Recovery-verified engineering baseline: v0.4.0 has green recovery, CI, and security evidence, but rollout gates remain open. It is not approved for production or real funds. Follow the active rollout tracker; the verified recovery foundation is preserved in completed epic #4.
PNYX Coin

Democracy, Reimagined

Blockchain governance with a maintained Beta client and a sovereign decentralized Alpha direction

Built on Cosmos SDK • Powered by PNYX Token • Current React Beta • Future Installable Alpha

Core Innovations

📊

Systemic Consensing

Move beyond binary voting with a -5 to +5 scale. Capture the intensity of preferences and find true consensus, not just majority rule.

🛡️

Proof-of-Domain

Anti-whale validator mechanism ensures network control stays with active community members, not wealthy investors.

🔐

ZKP Anonymous Voting

Groth16 membership architecture with chain-, proposal-, rating-, and recipient-bound proofs plus persisted nullifier protection. GH-266 replays a fresh synthetic Go/WASM proof through the real keeper payout boundary with atomic payout and replay checks; production ceremony, submission, and external cryptographic review remain required.

💰

VoteToEarn

Incentivize participation through economic rewards. Quality content costs PNYX, voting earns PNYX.

📜

Smart Contracts

CosmWasm integration with custom bindings lets smart contracts query governance state and interact with domain treasuries.

🔄

Integrated DEX

Merged PR #18 adds bank-backed custody, LP ownership, authority, and canonical burns. Merged PR #19 adds exact genesis reconciliation plus every-block supply, escrow, reserve, and LP invariants.

🌐

Self-Organizing Domains

Communities organize into domains with custom governance rules, treasuries, and autonomous moderation.

🏦

Domain Treasury Bridge

Dual accounting connects x/bank user wallets with domain treasuries. Deposit, withdraw, and manage community funds on-chain.

🌍

IBC Cross-Chain

Transfer PNYX across any IBC-enabled Cosmos chain via ICS-20. Connect to Cosmos Hub, Osmosis, and beyond.

🛠️

Developer Tooling

Complete toolkit for building on TrueRepublic: 4 CosmWasm contract examples, shared bindings, and testing utilities with 26 Rust tests.

📱

Beta Client / Sovereign Alpha

The maintained React Beta provides wallet, governance, DEX, admin and explorer surfaces. GH-215 defines the installable Alpha; GH-236 evolves it into a native TRChain edge architecture. GH-241 adds only the unwired canonical V4-0 Go protocol and tests; no native client or edge runtime exists yet.

How It Works

1

Create Domain

Establish a governance space for your community with custom rules and treasury.

2

Invite Members

Admin verifies and invites legitimate members to join the domain.

3

Submit Proposals

Members post suggestions using PayToPut to ensure quality content.

4

Vote & Earn

Rate proposals from -5 to +5 and earn PNYX for participation.

Use Cases

🗳️ Proxy Parties

  • Direct democracy within political organizations
  • Transparent member will representation
  • Bottom-up policy decisions

🏢 DAOs & Communities

  • Corporate governance
  • Investment DAOs
  • Community decision-making

🎯 Organizations

  • NGO coordination
  • Social movements
  • Cooperative management
PNYX
21M
Max PNYX Supply
2,486
Recovery-Verified Tests
61%
Rollout Checklist
Green
CI & Security
v0.4.0
Recovery Baseline

Built With Modern Tech

Cosmos SDK v0.50 CometBFT CosmWasm IBC (ibc-go v8) Groth16 ZKP React 18 + TypeScript Vite 8.2 CosmJS 0.39 TailwindCSS 3.4 Go 1.26.6 Rust 2,486 recovery-verified tests

Road to Rollout

The recovered v0.4 foundation is ready for continued engineering, not for production. These are the remaining blocking workstreams before any public-network rollout.

Delivery order: complete the Basic TrueRepublic rollout foundation and its reviewable evidence first. V4-1 runtime wiring and GH-232 remain deferred parallel tracks; V4-0 stays unwired and earns no rollout credit.

61%

Full rollout checklist

36 of 59 tracked items complete. GH-297 freezes the versioned ZKP protocol; production proving, artifacts, ceremony and review remain open.

71%

Seven-phase work

36 of 51 phase tasks complete before the final go/no-go gates.

86%

Phase 6: Operations

6 of 7 tasks complete; production topology and private live evidence remain.

30%

Phase 7: Release & Launch

3 of 10 tracker tasks complete; seven remain. Release freeze and accountable go/no-go are separate required subchecks of one counted task.

Phase 1

Network & Recovery

  • Verified and merged: failure, restart, catch-up, partitions, delayed peers, state sync, backup/restore, export/import, and app-hash agreement
  • Verified and merged: compatible binary replacement and fail-before-open rollback
  • Verified and merged: validator-key custody, single-signer failover, authenticated rotation, permanent revocation, and deterministic network policy
  • Verified locally: GH-184 governed v0.4.1 halt, partial-write rollback, deterministic recovery, and exact-once restart
Phase 2

ZKP & Privacy

  • Compatible real Groth16 client prover
  • Frozen circuit, inputs, encodings, and artifacts
  • Reproducible ceremony and key provenance
  • Verified locally: GH-209 front-running-safe recipient binding and atomic treasury payout; direct-payout linkability and independent privacy review remain
  • Verified locally: GH-266 fresh synthetic Go/WASM proof replay through the strict keeper payout boundary, including one-time nullifier and fail-closed adversarial checks; no production or rollout credit
  • Independent cryptographic and privacy review
Phase 3

IBC & Protocol

  • Verified locally: GH-175/GH-178/GH-181 two-chain proof relay, PNYX escrow/voucher, ACK, timeout refund, replay safety, pending-ACK and channel recovery, plus compatible in-place test-binary restart recovery
  • Verified locally: GH-184 real x/upgrade application migration with two-thirds governance and four-validator recovery
  • External relayer/counterparty and IBC client-upgrade qualification
  • Verified locally: GH-187 replaces unsupported staking/distribution stubs with explicit fail-closed adapters
  • Verified locally: GH-187 freezes and regression-tests the exact supported Cosmos/IBC feature boundary
Phase 4

Canonical Client

  • Verified: legacy mobile and web clients retired under GH-102/GH-112; client-web is canonical
  • Verified: newest-first submitted-transaction history with pagination, typed failures, and real local-chain evidence (GH-131); incoming-only history remains separate
  • Verified locally: canonical native ICS-20 signing, strict channel/balance/timeout checks, wallet-scoped records, and source-chain ACK/timeout recovery without automatic resubmission (GH-190)
  • Verified locally: GH-193 BIP-39 import, encrypted-store migration, derived-address/RPC-chain binding, and lock/switch/delete/reload signer invalidation; production custody remains separate
  • Real audited ZKP flow
  • Verified: 20 lazy routes and deterministic bundle budgets (GH-128/GH-190)
  • Verified: pinned Chromium, Firefox, and WebKit accessibility, responsive-layout, delayed-loading, and third-party-request checks for safe unauthenticated surfaces (GH-132)
Phase 5

Quality & Security

  • Raise DEX, governance, and root critical coverage
  • Verified: canonical client-to-chain transaction delivery (GH-115)
  • Verified: property, fuzz, invariant, race, shared-state contention, exact transaction replay rejection, and deterministic same-home restart evidence (GH-145/GH-172)
  • Verified: versioned cross-system threat model with fail-closed repository contract (GH-169)
  • Review-ready: versioned scope, evidence index, and fail-closed findings lifecycle (GH-294); the independent review and resolution of every critical/high finding remain open
Phase 6

Operations

  • 6 of 7 complete: liveness/readiness, secret-safe structured JSON logs, private metrics, an immutable dashboard with eleven tested alerts plus recovery/testnet objectives and role ownership, a strict synthetic incident rehearsal, and bounded four-validator capacity evidence
  • Qualified: strict synthetic topology and abuse-control contract (GH-89)
  • Verified and merged: incident, halt, validator, key, backup, restore, upgrade, and rollback runbook contract (GH-93)
  • Verified and merged: 96-transaction sustained-load, disk/log/RSS, retention, restart, and ledger contract (GH-97)
  • Verified and merged: secret-free digest-bound deployment-evidence envelope and offline verifier (GH-101); live deployment remains open
  • Next: private production deployment and live operator evidence
  • Production sizing, multi-day soak, and private-environment capacity evidence remain exit work
Phase 7

Release & Staged Launch

  • 3 of 10 tracker tasks complete: seven counted Phase-7 tasks remain; the public 59-item denominator is unchanged
  • Repository foundation verified: pinned tools/platforms/container bases and strict unsigned offline evidence (GH-212)
  • Repository candidate evidence verified: native repeated OCI parity (GH-258) and exact-commit plus simulated-tag metadata aggregation with every promotion claim false (GH-261)
  • Hosted exact-pair verified: runs 33465480131 and 33466167289 matched both daemon and all four OCI identities on exact commit 3b0d1639bb40c7df6733dd13a86252e1c8c9efd3; bounded JSON only, with every promotion and long-term-hermetic claim false (GH-273)
  • Reproducible signed binaries and containers
  • Candidate compatibility documented: versioned release notes, breaking actions, and evidence-bound production-false status (GH-225)
  • Signed checksums, SBOM and authenticated provenance for published artifacts
  • Frozen chain ID, genesis, validators, and allocations
  • Private testnet, then public testnet or canary
  • Release freeze and explicit go/no-go approval

Rollout gate

No public-network rollout until every phase has linked evidence, the tagged release CI is green, no critical/high finding remains, disaster recovery is repeatable, the real ZKP flow is audited, operations are observable, and signed release artifacts are reproducible.

Development Roadmap

📜

v0.3.0 — Historical milestone

ZKP architecture, multi-asset DEX, IBC and CosmWasm surfaces; current approval is governed by the v0.4 recovery audit.

Not a production approval
🔄

v0.4.0 — Recovery foundation verified

Implemented React client surface with recovery evidence complete; production rollout, external review and real-network gates remain open.

Track rollout issue #29
🔄

v0.4.1 — Planned

Production-qualified ZKP path, wallet-custody review, and governed upgrade readiness

Next Up
📋

Sovereign Alpha — Architecture track

Future installable domain, discussion and governance app with a non-custodial PNYX wallet and no mandatory hosted website. GH-236 adds the V4 edge target while keeping TRChain as the sole settlement chain; GH-241 implements only its unwired V4-0 protocol foundation. V4-1 begins only after Basic-rollout stabilization or a later explicit documented decision.

🎯

Production — No committed date

External reviews, signed reproducible artifacts, staged networks and explicit go/no-go approval remain mandatory.

Community Open Source

TrueRepublic is a community-governed project without a central corporate owner. Maintained source code and maintained documentation are Apache-2.0. Copyright remains with each contributor; the collective attribution is TrueRepublic contributors.

Brand assets, artwork, historical PDFs, archived historical evidence, and third-party materials remain excluded unless a file-specific notice documents provenance and permission. This licensing foundation does not change rollout progress or production readiness.

Ready to Get Started?

Join the movement for true grassroots democracy