Payment states
Follow the value. Check each step.
A regional transfer is a sequence of independently verified events. Each state tells the recipient something different.
CONTENT REVIEWED / 4 OCTOBER 2026
01 / The owner authorizes a request
Native review checks mature unspent inputs, owners, destination, amount and exact conservation. Signing authorizes one command; a queue acknowledgment alone does not include it in a block. Pending owner reservations are distinct from a native included debit.
02 / The source includes and finalizes an export
An export consumes source inputs and records the exact destination and export identity. Before finality, the region’s disclosed fork risk applies. Destination credit requires the adopted source finality and complete authenticated ancestry. After finality, timeout does not unlock the debit.
03 / Contacts carry the evidence
Reachable neighbors durably store and forward admitted evidence. A signed identity, candidate route, observed contact and destination transport receipt are different observations. Couriers have no right to issue currency or authorize a ledger import.
Delivery depends on physical contact, capacity and progress. More nodes can add useful paths, but cannot remove propagation delay or guarantee eventual arrival.
04 / The destination imports exactly once
The destination verifies currency and regional authority, source finality, complete history, ownership, conservation and dependencies. It binds the source chain and export ID to a unique import. Duplicate delivery can return an existing result or refuse; it never creates another credit. Invalid or conflicting evidence stops the affected transition.
05 / The recipient reaches local maturity
The destination advances under its own adopted rules before an imported output becomes locally spendable. In the paper’s Earth reference profile, an import at height 15 reaches maturity at height 21: six successor blocks, excluding the import block. That reference is neither a universal regional rule nor a wall-clock settlement promise.
06 / Local spending or a new journey
A mature output can fund an owner-authorized local payment. Onward export also needs recognized local finality protecting the original imported provenance and the new debit. A return to the earlier region is another export and unique import; the first source debit remains spent.
A returned receipt confirms its stated historical observation. It neither makes all regions simultaneously current nor overrides the destination’s finality and reorganization rules.
Account for every amount once, including pending exports
On compatible selected histories, issued value I = U + E + T. U includes immature and quarantined unspent outputs; E includes live channel escrows and adopted fee reserves; T includes every source export debit present on the selected history, even before finality, until its unique destination credit. These buckets never overlap, and fees are assigned exactly once.
Only finalized debits with complete admitted ancestry can be imported. Replay atomically reverses an orphaned unfinalized debit and restores its inputs; ordinary reorganization cannot undo a finalized debit. Atomic import records permanent ExportID consumption together with the unique credit. A missing receipt, expiry or timeout never refunds a finalized source debit; cancellation is excluded from the baseline.
Value proofs form a finite causal DAG rooted in authenticated origin issuance. A geographical return has new debit and import identities; a self-supporting ring of proofs is invalid. Split, merge, change, local payments, fees and channel settlement all carry the union of input provenance.
Conflicts follow value through every descendant
An authenticated finality or governance conflict quarantines every dependent output, escrow, pending import and onward export, including already received local balances and descendants created by payment, split, merge, fees or channels. Mixing disputed and clean lineage taints the entire resulting output in the baseline.
Quarantined value remains an accounted liability but cannot fund new local spends, channel updates or closes that create available value, imports or exports. Unrelated proven lineage may progress under its own qualified local quorum. Resumption needs the pre-adopted recovery authority, authenticated compatible decision and complete replay; waiting or deleting the incident cannot clear it.
Continue exploring
