Architecture

Two substrates, one reserve view

Assets settle on the major networks. Tenzro sits in the middle as a double-accounting layer and a buffer. Furcate supplies hardware identity for the devices Ground reads from. Boli supplies the registry, the observers, the challenge system and the headroom engine that turn them into a single reserve state.

Testnet

Boli runs no chain of its own. Assets settle on the major networks they already live on — EVM, Solana, Stellar and Canton. Tenzro sits between them as a double-accounting layer and a buffer. Pilots read live mainnet contracts on Ethereum, Arbitrum and Solana, and two independent observers sign each epoch.

The stack
Products
WalletPacksGroundMeta-reserve coordination
Boli protocol layer
Reserve registrySupply observersBridge nettingAttestation & challengeHeadroom engine
Substrates
Tenzro — double accountingTenzro — bufferTenzro — attested mintFurcate — TPM device identity
Networks
EVMSolanaStellarCantonBridges
Substrate — Tenzro and Furcate

Boli runs no chain of its own.

Assets settle on the major networks they already live on. Tenzro sits between Boli and those networks as a double-accounting layer and a buffer. Furcate supplies hardware identity for the devices Ground reads from.

Tenzro — the middle layer

A second set of books between Boli and the networks. Supply read on each network is accounted again on Tenzro, and the two sets are compared every epoch.

Tenzro — buffer

Networks confirm at different speeds and epochs do not line up. The buffer absorbs the difference and reconciliation runs against a settled view.

Tenzro — attested mint and identity

Minting checks the request against the attested reserve and refuses anything exceeding it. Identity for issuers and observers, and the record each attestation is written against.

Furcate — device identity

Each device Ground reads from has an identity rooted in its TPM and the software it booted — sensors, edge computers, and the network between them. A substituted device does not produce a worse reading; it produces one that is refused.

Furcate — signed system extensions

The software on a registered device is measured and signed per host. Changing what runs there changes what it can prove about itself.

Hardware identity, rooted in the TPM

Ground’s hardware sits on the premises of the party whose asset it measures. A TPM identity makes tampering visible there: resetting one takes firmware-level access to that specific machine, and the result is a device that no longer matches what was registered.

Enclave attestation assumes the attacker is not standing next to the machine. Intel and AMD both place physical attacks out of scope. WireTap extracted an SGX attestation key with a memory interposer for under $1,000, producing quotes indistinguishable from genuine ones. Battering RAM broke SEV-SNP attestation with a $50 device.

No enclave attestation covers model weights. SGX measures enclave pages, SEV-SNP a launch digest, and NVIDIA’s confidential computing carries no field for application data. Weights loaded at runtime fall outside all three. Ground pins the weights hash alongside the device.

Protocol — provided by Boli

Five components, one reserve state.

01

Reserve registry

On-chain records of registered assets, their representations on each network, the bridge routes between them, and the reserves attested against them. The canonical statement of what has been declared and by whom.

02

Supply observers

Network-specific readers that report circulating supply for each registered representation, at a pinned block. The same query returns the same answer to anyone who repeats it.

03

Bridge netting

Declared routes are subtracted at the source. A representation that has moved across a bridge is counted once.

04

Attestation & challenge

Anyone may submit reserve data or dispute it, inside a window that holds a new value before it binds. A challenge needs no account and nothing at stake.

05

Headroom engine

Attested reserve minus netted supply, per asset, published each epoch. Where no reserve has been attested it publishes that instead of a number.

Running today

Three assets, read from mainnet, every five minutes.

The coordination layer runs. It observes WBTC, USDC and USDT at their contract addresses on Ethereum, Arbitrum and Solana mainnet, nets the bridge lockbox out so the same coin is counted once, and anchors each epoch on Tenzro.

Epoch

300 seconds. Each one publishes netted supply and, where a reserve has been attested, the headroom left against it.

Bridge netting

WBTC is read on Ethereum and Arbitrum, and the canonical lockbox holding the Ethereum side is subtracted. The bridged supply is counted once.

Two observers, or none

Two independent observers watch the same contracts and sign each epoch separately. Their vectors are merged only when the signed bytes are identical — two nodes disagreeing about one epoch is equivocation, and the merge refuses it rather than picking a winner.

Where a reserve is missing

USDC and USDT report no headroom. Neither has a reserve source anyone can read without permission, so the feed records the absence as an absence — not checked, never checked and sound.

Anchoring

Each epoch is committed on Tenzro as it is produced, so a dispute argues with a record that already existed. Boli runs no chain of its own.

Networks

Bridges are inputs, not a reconciliation afterwards.

Supply is read natively on each network, and the routes between them are declared as part of the asset. A representation that moves across a bridge is netted at the source, so it is not counted on both sides.

Networks and bridges →
EVM

Ethereum and major L2s. Supply is read directly from the token contract at a pinned block.

Solana

SVM-native supply reads from the mint account.

Stellar

Stellar asset representations.

Canton

Daml-based representations, with party derivation verified against a live participant.

Bridges

Lockbox and mint-burn routes are declared as part of the asset, so a representation that crossed one is netted at the source rather than reconciled afterwards.

Where collateral sits

Bonding attaches to measurement, not to reads.

Supply observers post no collateral. A reading names the block it was taken at, and anyone repeating the query gets the same answer.

Attested measurement is where collateral earns its place. A Ground reading happened once, at a place you were not, and cannot be re-run. Agents producing those readings are paid for the work and bond against it.

The protocol

Settlement on the major networks. Coordination by Boli.

Tenzro in the middle as a second set of books and a buffer. Hardware identity from Furcate. The registry, the observers and the challenge system above them.