Skip to content
YSKAR

Whitepaper

YSKAR

A proof-of-work blockchain that anyone can mine and anyone can verify.

Version 1.0 · October 2026 · Network yskar-main-1

1. Summary

YSKAR is an independent blockchain secured by proof of work. Its coin is called YSR. At most 21 million YSR will ever exist; they are created exclusively as block rewards for miners, halving every 12,000 blocks. A new block is targeted every 10 minutes.

YSKAR was designed around two promises. First, mining for everyone: a phone in a Telegram Mini App, an Android app or a home PC can take part, alone or in a pool that never holds anyone’s money. Second, verifiable by anyone: every rule is fixed in open code, every block can be checked in an ordinary browser, and anyone can run a full node that verifies the chain from its first block. The genesis block carries the inscription that sums this up: proof, not promise.

This document describes the system as it is implemented, including its current limits.

2. Architecture

  • Full nodes store the chain, validate every block and transaction completely and exchange blocks over a peer-to-peer network. A node can also offer a mining interface and run a pool.
  • Miners request work from a node, search for a valid hash and submit results. They only need a payout address, never a private key.
  • Wallets create and keep keys on the user’s device and sign transactions there. The YSKAR app (Telegram Mini App and Android) is such a wallet.
  • The explorer displays the chain and independently re-verifies each block in the browser.
  • A database mirror of the chain serves the explorer and website for fast reads. It is a convenience only; the nodes are authoritative.

3. Blocks

A block consists of a 136-byte header and a list of transactions, the first of which is always the coinbase. All integers are little-endian.

OffsetFieldSizeMeaning
0version4Block version
4height4Position in the chain
8prev_hash32Hash of the previous block
40merkle_root32Commitment to all transactions
72state_root32Commitment to all account balances after this block
104timestamp8Seconds since 1970
112difficulty4Required work (encoding: section 5.4)
116tx_count4Number of transactions
120extranonce8Separates the search spaces of miners
128nonce8Varied by the miner

The size is deliberate: with SHA-256 padding, 136 bytes fill exactly three 64-byte blocks, and every field except the nonce lies in the first 128 bytes. A miner computes the state of the first two compression rounds once per job (the midstate) and then needs only two compressions per attempt.

Merkle tree. Leaves are sha256d(0x00 ‖ txid), inner nodes sha256d(0x01 ‖ left ‖ right). An odd node is passed up unchanged instead of being duplicated. The prefixes prevent an inner node from being presented as a leaf, and the absence of duplication avoids the ambiguity known from Bitcoin (CVE-2012-2459).

State root. Every header commits to the complete account state after the block. Two nodes with the same state root have computed exactly the same balances. A block whose state root does not match the node’s own computation is rejected.

Limits. At most 2,000 transactions per block, the coinbase included.

4. Transactions

YSKAR uses an account model: each address has a balance and a nonce, a counter of the transactions it has sent. There are two transaction types.

4.1 Transfer

A transfer contains the sender and receiver address, the amount, the fee, the sender’s next nonce, an optional expiry height (valid_until), an optional memo of up to 32 bytes, the sender’s public key and an Ed25519 signature. Without a memo, a transfer is 168 bytes long.

The signature covers all fields plus the chain ID, the SHA-256 hash of the network name. A transaction signed for the test network is therefore invalid on the main network and vice versa. The nonce must match exactly, so each transaction can be included only once and in order.

4.2 Coinbase

The first transaction of each block creates new YSR. Its total must be exactly the block reward plus the fees of all transactions in the block – not a unit more or less. Up to height 1,999 a coinbase has exactly one recipient. From height 2,000 (consensus version 2) it may have up to 64 recipients; this is what makes pool mining without custody possible (section 10). The coinbase may carry a short self-chosen name of the finder.

4.3 Fees

Up to height 3,999 every transfer costs a fixed minimum of 0.001 YSR. From height 4,000 (consensus version 3) the minimum is calculated per byte, as in Bitcoin: at least 1 unit (0.00000001 YSR) per byte. Nodes additionally require 10 units per byte before relaying a transaction; this is policy, not consensus, and can be adjusted without a fork. Amounts below 100 units (0.000001 YSR) are invalid from height 4,000, which prevents the state from being filled with dust. A waiting transaction can be replaced by one with the same nonce only if its fee is higher by at least the relay rate.

5. Proof of work and difficulty

5.1 The puzzle

The block hash is SHA-256(SHA-256(header)). A block is valid if its hash, read as a 256-bit number, does not exceed the target:

target = 2^240 / difficulty

One unit of difficulty therefore corresponds to 65,536 expected hashes on average. The network hashrate can be estimated as difficulty × 65,536 / block time.

5.2 Adjustment (LWMA)

The difficulty of each block is recalculated from the previous 45 blocks with a linearly weighted moving average: recent solve times count more than older ones. Single solve times are capped at six times the target, and the result may change by at most a factor of four per block. All arithmetic is done in integers; there is no floating point in consensus, so every node arrives at exactly the same value.

5.3 Emergency rule and timestamps

If no block appears for more than three times the target block time (30 minutes), the required difficulty decreases in proportion to the waiting time. This keeps the chain moving if hashrate suddenly disappears. A block must be within the range between this relaxed value and the regular value.

A timestamp must be later than the median of the previous 11 blocks and may be at most 120 seconds in the future. Without these rules, the difficulty could be manipulated through false times.

5.4 Difficulty without an upper limit

The header field for the difficulty is four bytes. Up to height 5,999 it is a plain unsigned integer, which ends at 4,294,967,295 – about 469 GH/s of network hashrate. From height 6,000 (consensus version 4) the same field is read differently:

top bit 0: difficulty = field (1 … 2^31 − 1) top bit 1: e = bits 23–30, m = bits 0–22 difficulty = (2^23 + m) · 2^e (2^31 … ≈ 2^240)

Below 2^31 the bytes are identical to the old format. Above it, the value is a floating-point number with 24 bits of precision. Every value has exactly one valid encoding; the adjustment rounds down to the nearest representable value. The upper bound lies just below 2^240, where the target reaches 1 – the limit of SHA-256 itself.

6. Choosing the chain

If two valid branches compete, nodes follow the one with the most accumulated work, not the longest one. Since the expected number of hashes is proportional to the difficulty, the work of a block is its difficulty, and the work of a chain is the sum. If two branches have exactly the same work, the one whose tip has the smaller hash wins – a rule every node can evaluate independently and identically.

7. Issuance

The reward starts at 875 YSR per block and halves every 12,000 blocks. It is computed with a bit shift, without rounding rules that could differ between implementations.

EpochBlocksRewardTotal after the epoch
10 – 11,999875 YSR10,500,000 YSR (50%)
212,000 – 23,999437.5 YSR15,750,000 YSR (75%)
324,000 – 35,999218.75 YSR18,375,000 YSR
436,000 – 47,999109.375 YSR19,687,500 YSR
548,000 – 59,99954.6875 YSR20,343,750 YSR
…………
37432,000 – 443,9990.00000001 YSR20,999,999.99832 YSR

From block 444,000 the reward is zero and miners are paid by fees alone. At the target block time an epoch lasts about 83 days; 99% of all YSR exist after roughly 1.6 years, the last unit after about 8.4 years. Because of rounding, the total stays slightly below 21 million.

No pre-allocation. There is no allocation in the code: every YSR comes from a coinbase whose amount the rules check exactly. The reward of the genesis block went to the all-zero address, for which no usable key exists.

8. Wallets and addresses

  • Recovery words: 12 words according to BIP39 produce a seed.
  • Keys: Ed25519 key pairs are derived with SLIP-0010 along the hardened path m/44'/9077'/account'/0'/index'.
  • Address: the first 20 bytes of SHA-256(public key), written in bech32m with the prefix ysr – for example ysr1…. The checksum catches typing errors.
  • On the device: the app stores the key encrypted with a user-chosen PIN locally. No server ever receives it. The PIN protects the device; the 12 words are the actual key and restore the wallet anywhere.

9. Mining

A miner opens a session at a node with its payout address and receives jobs: a complete block template with all fields except the nonce. Each session gets its own extranonce, which lies in the header, so two miners can never compute the same candidate.

The miner does not only report blocks but shares: hashes that meet an easier, personal target. The node adjusts this target so that each device finds about one share every 30 seconds. Shares show that the device is working and, in a pool, are the basis of the payout. The node recomputes every submitted hash itself and trusts no claim of the device.

Ways to mine today: the Telegram Mini App (computing in WebAssembly), the Android app (also in the background) and the PC miner for processors and NVIDIA graphics cards.

10. Pool mining without custody

A pool is not a separate service but a full node that splits its coinbase. Pool blocks pay all participants directly in the coinbase (consensus version 2). At no point does the operator hold anyone else’s money, and anyone can check the split in the explorer.

  • PPLNS: the last units of work are paid, across block boundaries. The window is twice the network difficulty, so hopping in shortly before an expected block brings no advantage.
  • Counted value: the share target that applied, not the value achieved by luck.
  • Limits: up to 63 miners per block plus the fee; work that does not fit is carried into the next block. The fee is at most 5%.
  • What still requires trust: the counting of shares. Shares are not in any block. The payout is verifiable; whether it was deserved is not. This applies to every pool, Bitcoin included.

11. Network

Nodes connect over TCP (default port 8646). On connecting they exchange the network name and the accumulated work of their chains, then fetch missing blocks. Every block arriving over the network is validated completely: header, proof of work, signatures, balances and state root. A peer supplies data, nothing more. Nodes that support it also exchange miner statistics, so that apps can show the miners of the whole network; these figures are reported, not proven.

12. Consensus changes

Rule changes are activated at a fixed height announced in advance. Blocks below that height remain valid byte for byte.

VersionActive fromChange
2Block 2,000Coinbase with up to 64 recipients (pool mining without custody)
3Block 4,000Fee per byte, dust limit
4Block 6,000Difficulty without an upper limit

13. Limits and outlook

We would rather name the weaknesses than hide them:

  • Few nodes. The network is young and runs on very few nodes and one large pool. Security grows with every independent node and pool.
  • Devices differ. SHA-256d runs far faster on graphics cards than on phones. Phones contribute; their share of rewards is correspondingly smaller. Existing SHA-256 ASICs cannot mine YSKAR because they are built for Bitcoin’s 80-byte header.
  • Confirmation time. With 10-minute blocks, a payment is secure only after confirmations. Instant payments via payment channels are being planned; there is no date yet.
  • Reported figures. Active miners and measured hashrate across nodes are reported by the nodes. The network hashrate derived from difficulty and block times is the provable figure.

Everything described here can be checked in the source code at github.com/dabitlex/YSKAR.