enderpearl.ai Guardian t-mining · Pearl Swap Mining on Pearl

Independent operator on Pearl

We mine on Pearl and run one of the three guardians of Pearl Swap.

Pearl Swap is the bridge between native PRL on Pearl and PRL on Hyperliquid. Our guardian checks every payment against its own Pearl node and its own reading of Hyperliquid before it signs. It cannot move anything alone, and neither can anyone else.

Operator
Enderpearl, independent. Not part of Pearl Research Labs or Pearl Swap.
Guardian
t-mining at guardian.enderpearl.ai
Threshold
2 of 3. Any two guardians can move the escrow.
Networks
Pearl Swap and our guardian run on Pearl testnet2 and Hyperliquid testnet. Test networks only, for now.
c[4,9] = 0 a[4,k] · b[k,9], summed over k C = A · B · A 12 × 8 · B 8 × 12 · entries −3 to 3 · seed 0x5EED (fixed until our guardian answers) · computed in your browser

Our guardian, live

GET guardian.enderpearl.ai/status · not read yet
Full status
Guardian Checking reading from your browser
Configuration — published 8a8615d2…
Pearl height — the height its own index has reached, Pearl testnet2
Uptime — since —

What we run

Two jobs, both on Pearl. We say who operates what, and we publish our keys.

Guardian · Pearl Swap

One of the three guardians of Pearl Swap

Every PRL token on Hyperliquid is matched one for one by native PRL in an escrow on Pearl. Three guardians hold the keys to it. Any two can move it. One cannot, and that includes ours.

Our id
t-mining
Address
guardian.enderpearl.ai
Host
Enderpearl A, with its own Pearl full node, pearld
Keys
Three, made on its own machine. Only the public halves leave it.
Our role in the 2 of 3
Mining · Pearl

Mining on Pearl, by useful work

Pearl's proof of work is matrix multiplication, the arithmetic of machine learning. Securing the chain and useful computation are the same act. We mine by doing that work.

C = A·B

We publish figures about our machines only when they are measured and public. There are none yet.

How Pearl's useful work works

How our guardian decides

enderpearl.ai/guardian

It believes nothing it is told. Before it signs a payment, it runs eight checks against its own Pearl node and its own reading of Hyperliquid. Four of them carry the idea.

  1. Checks 2, 4 and 5 of 8

    Believe nothing it is told

    It confirms the source on its own node, recomputes every amount from the agreed rules and rebuilds the transaction byte for byte.

  2. Check 3 of 8

    Destinations from cryptography only

    The account committed in the deposit script, or the sender's EIP-712 signature bound to that one transfer. Never a value supplied with the proposal.

  3. Check 8 of 8

    Intent before signature

    It writes down its intent to sign, and only then signs, so a crash cannot make it forget.

  4. Check 6 of 8

    One payout per source

    It checks its own history and never signs two payouts for one source that could both execute.

Any failure is a refusal with a reason, returned to the proposer and recorded. Refusals are normal: a guardian whose view lags refuses until it catches up.

All eight checks, in our words

Where things stand

dated facts only

Test networks only, for now. Nothing in the bridge runs on real networks yet, and the guardians refuse mainnet.

  1. A rehearsal, end to end

    Pearl Swap ran the guardian kit as three hosts on one machine, including a guardian switched off mid-run.

  2. Three operators, three machines

    Each operator set up its own server, its own Pearl node and its own keys.

  3. Our guardian on its own domain

    It answers at guardian.enderpearl.ai: public DNS, a valid Let's Encrypt certificate, and a TLS proxy in front of a guardian process that listens on localhost only.

  4. Configuration epoch 1 agreed

    One shared configuration for all three guardians. It adds the fee sweep and returns for small deposits, and removes the largest-payment and hourly caps. Earlier copies, f22e5e61… and f24767e2…, are superseded.

    Configuration fingerprint · epoch 1
    8a8615d24a920f6f3805c299318be5761beca9df218e4bb60a5f61d20bb67c06
  5. First payments, on test networks

    The first payments ran through the bridge on Pearl testnet2 and Hyperliquid testnet, using test PRL sent by the Pearl team.

  6. Next

    An outside audit, before real money

    An outside audit of the guardian software comes before any real funds. Until then, the bridge runs on test networks only.

The trust assumption

Two of three keys. One is ours.

Any two of the three guardians can move the escrow. So two colluding guardians could move it. That is the assumption, and we state it plainly.

3 keys, named in the escrow script and on the treasury2 needed

Any two can move it

Two signatures from three named keys move the escrow on Pearl and the treasury on Hyperliquid. Every Pearl node enforces the escrow script. Hyperliquid refuses any treasury action without two, including from the key that created the account.

One cannot

Not us, and not anyone else. Each chain enforces the rule itself. One guardian down costs only its turn. Two down pauses new payments without putting escrowed funds at risk.

So we disclose

The three guardians are run by different operators, on their own machines, with their own keys. We publish ours, and our guardian's record is public.

Check it yourself

You do not have to take our word for the parts that matter. Compare our published keys, and read our guardian's own record.