Four products. One reserve.
Each answers a different part of the same problem: the same economic value now exists as separate tokens on separate networks, and nothing keeps them honest with each other.
Boli runs no chain of its own. Assets settle on the major networks they already live on — EVM, Solana, Stellar and Canton. Tenzro sits between them as a double-accounting layer and a buffer. Pilots read live mainnet contracts on Ethereum, Arbitrum and Solana, and two independent observers sign each epoch.
Σ circulating supply across all supported networks ≤ attested global reserve
The chain enforces this on every mint. A request for more units than the attested reserve covers is refused — not flagged, not logged, refused.
The keys stay with the person.
A wallet rooted in a passkey. The signing key is derived on the device from the passkey's own secret and never leaves the browser — not to us, not to anyone.
- An email gets you in, a passkey signs
- A code sent to your address opens a session and expires in ten minutes. It never signs for you — provisioning a passkey is a separate, visible step, because presenting them as one flow would suggest the code in your inbox is what protects your money.
- Derived, not stored
- Each chain surface gets its own key, derived from your passkey when you need it. There is no vault to breach because there is nothing at rest to take.
- Linked devices hold the same key
- Adding a phone wraps the existing key for that device's passkey. A second device is a second holder of one identity, not a second account to reconcile.
- Recovery without custody
- Guardians, a second factor, and a delay you can watch. Nobody is ever handed your key in order to give it back to you.
- Every network, one identity
- EVM, Solana, Stellar, Tenzro and Canton — one passkey behind all of them.
Live at console.boli.technology. One passkey across EVM, Solana, Stellar, Tenzro and Canton. A wallet that stops after the email is a real state — it can look around, and it says plainly that it cannot hold anything yet.
Issue once. Mint anywhere.
A pack is an asset's blueprint: what backs it, how many units may ever exist, which networks it may be issued on, and at what price. A buyer mints on the network they prefer.
- The purchase funds the backing
- Payment enters the reserve as the unit is created, so a unit is covered the moment it exists. There is no window in which it is not.
- One asset, one price
- A unit on Solana and a unit on an EVM chain are the same claim on the same reserve, so they cost the same. Pricing them differently would let someone buy on the cheap leg and redeem on the dear one until the reserve was gone.
- Redemption is priced, never gated
- A redeemer draining the cheapest network imposes a cost on everyone still holding, so they pay for it in proportion. Nobody is ever refused their own money for arriving late.
- Restrictions the token itself enforces
- A transfer-restricted asset is only issued on networks where the token can refuse an ineligible holder. One network without enforcement would not weaken that network — it would weaken the asset everywhere.
- A share reserved is authorised, not issued
- An issuer may reserve part of a pack's cap for named holders or for the people who build it. Reserving is not minting: the units are authorised against a public ceiling, and issuing them still has to clear the reserve. A claim on a pool is not money in it.
- Contributors are paid for work that happened
- The builder's share is a pool that claims are paid out of, each naming the contribution it is for, and the founder draws from it on the same terms as anyone else — marked as such in the data, so it can be read rather than taken on trust.
Packs mint as ERC-20s on the network the buyer chooses. A mint exceeding attested reserves is refused: post-mint supply 1101 exceeds attested reserves 1000.
Backing that is measured, not asserted.
A pack's reserve is normally a number its issuer states. Ground lets part of it be a number that hardware measured — sensors and models on devices with a TPM-rooted identity, producing signed readings that move what the asset is worth.
- The device, the model and its weights are all measured
- Change any of them and readings stop being accepted. A retrained model is a different valuer.
- Every reading carries its uncertainty
- Backing is credited at the conservative end of the estimate, and a reading that is unsure carries less weight automatically. Cameras fog and drones stay grounded; the asset falls back to its stated reserve without anyone intervening.
- The issuer decides how much it counts
- A weight set in advance, and stated in the asset's own units before it is chosen. It is not a question of how much you trust the feed — it is how much of the asset's value you are handing to a measurement.
- A window to object, open to anyone
- A new reading is published and held before it binds. Anyone can see it and anyone can challenge it, including people who do not hold an account.
Built and tested. A feed carries meaningful weight once its model is checked against ground truth.
One reserve, checked in public.
The layer the other three report to. Open agents read circulating supply on each network, compare it against the attested reserve, and publish the difference.
- Anyone can run an agent
- Monitoring is not a privilege granted by us. An agent reads public chain state and public attestations, and anyone who disagrees with what it publishes can say so on the record.
- Headroom is a number you can query
- Reserve minus circulating supply, live, per asset and per network. Without it, a supply drift is only visible to whoever is already looking.
- Boli holds nothing
- We never take custody of an asset and we perform no issuance. The protocol coordinates a view; the assets stay where they were.
- Soft by default
- Publishing the discrepancy is the default. Economic penalties are a choice an issuer makes per asset, not something imposed on them.
Pilot running on WBTC, USDC and USDT at their Ethereum, Arbitrum and Solana mainnet addresses, 300-second epochs, bridge lockbox netted. Two independent observers sign each epoch and their vectors are merged only when byte-identical.
Two substrates, neither of them ours to reinvent.
The middle layer between Boli and the networks: a second set of books that supply is accounted in again, and a buffer across chains that confirm at different speeds. Attested minting will not issue units the reserve does not cover.
Hardware identity for everything Ground reads from — sensors, edge computers, the network between them — rooted in each device’s TPM and the software it booted. A substituted device does not produce a worse reading; it produces one that is refused.
Attestation proves a reading came from the device and model that were registered. Validation proves it is right. A feed’s authority stays capped until its model is checked against ground truth, and no reading mints a unit the reserve does not cover.
A coordination layer for multi-network reserve coherence.
One publicly verifiable reserve state, reconciled continuously by open agents across every supported network.