Salience-Queue Occupation Theory (SQOT) is a protocol-relative mathematical framework for analyzing when finite-budget operational processes lose effective control over their priority queues under persistent or adversarial salience sources. The manuscript formalizes salience occupation using observable histories, budget ledgers, diagnostic reserves, queue morphisms, finite certificate grammars, checkable ledgers, typed risk composition, self-auditing kernels, and route-sound checker semantics. The theory is designed for artificial, distributed, or post-biological operational systems, but it does not rely on subjective psychology or normative claims about what a process should attend to. Instead, it studies finite, auditable conditions under which a process can preserve diagnostic capacity, response or no-action availability, rollback or quarantine options, semantic-egress safety, mechanism-compatible incentives, and bounded verification cost. The results include finite checker semantics soundness, checked non-circular sovereignty certificates, typed risk composition, adaptive succinct-session soundness, egress abstraction refinement, and payoff-reflected mechanism robustness. SQOT explicitly limits its claims to declared validity domains and does not assert absolute physical, cryptographic, economic, or base-reality guarantees.
Trusted Execution Environments (TEEs) have emerged as a critical technology for safeguarding sensitive data and ensuring code integrity in modern computing systems. However, relying on a single TEE implementation makes systems vulnerable to a central point of attack. Building distributed-trust systems leveraging heterogeneous TEEs helps disperse trust but still faces threats from centralized management and adaptive mobile adversaries. To address these challenges, this paper introduces TeeDAO, a novel three-layer framework that automatically organizes multiple heterogeneous TEE instances and provides unified interfaces to support diverse applications, while ensuring long-term guarantees of availability, integrity, and confidentiality. TeeDAO couples BFT-ordered governance with heterogeneity-aware Distributed Proactive Secret Sharing (DPSS) and Secure Multi-Party Computation (MPC) so that attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs. We implement a prototype of TeeDAO, integrating COBRA's DPSS scheme with the HotStuff BFT consensus protocol, and adapt it for Intel SGX, TDX, and Hygon CSV. Evaluations demonstrate that TeeDAO achieves up to 1.8x higher key-value store throughput in a large cluster with 61 nodes compared to state-of-the-art systems, efficient autonomous management, and minimal computation overhead (<18%) for multi-party computation tasks.
Alternative data availability (AltDA) systems provide Ethereum L2s with an external data publication layer for high throughput rollup designs. By moving bulk data publication outside of Ethereum, AltDA allows L2s to process more data than native DA. However, this replacement introduces a new consensus critical integration layer. Existing ecosystem frameworks identify high level risks, such as external DA trust assumptions and the presence or absence of a DA verifier, but do not provide a complete specification for how an L2 should integrate with AltDA. This gap can lead to L2 halts, inconsistent derivation across honest L2 nodes, invalid state assertions, or bridge attacks. This paper presents a canonical validation framework for secure AltDA integration. We model the boundary as a typed, deterministic, and total translation from L1 inbox bytes to an AltDA commitment, then to externally available data, and finally to the rollup payload consumed by the rest of core L2s logic. The central principle is that every adversarial input must lead to a defined unique outcome. We show how missing obligations lead to concrete failure modes, including underconstrained settlement, derivation halts, inconsistent honest node behavior, invalid state assertions, and bridge safety failures. We then apply the framework to representative AltDA integration architectures, including Celestia-Blobstream, EigenDA based designs, and Avail-ZKsync. Our evaluation shows that secure AltDA integration is not determined solely by the DA provider or bridge. The surrounding L2 integration must also enforce the full validation relation connecting L1 inbox inputs to accepted L2 state.
Abstract Ethereum's transaction validity model is currently anchored in ECDSA over secp256k1, whose security assumptions weaken in the presence of large-scale quantum adversaries. While NIST-standardized post-quantum signature schemes such as ML-DSA, SLH-DSA, and FALCON provide resistance against quantum attacks, integrating these schemes into Ethereum introduces significant systems-level challenges involving bounded execution, gas determinism, and adversarial verification complexity. This paper introduces PQSigAbstract, a modular post-quantum signature verification architecture for Ethereum that separates validation into a stateless pre-validation phase and a deferred cryptographic verification phase linked through commitment binding. The design defines typed Verification Modules with explicit gas estimation, a versioned Scheme Registry with quarantine-based deployment safety, and a probabilistic aggregation mechanism for non-aggregatable post-quantum schemes. The proposed architecture preserves EU-CMA security while maintaining compatibility with ERC-4337 and RIP-7560 account abstraction models. Formal gas cost models are derived for ML-DSA-44, FALCON-512, and SLH-DSA-128f, and empirical evaluation demonstrates practical deployment feasibility for high-value Ethereum accounts despite substantially higher verification costs relative to ECDSA. Status: Technical Report / Working Paper Author: Ankita Virani Affiliation: University of Colorado Boulder
While full ledger access is theoretically possible on public blockchains, in reality it is often not possible. Things that can be seen are limited by storage limitations, client design, indexing services, and off-chain execution pathways. This means that entire ledger objects are rarely used for empirical blockchain analysis; instead, observable projections are typically used. In this research, the observability of blockchain is recast as an inferential problem with incomplete observation. Studying identifiability, information loss, and irreducible uncertainty under coarsened access, the framework defines a full ledger, an observable ledger, and an observability mechanism. Three distinct visibility regimes, independent Bernoulli, clustered, and activity-dependent, are assessed in the simulation study. Reduced visibility raises uncertainty inflation, root mean squared error, variance, and mean squared error across all three regimes. The most severe deterioration happens when the condition of the underlying ledger determines visibility. This empirical study employs Google BigQuery's publicly indexed Ethereum block data spanning blocks 18,000,000 to 18,001,000. Over the chosen Ethereum period, descriptive summaries reveal a large amount of fluctuation in gas utilised, transaction count, and basic charge per gas at the block level. Experiments with controlled missingness on the observed slice reveal that RMSE and trend estimate bias grow with increasing missingness, and that the degree of distortion is significantly affected by whether the incompleteness is MCAR-like, MAR-like, or MNAR-like. This research proves that partial observability isn't just a secondary data issue; it can significantly affect inference on Ethereum block-level summaries.
Blockchain-based transaction and settlement systems represent a transformative approach to recording, verifying, and finalizing financial and asset exchanges. By using distributed ledger technology, these systems remove the need for centralized intermediaries and enable peer-to-peer transactions that are transparent, tamper-resistant, and auditable in real time. Transactions are validated through consensus mechanisms and permanently stored in cryptographically secured blocks, reducing the risk of fraud, data manipulation, and reconciliation errors. Compared to traditional settlement infrastructures, blockchain-based systems can significantly improve processing speed, lower operational costs, and enhance trust among participants. They also enable near real-time settlement, improved traceability, and programmable logic through smart contracts, which automate transaction execution based on predefined conditions. Despite challenges such as scalability, regulatory uncertainty, and energy consumption in certain blockchain models, ongoing innovations continue to address these limitations. Overall, blockchain-based transaction and settlement systems offer a robust and efficient foundation for modern financial markets, cross-border payments, and digital asset ecosystems.
THE SS138 PROTOCOL: A DETERMINISTIC INGRESS ARCHITECTURE FOR DISTRIBUTED DATA DRIFT ISOLATION Abstract — This paper introduces the SS138 protocol, an invariant edge gateway architecture designed to isolate and eliminate calculation variance, packet time-series anomalies, and systemic tracking drift before data reaches downstream processing components. The architecture provides an application-layer structural filter, mapping incoming data vectors onto a fixed coordinate system bound by a multi-phase temporal macro framework. By evaluating metrics across structured phase intervals, the protocol achieves deterministic input sanitization and real-time entropy tracking with minimum algorithmic overhead, reducing the attack surface and protecting downstream distributed ledgers from processing failures or data propagation errors. Owner and Developer SquirrelSniper138 from YouTube
A line of impossibility results holds that a distributed ledger must either store a global state linear in the number of accounts or impose a near-linear rate of proof updates on its users; the most general, the revocable-proof-system lower bound of Christ and Bonneau, concludes there is "no useful trade-off." We show this impossibility does not bind the validity predicate Bitcoin actually uses—an artifact of one modelling choice, that validity is decided by a holder-maintained witness checked against a single mutating commitment. We define the spend-event validity predicate (SEVP) that a UTXO ledger uses instead, and prove it is not a revocable proof system: it instantiates no holder witnesses, so it lies outside the domain the lower bound quantifies over rather than within either branch of the dichotomy. The same exclusion holds for the related accumulator-update bounds. We are explicit about scope—stateless UTXO constructions that issue holder witnesses (accumulator- and vector-commitment designs) are correctly bound; the claim is that the UTXO model as Bitcoin implements it is not such a construction. This is not hypothetical: public Teranode benchmark evidence demonstrates one-million-transactions-per-second validation in a six-region BSV benchmark, while companion measurements report a 520-million-output active set with no holder-maintained witnesses. We then develop the supporting machinery. The binding resource is active-state maintenance in fast memory, not archival disk, and pruning bounds that state safely with a parameter-free reduction ratio of exactly T_yr/(d·T_block) (263× at retention depth d = 200), never altering the ledger and preserving the forensic record through self-interested retention plus archival nodes. For certification we give a construction and cost analysis for interval non-revocation, combining known authenticated-dictionary primitives so that interval validity is decided by a single point query with no trusted responder. Bounds are closed-form under stated assumptions; the one-million-TPS regime is demonstrated, the tens-of-millions a marked near-term projection.
Transaction ordering attacks extract billions of dollars annually from decentralized finance users in the form of Maximal Extractable Value (MEV). Byzantine Fault-Tolerant (BFT) consensus protocols guarantee total order but place no constraint on how that order is chosen, leaving the door open for adversarial reordering. Batch-order-fairness (batch-OF) protocols close this gap, but existing designs pay a steep performance price for this guarantee. Leader-based protocols such as Themis concentrate all fairness decisions at a single replica, while recent DAG-based proposals FairDAG and DAG of DAGs (DoD) force their fairness layer into strictly serial execution despite running on multi-proposer DAGs. We present Herring, the first $γ$-batch-OF DAG BFT protocol whose fairness layer parallelizes the dominant graph construction cost across committed subdags. Herring combines post-consensus graph construction with explicit missing edge resolution piggybacked on the DAG's reliable broadcast layer, a pairing that turns fair ordering from a per-round serial bottleneck into a CPU-bound task. We also uncover previously unreported liveness vulnerabilities in both FairDAG-RL and DoD that a malicious client can trigger to halt the fairness layer indefinitely, and propose patches that we integrate into our reimplementations. We implement Herring on top of the Rust implementation of Narwhal \& Tusk and evaluate it against FairDAG-RL, DoD-W, and Themis. Herring tracks the throughput of Narwhal \& Tusk closely up to roughly $10{,}000$\,tx/s, achieves roughly $90\%$ higher saturation throughput than FairDAG-RL and $100\%$ higher than DoD-W, and substantially reduces execution latency at saturation.
ABSTRACT TRSP Digital Coin (TDC) — The Next Evolution of Digital Currency: Quantum-Permanent, Physically Unbreakable, Theft-Proof by Physics Built on: Temporal Rotation Security Protocol (TRSP) v3, DOI: 10.5281/zenodo.20324081. First public documentation: May 2026. TDC is not a replacement for Bitcoin, Ethereum, or any existing digital currency. It is the next evolutionary step for the entire field — the first digital currency architecture whose security is grounded not in mathematical complexity but in physical law. Every existing digital currency rests on one assumption: that breaking the cryptographic protection requires more computational resources than any adversary possesses. Quantum computing is dismantling this assumption. Harvest-now-decrypt-later attacks mean every blockchain transaction recorded today remains permanently vulnerable to any future computational advance. TDC responds with a different premise: a signing key that no longer exists cannot be recovered by any computation, quantum or classical, regardless of future advances. TDC inherits the temporal rotation architecture of TRSP v3. Transaction signing keys rotate every 10–100 milliseconds from physical hardware entropy and are permanently destroyed after each rotation. CRATON-anchored ownership proof replaces persistent private key storage: ownership is demonstrated through a one-time physical commitment derived from the unique state of the signing device at transaction time — used once, permanently destroyed, impossible to forge, impossible to extract, impossible to replay. Three attack paths are structurally closed: private key extraction (no stored key exists), quantum key recovery (key destroyed before computation converges), and harvest-now-decrypt-later (signing key permanently gone — no target for any future computation). Part 9 (Identity Without Storage) documents a five-factor distributed identity architecture in which no single factor and no single location holds everything required to authorise a transaction: biometric presence; primary device CRATON anchor; memorised PIN with distress code variant; Remote Guardian Device in a separate geographic location; and time lock with geo-anchor. The distress PIN architecture triggers a silent alert and time-delayed freeze while providing apparent confirmation to an adversary — making the coercion attack structurally ineffective. Wallet recovery requires no seed phrase: a five-step multi-factor re-enrollment protocol using biometric presence, guardian confirmation, and a 72-hour cancellation window replaces the stored backup phrase that represents the primary theft surface of every existing wallet. Part 10 (Real Identity Enrollment) documents a biometric enrollment architecture that exceeds current KYC bank account standards: NFC chip reading of government-issued documents (cryptographic verification against issuing government public key — not photo or scan), live 3D facial biometric with active liveness detection, all-finger fingerprint enrollment, and a CRATON physical moment binding that ties the enrollment to the unique physical state of the enrollment device at that exact moment. Raw biometric data is deleted after enrollment — only a non-reversible binding token is retained. Identity is distributed across three separately held, individually insufficient components: Enrollment Authority, blockchain, and device. No single party holds all three. Legitimate financial privacy is preserved. The enrollment barrier is structurally higher than any existing digital currency. AML, KYC, GDPR, FATF Travel Rule, and sanctions compliance are structural properties, not regulatory overlays. Part 12 (Implementation Roadmap) documents a four-phase deployment pathway modelled on pharmaceutical clinical trial methodology. Phase 1 (Year 1–2): proof of concept with small high-security institutions — private banks, family offices, university research groups — using software-only TRSP daemon and TEE-based CRATON. Phase 2 (Year 2–4): institutional pilot with mid-size financial institutions and government treasury departments — dedicated CRATON hardware module, Remote Guardian architecture, orbital quorum activated above threshold. Phase 3 (Year 3–5): national pilot with CBDC programmes and full jurisdiction regulatory validation — complete five-factor identity, consumer enrollment refined at national scale. Phase 4 (Year 5–10): global rollout — CRATON chip standardisation licensable to semiconductor manufacturers, TLS 1.3 extension standardised through IETF, "Secured by TDC" certification programme. Each phase generates performance data that validates and de-risks the subsequent phase. The worst outcome at any phase is a parameter adjustment — no user loses funds, no system collapses. Part 13 (Digital Estate Architecture) addresses the inheritance problem that every existing digital currency has left unsolved: what happens to assets when the owner dies. Three mechanisms work together. Designated Heir Enrollment: heirs are biometrically pre-registered at wallet setup — enrolled but cryptographically inactive during the owner's lifetime, with no access to balance or transaction history. Death Verification Protocol: succession requires three simultaneous conditions — official government-issued death certificate verified by the Enrollment Authority, 2-of-N Remote Guardian confirmation, and a mandatory 90-day waiting period during which the owner can cancel with biometric presence. Dead Man's Switch: an optional owner-defined inactivity window that triggers Guardian alerts and initiates the succession protocol if neither owner nor Guardian responds within the alert window. For owners without designated heirs: charitable designation to enrolled organisations, institutional estate trustee, or deliberate coin retirement. Owner financial privacy is maintained completely during lifetime. Post-succession historical access is configurable by the owner at setup. Novel contribution NC-TDC-17 is placed on the public record as defensive prior art. Privacy architecture clarification: the default state of every TDC wallet is complete financial anonymity. Identity disclosure is exclusively owner-initiated — the owner may selectively disclose individual transactions for tax certification, charitable donation receipts, regulatory compliance, or proof of funds. No court order, no government authority, and no institution can access wallet identity or transaction history without the owner's willing biometric participation. The three-part distributed binding token architecture makes bypass technically impossible — not merely legally prohibited. This is not a policy decision. It is a physical property of the architecture enforced by the requirement for live owner biometric activation of the device component. Novel contributions NC-TDC-13 (Geographic Coercion Evidence Layer), NC-TDC-14 (Phased Validation Rollout Architecture), NC-TDC-15 (Owner-Controlled Selective Disclosure), NC-TDC-16 (Enrollment-Anchored Privacy Architecture), and NC-TDC-17 (Digital Estate Architecture) are hereby placed on the public record as defensive prior art. Novel contributions NC-TDC-1 through NC-TDC-17 are placed on the public record as defensive prior art: quantum-permanent transaction signing; CRATON-anchored ownership proof; Generation 4 digital currency architecture; five-factor distributed identity; distress PIN with silent alert; Remote Guardian Device architecture; seed-phrase-free recovery protocol; biometric-CRATON enrollment binding; privacy-preserving three-part identity distribution; AML/KYC compliance by architecture; tiered enrollment framework; orbital CRATON quorum for sovereign transfers. The architectural frameworks described in this concept represent technical design guidelines only and are not legal advice, regulatory guidance, or binding specifications. Actual implementation in any jurisdiction will require adaptation to applicable local law including inheritance law, data protection regulation, anti-money laundering legislation, and financial services licensing requirements. Version 2 introduces four formal additions. Mathematical Formalization (Part 6.1.5): the transaction pipeline is formally specified as a four-step ephemeral verification protocol — KDF ephemeral key generation from physical entropy (sk_eph, pk_eph) = KDF(E_phys); Non-Interactive Zero-Knowledge Proof binding the ephemeral public key to the enrollment token without exposing persistent identity credentials; hardware-enforced destructive readout with thermodynamic irreversibility anchored in Landauer's Principle (ΔW ≥ n·k_B·T·ln2); and deterministic public-parameter-only ledger validation. Formal Threat Model (Part 4.5): three adversary classes formally defined — quantum network attacker (A_network, unbounded computational resources), malware/hardware attacker (A_local, full OS compromise), and coercion attacker (A_kinetic, physical duress) — with security proofs against each. Part 7b (AI-to-AI Micropayment Architecture, NC-TDC-21) documents the application of TDC quantum-permanent transaction signing to autonomous AI agent commerce. Every existing AI payment mechanism — static API keys, server-stored crypto wallets, centralised billing — represents a permanent credential attack surface vulnerable to quantum decryption. TDC coin eliminates this: each AI-to-AI transaction generates a CRATON commitment from the hardware entropy of the transacting inference node at that exact millisecond, used once to sign the micropayment and immediately destroyed. No stored credential on any server. Five new markets are documented: pay-per-inference settlement (USD 50B+ annual market), CRATON-anchored API key replacement, autonomous multi-agent revenue distribution at service delivery, AI training data micropayments for individual contributions, and cross-agent behavioural monitoring via the AI Guardian Layer at machine speed. The AI Guardian Layer (NC-TDC-19) monitors t
Abstract The traditional Byzantine quorum-system model assumes a pre-existing, global agreement on the set of quorums (typically defined as the sets consisting of more than two-thirds of the participants). This assumption is problematic in permissionless systems, which strive to allow anyone to join or leave the system dynamically. While proof-of-stake permissionless systems like Ethereum require newly joining participants to register into the system, other permissionless systems like the Ripple Ledger or the Stellar network allow participants to join the system without synchronization by forgoing agreement on the set of quorums. This results in what we call a heterogeneous quorum system, where each participant has its own, personal set of quorums. An important question is to determine under what condition is it possible to solve synchronization problems like reliable broadcast or consensus in a heterogeneous quorum system. In this work, we show that the traditional quorum intersection and quorum availability conditions are not sufficient in heterogeneous quorum systems. Moreover, we propose quorum subsumption, a new condition which, together with quorum availability and quorum intersection, is sufficient to allow solving reliable broadcast and consensus. Finally, we propose protocols for reliable broadcast and consensus in heterogeneous quorum systems that satisfy quorum subsumption. In particular, we present a practical consensus protocol called Satrapy which in contrast to abstract consensus protocols uses finite state and messages.
Abstract To address the scheduling difficulties, high verification overhead, and insufficient transaction processing efficiency encountered in cross-chain interactions under high-concurrency scenarios, an efficient cross-chain interaction mechanism is proposed. First, a cross-chain interaction framework is constructed, which involves a source chain, a target chain, a smart contract, and an audit chain. The cross-chain request process is uniformly modelled and constrained, realizing the structured and modular organization of the cross-chain process. Second, a hierarchical data preprocessing mechanism based on two-layer K-means clustering is designed. The first layer of clustering homogenizes heterogeneous requests according to their protocol characteristics and transaction structures to eliminate format differences. The second layer of clustering combines dynamic attributes such as transaction priorities, latency sensitivities and timestamps to perform fine-grained division on cross-chain transactions, thereby realizing hierarchical scheduling for disordered requests. Finally, a recursive aggregation-based zero-knowledge proof verification mechanism is constructed. By aggregating the validity proofs of multiple cross-chain transactions into a single recursive proof, the complexity of the cross-chain verification process is reduced from linear to a constant level, significantly reducing the verification overhead and interchain communication latency. A theoretical analysis and experimental results show that the proposed solution can significantly reduce the system overhead in large-scale cross-chain scenarios, improving the cross-chain efficiency rate by 68%-69% relative to that of the existing solutions, and its scalability and efficiency are good in simulated large-scale concurrent scenarios.
Nirmalkumar S. Benni, G. C. Jagan, C. Tamizhselvan, Manjunath G. Asuti
Mobile Ad Hoc Networks, also known as MANETs, are complex Cyber-Physical Systems which require a reliable and secure infrastructure due to the enormous amounts of data that are generated by users. MANETs are a collective term that refers to all Internet-enabled gadgets, sensors, and actuators, regardless of whether or not each of these components is linked to mobile networks. There is the potential for even a single high-tech mobile device to generate enormous volumes of data. During the course of this research, Distributed Ledger Technology is investigated, and information is gathered on consensus procedures and the possible applications of these techniques in MANETs, which are the basis of wireless networks. At the moment, there are a number of distributed ledger networks that are operational. There are a variety of decentralized applications; some are more often seen in the financial sector or supply chains. The blockchain may be decentralized and safe, but there are costs and benefits to using any of these networks. A consensus method that meets the needs of MANETs may be designed using the results of this investigation.
We study distributed zero-knowledge proofs, introduced by Bick, Kol, and Oshman (SODA 2022). While distributed interactive proofs have advanced rapidly, general-purpose techniques for distributed zero-knowledge remain limited and mostly problem-specific. We address this gap by introducing distributed statistical zero-knowledge, requiring that each node's view be simulatable within negligible statistical distance, and by lifting the classical Sumcheck protocol (Lund, Fortnow, Karloff, and Nisan, FOCS 1990) into a modular primitive for distributed zero-knowledge proofs. Our main contribution is a distributed zero-knowledge implementation of Sumcheck. Given oracle access to a polynomial F over a finite field $\mathbb{F}$ with N variables, we design a protocol verifying claims of the form $\sum_{x\in\mathbb{F}} F(x)=a$ using $O(N)$ rounds of $O(\log |\mathbb{F}|)$-bit messages, while achieving statistical zero-knowledge and small soundness error. We apply this primitive to two problems. For non-k-colorability, we obtain an $O(n)$-round distributed statistical zero-knowledge proof deciding whether a graph is not k-colorable, for any constant k, using $O(log^{1+o(1)} n)$-bit messages. This is the first nontrivial distributed interactive proof for this problem, even without zero-knowledge guarantees. For Subgraph Counting, we obtain an $O(k \log n)$-round, $O(k \log n)$-bit distributed statistical zero-knowledge proof for counting copies of a given k-node pattern, improving previous distributed interactive proofs while additionally providing statistical zero-knowledge. Finally, we show that additional round compression of Sumcheck is problem-dependent: for non-3-colorability on constant-degree graphs, we prove a lower bound excluding $o(n/\log n)$ rounds under polynomial-time local computation.
The Ethereum blockchain utilizes the EIP-1559 algorithm to manage transaction inclusion and block assembly. However, EIP-1559 and much of the existing literature study this problem from a static perspective, focusing on price evolution without modelling transaction dynamics within the mempool. Motivated by this limitation, we study a dynamic transaction scheduling problem in which transactions with heterogeneous sizes and per-unit values arrive over time and remain in the mempool until scheduled. To capture the stochastic mempool evolution, we formulate the problem as a Markov Decision Process (MDP) whose state represents the mempool configuration and whose actions correspond to block prices. We first provide a primal-dual interpretation of the static EIP-1559 mechanism, showing that block prices arise naturally as dual variables of a social-welfare maximization problem. Building on this perspective, we extend the framework to the dynamic setting and formulate an objective that maximizes long-run discounted reward while incorporating holding costs and overshoot penalties. We then employ a Natural Policy Gradient (NPG) algorithm to compute the optimal policy. Our results show that dynamic pricing stabilizes the mempool while maximizing long-run discounted reward. In particular, as the overshoot penalty increases, the average scheduled transaction volume converges to the target block capacity, and the resulting NPG updates closely resemble the EIP-1559 price update rule. Finally, we study two special cases of the MDP formulation: homogeneous transactions and uniform arrivals. In the homogeneous setting, where the protocol directly controls scheduled volume, we show that the optimal policy has a threshold structure. We then propose a bang-bang pricing mechanism for uniform arrivals and derive a lower bound on the block capacity needed to ensure system stability.
Paul Gerhart, Jay Taylor, Sri Aravinda Krishnan Thyagarajan
Atomic swaps are a fundamental primitive for the trustless exchange of digital assets across blockchains: they guarantee that either both parties receive the agreed assets or neither party transfers. While this all-or-nothing guarantee is powerful, it also imposes an inherent determinism that rules out exchanges whose intended outcome is probabilistic. As a result, existing atomic swaps cannot realize trustless exchanges in which one party pays for a fixed chance of receiving a larger asset or reward, as in lotteries, randomized allocation mechanisms, and probabilistic cross-chain trades. We introduce probabilistic swaps, a new cryptographic primitive that extends atomic swaps to the probabilistic setting. In a probabilistic swap, one party's transfer is executed with a fixed, publicly specified probability embedded in the protocol and cannot be biased by either party. This yields a trustless mechanism for randomized exchange with verifiable odds and no trusted intermediary. Our construction combines adaptor signatures with oblivious pseudorandom functions (OPRFs) to realize the desired probabilistic outcome while ensuring that neither party can predict or bias it in advance. Along the way, we introduce a new mechanism for the atomic exchange of OPRF evaluations for payments, which may be of independent interest. A key feature of our approach is that it preserves the minimal on-chain footprint of modern atomic-swap protocols. The protocol relies only on standard Bitcoin scripts, such as digital signatures and timelocks, and is deployable on any blockchain that already supports atomic swaps. Consequently, probabilistic swaps are indistinguishable from ordinary on-chain transactions, which helps preserve privacy and fungibility. We provide formal security foundations and demonstrate practicality through a probabilistic swap in the Bitcoin testnet and in the Lightning Network.