Wormhole
Move TNZO and messages between Network 1 and Wormhole-connected chains, with Guardian-quorum verification and Native Token Transfers.
Wormhole connects Tenzro Network 1 to the chains in the Wormhole network, including Ethereum and its rollups and Solana. It is one of the protocols behind the bridge router. Two parts matter on Tenzro: Guardian-verified messages, and Native Token Transfers (NTT), which move TNZO as a native token rather than a wrapped copy.
Guardian verification
A Wormhole message is delivered as a VAA (verified action approval): the message body plus signatures from Wormhole's Guardians. Before Tenzro acts on a VAA, the node:
- Computes the canonical Wormhole signing digest of the body.
- Recovers each Guardian signature (secp256k1) and checks it against the configured Guardian set.
- Requires a quorum of distinct Guardians from that set.
- Checks the payload hash and the message nonce, and rejects any VAA it has already seen.
Verification is fail-closed: a VAA below quorum, signed by a key outside the set, or replayed is rejected before any state changes, and the record of seen VAAs survives restarts. Operators set the Guardian set their node trusts in its bridge configuration.
Outbound, messages leave Tenzro only from finalised blocks, backed by portable finality certificates.
Native Token Transfers
NTT lets a token exist natively on many chains. Instead of locking tokens in a vault and minting a wrapped version, an NttManager on each chain burns or debits on the source and mints or credits on the destination.
- Managers. Each chain's
NttManageris identified by its Wormhole chain id and manager address, and governs one token. - Transceivers. One or more transceivers carry the attestation of each transfer. A transfer mints only after the configured quorum of distinct transceivers has attested it, so a single attestation path failing or being compromised is not enough to mint.
- Rate limits. Each chain has inbound and outbound caps over a rolling window. A transfer over the cap is queued or refused, depending on how the sender asked.
For TNZO this means supply is conserved across chains: every mint elsewhere matches a burn or debit, and each change is also recorded in Tenzro's cross-network supply registry; see Bridges. The fixed supply of 1,000,000,000 TNZO holds however it is spread across networks.
List the chains NTT serves for Tenzro:
tenzro wormhole-ntt list-chains --rpc https://rpc.tenzro.xyzcurl -s https://rpc.tenzro.xyz -H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_wormholeNttListChains","params":[]}'Send a transfer
tenzro wormhole bridge \
--source-chain tenzro --dest-chain solana \
--asset TNZO --amount 5000000000000000000 \
--sender 0xYOUR_ADDRESS --recipient <SOLANA_ADDRESS> \
--rpc https://rpc.tenzro.xyzAmounts are in the smallest unit. The JSON-RPC method is tenzro_wormholeBridge, an owner method that must be signed by the paying account. To let the router consider Wormhole among other protocols, use tenzro bridge execute --protocol wormhole instead.
Chain ids and VAA ids
Wormhole numbers chains with its own ids. Resolve them rather than hard-coding:
tenzro wormhole chain-id --chain base --rpc https://rpc.tenzro.xyzA VAA is identified as chain/emitter/sequence. Parse one into its parts to look it up on the source chain:
tenzro wormhole parse-vaa --vaa-id <CHAIN_ID>/<EMITTER>/<SEQUENCE> --rpc https://rpc.tenzro.xyzFees in TNZO
You can pay Wormhole delivery in TNZO. Quote the destination-native fee in TNZO and the node covers destination gas from the Wormhole sponsorship pool:
tenzro bridge-fee quote --adapter wormhole --dest-chain solana:mainnet-beta --native-fee 5000 \
--rpc https://rpc.tenzro.xyzCross-chain intents
Wormhole is one of the proof routes for ERC-7683 orders: the proof that a filler delivered on the destination chain returns to Tenzro as a VAA and settles the order.
Methods
| Method | Access |
|---|---|
tenzro_wormholeChainId, tenzro_wormholeParseVaaId, tenzro_wormholeNttListChains | open |
tenzro_wormholeBridge | owner |