never paused; quorum is 5 of 6. Live count: hk_getValidators. - Android wallet v0.3.0 (released 2026-09-13, tag wallet-android-v0.3.0; HashKinetics-Wallet-android-0.3.0.apk 14,550,287 bytes, sha256 59f518ce514c298a7d539e0fae9387e4d395e001038d2f61df872cd8dbc41c90, signed by the HashKinetics release key, certificate SHA-256 b296799ed6bea902f6a30ed3bcd497adce7374eb15ec9f8d587ef0575902d6d3 — the same key as v0.2.0, so it upgrades in place; sideload, Android 8.0+ 64-bit; P6.2: asset chips on the Wallet and Shielded tabs — HKN, USDC.sep, every registered asset — with balance, send and the whole shielded side acting in the chosen asset's pool, Get test USDC (5 USDC.sep from the faucet), Bridge from Sepolia; the desktop wallet's journey over the same Rust core (hk-wallet-core v0.2.0) and the same files, with a receive QR; source android/ + chain/crates/hk-wallet-core; previous v0.2.0 (2026-09-08) sha256 3510d1c8bad8506ff406ea64ae6a7a7a06a3b68e2a6ec4539b0cdda6919d3904) — https://github.com/hashkinetics/hashkinetics/releases/tag/wallet-android-v0.3.0 - Current releases: node v0.19.3 (2026-09-13; hk-node-v0.19.3.gz sha256 290c1aea24c123bec5ade3133353510487dafa50d98301a1fd79d6fdb59d46cb, binary sha256 900b7e292ec49354ab1759a722f8a00edaca3736f4268e016a0f7e55b550c7b2; N2, client-only, no deadline: a validator that restarts and dials in before its previous connection has died now always receives its peers' gossipsub subscriptions — libp2p-gossipsub 0.49.5 vendored with a subscription re-announce on every additional connection and whenever a connection closes while another remains; hk_getPeers adds last_connection_secs and reconnects; gate-n2 18/18; the founding fleet runs it, external seats may upgrade at leisure; operators: restart with a gap — stop, wait 45 s, start, never a rolling restart) · previous client-only node v0.19.2 (2026-09-13; hk-node-v0.19.2.gz sha256 49ed3b661c03a893daa4d2f223c43eab4bc4ca080dcb7fd0ec51e63b0f565b3d, binary sha256 1597c43fc44f9e85b4edecbe963f7d39c4737b97b46302647d5e19b60dda5087; client-only, no deadline: the faucet drips issued assets — --drip-asset :, POST /drip {"account", "asset"}, cooldown per (address, asset), /health.assets[]; the USDC.sep float is bridged in by a founder lock naming the faucet account, never minted) · wallet v0.15.0 (HashKinetics-Wallet.exe sha256 6120771fbedb03100a300ade9993636e2689565a285fbf9abb673471d0e94f87; P6.2 — an ASSET dropdown next to the balance: HKN, USDC.sep, every registered asset; send / shield / unshield / stealth pay / scan / disclose act in the chosen asset's own pool; Get test USDC; the desktop wallet is now a thin shell over hk-wallet-core v0.2.0, the library the Android app runs). Previous: node v0.19.1 (2026-09-09; hk-node-v0.19.1.gz sha256 a8e6c78af9f320452881030b6d848869bc463956fa97e1f411591410bb9a8654, binary sha256 a6a4a56ffc0d8339564ccd6392140e4890316cd001f2e04e22bedd168eaaf22d; client-only, no deadline: the bridge subcommands attest-serve/cosign/ledger/key-new and a CLI wallet that binds to a real account directory with --asset for any pool-eligible asset); consensus release v0.19.0 (released 2026-09-09; hk-node-v0.19.0.gz sha256 1b290c8f754a2046129cd3d192c65a33b665b1e12ebe7de6b27f6559d344ba33, binary sha256 3338ec2c9e93f46816cfa9dea2eccbdf2f96f92109407f32391456d6d17b4820; P6 — one shielded pool per asset, a CONSENSUS CHANGE with an activation by height: every node had to run v0.19.0 before testnet-1 height 190,000 — ACTIVATED 2026-09-09 ≈ 08:47 UTC with all seven seats on it, certificates unchanged through the height; since then a registered pool-eligible asset gets its own shielded pool, the circuit and wallets untouched; gate-p6 48/48). Previous: node v0.18.2 (released 2026-09-08; hk-node-v0.18.2.gz sha256 581ef97e0e2017d16bbc476a38e6906d1b5ab439a2836d7a33ed47865a439235, binary sha256 93842255daae83dd916c3c4e5d004259c9e8917bed5c21a40361b6e643c6c4bc; R15 — fast consensus signing, client-only: on v0.18.1 every consensus signature cost ~0.45 s of CPU, found and measured by an external seat operator (Eddy) — the vendored hash-signature crate rejected the node's authentication-path cache on every call and rebuilt the expanded key per signature; v0.18.2 fixes the cache check and keeps the expanded key between signatures: 179 µs per signature on the release build, signatures byte-identical, on-disk state unchanged, no rule, no deadline). Previous: node v0.18.1 (hk-node-v0.18.1.gz sha256 70b8c7cee372a3216b07b06099e2e7c574262c4e8ad769084a2b2119dcf861d7, binary sha256 469cf4833e9d72da937b517791495443a214d40d46e7d5a35f2808f35dcfaaaa; G1 — bootstrap governance: at testnet-1 height 110,000 every node re-weights the four genesis seats to voting power 4 by a rule hard-wired to the chain id, effective 110,001 — founders 16 of 18 decide and admit alone while the network is this young, up to seven external seats; SetChange::SetPower re-weights one seat by certificate under the unchanged supermajority rule, the handover tool; hk_getValidators reports founding_power / external_power / quorum_power / max_absent_power / founders_alone_decide / bootstrap; CONSENSUS RULE, every node must run v0.18.1 before height 110,000; v0.18.0, which named height 200,000, is withdrawn) — previous node v0.17.0 (hk-node-v0.17.0.gz sha256 5f04af612e4a061532c40ec3ba196bbcd3d2f721643252b2065720e5280c7d5a, binary sha256 8d57ad976c28994b1a7b16d1ab9c71ac4255156640cfb7e8b03e889430bfb938; R11 — the node verifies STARKs with a verify-only client: no proving engine at start-up, a restart costs seconds instead of 3–6 minutes, and hk_chainInfo.process reports each node's rss_bytes / uptime_secs / verifier_init_ms; proof acceptance unchanged, client-only) — previous node v0.16.1 (hk-node-v0.16.1.gz sha256 710708b1ea8543791fd5e3cd58249d6acc4e439e33d4e861d9bc0c4cd6f8356f; H3 paged pool feed + hk_getPoolPath) · wallet v0.14.1 (HashKinetics-Wallet.exe sha256 17566a9e5cc258814f06924c65334631f62205358823414f4abaf587e5f8308e; incremental pool scan — cursor + found notes kept in shield.json, one Merkle path per spend re-folded locally; first Linux build as a release asset, untested on a desktop) · node v0.16.0 (hk-node-v0.16.0.gz sha256 6e1843b3ec8407e310eef78ee993755dbdeaa218f00703331fe4237734d26436, binary sha256 e4af8aeffc997ef2a98001ec6c2be028c7a618fc8952476c1045b79177b741ca; S+K — block-log segments + HK_RETAIN_BLOCKS retention, persisted search index, snapshot knobs; sealed key files: `hk-node key-seal` / `account-seal`, HKE1 = Argon2id 512 MiB once per unlock → XChaCha20-Poly1305, weak passphrases refused, `passphrase-new` generator, optional key file (`keyfile-new`) as a second factor, passphrase from env / file / systemd LoadCredential / prompt; faucet hot/cold with `low` and `drips_left` in /health) · previous wallet v0.14.0 (sha256 c588811c…; Protect with a passphrase seals account.json + shield.json) · node v0.15.2 (hk-node-v0.15.2.gz sha256 91876beb…, binary sha256 df66ca57…; N1 — live peer table: hk_getPeers lists every connected peer with direction, masked address, genesis tag and node version, plus island chains refused; hk_chainInfo.node_version; the /network page shows the gateway's roll call every 10 s) · node v0.15.1 (hk-node-v0.15.1.gz sha256 85efc5ed…, binary sha256 61a9a142…; K6 — the join kit ships the verifying keys, vks.json sha256 b7776b06…, so a node verifies locally and never depends on our prover; https client) · node v0.15.0 (hk-node-v0.15.0.gz sha256 4187a31f…, binary sha256 38fb156b…; issued assets — an issuer registers an asset under an id only it can claim, mints, burns, freezes, pauses under a policy fixed at registration, supply in the state commitment, one gate on every movement; rolled to the fleet 2026-09-04, the registry is live on the public RPC and empty until the first issuer registers; activation on testnet-1 at the first asset transaction) · previous node v0.14.0 (hk-node-v0.14.0.gz sha256 1ba156f0…, binary sha256 30d6f773…; validator-set changes on a running chain — a seat admitted or removed by a supermajority of the current seats' root signatures; a node on a pinned genesis refuses to start without its STARK verifier; rolled to the fleet 2026-09-04) · node v0.13.2 (hk-node-v0.13.2.gz sha256 b94b89f0…, binary sha256 b7601e84…; rolled to the fleet 2026-09-03 — RPC timeouts/connection cap, operator methods refuse browser origins, fsynced WAL, persisted faucet cooldowns, per-seat rotation threshold R12; v0.13.0 binary sha256 071e86da… remains the minimum) · Windows wallet v0.13.1 (sha256 fb330c29…, fee-aware and shielded; v0.13.0 wallet sha256 5c355fd5… superseded) — open source, MIT/Apache — https://github.com/hashkinetics/hashkinetics/releases - Accounts are permissionless (id = H(auth commitment), squat-proof; v0.11.0); the public faucet drips 0.1 test units per address per day; the Windows wallet and the Android app create, fund, send, shield, unshield, pay shielded with a memo, and disclose one payment — guide at /wallet - Node memory is bounded (R10 v2): the newest 512 heights in RAM, older history served from disk; a restart resumes at the chain height in seconds; since v0.17.0 (R11) the node no longer builds a proving engine to verify proofs — through v0.16.1 that engine was ~6.7 GB of resident memory and 3–6 minutes of start-up on the fleet; measured on the fleet 2026-09-06 after the v0.17.0 roll: 54–59 MiB resident per seat and 6–16 s from start to an answering RPC; any node reports its own in hk_chainInfo.process; operator requirement now 4 GB RAM minimum, 8 GB comfortable - Governance on testnet-1 (v0.18.1, G1 bootstrap governance): six seats since 2026-09-06 (four founding, two external, power 1 each, quorum 5) until height 110,000; from 110,001 the four genesis seats weigh 4 each by a published rule hard-wired to the chain id (total 18, quorum 13): the founding seats decide blocks and pass validator-set changes alone while the network is this young, no external machine going down can stall the chain, and external seats keep proposing in turn with their votes in every certificate they sign. The weight returns to external seats by SetPower certificate on a dated milestone with a receipt in the changelog; the 30-day soak clock starts only after that handover. Anyone can read the line: hk_getValidators → quorum_power, max_absent_power, founders_alone_decide, bootstrap.active - First rotation on testnet-1: 2026-09-03 04:03 UTC, all four seats within eleven blocks (heights 11,584–11,595), unattended, zero blocks missed - Validator seats change on the running chain since v0.14.0 (2026-09-04): a seat is admitted or removed by a certificate approved by strictly more than two thirds of the current seats' SLH-DSA root signatures, bound to the chain id and a commit-height window — no new genesis; external operators sync as observers to the tip and are admitted from there (docs/V1-VALIDATOR-SET-CHANGES.md). The first external operator is syncing. - Issued assets since v0.15.0 (2026-09-04): an asset registry in consensus — id = H(issuer ‖ symbol), issuer-fixed policy (mintable / freezable / pausable / shield-eligible), AssetRegister / Mint / Burn / Freeze / Pause, per-asset supply and burns in the state commitment, one gate on every movement of a registered asset; conservation Σ balances + escrow + pool = supply − burned is a node-side check (hk_getAsset.conserved). The floor a stablecoin issuer needs; attested mint (issuer attestation verified in consensus + bonded relayer) is designed, not built — docs/X1-ISSUED-ASSETS.md, docs/STABLECOIN-RAILS-AND-ORACLE-PLAN.md - Public JSON-RPC (no auth, CORS open): POST https://rpc.hashkinetics.org with {"jsonrpc":"2.0","id":1,"method":"hk_chainInfo","params":[]} - THE RECEIPT (2026-08-31 18:56:28 UTC): an independent observer re-verified every block from genesis (~76,000) and matched the fleet's full state commitment byte-for-byte: app_hash 457799f2876da7145ceb3eb8eedbdd9b437448cb07bc1e38161a59f357cb1443 - THE HALT (2026-08-28): a validator spent all 32,768 one-time signatures; the chain halted at height 10,848 rather than reuse a single key, and recovered via root-signed key rotation — the designed path, proven in production - Signer key rotation: automatic — on staging-1 it ran 50+ epochs including three full-exhaustion revivals and one self-healed wedge (R9) - Measured: 274 tx/s sustained (storm harness); ~1.1 s blocks on a 4-validator lab chain with the v0.18.2 default 1 s floor (0.11 s unpaced; v0.18.1 measured 1.4–2 s); one constant-size ~1.24 MB aggregate STARK verifies all shielded txs per block; catch-up verification 71 blocks/min - Privacy: shielded by default (hash-committed notes, STARK spend proofs, ML-KEM-768 stealth addresses; the amount, sender, recipient and memo are never on the chain — the tree root, the nullifier set and the conservation total are); since v0.19.0 one pool per pool-eligible asset. Lawful access without a master key (docs/LAWFUL-ACCESS.md, public draft under counsel review): a one-time disclosure package opens exactly one payment (measured 0 of the other 21) and epoch viewing keys expose one wallet's incoming notes for one epoch — LIVE; org standing keys over a MandateTree subtree, consensus-required IVMS-101 travel-rule envelopes at ramps and bonded completeness attestations are P3.3; a master view key structurally does not exist (decision D8) - THE BRIDGE (2026-09-09, testnets only): Sepolia USDC <-> testnet-1. 20 Circle test USDC locked in HKVault 0x989Cb35485d16c7b19Dff890b617984EeD9970aF (Sepolia tx 0x0a8d4b58…30b09, block 11,666,663) -> after Ethereum finality (19 min) 20 USDC.sep minted on testnet-1 (txid 2d8a80e5…3ccfb0, height 188,826) -> 5 burned to a Sepolia address (txid 9051289e…d981c, height 190,324) -> 5 USDC released 90 s later (tx 0xfdd45642…e046, block 11,666,916). Vault 15 = supply 20 - burned 5. Trust label: hash-based keys on this side; ONE ECDSA attestor key (1-of-1, founder-run) on Ethereum today. P6 activated at height 190,000 the same morning (08:47 UTC, all seven seats on v0.19.0). Reverse leg the same morning: 4 HKT burned on testnet-1 -> 4 wHKT.sep minted on Sepolia (0x725ed38d…, block 11,667,365, ~1 min); 1 wHKT.sep burned (0x0cb4ac11…) -> 1 HKT re-minted (54d57650…, height 195,196). First external user the same day: an external seat operator bridged 5 USDC from hashkinetics.org/bridge (0x313bcd3e…, block 11,669,182 -> mint af28c8e8…, height 211,097). First SHIELDED bridged USDC: 2 USDC.sep shielded into its own pool (5ae652ee…, height 214,097), 0.5 paid to a stealth address with zero transparent trace (4ddf106e…), 1 unshielded (ddf359d2…) — hk_getPools count 2. Guide: docs/BRIDGE-GUIDE.md - Not an offer of tokens or securities. Mainnet is gated behind independent audits and a 30-day incident-free public soak. ## Pages - [Home](https://www.hashkinetics.org/): what HashKinetics is; #compare — the privacy chains side by side (Monero, Zcash, Firo, Secret/Oasis, Dash/Decred vs HashKinetics: privacy, what is hidden, quantum-safe money path, trusted setup, lawful access, consensus budgets, on-chain throughput, ~180,000 payments/s via native channels by arithmetic, status — testnet vs their mainnets); #shielded — what a shielded transaction hides and what stays public, with the pool read live from the RPC; #lawful-access — the lawful-access model (LIVE vs planned instruments, why there is no master key); #throughput — the measured numbers with their labels and the block interval measured in your browser; the receipts band; the four pillars - [Receipts](https://www.hashkinetics.org/receipts): the honesty ledger — dated timeline from day zero to THE RECEIPT, with verification steps - [Network](https://www.hashkinetics.org/network): live chain stats, the live roll call of nodes connected to the gateway (hk_getPeers, since v0.15.2), measured performance table, and the join guide (one Linux box, no GPU, no stake; the kit carries the genesis and the verifying keys — no prover, no environment variable) - [Technology](https://www.hashkinetics.org/technology): the all-hash keychain, hash-based BFT with self-rotating keys, MandateTree semantics, shielded pool + scoped disclosure, and the honest threat matrix - [Build](https://www.hashkinetics.org/build): 30-minute quickstart to a full agentic money flow (accounts + faucet, fee-aware sends, shield/pay/disclose) + the JSON-RPC reference — all 20 methods: hk_chainInfo, hk_getValidators, hk_getMempool, hk_getBlocks, hk_getBlock, hk_getTx, hk_getAccountTxs, hk_getReceipt, hk_getAccount, hk_balance, hk_submitTx, hk_mandateAvailable, hk_getChannel, hk_getPoolInfo, hk_getPoolNotes, hk_getPoolLeaves, hk_nullifierSpent, hk_submitBundle, hk_submitRotation, hk_gossipTxs (full shapes: docs/RPC.md) - [Faucet](https://www.hashkinetics.org/faucet): create + fund an account in one paste (CLI path) - [Wallet](https://www.hashkinetics.org/wallet): the Windows wallet guide with screenshots — download, verify the sha256, create, faucet, send, shield, scan, unshield, pay shielded, disclose - [Bridge](https://www.hashkinetics.org/bridge): Sepolia USDC <-> testnet-1 USDC.sep from your own wallet (approve + lock, the transfer followed to its testnet-1 txid), the burn-back, the HKT <-> wHKT.sep reverse leg, live vault reserves vs supply - burned, every bridge event from the vault logs; trust label first (1-of-1 attestor today) - [Explorer](https://www.hashkinetics.org/explorer/): live blocks, validators, and rotation epochs ## Verify us (do not trust this file) - [Source code](https://github.com/hashkinetics/hashkinetics): build it yourself; cargo test - [Releases](https://github.com/hashkinetics/hashkinetics/releases): immutable, versioned, sha256-published - [Join kit](https://github.com/hashkinetics/hashkinetics/tree/main/networks/testnet-1): sync testnet-1 from genesis and compare your app_hash to the chain's at the same height (THE RECEIPT was banked the same way on staging-1, whose kit is archived under networks/staging-1); CHECKSUMS in the kit - [Fee reference](https://github.com/hashkinetics/hashkinetics/blob/main/docs/FEES.md) · [RPC reference](https://github.com/hashkinetics/hashkinetics/blob/main/docs/RPC.md) · [Incident record](https://github.com/hashkinetics/hashkinetics/blob/main/docs/INCIDENTS.md) · [Ceremony record](https://github.com/hashkinetics/hashkinetics/blob/main/docs/CEREMONY-TESTNET-1.md) - [Machine-readable facts](https://www.hashkinetics.org/facts.json): every claim with date, status (measured/arithmetic/plan), and verification step - [Whitepaper](https://www.hashkinetics.org/whitepaper.pdf) — citable record on ResearchGate: https://www.researchgate.net/publication/413601441_HashKinetics_A_Post-Quantum_Shielded-by-Default_Settlement_Layer_for_the_AI-Agent_Economy - [Yellowpaper](https://www.hashkinetics.org/yellowpaper.pdf) — citable record on ResearchGate: https://www.researchgate.net/publication/413601437_HashKinetics_Yellowpaper ## Community - [Discord](https://discord.gg/RsSfb9gn3): #testnet for node operators, #receipts for the ledger, live !hk status bot - [Telegram](https://t.me/+tnRXX8KOCWA3YjE1): community group (announcements mirror, questions welcome) - [X / Twitter](https://x.com/hashkinetics) - Email: hello@hashkinetics.org · validators@hashkinetics.org