One-page

i took my files off the internet and started handing them to strangers.

sounds insane for about ten seconds, until you look at what happens to a file the second you upload it. i’d rather one person hold it for a day than a company hold it forever.

so that’s HDMEx. a payment, a photo, a video, a message, it goes to someone already making the trip and they carry it. no server sees it.

the courier is not trusted and never was. the design assumes they copy what they’re carrying on day one and sit on it for fifteen years waiting for the hardware to catch up.

so before the file leaves, it goes through an all-or-nothing transform, which scrambles it until every part depends on every other part. then 32 bytes come out and travel by a different route, sealed with a classical algorithm and a post-quantum one at the same time.

the courier carries the rest. the rest is not 99.99% of your file, it’s noise. miss 32 bytes and you don’t have most of it, you have nothing. which is the point: the person carrying your file can be anyone at all, including someone who badly wants to read it.

that’s the road. the house is the other half.

your vault holds a seed and a colour. the seed never moves. the colour does, and it moves with what you actually do in the app. your key for a period comes from the two of them together, so a key that leaks is a key to one stretch of your life, not a key to you. that’s why the mascot is a chameleon and not a padlock.

to be precise, since it’s the first thing anyone competent asks. chroma guard is mine, i designed it. what it is not is a new cipher. the primitives underneath are the standard published ones, and what i invented sits above them, in how keys live and change. that layer is the one i expect to get shot at, and it should be.

now the part i care most about, and people usually mis-hear it. it is not “work replaces stake”. voting power is the square root of your stake times the square root of your participation, so you need both, and neither one alone gets you anywhere. capital pushes, work decides.

participation isn’t a count of deliveries either. recent work weighs more than old work, credit is capped per pair of counterparties so you can’t farm it with a friend, and every delivery has to be counter-signed by the sender and the receiver. and to become a validator at all you have to have carried things. the bar is a number of completed courses and it rises as the network matures. you don’t buy your way in.

the phone part is what i’m most pleased with. a phone can’t be a BFT validator, it sleeps, it loses signal, the OS kills it. so phones don’t sign blocks. they nominate, permanently, from 4G, holding their own keys, earning and voting with no uptime requirement at all. a separate rotating committee does the signing, opt-in, and never gets slashed for being offline. no proof of work anywhere.

to be clear, the chain still needs machines. every BFT chain does and mine is no exception. what it doesn’t need is anywhere to put your files, and on a messaging network that’s where nearly all the hardware normally goes.

and the honest limit, because it matters. none of that produces finality. block agreement runs on cometbft, boring and proven. my layer decides eligibility, weight, rewards and governance, and if i got it wrong the worst case is an unfair reward, never a broken chain. that separation was the first decision i made and the one i’d defend hardest.

i’m building it slowly and on purpose. no investors, and no deadline anyone else set. nobody in the room who can ask me to soften the ethics for a funding round. the chain is mine, written in C++. the scanner, the API and the web app in svelte, all mine. first early adopters at the end of 2026 or the start of 2027, with a beta. that’s the only date i’m giving anyone.