What Boli guarantees, and what it does not
A coordination protocol is only useful if its trust assumptions are stated plainly. Boli's strongest guarantee is about consistency between networks — not about the truthfulness of the reserve data it is given.
Reserve data is only as strong as the attestation sources provided at registration.
Boli reconciles circulating supply against an attested reserve. It can prove that the representations across every supported network sum to more than what was attested — it cannot, on its own, prove that the attestation was honest in the first place. A registered asset inherits the credibility of the sources declared for it.
Economic security around an open dispute process.
Reproducible reporting
Every supply reading names the block it was taken at, so anyone can repeat the query and get the same answer. Nothing is bonded and nothing is slashed — the check is that a false report is contradicted by the chain it claims to have read.
Permissionless dispute
Optimistic challenge windows allow anyone to dispute published state within a bounded period — no allowlist, no privileged challenger.
Parameters chosen per asset
Challenge delay, how far a single feed's authority may extend, and the reserve sources that count are set by the issuer at registration and published with the asset. There is no protocol-wide governance today, and no vote can change an asset's terms after it is issued.
No custody, no issuance
The protocol never takes custody of underlying assets and never mints the representations it counts.
Anyone can contest the state.
Submission and dispute of reserve data are both permissionless. Optimistic challenge windows give any participant a bounded period in which to contest published state before it is treated as settled — the same shape as an optimistic rollup's fraud-proof window, applied to reserve accounting.
An observer or attestor publishes reserve or supply data, naming the block it was read at.
Independent observers sign the same epoch separately and the signatures are merged only if the signed bytes match exactly. Nothing reconciles a near-miss: two observers publishing different numbers for one epoch is equivocation, and the merge refuses the pair rather than choosing between them.
The submission enters an optimistic window during which it can be disputed.
Any participant may challenge the submission, with no account and nothing at stake. Requiring either would filter out the holders most motivated to look.
A successful challenge withdraws the queued value, and the previous one stands until a newer reading arrives. An unchallenged submission settles into global state.
The protocol never takes custody of underlying assets.
This is a structural property, not a policy. Boli holds no keys to the reserves it observes and has no mint authority over the representations it counts. Even in hard mode, enforcement works through hooks an issuer chooses to adopt in its own minting logic — the protocol surfaces the condition; the issuer's own contract acts on it.
Nor of your keys.
The same property holds one level down, in the wallet. Signing keys live in your device's hardware and are derived per surface when they are needed. There is no seed phrase, no vault, and nothing at rest for anyone to take — including us.
Signing in has two halves with deliberately different authority. A code sent to your email opens a session and proves you can read that mailbox; it expires in ten minutes and it never signs. A passkey takes custody, and it is provisioned as a separate, visible step. Between the two, a wallet can look around and cannot hold anything — which it says, rather than implying the code in your inbox is what protects your money.
A passkey is bound to the origin that created it, so the wallet runs its own ceremony at its own address and only a public key ever crosses over. Recovery uses guardians, a second factor and a delay you can watch — nobody is handed your key in order to give it back to you.
Open your wallet →Guarantees you can check, not guarantees you're asked to take.
Reproducible readings, dispute open to anyone, terms set per asset and published with it, and no custody — the trust model is stated so it can be argued with.