Privacy-preserving blockchain built for the real world.
RingCT transaction privacy · CLSAG v5 active · Dynamic base-fee burn · Permissionless BFT-PoS
⬇ Install Node · 🛡 Become Validator · 🌐 Explorer · 💬 Telegram Bot
LPoD is an Aperod protocol subsystem developed and owned by the web3 Aperod APRO team. It coordinates opt-in positions, validator-linked accrual, canonical accounting and confirmed Guardian-principal refunds. LPoD is disabled by default and this repository does not claim that a 1B APRO production activation is live. The validator stake lock remains governed separately by the validator protocol.
Detailed functionality guide: LPOD.md — protocol behavior, status, and source scope.
The original LPoD implementation was authored by the web3 Aperod APRO team. Its source code and tests are licensed under the repository's Apache License 2.0, including the dedicated files identified in the LPoD source map. The guide and other original LPoD documentation are licensed under CC BY 4.0. Attribution details are published in the official LPoD authorship section.
These licenses permit use under their terms without prior approval. They do not claim ownership of LPoD as an abstract idea, method, algorithm, or protocol concept, and do not restrict independently developed clean-room implementations. Attribution requirements apply only when exercising rights in the licensed code or documentation. Dependencies and third-party material remain under their own terms. LICENSE-LPOD records the compatibility migration from the former restrictive notice.
- 🌐 Website: aperod.com
- 🔍 Explorer: explorer.aperod.com
- 📊 Live Status: status.aperod.com
- 🔐 Security Log: explorer.aperod.com/security-reports
- ⚙️ Source Code: github.com/aperod-network/aperod-node
- 💬 Telegram Bot: t.me/sup_apro_bot
- Why Aperod
- Protocol Status
- Install a Full Node
- Become a Validator
- Validator Rules
- Tokenomics & Fee Burn
- LPoD functionality, authorship, and licensing
- 📈 Why APRO? The Deflationary Case
- Architecture
- Building from Source
- Requirements
- Security
- License
- Contributors
| Feature | Detail |
|---|---|
| Privacy | RingCT with 16-member rings, Pedersen commitments, Bulletproof range proofs, and stealth addresses. CLSAG v5 is active from coordinated block 1,769,500 |
| Stealth addresses | Every payment generates a one-time address; receiver identity is never revealed |
| Telegram wallet | Full wallet inside Telegram — create, send, receive, and stake APRO without any app download |
| Dynamic base-fee burn | 100% of the protocol base fee is burned; any priority tip remains validator compensation |
| Permissionless validators | Anyone holding ≥ 100,000 APRO can run a validator — no whitelist, no approval needed |
| Block rewards | 3 APRO/block from a pre-allocated 2B APRO pool; then 1 APRO/block tail emission; no halving |
| Game integration | Native protocol support for in-game asset transfers and micropayments |
| Source licensing | Go source and tests, including LPoD, are Apache 2.0; original LPoD documentation is CC BY 4.0; dependencies retain their own terms |
The current public source contains the complete RingCT + CLSAG v5 transaction path:
- compact linkable ring signatures over public-key/commitment pairs;
- 16-member rings and canonical key images for double-spend prevention;
- Pedersen commitments, balanced pseudo-outputs, and Bulletproof range proofs;
- a persistent canonical ring-member index with bounded in-memory caching;
- replay compatibility for historical v1–v4 transactions.
CLSAG is a separate transaction version controlled by ring_ct_clsag_activation_height.
The value 0 keeps v5 disabled. The live network activated v5 at coordinated block
1,769,500 after the validator, wallet, storage, and API rollout completed.
Transaction-layer privacy does not hide IP addresses, timing metadata, compromised wallets, exchange records, or other network/application-layer information.
curl -fsSL https://raw.githubusercontent.com/aperod-network/aperod-node/main/deploy/install-node.sh | sudo bashSupported platforms: Ubuntu 22.04 · Ubuntu 24.04 LTS · Debian 12 · x86_64 · ARM64
The node installs as a systemd service and connects to the Aperod network automatically.
systemctl status aperod-node # service status
journalctl -u aperod-node -f # live logs
curl -s http://localhost:8545/api/v1/status | jq . # chain tipThe installer sets up a watchdog timer (aperod-node-watchdog.timer) that probes the node API every 60 seconds and automatically restarts the node if it stops responding.
To change the interval without editing unit files or redeploying:
# 1. Open the watchdog config (created automatically by the installer)
sudo nano /etc/aperod/watchdog.env
# 2. Set the desired interval in seconds (minimum: 5)
WATCHDOG_INTERVAL_SECS=15 # faster detection for HA setups
# WATCHDOG_INTERVAL_SECS=60 # default — suitable for most nodes
# WATCHDOG_INTERVAL_SECS=120 # reduced noise for low-power validators
# 3. Apply the change (writes a systemd drop-in and restarts the timer)
sudo aperod-watchdog-set-intervalVerify the new interval is active:
systemctl list-timers aperod-node-watchdog.timerThe 60 s default is preserved for all existing deployments — only nodes that explicitly set WATCHDOG_INTERVAL_SECS in watchdog.env and run aperod-watchdog-set-interval will use a different value.
Aperod uses stake-weighted, permissionless validator selection.
The top 21 nodes by staked APRO form the active validator set — no operator approval, no whitelist.
Block rewards go directly to your Telegram wallet. You need an APRO address before installing the node.
- Open @sup_apro_bot
- Tap Create wallet
- Copy your APRO address (≈ 95 characters, starts with
apr…)
curl -fsSL https://raw.githubusercontent.com/aperod-network/aperod-node/main/deploy/install-validator.sh | sudo bashThe installer will:
- Prompt for your APRO reward address
- Generate a consensus key (signs blocks only — cannot move funds)
- Configure the node as a
systemdservice and start it
Non-interactive install (CI / cloud-init):
APEROD_REWARD_ADDRESS=<your-apro-address> \
curl -fsSL https://raw.githubusercontent.com/aperod-network/aperod-node/main/deploy/install-validator.sh | sudo bashAfter install, the script prints your registration command. Run it:
curl -s -X POST https://aperod.com/api/validators/apply \
-H 'Content-Type: application/json' \
-d '{
"pubKey": "<consensus-public-key>",
"alias": "my-validator",
"endpoint": "/ip4/<server-ip>/tcp/30303",
"address": "<apro-reward-address>"
}'Transfer ≥ 100,000 APRO to your wallet address via @sup_apro_bot. Your node enters the active set automatically at the next epoch (~100 blocks · ≈ 5 min).
- Block rewards accumulate in your Telegram wallet
- You receive a Telegram notification for every reward payment
- Check balance and staking status anytime in the bot
See VALIDATORS.md for the complete rule set and protocol specification.
Quick reference:
| Parameter | Value |
|---|---|
| Minimum stake | 100,000 APRO |
| Maximum active validators | 21 |
| Epoch length | 100 blocks (~5 min) |
| Churn limit per epoch | 3 new validators |
| Full unbonding period | 144,000 blocks (~5 days) |
| Liveness requirement | Sign ≥ 2/3 of blocks per epoch |
| Slashing — double-sign | 10 % of stake, permanent ban |
| Slashing — extended downtime | 5 % of stake |
| Reward destination | Validator's APRO wallet address |
Every protocol base fee is permanently burned. 100 %. Always.
Aperod starts with a fixed genesis allocation and uses a deflationary fee model:
Guardian Fund preparation is not active. The documented nominal allocations already total 10B APRO, and no allocation debit for the proposed 1B APRO protocol lock has been approved. Node startup therefore rejects every nonzero Guardian activation setting. The node API may report
canonical_detectedwhen it sees the canonical transaction, but that is not BFT finality and must not reduce circulating supply; finality wiring is still incomplete. This preparation does not assert that the actual production genesis is empty, nor that global UTXO supply has been proven.
consensus.lpod_migration_file is an opt-in coordinated consensus fork, not
an administrative mint switch. No production reconciliation witness or approved
activation is included in the repository. The legacy Guardian activation must
remain disabled.
Activation requires the complete historical coinbase commitment openings and a strictly greater-than-two-thirds quorum of the trusted genesis validator set attesting the genesis, activation height, unambiguous full-body root, issued total, validator reserve remaining, and reconciliation witness root. Historical transaction hashes alone do not commit unambiguously to legacy bodies. Auditors must independently approve those bodies and budget; a self-hashed witness is not an audit. Missing, pruned, altered, or unattested history fails closed. The attested validator budget must equal the existing durable pool balance: it is never reset or silently reduced.
Available funding is computed as 10B minus historical issuance, the attested remaining validator reserve, and an additional protected 1B development reservation. The once-only 1B LPoD debit/credit, checkpoint, block, validator draw, payout outputs, consumed position key images, and AVM writes commit in one batch. Historical validator rewards are not charged twice. The full development reservation is conservative; this fork grants no authority to spend it.
- Version 9 positions use the existing MLSAG-v4 direct ownership/opening proof with a linked source key image, plus a separate beneficiary spend-key proof. Signatures bind genesis, source/position, vault, beneficiary, action and nonce. Deposits consume real unvested UTXOs; web sessions never create principal.
- Positions accrue individually with persistent integer APR remainders, including vaults whose validator did not propose. Canonical timestamp deltas are capped at 15 seconds per block. Newly deposited principal earns from the following block; inactive validators stop new accrual but existing arrears remain due.
- Signed full withdrawals stop subsequent accrual. After the withdrawal is canonically confirmed, Guardian principal is refunded exactly once without the former 144,000-block Guardian wait. This does not shorten or bypass the separate validator stake lock. Paid, fully closed positions release the 4,096-live-position capacity; spent source key images still prevent reopening an old deposit.
- Version 10 pays the exact leader, Angels and mature-principal plan as real wallet-scannable outputs; recipients are aggregated and sorted. Output ephemeral scalars are deterministic and parent/checkpoint-bound, not secret; protocol beneficiaries and amounts are public. Ordinary CLSAG spending works. Version 8 commits the complete resulting position/accounting checkpoint.
- Nine-tier leader shares and APRs use canonical stake. Scarce funds are allocated in canonical vault order, proportionally within each vault; unpaid amounts remain position-specific arrears and are retried, never counted as paid. Subsequent self-stake growth above 100M uses the top tier, while new Guardian deposits cannot push a vault above 100M.
- The existing 3-APRO pool reward, last partial draw, and 1-APRO tail continue. Tail issuance is recorded separately; after exhaustion the conservation equation is the initial 10B plus explicitly recorded tail issuance.
- Restart reads hash-keyed committed positions and carries, not a default pool. Ancestor rollback restores native indices and reserve selection. Rewind first to the common parent, then commit alternate blocks normally. Rewinding earlier than the attested funding parent requires additional historical budget evidence and fails closed; it does not guess the old reserve.
GET /api/v1/lpod-pool reports active monetary state only when the exact current
canonical checkpoint hash has live finality evidence. Restart does not invent
finality from height alone. Native position capability is reported separately
from activation; pending/disabled balances remain null. Source attestations,
protocol review, coordinated node upgrades and deployment authorization are
still required before any production activation. Such activation is a
protocol/governance event; availability under Apache License 2.0 does not itself
activate LPoD on any chain.
Genesis supply: 10,000,000,000 APRO (10B)
Circulating (launch): 9,000,000,000 APRO (9B — 90% Public / IDO / Liquidity)
Dev Fund locked: 1,000,000,000 APRO (10%, 12-month cliff + 48-month linear vest)
Block time: 3 seconds
Block throughput: 28,800 blocks / day
Pool reward: 3 APRO per block from a pre-allocated 2B APRO pool
Pool-phase issuance: 0 APRO (existing genesis supply is redistributed)
Tail emission: 1 APRO per block after pool exhaustion (~63 years)
Halving: none
Transaction fee: dynamic EIP-1559 · base 200 nAPRO/byte · adjusts ±12.5%/block
P2P transfer ~2 KB ≈ 0.004 APRO
Game / NFT tx ~4 KB ≈ 0.008 APRO
Base-fee destination: 🔥 complete base fee — burned 100%
Priority tip: optional proposer compensation
Validators earn the pool reward and, after pool exhaustion, tail emission. Transaction fees never reach validator wallets. The burn is enforced at the consensus layer — not a governance parameter, not toggleable.
See BURN_POLICY.md for full tokenomics and deflationary mechanics.
"The EIP-1559 mechanism in Aperod works like an automatic buyback — for every type of transaction. A simple wallet transfer burns APRO. An NFT trade burns APRO. A DeFi swap burns APRO. A game action burns APRO. The more the network is used for anything, the fewer coins remain in circulation. By year 5, even modest everyday usage alone shrinks the supply by ~10%, creating organic scarcity that pushes APRO price up — without any manipulation."
Every on-chain transaction type permanently destroys the base fee:
| Transaction type | Approx. fee burned per tx |
|---|---|
| P2P transfer (~2 KB) | ~0.004 APRO |
| Token swap / DeFi (~3 KB) | ~0.006 APRO |
| NFT trade (~4 KB) | ~0.008 APRO |
| Game action (~4 KB) | ~0.008 APRO |
The burn is consensus-enforced — not a governance parameter, not toggleable.
Starting at launch: −9.87 % supply reduction by 2031 from ordinary network usage alone.
Starting price $0.001 · Supply 10 B APRO · 5-year horizon (2026–2031)
| Scenario | Driver | Price target | Change |
|---|---|---|---|
| A · Conservative — deflation only, demand stable | Supply shrinks 9.87 %; market cap stays at $10 M. Pure math, no extra demand needed. | $0.001 → $0.00111 | +10.9 % |
| B · Realistic Web3 — deflation + organic gaming demand | Real network usage (transfers, DeFi, NFTs) + 20–30 games. Supply −10 % meets demand ×10–15 (normal for any active L1). Market cap grows to $100 M. | $0.001 → $0.011 | +1,100 % |
| C · Maximum — Global GameFi hub, year 25 | 3–4 B tokens burned over 25 years. Aperod reaches top-tier L1 network status. Market cap $1–2 B. | $0.001 → $0.15 – $0.30 | +15,000 % – +30,000 % |
During the pool phase, an equally productive member of a 21-validator set earns a theoretical reward of ≈ 1,501,714 APRO / year, before missed slots. As deflation drives the price up, that fixed reward becomes worth exponentially more in USD:
| APRO price | Annual validator income (USD) |
|---|---|
| $0.001 (illustrative) | ≈ $50 / year |
| $0.0011 (illustrative) | ≈ $55 / year |
| $0.011 (illustrative) | ≈ $551 / year |
| $0.15 (illustrative) | ≈ $7,509 / year |
| $0.30 (illustrative) | ≈ $15,017 / year |
Run the node, earn APRO. Let deflation do the rest.
Stake requirement: ≥ 100,000 APRO · Reward destination: your Telegram wallet · No approval needed
aperod-node/
├── cmd/
│ ├── node/ — aperod-node binary (full node + RPC)
│ └── cli/ — aperod binary (wallet CLI + chain inspection)
├── consensus/ — BFT-PoS engine: stake-selected active set, rotating proposer, ≥2/3 finality
├── core/ — Block, Transaction, UTXO, Mempool, Chain, Merkle root
├── crypto/ — Ed25519, SHA3-256/512, RingCT, CLSAG, Pedersen commitments, Bulletproofs
├── p2p/ — Peer discovery, block/tx propagation, DNS bootnode resolution
├── store/ — LevelDB with typed key prefixes; archive + light pruning modes
├── wallet/ — HD wallet (BIP-39 + SLIP-0010 + Ed25519), stealth address builder
├── config/ — node.yaml schema, genesis configuration
└── deploy/ — install scripts, Dockerfile, monitoring stack
Cryptographic primitives:
| Primitive | Library / Standard |
|---|---|
| Elliptic curve | Ed25519 — filippo.io/edwards25519 |
| Hash function | SHA3-256 / SHA3-512 — golang.org/x/crypto |
| Ring signatures | CLSAG v5, ring size 16 (active since block 1,769,500); historical MLSAG formats remain replay-compatible |
| Commitments | Pedersen over Ed25519 |
| Range proofs | Bulletproofs (IPA variant) |
| HD key derivation | BIP-39 mnemonics + SLIP-0010 + Ed25519 |
| Address format | Base58Check — dual-key (spend key + view key) |
- Go 1.25+ — install
make,git
git clone https://github.com/aperod-network/aperod-node.git
cd aperod-node
make buildOutputs:
| Binary | Path | Description |
|---|---|---|
aperod-node |
build/aperod-node |
Full node process |
aperod |
build/aperod |
CLI wallet & chain inspector |
# Start a full node
./build/aperod-node --config config/testnet.yaml
# Generate a new wallet (mnemonic + addresses)
./build/aperod wallet create
# Check wallet balance
./build/aperod wallet balance <address>
# Generate a validator consensus key
./build/aperod validator keygen --out ./keys/validator.key
# Inspect a block
./build/aperod chain block <height>Use upgrade-node.sh — the canonical single command for safe upgrades.
sudo bash /opt/aperod/blockchain/deploy/upgrade-node.shupgrade-node.sh is the recommended upgrade path. Before restarting the service it
guarantees that the memory-protection systemd drop-ins are present and active:
| Drop-in | Value | Purpose |
|---|---|---|
timeout.conf |
TimeoutStopSec=900 |
Prevents SIGKILL mid-snapshot (Aug 2026 outage root cause) |
gomemlimit.conf |
GOMEMLIMIT=5 GiB |
Prevents OOM-kill and LevelDB corruption under memory pressure |
The script then delegates to update-node.sh, which stops the service, pulls the
latest source, rebuilds the binary, installs it to /usr/local/bin/aperod-node, restarts
the service, and waits for the API to respond. Telegram alerts are sent on build or
startup failure.
The script is idempotent — safe to re-run at any time.
Why not
make build+cpdirectly? Copying over a running binary fails withText file busy. Building to any path other than/usr/local/bin/aperod-nodeis silently ignored by the service. A manual sequence also risks forgetting to apply the memory-protection drop-ins that prevent OOM-kill and snapshot corruption.upgrade-node.shprevents all of these mistakes in a single command.
make test # full test suite with race detector
make test-cover # with HTML coverage report| Component | Minimum | Recommended |
|---|---|---|
| CPU | 2 cores | 4 cores |
| RAM | 4 GB | 8 GB |
| Disk | 50 GB SSD | 200 GB NVMe |
| Network | 10 Mbps | 100 Mbps |
| OS | Ubuntu 22.04 | Ubuntu 24.04 LTS |
| Open ports | 30303 / tcp + udp | — |
| RPC | 8545 / tcp (localhost only) | — |
The node ships a built-in Go pprof endpoint that lets you capture CPU flame graphs, heap snapshots, and goroutine dumps in seconds — no rebuild required.
In node.yaml (or the production overlay), set:
pprof:
enabled: true
listen_addr: "127.0.0.1:8546" # loopback only — never expose publiclyRestart the node. You will see:
{"level":"INFO","msg":"pprof endpoint started","addr":"127.0.0.1:8546","hint":"go tool pprof http://127.0.0.1:8546/debug/pprof/profile?seconds=30"}
# 30-second CPU flame graph
go tool pprof http://127.0.0.1:8546/debug/pprof/profile?seconds=30
# Heap snapshot
go tool pprof http://127.0.0.1:8546/debug/pprof/heap
# Goroutine dump (text, great for deadlock diagnosis)
curl -s "http://127.0.0.1:8546/debug/pprof/goroutine?debug=2"
# Allocs, mutex, block profiles
go tool pprof http://127.0.0.1:8546/debug/pprof/allocs
go tool pprof http://127.0.0.1:8546/debug/pprof/mutex
go tool pprof http://127.0.0.1:8546/debug/pprof/block# On your laptop — forward remote 8546 to local 8546
ssh -L 8546:127.0.0.1:8546 user@your-server
# Then locally
go tool pprof http://127.0.0.1:8546/debug/pprof/profile?seconds=30listen_addrmust be127.0.0.1:…(loopback). Never bind to0.0.0.0.- Disable (
enabled: false) when not actively diagnosing — pprof exposes internal runtime metrics. - The endpoint runs on a separate port (default 8546) and is completely isolated from the public API (port 8545).
- Consensus key ≠ wallet key — the key that signs blocks has no ability to move funds
- RPC (port 8545) binds to
127.0.0.1by default — never expose externally without a firewall - pprof (port 8546) disabled by default — enable only for active diagnosis, loopback only
- Consensus key stored with
chmod 600— readable only by theaperodsystem user - Double-sign protection — automatic on-chain slashing (10 % of stake, permanent ban from validator set)
- View key sharing — share your view key for read-only auditing without granting spending ability
To report a vulnerability, see SECURITY.md.
Copyright 2024 aperod-network
Source code and tests are licensed under the Apache License, Version 2.0; see LICENSE. This includes the original LPoD implementation authored by the web3 Aperod APRO team.
Original LPoD documentation, including LPOD.md, is licensed under Creative Commons Attribution 4.0 International; see LICENSE-DOCS.
Attribution and the superseded LPoD notice are explained in NOTICE and LICENSE-LPOD. Dependencies and third-party material remain under their own terms.
![]() aperod-network |
