Security

Pre-production by design: validate the protocol before freezing compatibility.

WildRoot 1.0.0-dev is still a development/testing codebase. The project is intentionally free to reset development state and replace superseded pre-production formats until the first production protocol is frozen.

There has not yet been a WildRoot production release. Current chain IDs, network identity, genesis and development storage/wire details remain subject to the project's production-freeze process.
Cryptographic boundaries

Native signatures and proof of work use different primitives for different jobs.

Native accounts

ML-DSA-87

Native wrpq1 accounts use ML-DSA-87 signatures from FIPS 204 for the account-authentication layer.

PoW

512-bit WildRoot digest

Proof-of-work validation uses the WildRoot 512-bit consensus digest and full-width target comparison.

EVM

Ethereum-format compatibility

EVM accounts retain Ethereum-format transaction/address compatibility at the RPC boundary while WildRoot consensus governs admission and finality.

The site describes the primitives actually used; it does not label the entire blockchain “quantum-proof.” Security depends on the complete protocol, implementation and deployment—not one primitive in isolation.
Anti-abuse

Network work and memory are bounded before expensive paths are entered.

The P2P layer caps frame size, applies read/write/idle deadlines, limits connections, tracks per-peer message and byte budgets, separately budgets expensive synchronization requests, and bounds response pages, cursors, identifiers and relayed addresses.

Unsolicited synchronization bodies are rejected. Local DAG-capacity pressure is not automatically treated as remote peer misbehavior, avoiding false bans when the local queue is full.

Wire frame cap2 MiB
Checkpoint pagesBounded · single-flight
DAG pagesCursor-bounded
RPC exposureLoopback by default for sensitive services
Protocol mixingPre-production compatibility fingerprint fails closed on incompatible peers
Deterministic recovery

Fast paths are optional; correctness paths are not.

Immediate checkpoint durability

The reference sync path commits each accepted checkpoint crash-consistently before accepting the next one after live-node testing rejected a page-batched persistence experiment.

Reorg reconstruction

Forks, reorgs, application-frontier transitions and open-DAG recovery use full deterministic reconstruction rather than assuming the direct-tip fast path is safe.

Lagging application state

A node missing certified frontier data remains application-unsynchronized instead of fabricating state while still being able to validate the independent PoW checkpoint history.

Before production

Runtime tests are only one part of release readiness.

The development process separates automated runtime gates from the external assurance required before a public production release.

Independent security review

Consensus, networking, wallet/key handling, RPC boundaries and native/GPU code require external review before a production freeze.

Long-running multi-host soak

Real-node operation across multiple hosts must exercise synchronization, restarts, network failures, service limits and mining over extended runs.

Fuzzing & bug bounty

Protocol parsers, storage, transaction admission and integration surfaces need sustained adversarial testing beyond the deterministic harness.

Release provenance

Production artifacts require reviewed dependencies, SBOM/security checks and signing/notarization appropriate to each supported platform.