Protocol Parameters
Every parameter the protocol runs on, with its value, its unit, where it is fixed, and what it would take to change it.
A parameter with no stated unit and no stated owner is a number in marketing copy. This page gives each one its value, where it is fixed, and how it could change. Devnet values are labelled devnet.
Settlement and disputes
| Parameter | Value | Fixed where | How it changes |
| Challenge window | 432,000 slots, 48 hours at the 400 ms target | A single constant in the settlement core, read at chain initialization | Only by initializing a new chain. There is no setter, so the constant governs chains created after it and nothing already running |
| Air gap between proof and payout | 24 hours by the mainnet design; 3,600 s on the devnet portal | The portal's configuration at initialization | Portal configuration |
| Total exit | Window plus air gap, about three days | Derived | Quote this, never the window alone |
| Minimum response window per dispute move | 1,500 slots, 600 s at the target | Dispute core constant, enforced as a floor | Redeploy |
| Moves in a dispute | 2 × ceil(log2(steps)) + 1; 35 for a 131,072-step trace | Derived | Not a setting |
| Worst-case game duration | 5.8 hours at the floor, 35 hours at one-hour rounds | Derived | A dispute that cannot finish inside the window is refused at open |
| Proposer bond | 100,000 lamports, a devnet placeholder | Settlement configuration | Must be re-derived against value at risk before real deposits, with an automated review trigger as TVL grows |
| Largest disputable trace | 131,072 steps, the ceiling the proposer bond implies | Derived from the bond | Moves with the bond |
| Compute allowance for a witnessed step | 700,000 CU of a transaction's 1,400,000 | Dispute program | Redeploy |
The window and every dispute deadline are denominated in slots, not seconds. A halted chain produces no slots, so a move deadline freezes, an honest party cannot be timed out, and the window cannot run out while nobody could have challenged.
Devnet slots measure about 166 ms, not 400, so a 432,000-slot window runs about 20 hours of wall clock on devnet. Every duration quoted in hours in this paper is at the 400 ms target.
Sequencing
| Parameter | Value | Notes |
| Block cadence | 2 seconds, and only when there is work | An idle chain produces no blocks and costs nothing |
| Ordering rule | First-come, first-served by admission | Checkable against receipts and published batches |
| Forced-inclusion ceiling | 24 hours maximum delay | After it, derivation includes the transaction regardless of the operator |
| Blockhash validity window | 150 blocks of L2 history | The same replay guard wallets already understand |
| Sequencer minimum bond | 0.1 SOL on devnet | Mainnet value is a governance decision, sized to exceed what reordering inside one window could gain |
| Reporter's share of a slashed bond | 50 percent, remainder to the incinerator | Permissionless reporting, no allowlist |
| Unbonding delay | 604,800 seconds | Intended to exceed the challenge window, so a receipt from the last batch stays slashable while that batch is disputable |
Fees and rent
| Parameter | Value | Notes |
| User fee | 5,000 lamports, flat, in SOL | A placeholder for a composed fee, not a market price |
| Fee destination | Burned before a per-chain activation height, credited to the genesis sequencer after it | The current chain crossed at block 100 on 10 September 2026; each block reports which rule it used |
| Composed fee margin and floor | Zero, both | The absence of a published price rather than a price. Computed today, charged by nothing |
| Priority fees | Not honoured | An auction is planned |
| Settlement cost per block | 3,291,520 lamports sunk, plus a 100,000 bond returned | Rent is roughly 164x a block's fee revenue |
| Break-even fill | About 820 transactions per block at the flat fee | Below it the chain is subsidised |
| Measured data-availability floor | About 280 lamports per transaction on modelled sustained traffic | Sparse traffic compresses worse and costs more |
| Root retention before rent reclaim | 1,000 newer final roots and 6,480,000 slots, about thirty days | Built, not deployed. It is a proving deadline, so both bounds apply |
| Batch retention before rent reclaim | 3,240,000 slots, about fifteen days from seal | Built, not deployed. Longer than the window, shorter than root retention |
State and proofs
| Parameter | Value | Notes |
| State commitment | Sparse Merkle tree, depth 256, keyed by the hash of the public key | Accounts and withdrawal leaves in one tree |
| Proof size | A 256-bit bitmap plus non-empty siblings: 321 bytes, 8 siblings over a 256-account chain | Non-inclusion is provable, which insertion witnesses require |
| Hash calls | 257 per proof; 1,020 for a two-account witnessed step | |
| One-step verification, system transfer | 19,216 CU | Measured against the compiled program |
| One-step verification, SPL token transfer | 20,408 CU | Measured |
| Interpreter memory commitment | Page tree of 32-byte pages at depth 59, covering the full 64-bit address space | A proof is 59 hashes, about 9,000 CU |
| Interpreter instruction commitment | Merkle tree over the instruction stream: 16 hashes for a 65,536-instruction program | Binds index, instruction count and padding |
| Deposit record | 94 bytes | Domain tag, sequence, depositor, recipient, amount |
Chain identity
| Current chain (gamma) | Beta, stopped 12 September | Alpha, stopped | |
| Chain id | 7790 | 7789 | 7788 |
| Challenge window | 432,000 slots, 48 hours | 432,000 slots, 48 hours | Seven days, as created |
| State tree | Sparse, from block 0 | Sparse, from block 0 | Sorted-leaf |
| State commitment | Version 2: account data committed by its page-tree root, so a slice of an account can be proven without carrying the account | Version 1: account data hashed inline | Version 1 |
| Dispute authority | The dispute program's enforcer address, so verdicts enforce | The enforcer address | A plain key, so a verdict does not enforce |
Renumbering a chain produces a different chain: the genesis hash covers the Layer 1 program ids, so the identity and the deployment are bound together. A change to what the state commits is a new genesis for the same reason, which is why gamma exists: it was cut on 12 September 2026 from a node that records its commitment version in genesis, so a node built for another version refuses the chain by name instead of diverging at replay. Beta stopped the same day with all 158 of its blocks final and all four of its withdrawals paid; alpha's limitations were exactly why beta was created. Both are kept as history, not run.
The programs on Solana devnet
| Program | Address |
| Settlement | 7yH9bTF9s6d86pW6stgVdfxaSkxiCDNBQR1HvTk399YW |
| Data availability | DYyVbACxqDH77DSApL2dcwfZrGzNLujQi21bKehZC1Pr |
| Forced-inclusion inbox | 9pVAsoaCm9uU7jzGgPB3AqHuXs7LKWtqkZCCeZXwmkxq |
| Dispute game | BrHfePzDnV7oSTd4c4T7f7WDwz8H9zwxYe1nJ8e3rqeA |
| Bridge portal | 8hsKk9nDsXN7JMRH1tj5RYdXs12ohrvduGBkgwEwGqVM |
| Sequencer bond | 6KQdRji1ZKg3tGLUczeUyX9ywxnivXKbSSAM3hbzzY4L |
Which of these a token vote could ever change
Governable, because they are economic: fee margins and floors, the bridge fee, fast-exit fee caps, reward schedules, retention windows within a floor the code enforces, treasury spending, and admission to a staked sequencer set.
Not governable, because they are the security of the chain: the challenge window and its unit, the air gap and who may deny a root, the dispute authority, the one-step classes and their boundaries, the state commitment, and the supply rule. Those live in code and change by redeploy. A vote that could move them would make the token the security, which is what it must not be.