Trust Stack Network · Research

The engineering notebook behind a post-quantum, shielded proof-of-work chain.

Security analyses, consensus notes, and honest negative results from building TSN — a CPU-mined, ZK-shielded L1. We publish what held up under scrutiny, and what didn't.

4 papers live 2 in review Updated Aug 2026 Plonky2 · ML-DSA-65 · cache-hard PoW

Selected work

pinned
Architecture Negative result

The present that doesn't prove itself

RESTART → PRODUCING today ~16 min rebuild derived state from genesis (O(chain)) fixed seconds load persisted state, apply the delta (O(Δ))

We were tempted to reach for recursive "the present proves itself" proofs to kill a 16-minute miner warmup. An adversarial review corrected us: you don't prove your own disk to yourself. A note on caches versus proofs — and where each one actually pays.

12 min

All research

6 entries
№ 004Architecture
ArchitectureNegative result

The present that doesn't prove itself

Recursive proofs don't speed up a restart — a restart re-reads a disk you already trust. A precise line between a trust cache and a proof-carried checkpoint, and what each is actually for.

12 min
№ 003Security
Security

Stealing a shielded note across a fork

When you change the spend-authorization scheme, the fork boundary is a theft window unless every legacy note is re-bound or abandoned. The MigrateToAuth cutoff, and the invariant we should have had from day one.

9 min
№ 002Engineering
Engineering

Tilting proof-of-work toward the CPU

Sizing the PoW working set to live in CPU cache turns a GPU's throughput advantage into a memory-latency penalty. Measured: 26–40× CPU over GPU. And why "cache-hard" is a truce, not a victory.

10 min
№ 001Consensus
Consensus

Forging weight by lying about height

Fork-choice trusts cumulative work, and a block that inflates its own height can inflate its weight. The one-line admission rule — height == parent + 1 — that shuts the door.

7 min
№ 005Negative result
Negative resultIn review

Why fair block distribution between miners is subtle

A field diary of a wrong diagnosis: variance → pacing → propagation delay → a note-accumulator livelock. What actually makes two equal miners take turns in long streaks.

№ 006Systems
SystemsIn review

Two nodes on one LAN that refuse to talk directly

The reachability policy binds miners to loopback — which quietly routes same-LAN peers through a distant relay. The private-address exception we're adding, without re-exposing miners to the internet.