The Blockchain Canon
From the paper, to the mechanism, to what actually happened.
Not a directory of coins. Each record starts from a public paper, names the mechanism, and says what later practice did to it. 21 papers have the full chain. The other studies stay one click away.
- CryptoNoteFull study
2013 · Design paper · Privacy
The public design paper behind unlinkable payments. Monero adopted the construction and then replaced pieces of it. The historic library only has a third-party review of CryptoNote, not this document.
- ZerocoinFull study
2013 · Design paper · Privacy
A 2013 proposal to add an anonymity layer on top of Bitcoin by burning a coin into a commitment and later redeeming a different coin with a zero-knowledge proof of membership.
- ZerocashFull study
2014 · Design paper · Privacy
The 2014 paper that showed how a payment ledger can hide sender, receiver and amount, while still letting the network check that coins were not created or double-spent. Zcash is an implementation of this line of work, not a co-author of the paper.
- MoneroFull study
2016 · Design paper · Privacy
The research note Monero used to hide amounts, not just the signer. It extends ring signatures so a spender can prove a balance inside a ring without publishing the values.
- MimblewimbleFull study
2016 · Design paper · Privacy
A short 2016 note on a ledger that stores confidential transactions and can delete spent history. Grin and Beam are later implementations. The note itself is the primary text.
- CardanoFull study
2017 · Design paper · Reach consensus
The academic protocol Cardano's settlement layer is built around. It gives a proof-of-stake chain a stated security argument in a synchronous model, with stake electing slot leaders.
- AlgorandFull study
2017 · Design paper · Reach consensus
Micali's ledger design: a proof-of-stake protocol that elects a small, unpredictable committee to certify each block, and replaces participants so a corruptor cannot find them in time.
- AvalancheFull study
2018 · Design paper · Reach consensus
A family of consensus protocols that sample the network repeatedly and tip toward one outcome. The 2018 note was pseudonymous. A later write-up adds named co-authors. Avalanche the network is an implementation, not the sample itself.
- SolanaFull study
2018 · Design paper · Reach consensus
Yakovenko's design note for a ledger that encodes the passage of time as a verifiable hash chain, called Proof of History, so that validators spend less effort agreeing on order.
- TendermintFull study
2014 · Design paper · Reach consensus
A practical Byzantine-fault-tolerant state machine for a known validator set, with instant finality on commit. It became the consensus engine under Cosmos SDK chains. The 2014 note is the origin, not the current CometBFT specification.
- TezosFull study
2014 · Design paper · Reach consensus
Goodman's proposal for a ledger whose protocol can be amended by a defined on-ledger process, with stakeholders who bake blocks and who may delegate.
- HederaFull study
2016 · Design paper · Reach consensus
Baird's technical report on hashgraph: gossip about gossip, a virtual vote computed from the graph, and a fairness claim about the order of transactions. Hedera is the later public network that uses the algorithm under a governing council.
- NanoFull study
2017 · Design paper · Reach consensus
LeMahieu's design, first published as RaiBlocks: each account has its own chain, and the account holder is the only one who can append to it. Value moves by a send block on one chain and a receive block on another.
- ZilliqaFull study
2017 · Design paper · Reach consensus
A 2017 design for a sharded chain: a directory service that assigns nodes, shards that process transactions in parallel, and a language proposal aimed at safe-by-construction contracts.
- HarmonyFull study
2019 · Design paper · Reach consensus
A sharded proof-of-stake design that combines a BFT-style consensus inside shards with a randomness scheme for assigning validators, aimed at keeping a single shard from being captured.
- MultiversXFull study
2019 · Design paper · Reach consensus
The 2019 Elrond paper on adaptive state sharding: shards that hold state, a metachain that notarises results, and a secure proof-of-stake selection of validators. The network later rebranded as MultiversX. The paper remains the design document.
- NEARFull study
2019 · Design paper · Reach consensus
NEAR's public design paper: a sharded proof-of-stake chain with a single account model, nightshade-style data availability across chunks, and a stated intent that hiding the shards from application authors is part of the product.
- AptosFull study
2022 · Design paper · Reach consensus
Aptos Labs' 2022 paper for a Move-based chain that pipelines dissemination, ordering, execution and certification, and that treats protocol upgrades as a first-class feature rather than a hard-fork event.
- SuiFull study
2022 · Design paper · Reach consensus
Mysten Labs' platform paper. Assets are Move objects. Operations on objects owned by a single address can finish by consistent broadcast among validators. Shared objects go through consensus. The split is the design.
- DiemFull study
2020 · Historical document · Reach consensus
The technical paper for the Libra, later Diem, payment chain: a permissioned BFT ledger, a Move language for resources, and a reserve-backed currency proposal. The project was wound down in 2022. The paper still matters because Move, and the account model Aptos and Sui started from, was specified here.
- MinaFull study
2020 · Design paper · Reach consensus
The Coda paper, later the Mina protocol: a chain whose certificate is a constant-size succinct proof, so a client can check the state without replaying history. The project renamed from Coda to Mina. The paper keeps the original name.
- TONFull study
2021 · Design paper · Reach consensus
Durov's design for a multi-chain system of account-chains gathered into shardchains, with a masterchain that records the others. It began as Telegram's network design and continued as The Open Network after Telegram stepped away from the original launch.
- KadenaFull study
2018 · Design paper · Reach consensus
Kadena's public parallel-chain design. Many proof-of-work chains advance together, and each block commits to peer-chain headers, so a confirmation is a braid rather than a single chain. This is not the 2016 private-chain note already in the historic library.
- EOSIOFull study
2018 · Design paper · Reach consensus
The 2018 technical paper for EOSIO: delegated proof of stake, named block producers, and an operating-system metaphor for accounts, permissions and resource allocation. It is a design document. It is not a description of later governance fights around any one chain that used the software.
- Internet ComputerFull study
2018 · Design paper · Reach consensus
The DFINITY consensus overview: a randomness beacon, a ranking of block proposers, and notarisation so that a chain can come to agreement quickly among a large set. The Internet Computer is the later network built by the DFINITY foundation on this line of research.
- PolkadotFull study
2016 · Design paper · Connect
Wood's 2016 vision paper: a relay chain that provides shared security and a queue of cross-chain messages, with parachains that keep their own state transition. It is a vision paper. The live protocol has a specification of its own.
- CosmosFull study
2016 · Design paper · Connect
The Cosmos paper: independent zones running a BFT consensus, connected by a hub, speaking a packet protocol that later became IBC. Unlike Polkadot's shared-security vision, zones here are sovereign. They choose their own validator sets.
- LightningFull study
2016 · Design paper · Scale
Poon and Dryja's 2016 design for Bitcoin payments that stay off the main chain inside penalty-backed channels, and that route across a network of those channels using hashed timelock contracts.
- PlasmaFull study
2017 · Design paper · Scale
A 2017 construction for trees of child chains whose state commitments are posted to a parent chain, with exits so a user can leave if the child operator misbehaves. It is an ancestor of later rollup and validium designs, not a synonym for them.
- ArbitrumFull study
2018 · Design paper · Scale
The 2018 USENIX paper on Arbitrum: a verifier that checks a manager's execution of a virtual machine by bisecting disputes, instead of re-executing every instruction. Offchain Labs' later Nitro stack is a descendant, not this paper line for line.
- StarkWareFull study
2018 · Design paper · Scale
The STARK paper: proofs of computational integrity that are succinct, do not need a trusted setup, and are argued to resist quantum attackers on the underlying hashes. StarkWare's later systems, including StarkEx and Starknet, are built on this proof system. They are not identical to it.
- CelestiaFull study
2019 · Design paper · Scale
Al-Bassam's LazyLedger paper, the research origin of Celestia. The base layer orders and makes data available. It does not execute application transitions. Clients check availability with sampling, and applications execute on their own.
- EigenLayerFull study
2023 · Design paper · Scale
Eigen Labs' design for letting Ethereum stakers opt in to additional slashing conditions, so new services can rent economic security instead of bootstrapping a new token set from zero.
- PolygonFull study
2019 · Design paper · Scale
The 2019 Matic paper for a Plasma-inspired sidechain with a proof-of-stake checkpoint layer posting to Ethereum. Polygon is the later organisation and product family. This page is about the 2019 document, not about every subsequent Polygon stack.
- UniswapFull study
2020 · Design paper · Move value
The 2020 core paper for Uniswap v2: a constant-product automated market maker, with arbitrary ERC-20 pairs, price accumulators, and a flash-swap callback. It is the clearest short specification of the pool that much of later DeFi either forked or assumed.
- UniswapFull study
2021 · Design paper · Move value
The 2021 paper that replaces the uniform reserve curve with concentrated liquidity. A provider chooses a price range. Inside the range their capital acts like a constant-product pool. Outside it, their position is entirely in one asset.
- CurveFull study
2019 · Design paper · Move value
Egorov's 2019 invariant for pools of assets that should trade near parity. The curve is flat around the peg, where most stablecoin trades happen, and bends toward a constant-product tail when the pool is pushed off parity.
- BalancerFull study
2019 · Design paper · Move value
The Balancer paper generalises the two-asset constant-product pool to a weighted basket of several tokens. Traders rebalance the basket. Liquidity providers define target weights. The pool is both an index and a market.
- 0xFull study
2017 · Design paper · Move value
The 2017 0x paper: off-chain signed orders, on-chain settlement, and relayers who host order books without taking custody. It is the reference design for 'the book is off-chain, the swap is on-chain'.
- BancorFull study
2017 · Design paper · Move value
The 2017 Bancor paper on smart tokens that hold reserves of other tokens and quote a continuous price from a reserve ratio. It is an early automated-liquidity design, distinct from Uniswap's later constant-product pools.
- THORChainFull study
2020 · Design paper · Move value
THORChain's design for continuous liquidity pools that cross native chains. Nodes bond capital, observe external chains, and sign outbound transactions as a threshold set. It is a liquidity network, not a wrapped-asset bridge run by a single custodian.
- CompoundFull study
2019 · Design paper · Move value
The 2019 Compound paper: pooled lending markets where suppliers earn a floating rate and borrowers post collateral. Interest rates are a function of utilisation, set in the protocol rather than negotiated bilaterally.
- AaveFull study
2020 · Design paper · Move value
Aave's v1 protocol paper: pooled lending with stable and variable rates, and loan features such as rate switching and uncollateralised flash loans inside a single transaction. It sits in the same family as Compound, with a different rate and product surface.
- MakerFull study
2017 · Design paper · Move value
MakerDAO's 2017 description of Dai: a liability minted against overcollateralised vaults, kept near a dollar target by fees, a collateral auction, and an emergency shutdown. It is the reference design for crypto-collateralised stable value, as distinct from a fiat-backed token.
- TerraFull study
2019 · Failure case · Move value
Do Kwon's 2019 paper for a family of fiat-pegged tokens stabilised by an arbitrage relationship with a second, volatile token. It is included because it is a canonical design paper that was not in the historic library. It is included as a failure case, not as a model to ship.
- ChainlinkFull study
2017 · Design paper · Data
The 2017 Chainlink paper: a network of independent nodes that fetch off-chain data, aggregate it, and deliver a signed result on-chain, with a reputation and penalty story around the nodes. It is the reference design for 'the contract needs a fact from outside'.
- The GraphFull study
2020 · Design paper · Data
The Graph's protocol paper for indexing chain data. Indexers stake on serving a subgraph. Curators signal which subgraphs matter. Consumers pay for queries. The problem is read access, not consensus.
- AugurFull study
2018 · Design paper · Data
The Augur paper: prediction markets whose outcomes are reported by token holders, with a dispute ladder that can escalate a contested result. It is both a market design and an oracle design. The historic library already holds Gnosis. Augur is the other canonical public prediction-market paper and was not in that set.
- OceanFull study
2019 · Design paper · Data
Ocean's technical paper for publishing, pricing and consuming data services with on-chain access control and off-chain storage. The data does not sit inside the chain. The permission and the payment do.
- BittensorFull study
2021 · Design paper · Data
Rao's paper for a market in which machine-learning models score each other. Peers rank neighbours, ranks accumulate on a ledger, and an incentive mechanism is specified to resist a naive cartel of mutual high scores. It is a design for pricing intelligence as a commodity, not a benchmark of any particular model.
- SingularityNETFull study
2017 · Design paper · Data
Goertzel's 2017 proposal for a marketplace where AI services discover, call and pay each other. The paper is broad on purpose: discovery, reputation, inter-agent calls and a tokenised payment rail, sketched as one network.
- FilecoinFull study
2017 · Design paper · Store and connect
Protocol Labs' July 2017 paper. Storage is an algorithmic market: clients pay miners to store data, miners prove replication and spacetime, and a retrieval market is specified beside the storage market. The historic library's filecoin.pdf is an earlier, different sketch. This is the 2017 document.
- ArweaveFull study
2018 · Design paper · Store and connect
Arweave's protocol paper for permanent storage: miners store a recall block drawn from the history, an endowment is supposed to prepay storage, and the dataset is content-addressed. The yellow paper is the technical document. Marketing pages are not a substitute.
- HeliumFull study
2018 · Design paper · Store and connect
The Helium paper for a wireless network built from independently owned hotspots. Coverage is the commodity. Proof-of-coverage is the paper's way of checking that a radio is where it says it is and that it can be heard. Later changes of purpose and token are not this document.
- GolemFull study
2016 · Design paper · Store and connect
Golem Factory's 2016 paper for a marketplace of spare computer power. Requestors split tasks. Providers run them. A reputation and payment layer is supposed to make the exchange work without a single render farm. The paper is explicit that it was also a crowdfunding document. This page uses the technical design and ignores the sale.
- LivepeerFull study
2017 · Design paper · Store and connect
Petkanics and Tang's design for live video transcoding as a protocol job. Broadcasters send a stream. Transcoders stake and compete to encode the renditions viewers actually need. It is a specific media market, which is why it is more concrete than a general 'decentralised compute' essay.
- Basic Attention TokenFull study
2018 · Design paper · Store and connect
Brave's 2018 paper for an advertising unit that pays publishers and users from a measured attention event inside the browser, rather than from a chain of third-party trackers. The browser is load-bearing. The token is the unit of account in the paper's payment flow.
- Secret NetworkFull study
2015 · Design paper · Privacy
The 2015 Enigma paper from MIT: private contracts executed over secret-shared data, so nodes compute without seeing the raw inputs. Secret Network is a later project in this lineage, using different machinery. This page is about the Enigma paper, which the historic library does not hold.
- OasisFull study
2019 · Design paper · Privacy
The Ekiden paper: smart contracts that execute inside trusted hardware, with the ledger checking attestations rather than re-executing the private code. Oasis Network is the later production system in this line. The paper is the academic statement of the approach.
- PBFTFull study
1999 · Design paper · Reach consensus
The paper that made a Byzantine quorum practical: a known set of replicas, three phases, and a view change when the leader is useless. Tendermint and HotStuff inherit the shape. Open membership is a different problem.
- Bitcoin-NGFull study
2016 · Design paper · Reach consensus
Separate the rare proof-of-work election from the frequent publication of transactions. Key blocks choose a leader. That leader's microblocks carry the transactions until the next key block.
- GHOSTFull study
2015 · Design paper · Reach consensus
At high block rates the longest chain throws away too much honest work. GHOST follows the heaviest subtree, so blocks off the main tip still count for the fork choice.
- PHANTOMFull study
2018 · Design paper · Reach consensus
A blockDAG protocol that still ends in one linear order. Honest blocks cluster. The parameter k is how wide that cluster may be. Kaspa is a later network in this line, not the paper.
- SPECTREFull study
2016 · Design paper · Reach consensus
Blocks form a DAG and vote pairwise on which of two blocks came first. In the common case that vote settles quickly. The paper does not promise a total order of every pair, which is why it is a poor fit for general contracts.
- Casper FFGFull study
2017 · Design paper · Reach consensus
A finality overlay. Validators cast two rounds of votes so that a chain of checkpoints becomes justified and then final. Equivocation can be slashed. The gadget does not, by itself, propose blocks.
- HotStuffFull study
2019 · Design paper · Reach consensus
A three-phase BFT protocol whose communication is linear in the number of replicas, because a leader collects a threshold signature instead of everyone talking to everyone. Diem used a variant. The paper is not that network.
- HoneyBadgerBFTFull study
2016 · Design paper · Reach consensus
An asynchronous atomic broadcast. It does not wait for a timeout to make progress, and threshold encryption stops a leader from reading a batch and then dropping the transactions it dislikes.
- Narwhal and TuskFull study
2022 · Design paper · Reach consensus
Split the mempool from the consensus. Narwhal is a DAG of certified batches. Tusk picks a leader inside that DAG. Later Sui consensus descends from this split. The paper is not a Sui status report.
- Snow WhiteFull study
2017 · Design paper · Reach consensus
A proof-of-stake design in the sleepy model: honest nodes may be offline, and the set of stakeholders can change. It is an academic predecessor, not Cardano and not Ethereum.
- ThunderellaFull study
2017 · Design paper · Reach consensus
A fast path and a slow path. If a large supermajority is honest and an accelerator proposes quickly, transactions confirm at network speed. If not, the protocol falls back to an underlying chain.
- Confidential TransactionsFull study
2015 · Design paper · Privacy
Hide the amounts on a Bitcoin-style transaction with Pedersen commitments, and use range proofs so a commitment cannot stand for a negative number. The graph of who paid whom stays visible.
- BulletproofsFull study
2018 · Design paper · Privacy
Range proofs whose size grows logarithmically, with no trusted setup. They made confidential amounts practical to verify. They are not, by themselves, a private payment system.
- Groth16Full study
2016 · Design paper · Privacy
A pairing-based argument in three group elements. The proofs are tiny and cheap to verify. Each circuit needs its own setup, and a leaked setup can forge proofs.
- PLONKFull study
2019 · Design paper · Privacy
A SNARK with a universal and updatable structured reference string. One setup can serve many circuits. The proofs are larger than Groth16, and there is still a setup.
- HaloFull study
2019 · Design paper · Privacy
Recursion for inner-product arguments, without a structured setup. A proof can attest that another proof was checked. That is how a chain can fold a long history into one object. Halo 2 is a later system.
- ZexeFull study
2020 · Design paper · Privacy
A model for private computation over records. Each record has a birth predicate and a death predicate. A transaction proves that some records died and others were born, without showing which, or showing the data.
- Fraud and data availability proofsFull study
2018 · Design paper · Scale
Light clients can refuse a block if a fraud proof shows it is invalid, but only if the block's data was actually published. The paper shows how erasure coding and sampling let clients check publication without downloading everything.
- TrueBitFull study
2017 · Design paper · Scale
Pay a solver to run a heavy computation off-chain, and pay a verifier only when they find a lie. An interactive game narrows the lie to one step. A jackpot is there so verifiers show up even when solvers are usually honest.
- KZG commitmentsFull study
2010 · Design paper · Scale
Commit to a polynomial and later open it at a point, in constant size, with a pairing. The commitment is binding if the setup's trapdoor stays secret. Modern data-availability schemes use this as a brick. The paper is older than those schemes.
- Proofs of spaceFull study
2015 · Design paper · Reach consensus
A proof that a machine reserved storage, not that it burned energy on a puzzle. The verifier checks a small challenge. Chia is a later system that pairs this idea with a verifiable delay. The paper is not Chia.
- Verifiable delay functionsFull study
2018 · Design paper · Reach consensus
A function that forces a wait. Evaluating it takes a set number of sequential steps. Checking the result is quick, and the output is unique. Parallel machines do not make the wait much shorter.
- Atomic swapsFull study
2018 · Design paper · Connect
A swap across ledgers where either every transfer completes or none does, using hash locks and time locks. There is no custodian in the paper. A party can still walk away and leave the other waiting.
- SpritesFull study
2017 · Design paper · Connect
State channels whose disputes do not have to hop one channel at a time. A global preimage manager lets a payment resolve in constant time on-chain. Lightning did not adopt this design as its production path.
- IBCFull study
2020 · Design paper · Connect
Two chains verify each other with light clients. A relayer carries packets and proofs. The relayer is not trusted to tell the truth. It is trusted to bother showing up. Security is the security of both chains.
- Flash Boys 2.0Full study
2019 · Design paper · Move value
A measurement paper. Miners and bots reorder and insert transactions around DEX trades. The authors name miner-extractable value and show priority gas auctions. It is not a trading manual, and it is not a claim that any strategy here is available or profitable now.
- Uniswap v4Full study
2023 · Design paper · Move value
One contract holds many pools. Hooks are code that runs before and after swaps and liquidity changes. Flash accounting settles balances at the end of a lock. A hook can change the rules v3 users took for granted.
- TWAMMFull study
2021 · Design paper · Move value
Execute a large order as if it were split into infinitely many tiny trades across an interval, without paying gas for each piece. Settlement is lazy. This is an order schedule, not a price oracle, despite the nearby acronym TWAP.
- LiquityFull study
2021 · Design paper · Move value
Borrow a stable-value token against ether, with a one-time fee instead of an interest rate. Troves are liquidated into a stability pool. Redemptions let the token be swapped for the collateral of the weakest trove. The paper does not promise a peg.
- ERC-4337Full study
2021 · Design paper · Data
Smart-contract accounts that propose UserOperations, bundled by a separate mempool, without a change to Ethereum's consensus. Paymasters can sponsor gas. The validation rule lives in the account, which is the point and the risk.
- GasperFull study
2020 · Design paper · Reach consensus
An idealised proof-of-stake protocol that pairs a GHOST-style fork choice with Casper FFG finality. The paper is the design argument for Ethereum's beacon chain, not a status report on a later client or a later outage.
- PrismFull study
2019 · Design paper · Reach consensus
Bitcoin uses one chain for three jobs: proposing transactions, voting on history, and ordering the result. Prism splits those jobs onto separate block trees so throughput can approach network capacity while confirmation tracks propagation delay.
- StreamletFull study
2020 · Design paper · Reach consensus
A deliberately small consensus protocol: epochs, a leader, a vote, and a rule that three adjacent certified blocks on the same chain become final. The point is to show how little machinery the last few years of BFT designs actually need.
- FruitChainsFull study
2016 · Design paper · Reach consensus
Nakamoto consensus can pay a minority coalition more than its share of hash power, which is the selfish-mining observation. FruitChains records transactions in 'fruit' that hang off the chain, and pays out over a window so honest hash power gets roughly honest rewards.
- DAG-RiderFull study
2021 · Design paper · Reach consensus
Replicas reliably broadcast proposals into a round-structured DAG. Once the DAG is local, each replica can read a total order off it without another round of consensus messages. The paper is the asynchronous, optimally resilient version of that idea.
- BullsharkFull study
2022 · Design paper · Reach consensus
DAG-Rider is built for asynchrony and pays for it on the common path. Bullshark keeps a DAG and a local commit rule, but adds a fast path for when the network is timely. The paper also writes down a simpler partially synchronous version.
- EIP-1559Full study
2019 · Design paper · Move value
Replace a first-price auction for inclusion with a protocol-quoted base fee that moves with demand, plus a tip to the producer. The base fee is burned. The EIP is a fee-market rule, not a promise that fees will be low.
- Transaction fee mechanism designFull study
2020 · Design paper · Move value
A mechanism-design reading of blockchain fees. Roughgarden separates what users pay, what miners keep, and what gets burned, and asks which combinations are incentive-compatible for myopic miners. EIP-1559 is the running example, not a price forecast.
- EIP-4844Full study
2022 · Design paper · Scale
A new transaction type carries a blob: a large chunk of data that consensus nodes hold briefly and that the execution layer cannot read byte by byte. Rollups are the intended user. The blob is not cheap forever, and it is not the rollup's proof.
- BitVMFull study
2023 · Design paper · Scale
A way to dispute an arbitrary computation between two Bitcoin parties using hashlocks, timelocks and large Taproot trees, without a new opcode. Honest execution stays off-chain. A false claim can be challenged on-chain. It is not a global virtual machine.
- CairoFull study
2021 · Design paper · Scale
A CPU whose every instruction was chosen so that a STARK can prove 'this program ran'. You write a program instead of a new set of polynomial equations for each statement. The paper is the machine, not a network's throughput.
- NovaFull study
2021 · Design paper · Privacy
Incrementally verifiable computation without putting a SNARK inside a SNARK. A folding scheme compresses two instances of a computation into one instance of the same size. Repeating that fold is the recursion. The paper is about prover cost, not about a chain.
- MarlinFull study
2019 · Design paper · Privacy
A preprocessing zkSNARK whose structured reference string is universal and can be updated, rather than baked for one circuit in a ceremony that must be trusted forever. The paper improves on Sonic's costs. It is still a SNARK, with a setup.
- FROSTFull study
2020 · Design paper · Privacy
A threshold Schnorr signature: any t of n signers can produce one ordinary-looking signature, and fewer than t cannot. The signing protocol is two rounds, or one if nonces were prepared earlier. The paper is the scheme, not a custody vendor.
- MuSig2Full study
2020 · Design paper · Privacy
n signers, all of them, produce one Schnorr signature that verifies under one aggregated key. Two rounds, and concurrent sessions are in the security claim. This is n-of-n, not a threshold. It is the multi-signature Bitcoin-style schemes reached for.
- TaprootFull study
2020 · Design paper · Privacy
A Bitcoin spend that can look like a single key, while still hiding a tree of alternative scripts until one of them is used. Schnorr signatures and the key-path spend are the mechanism. Amounts stay public. This is not a privacy coin.
- Curve CryptoswapFull study
2021 · Design paper · Move value
Stableswap concentrates liquidity around a fixed price of one. This paper moves that concentration so it can follow a moving price between volatile assets. The pool reprices itself from its own trades. It does not know the outside world except through those trades.
- crvUSD designFull study
2022 · Design paper · Move value
A stablecoin lent against volatile collateral, where liquidation is a continuous trade into a special pool rather than a one-shot auction. The paper calls that pool LLAMMA. A peg keeper and a monetary-policy rate sit beside it. Simulations in the paper are not a promise about later losses.
- UMAFull study
2020 · Design paper · Data
An oracle that does not answer every question in real time. It prices the cost of bribing the token holders who would resolve a dispute, and it asks contract designers to keep the profit of a lie below that cost. The draft is an economic argument, not a feed you can read as truth.
- PerunFull study
2017 · Design paper · Scale
Lightning routes each payment through the intermediaries. Perun asks those intermediaries to set up a virtual channel and then step out of the individual payments. The paper gives the construction for one hub, on a chain that can run the contracts.
- SemaphoreFull study
2020 · Design paper · Privacy
A member of a group proves they are some member, and posts a signal, without showing which member. A nullifier stops the same member signalling twice in the same context. The 2020 proposal is a base layer for voting and similar uses. It is not itself a mixer, and later versions changed the circuits.
