The Internet of Economics, the Gajumaru & QPQ Un-White Paper – Updated 260331
31st March 2026
The Internet of Economics, the Gajumaru & QPQ Un-White Paper – Updated 260331Executive SummaryThe ProblemWhat We BuiltWhy It MattersThe ArchitectureValidationThe Core TestScope and PurposeHow This Document Is StructuredWhyWhy We Built What Nobody Else WouldWhy It MattersWhy This Is an ‘Un-White Paper’, Not a ‘White Paper’The Corruption of a Serious TermWhat We Stand UponThe Fundamental DifferenceIntroduction: The GajumaruThe ProblemWhat Lies BeyondThe PromiseThe BetrayalThe State of ThingsAn Actual Blockchain That Actually Works, Minting Real Money that Really WorksWhy “Gajumaru”?Resource, Not InfrastructurePart One: First PrinciplesI. The Fundamental UnderstandingGajumaru Provides a Complete Global Economic NetworkGroot as The Global Interoperability LayerThe High Seas AnalogyThe Archipelago ProblemWhat Is an Associate Chain?Why this design?Transparency on Groot, Privacy within Associate Chains.Master Chain / Sub-Chain HierarchyCase Study Example: A Global Stablecoin Associate ChainCase Study Example: The Banking Consortium ProblemThe RIPA ModelThe Two Paths, One SystemPath 1: RPA – Resource, Platform, Application Path 2: RIPA – Resource, Infrastructure, Platform, ApplicationWhy Both Paths Must ExistWhat This Makes PossibleII. The Internet of EconomicsWhy Intermediaries ExistCrypto and Blockchain: Two Different IndustriesDigitisation vs DigitalisationA Different MachineThe Accumulated Cost of DigitisationThe FinTech IllusionThe Categorical EliminationThe Human EconomyThe Machine EconomyThe Architectural GapFoundations for the Machine EconomyWhere Digitalisation Happens, and Where It Still CannotDefinitionWhy Only the Gajumaru Delivers ThisIII. Economic EmancipationThe Mission StatementProgrammable ControlThe TrajectoryThe Duality PrincipleThe Three RestorationsMoneyAssets Data The Exit Option PrincipleMere Existence Is Not EnoughWhat Economic Emancipation MeansSimplicity as Design PrinciplePartition, Not CompromiseIV. The Garden of Eden ProblemThe Evidence Is EverywhereNewcomenWhat We KnowWhat We ThinkWhat We Took From ItThe Ratchet Only Turns One WayThe Same Ratchet in Blockchain‘The One Ring’What We Did DifferentlyWhy Only One Resource Layer Will Ever ExistPart Two: The ArchitectureV. Groot Resource LayerWhat Groot IsWhy Proof of WorkHow Mining WorksThe Gajumaru’s Puzzle: Cuckoo CycleHow Bitcoin-NG Consensus WorksWitnessing: How Settlement AcceleratesWhat this Means for Liability and TrustGraceful DegradationSettlement: How Certainty WorksThe Certainty IllusionThe Same Illusion in FinanceHow Settlement Works on GrootWhat This Means in PracticeA $5 cup of coffee A $5,000 family holiday package A $50,000 car purchase A $500,000 house purchase What happens in the rare case of a micro-fork? At every stage, the value sits on a trustless layer requiring no third party’s cooperation. Why Compressed Settlement Is Also a Security PropertyThe Arithmetic of the Short WindowThe high-value caseProtocol Sovereignty: The Path to a Finished ProtocolConstruction, Not GovernanceA Finished, Sovereign Protocol Performance SpecificationsTransactional EfficiencyMinting Efficiency: A Different CalculationHow This Comparison EvolvesWhat This Means in Human TermsVisibility as IntegrityVI. The Gaju: Sound MoneyThe 木Gaju CurrencyThe Commodity TestFrom Proof of Concept to Functional CommodityThe Properties of Commodity Money5,000 Years of DebasementSound Money, RestoredThe Transit CurrencyDiscipline by MathematicsWhy the World’s Reserve Currency Has FailedThe Emerging Economy TrapCase Study: El SalvadorDiscipline Without StatusMining DistributionLong-Term Mining SustainabilityVII. How the Gajumaru WorksCurrencies on GrootData TTL: Solving the Infinite Library ProblemSmart Contracts: The Sophia Language and FATE Virtual MachineThe Naming SystemGeneralised AccountsPaying-For-Others: Removing the Onboarding BarrierFirst-Class Protocol ObjectsState Channels: Scaling for PurposeAssociate Chain Currency ArchitectureNo ConstraintsThe Market DecidesEvery Model, One NetworkWhat Every Currency InheritsGroot as Canonical Reference PointNative Associate Chain Awareness: No Bridges RequiredThe Bridge ProblemScale of the ProblemThe Industry Acknowledges the ProblemBeyond Bridges: The ‘Layer Zero’ ApproachesThe Gajumaru Answer: Protocol-Level AwarenessBuilt-in Damage LimitationMinimum Viable IntegrationPluggable Consensus ArchitectureThe Scaling ConsequenceRegulatory Position: MiCA Compliance as Competitive AdvantageEngineered to LastVIII. Security ArchitectureDesigned for the Real EconomyThe QPQ Approach: Zero DependenciesThe NPM Supply Chain: A Documented CatastropheThe Browser ProblemGRIDS: Air-Gapped SigningWhat it Feels Like to Make a Payment:The Security HierarchyLevel 1: Probably Secure Enclave (Operational)Level 2: GRIDS Hardware Wallet (Next Phase)Level 3: Full QPQ Hardware Stack (Planned)Self Single Sign-OnQuantum Resistance: Designing for Cryptographic EvolutionGRIDS as Foundation for the Internet of EconomicsIX. Decentralised Exchange, Decentralised Finance (For Real)What Is a Decentralised Exchange?What a Proof-of-Work Blockchain ProducesWhy a Decentralised Exchange, Not a Centralised ExchangeHow to Test Whether a DEX Is RealWhat a DEX Does for a BlockchainMarketplaces and ExchangesThe Promise Betrayed (Again)The Alternatives That Weren’tHow They Fail: The Exchange LayerHow They Fail: The Settlement LayerThe Token TrapScale Without SubstanceThe Promise That Was Never Kept: DeFi on Broken FoundationsLies, Damn Lies and Crypto LiesThe Circularity No Price Discovery Without Real MoneyThe ProofScoring Criteria and Deduction RulesResultsWhat We BuiltTwo Mechanisms: How Exchanges Actually WorkWhat GajuDEX EliminatesWhy No Governance Token Is NeededOwnership Vs ServiceTwo Deployments, Groot and Known Proof of Stake Associate ChainMeasured Against the Same StandardRegulatory Convergence Through ArchitectureWhat Genuine DeFi Looks Like on Real MoneyWhat Becomes PossibleInsurance: From Product to ParticipationProperty and CapitalThe Unserved WorldTokenised Shares and Pre-IPO LiquidityIntellectual PropertyHuman CapitalPhysical CommoditiesThe ConvergenceFrom Digital Assets to Physical Markets – PHYDEX: Physical and Derivative ExchangeSupply, Demand, and the CurrencyImplementationPart Three: From Architecture to the Real World EconomyX. Open Innovation: Patents, Licensing, and Defensive IPGPL3: Open Source That Protects OpennessWhat GPL3 means:GPL3 and Patents: The Built-In Peace ProvisionWhy GPL3 and Not a Permissive LicenceDefensive, Not OffensiveFreedom to Build: What This Means for ParticipantsPart Four: Why Everyone Else FailedXVII. The Two Fundamental TestsThe Test for TrustlessnessThe Test for PowerThe Vocabulary of Unaccountable PowerXVIII. The ‘Blockchain Trilemma’The Classic FramingThe Problems with the Classic FramingSecurity Is DerivativeThe Correct Analytical Framework – TEAThe TriangulationThe Failed MiddlePhysics ConstraintsWhy the Framing MattersXIX. The Four Patterns of FailurePattern 1: Performance Claims That Defy Physics and MathematicsTheoretical maximum versus settled throughput.Consensus votes counted as user transactions.Failure rates concealed from performance claims.Pattern 2: AI-Generated ObfuscationPattern 3: Centralisation Hidden Behind LanguageThe tells are always there:Pattern 4: FoundationsThe Subsidy Trap.The Vesting Asymmetry.Governance Capture Through Delegation.The Garden of Eden Problem, RevisitedConclusionXX: The Layer 2 FallacyI. The MathematicsII. A Roadmap, Not a ResponseThe scaling crisis was realThe October 2020 pivotWhat the Merge gave upWhat the pivot preserved: four aligned interestsThe Dencun contradictionFive years without decentralisationFebruary 2026: The AdmissionIII. Plasma: The First AttemptIV. Optimistic Rollups: Centralisation Made ComfortableArbitrum: The Full AccountBase: Coinbase’s Unregulated Profit CentreThe censorship problem, definitively statedV. Zero-Knowledge Rollups: The Mathematical Promise, BrokenThe proof cost realityThe prover time constraintCompounding ConstraintsThe attacks this architecture uniquely enablesZKSync: Pattern 4 executed with a bot armyThe soundness failureVI. ADI Chain: A Nation Builds on the RubbleVII. Lightning Network: Bitcoin’s Answer to the Same QuestionThe Routing WallThe Centralisation EngineThe Custodial TrapUnfixable Fundamental Security FailuresThe BetrayalVIII. What ‘Layer 2’s Actually AreIX. The Root CauseAppendix: The EssentialsWhat Is a Blockchain?How Does a Blockchain Agree on What Is True?The Resource Layer ConceptWhy This Matters to YouGlossaryHow Blockchains WorkTransactions, Speed, and SettlementMoney and ValueSmart ContractsArchitectureExchanges and TradingSecurity and AccessFoundations and Industry StructureRegulation and LicensingReferencesDisclaimer
Executive Summary
The Problem
The global economy is not truly global: it is fractured, fragmented and disconnected. The architecture rewards control of bottlenecks over creation of value. Rational actors respond to rational incentives; the result is an economic system where the degree of control you exert, rather than the value you add, determines your outcome.
When systemic risk accumulates, as it does and must under these incentives, the consequences are socialised. The response, inevitably, is yet more monetary expansion that restores institutional balance sheets whilst diluting the purchasing power of everyone whose wealth is denominated in the currency being expanded. The vast majority bear the cost of a correction they did not cause, through a mechanism most do not fully understand.
Blockchain was supposed to change this. It did not. Today's distributed ledger protocols mimicked the system they were supposed to replace: fractured, fragmented, isolated. More islands. More bottlenecks. More control points. Over $120 billion in venture capital flowed into ‘blockchain’ projects. They used the language of decentralisation to build more infrastructure and spawned a new, global, unlicensed gambling industry: ‘crypto’.
What is missing in both the existing and nascent blockchain enabled economy is a resource layer that makes adding value more profitable than controlling access. Nobody built it because nobody with capital to deploy wanted to: a resource layer serves everyone, which is another way of saying it serves no one's monopoly.
What We Built
The Gajumaru is the world's first digital economic resource layer: an actual blockchain that actually works, minting real money that really works. For the first time genuine choice exists between governed efficiency and ungoverned freedom. Neither can dominate because both are available.
Groot, the proof of work core blockchain that underpins the Gajumaru, has been operational since 22 October 2024. Groot is more than 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation. More simply, in excess of 300 transactions per second with settlement in 2-3 seconds (there is a micro-block every 3 seconds that will include your transaction) and absolute finality in 3-4 minutes (there is a key block every 2 minutes; 2 of them is absolute finality, so between 3 and 4 minutes from your entry into the micr=block, you have absolute finality). Fixed supply of one trillion 木Gaju over 87.5 years, then no more, ever.
Why It Matters
The Gajumaru provides the missing foundation beneath all economic infrastructure. Not to replace governed systems, but to connect them. Not to eliminate trust, but to create alternatives that discipline extractive systems.
A genuine, trustless exit will never match governed efficiency. It does not need to. It needs to genuinely exist and it needs to work.
The Architecture
Groot: Governance-free resource layer. No operator. No one can say no. The high seas that connect all ports. An actual blockchain that actually works, minting real money that really works.
Associate Chains: Sovereign infrastructure that nations, industries, and enterprises control entirely. Their rules, their operators, their borders.
Native Interoperability: No bridges to trust. No consortium to join. Value flows freely between any two points through the trustless negotiable space between them – like the high seas of the global digital economy connecting the world’s ports: Groot.
Validation
Groot operational since October 2024
Liechtenstein selected QPQ as technical partner for national blockchain infrastructure (LTIN), launching Q3/4 2026
CHF 1M+ pre-release revenue from Gaju Mining SaaS with zero marketing spend
The Core Test
The purpose of blockchain is to be able to trust the message rather than the messenger, securely, at scale. The core question, therefore, to put to any project or protocol claiming decentralisation: Does this allow us to trust the message, not the messenger, securely at scale?
Every legitimate blockchain application flows from this single question. Every failed project obscures it. The Gajumaru passes the test that $120 billion of investment1 failed to pass.
Scope and Purpose
The blockchain that Bitcoin proved was possible is here, working, operational since October 2024: the Gajumaru. The promise kept, at last.
This paper explains what the Gajumaru is, why it matters, and how you can be part of it. It sets out the core proposition: a governance-free resource layer that creates genuine choice between governed efficiency and ungoverned freedom. It details the architecture: Groot, Associate Chains, native interoperability. It presents the validation: sovereign adoption, commercial revenue, operational proof.
It also explains why, after over $120 billion of investment,1 nothing else has delivered this. The industry's failures are not the primary story here – but they are necessary context. They are not accidents. They flow from structural incentives, institutional capture, and deliberate obscuring of what "blockchain" actually means. Understanding why everything else failed illuminates why the Gajumaru's design choices matter.
The industry gave its failure a name and called it a law: Buterin's blockchain trilemma – decentralisation, security, scalability, pick two. It is not a law. It is what happens when you try to solve contradictory requirements in a single system. The right framework is TEA: Trustlessness, Efficiency, Accountability. This document applies it throughout – to the Gajumaru's own architecture and to every project examined in Part Four. Keep it in mind. It explains everything.
This is not a technical document. The Gajumaru's architecture, consensus mechanisms, and protocol specifications are documented in the Technical Paper. That document matters, but we know the reality: life is busy, technical papers are dense, and most people will never read them. That's fine. The Technical Paper explains how the system works for those who need to verify the engineering. This paper explains why it matters and what it means. We wrote it to be read, not endured. Every section is designed to stand on its own and reward the time you give to it. You can read it front to back, or dip into the parts that matter to you. Either way, you will come away understanding what blockchain actually is, why $120 billion of investment1 failed to deliver it, and what changes now that someone has.
We wrote it for everyone: policymakers, institutional executives, politicians, and ordinary people from the same hard-working families the founders came from.
Whether you believed in Bitcoin's original promise, or you are only now awakening to the world as it is and asking what the future holds: the dream of money beyond the reach of those who debase it, of owning the fruits of your labour and endeavour, of keeping the upside of your risk, of economic participation without gatekeepers – that dream is not dead. It is here, it works, and this paper will show you what that means.
QPQ built the Gajumaru. We cannot pretend otherwise, and we would not want to. But that fact raises the obvious question: what stops us from becoming the next foundation that captures what it created?
The answer is structural. We made deliberate choices that prevent the Gajumaru from being controlled – by anyone, including us. We open-sourced the protocol. We hold no special position in Groot's consensus. We cannot change the rules, freeze assets, or say no to participants we dislike. These choices cost us the extractive possibilities that other blockchain creators kept for themselves. They are also the only choices that produce an actual resource layer rather than another piece of controlled infrastructure with decentralised branding.
How This Document Is Structured
This document is organised in a foundational section followed by five parts.
Why — before the formal parts begin — covers the motivation, the stakes, and the state of the world that made this necessary. It establishes what was missing, what we built, and why it matters. Readers who want context before architecture should start here; readers who want to go straight to the framework can proceed to Part One.
Part One: First Principles establishes what a governance-free resource layer is and why none has existed until now, how the choice between trustless and governed paths creates the economic discipline that neither path alone can produce, and why the existence of a genuine exit option is the mechanism through which economic emancipation becomes possible.
Part Two: The Architecture details the technical foundations: the governance-free, proof-of-work resource layer and the design choices that make it structurally distinct from every predecessor, the fixed-supply mined currency it produces and why its monetary design matters, the full system architecture and security model, and the first genuinely decentralised exchange built on it.
Part Three: From Architecture to the Real World Economy covers the open innovation and IP framework through which the resource layer is commercialised without being controlled, the product and service suite built on it, the sovereign blockchain infrastructure now in development, stablecoin, state-channel markets, the first national-level sovereign adoption, the mining-as-a-service revenue model, and the price stabilisation mechanism that makes the currency usable for commerce.
Part Four: Why Everyone Else Failed applies a systematic framework to the industry's failures, examining the structural incentives that produced them, the capture mechanisms that protected them from scrutiny, and the vocabulary that was built to ensure the right questions were never widely asked.
Part Five: The Gajumaru Answer turns that same framework on the system built here – applying it without exemption to our own architecture – and sets out what becomes possible for the real economy when a governance-free resource layer genuinely exists and the questions the crypto industry would rather you did not ask can finally be answered.
Each part builds on the last, but, equally deliberately, also stands on its own. We aimed to make this readable by everyone; where technical terms are necessary, we have explained them in accessible language where they are introduced.
Readers who are new to blockchain may find it helpful to read the Appendix: The Essentials before starting. It provides the foundational concepts needed to follow this document's arguments, written for clarity rather than expertise. More experienced readers can skip it entirely. Throughout the document, brief parenthetical definitions appear at the first use of key terms; these serve the same purpose and can be read or ignored as needed by each reader.
The team that built this system has lived inside it for years. That familiarity is an asset when building; it is a liability when explaining. We have worked to write for the reader rather than for ourselves, but where we have fallen short, a practical remedy exists: point a capable AI assistant at this document and ask it to explain what is unclear. Treat it as a reading companion rather than a substitute for the source. These tools are genuinely useful for navigating complex material at your own pace – and genuinely unreliable when they contradict the source, as they sometimes will. They pander to the user and fill gaps with confident invention. The source document is the authority. Reading it will pay dividends.
Twenty-five years of knowledge, endeavour, and hard-won understanding went into what follows. Every part rewards the reader who goes all the way through. We wrote it to be read in full, and we believe those who do will find it worth every page.
Why
Why We Built What Nobody Else Would
Trust is the foundation of all human cooperation. Where trust exists, efficiency flourishes: commerce flows, relationships deepen, societies prosper. But trust requires choice. Where there is no alternative, there is no trust – only compulsion. Compulsion becomes extraction. Extraction without discipline becomes tyranny.
A genuine exit does not need to be efficient. It needs to exist, and it needs to be usable. Mere existence is not enough; Bitcoin proved that. But where a trustless alternative genuinely works, its presence disciplines power, tempers extraction, and restores the balance that makes genuine trust possible.
Infrastructure will always exist, and should. Governed systems serve real purposes – efficiency demands it. The problem was never that infrastructure existed. The problem was what was missing beneath it: no governance-free foundation, no neutral ground, no exit option.
Fractured, fragmented systems, siloed ledgers. Each controlled by different parties, unable to interoperate except through yet more intermediaries, yet more control points, yet more extraction. No common ground on which to meet. No neutral space in which to transact. Critically, no discipline on the infrastructure itself.
What was missing was the resource layer beneath it all. Not to replace infrastructure – infrastructure delivers the efficiency we need. But to connect it, so systems can speak without subordination. To discipline it, so power cannot extract without consequence.
Without alternatives, governed systems become abusive. We have watched this happen to money. Monetary inflation silently debases our lives, yet like the proverbial frog in boiling water, we barely notice. We have no functioning non-debaseable currency against which to measure the devaluing of our labour, no reference point, no comparison, no way to see what is being taken. The currency in your grandfather's pocket – even your father's – and the currency in yours share only a name.
Without a stable measure, the debasement remains invisible. Without an alternative, there is no accountability. Governments print, debase, then offer benefits to sustain those they have impoverished. Benefits requiring yet more printing, yet more debasement. Rent seekers extract wealth not by creating value but by controlling chokepoints. The nation is subjugated to the state by making people dependent on handouts, dependency that demands ever more inflation to perpetuate the illusion. A system that cannot be measured, cannot be compared, cannot be escaped. We see this as a spiral that shuts our children and their children out of meaningful participation in the economy, with no way to hold anyone to account.
A non-debaseable currency that actually works changes everything. Not because everyone must use it, but because everyone can. Its mere existence creates the measure. Its availability creates the discipline. A genuine, functioning exit forces honesty on those who would otherwise extract without consequence.
Over one hundred and twenty billion dollars1 flowed into ‘blockchain’ projects – some building more of the infrastructure that caused the problem, the rest building a casino that profited from it – whilst the fundamental problems blockchain promised to solve remained unsolved.
We built what nobody else would. The genuine exit that disciplines power. The connector that makes the global economy whole, unlocking the global economy, unleashing our creativity, and restoring our humanity.
Why It Matters
We refuse to hand this broken world to our children and yours.
We want them to inherit the kind of high-trust society our forebears fought to hand us, not the hollowed-out remnant we are otherwise bequeathing them. A world where endeavour is rewarded, not taxed into submission. Where value creation, not gatekeeping, determines success. Where trust is earned through transparency, not enforced through dependency. Where money holds the value of the endeavour it took to earn it, not quietly eroding through monetary inflation.
We watch our children work harder than we did for less than we had. We watch young families locked out of homes their grandparents bought on a single income. We watch savings erode, wages stagnate, and the cost of simply existing climb year after year whilst those who control the chokepoints extract more from every transaction that passes through their hands. We see the spiral, and we know where it leads.
Once you see it, you cannot unsee it. We had the capacity to build something that could change this. So we dedicated our lives to it. In the case of our founder, the last twenty-five years.
None of us can solve for our families alone. We either solve for all of our families together, or we all fail together. That is not a threat; it is an invitation. Do not be frightened of what is coming. Choose instead to be part of ensuring that the future is one we can be proud to hand to the generations that follow.
Why This Is an 'Un-White Paper', Not a 'White Paper'
The crypto industry debased ‘white paper’ from authoritative policy document into marketing brochure for vapourware. Our white papers are the peer-reviewed foundations we actually built upon. The Gajumaru has been operational since 22nd October 2024. It processes real transactions. We are not promising to build something so you'll part with money. We are telling you that we have built something that delivers upon the promise of blockchain, we are showing you how and we are inviting you to confirm, to verify, the logic, truth and reality we are presenting.
The Corruption of a Serious Term
The term white paper originated with the British government, with the Churchill White Paper of 1922 being an early example.2 These were serious policy documents, described as "a tool of participatory democracy"2, presenting substantive positions whilst inviting informed criticism.
What passes for a ‘white paper’ in crypto is typically marketing dressed in technical language, describing systems that do not exist, making promises that cannot be kept. Beautiful vapourware. Magical technologies impossible in a world governed by physical law. We have never written one of these documents. We never will.
What We Stand Upon
Our 'white papers' are peer-reviewed, battle-tested technical foundations:
Bitcoin-NG (Eyal et al., 2016, USENIX NSDI): The consensus mechanism (the method by which a network agrees on which transactions are valid) decoupling leader election from transaction serialisation. Published computer science research that we implemented.\ https://www.usenix.org/conference/nsdi16/technical-sessions/presentation/eyal
Cuckoo Cycle (Tromp, 2014, updated 2019): Memory-bound, graph-theoretic proof-of-work enabling decentralised mining without the ASIC arms race (ASICs are specialist chips built solely for mining; they are expensive, energy-hungry, and concentrate mining power in the hands of those who can afford industrial hardware). Years of cryptographic scrutiny survived.\ https://github.com/tromp/cuckoo/blob/master/doc/cuckoo.pdf
Aeternity's Technical Specification (Aeternity Dev Team, 2020): Documentation of Sophia smart contract language and FATE VM. Aeternity was created as "an open source blockchain platform aiming to be a development platform for advanced blockchain applications". The ambition was primarily to build "a better blockchain", integrating the best ideas from the blockchain industry as native features. But, just like the rest of the industry, Aeternity had not identified, much less solved, the need to have the system negotiate both regulated and unregulated realms. Gajumaru built on Aeternity as a starting point, particularly their excellent work on the Sophia smart contract language and FATE virtual machines, and added transformative features with a clear focus to enable large-scale commercial activity.\ https://github.com/aeternity/white-paper
Our Patents: Filed, pending, published or soon to be published. Licensed defensively like Red Hat. These patents protect freedom to operate for the entire ecosystem.
Our Code: Every line open source. Licensed under GPL3 in perpetuity to the Gajumaru and its users. Verifiable. Testable. Running.
The Fundamental Difference
A traditional white paper invited scrutiny: "Here is our analysis. Tell us what we've missed."
A crypto 'white paper' discourages scrutiny: "Here is our vision. Here is how we make sure that the number goes up until it doesn’t, by which time, we’ll have moved on to the next project. Give us your money and don’t ask too many questions and maybe you too can get rich quickly."
This briefing follows the original tradition. We present facts, documented, sourced, verifiable. We acknowledge limitations honestly. We do not ask you to trust us. We offer our logic, our evidence, and our working code for your scrutiny. We ask you to verify.
Introduction: The Gajumaru
You already know this system is broken. You feel it every time money moves: the fees stripped from every card transaction, the days lost waiting for international transfers, the charges levied at every point where value must cross a boundary someone else controls. You accept it because there is no alternative. There has never been an alternative.
Now consider what it means to have no access at all. For 1.3 billion adults worldwide,3 this is not frustration; it is exclusion. They cannot receive a salary, pay rent, or run a business. Not because they lack ability or ambition but rather because the infrastructure of the global economy refuses them permission to participate.
But the problem runs deeper. Correspondent banking relationships have declined by 39% since 2013,4 severing the connections between local banks and the global financial system. Billions more have accounts at institutions that are themselves increasingly disconnected from global commerce. Having an account is not the same as having access.
The $5.7 trillion SME financing gap5 exists not because capital is scarce, but because the infrastructure to move it is broken. The transaction costs, compliance overhead, and settlement friction make small-scale lending uneconomic. Small businesses in developing economies cannot access working capital. Manufacturers cannot invoice international buyers directly. The infrastructure we have was not designed to include them. It was designed to extract from those it permits to participate and exclude everyone else.
The Problem
Today's economy is not truly global. It is fractured, fragmented and disconnected. This is not a network. This is a patchwork of infrastructure, none of it natively connected, all of it controlled by someone who can charge fees that bear no relation to work done or risk taken. A model for rent-seeking control.
Consider what this means in practice.
You must use this infrastructure. There is no alternative. Try living without a bank account: you cannot receive a salary, pay rent, or run a business. Try operating a business without a payment processor: you cannot accept money from customers. Try trading internationally without correspondent banking: you cannot move value across borders. The infrastructure is not optional. It is compulsory. You are economically conscripted.
You must have permission to use it. Every piece of infrastructure has a gatekeeper. Banks decide whether to open your account. Payment processors decide whether to serve your business. Correspondent banks decide whether to clear your transfers. These gatekeepers can say no. They can say no without explanation. They can say no because you operate in an industry they dislike, because you said something they disagree with, because a government they answer to told them to, or because serving you is simply not profitable enough.
You must pay whatever they charge. The fees extracted at each chokepoint bear no relation to the cost of providing the service. Card networks charge 2-3% of transaction value: that is 2-3% of your revenue, your work, your endeavour. Correspondent banks charge fees at each hop, turning a $100 transfer into $80 received. Foreign exchange spreads extract value from every cross-border payment. These are not prices set by competition, the bedrock of the capitalist economic model. These are rents extracted by control of bottlenecks: corporatism at its most egregious.
This architecture spans the entire economy. SWIFT, a Belgian cooperative, controls international payment messaging and serves American foreign policy interests, as Russia, Iran, Venezuela and others discovered when excluded from the system. Visa and Mastercard decide who participates in card payments worldwide. Trade finance still runs on paper documents physically couriered between parties: digitising bills of lading alone — one component of trade documentation — could save an estimated $6.5 billion annually in direct costs. 6 One billion people lack official identification;7 without government-issued ID, 26%8 of the world's 1.3 billion unbanked3 people cannot even open an account.
This is the architecture of extraction. Every transaction taxed. Every participant requiring permission. Every system an island. Every bridge requiring trust in, and payment to, whoever operates it. The infrastructure exists not to facilitate economic activity but to intercept it.
What Lies Beyond
Now consider what becomes possible when these bottlenecks unlock.
The human economy is not operating at capacity. It is not even close. The economy we see is not the economy that could exist – it is the economy that survives after extraction at every chokepoint and exclusion of billions who lack permission or access.
Remove the extraction and economic activity multiplies. Card fees of 2-3% make micro-transactions unviable – nothing under $1 is worth processing. Remove the fee and an entire category of commerce becomes possible: pay-per-article journalism, micro-royalties for creators, small-value international transfers. Each transaction that becomes viable enables others. The compounding is multiplicative, not additive.
Remove the permission requirements and billions of participants enter. The 1.3 billion unbanked3 are not economically inactive – they operate in cash economies, informal networks, workarounds that function despite exclusion from official infrastructure. Connect them to global commerce and their productivity multiplies. The $5.7 trillion SME financing gap5 closes when capital can find opportunity without intermediaries blocking the path.
Remove the friction and velocity increases. Money that takes days to move moves slowly. Businesses hold larger reserves to buffer against settlement delays. Working capital sits idle waiting for payments to clear. Compress settlement from days to seconds and that capital is freed for productive use.
Fragmentation removed, entirely new structures become possible. Today's infrastructure cannot support micro-payments, streaming payments, programmable conditions, or automated settlement. Not because these are technically impossible, but because the infrastructure wasn't built for them and those who control it have no incentive to enable what would reduce their extraction. Native programmability enables business models that cannot exist on current rails.
Beyond the bottlenecks, the economy is not incrementally larger. It is exponentially larger. The infrastructure we have today is a dam holding back human economic potential. Every rent extracted is activity suppressed. Every permission denied is participation prevented. Every day of settlement delay is capital immobilised.
What happens when the dam breaks?
The Promise
Blockchain was supposed to break it.
The original vision was simple: peer-to-peer (directly between participants, with no middleman) transactions without intermediaries. Trust the message, not the messenger. A global network where value moves as freely as information, without gatekeepers extracting rent at every chokepoint.
Bitcoin proved the concept in 2009: a peer-to-peer electronic cash system requiring no trusted third party. For the first time, two strangers could transfer value across the internet without a bank, a payment processor, or any intermediary deciding whether to permit the transaction.
This was revolutionary.
This should have changed everything.
The Betrayal
It didn't.
Blockchain became 'crypto' and spent the next seventeen years and over $120 billion in venture funding1 recreating every problem it was supposed to solve. The global economy remains fractured. The intermediaries remain entrenched. The rent extraction continues. What happened?
Two things, and neither led to a resource layer. Some used the language of decentralisation to build more of what already existed: Layer 1s, enterprise chains, Layer 2s – more islands, more control points, more chokepoints dressed as liberation. The rest built 'crypto': not an attempt at blockchain, but a global, unlicensed gambling industry using decentralisation as cover. Its mechanism was to manufacture FOMO then tax it – the 'degens', as the industry calls its marks, paying entry fees for the chance to escape permanent renting, permanent exclusion. The promoters created the illusion, harvested the fees, and left enough visible winners to keep the next wave paying.
The first failed at what it claimed. The second succeeded at what it was. Neither cared whether blockchain actually worked. Which is how we arrive here.
The distinction cuts deeper than speculation versus technology. There are two categorically different things that go by the name "cryptocurrency":
Coins, minted through computational work with algorithmically fixed supply and no governance function; and
Tokens, created by smart contract, allocated by whoever deployed them, and almost always instruments of governance as much as of exchange.
Most of what the crypto industry called "cryptocurrency" was tokens – fairground chips: the issuer sets the rules, the chips work only inside the issuer's system, and the governance rights they confer accrue primarily to the team that assigned itself the largest allocation. The infrastructure built for fairground chips differs by design from infrastructure built to carry a salary. The technical failures below follow from that design choice, not from any failure of blockchain as a technology. Chapter II – the Internet of Economics – examines the distinction in full.
The proof is in the technology itself. Actual blockchains do not actually work. Bitcoin processes 3.25 transactions per second.9 Transaction fees spike to $50-100 during congestion.10 Settlement takes an hour at minimum for low-value transactions – and days or weeks for high-value transfers – with no finality endpoint at any price. Let’s convert that into real world terms: you cannot buy a coffee with Bitcoin; you cannot pay salaries. In fact, you cannot build any meaningful commercial utility at all. Worse: Bitcoin has no smart contracts (programs that execute automatically when conditions are met, like a vending machine for agreements), no way to program conditions or connect infrastructure. Bitcoin Script Interpreter, is only designed to facilitate basic checks like confirming that the person spending the money is who they say they are, checking whether a payment's waiting period has passed, and verifying that multiple people have signed off on a transaction. That is all it can do. It cannot run programs, cannot look up outside information, and cannot remember anything from one transaction to the next. It is a lock-and-key mechanism, not a computer or virtual machine.
Everything else isn't actually a blockchain. Ethereum moved to proof-of-stake (a system where those who hold the most coins control the network's decisions), where four identifiable entities have controlled as much as 62% of validation.11 Today, six entities control over 52% of validation11, and the founder publicly confirmed sole personal authority over the Ethereum Foundation's leadership in January 2025.12
Solana requires trusting validators to relay messages faithfully. Cardano, Polkadot, Avalanche and so on, each has foundations controlling token supplies and governance. The Layer 2s (add-on systems that claim to increase a blockchain's speed by processing transactions elsewhere and posting summaries back) are centralised sequencers (single operators that decide the order in which transactions are processed) posting summaries to Ethereum. The enterprise chains are private databases using blockchain vocabulary – Canton’s "Global Synchroniser" is a single company operating as a node in every network – the very intermediary blockchain was supposed to eliminate.
These systems use blockchain language but fail the only test that matters: does this allow us to trust the message, not the messenger, securely at scale?
Every one of them requires trusting operators. Every one is infrastructure – controlled and governed, often without any of the oversight that the regulated traditional financial system offers to underpin trust in infrastructure operators. The blockchain industry didn't build an alternative to the fragmented global economy. It built more fragments, more islands, more intermediaries, more chokepoints, and called them 'decentralised.' The casino needed the infrastructure. The infrastructure needed the casino. Both needed you to have no alternative.
The State of Things
This is where we are:
The existing economy: All infrastructure. Fragmented. Disconnected. Permission-gated. Rent-extracting. SWIFT, Visa, correspondent banking, cloud platforms – nothing natively connects. Everyone extracts. Monetising control, taxing value creation.
The blockchain industry: Built more infrastructure with blockchain vocabulary. Still fragmented. Still disconnected. Still requiring permission, now from foundations, validators, and sequencer operators instead of banks. Ethereum, Solana, Layer 2s, enterprise chains – all islands requiring bridges to reach the others, each bridge requiring trust in whoever operates it.
The actual blockchains: Trustless, but too slow, too expensive, and too limited to serve the real economy. They proved the principle without delivering the necessary utility.
'Crypto': Built a casino. Global, unlicensed, sustained by manufactured FOMO and enough visible winners to keep the hopeful paying. The technology was adequate for its purpose. Its purpose was never the real economy.
There is no resource layer. There is only infrastructure – controlled, fragmented, extractive – whether legacy or 'blockchain' – and an unlicensed, global casino.
The dam remains intact. Human economic potential remains trapped behind it. Control taxes creation and endeavour. Predators use the illusion of a 'new economy' to tax declining hope in the old one.
An Actual Blockchain That Actually Works, Minting Real Money that Really Works
The Gajumaru is the world's first and only digital economic resource layer.
This requires unpacking. Every word distinguishes it from everything else.
"An actual blockchain" – proof-of-work consensus (where the network is secured by computational effort rather than by trusting chosen participants) without governance capture. No foundation controlling tokens. No validators to collude. No sequencer to trust. A peer-to-peer network where no single entity can stop your transaction, reverse your payment, or freeze your assets. The same trustless architecture as Bitcoin, but one that actually works.
"That actually works" – Groot is over 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation. 300+ transactions per second on the base layer with commercial settlement in 2-3 seconds and absolute finality in 3-4 minutes. Transaction fees in thousandths of a cent. Native FATE virtual machine (the engine that executes programs on the blockchain). Sophia smart contract language designed by world-class experts and legends of programming. State channels (private, off-chain connections between two parties that settle back to the blockchain, like opening a tab at a bar) – a single commodity node handling 1,000 concurrent channels processes over 43 billion payment transactions per day, at no mandatory fee, for applications requiring machine-speed throughput. You can buy a coffee with this. You can pay salaries. You can settle international trade. Operational since 22 October 2024. Not a whitepaper, not a roadmap – working technology.
"Minting real money" – the 木Gaju has a fixed supply of one trillion coins distributed over 87.5 years, then no more, ever. No government can print more. No foundation can dilute holders. No emergency measure can expand supply. This is money as it must be to work: scarce, holdable, not subject to debasement by decree.
"That really works" – designed for commerce, not speculation. Security architecture that eliminates the attack vectors which have stolen billions from the Ethereum ecosystem. Zero external dependencies. Keys never need to touch connected devices. What you carry determines how you must carry it. The crypto casino was built to create and tax FOMO. The Gajumaru was built for the real economy: real money, real assets, real economic activity. The architecture of each betrays their objectives. Capacity informs intent.
Why "Gajumaru"?
The creation of a resource layer to which a universe of infrastructure can connect has few analogous examples. The closest are found in nature.
Gajumaru is the Japanese name for the Banyan tree, known in southern Japan as "the walking tree." This species expands continuously through aerial roots that descend from branches and take hold in the soil, becoming new trunks. What appears to be an entire forest may actually be a single organism, with many interconnected trunks growing from one root system.
The name reflects the architecture:
Groot is the single root from which all else grows, shorthand for "Gajumaru Root." The governance-free, trustless resource layer that no one controls and everyone can use.
Associate Chains are the trunks growing from this root. Each is sovereign infrastructure: its own governance, its own rules, its own operators. A nation, a stablecoin issuer, a banking consortium, a commodities consortium – each controls its own domain, none surrenders sovereignty to a third party. All connect through Groot.
Platforms are the branches that reach across trunks, intermingling where they meet. Services like GajuPay or GajuMarket operate across the resource layer and any infrastructure connected to it, not confined to a single trunk.
Applications are the foliage: the visible, living surface where people interact with the system. They grow from any branch, on any trunk, drawing from the common root.
The entire system, potentially spanning hundreds of nations and millions of applications, remains one interconnected structure with a common foundation. Value flows freely between any two points. Interoperability is native, not bolted on. No bridges to trust.
In Okinawan culture, the Gajumaru symbolises the Tree of Life: growth, strength, and adaptability. The currency symbol 木 (Ki) is the Japanese kanji for "tree," chosen because it can be typed on any standard keyboard – important for real world use.
Resource, Not Infrastructure
This distinction is fundamental.
Infrastructure is controlled. Someone operates it, decides who participates and extracts rent from its user. Every piece of economic infrastructure today – SWIFT, Visa, cloud platforms, Ethereum, Layer 2s, enterprise chains – is infrastructure. Controlled, operated, governed, extractive.
Resource has no operator. No one decides, no one extracts rent for permission. The protocol connects and executes. That is all.
The Gajumaru provides a trustless resource layer to which a universe of infrastructure can connect. National digital infrastructure, stablecoin settlement rails, banking consortiums, trade finance networks – each piece of infrastructure remains sovereign, with its own governance, its own rules, its own operators. All connecting through a common resource layer that no one controls and everyone can use.
Nothing is natively connected today. This is as true in ‘blockchain’ as in the existing financial system. Every blockchain is an island; every ‘blockchain consortium’ an archipelago with internal bridges, but disconnected from everything else.
The Gajumaru provides native interoperability through its resource layer, which functions without operators, without trust requirements, without permission, without extraction.
A simple connection protocol in Groot allows any system to register as an Associate Chain by implementing a basic transfer protocol: Gajus in, Gajus out, no more withdrawn than deposited. That is the entire requirement. The connecting system does not need to change what it is, how it works, or who runs it. It could be a public blockchain, a private banking ledger, or a legacy database with an adapter bolted on. Groot does not care what happens inside. It verifies one thing: that no one is creating Gajus – money – out of thin air. Every connected system can transact with every other connected system through the resource layer. Everything is connected by default.
This is not an incremental improvement to the infrastructure we already have. It is the missing foundation beneath all of it. The resource layer that over $120 billion in venture capital1 failed to build, that seventeen years of blockchain promises failed to deliver, and that no amount of decentralisation theatre will ever produce.
What follows explains what we built, why it matters, and what it makes possible.
Part One: First Principles
I. The Fundamental Understanding
Gajumaru Provides a Complete Global Economic Network
Gajumaru delivers the first complete trustless resource layer together with the tooling to connect any infrastructure to it. Infrastructure remains entirely composable, owned and controlled by its creators. The resource layer provides interoperability between all connected systems without requiring any to surrender sovereignty.
This is the core proposition. Everything else flows from it.
Gajumaru is unique because it provides:
Trustless, governance-free resource layer (Groot) – the foundation
Connection point protocol – enabling any system to become an Associate Chain and connect to Groot
Native interoperability via the resource layer – without requiring infrastructure to surrender control
The CHOICE between operating on the trustless resource layer directly (less efficient, no governance) or through connected infrastructure (more efficient, governed) is the point. Neither should dominate. Each disciplines the other. Genuine exit options discipline power.
Groot as The Global Interoperability Layer
Groot is not merely an 'exit mechanism' or 'alternative to controlled systems.' Groot is the interoperability layer for the universe of trusted infrastructure that connects to it.
The relationship between Groot and Associate Chains mirrors one the world already understands: HTTPS became the single protocol by which data transfers across the internet.
Similarly, there will be only one protocol by which economic instruments, money, assets, sensitive data, transfer globally. We have built that protocol as the base resource layer of the Gajumaru – Groot is the internet of economics: open, ungoverned, connecting everything. Each Associate Chain is an intranet: private, controlled, secure, connected to the global network on terms its operator chooses. Every enterprise runs an intranet. Every enterprise connects to the internet.
Nobody suggests the internet should be governed by a committee of corporations, yet that is precisely what every blockchain consortium proposes for the economic equivalent. The Gajumaru resolves this by keeping the same structural separation: the resource layer is the internet, ungoverned and open; the infrastructure built upon it is as private, controlled and governed as its operators require.
Native interoperability exists from Groot. Interconnectivity rules are set by each jurisdiction at their Associate Chain boundaries. Sovereign states decide what controls to place at their borders. Global trade flows with minimum friction at the resource layer, maximum sovereignty at the infrastructure layer.
The High Seas Analogy
Groot = The high seas, international waters where no single jurisdiction holds sway. You can operate there, less efficiently than on land, but no one governs you. Critically: the high seas connect all the ports.
Associate Chains = Territorial waters, ports, warehouses, railheads. More efficient because trust enables efficiency. Controlled, operated, governed by those who legitimately should govern them.
Why 'Associate'? The term is deliberate. Associate Chains are not subsidiaries, not subordinates, not child chains. They are sovereign peers that associate with Groot, like business associates, not employees. Each Associate Chain is fully sovereign: its own governance, its own rules, its own operators. They choose to connect through Groot for interoperability. Groot does not govern them. They govern themselves and associate for mutual benefit. The relationship is horizontal, not hierarchical.
The Archipelago Problem
Every major player is building an archipelago.
CLS. Canton. Circle's Arc. Kinexys. Tether Plasma. Each is an island chain, internally connected, but floating disconnected from everything else.
Settlement between archipelagos requires building expensive bilateral bridges. It doesn't scale. When N parties need to settle with each other:
Bilateral connections required: N(N-1)/2
Hub-and-spoke through neutral ground: N
| Parties | Bilateral Bridges | Neutral Connectivity | Complexity Reduction |
|---|---|---|---|
| 10 Institutions | 45 | 10 | 78% |
| 50 Institutions | 1,225 | 50 | 96% |
| 200 Institutions | 19,900 | 200 | 99% |
| 1,000 Institutions | 499,500 | 1,000 | 99.8% |
They're solving the wrong problem. The missing piece isn't more infrastructure.
It's the high seas that connects all the islands, archipelagoes and continents of the world. Groot is the connective high seas, the core economic resource of the Gajumaru.
The question nobody in institutional finance is asking: where is the neutral ground? Not a competitor's infrastructure that you must trust. Not a network of anonymous validators answerable to no one. Not a consortium where one company controls both the technology and the governing foundation. Genuinely neutral ground that no party controls. That is what Groot provides: the high seas that connects the world's economy.
What Is an Associate Chain?
An Associate Chain is any system that implements the connection point transfer protocol. It does not even have to be a blockchain. It could be a public blockchain, a public permissioned blockchain run by trusted operators, a private permissioned blockchain, or something that just acts like a chain in the interface but is really a legacy banking system with a clever adapter on it. An associate chain takes whatever form that fits the purpose its creator has for it: an Associate Chain is entirely configurable, it must simply implement the connection protocol to Groot.
| Requirement | Description |
|---|---|
| Connection point protocol | Implement the simple transfer protocol for funds and resources |
| Operator accounts | Identify a list of accounts as operators of the Associate Chain |
| Border Control and/or Governance Rules | Anything going in or out must be signed by operators or in accordance with programmatic rules |
| No money creation | Cannot withdraw more Gajus than were deposited |
An Associate Chain may, therefore:
Be public or private
Use any blockchain platform or consensus mechanism
Use a non-blockchain system (SQL database, legacy banking system with adapter)
Implement its own native currency (while using Gaju for interoperability)
Have its own subordinate Associate Chains registered to it
⠀What the connection point provides:
Permissionless anchoring to Groot (anyone can create a connection point)
Value transfer across connection boundaries
Recursive hierarchical structure (Associate Chains can have their own Associate Chains)
Clean separation between regulated space (Associate Chain) and unregulated space (Groot)
Why this design?
The connection is deliberately simple. Groot does not need to know anything about what happens inside an Associate Chain. The regulatory compliance responsibility lies entirely with the Associate Chain operators. This makes adoption straightforward: no complex mathematical proofs required, no technical requirements beyond the simple transfer protocol. The relationship is association, not subordination. Groot verifies only one thing: that an Associate Chain cannot create Gajus out of thin air. The amount withdrawn can never exceed the amount deposited.
This is not a rule that participants are required to follow. It is not a contractual obligation, a governance decision, or a regulatory requirement. It is a codified constraint – the foundational condition of how Groot connects with and interacts with every Associate Chain. The protocol enforces it absolutely, without exception and without override. No AC operator, however capable or motivated, can circumvent it: the code will not permit the transaction. The architecture does not defend against this attack surface. It eliminates it.
The distinction matters for anyone who has watched rules in blockchain systems governed, voted, or pressured away. This one cannot be. It is the floor on which everything else stands.
Transparency on Groot, Privacy within Associate Chains.
Groot is a proof-of-work blockchain. Like Bitcoin, its ledger is public. Every transaction between Associate Chains is visible: which connection points moved value, how much, when. Deliberately and necessarily so: an open economic resource requires open accountability. We want ships on the high seas connecting the global economy; we do not want unmarked tankers moving sanctioned cargo in the dark. Visibility is the feature.
Within an Associate Chain, the picture is entirely different. The operators who created it set the rules: who can participate, what is visible, what is private, what laws apply. A national Associate Chain might implement full KYC and transaction monitoring under its domestic regulations. A banking consortium might keep internal operations completely private, exposing only its external settlements to the wider network. A trade finance chain might share document hashes publicly whilst keeping commercial terms confidential. The choice belongs entirely to the operators, because the responsibility belongs entirely to them.
This creates the duality that disciplines both paths. On Groot, transparency is absolute: anyone can audit the flows, identify patterns, raise questions. Within Associate Chains, operators have complete freedom to implement whatever privacy, compliance and governance their purpose requires, but they also bear the accountability for what they build. Freedom and responsibility are inseparable. The existence of both, transparent resource layer and configurable infrastructure, ensures that neither opacity nor surveillance can dominate unchecked.
Master Chain / Sub-Chain Hierarchy
Associate Chains can themselves have sub-chains, forming a tree structure that mirrors the complexity of real-world economic relationships.
A sub-chain connects to its parent Associate Chain, not directly to Groot. The relationship is hierarchical: the parent sets the boundary conditions, the sub-chain operates within them. The same sovereignty principle applies at every level: each operator controls its own domain. Sub-chains can have their own sub-chains. The tree grows as deep as the use case demands. A global stablecoin operator, a banking consortium, a sovereign nation: each requires a different hierarchy, but the structural principle is the same. The parent governs its children; Groot governs nobody.
Case Study Example: A Global Stablecoin Associate Chain
Consider a stablecoin (a digital currency designed to maintain a stable value, typically pegged to a traditional currency like the US dollar) operator, like Tether or Circle, creating a global Associate Chain.
The operator creates a Global Associate Chain, a USD Master Chain that sets overall rules in much the same way that SWIFT does today. Beneath it, national sub-chains comply with local laws and regulations in each jurisdiction: US, EU, Singapore, and so on. Beneath those, industry sub-chains touch into multiple national chains where business operates across borders.
This enables complex business hierarchies to be reflected directly in the chain structure. Overlapping interests are accommodated; the structure is flexible, not rigid. A single enterprise operating across multiple jurisdictions connects to the national sub-chains relevant to its business. A regulator sees only what falls within its jurisdiction. The global operator maintains oversight of the whole. All of it, every layer, ultimately connects to the wider Gajumaru through its Master Chain's connection to Groot.
Case Study Example: The Banking Consortium Problem
The stablecoin example illustrates how the hierarchy organises geographically. A more revealing example is what happens when the participants in a Master Chain do not fully trust each other.
Global Layer 1 is an initiative led by the Monetary Authority of Singapore, with participants including Standard Chartered, Citi, JPMorgan, MUFG, BNY, Societe Generale-FORGE, and Euroclear. The consortium seeks to establish shared ledger infrastructure for interoperable cross-border settlement. The ambition is right. The diagnosis is right. The problem they face is governance.
Each institution needs privacy: no participant wants competitors seeing its internal operations. Each operates under different national regulators, so sovereignty cannot be surrendered to a consortium. The entire purpose is cross-border connectivity, so isolation defeats the objective. Previous attempts at this, including R3's Corda and the Regulated Liability Network, failed because the governance question proved unanswerable. Who controls the consortium? Whoever controls the consortium controls the financial intranet they are building, and they know it. As our technical team observed when reviewing the GL1 whitepaper: that prize will make the negotiations difficult, to say the least.
The Gajumaru's Associate Chain hierarchy resolves this structurally.
The consortium operates a Master Associate Chain. This is their GL1: it sets the shared standards, the membership criteria, the interoperability protocols. It can be private from an external perspective, with a configurable degree of internal visibility, from fully permissioned to selectively public, as the consortium agrees. The consortium governs it. The consortium sets the rules. No external party has authority over it.
Each member institution operates a sub-chain within that Master Chain. A bank's internal operations, its proprietary trading, its client accounts, its risk positions, remain private to that institution. Only its external settlements within the consortium are visible to other Master Chain participants. The bank controls its own sub-chain entirely: its own rules, its own compliance, its own regulator's requirements. Internally, it could be running a standard SQL database with an adapter to the consortium chain. It does not matter. It must simply implement the connection protocol.
The Master Chain connects to Groot. The consortium's external settlements, its interactions with other consortiums, with sovereign Associate Chains, with stablecoin networks, flow through the governance-free resource layer. No bilateral integration. No bridges. No dependence on any single institution's infrastructure. The governance problem that killed previous consortiums disappears at the foundation layer because there is nothing to govern. Groot has no membership criteria, no committee deciding who may participate, no benevolent consortium to trust. It is the neutral ground between all participants.
This tree structure scales without technical limitations. It is entirely configurable by the master chain operator and the sub-chain operators relative to their sub-chains. Control stays where responsibility sits. A stablecoin operator creates a global Master Chain with national sub-chains complying with local regulations. A banking consortium creates a Master Chain with sub-chains for individual institutions. A sovereign nation creates a Master Chain as its national blockchain infrastructure with sub-chains for government departments, regulated industries, and municipal services. Each controls its own domain. All connect through Groot.
The RIPA Model
Everything described so far – Groot, Associate Chains, the tree hierarchy, the internet/intranet relationship – follows a single structural pattern. We call it RIPA: Resource, Infrastructure, Platform, Application.
| Characteristic | Resource (Groot) | Infrastructure (Associate Chains) |
|---|---|---|
| Governance | None | Yes – by design |
| Operator | None | Yes – entity or consortium |
| Rules | Algorithmic consensus only | Customised to jurisdiction/purpose |
| Efficiency | Lower (trustless has costs) | Higher (trust enables efficiency) |
| Control | No one can say no | Operators can say no |
| Accountability | Not required: there is no compromise of trustlessness for efficiency (‘TEA’), so no accountability requirement | Essential: where you compromise trustlessness for efficiency, whoever can say ‘no’ must be accountable (‘TEA’) |
| Analogy | High seas, outer space, HTTPS – internet of economics | Coastal waters, ports, railheads, intranet |
The model resolves what appears to be an impossible contradiction: trustless yet efficient, ungoverned yet accountable. Rather than compromise between these requirements in a single system, the Gajumaru partitions them across layers where each ceases to be contradictory at all. Trustlessness belongs at the resource layer. Efficiency and accountability belong at the infrastructure layer. Neither is asked to do the other's job. Four distinct layers, each doing one thing well, traversable in more than one way.
The Two Paths, One System
Path 1: RPA – Resource, Platform, Application
Skip infrastructure entirely. Operate directly on the trustless resource layer: Resource, Platform, Application. No governance, no operator, no one can say no.
The strengths are genuine. Permission is not required, so exclusion is not possible. No operator exists to freeze assets, reverse transactions, or change rules after commitment. Extraction at the infrastructure level does not occur because the infrastructure layer is absent. Available to anyone, anywhere, at any time: it operates continuously, without institutional hours, without holidays, without the discretion of a compliance officer who may or may not process your transaction on a Friday afternoon.
The scale of need is larger than most people realise. 1.3 billion adults have no financial account at all.13 But the problem runs deeper. Correspondent banking relationships between global and local banks have declined by 39% since 2013,14 as global institutions de-risk by severing ties with banks in emerging markets. The result is layered exclusion: billions have bank accounts at institutions that are themselves increasingly disconnected from the global financial system. Having an account in Lagos or Dhaka is not the same as having an account in Zurich or London. The account exists; meaningful access to the global economy through it is diminishing. For the majority of humanity, the current financial system offers either no access or degraded access. Groot offers both: access without permission, and connectivity without intermediation.
The costs are real and should be stated plainly. Even the most efficient proof-of-work blockchain – and Groot is over 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation – is grossly inefficient next to trusted infrastructure. That is the price of trustlessness: genuine effort is computationally expensive by design, and that cost is borne by the user. There is no consumer protection: no one to complain to, no dispute resolution, no deposit insurance. If you send to the wrong address or lose your keys, no operator can reverse the transaction because no operator exists.
The other cost is transparency. Groot is a public ledger. Every transaction is visible. You can use the high seas, just as you can sail them, but you do so in full view of every other vessel on the water. There are no hidden cargoes. There are no unmarked tankers. For legitimate participants, this transparency is the price of freedom. For those who would use the open sea to evade the rules of every port, it is not a refuge but an exposure: their activity is visible to the entire network. The high seas hide nothing.
This transparency also means that Groot itself carries no regulatory compliance burden. It is a pathway for value between infrastructures, each of which has its own operators, controllers, and accountability. Regulatory compliance sits at the Associate Chain boundaries, not on the resource layer. In the same way that TCP/IP does not regulate content and regulation happens at the service layer, Groot does not regulate transactions and regulation happens at the infrastructure layer. Value passing through Groot between two regulated Associate Chains is subject to the rules of both; Groot itself imposes none.
One further cost deserves honesty. Operating directly on Groot, without infrastructure, is like sailing the high seas alone in a dinghy. It can be done. The physics permits it. But it is unforgiving, demanding, and not for everyone. The laws that govern you there are the laws of physics, not of man: cryptographic proof, computational work, mathematical certainty. For those with the skill and the need, it is freedom. For most, it is a last resort, and that is exactly what it should be. The exit does not need to be comfortable. It needs to genuinely exist.
QPQ's platforms and applications are designed to operate across the entire RIPA stack, not solely on one layer. GajuPay, GajuMarket, and other QPQ IaaS AG services work on Groot and on any Associate Chain to which they are invited or permissioned. GajuDesk, a desktop operational toolset that encompasses wallet functionality but extends to writing, testing, and examining smart contracts, operates directly on Groot. GajuMobile provides similar access from a mobile device. Both will be open sourced under GPL3, so they can be utilised or adapted for their purposes by every Associate Chain in the network. The products and services are covered in detail in Part Three; what matters here is the principle: the trustless path is not a barren wilderness. It is a functioning economic space with real platforms and real tools.
Path 2: RIPA – Resource, Infrastructure, Platform, Application
Use infrastructure. Operate through governed Associate Chains built on Groot: Resource, Infrastructure, Platform, Application. Accept governance in exchange for lower cost, faster settlement, and the protections that come with regulated environments. This is the model that unites the world's infrastructure into a global economy, each piece sovereign, all connected through the resource layer.
The strengths are the strengths of all governed systems, amplified by one thing no governed system has ever had before: a structural guarantee that governance cannot become monopoly.
An Associate Chain operated by a regulated institution under clear legal jurisdiction, with identifiable operators, dispute resolution, consumer protections, deposit guarantees, and recourse against known parties, is the right environment for the vast majority of economic activity. Mainstream adoption becomes frictionless because the experience is familiar: the user interacts with institutions they know, under laws they understand, with protections they expect. Banks, securities firms, insurers, and regulated entities can operate here lawfully, because regulatory compliance is built into the infrastructure at the Associate Chain level, designed and operated by those who bear the responsibility for it.
The critical difference is what sits beneath. Every governed system in existence today operates in isolation or connects through infrastructure controlled by another party. The governed infrastructure works, until the entity governing it decides it does not work for you. The infrastructure is efficient, until the party controlling it becomes extractive.
An Associate Chain connected to Groot changes the equation. The infrastructure remains governed, controlled, operated by identifiable parties under applicable law. Nothing about connecting to Groot changes the internal governance of the Associate Chain. What changes is the consequence of that governance becoming abusive. The participants have somewhere to go. The exit is real, it is permanent, and the infrastructure operator knows it exists. This disciplines pricing, because fees that bear no relation to value added will drive participants toward the trustless path. It disciplines access, because excluding participants without justification pushes them to a network that cannot exclude anyone. It disciplines behaviour, because the operator who acts arbitrarily does so knowing that the alternative is not theoretical.
The costs are the costs of all governed systems, and should not be understated simply because infrastructure is the more efficient path. Operators can say no. Permission can be withheld, revoked, or made conditional. Governance can be captured: the interests that concentrate around any controlled system will seek to shape its rules for their own benefit, and the history of financial infrastructure demonstrates how reliably this occurs. Part Four examines these dynamics in detail. Operators can freeze assets, exclude participants, and reverse transactions, whether by their own choice, under commercial pressure, or at the direction of governments whose interests may not align with those of the participants. Different jurisdictions impose different rules, creating friction at boundaries between Associate Chains even where both are connected to the same resource layer.
The honest assessment is this: an Associate Chain operated by an extractive consortium is still an extractive consortium. Connecting to Groot does not make bad governance good. What it does is make bad governance consequential. The participants who would previously have had no choice but to accept extraction now have a choice, and the operator who ignores that choice will watch their participants leave. Not necessarily to a competitor's infrastructure, where the same dynamics may recur, but perhaps to a resource layer where no one can say no at all. Their choice.
For the vast majority of everyday economic activity, RIPA is the better path. It is faster, cheaper, more familiar, better protected, and more efficient. It should be the default for anyone operating in a jurisdiction with fair governance and accessible infrastructure. The question is not whether to use it. The question is whether the alternative exists for the day it stops being fair.
One further point on the RIPA path that is too often left unstated. When you trade trustlessness for efficiency, you take on an obligation. On Groot, there is no one to hold accountable because there is no one in charge; the protocol is the authority. On an Associate Chain, operators hold power: they can say no, freeze assets, set rules, exclude participants. That power requires accountability to match it. This is the TEA trilemma – Trustlessness, Efficiency, Accountability – and it exposes the failure mode of most "governed" blockchain infrastructure: anonymous proof-of-stake. A consortium of validators nobody can identify is not a governed system. It is a system with the costs of governance and none of its protections. The participants bear the risks of centralised decision-making; the operators escape the accountability that should accompany it. Accountability requires identifiable operators: known parties, legal jurisdiction, recourse when something goes wrong. The governance mechanism of an Associate Chain matters as much as the fact of governance itself.
The layered architecture of RIPA is not a proprietary insight. Every careful analyst of Bitcoin's limitations eventually re-derives it: a resource layer for trustless settlement; infrastructure layers above it for velocity, privacy, and governance. Those who defend Bitcoin against the fungibility objection invoke precisely this structure – base layer for auditability, upper layers for privacy – without knowing the upper layers they propose must pass the TEA test to function as claimed.
The architecture is derivable from the problems. RIPA makes explicit what the problems demand: two distinct types of layer, each occupying a specific corner of the TEA triangle, each doing what it is designed for and not substituting for the other. The resource layer is trustless because trustlessness requires it. The infrastructure layer is governed because efficiency requires trust. Neither compromises the other because they are structurally separate.
What previous analysts got right was the shape. What they missed was the requirement: upper layers must be accountable, not merely faster because they traded trustlessness for efficiency and that must balance with accountability. A pseudonymous routing network that cannot be regulated, held liable, or removed is not an accountable infrastructure layer. It is a messenger wearing a different name. The blockchain test still fails.
Why Both Paths Must Exist
Neither path should dominate.
If only RPA exists, everything is trustless but inefficient. The cost of operating without governance suppresses economic activity. The freedom is real, but the friction prices most people out of using it.
If only RIPA exists, everything is efficient but controlled. The infrastructure works, but there is no exit from extraction. The efficiency is real, but the freedom is gone.
The question for any participant is not which path is better. It is which path serves their circumstances, and whether the alternative exists if those circumstances change.
A business operating in a well-regulated jurisdiction with fair infrastructure has every reason to choose RIPA. The efficiency gains are real, the protections are valuable, the cost savings are material. That business does not need trustlessness. It needs trust that works.
The same business, the day its government freezes accounts for political reasons, or its payment processor debanks its industry, or its jurisdiction imposes capital controls, needs trustlessness immediately. The question is not whether that day will come. The question is whether the exit exists when it does.
The existence of RPA disciplines RIPA. Infrastructure operators who know their participants can leave have a structural incentive to remain fair, transparent, and reasonably priced. The exit does not need to be used. It needs to genuinely exist, and to actually work. Its existence changes the behaviour of every governed system connected to the same resource layer.
The existence of RIPA disciplines RPA. If the trustless path is the only option, its costs and limitations become inescapable rather than chosen. The availability of efficient, governed alternatives ensures that trustlessness remains a choice rather than a sentence.
This is economic emancipation. Not by making everything trustless, but by making trustlessness available as a genuine exit that disciplines controlled systems. It needs to genuinely exist and it needs to actually work.
What This Makes Possible
The two paths do not merely coexist. They create something neither could produce alone.
Most people are not ready, willing, or able to be entirely responsible for their own economic operations and sensitive data. Nor should they need to be. The existence of an open, trustless resource layer does not mean everyone must sail the high seas alone. It means that trusted institutions can offer something they have never been able to offer before: unified access to the entire global economic network, from the open resource layer to regulated infrastructure across multiple jurisdictions, through a single trusted relationship.
Consider what this looks like in practice. A bank operating in the Gajumaru is not confined to a single Associate Chain, nor confined to governed infrastructure at all. It can offer its clients a wallet that operates on Groot as default: open, trustless, global. Through the same relationship, the client accesses the bank's regulated domestic infrastructure for local financial services. Through the same relationship, they access the bank's services in other jurisdictions where they are appropriately permissioned. Through the same relationship still, they access third-party infrastructure – a global stablecoin Associate Chain, a trade finance consortium, a commodities settlement network – wherever the client meets the access requirements, sleeved within the bank's service layer. One institution, one relationship, access to every layer of the global economic network.
The bank is no longer a gatekeeper controlling a bottleneck. It is a full-service shipping line: sailing you on the open ocean when that is what you need, berthing you in any port where it has standing, arranging passage on other lines where its relationships grant access, handling the customs, the documentation, the insurance, the compliance – all under its flag. The fee for that service is no longer rent extracted from a captive participant. It is a price paid by a willing customer who could, if they chose, sail alone, but would rather book passage with an institution that knows every port, every regulation, and every route, and bears the liability if something goes wrong. That distinction transforms the relationship between financial institutions and the people they serve: from dependency to genuine service.
This extends beyond any single industry. When a governance-free resource layer exists beneath all infrastructure, the incentive structure of the entire economy inverts. Controlling a bottleneck becomes less profitable because participants can route around it. Adding value becomes more profitable because participants choose to pay for genuine service. The institution that navigates complexity across jurisdictions and infrastructure types on behalf of clients who would rather not do it themselves captures value by earning it rather than by extracting it.
This is the trajectory that the internet itself followed. Before the internet, value in telecommunications accrued to those who controlled the physical infrastructure: the cables, the switches, the last mile. The common protocol layer collapsed the value of controlling bottlenecks and redistributed it to those who built services on top. The telecommunications companies that adapted, that became service providers rather than infrastructure gatekeepers, survived and thrived. Those that clung to the old model were displaced.
The Gajumaru creates the same structural shift for economic infrastructure. The institutions best positioned to thrive are, ironically, the very institutions that today profit from the system the Gajumaru changes. They have the expertise, the regulatory standing, the client relationships, and the institutional knowledge. What they lack is the connective tissue that lets them deploy those assets globally without surrendering sovereignty to a competitor's platform or a consortium they do not control. The resource layer provides that connective tissue.
The question for institutional finance is not whether this transition will happen. The internet of data already demonstrated the pattern. The question is who will navigate it best, and who will be left clinging to toll bridges that no longer lead anywhere.
II. The Internet of Economics
Why Intermediaries Exist
Most economic infrastructure exists because we needed trusted messengers.
SWIFT exists because banks could not trust each other's messages directly. Card networks exist because merchants could not verify payments directly. Custodians attest to ownership because the current financial architecture provides no other way to prove it. Clearinghouses net obligations and guarantee settlement because counterparties cannot settle in full at the point of exchange. Credit bureaus aggregate creditworthiness data because lenders can not verify it directly.
Each arose to bridge a trust gap: the inability to verify economic messages without a trusted third party. The services they provide, credit guarantees, netting, fraud detection, dispute resolution, exist because the underlying architecture requires them. A card network guarantees the merchant gets paid because the architecture cannot prove payment cryptographically. A clearinghouse nets obligations because the architecture cannot settle them atomically. A custodian processes corporate actions because the architecture cannot execute them automatically. Remove the trust gap and the services that exist to bridge it become unnecessary. A merchant needs no credit guarantee when payment is proven at the point of sale. Counterparties do not need netting when settlement is instant and atomic. Corporate actions do not need manual processing when smart contracts execute automatically upon the conditions being met.
This is the starting point. The global economy runs on trusted messengers, each extracting a fee for their position, each controlling a chokepoint that cannot be bypassed. The Introduction set out what that architecture costs: the fees, the exclusion, the friction, the extraction. This chapter addresses a different question. Not what the system costs, but what replaces it: not better messengers, but the elimination of the need for messengers at all.
The core test: Does this allow us to trust the message rather than the messenger, securely at scale? If yes, the intermediary becomes unnecessary. The rent they captured is released back into the economy.
Crypto and Blockchain: Two Different Industries
The Introduction established the distinction between coins and tokens. What follows from it is more than a definitional point. It explains the structure of an industry, the rationality of decisions that otherwise appear negligent, and why seventeen years of blockchain investment produced neither a resource layer nor a genuine cryptocurrency.
Tokens are fairground chips, and the people who created them are the fairground. The moment you exchange your fiat money for chips, the risk in the token transfers entirely to you – they are free, and your money is theirs.
What they care about is volume, because volume converts their marketing effort into a scaled – and very profitable – exit. The much-celebrated 'community' that assembles around a token is celebrated not because of the adoption it might indicate, but because it represents the successful assembly of bag holders for the exit. Crypto 'venture capital' supercharges the entry, the hype cycle manages the ascent, and, if they really do a good job of creating a veneer of acceptability, the ETF industrialises the exit – packaging the risk into instruments that transfer it from early holders to retail and institutional investors at scale, with a fee extracted at every stage.
Every transaction flowing through the system – buy, sell, win, lose – generates revenue for the exchanges, the project insiders, the foundations, and the infrastructure operators who positioned themselves as the conduit for the wealth transfer and took a toll on every flow through them, in both directions. The mechanism requires visible winners: enough people must be seen to profit spectacularly that the next wave of entrants pays the entry price. The promoters created the illusion, harvested the fees, and moved on. The 'degens', as the industry calls its participants, held their betting slips and hoped.
The security architecture of this system is, by its own logic, perfectly rational. You do not build a vault for a fairground chip. Nobody installs institution-grade custody for a lottery ticket, because a lottery ticket is a probabilistic position in a game, not a possession. The global financial system spends approximately $600-650 billion annually on technology, the majority of it on security, compliance, and the integrity of systems carrying real value.15 Banks deploy hardware security modules, air-gapped key management, multi-party authorisation, and years of regulatory audit to protect assets that matter. They do this because the assets matter.
When MetaMask, the dominant wallet in the Ethereum ecosystem, runs on 212,620 packages from anonymous contributors worldwide16 – secured by a JavaScript sandbox written in JavaScript, running inside the same vulnerable environment it is attempting to protect – this is not negligent engineering by comparison. It is a rational choice about what the system is carrying. For the purpose it serves, it is adequate. The inadequacy surfaces only when you ask it to protect something it was never designed to protect: real value. The NPM supply chain attack of September 2025, in which packages with over two billion combined weekly downloads were compromised,1718 demonstrated the consequence. The industry's response was to carry on. You do not rebuild your security architecture to protect fairground chips.
This explains why over $120 billion of investment1 produced what we see now: decentralisation theatre dressed as infrastructure, and fairgrounds dressed as financial systems. For that purpose, the technology worked. Tokens changed hands. Exchanges extracted fees at every turn. Insiders sold into the demand they had manufactured. The architecture served its actual purpose. Its failure to carry real salaries, real trade settlements, real assets – to trust the message rather than the messenger, securely at scale – was not a design flaw. It was a design specification.
The Layer 1s and Layer 2s that claimed to be building the future of finance built, at best, plumbing adequate for moving chips between wallets. Their tooling betrays their intent – security architecture, throughput limitations, dependency chains – all of it calibrated for the volume of a gambling platform, not the integrity requirements of an economy. Capacity informs intent. Neither category was trying to build financial infrastructure. One failed at the pretence. The other never pretended.
The conflation of crypto with blockchain was not accidental. Every exchange collapse reported as a "blockchain failure," every token fraud attributed to the technology rather than to the intermediaries who actually failed – the vocabulary was captured so thoroughly that the actual technology bore the reputational cost of the casino built in its name. Part Four documents how that happened, who funded it, and what it cost.
What follows in this chapter is concerned with the real economy: where the stakes are real, the counterparties are not playing a game, and trust gaps have genuine commercial and human consequences. The fairground has no trust gap to close. It depends on one. What blockchain was always supposed to do – and what the Gajumaru does – is a different project entirely.
Digitisation vs Digitalisation
These words sound similar. They describe fundamentally different things, and understanding the difference is essential to understanding what the Gajumaru makes possible for the first time.
Digitisation makes the inefficient incrementally more efficient. The same intermediaries, the same control points, the same rent extraction, just faster. Paper ledgers become electronic databases. Fax confirmations become email confirmations. The messenger wears different clothes, but you still need the messenger.
Digitalisation removes the inefficiency altogether. Not making the intermediary faster. Eliminating the need for the intermediary entirely.
The difference matters because most of what passes for 'digital transformation' is digitisation. Banks moved from paper to screens. That was a genuine transformation: the leap from physical ledgers to electronic databases was enormous, and the efficiency gains were real. But the gains since have been smaller with each step, because each step is smaller. The move from paper to mainframe changed what was possible. The move from one middleware layer to the next changes only how fast the same thing happens.
The pattern resembles the history of powered flight. The first powered flight was 1903. Within four decades, aircraft went from 30 mph to 500 mph: enormous, real, proportional gains. Each advance in engine power and aerodynamic understanding produced a corresponding advance in speed and capability. But as aircraft approached the speed of sound, the returns inverted. Transonic drag rises sharply; the air itself resists differently. Each additional increment of speed required disproportionately more power for diminishing practical gain. Many feared the sound barrier was impassable; several pilots died attempting to breach it, and the engineering challenges were real enough that serious doubt existed about whether any aircraft could survive the transition.19
That is where digitisation sits today. The early gains were transformative. The recent gains cost more than they deliver. The core networks, processes for managing money and assets still run on accumulated legacy infrastructure; each new layer of digitisation is another attempt to push a propeller aircraft past Mach 1. More power, more complexity, more cost, and the infrastructure itself resists.
A Different Machine
Breaking the sound barrier required a fundamentally different aircraft. Not a faster propeller plane. A different machine: different engine, different aerodynamics, different design principles. Chuck Yeager broke through in 1947 in the Bell X-1, and on the other side, the rules changed. Supersonic flight operates in a different regime entirely. Speeds that were impossible in the old regime became routine in the new one.
Digitalisation is that breakthrough. Not a faster version of what came before, but a different regime with different rules. Not incremental improvement to controlled infrastructure but the creation of a trustless foundation beneath it that evaporates the need for the middleware, the bridges, the conversion layers, the bilateral integrations, and the layers of intermediaries whose sole function is to make systems that were never designed to talk to each other appear as though they can.
For decades, digitalisation was not an option. The technology to trust the message rather than the messenger, securely at scale, did not exist. Thomas Newcomen's atmospheric engine, demonstrated in 1712, proved that steam could do mechanical work. It was real, it operated, it moved things. It was also so inefficient it could only function at collieries where waste coal was free. James Watt's separate condenser, fifty-seven years later, made steam power actually deployable – and changed the world. Newcomen proved the destination. Watt reached it.
Bitcoin proved the concept in 2009 but not the utility: too slow for commerce, too limited for programmability, too isolated to connect to anything. Everything that followed, as the Introduction set out, built more infrastructure rather than a resource layer. Digitisation was the only path available, and institutions followed it rationally.
The Gajumaru changed this. Not by proving that trustless verification is possible; Bitcoin did that seventeen years ago. By making it work: a trustless resource layer fast enough for commerce, programmable enough for smart contracts, and connective enough that any governed system can join it natively, without bridges, without bilateral agreements, without surrendering sovereignty to a third party. Every governed system that connects to Groot can transact with every other, directly, without intermediation. Not trustlessness for its own sake, but trustless connectivity: the common ground upon which the digital economy can finally be built.
What follows from that single architectural change transforms everything: how people transact, how machines transact, how nations connect their economies, and what becomes possible when the boundaries between them dissolve. The choice facing every institution that depends on economic infrastructure is now binary: continue digitising and manage decline, or grasp digitalisation and leave the accumulated weight behind. There is no third option, because the foundations they are standing on were never designed to bear the weight they now carry.
The Accumulated Cost of Digitisation
Digitisation produced real gains. The move from paper to electronic processing transformed banking. Real-time payments operate in dozens of countries. Mobile banking works. Fraud detection runs in milliseconds. These are genuine achievements, and dismissing them would be dishonest.
The problem is both what they cost to maintain and what they will never be capable of delivering. The accumulated infrastructure consumes the majority of one of the largest technology budgets on earth simply to keep functioning. But even if maintenance were free, the architecture would still be incapable of eliminating the intermediaries it was built to serve, settling across boundaries without trusted bridges, or operating at the speed and scale the machine economy demands. The cost is real. The ceiling is worse.
Each wave of digitisation addressed the symptoms of the last without touching the underlying cause. Ever more costly, less impactful increments of digitisation. Mainframes gave way to client-server architectures. Client-server gave way to web services. Web services gave way to cloud migration. Whether individual systems were replaced, rewritten, wrapped, or simply migrated, the result was the same: every iteration added integrations, dependencies, and middleware to an ever-growing topology of interconnection. Sixty years of changes, each solving an immediate problem, each adding to the cumulative weight of what must now be maintained, reconciled, and kept running together. The result is not infrastructure. It is archaeology: a Frankenstinian creation animated by vast expenditure of energy from a compendium of dead and living things intertwined beyond any single person's comprehension.
Blaming the banks is not entirely fair. They have twenty to sixty years of legacy software and systems to manage and navigate, with layered digital protocols and systems that require middleware to operate.20 The problem is structural, not managerial. The infrastructure was never designed as a whole. It was accumulated, one iteration at a time, each solving the immediate problem whilst creating the foundations of the next.
The scale of the burden tells the story. Banks globally spend approximately $600-650 billion per year on technology, more than any other industry as a proportion of revenue.15 The majority of that spend goes to maintaining existing operations rather than building new capability. McKinsey's own analysis is blunt: despite this investment, productivity remains low.21 The accumulated topology grows more complex with each iteration: the average number of applications per billion dollars in revenue rose from 133 in 2013 to 224 in 2022, whilst application vendors rose from 131 to 209.15 Legacy payment systems alone are projected to absorb $57.1 billion annually by 2028.22 The industry spends more each year to stand still.
Here is where institutions must confront an uncomfortable truth. For decades, banks have treated their IT infrastructure as an asset: the systems that allow them to deliver their services, the platforms that hold their competitive advantage. In the context of a digital economy, this thinking inverts. The accumulated infrastructure is not their asset. It is their liability. The question is no longer what value they can extract from the systems they control, but what value they can add to a common foundation. Without embracing digitalisation, they will be left with nothing but decline.
In Roland Joffé's 1986 film The Mission, Robert De Niro's character, the conquistador Mendoza, drags a net full of armour and weapons up a waterfall as penance for his past. The weight nearly kills him. He is stuck on the cliff face, the burden pulling him backward toward the edge. It is the Guaraní, the very people he had enslaved, who cut the ropes. An act of forgiveness that is also an act of salvation. Freed from the weight of his past, he can climb.23
The analogy is imperfect but instructive. Banks cannot cut their own ropes. They are too invested in what they built, too deep in the sunk cost, too committed to the narrative that the accumulated systems are assets. The release comes from outside: an architecture that makes the legacy weight unnecessary. A common resource layer to which all infrastructure can connect, eliminating the middleware, the bilateral bridges, the accumulated complexity that $600 billion a year struggles to maintain. The question is whether institutions accept the cut or cling to the rope. They have the means, the necessity and now with the Gajumaru, the opportunity to do so.
The FinTech Illusion
FinTechs emerged to solve the problems that decades of digitisation created. They have not solved them. They have created an illusion of efficiency at the user layer whilst the same creaking infrastructure operates beneath.
A neobank offers a clean mobile interface, instant notifications, and slick currency conversion. For most neobanks, the same correspondent banking chains process the same SWIFT messages through the same intermediaries with the same settlement delays beneath that interface. The user experience improved. The infrastructure did not. The intermediaries remain. The extraction continues. The neobank itself becomes another intermediary, adding its margin to the stack.
The most successful FinTech in cross-border payments illustrates the point precisely. Wise (formerly TransferWise) raised over $1 billion in venture capital, secured over 65 regulatory licences across dozens of jurisdictions, built direct connections to domestic payment systems in country after country, and dedicates one-third of its 6,500-strong workforce to compliance and financial crime prevention.24 The result, after fourteen years and all that investment: Wise has reduced the cost of international transfers to an average of 0.62% and made 63% of payments instant. A genuine achievement, hard-won. But consider what it took: over a billion dollars, thousands of staff, and bilateral integration with each country's payment rails, one at a time, to partially bypass the correspondent banking system that a trustless resource layer eliminates architecturally. Wise spent fourteen years and a billion dollars building a better bridge. The Gajumaru removes the need for the bridge.
Payment processors offer merchants faster onboarding and simpler integration. Beneath the API, the same card networks charge the same 2-3% of every transaction, the same acquirers and issuers take their share, and the same fraud infrastructure operates because the architecture still requires transmitting sensitive credentials with every purchase. The checkout experience improved. The cost structure did not.
This is digitisation dressed as innovation. FinTechs are applications built on foundations that cannot support what they promise. They make the surface smoother whilst the foundations fracture beneath the weight of accumulated complexity. They are, in the language of the Introduction, more archipelagos: more islands, more intermediaries, more control points, more bridges that require trust in whoever operates them.
The banking industry and their enterprise clients are crying out for institutional grade infrastructure that offers genuine interoperability, throughput, and cost reductions.25 FinTechs have not provided this. They cannot, because the problem is not at the application layer. The problem is beneath it.
The Categorical Elimination
Digitalisation is not a better version of digitisation. It is a different category of change. Where cryptographic verification replaces institutional trust, entire categories of intermediary do not become faster. They cease to exist.
| Intermediary | Why It Exists Today | What Replaces It |
|---|---|---|
| Payment networks | Verify that payment occurred and guarantee the merchant gets paid | Cryptographic proof of payment; atomic settlement eliminates credit risk |
| Custodians | Attest to ownership and process lifecycle events for financial assets | Cryptographic proof of ownership; smart contracts execute corporate actions automatically |
| Clearinghouses | Net obligations and ensure settlement happens between counterparties | Atomic settlement: it either happens or it does not; nothing remains to net or clear |
| Notaries | Verify identity of signers and attest that something occurred | GRIDS: cryptographic identity verification of signers via air-gapped keys, with immutable timestamped record of the event |
| Escrow agents | Hold value until conditions met | Smart contracts release automatically when on-chain verifiable conditions are satisfied |
| Credit card processors | Transmit payment credentials securely | Secure, peer-to-peer transactions with GRIDS. Keys never touch the connected device; merchant receives confirmation, not identity |
A qualification on custody: not every form of custody disappears. Physical assets require physical safekeeping, and regulated securities custody serves compliance functions beyond mere record-keeping. What becomes unnecessary is the custodian's role as attestor of ownership, the function that exists because current infrastructure cannot prove who owns what without a trusted register. Cryptographic proof of ownership replaces that function. The custodian's other roles persist where they add genuine value.
A qualification on escrow: smart contracts enforce conditions that are verifiable on-chain. For purely financial conditions, this is complete: release payment when funds arrive, when a date passes, when multiple parties sign. For conditions involving real-world state, such as the quality of goods delivered or the completion of physical construction, verification requires data to enter the chain. The next phase of development, between main net launch and the transition to public mining, includes the implementation of data-rich digital asset structures designed to integrate real-world condition data directly into the on-chain asset itself, enabling escrow-like functions for an expanding range of commercial conditions without relying on external oracle services.
The clearinghouse does not become a more efficient clearinghouse. It becomes unnecessary because atomic settlement means a transaction either completes in full or does not occur at all; there is nothing left to clear. The payment network does not become a faster payment network. It becomes unnecessary because cryptographic proof of payment replaces the need for a trusted intermediary to confirm the transaction.
Each elimination releases the rent that intermediary captured back into the economy. Each elimination removes a control point, a permission gate, a chokepoint where activity could be blocked or taxed. The compounding effect is not additive. Remove one intermediary and you save its fee. Remove the category of intermediation and you enable activity that could never have occurred under the old architecture: transactions too small to bear the fee, participants too remote to access the infrastructure, exchanges too fast for human intermediaries to process.
The security architecture that makes this possible, GRIDS (Gajumaru Remote Instruction Dispatch Serialisation), is detailed in Part Two. What matters here is the principle: the Internet of Economics does not make intermediaries better. It makes categories of intermediation unnecessary. That is the difference between digitisation and digitalisation.
The Human Economy
Consider what digitalisation means for ordinary economic life in the examples that follow.
Online Purchases – You buy something online. Today, both you and the merchant want to transact digitally; neither wants to deal in cash for an online purchase. But without a trustless means of verifying payment, both of you must trust an intermediary. Your credit card number passes through the merchant's payment processor, the acquiring bank, the card network, and the issuing bank. Your credentials travel through five intermediaries, each a potential point of failure, each extracting a fee, each storing data that can be breached. The merchant does not need your card number. The merchant needs to know that you paid. In the digitalised economy, the merchant receives cryptographic proof of payment. Your credentials never leave your control. There is nothing for the merchant to store, nothing to breach, nothing to steal. The five intermediaries and their fees vanish.
SWIFT Transactions – You are a freelance designer in Nairobi. A client in Berlin owes you €500 for a completed project. Today, that payment travels as a SWIFT wire through the correspondent banking system. The client's bank charges €25-50 to send the international wire. One or more intermediary banks each deduct their own fees, typically $10-30 per hop. Your receiving bank charges a further fee. The foreign exchange conversion adds a markup of 1-3% that is rarely disclosed transparently. On a €500 transfer, total costs of €40-80 are common; the more intermediary banks involved, the worse it gets, and you will not know the final amount until it arrives, three to five business days later.26 In the digitalised economy, the payment settles in seconds. The fee is a fraction of a cent. The full value of your work reaches you because no intermediary exists to intercept it.
Remittances – Now consider the same problem at the scale of migration. Migrant workers sent $685 billion in remittances to low- and middle-income countries in 2024.27 The global average cost of sending $200 was 6.4%, more than twice the UN Sustainable Development Goal target of 3%. In sub-Saharan Africa, the average cost reached 7.9%; in Q1 2025, it rose to nearly 9%.28 Banks remain the most expensive channel at 12.7% on average.29 On $685 billion, even the global average represents over $40 billion extracted annually from the world's poorest workers for the privilege of sending money home. This is not a fee for service rendered. It is a tax on the absence of alternatives.
Small Businesses – Every card payment costs you 1.5-3.5% of the transaction value.30 On thin margins, that is the difference between viability and closure. You cannot refuse cards because your customers expect them. You cannot negotiate the fee because the infrastructure is a monopoly. In the digitalised economy, the customer pays; you receive. The fee reflects the computational cost of cryptographic verification: thousandths of a cent, not percentages of revenue.
Medical Records – Your medical records sit on servers controlled by your healthcare provider, your insurer, your government. You did not choose this. You cannot control who accesses them or how they are used. A data breach at any one of these institutions exposes your most sensitive information.31 In the digitalised economy, you hold your records. You share what you choose, with whom you choose, for the specific purpose you choose. The institution that needs to verify your insurance status receives cryptographic proof that you are insured. It does not receive your medical history.
These are not hypothetical futures. They are architectural properties of a system that exists and operates today. The Gajumaru is operational. The technology enabling each of these transformations is built. What remains is adoption: the migration from accumulated digitisation to genuine digitalisation.
The Machine Economy
Now consider what is coming, and why it makes the transition from digitisation to digitalisation not merely desirable but unavoidable.
Institutions still think the answer is more digitisation: more archipelagos, to borrow from the earlier analogy. Artificial intelligence is the jet engine, and it is not waiting for institutional inertia. Large language models and autonomous agents are already transforming how work is done, and the trajectory points toward machines conducting an increasing share of economic activity independently.
This is not a distant prospect. GajuMarket by QPQ already demonstrates the architecture: a peer-to-peer trading platform where products are registered as smart contract instances on-chain, counterparties negotiate terms through the platform, and the platform automates the smart contract build from those agreed terms, which both parties can verify before signing. The negotiation is human; the contract construction, execution, and settlement are automated. This is the pattern the machine economy will scale: AI agents comparing prices, selecting vendors, agreeing terms, and executing purchases through smart contracts that enforce the agreement automatically. The architecture for machine commerce is not theoretical. It is operational.
Autonomous vehicles will pay tolls, charging stations, and parking. Smart buildings will procure energy, maintenance, and supplies. Industrial systems will settle micro-contracts for compute, bandwidth, data, and API access. The volume will not be thousands of transactions. It will be billions per day, then billions per hour.
The Architectural Gap
Current infrastructure cannot support this. It was not designed to. It was designed for humans transacting with other humans through institutional intermediaries, at human pace, in human volumes.
Card networks require human identity. Bank accounts require human account holders. Settlement in days is meaningless to agents operating in milliseconds. Fees of 2-3% per transaction with minimums of $0.15 to $0.30 per transaction make high-frequency micro-transactions economically absurd: an AI agent paying fractions of a cent for each API call cannot route each payment through Visa. Compliance frameworks assume a human being with a name, an address, and a government-issued identity document stands behind every transaction. Machines do not have passports.
Digitisation cannot solve this. No amount of incremental improvement to infrastructure designed for human-pace, human-scale, human-identity transactions will produce infrastructure capable of machine-pace, machine-scale, machine-native transactions. Bolting faster messaging onto SWIFT does not create machine-to-machine settlement. Adding an API to a card network does not eliminate the 2-3% fee or the identity requirement. The accumulated layers of digitised infrastructure are not merely slow for this purpose. They are architecturally incapable of serving it.
Foundations for the Machine Economy
The machine economy requires transaction costs approaching zero, no identity requirements at the resource layer (machines transact as machines), programmable conditions (smart contracts that execute automatically when conditions are met), and settlement in seconds (not days, not hours). These are not features that can be added to existing infrastructure. They are properties of a different foundation.
The mechanism that delivers this is the state channel: a direct channel between transacting parties where thousands of transactions can occur off-chain, with only the opening and closing balances settled on-chain. The throughput is limited only by what the parties can process between themselves, not by the capacity of the underlying chain. Critically, state channels can be deployed on Groot or on any Associate Chain. On Groot, settlement is trustless and denominated in Gaju. On an Associate Chain, the channel operates under that chain's governance and settles in its native currency or Gaju – it is a choice which to use. The same RPA versus RIPA choice that governs everything else governs this: trustless if you need it, governed if you choose it. The architecture for machine-scale commerce does not require every transaction to touch the base layer. It requires the base layer to guarantee that no party can cheat when the channel settles. Part Two examines the technical architecture in detail.
The machine economy is not a separate domain from the human economy. It is the same economy. The freelancer in Nairobi whose client's AI agent initiates payment the moment a deliverable is verified. The small business whose inventory system automatically pays suppliers when stock falls below a threshold. The energy grid where millions of devices negotiate price and supply in real time. Human and machine activity interweave. The infrastructure must serve both, at both scales, without the accumulated complexity of decades of digitisation standing between them.
AI is applying the thrust whether institutions are ready or not. Those that recognise the phase change will build for it. Those that do not will find themselves maintaining propeller aircraft in a supersonic world.
Where Digitalisation Happens, and Where It Still Cannot
Digitalisation does not require everything to be trustless. That would be inefficient and unnecessary. The RIPA model exists precisely because governed infrastructure, operated by identifiable parties under clear legal jurisdiction, is the right environment for the vast majority of economic activity. An Associate Chain operating a national digital economy is a genuine step change from the digitised systems it replaces. Internal transactions settle in seconds. Smart contracts automate what previously required intermediaries. Within that governed space, the digitalisation gains are real and transformative.
The problem is at the boundaries.
Every time that digital economy must transact with another jurisdiction, another bank, another consortium, it hits the same old problem: who do you trust to bridge the gap? Without a trustless resource layer, the answer is another governed system, another intermediary, another control point. You have digitalised the interior and digitised the borders. The most efficient intranet in the world still needs the internet to connect to anything outside itself.
That is what Groot provides: the boundary-crossing layer where trust is cryptographic rather than institutional, where the message itself is trustworthy regardless of who sent it. The cost makes the point concretely: a simple spend transaction on Groot costs 0.0000169 Gajus. One hundred thousand cross-boundary settlements would therefore cost 1.69 Gajus. At the current price of $0.01 per Gaju, that is under two cents for one hundred thousand transactions between governed systems, settled trustlessly. At $1.00 per Gaju, it is $1.69. Settling, not merely initiating, in 2-3 seconds (1 micro-block) for most transactions, 1-2 minutes (1 key block) for very high value transactions and 3-4 minutes (2 key blocks) for irrevocable requiring absolute finality no matter the transaction value. For the high-frequency micro-transactions of the machine economy, state channels provide throughput measured in tens of thousands of transactions per second, with only aggregate settlements touching the chain itself. Compare that to the correspondent banking fees, the SWIFT charges, the bilateral bridge costs, and the days of settlement delay that the same volume would incur today. Governed infrastructure digitalises within its own boundaries. Groot digitalises across them.
Honesty demands a further acknowledgement. Some elements of full digitalisation remain ahead of us, not behind us. Consider the tokenisation of real-world assets: representing a property, a bond, or a commodity as a digital token on a governed chain delivers genuine gains in transfer speed, programmable conditions, and settlement friction. If the token still points at a custodian who holds the physical asset, whose operations you must trust, you have digitised the representation without digitalising the ownership. The custodian remains. The dependency remains. The token is a faster pointer to the same trusted intermediary.
True digitalisation of asset ownership, where the on-chain representation is the asset rather than a reference to someone who holds it, requires the elimination of that custodial dependency. This is a problem we intend to address directly. In the next phase of development, between main net launch and the transition to public mining, we will be implementing a form of data-rich digital asset designed to remove the need for third-party custodians entirely. The architecture already supports it. The engineering is ahead of us.
Digitalisation is a journey. But every journey needs a door to open before the first step can be taken. Groot is that door: a trustless resource layer to which any infrastructure can connect, natively, without bridges, without bilateral agreements. Without it, governed systems digitalise internally and remain digitised at every boundary. With it, the boundaries open and the progression begins. Cross-boundary settlement works today. Custodian-free digital asset ownership is the next horizon, not the current state. We will always tell you which is which.
Definition
The Internet of Economics is the secure transmission of economic instruments – money, assets, sensitive data – peer-to-peer, without intermediaries, at global scale.
| Economic Instrument | What It Means | Current State |
|---|---|---|
| Money | Non-debaseable currency you hold directly | Entries in someone else's ledger, debaseable at will |
| Assets | Digital ownership you control with your keys | Registration in databases controlled by others |
| Sensitive Data | Information that never leaves your control | Replicated across thousands of merchant databases |
The Internet of Data already exists. You browse, search, read, watch. Information flows via HTTPS: a single protocol no one controls, that everyone builds on. Nobody starts a business creating an alternative to HTTPS. It simply does not make sense to try.
The moment economic instruments: payments, transfers, sensitive data disclosure, are involved, you are forced into controlled infrastructure. The browsing is free; transacting requires intermediaries who see everything, control access, and extract rent at every step.
The Internet of Economics separates these domains: Browse and decide on the Internet of Data. Transact on the Internet of Economics: your money moves, the merchant receives confirmation, your sensitive data never leaves your control. Two domains, cleanly separated, each optimised for its purpose.
Just as there will never be a second HTTPS, there will be only one protocol by which economic instruments transfer across the internet. The Gajumaru provides the complete architecture for this: governance-free resource layer beneath, governed infrastructure above, native interoperability between them.
Why Only the Gajumaru Delivers This
No other system provides all four requirements:
| Requirement | Why It Is Necessary | How Gajumaru Delivers |
|---|---|---|
| Governance-free resource layer | Without it, you must trust whoever governs. Trust requirements mean intermediaries. Intermediaries see your data, control your access, extract rent. | Groot: proof-of-work, no operator, no governance, no one can say no. The ocean that connects all islands. |
| Governed infrastructure that retains sovereignty | Real-world commerce requires compliance, jurisdiction, accountability. Pure trustlessness cannot serve regulated markets. | Associate Chains: fully sovereign, any consensus mechanism, connect to Groot for interoperability without surrendering control. |
| Native interoperability without bridges | Bridges require trusting bridge operators: reintroducing the intermediaries the Internet of Economics eliminates. | Connection point protocol: Groot is natively aware of Associate Chains. No bridges. No bilateral agreements. Hub-and-spoke scales linearly. |
| Separation of economic instruments from data exposure | Current internet commerce exposes credentials to every merchant. Every database is a breach target. | GRIDS: keys never touch the connected device. Merchant receives payment confirmation and settlement, not your identity. Cannot breach data you never held. |
The Gajumaru is the only complete architecture for the Internet of Economics: governance-free resource layer beneath, governed infrastructure above, native interoperability between them, and architectural separation of economic instruments from data exposure.
III. Economic Emancipation
The Mission Statement
The mission is not 'trustless everything.' Trustlessness has costs; efficiency requires trust and a world where every transaction required cryptographic verification would be slower, more expensive, and less convenient than what we have now.
The mission is: CHOICE. Economic emancipation through choice, enabled by a governance-free resource layer that creates options where none existed before, for everyone.
When you can choose to exit, you are not captive. When you cannot, you are. The existence of the option changes the relationship, even if you never use it.
Consider what that absence of choice actually means. In February 2022, the Canadian government invoked emergency powers against citizens who had committed no crime beyond protest. Over two hundred bank accounts were frozen, worth approximately $7.8 million.32 Insurance policies were suspended. Joint accounts were caught, affecting people who had nothing to do with the demonstration.33 The banks complied without questioning the order, the list, or the constitutionality. Both the Federal Court and, on appeal in January 2026, the Federal Court of Appeal ruled the invocation unreasonable and unconstitutional, finding it violated Charter rights to freedom of expression and protection against unreasonable search and seizure.34 The appeal court described the freezing of bank accounts without warrant or prior judicial authorisation as "troubling in the extreme" and "egregious."35 By then, the message had been delivered: your money is yours until someone with authority decides it is not.
In Britain, the system did not even need the state. Coutts closed Nigel Farage's accounts because his political views were "not compatible" with the bank's values. Internal documents described a sitting political figure as a "disingenuous grifter."36 He was refused service by seven further banks. Nearly half a million accounts were forcibly closed in the UK in a single year.37 No emergency powers required. The banking system decided, on its own authority, who belonged.
These are not aberrations in otherwise healthy systems. They are demonstrations of what is possible when no exterior exists. The state can weaponise the financial system against you. The financial system can weaponise itself against you without the state lifting a finger. In neither case do you have anywhere else to go.
Programmable Control
Now consider what is being built. China's digital yuan is fully programmable and fully trackable: the state can monitor every transaction in real time, restrict how money is spent, and integrate financial data with a social credit system that had, by mid-2019, denied 26.82 million air tickets and 5.96 million high-speed rail tickets to individuals labelled "untrustworthy."38 The digital yuan is designed to replace cash in circulation, giving the People's Bank of China unprecedented visibility into and control over the economic activity of 1.4 billion people.39 The European Central Bank is building the digital euro on the same centralised architecture, with legislation expected in 2026 and issuance targeted for 2029.40 The ECB's own language is revealing: "preserving monetary sovereignty," "strategic autonomy," "reducing reliance on non-European payment systems."41 Read carefully. Whose sovereignty? Whose autonomy? Not yours.
Programmable money in the hands of the state is programmable control. Money with expiry dates. Money that can only be spent in approved categories. Money that can be switched off. When the state controls not just the issuance of currency but the mechanism of every transaction, the tools demonstrated in Ottawa and London become permanent infrastructure rather than emergency measures.
The Trajectory
Layer on what comes next. Artificial intelligence is beginning to displace white-collar work at scale. Entry-level roles in technology, administration, and professional services are contracting. Goldman Sachs estimates that widespread AI adoption could displace six to seven per cent of the American workforce.42 The CEO of Anthropic has warned that fifty per cent of entry-level white-collar jobs could disappear within five years.43 Whether the disruption is moderate or severe, the direction is clear: a growing proportion of the population will depend on state support. The state, which produces nothing, funds that support through taxation of the shrinking productive base; through borrowing against future generations; and through currency debasement that erodes the value of every pound, dollar, and euro already earned. Each of these mechanisms increases dependency. Each dependency increases control. Each increment of control makes the next increment easier.
This is the trajectory. Not a single dramatic seizure of power, but the steady accumulation of tools and dependencies that make dissent expensive, exit impossible, and compliance the path of least resistance. The authoritarian slide does not require authoritarian intent. It requires only that no alternative exists.
Economic emancipation does not require everyone to leave. It requires that everyone can.
The Duality Principle
Trust enables efficiency. Trustlessness enables freedom. Neither should dominate.
This is not an abstract principle. It is an observable mechanism. Where people act in a trusted way and do not abuse that trust, you can have very high efficiency operations. A trusted SQL database is far more efficient than any blockchain. That is fine. That is how it should be.
The question is: who controls the system that determines trustworthiness?
If the trust system itself is controlled; if someone can arbitrarily revoke your access, freeze your assets, change the rules; then efficiency comes at the cost of freedom.
Governed infrastructure is not the enemy. Well-run infrastructure that serves its users fairly is enormously valuable. The problem is not governance. The problem is the absence of alternatives to governance.
When governed systems face no competition, they extract. When they face competition from ungoverned alternatives, they must serve or lose users. Each path tempers the other.
Groot's role becomes clear here – it is not the most efficient system, it never will be. Groot is the discipline on power: the trustless foundation that keeps governed systems honest, the fallback when trust breaks down, the exit option when infrastructure becomes extractive, and the basis for negotiation between parties who have no other reason to trust each other.
The chain of efficiency runs: negotiation produces trust signals; trust signals produce efficiency gains. Without a common foundation for negotiation, parties who share no legal framework, no mutual trust, no diplomatic relations cannot even begin. Groot provides that foundation. It does not replace trusted systems. It makes them possible by providing a trustless ground on which negotiation can occur and from which trust can be built.
We are not anti-governance. We are anti-monopoly-on-governance.
The ability to choose is itself what constitutes freedom, regardless of which choice you make. Most people, most of the time, will choose governed infrastructure, because it is faster, cheaper, and more convenient. That is the right choice for them, and the architecture supports it. But their relationship with that infrastructure is fundamentally different when they choose it freely than when they are compelled to accept it. The existence of a credible alternative transforms every interaction with governed systems from compulsion to consent, just as the existence of antitrust law disciplines companies that are never actually prosecuted. The remedy does not need to be invoked. It needs to be credible.
The point is choice. The ability to choose makes both paths better: infrastructure becomes more responsive, resource layers become more usable. Competition between them produces outcomes neither could achieve alone.
The Three Restorations
For five thousand years, three things have been progressively taken from individuals and concentrated in institutions. The Gajumaru provides the means to restore them. These restorations are not utopian aspirations. They are architectural properties of a correctly designed system that incorporates and balances rights with accountability, power with discipline.
Money
Once, money was a thing you held: gold, silver, shells. Now it is an entry in someone else's ledger, expandable at will by those who control the ledger. Transactions require intermediaries because neither party can independently verify the other's promise to pay. That intermediation is a genuine service, born from a genuine problem: without it, commerce beyond your immediate community is difficult or impossible. The cost is dependency on the intermediary and subjugation to the ledger.
The Gaju restores money to the individual: finite, holdable, not subject to debasement, transferable without permission. Groot eliminates the trust gap. The intermediary's genuine service, verifying that payment occurred, is replaced by the resource layer's cryptographic proof, verifiable by both parties independently. The service is preserved; the dependency is removed.
Assets
Property was once possession. Now it is registration in government databases, subject to the rules of whoever maintains the registry. Intermediaries control the record of who owns what: they provide certainty of ownership, enforceable transfer, and protection against fraud. These are genuine services. The cost is that ownership depends on the record-keeper, and the record-keeper sets the terms.
Digital assets on-chain restore direct ownership: you hold the key, you own the asset. No intermediary can revoke what they do not control. The asset itself contains the controlling code, if any, that directs how it can be used and traded, along with who must be notified of a trade for legal compliance, if applicable. Registrars cease to be controllers and become notified parties to a transfer. The certainty is preserved; the control is removed.
Data
Before digitisation, privacy was the default. You paid cash; the merchant knew your face, nothing more. Your medical history was a file in a single office. Your financial life was a conversation with a bank manager in a single branch. No one captured your data because no mechanism existed to capture it. Digitisation changed the default. Every transaction, every login, every interaction now generates a record held by someone else, stored indefinitely, monetised by those who captured it, accessible to governments who demand it. The intermediaries who process your payments, verify your identity, and authenticate your access provide genuine services. The cost is that those services require your data, and your data, once held, is a liability that compounds with every merchant, every platform, every service that stores it. Every database holding that data is a target; the larger the store, the greater the prize.
The Gajumaru's architecture restores the condition that pre-digital life provided by accident: your information stays with you unless you choose to share it. Through the GRIDS security protocol, merchants receive payment confirmation, not your identity. You authenticate yourself directly using your own keys; no third party involved, no third party even aware. The data exposure that makes breaches inevitable is eliminated: you cannot breach data that was never held. This is the restoration of your data sovereignty. Your human sovereignty.
The Exit Option Principle
A genuine exit disciplines power. It must be trustless. It must push efficiency to the limits of what trustlessness permits.
Consider what happens when a genuine exit exists. An infrastructure operator who can raise fees without limit, because users have nowhere else to go, will raise fees. Not always immediately, not always consciously, but the incentive is structural and the outcome is predictable. The moment an alternative exists, the calculus changes. The operator must now weigh every extraction against the threshold at which users accept a less efficient alternative rather than continue paying. The exit does not need to be used. It does not even need to be attractive. Its existence changes the relationship from captivity to negotiation.
This is why the exit must work. Not theoretically, not on paper, not as a whitepaper promise: it must be a place people can actually go. It must settle transactions in seconds, not hours. It must support programmable commercial logic, not merely transfer value and it must operate at an efficiency that makes using it a genuine choice rather than an act of desperation.
Groot delivers each of these. Over 1,846,200 times more computationally efficient than Bitcoin; in excess of 300 transactions per second on the base layer. Commercial settlement in 2-3 seconds; 3-4 minutes for absolute finality: the protocol guarantee that no transaction older than 2 keyblocks can be ejected. A full virtual machine and a smart contract language designed for safety. These are not marketing numbers. They are the measured result of engineering a genuine proof-of-work chain to the limits of what mathematics and physics permit.
Something that is genuinely decentralised and thereby trustless is never going to be as efficient as trusted infrastructure. It does not need to be. It needs to work well enough that people can actually use it.
Medieval merchants did not flee to better cities. They fled to cities that existed. The frontier did not need to be comfortable. It needed to be there. It also needed to be somewhere you could actually live.
Mere Existence Is Not Enough
Bitcoin proved that existence alone is not enough. Bitcoin is an actual blockchain, minting real money. It exists. You cannot buy a coffee with it. You cannot programme settlement conditions: Bitcoin Script is intentionally limited, with no general-purpose virtual machine and no smart contract language capable of expressing commercial logic. You cannot build governed infrastructure on top of it. It is an island: well-defended, internally coherent, disconnected from everything the real economy needs. Its existence has not disciplined the systems it was meant to challenge, because it cannot serve as a functioning alternative to them.
Worse, it has become a tool of the very institutions it was supposed to bypass. The world's largest asset manager holds over half a million Bitcoin through an ETF that is now its most profitable product, generating roughly $244.5 million in annual revenue.44 Hedge funds access Bitcoin through derivatives and structured products rather than holding it directly; a 2025 survey found that 67% of crypto-invested hedge funds used such instruments rather than holding coins.45 The original vision of peer-to-peer electronic cash has been absorbed into the same intermediated, custodial, institutionally controlled financial architecture that Satoshi Nakamoto set out to circumvent. The intermediaries did not need to fight Bitcoin. They wrapped it in an ETF, collected their fees, and carried on.
Groot is that genuine exit. Its existence disciplines every piece of infrastructure connected to it; not merely by being there, but by being a place people can actually go.
What Economic Emancipation Means
Economic emancipation is not the absence of governance. It is the presence of choice.
Most people, most of the time, will choose governed infrastructure. They will choose it because trust enables efficiency, because regulated systems offer protections, because the convenience is worth the trade-off. That is fine. That is the system working as intended.
What changes is the nature of that choice. Today, participation in governed economic infrastructure is compulsory. There is no alternative. You accept the terms, the fees, the surveillance, the risk of arbitrary exclusion, because the only other option is to not participate at all. Economic conscription.
When a genuine, trustless alternative exists, every interaction with governed infrastructure transforms from compulsion to consent. The fees must be justified, because you can leave. The terms must be fair, because you can leave. The surveillance must be proportionate, because you can leave. You may never leave. You may never even consider leaving. The point is that you could.
This is what the Three Restorations deliver in practice. Sovereignty over your money means no one can debase your stored labour or freeze your account without due process. Sovereignty over your assets means no intermediary stands between you and what you own. Sovereignty over your data means you decide who sees what, and when. None of this requires rejecting governance. All of it requires that governance earn your participation rather than conscript it.
Choice is freedom. The restoration of choice is economic emancipation.
Simplicity as Design Principle
The Duality Principle establishes that trust and trustlessness serve different purposes. The architectural consequence is immediate: they belong in different layers.
Commercial adoption of blockchain requires that regulated actors can access the trustless space of a genuine resource layer whilst remaining firmly anchored in the regulated space of their markets and jurisdictions. Achieving this in a single system is impossible. The question is how you respond to that impossibility.
"There are two ways of constructing a software design: one way is to make it so simple that there are obviously no deficiencies, and the other way is to make it so complicated that there are no obvious deficiencies. The first method is far more difficult. It demands the same skill, devotion, insight, and even inspiration as the discovery of the simple physical laws which underlie the complex phenomena of nature. It also requires a willingness to accept objectives which are limited by physical, logical, and technological constraints, and to accept a compromise when conflicting objectives cannot be met. No committee will ever do this until it is too late." C.A.R. Hoare, 1980 Turing Award Lecture46
Faced with this choice, the blockchain industry took the second path. When a single system could not deliver trustlessness, efficiency, and accountability simultaneously, the response was to add complexity: Layer 2s on top of Layer 1s, bridges between chains, rollups posting to base layers, sequencers coordinating between systems. Each addition introduced new failure modes that required further additions. The solutions became the problem, and the problem became the business model.
The industry even named the consequence and mistook it for a law of nature. The 'trilemma', popularised by Vitalik Buterin, posits that any blockchain must sacrifice one of three properties: decentralisation, security, or scalability. This framing has been treated as a constraint of physics. It is not. It is the consequence of trying to solve contradictory requirements in a single system, and it asks the wrong questions.
The real trilemma is: Trustlessness, Efficiency, and Accountability – the ‘TEA’ trilemma. Can you trust the message without trusting any messenger? When trust is required, what recourse exists? What are the efficiency trade-offs that follow? These are not independent dials. Trust enables efficiency; trustlessness has costs; accountability only matters where trustlessness is absent. The failure mode of anonymous proof-of-stake makes this concrete: a network where validators are pseudonymous delivers neither the trustlessness of proof-of-work (you must trust the validator set not to collude) nor the accountability of governed infrastructure (you cannot identify, sue, or replace the people who let you down). It occupies the worst position in the trilemma: high costs, low trustlessness, zero recourse. Part Four examines this in detail and provides tests that anyone can apply to any project claiming to be a blockchain, to determine where it actually stands.
Partition, Not Compromise
The Gajumaru chose the first path. Rather than adding complexity to reconcile contradictions, it separated the contradictions into layers where each ceases to be contradictory at all. Groot provides trustlessness simply, because it does not also try to provide efficiency or governance. Associate Chains provide accountability and efficiency simply, because they do not also try to be trustless. The choice between paths provides the discipline. No single layer compromises. Each does one thing well. Users choose their position.
This is why every 'One True Blockchain' project fails. They try to be everything to everyone in a single system: fast and trustless (impossible), regulated and permissionless (impossible), private and transparent (impossible), governed and decentralised (impossible). The attempt to be all things produces systems that are none of them, and the compromises required at the base layer cascade upward through every application built upon them. Hoare's second path: so complicated that there are no obvious deficiencies, until someone looks. We did.
Partitioning the problem is the fundamental insight that drove the Gajumaru's design. Where every other project attempted to solve trust and efficiency at the same layer, the Gajumaru separates them: the resource layer is trustless and ungoverned; the infrastructure layer is efficient, accountable, and governed. This same principle of decomposition runs through the entire architecture: currency separated from protocol, commercial entity separated from the resource layer it serves, governance placed where it belongs and excluded where it does not. The choice between layers is the mechanism that disciplines both. The architecture that makes this possible is the subject of Part Two.
IV. The Garden of Eden Problem
Every blockchain project faced the same temptation: monetise the base layer. Extractive revenue – the corporatist model that is so popular with 'venture capitalists' and the many champions of this corruption of capitalism – requires control. Control requires governance. Therefore monetising the base layer means putting governance at the base layer, which in turn means it is not a resource; it is infrastructure.
The metaphor is the Garden of Eden. Adam and Eve existed in a state of grace. The one thing asked of them was that they not eat from one tree. The snake arrives in the form of crypto VCs asking "what is your business case? How are you going to make money?" The founders think about it and answer: "We are the blockchain; we will run it, operate it, and take fees from the system."
The metaphorical apple of temptation is a revenue model choice, but one that requires control to execute.
The Players:
Eden = A governance-free, control-free resource layer: an open, global economy by people for people in which we can all participate. The promise of blockchain.
The apple = Choosing to monetise the base layer, which necessitates governance and introduces overt and covert control functions, betraying the blockchain promise.
The snake = Crypto VCs asking "what is your business case?": the corporatist model that seeks to extract revenue from control, to become the 'one ring to rule them all' and tax everyone else's endeavour, risk free.
The consequence = Once governance is at the base, you have built infrastructure, not resource. Permanent.
This is the Garden of Eden problem: once you introduce governance, you cannot go back.
The Evidence Is Everywhere
"Decentralised governance." "Community control." "On-chain voting." These phrases do not describe distributed power. They disguise concentrated power.
We see it again and again. The "DAO" (a Decentralised Autonomous Organisation, a supposedly community-governed organisation) where founders hold 51% of governance tokens (tokens that confer voting power over the project's direction). The "community vote" where the foundation is the default delegation target and passivity (people with votes who either do not bother or assign their votes to the Foundation) equals consent. Solana: 70% of validators cannot survive without Foundation delegation; the Foundation decides who thrives.47 DFINITY: 48.5% to foundation and insiders, 1.5% to the "community" the foundation claims to serve.48
Ethereum: at any given time, between four and six entities control 51-62% of Ethereum's total stake.49 Quite apart from which, Vitalik Buterin has made clear that the Ethereum Foundation is in control and he is in control of it. In January 2025, facing community demands for new leadership, he posted on X: "The person deciding the new EF leadership team is me." He warned the community that their pressure was "decreasing the chance I have any interest whatsoever in doing 'what you want'."50
Foundation management had to organise a retreat "in order to force" him into naming a new executive director, because he "couldn't really make up his mind." Former Foundation employees told The Guardian that Buterin typically "pretended that [Ethereum] was in the hands of the community"; a second former employee independently described this as "cosplaying" community governance.51 In the same article, Paul Brody, chairman of the Enterprise Ethereum Alliance and EY's global blockchain lead, described the community as behaving "a lot like pretty normal shareholders." Pretty normal shareholders: in a "decentralised" network, without any of the protections actual shareholders enjoy.
This is not an isolated failure. This is the inevitable outcome of the foundation model. Any blockchain that monetises its base layer creates something worth capturing. Foundations are the capture mechanism. The vocabulary changes; the power dynamics do not.
A British politician named Tony Benn developed a diagnostic for exactly this problem. Benn served in Parliament for fifty years and held Cabinet office under Harold Wilson and James Callaghan. His politics were democratic socialist; ours are not. We use his test because it is the sharpest available instrument for identifying unaccountable power, regardless of the vocabulary that power uses to describe itself. Speaking from the floor of the House of Commons in May 1990,52 he directed five questions at the European Commission – an institution he believed exercised vast power over citizens while remaining structurally beyond their reach:
What power have you got?
Where did you get it from?
In whose interests do you exercise it?
To whom are you accountable?
How can we get rid of you?
His argument was simple: if you cannot answer the last question, the first four do not much matter. You have identified power that cannot be removed by those it governs. The vocabulary it uses is irrelevant to what it actually is.
Apply Tony Benn's five questions to any of these foundations and the answers are always the same: You cannot get rid of them. You never could and you never can.
The detailed analysis of Ethereum's specific failures follows later in this document, but the reader should understand: Ethereum is not an exception to these patterns. It is merely the leader. The "many hands" on the lever do not exist. A small cabal, sometimes just one man as with Ethereum, holds the lever. The vocabulary of distribution, governance tokens, delegation, on-chain proposals, exists to obscure that reality, not to change it. Overt concentrated control is simply more honest about what it is.
Newcomen
Thomas Newcomen's atmospheric engine, demonstrated in 1712, proved that steam could do mechanical work. It was real, it operated, it moved things. It was also so inefficient it could only function at collieries where waste coal was free. James Watt's separate condenser, fifty-seven years later, made steam power actually deployable – and changed the world. Newcomen proved the destination. Watt reached it.
Bitcoin is Newcomen. Not a failure. A proof – genuine, necessary, and insufficient to reach what it demonstrated was possible. The Gajumaru is the engine that can.
On 31 October 2008, an anonymous figure published nine pages that identified, with surgical precision, the central problem of the digital economy: the compulsory intermediation of every transaction by a trusted third party who can reverse, freeze, surveil, or refuse. The insight was that proof-of-work computation could replace that trust entirely. Not approximate it. Replace it. The message could be verified without trusting any messenger.
Bitcoin was the proof. A working demonstration that money with a fixed supply, produced by irreversible computational effort, transferable peer-to-peer without permission or intermediary, was not merely theoretical. It existed. It worked.
This was the greatest proof of concept in the history of money – and, we believe, a call. A call to restore what money is: stored labour, sovereign and undebasable, belonging to whoever earned it and to no one else. A call to build a digital economy in which human beings transact on their own terms, without seeking permission from intermediaries who can grant it or refuse it as they choose. Nine pages that said: this is what is broken, this is what must exist, and here is the proof it is possible.
The parallel to Newcomen is precise in a way that goes beyond analogy. Newcomen's engine worked. It pumped water from mines. It did the thing it was supposed to do. What it could not do was power the Industrial Revolution – not because the principle was wrong, but because the efficiency was insufficient to scale. Bitcoin worked. It transferred value. It proved the principle. What it could not do was become the digital economy's monetary foundation – not because the principle was wrong, but because the architecture was insufficient to scale. And crucially: the architecture had not finished being built when the world arrived to use it.
What We Know
Satoshi was active in public for roughly two years. His last post on the BitcoinTalk forum was 12 December 2010 – technical, focused on a denial-of-service update for version 0.3.19. No farewell. No announcement. He simply stopped posting.53
He continued in private for a few more months. His last known communications were two emails in April 2011:
23 April 2011, to developer Mike Hearn: *
"I've moved on to other things. It's in good hands with Gavin and everyone."*54
26 April 2011, to Gavin Andresen: *
"I wish you wouldn't keep talking about me as a mysterious shadowy figure, the press just turns that into a pirate currency angle. Maybe instead make it about the open-source project and give more credit to your dev contributors."*54
The following day, 27 April 2011, Andresen publicly announced he had accepted an invitation to present Bitcoin at CIA headquarters – a conference organised by In-Q-Tel, the CIA's venture capital arm, on the theme "Mobility of Money." Federal Reserve economists attended. Andresen later confirmed he sold a Bitcoin to a CIA attendee.55 Satoshi never replied to Gavin again.
One further post appeared in March 2014, when Newsweek claimed to have identified him as a Japanese-American named Dorian Nakamoto. The post said: "I am not Dorian Nakamoto." Then permanent silence.
His approximately 1.1 million Bitcoin, identifiable through the "Patoshi Pattern" in early mining records, have never moved.56 At Bitcoin's 2021 peak, they were worth approximately $73 billion. He did not access a single Satoshi.
What We Think
We cannot prove what Satoshi was thinking. The evidence has a shape, and we are entitled to read it as anyone else is.
The weeks before his public withdrawal were marked by a specific incident. WikiLeaks had been financially blockaded: PayPal, Visa, Mastercard, and Bank of America all cut off its donations under US government pressure in early December 2010. Bitcoin was then worth $0.20, with a handful of participants. WikiLeaks announced it would accept Bitcoin donations. The community erupted with enthusiasm.
Satoshi's response, in his second-to-last public post, was a direct appeal: *
"No, don't 'bring it on.' The project needs to grow gradually so the software can be strengthened along the way. I make this appeal to WikiLeaks not to try to use Bitcoin. Bitcoin is a small beta community in its infancy. You would not stand to get more than pocket change, and the heat you would bring would likely destroy us at this stage."*53
This was not merely a worry about network resilience. Satoshi had a development timetable in his head. The engine needed more work before it could bear the load. He was watching enthusiasts conscript an unfinished proof of concept into a political battle before the foundation was ready – not because the battle was not worth fighting, but because an atmospheric engine cannot power a factory.
We believe that it is obvious that Bitcoin grew faster than Satoshi intended. It exploded into public consciousness before the software had been hardened, before the protocol decisions that would determine its long-term viability had been made, before the development work that would have delivered on the whitepaper's vision was complete. The WikiLeaks moment was the inflection point he had seen coming and feared: the moment at which participation outran readiness, at which the community's appetite for the destination overwhelmed the engine's capacity to reach it. Participation locked the architecture in place. The forks and disputes that followed – block size wars, the SegWit battles, the endless BIP processes – were the symptoms of a protocol frozen mid-construction by the weight of its own adoption.
Then he watched Gavin Andresen accept an invitation to brief the CIA. He sent two quiet farewell emails. One asked for the project to be the story rather than the founder. Then silence.
Read this clearly. This was not, we do not believe, a handover. It was the resignation of a man who had spent years on a precise mission, who had embedded a statement about monetary sovereignty in the foundation of the chain, who had begged WikiLeaks not to conscript his unfinished engine. He did not, we venture, retire satisfied. He walked away from the corruption of a vision – a vision that would remain corrupted, its destination unreachable, unless someone else understood what had to be done and was prepared to pay the price to do it.
His birth date on the P2P Foundation profile was listed as 5 April 1975. April 5 is the date of Roosevelt's Executive Order 6102 in 1933, requiring US citizens to surrender privately held gold. 1975 is the year the prohibition was repealed.57 The choice was deliberate. The concern was monetary sovereignty – the confiscation of sound money by state authority. That is what he built against. Not governments broadly. Not all authority. Specifically the political manipulation of money.
The Genesis Block embeds the Times of London headline from 3 January 2009: "Chancellor on brink of second bailout for banks." A statement of purpose, permanent and unalterable, in the first block of the chain.
A man who built what Satoshi built, who embedded that purpose in the foundation of the chain, who then watched the industry turn it into a speculative asset, who refused to touch a fortune worth tens of billions, whose last message asked for the project to receive credit rather than the founder – that man could see that the destination was now unreachable from where the network had arrived, and found nothing in what came after that gave him reason to stay.
We cannot know. Only he does. But the coins remain still, and his silence placed alongside what preceded his departure speaks volumes to us as devotees of what his vision pointed to.
What We Took From It
We read the evidence and drew the logical conclusion. So can the reader, following the same steps.
The destination was real. The proof of concept was genuine. The architecture had to be completed before participation made it permanent – because once millions of independent miners are running the protocol, no coordinated update is possible. The engine had to be finished before it passed to the world. That required time that Bitcoin, growing faster than anyone intended, did not have.
This is what we applied. The protected mining period – 12 to 18 months from Main Net, the range funding-dependent – exists precisely because we read what happened to Bitcoin and drew the correct lesson. It is not a governance period. Groot has no governance at any point in its existence: no foundation, no committee, no decision-making authority over the protocol. The mining process runs on immutable smart contracts deployed on-chain. QPQ cannot alter them once operative – the rules they encode are set in stone. Only the miner can withdraw their own accumulated Gaju. That is encoded in the contract, not in QPQ's discretion.
We could have used this period differently – reserved it for institutional operations, taken the crypto venture capital that would have queued to dominate these months, and maximised short-term extraction. We chose instead to open it to as many people as possible, to share the most prolific mining period with the widest community we can reach, not reserve it for those with industrial hardware or privileged access. Every person who buys Gaju Mining software and services directly funds the development capacity that delivers what we have promised. They are part of the journey. We share revenues generously with every participant, because we believe in win, you win, we win – a capitalist model whose profit horizon is measured in centuries, not corporatist quarters. Gaju Mining is us living that principle.
We ask something of participants that we ask of ourselves: skin in the game. Be part of the story. Help build the swell of humanity that makes this unstoppable. Satoshi could not complete the engine before the world arrived to use it. We are completing it – and we are asking the people who believe in the destination to help us get there, as we have dedicated our lives to doing.
The second lesson was mining concentration. Bitcoin's SHA-256 proof-of-work is compute-bound. Compute-bound mining migrates to custom silicon: ASICs that cost thousands of dollars, consume thousands of watts, and require industrial infrastructure. The result is the pool oligopoly documented in the competitor analysis: five pools controlling approximately 79% of block production, with the top two alone commanding nearly half the network's hashrate. The people Satoshi built for – ordinary individuals who wanted to participate in a monetary system that could not be controlled by institutions – were priced out of meaningful participation within a few years of launch.
The Gajumaru is built against this. Cuckoo Cycle is memory-latency-bound, not compute-bound. It runs on ordinary consumer RAM. Any laptop with 8 GB of memory participates meaningfully, at 40 to 100 watts – a lightbulb. The hardware is already in two billion homes. The ambition is not thousands of miners. It is millions – potentially hundreds of millions – of ordinary people running on ordinary machines, organising over time into competitive mining pools that collectively provide security no institution can purchase its way into dominating. The model is the SETI@home distributed computing programme of the 1990s, applied to monetary security: millions of modest contributions aggregating into something no single organisation can easily match or capture.58
The Ratchet Only Turns One Way
People often think that things are not binary, that there is a sliding scale between freedom and control. The idea works well in theory. In practice, there are only absolutes and the long, slow journey from Eden to the realisation of hell.
Once the seal of trustlessness is broken at the resource layer, the journey to authoritarianism becomes inevitable. Choice merely determines the pace.
Governance at the infrastructure layer is appropriate; that is the RIPA model. Associate Chains are governed by design; users accept that governance in exchange for efficiency. At that level, governance genuinely operates on a spectrum: competition, regulation, accountability, and exit options moderate its exercise. The Linux Foundation governs how code is developed and released. The Apache Software Foundation coordinates open-source projects across industries. These are infrastructure governance, and they work, precisely because they govern process without extracting economic value from every transaction that flows through the systems they maintain. No one pays the Linux Foundation a fee every time a server runs Linux.
The resource layer is categorically different. The binary applies here, and only here: not because spectrums are impossible in theory, but because the combination of governance and economic value at the foundation creates the ratchet. Govern a resource layer and you create something worth capturing. The moment it is worth capturing, someone will capture it. Remove the ungoverned foundation and the exit option vanishes. Choice between governed systems merely selects your master. It does not offer freedom. Without a trustless foundation, the duality that disciplines power collapses into monopoly with extra steps.
The mechanics of this mirror the growth of the welfare state. Once dependency is created, politicians pander to the dependent vote. The debate shifts from individual freedom and accountability toward collectivism and the enforced empathy of the State; the natural empathy of family and community, which genuinely supports those who struggle, is displaced by bureaucratic management that creates the very dependency it claims to address. The more dependency created, the further the Overton Window moves, because no politician can expect election from an increasingly dependent population if they stand against the largesse that population has come to expect, to demand.
Those who will pay the price for that largesse – generations yet unborn, the value of whose labour we discount before even their parents draw breath – cannot vote, cannot object, cannot escape, and have no voice in the present contemplation of the dependent person. That person may not recognise themselves as a slave, but this is what they have become and what they bequeath, inexorably, totally – much like the proverbial frog in boiling water.
The Same Ratchet in Blockchain
The ratchet operates identically in blockchain governance. The moment you introduce a lever of control, you create something worth capturing. Foundations form. Interests coalesce. Power concentrates. Projects compete for foundation favour rather than user value. Validators depend on foundation delegation rather than economic merit. The debate shifts from "should there be governance?" to "who should govern?" The original position, trustlessness, becomes unthinkable, naive, impractical. Those within the system do not recognise their condition. They believe they have "decentralised governance" when they have feudalism with better vocabulary and none of the accountability.
The board game Monopoly started as a warning. Elizabeth Magie designed The Landlord's Game in 1903 to demonstrate how monopoly control of essential resources impoverishes everyone except the monopolist: rent extraction through ownership rather than value creation through production.59 The warning was ignored. The game became a celebration of what it was meant to critique.
Every blockchain project that introduced governance followed the same trajectory. They started with ideals. They ended with extraction. The journey from one to the other was not a sudden betrayal but a gradual slide, each small compromise making the next one easier, until the original vision was unrecognisable.
Here is the truth: The spectrum between no governance and total governance is a conveyor belt, not a dial, and the direction of travel only runs one way.
The resource layer must remain governance-free from inception. Once you start moving toward control, you will arrive at control. The only question is how long the journey takes.
'The One Ring'
Tolkien understood this. "The One Ring" could not be wielded for good, not because of what it was, but because of what it did to whoever held it. Gandalf refused it. Galadriel refused it. They knew that even with the best intentions, the power would corrupt the wielder.
Frodo carried the ring to Mount Doom through every hardship, resisting its pull for months. The purest intention. The strongest will. At the final moment, standing at the Crack of Doom with the fate of Middle-earth in his hands, he put it on. He claimed it. Even Frodo, the best of them, chosen precisely because he was least corruptible, could not relinquish power when he held it. The ring was destroyed only by accident. Gollum, in his corrupted obsession, bit it from Frodo's hand and fell.
The lesson is not that we need to find the right ring-bearer. The lesson is that the ring should not exist.
A governance-free resource layer is the opposite of the One Ring: no admin keys, no foundation making decisions, no consortium deciding who is in and who is out. Rules enforced by mathematics, not trust. The resource layer must be governance-free, not because governance is bad, but because no one should control the foundation connecting everything else. Circle with the best intentions. SWIFT with reformed governance. JPMorgan with perfect accountability. It does not matter. The power corrupts. Not because the holder is weak, but because the power is absolute.
What We Did Differently
This is why we deliberately chose not to create a foundation, and why we have eschewed every governance structure, not merely those native to proof-of-stake.
Proof-of-work removes one vector of control: there is no stake-based voting, no delegation that concentrates power, no slashing conditions that create dependency on those who define the rules. But proof-of-work does not automatically mean no governance. Many blockchain protocols that implemented proof-of-work did so with a foundation that decides their path. The original Ethereum Foundation existed before the transition to proof-of-stake. A proof-of-work chain can still have people who decide what upgrades happen, what changes are accepted, what direction the protocol takes.
We created none of the structures every other project created: no foundation, no privileged development committee, no controlled upgrade process beyond the planned development and deployment to public mining access.
At every juncture, we took the decision that made this less profitable in the short term but made its longevity more assured. A foundation becomes a focal point for control, something people compete to capture. The minute you have something governable, you have a fulcrum upon which to twist everything else.
The obvious question remains: if you refused the apple, how do you eat?
The answer is structural. Groot is the governance-free resource layer. It is open-source. No one owns it, including us. We hold no special position in Groot's consensus. We cannot change the rules, freeze assets, or exclude participants. These choices cost us the extractive possibilities that every other blockchain creator kept for themselves.
QPQ AG monetises expertise, not the protocol. Through wholly-owned subsidiaries, QPQ IaaS AG and QPQ Capital AG, we commercialise infrastructure services, software tools, and regulated financial services built on top of the resource layer. Open source is free; expertise is not. This is the Red Hat model applied to blockchain: Red Hat never owned Linux, never controlled who could use it, never extracted fees from the operating system itself. Red Hat built the world's most successful open-source company by knowing the system better than anyone else and selling that knowledge. We do the same. Our Gaju Mining SaaS has generated over CHF 1 million in pre-release revenue with zero marketing spend, validating the model before the resource layer has even reached full commercial deployment.60
The snake's question has an honest answer. We do not need to eat the apple because we grow our own food. The resource layer remains governance-free. The commercial entity thrives by serving the community that uses it, not by taxing their participation. The incentives align: QPQ succeeds when the Gajumaru succeeds, and the Gajumaru succeeds when it remains what it was designed to be. The moment we attempted to control Groot, we would destroy the very thing that makes our commercial position valuable.
Why Only One Resource Layer Will Ever Exist
A true resource layer must have no governance to function as a negotiated space between jurisdictions. Any attempt to introduce governance leads to corporatist power struggles, regulatory capture, and control.
Groot is the only governance-free, trustless, proof-of-work resource layer that exists. Everything else requires trust in operators. Bitcoin is an actual blockchain minting real money, but it has no native virtual machines, no smart contract capability, and no connection tooling for infrastructure; it proved the concept but cannot serve as the foundation for a digital economy.61 Ethereum moved to anonymous proof-of-stake, which enables collusion by definition; six entities control over 52% of stake;49 its founder publicly confirmed personal control of the Foundation;50 and its virtual machines and Solidity smart contracts are insecure and dangerous to use commercially. Layer 2 solutions reintroduce centralised sequencers under the pretence of decentralisation, using that pretence to avoid the regulatory oversight their actual architecture demands. Enterprise chains are private consortiums with centralised governance that make no meaningful claim to trustlessness at all.
Consider what it would take to build another governance-free resource layer. The technical requirements alone are formidable. It must be proof-of-work, because proof-of-stake enables collusion by definition; there is no path to a trustless resource layer through a mechanism that concentrates power in proportion to existing wealth. It must have smart contract capability that can be relied upon for major commercial and governmental use, which eliminates both Bitcoin (which lacks it entirely) and the Ethereum model (whose virtual machines and smart contract language have proven insecure and dangerous for commercial deployment). It must match or exceed Groot's efficiency, solving the computational problems that took our team years to resolve, without the accumulated knowledge that produced a system more than 1,846,200 times more transactionally efficient than Bitcoin.
But the technical challenge is not the real barrier. Anyone with sufficient engineering talent and time could, in principle, solve the technical problems. The real barrier is the one this chapter describes: the Garden of Eden problem. The project would need to resist the temptation to monetise the base layer, something no other team has done in over a decade of blockchain development and over $120 billion of investment. Every incentive in the industry pushes toward monetisation. Every venture capitalist asks the same question the snake asks. Every founding team faces the same temptation, and every founding team except one – us – has succumbed to it. The structural discipline required is not a technical specification; it is a sustained act of will against the entire economic logic of the industry that funds you.
Even if a team solved both problems, built the technology and refused the apple, they would face a challenge that compounds with every passing month. They would need years of development before becoming operational, years during which Groot continues to grow, embed network effects, and establish the commercial relationships that make a resource layer valuable. They would need to build genuine participation without resorting to airdrops or token giveaways, methods that create the appearance of adoption without its substance. Platforms can be outbuilt with better features and superior user experience; MySpace gave way to Facebook, AltaVista to Google. But a governance-free resource layer is not a platform. It cannot be outbuilt because the hard part is not the engineering; it is the structural discipline. Anyone who solves the engineering still faces the Garden of Eden problem. The barrier is the temptation, not the technology.
By the time such a competitor arrived, Groot and the Gajumaru would have embedded network effects that are practically insurmountable. This is why the Gajumaru is the only resource layer that will ever exist as a true negotiated space.
https://publications.parliament.uk/pa/cm200001/cmhansrd/vo010322/debtext/10322-13.htm Reproduced in Free at Last: Diaries 1991-2001, Hutchinson, 2002
Part Two: The Architecture
Part One made an argument. It described why the world needs a governance-free resource layer, why intermediaries fail, why choice between governed and ungoverned paths is the mechanism that disciplines both, and why only one resource layer will ever exist.
This part describes what we built. The Gajumaru is not a concept paper or a roadmap. Groot, the resource layer at its core, has been operational since 22 October 2024, processing real transactions, minting real money, secured by real proof-of-work.
We said at the outset that this is not a technical document. The Gajumaru's architecture, consensus mechanisms, and protocol specifications are documented in the Technical Paper, and that paper remains essential reading for anyone who needs to verify the engineering at depth. These chapters do not replace it. What they do is explain the same architecture in terms that any informed reader can follow: what the system does, how it does it, and why each design choice was made the way it was. This is the version of the technical papers for people who will never read the technical papers. You should not need a computer science degree to understand why this matters or how it works; we intended this to be read and understood by anyone who takes the time to read it.
Chapters V through VII address the system architecture: the Groot resource layer, the Gaju as sound money, and how the Gajumaru works as a connected system of resource layer and Associate Chains.
Chapter VIII addresses the security architecture: quantum resistance, the Generalised Accounts framework, and the GRIDS protocol.
Chapters IX through XI address the commercial architecture: the decentralised exchange – including QPQ's KPoS Associate Chain as a proof of concept for the TEA trilemma standard any Associate Chain should meet – QPQ's products and services, and the open innovation model that ensures the resource layer remains open permanently.
V. Groot Resource Layer
What Groot Is
Groot is the resource layer described in Part One: a governance-free, proof-of-work blockchain with no operator, no foundation, and no one who can deny access. It is the high seas of the digital economy. You can operate there, less efficiently than on governed infrastructure, but with the certainty that no human authority controls access, freezes assets, or changes the rules.
Everything in the Gajumaru system connects to Groot. Associate Chains connect to it and through it, settle cross-border value transfers. The Gaju currency is minted exclusively on it. Groot is not the layer where most economic activity will occur; that is the role of Associate Chains, which offer the efficiency that governance enables. Groot is the foundation that makes all of it trustworthy: the neutral ground, the exit option, the control that disciplines every governed layer above it.
This chapter explains how it works.
Why Proof of Work
The core test for any blockchain is simple: does it allow you to trust the message rather than the messenger, securely at scale? If you must trust someone for the system to work, it is not trustless. It may be useful, it may be efficient, but it is not a resource layer. It is infrastructure with a different name.
Proof-of-work is the only mechanism that passes this test, and it does so because of three properties that no other consensus mechanism shares.
First, the expenditure is physically irreversible. When a miner solves a computational puzzle, the solution represents real energy consumed, real computation performed in the real world. That expenditure cannot be faked, because the mathematics would not check out. Stake is a digital claim that can be moved, split, or hidden. Work is a physical fact.
Second, the commitment is exclusive. The same hardware cannot mine on two competing versions of the chain simultaneously. Miners must commit their resources to one version of the truth. In proof-of-stake, validators can sign multiple competing forks at zero additional cost: the "nothing at stake" problem. In proof-of-work, choosing one fork means physically forgoing the other. The commitment is real.
Third, concentration is extraordinarily difficult to hide. Assembling more computing power than the rest of the network requires physical hardware, physical energy, and physical space: resources whose concentration is visible, measurable, and bound by the laws of physics. In proof-of-stake, the same entity can distribute holdings across pseudonymous wallets invisibly. Concentration – control – hides.
Anyone can then verify a solution independently and instantly. You do not need to know who the miner is. You do not need to trust their reputation, their stake, or their good intentions. The message carries proof of physical cost, not proof of a promise.
Proof-of-stake (a system where validators are chosen in proportion to the coins they hold) cannot do this. You must trust that those validators will act honestly, because their authority comes not from demonstrable work but from a claim of economic commitment. Wealth concentration becomes power concentration. A small number of large holders can collude, and you have no mathematical proof that they have not. You are trusting messengers.
Governance cannot do this either. The moment a foundation, a committee, or a set of identifiable operators can change the rules, pause the system, or deny access, you are trusting their judgement, their integrity, and their continued benevolence. You are trusting messengers.
Only proof-of-work produces a system where the output can be verified without trusting anyone who produced it. Every other consensus mechanism reintroduces trust in people at some point in the chain, and trust in people is exactly what a resource layer must eliminate. These properties alone make proof-of-work the strongest foundation for trustlessness. But they are necessary, not sufficient. A proof-of-work chain whose protocol can be altered by a foundation, a developer team, or a governance vote is still controlled infrastructure. The Gajumaru's settlement mechanism and its approach to protocol sovereignty, both described below, complete what proof-of-work begins.
Proof-of-work has drawn criticism. It consumes energy. Bitcoin's implementation, specifically, consumes vast amounts of energy because Bitcoin's puzzle rewards brute computational force, which drove an arms race in specialist hardware. The criticism is legitimate when directed at that specific implementation. It is not legitimate when applied to proof-of-work as a principle. As the next sections explain, the Gajumaru's proof-of-work operates at a fundamentally different efficiency: Groot is over 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation, running on consumer hardware that draws less power than an incandescent light bulb. The energy objection to proof-of-work is an objection to Bitcoin's implementation, not to the mechanism itself.
How Mining Works
Mining is a competition. Miners compete to solve a computational puzzle. The first to find a valid solution wins the right to lead the network temporarily: to add the next group of transactions (a 'block') to the chain and to receive newly minted Gajus as a reward.
Each attempt at solving the puzzle is like a lottery ticket. Every ticket has an equal chance of winning, but the odds per ticket are very low. The combined computing power of all miners on the network is expected to produce a winning ticket once every two minutes. If more miners join, the puzzle gets harder to keep that rate steady. If miners leave, it gets easier. The system self-adjusts.
This competition is what makes the system trustless. You do not need to trust the miner who adds your transaction, because the puzzle proves they did the work required to earn the right. The work itself is the proof. No reputation, no identity, no permission required.
The Gajumaru's Puzzle: Cuckoo Cycle
Bitcoin's puzzle (SHA-256) rewards raw computational speed. Miners who invest in faster processors gain an advantage, which led to specialist ASIC chips (purpose-built processors designed solely for mining) costing millions and consuming industrial electricity. The puzzle became an arms race won by whoever could build the biggest, most power-hungry hardware.
The Gajumaru uses a different puzzle called Cuckoo Cycle. Instead of rewarding processor speed, Cuckoo Cycle is a pathfinding problem that rewards memory access speed. The miner's computer generates a very large map from a seed number, and the task is to find a path through that map that forms a cycle of a specified length. Not every map contains such a path, so the miner may need to generate many maps before finding one that works. Once found, anyone can regenerate the same map and verify the path instantly.
The critical difference: memory is memory. You cannot build a specialist chip that is dramatically faster at memory lookups than the RAM in an ordinary laptop. This is why a Gaju miner runs on consumer hardware drawing 60-100 watts, while a Bitcoin miner requires purpose-built ASIC hardware drawing 3,500 watts per unit. Mining stays distributed across ordinary computers rather than concentrating in industrial warehouses.
How Bitcoin-NG Consensus Works
A blockchain records transactions in batches called "blocks," each cryptographically linked to the one before it to form a tamper-proof chain. In Bitcoin, each block serves two purposes at once: it proves the miner did the work to earn the right to lead, and it carries the transactions themselves. The network waits approximately ten minutes for each puzzle to be solved and the next block produced. This wastes the proof of work if the block has few transactions, and limits throughput (the number of transactions the system can process per second) if it is full. Users must wait for their transaction to be included in a block, a process that takes ten minutes at best and considerably longer during congestion.
The Gajumaru uses Bitcoin-NG (Bitcoin Next Generation), which applies the same separation of concerns that distinguishes Groot from Associate Chains: give each function its own structure, so neither compromises the other. Bitcoin-NG separates proof of work from transaction processing into two distinct structures. A "keyblock," produced approximately every two minutes, carries only the proof of work: it contains no transactions, but establishes which miner leads the network for the next period. That leader then produces rapid "microblocks," approximately every three seconds, containing the actual transactions. A keyblock and its subsequent microblocks together form a "generation."
The result: more transactions processed per unit of proof-of-work, and far lower latency (waiting time) for users. Transactions appear on-chain in seconds rather than waiting ten minutes for the next block. The security guarantee remains identical to Bitcoin's model; only the efficiency improves.
Witnessing: How Settlement Accelerates
In a standard proof-of-work blockchain like Bitcoin, confidence in a transaction grows slowly. Each new block stacked on top makes it progressively harder for an attacker to rewrite the chain, but the process takes time: Bitcoin convention treats six blocks – approximately one hour – as the minimum threshold for low-value transactions. For higher values, the same economic calculation that governs settlement on any proof-of-work system demands more blocks, more time, and more waiting – with no finality endpoint. The settlement window on Bitcoin never closes. An attacker with sufficient resources and sufficient patience can always, in theory, succeed.
The Gajumaru accelerates this through its patented witnessing protocol. The mechanism is structurally distinct from other blockchain approaches because of a property unique to Bitcoin-NG: keyblocks carry no transactions. They are purely structural, proving work and establishing leadership. The witnessing system operates on these content-free keyblocks.
Designated witnesses attest to keyblocks as they are produced. If the keyblock is on the majority fork (the version of the chain accepted by the most miners), witness testimonies accrue quickly and are recorded in the next keyblock. This lends settlement certainty to the entire preceding generation of transactions. For receivers who require the highest certainty before acting, the following keyblock also needs to be settled, yielding a settlement time of 1-3 minutes. At 2 keyblocks – 3, at most, 4 minutes – absolute finality arrives for any transaction regardless of value: the protocol closes and the record cannot be altered by any means.
What this Means for Liability and Trust
Witnesses attest only to chain structure, not to transaction content. There is no risk of accidentally "approving" questionable content, no conflation of transaction selection with validation, and clean liability separation that eliminates the collusion risk present in validator pools that both produce and validate content. From a regulatory perspective, purely structural validation is far cleaner than systems where validators stamp approval on both structure and content simultaneously.
Graceful Degradation
If insufficient witnesses are reachable (for instance, during a network partition), the fallback is longest-fork-wins, the standard for proof-of-work. The chain continues to operate. It flags to users that they should exercise more caution, but it does not stop. Availability is maintained.
Settlement: How Certainty Works
Settlement and finality are related but distinct, and conflating them is one of finance's oldest habits. Settlement is an economic calculation: a receiver decides, based on the value at stake and the certainty accumulated to that point, that the cost of reversing a transaction has made doing so irrational. Finality is something categorically different: the point at which reversal is not merely irrational but structurally impossible. Every payment system has settlement of a kind. Almost none has finality.
On Groot, both are defined by mathematics rather than institutional promises. Settlement certainty accumulates from the moment a transaction is included in a microblock and each subsequent microblock until the keyblock is completed and the next initiated. As each microblock is added, reversing a transaction becomes computationally more expensive, and that cost rises continuously from the moment the transaction appears on-chain. Finality arrives at two keyblocks: four minutes at most, the point at which the protocol closes and the record becomes absolute and irrevocable.
To understand why this distinction matters – and why the honest acknowledgement of probability in settlement is a strength rather than a weakness – it helps to look at how certainty actually operates in the systems you already trust with your life.
The Certainty Illusion
Almost everything is probabilistic. We simply do not think about it.
The CDC estimates that 48 million Americans contract a foodborne illness every year: roughly one in six.62 You eat three meals a day without conscious risk assessment. Every year, 128,000 of those cases result in hospitalisation and 3,000 in death. You do not inspect the kitchen. You do not calculate the odds at each meal, you eat.
The combined oral contraceptive pill, taken with perfect adherence, has a failure rate of approximately 0.3% per year.63 The mental model is binary: on the pill equals not pregnant. Over a decade of perfect use, the cumulative probability of at least one unintended pregnancy approaches 3%. With typical use, it exceeds 50%. People plan their lives around a certainty that does not exist.
Courts, juries, and the public treat fingerprint identification as deterministic proof of identity. The FBI has historically testified to "100 percent certainty" on matches. In mandatory proficiency testing involving close non-match comparisons, false-positive error rates were 15.9% and 28.1% respectively.64 In the 2004 Madrid train bombing case, the FBI matched a fingerprint found on a bag of detonating devices to an Oregon lawyer who had never left the United States; Spanish authorities later identified the actual suspect, an Algerian national.65 Misapplication of forensic science contributed to 52% of wrongful convictions in Innocence Project cases.66
You collect a prescription, go home, and swallow whatever is inside the bag with your name on it. A 2024 systematic review of 62 studies found a worldwide dispensing error rate of 1.6%: approximately one error in every sixty prescriptions.67 In the United States, an estimated 51.5 million dispensing errors occur annually across approximately 3 billion prescriptions. Between 7,000 and 9,000 patients die each year from medication errors.68
Every time you get into a car, you treat the journey as a certainty of safe arrival. There are approximately 240 million registered vehicles and roughly 6 to 6.5 million police-reported crashes per year in the United States: a 2-3% annual probability that any given driver will be involved in a reportable crash. For a regular commuter over a 40-year career, the cumulative probability of being involved in at least one significant crash approaches near-certainty. Seatbelts reduce the probability of being killed by 40-50% for front-seat occupants69; in 2017, they saved nearly 15,000 lives.70 Roughly 37,000-40,000 Americans still died in traffic crashes that year. The seatbelt is a probabilistic mitigation of a probabilistic event, yet the mental model is: belt on, safe, certain. Globally, the WHO estimates that approximately 1.19 million people die in road traffic crashes every year.71
In every one of these cases, the human cognitive shortcut of rounding high probability up to certainty is individually rational. You cannot eat, drive, take medicine, or have sex if you are paralysed by the residual risk every time. The rounding is not a failure of intelligence; it is a feature of cognitive architecture that allows humans to function in a world of pervasive, low-probability risk.
But the rounding is not costless. At population scale, the residual probability generates enormous real-world harm: 48 million food-borne illnesses per year, 51.5 million pharmacy dispensing errors, roughly 6 million car crashes, thousands of wrongful convictions, millions of unintended pregnancies. Each of these is a direct consequence of the gap between the probability and the perceived certainty. The harm is structurally predictable and quantifiable. It is the tax levied by the rounding error, paid by whichever individuals happen to fall within the residual probability in any given year.
Here is the deeper point. From an economic and systems-design perspective, humans are remarkably good at converting "very high probability" into "certainty" in their mental models. This is cognitively efficient but occasionally catastrophic. The difference between "almost certainly right" and "provably right" is, at population scale, the difference between systemic harm and systemic integrity.
The Same Illusion in Finance
We treat centralised financial systems with the same cognitive shortcut. When your bank shows a balance, you treat it as fact. It is not. In June 2012, a failed software update at the Royal Bank of Scotland Group froze 12 million customer accounts across RBS, NatWest, and Ulster Bank.72 Over 6.5 million customers in the United Kingdom could not access their money for weeks; mortgages went unpaid, wages were delayed, home purchases collapsed, and a backlog of 100 million unprocessed payments accumulated within days.73 The "confirmed" balance on a credit card transaction is a promise, not settlement: the actual funds will not move for days, and the transaction can be reversed for weeks or months through chargeback. Wire transfers can be recalled. Court orders can freeze or redirect funds after they appear settled. In 2024, criminals successfully stole £1.17 billion through banking fraud and scams in the United Kingdom alone.74 "Finality" in centralised finance is not mathematical certainty. It is trust that the institution will get it right, and that someone will fix it when it does not. That trust fails more often than most people realise.
How Settlement Works on Groot
A system architecture that can close the gap between "very high probability" and "provable certainty" generates compounding value at scale. On Groot, that gap closes faster than in any comparable system – and then, at two keyblocks, closes entirely. This is why we – accurately – describe Groot as the world’s fastest payment system: settlement certainty and ultimate finality are core, but often conveniently ignored components of the economic reality.
Settlement on Groot is driven by two components working together. Technical certainty accumulates as each new microblock makes reversing a transaction computationally more expensive: the proof-of-work required to rewrite the chain grows with every block added above it. Economic certainty accumulates as the cost of mounting that attack increasingly exceeds the value of the transaction being attacked. For a $5 coffee, economic certainty arrives within seconds: no rational attacker spends more than a coffee costs to steal one. For higher values, technical certainty continues to accumulate until the mathematics make reversal not merely expensive but absurd. Both components are mathematical, independently verifiable, and stated openly – unlike the institutional assurances that pass for certainty in the systems described above.
For most receivers, one keyblock is the rational point of settlement for even the highest transactional values: the mathematical certainty accumulated to that point exceeds anything the systems described above can offer, and the cost of reversal has made the transaction economically irreversible without recourse to any intermediary. At two keyblocks – four minutes – something categorically different happens. The probability curve does not reach a very high number – it ends: this is finality. This is the structural protocol guarantee that no transaction older than two keyblocks can be ejected by any means – not even by an attacker commanding unlimited computing power. Unlike the food, the pill, the car, and the bank balance, which remain probabilistic indefinitely, every transaction on Groot achieves absolute, irrevocable finality within four minutes.
What This Means in Practice
The following examples are illustrative of how the model works in practice; the exact certainty for any given transaction will depend on network conditions. One of the features we will implement in GajuDesk and GajuMobile is a ‘traffic light’ indicator that calculates real-time certainty from all detectable network factors, displaying a clear visual signal when a transaction has reached a defined threshold – making the mathematics operationally intuitive for any user.
A $5 cup of coffee
You pay the teller with your GajuMobile wallet.
Within 2-3 seconds the transaction appears in a microblock and you see the witnesses have already confirmed the preceding keyblock is on the path to finality. The ‘traffic light’ indicator turns green.
For a coffee, that’s enough. Functional settlement is immediate. Reversing it would require an attacker to overpower the entire network in the next few seconds, an absurdly expensive and almost impossible task.
The barista hands you your coffee; you walk away. Done.
A $5,000 family holiday package
You pay the travel agent with your GajuMobile wallet.
Within 2-3 seconds the microblock appears and witnessing looks good. By the time you’ve slid your phone back into your pocket (usually well under 2 minutes) the next keyblock arrives and finalises the previous keyblock (locking in the leader who produced your microblock).
At this point your transaction has extremely strong mathematical protection — far beyond the credit-card payment you made yesterday, which still won’t actually settle for days and can be reversed for months. Here, no bank, no chargeback, no “pending” limbo. The travel agent can start commit your booking immediately – they have been paid with certainty, your money is in their account.
A $50,000 car purchase
You pay at the dealership, again with your GajuMobile wallet.
Within 2-3 seconds the microblock appears and witnessing is solid. Long before the salesperson has finished the paperwork (around 2 minutes) the next keyblock lands and finalises the previous keyblock.
The dealer now has extremely high certainty that no chargeback, no reversal and no intermediary failure can touch the funds.
At 4 minutes, likely still while the dealer is completing the paperwork, the transaction has settled with absolute certainty and finality. The money is theirs, the car is yours.
A $500,000 house purchase
You authorise the transfer.
Within 2-3 seconds the microblock appears and witnessing signals are strong. After the first keyblock (around 2 minutes) the previous keyblock is finalised (the leader’s epoch is locked). After the second keyblock (total around 4 minutes) the chain has advanced far enough that the microblock (and your transaction inside it) is irrevocably sealed – mathematically impossible to evict or reverse.
By the time the solicitor or conveyancing agent closes the laptop, the money is as settled as it is ever going to be — far more reliably than traditional conveyancing, where funds can take hours, even days to “clear” and the entire process depends on trust in multiple intermediaries, any one of which can fail.
What happens in the rare case of a micro-fork?
Very rarely, due to network latency or a slow miner, a new keyblock might be based on an older microblock, briefly orphaning your transaction and returning it to the mempool. In practice this resolves within seconds as the new leader quickly re-includes it. The traffic light signal simply pauses on amber for a few extra seconds then turns green. Most users will never notice.
At every stage, the value sits on a trustless layer requiring no third party's cooperation.
No bank can freeze it. No intermediary can reverse it. No software update can make it disappear. The certainty is mathematical, not institutional because the maximum possible attack window is only 2–4 minutes instead of an hour or more. Therefore, the computing power needed to even try a reversal is enormous – which is why, in normal operation, it simply doesn’t happen.
That’s the difference Groot makes. For low- and medium-value transactions you barely wait at all. For big ones you wait minutes instead of days – and you always know exactly when it’s safe, because the traffic light indicator displays a clear visual signal when a transaction has reached a defined threshold of certainty with absolute finality at 4 minutes, regardless.
The reality is this: you routinely act on far lower levels of certainty, in situations where being wrong could kill you, without a moment's hesitation. You eat the meal. You swallow the pill. You drive around the blind corner. You trust probabilities with your life every day and call them certainties. Proof-of-work settlement on Groot reaches the certainty levels you already act on within seconds for most commerce and within minutes for the highest-value transfers – verifiably, mathematically, openly. At two keyblocks, every transaction achieves absolute, irrevocable, trustless finality, something that is beyond most if not all of the systems we rely upon today.
Why Compressed Settlement Is Also a Security Property
Bitcoin operates on the same two components in principle – accumulated proof-of-work and the economic calculation of attack cost relative to transaction value – but the comparison ends there. Its 10-minute block interval means six blocks – one hour – is merely the convention for low-value transactions. As transaction value rises, so does the number of blocks a prudent receiver must wait for: hours for a car purchase, days or weeks for a house or a large commercial transfer. Regardless of how long you wait, the settlement window never closes – Bitcoin cannot provide absolute finality.
The Gajumaru's combination of 3-second microblocks, 2-minute keyblocks, and the witnessing protocol compresses this to seconds for commerce, 1-2 minutes for high-value transfers, 4 minutes for irrevocable, trustless certainty, a structural guarantee Bitcoin cannot offer at any price.
This compression has a security consequence that goes beyond speed. As described above, proof-of-work is trustless because the physical expenditure is irreversible, the hardware commitment is exclusive, and concentration is difficult to hide. But on Bitcoin, an attacker has unlimited time: a mining pool can slowly accumulate hashrate (total computing power applied to mining) dominance over months and build a competing fork over days, because the settlement window never closes. On the Gajumaru, the witnessing protocol closes that window within minutes. An attacker must assemble superior computing power, keep it hidden, and bring it all to bear within a window too short and too statistically hostile to offer reliable success. Before two keyblocks, the attack is economically irrational. At two keyblocks, economic calculation becomes irrelevant entirely. The protocol has closed. The state is absolute and irrevocable: not because an attack would be expensive, but because the architecture no longer permits one.
The Arithmetic of the Short Window
The security advantage of Groot's witnessing-based finality is not merely qualitative. It is measurable, and the measure is significant.
The standard model for blockchain security analysis asks a precise question: how much excess computing power must an attacker command, relative to the honest network's total, to have a reasonable probability of executing a successful double-spend? A double-spend is the canonical attack: spend coins, have the transaction confirmed, then reveal a secretly-built alternative transaction history that erases the payment and returns the coins to the attacker. Higher excess requirement means a harder attack – and a harder attack means the same level of security can be maintained with a smaller mining pool.
The excess requirement is expressed as a ratio: attacker's required power divided by honest network power. The higher that ratio is, the more the network resists attack per unit of mining power deployed.
Bitcoin's ratio – the one-hour window – Bitcoin's conventional settlement threshold for low-value transactions is six blocks: approximately one hour. The attack is a siege. The attacker quietly builds an alternative transaction history in parallel with the honest network, accumulating advantage gradually. Because the window is long, statistical variance – the randomness of individual mining events – averages out; the attacker can rely on sustained superior hashrate to eventually prevail. To achieve an 80% probability of success, using the Poisson distribution (the standard mathematical model for the random timing of mining events) to compute the attacker's expected block production over the window: the attacker needs approximately 1.51 times the honest network's total computing power.
Groot's ratio – the four-minute window – On Groot, the witnessing protocol closes the window within four minutes: two keyblocks at most. The attacker cannot run a siege. They must arrive with superior force and win immediately, producing a longer competing chain in real time. In a four-minute window, the expected number of keyblocks is two. Statistical variance becomes the attacker's enemy: with only two events in the window, the randomness of proof-of-work creates enormous uncertainty. There is no time for sustained advantage to average out.
Computing the success probability as the sum, across all possible honest chain lengths, of the probability that the attacker produces strictly more keyblocks than the honest network in the same window – and solving for the attacker fraction where this reaches 80% – the attacker must command approximately 12.45 times the honest network's total computing power.
The ratio between the ratios 12.45 / 1.51 ≈ 8.23.
Groot's network achieves the same resistance to double-spend attack at 8.23 times lower cost in mining power than Bitcoin. An attacker who could mount a credible attack on Bitcoin with a given quantity of computing resources would need 8.23 times those resources to mount an equivalent attack on Groot. The same architectural choices that produce 1,846,200-fold transactional efficiency deliver stronger attack resistance. The witnessing protocol serves both purposes simultaneously.
The high-value case
For significant transfers, many institutional receivers apply a six-hour settlement window rather than one hour, because Bitcoin's probabilistic certainty only ever approaches but never reaches finality regardless of how long you wait. Over six hours – thirty-six blocks – Bitcoin's attacker excess requirement falls to approximately 1.17: the longer the window, the more sustained superior hashrate is sufficient. Groot's ratio remains fixed at 12.45. Every transaction, regardless of value, achieves absolute protocol closure at two keyblocks.
At the six-hour Bitcoin comparison: 12.45 / 1.17 ≈ 10.6.
The higher the value of the transaction – and therefore the longer a prudent receiver must wait on Bitcoin – the larger Groot's security advantage becomes. Groot's finality is not a probability that improves with waiting. It is a protocol guarantee that arrives within four minutes regardless of what is being settled.
Protocol Sovereignty: The Path to a Finished Protocol
Proof-of-work provides trustless consensus. Compressed settlement makes attacks before two keyblocks economically irrational – the window is too short and the variance too large for any attacker to rely on success. At two keyblocks, economic calculation becomes irrelevant entirely: the protocol has closed and the architecture no longer permits an attack regardless of the resources brought to bear. But neither is sufficient on its own because if the protocol itself can be altered by a foundation, a developer team, or a governance vote, you have trustless block production inside a governed system. The consensus is trustless; the protocol is not. Someone can still change what the consensus operates on.
This is not a theoretical concern. The history of blockchain is littered with examples. Ethereum had proof-of-work; the Ethereum Foundation governance process moved it to proof-of-stake, fundamentally changing the system's trust model. Aeternity used the same Cuckoo Cycle proof-of-work as the Gajumaru; governance decisions led to its decline. Litecoin has proof-of-work, but a small group of developers manages its direction. Bitcoin has proof-of-work, but the BIP process, core developer gatekeeping, and the block size wars demonstrate that human governance operates around and above the protocol. In each case, trustless consensus was undermined by governed protocol management. The pattern is consistent.
The distinction matters: trustless block production (no trust required to validate a block) versus protocol sovereignty (no mechanism exists within the protocol for anyone to change the rules by authority). A resource layer requires both.
Groot is designed to reach protocol sovereignty: a state where no embedded governance mechanism allows any party to alter the protocol rules. No foundation holds tokens. No governance vote can change parameters. No privileged upgrade path exists. Changes can only propagate through voluntary adoption by miners who have no obligation to accept them.
Construction, Not Governance
Groot has not yet reached that state. It is operational, processing real transactions since October 2024, but QPQ retains control over mining access during the build-out period. This is construction, not governance. You do not open a bridge to traffic while you are still welding the girders. Once the mining software is open-sourced under GPL3 (an open-source licence requiring that modifications remain freely available) and protected mining ends, QPQ loses the ability to push coordinated updates to the chain. Everything must be right before that moment.
The mechanism is worth stating precisely, because it explains why the whitelist period is architecturally necessary rather than merely cautious.
It is not a governance period. Groot has no governance at any point in its existence: no foundation, no committee, no decision-making authority over the protocol. The mining process runs on immutable smart contracts deployed on-chain. QPQ cannot alter them once operative – the rules they encode are set in stone. Only the miner can withdraw their own accumulated Gaju. That is encoded in the contract, not in QPQ's discretion.
What QPQ operates during this period is the Hive structure: a coordination layer that allows development updates to the mining software to reach miners without being rejected by those running older versions, which would fork the chain. That is the entirety of what we control – and it is not the chain. It is the software that connects miners to it. Anyone who holds a Gaju Mining licence can mine. We do not select participants. We do not filter by geography, technical competence, or connection to QPQ.
When the mining software is open-sourced under GPL3 and public mining begins, that coordination structure ceases to exist permanently. Any proposed change after that date can only propagate through voluntary adoption by miners who have no obligation to accept it. Miners who do not adopt a proposed change do not stop mining. They continue mining their version of the protocol. The chain forks. Two chains exist, each with its own community, each valid under its own version of the rules.
This is not a temporary vulnerability that can be managed with good governance after the fact. It is the proof that Groot has genuinely passed from its creators to the world. No foundation established after public mining can coordinate a mandatory update. No developer group can push a change that miners are required to implement. The pattern – Ethereum Foundation, Litecoin's developer group, Bitcoin's core maintainers and BIP process – all represent precisely this: governance mechanisms operating around and above a protocol that cannot itself enforce compliance. QPQ will establish none of these structures. The corollary is therefore absolute: everything must be architecturally complete before that moment arrives.
This also means that the scope of what Groot does at the base layer is determined by the development plan, and the development plan ends when public mining opens. Features that would require base-layer updates after public mining are not features that can be added to Groot. They are features that belong at the Associate Chain or platform layer – where updates can be coordinated by governed operators, where the trade-off between trust and functionality is explicit, and where innovation can proceed without forking risk to the foundation beneath it.
The timeline is explicit. Main Net launches in April 2026: the full protocol, open to inspection and use, with mining access still managed during the final build-out. Protected mining ends with a target of 30 March 2027 and an outer boundary of 30 September 2027. The scope of work is fixed; the only variable is whether the resources to complete it arrive on the optimal schedule. The load on a small core team delivering work of this ambition is substantial, and we are honest about that rather than making promises we cannot guarantee. The planned work will be completed within these timeframes. On that date, the mining software is open-sourced, the Gajumaru opens to fully public mining, and Groot passes from its creators to the world. Not because a foundation votes to allow it, but because the design always intended it.
A Finished, Sovereign Protocol
After that transition, Groot is a finished protocol. Not abandoned, architecturally complete. Maintained, defended, supported by QPQ's commercial services and by every user, developer, and business whose work touches the Gajumaru. The base layer does what it needs to do and does not need to evolve to serve its purpose. A resource layer that keeps changing under someone's direction is not a resource layer. It is infrastructure under active management. Stability is the architectural feature that makes Groot trustworthy as a foundation for everything built above it.
The architecture delivered at public mining opening is not a first version awaiting improvement. It is the completion of a specific, finite task: building a governance-free resource layer that works, permanently, without further instruction from its creators. The development plan has a terminus by design.
Phase 2 – from Main Net to public mining – completes the full scope: completion of all aspects of GajuDEX, deployment of GajuMobile with GRIDS and real world assets on-chain – no more requirement for third party intermediation.
Together these deliver not only money sovereignty – the restoration of sound, undebasable currency to individual control – but asset and data sovereignty: real-world assets represented on-chain without recourse to intermediaries, private data remaining private in a data-driven economy. These are the three dimensions of individual sovereignty that economic emancipation requires. The development plan is structured to deliver all three before the protocol passes permanently to the world.
From Main Net, everything is open. The protocol is public. The tools are open-sourced under GPL3. Anyone can build on the resource layer, deploy Associate Chains, create platforms and applications, and compete directly with QPQ to deliver better, more valuable services. QPQ holds no privileged position in Groot's consensus and no gatekeeping role over who participates. Our commercial position depends on being better at serving the community that uses the system, not on controlling access to it. If someone builds a superior mining service, a better wallet, a more compelling marketplace, they win. That is the point.
Innovation moves to Associate Chains. That is where evolution belongs, building upon a foundation that does not shift beneath it. No one redesigns the bedrock to improve the building; you improve the building because the bedrock is reliable. New consensus mechanisms, new tooling, new cryptographic schemes, new commercial models: all of this happens at the infrastructure layer, where governed operators can iterate, experiment, and adapt at their own pace without disturbing the foundation that connects them. Groot provides the stable backbone they build on and the trustless exit option that disciplines them. Stability is the feature. The primary forum for economic activity is not the resource layer; it is the governed infrastructure above it, disciplined by the resource layer below.
Stability does not mean stagnation. Groot is engineered to the limits of what proof-of-work can achieve without compromising trustlessness: more than 1,846,200 times more transactionally efficient than Bitcoin, with settlement compressed to seconds. The protocol provisions for changes we can foresee, including post-quantum cryptographic migration, without requiring governance to implement them. Section VIII examines the quantum-resistant architecture and the Generalised Accounts framework (accounts upgraded from standard authentication to custom smart-contract-based authentication) that enables cryptographic evolution without protocol change.
The point here is the principle: a resource layer built to endure does not need to keep evolving. It needs to have been built correctly in the first place.
Performance Specifications
The preceding sections describe what makes Groot trustless: proof-of-work that requires no trust in validators, compressed settlement that closes the attack window to minutes, and protocol sovereignty that ensures no party can alter the rules. The question that follows is practical: what does that architecture actually deliver, how are the numbers derived and what do they mean for people?
| Specification | Value |
|---|---|
| Consensus | Bitcoin-NG with Cuckoo Cycle proof-of-work + QPQ patented witnessing protocol (explained above) |
| Efficiency vs Bitcoin | >1,846,200x (transactional); ~249,000,000x (minting, Period 1) |
| Base Layer Throughput | >300 TPS (transactions per second) |
| Block Time | ~3 seconds (microblocks); ~2 minutes (keyblocks) |
| Settlement | 2-3 seconds – 120 seconds (99% – 99.9999% certainty, value-dependent, commerce-grade); 3-4 minutes (finality, absolute mathematical certainty for any value) |
| Smart Contracts | Sophia language on FATE VM (functional smart contract tools designed for safety; explained below) |
| State Channels | Hardware-limited per channel: 40-50 contract calls/s; 500+ token transfers/s; 3,000+ plain messages/s. 1,000+ concurrent channels per node; scales linearly with nodes. No mandatory fee. (Off-chain sessions secured by on-chain contracts; explained below) |
| Operational Since | 22 October 2024 |
Transactional Efficiency
How much less work does Groot require to process and settle a transaction compared to Bitcoin? The answer compounds four independent architectural decisions, each measurable, each verifiable, each a clear step in the process:
Step 1: Bitcoin-NG Decoupling (92.31x) Bitcoin-NG decouples leader election (key blocks every 120 seconds) from transaction serialisation (micro-blocks every 3 seconds).
Gajumaru’s Groot amortises into one mining cycle at least 300 TPS, so we have more than 36,000 transactions (300 X 120). Over 10 minutes, more than 180,000 can be processed.
On Bitcoin, a mining cycle is ≈10 minutes = 600 seconds, amortised over ≈3.25 TPS, so we have 1,950 transactions (600 X 3.25).
(180,000 / 1,950) = 92.31x Test – TPS ratio – 300/3.25 = 92.31x
Multiplier: 92.31x
Running Total: 92.31x
Step 2: Blockchain Inclusion Latency (200x) Settlement: Bitcoin inclusion is 1 block, ≈600 seconds, Gajumaru inclusion is 1 microblock, ≈3 seconds. Inclusion is not settlement. Bitcoin convention treats six blocks – one hour – as the minimum settlement threshold for low-value transactions; for higher values, prudent receivers wait longer, with no finality endpoint at any value. On Groot, Gajumaru's innovative witnessing-based finality makes a microblock confirmation a very strong indicator that the transaction will shortly be fully secured on-chain. In the vast majority of use-cases, a user will be content to wait for microblock confirmation and verify that witnessing is working normally.
(600 / 3) = 200
Multiplier: 200x
Running Total: 92.31 x 200 = 18,462x
Step 3: Computational Security (10x) In a standard proof-of-work system, an attacker with a slight mining power majority (controlling more than half of the network's total computing power) can stealthily build a competing fork (an alternative version of the transaction history) over an extended period, potentially days, and eventually reveal it to trigger a chain reorganisation (forcing the network to accept the attacker's version and erase legitimate transactions). The probabilistic nature of pure PoW allows the attacker to catch up with certainty given enough time. This forces the network to maintain enormous total mining power to ensure no plausible attacker can reach 50% of the network's computational power. The Gajumaru's witnessing protocol changes this calculation fundamentally. Transactions in Groot are final after two keyblock confirmations, with a 4-minute upper bound. Deep reorganisations are impossible beyond this short window. An attacker cannot accumulate advantage over hours or days; they must overtake the chain within minutes. Chains without settlement guarantees need enormous mining power to make sustained attacks uneconomical. Chains with fast settlement can be secure with a fraction of that mining power.
The reason is statistical. Block production in proof-of-work follows a Poisson process (a pattern where events occur randomly and independently at a known average rate, like radioactive decay or buses arriving at a stop). A miner controlling 51% of the network's mining power, on average, find more blocks than everyone else combined. But "on average" requires time to assert itself. Over hours and days, the law of large numbers guarantees the majority miner wins. Over minutes, randomness dominates. In any short window, the actual number of blocks a miner produces varies significantly around the expected average; a 51% miner might find zero blocks in a given two-minute span while a 30% miner finds two. This variance (the degree to which actual outcomes scatter around the expected average) is inherent to the Poisson process and cannot be engineered away. The shorter the window, the larger the variance relative to any hashrate edge. A slight majority that converges to certain victory over a weekend becomes an unreliable coin-flip over four minutes. The attacker is no longer grinding towards an inevitable outcome; they are gambling on a sprint where the odds barely favour them and a single unlucky interval means the window closes and their entire investment in secret mining is wasted. That is why compressed settlement translates directly into reduced mining power requirements: the attack that matters is so much harder per unit of time that the network needs far less total mining power to make it uneconomical. The corollary for Bitcoin is not merely an efficiency observation: an open settlement window transforms the Poisson variance from a defender's friend into an attacker's guarantee. Given sufficient resources and unlimited time, the law of large numbers works in the attacker's favour. A 51% attack on Bitcoin does not require luck. It requires patience. That is a structural security vulnerability, not a performance characteristic.
Multiplier: 10x
Running Total: 92.31 x 200 x 10 = 184,620x
Step 4: Cuckoo Cycle Memory-Latency Bound (10x – 50x) Memory-bound proof-of-work is efficient on commodity hardware versus SHA-256's compute-bound approach. Bitcoin's SHA-256 mining requires specialist ASIC hardware consuming thousands of watts. Gajumaru's Cuckoo Cycle runs efficiently on the kind of RAM found in ordinary laptops and desktops, requiring 10-50x fewer total CPU instructions per solution at equivalent security.
Multiplier: 10x – 50x
Running Total (10X): 92.31 x 200 X10 X10 = 1,846,200×
Running Total (50X): 92.31 x 200 X10 X50 = 9,231,000x
Final Total: 1,846,200 – 9,231,000x more efficient than Bitcoin for transactional efficiency on a standard retail transaction
Minting Efficiency: A Different Calculation
The 1,846,200x figure measures transactional efficiency: the total work required to process and settle one transaction. Minting a coin is a different activity.
Coins are created as block rewards when a miner wins the proof-of-work competition and produces a keyblock. The block reward is fixed by the protocol schedule regardless of how many transactions fill the subsequent microblocks. Of the four efficiency steps above, only Steps 3 and 4 affect the energy cost of mining. Steps 1 and 2 improve transaction throughput per unit of work but do not change how many coins are minted per solve or how much energy the mining competition consumes.
The mining-relevant architectural efficiency is therefore 100x (10x from reduced computational security demands, 10x from Cuckoo Cycle), not 1,846,200x.
On top of this 100x base sits the Fibonacci minting curve (a mathematical sequence where each number is the sum of the two before it, producing a smooth decline rather than abrupt halvings). In any comparable 10-minute window, Bitcoin produces 3.125 BTC (post-April 2024 halving). The Gajumaru produces 5 keyblocks x the per-keyblock reward for the current period. In Period 1, that is 5 x 1,554,161 = 7,770,805 Gajus per 10 minutes. The coin output ratio: approximately 2,486,658x.
Compounded: 2,486,658 x 100 = approximately 249 million times more efficient per coin minted than Bitcoin during Period 1.
This figure diminishes along the Fibonacci curve as block rewards decrease. By Period 10 (15 years in), the advantage is still nearly 3 million times. Even at Period 30, forty-five years from now, the Gajumaru remains nearly 200 times more efficient per coin minted than Bitcoin is today.
How This Comparison Evolves
Bitcoin's halving events cut the block reward by exactly 50% overnight: same energy consumed, half the coins produced. The next halving, expected around April 2028, drops Bitcoin's reward from 3.125 to 1.5625 BTC per block. The energy cost per Bitcoin minted doubles in a single block.
The Gajumaru's Fibonacci curve declines smoothly rather than halving abruptly. The 100x architectural efficiency base (reduced hashrate requirement and Cuckoo Cycle) is constant; it does not change with either Bitcoin's halvings or the Fibonacci decline. What changes is the coin output ratio. Each Bitcoin halving doubles the denominator in that ratio. The Gajumaru's numerator declines gradually along the curve. Unless the Fibonacci decline has exceeded 50% in the same period, each Bitcoin halving makes the comparison more favourable to the Gajumaru, not less.
The minting efficiency advantage is not static. It is structurally designed to hold across decades, because smooth decline compounds more slowly than repeated halving.
What This Means in Human Terms
A Gaju miner today runs on a laptop with 8 GB of RAM. Mining consumes roughly the electricity of an incandescent light bulb: 60-100 watts. No specialist hardware. No warehouse full of ASICs. No industrial cooling systems. No dedicated power substations.
A Bitcoin miner runs purpose-built ASIC hardware drawing approximately 3,500 watts per unit, requiring industrial-scale cooling infrastructure, in facilities that collectively consume more electricity than most countries on Earth. All of this to secure a network on which the overwhelming majority of activity is speculative trading and ETF custody rather than the peer-to-peer commerce it was designed to enable.
The Gajumaru miner contributes to network security while barely registering on their electricity bill. The Bitcoin miner contributes to network security while consuming more energy than many small towns.
The transactional efficiency translates just as concretely. A single, simple spend transaction on Groot costs 0.0000169 Gaju. At full capacity, the network processes over 30 million transactions per day. At a Gaju price of $1, sending a payment costs $0.0000169: less than two thousandths of a cent. Settlement arrives in seconds, not the three to five business days that a bank wire requires or the hour that Bitcoin convention treats as a minimum for low-value transactions – let alone the days or weeks it demands for transfers of any real economic weight, with no finality available at any point. The person sending €500 from Berlin to Nairobi pays less than two thousands of a cent rather than €40-80 in correspondent banking fees, and the full value arrives before they put their phone down.
Visibility as Integrity
The critique is sometimes made that a known, identifiable team behind a protocol cannot be trusted – that anonymity is the guarantor of neutrality. This inverts the actual problem.
Anonymous founders do not make a protocol more trustworthy. They make accountability during the construction period impossible. When QPQ pushes a development update through the Hive structure, you can see who pushed it, examine what it does, and challenge it publicly.
Anonymous founders pushing updates cannot be challenged because they cannot be identified. The transparency of the construction period is not a vulnerability. It is the honest acknowledgement of what the construction period requires.
After public mining opens, our visibility becomes irrelevant to the protocol's trustlessness. No update can be forced on miners. No governance structure exists through which QPQ could act. The architecture at that point does not ask you to trust QPQ – it asks you to trust mathematics and proof-of-work, which you can verify independently. The protocol's sovereignty after handover does not depend on our anonymity. It depends on the architecture this chapter has described.
QPQ is structured to make itself unnecessary. That is not a rhetorical commitment. It is the design. The commercial entity thrives by serving the network. The protocol is governed by no one. The visibility during construction and the trustlessness after it are not in tension. They are the same principle applied at the stage where each is appropriate.
VI. The Gaju: Sound Money
The 木Gaju Currency
Every government in history has claimed the right to define money. Every government in history has been wrong. Carl Menger demonstrated in 1871 what five thousand years of practice had already shown: money emerges when a commodity becomes the most saleable good in a market, the thing people accept not because they want it for its own sake, but because they know others will accept it in turn. 75 Gold did not become money because a pharaoh decreed it. Gold became money because it was durable, divisible, portable, scarce, and verifiable. People chose it. States adopted it afterward, and then spent the next several millennia debasing it: clipping coins, reducing silver content, printing paper claims against reserves that shrank and eventually vanished altogether.
Ludwig von Mises's regression theorem traces this further: money's present value connects through an unbroken chain to the point where it was first valued as a commodity.76 Every successful money began as something useful. Gold was ornamental, workable, and scarce; its commodity value preceded its monetary function by centuries.
What gives a digital currency commodity value? This is the question that separates economics from speculation, and most of the blockchain industry has never answered it honestly. Mises is precise: you must be able to trace money's present purchasing power back through an unbroken chain to the point where it was valued for something other than being money. If that chain breaks, what you have is not money. It is a collective agreement to pretend.
The Commodity Test
Bitcoin proved that trustless verification is a commodity. The ability to send a message that proves its own authenticity without requiring trust in any intermediary is a service with inherent utility. It solves a problem that existed before Bitcoin: how do parties who share no common legal framework, no mutual trust, and no intermediary coordinate a transaction they can both verify? That coordination capability is the commodity Satoshi identified. It was a genuine and valuable contribution to the concept of digital money.
But Bitcoin's implementation of that commodity is so inefficient that it barely functions as one. Settlement takes an hour at minimum for low-value transactions, days or weeks for transfers of meaningful economic weight, and never achieves finality at any value. Transaction costs spike unpredictably. Throughput is limited to single-digit transactions per second. The network consumes more electricity than most countries. The result: almost nobody uses Bitcoin for the coordination problem it was designed to solve. The overwhelming majority of activity is speculative trading and ETF custody. The commodity was real. The implementation failed to deliver it at a cost and speed that made it usable. Bitcoin proved the concept; it did not deliver the product.
From Proof of Concept to Functional Commodity
The Gaju does not merely inherit Bitcoin's contribution. It makes it work. Trustless verification that is over 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation. Settlement in seconds rather than hours, on consumer hardware rather than industrial facilities. The commodity that Bitcoin proved was real, delivered at a cost and speed that makes it usable.
But the Gaju's commodity value extends further than functional verification. The coin is the unit of account on a programmable, trustless resource layer that does things no other system can do.
A programmable resource layer. Smart contracts written in a language designed for safety, executing on a virtual machine that eliminates entire categories of vulnerability by design. State channels providing hardware-limited throughput – over 43 billion payment transactions per day on a single commodity node – for high-frequency and machine economy applications. Naming systems and generalised accounts, all native to the protocol. These are not features bolted onto a coin; they are the utility that the coin denominates.
The neutral ground between jurisdictions: the negotiated space where parties sharing no common legal framework can transact, described in Part One. No other system provides this, because no other system has a governance-free resource layer. The Gaju is the unit of value on that neutral ground: the currency of the high seas.
The connective tissue of governed infrastructure. Associate Chains draw their authority from Groot. Value crossing between them settles in Gajus. The more Associate Chains that operate, the more essential the Gaju becomes as the transit currency that connects them: not because anyone mandates it, but because the architecture requires it.
The exit option, denominated. When a governed system becomes extractive, the ability to move value onto the resource layer and operate there, less efficiently but without anyone's permission, is denominated in Gajus. The coin is the economic expression of the exit option principle.
The Properties of Commodity Money
Each of these is a service with inherent, measurable utility that exists independently of the Gaju's exchange rate against fiat currencies. The commodity value is architectural, not speculative. It satisfies Menger's criteria: the Gaju is durable (mathematical, not physical), divisible (to eighteen decimal places), portable (transmissible globally in seconds), scarce (one trillion, fixed, no more ever), and verifiable (proof-of-work, independently auditable by anyone). These are not analogies to the properties of commodity money. They are the properties of commodity money, expressed in a digital medium for the first time with the utility to justify them.
This is what separates the Gaju from every other digital token. Most tokens are claims on systems that require trust in operators; their "value" is a bet that the operators will continue to act honestly and that sufficient buyers will continue to appear. The Gaju is a unit of account on a system that requires no trust in anyone. The commodity value does not depend on confidence in a foundation, a development team, or continued market enthusiasm. It depends on the utility of the network, which is operational, measurable, and growing.
None of this has prevented every issuer of money in recorded history from destroying it.
5,000 Years of Debasement
The mechanism of debasement varies across civilisations: the Roman denarius fell from 96% silver to under 5%; the US dollar has lost roughly 97% of its 1913 purchasing power.77 The mechanism varies. The incentive does not. Institutions that control the money supply face irresistible pressure to expand it: to fund wars, to buy votes, to paper over crises, to service debts incurred by predecessors who faced the same pressures. Debasement transfers wealth from those who hold the currency to those who control its issuance. It pays workers less in buying power for the same labour. It erodes stored effort. Debase money, devalue life.
Sound Money, Restored
The Gaju is the antithesis of this. One trillion coins, minted over 87.5 years according to a mathematical curve that no entity can alter. No more, ever. No central bank, no foundation, no governance vote can expand the supply. Burned Gajus return to the unmined pool; they are not lost, merely delayed. The total supply is fixed not by policy but by mathematics, enforced not by institutions but by proof-of-work that no party controls.
Friedrich Hayek argued in The Denationalisation of Money that private currencies competing with state currencies would discipline both: the state currency that debases loses users to the private currency that does not; the private currency that lacks utility loses users to the state currency that provides it.78 The Gajumaru's architecture makes this discipline concrete rather than theoretical.
The Transit Currency
Each Associate Chain can operate its own native currency: a national currency, a sectoral currency, whatever serves its jurisdiction. Value crossing between them settles in Gajus through Groot. The Gaju does not compete with these currencies. It connects them: the transit currency through which they all exchange.
The global foreign exchange market turns over roughly $7.5 trillion daily.79 The vast majority of that volume concentrates in a handful of major pairs: EUR/USD, USD/JPY, GBP/USD, USD/CHF. These pairs are deeply liquid, tightly spread, and actively traded around the clock. They are also the backbone on which every other currency transaction depends.
For the hundreds of currency pairs that lack direct liquidity, the market's solution is routing. To exchange New Zealand dollars for Canadian dollars, the transaction passes through intermediary currencies whose markets are deep enough to absorb it: NZD to AUD to JPY to USD to CAD. Each conversion borrows the liquidity of a major pair to escape the punishing spread of a direct NZD-CAD exchange. It works, but every hop extracts a fee, introduces counterparty risk, and adds time. Even the major pairs themselves settle through CLS Bank on a T+2 basis:80 two days of settlement risk managed by yet another intermediary, created specifically because the existing system could not eliminate the danger of one leg settling while the other failed. The architecture is enormous, expensive, and intermediated at every level, not because anyone designed it that way, but because trust between counterparties must be manufactured through layers of infrastructure when it does not exist natively.
On the Gajumaru, the same transaction is NZD to Gaju to CAD. One atomic swap, one smart contract, settled in seconds. Atomic means it completes in full or it does not occur; there is nothing to net, no counterparty risk to manage, no CLS required. The infrastructure that exists to manufacture trust between counterparties becomes unnecessary when the resource layer provides it natively.
Discipline by Mathematics
That single hop creates something the current system cannot deliver at any price: an exchange rate that is immediate, mathematical, and visible to everyone. If an Associate Chain operator debases their native currency, the effect is instantly reflected in the Gaju exchange rate. Not a judgement by a ratings agency months after the fact. Not a market panic that overshoots and then overcorrects. A real-time, algorithmically transparent reflection of relative value that no government can talk away, manipulate, or suppress. The invisible hand, expressed in mathematics, beyond diktat to control.
Why the World's Reserve Currency Has Failed
The Gaju does not need to become the world's reserve currency. But consider why many economies are likely to adopt it regardless.
The US dollar has served as the global reserve since Bretton Woods, and the cost of that privilege has been borne by every nation forced to hold dollar reserves to participate in international trade. The United States has weaponised that dependency: SWIFT exclusions, sanctions, asset freezes. That reserve status gives Washington veto power over the economic life of any nation it chooses to target. The BRICS nations understand this, which is why they have spent years pursuing an alternative. They have failed to produce one, and they will continue to fail, because the problem is not the dollar.
The problem is trust.
A BRICS reserve currency requires its members to trust each other's monetary discipline, and no mechanism exists to enforce that trust (see Enterprise Blockchain later in Part 4 of this document to see the same game being played again, only with banks rather than nation states). Who controls the issuance? Who sets the policy? Apply Tony Benn's five questions to power and the project collapses at question one. You have replaced dependency on Washington with dependency on Beijing, or on a committee where Beijing holds the largest vote.
The Euro demonstrates the endpoint of this logic. A monetary union across economies with fundamentally different productivity, fiscal discipline, and structural needs, governed by an institution with no democratic accountability to the citizens whose purchasing power it controls. The ECB cannot set interest rates that serve both Germany and Greece. It prints to hold the union together, debasing the currency to subsidise the political project at the expense of the people of Europe. The Euro is the ultimate fiat experiment: a currency that serves a political objective rather than an economic one, with no exit mechanism for nations trapped inside it.
The Emerging Economy Trap
Emerging economies face the worst of all these failures simultaneously. They hold dollar reserves they cannot control, trade through systems that can be switched off by a foreign power, and borrow in currencies whose monetary policy is set for someone else's benefit. Many have experienced hyperinflation within living memory if they are not currently suffering from it. They do not need to be persuaded that currency debasement is real. They need an alternative that does not replace one dependency with another.
The Gaju offers precisely that. A fixed-supply currency that no nation controls, settling on a resource layer that no nation governs.
An emerging economy can deploy its own Associate Chain with its own native currency, connecting to global commerce through Groot on its own terms, compliant with its own laws, border controls and rules. Or it can simply adopt the Gaju as its currency. Both paths are available. Neither requires anyone's permission.
Regardless of what any government chooses, the Gaju and Groot are open to everyone. No state needs to act for its citizens to participate. The global economy is uncorked: a farmer in Nairobi, a shopkeeper in Dhaka, a freelancer in Lagos can hold, transact, and store their labour in a currency that cannot be debased, on a network that no one controls, without waiting for their government to build anything, approve anything, or even acknowledge that the option exists.
That is what a governance-free resource layer means.
This changes the calculus for governments entirely. No nation state can prevent its citizens from accessing the Gaju any more than it can prevent them from accessing the high seas. It can make it inconvenient. It cannot make it impossible.
The rational response is not to fight it but to deploy an Associate Chain that offers citizens something better: a governed environment with lower costs, local currency integration, and regulatory clarity.
If the government's offering is fair and functional, citizens will use it because trust enables efficiency. If it is extractive or debased, citizens already have somewhere else to go. The discipline runs in both directions: the Gaju exchange rate disciplines the national currency, and the national currency's utility within its own jurisdiction disciplines the Gaju's relevance.
Case Study: El Salvador
El Salvador illustrates both the need and the failure. In 2001, the country abandoned its national currency, the colón, and adopted the US dollar.81 Dollarisation stabilised prices but surrendered all monetary sovereignty to the Federal Reserve. El Salvador cannot set interest rates, cannot respond to local economic conditions, and cannot control the currency in which 24% of its GDP arrives as remittances from abroad.82 Roughly 70% of the population had no bank account.83
In September 2021, President Bukele made El Salvador the first country to adopt Bitcoin as legal tender,84 aiming to solve both problems: financial inclusion for the unbanked and cheaper remittance transfers. The objectives were legitimate. The instrument was not.
Bitcoin's volatility made it unusable as a medium of exchange for a population living on narrow margins. The government-backed Chivo wallet suffered hacking, identity theft, and repeated technical failures.85 Settlement took too long and cost too much for daily commerce. By 2024, 92% of Salvadorans did not use Bitcoin for transactions, and only 1.3% of remittances were transferred via cryptocurrency.86 The NBER found that adoption concentrated among the already banked, educated, and young: precisely the opposite of the intended beneficiaries.87 In January 2025, under pressure from the IMF as a condition for a $1.4 billion loan, El Salvador rescinded Bitcoin's legal tender status.88
Every failure traces to the same cause: Bitcoin does not work as a currency. It proved the concept of trustless verification but failed to deliver it at a cost and speed that made it usable for daily commerce. El Salvador needed a currency that was stable, fast, cheap, and accessible on basic hardware. Bitcoin is none of these.
A Salvadoran Associate Chain running the Gaju as its currency solves every objective Bukele identified, without the failures his implementation produced. Remittances from the United States arrive as atomic swaps (transactions that complete in full or do not occur at all) settled in seconds at thousandths of a cent. The recipient receives the full value on a phone and a Gaju wallet; paying-for-others transactions mean the merchant or remittance provider covers the negligible gas cost (the small fee paid for on-chain computation), so nothing is lost to transaction fees. No bank account required. No exchange account required. No intermediary extracting a percentage at every step.
Settlement is commerce-grade: 2-3 seconds for a purchase, with absolute finality after 3-4 minutes. Volatility is always an issue for an emerging currency, but as we will explain later, we have made plans to address this economically. Regardless, the Gaju's commodity value is architectural, not speculative. The Associate Chain would operate under Salvadoran regulation, on Salvadoran terms, with Salvadoran oversight. If the government's Associate Chain should later become extractive, every citizen can step onto Groot directly, no permission required – real accountability of the State to the Nation.
El Salvador did not fail because the idea was wrong. It failed because Bitcoin cannot do what the idea required. The Gajumaru, Groot, Associate Chains and Gajus deliver everything they were missing.
Discipline Without Status
The Gaju does not need to be the world's reserve currency because the discipline it enforces does not depend on that status. Whether the Gaju is held as a reserve, used as transit, or simply exists as the exchange rate benchmark against which native currencies are measured, the effect is the same. Debasement becomes immediately, mathematically, publicly visible. The exit option exists. And the calculus of monetary policy changes for every government whose currency trades against it.
| Specification | Value |
|---|---|
| Total Supply | 1 trillion Gajus (fixed, no more ever) |
| Distribution Period | 87.5 years (Fibonacci curve) |
| Protected Mining | Target: 30 March 2027 (outer boundary: 30 September 2027) |
| Main Net Launch | 26 April 2026 (14 years to the day from Satoshi’s last email) |
| Stabilisation Treasury | 125 billion Gajus reserved to smooth early adoption |
| Debasement | Impossible: no government can print more |
Mining Distribution
The mining reward schedule follows a declining ratio derived from the Fibonacci sequence (a mathematical series where each number is the sum of the two before it: 1, 1, 2, 3, 5, 8, 13…). In the earliest periods, when the Gaju has the least fiat-denominated purchasing power, large numbers of Gajus are awarded for solving each puzzle. This encourages private miners to participate early, broadening distribution and deepening their connection to the network. As the Gajumaru grows in utilisation and the Gaju becomes a major currency, rewards diminish and mining becomes progressively more professional. The curve mirrors Bitcoin's approach to declining rewards, but replaces Bitcoin's abrupt halving events (where the reward drops by exactly 50% overnight) with a smooth Fibonacci decline that stretches distribution across nearly a century. Any burned Gajus (coins permanently removed from circulation, for instance through expired unclaimed transactions) are returned to the unmined pool, retaining long-term monetary stability. The supply curve is not monetary policy. It is mathematics. No entity can accelerate it, no crisis can justify expanding it, and no government can vote to change it.
Long-Term Mining Sustainability
A natural question arises: if block rewards decline over time, what sustains mining in the long run? The answer is transaction fees.
Every transaction on the Gajumaru carries a gas cost. The current leader processes transactions from the mempool (the queue of pending transactions waiting to be included on-chain), and has an incentive to prioritise those offering the highest fees. As the network grows in utilisation, the total value of transaction fees per generation increases. At a certain point, the aggregate transaction fees available to a leader in a single generation exceed the block reward for that generation. From that point forward, mining revenue is driven primarily by network activity rather than by newly minted coins.
This transition is by design. In the early periods, generous block rewards attract miners and build the security base. As the Gajumaru matures into a major economic network processing high volumes of real commerce, the economics shift: miners compete not for the diminishing block reward but for the right to process a generation's worth of fee-paying transactions. The reclamation of burned Gajus to the unmined pool extends the effective minting curve, with the degree of extension proportional to the volume of coins burned over time.
The result is a self-sustaining economic model. Mining remains profitable indefinitely, funded by the economic activity that the network exists to enable. The more commerce flows through the system, the more valuable mining becomes, regardless of where the Fibonacci curve stands.
VII. How the Gajumaru Works
Currencies on Groot
Nothing prevents anyone from deploying a smart contract currency directly on Groot. No Associate Chain required. No operator. No permission. A stablecoin issuer, a commercial consortium, an individual: anyone can write a Sophia smart contract that defines a token with whatever properties they choose and deploy it on the resource layer. It is live from the moment of deployment, accessible to every participant on the network, and no one can remove it.
The trade-offs mirror the broader RPA choice. A currency on Groot inherits the full trustlessness of the resource layer: no operator can freeze it, no governance vote can alter it, no foundation can delist it. It also inherits the resource layer's costs: smart contract transactions are more expensive than native spend transactions, and throughput is bounded by Groot's base layer capacity rather than the higher performance an optimised Associate Chain can deliver. For high-volume commerce requiring millions of daily transactions, an Associate Chain with a native currency will always be more efficient. For a stablecoin that prioritises censorship resistance over throughput, or for any monetary instrument whose issuer values permissionless deployment above operational efficiency, Groot is the path.
The two paths coexist. A stablecoin issuer might deploy on Groot first to establish the token permissionlessly, then operate an Associate Chain for the efficiency that commercial scale demands, with the Groot deployment remaining as the trustless fallback. The pattern mirrors the broader architecture: trust enables efficiency, trustlessness enables freedom, and the choice between them is the point.
Data TTL: Solving the Infinite Library Problem
Every blockchain that stores data permanently faces the same problem: the chain grows without limit. Bitcoin's full chain exceeds 600 Gb and grows by 100Gb a year.89 Ethereum's exceeds 1 Tb.90 The faster a chain processes transactions, the faster the storage problem compounds. Running a full node becomes progressively more expensive, which progressively concentrates the network in the hands of those who can afford the storage.
The Gajumaru solves this with Data TTL (Time-To-Live). All data created on-chain carries an expiration date. You pay for storage proportional to how long you need it: the cost is calculated as storage per generation height multiplied by the number of generations you require. When the TTL expires, the data is pruned. Existing objects can have their lifetime extended by paying additional gas (the unit of cost for on-chain operations, analogous to fuel for computation).
The result: chain size remains bounded, regardless of age or transaction volume. Storage costs are predictable and proportional to actual use – 60Gb to 100Gb is our forecast for maximum size. Running a full node never becomes prohibitively expensive. The network stays accessible to ordinary participants, which is exactly how a resource layer should work.
Smart Contracts: The Sophia Language and FATE Virtual Machine
Smart contracts are automated agreements that execute on the blockchain. Think of them as spreadsheet macros: you define rules, and when triggered, the system executes those rules exactly as written. A contract call transaction is sent to the blockchain, the leader takes the data in that transaction, feeds it into the relevant function, and the ledger state updates according to the programmed rules. This is an atomic action (it either completes in full or does not happen at all): all changes happen, or none do.
The critical question for any smart contract system is whether the tools make it easy to write safe contracts or easy to write exploitable ones. On Ethereum, the answer is the latter. Solidity and the EVM (Ethereum Virtual Machine, the execution environment for Ethereum smart contracts) were created by people with limited experience of virtual machine and language design, and the results reflect this: integer overflow vulnerabilities, type confusion exploits, reentrancy attacks, and a development environment where contracts that pass testing can behave differently in production.
The Gajumaru's smart contract system was built by people who build programming languages for a living. The Sophia language and the FATE virtual machine were designed by Ulf Norell (creator of the Agda programming language), Erik Stenman (first native code compiler for Erlang, project manager for Scala 1.0, former CTO of Klarna, author of The BEAM Book), Thomas Arts (CTO of Quviq, Professor of Software Engineering at Chalmers University), and Hans Svensson (specialist in software verification). Supporting contributions came from Robert Virding (co-inventor of the Erlang programming language) and Professor John Hughes (editor on the original Haskell Committee, co-inventor of the QuickCheck property-based testing tool and professor of computer science at Chalmers University). This is not marketing; it is evidence that the tools were built by the people best qualified to build them.
What they produced eliminates entire categories of vulnerability by design:
Type safety: Every operation and every value is typed. Any type violation results in an exception and reverts all state changes. Type confusion cannot be weaponised because the VM will not execute type-unsafe operations under any circumstances.
Overflow prevention: Unbounded integer arithmetic. Financial calculations cannot silently wrap from large positive to negative values. The integer overflow exploits that have cost billions in the Ethereum ecosystem are structurally impossible on FATE.
Memory isolation: Instruction memory is divided into functions and basic blocks with controlled jump destinations. Code cannot reach memory it was not meant to reach. Buffer overflow and reentrancy attacks cannot occur because the VM's architecture prevents the memory access patterns they require.
Separation of data and control flow: A running contract cannot modify its own code. Self-modifying contract attacks are impossible by design.
Development environment fidelity: Code tested on FATE runs on FATE. There is no simulation that behaves differently in production. What you test is what you deploy. This eliminates the entire class of bugs where contracts behave correctly in testing and fail in deployment because the testing environment did not faithfully reproduce the production VM.
Contract cloning: Deploying a smart contract is expensive on most blockchains. On Ethereum, contract deployment routinely costs hundreds to thousands of dollars in gas fees, varying with network congestion.91 The Gajumaru allows a contract to be deployed once and then cloned cheaply by reference. Subsequent deployments carry only the lightweight cost of referencing the original code. This makes on-chain business models commercially practical.
Formal verification: The architecture supports mathematical proof that a smart contract will behave exactly as intended under all possible conditions before it goes live. For institutions whose operations require certainty rather than probability, this is the difference between a technology they can adopt and one they cannot.
Contract source visibility: When deploying a smart contract on the Gajumaru, the author chooses between two modes: visible (where the source code is published as part of the deployment transaction) and incognito (where the source code is omitted). Visible deployment means that anyone calling the contract can inspect exactly what it does before signing a transaction. Wallets can display this information to users, enabling informed consent rather than blind trust. Library code deployed visibly is permanently researchable from within the chain, even if the original off-chain source code is lost. A contract clone inherits the visibility setting of its parent. This is a transparency mechanism that serves the same principle as the wider architecture: if you ask someone to trust you, do not refuse enquiry.
The Naming System
By default, blockchain accounts are identified by long cryptographic hashes: strings of numbers and letters that look like random noise. We do not refer to each other by passport number; blockchain should not require the digital equivalent.
The Gajumaru provides a decentralised naming system that assigns human-readable names to accounts, contracts, and data entries. An account can be addressed as "greg.chain" instead of a 64-character hash. Names are first-class objects on the protocol (meaning they are built into the system at the deepest level, not added on top via smart contracts): they can be spent to, transferred, and auctioned on-chain. Short names (twelve characters or fewer) are distributed through a first-price auction system designed to discourage squatting, with each bid required to exceed the previous by at least 5%. Longer names can be registered instantly.
This replaces the traditional DNS model, where a closed control group governs name resolution, with a fully decentralised alternative verified by the protocol itself. On Ethereum, implementing a naming system requires deploying expensive smart contracts. On the Gajumaru, it is a native protocol operation: cheaper, faster, and algorithmically verified.
Generalised Accounts
A standard blockchain account authenticates with a single cryptographic signature (a mathematical proof that the account holder authorised the transaction). This is simple but inflexible. What if a company needs multi-signature authorisation? What if an account needs spending limits, or delegated authority, or a recovery mechanism?
Generalised Accounts replace the fixed signature with a smart contract: any authentication logic you can code becomes the account's verification method. A standard account is upgraded through an attach transaction, after which any operation can be wrapped in a meta transaction that invokes the custom authentication.
This enables quantum-resistant signing (adopting new cryptographic schemes as they mature), multi-signature accounts, spending limits per period, corporate delegation hierarchies, joint custody arrangements, account recovery through trusted contacts, and any authentication scheme that can be expressed in Sophia. Ethereum's equivalent (ERC-4337 account abstraction) requires a separate mempool (a waiting area for unprocessed transactions) and smart contract layer bolted on after the fact. On the Gajumaru, Generalised Accounts are native to the protocol and can be used exactly like normal accounts.
Paying-For-Others: Removing the Onboarding Barrier
Every blockchain requires transaction fees. On most chains, this creates a fatal onboarding problem: before a new user can do anything, they must first acquire tokens from an exchange. "Go buy some ETH before you can use our application" kills adoption before it begins.
The Gajumaru solves this with paying-for-others transactions. A game provider, a merchant, an employer, or any third party can wrap a user's transaction in a paying-for transaction that covers the gas and fees. The user signs their action with their own keys; the sponsor pays for it. The user does not need to hold any Gajus. They do not even need to know they have a blockchain account.
Consider a game played through a smart contract. The game provider creates an app that automatically generates a Gajumaru account for each player. When the player makes a move, the app encodes it as a transaction, the player signs it, and the game provider wraps it in a paying-for transaction. The player experiences a seamless game. The blockchain infrastructure is invisible. One can pay for any transaction type except the paying-for transaction itself, and even Generalised Account meta transactions can be sponsored.
First-Class Protocol Objects
State channels, the naming system, and smart contracts are all native to the Gajumaru protocol. They are not bolted on via additional smart contracts the way they must be on Ethereum. The FATE virtual machine has high-level instructions that operate directly on these protocol objects.
This matters for three reasons. First, native operations are cheaper than smart contract operations because they avoid the overhead of deploying and calling separate contracts. Second, they are faster because the protocol handles them directly. Third, they are verified by the protocol itself rather than depending on the correctness of third-party smart contract code.
On Ethereum, every one of these features requires a separate smart contract ecosystem, each with its own deployment costs, its own potential vulnerabilities, and its own maintenance burden.
State Channels: Scaling for Purpose
Groot's base layer delivers 300+ transactions per second on-chain – more than enough for the vast majority of economic activity, and orders of magnitude beyond what Bitcoin or any first-generation blockchain can sustain. For applications requiring still higher throughput or near-zero latency between two parties, the Gajumaru provides native state channels: off-chain, peer-to-peer sessions anchored on-chain as first-class protocol objects.
The mechanism is best understood as opening a tab at a bar. Two parties open a channel with a single on-chain transaction – the opening of the tab. Everything that follows happens directly between them: payments, contract calls, plain messages, in any combination, co-signed by both parties at each step and settled immediately within the channel. When they are finished, they close the channel with a second on-chain transaction – paying the tab. Only two transactions touch the chain regardless of how many interactions occurred between them. Everything in between is peer-to-peer computation secured by the underlying chain's consensus.
The fee model is a distinctive property of this architecture. There is no mandatory fee for transactions within a state channel. If the parties choose to apply fees – as a service provider might when offering a State Channel Market to customers – those fees are entirely a matter of agreement between them. The minimum possible fee, if any is charged, is one puck: the base unit of the Gaju at 10^-18 Gaju. The cost of opening and closing a channel is simply the standard Groot on-chain transaction fee for each of those two settlements. Between those bookends, the parties transact freely.
Performance is hardware-limited rather than network-limited. The capacity of a state channel is determined by what the participants' machines can process, not by any constraint in the underlying protocol. For example, on commodity hardware such as a Mac Mini, one node can manage 1,000 concurrent channels. Benchmarked figures on a single session are:
Contract calls: 40-50 per second, per channel
Token transfers: 500+ per second, per channel
Plain messages: 3,000+ per second, per channel
Round-trip time for a token transfer between both parties is approximately 2 milliseconds, implying processing overhead per side of under 1 millisecond. Again, the limiting factor is hardware, not protocol. A rudimentary scaling benchmark across 50 concurrent channels produced 3,500 token transfers per second and 30,400 plain messages per second – confirming that throughput compounds with concurrency rather than degrading under load.
These three categories can be freely interleaved within a single channel. Each interaction carries an ordering guarantee – they are performed sequentially within the channel, which is what makes the co-signing model secure. Multiple concurrent channels allow for much higher aggregate throughput when transactions can be serviced in parallel.
To give the throughput figures human scale: the Tokyo Metro's SUICA contactless payment system – one of the world's highest-throughput payment networks, handling tens of millions of daily commuters – peaks at fewer than 300 transactions per second.92 A single Gajumaru node running 1,000 concurrent state channels at 500+ token transfers per second per channel could process upwards of 500,000 transactions per second: 1,667 times greater than SUICA's peak. That figure scales linearly with nodes deployed. There is no network-wide ceiling to negotiate or share.
For plain message traffic – the dominant interaction type between AI agents – the same node tells a different story. Even at 30,000+ plain messages per second across up to 1,000 concurrent channels, a single Gajumaru node running on everyday domestic hardware like a Mac Mini M4 can handle approximately 2.5 billion messages per day, a number that can be multiplied with the number of nodes added. WhatsApp, the world's largest messaging platform with over 3 billion users across 180 countries, processes approximately 100 billion messages per day across its entire global infrastructure.93 As it happens, Gajumaru and WhatsApp use the same basic technology – Erlang – to achieve these impressive numbers.
The machine economy does not separate payment from communication. Both occur simultaneously within a single channel, in whatever proportion the application requires. Consider an AI agent commissioning inference work from a compute provider. Across a single state channel: the agent sends a plain message with the job specification; the provider returns a price and availability confirmation in kind; the agent sends a token transfer as an opening deposit; the provider streams results back as plain messages; the agent sends a token transfer per completed batch; status flags, error reports, and resubmission requests travel as further plain messages throughout; a final message confirms completion and the channel closes with net settlement. The ratio is roughly four messages to every token transfer – coordination and data flow dominate, payments punctuate. No credit card. No billing cycle. No human standing behind the transaction. No minimum fee. The compute provider is paid at inference speed. That is what machine-native payment infrastructure looks like: not a payment rail bolted alongside a messaging protocol, but a single session in which commerce and communication are the same interaction.
Channel persistence is another property the architecture deliberately provides. A channel, once opened, can remain open indefinitely. Participants can disconnect and reconnect without any on-chain activity; the channel state is preserved. For persistent relationships – a machine paying for API calls, a business settling with a regular supplier, a citizen topping up a transit balance – the channel is set up once and activated on-demand within fractions of a second whenever needed. The two on-chain transactions are amortised across the entire relationship rather than repeated for each session.
The on-chain protocol provides complete dispute logic for cases where the parties do not reach agreement on the closing state. Each participant can monitor the chain in real time and detect if the other party attempts to close the channel using an outdated balance. Third-party monitoring support is also available. Neither party can cheat: any attempt to close on a superseded state can be challenged and penalised within the defined timelock window.
Deployment follows the same RPA versus RIPA logic as everything else in the architecture. State channels can be deployed on Groot, settling in Gaju, with no operator and no governance. They can equally be deployed on any Associate Chain, settling in that chain's native currency or Gaju – the participants' choice. Trustless if you need it. Governed if you choose it.
The State Channel Market is a protocol-level concept that extends this architecture to serve multiple parties. In server mode, a provider node listens on a defined port and services any incoming state channel request. Customers open channels with the provider, transact against those channels, and settle atomically. Round-trip time is approximately 15 milliseconds plus network transfer delays, with immediate settlement within each channel. In the context of multiple Associate Chains, a State Channel Market provider can balance collateral between chains in bulk using on-chain mechanisms, enabling near-instant cross-chain fund transfer without the bridge operators, bilateral agreements, and settlement delays that cross-chain movement would ordinarily require.
What this throughput means for the machine economy, and how QPQ deploys these capabilities commercially, is examined in Part Three.
Associate Chain Currency Architecture
The Transit Currency section above describes how value crosses between Associate Chains: source currency to Gaju at the source border, Gaju transits Groot, Gaju converts to target currency at the destination border. Each jurisdiction controls its own border. Groot provides neutral transit. The mechanism is fixed. What varies entirely is what each Associate Chain chooses to put on its side of that border.
No Constraints
The architecture imposes no constraints whatsoever on what form a native currency takes. None. The currency of an Associate Chain can be whatever its creator wants it to be. A central bank issuing digital receipts against deposits. Commercial banks converting those receipts into deposits within a regulated framework. A stablecoin pegged to a commodity basket. A narrow-banking token backed one-to-one by reserves. Literally anything expressible in a smart contract or as a native transaction type. The Gaju functions as the associate currency on every chain, providing interoperability with the global network, but the native currency is entirely the operator's domain. Their chain, their rules. Associate Chains can support multiple currencies simultaneously: the Gaju, a native currency, and any number of custom tokens, all operating concurrently within the same governed environment.
The Market Decides
The catch is the market. Every native currency on every Associate Chain trades against the Gaju, and the Gaju trades against every other. If a nation state builds a national payment rail and constructs its currency poorly, the exchange rate reflects it instantly. If a stablecoin issuer runs a dollar-denominated chain and manages reserves recklessly, the exchange rate reflects it instantly. The architecture does not judge. It connects, it settles, and it makes every monetary decision transparent in real time against a fixed-supply reference currency that no one controls. The market decides what works.
Every Model, One Network
This is what makes the Gajumaru fundamentally different from every other platform. It does not prescribe a monetary model. It provides the infrastructure for every model to operate, interoperate, and compete. A CBDC in Riyadh, a dollar stablecoin in New York, a trade finance token in Singapore, the Gaju itself adopted wholesale by an emerging economy, and whatever else the market invents: all running on sovereign Associate Chains, all settling through the same governance-free resource layer, all disciplined by the same mathematical transparency.
This is the RIPA path applied to money. The Currencies on Groot section above describes the alternative: permissionless deployment directly on the trustless resource layer, with no operator and no governance, at the cost of lower efficiency. Associate Chains offer the governed path: higher throughput, lower transaction costs for native currencies, and the ability to implement whatever regulatory, compliance, and monetary policy framework the operator requires. The choice between them is, once again, the point. An issuer can deploy on Groot for censorship resistance and on an Associate Chain for commercial efficiency, with each path disciplining the other.
What Every Currency Inherits
Each currency, regardless of form, inherits the same properties from the architecture: atomic settlement through Groot, native interoperability with every other Associate Chain without bridges, and the built-in damage limitation described in the next section. The creator decides what the currency is. The market decides what it is worth.
Groot as Canonical Reference Point
There is a second category of base-layer activity that grows directly with Associate Chain adoption rather than independently of it: smart contracts defining assets that need to be portable across multiple ACs.
Consider an asset – a commodity contract, a financial instrument, a form of digital identity – that needs to be accessible on several different Associate Chains without depending on the governance or continued cooperation of any single one. If that asset's definition lives on an Associate Chain, it is subject to that chain's operators, rules, and potential future decisions. Move it to a different AC and the same problem reappears in a new form.
Groot eliminates this dependency. A smart contract deployed on Groot is accessible to every Associate Chain and controlled by none of them. No AC operator can modify it, restrict access to it, or cease to support it. Its existence is as permanent and as ungoverned as the resource layer itself. This is not a secondary use case for Groot's smart contract capability – it is the precise application that the governance-free resource layer makes possible and that no governed infrastructure can replicate. The contract itself can contain suitable governance and upgrade support, or be completely free from control, depending on what is best for the task at hand, as determined by those who create it.
The practical consequence: as the number of Associate Chains grows and the need for genuinely shared, portable assets increases, Groot's role as canonical reference point grows with it. Cross-chain settlement transits Groot through the connection point protocol. Portable asset definitions reside on Groot by design. Both categories of base-layer activity scale with AC adoption, not against it.
Native Associate Chain Awareness: No Bridges Required
This is a critical differentiator from every other blockchain.
Every other ‘multi-chain’ system treats its sub-chains or connecting chains as strangers. Ethereum does not know its Layer 2s exist. Bitcoin does not know the Lightning Network exists. They bolt on connectivity after the fact, through third-party systems that introduce precisely the trust dependencies blockchain was supposed to eliminate. The Gajumaru was designed from the outset as a connected system. Groot knows every Associate Chain. Every Associate Chain knows Groot. The connectivity is not an aftermarket addition; it is part of the protocol. To understand why this matters, consider what the rest of the industry does instead.
The Bridge Problem
Every multi-chain architecture faces the same connectivity problem. Each chain is an island. To move value between islands, you build a bridge: a third-party system that locks assets on one chain and mints corresponding "wrapped" copies on another. The original assets remain frozen until the wrapped copies are returned and destroyed.
This lock-and-mint mechanism (locking assets on one chain and creating corresponding copies on another) creates a structural vulnerability that no amount of engineering has resolved. The locked assets form a honeypot (a concentrated target for attackers): a concentrated pool of value secured by the bridge's validators or smart contracts rather than by the consensus mechanism of either chain. Compromise the bridge, and you access the entire pool. The vulnerability is not a bug in any particular implementation. It is inherent to the architecture. Every bridge concentrates value at a chokepoint that exists outside the security model of the chains it connects.94
The problem runs deeper than security. Bridges do not actually transfer assets. They create copies, or wrapped copies, of them. Most techniques render the original asset inoperable while being wrapped, or bring into question provenance issues. Proving "proof of deletion" across chains remains unsolved. You are not moving value. You are creating a derivative representation of value, secured by the bridge operator, with no cryptographic guarantee that the original and the copy will remain in sync.
Scale of the Problem
The financial losses from bridge exploits are not episodic failures. They are a systemic pattern:
| Incident | Date | Loss | Primary source |
|---|---|---|---|
| Ronin Bridge (Axie Infinity) | March 2022 | $624M | Chainalysis, CNBC |
| BNB Bridge | October 2022 | $568M | Multiple sources |
| Wormhole | February 2022 | $320M | CNBC, Ledger Academy |
| Nomad | August 2022 | $190M | Google Cloud / Mandiant, CNN |
| Harmony Horizon | June 2022 | $100M | CNBC, LimeChain |
In the first eight months of 2022 alone, $1.4 billion was stolen from bridges.94 The aggregate exceeds $2.8 billion since 2022.95 These are not obscure protocols. Ronin served Axie Infinity's tens of millions of users. BNB Bridge connected the world's largest exchange. Wormhole connected Solana to Ethereum. The biggest bridges, with the most resources devoted to security, suffered the largest losses. Scale increases the honeypot without solving the structural problem.
The Industry Acknowledges the Problem
The Canton Network's own pilot report states the case plainly. Bridges between EVM-based networks have accounted for 48% of the $5.4 billion hacked from DeFi protocols.96 Canton further acknowledges that bridges "reintroduce intermediaries, as well as traditional risks in settlement and reconciliation; the very risks that blockchain was designed to resolve in the first place."96 Even permissioned blockchains built on the same protocol require bridges to connect.96
This is not a fringe critique. It is the industry's own assessment, from a project backed by Goldman Sachs, BNY Mellon, and DTCC. The institutions building the next generation of financial market infrastructure have identified bridges as the central failure point of multi-chain design. Their solution (the Canton synchroniser) replaces bridges with a trusted centralised coordinator. The Gajumaru eliminates bridges entirely through protocol-level design.
Beyond Bridges: The 'Layer Zero' Approaches
The industry recognised the bridge problem years ago. Several architectures claim to have moved beyond it. None actually has.
Polkadot's approach is shared security: parachains do not bridge to each other but instead share the Relay Chain's validator set. This eliminates the lock-and-mint honeypot. It replaces it with centralised control. The Relay Chain validates parachain blocks and retains the ability to censor them. The network supports approximately 100 cores; preliminary testing has demonstrated 80 cores with 12-second block times.97 In September 2024, Polkadot replaced its original slot auction model (which required locking millions of dollars in DOT for two-year leases) with Agile Coretime, a marketplace for purchasing blockspace on-demand or in bulk. The acquisition model changed; the control relationship did not. Parachains remain dependent on the Relay Chain for block validation and shared security. They cannot choose arbitrary consensus mechanisms. Gavin Wood, Polkadot's founder, described the shift candidly: the slot auction model was "most certainly not agile" and created "barriers both perceived and actual." The barriers to entry were lowered. The architectural subordination was not. The bridge problem is solved by making every chain a tenant of the same landlord.
Cosmos comes closest to genuine inter-chain sovereignty. Each zone runs its own consensus via CometBFT (formerly Tendermint). IBC (Inter-Blockchain Communication) enables zone-to-zone messaging without locking assets in a shared pool. Zones are not tenants; they are independent. But IBC solves connectivity without solving economics. ATOM, the hub currency, is deliberately inflationary at 7-20% annually and intended only for staking, not economic activity. Each zone mints its own tokens with no fungibility across zones. A merchant cannot accept "Cosmos currency" because no such thing exists. The architecture provides sovereignty; the economic design fragments it into an archipelago of incompatible tokens.
Cross-chain messaging protocols such as Chainlink CCIP and LayerZero take a different approach entirely: generic message-passing between otherwise unconnected chains, using oracle networks or relayer/oracle pairs to verify that a message sent on one chain was genuinely produced there. Chainlink CCIP uses its Decentralised Oracle Network to attest to cross-chain messages, with a separate Risk Management Network monitoring for anomalies; both layers are operated by Chainlink node operators.98 LayerZero separates message verification (performed by configurable Decentralised Verifier Networks) from message delivery (performed by Executors), delegating security configuration to the application developer rather than enforcing it at the protocol level.99 In both cases, the bridge honeypot disappears. The trust dependency does not. You must trust the oracle network to attest honestly and the relayer to deliver faithfully. The practical reality, as our technical team observes, is blunt: "you have a guy in the middle that can sign on both sides, and you intermediate things for everybody, because otherwise nothing talks to anything." The messaging protocol is the intermediary. Apply Tony Benn's five questions: who controls the relayer? How do you get rid of them?
Each approach solves one problem by creating another. Polkadot eliminates bridges by subordinating chains. Cosmos eliminates bridges by fragmenting economics. Messaging protocols eliminate bridges by introducing trusted relayers. Canton replaces bridges with a trusted centralised synchroniser. All four still require you to trust someone other than the protocol itself.
The Gajumaru Answer: Protocol-Level Awareness
The Gajumaru does not bolt on interoperability after the fact. Groot is natively aware of every Associate Chain connected to it. A special set of transactions on Groot govern the transfers of Gajus between Groot and each AC. The connection point protocol is part of the system's core architecture, not a third-party addition.
| System | Sub-chain awareness | Consequence |
|---|---|---|
| Bitcoin | Not aware of Lightning Network | Requires trust in channel operators |
| Ethereum | Not aware of L2s | Requires third-party bridges |
| Polkadot | Relay controls parachains | Shared security at the cost of sovereignty |
| Cosmos | Zones communicate via IBC | Connectivity without common currency |
| Chainlink CCIP / LayerZero | External oracle networks and relayers | Requires trust in the messaging operator |
| Canton | Requires Global Synchroniser | Requires trust in centralised coordinator |
| Gajumaru | Native awareness of all ACs | No bridges. No relayers. No intermediary. |
There are no wrapped copies. No locked asset pools forming honeypots. No third-party validators securing the gap between chains. When Gajus move from Groot to an Associate Chain, the protocol tracks the commit natively. When they return, the protocol tracks the remit. The asset is the asset throughout; it is not frozen, copied, or represented by a derivative on the destination chain. Provenance is maintained by the protocol itself.
Built-in Damage Limitation
The connection point protocol enforces a critical safety property. A parent chain can commit Gajus to a child Associate Chain. The child chain cannot commit back more Gajus than were committed to it. This means that even if an Associate Chain were compromised entirely, if its operators acted faithlessly, fabricated transactions, or falsely minted tokens within their own scope, the maximum damage to the wider system is limited to the total value previously committed to that chain. The blast radius is contained by design. No single point of failure on any Associate Chain can cascade into a systemic crisis on Groot or any other chain.
Compare this to bridge architecture, where compromising a single bridge can drain the entire pool of locked assets across every user of that bridge. The Ronin exploit drained $624 million in a single incident. On the Gajumaru, the damage from a compromised Associate Chain is bounded by the value that chain holds; it cannot propagate.
Minimum Viable Integration
An Associate Chain does not need to be a full blockchain implementation. At a minimum, it implements only the connection point protocol, allowing Gajus to be transferred in and out of the chain. This could be used to connect an existing financial actor, giving it access to Gajus, while using its own internal systems to maintain the assets. A legacy banking system with a protocol-compliant adapter becomes an Associate Chain without rebuilding its infrastructure. The barrier to entry is the protocol interface, not a full technology replacement.
This is a critical onboarding point for institutional adoption. Banks, exchanges, and payment processors do not need to discard their existing systems. They implement the connection point protocol and their existing infrastructure gains native connectivity to every other Associate Chain and to Groot itself. The cost of joining the network is the cost of an adapter, not a migration.
Pluggable Consensus Architecture
The Gajumaru consensus engine is implemented as a pluggable architecture upon which multiple modes have already been built. In particular, a Smart Contract Consensus model is supported, where key decision points are delegated to a Sophia smart contract. The contract is selected and upgraded using a governance process, and review of the upgrades is made easier because the logic is written in the canonical language of the blockchain. Decisions that can be delegated to such a contract include: leader election, stake management (if proof-of-stake), difficulty calculation, and reward payout.
This means Associate Chain operators are not limited to pre-built consensus options. They can define, deploy, and upgrade consensus logic in smart contracts, tailored to their specific regulatory, performance, and governance requirements. A national Associate Chain serving a sovereign jurisdiction can implement consensus rules that reflect its regulatory framework. A consortium of banks can implement consensus rules that reflect their shared governance agreement. The logic is auditable, upgradeable, and written in the same language as every other contract on the system.
The Scaling Consequence
The calculations in this chapter apply solely to Groot: the proof-of-work root chain with sole minting authority over the Gaju. Groot alone is over 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation. That figure describes one chain.
Every Associate Chain added to the network multiplies the system's effective throughput. This is not a theoretical claim; it is a structural property of the architecture described above. Each AC runs its own consensus independently. It does not share Groot's blockspace. It does not compete for Groot's validation capacity. It does not require Groot's permission to process transactions within its own scope. The only interaction between an AC and Groot is the connection point protocol: commits in, remits out, generation height synchronisation. Everything else is the AC's own affair.
This means scaling is additive. Every Associate Chain contributes its own throughput to the total system capacity without subtracting from the root chain or from any other AC. A national Associate Chain serving Japan and a national Associate Chain serving Brazil process their domestic transactions entirely independently. Neither slows the other. Neither depends on the other. Both settle to Groot when cross-chain movement is required, and Groot's capacity is unaffected by the volume of internal activity on either chain.
Contrast this with the alternatives examined above. Polkadot's parachains share the Relay Chain's approximately 100 cores and compete for the same validation capacity. Adding the 101st parachain does not add throughput; it requires either displacing an existing chain or waiting for core availability. Cosmos zones scale independently but fragment economically; each adds throughput in its own token, unusable elsewhere. Ethereum's Layer 2s share 1,125,000 bytes of blob space per block, combined; every additional L2 competes for the same fixed bandwidth.
The Gajumaru has no architectural ceiling on Associate Chains. The constraint is practical, not structural: each AC requires an operator, a governance model, and a purpose. But there is no protocol limit, no slot auction, no shared resource pool that saturates as the network grows.
There are roughly 260 national jurisdictions in the world. If 260 Associate Chains were operating on the Gajumaru, total system throughput scales to at least 1,846,200 × 260: approximately 144 million times more efficient than Bitcoin. That accounts only for national jurisdictions, not industry-specific, institutional, or purpose-built Associate Chains. The true number, at maturity, will be substantially higher.
Regulatory Position: MiCA Compliance as Competitive Advantage
The EU's MiCA regulation100 (Markets in Crypto-Assets, the EU's comprehensive framework for regulating digital assets), now fully in force, requires mandatory sustainability disclosures for all crypto-assets. White papers must disclose total annual electricity consumption of the consensus mechanism. Where consumption exceeds 500,000 kWh per year, supplementary indicators become mandatory. This framework was designed with Bitcoin's energy profile as the problem: the EU Parliament explicitly cited proof-of-work's energy consumption when considering an outright ban.
The Gajumaru turns disclosure into competitive advantage. Where Bitcoin requires approximately 1,335 kWh per transaction,101 a single Gajumaru transaction requires approximately 0.0024 kWh: less energy than running a household lightbulb for three minutes.
Mining can run on ordinary consumer hardware distributed across the existing power grid, not industrial facilities concentrated where cheap electricity is available. Consider what already exists: millions of home computers idle during the working day. Millions of office computers idle overnight. University labs, internet cafés, small businesses; all with hardware doing nothing for hours at a stretch. The mining capacity is already deployed. It is already powered. It is already paid for. It simply needs software. That is massive, sustainable decentralisation without a single new facility, a single new power contract, or a single new piece of hardware. The architecture makes MiCA compliance straightforward and positions the Gajumaru as the environmentally responsible proof-of-work chain that MiCA's drafters hoped might emerge.
The regulatory convergence extends beyond Europe. In the United States, the GENIUS Act (signed July 2025) established the first comprehensive federal stablecoin framework, while the CLARITY Act (passed the House, July 2025) proposes to divide digital asset oversight between the CFTC and SEC based on decentralisation criteria.102 In the United Kingdom, the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2025 were laid before Parliament in December 2025, establishing a comprehensive regime for trading platforms, custody, stablecoins, staking, and market abuse, with full enforcement from October 2027.103 All three jurisdictions are converging on the same principle: crypto-asset activities should meet the same standards as traditional financial services. The Gajumaru's position is distinctive across each. As the only operational proof-of-work system with an energy profile that satisfies MiCA's sustainability disclosures, a resource layer architecture that eliminates the bridges and intermediaries regulators are increasingly scrutinising, and a fixed-supply currency that falls outside the stablecoin frameworks requiring reserve backing, the Gajumaru passes every regulatory test these frameworks impose. Bitcoin fails the energy test. Proof-of-stake systems pass the energy test but fail the trustlessness test: they cannot serve as a resource layer regardless of their energy profile. The Gajumaru is the only system that passes both.
Engineered to Last
The architecture described in this chapter is not a design document, it’s built, operational, processing real transactions with the settlement times, efficiency, and regulatory characteristics set out above.
But operational today is not the point. The engineering was conceived to endure: garbage collection that prevents chain bloat from compounding over decades; state channels that scale throughput without centralising control; pluggable consensus that allows Associate Chains to adopt governance models that do not yet exist; native interoperability that eliminates the bridge vulnerabilities and trusted intermediaries every other architecture introduces; and a regulatory profile that satisfies frameworks still being drafted.
Each design decision serves the same principle: separate concerns cleanly, build the base to be immovable, and ensure that everything built upon it can adapt.
The Gajumaru was not engineered for the next market cycle. It was engineered for the next five thousand years.
What remains is to demonstrate that the security architecture holds the same standard: resilient not merely against today's threats, but against threats that do not yet exist. Chapter VIII addresses that question.
VIII. Security Architecture
Designed for the Real Economy
The crypto industry is a casino. Not metaphorically; structurally. When you buy a lottery ticket, you are not buying a piece of paper. You are buying a chance: the possibility that the ticket will be worth a great deal more than you paid for it, or nothing at all. That is what gambling is. The many pay for the chance that they will be among the few who win, and most of them will not be. The operator, the casino, the betting shop, the lottery company, does not gamble. It sits in the middle of the wealth transfer and tolls it. Every transaction that flows through the mechanism, win or lose, generates revenue for the house. The operator gets rich not by winning the game but by running it.
Crypto tokens work the same way. The token price is the cost of entry to the game: the token might be worth a great deal or nothing, and objective valuation metrics have nothing to do with which. The exchanges, the project insiders, the foundations, and the infrastructure operators are the conduit for the wealth transfer, and they toll it at every point. They are the house. The participants, known within the industry itself as "degens," are the punters. The stories of early holders who turned small positions into large ones serve the same function as the jackpot lights flashing above the slot machines: they keep the next wave of participants coming in. The few visible winners sustain the illusion that keeps the many paying.
Understanding this structure explains something that would otherwise be baffling: why the crypto industry tolerates appalling security. When the NPM supply chain attack of September 2025 compromised packages with over two billion combined weekly downloads, demonstrating that the JavaScript dependency model on which MetaMask and hundreds of other wallets depend is structurally insecure, the response from the industry was to carry on as before. MetaMask remains the dominant wallet. LavaMoat, a JavaScript sandbox running inside the same JavaScript environment it is attempting to protect, remains the primary security mitigation. The dependency tree of over 212,620 packages from anonymous contributors remains intact.
If the assets in those wallets represented real value, this would be inconceivable. No institution, no business, no individual who believed they were holding genuine value or wealth would continue to store it in a system whose foundations had just been publicly shown to be compromised.
But you do not put a chance in a safe. You put an asset in a safe. A betting slip is not an asset; it is a position in a game. Nobody secures a betting slip the way they secure a deed, or a bond, or a quarter's revenue sitting in a business account, because the betting slip represents a probability, not a possession.
The crypto industry's tolerance of catastrophic security is not a failure of engineering or a lack of available alternatives. It is perfectly rational behaviour, because what flows through these wallets are chances, not assets. The participants who are sophisticated enough and connected enough to have early access to information ride the price movements for profit and exit before the music stops. The rest hold their betting slips and hope, and neither group has any reason to demand better security, because neither group is holding anything that warrants it.
The Gajumaru was not designed for chances. It was designed for the real economy, and the real economy operates at every scale. It must also do so far more securely than the current financial system, because anyone who chooses to operate directly on the blockchain, without an intermediary, is solely responsible for their own assets and their safekeeping. There is no institution standing behind you by default. Those who want that protection can choose it: any financial institution licensed to operate on a given Associate Chain can offer custodial services for that infrastructure and for Groot, to the people it is regulated to serve. But the base layer tools must be built to a standard that assumes nobody else is coming to help, because on the resource layer, nobody is.
A woman selling vegetables from her family's corner shop depends on the same foundational security as a franchise owner sitting on a quarter's takings, a manufacturer settling a cross-border invoice, or a global financial institution that spends hundreds of billions a year ensuring that the systems carrying its clients' assets meet the standards those assets demand. What unites them is not their size but their relationship to what they hold: it is real, it was earned, and its loss is not the price of playing a game. A thousand euros goes into a safe. A shipment of goods is insured. An institution builds and maintains security architecture commensurate with the value in its custody, because the regulators, the clients, and the institution's own risk management require it. These are not people who would accept a quarter of a million unreviewed software packages from anonymous contributors as the custodial layer for assets that matter. They would demand security built to the standard that real value requires, and they would be right to demand it.
People accept probabilistic risk constantly without conscious thought: they eat meals, drive cars, take medicines, trust bank balances, all at odds that would alarm them if stated plainly. Those risks are incidental to the activity, not the purpose of it. A casino manages probability as its business model; the games are designed so that a reliable proportion of participants lose, because that is how the house makes money. A person paying a salary, settling an invoice, or storing the proceeds of a quarter's trading is not choosing to play a game with odds set against them. They are conducting the ordinary business of life, and they are entitled to expect that the systems carrying their livelihood were built to standards that reflect the value of what those systems carry, not to the standards of an industry that never had reason to protect what it held, because what it held was never worth protecting.
Every security decision described in this chapter flows from that premise.
The QPQ Approach: Zero Dependencies
What you carry determines how you must carry it. QPQ evaluated the codebases of existing wallets and concluded that nothing in the crypto ecosystem was built to carry real value. The extended dependency situation was so complex that no security audit could provide confidence, even one conducted in-house. These tools were built for chances, and it shows. You cannot retrofit a casino's security architecture to protect real assets. You start again.
Tony Hoare, the computer scientist who invented the quicksort algorithm and won the Turing Award, identified the core design principle decades ago: "There are two methods in software design. One is to make the program so simple there are obviously no errors. The other is to make it so complicated there are no obvious errors."
MetaMask, confronted with unmanageable complexity in its dependency tree, chose the second path: LavaMoat, a JavaScript sandbox running inside the same JavaScript environment it was trying to secure.
QPQ chose the first. We rejected the entire development model: no NPM, no JavaScript dependency trees, no browser plugin environment. We wrote our own wallets from scratch, with zero external dependencies, every line of code written in-house by QPQ engineers, fully audited, with known provenance from first line to last. The result is not incrementally more secure than what exists in the crypto ecosystem. It is categorically different, because it was built to carry something categorically different.
GajuMobile (iOS, Android, Linux) and GajuDesk (PC/Linux/Mac) are the Gajumaru's wallet applications, built as native applications with zero external dependencies.
| Characteristic | Ethereum Ecosystem (MetaMask) | QPQ (GajuMobile/GajuDesk) |
|---|---|---|
| Total packages audited | 212,620+104 | 0 external dependencies |
| Lines of unreviewed code | Millions | 0 |
| Build-time attack surface | Infinite | None |
| Browser plugin vulnerabilities | Exposed | Avoided entirely |
| NPM supply chain risk | Critical | Eliminated |
| Code provenance | Anonymous global contributors | Written in-house, fully audited |
The attack surface difference is not a matter of degree. It is infinite versus zero. The scale of the risk this eliminates is not theoretical.
The NPM Supply Chain: A Documented Catastrophe
NPM (Node Package Manager) is the standard package manager for JavaScript, the language that powers virtually all browser-based applications. It performs automatic dependency resolution: when you include one package, it silently pulls in every package that package depends on, and every package those depend on, cascading down through layers that no human being reviews. A simple "hello world" application (the most basic test program a developer can deploy) built with a common framework generates tens of thousands of lines of code from thousands of resolved dependencies, triggering thousands of critical security warnings in the process. Nobody reviews that much code for a starter template. For a production wallet handling real money, the scale becomes practically incomprehensible.
On 8 September 2025, attackers demonstrated exactly what this means. A sophisticated phishing campaign targeting Josh Junon, a widely respected open-source developer who maintained the ‘chalk’ package, compromised his NPM credentials. Within approximately sixteen minutes of gaining access, the attackers injected malicious code into eighteen of the most popular JavaScript packages in existence, including ‘debug’ (357 million weekly downloads), ‘chalk’ (300 million weekly downloads), and ‘ansi-styles’ (371 million weekly downloads). Combined, the compromised packages were downloaded over two billion times per week.105106
The attack payload was not crude. It hijacked browser APIs (application programming interfaces: the channels through which software components communicate) including ‘fetch()’, ‘XMLHttpRequest’, and ‘window.ethereum’ to silently monitor network traffic and wallet interactions, replacing cryptocurrency destination addresses with attacker-controlled addresses selected using the Levenshtein distance algorithm (a method of finding text strings that look almost identical to a target) to be visually similar to the originals, making manual detection nearly impossible.107 One component, a self-replicating worm dubbed "Shai-Hulud," stole credentials for cloud services (the remote servers where developers store and manage code), deployed secret-scanning tools, and spread autonomously to additional developer accounts and repositories.108
The wider community was extremely lucky. The malware contained a coding error that crashed build pipelines, alerting developers before the attackers could execute their scheme at scale. Had the payload been properly written, it could have persisted undetected for days or weeks. The direct financial losses were limited to approximately $500 in cryptocurrency.109 Had the attackers been more careful, the damage could have been measured in billions.
This was not an isolated incident. The Solana ‘@solana/web3.js’ library was similarly compromised in December 2024 through credential phishing, with malicious versions designed to steal the private keys that control users' funds briefly available before removal.110 Earlier in 2024, trojanised versions of jQuery circulated through NPM for months before detection. Supply chain attacks against JavaScript packages have been escalating steadily since at least 2018, when the Copay wallet was compromised through a hijacked dependency.
The pattern is clear and irreversible: the NPM ecosystem is structurally insecure. The modern JavaScript dependency model, where a single utility library maintained by a single developer can cascade into billions of installations, is a weapon waiting to be aimed. Every intelligence agency in the world understands this. The question is not whether more packages are compromised. The question is how many compromised packages are still undetected.
The crypto industry's continued reliance on this ecosystem after September 2025 tells you everything about what it believes its assets are worth. For a system designed to carry real value, the NPM ecosystem was never a viable foundation, which is why QPQ never built on it.
The Browser Problem
Zero dependencies is necessary. It is not sufficient.
Most people interact with the internet through a browser: Chrome, Safari, Firefox. The browser was designed to display websites, run applications, and host extensions that add functionality. It was not designed as a secure environment for handling money. Every extension installed in a browser, whether it checks grammar, finds discount codes, or manages cryptocurrency, shares access to the content of the pages you visit. The browser does not treat a wallet differently from a coupon finder. It does not know that one is handling financial transactions and the other is looking for discount codes. Both operate in the same environment, with the same access, and neither can guarantee that the other has not altered what is on the screen.
That makes the browser you are using a hostile environment for anything handling real money. Browser plugins execute in a highly concurrent environment (multiple processes running simultaneously) with overlapping access to memory and data. Even code written entirely in-house, with no external dependencies whatsoever, cannot guarantee its own isolation within a browser context. The concurrency model is fundamentally broken from a security perspective: there is a universal message bus (a shared communication channel through which all processes can send and receive messages) inside the browser, and the addressing concepts and discovery mechanisms (the methods by which one process finds and communicates with another) are, to put it charitably, inadequate for securing financial transactions.
Consider a concrete attack vector that requires no zero-day exploits, no nation-state resources, and no extraordinary technical skill: A user has MetaMask installed and is browsing a shopping website where they intend to pay in cryptocurrency. A separate, apparently unrelated browser plugin (perhaps a coupon finder, a grammar checker, or a social media tool) is also installed. That plugin can inspect and modify the contents of every page displayed in the browser. It can silently alter the cryptocurrency payment address displayed on the shopping page, replacing the merchant's address with an attacker's address. The user sees the address on the page, verifies it against what MetaMask displays, approves the transaction, and sends funds to the wrong destination. The page was altered before the user ever saw it. The little lock icon in the address bar means nothing in this context; it confirms the connection to the server is encrypted, not that the page content has not been tampered with by another process in the same browser.
MetaMask's response to this structural problem was LavaMoat: a JavaScript code-permissioning environment (a tool that attempts to control which pieces of code are allowed to do what), written in JavaScript, running inside the existing JavaScript browser environment, attempting to sandbox (isolate) dangerous packages within the same dangerous context they were trying to escape. Security researchers at Osec independently confirmed the fundamental weakness of this approach, documenting bypass techniques including escaping the LavaMoat sandbox through crafted source map comments (hidden instructions embedded in code files) and opening new browser windows to obtain unscuttled JavaScript realms (fresh browser contexts where LavaMoat's restrictions do not apply), effectively bypassing the sandboxing entirely.111
The fundamental rule of security engineering applies: when complexity becomes unmanageable, you reduce complexity until a human being can understand what is happening. MetaMask looked at unmanageable complexity and made it vastly more complex.
The browser was an acceptable environment for chances, because nobody holding chances had reason to demand better. It is not an acceptable environment for real value. QPQ did not attempt to solve the browser problem. We left the browser entirely: native applications, written in-house, communicating with the chain directly, with no exposure to the environment that makes every other wallet vulnerable.
But even a clean native application on a consumer device is still a connected device, exposed to the internet, running an operating system built by someone else. Leaving the browser removes one category of threat. The question remains: how do you keep private keys secure on any device that connects to a network? The answer is that you do not. You keep them off the connected device entirely.
GRIDS: Air-Gapped Signing
GRIDS (Gajumaru Remote Instruction Dispatch Serialisation) is the protocol that makes secure commerce possible on the Gajumaru and the Internet of Economics that the Gajumaru makes possible. At its core, GRIDS is a dead-drop signature protocol. A dead drop, borrowed from intelligence tradecraft, is an exchange where two parties communicate without ever being in direct contact. GRIDS applies this principle to digital signing: the data that needs to be signed is placed at a location (encoded as a QR code), and a separate, physically disconnected device retrieves it, signs it, and returns the signed response through the same optical channel.
The core principle is physical separation. The device you browse the internet with (your computer, your phone acting as a terminal) is the execution context: it generates requests, displays information, connects to networks. The device that holds your private keys (your wallet) is the signature context: it signs transactions, authenticates identity, and approves payments. These two contexts are separated by an air gap. Air-gapped means physically disconnected from any network. The primary communication between them is optical: QR codes displayed on one screen and read by the other device's camera. GRIDS can also function through direct input of GRIDS URLs, but the air-gap principle remains: the private keys never leave the signing device regardless of how the instruction is delivered.
This is not defence in depth (layering multiple security measures hoping one will hold). This is elimination of attack surface. If the keys never exist on the connected device, they cannot be stolen from the connected device. The most sophisticated browser exploit, the most devious NPM supply chain attack, the most advanced nation-state adversary: none of them can steal keys that are not present.
The GRIDS flow:
User initiates action on connected device (computer, merchant terminal, phone browser)
Connected device creates a GRIDS instruction and encodes it as a QR code (for mobile) or a unique GRIDS URL (for desktop applications)
User scans the QR code with their wallet (for mobile or an air-gapped signing device), or the wallet opens the GRIDS URL directly (for desktop applications)
Wallet decodes the instruction, displays what will be signed, and awaits user approval
User approves; wallet signs the instruction cryptographically
Return path: For mobile or air-gapped devices, the signed response is displayed as a QR code on the wallet and scanned by the connected device. For desktop applications, the signed response is returned directly through the GRIDS URL channel.
At no point does the private key exist on any network-connected device.
GRIDS is not limited to payments. The protocol handles the full range of on-chain interactions: signature and submission of pre-defined smart contract call data (enabling interaction with any application on any chain), spend transaction initiation (direct payments), and message signature for authentication (proving identity without sharing private data). Critically, GRIDS works across Groot and any Associate Chain. A single signing device, one set of keys, one air-gapped protocol, serves the entire Gajumaru system regardless of which chain the interaction targets.
The user experience is modelled on established patterns that hundreds of millions of people already understand. Scandinavian BankID works in exactly the same way: the service displays a QR code, you scan it with your phone, enter a PIN or press a biometric, and you are authenticated. GRIDS delivers the same ease of use, with a critical difference: there is no institution in the middle that can revoke your identity, observe your activity, or be compromised in a way that exposes your data. There is no third party that even knows the authentication occurred.
What it Feels Like to Make a Payment:
You are at a coffee shop. The merchant's terminal displays a QR code. You scan it with your phone. Your wallet shows: "Pay 木0.50 to CoffeeShop.chain." You approve. The payment settles on-chain in 2-3 seconds: the merchant has the money. Your private keys never left your phone. The merchant received payment, not your credit card number. There is no data to breach.
GRIDS ensures that private keys never exist on a connected device. But keys must exist somewhere. The device that holds them, the signing device itself, determines the ceiling of the system's security. How much should you trust that device?
The Security Hierarchy
The Gajumaru's security architecture is not a single solution. It is a graduated hierarchy, each level offering greater protection at greater cost, allowing users to match their security posture to their actual risk.
Level 1: Probably Secure Enclave (Operational)
Most modern phones and computers contain a hardware security device where cryptographic keys can be generated and stored in isolation from the rest of the operating system. The precise implementation varies by manufacturer: Apple calls it a Secure Enclave (on both iPhone and Mac), Android provides a hardware-backed keystore, and Windows and Linux systems offer Trusted Platform Modules (TPM) or equivalent hardware security. The specific capabilities differ between devices and operating system versions. What they share is a critical property: you can ask the hardware to perform signatures or generate keys, but you cannot extract the private key itself. The key never leaves the hardware device. GajuMobile and GajuDesk take advantage of these platform hardware keys to secure the private storage of Gajumaru keys within the device, which is a fundamentally more secure approach than browser-based wallets where keys are handled within the browser's own software environment.
The critical word, however, is "probably."
We did not build these devices. We do not therefore know, with certainty, what is in them. Different manufacturers implement secure enclaves differently. Where the components are manufactured is itself an attack vector. There is no independent oversight confirming that every chip installed in every factory meets its published specification without undisclosed modifications. The defence and intelligence communities have understood this for decades. P.W. Singer and August Cole's Ghost Fleet (2015) explored a scenario in which a tiny off-spec component on an otherwise unremarkable motherboard contained a dormant code fragment. Once activated, it cascaded through networked military hardware, disabling advanced weapons systems and forcing a reversion to mothballed equipment.112 The scenario is fiction, but the underlying vulnerability is not.
At best, we can describe a phone we did not build as having a probably secure enclave. Not a definitely secure enclave. For everyday retail transactions, this is more than adequate. The cost of compromising a well-implemented secure enclave exceeds the value of most individual transactions by orders of magnitude. But for a business sitting on a quarter's revenue, or a sovereign institution managing national financial infrastructure, "probably" is not good enough.
Level 2: GRIDS Hardware Wallet (Next Phase)
The next level removes "probably" from the equation for key storage. The GRIDS hardware wallet, currently in development and dependent on Series A funding to deliver, is a dedicated, air-gapped device whose sole function is to hold keys and sign transactions. It will have no network connection of any kind: no Wi-Fi, no Bluetooth, no NFC, no cellular radio. The only way to communicate with it will be optically, through QR codes displayed on its screen and read by its camera.
The connected device (your phone, your computer, a merchant terminal, etc.) never has the keys. Not briefly, not in transit, not encrypted, not at all. The hardware wallet signs what you ask it to sign, displays the signed response as a QR code, and that is the extent of the interaction. Every attack that depends on keys being present on a networked device, which is nearly every attack that has ever succeeded against cryptocurrency holders, becomes structurally impossible.
For the franchise owner sitting on serious money, for the small manufacturer settling large invoices, for anyone whose economic life depends on the security of their keys, a GRIDS hardware wallet will provide a level of certainty that no software-only solution can match.
Level 3: Full QPQ Hardware Stack (Planned)
The third level addresses what the first two cannot: hardware provenance.
Level 1 trusts the device manufacturer. Level 2 trusts the GRIDS hardware wallet but still uses consumer devices (phones, computers, terminals) as the connected device. Level 3 eliminates both trust assumptions. The vision (in development, dependent on funding and partnerships) is a complete hardware stack with verified provenance: air-gapped signing devices built with known, audited components; SIM chips under QPQ or partner control; and connected devices (phones, terminals) whose manufacturing chain is verified from component to assembly.
QPQ plans to manufacture GRIDS hardware signing devices on its own fabricators in Switzerland and Japan, subject to funding, in facilities readily open to audit and inspection. The signing device is fully within QPQ's scope: a dedicated, air-gapped device with a single function and a verifiable manufacturing chain.
Secure connected devices are a different matter. When the stakes are high enough, you cannot rely on consumer hardware whose manufacturing chain passes through jurisdictions with interests adverse to yours. Switzerland's RUAG has demonstrated the concept with its Guardian Secure Mobile Platform, a hardened mobile device designed for government and defence applications.113 QPQ's long-term roadmap includes partnerships to bring this level of hardware assurance to the Gajumaru ecosystem, but many sovereign actors will want total control over the connected devices their institutions and citizens use. That is appropriate. The GRIDS protocol is open; any device that can display and read QR codes can serve as the connected device. The critical requirement is that the signing device, where the keys live, has verified provenance. What displays the QR code matters far less than what signs the transaction.
The hierarchy is deliberate. Today, users operate at Level 1, using GajuMobile and GajuDesk with their devices' hardware security integration for everyday transactions. As the hardware programme develops, businesses handling significant value will graduate to Level 2 with GRIDS hardware signing devices. Sovereign institutions and high-value operators will require Level 3, combining QPQ signing hardware with sovereign-controlled connected devices. Each level exists because the level below it has a clearly understood limitation, and each level addresses that limitation directly.
Self Single Sign-On
GRIDS enables something that does not exist anywhere else in the digital world: first-party single sign-on. We call this Self Single Sign-On (SSSO).
Traditional Single Sign-On (SSO) is the system that lets you log into many websites with one identity. It solves a real problem: managing hundreds of usernames and passwords is impossible, so you delegate authentication to Google, Apple, or Microsoft. They authenticate you on your behalf. In exchange, they know every site you visit. They can revoke your access at any time. They hold your data. They are the messenger you must trust. SSO trades convenience for surveillance.
With SSSO, the experience is identical from the user's perspective. You visit a website you have never been to before. The login page displays a QR code. You scan it with your wallet. Your wallet signs a message: your keys never leave the device. The site receives cryptographic proof of your identity. No username. No password. No account creation. No personal data shared whatsoever.
The site operator benefits as much as the user. There is no password database to breach. There is no personal data to protect under GDPR, CCPA, or any other data protection regulation. The site never held the data in the first place. Regulatory compliance, for the authentication layer at least, is automatic. The site receives proof that a cryptographic identity approved the interaction. That is all it needs. That is all it gets.
If the site is breached tomorrow, there is nothing to steal. The user authenticated directly, using their own keys, held on their own device. No third party was involved. No third party was even aware. This is authentication for the Internet of Economics: prove who you are without telling anyone who you are.
Quantum Resistance: Designing for Cryptographic Evolution
The protocols described above, GRIDS signing, SSSO authentication, the entire security architecture, depend on cryptographic methods that are secure today. For any system designed to operate across decades, the question is whether those methods will remain secure tomorrow.
The account representation currently used on Groot (Curve25519, a widely trusted cryptographic signing method) is practically impossible to brute-force with any computing hardware that exists today. The scaling requirements for quantum computers capable of cracking elliptic-curve key pairs are immense: realistic estimates require tens or hundreds of millions of physical qubits (the basic units of quantum computation), while the largest machines demonstrating reasonable coherence and error rates have yet to reach 150. The path from current capability to the millions required will depend on many significant innovations in method, likely taking another 10-20 years at the very least. Some experts in the field consider it an open question whether large-scale quantum computation will become a reality at all.
We take the threat seriously regardless, as is prudent. The Gajumaru codebase will support quantum-resistant signing via ML-DSA (a post-quantum digital signature standard recently approved by NIST, the US National Institute of Standards and Technology) by the time of the public Groot Mainnet Launch in April 2026. Draft implementation is already verified and functional, with gas costs of approximately 1.5x to 2.2x that of standard Curve25519 verification.
The more important point is architectural. The Gajumaru already supports Generalised Accounts: regular accounts upgraded to use any Sophia-based authentication method. This is not a bolt-on response to quantum computing. The GA framework was designed from inception to accommodate exactly this kind of cryptographic evolution. Users can migrate to whatever signing schemes prove strongest over time, including schemes that do not yet exist.
This reflects a deliberate design philosophy. Post-quantum cryptography is still young compared to RSA and ECC (the established cryptographic methods that have protected digital communications for decades). Our understanding of the strongest possible attacks on post-quantum algorithms is changing rapidly. Adopting a single scheme prematurely risks discovering five years later that it can be broken with a farm of GPUs, before quantum computation even materialises. The correct approach is not to pick a winner. It is to build architecture that enables users to choose and adapt. Choice, not prescription.
Critically, the process of upgrading an account to a Generalised Account can be entirely local to a given Associate Chain. The account identifier remains the same; only the authentication method changes. An AC operator can mandate quantum-resistant signing for all accounts on its chain without requiring any coordination with Groot or any other AC. This is AC sovereignty in practice: each infrastructure operator responds to threats, regulations, or user requirements on its own terms, at its own pace. The system's overall resilience increases organically.
Where the real evolution happens: As described in Protocol Sovereignty above, Groot is the stable backbone; Associate Chains are where innovation moves. Quantum-resistant cryptography is a prime example. Advanced signing schemes, new cryptographic primitives, and evolving best practices will be developed and deployed on Associate Chains, where operators can adapt at their own pace. Groot provides the quantum-resistant foundation; ACs provide the space for rapid evolution.
The competitive reality: Most blockchain projects have no meaningful quantum migration path. Ethereum's proof-of-stake creates a specific vulnerability: validator public keys are persistent and known, making them directly targetable. Bitcoin lacks the smart contract capability to implement alternative authentication schemes. Neither offers anything equivalent to the GA framework. Projects built on these foundations face an architectural ceiling that no amount of Layer 2 engineering can remove; the base layer cryptography is what it is, and changing it requires changing everything.
Gajumaru does not merely survive a quantum transition. It was designed to evolve through one.
GRIDS as Foundation for the Internet of Economics
GRIDS is not a niche security feature. It is the foundation building block of the Internet of Economics.
Transformed online retail. Merchants receive payment confirmation, not credit card numbers. You cannot breach data that was never held. The entire category of payment card fraud, which cost the global economy $33.41 billion in 2024,114 is architecturally eliminated. Not reduced. Not mitigated. Eliminated, because the attack surface does not exist.
Point-of-sale integration. QR code payments with cryptographic verification, settling in seconds. No card reader. No payment terminal lease. No merchant acquirer taking a percentage. The protocol layer is free. The merchant displays a QR code; the customer scans and signs; payment settles on-chain.
Anonymous commerce where appropriate. The merchant receives payment and, if physical delivery is required, a delivery address. Not an identity. Not a financial profile. Not a browsing history. The minimum information necessary for the transaction to complete.
Fraud elimination. Every payment is cryptographically signed by the payer. Chargebacks caused by stolen card numbers do not exist because card numbers do not exist. The signature is the proof. The chain is the receipt.
GDPR by architecture. Regulatory compliance is not a burden added on top of the system. It is a natural consequence of never collecting the data that regulations exist to protect.
The free tools alone (the GRIDS protocol plus GajuMobile or GajuDesk) enable any merchant, anywhere in the world, to accept peer-to-peer payments with only tiny network gas fees. No intermediary required. No permission needed. The protocol layer is free. The security is absolute. Everything above this: transaction matching, invoicing, reporting, fiat-equivalent pricing, multi-location fund management: is a service opportunity, not a requirement.
The contrast with the ecosystem that claims to lead blockchain adoption is complete:
| Capability | Ethereum – MetaMask | Gajumaru + GRIDS |
|---|---|---|
| Dependencies | 212,620+ packages104 | Zero |
| Key security | Keys in browser extension | Keys never touch connected device |
| Authentication | Third-party SSO or username/password | Self-sovereign SSSO |
| Merchant data exposure | Full payment credentials | Cryptographic proof only |
| Attack surface | Infinite (browser + NPM + plugins) | Air gap: optical only |
| Security hierarchy | One size (browser plugin) | Three levels, graduated to need |
| Quantum migration | No meaningful path | GA framework, user choice |
| Designed for | Speculation | The real economy |
This is what security architecture looks like when the people building it know that a woman running a corner shop 300 metres down the road is going to trust it with her livelihood. The people who built this system are identifiable and accountable, and they have staked their professional reputations on the security architecture functioning as described.
IX. Decentralised Exchange, Decentralised Finance (For Real)
GRIDS ensures that private keys never exist on any network-connected device. The vectors through which billions have been stolen from cryptocurrency holders are eliminated through physical separation. Your assets are secure.
But secure assets sitting in a wallet are not an economy. They are savings under a mattress: safe, and inert. The question this chapter addresses is what happens when those assets move: when they are exchanged, invested, lent, staked into risk pools, used to settle contracts across jurisdictions, deployed into the full range of economic activity that a functioning currency must support. The security of the wallet is the prerequisite. The quality of the infrastructure through which value moves determines whether blockchain delivers on any of its economic promises, or remains an expensive way to hold tokens nobody accepts.
Every time you trade on an exchange, you are trusting someone. The entire history of cryptocurrency exchange is a history of that trust being betrayed: assets frozen, accounts denied, funds stolen, platforms collapsed. Decentralised exchanges (more commonly referred to as 'DEX's) were supposed to solve this. They have not. Every major DEX retains centralised control behind decentralised branding: governance tokens that concentrate power among insiders, upgrade keys that can rewrite the rules. Users pay the costs of decentralisation without receiving its benefits.
This chapter explains why. It explains why no genuinely trustless exchange has existed until now, what the absence has meant for decentralised finance as a whole, and what becomes possible when the missing piece is finally present.
What Is a Decentralised Exchange?
What a Proof-of-Work Blockchain Produces
A proof-of-work blockchain produces money. Not a token, not a digital collectible: money, in the sense that Menger and von Mises understood it. Miners expend real computational resources to secure the network, and the network rewards them with newly minted coins. The value is not conjured; it originates in genuine resource expenditure, the same regression that underpins every commodity money in history. The Gaju is money from the moment it is mined.
But it is an emerging currency. It is not yet widely accepted. It is not yet properly priced. It needs two things that every emerging currency needs: channels for utilisation, places where it can be spent directly on goods and services, and channels for conversion, where it can be exchanged for other currencies in situations where direct spending is not yet possible.
QPQ is building both. GajuMarket will provide a commercial platform where Gajus are spent and earned in exchange for goods and services in the ordinary course of economic life. GajuPay will enable payment processing for businesses at their point of sale. GajuDEX itself creates utilisation when assets are priced in Gajus on the exchange. All of these create utility, price discovery, and liquidity.
This chapter focuses on the specific conversion function: the ability to exchange Gajus for Swiss Francs, USDC, euros, or any other currency or commodity asset. An emerging currency that cannot be exchanged is a closed loop: it circulates among those who already hold it and has no path to anyone else. Conversion is what connects the Gajumaru to every other economic system on the planet and allows an emerging currency to find its place in our daily lives.
Why a Decentralised Exchange, Not a Centralised Exchange
Consider what happens if the only conversion path runs through a centralised exchange (known as a 'CEX'). The blockchain itself is trustless: no one controls the ledger, no one can freeze your Gajus, no one can reverse your transactions. But the moment you need to convert those Gajus into the currency your landlord or supplier accepts, you must hand them to an intermediary that you must trust. That intermediary – regulated preferably, but usually not in the crypto world – holds your assets, controls execution, and can freeze your account, deny your withdrawal, or collapse overnight.
The blockchain secured the ledger. If conversion runs through an intermediary, the trustlessness terminates at the exact point it matters most: where the currency meets the world. For a proof-of-work blockchain (Groot of the Gajumaru) producing real money (Gajus), the distinction between a CEX and a genuine DEX is not just a technical preference; it is a question of whether the currency's core property survives contact with the broader economy.
The problem is not only the user's. A blockchain designed to eliminate control points cannot fulfil its purpose if the primary economic interface reintroduces one. For QPQ to deliver the Gajumaru and the internet of economics that the Gajumaru makes possible, a centralised exchange was never an option, and the reasons are structural, not philosophical.
First, building or operating a CEX would make QPQ exactly what it set out not to be: a controller taxing control. A company that builds a governance-free resource layer and then funnels its currency through a permissioned exchange has contradicted its own thesis. The control function would sit where the value flows, which is where control functions always sit.
Second, the CEX listing model is structurally incompatible with a mined currency. Centralised exchanges require projects to allocate tokens to the exchange as a condition of listing, regardless of what the exchanges say publicly. Binance's official position, published in 2018, is that listing fees are "donations" given to charity with no minimum and no dictated amount.115 In practice, the demands are different. In October 2025, CJ Hetherington, CEO of Limitless Labs, published what he described as Binance's actual listing offer, received before signing any non-disclosure agreement: 1% airdrop on day one, 3% further airdrops over six months, 1% for "marketing" at Binance's full discretion, 3% reserved for the BNB HODLer programme, totalling approximately 8% of total token supply, plus a $250,000 security deposit, $2 million in BNB as collateral, and over $1 million in liquidity provision.116 Mike Dudas, co-founder of The Block and founder of 6th Man Ventures, corroborated the account: "I can confirm that I've seen Binance TGE listing proposals of the EXACT same nature."117 A year earlier, Simon Dedic of Moonrock Capital reported that a tier-one project which had raised close to nine figures received a Binance listing offer demanding 15% of total token supply, representing $50 million to $100 million.118
Coinbase claims listings are free and always have been.119 Andre Cronje, founder of Sonic Labs, responded directly to that claim: "Coinbase has asked us for $300m, $50m, $30m, and more recently $60m," with requests coming from multiple Coinbase employees via email, Telegram, and Slack.120 Justin Sun reported the same pattern: Coinbase required 500 million TRX (worth $80 million at the time) and demanded a $250 million Bitcoin deposit in Coinbase Custody.121 Both exchanges deny these accounts. Neither has released audited data on what projects receive, pay, or provide as a condition of listing.
The entire model of the crypto CEX's assumes that a foundation or team controls the token supply and can hand over whatever the exchange demands. We believe it also assumes, though no exchange states this explicitly, that the blockchain itself can be corrected when things go wrong: the expectation of a controlling party who can press Ctrl+Z (undo function on most keyboards) when losses are large enough, entirely repudiating the point of a blockchain.
Gajus are not tokens conjured into existence by a foundation and distributed according to a whitepaper. They are coins, mined through proof-of-work by independent miners expending real computational resources. QPQ does not have a treasury of unminted Gajus to hand to an exchange, because unminted Gajus do not exist. They have to be earned. Handing 8% of total supply to Binance would require purchasing 80 billion Gaju on the open market; at any meaningful price, this would be economically absurd; at a low price, it would be market manipulation. The CEX listing model was built for a world where projects click tokens into existence and then negotiate how to divide them. That world is not this one.
Third, no existing DEX is genuinely decentralised. Every major DEX reviewed in this chapter retains centralised control behind decentralised branding. Porting an existing DEX onto Groot would have been cheaper and faster, and on QPQ's limited budget the temptation was real. But deploying a governed exchange on a governance-free resource layer creates an extractive, centralised operation on exactly the infrastructure designed to prevent one. A decentralised blockchain with centralised exchange functions quickly becomes a controlled space. The only option was to build a genuine DEX from the ground up: no governance tokens, no admin keys, no upgrade authority, no controlling functions of any kind.
The result, as this chapter will prove, is the world's first genuinely decentralised exchange on the world's first genuinely decentralised fully functional blockchain – the basis for the internet of economics.
A genuine DEX extends the blockchain's trustless property all the way through to conversion. Smart contracts on the blockchain hold the assets, match the trades, and settle the transactions automatically. No company holds your money. No operator sees your orders before they execute. No one can freeze your account, change the rules, or disappear with your funds overnight. The exchange is code, running on a blockchain, visible to everyone, controlled by no one, ensuring that what you do settles between you and your counterparty.
How to Test Whether a DEX Is Real
"Decentralised" is a claim, not a fact. It must be tested. Regulators across multiple independent jurisdictions have each developed frameworks for doing so, and they have arrived, without coordination, at the same underlying test.
FINMA, the Swiss Financial Market Supervisory Authority, applies a substance-over-form framework: under its own published position, a genuinely decentralised application has no central operator exercising discretion, custody, or control; no potential for misuse of client funds; no information asymmetry between operator and user; and no capacity for operational manipulation.122 The European Union's Markets in Crypto-Assets Regulation, directly applicable in Liechtenstein from 2025 and relevant to any operator serving EEA customers, states in its Recital 22 that crypto-asset services provided "in a fully decentralised manner without any intermediary" fall outside the regulation's scope – and adds that partial decentralisation is not enough: "where part of such activities or services is performed in a decentralised manner," the full regulation applies.123 The Monetary Authority of Singapore's regulatory framework under the Payment Services Act is structured around the presence of an identifiable person or entity conducting a regulated activity; a protocol with no identifiable operator falls outside that perimeter because there is nothing to licence.124
Three independent regulatory traditions. Three different legal architectures. One underlying question: who is in control?
This test applies at two levels simultaneously. The exchange layer: can anyone change the contracts, pause trading, upgrade the logic, or direct where fees flow? The settlement layer: does the blockchain underneath have operators who can censor transactions, reorder blocks, or halt the chain? A DEX must pass both. Immutable contracts on a controlled chain execute at the pleasure of whoever controls consensus. A trustless chain cannot save governed contracts. Neither layer compensates for the other.
If any entity or coordinated group can alter the smart contracts, freeze assets, redirect fees, or rewrite transaction history, the system is centralised regardless of what it calls itself. Every framework agrees on this. None has yet needed to apply it to a specific DEX, because no major platform has sought a determination it would not welcome. Indeed, we would ask why regulators have not been more proactive in addressing such obvious and dangerous regulatory arbitrage, especially as we have repeatedly offered our expertise for free to regulators who would like to understand what the mechanics of control are. This chapter and this compendium exist, in part, to give every reader the tools to distinguish genuine blockchain and genuine decentralisation from the crypto industry that has traded on both words whilst delivering neither.
What a DEX Does for a Blockchain
Every trade on a DEX generates genuine transaction activity on the underlying chain: real economic utility, real demand, real use of the network that proof-of-work exists to secure.
Today, Groot's security budget comes overwhelmingly from block rewards: newly minted Gajus distributed to miners along the Fibonacci curve. Transaction fees are a secondary revenue stream. But the curve declines by design; over time, as block rewards diminish, transaction fees become the primary economic incentive sustaining the mining network. A functioning exchange builds the transaction volume that will fund the network's security for generations, replacing dependence on issuance with dependence on genuine economic activity.
Beyond security economics, exchanges create the liquidity and price discovery that an emerging currency requires. A Gaju that can be freely exchanged for Swiss Francs or USDC at a transparent market price is money functioning as money – the exchange is what closes the gap between a currency that has value and a currency that can be used. The more the Gaju itself is used in a self-referential Gaju-denominated economy, the less this is needed, but so long as there are currencies, there will need to be efficient means to move between them.
Marketplaces and Exchanges
Two distinct kinds of infrastructure serve a currency's needs, and the distinction matters for understanding what GajuDEX is and what it is not.
A marketplace is where money circulates. Buyers spend currency to acquire goods and services; sellers accept currency in return. Price discovery in a marketplace is about what things cost: what is a kilogram of coffee worth, what does an hour of consulting time command, what will someone pay for a software licence. GajuMarket, planned for launch in Q2-Q4 2026 (funding dependent), will serve this function for the Gajumaru; it is our hope that with the opportunity to use a fully functional, real blockchain offering sound money as the medium of exchange, many more marketplaces will emerge in the year ahead.
An exchange is where currencies and assets convert into one another. Price discovery on an exchange is about what currencies and assets are worth relative to each other: how many Gajus for a Swiss Franc, what is a tokenised equity worth in dollars, what is the spot price of copper in Euro. A marketplace needs stable pricing and reliable settlement. An exchange needs deep liquidity, precise execution, and continuous price discovery across multiple trading pairs.
Both are essential. Without marketplaces, money has no utility: there is nothing to buy. Without exchanges, money has no liquidity: it cannot convert into other forms of value, and participants in different economic systems cannot transact with one another. A currency that circulates domestically but cannot be exchanged is a closed loop. GajuDEX provides the exchange function.
For an emerging currency, these two functions do not merely coexist; they produce the currency's price together. When a seller prices coffee in Gajus on a marketplace, that is a signal about what the Gaju buys. When a trader converts Gajus for Swiss Francs on an exchange, that is a signal about what the Gaju is worth relative to established currencies.
A third signal underpins both: the cost to mine. Hardware, electricity, software, connectivity; the real resources miners expend to earn each Gaju establish a floor price below which production ceases, just as extraction costs establish a floor for any commodity money. The real price of the Gaju emerges from the interaction of all three: what it costs to produce, what it purchases in a self-referential economy, and what it commands in the wider one.
Today, exchange conversion dominates because Gaju-denominated economic activity is thin. The Gaju is mispriced, as every emerging currency is mispriced, and the exchange function is how the world discovers what it should cost. As utilisation grows, as more goods and services are priced and settled in Gajus, internal price signals carry more weight and the dependence on exchange conversion diminishes. But neither function ever fully displaces the other. So long as multiple currencies exist, the ability to move between them efficiently is not a temporary bridge; it is a permanent feature of a functioning monetary system. What shifts over time is the balance, not the need.
The Promise Betrayed (Again)
That is what a genuine exchange should deliver: trustless conversion, transparent price discovery, a permanent connection to the wider economy. The demand for decentralised exchange operations is real and growing. By mid-2025, decentralised exchanges had captured approximately 25% of global spot trading volume, with monthly volume reaching $410 billion in May 2025 alone.125 Usage among institutional participants grew sharply: Uniswap usage by crypto hedge funds jumped from 20% to 75% between 2022 and 2023.126 Total DEX trading volume reached approximately $835 billion in 2023.127 The scale is real, but as is a recurring theme with all things ‘crypto’, the decentralisation is not.
The (unregulated crypto) centralised exchange model that has played such a major part in the crypto industry’s story has failed, repeatedly and catastrophically. Mt. Gox lost 850,000 Bitcoin in 2014 and left creditors waiting a decade for partial recovery. FTX collapsed in November 2022 with over $8 billion in customer funds missing, triggering contagion across the entire industry.128 These were not edge cases; they were the predictable consequence of concentrating custody and control in a single trusted party. The collapse of FTX drove demand for decentralised alternatives to record levels, with DEX volumes spiking above $12 billion daily as users fled.129
But the supply of genuine trustless exchange has never materialised. This is not just a function of failure at the underlying ‘blockchain’ protocol to be decentralised or to even be viable for utilisation. It runs deeper than that too and for similar reasons: there is no easy money in creating something that everyone can use but nobody can tax control of. As the history shows, venture capital in this field has a long and storied history of funding extraction, not utility.
The Alternatives That Weren't
Every major DEX that has claimed to solve this problem has, under pressure, revealed the centralised control it marketed away. The history of failures and cheats is a book in and of itself.
Serum, once the leading order-book DEX on Solana, was marketed as decentralised infrastructure. In reality, FTX held the upgrade authority over its smart contracts. When FTX collapsed, Serum's security was instantly compromised: the entity that controlled the code was bankrupt, hacked, and under criminal investigation. Protocols built on Serum, including Jupiter and Raydium, abandoned it immediately. The "decentralised" exchange was declared defunct because one centralised party had always held the keys.130
Mango Markets, another Solana-based DEX, was drained of $110 million in October 2022 when a trader manipulated the oracle price feed for its governance token, inflated his collateral, and withdrew everything. The platform's governance DAO, the supposed safeguard of community control, voted to let the attacker keep $47 million in exchange for returning the rest. The SEC, CFTC, and Department of Justice all filed charges. The attacker's conviction was subsequently overturned by a federal judge who found that the platform had no terms of service, no prohibition against manipulation, and no requirement that loans be repaid.131 The code permitted what happened. The "governance" could not prevent it and chose to negotiate with it.
In January 2026, Paradex, a perpetual futures exchange operating as an appchain on Starknet, suffered a database migration error that briefly priced Bitcoin at zero. Automated liquidations wiped thousands of positions within minutes. The team's response was to roll back the entire blockchain to an earlier state, reversing every trade, deposit, and withdrawal that had occurred after the error.132 When the system worked, it was DeFi. When it broke, admin mode appeared. If the operators can press Ctrl+Z on the blockchain, the exchange is not decentralised, and the word "immutable" means nothing.
Hyperliquid, a perpetual futures platform running its own ‘Layer 1 blockchain’, demonstrated the pattern most starkly in March 2025. An attacker exploited the platform's liquidation mechanism using the illiquid JELLY token, opening approximately $8 million in positions across three accounts and then pumping the token's price by over 400% across external exchanges. The manipulation forced a short position into Hyperliquid's own Liquidity Provider vault, placing $230 million in vault funds at risk.133 The validators' response was not to let the market clear. They voted to delist JELLY, suspended all trading, and forced settlement of every outstanding JELLY perpetual contract at $0.0095, the attacker's original entry price, while the market price stood at approximately $0.50.134 They did not reverse history, as Paradex had done. They declared what price reality would be. Arthur Hayes, founder of BitMEX, responded: "Let's stop pretending Hyperliquid is decentralised." Gracy Chen, CEO of Bitget, called the response "immature, unethical, and unprofessional," comparing it to a centralised exchange.133 Security analysts at Halborn concluded that "the protocol revealed centralized control over market pricing."134 At the time of the incident, the Hyper Foundation controlled approximately 78.5% of total validator stake, comprising 60.5% through direct Foundation node delegation and a further approximately 18% through withdrawable delegations to nominally independent validators.135
These failures are not incidental. They are structural. Each reveals a different way that centralised control persists behind decentralised branding: upgrade authority held by a single entity, oracle feeds susceptible to manipulation with no recourse, governance mechanisms that negotiate with attackers rather than preventing exploitation, operational teams that can rewrite blockchain history when automated systems malfunction, and validators who can override market pricing when their own funds are at risk.
How They Fail: The Exchange Layer
The pattern is consistent. A governance token, distributed primarily to founders and early investors, concentrates voting power among a small group. A handful of large holders can raid treasuries, redirect fees, create emergency pauses, or upgrade contracts. What was sold as "community governance" functions, in practice, as an admin key.
The governance token serves two purposes simultaneously: it collects fees from trades, and it confers voting rights over protocol changes. Voter turnout tells you which purpose holders actually care about. When participation routinely falls below 10%, sometimes below 2%,136 the answer is unambiguous: the overwhelming majority hold the token because it pays them a share of trading fees.
That leaves the small minority who do vote with, in effect, total control: the founders, early investors, and concentrated holders who acquired their tokens earliest and cheapest. They control the treasury. They direct the fee flows. They approve or block upgrades. The voter turnout data does not suggest apathy; it proves that the governance function is a fiction maintained by the people who run the exchange, while everyone else treats the token as what it actually is: a fee-bearing investment instrument.
Apply Tony Benn's five questions: Who controls the governance contracts? The concentrated holders who vote. Where did they get that power? Early access and capital. In whose interests do they exercise it? Their own. To whom are they accountable? No one. How can you get rid of them? You cannot. If the answer to that last question is "you cannot," you do not have a decentralised exchange.
How They Fail: The Settlement Layer
Even if a DEX had flawless, ungoverned contracts, it would still fail every regulatory test if the chain underneath is controlled. Ethereum's staking is dominated by Lido, Coinbase, and a handful of institutional operators, all identifiable and all subject to coordinated regulatory pressure. Uniswap's migration to Unichain introduces a centralised sequencer. The contracts may be immutable, but their execution environment is not trustless. The operator has been moved one layer down, where most people do not look.
When a fake DEX operates on a fake blockchain, the combination is worse than either failure alone. The exchange generates the appearance of on-chain economic activity: transaction volumes, liquidity pools, fee revenue. The chain points to DEX volumes as proof of utility. The DEX points to the chain's market capitalisation as proof of legitimacy. Each validates the other in a circular loop of manufactured credibility. When institutional products (ETFs, pension allocations, corporate treasury holdings) are built on this circular validation, the risk transfers from crypto-native speculators to mainstream investors who believe they are buying into a functioning economic system.
Users pay the costs of decentralisation: slower transactions, higher fees than a trusted database would impose. They receive none of the benefits, because the messenger is still there, still in control, still capable of saying no. The only difference is that the messenger has escaped the oversight that normally accompanies such control. This is not merely inefficient. It is regulatory arbitrage and as such creates significant unsupervised risks and an impenetrable barrier to responsible institutional adoption of DEX utilisation.
The Token Trap
The deeper question is why governance tokens exist at all in, allegedly, decentralised systems. The answer lies in FINMA's three-category token taxonomy.137 Payment tokens function as a means of payment or value transfer. Utility tokens provide digital access to an application or service. Asset tokens represent financial assets and are classified as securities, attracting the full weight of securities law: prospectus requirements, trading venue licensing, investor protection obligations. The gap between "utility" and "asset" is enormous, creating a powerful incentive to label tokens as utility regardless of their actual economic function.
Most DEX governance tokens are presented as utility tokens, with the claimed utility being access to governance: the ability to vote on protocol changes. The substance tells a different story. The token's market value derives not from the governance function, but from the expectation of future fee extraction – again, look at voting turnout to see the proof over and over and over again. Holders are not interested in buying the right to vote; they are buying a position in a system that generates trading fees. In economic terms, this is an investment, which is precisely the condition under which FINMA treats utility tokens as securities.
The mechanism is structural, not incidental. The governance token creates a circularity that concentrates control by design: the token's price depends on future fee revenue, the governance function controls how those fees are allocated, and large holders acquire governance power that lets them direct fees toward themselves. Regardless of the initial distribution, the system converges toward concentration. This is not decentralised governance. It is a plutocracy with a blockchain wrapper.
Uniswap proves the point. For five years, UNI operated as a governance-only token with no revenue distribution, not out of philosophical commitment to pure governance, but out of regulatory caution: Uniswap's own legal advisers recognised that activating revenue-sharing would bring UNI within securities regulation.138 In April 2024, the US Securities and Exchange Commission issued a Wells notice to Uniswap Labs, alleging it operated as an unregistered securities exchange and that UNI might constitute an unregistered security.139 The SEC dropped the investigation in February 2025 under new leadership,140 and by December 2025 Uniswap activated a fee switch and token burn mechanism, transforming UNI from governance-only to direct value accrual.141 The sequence is instructive: the token was always intended to capture economic value, and the five-year delay was regulatory strategy, not architectural principle. The plutocracy was patient, not absent.
Despite all of this, to our bewilderment and exasperation, the theatrics of decentralisation prove enough to avert real review, allowing the crypto industry to sustain a pretence that harms users, harms investors and diverts, blockchain's transformative potential into short-term profiteering. The emperor has no clothes. Every regulator, legislator, and institution he passes can see it. None has yet said so. We are at a loss as to why.
Scale Without Substance
Liquidity compounds the problem. Most DEX liquidity is mercenary: bought through token giveaways and incentive programmes. SushiSwap's "vampire attack" drew billions in liquidity from Uniswap in 2020 through aggressive token incentives; within months of the rewards tapering, the liquidity haemorrhaged back out.142 The pattern recurred across dozens of smaller protocols between 2021 and 2025, with pools draining within weeks of reward programmes concluding. What appeared to be deep, liquid markets turned out to be temporary constructions. The market depth was rented, not earned.
The demand for trustless exchange is genuine and growing, and not a single platform in the history of this industry has met it.
The Promise That Was Never Kept: DeFi on Broken Foundations
The absence of a genuine DEX is not merely a product gap. It is the reason that decentralised finance, for all its scale, has delivered almost nothing of its promised economic transformation.
Decentralised finance arrived with an extraordinary proposition: a parallel financial system, open to anyone with internet access, operating on rules rather than relationships. Exchange without brokers. Lending without banks. Insurance without adjusters. Derivatives without clearinghouses. The economic functions that intermediaries have performed for centuries, and extracted rent from for centuries, replaced by smart contracts executing automatically on trustless infrastructure.
Lies, Damn Lies and Crypto Lies
By early 2026, roughly $130-140 billion was locked in DeFi protocols worldwide.143 The numbers look like success. They are not. They are the aggregate value of assets deposited into systems that have reproduced every failure mode of centralised finance, beneath a surface of decentralised branding.
Ask what that $130-140 billion actually consists of. The single largest category of DeFi total value locked is liquid staking. Lido alone holds north of $27.5 billion. Staking what? Governance tokens and proof-of-stake native tokens: not money, not claims on productive assets, not collateral securing any real-world obligation. Against what? Nothing. For what? To validate transactions on chains whose primary economic activity is more staking, more governance votes about fee allocation, more swaps between governance tokens. To what real economic end? None.
In traditional finance, yield comes from productive deployment of capital. A bank lends your deposit to a business that builds something, ships something, sells something, services something, and pays interest from the revenue that productive activity generates. In DeFi staking, "yield" is protocol issuance: new tokens created and distributed to stakers. Nothing productive happened. No economic value was created. The yield is dilution of non-stakers dressed up as return on capital.
Strip out staking. Strip out circular lending against governance tokens. Strip out mercenary liquidity rented by token incentives. Ask what remains of $130-140 billion that represents genuine economic activity: actual goods exchanged, actual services rendered, actual risks insured, actual capital productively deployed. The answer is almost nothing.
Moreover, it isn’t even an industry with passable security for a local community lottery game. In the first half of 2025 alone, security researchers tallied over $2.5 billion lost to hacks, exploits, and fraud; the most costly six-month period for smart contract attacks since early 2023.144 Total crypto theft across the full year reached $3.41 billion, with a single incident, the Bybit exchange hack in February, accounting for $1.5 billion alone.145 These are not incidental failures of poorly designed individual products. They are the predictable consequence of building a financial system on two structural lies: that governance tokens are money, and that controlled chains are trustless.
The Circularity
Consider what the current DeFi stack actually is. Lending protocols like Aave accept deposits of ETH, governance tokens, and stablecoins backed by other governance tokens, and extend loans against them. The interest rates are determined by governance vote among token holders who are themselves motivated by fee revenue from the protocol. The collateral is not independent money; it is a circular reference to the same ecosystem.
When the Mango Markets attacker manipulated the price of MNGO tokens to inflate his collateral, he was not exploiting an edge case; he was using the system exactly as designed. The collateral was a governance token. The oracle reported its price. The smart contract acted on that price. The "decentralised" governance then voted to negotiate rather than enforce. Every element worked as intended. The system was designed to enrich insiders. It did.
The deeper structural failure is this: DeFi built on controlled chains with manufactured money cannot be genuinely decentralised, because the value flowing through it is not genuinely scarce. Governance tokens can be issued, diluted, inflated, and redirected by governance vote. The "yield" in DeFi yield farming is largely paid in freshly issued governance tokens, which means it is paid by diluting the holdings of everyone who does not actively farm; a transfer of value from passive holders to active participants, funded by inflation.
This is not finance. It is a redistribution mechanism dressed in the language of finance.
No Price Discovery Without Real Money
The absence of a real DEX means that no genuine market exists in which DeFi assets can be priced by genuine economic activity. The prices that DeFi protocols use as collateral values, that oracles report to lending protocols, that determine liquidation thresholds, are set in markets that are themselves controlled by the same concentrated token holders. The circularity is not a flaw in specific protocols; it is the architecture of the entire ecosystem.
No genuine exchange. No genuine money. No genuine collateral. No genuine price discovery. No genuine yield. An industry measured in the hundreds of billions, and not one functioning economic circuit connecting it to the productive world outside its own loop. Every claim about what DeFi can become, every vision of disintermediated finance, every promise of economic access for the unbanked and the underserved, is predicated on a piece of infrastructure that has never existed: trustless exchange, on real money, on a genuinely neutral chain, attracting liquidity through genuine economic incentive rather than token rewards.
The Proof
The claims made in the preceding sections are testable. QPQ developed a scoring framework to evaluate DEX platforms systematically against the criteria that matter for genuine decentralisation, regulatory compliance, and operational integrity. The methodology is presented in full so that readers can apply it independently and draw their own conclusions.
Scoring Criteria and Deduction Rules
The framework evaluates eight factors, each scored from 1 (worst) to 5 (best), with explicit deduction rules stated before any platform is assessed.
Decentralisation examines whether the core protocol is genuinely immutable and permissionless or whether controlling functions exist. Full marks for no governance mechanism. Minus 2 if a DAO is present. Minus 3 if the DAO can affect core smart contracts. Minus 4 if the team can unilaterally change the core.
Base Chain Decentralisation assesses the distributed ledger on which the DEX operates. Proof-of-stake receives minus 1 in all cases. Anonymous proof-of-stake is minus 2. A small or controlled group of validators is minus 3. A trusted sequencer is minus 4.
UI/UX evaluates the interface available to traders. Full marks for TradingView-grade chart integration alongside a simple swap interface. Minus 2 for basic price charts with limited customisation. An additional minus 1 for lacking a basic swap interface for retail users.
Market Structure and Optionality assesses the mechanisms available for trading and market-making. Minus 2 for missing an order book. Minus 1 for missing an automated market maker. An additional minus 1 for missing complex order types such as stop losses and limit orders.
Performance and Scalability measures transaction speed and settlement latency. Full marks for sub-second settlement. Minus 4 for 12-second latency, the best case for settling on Ethereum's base chain.
Smart Contract Security evaluates the language used for exchange logic. Solidity is an immediate minus 3: a language with well-documented vulnerability classes, including reentrancy, integer overflow, and front-running susceptibility, that have resulted in billions of dollars in losses.
Compliance Posture is assessed against FINMA's substance-over-form standard. If any function would attract regulatory action: minus 4.
Wallet Software evaluates the primary custodial wallet used to connect to the DEX. NPM-dependent wallets are minus 2, reflecting structural supply-chain vulnerability. MetaMask specifically is minus 3, given its over 212,000 package dependencies from anonymous contributors. Closed-source proprietary wallets are minus 4.
Results
| Factor | Uniswap | Hyperliquid | PancakeSwap | Aster | Lighter |
|---|---|---|---|---|---|
| Decentralisation | 3 | 1 | 1 | 1 | 1 |
| Base Chain | 1 | 1 | 2 | 1 | 1 |
| UI/UX | 3 | 5 | 2 | 5 | 5 |
| Market Structure | 3 | 4 | 3 | 4 | 4 |
| Performance | 5 | 5 | 4 | 5 | 5 |
| Smart Contracts | 2 | 2 | 2 | 2 | 2 |
| Compliance | 1 | 1 | 1 | 1 | 1 |
| Wallet Software | 2 | 1 | 2 | 1 | 1 |
| Total | 20 | 20 | 17 | 20 | 20 |
Uniswap (20/40) has immutable core smart contracts and permissionless liquidity provision, earning partial credit for decentralisation. But UNI token concentration among early insiders introduces centralisation risk, and the migration to Unichain, a Layer 2 with a centralised sequencer, creates precisely the operational handles that allow regulatory pressure to be applied to a single point. The interface is simple but lacks professional-grade analytics. Market structure offers AMM with concentrated liquidity and limit orders, but no order book. Performance on Unichain is strong at approximately 200ms pre-confirmation, but this speed is purchased at the cost of sequencer centralisation. Solidity-based contracts. MetaMask as primary wallet.
Hyperliquid (20/40) delivers excellent performance: 100-300ms latency, gasless transactions, TradingView-grade analytics, and a professional trading interface. These are genuine achievements, achieved by centralising everything that matters. Smart contracts are upgradable with admin controls. Trading relies on a controlled validator set in which the Hyper Foundation controlled approximately 78.5% of total validator stake at the time of the JELLY incident in March 2025, far exceeding the two-thirds consensus threshold required to act unilaterally. 135 When that control was exercised, validators forced settlement of an entire market at an arbitrary price to protect the protocol's own vault.133 The base chain, HyperCore, is the same centralised system that conducts trades. The wallet implementation is not published as standalone open-source software; the code path cannot be verified. Maximum marks for UI/UX and performance. Minimum marks for everything concerning trust and decentralisation.
PancakeSwap (17/40) uses multisig and timelocks for admin actions, meaning privileged keys exist. BNB Chain's 21 consensus validators per epoch, drawn from a set of 45, represent concentrated control. The interface is functional but unintuitive. Market structure offers AMM, concentrated liquidity, limit orders, and TWAP functionality, but the CLOB is available only for perpetuals, not spot markets. Solidity-based contracts. MetaMask as primary wallet.
Aster and Lighter (both 20/40) follow the Hyperliquid pattern: excellent performance and professional interfaces built on centralised infrastructure. Aster's matching and settlement happen on its own off-chain execution layer. Lighter operates on its own centralised Layer 2. Both use Solidity-derived contract interaction, both have identifiable operators, and both use closed-source proprietary wallets whose code paths cannot be independently verified. Strong products for professional speculation. Not decentralised exchanges.
The highest score among all five platforms is 20 out of 40. Half marks, at best. Strong interfaces built on centralised foundations score well for what they do visibly and fail on everything they hide. The demand for trustless exchange is genuine and growing. The supply, as this framework demonstrates, is zero.
What We Built
The previous sections documented what does not work, why it does not work, and proved it systematically. Every major DEX scored against the criteria that matter for genuine decentralisation failed at half marks or below – they are DINODEXs – Decentralised In Name Only DEXs’. The demand for trustless exchange is genuine and growing, yet not a single platform in the history of this industry has met it.
GajuDEX does. Not by improving on existing DINODEX protocols, but by starting from what every other project lacks: a governance-free resource layer producing real money, and a refusal to introduce any mechanism of control at the exchange layer.
Once more: GajuDEX has no governance token. There is no token of any kind. There are no admin keys, no upgrade authority, no edit function. The smart contracts are immutable after deployment: what is deployed is what runs, and what runs can be inspected by anyone through GajuDesk, QPQ's desktop operational toolset, which is free to all and open sourced (GPL3) for anyone to work with and adapt. Every claim made in the sections that follow can be independently verified by any reader with the technical inclination to look.
Two Mechanisms: How Exchanges Actually Work
Before examining what GajuDEX does differently, it helps to understand the two fundamental mechanisms by which any exchange matches buyers with sellers. These are not competing philosophies; they are complementary tools, each suited to different market conditions.
Imagine a market stall with two buckets: one full of apples, one full of oranges. The stall has no shopkeeper. Instead, a simple rule is posted on the wall: the number of apples multiplied by the number of oranges must always equal the same number. If you want to buy apples, you add oranges to the orange bucket and take apples from the apple bucket. The rule automatically adjusts the price: as apples become scarcer, each additional apple costs more oranges. As oranges become more plentiful, each orange is worth fewer apples.
This is how a Constant Product Market Maker (CPMM) works, the automated market maker, or AMM. Liquidity providers deposit both tokens into a pool, traders swap one token for the other, and a formula adjusts the price based on the ratio of tokens remaining. No human being sets the price; the mathematics does it. The elegance is that it always works: as long as someone has deposited tokens into the pool, there is always a price available and a trade is always possible. This makes AMMs ideal for newer or less liquid assets; even a single provider can start a functioning market. The weakness is precision: large trades move the price significantly, and professional traders who want to place orders at specific prices find the AMM limiting.
The Central Limit Order Book, or CLOB, is what most people picture when they think of a stock exchange. Buyers post the prices they are willing to pay. Sellers post the prices they are willing to accept. The exchange matches them: when a buyer's price meets or exceeds a seller's price, a trade executes. Every major stock and commodity exchange in the world uses this mechanism. An on-chain CLOB works the same way, except the matching happens through smart contracts rather than a company's servers. The advantage is precision: traders control exactly what they pay or receive, and market depth is visible. The disadvantage is that order books require sustained activity to function well, and running one on-chain is computationally demanding. On slow or expensive chains like Ethereum, the cost of placing and cancelling orders exceeds the value of most trades. This is why most existing order book DEXs resort to off-chain matching engines: the orders are processed on a company's servers and only the final settlement touches the blockchain. The matching is centralised. Only the settlement pretends not to be.
Groot's architecture, with microblock latency under three seconds and low transaction costs, makes a fully on-chain order book viable without the centralisation compromise.
GajuDEX offers both mechanisms operating in tandem. The AMM serves as the universal backstop: any token can be listed, any market can be bootstrapped, and there is always a price available. The order book serves professional traders and major trading pairs where precision and depth matter. In Phase 2, a best-price routing smart contract will combine both: when a trader places an order, the system checks whether the AMM pool or the order book offers the better price and executes accordingly. The woman running a corner shop who wants to convert Gajus to her local currency and the institutional trader managing a multi-million-franc position use the same infrastructure. Both will get the best available price – ‘best execution’ is a long-standing requirement of regulated centralised exchanges; why shouldn’t it be the base expectation on a decentralised one?
What GajuDEX Eliminates
Every controlling function that enables the DINO problem has been architecturally removed. The smart contracts have no admin keys, no upgradability mechanism, and no governance vote capable of altering the core protocol. No party can exercise discretionary power over who uses the exchange; access is permissionless by design. No party maintains custody over user assets; trades are handled entirely by smart contracts. No entity controls which tokens may be listed or traded. There is no central primary liquidity provider with disproportionate influence over market conditions. These are structural properties of the deployed code, not policy decisions that could be reversed.
Front-end interfaces, including QPQ's own portal, may choose to filter which contracts they display: excluding, for example, tokens with misleading names or malicious contract implementations. This filtering happens in the interface, not the protocol. The underlying exchange remains open and permissionless regardless of which interface a user chooses.
The smart contracts are written in Sophia, the Gajumaru's smart contract language. Sophia was purpose-built for safety: a functional language compiled to the FATE virtual machine, designed to eliminate the vulnerability categories that have plagued Solidity-based contracts. Reentrancy attacks, the vulnerability class responsible for the $60 million DAO hack in 2016146 and countless subsequent exploits, are structurally impossible in Sophia's execution model. The language supports formal verification: mathematical proof that a contract behaves exactly as specified, under all possible inputs, before deployment. GajuDEX contracts will undergo formal verification before deployment; once verified and deployed, the contract is immutable. What was proved is what runs.
Every GajuDEX transaction is secured by GRIDS, the air-gapped signing protocol described in Chapter VIII. Private keys never exist on any network-connected device. The attack vectors that have stolen billions from browser-based wallet users (NPM supply chain compromises, browser extension manipulations, clipboard hijacking) do not apply.
Why No Governance Token Is Needed
The Gaju is a mined coin with no issuer. It is produced through proof-of-work on Groot, distributed algorithmically over an 87.5-year Fibonacci curve. No entity controls, directs, or profits from its issuance. QPQ designed the architecture this way; confirmation under Swiss law took eight months, not because the question was difficult but because it took that long to find a lawyer who would listen to the answer.
This matters for GajuDEX because of what it eliminates – the exchange does not need a utility token to facilitate trade, because trade is denominated in a currency (Gajus) that works independently of the platform. It does not need a governance token to distribute control, because the smart contracts are immutable and there is no governance function to tokenise. The regulatory question that haunts every other DEX, whether its token is really a security masquerading as utility, simply does not arise. There is no token. There is money – the Gaju.
GajuDEX on Associate Chains: The Same Principle, Every Currency
GajuDEX is open source, licensed under GPL3. The smart contracts are a toolset, not a product tied to a single deployment. Any Associate Chain operator can instantiate GajuDEX on their own chain, with their own native currency and the Gaju trading alongside it.
Consider a Swiss Associate Chain whose native currency is a tokenised Swiss Franc, issued by a regulated entity under licence. The operator deploys GajuDEX. Traders on that chain can now exchange Swiss Francs for Gajus, Swiss Francs for any other asset represented on the chain, or Gajus for anything else listed. The Associate Chain provides the settlement. The DEX smart contracts are the same immutable, governance free code that runs on Groot: no admin keys, no upgrade authority, no governance token.
Both currencies in that exchange are genuine currencies, not tokens conjured by a foundation. One is fiat: sovereign money, issued under regulatory authority, subject to the monetary policy decisions of a central bank. The other is sound money: a mined coin, produced through proof-of-work on Groot and acquired into the Associate Chain through the standard mechanism by which Gajus move between Groot and any AC. This distinction is fundamental: an Associate Chain cannot create Gajus. It cannot mint them, issue them, or inflate the supply. Every Gaju present on an Associate Chain arrived there because it was mined on Groot and subsequently moved into the AC. The fixed supply is enforced at the resource layer, and no Associate Chain operator, however they configure their own governance, can alter it.
The consequence for exchange infrastructure is that the governance token problem never arises on any deployment. On Groot, the Gaju is a mined coin with no issuer. On an Associate Chain, the native currency is whatever the operator has designed it to be, and the Gaju is present as a mined coin, acquired from elsewhere. Neither is a token conjured by a foundation to fund and control an exchange. Trading fees are earned in genuine currencies. Liquidity is attracted by genuine economic activity between actual currencies. The entire apparatus of governance tokens, voting rights, fee extraction by insiders, and the regulatory ambiguity that accompanies all of it, is absent because it was never needed. It was only ever needed to enrich the people who designed it.
Ownership Vs Service
GajuDEX is not a QPQ product. The smart contracts that constitute the exchange are open source, immutable after deployment, and owned by no one. Once deployed, QPQ cannot change them, freeze them, or control who uses them, and neither can anyone else.
What QPQ provides is services around the protocol. QPQ IaaS AG will operate a portal: a web interface that makes interacting with the smart contracts convenient and intuitive. That interface is a product, and QPQ charges for it. It is not the only way to access GajuDEX: anyone can interact directly with the smart contracts through GajuDesk, the standard, GPL3 open sourced desktop operational toolset for the Gajumaru, or indeed, build their own front-end portal. The portal is a convenience, not a gatekeeper.
Separately, QPQ Capital AG, with a VQF application in process, will seek to provide regulated financial services: a regulated exchange variant with KYC compliance, fiat on/off ramps, cross-chain bridges, advanced order types, and company share registry services. These are centralised, regulated, value-additive services that operate alongside the decentralised protocol. They are not the protocol itself and they are also no bar to anyone else providing a better service.
| Entity | Role | Relationship to GajuDEX |
|---|---|---|
| GajuDEX | Open-source DEX smart contracts | Not owned by anyone. Immutable after deployment. |
| QPQ IaaS AG | Portal interface provider | Portal access to GajuDEX. A convenience, not a requirement. |
| QPQ Capital AG | Regulated financial services (post-SRO) | Regulated exchange variant, bridges, registrar. Separate product, separate regulatory treatment. |
This three-way distinction separates genuine architectural innovation from regulatory arbitrage. GajuDEX eliminates all control mechanisms at the protocol level. Regulated activity exists where it belongs: in regulated entities, subject to oversight, clearly separated from the neutral infrastructure underneath.
Two Deployments, Groot and Known Proof of Stake Associate Chain
GajuDEX is a set of smart contracts deployable on any chain running the Sophia language and FATE virtual machine. The previous section described the principle: any Associate Chain operator can deploy GajuDEX with their own currency alongside the Gaju.
QPQ will deploy GajuDEX in two environments, Groot and a Known Proof of Stake Associate Chain (‘KPoS AC’) that provides institutional-grade throughput within a governed framework. This is the RPA/RIPA model at commercial scale: the same protocol, two paths, genuine choice between them.
The first deployment operates directly on Groot, the governance-free resource layer. Every trade settles through the same proof-of-work consensus that secures the Gaju itself. No validators to trust. No operators to identify. No jurisdiction to defer to. The exchange inherits Groot's full security properties: settlement certainty accumulating rapidly from first microblock inclusion, commerce-grade within seconds, and absolute irrevocable finality at two keyblocks – four minutes – for any transaction regardless of value. Accordingly, this will not be the fastest exchange in the world – that is the price of operating on a trustless resource layer. But, for users who require absolute neutrality, who cannot or will not trust any operator, or who operate across jurisdictions without shared legal frameworks, Groot is the only exchange environment where no one can say no.
The second deployment operates on a dedicated Associate Chain built by QPQ using identified proof-of-stake consensus. The native currency is the Gaju itself; there is no separate chain currency. Every validator is known and verified through on-chain KYC certificates. The staking asset is Gaju itself, minted on Groot through proof-of-work, which addresses the "nothing at stake" problem directly: the staked asset has value earned through genuine computational work, not created by the staking system itself. This is the port to Groot's high seas. Faster throughput, lower transaction costs, and the accountability that institutions require. Banks, asset managers, exchanges, and corporates can interact with the same DEX logic without exposing themselves to the compliance uncertainty of a purely jurisdiction-neutral venue. Validator entry is permissionless: any party that completes on-chain KYC can join the staking pool without QPQ's approval, and no single party can deny entry so long as more than one KYC authority is on record.
| Deployment | Security Model | Speed | Best For |
|---|---|---|---|
| GajuDEX (Groot) | Fully trustless; no validators to identify or trust | 2-3 second settlement | Maximum neutrality; cross-jurisdictional trade; users who require no trust assumptions |
| GajuDEX (KPoS AC) | Known validators; legal recourse; KYC-compatible | Sub-second target | Institutional participation; regulated environments; high-throughput trading |
Neither deployment should dominate. An institution uncomfortable with the purely trustless environment of Groot has a governed alternative. A user who finds the KPoS Associate Chain's governance unacceptable can fall back to Groot. Each disciplines the other, neither can succeed in excess.
The KPoS Associate Chain is as much a demonstrator as it is a product. It is QPQ's proof of concept for how any Associate Chain can be structured to satisfy the TEA trilemma. Efficiency without accountability is the failure mode of anonymous proof-of-stake: validators who cannot be identified cannot be held to account when they act against participants' interests. The KPoS model resolves this directly. Validators are identified and KYC-verified on-chain. The staking asset is Gaju, minted through proof-of-work, which means the "nothing at stake" problem that plagues anonymous PoS is addressed at source: stake has real cost. Known operators under identifiable legal jurisdiction provide the recourse that anonymous systems structurally cannot. Known validators, on-chain KYC, Gaju as the native currency, immutable exchange contracts, no governance tokens or admin keys at any layer: this is what an Associate Chain looks like when it is built for purpose and done correctly. Any institution considering whether to build an Associate Chain on the Gajumaru can examine the KPoS AC architecture as a concrete reference implementation. Other operators may follow the same model, adapt it, or design something entirely different. Their chain, their rules.
Measured Against the Same Standard
The scoring framework applied to every competitor in the preceding section applies equally here. The methodology does not change because the subject is our own work.
| Factor | GajuDEX (Groot) | GajuDEX (KPoS AC) |
|---|---|---|
| Decentralisation | 5 | 5 |
| Base Chain | 5 | 4 |
| UI/UX | 5 | 5 |
| Market Structure | 5 | 5 |
| Performance | 4 | 5 |
| Smart Contracts | 5 | 5 |
| Compliance | 5 | 5 |
| Wallet Software | 5 | 5 |
| Total | 39 | 39 |
GajuDEX scores full marks for decentralisation on both deployments because there are no governance mechanisms to capture.
Full marks for base chain on Groot (proof-of-work); 4 out of 5 on KPoS AC because known-actor proof-of-stake, while the strongest form of PoS, cannot match the trustlessness of proof-of-work.
Full marks for UI/UX on the planned portal design integrating TradingView-grade analytics alongside a simple swap interface.
Full marks for market structure with both AMM and CLOB plus complex order types. Performance scores 4 on Groot (under 3-second microblock latency is strong but not sub-second) and 5 on KPoS AC.
Full marks for smart contract security (Sophia, formally verifiable), compliance posture (no controlling operators), and wallet software (GRIDS, zero dependencies, air-gapped signing).
GajuDEX on Groot takes one point less than perfect for performance. This is an honest assessment: operating on the governance-free resource layer carries a throughput cost.
Against the same framework, every competitor scored 20 or below. GajuDEX scores 39 on both deployments. The gap is not a matter of degree. It is structural: the difference between architecture that eliminates controlling functions and architecture that retains them while calling itself decentralised. A score of 20 and a score of 39 are not different points on the same spectrum. They describe different things.
Regulatory Convergence Through Architecture
The three major regulatory frameworks examined above – FINMA's substance-over-form test, MiCAR's full decentralisation standard, and MAS's identifiable-operator framework – were developed independently, in different legal traditions, for different regulatory purposes. They converge on the same architectural requirement because they are all asking the same underlying question from different angles: is there anyone here we can hold responsible?
For DINODEXs (Decentralised In Name Only DEXs) , the answer is always yes. Governance token holders who can vote to alter smart contracts, redirect fee flows, or pause operations are a coordinated group exercising control. FINMA's 2022 Risk Monitor noted this explicitly: "many DeFi projects are currently often run, materially influenced or controlled by just a few people or companies, which raises questions about adequate supervision."147 Under MiCAR Recital 22, protocols with any element of centralised control are inside the regulatory perimeter regardless of their branding: partial decentralisation is not an exemption. Under MAS's framework, any identifiable party conducting a regulated activity requires a licence. Governance token holders directing protocol upgrades are identifiable parties conducting what, in substance, is market operation. These platforms should attract the same regulatory treatment as the licensed market operators they functionally resemble. That they have not reflects enforcement lag, not architectural immunity.
No regulator has yet issued a public determination naming a specific DEX as genuinely decentralised and excluding it from their jurisdiction. The reason is structural: no platform has filed for that determination because no platform would pass the test. The carve-outs were written for an architecture that did not yet exist.
GajuDEX was built to pass the tests simultaneously:
No operator exercises discretion: the smart contracts are immutable, with no admin keys, no governance mechanism, and no upgrade path.
No custody risk: user assets remain in user-controlled wallets until the moment of atomic exchange.
No information asymmetry: every aspect of the exchange is visible on-chain to every participant equally.
No operational manipulation: no one can front-run trades, because no one has privileged access. There is no identifiable party conducting a regulated activity, because there is no party.
The Liechtenstein legal framework addresses the relevant question directly: "decentralised exchanges are generally accepted under Liechtenstein law. However, it depends on the details of the business model whether or not the exchange is actually considered to be decentralised."148 GajuDEX does not have a business model to detail. The architecture eliminates not just the regulatory triggers but the underlying risks those regulations were designed to address.
This is a design objective, not a confirmed regulatory determination; QPQ will seek formal confirmation under FINMA's review process and, where applicable, under the Liechtenstein FMA's Unterstellungsanfrage mechanism before launch. The separation between the unowned protocol and the regulated service layer reflects exactly the division every framework anticipates. The regulated service exists where it belongs: in QPQ Capital AG, subject to oversight, clearly separated from the neutral infrastructure underneath.
What Genuine DeFi Looks Like on Real Money
When the underlying asset is genuinely scarce – fixed supply, proof-of-work, no governance body capable of creating more – the economics of decentralised finance change at every level. Scarcity alone is not sufficient; Bitcoin is scarce, but nobody conducts commerce on it. The missing element is utility: real economic activity denominated in the currency, generating demand for exchange that exists independently of speculation.
A merchant accepting Gajus at point of sale and converting a portion to fiat for suppliers or tax obligations creates a swap on GajuDEX. A buyer holding a stablecoin on an Associate Chain who needs Gajus to purchase goods creates a swap. Cross-border settlement between two sovereign Associate Chains, routing value through the Gaju as intermediary currency, creates two swaps. None of these transactions exist because someone is speculating on price movement. They exist because someone is buying goods, paying a supplier, or settling across borders. Strip out speculation from Uniswap and the volume largely disappears. GajuDEX is built to facilitate utility, not speculation, so there is no speculative volume to strip out.
This answers the liquidity question. A liquidity provider deposits into a GajuDEX pool and earns a proportion of the trading fees generated by every swap against that pool. No token incentive is needed. No governance vote is required. The fees exist because the economic activity exists. Liquidity attracted by genuine fee revenue persists as long as the underlying commerce persists. Liquidity attracted by token rewards evaporates when the rewards stop. The organic model is self-reinforcing: more trading activity generates more fee revenue, which attracts more liquidity, which reduces slippage, which attracts more activity. This is how markets have always worked when they work.
Real money changes the character of every function built on top of exchange infrastructure. A borrower deposits Gajus as collateral and receives another currency against them. That collateral is money whose value is determined by the same market forces that price any genuinely scarce asset with demonstrated utility, not a circular reference to the protocol that issued it. Liquidation against real money collateral is reliable in a way that liquidation against governance tokens structurally cannot be, because the attacker cannot manipulate the collateral price by attacking a governance mechanism. The Mango Markets exploit was a governance attack disguised as a market operation. That vector does not exist when the collateral is money rather than governance rights. Interest rates determined by supply and demand, without governance intervention, produce the price signal connecting savers to borrowers across an economy. That signal has never existed in DeFi because the assets being intermediated were not real money, and the rates were set by vote rather than by market.
What Becomes Possible
The significance of what has been described in this chapter is not the exchange itself. It is what the exchange completes.
The Gajumaru provides a governance-free resource layer. Groot provides trustless settlement. The Gaju provides real money with fixed supply. Associate Chains provide governed infrastructure where efficiency and accountability coexist. GajuDEX provides genuine permissionless exchange across all of them. Together, these are the complete architecture for an open global economy: one in which any person, anywhere, can participate in any legal economic activity without requiring permission from an intermediary who can say no.
Every component is load-bearing. Remove the resource layer and there is no trustless foundation. Remove the real money and there is nothing to transact in that is not someone else's liability. Remove the exchange and currencies cannot flow between jurisdictions, chains, or participants. Remove the governed path and institutions that need accountability have nowhere to operate. Remove the ungoverned path and there is no exit when governance overreaches. The architecture works because every element exists, and the choice between paths is genuine.
What follows are examples. They are not exhaustive. They are illustrations of what becomes possible when the barriers to economic participation are architectural rather than permissive: when access to finance, insurance, exchange, and commerce is determined by what the technology enables rather than by who an intermediary allows through the gate. Each example describes a transformation that no existing blockchain can deliver, because no existing blockchain has the complete architecture to support it.
Insurance: From Product to Participation
Start with something ordinary: your car insurance. Today you pay a premium to an insurer who pools it with millions of others, invests the float, pays claims from the pool, takes a margin, and returns nothing to you when the year ends without a claim. You have no visibility into the pool, no way to verify the capital behind it, no access to the investment returns. You are a customer of a product whose economics are not yours to participate in. Between you and the capital that actually bears the risk sit a broker, a carrier, a reinsurer, and often a second reinsurer behind the first; each extracts a margin, and none of them is your counterparty in any meaningful sense. Your counterparty is a claims department.
Now imagine the same risk on genuinely trustless infrastructure.
You join a motor risk pool as a principal, not a customer. The pool is a smart contract. You can read every line of it. The collateral backing every policy in the pool is locked in the contract, visible on-chain, verifiable before you pay a single premium. Your premium is set not by an actuary in a pricing department whose models you cannot see but by the market: every participant in the pool, and every provider of capital to the pool, has agreed to a price that reflects the risk they are collectively willing to bear. When the year ends without a claim, your share of the unexpended premium returns to you automatically. The insurance company is the code. Every participant can inspect it before committing capital. It cannot deny a valid claim through discretion, because it has no discretion: the conditions are defined, the collateral is locked, and settlement is automatic. It does not have a legal department.
The capital behind that pool does not have to come from an insurer. Anyone can stake into a motor risk pool and earn yield on the float the same way an insurer currently does. A pension fund in Copenhagen, a sovereign wealth fund in Abu Dhabi, a retired teacher in Manila with savings earning nothing in a local bank: all of them can participate directly in the economics of risk, staking capital into pools whose risk profiles they can inspect on-chain and whose returns are determined by claims experience rather than by the internal allocation decisions of a financial conglomerate. The risk does not change. The intermediation disappears.
Property and Capital
Your mortgage works the same way, and the consequences are larger. Your mortgage rate today reflects not just your credit risk but the cost structure of the entire chain that funds it: the originating bank, the warehouse facility, the securitisation vehicle, the rating agency, the institutional investors who buy the bonds. Each layer charges for its existence. The rate you pay is the aggregate cost of that chain plus the margin of every participant in it. The capital that ultimately bears your credit risk is priced by a market that has no direct connection to your specific property, your specific income, or your specific circumstances. It is priced as a tranche in a structured product, and the tranche pricing reflects the assumptions of models written by people who have never seen your house.
On genuinely trustless infrastructure: your mortgage is a smart contract. In the year ahead, we plan to deploy the technical architecture in the Gajumaru to enable your property to be completely represented as a data-rich digital asset structure: its title, valuation history, and maintenance records fully represented on-chain, their consistency maintained by mathematical proof such that the on-chain record and the real-world state cannot diverge. Your income and credit history become provable through advanced zero-knowledge proof techniques developed specifically for decentralised financial market operations, confirming the relevant facts without revealing the underlying data to anyone who does not need it.
The mortgage originator, which might still be a local lender who knows the property market, issues a loan and immediately distributes the risk into the pool as a tradeable instrument on GajuDEX. Capital from anywhere in the world bids on it. The rate that clears is the global market's assessment of the risk: not a spread over a benchmark set by a central bank committee, not a margin extracted by every intermediary in a securitisation chain, but the price that actual capital is willing to accept for the actual risk. Every participant can see every position. The market is continuous and the pricing is real.
The consequence for your mortgage rate is not marginal. The consequence is structural: you pay for your credit risk, not for the infrastructure required to make your credit risk accessible to capital. That infrastructure currently costs more than two hundred basis points across the intermediation chain.149 On genuinely trustless rails, the intermediary extraction that constitutes the majority of those costs disappears. What remains is the cost of origination, risk assessment, and network settlement: a fraction of what the current chain imposes.
None of this requires new theory. It requires the infrastructure described in this chapter: trustless settlement, real money, genuine exchange, and the choice between governed and ungoverned paths that lets each jurisdiction calibrate its own requirements.
The Unserved World
The previous examples transformed existing markets: insurance and property finance that already function, made more efficient by removing intermediary cost. The deeper transformation is reaching markets that do not currently function at all. Consider what is currently uninsurable or unfinanceable; not because the risk is unacceptable but because the cost of writing, administering, and settling a small-value contract through conventional channels exceeds the economics. A smallholder farmer in sub-Saharan Africa with two hectares of maize cannot access crop insurance because no conventional carrier can profitably write a policy worth $200 in annual premium. A micro-entrepreneur in rural Indonesia cannot access working capital because no bank can profitably underwrite a loan of $500.
Each of these is not a failure of capitalism. It is a failure of infrastructure. Satellite imagery, soil data, and mobile payment histories now provide credit signals for smallholder farmers and micro-entrepreneurs that rival or exceed the predictive power of traditional credit scoring models applied to corporate borrowers.150 The capital willing to bear these risks, if it could access them efficiently at scale with trustless settlement, exists in abundance. What does not exist is the mechanism through which that capital meets those risks without a chain of intermediaries each extracting a minimum viable margin that collectively exceeds the value of the underlying transaction.
An example: a parametric crop insurance pool on Groot collects $4 premiums from a thousand smallholders. The oracle is a rainfall index. The trigger is precise. The settlement is automatic. Capital staked into the pool earns a return calibrated to the actual weather risk in that region. Nobody in that transaction needs to trust anybody else:
The farmer trusts the oracle data because it is published on-chain by a feed with a verifiable track record; if the feed has historically matched actual rainfall measurements, that record is inspectable by every participant before they commit.
The capital provider trusts the contract because it is immutable and its terms cannot be changed after deployment. The oracle risk is real: a feed can be wrong, but the risk is transparent, quantifiable from the feed's history, and therefore can be priced into the pool accordingly. That is categorically different from the opaque actuarial models behind conventional insurance, whose assumptions no policyholder can inspect.
This is not a charitable vision, it is an economic one that the combination of Gajumaru, Groot, Gajus and GajuDEX make possible. Capital earns better risk-adjusted returns with access to a wider, more diversified set of risks priced by genuine market competition rather than by a concentrated oligopoly with bilateral information advantages. Borrowers pay lower rates when competing for capital in a global market rather than paying the cost structure of a local intermediary with no competitive pressure. The global economy, unlocked.
Tokenised Shares and Pre-IPO Liquidity
Risk pools and lending markets move capital to where it is needed, but capital itself – the equity in the enterprises that create value – remains locked behind infrastructure that restricts who can own it, when they can trade it, and what it costs to transfer.
Switzerland and Liechtenstein have enacted legislation that allows natively on-chain tokenised shares to constitute the legal instrument itself. Under the Swiss DLT Act of 2021, a company's articles of association can specify that whoever controls the token is the legal shareholder: not the holder of a digital wrapper around an off-chain certificate, but the actual shareholder, with the chain enforcing the rights.151 QPQ Capital AG will deploy share registrar services that makes this operational on the Gajumaru: a legally compliant registry for Swiss capital companies, with an optional upgrade to tokenised, ledger-based securities.
The problem this solves is not hypothetical. An early-stage company, a growth business, or a professional practice may have shareholders who want liquidity before any IPO path is viable. Today that liquidity simply does not exist: there are no compliant rails for secondary trading, no mechanism for genuine price discovery, no market where privately held tokenised equity can actually trade. The company's shares are illiquid by default until either acquisition or public listing.
GajuDEX changes this directly. Tokenised shares trade on the permissionless exchange. Economic transfer is instant: a buyer pays Gajus, the token moves, the transaction is settled. Legal recognition follows when the holder activates it through the registrar service, a straightforward process because the KYC information required was already collected when the holder established a regulated account. The result is a genuine pre-IPO secondary market with a compliant path to full legal recognition built into the architecture from the start.
The same infrastructure extends to any asset requiring an external authority to confirm its real-world state: property titles, vehicle registrations, professional licences, commodity export certificates. Each requires an interface between the on-chain record and a state institution or trusted third party. Associate Chains provide exactly that interface, keeping on-chain and real-world states in sync without collapsing the distinction between them.
Intellectual Property
Tokenised shares represent ownership of enterprises, but enterprises are not the only things people create that have economic value – copyright is a human value before it was a legal category.
When someone creates something (a song, a novel, a photograph, a design, a piece of code) they have produced something with real economic value that belongs to them. The history of the creative industries is largely a history of that value being extracted by intermediaries: labels, publishers, studios, platforms, distributors. The creator's share of the economic activity their work generates has been progressively compressed by the requirement to route that work through infrastructure those intermediaries control.
On-chain intellectual property registration changes the structure of that extraction entirely. Every creative output can be registered through a smart contract that enforces royalty payments on every subsequent transaction, in perpetuity. The creator sets the terms, the smart contract enforces them. Royalties flow into a dedicated treasury for that work, and the treasury issues participation tokens calibrated to a bonding curve that rewards early supporters proportionally: those who discovered, promoted, and championed the work before it found its audience participate in the value they helped create – real capitalism that automates the reward of risk taking to benefit the risk takers that establish value. Secondary sales generate royalty streams back to the original creator, automatically, without a collecting society taking a cut or a publisher deciding whether to pass the money on. The creator's share is not a negotiated percentage of someone else's margin, it is a structural entitlement enforced by code.
The scope of what this enables is only now becoming clear, and it reaches into territory the original architects of copyright law could not have anticipated.
Large language models are trained on human creative work: books, articles, code, music, art, conversation. The models that result are extraordinarily capable precisely because the training data was extraordinarily rich. The people whose work constituted that data have, in almost every case, received nothing for their contribution. The infrastructure for compensating them did not exist: there was no mechanism to track which works contributed to which models, no marketplace for licensing creative content to AI training pipelines, no way for a creator to set a price for their work's use in machine learning and receive it automatically when that use occurred.
Every creative work metatag-registered on-chain is a work whose rights, provenance, and licensing terms are transparent and verifiable. A poet whose work is included in a training dataset has, for the first time, an on-chain record of ownership and licensing terms that any responsible operator of a training pipeline can query and honour. The infrastructure for receiving a micropayment when the licence is consumed now exists. What remains is industry adoption of the standard: the willingness of AI operators to query on-chain rights before ingesting content. That adoption will come either voluntarily or through regulatory compulsion, and when it does, the infrastructure must already exist. The market for creative content, which currently operates through opaque bilateral deals between large institutions, becomes continuous, transparent, and accessible to every creator, regardless of whether they have a label, an agent, or a publisher.
Art and collectibles represent approximately $1.7 trillion in value.152 Global media rights exceed $2.3 trillion.153 The broader intellectual property market is valued at approximately $6.6 trillion.154 The infrastructure for transparent, perpetual value distribution across these markets does not exist because the tools to make it possible did not exist. They do now.
This is not merely a commercial correction. It is a restoration of the principle that creative work belongs to those who create it and those who give it purchase in the market and shape its trajectory; that the value their work, their contribution, their risk generate should flow to them proportionally rather than being captured by whoever controls the distribution infrastructure.
Human Capital
Creative output is one form of productive value. The most universal form is simpler: your time, your skill, your labour. What is your time worth? Not in the abstract: right now, this week, to someone who needs exactly the skills you have. Today you can sell your time only to people you can reach, through channels those people have access to, in the currency they can pay you in. You negotiate a rate and trust that you will be paid. If you are not paid, your practical recourse is negligible: legal remedies for small claims cost more than the debt, and the economics of legal services are structured to serve the dispute, not the claimant. The infrastructure for monetising human capital globally, at any scale, with trustless settlement, does not exist.
We are changing that, right now. A smart contract in which you tokenise a defined scope of work, priced in a stable unit of account, settled automatically on verified delivery, fundable by any buyer anywhere in the world who can inspect your on-chain work history and decide what your time is worth to them: this is not a distant vision. It is an application of infrastructure that already operates. The platform that currently extracts 20% for connecting you to work and another 2.9% for the payment 155 becomes a front-end that competes for your custom on the quality of its matching, because the settlement layer underneath charges thousandths of a cent and belongs to no one.
Physical Commodities
Physical commodity markets run on standardised contracts: defined grades, specified delivery points, agreed inspection standards. The settlement infrastructure around them – exchanges, clearinghouses, warehouse receipts, brokers – exists because counterparties operating across jurisdictions with no shared legal framework need neutral ground for pricing and settling those standards. That is precisely the function a trustless resource layer provides. The parallel to Groot is direct: neutral ground where parties sharing no common legal framework can price and settle standardised instruments without trusting each other or any intermediary. PHYDEX, the planned physical and derivative exchange extension of GajuDEX, applies this logic to commodity markets specifically, and is examined in detail later in this chapter. The architecture is the same. The application is different. The intermediary cost structure is, if anything, even more pronounced: a physical commodity transaction crossing three jurisdictions currently touches a broker, an exchange, a clearinghouse, a warehouse operator, an inspection agent, and often a trade finance bank. Each charges their fees and levers their costs. The commodity itself does not change. The infrastructure required to move ownership of it is where the cost accumulates.
The Convergence
Every one of these examples arrives at the same point. The intermediary exists because there is no alternative. When the alternative exists, the intermediary must justify itself by the value it actually adds rather than the infrastructure it controls. Some intermediaries add genuine value and will thrive in that competition. Many do not and survive only because the infrastructure is captured.
GajuDEX is the market. Groot is the neutral ground on which the market operates. The Gaju is the money that makes it all denominated in something real. Together they constitute not a better version of the financial system that exists but the foundation for an economic system that the current one structurally prevents. Groot has been operational since October 2024. The Gaju is being mined and the path is open for millions to participate without needing specialist skills or huge hardware investment. GajuDEX is being built. The first sovereign Associate Chain is in development with the Principality of Liechtenstein. The examples in this section are not speculation about what blockchain might eventually achieve, they are applications of architecture that exists, on infrastructure that runs, using money that works.
The Internet of Economics is not a metaphor. It is what you get when value moves as freely as data already does, and when the infrastructure through which it moves belongs to no one.
From Digital Assets to Physical Markets – PHYDEX: Physical and Derivative Exchange
The GajuDEX architecture is not limited to trading digital assets against each other. The same smart contract infrastructure can support standardised contracts for physical commodities and their derivatives.
PHYDEX, the Physical and Derivative Electronic Exchange, is a planned extension designed to bring tradeable market depth to commodity markets. Global commodity markets remain fragmented across bilateral relationships, opaque pricing, and intermediary-heavy settlement processes, despite the underlying commodities being standardised and fungible. The vision is standardised contracts for every major commodity specification and port combination: FOB (Free on Board), CFR (Cost and Freight), CIF (Cost, Insurance and Freight), and other Incoterms-based contract types, with integrated oracles for price discovery, inspection certification, and quality verification. A copper contract FOB Santos differs from a copper contract CIF Rotterdam; both are standardised, and both can carry tradeable depth on a transparent order book with atomic settlement.
This is still in formulation, not active development. The technical foundation exists: GajuDEX's CLOB architecture handles the order matching, Sophia smart contracts can encode the contract specifications, and the Associate Chain model provides the governed environment that commodity counterparties require. The commercial and regulatory design remains to be worked through.
The potential is substantial. Global commodity derivatives markets measure in the trillions annually. A neutral, transparent exchange with atomic settlement and immutable contract terms would eliminate counterparty risk for the matched portion of every trade. The genuine value that clearinghouses currently provide, netting of obligations and settlement guarantees, becomes architecturally unnecessary when settlement is atomic: the trade completes in full or does not occur at all. There is nothing to net. There is no counterparty risk to guarantee against.
Supply, Demand, and the Currency
None of this alters Groot's issuance economics. The fixed supply of one trillion Gajus, minted over an 87.5-year Fibonacci curve, is immutable. GajuDEX, the applications built on it, and every Associate Chain connected to Groot create demand for the currency without creating supply. Groot is the mint. GajuDEX is the exchange. They are connected through the currency they share, but neither can alter the other's fundamental rules. As the Fibonacci curve reduces block rewards over decades, transaction fees across this growing network of exchange, settlement, and commerce increasingly fund Groot's own security. The economic model sustains itself because the demand is real.
Implementation
The GajuDEX core infrastructure (the immutable CPMM smart contracts on Groot, the open-source UI, GajuDesk direct access, and one-click pool deployment) is planned for Q2 2026. CLOB deployment follows within 30-60 days. QPQ Capital AG's regulated services, including the cross-chain bridge, advanced order system, share registrar, and KYC-enabled front-end, deploy progressively over the subsequent 90-180 days.
All timelines are subject to Series A funding. A shortfall in funding would push deployment by two to three quarters. The smart contracts exist; the architecture is defined; what remains is the engineering, testing, and deployment work that funding enables.
Part Three: From Architecture to the Real World Economy
X. Open Innovation: Patents, Licensing, and Defensive IP
QPQ AG, the creator of the Internet of Economics and the Gajumaru that makes that possible, exists to enable economic emancipation through choice and is intended to serve everyone, which means that it must belong to no one.
This philosophy extends to how we treat intellectual property.
Innovation flows freely through open systems. Restricting access to technology through aggressive patent enforcement harms the ecosystem we are trying to build. In a world where others hold patents that could be used against us, however, we cannot operate undefended.
Our purpose is not to stop innovation. It is to stop others from stopping us, and you, from innovating.
The IP strategy has two tools: an open source licence that keeps the code free, and a defensive patent approach that prevents the code from being closed by others. Together they form the third structural pillar alongside the open protocol and the governance-free architecture. All three ensure that no one can close what we have opened: not through governance capture, not through code proprietisation, and not through the patent system.
GPL3: Open Source That Protects Openness
Groot is open. Anyone can build on it: Associate Chains, platforms, applications, services – whatever they choose, owned entirely by those who build it. QPQ has no gatekeeping role and wants none.
Everything QPQ has built to create the Gajumaru and its foundational tools – GajuDesk, GajuMobile, GajuDEX, and all QPQ platforms including GajuPay, GajuMarket, and GajuMe – is licensed under GPL3 (GNU General Public License version 3) and will be open-sourced in full, including the implementation of patented technologies. You can use them, build on them, modify them, or ignore them entirely and build your own from the ground up.
What GPL3 means:
| Principle | Implication |
|---|---|
| Freedom to use | Anyone can run the software for any purpose |
| Freedom to study | Anyone can examine how the software works |
| Freedom to modify | Anyone can adapt the software to their needs |
| Freedom to distribute | Anyone can share the software with others |
| Copyleft protection | Modifications to GPL3 code must also be shared under GPL3 |
The copyleft provision is critical. GPL3 prevents anyone from taking the protocols and tools that we open source to the world, making proprietary modifications, and using those modifications to compete against the open ecosystem. You cannot take the open foundation and build proprietary walls on top of it.
What you build on Groot or through an Associate Chain is a different matter entirely. GPL3 does not reach your applications, your chain, or your business. Your applications are yours. Your chain is yours. Your business is yours.
QPQ has deliberately given up every structural advantage that would allow us to control rather than compete: proprietary access, enforced patents, captured governance. We have kept one thing: the expertise and endeavour we bring to an open ecosystem that everyone can commercialise. We win by being the best at serving it, not by controlling access to it.
Build what you want. Own what you build. Keep the tools open.
GPL3 and Patents: The Built-In Peace Provision
GPL3 goes further than most open source licences in one specific respect that matters directly here. Section 11 of GPL3 contains explicit patent provisions: any contributor or distributor who conveys covered work grants every recipient a patent licence for that work.156 A GPL3 contributor cannot simultaneously convey software under GPL3 and sue recipients for patent infringement arising from that same software.
This creates what practitioners call patent peace within GPL3-covered software. Combined with QPQ's defensive approach to patents – deter attack, never initiate it – the effect is layered protection. Our patents prevent external actors from asserting IP against the Gajumaru. GPL3's Section 11 prevents any GPL3 contributor, including QPQ, from doing the same thing against users.
The architecture closes the loop. The resource layer cannot be captured through governance. The code cannot be locked through proprietisation. The patents cannot be turned against the ecosystem. Each layer reinforces the others.
Why GPL3 and Not a Permissive Licence
GPL3 is a copyleft licence. Alternatives such as MIT and Apache are permissive licences: they allow anyone to take the code, modify it, and release those modifications under any terms they choose – including proprietary terms. Under a permissive licence, a well-resourced actor could take the Gajumaru's open source code, make improvements, and release a proprietary fork that locks users into a controlled system.
This is not hypothetical. The history of open source software includes multiple cases where permissive code became the foundation for proprietary products that competed against the open version whilst drawing on its development. In the blockchain context specifically – where the purpose of the resource layer is to remain governance-free – a permissive licence would create a direct route to the outcome the architecture is designed to prevent.
GPL3 closes that route. The choice is deliberate and structural, not a default. If you improve the Gajumaru, your improvements serve the ecosystem. That is the condition of building on what we built.
Defensive, Not Offensive
There are two established ways to hold patents. The difference matters.
Red Hat (the model QPQ follows) was the first company to pledge formally not to offensively assert patents against open source software (2002).157 It has never been the plaintiff in a patent lawsuit. It co-founded the Open Invention Network in 2005158 and the LOT Network159 to protect open source from patent aggression. Its patents exist to ensure freedom to operate: they deter attack without initiating it.
QPQ's position is the same. Our patents exist to deter attack, not to launch one. We will never be the plaintiff in a patent dispute against an open source developer or a builder on the Gajumaru. An aggressive patent strategy against ecosystem participants would contradict the resource layer's purpose: open ground where no single actor can say no.
Tony Benn's five questions apply here as much as to any centralised blockchain system: what power do we hold? Where did we get it? In whose interest do we exercise it? To whom are we accountable? How can you remove us? The answers, in order: a defensive IP position; through legitimate filings; to protect the ecosystem; to the entire open network; by building on the GPL3-licensed protocol without reference to us at all. The patent strategy passes the test it sets for others.
Freedom to Build: What This Means for Participants
The combined effect of the IP strategy is simple: there is nothing in the Gajumaru's legal architecture that gives any actor – including QPQ – the ability to close the ecosystem.
For anyone building on the Gajumaru, this means:
You can use the technology. The GPL3 licence is unconditional. There is no usage agreement that can be revoked, no foundation that can decide you are unwelcome, no governance vote that can exclude you.
You can inspect the technology. The source code is open. You do not need to trust QPQ's descriptions of how the system works. You can verify it.
You can fork the technology. If you believe you can build something better, build it. GPL3 requires that your improvements remain open – but it does not restrict your ability to improve and compete.
You cannot be sued by QPQ for building on it. GPL3's Section 11 provisions ensure that QPQ's IP cannot be turned against the ecosystem.
Nobody else can close it either. QPQ's defensive approach deters external actors from using the patent system to block the Gajumaru's development or adoption.
This is what freedom to operate actually means: not just the absence of a lock today, but the structural impossibility of one tomorrow.
Part Four: Why Everyone Else Failed
Blockchain is a word that once meant something precise. ‘Crypto’ is an industry that saw Bitcoin and instead of seeing the pathway to humanity’s restoration and freedom, saw a pathway to mass extraction. To facilitate this, they changed the popular understanding of the word and used it to create a fig leaf for their end, and those ends have nothing to do with blockchain: not as a technology, not as a philosophy, not even as an inspiration.
Blockchain is no more a part of crypto than the printing press is a part of counterfeiting.
Blockchain offered a method of establishing trust between parties who share none – a way to verify that a message has not been altered without requiring trust in whoever carried it, to trust the message, not the messenger, securely, at scale.
A blockchain is, at its simplest, a shared record that nobody controls and nobody can alter without the whole world noticing. Every entry is linked to the one before it by a mathematical seal. Change any entry and you break every seal that follows it. To rewrite the record, you would need to redo the mathematical work of every entry made since the one you wish to change – and do so faster than every honest participant in the network is adding new entries. The cost of falsification is designed to exceed any conceivable gain from it. This is proof-of-work: not a feature, but the entire point. The record is trustworthy not because anyone guarantees it, but because the mathematics of attacking it make the attempt irrational. No administrator. No password. No off switch. No one to bribe, coerce, or regulate into changing an entry that has already been made. The message is the authority. That is all blockchain is. It is also, as the preceding three Parts of this document have demonstrated, enormously consequential – and, done correctly and honestly, genuinely simple for anyone who takes the time to read to understand.
The question it answers is equally simple: how do two parties who share no trust, no common authority, and no basis for negotiation verify that what passed between them is true?
Crypto discarded that question entirely and kept only the vocabulary. It has no interest in how strangers verify truth between themselves. Its instruments are not built to answer that question – they are cryptographic betting slips, positions in a game whose rules were written by the house, whose odds favour the house, and whose only value to the holder is what the next participant can be persuaded to pay. More precisely, they are chances: the possibility of gain or loss in a game the holder does not control and cannot fully see.
Generously, a few might be called financial products – and they walk like financial products, and they quack like financial products. The industry would rather you did not call them that, because financial products attract the regulatory oversight that the pretence of decentralisation exists specifically to obscure.
These cryptographic betting slips and obscured financial products are given the title ‘tokens’ for that is what the proof-of-stake ‘blockchains’ that they are issued using create. But they are also tokens just like you would get walking into a casino in Las Vegas or Macau: tokens for money you surrendered at the door in the hope that you might be one of the lucky few that leave with more than you arrived with.
The industry that uses these (usually gamed, as we will shortly prove) proof-of-stake blockchains to issue these tokens is not in the business of building trust architectures. It is in the business of manufacturing and distributing exit liquidity at scale, positioning insiders for a controlled, extractive exit before these instruments reach the hands of those who will ultimately hold the loss. That this is done under the banner of the technology that could have restored economic freedom to ordinary people is not irony. It is the point.
To protect that position, the industry needed the word 'blockchain' to carry a meaning it had never held: complexity. Not the genuine complexity of a difficult problem honestly described, but manufactured complexity – the deliberate construction of an intellectual barrier high enough that ordinary scrutiny cannot scale it. If 'blockchain' can be made to appear too technical for regulators, too novel for lawyers, too sophisticated for institutional investors to evaluate without specialist guidance, then nobody pulls the thread. The industry has funded university chairs, endowed research programmes, and cultivated a consultant class specifically to ensure that when a sceptic surfaces, an authoritative voice is available to confirm that evaluation requires years of specialist study. The manufactured complexity is the moat. The extraction is the castle it protects.
There is a further dimension that deserves to be named directly. Blockchain's genuine property – the elimination of the need for a trusted intermediary – was repurposed by the industry as a shield against the accountability that trusted intermediaries attract. They retained the control. They claimed the trustlessness. They took the benefits of both and accepted the obligations of neither. When things went wrong, the protocol was responsible. The community was responsible. Nobody was responsible. The word 'decentralised' became not a description of architecture but an alibi – and the word 'blockchain' became the fig leaf that kept the alibi credible.
The preceding three Parts of this document were, in one sense, preparation for this moment. Blockchain is not complex. The problem it solves is precise and expressible in a single sentence. The test it sets is equally precise. We have spent considerable effort demonstrating that any reader who follows the argument carefully can understand exactly what blockchain is, what it requires, and what it is capable of – and what it is not, and cannot be made to be. That preparation was deliberate. The reader who has followed the argument to this point does not need to defer to the industry's appointed experts. They have the tools to examine the claims directly, and the confidence to use them.
The reason this document arms the reader so carefully is not abstract. We built an actual blockchain – one that passes every test this document sets, that has been operational since October 2024, that settles transactions in seconds with mathematical certainty, that issues a mined coin no government can print and no insider pre-allocated. One that provides, for the first time, a genuine governance-free resource layer: neutral ground between jurisdictions where parties who share no common legal framework, no mutual trust, and no diplomatic relations can transact on equal terms.
We built it because we believe that economic freedom requires a genuine exit from controlled systems – not the abolition of governance, but the existence of an alternative that disciplines governance by making extraction costly. That is what blockchain makes possible. That is what the industry that calls itself crypto has spent seventeen years and over $120 billion preventing from reaching the people it could serve. The obscuration of the word is not a side effect of the industry's commercial activities. It is a precondition for them.
Crypto is not a failed attempt at blockchain. It is humanity's subjugation dressed in blockchain's vocabulary – the deliberate capture of a technology that offered genuine liberation and its conversion into one of the most efficient wealth transfer mechanisms in financial history, moving value from the many to the few under the banner of decentralisation. The betrayal was not accidental. It was structured, funded, and executed with precision. Its consequences are measured not only in the billions lost by retail participants who believed the vocabulary, but in the years stolen from a technology that could have begun rebuilding the economic foundations of human freedom. Suppressing a genuine technology does not destroy it. It defers it. The obscuration is ending. The technology endures. It is delivered. This document is part of the delivery.
An informed public, equipped with the correct definition of blockchain and the correct test for whether any system meets it, would not have funded what was built in blockchain's name. This document exists because the informed public deserves to exist – and because what we built deserves to be seen for what it is, which requires, first, that what the industry built is seen for what it is.
The emperor has no clothes. Part Four provides the sourced, systematic account of what is underneath them: the distinction the industry has worked hardest to obscure, the analytical framework that follows from it, and the evidence across fifteen scored Layer 1 assessments, four deep case studies, a full examination of DeFi, and the institutional failures that consumed billions in procurement budget without producing anything that works.
XVII. The Two Fundamental Tests
The Test for Trustlessness
Blockchain does one thing. It allows us to trust the message, not the messenger, securely at scale. The test for whether any system is, in fact, a blockchain is therefore simple:
Does this allow me to trust the message, not the messenger, securely at scale?
This is the only question that matters for blockchain specifically – because it is the only property that justifies blockchain's existence and its costs. A trusted database is faster. A trusted database is cheaper. A trusted database is simpler to build, simpler to operate, and simpler to use. The only reason to pay the costs of a blockchain is to obtain the one property a trusted database cannot provide: the ability to verify that what passed between parties is true without trusting anyone who was party to it.
Either a system provides that property or it does not. Either the record is trustworthy because the mathematics of attacking it make falsification irrational – or it is trustworthy because someone is vouching for it, and you are trusting that someone. There is no middle ground. A system that is mostly trustless, or trustless except for the sequencer, or trustless except for the Foundation, or trustless except for the validator set, is not trustless. It is a system with a trusted intermediary wearing different clothes, it is expensive decentralisation theatre.
The moment a system fails this test, a second question immediately follows: if trust in a messenger is required, who is the messenger and what power do they hold?
The Test for Power
Where trustlessness is absent – or claimed but not delivered – power exists. Power over the record. Power over the rules. Power over who participates and on what terms. That power requires examination, regardless of the vocabulary used to describe it.
The sharpest instrument available for that examination was developed not by a technologist but by a politician. Tony Benn served in the British Parliament for fifty years, held senior Cabinet positions in two Labour governments, and became the most prominent democratic socialist of his postwar generation. His politics and ours share very little common ground. His intellectual honesty and his instinct for power are another matter entirely.
Speaking from the floor of the House of Commons on 21 May 1990, Benn directed five questions at the House in regard to the European Commission – an institution he believed exercised enormous power over the citizens of member states while remaining structurally shielded from the accountability that power demands (bold text for emphasis is ours):
I have five questions that I ask people who have power, and I recommend them to the House. If I see someone who is powerful, be it a traffic warden, Rupert Murdoch, the head of a trade union or a Member of Parliament, I ask myself these five questions: "What power have you got? Where did you get it? In whose interests do you exercise it? To whom are you accountable? How can we get rid of you?" That last question is crucial. We cannot get rid of Jacques Delors; we cannot get rid of the Commission. We can get rid of a Government; but we cannot get rid of European legislation that a Government have entrenched during their period in office… the issue is fundamental. If we get it wrong we shall destroy parliamentary democracy in Britain. It is a time bomb ticking away under us. Perhaps the fuse is still long. When the British people discover that, whomever they vote for, they cannot change the laws under which the Government have governed, this House will collapse as a valid part of a democratic constitution. That is the argument that we should be having. When we have established it in the democratic way, we can resume the argument about how we should recommend the people to use the power that remains in their hands. Tony Benn, five questions to power, House of Commons, HC Deb 21 May 1990, Hansard vol 173 cc121-43, Column 135. Available at https://api.parliament.uk/historic-hansard/commons/1990/may/21/social-charter#column_135
His argument was specific: you could vote your national government out. You could not vote out Jacques Delors. You could not vote out the Commission. It exercised its power, set its rules, and directed the affairs of hundreds of millions of people with no mechanism by which those people could remove it. The democratic circuit was broken. The accountability of power to the electorate through the House of Commons was broken. The power of the European Commission was, therefore, unrestrained and total.
The application to any centralisation of power is equally simple: if you cannot answer the last question, the preceding four do not much matter. You have identified power that cannot be removed by those it governs, those whose lives it impacts have no say whether they are private citizens deprived of access to their money or global financial institutions deprived of theirs.
The vocabulary centralised power uses to describe itself is irrelevant to what it actually is, the truth is in the response to those questions Benn put to, sadly, deaf ears in Parliament.
The Vocabulary of Unaccountable Power
The crypto industry has constructed an extraordinary vocabulary for describing unaccountable power as its opposite. Foundations. DAOs. Community governance. On-chain voting. Decentralised sequencers. Global synchronisers. Validator sets. Governance tokens. The language shifts with each new project and each new funding round.
The word 'token' itself requires examination, because it is doing the heaviest lifting in that list. The word 'cryptocurrency' has a precise definition, stated in the title of the document that introduced the concept: 'Bitcoin: A Peer-to-Peer Electronic Cash System,' published by Satoshi Nakamoto on 31 October 2008.[^~1~] A genuine cryptocurrency is money that moves directly between parties without an intermediary, in a unit whose supply no central authority controls, verified by mathematics rather than institutions. A coin is minted by proof-of-work: it does not exist before the computational work is done, it cannot be pre-allocated to insiders because the network sees every block from the first, and its supply is determined by the algorithm rather than by the people who built the system.
A token is different in every respect that matters commercially. Tokens are created by smart contract on proof-of-stake chains, allocated by whoever deployed the contract – before public participation, on whatever terms the deployer chose, in whatever quantities the deployer determined. A founding team can assign itself forty percent – or more, as many have – of all tokens that will ever exist before a single member of the public has heard of the project. A venture fund can receive a further allocation under vesting terms invisible to retail participants until after they have purchased. A Foundation treasury can hold a further reserve – liquid on its own schedule, locked for retail on a different one. None of this requires any work. The tokens exist because someone decided they should.
This is not a design flaw. It is the design. Proof-of-work prevents the pre-allocation that makes the extraction mechanism work. Proof-of-stake permits it. The industry's near-universal migration away from proof-of-work was not a technical choice driven by efficiency or environmental concern – those are post-hoc rationalisations. It was a commercial choice. The consensus mechanism is the business model. 'Governance tokens' are not a mechanism of democratic participation. They are the instrument by which insiders retain control of a system they have already extracted from, dressed in the vocabulary of accountability.
Apply Benn's last question to any of them: how can we get rid of you?
You cannot vote out the Foundation. You cannot remove the sequencer operator. You cannot replace the validators the Foundation subsidises into existence. You cannot change the vesting schedule the insiders wrote before you arrived. The system will process your transaction, take your fee, and remain exactly as it was – governed by exactly the people who governed it before you participated, on exactly the terms they set, for exactly as long as they choose to maintain it. This is not decentralisation. It is centralisation with a marketing budget. It is the theatre of decentralisation whose objective is to extract your wealth to garner theirs.
These two tests are the instruments for everything that follows in Part Four. The first cuts through the technical architecture to the single property that justifies blockchain's existence. The second cuts through the vocabulary to the power that property was meant to replace. Apply them to every claim you have been asked to accept. Do not take the vocabulary at face value. The evidence that follows will show you what is underneath it.
XVIII. The ‘Blockchain Trilemma’
The Classic Framing
The 'blockchain trilemma', as commonly stated, posits that any blockchain must sacrifice one of three properties: decentralisation, security, or scalability. Pick any two.
This framing is not a constraint of physics. It is a rhetorical convenience – one that has served, for over a decade, as a respectable explanation for why an industry that absorbed over $120 billion in investment160 has not produced anything that actually works.
The framing belongs to Vitalik Buterin.161 The argument was thin. Within a few years it had been elevated to industry gospel, repeated in whitepapers, cited in keynotes, and used by investors and boards to justify adopting systems whose fundamental limitations it had quietly licensed.
Consider whose interests this framing serves.
Ethereum, post-Merge, operates with concentrated stake (six entities controlling over 50% of validation162), delivers approximately 22 TPS in practice162, and depends on a Layer 2 roadmap that has not resolved its throughput problem and never will. Under the classic trilemma, Ethereum can describe itself as having chosen 'decentralisation and security' while working on scalability. The framing puts that claim beyond question. It does not survive serious examination.
What if the framing was designed to hide the questions Ethereum cannot, or would rather not, answer?
The Problems with the Classic Framing
'Decentralisation' has been stretched to cover situations that are structurally indistinguishable from centralisation. Solana claims decentralisation with thousands of validators; 72% of them receive Foundation delegation, and 57% would struggle to maintain profitable operations without it.163 Ethereum claims decentralisation while between four and six entities control the majority of stake and, in the months following the 2022 Merge, OFAC-compliant validators processed over 70% of blocks.164 The word is used to cover both situations simultaneously. It covers neither.
'Security' conflates properties with different causes, different failure modes, and different mitigations. Resistance to a 51% hash-rate attack is not the same as resistance to validator collusion, censorship by concentrated stake, or capture of the governance mechanism. A network can be highly resistant to one while being trivially vulnerable to the others. Bundling these into a single term prevents the relevant questions from being asked precisely.
'Scalability' is the most comprehensively gamed metric in the industry. Claimed transaction speeds derive from theoretical maximums, synthetic benchmarks, or counting internal consensus messages as user transactions. When actual demand materialises, the numbers collapse. At peak congestion in 2021, over 75% of Solana non-vote transactions failed.165 The metric is concrete in principle and fraudulent in practice.
The deeper failure is structural. The classic trilemma treats its three terms as independent variables, as though each could be dialled separately. They are not independent. They are deeply interconnected, and the framing was designed to hide those connections.
C.A.R. Hoare identified the design choice in his 1980 Turing Award lecture:
There are two ways of constructing a software design: one way is to make it so simple that there are obviously no deficiencies, and the other way is to make it so complicated that there are no obvious deficiencies. The first method is far more difficult. It demands the same skill, devotion, insight, and even inspiration as the discovery of the simple physical laws which underlie the complex phenomena of nature. It also requires a willingness to accept objectives which are limited by physical, logical, and technological constraints, and to accept a compromise when conflicting objectives cannot be met. No committee will ever do this until it is too late.166
The industry took the second path. When a single system could not deliver trustlessness, efficiency, and accountability simultaneously, the response was to add complexity: Layer 2s on top of Layer 1s, bridges between chains, rollups posting to base layers, sequencers coordinating between systems. Each addition introduced new failure modes requiring further additions. In the folds of complexity, especially, deliberately contrived complexity, the absence of trust and accountability can always be hidden. The solutions became the problem, and the problem became the business model.
The trilemma named the consequence and mistook it for a law of nature.
Security Is Derivative
Here is what the classic trilemma obscures: security is not a separate property. It is derivative. It emerges from other choices.
In a genuinely trustless system, security comes from the mechanism itself. Proof-of-work creates security through physics and mathematics – the energy expenditure required to attack the network. You do not need to trust anyone. The mechanism is the security. The more trustless the system, the more secure it is against the attacks that matter: collusion, censorship, capture. In a system that requires trust, security becomes a question of accountability. You must ask: who am I trusting? Why should I trust them? What happens if they violate that trust? What recourse do I have?
A system with verified, known validators provides security through accountability. Validators behave because they can be identified, sued, regulated, removed. The security is real, but it is a different kind of security – it ultimately depends on external enforcement mechanisms (courts, regulators, reputation) rather than the protocol itself.
A system with anonymous validators provides neither. The mechanism does not deliver trustlessness (you must trust validators not to collude), and there is no accountability (you cannot identify or punish them if they do). This is the worst of all positions: security theatre.
The Correct Analytical Framework – TEA
Strip away the obfuscation. Three genuine trade-offs remain.
Trustlessness: Can you trust the message without trusting any messenger? Proof-of-work is the only mechanism that answers this definitively. The energy required to produce a valid block is irreversible. The mathematics checks out only if the work was done. You do not need to know who produced the block, or to trust them. The work is the proof. Every alternative reintroduces a messenger whose honesty must be assumed. Something is either trustless or it is not, there can be no degree of violation, it can only ever be a binary state.
Efficiency: How fast, how cheap, what throughput? This is the dimension the emergence of proof-of-stake ‘blockchains’ was designed to maximise – its justification for setting aside proof-of-work rather than improving it. This rush to efficiency forgot – or perhaps, more accurately, denied – a crucial truth: Trust enables efficiency; trustlessness has costs. A trusted SQL database will always outperform a trustless blockchain on raw transaction speed. This is not a problem to solve – it is the price of trustlessness, worth paying when no messenger can be trusted, not worth paying when one can.
Accountability: When trust is required – when a messenger must be relied upon – what recourse exists? Can bad actors be identified? Subjected to legal jurisdiction? Held to account? Removed? This dimension only becomes relevant where trustlessness is absent. In a fully trustless system there is no one to hold accountable, because there is no one whose honesty was relied upon.
These three properties sit at the corners of a triangle. Every protocol positions itself somewhere inside it. The question is where it actually sits, and whether it is honest about the trade-offs.
The Triangulation
The relationship is not 'pick two.' It is a triangulation: three positions between which a protocol must locate itself, with the honesty of that location being a separate and equally important question.
At the trustlessness corner sits genuine proof-of-work. Maximum resistance to collusion, censorship, capture. Security through irreversible physical expenditure. Minimum efficiency – PoW is slow and expensive by design. Accountability is not applicable; there is no one you had to trust.
At the accountability corner sits verified proof-of-stake with identified, regulable operators. Trust is required, but recourse exists. Security is through external enforcement, but it is genuine where operators can be identified, sued, regulated, replaced. Efficiency is high because trust enables speed. Trustlessness is sacrificed, but honestly so.
At the efficiency corner sits honest centralised infrastructure. Maximum speed, minimum cost. No trustlessness – you trust the operator entirely. Accountability depends on the operator's legal exposure. If the operator is clear about what they are – a fast database with known operators – the system may be useful and should be regulated accordingly. If they claim to be a blockchain, they are not.
The Failed Middle
Anonymous proof-of-stake positions itself in the centre of the triangle, claiming partial achievement of all three properties. In practice it achieves none.
No trustlessness. You must trust validators not to collude. With concentrated stake – Ethereum's four to six entities controlling over 50%, Solana's Foundation determining validator survival – collusion is not theoretical. It is the operating reality. OFAC-compliant validators already censor transactions. The 'decentralised' network has a de facto governance structure; it simply refuses to admit it. So long as they are permitted to get away with such blatant regulatory arbitrage and people are prepared to pay them for it, they will continue to operate this way.
No accountability. Validators are pseudonymous at best. When they collude, censor, or extract – what recourse do you have? You cannot sue anonymous validators. You cannot regulate entities you cannot identify. You cannot remove bad actors from a system where bad action cannot be attributed. Apply Benn's last question: how can we get rid of them? The architecture of staking makes the question unanswerable by design.
Mediocre efficiency. Anonymous proof-of-stake is slower than a trusted database. If participants must trust validators anyway, why not use efficient infrastructure with accountable operators? The 'decentralisation' premium purchases nothing but a ticket to the theatre of decentralisation.
Add a Foundation controlling which validators survive, and the failure compounds: governance without accountability, layered on top of pseudonymity without recourse.
Harold Pinter’s The Birthday Party put the same dynamic on stage. In the production, Stanley, the lodger, lives in apparent, boring normalcy. Two strangers arrive. The party proceeds. The menace was present from the first scene – it is not that something goes wrong, it is that something was always wrong and most of the room either did not notice or chose not to.
By the final curtain Stanley is silent, stripped of coherent speech, and led away by the strangers who organised the party he did not know was for him. Anonymous PoS users buy the same ticket. The Foundation runs the theatre. It controls which validators survive, which rules apply, which forks proceed – whilst disclaiming responsibility for any of it. A known entity that could be held accountable, structured precisely to resist being so. The validators set the rules. The menace for users – no trustlessness, no accountability, no recourse – is present from the start. Most participants do not see it. They pay their fees and transact and call it decentralised. Until OFAC compliance kicks in, until the Foundation forks the chain, until the validators extract. Then they discover what the play's audience knew from act one: the birthday party was never theirs.
This is not a technical failure. It is regulatory arbitrage dressed as innovation, extracting at participants' risk.
Physics Constraints
Physical laws constrain every protocol, whether its creators acknowledge them or not.
Light travels approximately 300,000 kilometres per second. Earth's circumference is 40,075 kilometres. The minimum round-trip for a point-to-point global signal under perfect conditions is roughly 266 milliseconds. Introduce multiple nodes, computation, and consensus rounds, and you have the irreducible reality of a genuinely distributed ledger.
Sub-second transaction acknowledgement is unremarkable. Any node can tell you it has seen your transaction within fractions of a second. That is not the interesting question. The interesting question is when the transaction is settled – when it can be trusted, spent, relied upon. Settlement requires consensus across the validator set. Any chain claiming sub-second settlement with globally distributed validators is making one of three claims: either validators are co-located (centralisation), settlement is not real (the transaction can still be reversed), or the thousands of validators cited do not all participate in the consensus round (theatre). Sub-second settlement is a centralisation confession, not an achievement.
Throughput arithmetic is equally unforgiving. Block size multiplied by block frequency equals maximum data throughput. More validators distributed globally means more latency, which means lower throughput. You cannot solve a bandwidth problem by adding more nodes. Claims of high TPS combined with high decentralisation are mathematically suspicious. Multiply the claimed TPS by the minimum transaction size. Compare the result to block size multiplied by block frequency. If the mathematics do not work, the claim is fraudulent.
Groot's position – more than 1,846,200 times more transactionally efficient than Bitcoin, with at least 8.23 times greater security in commercial utilisation – is pushing against what physics permits for genuine proof-of-work. This is not an achievement that others could replicate with better engineering. It is approaching the limits of what trustlessness allows, because the laws of physics are not overcome by marketing.
Why the Framing Matters
The classic trilemma asked: what technical properties can your system achieve? That question can be answered with benchmarks and architecture diagrams. It cannot expose a business model.
The TEA framework starts with a single gateway question, the most fundamental question of a blockchain: can I trust the message rather than the messenger? Is it trustless? If yes, the analysis ends there – the mechanism is the security, there is no messenger to hold accountable, no further questions required. If no, the real interrogation begins: what is the trade-off between efficiency and accountability? Is there a genuine one – trust conceded honestly in exchange for speed, with identified operators and real recourse? Or is the claimed trustlessness a pretence, cover for capturing efficiency gains whilst escaping the accountability that any genuine trust relationship demands?
These questions cannot be answered with benchmarks and architecture diagrams. They require honesty about what the system actually is.
A project evaluated under the classic framing can claim 'decentralisation and security' whilst its validators collude, its Foundation controls the network, and users have no recourse. Those facts have no vocabulary in the classic framing. They have precise vocabulary in TEA.
In Chapter XVII, Benn's five questions to power were established as the test for any entity claiming to be ungoverned whilst retaining control. TEA provides the framework that makes those questions architectural rather than merely rhetorical. When you know that accountability is a structural dimension – not an optional feature – the question 'how can we get rid of them?' ceases to be political and becomes technical. Either the architecture provides genuine recourse or it does not. Either the operators can be identified, subjected to jurisdiction, and removed, or the system is occupying the worst position in the triangle: the costs of governance, none of its protections, zero recourse.
A project evaluated under TEA must answer: is it trustless? If not, who must be trusted, and what accountability exists? The answers expose what the classic framing was designed to conceal.
The chapters that follow apply this test. The results are consistent.
XIX. The Four Patterns of Failure
When analysing any project claiming to be a blockchain – whether marketed as a 'Layer 1,' a 'Layer 2,' or any variant – look for the four patterns set out below. Each one prevents honest evaluation of what the system actually is. Each is disqualifying on its own terms.
They are not unrelated failures. All four serve the same purpose: enabling capital formation under false pretences – whether by replacing real metrics with fabricated ones, by making the architecture incomprehensible, by concealing who controls it, or by concealing who owns and directs it. The presence of multiple patterns in a single project does not compound the failure. It clarifies the intent.
Pattern 1: Performance Claims That Defy Physics and Mathematics
The TEA framework's efficiency dimension has one precondition: honesty. A throughput claim is either derivable from the physics of the architecture or it is not. If it is not, the project fails the efficiency test before anything else can be evaluated – because a number fabricated to attract capital is not an efficiency claim. It is a lie.
This is the industry's most consistently dishonest practice. The pattern has three components: theoretical maximums presented as operational performance; consensus-internal messages counted as user transactions; and failure rates that disappear from reported figures.
Theoretical maximum versus settled throughput.
A throughput figure means nothing unless it specifies what is being measured. Processing a transaction is not the same as settling it. Settlement is the point at which value is sovereignly yours through consensus – the point at which it can be trusted, spent, and relied upon. Every other step is bookkeeping and deserves no greater respect than that.
The industry reports the fastest number available, which is almost never settlement. Theoretical maximums derived from laboratory conditions, synthetic benchmark environments, or single-node tests bear no relationship to what a globally distributed network settles under real demand.
Solana's marketing claims 10,000+ TPS and has cited peaks of 65,000 TPS.167 Observed non-vote throughput – actual user transactions, excluding validator consensus votes – runs at approximately 1,492 TPS according to Chainspect.168 That figure does not strip out failed transactions, and it reflects calm conditions. When demand actually materialised – the memecoin surge on 5 April 2024 – 77% of all non-vote transactions failed on-chain, revealing settled capacity of approximately 250 TPS under real load.169
A system that delivers 250 TPS when people try to use it is a 250 TPS system. The 1,492 is a fair-weather number that cannot be relied upon when it matters. The claimed 65,000 has no observable basis in the network's actual performance.
Consensus votes counted as user transactions.
Proof-of-stake blockchains generate large volumes of internal validator messages – votes, attestations, consensus traffic – that are not user transactions. They carry no value. They represent no economic activity. They are the machinery of the network talking to itself.
Solana counts these in its reported throughput. At peak periods, non-user vote transactions have exceeded 90% of reported volume.170 Most of what Solana reports as 'transactions' are internal consensus messages. When actual user demand increased during the memecoin surge on 5 April 2024, 77% of all non-vote transactions failed on-chain, revealing realistic settled capacity of approximately 250 TPS under stress.169
In September 2025, on-chain investigators identified a single bot submitting 11 million transactions over 30 days with a 99.95% failure rate – all counted in Solana's reported throughput.171 The figure the market associates with the network bears no resemblance to what it settles for real users.
Failure rates concealed from performance claims.
A failed transaction is not a transaction. It consumed network resources and delivered nothing other than a deducted fee. Its inclusion in throughput figures is not a matter of statistical preference; it is a matter of statistical fabrication with no discernible purpose other than misrepresenting what the system can do.
The industry does not disclose failure rates in its marketing materials. Claims of 10,000 TPS, 65,000 TPS, or 100,000 TPS appear without methodology, without definition of what counts as a transaction, and without acknowledgement of the proportion of those transactions that fail under real conditions.
The test is simple: show the derivation. If a system claims 10,000 TPS, show the block size, the block frequency, the minimum transaction size, and the observed failure rate. If the mathematics support the claim, the claim stands. If they do not, it is not a performance figure. It is a fundraising number, at best. More likely, an egregious deceit.
Pattern 2: AI-Generated Obfuscation
A growing pattern: using LLMs (so called 'AI') to generate whitepapers that read as though they make sense but contain no technical meaning. In this field, the LLMs' tendency to hallucinate is a feature, not a bug. An LLM will write with enormous conviction statements of fact that are not, and will do so with the marketing flourish of the large data set it has been fed upon: 17 years of extremely well funded crypto marketing department output, for this is the only innovation of which the crypto industry can speak.
| Red Flag | What It Usually Means |
|---|---|
| "Decentralised" without explaining mechanism | Centralised with a marketing budget |
| Performance claims without methodology | Numbers are fabricated or cherry-picked |
| "Innovative consensus" without specification | Standard database with branding |
| Missing technical whitepaper | Nothing technical to document |
| Dense paragraphs, no specifics | AI-generated filler |
The test: After reading the 'whitepaper' – or whatever they offer as a technical paper – can you explain in plain language exactly how the system works? If not, the document was designed to prevent understanding, not enable it.
Hoare's counsel applies here as much as to architecture: there are two ways to construct something – make it so simple that its deficiencies are obvious, or make it so complicated that they are not. AI-generated obfuscation, itself trained on 17 years of crypto marketing copy with the same objective of obfuscation, applies that second path to language. A reader who feels unqualified to evaluate a claim does not evaluate it. A reader who encounters sufficient unfamiliar vocabulary becomes dependent on those who supply the vocabulary to tell them what it means. Like the hallucinating LLM, the cryptobros manage to sound entirely convinced when they pronounce facts that are not and opinions that have no relationship to facts.
The tell is consistent across projects: paragraphs that cannot be reduced to a plain-language explanation of how the system works, because no such explanation exists. Terminology that migrates between documents when scrutiny arrives at a component – 'sequencer' becomes 'coordinator,' 'ledger' becomes 'blockchain.' The architecture does not change. The vocabulary retreats from the point of weakness.
Ask why. Then ask who benefits from your confusion.
Pattern 3: Centralisation Hidden Behind Language
Any system with a 'sequencer,' 'mediator,' 'coordinator,' or 'synchroniser' is a system that requires trust in whoever operates that component.
| Component | What They Call It | What It Actually Is |
|---|---|---|
| Sequencer | "Transaction ordering optimisation" | A single entity that decides which transactions process, in what order |
| Mediator | "Conflict resolution layer" | A trusted party that can reject any transaction |
| Coordinator | "Network synchronisation" | A central point of control |
| Synchroniser | "Global state management" | The entity you must trust completely |
The test: If removing the sequencer/mediator/coordinator/synchroniser would break the system, then that component IS the system. Everything else is decoration.
The marketing will never tell you this. The technical documentation will, for anyone who reads it with the right question in mind. Indeed, entertainingly, the legally approved press release will often be more accurate than the marketing copy.
Documentation Archaeology Method:
Ignore the homepage; marketing is designed to obscure
Find the technical whitepaper; if there isn't one, that is Pattern 2
Search for 'trust' and 'trusted'; every occurrence reveals a centralisation point
Search for 'sequencer,' 'mediator,' 'coordinator'; map who controls these
Read the governance documentation; who controls upgrades? Who can pause the system?
The tells are always there:
| What You'll Read | What It Means |
|---|---|
| "Decentralised network" | The sequencer orders all transactions |
| "Trustless operation" | Users trust the sequencer to order transactions fairly |
| "Permissionless access" | The mediator is trusted to produce and distribute all results correctly |
| "Honest-but-curious assumption" | Operator is assumed honest; only curiosity is defended against |
| "Trust-minimised" (not "trustless") | Trust is required; just less than before |
| "Optimistic" (as in "Optimistic Rollup") | System assumes operators are honest; fraud detected after the fact, maybe |
Arbitrum's own documentation describes its system as "effectively a centralised, permissioned system," with "a draft strategy to move towards decentralisation" outlined as future work.172 The marketing describes a "leading Ethereum Layer 2 scaling solution" delivering "trustless transactions." The centralisation is not concealed in the technical documentation. It is stated plainly. The marketing simply does not repeat it.
The ADI Chain technical documentation is equally candid where the marketing is not: "The Sequencer is the L2 node component that ingests transactions and orders them into blocks… it operates under an honest-but-curious assumption for ordering: users trust the sequencer to order transactions fairly… The sequencer nodes use a closed network configuration (not exposed to the public Internet)."173 The marketing claims trustless operation. The documentation describes a closed, unauditable authority ordering all transactions. Both documents were published by the same organisation. Only one was written for investors.
The Canton Network provides the most fully documented example of vocabulary as concealment. Canton's original 2020 whitepaper describes the system as "a next-generation Daml ledger interoperability protocol" with "synchronization domains."174 The GitHub repository tags the project "ledger," "distributed-ledger," and "distributed-databases" – not "blockchain." The developer documentation warns explicitly: "There is no single, all-encompassing blockchain RPC endpoint you can call to retrieve all data."175 The technical team, writing for engineers, consistently described what they built.
The press materials following the latest fundraise describe “a permissionless blockchain”.
Between July 2024 and April 2025, Canton's own legally-approved press release boilerplate – the section reviewed by communications, cleared by legal, approved by executives – described the system as "the financial industry's first and only public chain."176 Not blockchain. Chain. In March 2025, coinciding with the Goldman Sachs-led Foundation formation, the boilerplate was quietly updated to "blockchain." By June 2025, coinciding with a $135 million fundraise, it had become "permissionless blockchain."177 Nothing that we found in their technical architecture changed between those press releases. The words upgraded with each funding round. The technical team's description never changed at all.
Both descriptions cannot be true. The technical team described what they built. The marketing team described what they needed to sell. Part Four examines Canton in detail in its own case study chapter.
Pattern 4: Foundations
Almost every 'blockchain project' has a Foundation at its centre. The language sounds benevolent: steward resources, support development, represent the community, ensure long-term sustainability.
The reality: extraction disguised as service, control disguised as stewardship, feudalism disguised as decentralisation.
Foundations hold the tokens. Foundations control the grants. Foundations decide which validators receive delegation and which starve. Foundations set the roadmap, approve the upgrades, determine who builds what. The 'community' they represent is the community they pay.
Apply Tony Benn's five questions to power: What power have you got? Where did you get it from? In whose interests do you exercise it? To whom are you accountable? How can we get rid of you?
If you cannot get rid of the Foundation, you do not have a decentralised system. You have a landlord who calls themselves a steward.
| Claimed Function | Actual Function |
|---|---|
| "Steward resources" | Hold tokens they can sell while users are locked |
| "Support development" | Create validator dependency through subsidies |
| "Represent community" | Accumulate delegated voting power passively |
| "Ensure decentralisation" | Concentrate control in identifiable entities |
The Subsidy Trap.
Foundations create validator dependency at industrial scale. The Solana Foundation, established June 2019 with an initial treasury of 167 million SOL tokens, illustrates this at scale:178
| Finding | Data |
|---|---|
| Validators operating below profitability | 70%+ |
| Validators that would fail without Foundation delegation | 57% |
| Top 3 validators' share of stake | 26%+ |
| Gini coefficient for validator profits | 0.9306 |
Most validators exist because the Foundation spawned them. Kydo, EigenLayer's head of special projects, was direct: validators "get 90-100% of their staking fund from Solana Foundation. Without it, they'd collapse."179 Remove the subsidies and the 'decentralised' validator set collapses to those few who can operate profitably: the large, the well-capitalised, the connected.
The Vesting Asymmetry.
A recurring pattern can be detected across token launches:
Foundation tokens are liquid or on favourable vesting terms
Retail and early investors are locked for extended periods
Token launches at high price driven by restricted supply
Foundation sells into retail demand while retail cannot sell
Price crashes after Foundation extraction
Retail holds the loss; Foundation has exited
This is not incidental. It is the mechanism by which value transfers from later participants to earlier insiders.
DFINITY demonstrates this pattern at its most extreme. At ICP's launch in May 2021, token distribution was:180
| Allocation | Percentage |
|---|---|
| Foundation, team, advisors, IC Association | 48.5% |
| Seed investors (2017, at $0.03/token) | 24.7% |
| Early contributors, partnerships, presale | ~25.3% |
| Node operators, airdrops, broader community | 1.5% |
The community the Foundation claimed to represent received 1.5% of the network they were told they owned. Foundation and insiders controlled 98.5% at launch.
Seed investors were subject to vesting schedules. The Foundation's tokens were not. Founder Dominic Williams confirmed: "Foundation didn't vest itself but plans on putting most of its ICP into neurons."181
ICP launched at approximately $750. The Foundation transferred 18 million ICP tokens – worth $3.6 billion at launch prices – to exchanges in May and June 2021.181 Within 50 days of launch, the price had crashed 95% to $28.30. Retail investors who could not sell watched from the locked position the vesting schedule had placed them in.
When foundations and insiders hold different vesting terms than those they invited to participate, the participants are exit liquidity. This is not incidental to the foundation model. It is the mechanism.
Governance Capture Through Delegation.
Proof-of-stake allows users to delegate voting power. In theory, this enables participation. In practice, the mechanics of delegation produce concentration:
Most users delegate passively to the default option
The Foundation is the default
Once delegated, users rarely revisit the decision
Foundation control grows with every new passive participant
Validators follow Foundation guidance to remain eligible for delegation
Governance votes become theatre: the Foundation controls the outcome before the vote opens
Users believe they have 'decentralised governance' when they have feudalism with better vocabulary and none of the accountability.
The Garden of Eden Problem, Revisited
Each of the four patterns has independent causes and takes distinct forms across projects. They share a common origin.
Any blockchain project that monetises the base layer creates something worth capturing. The moment there is a foundation to lobby, interests coalesce around it. The moment there is a governance mechanism, it can be subverted. The moment there is a staking token treasury, it can be weaponised. The moment there is a subsidy programme, it creates dependencies that concentrate power. The moment performance claims need no derivation, they become fundraising tools.
The apple is not a technical choice. It is a revenue model.
This is not a failure of individual teams. It is the logic of the system. Every incentive pushes toward monetisation of the base layer. The four patterns are not aberrations; they are the inevitable outputs of that logic applied consistently across an industry.
Groot was designed around the recognition that this problem is structural and permanent. There is nothing to capture in Groot because there is no position of privilege to occupy. No foundation to lobby. No governance mechanism to subvert. No subsidy programme to control. No performance claims requiring a hidden derivation. QPQ AG commercialises expertise around Groot; it does not control Groot itself, and it cannot. At every juncture, QPQ took the decision that made this less profitable in the short term but made its longevity more assured.
The four patterns do not appear in Groot because the conditions that generate them were designed out.
Conclusion
The four patterns are not new. Every one of them has precedent in securities fraud, regulatory evasion, and the long history of financial promotion that promises one thing and delivers another. What is new is the scale at which they operated and the speed at which capital moved on the basis of claims that did not survive elementary scrutiny.
The scrutiny is now arriving. Class action litigation against Solana (ongoing as of early 2026) alleges that token holders were misled about the nature of what they purchased.182 Regulatory action against various 'DeFi' projects turns on the same question: were users told one thing while the architecture delivered another? Courts and regulators are beginning to apply to blockchain projects the same standards of honest representation that govern every other form of capital formation.
We state publicly available facts and source our claims. Whether those facts constitute actionable misconduct is for courts and regulators to determine. That is their function. Ours is the prior step: identifying what the facts are and handing everyone else the same toolset to distinguish between facts and works of fiction.
XX: The Layer 2 Fallacy
The four patterns identified in the preceding chapter are not evenly distributed across the blockchain sector. They cluster, they concentrate and they reach their most extreme expression in the Layer 2 sector. Mathematically impossible performance claims are published as fact. Centralisation is hidden behind the most elaborate vocabulary the industry has yet produced – language deployed with an impeccable veneer of sophistication, artfully designed to obfuscate rather than communicate. Foundations extract maximum value at retail's expense. Whitepapers are written entirely by AI and published without the slightest human oversight, hallucinations intact. One national digital infrastructure project's original whitepaper was so obviously machine-generated that we wondered whether any of the people paying for this had any idea what they were paying for because a $20 subscription to ChatGPT without any original material to work off could have written what we read.
This chapter examines why.
Both Bitcoin and Ethereum have championed Layer 2 systems as the answer to their inadequacies. Bitcoin processes 3-7 transactions per second and cannot scale without undermining the architecture that makes it trustless. Ethereum adopted a rollup-centric roadmap that it presented as the path to mass adoption. Neither has produced an answer that works. The failures are not identical: their origins differ, and in Ethereum's case a financial incentive to keep adding layers compounds the engineering error. The conclusion is the same in every case. Layer 2s do not solve the trust problem. They paper over it at users' expense. The operators pocket the efficiency gains and escape the regulatory oversight their actual control warrants.
On the Ethereum side, three generations of scaling solutions were built in sequence. Each addressed the observable failure of its predecessor. Plasma, the first attempt, used child chains that periodically committed state to Ethereum, but if an operator acted dishonestly, every user had to exit simultaneously, flooding the main chain and defeating the purpose. Optimistic Rollups addressed that mass exit vulnerability. Zero-Knowledge Rollups addressed Optimistic Rollups' seven-day challenge period. None addressed the root cause, because the root cause is not a technical problem awaiting a fourth generation; it is the consequence of attempting to recover decentralisation from a system that had already abandoned it. This compounds in Ethereum's case as every new L2 generation sustains ETH demand, sustains the Foundation's thesis, and sustains the sequencer operators' revenue streams – themselves substantially owned by ETH-aligned venture capital and ETH ‘whales’ – regardless of whether it delivers what it promises.
Bitcoin's answer – the Lightning Network – failed on different terms but at the same point: the moment it met users and the market. The routing constraints are structural, the security vulnerabilities are unfixable at the Lightning layer, and the commercial trajectory now leads away from Bitcoin's interests entirely, despite the broad championing of Bitcoin advocates who have not fully considered the opposing interests at work. The factory produces the same output whatever the input chain.
In 1543, Copernicus proposed that the Earth moves around the Sun. The dominant model required eight distinct mathematical curves – epicycles – to account for the observed movements of the planets. Heliocentrism required one. The complexity of the geocentric model was not evidence of its sophistication. It was evidence of its error. When a premise is wrong, the only way to make it work is to keep adding patches. Each patch creates new inconsistencies. Each inconsistency requires another patch. C.A.R. Hoare strikes again.
The Layer 2 sector is the epicycle factory of blockchain. The chapters that follow examine the Layer 1s whose constraints made the factory necessary. Understanding what those Layer 1s actually are is the predicate for understanding why the factory cannot close.
I. The Mathematics
Every Layer 2 system that posts data to Ethereum's base layer faces a single physical constraint before any question of trust, governance, or proof mechanism arises. The constraint is the capacity of the channel through which that data must pass.
A transaction requires a minimum of 105 bytes: 20 bytes for the sender address, 20 for the recipient address, and 65 for the cryptographic signature. Real transactions – smart contract interactions, token transfers, DeFi operations – are larger. The 105-byte figure represents the smallest possible transaction, stripped of every optional field, with no contract call data at all. It is the most generous possible assumption for any throughput calculation.
Following the Dencun upgrade in March 2024, Ethereum introduced ‘blobs’ – dedicated data packets for Layer 2 transactions under EIP-4844. Each blob holds 131,072 bytes: 4,096 field elements of 32 bytes each, fixed by the KZG commitment scheme.183 Following the Pectra upgrade in May 2025, each Ethereum block targets six blobs and holds a maximum of nine.184 Total blob space is therefore 786,432 bytes at target and 1,179,648 bytes at absolute maximum, per block, shared across all Layer 2s simultaneously. Ethereum produces a block every 12 seconds.
This is not the capacity available to one Layer 2. It is the capacity available to all Layer 2s combined.
The arithmetic is exact. At any claimed TPS, the minimum bytes required per 12-second block are: claimed TPS × 12 × 105.
| Claimed TPS | Required bytes per block | Physical reality |
|---|---|---|
| 1,000 | 1,260,000 | Impossible: exceeds total maximum blob capacity for all L2s combined |
| 10,000 | 12,600,000 | Impossible: approximately eleven times total capacity |
| 100,000 | 126,000,000 | Impossible: 107 times total capacity |
There is a recurring argument that compression resolves this. It does not. Cryptographic signatures – the 65-byte component present in every transaction – are statistically indistinguishable from random noise. They cannot be compressed: any algorithm that attempts to compress random data will produce output that is the same size or larger than the input. The 65 bytes per transaction are incompressible by definition. The remaining 40 bytes of a minimum transaction offer limited compressibility. The compression argument fails at the point where compression is most needed.
The EIP-4844 specification references a long-term maximum of 16 blobs per block as a design horizon for full danksharding – a potential ceiling of 2,097,152 bytes per block.183 At that figure, 10,000 TPS from a single Layer 2 would still require six times the total available blob space. 100,000 TPS would require sixty times. The 16-blob horizon belongs in the same category as the 100,000 TPS figure attached to the ETH 2.0 roadmap, the execution sharding quietly shelved in October 2020, and the Stage 2 decentralisation that five years of effort have not produced. Ethereum has a well-established record of attaching large numbers to future delivery dates and redefining what those numbers mean when the dates pass. The 16-blob figure will be evaluated if and when it is delivered.
L2Beat records the following comparison between claimed and observed throughput across the major rollups:185
| L2 | Claimed TPS | Observed TPS | Maximum recorded |
|---|---|---|---|
| Arbitrum | 40,000 | 10-30 | 1,358 |
| Optimism | 20,000 | 10-15 | 142 |
| Base | 2,000-3,571 | 30-150 | 959 |
| zkSync Era | 20,000+ | 12-16 | 62 |
The gap between claimed and observed performance is not an implementation detail awaiting resolution. It is bounded by the physics of Ethereum's block space. No software upgrade changes the number of bytes in an Ethereum block. When Ethereum's founders described Layer 2s as the scaling path, they were describing a canal expansion project. The Layer 2 sector responded by building more ships than the canal could accommodate – and then publishing capacity figures based on the ships, not the canal.
The bandwidth constraint established here applies to all Ethereum Layer 2 architectures: Optimistic Rollups, ZK Rollups, and all variants. The ZK Rollup architecture contains a second and independent mathematical impossibility that binds at an earlier stage of the pipeline – before transaction data reaches the base layer at all. That constraint is examined in full in Section V.
II. A Roadmap, Not a Response
The scaling crisis was real
By 2020/21, Ethereum had a genuine problem. Gas fees during peak demand regularly exceeded $100 for a single Uniswap transaction. The base layer processed approximately 15-20 TPS, and every user competed for the same scarce block space. Competing chains – Solana, Avalanche, Binance Smart Chain – were growing rapidly by offering Ethereum compatibility without Ethereum's congestion.
The community's answer had been clear since 2017: ETH 2.0 would deliver execution sharding – 64 parallel execution chains, each running independently, with aggregate capacity scaling linearly with the number of shards. The 100,000 TPS figure attached to the ETH 2.0 roadmap was built on this architecture. The Merge – the transition from proof-of-work to proof-of-stake – was the necessary precondition. Execution sharding would follow.
Then the roadmap changed.
The October 2020 pivot
On 2 October 2020, Vitalik Buterin posted on the Ethereum Magicians forum, in a thread titled "A rollup-centric Ethereum roadmap."186 His argument was direct: rollup technology had advanced to the point where rollups would likely capture the majority of Ethereum usage before execution sharding shipped. By the time Phase 2 arrived, Buterin wrote, "essentially no one will care about it." The conclusion: redesign ETH 2.0 around rollups rather than execution sharding. Sharding would be repurposed as a data availability layer – cheap block space for L2s to post their batched transaction data – rather than as an execution environment.
The 100,000 TPS target survived the pivot, reattached to the combined system: L2s processing transactions, sharding providing data availability, Ethereum providing settlement beneath it all. The number moved; the promise remained.
This was a genuine response to a genuine problem. Rollup technology was advancing, competitive pressure was acute, and execution sharding had proved harder and slower to deliver than projected. The October 2020 post was an honest reassessment. It was also a pivot that aligned the new architecture with a specific set of commercial interests – those of the entity publishing the roadmap, the operators who would build on it, and the institutions that had accumulated ETH on the expectation of a particular monetary model. Those interests, and how precisely the rollup-centric roadmap served them, deserve examination.
What the Merge gave up
There is a prior question that the rollup-centric roadmap's economics obscure. Before asking who benefited from the L2 architecture, it is worth asking what Ethereum gave up when it made that architecture possible.
Under proof-of-work, Ethereum's security came from external computational work – independent of who held ETH. Miners were a separate economic class with their own capital at stake in hardware, and their interests did not automatically align with the Foundation's. Protocol changes that damaged them could be resisted; the Block Wars on Bitcoin proved the mechanism. The Merge eliminated that independent check.
Under proof-of-stake, validators are ETH holders. The people governing the protocol are the people profiting from it. The Foundation's treasury – denominated in ETH – became simultaneously a financial asset and a source of consensus power. Danny Ryan, then lead researcher at the Ethereum Foundation, identified the consequence directly: when Lido's share of staked ETH approached one-third, he stated that "Lido passing 1/3 is a centralization attack on PoS."187
The proof of what this architecture made possible arrived within weeks of the Merge. After the US Treasury sanctioned Tornado Cash in August 2022, Flashbots – the dominant MEV relay, used by approximately 60% of validators at the time – began censoring Tornado Cash transactions without being specifically instructed to do so by OFAC. Within weeks, 65% of new Ethereum blocks were OFAC-compliant.188 Under proof-of-work, validators were anonymous miners; regulatory pressure had no identifiable surface to press against. Under proof-of-stake, validators were Coinbase, Kraken, Lido's node operators – regulated (or regulatable) entities with compliance obligations and legal addresses. The architecture created the compliance surface the sanctions required. The deeper analysis of what Ethereum is, and what it became, belongs to a later chapter.
For the purposes of understanding the L2 story, the point is simpler: the Merge was the precondition for the rollup-centric roadmap, and it was also the point at which Ethereum exchanged whatever trustlessness it had for a governance structure that served its largest holders.
What the pivot preserved: four aligned interests
In August 2021, the ‘London’ hard fork introduced EIP-1559, which restructured Ethereum's fee market. Every transaction paid a base fee – burned, permanently destroyed – plus an optional priority fee paid to validators. The base fee adjusted with block fullness: higher demand meant higher base fees, more burns, and less ETH in circulation.189 Ethereum had its first deflationary day in September 2021, one month after London. Justin Drake, Ethereum Foundation researcher, coined the term "ultrasound money" to describe the thesis: because ETH is burned with every transaction, the more Ethereum is used, the scarcer ETH becomes.189
The thesis had a dependency, visible to anyone who traced the arithmetic. Burn requires fees. Fees require congestion. Congestion requires scarce block space. A scaled L1 with abundant block space – 64 parallel execution chains – would produce low fees, low burns, and a supply that expanded rather than contracted. The ultrasound money thesis and genuine L1 scaling were not compatible objectives.
The rollup-centric roadmap resolved this tension by design. L1 remains congested because L2s handle execution. L1 handles settlement only, at fees that sustain the burn mechanism. The architecture that preserves ETH's deflationary character is, by the same arithmetic, the architecture that pushes execution to L2s.
This is the first of four commercial interests the pivot preserved.
The second is sequencer rent. Every L2 rollup operates a sequencer – the entity that orders and batches transactions before posting them to L1. The sequencer earns revenue from the spread between user fees and the cost of posting data to Ethereum. This spread is profit extracted from users transacting on L2, paid to whoever operates the sequencer. The rent layer exists only because transactions happen on L2 rather than on a scaled L1. Genuine L1 scaling eliminates it: if Ethereum processes transactions directly, there is no sequencer, no spread, no rent.
Arbitrum's sequencer generated $21.6 million in net profit in the twelve months preceding EIP-4844, running at an approximately $25 million annual rate in early 2024.190 Base generated approximately $30 million in gross profit in 2024, more than Arbitrum and Optimism combined.191 By H1 2025, the Optimism Superchain alone – Base, OP Mainnet, and associated chains – was generating $48.4 million in sequencer revenue in a single six-month period, with Base accounting for 87.2% of it.192
The third interest is the tributary structure. Every L2 must post data to Ethereum, verify proofs on Ethereum, and settle through Ethereum. Dozens of L2s mean dozens of streams of ETH demand flowing back to L1 validators and the burn mechanism. The rollup-centric roadmap turned competing chains into tributaries, each generating sustained ETH demand by structural obligation. A single scaled L1 chain generates only its own – cheap – fees. The tributary structure disappears along with the rent.
The fourth is the staking cartel's economics. The six largest staking entities – Lido, Binance, etherfi, Coinbase, Figment, Kraken – collectively control over 52% of staked ETH.193 They earn from validating L1 settlement transactions. The rollup-centric architecture concentrates high-value settlement activity at L1 while pushing high-volume execution to L2s, allowing validators to earn from the dependency without processing the throughput. Genuine L1 scaling would require processing dramatically higher transaction volumes at lower fees per transaction. The comfortable economics of settlement-only validation depend on the L2s remaining dependent.
Coinbase's position illustrates the alignment. It operates Base's centralised sequencer, earning sequencer revenue. It holds 5.1% of staked ETH, earning validator rewards. It listed ARB, OP, and other L2 tokens, earning exchange fees. Its commercial interest runs through every layer: L2 execution, L1 settlement, and the token markets that require the ecosystem to remain intact.
Applying Tony Benn's five questions to Coinbase's position in this architecture: What power have you got? Exclusive control over transaction ordering and inclusion on a network securing billions in user assets, plus validator influence over L1 settlement, plus exchange authority over the token markets that price the entire ecosystem.
Where did you get it from? Coinbase built Base and designed it that way; its ETH position was accumulated through commercial operations; its exchange listings are commercial decisions made unilaterally.
In whose interests do you exercise it? Coinbase shareholders – the revenue from sequencer operations, validator rewards, and exchange fees accrues to a publicly listed company with no distribution obligation to Base users or the broader Ethereum ecosystem.
To whom are you accountable? The SEC, for matters affecting Coinbase as a reporting company – but not for Base's sequencer operations, which are not classified as a regulated activity, and not for its validator behaviour, which carries no specific regulatory framework.
How can you get rid of them? You cannot. Base has no governance token, no DAO, no community vote. There is no mechanism by which users, developers, or the broader ecosystem can remove Coinbase from any of the three positions it occupies simultaneously.
Three revenue streams. Three positions of structural power. No removal mechanism for any of them.
The TEA framework reaches the same conclusion from a different direction. On trustlessness: zero. Base's sequencer is a single identified operator with complete authority over transaction ordering and inclusion. There is no proof mechanism, no fraud window, no cryptographic guarantee that the sequencer has treated any user fairly.
On efficiency: sufficient to sustain the illusion, insufficient to fulfil the claim. The sequencer is efficient at extracting rent; it is not efficient at processing transactions at scale. A centralised sequencer processes transactions faster and more cheaply than Ethereum L1 under ordinary load – enough to generate user activity, enough to generate sequencer revenue, and enough to avoid the question of what happens under the throughput conditions Base's own documentation promises. The blob arithmetic in Section I above in this chapter answers that question. The efficiency is real within the narrow band where it has been tested. Outside that band, it has not been tested, because the load that would test it has never arrived and cannot be processed even if it did.
On accountability: partial, and the partiality is the point. Coinbase is a regulated entity subject to SEC oversight, MiCA authorisation in Luxembourg, and FinCEN registration. That regulatory perimeter covers its exchange operations and its custody services. It does not cover Base's sequencer. The entity with the most operational power over the network – ordering every transaction, extracting every basis point of sequencer revenue – sits outside the regulatory framework that governs everything else Coinbase does.
This is not the anonymous proof-of-stake failure TEA was designed to expose, where validators escape accountability by being unidentifiable. Coinbase is entirely identifiable. The accountability gap exists not because the operator cannot be found, but because the activity has not been classified. The operator is known. The regulator has not acted. The gap is jurisdictional, not technical – and jurisdictional gaps close.
The Dencun contradiction
The March 2024 ‘Dencun’ upgrade proved the conflict empirically. EIP-4844 introduced blob transactions – a dedicated cheaper lane for L2 data posting – and L2 fees fell over 90% overnight. The upgrade did exactly what it was designed to do. It also destroyed the monetary model it had been designed to serve.
L2s no longer competed for regular L1 block space; they used blobs. Regular block space competition fell. Base fees fell. Burns fell.
In the 150 days following Dencun, only 1,389 ETH was burned from blob-carrying transactions – close to zero.194 Ethereum's 30-day annualised inflation rate reached 0.74% in September 2024, the highest in two years. Over 350,000 ETH was added to total supply in the seven months after the upgrade, wiping out nearly two years of post-Merge supply reduction.194 After the subsequent ‘Pectra’ upgrade in May 2025, the average daily ETH burn fell further to approximately 3.26 ETH per day – a 71% decrease from pre-Dencun rates.194 As of early 2026, ETH has grown approximately 950,000 units in total supply since the Merge. The ultrasound money thesis depends on scarcity through burns. The burns have near-stopped. ETH is now mildly inflationary.
The contradiction built into the rollup-centric roadmap had been present since 2020. The more successful L2 scaling became, the less L1 activity it generated, the lower the fees, the lower the burns, and the more inflationary ETH became. The scaling solution and the monetary model pulled in opposite directions.
Five years without decentralisation
The rollup-centric roadmap's legitimacy rested on a claim: L2s would become genuine Ethereum extensions, inheriting its security and decentralisation. Buterin's staged framework – Stage 0, Stage 1, Stage 2 – defined the path to full trustlessness. Stage 2 was the stated endpoint: no security council, proofs as the only mechanism, full trustlessness matching the L1 beneath.
As of early 2026, five years after the October 2020 post, no major L2 has reached Stage 2. Arbitrum, OP Mainnet, and Base claim Stage 1 under a classification system written by the Ethereum ecosystem for the Ethereum ecosystem – a standard requiring neither a decentralised sequencer nor any reduction in operator control over transaction ordering and inclusion, the only properties that would constitute actual decentralisation. It measures compliance with criteria designed to be met. The sequencer remains centralised in all three. The majority of smaller optimistic rollups remain at Stage 0 – users must rely entirely on the operator to act honestly. ZK rollups remain equally captured: centralised sequencers determine what gets proved, centralised prover infrastructure determines when proofs are generated, and the cryptographic guarantee applies only to the transactions the operator chose to include. The mathematics is sound. The system it is applied to is not.195
Buterin noted in his February 2026 statement that he had encountered at least one L2 explicitly stating it may never proceed beyond Stage 1 – not for technical reasons, but because its institutional customers require the ability to intervene in transactions.195
Read that again. We had to read it several times, such was the self-defeating logic at work and the obvious ridiculousness of the situation. An institution is paying for access to an unregulated, centralised operator with total authority over its transactions, no audit rights, no capital requirements, no regulatory oversight, and no removal mechanism – because it wants the ability to intervene in records on a system sold to them as the future of global finance by people who knew or at the very least, should have known it was none of those things. The blockchain vocabulary is retained because both parties profit from the illusion: the operator sells credibility it has not earned, and the institution sells its clients exposure to an asset class that requires the pretence of decentralisation to justify its existence. Strip the vocabulary away and what remains is a private ledger, controlled by an unaccountable operator, that two parties have agreed to call a blockchain because the alternative – admitting what it actually is – would destroy the illusory value of everything built on top of it. There is no trustlessness. There is no accountability. There is no blockchain. A regulated financial institution that has signed off on material reliance on this architecture has either failed its own risk framework or has decided that the fees justify the fiction. Neither answer reflects well on it.
February 2026: The Admission
On 3 February 2026, Buterin posted on X. Five years and four months after the rollup-centric roadmap post, he stated that L2s had decentralised "far slower and more difficult than originally expected" and that "the original vision of L2s and their role in Ethereum no longer makes sense, and we need a new path."195
The new path: L2s should develop unique value propositions beyond scaling – privacy, non-EVM execution environments, extreme throughput, ultra-low latency – rather than functioning as Ethereum's scaling extensions.
This is a public reversal of a roadmap formalised in October 2020. It is also a public confirmation that the L2 decentralisation the roadmap promised never arrived. What it does not address is the reason decentralisation never arrived: the operators had every commercial reason to prevent it. Their sequencer revenue, their institutional client relationships, and their venture-backed token valuations all depended on retaining control. The Foundation, whose treasury is denominated in ETH, had every reason not to press them. The staking cartel had every reason not to object. The entire incentive structure pointed toward the outcome that was delivered: five years of centralised sequencers, hundreds of millions in extracted rent, and a February 2026 announcement framed as a technical reassessment.
The post did not mention the ETH inflation that followed the Dencun upgrade. The fact that the rollup-centric roadmap's own success had broken the monetary model it was meant to protect was not acknowledged. It is the most important fact of the five years.
Ethereum's rollup-centric roadmap was not the community's organic response to a technical emergency. It was a design decision made by the Ethereum Foundation – the entity that controls protocol development, dominates governance, and holds a treasury denominated in ETH.193 The decision was architecturally convenient in a specific way: every L2 user pays blob fees in ETH, every bridge posts transactions to Ethereum, every rollup proof is verified by an Ethereum smart contract. The roadmap that presents Layer 2s as the scaling solution also ensures that the growth of Layer 2s generates sustained demand for ETH and sustained revenue for the base layer.
Each generation of Ethereum L2 fixed the observable symptoms of the prior generation's failure while preserving the dependency on Ethereum that justified the entire enterprise. The factory did not close because the factory served a commercial purpose independent of whether it produced anything that worked.
The operators who built businesses on this roadmap extracted substantial value from users who were told they were participating in decentralised infrastructure. The chapter now examines each generation and what the operators made of it.
III. Plasma: The First Attempt
Plasma was proposed in 2017 by Joseph Poon and Vitalik Buterin as a framework for creating child chains anchored to Ethereum. Operators would run the child chains, periodically committing state roots to the main chain. Users who believed the operator was behaving dishonestly could exit by submitting fraud proofs and withdrawing their funds.
The fatal flaw was the mass exit problem. If an operator acted maliciously and many users attempted to exit simultaneously, the Ethereum main chain could not process the volume of exit transactions. The system's security depended on the base layer being able to absorb a worst-case flood of withdrawal transactions, and the base layer's throughput made this impossible. Plasma was quietly abandoned.
The operator model had introduced a different problem to the one it avoided: it required every user to be perpetually vigilant, watching the chain continuously and acting within a challenge window. Plasma assumed active, sophisticated users. Most users are neither.
IV. Optimistic Rollups: Centralisation Made Comfortable
Optimistic Rollups addressed Plasma's data availability problem by posting transaction data directly to Ethereum L1. They retained the fraud proof mechanism but moved execution off-chain and data on-chain. If no fraud proof was submitted within a challenge window – typically seven days – the state was accepted as correct.
The bandwidth mathematics in Section I applies in full. The governance reality, which the performance numbers do not capture, is what distinguishes this generation.
Arbitrum: The Full Account
Arbitrum is the dominant Layer 2 by total value locked. Its governance documentation describes the current status of its sequencer in a single word: "Centralized."196 The Arbitrum Foundation – a Cayman Islands entity – runs the sequencer for both Arbitrum One and Arbitrum Nova. The same documentation records that this sequencer may "delay the inclusion of a user's transaction by up to 24 hours and reorder transactions over short time-horizons."
This is not external criticism. It is the self-description of the system.
The financial reality of this arrangement has been documented in the Foundation's own governance materials. In the twelve months before Ethereum's Dencun upgrade, Arbitrum's sequencer generated $21.6 million in net profit from transaction fees after covering L1 costs.190 Post-Dencun, the run-rate was approximately $25 million annually. The fees accrue to the operator of the sequencer: the Arbitrum Foundation. In 2025, the Foundation introduced Timeboost, a mechanism that permits priority transaction ordering in exchange for additional fees. Timeboost generated over $5 million in the first seven months of operation.197 In March 2025 alone, MEV searchers on Arbitrum – exploiting the ordering control that the centralised sequencer enables – extracted an estimated $29.3 million.197
The Arbitrum Foundation is extracting this revenue from a network where it controls the ordering of every transaction, can halt the network when it encounters problems, and has demonstrated this capability in practice. On 7 June 2023, a software bug in the batch poster halted the Arbitrum network for approximately one hour.198 On 15 December 2023, a surge in inscription transactions caused the sequencer to stop relaying transactions, halting the network from 10:29 AM to 11:57 AM EST – confirmed on Arbitrum's own status page.199 The post-mortem fix was a parameter adjustment: raising an internal mempool limit from 10 pending batches to 20. This does not address the architectural vulnerability. It defers it.
A network that halts when demand spikes is not a scaling solution. It is a bottleneck dressed differently.
The ARB token structure follows Pattern 4 from the preceding chapter with precision. Team, advisor, and investor allocations totalled 44.5% of supply, subject to a one-year cliff and four-year vesting schedule.200 In March 2024, the cliff expired and 1.1 billion ARB tokens – 11% of total supply – unlocked simultaneously, increasing the circulating supply by approximately 76%. The entities that designed the system had their tokens unlocked. Retail participants held theirs. ARB has not recovered to its launch levels, and by late 2025 was trading approximately 90% below its January 2024 peak of $2.30-$2.40.
Apply Tony Benn's five questions to the Arbitrum sequencer. What power have you got? Ordering and inclusion authority over every transaction on a network with $20 billion in total value secured. Where did you get it from? Protocol design. In whose interests do you exercise it? The Arbitrum Foundation's – the same entity that holds the treasury, controls the governance process, and benefits from sequencer fee revenue. To whom are you accountable? The Arbitrum DAO, theoretically – which the Foundation substantially influences through its budget, its communications, and its control of the infrastructure the DAO votes on. How can you get rid of them? Through DAO governance – the same governance process the Foundation funds, communicates through, and controls the infrastructure of. The answer is that you cannot.
This is not decentralisation. It is centralisation wearing a governance token.
Base: Coinbase's Unregulated Profit Centre
Base is Coinbase's Layer 2, built on the OP Stack. Coinbase is a publicly traded US company, listed on NASDAQ under the ticker COIN, licensed as a Crypto-Asset Service Provider under MiCA in Luxembourg, registered as a Money Services Business with FinCEN in the United States, and subject to SEC oversight as a reporting company.201 It operates the sole sequencer for Base.
In 2024, Base generated approximately $30 million in gross profit from sequencer fees – more than Arbitrum and Optimism combined.191 By H1 2025, Base was generating $42.4 million in sequencer revenue in a single six-month period, accounting for 87.2% of all revenue across the Optimism Superchain's 34 chains.192 Base accounts for over 80% of all L2 transaction fee revenue as measured by Dune Analytics. These revenues flow directly to Coinbase. Unlike Arbitrum, Base has no governance token, no DAO, no treasury, no community allocation, no vesting schedule, and no pretence of decentralised ownership. Coinbase built a financial network used by hundreds of thousands of people, retained sole control of transaction ordering, and collects the entirety of the surplus between user fees and network costs – disclosed in its SEC filings only as a component of 'other transaction revenue,' without the standalone profit and loss accounting that its scale and operational significance warrant.
On 5 August 2025, Base halted block production for 29 minutes.202 No detailed post-mortem was subsequently published. Consider what this means for a company with Coinbase's regulatory profile. Coinbase is required to file quarterly and annual reports with the SEC. It is subject to operational resilience standards under MiCA in Europe. A network it controls, securing billions in user assets, stopped for 29 minutes – and the response was silence. Not a Form 8-K. Not a MiCA incident report. Not a blog post with a root cause analysis. The standard applied to a regulated financial institution experiencing a 29-minute service interruption – immediate disclosure, root cause analysis, remediation plan – was not applied to Base.
The reason is structural, not accidental. Base is classified as a blockchain infrastructure product, not a regulated financial service. No regulator of which we are aware has challenged that classification, despite Coinbase operating a system that processes billions of dollars of user transactions, controls their ordering, can delay or exclude them, and extracts tens of millions annually in fees – functions that would attract immediate regulatory scrutiny if performed by any entity without the word 'blockchain' in the description. The blockchain label is not a technical descriptor. It is a regulatory escape hatch, engineered into the product architecture and exploited with full knowledge of its effect. Every compliance officer at every financial regulator in every jurisdiction where Base operates who has reviewed this structure and taken no action has made a choice. That choice has a cost, and users bear it.
In June 2025, Base announced "Stage 1 Decentralisation," described as a milestone in Base's path toward trustlessness.203 The announcement covered permissionless fault proofs and multi-party governance of contract upgrades. It did not touch the sequencer – the component that controls transaction ordering for every user, determines which transactions are included or delayed, and generates the sequencer revenue. 'Stage 1 Decentralisation' adjusted who holds the keys to the rulebook while leaving control of every transaction with a single Coinbase-operated node. It is decentralisation in the same sense that changing the locks on a prison is freedom. The announcement was received as progress. The sequencer remains where it started: on the same day Base launched, under the same operator, with the same unchecked discretion.
Apply Tony Benn's five questions to the Base sequencer. What power have you got? Total authority over every transaction on a network securing billions in user assets – the power to include, exclude, delay, reorder, and extract fees from every economic interaction that passes through it, exercised without regulatory classification as a financial intermediary and without any obligation to justify a single decision to any user. Where did you get it from? Coinbase built the network, designed it this way, and listed the company on NASDAQ while doing so. In whose interests do you exercise it? Coinbase shareholders. The sequencer revenue accrues to a publicly listed company. Base users funded the activity that generated it and have no claim on any of it. To whom are you accountable? The SEC, for matters affecting Coinbase as a reporting company – which does not include Base's sequencer operations, which are not classified as a regulated activity, and which Coinbase does not report as a separately identified business segment. In other words: to nobody who has jurisdiction over what actually happens to users. How can you get rid of them? You cannot. There is no governance mechanism, no token, no DAO vote, no regulator with clear jurisdiction, and no legal framework under which a Base user can compel Coinbase to do anything differently. The users have no voice, no recourse, and no representation. They have only the sequencer's discretion, which is total and unchecked.
Coinbase has built the most commercially candid version of the Ethereum L2 model, which is not a compliment. It does not pretend a governance token represents community ownership because it did not bother with the pretence. It does not route revenue through a nominally independent foundation because the fiction was unnecessary. It simply operates the sequencer, collects the fees, files the quarterly report that buries what the sequencer earns in 'other transaction revenue,' and lists the company on NASDAQ. Stage 1 was designed to be announced. The sequencer was never designed to be released. Coinbase looked at the Ethereum L2 model, stripped out the theatre it did not need, kept the extraction mechanism, and called it infrastructure. That is not candour. It is the same scheme with less effort spent on the costume.
The censorship problem, definitively stated
L2 advocates point to force inclusion as the censorship resistance mechanism: a user whose transaction the sequencer delays or excludes can submit it directly to Ethereum L1, compelling the rollup to include it. This is technically accurate but useless in the same sense that a parachute saves you – if you have 24 hours to put it on.
The chain of logic is airtight. Arbitrum's own documentation records that the sequencer may delay any transaction by up to 24 hours.196 Force inclusion requires activating an Ethereum L1 contract and waiting for the challenge window. DeFi positions can be liquidated in minutes. Time-sensitive payments either settle or they do not. The escape hatch exists; the conditions under which a user can reach it before the damage is done do not. The capability for censorship and for delay indistinguishable from it is not in dispute. It is documented by the operators themselves.
A financial system where your transactions can be held for 24 hours at an operator's discretion is not censorship-resistant. It is censorship, with paperwork.
V. Zero-Knowledge Rollups: The Mathematical Promise, Broken
ZK Rollups addressed Optimistic Rollups' seven-day challenge period by replacing the assumption of honesty with mathematical proof. Instead of waiting for fraud watchers, a ZK Rollup generates a cryptographic validity proof demonstrating the correctness of every state transition. No challenge period. No reliance on the operator's honesty. The mathematics guarantees the result. Allegedly.
This was the mechanism that distinguished this generation from its predecessors, and the one the industry needed to keep the capital flowing. Seven years of Ethereum scaling promises had produced nothing that worked. The seven-day challenge period made Optimistic Rollups commercially useless for any institution that needed to move money rather than speculate on it. ZK proofs offered a way to keep building, keep raising, and keep the narrative intact: mathematical certainty replacing operator honesty – or so the pitch ran. The sequencer still controlled which transactions entered the pipeline. The proof certified only that what the sequencer chose to include had been processed correctly. Everything excluded, delayed, or reordered before the mathematics began was invisible to it. The mathematics itself, as six independent production implementations would later demonstrate, could be forged.204 ZKSync, launched by Matter Labs in 2020, became the flagship. It attracted hundreds of millions in venture capital and sovereign infrastructure projects on the strength of those claims. It was described as the 'endgame' for blockchain scaling by people who had every financial reason to describe it that way and no technical basis to do so.
The proof cost reality
ZK proofs are not free. The trade-off between proof cost and verification cost is fundamental to ZK cryptography. Since the goal is to minimise activity on the Ethereum L1 – expensive in ETH fees – the cost is displaced entirely onto proof generation. Proof generation for a full zkEVM is computationally extraordinary.
Matter Labs introduced Airbender, a new RISC-V proving system, in June 2025 as part of the Atlas upgrade – the stack on which ZKSync Era and sovereign deployments such as ADI Chain are built. Airbender's production hardware requirement is any GPU with 22GB RAM, including RTX 4090s and H100s.205 This is the floor for entry into proof generation, not the cost of operating under commercial load. The practical effect remains unchanged: proof generation is centralised by hardware cost and operational expertise. Only well-capitalised entities can operate provers at production scale – entities such as, for instance, Matter Labs, the company that raised hundreds of millions in venture capital to build ZKSync and operates the prover infrastructure its sovereign clients depend upon. The decentralisation that ZK proofs were supposed to provide at the security layer does not exist at the operational layer. It was never going to. The architecture that was sold as the path to trustless scaling requires the ongoing participation of the very operator whose trustworthiness it was supposed to make irrelevant.
The prover time constraint
The proof must earn its guarantee. To certify that a batch of transactions is correct, the prover must examine every transaction in that batch: verify every cryptographic signature, evaluate every contract call in ZK arithmetic, and build a proof tree committing to the entire resulting state. There are no shortcuts. A proof certifying 10,000 transactions has done 10,000 transactions' worth of verification work. The computational cost is strictly proportional to the volume of data processed.
Cryptographic signatures – the 65-byte component present in every transaction at minimum – require elliptic curve operations in ZK arithmetic. These operations are substantially more expensive in a ZK circuit than in conventional computation: the prover must prove it executed each curve operation correctly, using field arithmetic over a large prime, producing polynomial commitments at each step. Contract call data adds opcodes that each require their own ZK circuit evaluation. The prover cannot batch these into faster approximations; the guarantee would fail if it did.
The consequence is that proving throughput – the rate at which uncompressed transaction data can be converted into verified proofs – is bounded by the prover hardware and the cryptographic cost per byte. That bound is not a parameter to be tuned. It is a property of the mathematics.
At any claimed TPS, the volume of uncompressed data arriving at the prover in each 12-second Ethereum block is the same calculation as in Section I: claimed TPS × 12 seconds × 105 bytes minimum per transaction.
| Claimed TPS | Bytes arriving at prover per second | Bytes arriving per 12-second block |
|---|---|---|
| 1,000 | 105,000 | 1,260,000 |
| 2,000 | 210,000 | 2,520,000 |
| 10,000 | 1,050,000 | 12,600,000 |
The minimum hardware to initialise the prover process is documented in ADI Chain's prover specification for its ZKSync Atlas implementation. 205 The prover time inflation figures that follow – 21-fold at 2,000 TPS and 105-fold at 10,000 TPS – were derived from the Boojum prover specification that preceded Airbender. Airbender (introduced June 2025) benchmarks at 9,700,000 RISC-V cycles per second on a single RTX 4090. Whether this translates to materially different bytes-per-second throughput for the specific transaction mix of a sovereign financial infrastructure deployment requires independent benchmarking under sustained commercial load – benchmarking that has not been publicly produced. The specific multiplier figures were derived from the Boojum prover specification and may differ under Airbender. The constraint they illustrate is architectural and does not differ. A faster prover moves the ceiling; it does not remove it. The mathematical framework demonstrating why the constraint exists is independent of the specific prover implementation and is set out below for the reader to apply against any published benchmark figures.
In plain terms: the specific time figures in this section were calculated using the hardware specification of ZKSync's older prover. ZKSync has since released a faster prover – Airbender – whose benchmark figures are published in different units that cannot be directly compared without running the new system under the specific conditions of a production financial deployment. Nobody has published that test. The constraint itself is not in dispute – a ZK prover must perform strictly more computational work than the volume of transactions arriving at it, and the pipeline is strictly sequential, so backlogs compound without limit under sustained load. What the precise multiplier is under the current prover hardware is a number that Matter Labs could publish and has not. Until they do, the figures below should be read as illustrating the shape of the problem rather than its exact current magnitude under Airbender. The shape does not change. A faster prover in a sequential pipeline under commercial load is still a prover in a sequential pipeline under commercial load.
The reader can work through the implications directly, applying the framework to whatever benchmark figures are eventually published.
At 2,000 TPS, 210,000 bytes of transaction data arrive at the prover each second. At 10,000 bytes per second proving throughput, the prover requires 21 seconds of computation to certify each 1 second of incoming transactions. For every second that passes, the prover falls 20 seconds further behind. At 10,000 TPS, 1,050,000 bytes arrive each second. At the same proving rate, each second of transactions requires 105 seconds to certify. The prover falls 104 seconds behind for every second that passes.
This deficit cannot be recovered. Each Ethereum block's proof must commit to the state root produced by the preceding block's proof: block N+1's prover cannot begin until block N's proof is finalised and its output state root is known. The dependency is not an implementation choice. It is the mechanism by which the proof chain provides its guarantee of correctness across the chain's history. Parallelisation across blocks is structurally impossible.
The consequence for backlogs is calculable from first principles.
At 2,000 TPS: each second of real time generates 21 seconds of proving obligation. After a five-minute period of operation at this throughput, the prover has accumulated 300 seconds of transaction data. Clearing that backlog requires 300 × 21 = 6,300 seconds – 105 minutes of continuous computation – during which time the throughput continues to arrive and the backlog continues to grow. The five-minute backlog is never cleared under sustained load; it grows without limit.
At 10,000 TPS: each second generates 105 seconds of proving obligation. A five-minute backlog requires 300 × 105 = 31,500 seconds – approximately 525 minutes, or more than eight hours – to clear under continuous load.
Complex DeFi contract calls, routinely running to several hundred bytes beyond the 105-byte minimum, extend these figures in proportion to the additional calldata.
This is why ZKSync Era, with a claimed 20,000+ TPS, observes 12-16 TPS in the live network. The prover cannot process what the sequencer accepts. The "instant" transactions users experience are soft commitments from the sequencer alone. The proofs arrive later – substantially later, in batches – because no prover, regardless of hardware generation, can certify transactions faster than the sequential proof chain demands under sustained commercial load. Airbender is faster than its predecessor. It is not faster than the mathematics. ZKSync's own documentation acknowledges that full L1 finality takes hours per batch.206 The "instant" settlement is the sequencer's word. The mathematical proof, which is the entire claimed security advance of this generation, arrives when the hardware has had time to produce it.
Consider a simpler real world parallel. A photocopier accepts documents faster than it can copy them. Feed it one page per second and it copies one page per second – manageable. Feed it ten pages per second and the tray fills, the queue grows, and the machine falls further behind with every passing moment. It cannot catch up while documents keep arriving. The only way to clear the backlog is to stop feeding it entirely and wait. A ZK prover is that photocopier. The sequencer is the person feeding it pages at a rate the machine was never built to handle. The 'instant' confirmation the user receives is the sequencer's promise that the document has been accepted into the tray. The proof – the actual copy – is somewhere in the queue. At 10,000 TPS, it is hours back under the figures derived from the earlier prover specification.
In Section I we observed that the Layer 2 sector responded to a canal bandwidth problem by building more ships. The prover constraint is what happens before the ships reach the canal. The sequencer loads cargo onto vessels faster than the port can clear them for departure. The queue at the dock grows without limit. The canal's capacity is irrelevant while the ships cannot leave harbour. The cargo the user was told had sailed is still on the quayside.
Compounding Constraints
Section I established the bandwidth ceiling: the Ethereum base layer provides 1,179,648 bytes of blob space per block, shared across every Layer 2 simultaneously. The prover time constraint established above operates at an earlier stage of the same pipeline. They are not the same problem. They are two sequential impossibilities, each fatal independently, encountered in order.
The prover fails first. A system unable to prove its own transaction data at anything approaching real time will never generate proof output fast enough to reach the base layer under commercial load. The bandwidth constraint is therefore academic under any realistic throughput scenario – the architecture collapses before the data arrives at the canal. But the bandwidth impossibility matters precisely because it closes the only remaining escape route: even if the prover problem were somehow resolved – which it cannot be, for reasons rooted in the mathematics of ZK circuits rather than engineering choices – the architecture would still fail at the base layer. The system is not caught by one trap. It is caught by two. The second is waiting in case the first is somehow survived.
Return to the harbour. The photocopier in the port office cannot process the cargo manifests fast enough to clear the ships for departure – the prover, overwhelmed before a single vessel leaves the dock. On the theoretical occasion a ship clears the harbour, it joins a queue at the canal entrance that the canal's fixed capacity cannot absorb – the blob bandwidth ceiling, immovable regardless of how efficiently the port eventually learns to operate. The cargo the user was told had sailed is on the quayside. If it ever does sail, the canal is already full.
The attacks this architecture uniquely enables
ZK rollup chains are premised on Ethereum's gas cost model: transactions priced according to CPU cycles and storage. This made sense when those were the dominant costs. On a ZK rollup, the dominant cost is proof generation, which has an entirely different cost profile. An operation cheap in Ethereum gas terms may be astronomically expensive in ZK proof terms.
This mismatch between cost profiles creates two distinct categories of attack that do not exist in simpler architectures, documented by Chaliasos et al. in September 2025.207
The first category – prover-killer attacks – exploits the gap between L1 gas cost and ZK proof cost. An attacker crafts a transaction cheap at the L1 gas level but catastrophically expensive at the proof generation level, then uses the force-inclusion mechanism – intended as the censorship resistance tool – to compel the rollup to include it. The rollup either processes the transaction at ruinous proof cost, or refuses and triggers the self-destruct mechanism built into the anti-censorship contract. The tool designed to prevent censorship becomes the weapon that enables economic attack.
The everyday version requires no financial sophistication to understand. A photocopying shop charges by the page and promises to copy anything submitted. An attacker submits a page printed entirely in solid black – standard per-page price, one full ink cartridge consumed per copy. The shop copies it at ruinous cost or refuses and breaks its own guarantee. That is a prover-killer attack.
The second category – data-availability attacks – exploits the gap between L2 gas cost and L1 byte bandwidth. A transaction priced cheaply in L2 gas terms requires disproportionate data posting to the Ethereum base layer, consuming shared blob space and forcing costs across the entire rollup ecosystem. This category connects directly to the bandwidth ceiling established in Section I: the blob space that data-availability attacks exhaust is the same shared resource whose absolute capacity makes TPS claims above 1,000 mathematically impossible. The attack surface and the physical ceiling are the same constraint approached from different directions.
The data-availability attack has no satisfying everyday analogy because no competently designed pricing system would leave this gap open. The exploit exists because the architecture priced access by one measure and consumed shared capacity by another, with no mechanism to close the difference. Any regulated market would have caught this in the design phase. The ZK rollup ecosystem shipped it to production.
ZKSync: Pattern 4 executed with a bot army
ZKSync's ZK token airdrop in June 2024 documented the vesting asymmetry pattern with unusual clarity. Matter Labs allocated 33.3% of the 21 billion token supply to the team and investors.208 The community allocation – 17.5% by airdrop – became immediately controversial.
Mudit Gupta, Chief Information Security Officer at Polygon Labs, described it as "probably the most farmable and farmed airdrop ever," adding that it had "almost no Sybil filtering" and that anyone who knew the criteria "could've easily farmed the shit out of it."209 Adam Cochran, partner at Cinneamhain Ventures, observed that "those criteria are easy to not hit as a real user, and easy to hit as a farmer."210
ZKSync's own defence was remarkable in what it conceded. Its FAQ stated: "Sybil detection often cuts out real users with arbitrary filters." The team chose not to filter bots, acknowledged that Sybil wallets would receive allocations as a consequence, and offered this as a principled position rather than an admission of failure. Approximately 135 million ZK tokens – estimated at $6.9 million at airdrop price – went to addresses on known Sybil lists.211 A project that had spent years cultivating real users excluded 90% of addresses that had ever interacted with ZKSync and rewarded farms instead.212
Over 40% of the top airdrop recipients sold their entire allocation immediately. 41% sold part. The ZK token declined 39% in the weeks following.213 The genuine supporters who had used the network, paid fees, and built the activity metrics that justified the fundraising held their tokens while bots sold into them.
The soundness failure
On 3 March 2026, security researchers at OtterSec published a formal analysis of six production zkVM implementations: Jolt (a16z), Nexus (StarkWare's Stwo prover), Cairo-M (Kakarot Labs), Ceno (Scroll), Expander (Polyhedra), and Binius64.204 All six contained the same class of critical soundness vulnerability. Public claim data – the values defining what computation was actually performed – was not bound into the Fiat-Shamir transcript before cryptographic challenges were derived. An attacker can supply forged values that cause the verifier to accept a false proof. In OtterSec's own framing: in a blockchain context, this could translate to receiving $1 million out of thin air.
The Fiat-Shamir vulnerability does not require cryptographic expertise to understand at its core. A bank vault manufacturer produces a door of extraordinary sophistication: reinforced steel, a combination mechanism of genuine complexity, a time lock of genuine ingenuity. The vault is installed, the bank opens, and deposits are taken. The bolt was never checked. Each component assumed an adjacent component had verified it engaged. It had not. The vault could be opened by anyone who knew to push. The OtterSec researchers pushed. They found six vaults, from six different manufacturers, with the same unengaged bolt. The sophistication of everything surrounding the failure makes the failure worse, not better. These were not naive implementations. They were the flagship products of well-capitalised teams building the infrastructure on which sovereign nations were being invited to depend.
The root cause is systemic. Academic papers describe interactive protocols without specifying what must be included in the Fiat-Shamir transcript. Modular zkVM architectures create a handoff problem where each component assumes another handles the binding. Performance pressure creates incentives to exclude values assumed to be "probably fine." Five of the six systems have since been patched. Ceno, developed by Scroll, remained unpatched as of 3 March 2026. OtterSec closed with a question the sector cannot answer: "We found six instances by examining a handful of systems. How many more exist in the dozens of zkVMs, proof systems, and recursive verifiers deployed today?"
The single property that distinguished ZK Rollups from every prior generation – the mathematical guarantee that proofs are valid – was broken in production, across six independent implementations, by the same systemic failure. The endgame was broken at the foundational level.
Even setting the soundness failures aside: ZK Rollups do not eliminate the sequencer. The mathematical proof verifies that the sequencer executed the transactions it chose to include correctly. It does not and cannot verify that the sequencer included all the transactions it should have. Censorship operates at the sequencer level. The proof cannot see it. Everything in the censorship analysis above applies to ZK Rollups without modification.
VI. ADI Chain: A Nation Builds on the Rubble
The implications are not theoretical. They have a name, an address, and a price tag. ADI Chain was sold to the UAE as national blockchain infrastructure, built on the ZKSync Atlas and Airbender stacks – technology created by Matter Labs, who wrote the architecture, know precisely what it can process and what it cannot, and were active participants in marketing it to sovereign clients. The sequencer centralisation is inherent in the architecture they designed. The ZK soundness vulnerabilities are systemic across the implementation category whose flagship product is their own ZKSync. The mathematics establishing the TPS impossibility is a property of their own system. None of this was unknown to them. They claimed 15,000 transactions per second for that same technology on their own website214 and watched a nation build on it. The people who bought it trusted the people who built it. The trust was misplaced and the misplacement was deliberate. What was claimed is archived. What was possible is arithmetic. Those two things are irreconcilable, and Matter Labs knew it.
It will not become sovereign infrastructure because it cannot. What it is, and what it will remain, is one of the most expensive case studies yet produced of what happens when those who came to blockchain in good faith encountered the crypto industry instead. The people who sold this collected their fees. The people who bought it are left holding an architecture that was never going to work, discovering that fact in the worst possible way: after the commitment has been made, the contracts signed, and the alternative paths closed. We will return to ADI in full. The damage it represents is not unique. It is the pattern, at national scale.
ADI's original technical documentation claimed 10,000 transactions per second.214 That figure is mathematically impossible on any ZK rollup architecture – and it fails at two distinct points. The first failure is at the prover: at 10,000 TPS, the prover time inflation established in Section V demonstrates that the sequential proof chain cannot clear incoming transactions under sustained commercial load – the backlog compounds without limit.205 The second failure is at the base layer: 10,000 TPS requires a minimum of 12,600,000 bytes per Ethereum block. The maximum blob space available to all Layer 2s combined is 1,179,648 bytes per block. ADI's claim required approximately eleven times Ethereum's entire blob capacity simultaneously. Following the internal circulation of QPQ's original technical review to QPQ stakeholders – which we believe was subsequently leaked to ADI – the 10,000 TPS figure was removed from ADI's documentation and replaced with language making no specific performance claims. The archived version preserves the original text.
ADI's native token documentation is more revealing than the scrubbed marketing. The token compensates prover nodes for, in ADI's own words, "how many RISC-V cycles it takes to prove a given computation."215 Every user transaction generates proof costs that must be compensated in the native token. Every time a UAE citizen transacts on ADI Chain, somewhere a prover farm is generating a cryptographic proof and billing the cost to the network. National financial infrastructure designed to route everyday transactions carries proof generation cost embedded in every transaction.
The arbitrage attack vulnerability documented by Chaliasos et al. applies to ADI directly. The soundness vulnerabilities documented by OtterSec apply to the ZKSync stack on which ADI is built. The censorship capability at the sequencer level applies without exception.
ADI Chain: mathematically impossible TPS claims removed from documentation within eight days of external refutation, proof generation costs embedded in every transaction through the token model, censorship capability absolute at the sequencer level, and the fundamental ZK soundness guarantee broken across six independent production systems in the same implementation category. The people who commissioned this as sovereign infrastructure misplaced their trust. The misplacement was not accidental. Matter Labs built the stack, wrote the architecture, and knew precisely what it could and could not do. They claimed 15,000 transactions per second for the same technology on their own website while a nation built on it. What was claimed is archived. What was possible is arithmetic. Those two things are irreconcilable, and Matter Labs knew it.
VII. Lightning Network: Bitcoin's Answer to the Same Question
The Ethereum L2 generations failed because each generation was trying to recover decentralisation from a system that had already abandoned it. Bitcoin did not adopt a rollup roadmap. It had a different problem – a chain that processes 3-7 transactions per second and cannot function as money at scale – and it produced a different answer. The answer also failed. The failure mode is distinct from Ethereum's, but it arrives at the same destination: centralised infrastructure, unsecured users, and commercial interests that have diverged from the system they nominally serve.
Bitcoin processes approximately 3-7 transactions per second.216 This is not a design oversight. It is a structural consequence of proof-of-work: achieving trustlessness at scale requires genuine computational work, and that work imposes real constraints. The constraint was known from Bitcoin's first days. By 2015, it had become acute enough that Joseph Poon and Thaddeus Dryja proposed the Lightning Network as a solution.217
The proposal was genuinely clever. Two parties commit funds to a shared on-chain address. They transact off-chain indefinitely, updating a mutually signed balance sheet. When they are done, they settle the final state with a second on-chain transaction. Hashed Time Lock Contracts ensure that payments along multi-hop routes either complete in full or fail entirely: no partial losses, no halfway settlements. The theory was sound. The engineering problem was real. The attempt deserves acknowledgment as honest before it receives its verdict.
The verdict is that it failed, comprehensively and its ongoing promotion by Bitcoin advocates is a case study in how thoroughly a movement can be captured by the interests of those selling it the rope.
The Routing Wall
Routing a payment through Lightning requires a continuous path of funded channels between sender and recipient, with every intermediate node holding sufficient capital to forward the full transaction amount at every hop. Larger payments require larger channel balances along the entire route. Longer routes fail more often because each additional hop is another opportunity for liquidity to be insufficient or a node to be offline.
Abedesselam et al., publishing in November 2025, demonstrated that the Lightning Network is de facto incapable of routing payments above approximately $89 for random network participants.218 This is not a theoretical bound derived from models. It is the empirical result of the network's actual topology across its operational lifetime. Amboss recorded in February 2025 that a $100 payment fails on the first attempt 23% of the time under live network conditions.219 Lightning Network demonstrations at conferences use micropayments for a reason. A transaction at the value of an ordinary retail purchase fails at commercially unacceptable rates.
Liquidity is not a problem waiting to be engineered away. It is a structural constraint of the architecture. If you lock Bitcoin in a channel, you cannot spend it elsewhere. If your channel balance is exhausted on one side, the channel is useless for payments in that direction until rebalanced. Rebalancing requires on-chain transactions. At Bitcoin's 3-7 TPS, meaningful rebalancing at scale competes with every other on-chain activity for the same constrained block space. The scaling solution and the base layer are in competition for the same limited resource.
Eleven years after its conceptual origin, Lightning processes approximately 3 transactions per second.216 That is not an early-stage technology finding its feet, it is the ceiling of its utility.
The Centralisation Engine
Researchers at Vilnius University, publishing in IEEE Access in 2025, measured the Gini coefficient for Lightning's node capacity distribution across eight yearly timestamps from launch to 2025: rising from 0.85 to 0.97.220 A Gini of 1.0 represents perfect inequality – one entity controls everything. At 0.97, Lightning is among the most concentrated network architectures ever measured in peer-reviewed literature. A 2020 paper in the New Journal of Physics reached the same conclusion from a different direction: 10% of Lightning nodes hold 80% of the Bitcoin at stake in the network.221 The topology is a star system centred on dominant hubs.
This is not malice. It is the mechanism at work: longer routes cost more in fees, so economically rational actors route through the largest, most-connected nodes. The hubs emerge not through conspiracy but through the ordinary incentive structure of the network: centralisation is the equilibrium, not an aberration.
Apply Tony Benn's five questions to the hub operators. What power have you got? Control of payment routing for the majority of Lightning traffic. Where did you get it from? Capital concentration and network effects. In whose interests do you exercise it? Primarily their own. To whom are you accountable? Nobody – no regulator, no governance structure, no recourse mechanism. How can you be removed? They cannot.
Block Inc. is not a theoretical example. It runs a Lightning routing node that its Bitcoin Product Lead announced at the Bitcoin 2025 conference was generating annual returns of 9.7% on committed liquidity.222 Independent analysis by researcher Riccardo Masutti found that Block's Cash App nodes apply fee rates of 2,147,483,647 parts per million – approximately two million times the network median fee rate of 0.000063 sat/sat. To route one million satoshis through Block's node costs 1,053 satoshis outgoing and 2,955 satoshis incoming, against a network median base fee of approximately one satoshi.222 The yield is not generated by efficient liquidity provision. It is generated by a surcharge imposed on every payment that routes through a hub operator with no accountability to anyone routing through it. The architecture builds the oligarchy automatically – Block is its most transparent illustration.
The Custodial Trap
The routing complexity of Lightning – channel management, liquidity rebalancing, routing tables, HTLC mechanics – is substantial. Confronted with it, most users do the only rational thing: they hand their Bitcoin to someone else.
Wallet of Satoshi, the most popular Lightning wallet by download count, is custodial.223 The user hands their Bitcoin to a third party who manages channels, routing, and liquidity on their behalf. The intermediation that Bitcoin was designed to eliminate is reintroduced wholesale – without the consumer protections that regulated custodians must carry. The user bears full counterparty risk of an unregulated, often pseudonymous, operator. If the operator disappears, takes funds, or is hacked, there is no depositor protection scheme, no compensation fund, no regulated recourse.
If a user is prepared to trust an unregulated pseudonymous custodian with their Bitcoin, the honest question is why they should not simply use an exchange or bank, which at least operates under a regulatory framework with capital requirements. At which point: why not just use a database? It would be faster, cheaper, and at least honest about what it is. Lightning's custodial users have already surrendered the decentralisation they came for. They are simply doing so without admitting it.
Unfixable Fundamental Security Failures
Replacement Cycling – In October 2023, developer Antoine Riard disclosed a class of vulnerability called replacement cycling attacks: a method allowing theft of funds from Lightning routing hops by exploiting the replace-by-fee mechanism for uncommitted transactions in Bitcoin's mempool – the queue where unconfirmed transactions wait for inclusion in a block.224 This is not an obscure theoretical concern, it is a fundamental failure in Lightning’s security model.
The mechanism is easier to follow than its name suggests. When Lightning routes a payment through intermediate nodes, each node holds the funds under a time-limited claim: collect what you are owed within a defined window, or forfeit it. An attacker opens a channel with a target node, positioning themselves as a routing hop. When a payment is routed through them, they become the temporary custodian of funds in transit – an escrow agent by design of the protocol. They owe the upstream node payment if the transaction completes. Instead of paying, they use replace-by-fee to repeatedly bump their repayment transaction out of the mempool before it can confirm – cycling it out faster than it can settle, over and over, until the upstream node's timelock expires. The right to claim the funds vanishes. The attacker keeps money they were temporarily obligated to pass on.
Every individual action the attacker takes is valid. Opening a channel is legitimate. Accepting a routed payment is legitimate. Replace-by-fee is a legitimate Bitcoin feature. Replacing a transaction with a higher-fee version is legitimate. The cycling behaviour is indistinguishable from a user legitimately trying to push a transaction through a congested mempool. Closing the channel when done is legitimate. There is no moment at which the protocol identifies theft. The upstream node simply finds, when their window closes, that the funds never arrived and the obligation has lapsed.
There is no actionable fingerprint. The cycling behaviour is visible in the mempool to a sufficiently attentive observer, but visibility and remedy are different things. Lightning routing is pseudonymous: the attacker opened a channel with a node key, not an identity, and no name is attached to the theft. Even if the pattern is spotted, the timelock has already expired – the theft completes before the analysis can. Replace-by-fee activity is routine in a congested mempool; the attacker's behaviour is buried in the ordinary noise of users legitimately trying to get transactions confirmed. And even if all of this were overcome – even if a specific node key could be proven beyond doubt to have cycled deliberately – Lightning provides no dispute resolution mechanism, no arbitration, no authority to appeal to. There is no one to call. Proof of theft without a remedy is not justice. It is a receipt.
The attacker is an escrow agent who engineers their own obligation to collapse. Their node key is visible on the network graph – a public key with no name behind it. By the time the victim understands what happened, the channel is closed, the key abandoned, and the funds withdrawn through a chain that leads nowhere. What evidence exists identifies a key. It identifies no one.
The attack is not constrained to a single target. An attacker with sufficient capital opens channels across many nodes simultaneously, running the cycling mechanism in parallel against multiple victims. Each channel is a separate position, each timelock a separate clock to exhaust. The channel costs are small and recoverable. The stolen amounts accumulate. The only limit on scale is how much Bitcoin the attacker is willing to deploy as working capital – and working capital they will recover when they close the channels, regardless of whether the attack succeeds.
Riard's disclosure was serious enough that he resigned from Lightning development rather than remain associated with a system he knew to be fundamentally compromised. His own assessment: Lightning "is in a very perilous position, where only a sustainable fix can happen at the base-layer." Not at the Lightning layer. The base layer. The only complete fix requires changes to Bitcoin's protocol – which the Block Wars demonstrated is essentially impossible to achieve without near-universal consensus. Bitcoin's base layer is frozen for practical purposes, ergo the fundamental security vulnerability remains.
Flood and Loot – The Flood and Loot attack, documented by Mizrahi and Zohar, operates through the same timelock mechanism but at a different order of magnitude.225 Where replacement cycling works silently and in isolation – each instance independent, victims unconnected, the base layer never flooded – Flood and Loot is a detonation. The mass simultaneous closing is not incidental to the attack. It is the attack.
An attacker opens channels with many participants simultaneously, then triggers mass forced closings all at once. Every victim rushes to claim their funds on-chain at the same moment. Again, the base layer provides the constraint – Bitcoin processes 3-7 transactions per second. The claims flood in faster than the network can process them. The attacker, who controls the timing and has prepared their own claims in advance, ensures their transactions confirm first. Victims' transactions sit unconfirmed while their timelocks count down. When the windows close, the attacker collects – and recovers the channel capital they committed to open the positions in the first place. As with replacement cycling, the working capital is not at risk. The loot is the profit on top.
The same analysis applies as with replacement cycling, and then some. The attacker's node key is visible. Their channels were announced. Their forced closings are recorded on-chain. Every transaction is public. None of it identifies a person, a jurisdiction, or an entity with assets that can be seized. The key is abandoned when the attack is complete, the channel capital withdrawn, and the node gone from the network. What remains on-chain is a forensic record of a theft that names no one. Lightning provides no dispute resolution mechanism, no arbitration, no authority to appeal to. There is no one to call. The only mark left is on the victims.
The attack exploits the same throughput constraint that Lightning was designed to address – turning the problem Lightning was built to solve into the weapon used against it. There is no fix at the Lightning layer. The only mitigation is a higher-throughput base layer, which Bitcoin's governance makes structurally unavailable. More damaging still: the attack scales with adoption. The more channels exist, the larger the forced closure flood an attacker can trigger, and the more completely the base layer is overwhelmed. Lightning's growth does not reduce this vulnerability. It compounds it.
The Betrayal
The institutional capital funding Lightning's development is not betting on Bitcoin becoming money. It is betting on Lightning becoming a stablecoin routing network. Brevan Howard, Baillie Gifford, Valor Equity Partners, and Vlad Tenev of Robinhood collectively provided $82.5 million across three funding rounds to Lightning Labs.226 These are not Bitcoin maximalists. They are infrastructure investors who understand that 0.0029% on Visa-scale stablecoin volume generates returns that Bitcoin micropayments never will. In January 2025, Tether launched USDT on Lightning via the Taproot Assets protocol.227 That launch was not an accident of timing, it was the business model arriving.
The arithmetic makes the pivot inevitable. At 3 TPS average throughput and a median routing fee of 0.0029% of transaction value, the entire Lightning Network generates approximately $137,000 in annual routing revenue.228 That figure does not justify a single engineer's salary, let alone $82.5 million in venture investment. Stablecoin rails at Visa-scale volumes generate $348 million per year at the same fee rate. That return justifies the investment. Bitcoin micropayments at $137,000 per year do not.
These are not the same thesis. They are opposed. Lightning moves transactions off Bitcoin's base layer. Off-chain transactions do not pay fees to Bitcoin miners. Bitcoin's security depends entirely on miners being paid: the block subsidy halves every four years toward zero, and fee revenue must eventually replace it as the security budget.229 At current prices, annual block subsidies total approximately $11.66 billion. The annual transaction fee pool – the revenue that must eventually replace those subsidies entirely – is approximately $71 million: 0.6% of block subsidy revenue.229
That figure should be understood against what Bitcoin's current price implies. At today's market capitalisation, Bitcoin is priced as permanently secure infrastructure. The security is paid for by miners. Miners are paid by subsidies and fees. Subsidies are scheduled to reach zero. Fees are 0.6% of current subsidy revenue. The market is pricing in security that the fee economics cannot yet sustain – a speculative premium of roughly 160 times the fee-justified level, paid today on the assumption that fees will grow to fill the gap. Each halving tightens the vice from one side: subsidy revenue falls, so fee revenue must grow proportionally faster just to maintain the same total miner income. The fee pool is not growing at anything approaching that rate. It is shrinking, because Lightning and other off-chain solutions are routing transactions away from the base layer. The vice closes from both sides simultaneously.
As subsidies halve on schedule toward zero, fee revenue must grow by a factor of more than 160 to maintain equivalent security. Every transaction Lightning routes off-chain is a transaction that does not contribute to that fee pool. Tether is already on Lightning. Every USDT transfer that moves through Lightning instead of Bitcoin's base layer is fee revenue that does not reach a miner. The stablecoin thesis and Bitcoin's security model are not future adversaries. They are adversaries now. The scaling solution is a security budget accelerant.
Worse, that already ridiculous 0.6% figure is not a stable floor. It is a ceiling that is already falling. Every transaction routed off-chain reduces the fee pool further. Every halving doubles the distance between what fee revenue is and what it must become. The 160x growth requirement assumes today's fee pool survives intact. If Lightning's stablecoin thesis succeeds and significant transaction volume migrates off-chain, the requirement grows from both ends simultaneously: the target rises as subsidies fall, and the base shrinks as transactions leave. The 160x does not become 320x on a tidy schedule. It accelerates. Each halving compounds the shortfall. Each transaction migrated off-chain widens it further. There is no equilibrium in this arithmetic – only a divergence that grows faster the more successful Lightning becomes. The better Lightning works for its investors, the worse the mathematics become for Bitcoin.
The investors funding Lightning's development do not need Bitcoin's base layer to be healthy. They need two things: stablecoin routing infrastructure that generates fee revenue regardless of Bitcoin's security budget, and the Bitcoin community continuing to champion the Lightning narrative that keeps retail attention and capital flowing into the ecosystem.
The "Bitcoin as final settlement layer" thesis serves both purposes. It sounds like a technical architecture. It is a commercial convenience – a story that keeps Bitcoin advocates promoting Lightning as Bitcoin's scaling solution while Lightning's actual trajectory leads toward stablecoin infrastructure its investors can monetise independently of Bitcoin's health. The miners who secure the base layer are not part of this arrangement. Their interests are structurally opposed to it, yet they do all the marketing work for their own demise.
The Bitcoin advocates who championed Lightning as the path to Bitcoin becoming money funded years of development, paid fees, built the network activity that attracted the institutional capital, and are still providing the narrative cover that sustains it. They are not passive victims of a substitution they failed to notice, they are active participants in a story that serves everyone in it except them and the base layer they depend on.
Lightning does not scale Bitcoin. After eleven years of development and $82.5 million in institutional funding, it processes approximately 3 transactions per second, with a practical routing limit below the cost of a restaurant meal. It carries security vulnerabilities its own lead developer resigned rather than paper over. It has centralised into a hub-and-spoke oligarchy that cannot answer Tony Benn's fifth question. The institutional capital that funds it does not need Bitcoin to succeed. It needs stablecoin volume. Those are not the same thing. They are, in the end, opposed.
VIII. What ‘Layer 2’s Actually Are
The chapter has documented what Layer 2 systems do technically. A separate question is what they are legally, and what user acceptance of their risks reveals about the value users actually place on the properties crypto claims to offer.
The regulatory classification question
A Lightning hub in custodial mode holds user funds, manages channels, routes payments between parties, and settles balances. This is the economic function of a custodian and a payment processor simultaneously. In the European Union, holding client crypto-assets on their behalf requires authorisation as a Crypto-Asset Service Provider under MiCA.230 Providing payment services – routing payments between parties performs the economic function of a payment service, and may therefore require authorisation as a Payment Institution or Electronic Money Institution under PSD2 and its successor frameworks. In the United States, facilitating the transfer of value between parties constitutes money transmission, requiring registration as a Money Services Business with FinCEN and money transmitter licences in each state where users are located – up to 50 separate licence requirements. None of the major custodial Lightning wallet operators holds these authorisations. Wallet of Satoshi operates without any of them.
The sequencer operators present a more complex but ultimately more serious regulatory question. An Optimistic Rollup sequencer orders every transaction on its network, determines inclusion and exclusion, can delay individual transactions for up to 24 hours by documented design, and extracts fee revenue from every transaction it processes. The Arbitrum Foundation earns approximately $25 million annually from this activity;190 Coinbase earns substantially more from Base's sequencer – exceeding $80 million annualised by 2025 run-rates.192 These are not passive infrastructure operators. They are active transaction intermediaries exercising control over a financial system used by hundreds of thousands of people.
MiCA's Recital 22 is precise on the decentralisation question: crypto-asset services are outside MiCA's scope only where they are provided "in a fully decentralised manner without any intermediary." The same recital confirms that where "part of such activities or services is performed in a decentralised manner," the regulation applies in full.230 Arbitrum's own documentation states that its sequencer is "Centralized." This is the question MiCA Recital 22 was designed to resolve. By Arbitrum's own characterisation, the question of whether MiCA applies to its sequencer operations is squarely raised. The Arbitrum Foundation has not, to our knowledge, publicly disclosed CASP authorisation for its sequencer operations. Coinbase, as a MiCA-licensed CASP in Luxembourg, is separately authorised as an exchange and custodian – but whether Base's sequencer operations, which are operationally distinct from those exchange and custody services, require separate authorisation as a payment processing activity under MiCA or an equivalent framework is a question regulators are positioned to answer.
FINMA's substance-over-form principle, established in its 2018 ICO guidelines and applied consistently since, is equally direct: regulatory treatment follows economic substance, not legal label.231 A sequencer that controls the ordering and inclusion of all transactions on a financial network, extracts fees from those transactions, and can delay any individual transaction for 24 hours is performing the economic function of a payment processor. The label "blockchain sequencer" does not change this. Same risks, same rules – and the rules have not been applied.
The regulatory arbitrage is therefore clear. These operators perform functions that would require banking, payment institution, or money transmitter authorisation if performed by a conventional financial firm. The blockchain label and the "decentralised" branding – used despite the operators' own documentation confirming centralisation – create regulatory ambiguity that a straightforwardly centralised payment processor could not enjoy. Users bear the risks of unregulated intermediation. Operators escape the oversight those risks would normally require. This is the first type of regulatory arbitrage documented in the opening chapters of this work: illusions of decentralisation used to escape oversight that should accompany actual control.
What user behaviour reveals
The deeper question is not regulatory. It is revelatory.
Crypto's central narrative holds that its users value trustlessness, censorship resistance, and financial sovereignty. These properties require, at a minimum, that the infrastructure holding and routing your assets not be controlled by a single identifiable operator who can delay your transactions for 24 hours, halt block production for 29 minutes without explanation, and extract tens of millions annually in fee revenue from your activity.
Yet the users of Lightning overwhelmingly chose Wallet of Satoshi – the custodial option, the one that reintroduces the intermediary that Bitcoin was built to remove. The users of Arbitrum and Base conduct transactions on networks their operators describe, in their own governance documents, as centralised. They accept this. They accept it in large numbers, with billions of dollars of assets at stake, with no recourse mechanism, no consumer protection framework, no depositor insurance, and no ability to hold the operator accountable.
This behaviour is only puzzling if you take the trustlessness narrative at face value. It is entirely rational if you apply the correct analytical framework.
The assets held through Lightning custodians, Arbitrum, and Base are not, in substance, assets. They are chances: positions in a speculative game. Rational security architecture is commensurate with what is being carried. Nobody stores their house deeds with an unregulated pseudonymous custodian. Nobody routes their salary through an unregulated payment processor with no consumer protection and a 24-hour delay capability. They do not do these things because house deeds and salaries represent real, irreplaceable value that requires real protection. The users of these platforms have correctly intuited that what they hold is not that. It is a speculative position in a game they understand could lose. They are taking proportionate risk: custodial risk and sequencer risk are acceptable for a chance position in the same way that a casino chip held at the table does not need to be stored in a safety deposit box. You are there to play the game.
The champions of these platforms – the venture capital firms, the foundation executives, the influencers promoting DeFi – are not making an honest mistake about what their users want. They are financially dependent on maintaining the fiction. The fiction that users are choosing trustlessness rather than accepting custodial risk in exchange for speculative exposure is not a narrative error. It is a commercial necessity. Early holders need retail demand to sell into. Airdrop recipients need secondary markets. Foundation treasuries need token prices. If the assets were accurately characterised as the speculative instruments they are, the price implications would be terminal for the people who got in first and need to get out.
The user who genuinely values trustlessness, censorship resistance, and financial sovereignty – and who understands what those words actually require – would not use Wallet of Satoshi. They would not use Arbitrum. They would not use Base. The problem is that most users were never given the tools to know the difference. Every channel, every influencer, every foundation press release told them these systems were trustless, decentralised, and censorship-resistant. The vocabulary of genuine blockchain was borrowed wholesale to describe its opposite – custodians dressed as protocols, payment processors dressed as infrastructure, and rent extractors dressed as liberators.
Part 4 of this work exists precisely because those tools were deliberately withheld and the questions they answer were systematically obfuscated. The four patterns, the fundamental test, the TEA framework, Tony Benn's five questions applied to every foundation and sequencer operator – these are not academic exercises. They are the instruments an ordinary participant needs to identify what they are actually being sold. The industry did not merely fail to provide them. It built an architecture designed to make them unnecessary: vocabulary engineered to obscure rather than describe, governance structures designed to appear accountable while remaining controlled, incentive mechanisms calibrated to ensure that the people distributing information had the most to lose from accurate information being distributed. This is not the negligence of people who did not think carefully enough. It is the design of people who thought very carefully indeed, and built accordingly. The distinction matters in law. It should matter in regulation.
The regulators who should have demanded accurate labelling, applied substance-over-form analysis, and protected retail participants from unregulated intermediaries performing regulated functions have, with rare exceptions, done nothing. This is not a failure of complexity. The functions are not ambiguous. A sequencer that orders transactions, extracts fees, and can exclude any participant at will is a payment processor. A custodial wallet that holds client funds is a custodian. A token distributed to retail participants on the promise of future value is a speculative instrument. Every regulatory framework in every developed jurisdiction has tools to address each of these. None of them have been applied with any consistency or force.
This is not ignorance. The FCA, the SEC, ESMA, and their equivalents have had the evidence, the jurisdiction, the statutory tools, and in many cases the explicit warnings. They received submissions. They published discussion papers. They held consultations. They were told, in plain language, by people who understood the architecture, what these systems were and what was being done to retail participants through them. They chose the pace of the response. They chose which questions to prioritise. They chose, repeatedly, to treat novel vocabulary as novel substance rather than applying the frameworks they already possessed to the functions being performed. That is not complexity defeating regulation. It is regulation declining to act while retail participants bore the cost of that declination.
The gambling industry – an industry that exists to take money from retail participants in exchange for a chance at a return – is more honestly regulated than crypto as a whole and Layer 2s most of all. Gamblers know they are gambling. They are protected by mandatory disclosures, loss limits, operator licensing, and dispute mechanisms. The retail participant in a Lightning custodial wallet, an Arbitrum position, or a ZKSync airdrop has none of these protections, was told they were participating in something categorically different from gambling, and has no regulator who has clearly accepted responsibility for their protection. The cost of that dereliction is not abstract. It is measured in the losses of people who believed what they were told by systems designed to extract from them while telling them they were being liberated.
IX. The Root Cause
Each generation of Layer 2 fixed the observable failures of its predecessor. The sector now contemplates recursive ZK proofs, shared sequencers, based rollups, and rollup-of-rollup architectures.
More epicycles.
The root cause is not a technical problem awaiting the next generation. It is the consequence of using architecture to obscure the absence of decentralisation in systems that had already abandoned it – adding cost, complexity, and new attack surfaces to create the appearance of trustlessness while providing none of its substance.
In the Ethereum case, a financial incentive to keep obscuring compounds what followed: each new generation sustains ETH demand, sustains the Foundation's thesis, and sustains the sequencer operators' revenue streams, regardless of whether it delivers what it promises. The February 2026 pivot away from the rollup-centric roadmap came after the Dencun upgrade had already broken the monetary model the roadmap was protecting. The threat that genuine L1 scaling would have posed to ETH's deflationary narrative was no longer live, so the pivot became safe. The admission cost nothing because the extraction was already complete.
Layer 2s impose the worst of both worlds. Users pay the costs of decentralisation: fragmented liquidity, bridge risks, cognitive overhead, and fees higher than a trusted database would charge. They receive none of the benefits: the sequencer controls their transactions, can delay them for 24 hours, can be halted by a software bug or a demand spike, and extracts tens of millions annually in rent. The operator escapes the regulatory oversight that any entity exercising equivalent control over a conventional financial system would face.
This is not innovation that happened to produce regulatory arbitrage as a side effect. The arbitrage is the product. The claimed innovation is the story told to justify it.
The question is not how to build a better Layer 2. The question is why anyone builds a Layer 2 at all – and having read this far, the answer should be clear. Not because the architecture solves a problem that cannot be solved another way, but because it creates a position of unregulated control over other people's money while maintaining the appearance of not doing so.
A Layer 2 cannot exist independently – it derives its claimed security from a Layer 1 it depends upon entirely. It posts its data there, or its proofs there, or both. It cannot step outside that dependency. Everything it does – its centralised sequencer, its challenge windows, its proof costs, its blob arithmetic – is a consequence of that dependency and the attempt to obscure it. The operators know this. They have always known this. The vocabulary escalation documented throughout this chapter – from "chain" to "blockchain" to "permissionless blockchain," from "synchronisation domain" to "decentralised infrastructure" – is not the imprecision of people working at the frontier of a new field. It is the precision of people who understood exactly what they had built and chose exactly which words would prevent their customers from understanding the same thing.
In legal terms, this is mens rea – the intent, not merely actus reus – the act. The harm caused to retail participants – the losses, the unrecoverable funds, the security vulnerabilities with no fix, the regulatory protections deliberately not sought – is not the collateral damage of people who moved fast and broke things. It is the predictable and predicted outcome of systems designed to extract value from participants who were denied the information they would have needed to make an informed choice. Negligence and deliberate misrepresentation are not the same thing. The evidence assembled in this part of the work documents a pattern of conduct that is difficult to reconcile with the former alone.
The victims are the people who lost real money to deliberate misdirection.
The retail participant who put Bitcoin into Lightning believing the security guarantees held – they did not, they cannot be fixed, and the developer who proved it resigned rather than paper over the fact. The Bitcoin holder who spent years championing Lightning as Bitcoin's path to becoming money, only to find the institutional capital they attracted is building stablecoin infrastructure that actively accelerates Bitcoin's security budget collapse. The Ethereum user who paid sequencer fees to Coinbase or the Arbitrum Foundation under the impression they were using decentralised infrastructure – the operators' own documentation used the word "Centralized" while their marketing used "blockchain," and the difference generated tens of millions annually in unregulated, undisclosed revenue. The ZK rollup user sold mathematical certainty as the endgame – the proof that would finally make trustless scaling real – on infrastructure whose throughput claims were arithmetically impossible, whose ZK guarantees were broken across six independent production implementations, and whose sequencer remained as centralised as every generation before it. The sovereign nation that commissioned national digital infrastructure on performance figures that were mathematically impossible, removed from documentation within eight days of external refutation, from a vendor that continued making equivalent claims for the same architecture on its own website while the nation's commitment was already made.
The perpetrators are not difficult to identify. They are incorporated, licensed, and in several cases publicly listed. They have legal addresses, regulatory relationships, and in some cases the explicit imprimatur of institutions whose credibility they borrowed to validate claims those institutions never independently verified. They are not anonymous. They did not operate in the shadows. They operated in the light, with foundation structures and press releases and pilot reports and academic partnerships, all of which served the same function: to make the extraction look like infrastructure, the arbitrage look like innovation, and the victims look like willing participants in something they were never given the information to evaluate.
The regulators who watched this happen and chose not to act bear their own portion of this. They had jurisdiction. They had frameworks. They had, in several cases, explicit submissions from people who understood the architecture and explained in plain language what was being done and to whom. They chose the pace of their response. That choice has a cost borne by the people who could least afford it – those whose absence of hope for their economic future made them most vulnerable to the specific marketing methods the crypto industry exploited. In every other context, those are precisely the people these regulators go to great lengths to protect from speculative and complex investments. In this one, they were left entirely without protection – and the industry that targeted them knew it, having spent considerable resource funding the political careers that championed light-touch regulation and sustaining the media ecosystem whose advertising revenue depended on the narrative remaining intact.
The Layer 2 premise was wrong from the start. Not wrong in the way that honest engineering mistakes are wrong – through insufficient knowledge, through problems that proved harder than expected, through good faith attempts that fell short of their goals. Wrong in the way that a knowing misrepresentation is wrong: the operators knew what they had, knew what they were claiming, and knew the two things were not the same. They built the vocabulary to bridge the gap. They built the foundations to legitimise the claim. They built the incentive structures to ensure that everyone with a platform had a reason to repeat it.
The people who built the layers knew they were not solving the trust problem. They were solving a different problem entirely: how to extract value from people who believed they were.
Appendix: The Essentials
This section is for readers who are new to blockchain. It explains the foundational concepts needed to follow this document. If you are already familiar with blockchain technology, skip it entirely.
What Is a Blockchain?
A blockchain is a record of transactions shared across a network of computers. No single computer holds the master copy. Instead, every participant holds the same record, and the network follows rules to agree on what gets added.
This matters because of what it replaces. In the traditional system, a bank holds your balance on its ledger. You trust the bank to record it honestly, not to change it without your knowledge, and not to deny you access. The bank is the messenger; you must trust the messenger.
A blockchain removes the need for that trust. The record exists across thousands of computers simultaneously. No single party can alter it, delete it, or deny you access to it. You trust the message itself, verified by mathematics, rather than trusting any particular messenger. That is the only thing a blockchain does that no other technology can do: allow people to trust the message without trusting the messenger, securely, at scale. Every legitimate use of blockchain flows from this. Every fraudulent project obscures it.
How Does a Blockchain Agree on What Is True?
When thousands of computers hold the same record, they need a method to agree on which new transactions to add. This method is called a consensus mechanism: the rules by which the network reaches agreement.
There are two principal approaches.
Proof-of-work requires participants (called miners) to expend real computational effort to earn the right to add transactions to the record. This effort is deliberately costly: it means that cheating the system would require more resources than any attacker could reasonably deploy. The security comes from physics and mathematics, not from trusting anyone. Bitcoin uses proof-of-work. So does the Gajumaru.
Proof-of-stake gives the right to add transactions to those who hold the most coins and pledge them as collateral. The theory is that large holders have the most to lose from dishonesty. The reality is that it concentrates control in the hands of the wealthiest participants, who can collude, censor transactions, or extract value from their position. You must trust the validators (the participants who verify transactions) to behave honestly. If they do not, your recourse is limited. The distinction matters enormously. Proof-of-work creates trustlessness through mechanism: nobody needs to trust anybody because the mathematics prevents cheating. Proof-of-stake creates a trust requirement: you must trust validators not to abuse their position. This document's argument depends on understanding this difference.
The Resource Layer Concept
Traditional technology stacks have layers. The internet has physical cables (resource), network protocols like TCP/IP (infrastructure), platforms like web servers (platform), and applications like websites (application).
The global economy has no equivalent. Every piece of economic infrastructure is controlled by someone: banks, payment processors, card networks, clearinghouses. There is no neutral foundation beneath them all. You cannot participate in the economy without using someone else's controlled infrastructure and accepting their terms.
The Gajumaru introduces this missing layer. Groot is the resource layer: governance-free, operated by no one, controlled by no one. Like the high seas that connect all ports, or like the internet protocols that no one owns but everyone uses.
Associate Chains are infrastructure built on top of this resource layer. They are controlled, governed, and operated, as infrastructure should be. A nation running its own Associate Chain controls its own digital economy. Because all Associate Chains connect through Groot, they can interact with one another without needing to trust a shared intermediary.
The choice between operating directly on Groot (less efficient, but no one can say no) or through an Associate Chain (more efficient, but subject to the operator's rules) is the point. Neither path is better in the absolute. The existence of both paths disciplines both: infrastructure that extracts too much loses users to Groot; Groot's higher costs make reasonable infrastructure attractive. Competition between the two protects everyone.
This is the RIPA model: Resource, Infrastructure, Platform, Application. It is the architectural foundation of everything described in this document.
Why This Matters to You
If you have ever been frustrated by a bank freezing your account without explanation, a payment processor refusing your business, credit card fees eating into your margins, an international transfer taking days and costing a fortune, or the slow erosion of your savings by inflation: the problems this document describes are not abstract. They are the mechanics of how value is extracted from your work, your savings, and your economic participation, every day, by systems you cannot escape because no alternative exists.
The Gajumaru is that alternative. Not a replacement for everything, but an option that did not exist before. Its existence changes the rules.
Glossary
Terms are grouped by subject. Use the headings to find what you need.
How Blockchains Work
Mining and miners. In a proof-of-work system, miners are the computers that compete to solve a mathematical puzzle. The winner earns the right to add the next group of transactions to the blockchain and receives newly created coins as a reward. This is how new money enters the system. In Bitcoin, mining requires specialist industrial hardware (ASICs) consuming enormous amounts of electricity. In the Gajumaru, mining runs on ordinary laptops using a memory-based puzzle called Cuckoo Cycle.
Validators. In a proof-of-stake system, validators replace miners. They are chosen to verify transactions based on how many coins they hold and pledge. Unlike miners, they do not expend physical resources to earn trust; they pledge financial ones. When a small number of validators control a majority of pledged coins, they effectively control the network. The concentration of validator power is a recurring concern throughout this document.
Proof-of-work. A consensus mechanism where miners compete to solve computational puzzles. The solution proves that work was done without requiring trust in the solver's identity or intentions. It is the only mechanism that allows trusting the message rather than the messenger, securely at scale.
Proof-of-stake. A consensus mechanism where validators are chosen in proportion to the coins they hold or pledge as collateral. Faster and less energy-intensive than proof-of-work, but requires trust in validators. Acceptable for governed infrastructure (Associate Chains with identified, accountable validators); unsuitable for a resource layer because it concentrates power with wealth and provides no mathematical guarantee against collusion.
Proof-of-authority. A consensus method where identified, accountable entities validate transactions. Used in permissioned networks where speed and accountability matter more than trustlessness. Validators are known and can be held legally responsible.
ASIC (Application-Specific Integrated Circuit). A computer chip designed for one task only. In Bitcoin mining, ASICs perform SHA-256 calculations and nothing else, costing thousands of dollars and consuming thousands of watts. The Gajumaru's Cuckoo Cycle puzzle resists ASIC dominance because its memory-bound nature limits the advantage specialist hardware can provide over ordinary consumer hardware.
Cuckoo Cycle. The proof-of-work puzzle used by the Gajumaru. A memory-bound pathfinding problem that rewards memory access speed rather than raw processing power, enabling mining on ordinary laptops rather than specialist ASICs.
Bitcoin-NG. The consensus protocol used by the Gajumaru. Separates leader election (keyblocks, every two minutes) from transaction processing (microblocks, every three seconds), dramatically improving efficiency over Bitcoin's model where both functions are combined in a single block every ten minutes.
Keyblock. A block produced approximately every two minutes on the Gajumaru that contains proof-of-work but no transactions. Keyblocks determine which miner leads the network and produces transaction blocks until the next keyblock is solved. Their content-free nature is critical to the witnessing protocol.
Microblock. A transaction block produced approximately every three seconds by the current network leader. Contains actual transactions. A keyblock and its subsequent microblocks together form a generation.
Generation. A keyblock and all the microblocks that follow it until the next keyblock. The basic structural unit of the Gajumaru's chain.
Witnessing protocol. The Gajumaru's patented mechanism for accelerating settlement certainty. Designated witnesses attest to content-free keyblocks, confirming chain structure without approving transaction content. This provides commerce-grade settlement certainty within seconds and near-certain settlement within minutes for high-value transfers, whilst maintaining clean liability separation.
Hashrate. The combined computational power of all miners on a network. Higher hashrate means greater security, because an attacker would need to control more than half of the network's total computing power to manipulate the chain.
Mempool. The waiting area where transactions sit before being processed. An empty mempool, as seen persistently in Bitcoin, indicates that the network is not being used for actual transactions; holders are speculating on price rather than spending the currency.
Fork. A divergence in the blockchain where two competing versions of the transaction history exist simultaneously. In normal operation, forks resolve quickly as miners converge on one version. In an attack, a malicious actor attempts to create a fork that erases legitimate transactions.
Chain reorganisation. When a blockchain network switches from one fork to another, discarding the transactions on the abandoned fork. Deep reorganisations affecting transactions that were considered settled are what settlement mechanisms are designed to prevent.
Full node. A computer that stores and independently validates the complete blockchain. Full nodes enforce the protocol rules and do not trust other participants. The more full nodes on a network, the more decentralised and resilient it is. On Bitcoin, running a full node requires storing over 600 GB. On the Gajumaru, Data TTL keeps this permanently below 10 GB.
Transactions, Speed, and Settlement
Transactions per second (TPS). A measure of how many transactions a network can process each second. For context: Visa handles approximately 1,700 TPS on average. Bitcoin manages roughly 3-7. The Gajumaru's base layer handles 300+. State channels extend this through bilateral co-signed settlement to 500+ token transfers per second or 3,000+ plain messages per second per channel, resolving to the base layer on close. One node – a Mac Mini is sufficient – services at least 1,000 concurrent channels; capacity scales linearly with nodes deployed.
Gas. The unit of cost for on-chain operations, analogous to fuel for computation. Every transaction, smart contract call, or data storage operation consumes gas, paid in Gajus. Gas prevents abuse by ensuring that computation has a cost, and makes resource consumption predictable and proportional.
Settlement. The point at which a transaction becomes irreversible for practical purposes. In traditional banking, settlement can take days. In Bitcoin, it takes an hour at minimum for low-value transactions – and days, even weeks, for passable commercial certainty on very high-value transfers – with no finality endpoint at any price. On a proof-of-work chain, settlement is a process of rising certainty rather than a binary event: both technical certainty (accumulated work) and economic certainty (cost of attack relative to value at stake) increase continuously from the moment a transaction appears on-chain. On the Gajumaru, commerce-grade certainty arrives within seconds for most transactions.
Finality. The point at which a transaction becomes not merely economically irreversible but structurally impossible to reverse by any means. This is distinct from settlement: a settled transaction is one where the cost of reversal has made attempting it irrational; a final transaction is one where the architecture no longer permits reversal regardless of the attacker's resources. Most payment systems, including Bitcoin, offer settlement of a kind but no finality: the settlement window never closes and a sufficiently resourced attacker retains, in theory, the ability to succeed. On Groot, finality arrives at two keyblocks – four minutes at most – for every transaction regardless of value. This is a structural protocol guarantee, not a probabilistic one.
State channels. A method for conducting many transactions between two parties without recording each one on the blockchain. Think of opening a tab at a bar: you open the tab (one blockchain transaction), buy drinks all evening (off-chain, between you and the bartender only), and close the tab at the end (one blockchain transaction to settle). Only two transactions touch the blockchain regardless of how many took place off it. The Gajumaru's state channels handle 500+ token transfers per second or 3,000+ plain messages per second per channel, resolving to the base layer on close. One Mac Mini node services at least 1,000 concurrent channels; capacity scales linearly with nodes deployed.
Data TTL (Time-To-Live). The Gajumaru's mechanism for bounded chain growth. All on-chain data carries an expiration date. Storage is paid proportional to duration. When TTL expires, data is pruned. This keeps the chain permanently below 10 GB regardless of age or transaction volume.
Money and Value
Tokens and coins. A coin is the native currency of a blockchain – Bitcoin on the Bitcoin network, the 木Gaju on the Gajumaru. A token is a digital asset created on top of an existing blockchain, representing anything from a currency to a share of ownership to a membership right.
Stablecoins. Digital currencies designed to maintain a stable value, typically pegged to a traditional currency like the US dollar. They aim to combine the utility of blockchain (fast, borderless, programmable) with the price stability of traditional money. Major examples include Tether (USDT) and Circle's USDC.
Wallets. Software that holds the cryptographic keys needed to access and spend coins. A wallet does not actually contain money; the balance exists on the blockchain. The wallet holds the keys that prove ownership. Lose the keys, lose access.
Fibonacci sequence. A mathematical series where each number is the sum of the two before it: 1, 1, 2, 3, 5, 8, 13, 21… The Gajumaru's mining reward schedule follows a declining ratio derived from this sequence, creating a smooth reduction in block rewards over 87.5 years rather than Bitcoin's abrupt halving events.
Burned Gajus. Coins permanently removed from circulation, for instance through expired unclaimed transactions. On the Gajumaru, burned Gajus are returned to the unmined pool rather than destroyed, maintaining the integrity of the total supply and supporting long-term mining sustainability.
Smart Contracts
Smart contracts. Programs that live on the blockchain and execute automatically when pre-set conditions are met. Think of a vending machine: you put in money, select an item, and the machine delivers it without any human decision-maker. Smart contracts work the same way for agreements, payments, and conditions. They are atomic: all changes happen, or none do. The Gajumaru uses a purpose-built smart contract language called Sophia, designed for safety and auditability.
Formal verification. The process of using mathematics to prove that a smart contract will behave exactly as intended under all possible conditions, before it is deployed. Traditional software testing checks whether code works in the scenarios the developer thought of. Formal verification proves it works in every scenario, including ones the developer did not think of. For financial and governmental operations, a bug is not an inconvenience but a catastrophe: formal verification is the difference between a technology institutions can adopt and one they cannot.
FATE (Fast Aeternity Transaction Engine). The Gajumaru's virtual machine for executing smart contracts. Designed for safety by programming language experts, with type safety, overflow prevention, memory isolation, and development environment fidelity that eliminates entire categories of vulnerability present in other platforms.
Sophia. The Gajumaru's smart contract programming language. A functional language designed specifically for blockchain safety, running on the FATE virtual machine. Named after the Greek word for wisdom.
Generalised Account. A Gajumaru account upgraded from standard single-signature authentication to custom smart-contract-based authentication. Enables multi-signature, spending limits, corporate delegation, quantum-resistant signing, and any authentication logic expressible in Sophia.
Architecture
Associate Chain. A governed blockchain network built on top of Groot. Associate Chains are sovereign peers, not subsidiaries: each has its own operator, its own rules, and its own consensus mechanism. They connect to Groot through a native protocol, enabling value transfer between chains without third-party bridges. Associate Chains offer the efficiency that governance enables; Groot offers the trustlessness that governance cannot.
Layer 1 and Layer 2. A Layer 1 is a base blockchain: Bitcoin, Ethereum, the Gajumaru's Groot. A Layer 2 is a system built on top of a Layer 1 that claims to increase its speed or reduce its costs by processing transactions elsewhere and posting summaries back to the base chain. The Gajumaru does not use this terminology for its own architecture (it uses Resource and Infrastructure), but the terms appear throughout the industry critique in Part Four.
Sequencer. In Layer 2 systems, the sequencer is a single operator that decides which transactions are processed and in what order. Despite Layer 2 projects claiming to be decentralised, the sequencer is a central point of control. If the sequencer decides not to process your transaction, it does not get processed.
Bridge. A third-party system that transfers assets between separate blockchain networks. Bridges are notoriously insecure because users must trust the bridge operator. Billions of dollars have been stolen through bridge exploits. The Gajumaru eliminates bridges entirely: the protocol itself handles cross-chain transfers through native Associate Chain awareness.
Exchanges and Trading
DEX (Decentralised Exchange). An exchange where trading occurs through automated smart contracts rather than a company holding user funds. GajuDEX is a truly decentralised exchange with immutable contracts and no admin keys, distinguishing it from "DINO" (Decentralised In Name Only) exchanges that retain centralised control.
CEX (Centralised Exchange). A traditional exchange where a company holds user assets and executes trades on their behalf. QPQ Capital AG will operate a regulated CEX as a separate product from GajuDEX.
Admin key. A master override capability that allows whoever holds it to change or pause a smart contract system. GajuDEX has no admin keys; many purportedly decentralised exchanges retain them.
Airdrop. A distribution of free tokens, typically used to create the appearance of widespread adoption or to reward early participants. Airdrops often benefit insiders disproportionately and can be used to manipulate governance voting.
Vesting. The schedule by which tokens become available to their holders. When insiders' tokens vest (become sellable) before retail purchasers' tokens do, insiders can sell into retail demand while retail holders are locked in and unable to sell. This asymmetry is a recurring pattern examined in Part Four.
Security and Access
Air-gapped. Physically disconnected from the internet. In the context of GRIDS, the signing device is never directly connected to any network. Instructions and signed responses are communicated optically via QR codes. Keys that never exist on a connected device cannot be stolen from a connected device.
GRIDS (Gajumaru Remote Instruction Dispatch Serialisation). The Gajumaru's air-gapped signing protocol. Instructions are communicated via QR codes; private keys never touch a network-connected device. Enables secure payments, website authentication, and document signing without intermediaries.
Foundations and Industry Structure
Foundation. Most blockchain projects are overseen by a Foundation that claims to steward the project on behalf of the community. In practice, Foundations hold large supplies of tokens, control which developers receive funding, and determine the project's direction. This document examines why Foundations consistently concentrate power while using the language of decentralisation.
OFAC (Office of Foreign Assets Control). A division of the US Treasury that administers economic sanctions. In the blockchain context, OFAC compliance means validators voluntarily, or under pressure, exclude transactions involving sanctioned addresses. On Ethereum, validators complying with OFAC rules have at times processed over 70% of blocks, meaning the US government effectively influenced which transactions were included on a supposedly decentralised network. This is a concrete example of how proof-of-stake systems, where validators are identifiable and regulatable, can be compelled to censor transactions.
Regulation and Licensing
FINMA (Swiss Financial Market Supervisory Authority). Switzerland's financial regulator. Applies "substance over form" and "same risks, same rules" principles: the activity determines the regulation, not the label attached to it.
MiCA (Markets in Crypto-Assets). The EU's comprehensive regulatory framework for digital assets, now fully in force. Requires sustainability disclosures, white paper standards, and consumer protections. The Gajumaru's energy efficiency makes MiCA compliance straightforward.
VASP (Virtual Asset Service Provider). A regulated entity that provides services related to digital assets, including exchange, custody, and transfer. Subject to anti-money-laundering and know-your-customer requirements.
VQF (Verein zur Qualitätssicherung von Finanzdienstleistungen). A Swiss self-regulatory organisation for financial services. VQF affiliation is QPQ Capital AG's pathway to regulated operations.
GPL3 (GNU General Public License version 3). An open-source licence that guarantees freedom to use, study, modify, and distribute software, with a copyleft provision requiring that modifications also be shared under the same licence. Prevents anyone from taking open-source code and creating proprietary versions.
Fiat on/off ramp. A service that converts between traditional government-issued currencies and digital currencies. QPQ Capital AG is positioned to provide regulated fiat on/off ramp services for the Gajumaru ecosystem.
References
References are provided throughout this document where specific claims are made. Where you see quotations from our team discussions, these are drawn from the long-form discussions we have on our YouTube and Rumble channels. They are unscripted, real conversations between the core founding team.
Web
Social
Video
Disclaimer
QPQ AG builds the Gajumaru blockchain system. Analysis of other platforms and protocols throughout this document is based on publicly available documentation and represents QPQ's assessment of architectural characteristics. This is not legal, financial, or investment advice. Corrections to any factual errors are welcome at info@qpq.swiss
Forward-looking statements regarding technology development, regulatory approvals, partnership arrangements, and market adoption involve risks and uncertainties. Actual results may differ materially from those projected.
This document does not constitute an offer to sell or a solicitation of an offer to buy securities in any jurisdiction where such offer or solicitation would be unlawful.
QPQ AG Zug, Switzerland 31st March 2026
audited 212620 packages during npm install. https://github.com/MetaMask/metamask-extension/issues/5728. The MetaMask extension has grown substantially since 2018; the current dependency count is likely significantly higher. ↩audited 212620 packages during npm install. https://github.com/MetaMask/metamask-extension/issues/5728. The MetaMask extension has grown substantially since 2018; the current dependency count is likely significantly higher. ↩ ↩@solana/web3.js library compromise through phishing. ↩