Pay the person. The address stays underneath.
Verified phone aliases connect to wallet-signed payment profiles. Contact names remain local to the device, while SOS handles settlement underneath.

A post-quantum settlement network for SOS, stable assets and programmable applications. Transparent by default, private by choice, connected to Ethereum without trusted custodians.
ML-DSA-65 signatures. ML-KEM-1024 key exchange. NIST FIPS 203/204 standardized. Every signature, every key exchange, every proof—quantum-resistant from day one.
PQ-MWEB extension blocks with STARK proofs. Shield your balance when you want. Transparent by default, private by choice. Always your decision.
SOS secures the network and pays fees while bridged and application-issued assets retain independent identities, policies and supply accounting.
Deterministic execution with consensus-bound state, bounded resources and post-quantum authorization. Implemented in the mainnet candidate and activation-gated.
Trustless interoperability
The bidirectional SOS ↔ Ethereum bridge connects verifiable post-quantum value with Ethereum's liquidity and DeFi ecosystem, without introducing a custody multisig or bridge committee.
When SOS moves to Ethereum, wSOS is minted only after the bridge contract verifies proof of SOS finality and transaction inclusion.
When value returns, SOS validators verify finalized Ethereum state and the recorded wSOS burn before releasing the corresponding SOS.
This gives SOS a verifiable route into Ethereum markets, applications, and capital while keeping issuance and backing accountable on both sides of the bridge.
Relayers move proofs, not authority.
They cannot invent deposits, redirect funds, mint unbacked wSOS, or release SOS without valid cross-chain evidence.
SOS → Ethereum
Issue wSOS
Ethereum → SOS
Return to SOS
Live on the SOS public testnet and Ethereum Sepolia with real proofs. Test assets only. Mainnet activation follows independent audit, guarded TVL limits, and bridge-domain migration controls.


Verified phone aliases connect to wallet-signed payment profiles. Contact names remain local to the device, while SOS handles settlement underneath.
A coherent path from settlement to useful applications
SOS pays fees, secures consensus and preserves its own fixed monetary policy without becoming the accounting unit for every asset.
Transfer native and bridged value with explicit asset identity, fast BFT finality and optional private settlement.
Build bounded public or private application logic on deterministic, consensus-bound execution.
Reach people through products such as SOS Connect while addresses, keys and settlement remain self-custodial.
Multi-asset value, optional privacy, scoped disclosure, deterministic execution and a proof-verified capital route are most useful when designed together.
Shared private state and FHE remain a separate research line. They are not presented as part of the activation-gated VM.
Asset registry, relayers and scoped disclosure for payments that can be private to the public while remaining auditable by authorized parties.
Recurring payments, Agent Mandates and policy-bound execution without exposing every operational balance or instruction.
Convert the assets used by a treasury through bounded requests for quotation before introducing shared liquidity pools.
Sealed auctions, Forecast markets and RWA delivery-versus-payment using private intent with verifiable settlement.
Credit, receivables and parametric insurance with explicit counterparties, assets, conditions and settlement authority.
AMMs, pooled lending, options and higher-TVL products only after the narrower primitives and risk controls are proven.
Full-spec Mainnet V1 architecture
| Network and consensus | |
|---|---|
| Consensus | HotStuff BFT Proof-of-Stake |
| Protocol time | 5-second slots; skipped slots permitted |
| Finality | Deterministic >2/3 stake-weighted BFT commit |
| Reward epoch | 120,960 slots · exactly 7 days |
| Unbonding | 362,880 slots · exactly 21 days |
| Post-quantum cryptography | |
| Signatures | ML-DSA-65 · FIPS 204 · NIST Level 3 |
| Key exchange | ML-KEM-1024 · FIPS 203 · NIST Level 5 |
| Hashing | SHA3-256 + SHAKE-256 · FIPS 202 · globally domain-separated |
| Privacy | PQ-MWEB multi-asset shielded notes · opt-in |
| Proof architecture | |
| Proof system | Transparent hash-based STARKs · no trusted setup |
| FRI | Two-adic FRI commitments · Keccak-f[1600] Merkle |
| Native AIR | Plonky3 / BabyBear · bit-exact batched ML-DSA-65 verification |
| zkVM | RISC Zero rv32im · recursive receipts · journal-as-truth |
| Guest identity | Network-bound, ceremony-pinned ELF hashes and image IDs |
| Internal receipts | Bare hash-based STARK receipts only |
| Ethereum boundary | Groth16 / BN254 wrap only where Ethereum verification requires it |
| Execution, assets and interoperability | |
| Assets | Canonical network-bound AssetId registry + independent supply |
| Execution | Deterministic restricted-Wasm VM |
| Private apps | Atomic private intent + public handler + asset-aware settlement |
| State commitment | Versioned SHA3-256 app hash binding asset, privacy and VM roots |
| Disclosure | Full viewing keys + scoped, revocable, non-spend capabilities |
| Recovery | 24-word seed · deterministic scan, rescan and witness recovery |
| Bridge | Bidirectional proof-verified SOS ↔ Ethereum routes |
| Bridge safety | Per-route TVL caps · pause, rotation and drain · fail closed |
| Economics and implementation | |
| Fee asset | SOS · explicit paymaster sponsorship supported |
| Supply cap | 21,000,000 SOS |
| Mainnet distribution | Pending owner-approved source of truth and legal review |
| Emission | 210,000 SOS / year |
| Emission split | 70% stakers · 20% operators · 10% treasury |
| Fee burn | 30% of each fee |
| Language | Rust |
| Contract toolchain | Rust → deterministic restricted Wasm |
Target launch architecture for SOS Mainnet V1. These parameters describe the final network, not the current public testnet.
Live from the SOS network
78% of SOS is emitted to the people who secure and use the chain. The genesis allocation — sales, team and treasury — is disclosed and protocol-vested. Public node releases are signed, checksummed and independently verifiable while mainnet-candidate systems move through review, reproducibility and external-audit gates.
Progress measured by evidence and activation gates
Protocol engineering, product delivery and verifiable releases.

Shutaru
Lead Developer
“Rust maximalist. Sleeps in vim.”

MrYoda
Strategy & Tokenomics
“If the math checks out, ship it.”

Jehuty
Protocol Engineering
“Breaks consensus, then fixes it better.”

TateTuga
Security & Infra
“Reads NIST papers for fun. Paranoid by design.”

Majlerin
Devil's Advocate
“If it can break, he'll find out why.”

Ze Gato II
QA & Community
“Breaks things so you don't.”
to Q-Day — the projected arrival of a cryptographically-relevant quantum computer able to break RSA-2048 / ECDSA. Counting down to the earliest credible “first impact” estimate: Jan 2029 (Google's ~2029 target). The field's range runs later — to ~2035+ and beyond; see the forecasts and estimate band below.
SOS crossed Q-Day at genesis — post-quantum from block 0. The countdown is for everyone else.
If the time your data must stay secret (X) plus the time you need to migrate (Y) is greater than the time until Q-Day (Z), you are already exposed. “Harvest-now, decrypt-later” lets an adversary capture ECDSA-signed transactions today and break them after Q-Day. SOS sets Y = 0: it was post-quantum from block 0.
Sources: Global Risk Institute, NIST, NSA, Google Quantum AI, IBM, Microsoft, The White House. Forecasts are estimates, not predictions — informational only, not financial advice.
Full intelligence report →“We hope quantum attacks never come. But if they do,
everyone deserves post-quantum money.”