Alexandria
Real-world assets · Ricardian contracts
Each RWA token is bound to its off-chain legal document by cryptographic hash commitment, with compliance whitelists and jurisdiction tracking enforced on transfer.
Xeris is a Layer 1 built in Rust. Proof-of-History sets the order, Scrypt Proof-of-Work produces the block and stake-weighted election picks the leader, all pipelined into one four-second slot. Post-quantum signatures start at the first block.
Why it exists
Today’s Layer 1s fall into two camps. Neither meets our two requirements: native orchestration of autonomous AI agents, and regulated tokenization of real-world assets with enforceable legal bindings.
Camp one
High-throughput chains gain speed by narrowing the set of machines allowed to produce blocks, and the validator list ends up short.
Camp two
Proof-of-work chains have defended their ledgers for over a decade, and building a modern application on one means working around the chain.
Forging a block means defeating all three inside one slot.
The Xeris position
Xeris layers three consensus mechanisms. Proof-of-History fixes local ordering without an external clock. Scrypt Proof-of-Work keeps block production memory-hard and mineable on commodity hardware. Stake-weighted election decides who leads each slot. To forge a block, an attacker has to defeat all three in the same four-second slot.
Consensus architecture
Each stage constrains the next, and the whole sequence has to complete inside the slot window or the slot is forfeit.
Each hash input is the previous output plus nanosecond entropy from the validator’s monotonic clock. Slot boundaries come from the hash chain itself. No external clock or BFT round is needed to agree on the time.
The eligible set is every validator with at least 1,000 XRS staked, sorted by public key so every node derives the same order. A weighted draw seeded from the previous block’s hash picks the leader. Producing that hash took work, so the leader cannot be predicted before that block is mined.
Block production is a memory-hard Scrypt puzzle. If mining runs past the 3.9-second ceiling, the slot is forfeit. Non-leaders may mine the same slot at 4× difficulty: the chain stays live if a leader stalls, and they cannot outrun the elected leader.
The header commits to its transactions by Merkle root and carries two signatures: classical Ed25519 and post-quantum Dilithium3. Both must verify, so an adversary has no classical-only path to downgrade to.
Non-leader validators mine at 4× the difficulty target. Forward slot leaps are bounded by elapsed Proof-of-History time plus a two-slot skew tolerance, so a proposer cannot time-warp slot-gated logic such as unbonding.
Protocol datasheet
Each figure here is specified in the technical whitepaper. A block that violates any of them is rejected.
Native protocols
Contracts on Xeris are 23 typed, protocol-defined primitives. The runtime executes no arbitrary bytecode, which rules out reentrancy, unchecked delegatecall and storage collisions. The protocols below are instruction variants in the same runtime that moves tokens, under the same fee accounting and replay protection.
Real-world assets · Ricardian contracts
Each RWA token is bound to its off-chain legal document by cryptographic hash commitment, with compliance whitelists and jurisdiction tracking enforced on transfer.
Autonomous agents · Hierarchical delegation
AI agents are registered as protocol objects with a per-transaction spend limit, a daily cap, a contract whitelist and a kill switch. An agent can sub-delegate within those bounds and cannot widen them.
Cryptography · Groth16 · BN254
Prove a statement and settle without revealing the data behind it. Verification is bounded: proofs are capped at 512 bytes, verifications at 64 per block, and encodings must consume their input exactly.
Signatures · Ed25519 + Dilithium3
Hybrid block signing is mandatory from slot 1 and permanent. The on-chain key registry binds each proposer to its lattice key, and rotation requires a signature from the current post-quantum key.
Markets · AMM · bonding curves
Constant-product pools, a bonding-curve launchpad, limit and DCA orders and a staked oracle registry are all protocol primitives.
Upgrades · Slot-activated
Stake-weighted proposals tally on-chain over a minimum 24-hour voting window, and new consensus rules activate at a fixed slot number, with no hard fork or coordinated restart.
Independently verified
All 70 findings, XWC‑01 through XWC‑70, are remediated in the current revision, and each fix is cited inline in the whitepaper.
Patent pending·US #63/887,511
Verify on CertiK Skynet (opens in a new tab)The token
XRS pays fees, secures the network through staking and rewards the validators that produce blocks. The runtime caps supply: mining, staking and attestation rewards draw from one fixed budget.
Hard cap
700,000,000
Mining + staking + attestation · 71.4%
Genesis allocation · 28.6%
10 XRS per block, halving every 25,000,000 blocks (about every 3.17 years at four seconds a slot). The series sums to exactly the 500M budget.
7% annually, distributed every 900 blocks to anyone staking 100 XRS or more. Rewards are liquid and restaking is manual.
Signing two headers for one slot costs 10% of slashable balance. The reporter takes 5% of it as bounty. The remaining 95% burns.
XRS on Solana is the pre-mainnet token. At mainnet it swaps in at a fixed 5:1 for native XRS.
XRS on Solana—Native, implied—Live tracker
Solana contract
9ezFthWrDUpSSeMdpLW6SDD9TJigHdc4AuQ5QN5bpumpThe whitepaper specifies the consensus pipeline, instruction set, contract taxonomy, cryptographic stack and governance model, with the audit remediations cited in place.