the deliberately simple version

Astrea, explained
as simply as we can

Everything on this page is simplified on purpose. Each section links to the page that says the same thing exactly, scope and caveats included. Start here, then dig into whichever part you get curious about.

01 · what a proof is

A proof is a photo you cannot fake

The whole idea in one picture

When something important happens, you photograph it, and later the photo settles the argument. Astrea's proofs work the same way: every time a computation runs, the system produces a small mathematical "photo" of it. Anyone can look at that photo later and confirm the thing really happened, exactly by the rules, without redoing the work or trusting whoever did it.

The difference between this photo and a real one is that math makes it unforgeable. Faking a single Astrea proof would take longer than the life of the universe, and that statement is designed to keep holding even against a quantum computer. And because every proof is zero-knowledge, the photo shows that the rules were followed without showing the private things inside — like a photo that proves a letter was signed without showing what the letter says.

SOMETHING HAPPENS · A PROOF GETS TAKEN · ANYONE CHECKS IT
the unfakeable photo
A computation becomes a sealed proof that anyone can check A computation runs once, the proving step produces a sealed zero-knowledge proof, and any number of participants can verify that proof forever without redoing the work. SOMETHING HAPPENS a computation runs once THE PROVING STEP PixelVM takes the photo while the work happens THE PROOF zk sealed · unforgeable ANYONE checks it, forever
One computation, one sealed zero-knowledge proof, any number of checkers — nobody has to redo the work, and nobody has to be trusted.

The precise version: Astrea is engineered for 160-bit post-quantum security in its primary profile, with an absolute 128-bit floor — both conditional on the declared construction and assumptions. The network page states this exactly, and the PixelVM page explains how the photo gets taken.

02 · what is broken today

Four problems Astrea was built to remove

Quantum exposure

Almost every chain running today — including ones with a post-quantum roadmap — still has classical pieces a future quantum computer breaks: the signatures, the key exchange, or the privacy math itself. Worse, encrypted traffic can be recorded now and unwrapped later, once the hardware exists.

Astrea is post-quantum from the ground up. Every protected boundary carries a classical lock and a post-quantum lock together, from the first epoch onward, and the post-quantum lock is mandatory — never an optional extra.

Servers you must believe

When your wallet asks a server for your balance, you get a number and a promise. The server can be wrong, hacked, or lying — about your balance, about whether your transaction happened — and on most networks your only defense is a chain of certificates you never actually check.

On Astrea, every answer arrives with a proof, and your wallet checks that proof against a certified root whose provenance chains back to the first epoch. You can trust nothing — not the server, not the operator, not the middleman — and still verify the chain is consistent and the answer is real.

Privacy as an afterthought

On most chains, everything is public by default and privacy is a bolt-on feature you opt into, with its own gaps. Zcash is the exception that got the money right, and even there the privacy stops at the pool's edge: the moment coins leave for an exchange or another chain, they are public again. On Astrea there is exactly one kind of computation evidence, and it is zero-knowledge: proofs show the rules were followed while private inputs stay private, by construction rather than by option, with no public mode to fall back into and no edge to fall off.

Wallets you have to understand

Using a chain today means learning addresses, fees, bridges, and confirmations, and one mistake is final. We believe most people will never learn that, and will not have to. They will use an AI agent instead: a program you talk to in plain language, which holds your keys, knows the rules you gave it, and does the chain work for you. You tell it what you hold, what it may do with it, and what it must never do. It handles the addresses, the fees, the bridge, and the timing.

Astrea is built for that agent. The agent can only act inside the limits its owner set. Every action it takes leaves a receipt the owner can check afterward, so a mistake or a bad decision is visible rather than silent. And the markets it trades on see only what they need, never the owner behind it.

The agent itself is private too. Astrea's own AI is called AxiomAI, a desktop app for private chat and code that is live today. Every prompt is encrypted before it leaves your device and runs only inside verified hardware, a sealed part of the chip that even the company running the servers cannot look into, so nothing you type is stored or read by anyone else. AxiomAI is where you will create an agent, give it tools, and set its limits. Astrea is where that agent acts, and Zcash is the money it acts with. The agents page makes the case, and astrea.systems has the product.

ASK AND BELIEVE vs ASK AND VERIFY
the server that cannot lie to you
A server you must believe compared with an answer you can verify In the common model a wallet asks a server for its balance and has to believe the reply. On Astrea the reply carries a proof that the wallet checks against a certified root, so a wrong answer fails the check. MOST NETWORKS · ASK AND BELIEVE YOUR WALLET RPC SERVER "your balance is 42" YOUR ONLY OPTION believe it — or a chain of certificates if the server lies, nothing in the reply can tell you ASTREA · ASK AND VERIFY YOUR WALLET ANSWER + PROOF "42 — and here is the evidence" YOUR WALLET CHECKS proof vs certified root a lie cannot check out
The reply on top asks for belief. The reply below carries evidence: the wallet recomputes the proof against a certified root, so a wrong answer fails on the spot instead of being taken on faith.

The precise version: proof-backed point reads, versioned authenticated roots, and their exact boundaries live on the data page. Anchored checkpoints and how history stays checkable end to end live on the consensus page.

03 · privacy that holds

Zcash keeps money private at rest. Astrea keeps it private in motion.

The vault photo and the shipping photo

Zcash is a vault with an unfakeable photo of its own: every shielded spend comes with a proof that the rules were followed, and the coins, the sender, and the amount stay sealed. That is why we believe it is the closest thing to private digital gold. The vault has one weak spot, and it is the door. Coins that leave for an exchange, a bridge, or Ethereum are public again, and researchers have matched what went in with what came out just by comparing amounts and times. Astrea is the bridge that keeps the vault's promise: your coins arrive as an ordinary shielded transfer, Astrea proves the Zcash chain itself to credit them, they stay private inside as zero-knowledge receipts, and they go back into the vault the same way they came.

The coins are only half of it. Even a perfectly sealed transaction has a shape on the network: when it was sent, how big it was, and which machine sent it. Zcash hands that to ordinary gossip, the same broadcast Bitcoin uses, and timing alone has been enough to tell which node was receiving a shielded payment. You can run a Zcash wallet over Tor, and that hides your address, but Tor has no cover traffic and does not know what a transaction is, so it cannot hide when you acted or how big the transaction was, and the wallet's own server still learns which transactions are yours when it fetches them. Astrea sends the bridge's traffic through PRISM, a mixnet built into the protocol: onion envelopes so no relay learns both ends, cover traffic so silence and activity look alike, everything bucketed into standard sizes so no packet is a fingerprint, jittered timing so events stop lining up, and rotating routes so nobody keeps a long view. Dandelion# hides where a public transaction first entered the network. The same route carries your Zcash traffic and your Ethereum traffic. A VPN puts a tunnel between you and the internet: the site you visit sees the VPN's address, not yours, and your internet provider sees a tunnel, not the site. Astrea is a VPN for chains. Ethereum sees Astrea's address, not yours, and the network sees shaped traffic, not your transaction. The one difference favors you: a VPN company can read everything in its tunnel, and Astrea cannot, because what its validators check is a zero-knowledge proof rather than your balance.

Receipts: Kappos, Yousaf, Maller, and Meiklejohn, "An Empirical Analysis of Anonymity in Zcash" (USENIX Security 2018): in the Sprout era, to January 2018, boundary heuristics shrank the anonymity set by 69.1 percent and exact-value round trips linked 28.5 percent of deposited coins, while transactions that stayed inside the shield were 0.3 percent of the total and were not linked. Tramèr, Boneh, and Paterson, "Remote Side-Channel Attacks on Anonymous Transactions" (USENIX Security 2020): recipients of shielded transactions identified from node timing, fixed after disclosure. The full case is on the Zcash page; what PRISM reduces and what it does not is on the privacy page.

04 · the bridge

A vault is not an economy

A port city is not rich because of the gold in its vaults. It is rich because of its infrastructure: the harbor, the roads, the bonded warehouses, and the customs house that let goods from one economy move into another without being opened on the dock. That is what Astrea is. Zcash is the gold. Astrea is the infrastructure that moves private money around. You send shielded coins to the bridge, and on Zcash that looks like any other shielded transaction. The coins stay shielded: the bridge holds them in Zcash's shielded pool and never unshields them, and Astrea only keeps track of whose they are, with zero knowledge. Astrea does not take anyone's word that your coins arrived: it proves the Zcash chain itself, block by block, and credits you inside. From then on your ZEC is a private balance. Smart contracts can hold it and move it. When your AI agent wants to act on Ethereum, it goes through Astrea's own accounts, and Astrea proves Ethereum's state back in through the beacon chain the same way. When you leave, your coins come back to you as a shielded transfer.

Everything the market does not need stays private: who you are, your balance, your strategy, and who else you deal with. The market sees the bridge and the manifest, the fields you agreed to show, and nothing else. Three things make this different from the swap networks that move ZEC today. Nobody's signature stands in for the truth about the other chain, because Astrea proves it. The key that releases coins on Zcash is not held by a separate group of signers: it is split across Astrea's own validators, it is only used for a withdrawal that has already been proved, and it takes as many validators to sign as it takes to run the network, so there is nobody new to trust. And every proof, session, and signature on Astrea's side is post-quantum, so what is recorded today does not open later. Ethereum is first. Any chain whose state Astrea can prove in can follow.

The precise version, including the Zcash chain proof, the beacon-chain import, the private ledger, the custody policy, and what is still a design rather than a running network, is on the Zcash page.

05 · speed without waste

One execution, a million verifications

The energy story

Proof-of-stake fixed mining's energy bill and kept a quieter one: repetition. Ethereum coordinates more than a million validator slots, and every full node re-executes every transaction, forever — the same work, redone across the whole network, just to agree on what already happened. Astrea spends the work once. One machine executes and takes the photo; everyone else glances at the photo. Verification costs a small, bounded fraction of the original run, so adding verifiers adds security without adding the computation bill again.

And no built-in speed limit

There is a piece of math called a trace monoid that answers one question: when does the order of two operations not matter? Your coffee purchase and a stranger's rent payment touch none of the same state — any order gives the same world, so there is no reason to make one wait for the other. Astrea registers those independence rules inside the protocol itself and shards work along them automatically. Independent operations run side by side without a ceiling built into the design; only operations that genuinely conflict — two spends of the same coin — wait their turn. Throughput grows with independence, and real workloads are overwhelmingly independent. Follow that to its end and there is no transactions-per-second ceiling in the design at all — theoretically unlimited TPS, bounded only by how much genuinely conflicting work you feed it.

The precise version: semantic concurrency, hot keys, auto-sharding boundaries, and why more shards help only independent work are on the consensus page. No benchmark is being claimed here; the claim is about the design's shape.

06 · the database underneath

A real database, built on the web's oldest big-data trick

In 2004, Google published a paper describing MapReduce: split a huge job into independent pieces, process them all at once, combine the results. That one idea became Hadoop, then the entire big-data stack — it is the pattern the web's largest services have crunched their data with for twenty years. It is boring in the best possible way: ancient, hammered on, and known to work.

Blockchains never got any of it, because chains do not have databases. They have key-value buckets — put bytes in under a key, get bytes back — and anything smarter gets bolted on as a separate "indexer" you have to trust. Building a real database is hard enough that nobody did it inside a chain. Astrea did: structured records with fields and versions, registered indexes, and deterministic map-reduce summaries — count by status, sum by bucket — computed in parallel and returned with a receipt, so even the summary of a million records is an answer you verify rather than believe.

Source: Dean and Ghemawat, "MapReduce: Simplified Data Processing on Large Clusters" (OSDI 2004). The precise version — bounded reducers, canonical reduction order, and the evidence path that binds a summary to a certified snapshot — is on the data page.

07 · not a blockchain

There are no blocks left to chain

A blockchain is named after its data structure: bundle transactions into a block, chain each block to the one before it, and make every participant re-run the contents to check them. Astrea kept the goal and replaced every part of that sentence. There are no blocks, there is no single chain, and nobody re-runs anything.

What is actually inside is stranger. Validators pour operations into a DAG — a directed acyclic graph, a web of proposals growing in parallel instead of a single-file line. The protocol shards that web automatically along its trace monoid, the algebra from concurrency theory (the full name is a partially commutative monoid) that records exactly which operations are allowed to ignore each other's order. Independent work flows through separate shards at once; only genuine conflicts wait. The design puts no ceiling on it: feed it more independent work and throughput keeps climbing — in theory, unlimited transactions per second.

Nothing gets re-executed, because every operation arrives as a zero-knowledge proof. Those proofs then get folded — two proofs combine into one proof of the same small size, that one combines with the next, again and again — until a whole stretch of history is a single compact object, and the folded objects are sealed into epochs. If Astrea is a chain of anything, it is a chain of folded proofs. No part of that describes a blockchain.

The machinery underneath has never been deployed like this before. Proofs live on hypercubes — grids with no fixed number of dimensions, growing into as many as the computation needs, in effect an infinite-dimensional space — where checking an entire computation collapses into poking a few random points. Those hypercubes are then read as streaming multilinears: the proof machinery CHARK lays the grid out, and CHASM streams it as one continuous line that a verifier can check in small pieces without ever holding the whole object in memory. And beneath all of it sits a mathematical framework we built from scratch, because the published mathematics made these primitives too expensive to compute. That framework is ours, it is not public, and it is the reason the rest of this page works.

The parts have names. PixelVM is the engine that runs an operation once and proves it, against a typed contract pinned down by CHL, its claim layer. CHARK is the proof architecture that lays work out on the hypercubes; Granite is the field-native hashing designed for efficient work inside it; CHASM is the accumulator that streams the grid as one line. NeoFold composes neighboring proofs, and NeoFold/UM-QFNA squeezes the finished package small. Consensus is a hardened Mysticeti that accepts zkCHARK receipts and nothing else. State lives in versioned authenticated sparse trees, the structure behind every proof-backed read. Resonance is the post-quantum signature family with a typed batch-verification path. PRISM shapes the traffic; Dandelion# hides where a broadcast began. One machine wearing thirteen names — and every one of them is doing a job a blockchain never asked anyone to do.

Stack the rest of the system on top and there is nothing to compare it to. PRISM wraps the network in mix-style routing, so even the traffic patterns stop telling stories. The database underneath is the same breed of big-data machinery the largest services on earth trust their core data to: the storage architecture Facebook built and Instagram scaled, the log-structured family X runs on, and the map-reduce pattern the AI labs' data pipelines descend from, OpenAI's and Anthropic's included. Except here, every answer the database returns carries a proof. Every session and every signature is then sealed twice, once with classical cryptography and once with post-quantum cryptography, both mandatory, so breaking one lock buys an attacker nothing. Taken together: a system faster than anything running today, and, from a networking and forward-security standpoint, quite possibly harder to attack than anything that has ever been built. Traffic recorded off the wire today does not ripen into plaintext when quantum computers arrive. It stays noise.

Put the pieces in one sentence: an auto-sharded DAG, ordered by consensus, carrying zero-knowledge receipts, folded into epoch proofs, moving over mix-routed and double-locked networking, answering queries from a proof-carrying big-data store, running on mathematics nobody else has. Computer science does not have a shelf for that yet. We call it the proof manifold, and the system that operates it a verification operating system — the next generation of trustless, verifiable computing.

THE SHAPE OF THE MANIFOLD
conceptual · tesseract visualization
Sharded streams of operations enter the hypercube, the hypercube folds them down, and the folded proofs line up into epochs. This is the picture the words above describe: not blocks in a chain, proofs in a manifold.

The precise versions live on the consensus page (the DAG, epochs, and trace-monoid sharding) and the PixelVM page (the proof pipeline and folding). The construction names appear there at the same capability level as here; the framework underneath them is deliberately not described anywhere public.

08 · beyond the blockchain

From chains to chips

Anywhere a record must later stand up to a regulator, a court, an insurer, or an incident review, a proof beats a promise. A hospital proves who accessed a record and that it was authorized. A bank proves a settlement followed its rules. A lab proves the cold chain held. An AI provider proves which model served a request. A newsroom proves footage came from an attested camera.

And none of it has to happen on a public chain. Astrea is a verification operating system: the same manifold can run as a public network, or be installed into real-world systems — a hospital network, a bank, a factory, a government agency — as its own dedicated deployment. Because the proving math is simple and regular, it is designed to be embedded in hardware too, down to dedicated chips inside cameras, sensors, routers, and industrial controllers. It is not another blockchain: it is the world's first proof manifold, a new generation of verification-based computing, where anything a system does can carry proof that it did it.

09 · the scoreboard

Same questions, different machines

Everything above, asked as a checklist. The right column is the state of the art everywhere else; the numbers in it are public measurements of real systems.

AstreaEveryone else
who does the work? ✓ one machineEvery operation runs once and proves itself; everyone else checks the receipt. ✕ all of themEvery full node re-executes every transaction.Ethereum keeps more than 1,000,000 validator slots doing the same work
what do you trust for an answer? ✓ nothingAnswers check against a certified root, with provenance chained back to the first epoch. ✕ the serverThe answer is whatever the RPC endpoint says it is.
how fast can it go? ✓ no design ceilingAuto-sharded along trace-monoid independence; in theory, unlimited TPS. ✕ one global queueEvery operation waits in the same line.base layers run on the order of 7 TPS (Bitcoin) and 15 TPS (Ethereum)
is money private at rest? ✓ settled in ZECHoldings rest in Zcash's shielded pool, the vault we believe is the closest thing to private digital gold. △ Zcash yes, most chains noBitcoin and Ethereum publish every balance. Zcash encrypts the ledger and verifies proofs instead.
is money private in motion? ✓ the bridgeZEC arrives as a shielded transfer, is credited by a proof of the Zcash chain, stays private inside as zero-knowledge receipts, and returns to the shield the same way. ✕ the crossing leaksLeaving a shielded pool for an exchange, a swap network, or another chain is public.Sprout-era Zcash: boundary heuristics removed 69% of the anonymity set (USENIX Security 2018) · early Monero spends widely traced (PoPETs 2018)
what vouches for the other chain? ✓ a proofAstrea proves the Zcash chain and Ethereum's finalized beacon-chain checkpoints itself, and every validator checks the proof. ✕ a signer setSwap networks sign on the other chain's behalf with a threshold of MPC nodes or vault keys, and you trust that fewer than the threshold collude.NEAR chain signatures: an MPC network · vault networks: threshold-signed vaults
who holds the key on Zcash? ✓ the validatorsOne threshold key split across the validators by distributed key generation, used only for proved withdrawals, with the same threshold as consensus.Zcash's own FROST construction, ZIP 312 ✕ a separate signer setAn MPC network, a vault's node operators, or a fixed multisig that signs whatever it is instructed to.
can the network see you? ✓ shaped trafficPRISM mix routing, cover traffic, size buckets, jitter, and Dandelion# encrypted stems, built into the protocol, for Zcash traffic and Ethereum traffic alike. ✕ visiblePlain gossip on Bitcoin and Zcash. Tor hides the address but not the timing or the shape, and the light-wallet server still learns which transactions are yours. Readable Dandelion++ stems on Monero.shielded Zcash recipients identified from node timing (USENIX Security 2020, fixed after disclosure)
quantum computers? ✓ priced inPost-quantum proofs, and classical plus post-quantum locks on every session and signature, both mandatory, from the deposit proof inward.160-bit post-quantum target · absolute 128-bit floor ✕ exposedsecp256k1 and Ed25519 alone, including the swap networks' MPC signatures; traffic recorded today is decrypted later.
is the consensus provably right? ✓ machine-checkedA safety and liveness theorem for the consensus core, checked in Lean. ✕ arguedWhitepapers, audits, and tests standing in for proof.
is there a real database? ✓ yesDocuments, indexes, and map-reduce summaries, every answer carrying a proof. ✕ bucketsKey-value storage, plus an indexer you have to trust.

Public figures: Ethereum's active validator set exceeds one million slots; base-layer throughput figures are the commonly cited ones for Bitcoin and Ethereum; Zcash boundary linkage from Kappos, Yousaf, Maller, and Meiklejohn (USENIX Security 2018, Sprout-era data); the Zcash timing side channel from Tramèr, Boneh, and Paterson (USENIX Security 2020); Monero tracing from Möser et al. (PoPETs 2018); swap-network descriptions from NEAR's chain-signatures and intents documentation. The left column states design properties and targets, not benchmarks — the precise, conditional wording lives on the linked pages, and the bridge rows describe a design being built toward a testnet.

Scope

This page rounds off on purpose. Where it says "unforgeable," the exact statement is a conditional post-quantum security target; where it says "unlimited," the exact statement is a design without a built-in ceiling and with honest serialization for conflicting work. The linked pages carry the exact wording.