Two substrates, one reserve view
Assets settle on the major networks. Tenzro sits in the middle as a double-accounting layer and a buffer. Furcate supplies hardware identity for the devices Ground reads from. Boli supplies the registry, the observers, the challenge system and the headroom engine that turn them into a single reserve state.
Boli runs no chain of its own. Assets settle on the major networks they already live on — EVM, Solana, Stellar and Canton. Tenzro sits between them as a double-accounting layer and a buffer. Pilots read live mainnet contracts on Ethereum, Arbitrum and Solana, and two independent observers sign each epoch.
Boli runs no chain of its own.
Assets settle on the major networks they already live on. Tenzro sits between Boli and those networks as a double-accounting layer and a buffer. Furcate supplies hardware identity for the devices Ground reads from.
A second set of books between Boli and the networks. Supply read on each network is accounted again on Tenzro, and the two sets are compared every epoch.
Networks confirm at different speeds and epochs do not line up. The buffer absorbs the difference and reconciliation runs against a settled view.
Minting checks the request against the attested reserve and refuses anything exceeding it. Identity for issuers and observers, and the record each attestation is written against.
Each device Ground reads from has an identity rooted in its TPM and the software it booted — sensors, edge computers, and the network between them. A substituted device does not produce a worse reading; it produces one that is refused.
The software on a registered device is measured and signed per host. Changing what runs there changes what it can prove about itself.
Ground’s hardware sits on the premises of the party whose asset it measures. A TPM identity makes tampering visible there: resetting one takes firmware-level access to that specific machine, and the result is a device that no longer matches what was registered.
Enclave attestation assumes the attacker is not standing next to the machine. Intel and AMD both place physical attacks out of scope. WireTap extracted an SGX attestation key with a memory interposer for under $1,000, producing quotes indistinguishable from genuine ones. Battering RAM broke SEV-SNP attestation with a $50 device.
No enclave attestation covers model weights. SGX measures enclave pages, SEV-SNP a launch digest, and NVIDIA’s confidential computing carries no field for application data. Weights loaded at runtime fall outside all three. Ground pins the weights hash alongside the device.
Five components, one reserve state.
Reserve registry
On-chain records of registered assets, their representations on each network, the bridge routes between them, and the reserves attested against them. The canonical statement of what has been declared and by whom.
Supply observers
Network-specific readers that report circulating supply for each registered representation, at a pinned block. The same query returns the same answer to anyone who repeats it.
Bridge netting
Declared routes are subtracted at the source. A representation that has moved across a bridge is counted once.
Attestation & challenge
Anyone may submit reserve data or dispute it, inside a window that holds a new value before it binds. A challenge needs no account and nothing at stake.
Headroom engine
Attested reserve minus netted supply, per asset, published each epoch. Where no reserve has been attested it publishes that instead of a number.
Three assets, read from mainnet, every five minutes.
The coordination layer runs. It observes WBTC, USDC and USDT at their contract addresses on Ethereum, Arbitrum and Solana mainnet, nets the bridge lockbox out so the same coin is counted once, and anchors each epoch on Tenzro.
300 seconds. Each one publishes netted supply and, where a reserve has been attested, the headroom left against it.
WBTC is read on Ethereum and Arbitrum, and the canonical lockbox holding the Ethereum side is subtracted. The bridged supply is counted once.
Two independent observers watch the same contracts and sign each epoch separately. Their vectors are merged only when the signed bytes are identical — two nodes disagreeing about one epoch is equivocation, and the merge refuses it rather than picking a winner.
USDC and USDT report no headroom. Neither has a reserve source anyone can read without permission, so the feed records the absence as an absence — not checked, never checked and sound.
Each epoch is committed on Tenzro as it is produced, so a dispute argues with a record that already existed. Boli runs no chain of its own.
Bridges are inputs, not a reconciliation afterwards.
Supply is read natively on each network, and the routes between them are declared as part of the asset. A representation that moves across a bridge is netted at the source, so it is not counted on both sides.
Networks and bridges →Ethereum and major L2s. Supply is read directly from the token contract at a pinned block.
SVM-native supply reads from the mint account.
Stellar asset representations.
Daml-based representations, with party derivation verified against a live participant.
Lockbox and mint-burn routes are declared as part of the asset, so a representation that crossed one is netted at the source rather than reconciled afterwards.
Bonding attaches to measurement, not to reads.
Supply observers post no collateral. A reading names the block it was taken at, and anyone repeating the query gets the same answer.
Attested measurement is where collateral earns its place. A Ground reading happened once, at a place you were not, and cannot be re-run. Agents producing those readings are paid for the work and bond against it.
Settlement on the major networks. Coordination by Boli.
Tenzro in the middle as a second set of books and a buffer. Hardware identity from Furcate. The registry, the observers and the challenge system above them.