Skip to content
ProtoLedger
v4.0 Apache-2.0 Open for Community Review

ProtoLedger Money Standard

A Two-Layer Standard for Evaluating Money and the Systems That Issue It

Fitness for purpose, at a stated readiness · Outcome-scored · Evidence-graded · Tail-aware · Value-disclosed · Falsifiable.

The M×S grid glyph (§VI.7): two scales, never summed.

What this is

A two-layer instrument for evaluating money and the systems that issue it. Layer A — Monetary Fitness asks whether a thing works as money for its users. Layer B — System Soundness asks whether the system behind it is sound. The two are scored on their own 0–10 scales and reported as a pair — never added, never blended.

Every property is scored on its outcome, not its mechanism; every score cites evidence of a named tier; reliability claims are scored on the tail, not the average day. Genuinely contested choices — privacy, personhood, issuance ethic, autonomy — are disclosed, never scored. And the Standard is falsifiable: §XII defines how any omission can be demonstrated and incorporated.

Specification
v4.0 · June 2026

7 Layer A properties · 10 Layer B properties · 8 Layer C disclosure axes · 5 use-case archetypes.

Layer A — Monetary Fitness

Does it work as money?
A1

Acceptability & Liquidity

Counterparties will take it, and it can be entered or exited at scale without large loss. The master property.

Evidence & detail →
A2 tail-scored

Value Stability

Predictable purchasing power over the relevant horizon. Short-horizon (unit-of-account) and long-horizon (store-of-value) figures reported separately. Tail-scored.

Evidence & detail →
A3

Usability & Safety

A non-expert can hold and transfer it without specialised skill, and survive error, loss, theft, and fraud without catastrophe.

Evidence & detail →
A4

Portability & Divisibility

Moves and splits cleanly at the scale and speed of real transactions, including across borders.

Evidence & detail →
A5

Fungibility

Units are interchangeable in practice; no unit carries history that degrades its acceptance. Scores the observed outcome, not the privacy design (see Layer C).

Evidence & detail →
A6

Recognizability

Easy for an ordinary holder to authenticate; hard to counterfeit. For digital instances: hard to spoof — fake tokens, ticker confusion, look-alike contracts, address poisoning, and phishing rank here.

Evidence & detail →
A7

Cost Efficiency & Capacity

Low cost to transact and to hold at the declared archetype's scale — not merely at today's load. Cost at current load is not capacity at target load.

Evidence & detail →

Layer B — System Soundness

Is the system behind it sound?
B1

Supply Integrity

No privileged party can quietly dilute holders; the issuance rule is known and hard to change. A fixed cap is not required — a rule-bound elastic supply qualifies.

Evidence & detail →
B2 tail-scored

Settlement Assurance

Confirmed transactions stay confirmed and behave as promised; no silent reversal, no double-spend. Tail-scored.

Evidence & detail →
B3

Resilience, Liveness & Capacity

Keeps settling — at usable capacity — through attack, outage, partition, and the failure or coercion of any single operator. (Liveness outcome: "does it keep running?")

Evidence & detail →
B4

No Single Point of Control

No one party can unilaterally rewrite state, censor transactions, seize funds, or gate participation arbitrarily. Includes resistance to cheaply manufactured consensus identities. (Integrity/censorship outcome.)

Evidence & detail →
B5

Rule Auditability

Anyone can independently verify the rules and the current state.

Evidence & detail →
B6

Forward Security Margin

Cryptographic and economic assumptions have headroom against foreseeable threats. Post-quantum readiness is one case, not the whole line.

Evidence & detail →
B7

No Invisible Rent

Operators cannot skim value from transaction ordering, position, or privileged information. The outcome that MEV-resistance targets.

Evidence & detail →
B8

Capture-Resistant Rule-Change

The rules for changing the rules are explicit and resist takeover by any single faction.

Evidence & detail →
B9

Resource Proportionality

Running cost is proportional to the value secured; no waste for its own sake. Mechanism-agnostic.

Evidence & detail →
B10 tail-scored

Claim Enforceability

Where the money is a claim on an issuer or custodian: the claim is legally enforceable, the backing is bankruptcy-remote, and redemption works in practice — including on a bad day. Tail-scored. Bearer instances with no claim structure: N/A by design, with the argument logged.

Evidence & detail →

Layer C — Disclosed, not scored

Contested values & mechanism facts

These are genuinely contested or purely descriptive. The Standard records a position and discloses it; it never marks a position "wrong" or awards points for it.

Privacy posture

contested value

From fully transparent, through fungibility-grade privacy, to total untraceability. (The outcome side — whether units are in fact discriminated — is scored in A5.)

Identity / personhood model

contested value

Anonymous → pseudonymous → verified unique human. Flagged dual-use: a personhood proof is at once a freedom tool and a powerful instrument of control.

Issuance ethic

contested value

Fixed cap, rule-bound elastic, work-based, egalitarian mint, or pre-allocated.

Autonomy ⇄ Accountability

contested value

Independence from issuer or state versus recourse, consumer protection, and legal acceptability.

Consensus / cost mechanism

mechanism fact

Proof-of-Work, Proof-of-Stake, BFT, institutional, or none.

Governance model

mechanism fact

Ossified, on-chain vote, or institutional — with its characteristic capture surface named: sclerosis, plutocracy, or opacity.

Jurisdictional posture

mechanism fact

Issuer/operator jurisdictions, applicable regimes, and known legal constraints on holders by region. (Whether a redemption claim is enforceable is scored in B10.)

Catastrophic failure modes

mechanism fact

The named worst cases for this instance — depeg, bridge failure, custodian insolvency, 51% capture, protocol bug class — with the tail-scored properties they feed (A2, B2, B10).

Archetypes & gates

The same subject scores differently across use-cases; that divergence is information, not noise. Each archetype names conjunctive gates that cap the verdict unless all hold.

# Archetype Evaluated for Gates (verdict capped unless all hold)
A Daily Medium of Exchange Retail payments and remittances: low friction, stable enough to price a coffee, safe for non-experts. A1 ≥ 7 and A3 ≥ 7
B Long-Horizon Store of Value Savings and reserve: supply integrity, resilience, durability across years. A1 ≥ 7 and B1 ≥ 7
C Censorship-Resistant Settlement Value movement no authority can stop. A1 ≥ 7 and B3 ≥ 7 and B4 ≥ 7
D Programmable Collateral / Base Layer Foundation for contracts and settlement: assurance, programmability, freedom from invisible rent. B2 ≥ 7 and B5 ≥ 7
E Unit of Account Denomination and pricing: stability of the measuring-stick over the short horizon. A2 (short-horizon) ≥ 7

Universal gates (all archetypes)

  • Any "money in use" / "ready today" verdict requires A1 ≥ 7 on the Today score.
  • Any "sound system" verdict requires B1 ≥ 7 and B2 ≥ 7 on the Today score.
  • Ceiling scores never satisfy a gate for a "ready today" verdict — only for a verdict explicitly labelled ceiling.
Versioning. This is v4.0. Earlier versions are archived and never silently edited — see v3.0 (archived). A score is always read as (subject, instance, archetype, standard version, assessment version, date).