Skip to content
ProtoLedger
v2.0 Apache-2.0 Assessed vs Standard v3.0

ProtoLedger Core

Speculative — ceiling verdict, never ready-today

A peer-to-peer electronic cash system and programmable settlement layer, assessed against the ProtoLedger Money Standard on the Standard's own terms. DAG-BFT consensus, post-quantum cryptography, zk-STARK privacy by default, structural MEV elimination, and an optional proof-of-personhood layer anchoring an egalitarian monetary base.

M 5.3 / S 7.2
M = Layer A mean · S = Layer B mean · never summed
Archetype D · ceiling read
Illustrative pair under a ceiling (best-buildable) reading — not a measurement.
Gate check: capped

CAPPED. A1 (Acceptability) = 0 fails the ≥ 7 gate → no "money in use / ready today" verdict. B1 ≥ 7 and B2 ≥ 7 are met on a buildable reading, so a labelled ceiling "sound system" read is permitted — and labelled as such.

Declared archetype
D (Programmable Collateral / Base Layer) for the system; money read against B (Store of Value); explicitly weak against E (Unit of Account).
Readiness target
ceiling, not "ready today"
Readiness mix
0% achieved · 80% buildable · 20% speculative

ProtoLedger Core

A Peer-to-Peer Electronic Cash System, Assessed Against Its Own Yardstick

Specification v2.0 · June 2026 · Standard-Aligned Edition · Open Community Standard

Authored by Oleh Bezuhlyi. Companion to "Bitcoin: A Revolution That Never Happened?" and to the ProtoLedger Money Standard. Released under Apache 2.0 — fork it, challenge it, build it.

Framing statement. ProtoLedger Core (PLC) is a speculative protocol specification — a coherent blueprint for a distributed ledger built to the maximum extent permitted by current research and hardware. This edition makes one change of posture from v1.0: it stops grading its own exam. v1.0 scored itself 100/100 against ten principles it defined. That number measured nothing — a design that has never met production always wins on paper. v2.0 instead assesses PLC against an external instrument, the ProtoLedger Money Standard, on that Standard's own terms. The cryptography, consensus, and privacy primitives are real and largely buildable today. The network, the token, the foundation, and the consumer identity hardware are not. Under the Standard's readiness rule this document can therefore earn, at most, a labelled "ceiling" verdict — never "ready today."

Abstract

We present ProtoLedger Core — a peer-to-peer electronic cash system and programmable settlement layer designed from first principles, unconstrained by path dependency, incumbent interests, or the need to raise a venture round. PLC integrates a DAG-BFT consensus backbone (Shoal++ lineage) targeting sub-second deterministic finality; post-quantum lattice cryptography with built-in algorithm agility; default zk-STARK transaction privacy with selective disclosure; a Proof-of-Useful-Stake validator mechanism; structural MEV elimination via content–metadata separation; on-chain quadratic-vote governance; and an optional biometric proof-of-personhood layer that anchors an egalitarian, population-indexed monetary base.

Token: ProtoLedger Core (PLC). Supply (post-personhood): N × B, where N = verified living identities and B = 1,000 PLC (constitutional constant). Smallest unit: 1 nanoPLC = 10⁻⁹ PLC.

System overview: four interoperating layers

LayerNamePrimary outcomes served (Money Standard)
Layer 0NetworkB3 Resilience & Liveness, B4 No Single Point of Control
Layer 1ConsensusB2 Settlement Assurance, B7 No Invisible Rent
Layer 2Execution & PrivacyA5 Fungibility, B5 Rule Auditability
Layer 3Identity & GovernanceB8 Capture-Resistant Rule-Change; Layer C identity disclosure

Key design points

  • Consensus — DAG-BFT with Proof-of-Useful-Stake. Data dissemination is separated from consensus ordering (Narwhal → Bullshark → Shoal++ lineage). Safety holds while fewer than n/3 validators are Byzantine, under partial synchrony. The often-quoted ~47,000 TPS at 128 validators is an illustrative projection, flagged Buildable, not Achieved. Proof-of-Useful-Stake rewards verifiable work (zk-STARK proof generation, data-availability sampling) with an α = 0.4 cap so the wealthiest validators cannot also capture consensus through hardware.
  • Cryptography — post-quantum with algorithm agility. The mandatory baseline is ML-DSA (Dilithium, FIPS 204), finalised August 2024; the signature scheme is a governable, swappable parameter, not a hard-wired choice. FN-DSA / Falcon is not a finalised standard (FIPS 206 draft, expected late 2026 / early 2027) and is only permitted once final. Key encapsulation uses ML-KEM-768 (FIPS 203). Proofs use Circle STARKs — no trusted setup, post-quantum by construction.
  • Privacy — shielded by default. Every transaction is private; a transparent transfer is the opt-in exception, so each transaction contributes to every other's anonymity set. Viewing keys and compliance proofs give the holder time-boxed, revocable disclosure — never a protocol backdoor. Privacy posture is a contested value: it is disclosed, not scored.
  • MEV — eliminated structurally. Content (amount, recipient, proof) is encrypted under the recipient's ML-KEM key before gossip; validators order by fee bid on metadata only; content is decrypted only after the order is irrevocably committed. With no visibility into content there is no profitable reordering. Targets outcome B7, No Invisible Rent.
  • Identity — Sybil-resistant proof of personhood, honestly bounded. DNA is rejected as a biometric root (it is shed everywhere, unrevocable, and a political non-starter). The stack is iris (uniqueness) + subdermal vein (liveness) + attested challenge–response (binding). Templates never leave the device. The "100% reliable" claim is removed and replaced by: "Best-achievable Sybil resistance under a stated threat model, with published FMR/FNMR, graceful degradation, and live re-attestation — coercion-resistance and enrolment integrity identified as open problems."
  • Token economics — egalitarian, hybrid boot. Layer 1 runs permissionlessly and pseudonymously from genesis with a rule-bound, transparent bootstrap issuance; the egalitarian per-human mint (every verified human mints exactly B = 1,000 PLC once) activates once personhood is live. No pre-mine, founder tranche, or investor allocation. The fairness–stability tradeoff is disclosed, not defined away: PLC optimises supply integrity and issuance fairness (B1) at the cost of value stability (A2), making it a strong candidate base-layer and a poor stand-alone unit of account.
  • Governance — on-chain, quadratic. Vote weight is quadratic in stake × an identity factor (1.0 unverified → 2.0 full biometric). Capture surfaces are disclosed, not hidden: residual plutocracy before personhood is live, and potential sclerosis from high amendment thresholds.

Section 11 — Self-assessment against the ProtoLedger Money Standard

This section replaces v1.0's 100/100 scorecard. It applies the Standard honestly: outcomes scored 0–10, a readiness flag on every line, contested values disclosed not scored, and — critically — the gates applied. Because no network runs, A1 Acceptability is absent, which caps the verdict at a labelled ceiling. The scores below are judgement-based illustrations under a ceiling (best-buildable) reading, not measurements.

Declared archetype: D (Programmable Collateral / Base Layer) for the system; the money is read against B (Store of Value), and is explicitly weak against E (Unit of Account). Readiness target: ceiling, not "ready today."

In plain terms: as a blueprint, PLC's system soundness is strong and largely buildable; its monetary fitness is gated by the fact that it does not yet exist and, by design, trades stability for fairness. The two numbers are reported as a pair and never summed. The project does not grade its own exam against running chains; third parties are invited to score PLC by the same public methodology.

Open problems

  • Resource budget. Publish per-validator bandwidth and storage at target throughput, and a state-expiry / statelessness plan, before quoting any TPS figure as more than a ceiling.
  • Monetary unit-of-account. Specify the pricing instrument or stabilisation layer that carries unit-of-account duty, since PLC itself is a poor measuring-stick by design.
  • Enrolment integrity. Decentralised, adversarial, multi-operator enrolment with a dispute window — the root of trust the biometric cannot itself establish.
  • Coercion and credential rental. A formal threat model and proof that live re-attestation raises proxying cost enough in practice. Currently unsolved.
  • Personhood hardware. A certified iris + vein + secure-enclave peripheral at consumer price points, with an open attestation protocol. Speculative.
  • Execution-layer formal verification. Full Lean 4 verification of WASM semantics, opcodes, and gas accounting — not yet achieved by any production VM.

"Bitcoin won the price war. The cypherpunk dream did not. ProtoLedger Core is a blueprint for what winning might have looked like — and an honest account of how far it still is from running."

Layer A — Monetary Fitness (scored on outcome)

Layer A mean (illustrative): ~5.3 / 10 — but the A1 gate fails, so any "money in use" verdict is capped regardless of the mean.

# Property Score Readiness Note
A1 Acceptability & Liquidity 0 Absent No network, no counterparties. Fails the A1 ≥ 7 gate → no "ready today" verdict possible.
A2 Value Stability 2 Speculative Population-indexed base says nothing about purchasing power; fairness is traded for stability by design.
A3 Usability & Safety 5 Buildable Layered keys and recovery are designed, but biometric onboarding friction and lockout risk are real.
A4 Portability & Divisibility 8 Buildable nanoPLC divisibility, sub-second finality, optional channel mesh.
A5 Fungibility 9 Buildable Privacy-by-default means no unit carries degrading history. A genuine strength.
A6 Recognizability 7 Buildable STARK-verified, light-client checkable.
A7 Cost Efficiency & Capacity 6 Buildable Low fees by design; unproven at scale and resource budget unpublished.

Layer B — System Soundness (scored on outcome)

Layer B mean (illustrative): ~7.2 / 10. B1 ≥ 7 and B2 ≥ 7 are met on a buildable reading, so a ceiling "sound system" verdict is available — but not a "ready today" one, since nothing is flagged Achieved. (Assessed against Standard v3.0, before B10.)

# Property Score Readiness Note
B1 Supply Integrity 7 Buildable N × B rule is transparent and hard to change; the active-human count it depends on is Speculative until personhood is live.
B2 Settlement Assurance 8 Buildable Deterministic BFT finality; no reorg under f < n/3.
B3 Resilience, Liveness & Capacity 7 Buildable DAG-BFT liveness under partial synchrony; validator decentralisation unproven in practice.
B4 No Single Point of Control 6 Buildable Consensus is stake-based; the enrolment-operator and registry honeypot risk on the identity side pulls this down.
B5 Rule Auditability 8 Buildable Open spec, STARK proofs, light-client verifiable. Full Lean 4 execution-layer verification is Speculative.
B6 Forward Security Margin 8 Buildable PQC from genesis with algorithm agility — the corrected, stronger version of v1.0's claim.
B7 No Invisible Rent 8 Buildable Content–metadata separation eliminates MEV structurally.
B8 Capture-Resistant Rule-Change 6 Speculative Quadratic + identity-weighted voting; true 1p1v depends on personhood. Pre-personhood it leans plutocratic.
B9 Resource Proportionality 7 Buildable PoS-class energy; but state-growth and bandwidth are unbounded as written — see the resource-budget gap.

Layer C — Disclosed, not scored

Privacy posture

Privacy-by-default with voluntary selective disclosure — high on the privacy axis, short of total untraceability.

Identity / personhood

Verified unique human (iris + vein). Dual-use, flagged: a freedom tool and a powerful instrument of control at once.

Issuance ethic

Egalitarian mint (post-personhood); rule-bound elastic bootstrap (pre-personhood). No pre-allocation.

Autonomy ⇄ Accountability

High autonomy (no backdoor) with opt-in accountability tools (viewing keys, compliance proofs).

Consensus / cost

BFT (DAG-BFT), PoS-class energy with Proof-of-Useful-Stake weighting.

Governance model

On-chain vote. Named capture surfaces: residual plutocracy pre-personhood; potential sclerosis from high thresholds.

Re-score invited. The project does not grade its own exam against running chains. Third parties are invited to score ProtoLedger Core by the same public methodology and challenge the figures. Corrections are published with attribution.