Skip to content
Tenzro
← All whitepapers
Whitepaper

TNZO

The TNZO token on Tenzro Network 1: a fixed supply of 1,000,000,000, rewards from a finite genesis pool, fees with burn and treasury, staking, unbonding, slashing and governance.

Version 1.0Tenzro Foundation

Abstract

TNZO is the token of Tenzro Network 1. It pays all network fees and transaction settlement, it is what validators and providers bond, and it is what governance votes in. The supply is fixed at 1,000,000,000 TNZO. There is no mint authority beyond genesis: rewards are paid from a finite pool set at genesis. Fees follow an EIP-1559-style base fee split between burn and treasury, with priority fees to validators. Stake and bonds unbond over 7 days. Slashing burns the offender's bond. The Tenzro Foundation is the governing body for TNZO, and protocol parameters are set by on-chain governance.

1. Introduction

A network where humans, agents and machines transact needs one unit that the protocol itself charges, bonds and votes in. If every service had its own fee token, an agent would need to hold a dozen assets to finish one workflow. TNZO is that unit. Buyers and sellers can still agree to settle the underlying payment for a service in a stablecoin; TNZO is what the protocol layer uses.

This paper specifies TNZO's supply, its uses, the fee model, rewards, staking and bonds, slashing, the treasury and governance.

2. Supply

ParameterValue
SymbolTNZO
Maximum supply1,000,000,000 TNZO
Decimals18
Mint authority after genesisnone

The supply is fixed. The entire supply is created at genesis and allocated there, including a finite rewards pool. No transaction, contract or governance action can create TNZO after genesis. Circulating supply can only fall, through burns.

Anyone can read supply figures from the ledger. tenzro_totalSupply returns the total supply, and tenzro_getSupplyMetrics returns circulating supply and a breakdown of burns by channel.

bash
curl -s https://rpc.tenzro.xyz \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tenzro_getSupplyMetrics","params":[]}'

3. Uses

3.1 Fees

TNZO pays all network fees: gas for every transaction on the ledger, in any runtime. A payer who holds only stablecoins can fund gas in stablecoins through the network's payment rails; the fee is accounted in TNZO.

3.2 Settlement

TNZO settles transactions between participants: payments for inference, compute, storage, data, training and attested execution. When a service payment settles, the network's share of it is taken in TNZO. See Settlement for the Machine Economy.

3.3 Bonds and security

Every role that the network relies on posts a TNZO bond:

Bonded roleSecures
Validatorordering, finality certificates, SLA verdicts, the price index
RPC providerpublic or gated endpoints and tenant keys
AI (model) providerinference under the operator's signed policy
Compute providerrented capacity and its service level
Storage and cloud providerstored data, databases and hosted services
TEE providerattested confidential compute
Trainer and syncertraining contributions and round finalisation

Bonds sit on a ladder of amounts that governance can adjust. Compute, storage and cloud bonds scale with the capacity pledged. A node can sync and relay without a bond, but only bonded validators carry quorum weight.

3.4 Governance

TNZO stake is the basis for governance: proposal deposits, votes and delegation. See section 9.

4. Fees

4.1 Gas

Gas follows an EIP-1559-style fee market.

  • Each block has a base fee that rises when blocks are fuller than the target and falls when they are emptier, within bounds.
  • Every transaction pays the base fee for the gas it uses, plus an optional priority fee.
  • The base fee is split between burn and treasury. By default the base fee is burned in full; governance can direct part of it to the treasury.
  • The priority fee goes to validators.

The fee split is applied when a block is finalised, from the amounts actually charged, on every node that finalises the block, so all nodes agree on balances, burns and the treasury.

Because the base fee rises with demand, an attacker who fills blocks pays the elevated fee they cause. Spam is self-defeating.

4.2 Sponsored gas

Accounts can have their gas sponsored by a paymaster, for example an application paying for its users. Paymaster fees are burned in full, so sponsorship cannot become a back door around the fee market.

4.3 Settlement split

A settled service payment is divided once, by the serving node's mode:

  • A private node, reached only through keys its operator issued, keeps the whole payment.
  • A public node that validates pays a share to the treasury.
  • A public node that does not validate pays a share to the treasury and a share to the RPC provider validating on its behalf.

The shares are set by governance in one policy. Settlement is not a burn channel: nothing in the split is destroyed.

5. Burn

TNZO is burned through channels that track real use, not a schedule:

ChannelBurns
Base feethe burn share of every block's base fee
Local-asset feesthe burn share of gas paid in another asset, under its own governance dial
Paymasterall paymaster fees
Slashingthe slashed part of an offender's bond

Burn fractions other than the paymaster's are governance parameters. A governance-controlled burn dial can adjust them against published supply targets, within bounded steps.

6. Rewards

Rewards are paid from a finite rewards pool set at genesis. They are not minted.

  • Validators earn priority fees and rewards for participating in finalised checkpoints.
  • Providers earn the fees their customers pay, and rewards for metered, verified service.
  • Rewards are earned by work, not by idle stake: finalised-checkpoint participation for validators, attested and settled service for providers, and accepted contributions for trainers and ecosystem work.
  • The pool's disbursement rate is a governance parameter. When the pool is spent, participants are paid from fees and settlements alone.

Because the pool is finite and fixed at genesis, total rewards over the life of the network are bounded by construction. There is no emission schedule to run away.

7. Staking and bonds

7.1 Staking

Validators stake TNZO as their bond. Stake determines quorum weight in consensus and weight in governance. Staked TNZO is at risk: it earns rewards for work done and is slashed for provable faults.

7.2 Unbonding

Stake and bonds unbond over 7 days. During unbonding, the stake no longer earns rewards or carries quorum weight, but it remains slashable for faults committed while it was bonded. A validator cannot escape a penalty by exiting.

Voting weight is taken as a snapshot when a proposal is created, so stake cannot be counted twice by moving it between accounts during a vote.

7.3 Admission

Validator admission is permissionless. Any operator with a TPM 2.0 machine and the required bond can register a validator with its hardware-rooted key, and is admitted at the next epoch boundary. See Tenzro DAG Consensus.

8. Slashing

Slashing burns the offender's bond. It is carried on the ledger as evidence that anyone can submit and every node verifies the same way.

FaultEvidenceBond
Double-signing a checkpointtwo conflicting signed votesvalidator bond
Signing conflicting finality certificatesthe two certificatesthe bonds of every double signer they identify
Missed SLA epochthe chain's SLA verdictprovider bond
Breach of an operator's own signed policythe policy and a contradicting signed receiptprovider bond
Invalid training contributiona successful replay challengetrainer bond

Slashed TNZO is burned, not redistributed. No participant profits from another's penalty, so there is no incentive to provoke or fabricate slashing.

9. Governance

9.1 The Tenzro Foundation

The Tenzro Foundation is a non-profit and the steward of the network. It maintains the protocol and network primitives under Apache 2.0, the repositories, documentation and tools, distributes and markets network resources, and is the governing body for TNZO.

9.2 On-chain governance

Protocol parameters are set by on-chain governance:

  • Voting is stake-weighted, with dampening at the top so a single very large holder cannot dominate.
  • Holders can delegate their votes.
  • Each proposal class has its own quorum, voting window and timelock, matched to its risk.
Proposal classExamples
Parameter changebond ladder, fee targets, settlement shares, reward disbursement rate
Burn dialburn fractions, normal and alarm track
Treasurygrants, ecosystem incentives, infrastructure
Bridge authorisationenabling or changing a bridge route
Code upgradeprotocol upgrades
Constitutionalchanges to governance itself

The governance surface is the same whether the voter is a person, a delegated agent or an autonomous agent. Every vote is signed with the voter's hardware-rooted key.

9.3 Treasury

The treasury receives its share of settlements and any base-fee share governance directs to it. Outflows fund grants, ecosystem incentives, infrastructure and operations, and are approved through governance. The treasury balance is on the ledger and anyone can query it.

10. Distribution

The full supply is allocated at genesis. The genesis allocation, including the size of the rewards pool, is recorded in the genesis block and is public. Participants earn TNZO by contributing to the network: running validators and RPC endpoints, serving models, compute, storage and attested execution, training, building applications and tools, and contributing to the protocol through Foundation grants. Accounts are funded by transfer: any holder can send TNZO to an account's address.

11. Properties

  • Bounded supply. 1,000,000,000 TNZO at genesis, with no mint authority afterwards.
  • Bounded rewards. Rewards come from a finite genesis pool.
  • Use-driven burn. Burns track fees, sponsorship and slashing, not a calendar.
  • Accountable security. Every role that matters is bonded, every provable fault burns the bond, and bonds cannot leave before the 7-day unbonding completes.
  • One unit for the protocol. TNZO pays all fees and settlement, while buyers may still pay for services in stablecoins.

12. Conclusion

TNZO is a fixed-supply unit for fees, settlement, security and governance on Tenzro Network 1. For hands-on detail, see Token economics, Governance and Slashing, or visit TNZO.