Qumbra

quantum + umbra — the innermost shadow, the region an eclipse makes fully dark quantum + umbra —— 本影,日食中被完全遮暗的那一块

A post-quantum privacy chain,
designed from scratch in 2026.
一条后量子隐私链,
从零开始按 2026 年的条件设计。

The “post-quantum privacy chain” question was last answered with 2018-era tools. Qumbra asks what the 2026 answer is — NIST PQC standards finalized, STARK proof systems production-mature, hybrid schemes with industrial precedent. All load-bearing cryptography is post-quantum. There is one shielded pool and everything is in it by default. 「后量子隐私链」这个问题,上一次被回答时用的还是 2018 年的工具。Qumbra 问的是 2026 年的答案是什么 —— NIST 后量子标准已定稿、STARK 证明系统已进入生产成熟期、混合方案已有工业先例。所有承重密码学都是后量子的; 只有一个屏蔽池,并且默认所有交易都在池内。

Three commitments the rest follows from三条承重约定,其余都从此推出

The PQ red line后量子红线

No elliptic curve carries weight anywhere in consensus. Hash-based STARKs over Keccak, ML-KEM-768 addresses and note encryption, ML-DSA committee votes. Conservative hash everywhere inside the proof system — the layered hedge an earlier draft proposed was retracted as unsound. 共识中没有任何一处由椭圆曲线承重。基于 Keccak 的哈希型 STARK、ML-KEM-768 地址与票据加密、 ML-DSA 委员会投票。证明系统内部一律使用保守哈希 —— 早期草稿里那套分层折中方案已被判定不成立并撤回。

One pool, private by default单池,默认隐私

Notes, not accounts. A single global shielded pool, not rings — the anonymity set is every note that ever existed. There are no protocol privacy tiers, because a tier is just a pool split, and a split pool is a smaller anonymity set wearing a feature's name. 用票据(note)而非账户。单一全局屏蔽池,而不是环签名 —— 匿名集就是历史上存在过的全部票据。 协议层没有隐私分级,因为分级本质上就是把池子切开,而切开的池子不过是顶着功能名字的更小匿名集。

Auditable without a backdoor可审计,但没有后门

Disclosure is the holder's to give, in four layers: standing viewing keys, a per-transaction disclosure STARK, exculpatory watch proofs, and the deposit edge. The coinbase is the chain's only transparent flow, which makes it the supply-audit anchor. 披露权在持有人手里,分四层:常驻查看密钥、单笔交易的披露 STARK、自证清白的 watch 证明, 以及入金边界。coinbase 是全链唯一透明的资金流,因此它同时充当供应量审计锚点。

Two inputs enter, two outputs leave,
and the box between them is opaque.
两路输入进,两路输出出,
中间那个盒子是不透明的。

That is not a metaphor for privacy. It is the frozen v1.0 circuit shape: every Qumbra transaction is exactly 2-in / 2-out — two depth-32 Merkle membership proofs, two nullifier PRFs, two spend-key knowledge proofs, two commitment well-formedness checks, and an in-circuit value balance. What happens inside the box is what the STARK proves without showing. 这不是一个关于隐私的比喻,而是已冻结的 v1.0 电路形状:每一笔 Qumbra 交易都严格是 2 进 / 2 出 —— 两条深度 32 的 Merkle 成员证明、两个 nullifier PRF、两个花费密钥知识证明、两个承诺良构性检查, 外加电路内的金额平衡。盒子里发生的事,正是 STARK 要在不展示的前提下证明的东西。

The mark deliberately encodes no parameter — no N=21, no 75 s. Those are frozen today and some still carry [devnet-placeholder]; a mark that encodes a number inherits that number's revisions. The 2×2 shape is different in kind: changing it would not be a parameter change, it would be a different chain. The 45° angles are geometry, not taste — both diagonal edges of a rotated square are perpendicular to the travel direction, so the lines meet the diamond square and need no mitre. 标识刻意不编码任何参数 —— 没有 N=21,没有 75 s。这些参数今天是冻结的, 但其中一部分仍标着 [devnet-placeholder];把数字画进标识,就等于继承这个数字的每一次修订。2×2 的形状 性质不同:改变它不是改参数,而是换一条链。45° 是几何而非品味 —— 正方形旋转后的两条对角边都与走线方向垂直, 所以线条正交地接上菱形,不需要斜接处理。

The load-bearing numbers承重数字

Measured in the prototype lab, not estimated. Lab numbers enter a design doc only after being reproduced twice on the same rig plus an independent rerun — every result records the git rev, the prover crate revs, the hardware, the OS and the power state. 这些数字是在原型实验室里测出来的,不是估的。实验室结果必须在同一台机器上复现两次并经过一次独立重跑, 才能写进设计文档 —— 每条结果都记录 git rev、prover crate rev、硬件、操作系统和电源状态。

145.1 KB
consensus transaction (148,625 B, b16 — as minted 2026-08-04)共识交易大小(148,625 B,b16 —— 2026-08-04 铸造版本)
~100 bit
conjectured FRI security, corrected accounting修正后核算下的 FRI 猜想安全强度
2.0 s
prove time, narrow Keccak AIR at 402 columns证明耗时,402 列窄 Keccak AIR
75 s
block time — RandomX-class PoW + Zawy LWMA-1出块间隔 —— RandomX 类 PoW + Zawy LWMA-1
21
BFT finality committee, Crosslink-shape, day oneBFT 终局委员会规模,Crosslink 形状,第一天就上
~52 MB/day
PQ compact blocks at launch (R=1)上线时的后量子紧凑区块带宽(R=1)
108
bessel per QMB — after the Besselian elements of eclipse computation每 QMB 的 bessel 数 —— 取自日食计算中的贝塞尔要素
65/15/20
miners / committee / treasury — fair launch, zero premine, no hard cap矿工 / 委员会 / 国库 —— 公平启动,无预挖,无硬顶

The PQ tax is real and accepted: roughly 20–30× the transaction size of curve-based state of the art. Aggregation rung 1 makes per-transaction proofs prunable after the block proof lands; the permanent cost is the ciphertexts, not the proofs. 后量子代价是真实的,而且是被接受的:交易体积约为曲线派最优方案的 20–30 倍。聚合 rung 1 让单笔证明在区块证明落地后 可被剪枝;永久成本是密文,不是证明。

The protocol stack协议栈

  1. Ecosystem & wallets生态与钱包 Mobile wallet is the product; one Rust kernel behind five shells (desktop, macOS, iOS, Android, browser extension), and the desktop shell has made a live on-chain spend. Binding exclusions: no L1 DeFi, no early bridges, no paid listings, no proving service.移动钱包就是产品;一个 Rust 内核,五个外壳(桌面、macOS、iOS、Android、浏览器扩展),桌面壳已完成一笔真实链上花费。硬性排除项:不做 L1 DeFi、不做早期跨链桥、不买上所、不做代证服务。
  2. Auditability & disclosure可审计与披露 Four-layer key/edge disclosure stack. No protocol tiers — a tier is a pool split.四层密钥/边界披露栈。协议层不设分级 —— 分级就是切池。
  3. Transaction layer交易层 Notes + one global shielded pool. Monolithic per-tx STARK with spend authorization in-proof, in-circuit value balance, 2×2 metadata buckets.票据 + 单一全局屏蔽池。单体式单笔 STARK,花费授权在证明内完成,金额平衡在电路内校验,2×2 元数据分桶。
  4. Note discovery票据发现 Launch on PQ compact blocks; discovery bound to the consensus wire (omission is consensus-invalid). OMR overlay sits behind a triple gate; FMD excluded.上线走后量子紧凑区块;发现数据绑定在共识线上(缺失即共识无效)。OMR 覆盖层设三重门槛;FMD 排除。
  5. Aggregation聚合 Rung ladder 0→2. Rung 1 proves per-block transaction validity plus an epoch supply-attestation rider; proofs prunable after.0→2 三级阶梯。Rung 1 证明整块交易有效性,并附带一个 epoch 供应量证明 rider;之后证明可剪枝。
  6. Consensus共识 RandomX-class PoW for block production, N=21 BFT finality committee with ML-DSA votes, 24 h epochs, slash 10% + tombstone. ZIP-317-shape posted fees.出块用 RandomX 类 PoW,N=21 的 BFT 终局委员会以 ML-DSA 投票,epoch 24 小时,罚没 10% 并墓碑化。费用采用 ZIP-317 形状的明码费率。
  7. Network网络 P2P with peer discovery and hardening. Dandelion++ and Tor are defense-in-depth — never anonymity load-bearing.P2P,含节点发现与加固。Dandelion++ 与 Tor 属于纵深防御 —— 绝不让它们承担匿名性。
  8. Economic base经济基础 Fair launch, zero premine. Smooth closed-form decay into a perpetual tail — no halving cliffs, because every cliff re-opens the dev-fund question on a timer.公平启动,零预挖。平滑的闭式衰减进入永续尾部发行 —— 不设减半悬崖,因为每一次悬崖都会按时重启一轮开发基金之争。

Where it actually is目前真实进展

Status-first, including the parts that are not working. As of 2026-08-17. 状态优先,包括跑不通的部分。截至 2026-08-17。

T1 public mining — OPENT1 公开挖矿 —— 已开放

Since 2026-08-16 anyone can run a node and mine — no registration, no permission, a CPU is enough. The door opened only after both real-money paths had actually run: the first user journey (2026-08-10: faucet → detect → spend → receive, proved in 3.62 s on the user's own laptop) and the first miner journey (2026-08-16: 574 blocks mined to an ordinary wallet, the coinbase matured, was spent, and the recipient detected it). 自 2026-08-16 起,任何人都可以运行节点并挖矿 —— 无需注册、无需许可,一颗 CPU 就够。开门之前,两条真实资金路径都已真正跑通:首个用户旅程 (2026-08-10:水龙头 → 检测 → 花费 → 收款,在用户自己的笔记本上 3.62 秒完成证明),以及首个矿工旅程 (2026-08-16:向一个普通钱包挖出 574 个区块,coinbase 成熟、被花费、收款方成功检测)。

The chain underneath — soaked and drilled底下这条链 —— 泡过、演练过

Four node hosts, three continents, one Terraform state; genesis 138e1524…addb minted 2026-08-04, reproduced byte-identically twice, running since. A 48-hour WAN soak sealed the consensus core; all four scenario drills — restart, late-joiner, committee stall, 2+2 partition — were adjudicated PASS: no safety stop-point was reached in any of them. A stranger's node syncs in minutes, not hours. Every incident to date has been liveness, never safety. 四台节点主机、三个大洲,共用一份 Terraform 状态;创世 138e1524…addb 于 2026-08-04 铸造,两次逐字节复现,持续运行至今。48 小时广域网浸泡测试封存了共识内核;四项场景演练 —— 重启、后加入者、 委员会停摆、2+2 网络分区 —— 全部裁定通过:任何一项都没有触及安全性停止条件。 陌生节点分钟级完成同步,而不是数小时。迄今所有事故都是活性问题,从未涉及安全性。

The supply audit worked — once, for real供应量审计真的抓到过一次

Consensus never validated the coinbase against the emission schedule, and the audit found exactly one under-paying block on the live net (height 1377, −4,114 bessel), fleet-unanimous. The schedule is now a validity rule: activated 2026-08-12 at height 8,640 via a planned halt — unanimous finality id across the fleet, emission audit clean on resume. The coinbase-as-audit-anchor thesis above got its first real test and held. 共识层此前从未用发行时间表校验 coinbase,而审计在运行中的网络上恰好找到一个少付的区块 (高度 1377,−4,114 bessel),全集群一致确认。发行时间表现已成为有效性规则:2026-08-12 经计划停机在高度 8,640 激活 —— 全集群 finality id 一致,恢复后发行审计零差异。上文「coinbase 即审计锚点」的立论迎来第一次实战检验,并且成立。

Honest limits诚实的边界

T1 is a testnet: coins have no value and will not survive the next re-genesis. Block production is permissionless, but the finality committee is still operator-run — decentralizing it is a later phase. The development tree (design docs, node source, deployment) stays private during T1 and opens on its own schedule; the public docs mirror it at publication. ⚠️ Binaries published before the upcoming name-service release stop following the chain at height 19,008 — update before ~Aug 21. T1 是测试网:币没有价值,也不会在下一次重新创世后存续。出块无需许可,但终局委员会仍由运营方运行 —— 去中心化是后续阶段。开发树(设计文档、节点源码、部署)在 T1 期间保持私有,将按自己的节奏开放; 公开文档在发布时与其同步。⚠️ 在即将到来的 name-service 版本之前发布的二进制,会在高度 19,008 停止跟链 —— 请在约 8 月 21 日前更新。

The authoritative public record is the T1 announcement and the live chain-health page; found something broken, open an issue. The project's full roadmap lives in the development tree, private during T1. 权威的公开记录是 T1 公告实时链健康页;发现问题请提 issue。 完整路线图在开发树中,T1 期间保持私有。

Read the T1 announcement阅读 T1 公告

What's public公开的部分

The development tree — design docs, node source, deployment — is private during T1 and opens on its own schedule. What follows is public today, and the public docs mirror the tree at publication. 开发树 —— 设计文档、节点源码、部署 —— 在 T1 期间保持私有,将按自己的节奏开放。 以下是今天已公开的部分;公开文档在发布时与开发树同步。