Public statement · Guardian, Pearl Swap
Test networks only, for nowAttestation · guardian t-mining · configuration epoch 1
Guardian key attestation
Every item is numbered. Section 6 shows how to check each one without taking our word for it.
Statement
Enderpearl operates guardian t-mining, one of the three guardians of Pearl Swap. The three keys in section 1 are ours. We generated all three on our own machine. Their private halves have never left it. Only the public halves are published: here, and in the configuration all three guardians run.
Our Pearl signing key, 1.1, is one of the three keys named in the Pearl escrow. Our Hyperliquid address, 1.2, is one of the three signers on the Hyperliquid treasury. Any two of the three guardians can move the escrow, so two colluding guardians could. We cannot move anything alone. Neither can anyone else.
Section 1. Our public keys
Each guardian holds three keys. These are the public halves of ours.
Pearl signing key
Our share of the escrow on Pearl. It is one of the three keys the escrow script names.
c3679e6cd3ed26d5775fc136bdef2aad0eda6018c04765658efecd3b9e5ab70a
x-only public key, hex · 32 bytes · 64 characters
Hyperliquid signer address
Our share of the treasury on Hyperliquid, as one of its three authorised signers. We use this account for signing bridge payouts and nothing else. It is active: it has received the deposit Hyperliquid requires before an account can submit payouts.
0xc87e693808208c814b79a0ec024f314aa8d4f3fd
Hyperliquid address, hex, lower case · 20 bytes · 0x and 40 characters
Identity key
Signs our guardian’s messages to the other guardians, and the deposit addresses it vouches for. It is separate from the two keys that sign for funds.
302a300506032b65700321004e6033092f793d3f8943fd3c3d52f164cf3bad27d759d0741bfe6e3ec25c27d4
Ed25519 public key, DER SubjectPublicKeyInfo, hex · 44 bytes · 88 characters
The first 12 bytes, 302a300506032b6570032100, are the DER header that marks an Ed25519 key. The last 32 bytes are the raw public key.
Section 2. The configuration
One configuration, shared by all three guardians. Its fingerprint identifies it.
Configuration fingerprint
Current · epoch 18a8615d24a920f6f3805c299318be5761beca9df218e4bb60a5f61d20bb67c06
64 hex characters · read it in groups of eight · all 64 must match
It is computed from the whole configuration: the three guardians and their keys, the threshold, the treasury and the token, the networks and the fees. Change any of it, a fee included, and the fingerprint changes. A guardian rejects anything built under a different configuration, matched by this fingerprint. Each guardian reports the one it runs as configHash at /status.
Earlier copies
f22e5e61…Supersededf24767e2…Superseded
Do not use either.
- 2.2Epoch
- 1, agreed 23 September 2026.
- 2.3Threshold
- 2 of 3. Any two guardians can sign a payment. One cannot.
- 2.4Networks
- Pearl testnet2 and Hyperliquid testnet. The guardians refuse mainnet. Test networks only, for now.
- 2.5Pearl confirmations
- 2 before a deposit counts, a testnet setting.
Section 3. What the keys control
An escrow on Pearl, a treasury on Hyperliquid, and the token. Each chain enforces its own 2 of 3. No guardian’s software can relax either rule.
Pearl escrow
testnet2A P2TR output with an unspendable internal key. Its script needs 2 signatures from 3 named keys, and 1.1 is one of them. Every Pearl node enforces it.
tprl1pxzutjzl6dar32p8389gkhdylnq0659sv4r3xthpj8ytdst2jcuzq2mzte6
Taproot address, bech32m · prefix tprl · 64 characters
Hyperliquid treasury
testnetA native 2-of-3 multi-signature account naming the same three guardians, with 1.2 as one of its signers. It holds the PRL token supply. Hyperliquid refuses any action without two signatures, including from the key that created the account.
0xefb6f8c559bca7b546b3dbc83f652a3fa1239c0d
Hyperliquid address, hex, lower case · 20 bytes
PRL token on Hyperliquid
testnetPRL circulating on Hyperliquid is matched one for one by native PRL in escrow on Pearl. Each guardian checks this before it signs, and stops rather than sign a payment that would break it.
PRL:0x214b38dd02161ada14b926ab13bbd5e3
Token name and id, as the configuration writes it · id 16 bytes
Section 4. The guardian set
Epoch 1. Three guardians, run by different operators.
| Guardian | Answers at |
|---|---|
| 4.1mc-miningAnother operator | https://guardian.deepnacre.com |
| 4.2pearl-swapAnother operator | https://g1.pearlswap.ai |
| 4.3t-miningEnderpearl Ours | https://guardian.enderpearl.ai |
Listed in the configuration’s order. The escrow script takes the three Pearl keys in this order (6.4).
Each guardian runs on its operator’s own server, with its own Pearl node and its own three keys. Only the public halves of each guardian’s keys are published, in the configuration all three run. Ours are in section 1.
An id carries no privilege. Whose turn it is to lead a payment is a hash of the payment and the id, so the order is worked out afresh for every payment.
Section 5. What we will never ask you for
If anyone asks you for these in our name, it is not us.
-
5.1Private keys
Ours or yours. There is no procedure in which a private key is sent to anyone.
-
5.2Signatures out of band
We will not ask you to sign a message or a transaction by email, by chat, or because it is urgent. Our guardian acts only on what it has checked itself.
If anyone asks, do not act on it. Tell us at ops@enderpearl.ai. The rule runs both ways: we never send our private keys to anyone. If asked, the answer is no, and the other guardians are told.