Qumbra

quantum + umbra — the innermost shadow, the region an eclipse makes fully dark quantum + umbra —— 本影,日食中被完全遮暗的那一块

A post-quantum privacy chain,
designed from scratch in 2026.
一条后量子隐私链,
从零开始按 2026 年的条件设计。

The “post-quantum privacy chain” question was last answered with 2018-era tools. Qumbra asks what the 2026 answer is — NIST PQC standards finalized, STARK proof systems production-mature, hybrid schemes with industrial precedent. All load-bearing cryptography is post-quantum. There is one shielded pool and everything is in it by default. 「后量子隐私链」这个问题,上一次被回答时用的还是 2018 年的工具。Qumbra 问的是 2026 年的答案是什么 —— NIST 后量子标准已定稿、STARK 证明系统已进入生产成熟期、混合方案已有工业先例。所有承重密码学都是后量子的; 只有一个屏蔽池,并且默认所有交易都在池内。

Three commitments the rest follows from三条承重约定,其余都从此推出

The PQ red line后量子红线

No elliptic curve carries weight anywhere in consensus. Hash-based STARKs over Keccak, ML-KEM-768 addresses and note encryption, ML-DSA committee votes. Conservative hash everywhere inside the proof system — the layered hedge an earlier draft proposed was retracted as unsound. 共识中没有任何一处由椭圆曲线承重。基于 Keccak 的哈希型 STARK、ML-KEM-768 地址与票据加密、 ML-DSA 委员会投票。证明系统内部一律使用保守哈希 —— 早期草稿里那套分层折中方案已被判定不成立并撤回。

One pool, private by default单池,默认隐私

Notes, not accounts. A single global shielded pool, not rings — the anonymity set is every note that ever existed. There are no protocol privacy tiers, because a tier is just a pool split, and a split pool is a smaller anonymity set wearing a feature's name. 用票据(note)而非账户。单一全局屏蔽池,而不是环签名 —— 匿名集就是历史上存在过的全部票据。 协议层没有隐私分级,因为分级本质上就是把池子切开,而切开的池子不过是顶着功能名字的更小匿名集。

Auditable without a backdoor可审计,但没有后门

Disclosure is the holder's to give, in four layers: standing viewing keys, a per-transaction disclosure STARK, exculpatory watch proofs, and the deposit edge. The coinbase is the chain's only transparent flow, which makes it the supply-audit anchor. 披露权在持有人手里,分四层:常驻查看密钥、单笔交易的披露 STARK、自证清白的 watch 证明, 以及入金边界。coinbase 是全链唯一透明的资金流,因此它同时充当供应量审计锚点。

Two inputs enter, two outputs leave,
and the box between them is opaque.
两路输入进,两路输出出,
中间那个盒子是不透明的。

That is not a metaphor for privacy. It is the frozen v1.0 circuit shape: every Qumbra transaction is exactly 2-in / 2-out — two depth-32 Merkle membership proofs, two nullifier PRFs, two spend-key knowledge proofs, two commitment well-formedness checks, and an in-circuit value balance. What happens inside the box is what the STARK proves without showing. 这不是一个关于隐私的比喻,而是已冻结的 v1.0 电路形状:每一笔 Qumbra 交易都严格是 2 进 / 2 出 —— 两条深度 32 的 Merkle 成员证明、两个 nullifier PRF、两个花费密钥知识证明、两个承诺良构性检查, 外加电路内的金额平衡。盒子里发生的事,正是 STARK 要在不展示的前提下证明的东西。

The mark deliberately encodes no parameter — no N=21, no 75 s. Those are frozen today and some still carry [devnet-placeholder]; a mark that encodes a number inherits that number's revisions. The 2×2 shape is different in kind: changing it would not be a parameter change, it would be a different chain. The 45° angles are geometry, not taste — both diagonal edges of a rotated square are perpendicular to the travel direction, so the lines meet the diamond square and need no mitre. 标识刻意不编码任何参数 —— 没有 N=21,没有 75 s。这些参数今天是冻结的, 但其中一部分仍标着 [devnet-placeholder];把数字画进标识,就等于继承这个数字的每一次修订。2×2 的形状 性质不同:改变它不是改参数,而是换一条链。45° 是几何而非品味 —— 正方形旋转后的两条对角边都与走线方向垂直, 所以线条正交地接上菱形,不需要斜接处理。

The load-bearing numbers承重数字

Measured in the prototype lab, not estimated. Lab numbers enter a design doc only after being reproduced twice on the same rig plus an independent rerun — every result records the git rev, the prover crate revs, the hardware, the OS and the power state. 这些数字是在原型实验室里测出来的,不是估的。实验室结果必须在同一台机器上复现两次并经过一次独立重跑, 才能写进设计文档 —— 每条结果都记录 git rev、prover crate rev、硬件、操作系统和电源状态。

145.1 KB
consensus transaction (148,625 B, b16 — as minted 2026-08-04)共识交易大小(148,625 B,b16 —— 2026-08-04 铸造版本)
~100 bit
conjectured FRI security, corrected accounting修正后核算下的 FRI 猜想安全强度
2.0 s
prove time, narrow Keccak AIR at 402 columns证明耗时,402 列窄 Keccak AIR
75 s
block time — RandomX-class PoW + Zawy LWMA-1出块间隔 —— RandomX 类 PoW + Zawy LWMA-1
21
BFT finality committee, Crosslink-shape, day oneBFT 终局委员会规模,Crosslink 形状,第一天就上
~52 MB/day
PQ compact blocks at launch (R=1)上线时的后量子紧凑区块带宽(R=1)
108
bessel per QMB — after the Besselian elements of eclipse computation每 QMB 的 bessel 数 —— 取自日食计算中的贝塞尔要素
65/15/20
miners / committee / treasury — fair launch, zero premine, no hard cap矿工 / 委员会 / 国库 —— 公平启动,无预挖,无硬顶

The PQ tax is real and accepted: roughly 20–30× the transaction size of curve-based state of the art. Aggregation rung 1 makes per-transaction proofs prunable after the block proof lands; the permanent cost is the ciphertexts, not the proofs. 后量子代价是真实的,而且是被接受的:交易体积约为曲线派最优方案的 20–30 倍。聚合 rung 1 让单笔证明在区块证明落地后 可被剪枝;永久成本是密文,不是证明。

The protocol stack协议栈

  1. Ecosystem & wallets生态与钱包 Mobile wallet is the product; one Rust kernel behind five shells (desktop, macOS, iOS, Android, browser extension), and the desktop shell has made a live on-chain spend. Binding exclusions: no L1 DeFi, no early bridges, no paid listings, no proving service.移动钱包就是产品;一个 Rust 内核,五个外壳(桌面、macOS、iOS、Android、浏览器扩展),桌面壳已完成一笔真实链上花费。硬性排除项:不做 L1 DeFi、不做早期跨链桥、不买上所、不做代证服务。
  2. Auditability & disclosure可审计与披露 Four-layer key/edge disclosure stack. No protocol tiers — a tier is a pool split.四层密钥/边界披露栈。协议层不设分级 —— 分级就是切池。
  3. Transaction layer交易层 Notes + one global shielded pool. Monolithic per-tx STARK with spend authorization in-proof, in-circuit value balance, 2×2 metadata buckets.票据 + 单一全局屏蔽池。单体式单笔 STARK,花费授权在证明内完成,金额平衡在电路内校验,2×2 元数据分桶。
  4. Note discovery票据发现 Launch on PQ compact blocks; discovery bound to the consensus wire (omission is consensus-invalid). OMR overlay sits behind a triple gate; FMD excluded.上线走后量子紧凑区块;发现数据绑定在共识线上(缺失即共识无效)。OMR 覆盖层设三重门槛;FMD 排除。
  5. Aggregation聚合 Rung ladder 0→2. Rung 1 proves per-block transaction validity plus an epoch supply-attestation rider; proofs prunable after.0→2 三级阶梯。Rung 1 证明整块交易有效性,并附带一个 epoch 供应量证明 rider;之后证明可剪枝。
  6. Consensus共识 RandomX-class PoW for block production, N=21 BFT finality committee with ML-DSA votes, 24 h epochs, slash 10% + tombstone. ZIP-317-shape posted fees.出块用 RandomX 类 PoW,N=21 的 BFT 终局委员会以 ML-DSA 投票,epoch 24 小时,罚没 10% 并墓碑化。费用采用 ZIP-317 形状的明码费率。
  7. Network网络 P2P with peer discovery and hardening. Dandelion++ and Tor are defense-in-depth — never anonymity load-bearing.P2P,含节点发现与加固。Dandelion++ 与 Tor 属于纵深防御 —— 绝不让它们承担匿名性。
  8. Economic base经济基础 Fair launch, zero premine. Smooth closed-form decay into a perpetual tail — no halving cliffs, because every cliff re-opens the dev-fund question on a timer.公平启动,零预挖。平滑的闭式衰减进入永续尾部发行 —— 不设减半悬崖,因为每一次悬崖都会按时重启一轮开发基金之争。

Where it actually is目前真实进展

Status-first, including the parts that are not working. As of 2026-08-13. 状态优先,包括跑不通的部分。截至 2026-08-13。

T0 internal net — live, drills passedT0 内部网 —— 运行中,演练通过

Four node hosts, three continents, one Terraform state. The 48-hour WAN soak sealed 2026-07-28; the net was re-minted 2026-08-04 (genesis 138e1524…addb, reproduced byte-identically twice) and has run since. All four scenario drills — restart, late-joiner, committee stall, 2+2 partition — ran on 2026-08-07 and were adjudicated PASS: no safety stop-point was reached in any of them. Every incident to date has been liveness, never safety. 四台节点主机、三个大洲,共用一份 Terraform 状态。48 小时广域网浸泡测试于 2026-07-28 封存; 网络于 2026-08-04 重新铸造(创世 138e1524…addb,两次逐字节复现)并持续运行至今。四项场景演练 —— 重启、后加入者、委员会停摆、2+2 网络分区 —— 已于 2026-08-07 全部跑完并裁定通过: 任何一项都没有触及安全性停止条件。迄今所有事故都是活性问题,从未涉及安全性。

The first user journey is complete首个用户旅程已走通

On 2026-08-10 a real user went keygen → faucet grant → detect → spend → receive, end to end over the public https edge; the spend proved in 3.62 s on their own laptop, and their final ledger reconciles to the bessel. Seven defects stood in the way — found by that user's real money, all fixed inside one day. An earlier version of this card said the recipient of a payment could not spend it; the mint's unconditional single-note latch closed exactly that. 2026-08-10,一位真实用户完整走通了 keygen → 水龙头发放 → 检测 → 花费 → 收款, 全程经由公开 https 边缘;这笔花费在他自己的笔记本上 3.62 秒完成证明,最终账本精确到 bessel 对账。 途中拦路的七个缺陷 —— 全部由这位用户的真实资金暴露,并在一天之内修复。本卡片的上一版写着「收款人花不出收到的钱」; 铸造带来的无条件单票据 latch 恰好关闭了这个问题。

The supply audit worked — once, for real供应量审计真的抓到过一次

Consensus never validated the coinbase against the emission schedule, and the audit found exactly one under-paying block on the live net (height 1377, −4,114 bessel), fleet-unanimous. The schedule is now a validity rule: activated 2026-08-12 at height 8,640 via a planned halt — unanimous finality id across the fleet, emission audit clean on resume. The coinbase-as-audit-anchor thesis above got its first real test and held. 共识层此前从未用发行时间表校验 coinbase,而审计在运行中的网络上恰好找到一个少付的区块 (高度 1377,−4,114 bessel),全集群一致确认。发行时间表现已成为有效性规则:2026-08-12 经计划停机在高度 8,640 激活 —— 全集群 finality id 一致,恢复后发行审计零差异。上文「coinbase 即审计锚点」的立论迎来第一次实战检验,并且成立。

Public mining: gates closed, door not open公开挖矿:门槛已清,门还没开

All four pre-public-mining gates are closed or ruled — the coinbase rule, the mempool wedge, wire-native node discovery, the pool payout axis. What remains is operational, not consensus: the first-miner-journey drill (mine → detect → mature → spend, a path that has never run live), resume coverage on the hosts the boundary halt left behind, and the fleet still mines to an unspendable placeholder until the miner-payout decision is taken. The faucet's rate limiter is still one global bucket. 公开挖矿前的四道门槛已全部关闭或裁定 —— coinbase 规则、内存池楔子、节点的线上原生发现、矿池支付轴。 剩下的是运维项而非共识项:first-miner-journey 演练(挖矿 → 检测 → 成熟 → 花费,这条路径从未真实跑过)、 边界停机后尚未恢复主机的覆盖,以及在矿工收款决定做出之前,集群挖到的每一枚币都进入不可花费的占位地址。 水龙头的限流器目前仍是单个全局桶。

The T1 product surface has no open design decisions left — discovery serving, faucet access, public host, wallet send seams and the explorer split are all stamped. What stands between here and inviting strangers is execution and drills, not deliberation. The authoritative, continuously-updated version of all of this is the roadmap. T1 产品面已没有悬而未决的设计决定 —— 发现服务、水龙头准入、公开主机、钱包发送接缝、浏览器拆分均已敲定。 从这里到向陌生人开放,隔着的是执行与演练,而不是论证。以上内容的权威版本与持续更新在路线图里。

Read the roadmap查看路线图

Four repos四个仓库

The design → lab → deploy split is a blast-radius decision, not a tidiness one: no node host ever holds a credential that can read lab source. design → lab → deploy 的拆分是爆炸半径决策,不是整洁度决策:任何节点主机都不持有能读取 lab 源码的凭据。

qumbra-design

43 paired EN/ZH design docs plus seven English-only appendices. protocol-spec.md is the normative core. Specs and task books flow down to the lab. 43 组中英对照设计文档,外加七篇仅英文的附录。protocol-spec.md 是规范核心。规格与任务书由此下发给 lab。

qumbra-lab

Rust workspace, 20 crates: the AIR and bench harness, the qumbra-node binary, PoW, P2P, wallet, note encryption, disclosure STARK, compact-block server, faucet, explorer endpoint, operator view. Not a chain implementation — the lab that decides whether one is worth building. Rust 工作区,20 个 crate:AIR 与 bench 框架、qumbra-node 二进制、PoW、P2P、钱包、票据加密、披露 STARK、紧凑区块服务、水龙头、浏览器端点、运维视图。它不是链的实现 —— 而是用来判断这条链值不值得建的实验室。

qumbra-deploy

Terraform: four node hosts across four regions plus the service edge, one state. The T0 internal net and its public https face. The node image is public on GHCR; keys, genesis and per-host env are host files only, never in git. Terraform:四个区域的四台节点主机,外加服务边缘,共用一份状态。承载 T0 内部网及其公开 https 门面。节点镜像在 GHCR 上公开;密钥、创世文件与各主机环境变量只以主机文件形式存在,绝不入库。

qumbra-explorer-web

The chain-health page, split out of the node binary on purpose: static files, no build step, no framework, a client of one endpoint. Deliberately not a transaction explorer — a single shielded pool leaves nothing to look up, and that exclusion is binding. 链健康页面,刻意从节点二进制中拆出:纯静态文件,零构建,零框架,只消费一个端点。它刻意不是交易浏览器 —— 单一屏蔽池没有任何可查询的东西,这条排除是硬性的。