From 0d253ba08a2ae63a170139cdb88d1d6b5443a2cb Mon Sep 17 00:00:00 2001 From: Aere Network Date: Mon, 20 Jul 2026 01:31:57 +0300 Subject: [PATCH] Initial public release Aere Network public source. Everything here can be checked against the live chain (chain id 2800, https://rpc.aere.network). Scope note, stated up front rather than buried: consensus on chain 2800 is classical secp256k1 ECDSA QBFT. The post-quantum work in this repository is at the signature, precompile, account and transport layers. Nothing here makes the consensus post-quantum, and no document in it should be read as claiming so. --- README.md | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/README.md b/README.md index 769c029..39adcb2 100644 --- a/README.md +++ b/README.md @@ -8,6 +8,30 @@ post-quantum cryptography and governance documents, the STARK verifier port spec their explicit caveats), the formal verification coverage reports, the reproducible-build and cross-client determinism documents, and the reproducibility manifest. +## Scope, stated up front + +Aere Network runs post-quantum signature verification natively on mainnet: Falcon-512 (`0x0AE1`), +Falcon-1024 (`0x0AE2`), ML-DSA-44 (`0x0AE3`), SLH-DSA-128s (`0x0AE4`) and SHAKE256 (`0x0AE5`) +have been live as precompiles since block 9,189,161. You can call them yourself against +`https://rpc.aere.network` without asking us for anything. + +**Consensus on chain 2800 is classical secp256k1 ECDSA QBFT.** The post-quantum work lives at the +signature, precompile, account and transport layers. Nothing in this repository makes the consensus +post-quantum, and nothing in it should be read as claiming so. Where you see post-quantum consensus +discussed, it is research about what a future activation could look like, not a description of the +running chain. + +Two further limits worth knowing before you judge anything else here: + +- `0x0AE6` (ML-KEM-768) and `0x0AE7` (Falcon HashToPoint) are **testnet only**. They are not + active on mainnet. +- The on-chain zero-knowledge verifiers are classical BN254. They are broken by Shor's algorithm + like any other elliptic-curve construction, and we do not describe them as quantum-safe. + +The network is operated by seven Foundation-run validators, so its Nakamoto coefficient is +effectively one today. That is a real limitation, it is on the roadmap, and it is not fixed by any +code in this repository. + ## Start here - `REPRODUCE.md` the single reproducibility manifest. It lists real paths, real commands, and