Skip to content
TSN Trust Stack Network
Explorer ↗ Download

Trust Stack Network

Trust Stack Network (TSN) is a Layer 1 blockchain built around three properties from the ground up: proof-native consensus, post-quantum cryptography, and shielded-by-default transactions. Every transaction on TSN is a zero-knowledge shielded transaction — there is no "optional privacy" toggle — and every signature and hash in the current cryptographic suite is chosen to resist both classical and quantum adversaries.

TSN is written from scratch in Rust: no forked chain, no Substrate/Cosmos SDK framework underneath.

What "proof-native" means here

Block production (mining) and shielded-transaction validity both run over the same field: Proof-of-Work hashes with Poseidon2 over the Goldilocks field, and shielded transactions are proven valid with Plonky2 — a STARK-style proof system over that same field, requiring no trusted setup. One field, no separate "mining chip" and "privacy chip" bolted together after the fact.

Two Poseidon permutations, not one

TSN actually uses two distinct Poseidon-family permutations, both over Goldilocks, chosen for two different jobs: the real Poseidon2 (width-8, p3-poseidon2) hashes block headers/PoW, while the note-commitment, nullifier, and Merkle-tree layer uses Plonky2's native Poseidon (width-12, not "Poseidon2") deliberately — so the same hash runs identically in-circuit and out-of-circuit. See Cryptography & Security → Signatures & Hashing for the precise split.

What "shielded-by-default" means here

There is one transaction type, and it always carries a zero-knowledge proof. A shielded transaction spends and creates notes — commitments to (value, owner, randomness) — and reveals a nullifier to prevent double-spending, without revealing which note was spent or to whom the new note belongs. See Concepts → Shielded Transactions for the mechanics.

What "post-quantum" means here

The live cryptographic suite (suite id 1, see Crypto-Agility) is:

Layer Primitive Standard
Signatures ML-DSA-65 NIST FIPS 204
Proof-of-Work / consensus hash Poseidon2 (Goldilocks field) —
Zero-knowledge proofs Plonky2 (PLONK + FRI) — (hash-based, no trusted setup)

Every block header carries a crypto_suite_id field that is always committed into the block hash. This is what makes the chain crypto-agile: a future primitive swap (for example adding SLH-DSA/FIPS 205, currently tracked as a migration effort — see Crypto-Agility) is a new registry entry and a coordinated version bump, not a destructive network reset.

Network status

Live network tsn-devnet-v4 — a fresh-genesis devnet carrying crypto-agility (the crypto_suite_id header field) and the accumulated hardfork schedule from the network's prior gen4 development cycle, under a distinct genesis/chain identity
Software version 3.0.0-rc.48
Mainnet Planned — not launched. Treat any TSN token on the current devnet as having no monetary value.

TSN's public devnet history includes an older, now-abandoned gen4 network identity (tsn-devnet-v2-gen4). The current live network is tsn-devnet-v4, a distinct chain identity — do not confuse the two if you find older references to "gen4" in project history.

Devnet software

This documents pre-mainnet devnet software. Interfaces, ports, activation heights, and reward parameters below are read directly from the current source tree and can change before mainnet. Anything not directly confirmable in code is marked TODO: verify rather than guessed.

Highlights

  • One field for mining and privacy — Poseidon2 (PoW) and Plonky2 (ZK proofs) both run over the same Goldilocks field, see Architecture.
  • 90 / 5 / 5 block reward split — miner / dev fund / service-node pool, enforced at compile time (the split is asserted to sum to 10,000 basis points). See Reference → Protocol Parameters.
  • Five node roles in the current devnet-v2/v4 protocol: miner-v2, service-node, indexer, cortex-v2, ingress — each a distinct binary role with its own port and data directory. See Architecture → Node Roles.
  • Headers-first sync with a fork-choice engine that treats missing block bodies as a first-class case ("require-bodies") rather than trusting headers alone. See Architecture → Fork Choice & Sync.
  • A documented, code-fixed fund-theft class — the spend-authorization ("AuthBound") hardfork binds every shielded spend to proof-of-knowledge of the note's secret key, closing a vulnerability class where a note's public visibility alone previously let anyone forge a spend of it. See Cryptography & Security → Threat Model.

Where to go next

  • New to TSN? Start with Get Started to install the binary, create a wallet, and send a transaction.
  • Want to mine? See Mining.
  • Running infrastructure? See Run a Node.
  • Building on TSN? See Develop.
  • Looking for an exact parameter value? See Reference — every number there is sourced directly from src/config/devnet_v2.rs and cross-checked against the compiled binary.