Permissioned ledger
Canton Network ticker CC
Summary
Canton's docs describe two layers of consensus. In the first, which they call proof of stakeholder, only the validators hosting a transaction's stakeholders receive their encrypted parts of it, re-run the Daml logic and send an approval or rejection to a mediator. In the second, the Global Synchronizer's sequencers put all messages into one order using Byzantine fault tolerant consensus among Super Validators, each running a sequencer, a mediator and an ordering node. Ordering stays safe while fewer than one third of the ordering nodes are faulty. On MainNet the ordering nodes currently run CometBFT. The mediator then issues a commit or reject verdict that the sequencers deliver to every informed validator. The Canton Foundation's MainNet configuration, updated 2026-09-28, lists 13 approved Super Validator nodes, two each run by Digital Asset and Cumberland. 4561113202226
Design
- System
- Permissioned ledgerCanton Network runs Daml contracts on participant nodes (validators) that store only their own parties' data, coordinated by synchronizers; the shared one is the Global Synchronizer, run by Super Validators with Splice software, whose MainNet went live in June 2024 with Canton Coin (CC). Canton's docs call it a public layer 1, and anyone can request a validator, but MainNet validators need Canton Foundation approval, a Super Validator sponsor and an allowlisted IP address, and Super Validators are admitted by vote. The permissioned class follows who may run nodes and order transactions.
- Settlement family
- Its own design
- Scarce resource
- Reputation
- State model
- UTXO
- Finality
- Other
- Who makes blocks
- Any validator submits encrypted transaction views; only the Super Validators' ordering nodes agree on their order and group them into blocks among themselves. Super Validators are organisations added by a vote of existing ones; each Super Validator node has one vote, and an action needs about two thirds of them. Many more organisations have been approved as Super Validators through Canton Improvement Proposals than there are nodes; the Foundation's MainNet configuration records most of them as reward-weight beneficiaries hosted on one of the 13 nodes.
- Fork choice
- None in the chain-selection sense. The sequencers give one total order per synchronizer, and a transaction is final once the mediator's verdict is sequenced and delivered; Canton's transaction lifecycle page says there are no forks, reorganizations or rollbacks after that. Safety needs more than two thirds of the ordering nodes to be honest, and no stake is slashed if that fails.
Qualifications
- System class · Contested. Canton's docs call the network a public layer 1 blockchain, and its FAQ says anyone can request a validator, currently with sponsorship. Joining MainNet still needs Canton Foundation approval, a Super Validator sponsor and an allowlisted IP address, and Super Validators are admitted by vote, so this profile files it by who may run nodes and order transactions. Because the ledger has no shared chain of blocks, a reviewer could also file it as a non-block ledger.
- Settlement family · Partial. Recorded as other. Canton Network's own terms: Daml contracts executed by participant nodes (validators) running Digital Asset's Canton protocol, with messages ordered by synchronizers; the Global Synchronizer is the shared synchronizer, run by Super Validators with the open-source Splice applications that also implement Canton Coin.
- Finality · Partial. Recorded as other. Canton Network's own terms: a transaction commits when the mediator, after the required stakeholders' validators confirm, issues a verdict that the sequencers deliver in the synchronizer's total order; the docs state there are no forks, reorganizations or rollbacks after that. It relies on more than two thirds of the Super Validators' ordering nodes being honest, and no stake is slashed.
- Scarce resource · Partial. Super Validator nodes are added by a vote of existing Super Validators, and MainNet validators are approved by the Foundation's Tokenomics Committee, so membership rests on approval and reputation. Under CIP-0105 (approved March 2026) a Super Validator keeps its full reward weight only while it locks a set share of its earned Canton Coin, and under-locked weight can be removed; the locks affect reward weight only, governance votes stay one per node and no stake is slashed. The CIP describes Canton as relying primarily on reputation for this alignment and adds the locks as a visible commitment.
- State model · Partial. Canton Network's own terms: an active contract set of immutable Daml contracts that transactions create and archive, which its docs call UTXO-based. There is no single shared state: each validator holds only the contracts of the parties it hosts, and each Canton Coin holding is its own coin contract.
- Privacy scope · Partial. Sub-transaction privacy covers Daml contracts: each validator receives only the parts of a transaction its parties are entitled to see, and sequencers and mediators handle encrypted payloads while seeing metadata such as recipients and message sizes. Canton Coin is the exception: its balances and transfer history are visible to the Super Validators' shared party and served through their Scan services.
- Block metrics · Not applicable. Validators receive only the messages meant for their parties, so there is no public stream of blocks to measure. The ordering nodes group messages into blocks among themselves, but block time, size or fullness would not describe the ledger that users and validators see.
- Public node access · Not applicable. There is no public node endpoint. Applications use the Ledger API of a validator that hosts their parties. The Scan API that Super Validators run for Canton Coin and governance data restricts access by IP address, and the third-party indexers found need an account or payment.
- Ordering backend · Unknown. The Global Synchronizer's ordering currently runs CometBFT. A Canton-native BFT orderer (CantonBFT) replaced it on DevNet on 29 July 2026; on 8 September 2026 the Foundation's forum said adoption on TestNet and MainNet was delayed and would come at the next scheduled upgrade (MainNet on 9 to 10 October 2026) only if ready.
- Dedicated synchronizers · Partial. Organisations can run dedicated synchronizers, their own sequencer and mediator nodes, alongside the Global Synchronizer, and contracts can move between synchronizers a validator connects to. The docs describe them as added capacity inside the one network, not separate chains, so no scaling layer is listed here. They must stay connected to the Global Synchronizer, and the docs say their validators will soon have to burn Canton Coin.
- Super validator governance · Applies. Super Validators vote on Daml vote requests recorded on the ledger. An action passes with ceiling((n + f + 1) / 2) votes, where n is the number of Super Validators and f is floor((n - 1) / 3). Votes cover adding or removing Super Validators, reward weights, fee, traffic and issuance settings and featured-app rights; Canton Improvement Proposals are also ratified by these votes.
- Tps · Unknown. No sourced, classed throughput figure was found. The docs describe scaling by having each validator process only its own parties' transactions and by adding dedicated synchronizers, and give no transactions-per-second figure.
Tradeoffs
- Emphasizes
- Security and Scalability Contested
- Gives up
- Open participation and independent full verification. Super Validators are admitted by a vote of existing ones; a MainNet validator needs Tokenomics Committee approval, a Super Validator sponsor, an allowlisted egress IP and a one-time onboarding secret. No node follows the whole ledger: each validator sees only its own parties' contracts, and the Canton Coin record is served by Super Validators' Scan services, which also filter access by IP address.Canton's docs call the network public and decentralized, citing independent Super Validators, BFT ordering and Canton Foundation governance; others read Foundation approval of validators and 13 ordering nodes, two organisations running two each, as permissioned, so listing decentralization as the cost is contested. Security here means BFT ordering that stays safe while under a third of ordering nodes are faulty, plus stakeholder validation; no stake is slashed. Scalability means each validator processes only its own parties' transactions, and dedicated synchronizers add capacity.
- Full node at home
- Not applicable 12914151621There is no role for a node that follows the whole ledger: each validator stores and checks only the contracts of the parties it hosts, and Super Validators run the ordering, mediator and Scan services. Canton's reference sizing for a production validator with little activity is 2 CPUs and 8 GB of memory plus a database with 2 CPUs, 4 GB of memory and 10 GB of storage, but joining MainNet needs Tokenomics Committee approval, a Super Validator sponsor, an allowlisted egress IP and a one-time onboarding secret.
- Throughput claims
- No classified figure recorded
Scaling layers
No scaling layer recorded in this profile.
Capabilities
| Capability | How it is provided | Notes and sources |
|---|---|---|
| Account abstraction | Structured assessment pending | Not yet assessed for any chain. |
| Atomic swaps | Unknown | Not yet assessed under this row's current definition; the reviewed evidence is building blocks. Each Daml transaction commits all or nothing, and the token standard (CIP-0056) defines allocations: each party locks holdings to a named settlement until a deadline, a sender can withdraw before settlement, and a settlement app submits one transaction that executes every leg or none. Splice implements allocations for Canton Coin, but no cited source shows a settlement app running such swaps on MainNet or names its publisher. 712232835 |
| Authenticated data publication | Unknown | Not yet assessed under this row's current definition. Each Super Validator's Scan service serves the Canton Coin and governance data visible to the Super Validators' shared party and cross-checks it against other Super Validators' Scans, but no commitment recorded by the network that outside readers can check published data against was found in the reviewed docs. 31117 |
| Light clients | Unknown | No light client was found in the reviewed docs. Validators store only their own parties' contracts and rely on signed sequencer messages; a validator's Scan proxy reads from several Super Validators' Scan instances and compares the answers, which is a read quorum, not light verification of the ledger. The Canton Coin white paper says each Super Validator publishes all Canton Coin data for independent validation, but no tool that checks it without trusting Super Validators was found. 91125 |
| Native staking or delegation | Structured assessment pending | Not yet assessed for any chain. |
| On-chain governance | Structured assessment pending | Not yet assessed for any chain. |
| Parallel execution | Structured assessment pending | Not yet assessed for any chain. |
| Payment or state channels | Unknown | No payment or state channel layer was found in the reviewed docs; absence was not exhaustively verified. |
| Programmable spending | Native (protocol or core-team software) Earlier definition | Daml contracts state which parties must authorize each action (signatories and controllers) and who may see it, and stakeholders' validators check those authorizations before a transaction commits. External parties can register up to 20 signing keys with a threshold in the network's topology state. Contract packages must be uploaded and vetted on the validators hosting their stakeholders. 6781027 |
| Protocol-verified messaging | Structured assessment pending | Not yet assessed for any chain. |
| Reversible transfers or recovery | Core-team softwareLimited scope | Part (a) only, through the token standard's default two-step transfer, which Splice (code published by Digital Asset) implements for Canton Coin: the sender's funds are held in a transfer instruction with a deadline, and the sender can withdraw it and get them back until the receiver accepts. Receivers with a transfer pre-approval get one-step transfers, which cannot be withdrawn. Part (b) was not verified: external parties can register several signing keys with a threshold, a plain multi-key setup, and no recovery path without the lost key was found. 101219233538 |
| Rollups | Unknown | No rollup that settles to Canton was found in the reviewed docs; dedicated synchronizers are extra ordering capacity inside the network, not rollups. Absence was not exhaustively verified. 18 |
| Shielded transfers | Structured assessment pending | Not yet assessed for any chain. |
| Signed partial offers | Unknown | Not yet assessed under this row's current definition. The nearest documented mechanism, token-standard allocations, locks each party's holdings to one named settlement and settlement app before execution, so it is not an open offer that any taker can complete. 23 |
Reading these values
- How this feature is provided
- Built into the protocol, core-team software or independent software says where a feature lives and who can change it. These are implementation layers, not quality: core-team software is not closer to the protocol than independent software.
- Structured assessment pending
- The shared review has not assessed this feature for any chain yet (Account abstraction, Native staking or delegation, On-chain governance, Parallel execution, Protocol-verified messaging and Shielded transfers). That does not mean it is absent, and a chain’s profile may already describe it.
- Unknown
- The review has not established this for this chain under the current definition; the note beside it says why. Unknown is not absent and not a low score. A feature reads “Not present” only when a source shows it is absent.
- Earlier definition
- Payment or state channels, Programmable spending and Rollups keep the earlier definition until the next fact-check. There, “Native” does not separate the protocol from core-team software, “Ecosystem software” does not say who publishes it, and “Partial” does not say which layer.
- Reading across rows
- The list of capabilities is incomplete. Do not read these rows as a chain leading or lagging overall.
Ecosystem & custody
| Product type | Status | Notes and sources |
|---|---|---|
| Automated market makers | Unknown | No automated market maker on MainNet was verified in reviewed primary sources. Trading venues listed by third-party directories were not reviewed. |
| Issuer-native stablecoins | ThinUSDCx (backed by USDC in Circle xReserve) | Neither Circle's USDC address list nor Tether's supported-protocol list includes Canton. USDCx is a token-standard asset minted on Canton after USDC is deposited into Circle's xReserve contract on Ethereum and Circle's xReserve service issues an attestation; Circle describes it as created by a decentralized protocol on Canton, and the operator of its Canton registry was not verified. Supply and use were not measured. 29303132 |
| Algorithmic stablecoins | Unknown | Algorithmic or hybrid stablecoins on Canton were not reviewed. |
| Bridges | Established in the ecosystemCircle xReserve (USDC to USDCx), LayerZero | Circle's xReserve moves USDC value between Ethereum and Canton as USDCx, live since December 2025. LayerZero announced its Canton integration, in the future tense, on 26 March 2026 for routing tokenized assets to other chains, and LayerZero's deployment metadata lists a Canton MainNet endpoint as active. Which assets use it was not verified. Other bridges were not reviewed. Risk: USDCx minting and redemption depend on Circle's xReserve contract and attestation service, and the Canton registry operator was not verified. For LayerZero, each application chooses the verifiers that attest its messages; LayerZero's metadata lists LayerZero Labs and Nethermind as verifiers available on Canton, but the configuration of any Canton asset was not reviewed, so what its users must trust is unknown. A bridged asset is only as sound as the bridge that minted it. 29303334 |
| Block explorers | First-partyScan (run by each Super Validator), CC View, CC Space (ITRocket) | Every Super Validator runs a Scan app and web UI from the Splice software that indexes Canton Coin transfers, rewards and governance; the validator onboarding guide says the Scan web UI is not yet fully public and needs an allowlisted IP or a Super Validator's VPN. CC View and CC Space are third-party explorers open on the web, each with a paid or key-gated API. None of them shows contracts private to other parties. 11153637 |
| Hardware wallets | Established in the ecosystemLedger | See custody rows: Ledger announced Canton Coin support in its Ledger Wallet app in August 2026, and Trezor's Canton page says Trezor does not currently support Canton. 383940 |
Hardware-wallet custody
| Device maker | Status | What users can and cannot do |
|---|---|---|
| Ledger | Native supportSame as native: Unknown | Can: Create a Canton account and send and receive Canton Coin in Ledger Wallet on desktop and mobile, per Ledger's announcement of 19 August 2026 Can: Review Canton transactions on the device screen before signing, which Ledger calls clear signing Cannot: Receive Canton Coin without acting: Ledger says Canton transfers work as requests, and an incoming transfer must be confirmed and signed before it reaches the accountLedger's published currency list (@ledgerhq/cryptoassets 13.56.0) includes Canton Network with ticker CC and a device app named Canton. The reviewed page does not name the supported device models. Ledger is also a Super Validator weight holder under CIP-0069 in the Foundation's MainNet configuration. 3839 |
| Trezor | None foundSame as native: No | Cannot: Use Canton or Canton Coin with a Trezor device; Trezor's Canton page says Trezor does not currently support CantonTrezor's page names no third-party wallet for Canton. 40 |
Public data
iKnow Blockchain has no public-data lookups for Canton Network yet. This is a limit of the service, not a statement about the network.
| Lookup | Status | What it covers and its limits |
|---|---|---|
| Address or account | Not available yet | Public-data lookups for this chain are not built yet. |
| Tokens and assets | Not available yet | Public-data lookups for this chain are not built yet. |
| NFTs | Not available yet | Public-data lookups for this chain are not built yet. |
| Transactions | Not available yet | Public-data lookups for this chain are not built yet. |
Sourced developments
Developments: Reviewed Sep 29, 2026 Next review due Oct 9, 2026, 12:00 UTC.
Publication date · newest first
-
CantonBFT ordering runs on DevNet; TestNet and MainNet adoption delayed
A Logical Synchronizer Upgrade on 29 July 2026 moved DevNet's ordering to CantonBFT, Canton's own BFT orderer. On 8 September 2026 the Foundation said the Splice and Canton teams recommended a temporary delay on TestNet and MainNet; if ready, MainNet would adopt it at the upgrade window of 9 to 10 October 2026. Splice 0.8.0 (4 September 2026) prepared the ordering layer for the switch.
- Proposal:planned; the June 2026 schedule had set MainNet adoption for 8 August 2026
- Implementation:CantonBFT in Canton 3.5; Splice 0.8.0 prepared the ordering layer for the switch
- Release:live on DevNet since 29 July 2026
- Activation:not active on TestNet or MainNet; MainNet adoption possible on 9 to 10 October 2026 if ready
Sources: Canton Network Forum (Announcements) — Logical Synchronizer Upgrade (LSU) Updates (external site) · Canton Network Forum (Announcements) — Canton 3.4 to canton 3.5 transition (external site) · Canton Network Docs — Splice release notes (external site) · Splice (GitHub) — Splice 0.8.0 release (external site)
-
Traffic-based app rewards (CIP-0104) not activated on MainNet; no new date set
The Canton Foundation said traffic-based app rewards would not go live on MainNet on 18 August 2026 because the on-chain proposal combining the supporting Daml models with activation was not approved. The notice said the models would instead be enabled on 18 August and Super Validators would gain a voting interface for featured-app weights, while activation awaits further governance with no revised date.
- Proposal:CIP-0104 approved on 2026-02-12
- Implementation:supporting Daml models scheduled to be enabled on MainNet on 18 August 2026, per the 17 August notice
- Release:shipped in Splice; the combined activation proposal was not approved
- Activation:not active on MainNet as of the 17 August 2026 notice; no revised date
Sources: Canton Network Forum (Announcements) — CIP-0104 MainNet Go-Live Update (external site) · Canton Foundation (CIPs repository) — CIP-0104: Traffic-Based App Rewards (external site) · Canton Network Docs — Canton Coin Tokenomics (external site)
-
MainNet moves to Canton protocol version 35 with a Logical Synchronizer Upgrade
Canton announced that Logical Synchronizer Upgrades are live on MainNet with Canton 3.5: the upgraded synchronizer runs in parallel and the switch completes in seconds or minutes. The Foundation's schedule set the MainNet upgrade from protocol version 34 to 35 for 27 June 2026, with party onboarding and other topology changes paused for the preceding 24 hours.
- Implementation:shipped in Canton 3.5
- Release:released; minimum Splice 0.6.5 for validators
- Activation:MainNet upgrade scheduled for 2026-06-27 13:00 UTC; Canton's 29 June post says the upgrades are live on MainNet
Sources: Canton Network Blog — Canton Network Goes Live with Logical Synchronizer Upgrades (external site) · Canton Network Forum (Announcements) — Canton 3.4 to canton 3.5 transition (external site)
-
CIP-0105 ties Super Validator reward weight to locked Canton Coin
CIP-0105, approved on 2 March 2026, says a Super Validator earns its full reward weight only while it keeps a set share of its lifetime Super Validator rewards locked, starting at 70% and stepping down over the following years; lower tiers earn part of the weight, and unlocking vests over a year. The Foundation's MainNet configuration shows weight adjustments made under it, the latest on 28 September 2026.
- Proposal:CIP-0105 approved on 2026-03-02
- Implementation:enforced through reward-weight entries in the Foundation's MainNet configuration
- Release:policy applied by configuration; no software release identified
- Activation:active; the MainNet configuration records enforcement and reversals, the latest on 2026-09-28
Sources: Canton Foundation (CIPs repository) — CIP-0105: Super Validator (SV) Locking & Long-Term Commitment Framework (external site) · Canton Foundation (configs repository) — MainNet approved-sv-id-values.yaml (external site) · Canton Foundation (configs repository) — Commit history of the MainNet approved-sv-id-values.yaml file (external site)
-
CIP-0096 approved: validator liveness rewards phased down to zero by 30 April 2026
Super Validators approved CIP-0096, which lowered the cap on rewards validators earned just for being online in stages until it reached zero on 30 April 2026. Canton's tokenomics docs now say activity rewards, earned in proportion to the Canton Coin a validator's users burn, are the only way validators mint CC.
- Proposal:CIP-0096 approved on 2025-12-31
- Implementation:CIP-0096 specifies four on-chain Super Validator votes lowering the validator liveness reward cap in stages; the individual votes were not checked
- Release:configuration change voted on the ledger; no software release required
- Activation:cap at zero effective 2026-04-30, per Canton's tokenomics docs
Sources: Canton Foundation (CIPs repository) — CIP-0096: Removing Liveness Rewards from Validator Rewards Pool (external site) · Canton Network Docs — Canton Coin Tokenomics (external site) · Canton Network Docs — Tokenomics of the Global Synchronizer (external site)
Topics your AI can explain
Your AI can explain these topics for Canton Network through the connection, with sources.
Known gaps
What this profile's review did not establish:
- The Foundation's MainNet configuration lists 13 approved Super Validator node identities; how many were online on the review date, and each organisation's current reward weight after CIP-0105 adjustments, were not verified.
- The number of approved MainNet validators was not measured: the Scan endpoint that lists validator licenses refused requests from a non-allowlisted address.
- Whether the Global Synchronizer's ordering moves from CometBFT to CantonBFT at the MainNet upgrade planned for 9 to 10 October 2026 was not known on the review date.
- Traffic-based app rewards (CIP-0104) had not gone live on MainNet as of the Foundation's 17 August 2026 notice, and no later activation was verified.
- The operator of the USDCx registry on Canton, USDCx supply and its use were not verified.
- No automated market maker or other exchange venue on Canton was reviewed from a primary source.
- Which assets use LayerZero on Canton, and which verifiers each of them configures, were not reviewed; LayerZero's announcement and metadata do not say.
- No throughput figure with a stated method was found, so none is recorded.
- Current issuance settings on the network (yearly issuance ceiling and tranche percentages) and the current holding fee were not read from the ledger; the minting curve comes from the July 2024 white paper.
- Ledger's announcement does not list supported device models, and Ledger's support article did not render as readable text.
- Whether any Super Validator exposes its Scan API without IP allowlisting was not tested beyond one request to the Canton Foundation's MainNet Scan.
- No light client, payment channel, rollup or recovery path without a lost key was found; absence was not exhaustively verified.
- How a party's hosting and signing keys can be rotated or recovered after key loss was not researched.
- Which settlement apps run token-standard swaps on MainNet, who publishes them and how their settlement contracts bind every leg were not reviewed.
Sources
Oldest dated source check: Source checked Sep 29, 2026 Next check due Oct 29, 2026.
- What is Canton Network? (external site)
- The Global Synchronizer (external site)
- Canton Coin and the Global Synchronizer (external site)
- Two-Layer Consensus (external site)
- Ordering Consensus (external site)
- Transaction Lifecycle (external site)
- The Ledger Model (external site)
- Privacy Model Explained (external site)
- Trust Model Overview (external site)
- Local and External Parties (external site)
- Super Validator Components (external site)
- Canton Coin Tokenomics (external site)
- SV Governance Reference (external site)
- CF Policies (Canton Foundation policies and governance framework) (external site)
- Validator Onboarding Process (external site)
- Prerequisites (validator hardware requirements) (external site)
- Scan APIs (external site)
- Dedicated Synchronizers (external site)
- Transfer Types (Wallet SDK guide) (external site)
- Splice release notes (0.8.0 to 0.8.4) (external site)
- Frequently asked questions for the Canton Network (external site)
- MainNet approved-sv-id-values.yaml (approved Super Validator identities, reward weights and beneficiaries; last commit 2026-09-28) (external site)
- CIP-0056: Canton Network Token Standard (external site)
- CIP-0105: Super Validator (SV) Locking & Long-Term Commitment Framework (external site)
- Canton Coin: A Canton-Network-native payment application (July 2024) (external site)
- Logical Synchronizer Upgrade (LSU) Updates (8 September 2026) (external site)
- digital-asset/canton: Canton, a Daml ledger interoperability protocol (external site)
- canton-network/splice: applications for operating Validators and Super Validators on the Canton Network (external site)
- USDCx on Canton now available via Circle xReserve (4 December 2025) (external site)
- USDCx Now Live on Canton, Unlocking Private and Composable USDC-Backed Settlement (external site)
- USDC contract addresses (external site)
- Supported protocols (external site)
- LayerZero Partners with Canton to Bring Institutional Assets to Global Crypto Markets (26 March 2026) (external site)
- LayerZero deployments metadata (Canton MainNet entry: endpoint IDs 567 and 30567, status active, verifiers LayerZero Labs and Nethermind) (external site)
- Splice token standard allocation interface (execute, cancel and sender withdrawal choices) (external site)
- CC View: Canton Blockchain Explorer (external site)
- CC Space: Canton Network Explorer and Analytics (external site)
- Canton Coin Now Available on Ledger Wallet (19 August 2026) (external site)
- @ledgerhq/cryptoassets 13.56.0 currency list (canton_network entry) (external site)
- Canton wallet (external site)
Report an error
Found something wrong or out of date? Reporting is free, and every chain goes through the same process. Published corrections appear in the public log.
Funding disclosure
Funding disclosures appear here when an upkeep arrangement exists, in the form “Upkeep funded by [name]; verdicts unaffected.” The funder ledger has not been published yet. Neutrality & funding