Secret³: Decentralized Confidential Computation on a Public Ledger

Status

This page is a public reading of Secret³ whitepaper Version B, draft v0.1.5, 30 August 2026, by Ian Spiegel. It is a draft. It is not community-ratified, and it is not a claim that mainnet already runs this design. The draft is at https://secret3.dev/whitepaper/ .

Why a control plane and a private machine

Public ledgers coordinate value and enforce rules without a single administrator. Their default transparency makes them a poor place for sensitive data, because replication means every full node sees every input. The workloads that most need protection — health, finance, identity, industrial process, and model inference — still tend to run in opaque centralized services.

The requirement carried forward from 2015 is joint storage and computation on data while keeping the data private, with a public chain as controller and audit log, and without a trusted third party for every sensitive use. General secure multi-party computation is still costly for rich application logic at network scale. Succinct zero-knowledge systems advanced integrity and compression more than general private mutable state. Trusted execution environments are the substrate live confidential-contract networks shipped on. Physical attacks on server trusted execution environments showed that attestation is not a complete answer to an adversary who controls the chassis.

What Secret³ is

Secret³, in this draft, is a decentralized platform for confidential computation coordinated by a public ledger. Sensitive application state does not appear in cleartext on the chain or on host disks in ordinary operation. Users authorize use of data under policy rather than by permanently copying plaintext to a counterparty. Inputs are encrypted to material that is only unwrapped inside admitted confidential virtual machines. Application state is stored as authenticated ciphertext.

The platform is public where coordination needs a shared truth: balances, validator sets, governance outcomes, host membership, and economic parameters. The public chain is the control plane. Private execution runs on admitted confidential virtual machines. That is one operational layer, not two. Confidential tokens, long-running services, agents, and storage are programs and disks on that layer. They share policy and token. They do not share a vault or a data key unless they are the same program.

Validators do not execute private logic. Revocation, key rotation, and policy updates can cut off future release even when historical ciphertext remains. That stops new unwrapping. Material already in an admitted machine’s memory remains until that machine is stopped.

Three planes

The public control plane is a Byzantine-fault-tolerant ledger. It orders transactions and holds staking, governance, balances, and the registries that bind hosts, measurements, and rentals. It records checkpoints and vaults when a confidential virtual machine locks value. Correctness of public accounting does not require public application secrets.

The confidential-virtual-machine plane runs private logic in measured machines. Intel TDX is the intended shape. The runtime is dstack, the Linux Foundation guest stack: a measured operating system, a virtual machine monitor, and a guest agent. A machine that would have been a confidential contract checkpoints to the control plane. Only admitted measurements on admitted machines receive the material needed to decrypt state. Outputs leave as ciphertext, as deliberately public results, or as vault motion on a checkpoint.

Key custody for confidential-virtual-machine disks and history uses wrapping keys released by a two-of-two committee. That committee is not the validator set, and it is not dstack’s built-in key service. Authorization queries on-chain bindings. Retail payment may occur off-ledger. Native-token demand for capacity is an operator-side burn.

What an ordinary observer sees

The ledger holds ordering, balances, governance, registries, checkpoint hashes, and vaults. An observer sees public transactions and parameters.

The confidential virtual machine holds decrypted application state during execution and a sealed history key in RAM. An observer sees ciphertext objects, access patterns, and client connections.

Pin hosts hold encrypted history and snapshots. An observer sees ciphertext, size, and order metadata, never the data key.

The key-management pair holds one share each of the wrapping root at rest. An observer sees release traffic, not a full root on one honest node.

Encrypted envelope

The invariant is the envelope, not a particular interpreter. A user encrypts inputs toward material that is only available inside an admitted confidential virtual machine. The machine decrypts, evaluates, and writes authenticated ciphertext back to a sealed log. History is that sealed log, held by listed pin hosts, not encrypted rows in the chain’s state tree. The ledger stores a hash of the head. Replacing a confidential-virtual-machine binary should not require rewriting historical ciphertext if the log format is stable.

Hosts that store encrypted objects still observe when data is written and fetched. Oblivious RAM is not assumed. Access-pattern leakage is part of the threat model.

The confidential virtual machine replaces the confidential contract

Someone who would have written a confidential smart contract builds a measured confidential virtual machine and checkpoints to the control plane. The chain admits the image and the machines, names the head of history, and holds a vault when the app locks coins. It does not run the app’s bytecode.

Today’s Secret Network validators execute CosmWasm inside SGX on the consensus path and share a network seed. Replicating that single trusted-execution-environment evaluation across validators is not multi-party computation: each replica still sees plaintext inside its own boundary. This draft takes private execution off that path. Validators run ordinary Cosmos software. They have no enclave requirement and hold no application keys.

Admission is measurement plus machine. For the money program, governance names the binary and the platforms allowed to boot it, from the quote’s hardware identity. For a tenant computer — a site, an app, or an agent — the owner of that program names the image. A random TDX machine on the internet cannot hydrate a listed money program.

Private money

sSCRT and other SNIP tokens move onto this primitive as a money confidential virtual machine: wrap-backed tokens, private transfers, authenticated views, and unwrap back to native. Adding a denomination is a registry row, not a new binary. Users lock coins into a public vault, then transfer and view against the machine. Native leaves the vault only on a checkpoint.

That is more private than today’s SNIP against anyone who only watches the chain. A SNIP-20 transfer is an on-chain execute: the sender’s address, the token contract, and the fact of interaction are public, even though amount and recipient are not. After wrap, a confidential-virtual-machine transfer is not a ledger transaction, so the address that moved wrapped coins does not appear. Wrap and unwrap stay public. The host can still see that a client connected.

This does the same job as a layer two in one respect: those transfers are not on the base chain, coins sit in a public vault, a designated writer sequences private history, and the ledger only learns what a checkpoint publishes. It is not a rollup. A rollup posts enough data that anyone can reconstruct or challenge, and it enforces correctness with proofs. Here the history is sealed, the chain stores a tip hash, and integrity is admitted hardware, not fraud proofs or validity proofs.

Who may write is a lease. If that machine dies, another measured instance hydrates the same log. Do not copy today’s CosmWasm contracts into the money machine. For sSCRT, users redeem on the old contract, then wrap into the new machine. Other CosmWasm apps have to be rewritten as confidential-virtual-machine apps, or they stop. If the writer cannot boot again, the coins stay in the vault. There is no governance payout list and no unwrap without a checkpoint.

What isolation does and does not do

Intel TDX is the intended shape. AMD SEV-SNP is contemplated as a later second family, not the current shape. Isolation encrypts workload memory against ordinary host software, identifies the code image by measurement, and binds a report to that measurement. That raises the cost of casual exfiltration by a remote attacker or a curious but non-physical host.

It does not defeat a physical adversary who owns an admitted machine. Interposers on memory buses have extracted attestation keys and produced quotes that verification accepted. Under that adversary, “release only to attested code” becomes “release to whoever controls a platform the network has already allowlisted.” That adversary can observe plaintext the machine is entitled to decrypt. Putting the same class of trusted execution environment on many boxes does not become multi-party computation.

Two-of-two custody of wrapping keys raises the cost of stealing that material at rest. It is not multi-party evaluation of guest logic, and it does not stop both honest custodians from accepting a forged but policy-valid release if attestation is forged on an allowlisted platform. A whole guest kernel, instead of a minimal enclave, improves performance and programmability and worsens remote surface. That trade is accepted for throughput.

Residual controls named in the draft: governance-curated measurement and machine sets, with the risk that a supermajority can publish a malicious image; reproducible builds; threshold custody starting at two-of-two, not the validator set; each custodian verifies this chain itself; fork protection by a light client inside the confidential virtual machine and each custodian, not the host’s RPC; and commercial and legal accountability for operators, including the right to refuse workloads.

The promise that matches the model is confidentiality against remote observers and ordinary host software under isolation assumptions, a higher cost to extract a shared wrapping root at rest, and public, auditable policy. It is not a promise that a motivated physical adversary with a whitelisted machine cannot win. Page, cache, and branch side channels remain an engineering obligation. If a confidential virtual machine dies, another admitted machine can hydrate the sealed log and continue from the ledger hash. That is a crash property. It is not a claim that a Byzantine trusted execution environment cannot steal during an open lease.

Confidential cloud, same primitive

Not every private workload is a token. Long-running services, agent runtimes, model serving, training jobs, private network gateways, and large artifacts use admitted confidential virtual machines and the same control plane. They do not share the money machine’s writer, vault, or data key.

Admitted hosts, not block producers, offer attested machines. Placement is mediated on-chain but not forced. The operator must accept before provision and before protocol fees accrue. No consensus rule can compel a host to run a particular tenant’s code. Each customer gets a key namespace that is random and rotatable. Allowlisting an image means that image may run as a workload, not that it may read every secret on the host. Cross-tenant isolation is separate virtual machines plus per-namespace keys. Physical compromise of the host remains.

Storage objects are encrypted before they leave the client or the renter’s machine. Providers store ciphertext. Redundancy uses erasure coding across admitted providers so repair does not need the data key. Possession challenges are content-blind. Retrieval stays among the admitted set rather than a global public distributed hash table. A small allowlist that colludes can still under-store.

There is no network seed in this design. A separate root is two-of-two between two entities, each on an isolated machine that holds a share. They are not validators, not money-program machines, and not pin hosts. Release is threshold public-key encryption: each custodian emits a partial re-encryption toward the requesting machine’s ephemeral key, and that machine combines. The root is not assembled on one online box. This is not a Shamir split that is later put back together. One member down means no new boots. Live machines that already have keys in memory continue. One member alone cannot complete a release. Both, if compromised or physically owned, own the root. Governance can change who holds shares, while the current custodians are live and cooperating, without changing the wrapping key. A lost share at two-of-two is a new wrapping key. Old wraps do not open unless a live machine rewrapped from memory first. Start is two-of-two. Governance may change those numbers. The pair cannot add itself.

Incentives

Public-chain security stays on staking and consensus rewards. That budget is not reopened here to fund cloud operations. Stake makes the checkpoint head as hard to reorganise as Secret Network. The vault does not mint. Native does not leave except on a checkpoint. A listed writer that holds the lease can still empty what is in the vault. Stake does not make that machine honest.

Private transfers inside a confidential virtual machine do not create a ledger fee and do not burn the native token. Wrap, unwrap settlement, and checkpoints pay ordinary public gas. Operators who provide confidential capacity prefund the native token and burn a governance-tunable fee per attested unit of compute. The fee starts near zero and can rise. One hundred percent of that fee is destroyed. Customers may pay retail gateways in ordinary currency, so consumer billing can stay off the token. Structural demand is on the supply side: operators obtain token to keep machines enrolled. The draft rejects skimming cloud revenue to stakers as real yield. Metering that drives the burn is signed inside the tenant environment’s measured base. Under the physical adversary above, that signature can still be forged.

Application classes

The classes are functional names, not product brands. Private money. Confidential applications — finance, credentials, and multiparty workflows — in the slot confidential contracts occupied, without bytecode on the consensus path. Measured application hosting. Attested ephemeral functions: short-lived jobs that boot a measured image, run once, and terminate. Confidential agents that hold tools, memory, and credentials inside an attested environment. Attested private networking, where peers authenticate by remote attestation as well as classical credentials. Confidential inference, with weights, prompts, and outputs released only into attested runtimes. Confidential training and fine-tuning over sealed datasets, where aggregates, gradients, or a model may leave and the raw corpora do not. Encrypted object stores with computable access. Selective disclosure and private credentials: predicates evaluated in isolation, and only the boolean or derived claim leaves.

These classes compose. Across separate machines that composition is asynchronous. Atomicity is inside one program.

Earlier work, and what this does to live Secret contracts

The draft accepts the 2015 Enigma requirement and uses a different primary substrate: hardware isolation plus an encrypted envelope, with secret-shared management of non-consensus wrapping keys. That is not a claim that multi-party computation is obsolete. Secret³ confidential virtual machines run on dstack. The ledger does not import dstack’s Ethereum policy contracts or its built-in key service. Stronger machinery can be added later under the same envelope, including zero-knowledge proofs of transitions or traces, selective multi-party evaluation, proofs of cloud placement, and hybrid schemes. None of those is required for this architecture to be coherent. What should stay stable is the public control plane, the encrypted state interface, and honest documentation of which adversary each layer addresses. Secret’s technical documentation is at https://docs.scrt.network/ .

Secret Network showed that private smart contracts can run on a blockchain: data stays encrypted, execution happens inside isolation, and only intended results leave. This design keeps that privacy model and moves the execution. Validators no longer run CosmWasm. The preferred chain identity stays. Compute is dropped in a staged upgrade after a money confidential virtual machine is live. There is a redeem window: users redeem old sSCRT, then wrap into the new computer. Dust remains. After execute is halted, leftover CosmWasm balances are gone. Encrypted contract state is not imported. The consensus seed is retired in ceremony and is not given to the key committee. A retained copy would still decrypt archived contract ciphertext. Secret³ on this path is still one blockchain and one token. Operators who sell capacity pay SCRT. Retail may stay fiat.