HYBRID-CHAINControl plane ↗

MPC WALLET ACTIVITY & SETTLEMENT PROOFS

Wallets funded.
Value transferred.
Evidence retained.

See the public lifecycle of Hybrid-native MPC wallets: activation, test-network funding, native transfers, and final proof state. Infrastructure evidence remains available separately and never substitutes for a customer transaction.
MPC WALLETS0Activated customer wallet proofs
TEST CREDITS0Devnet and Testnet faucet receipts
NATIVE TRANSFERS00 settled
SETTLEMENT PROOF EVENTSAppend-only transfer transitions
PROOF CONTINUITYREVIEW0 legacy archive sequence gaps

CANONICAL MPC ACTIVITY

One timeline for the wallet lifecycle.

Wallet ceremonies establish control. Faucet claims create isolated test balances. Native transfers change those balances. Each row links to the proof that explains exactly what happened.
01 WALLET ACTIVATION02 TEST FUNDING03 NATIVE TRANSFER04 FINAL PROOF
No MPC wallet activity matches this network.Mainnet may correctly show no records until production MPC settlement is explicitly enabled and exercised.
WHAT THIS VIEW EXCLUDESNO LEGACY VAULT OWNERSHIP · NO PRIVATE CUSTOMER IDENTITY · NO SIGNER TOPOLOGYOlder settlement bundles remain in the Legacy proof archive for historical verification. They are not presented as the current MPC wallet transaction model.

NETWORK TRUST BOUNDARIES

Three lanes. No implied equivalence.

Development, testing, and production evidence are deliberately separated. Core classifies every proof against a closed registry; an unknown network is never promoted to Mainnet.

NETWORK ASSURANCE & PROMOTION

Evidence can qualify a lane. Only governance can promote it.

Core derives technical readiness from public proof evidence and retained verification roots. Promotion always requires a separate signed governance action.
PRODUCTION NETWORKHybrid MainnetUNOBSERVED

Readiness dossierAWAITING CORE STATUS

REQUIRED EVIDENCECORE ACCEPTED SETTLEMENTPROMOTIONNOT ELIGIBLE
TEST NETWORKHybrid TestnetUNOBSERVED

Readiness dossierAWAITING CORE STATUS

REQUIRED EVIDENCECORE ACCEPTED SETTLEMENTPROMOTIONNOT ELIGIBLE
DEVELOPMENT NETWORKHybrid DevnetUNOBSERVED

Readiness dossierAWAITING CORE STATUS

REQUIRED EVIDENCEVALUELESS QUORUM CANARYPROMOTIONNOT ELIGIBLE
PUBLIC SAFETY BOUNDARYTECHNICAL READINESS ≠ GOVERNANCE APPROVAL ≠ SETTLEMENT AUTHORITYHistorical proofs remain verifiable when an observation becomes stale. Freshness describes current network visibility only; it never invalidates an accepted record.

SIGNED NETWORK GOVERNANCE

Readiness is observed. Promotion is authorized.

Every approval is bound to one exact technical-readiness snapshot and the active participant, validator, and durability trust roots. A later readiness dossier cannot inherit an older approval.
No signed network promotion has been published.Technical readiness may still be visible above. Until a quorum-approved certificate is imported and activated by Core, the network remains in its current lane.
PUBLIC PRIVACY BOUNDARYCOMMITMENTS · THRESHOLD · WINDOW · IMMUTABLE EVENTSApprover keys and signatures remain protected. Core publishes enough commitment evidence to bind the decision without exposing governance signing material.

THRESHOLD AUTHORIZATION PLANE

Awaiting a Core-reverified authorization ceremony.

The authorization plane remains fail-closed until one complete ceremony is cryptographically verified and bound to the currently pinned participant, validator, and durability roots.
No public authorization activation matches this view.No incomplete or partially verified ceremony is promoted into the public proof chain.
PUBLIC SAFETY BOUNDARYAUTHORIZATION QUORUM ≠ VALUE-BEARING SETTLEMENTOnly commitments, quorum counts, operator-domain counts, and verification state are public. Signer routes, topology, shares, nonces, recovery material, and private credentials are never included.

CUSTOMER MPC WALLET LIFECYCLE

Awaiting a customer-bound enrollment request.

Customer wallet enrollment begins with an authenticated, idempotent Core record. It does not create a public key, authorize funds, or permit settlement until the later threshold ceremony completes.
PUBLIC CLASSIFICATIONCUSTOMER BOUND · VALUELESS · NOT ACTIVATEDCore discloses only one-way commitments, the native public address after activation, quorum evidence, and state. Customer identity, authentication secrets, master-password material, challenges, routes, shares, nonces, and recovery material stay private.
No customer MPC wallet enrollment matches this view.No private customer or account identifiers are inferred from public wallet activation evidence.
MPC SECURITY BOUNDARYNATIVE AUTHORIZATION → EXACT DKG INTENT → INDEPENDENT ADMISSION → ENTROPY TRANSCRIPT → DKG → ACTIVATIONEntropy evidence is a prerequisite, not wallet activation. Fresh participant-local OS CSPRNG input, threshold DKG, signer receipts, validator finality, and independent Core verification remain mandatory.

SYSTEM MPC CANARY ACTIVATIONS

Awaiting a Core-reverified system canary.

System canary evidence appears only after Core replays the complete public ceremony against the pinned authorization roots.
PUBLIC CLASSIFICATIONVALUELESS · SYSTEM CANARY · NO USER FUNDSThe address and proof commitments are public. Key shares, DKG transcripts, nonces, signer routes, credentials, and recovery material remain private.
No MPC wallet activation matches this view.No incomplete ceremony, partial threshold signature, or value-bearing instruction is published as a wallet activation.
SYSTEM CANARY BOUNDARYFROST SIGNATURE → VALIDATOR CERTIFICATE → CORE RE-VERIFICATIONThis is signature-system evidence only. It creates no customer account, accepts no deposit, moves no asset, and opens no settlement route.

TEST-NETWORK ASSET SUPPLY

Awaiting the first MPC-gated test credit.

Claims remain unavailable until Core observes an active wallet and a current threshold-signing proof on the same network.
ECONOMIC CLASSIFICATIONNETWORK-ISOLATED BALANCE · NO RESERVE CLAIM · NO WITHDRAWAL · NO BROADCASTDHYBRID exists only on Devnet; THYBRID exists only on Testnet. Neither asset is money, a deposit, a Layer-1 reserve claim, redeemable HYBRID, or transferable across network boundaries.
No public faucet claim matches this view.Issuance never bypasses same-network MPC activation, fresh signing evidence, cooldown, daily limit, maximum balance, or the selected network’s capped test supply.
CONTROL CHAINACTIVE WALLET → FRESH SIGNING PROOF → RATE LIMIT → COLLATERAL ENTRY → PUBLIC RECEIPTCustomer identity and private signing material remain concealed while the exact operational and accounting bindings remain independently inspectable.

DURABILITY MEMBERSHIP

Awaiting a pinned replica set.

Settlement evidence remains fail-closed until a governance-approved durability membership is installed.
PUBLIC BOUNDARYMEMBERSHIP PROOF · NO PRIVATE TOPOLOGYOnly commitments, thresholds, epochs, and activation state are exposed. Replica addresses, regions, and signing material remain private.

VALUELESS QUORUM CANARIES

Five votes. One retained boundary.

These certificates prove that the admitted durability replicas retained the same journal transition. They are operational quorum evidence only: no balance changed, no external asset moved, and no financial settlement is inferred.
CLASSIFICATIONVALUELESS · NON-FINANCIAL · QUORUM RETENTIONCore independently resolves the pinned membership epoch and verifies every Ed25519 vote before publishing a record.
No valueless quorum canary matches the selected network and proof search.
TRUST BOUNDARYREPLICA CERTIFICATE → PINNED MEMBERSHIP → CORE RE-VERIFICATIONNo mesh endpoint, private key, clear fault-domain label, or external-value instruction is published.

LIVE COORDINATOR OPERATIONS

Readiness now. Proof after finality.

This health signal reports whether an admitted replica route can currently coordinate settlement. It cannot authorize value movement and is never counted as a finalized settlement proof.
The settlement proof ledger remains available. Live coordinator readiness will appear after the first privacy-filtered supervisor report reaches Core.
BOUNDARYOPERATIONAL TELEMETRY · NOT SETTLEMENT PROOFNo replica addresses, endpoint identities, fault-domain labels, private route topology, or signing material are exposed.

REGIONAL ARCHIVE CONTINUITY

Every retained bundle. One exact boundary.

Regional replicas sign an ordered inventory of finalized settlement bundles. Core accepts a checkpoint only after its inventory matches the records already admitted, then returns a separate signed acceptance receipt.
CHECKPOINTS00 represented networks
UNCHECKPOINTED RECORDS0Newer accepted records await a boundary
CORE ACCEPTANCEUNREPORTED0 missing signed receipts
LATEST BOUNDARY
No regional archive checkpoint has reached the public Core record yet.
PUBLIC PROOF CHAINREGIONAL SIGNATURE → EXACT INVENTORY → CORE ACCEPTANCECheckpoint evidence proves retained-set completeness without exposing replica locations, private signing material, storage paths, or internal transport topology.

LIVE CRYPTOGRAPHIC RE-VERIFICATION

Recent proof rows. Recomputed now.

Core re-opens a bounded recent window, resolves every receipt against its historical public acceptance key, recomputes stored commitments, and independently verifies regional archive signatures. This is an active audit, not a database status flag.
SETTLEMENT RECEIPTS0 / 00 missing · latest sequence
REGIONAL CHECKPOINTS0 / 00 networks · latest sequence
CORE ARCHIVE RECEIPTS0 / 00 missing signed receipts
ACCEPTANCE KEY HISTORY0 KEYS
VERIFICATION POLICYRECENT_WINDOW_UNAVAILABLEAudited . This panel deliberately describes the bounded recent window; the append-only ledger below remains the full public history.

LEGACY SETTLEMENT PROOF ARCHIVE

Historical bundles, kept separate.

These Core-accepted records predate the current customer MPC wallet activity model or use the older bundle vocabulary. They remain verifiable, but they are not wallet balances, faucet credits, or the native transfer timeline shown in MPC activity.
OPEN CURRENT TRANSFER PROOFS ↗
SYNCHRONIZING HISTORICAL SETTLEMENT PROOFS…