Skip to content

The Blockchain Canon

From the paper, to the mechanism, to what actually happened.

Not a directory of coins. Each record starts from a public paper, names the mechanism, and says what later practice did to it. 21 papers have the full chain. The other studies stay one click away.

110 studies. Bitcoin and Ethereum remain the original PDFs, not new essays.

  • CryptoNote

    2013 · Design paper · Privacy

    The public design paper behind unlinkable payments. Monero adopted the construction and then replaced pieces of it. The historic library only has a third-party review of CryptoNote, not this document.

    Full study
  • Zerocoin

    2013 · Design paper · Privacy

    A 2013 proposal to add an anonymity layer on top of Bitcoin by burning a coin into a commitment and later redeeming a different coin with a zero-knowledge proof of membership.

    Full study
  • Zerocash

    2014 · Design paper · Privacy

    The 2014 paper that showed how a payment ledger can hide sender, receiver and amount, while still letting the network check that coins were not created or double-spent. Zcash is an implementation of this line of work, not a co-author of the paper.

    Full study
  • Monero

    2016 · Design paper · Privacy

    The research note Monero used to hide amounts, not just the signer. It extends ring signatures so a spender can prove a balance inside a ring without publishing the values.

    Full study
  • Mimblewimble

    2016 · Design paper · Privacy

    A short 2016 note on a ledger that stores confidential transactions and can delete spent history. Grin and Beam are later implementations. The note itself is the primary text.

    Full study
  • Cardano

    2017 · Design paper · Reach consensus

    The academic protocol Cardano's settlement layer is built around. It gives a proof-of-stake chain a stated security argument in a synchronous model, with stake electing slot leaders.

    Full study
  • Algorand

    2017 · Design paper · Reach consensus

    Micali's ledger design: a proof-of-stake protocol that elects a small, unpredictable committee to certify each block, and replaces participants so a corruptor cannot find them in time.

    Full study
  • Avalanche

    2018 · Design paper · Reach consensus

    A family of consensus protocols that sample the network repeatedly and tip toward one outcome. The 2018 note was pseudonymous. A later write-up adds named co-authors. Avalanche the network is an implementation, not the sample itself.

    Full study
  • Solana

    2018 · Design paper · Reach consensus

    Yakovenko's design note for a ledger that encodes the passage of time as a verifiable hash chain, called Proof of History, so that validators spend less effort agreeing on order.

    Full study
  • Tendermint

    2014 · Design paper · Reach consensus

    A practical Byzantine-fault-tolerant state machine for a known validator set, with instant finality on commit. It became the consensus engine under Cosmos SDK chains. The 2014 note is the origin, not the current CometBFT specification.

    Full study
  • Tezos

    2014 · Design paper · Reach consensus

    Goodman's proposal for a ledger whose protocol can be amended by a defined on-ledger process, with stakeholders who bake blocks and who may delegate.

    Full study
  • Hedera

    2016 · Design paper · Reach consensus

    Baird's technical report on hashgraph: gossip about gossip, a virtual vote computed from the graph, and a fairness claim about the order of transactions. Hedera is the later public network that uses the algorithm under a governing council.

    Full study
  • Nano

    2017 · Design paper · Reach consensus

    LeMahieu's design, first published as RaiBlocks: each account has its own chain, and the account holder is the only one who can append to it. Value moves by a send block on one chain and a receive block on another.

    Full study
  • Zilliqa

    2017 · Design paper · Reach consensus

    A 2017 design for a sharded chain: a directory service that assigns nodes, shards that process transactions in parallel, and a language proposal aimed at safe-by-construction contracts.

    Full study
  • Harmony

    2019 · Design paper · Reach consensus

    A sharded proof-of-stake design that combines a BFT-style consensus inside shards with a randomness scheme for assigning validators, aimed at keeping a single shard from being captured.

    Full study
  • MultiversX

    2019 · Design paper · Reach consensus

    The 2019 Elrond paper on adaptive state sharding: shards that hold state, a metachain that notarises results, and a secure proof-of-stake selection of validators. The network later rebranded as MultiversX. The paper remains the design document.

    Full study
  • NEAR

    2019 · Design paper · Reach consensus

    NEAR's public design paper: a sharded proof-of-stake chain with a single account model, nightshade-style data availability across chunks, and a stated intent that hiding the shards from application authors is part of the product.

    Full study
  • Aptos

    2022 · Design paper · Reach consensus

    Aptos Labs' 2022 paper for a Move-based chain that pipelines dissemination, ordering, execution and certification, and that treats protocol upgrades as a first-class feature rather than a hard-fork event.

    Full study
  • Sui

    2022 · Design paper · Reach consensus

    Mysten Labs' platform paper. Assets are Move objects. Operations on objects owned by a single address can finish by consistent broadcast among validators. Shared objects go through consensus. The split is the design.

    Full study
  • Diem

    2020 · Historical document · Reach consensus

    The technical paper for the Libra, later Diem, payment chain: a permissioned BFT ledger, a Move language for resources, and a reserve-backed currency proposal. The project was wound down in 2022. The paper still matters because Move, and the account model Aptos and Sui started from, was specified here.

    Full study
  • Mina

    2020 · Design paper · Reach consensus

    The Coda paper, later the Mina protocol: a chain whose certificate is a constant-size succinct proof, so a client can check the state without replaying history. The project renamed from Coda to Mina. The paper keeps the original name.

    Full study
  • TON

    2021 · Design paper · Reach consensus

    Durov's design for a multi-chain system of account-chains gathered into shardchains, with a masterchain that records the others. It began as Telegram's network design and continued as The Open Network after Telegram stepped away from the original launch.

    Full study
  • Kadena

    2018 · Design paper · Reach consensus

    Kadena's public parallel-chain design. Many proof-of-work chains advance together, and each block commits to peer-chain headers, so a confirmation is a braid rather than a single chain. This is not the 2016 private-chain note already in the historic library.

    Full study
  • EOSIO

    2018 · Design paper · Reach consensus

    The 2018 technical paper for EOSIO: delegated proof of stake, named block producers, and an operating-system metaphor for accounts, permissions and resource allocation. It is a design document. It is not a description of later governance fights around any one chain that used the software.

    Full study
  • Internet Computer

    2018 · Design paper · Reach consensus

    The DFINITY consensus overview: a randomness beacon, a ranking of block proposers, and notarisation so that a chain can come to agreement quickly among a large set. The Internet Computer is the later network built by the DFINITY foundation on this line of research.

    Full study
  • Polkadot

    2016 · Design paper · Connect

    Wood's 2016 vision paper: a relay chain that provides shared security and a queue of cross-chain messages, with parachains that keep their own state transition. It is a vision paper. The live protocol has a specification of its own.

    Full study
  • Cosmos

    2016 · Design paper · Connect

    The Cosmos paper: independent zones running a BFT consensus, connected by a hub, speaking a packet protocol that later became IBC. Unlike Polkadot's shared-security vision, zones here are sovereign. They choose their own validator sets.

    Full study
  • Lightning

    2016 · Design paper · Scale

    Poon and Dryja's 2016 design for Bitcoin payments that stay off the main chain inside penalty-backed channels, and that route across a network of those channels using hashed timelock contracts.

    Full study
  • Plasma

    2017 · Design paper · Scale

    A 2017 construction for trees of child chains whose state commitments are posted to a parent chain, with exits so a user can leave if the child operator misbehaves. It is an ancestor of later rollup and validium designs, not a synonym for them.

    Full study
  • Arbitrum

    2018 · Design paper · Scale

    The 2018 USENIX paper on Arbitrum: a verifier that checks a manager's execution of a virtual machine by bisecting disputes, instead of re-executing every instruction. Offchain Labs' later Nitro stack is a descendant, not this paper line for line.

    Full study
  • StarkWare

    2018 · Design paper · Scale

    The STARK paper: proofs of computational integrity that are succinct, do not need a trusted setup, and are argued to resist quantum attackers on the underlying hashes. StarkWare's later systems, including StarkEx and Starknet, are built on this proof system. They are not identical to it.

    Full study
  • Celestia

    2019 · Design paper · Scale

    Al-Bassam's LazyLedger paper, the research origin of Celestia. The base layer orders and makes data available. It does not execute application transitions. Clients check availability with sampling, and applications execute on their own.

    Full study
  • EigenLayer

    2023 · Design paper · Scale

    Eigen Labs' design for letting Ethereum stakers opt in to additional slashing conditions, so new services can rent economic security instead of bootstrapping a new token set from zero.

    Full study
  • Polygon

    2019 · Design paper · Scale

    The 2019 Matic paper for a Plasma-inspired sidechain with a proof-of-stake checkpoint layer posting to Ethereum. Polygon is the later organisation and product family. This page is about the 2019 document, not about every subsequent Polygon stack.

    Full study
  • Uniswap

    2020 · Design paper · Move value

    The 2020 core paper for Uniswap v2: a constant-product automated market maker, with arbitrary ERC-20 pairs, price accumulators, and a flash-swap callback. It is the clearest short specification of the pool that much of later DeFi either forked or assumed.

    Full study
  • Uniswap

    2021 · Design paper · Move value

    The 2021 paper that replaces the uniform reserve curve with concentrated liquidity. A provider chooses a price range. Inside the range their capital acts like a constant-product pool. Outside it, their position is entirely in one asset.

    Full study
  • Curve

    2019 · Design paper · Move value

    Egorov's 2019 invariant for pools of assets that should trade near parity. The curve is flat around the peg, where most stablecoin trades happen, and bends toward a constant-product tail when the pool is pushed off parity.

    Full study
  • Balancer

    2019 · Design paper · Move value

    The Balancer paper generalises the two-asset constant-product pool to a weighted basket of several tokens. Traders rebalance the basket. Liquidity providers define target weights. The pool is both an index and a market.

    Full study
  • 0x

    2017 · Design paper · Move value

    The 2017 0x paper: off-chain signed orders, on-chain settlement, and relayers who host order books without taking custody. It is the reference design for 'the book is off-chain, the swap is on-chain'.

    Full study
  • Bancor

    2017 · Design paper · Move value

    The 2017 Bancor paper on smart tokens that hold reserves of other tokens and quote a continuous price from a reserve ratio. It is an early automated-liquidity design, distinct from Uniswap's later constant-product pools.

    Full study
  • THORChain

    2020 · Design paper · Move value

    THORChain's design for continuous liquidity pools that cross native chains. Nodes bond capital, observe external chains, and sign outbound transactions as a threshold set. It is a liquidity network, not a wrapped-asset bridge run by a single custodian.

    Full study
  • Compound

    2019 · Design paper · Move value

    The 2019 Compound paper: pooled lending markets where suppliers earn a floating rate and borrowers post collateral. Interest rates are a function of utilisation, set in the protocol rather than negotiated bilaterally.

    Full study
  • Aave

    2020 · Design paper · Move value

    Aave's v1 protocol paper: pooled lending with stable and variable rates, and loan features such as rate switching and uncollateralised flash loans inside a single transaction. It sits in the same family as Compound, with a different rate and product surface.

    Full study
  • Maker

    2017 · Design paper · Move value

    MakerDAO's 2017 description of Dai: a liability minted against overcollateralised vaults, kept near a dollar target by fees, a collateral auction, and an emergency shutdown. It is the reference design for crypto-collateralised stable value, as distinct from a fiat-backed token.

    Full study
  • Terra

    2019 · Failure case · Move value

    Do Kwon's 2019 paper for a family of fiat-pegged tokens stabilised by an arbitrage relationship with a second, volatile token. It is included because it is a canonical design paper that was not in the historic library. It is included as a failure case, not as a model to ship.

    Full study
  • Chainlink

    2017 · Design paper · Data

    The 2017 Chainlink paper: a network of independent nodes that fetch off-chain data, aggregate it, and deliver a signed result on-chain, with a reputation and penalty story around the nodes. It is the reference design for 'the contract needs a fact from outside'.

    Full study
  • The Graph

    2020 · Design paper · Data

    The Graph's protocol paper for indexing chain data. Indexers stake on serving a subgraph. Curators signal which subgraphs matter. Consumers pay for queries. The problem is read access, not consensus.

    Full study
  • Augur

    2018 · Design paper · Data

    The Augur paper: prediction markets whose outcomes are reported by token holders, with a dispute ladder that can escalate a contested result. It is both a market design and an oracle design. The historic library already holds Gnosis. Augur is the other canonical public prediction-market paper and was not in that set.

    Full study
  • Ocean

    2019 · Design paper · Data

    Ocean's technical paper for publishing, pricing and consuming data services with on-chain access control and off-chain storage. The data does not sit inside the chain. The permission and the payment do.

    Full study
  • Bittensor

    2021 · Design paper · Data

    Rao's paper for a market in which machine-learning models score each other. Peers rank neighbours, ranks accumulate on a ledger, and an incentive mechanism is specified to resist a naive cartel of mutual high scores. It is a design for pricing intelligence as a commodity, not a benchmark of any particular model.

    Full study
  • SingularityNET

    2017 · Design paper · Data

    Goertzel's 2017 proposal for a marketplace where AI services discover, call and pay each other. The paper is broad on purpose: discovery, reputation, inter-agent calls and a tokenised payment rail, sketched as one network.

    Full study
  • Filecoin

    2017 · Design paper · Store and connect

    Protocol Labs' July 2017 paper. Storage is an algorithmic market: clients pay miners to store data, miners prove replication and spacetime, and a retrieval market is specified beside the storage market. The historic library's filecoin.pdf is an earlier, different sketch. This is the 2017 document.

    Full study
  • Arweave

    2018 · Design paper · Store and connect

    Arweave's protocol paper for permanent storage: miners store a recall block drawn from the history, an endowment is supposed to prepay storage, and the dataset is content-addressed. The yellow paper is the technical document. Marketing pages are not a substitute.

    Full study
  • Helium

    2018 · Design paper · Store and connect

    The Helium paper for a wireless network built from independently owned hotspots. Coverage is the commodity. Proof-of-coverage is the paper's way of checking that a radio is where it says it is and that it can be heard. Later changes of purpose and token are not this document.

    Full study
  • Golem

    2016 · Design paper · Store and connect

    Golem Factory's 2016 paper for a marketplace of spare computer power. Requestors split tasks. Providers run them. A reputation and payment layer is supposed to make the exchange work without a single render farm. The paper is explicit that it was also a crowdfunding document. This page uses the technical design and ignores the sale.

    Full study
  • Livepeer

    2017 · Design paper · Store and connect

    Petkanics and Tang's design for live video transcoding as a protocol job. Broadcasters send a stream. Transcoders stake and compete to encode the renditions viewers actually need. It is a specific media market, which is why it is more concrete than a general 'decentralised compute' essay.

    Full study
  • Basic Attention Token

    2018 · Design paper · Store and connect

    Brave's 2018 paper for an advertising unit that pays publishers and users from a measured attention event inside the browser, rather than from a chain of third-party trackers. The browser is load-bearing. The token is the unit of account in the paper's payment flow.

    Full study
  • Secret Network

    2015 · Design paper · Privacy

    The 2015 Enigma paper from MIT: private contracts executed over secret-shared data, so nodes compute without seeing the raw inputs. Secret Network is a later project in this lineage, using different machinery. This page is about the Enigma paper, which the historic library does not hold.

    Full study
  • Oasis

    2019 · Design paper · Privacy

    The Ekiden paper: smart contracts that execute inside trusted hardware, with the ledger checking attestations rather than re-executing the private code. Oasis Network is the later production system in this line. The paper is the academic statement of the approach.

    Full study
  • PBFT

    1999 · Design paper · Reach consensus

    The paper that made a Byzantine quorum practical: a known set of replicas, three phases, and a view change when the leader is useless. Tendermint and HotStuff inherit the shape. Open membership is a different problem.

    Full study
  • Bitcoin-NG

    2016 · Design paper · Reach consensus

    Separate the rare proof-of-work election from the frequent publication of transactions. Key blocks choose a leader. That leader's microblocks carry the transactions until the next key block.

    Full study
  • GHOST

    2015 · Design paper · Reach consensus

    At high block rates the longest chain throws away too much honest work. GHOST follows the heaviest subtree, so blocks off the main tip still count for the fork choice.

    Full study
  • PHANTOM

    2018 · Design paper · Reach consensus

    A blockDAG protocol that still ends in one linear order. Honest blocks cluster. The parameter k is how wide that cluster may be. Kaspa is a later network in this line, not the paper.

    Full study
  • SPECTRE

    2016 · Design paper · Reach consensus

    Blocks form a DAG and vote pairwise on which of two blocks came first. In the common case that vote settles quickly. The paper does not promise a total order of every pair, which is why it is a poor fit for general contracts.

    Full study
  • Casper FFG

    2017 · Design paper · Reach consensus

    A finality overlay. Validators cast two rounds of votes so that a chain of checkpoints becomes justified and then final. Equivocation can be slashed. The gadget does not, by itself, propose blocks.

    Full study
  • HotStuff

    2019 · Design paper · Reach consensus

    A three-phase BFT protocol whose communication is linear in the number of replicas, because a leader collects a threshold signature instead of everyone talking to everyone. Diem used a variant. The paper is not that network.

    Full study
  • HoneyBadgerBFT

    2016 · Design paper · Reach consensus

    An asynchronous atomic broadcast. It does not wait for a timeout to make progress, and threshold encryption stops a leader from reading a batch and then dropping the transactions it dislikes.

    Full study
  • Narwhal and Tusk

    2022 · Design paper · Reach consensus

    Split the mempool from the consensus. Narwhal is a DAG of certified batches. Tusk picks a leader inside that DAG. Later Sui consensus descends from this split. The paper is not a Sui status report.

    Full study
  • Snow White

    2017 · Design paper · Reach consensus

    A proof-of-stake design in the sleepy model: honest nodes may be offline, and the set of stakeholders can change. It is an academic predecessor, not Cardano and not Ethereum.

    Full study
  • Thunderella

    2017 · Design paper · Reach consensus

    A fast path and a slow path. If a large supermajority is honest and an accelerator proposes quickly, transactions confirm at network speed. If not, the protocol falls back to an underlying chain.

    Full study
  • Confidential Transactions

    2015 · Design paper · Privacy

    Hide the amounts on a Bitcoin-style transaction with Pedersen commitments, and use range proofs so a commitment cannot stand for a negative number. The graph of who paid whom stays visible.

    Full study
  • Bulletproofs

    2018 · Design paper · Privacy

    Range proofs whose size grows logarithmically, with no trusted setup. They made confidential amounts practical to verify. They are not, by themselves, a private payment system.

    Full study
  • Groth16

    2016 · Design paper · Privacy

    A pairing-based argument in three group elements. The proofs are tiny and cheap to verify. Each circuit needs its own setup, and a leaked setup can forge proofs.

    Full study
  • PLONK

    2019 · Design paper · Privacy

    A SNARK with a universal and updatable structured reference string. One setup can serve many circuits. The proofs are larger than Groth16, and there is still a setup.

    Full study
  • Halo

    2019 · Design paper · Privacy

    Recursion for inner-product arguments, without a structured setup. A proof can attest that another proof was checked. That is how a chain can fold a long history into one object. Halo 2 is a later system.

    Full study
  • Zexe

    2020 · Design paper · Privacy

    A model for private computation over records. Each record has a birth predicate and a death predicate. A transaction proves that some records died and others were born, without showing which, or showing the data.

    Full study
  • Fraud and data availability proofs

    2018 · Design paper · Scale

    Light clients can refuse a block if a fraud proof shows it is invalid, but only if the block's data was actually published. The paper shows how erasure coding and sampling let clients check publication without downloading everything.

    Full study
  • TrueBit

    2017 · Design paper · Scale

    Pay a solver to run a heavy computation off-chain, and pay a verifier only when they find a lie. An interactive game narrows the lie to one step. A jackpot is there so verifiers show up even when solvers are usually honest.

    Full study
  • KZG commitments

    2010 · Design paper · Scale

    Commit to a polynomial and later open it at a point, in constant size, with a pairing. The commitment is binding if the setup's trapdoor stays secret. Modern data-availability schemes use this as a brick. The paper is older than those schemes.

    Full study
  • Proofs of space

    2015 · Design paper · Reach consensus

    A proof that a machine reserved storage, not that it burned energy on a puzzle. The verifier checks a small challenge. Chia is a later system that pairs this idea with a verifiable delay. The paper is not Chia.

    Full study
  • Verifiable delay functions

    2018 · Design paper · Reach consensus

    A function that forces a wait. Evaluating it takes a set number of sequential steps. Checking the result is quick, and the output is unique. Parallel machines do not make the wait much shorter.

    Full study
  • Atomic swaps

    2018 · Design paper · Connect

    A swap across ledgers where either every transfer completes or none does, using hash locks and time locks. There is no custodian in the paper. A party can still walk away and leave the other waiting.

    Full study
  • Sprites

    2017 · Design paper · Connect

    State channels whose disputes do not have to hop one channel at a time. A global preimage manager lets a payment resolve in constant time on-chain. Lightning did not adopt this design as its production path.

    Full study
  • IBC

    2020 · Design paper · Connect

    Two chains verify each other with light clients. A relayer carries packets and proofs. The relayer is not trusted to tell the truth. It is trusted to bother showing up. Security is the security of both chains.

    Full study
  • Flash Boys 2.0

    2019 · Design paper · Move value

    A measurement paper. Miners and bots reorder and insert transactions around DEX trades. The authors name miner-extractable value and show priority gas auctions. It is not a trading manual, and it is not a claim that any strategy here is available or profitable now.

    Full study
  • Uniswap v4

    2023 · Design paper · Move value

    One contract holds many pools. Hooks are code that runs before and after swaps and liquidity changes. Flash accounting settles balances at the end of a lock. A hook can change the rules v3 users took for granted.

    Full study
  • TWAMM

    2021 · Design paper · Move value

    Execute a large order as if it were split into infinitely many tiny trades across an interval, without paying gas for each piece. Settlement is lazy. This is an order schedule, not a price oracle, despite the nearby acronym TWAP.

    Full study
  • Liquity

    2021 · Design paper · Move value

    Borrow a stable-value token against ether, with a one-time fee instead of an interest rate. Troves are liquidated into a stability pool. Redemptions let the token be swapped for the collateral of the weakest trove. The paper does not promise a peg.

    Full study
  • ERC-4337

    2021 · Design paper · Data

    Smart-contract accounts that propose UserOperations, bundled by a separate mempool, without a change to Ethereum's consensus. Paymasters can sponsor gas. The validation rule lives in the account, which is the point and the risk.

    Full study
  • Gasper

    2020 · Design paper · Reach consensus

    An idealised proof-of-stake protocol that pairs a GHOST-style fork choice with Casper FFG finality. The paper is the design argument for Ethereum's beacon chain, not a status report on a later client or a later outage.

    Full study
  • Prism

    2019 · Design paper · Reach consensus

    Bitcoin uses one chain for three jobs: proposing transactions, voting on history, and ordering the result. Prism splits those jobs onto separate block trees so throughput can approach network capacity while confirmation tracks propagation delay.

    Full study
  • Streamlet

    2020 · Design paper · Reach consensus

    A deliberately small consensus protocol: epochs, a leader, a vote, and a rule that three adjacent certified blocks on the same chain become final. The point is to show how little machinery the last few years of BFT designs actually need.

    Full study
  • FruitChains

    2016 · Design paper · Reach consensus

    Nakamoto consensus can pay a minority coalition more than its share of hash power, which is the selfish-mining observation. FruitChains records transactions in 'fruit' that hang off the chain, and pays out over a window so honest hash power gets roughly honest rewards.

    Full study
  • DAG-Rider

    2021 · Design paper · Reach consensus

    Replicas reliably broadcast proposals into a round-structured DAG. Once the DAG is local, each replica can read a total order off it without another round of consensus messages. The paper is the asynchronous, optimally resilient version of that idea.

    Full study
  • Bullshark

    2022 · Design paper · Reach consensus

    DAG-Rider is built for asynchrony and pays for it on the common path. Bullshark keeps a DAG and a local commit rule, but adds a fast path for when the network is timely. The paper also writes down a simpler partially synchronous version.

    Full study
  • EIP-1559

    2019 · Design paper · Move value

    Replace a first-price auction for inclusion with a protocol-quoted base fee that moves with demand, plus a tip to the producer. The base fee is burned. The EIP is a fee-market rule, not a promise that fees will be low.

    Full study
  • Transaction fee mechanism design

    2020 · Design paper · Move value

    A mechanism-design reading of blockchain fees. Roughgarden separates what users pay, what miners keep, and what gets burned, and asks which combinations are incentive-compatible for myopic miners. EIP-1559 is the running example, not a price forecast.

    Full study
  • EIP-4844

    2022 · Design paper · Scale

    A new transaction type carries a blob: a large chunk of data that consensus nodes hold briefly and that the execution layer cannot read byte by byte. Rollups are the intended user. The blob is not cheap forever, and it is not the rollup's proof.

    Full study
  • BitVM

    2023 · Design paper · Scale

    A way to dispute an arbitrary computation between two Bitcoin parties using hashlocks, timelocks and large Taproot trees, without a new opcode. Honest execution stays off-chain. A false claim can be challenged on-chain. It is not a global virtual machine.

    Full study
  • Cairo

    2021 · Design paper · Scale

    A CPU whose every instruction was chosen so that a STARK can prove 'this program ran'. You write a program instead of a new set of polynomial equations for each statement. The paper is the machine, not a network's throughput.

    Full study
  • Nova

    2021 · Design paper · Privacy

    Incrementally verifiable computation without putting a SNARK inside a SNARK. A folding scheme compresses two instances of a computation into one instance of the same size. Repeating that fold is the recursion. The paper is about prover cost, not about a chain.

    Full study
  • Marlin

    2019 · Design paper · Privacy

    A preprocessing zkSNARK whose structured reference string is universal and can be updated, rather than baked for one circuit in a ceremony that must be trusted forever. The paper improves on Sonic's costs. It is still a SNARK, with a setup.

    Full study
  • FROST

    2020 · Design paper · Privacy

    A threshold Schnorr signature: any t of n signers can produce one ordinary-looking signature, and fewer than t cannot. The signing protocol is two rounds, or one if nonces were prepared earlier. The paper is the scheme, not a custody vendor.

    Full study
  • MuSig2

    2020 · Design paper · Privacy

    n signers, all of them, produce one Schnorr signature that verifies under one aggregated key. Two rounds, and concurrent sessions are in the security claim. This is n-of-n, not a threshold. It is the multi-signature Bitcoin-style schemes reached for.

    Full study
  • Taproot

    2020 · Design paper · Privacy

    A Bitcoin spend that can look like a single key, while still hiding a tree of alternative scripts until one of them is used. Schnorr signatures and the key-path spend are the mechanism. Amounts stay public. This is not a privacy coin.

    Full study
  • Curve Cryptoswap

    2021 · Design paper · Move value

    Stableswap concentrates liquidity around a fixed price of one. This paper moves that concentration so it can follow a moving price between volatile assets. The pool reprices itself from its own trades. It does not know the outside world except through those trades.

    Full study
  • crvUSD design

    2022 · Design paper · Move value

    A stablecoin lent against volatile collateral, where liquidation is a continuous trade into a special pool rather than a one-shot auction. The paper calls that pool LLAMMA. A peg keeper and a monetary-policy rate sit beside it. Simulations in the paper are not a promise about later losses.

    Full study
  • UMA

    2020 · Design paper · Data

    An oracle that does not answer every question in real time. It prices the cost of bribing the token holders who would resolve a dispute, and it asks contract designers to keep the profit of a lie below that cost. The draft is an economic argument, not a feed you can read as truth.

    Full study
  • Perun

    2017 · Design paper · Scale

    Lightning routes each payment through the intermediaries. Perun asks those intermediaries to set up a virtual channel and then step out of the individual payments. The paper gives the construction for one hub, on a chain that can run the contracts.

    Full study
  • Semaphore

    2020 · Design paper · Privacy

    A member of a group proves they are some member, and posts a signal, without showing which member. A nullifier stops the same member signalling twice in the same context. The 2020 proposal is a base layer for voting and similar uses. It is not itself a mixer, and later versions changed the circuits.

    Full study

Bitcoin PDFStake and workEvery study