Layer 1 blockchain
Symbol ticker XYM
Summary
Symbol produces blocks by harvesting under what it calls Proof-of-Stake Plus (PoS+). Every 720 blocks, about six hours, each account holding at least 10,000 XYM receives an importance score that is 95% its share of harvesting balance and 5% an activity score built from fees paid and times named as a node beneficiary; its chance of harvesting the next block follows that score, randomised with a linked VRF key. Blocks target 30 seconds. A separate finalization process then runs in epochs of 1,440 blocks: accounts that own a node, hold at least 3 million XYM and have registered a voting key vote in rounds, weighted by balance, and a block is final once more than two-thirds of the selected voting balance (the docs say 67%) supports it. 1231315181920
Design
- System
- Layer 1 blockchainIndependent proof-of-stake chain with its own harvesters and finalization voters; it settles to no other chain. Symbol launched on 16 March 2021 as the successor chain to NEM's original network, NIS1, rebuilt from scratch in a C++ client called Catapult. NIS1 is a separate chain with its own currency, XEM; an opt-in gave NIS1 holders one XYM per XEM but did not merge the ledgers.
- Settlement family
- Its own design
- Scarce resource
- Stake (proof of stake)
- State model
- Accounts
- Finality
- Checkpointed
- Who makes blocks
- Any account holding between 10,000 and 50 million XYM (the live mainnet limits) that has linked a VRF key can harvest: on its own node with a remote proxy key, or by delegating to another node that accepts it. The node may keep up to 25% of rewards as beneficiary and 5% goes to a network account that funds voting-node rewards. Harvesting uses the account's ordinary balance; the reviewed docs describe no lock-up and no penalty for misbehaviour. How concentrated harvesting and voting balances are was not measured in this review.
- Fork choice
- Nodes adopt a remote chain that promises a higher chain score, the sum of block scores that rise with difficulty and fall as time between blocks grows. Mainnet sets its rollback limit to zero, which turns on the finalization gadget, so synchronization only reconsiders blocks after the last finalized block: unfinalized blocks can be rolled back to any depth, finalized blocks never.
Qualifications
- Settlement family · Partial. Recorded as other. Symbol's own terms: an independent chain run by the Catapult client, with Proof-of-Stake Plus harvesting, a finalization voting gadget, accounts that hold mosaics and namespaces, and built-in transaction types added as system plugins; it settles to no other chain.
- Importance score · Partial. Recorded as stake. Symbol's own term is importance: 95% of an account's score is its share of XYM held by eligible accounts and 5% is an activity score from fees paid and node-beneficiary counts, divided by balance so smaller accounts gain relatively more from activity. Only balances from 10,000 to 50 million XYM can harvest, and finalization votes use balance alone, not importance.
- Finalization voting · Partial. Blocks are probabilistic until a finalization round covers them. Voting accounts must own a node, hold at least 3 million XYM and register a voting key valid for up to 360 epochs; votes are weighted by balance. Block production continues when finalization is slow, and the docs warn that low connectivity or many bad actors can delay finalization and cause large rollbacks of unfinalized blocks.
- Slashing · Not applicable. Symbol has no slashing: harvesting and voting use ordinary balances and the reviewed docs describe no confiscation. The technical reference says voters who break the voting rules are considered Byzantine and might be punished in the future.
- Smart contracts · Not applicable. Users do not deploy contract code on Symbol. Its vision page says functionality is extended through system-level plugins, and every transaction type is a plugin in the node software, so new behaviour needs a node upgrade. Multisig rules, aggregates, secret locks, restrictions and metadata are the programmable building blocks.
- Tps · Unknown. The only figure found is the per-block limit in the block documentation and the live network settings, kept in the classified claims list; no transactions-per-second figure or observed rate was reviewed.
- Documentation currency · Partial. Several docs.symbol.dev pages predate the live mainnet settings. The namespace page gives a 365-day maximum rental and 256 subnamespaces per root, while the mainnet network preset and a mainnet node's settings read on 2026-09-29 give 1,825 days and 100; this profile uses the live settings where they differ.
Tradeoffs
- Emphasizes
- Decentralization and Security
- Gives up
- Throughput. Symbol's technical reference says the design lets any node download and independently verify the whole chain and lets nodes with enough harvesting power create blocks without relying on a leader, and that these choices necessarily sacrifice some throughput. Blocks target 30 seconds, and per-block limits are recorded in the classified claims list.Finalization rests on accounts holding at least 3 million XYM and running a node, a requirement that limits who can vote. Votes are weighted by balance and nothing is slashed, so the safety of finalized blocks assumes that more than two-thirds of voting balance is honest. Harvester and voter concentration were not measured.
- Full node at home
- Practical at home 2141922Symbol's node guide lists minimums of 2 CPU cores, 8 GB of RAM and a 500 GB SSD rated at 1,500 IOPS for a peer node (4 cores and 16 GB recommended), and 4 cores, 16 GB and 750 GB for API, dual and voting nodes. First sync downloads the whole chain, which the guide says may take a few hours; the guide dates from 2022 and the chain has grown since. The newer Shoestring setup tool points to weekly data snapshots for recovery, which a node would trust instead of replaying history. Harvesting does not need a node (delegation), while voting needs a node plus at least 3 million XYM.
- Throughput claims
- Theoretical peak: 6,000 320Theoretical peak; not comparable across chains or with observed load.Transactions per block on the public network, at a 30-second block target; no per-second figure is published in the reviewed docs.Symbol's block page states the per-block limit and the 30-second target, and the network preset and a mainnet node's settings read on 2026-09-29 show the same limit; this review found no published transactions-per-second figure and did not derive one. It is a configured ceiling, not a measurement; no observed rate was measured. An aggregate transaction counts once but can carry up to 100 inner transactions, so the limit does not map directly to payments. Block size, fee levels and node performance under load were not tested.
Scaling layers
- Planned subChains (handbook vision page) · Rollup, research 17
Symbol's vision page, last updated in November 2023, describes small purpose-built subChains anchored to the main chain through a rollup-centric interconnect based partly on zero-knowledge proofs, each with its own token and harvesters, with XYM required for settlement. It is a stated direction; no live subChain was found in the reviewed sources.
Capabilities
| Capability | How it is provided | Notes and sources |
|---|---|---|
| Account abstraction | Structured assessment pending | Not yet assessed for any chain. |
| Atomic swaps | Built into the protocolLimited scope | Protocol, limited: built-in secret lock and secret proof transactions implement hash-time-locked swaps. A secret lock holds a mosaic for a named recipient until someone reveals the proof whose hash matches, or returns it to the sender when its duration ends (up to 365 days on mainnet). The limit: Symbol's guide shows a swap between its public chain and a private chain built on Symbol technology; a swap with another network needs a matching hash lock there, and no maintained tool for such swaps was verified. Both parties must act before the locks expire. 4619 |
| Authenticated data publication | Unknown | Only building blocks were found. Transfer messages of up to 1,023 characters, which Symbol's docs suggest for timestamping data, are committed through each block's transaction Merkle root and can be checked with Merkle proofs, and metadata entries of up to 1,024 characters are key-value records in chain state, which this row does not count. No feature for publishing data against a chain-recorded commitment with discoverable updates was reviewed. 91121 |
| Light clients | Built into the protocolLimited scope | Protocol, limited: block headers commit to transactions, receipts and chain state through Merkle and Patricia trees, enabled in the mainnet settings; finalization proofs carry voters' signatures, and importance blocks record the total voting balance so a client can check a proof's two-thirds threshold. The technical reference says the trees exist to support trustless light clients. The limit: no packaged light client was found, so a client must fetch headers and proofs from nodes and needs the epoch's voter set. 3111820 |
| Native staking or delegation | Structured assessment pending | Not yet assessed for any chain. |
| On-chain governance | Structured assessment pending | Not yet assessed for any chain. |
| Parallel execution | Structured assessment pending | Not yet assessed for any chain. |
| Payment or state channels | Unknown | No payment or state channel layer anchored to Symbol was found in the reviewed docs. Secret locks, hash locks and aggregate bonded transactions are building blocks; absence was not exhaustively verified. |
| Programmable spending | Partial (layer not stated) Earlier definition | Spending rules come from built-in transaction types, not user-written code: M-of-N multisig accounts with up to 25 cosignatories nested up to three levels, secret locks with hash and time conditions, account restrictions on addresses, mosaics and operation types, and aggregate transactions that apply several inner transactions all or nothing. New behaviour needs a system plugin in the node software. 5671012 |
| Protocol-verified messaging | Structured assessment pending | Not yet assessed for any chain. |
| Reversible transfers or recovery | Built into the protocolLimited scope | Part (a) through built-in secret locks: funds locked for a recipient move only if the proof is revealed before the lock's duration ends and otherwise return to the sender automatically, so a sender who keeps the proof can let an unreleased payment lapse. No way to reclaim a completed transfer was found. Part (b) is not met by the protocol: a multisig account whose cosignatories can remove and replace a lost key is a plain multisig threshold. Mosaic creators who set the revokable flag can reclaim that mosaic from holders, which is issuer control over one mosaic. 678 |
| Rollups | Unknown | No rollup settling to Symbol was found. Symbol's vision page describes planned subChains anchored to the main chain through a rollup-centric interconnect, recorded as research in the scaling layers; they were not found live, and absence was not exhaustively verified. 17 |
| Shielded transfers | Structured assessment pending | Not yet assessed for any chain. |
| Signed partial offers | Not present | None: Symbol's list of built-in transaction types has no offer or exchange type, and the nearest feature, an aggregate bonded transaction, lets a maker sign a bundle of inner transactions and wait up to 48 hours for cosignatures, but each inner transaction names its signer's public key and the aggregate's hash commits to them, so only the parties named when the maker signs can complete it, not any taker. Announcing one also needs a 10 XYM hash lock deposit, refunded on confirmation. 4518 |
Reading these values
- How this feature is provided
- Built into the protocol, core-team software or independent software says where a feature lives and who can change it. These are implementation layers, not quality: core-team software is not closer to the protocol than independent software.
- Structured assessment pending
- The shared review has not assessed this feature for any chain yet (Account abstraction, Native staking or delegation, On-chain governance, Parallel execution, Protocol-verified messaging and Shielded transfers). That does not mean it is absent, and a chain’s profile may already describe it.
- Unknown
- The review has not established this for this chain under the current definition; the note beside it says why. Unknown is not absent and not a low score. A feature reads “Not present” only when a source shows it is absent.
- Earlier definition
- Payment or state channels, Programmable spending and Rollups keep the earlier definition until the next fact-check. There, “Native” does not separate the protocol from core-team software, “Ecosystem software” does not say who publishes it, and “Partial” does not say which layer.
- Reading across rows
- The list of capabilities is incomplete. Do not read these rows as a chain leading or lagging overall.
Ecosystem & custody
| Product type | Status | Notes and sources |
|---|---|---|
| Automated market makers | Unknown | No automated market maker on Symbol was found, and DeFiLlama's protocol index listed no protocol on Symbol on 2026-09-29. Users cannot deploy contract code on Symbol, so a pooled market maker would have to run off chain or as a new built-in transaction type; operator-run swap services were not surveyed. 1234 |
| Issuer-native stablecoins | None found | Neither Circle's USDC network list nor Tether's supported-protocol list includes Symbol, and no other issuer-native stablecoin was found. 3233 |
| Algorithmic stablecoins | Unknown | No algorithmic stablecoin on Symbol was found; mosaics issued by companies on Symbol were not surveyed. |
| Bridges | UnknownSymbol bridge software (symbol/product repository, version 0.1.0) | The core developers' product repository publishes bridge software that can wrap XYM or XEM into tokens on Ethereum (for example wXYM), issue staked tokens that share harvesting rewards, or swap XYM for ETH, but no live mainnet deployment, contract address or operator was verified. Risk: As published, the design is custodial: users send tokens to a bridge account and the operator pays out from a pre-funded account on the other network, so users trust the operator's keys and solvency. A wrapped asset is only as sound as the bridge that minted it. 2627 |
| Block explorers | First-partySymbol Block Explorer (symbol.fyi), NodeWatch (Seven Seas Explorer) | The explorer's source and changelog are in the symbol GitHub organisation, Symbol's docs point readers to symbol.fyi for the current node list, and the explorer's configuration points to NodeWatch for node data. Who operates the symbol.fyi deployment is not stated on the site. Listing is not a quality check, and explorer data is indexed from REST nodes. 232425 |
| Hardware wallets | ThinLedger (through Symbol Desktop Wallet) | See custody rows: Ledger devices sign through Symbol Desktop Wallet with a Symbol device app, and Trezor states that it does not support Symbol. 163031 |
Hardware-wallet custody
| Device maker | Status | What users can and cannot do |
|---|---|---|
| Ledger | Through an intermediarySymbol Desktop Wallet, with the Symbol app installed on the Ledger deviceSame as native: Unknown | Can: Send and receive XYM and other mosaics from Symbol Desktop Wallet with keys held on a Ledger Nano S or Nano X, per Symbol's guide (updated 2025-07-24) Can: Sign multisig, namespace, mosaic, metadata, restriction and delegated-harvesting transactions from the same wallet Cannot: Find XYM in Ledger's published Ledger Wallet currency list (@ledgerhq/cryptoassets 13.56.0) Cannot: Confirm from a readable Ledger page which models Ledger Live offers the Symbol app for; Symbol's guide names the Nano S and Nano X, and Ledger's app-symbol build file lists the Nano X, Nano S Plus, Stax, Flex and one moreSymbol's guide has users install the Symbol app from Ledger Live's app catalog. Ledger keeps the device app's source in its own app-symbol repository, and the symbol GitHub organisation publishes a fork of it. Ledger's own support article on Symbol renders only in a browser and was not read in this review. 16282930 |
| Trezor | None foundSame as native: No | Cannot: Manage XYM with a Trezor device; Trezor's page says it does not currently support SymbolTrezor's page asks users who used this asset with Trezor in the past to contact support. 31 |
Public data
iKnow Blockchain has no public-data lookups for Symbol yet. This is a limit of the service, not a statement about the network.
| Lookup | Status | What it covers and its limits |
|---|---|---|
| Address or account | Not available yet | Public-data lookups for this chain are not built yet. |
| Tokens and assets | Not available yet | Public-data lookups for this chain are not built yet. |
| NFTs | Not available yet | Public-data lookups for this chain are not built yet. |
| Transactions | Not available yet | Public-data lookups for this chain are not built yet. |
Sourced developments
Developments: Reviewed Sep 29, 2026 Next review due Oct 9, 2026, 12:00 UTC.
Publication date · newest first
-
Symbol SDK 3.3.3 fixes fee calculation for transactions with cosignatures
The JavaScript and Python SDK 3.3.3 releases fix the Symbol transaction fee calculator added in 3.3.2 in June 2026, which had not multiplied the size of cosignatures by the fee multiplier. The Python release also adds functions that build a transaction or embedded transaction from a raw descriptor. The 3.3.1 releases in April 2026 added TypeScript 6 and Python 3.14 support and JSON output for multisig workflows, and the 3.3.2 releases in June 2026 added the fee-calculation helpers.
- Implementation:released in the JavaScript and Python SDKs 3.3.3
- Release:published on GitHub 2026-08-31
- Activation:takes effect when an application upgrades; no network activation
Sources: Symbol (GitHub) — Symbol Javascript SDK 3.3.3 release notes (external site) · Symbol (GitHub) — Symbol Python SDK 3.3.3 release notes (external site) · Symbol (GitHub) — Symbol Javascript SDK 3.3.1 release notes (external site) · Symbol (GitHub) — symbol/symbol releases (external site) · Symbol (GitHub) — Symbol Javascript SDK 3.3.2 release notes (external site) · Symbol (GitHub) — Symbol Python SDK 3.3.1 release notes (external site)
-
Post-mortem published for the aggregate transaction hash fix activated by hard fork
A post-mortem first posted on the Symbol Syndicate's Notion site and reprinted by Symbol Community Web explains a bug found in September 2025: when an aggregate held a number of inner transactions that was not a power of two, a copy with duplicated final transactions could share its hash, which could have let a recipient replay a signed transfer and split the network. Catapult client v1.0.3.9 fixed it with aggregate version 3, which adds the embedded transactions' total size to the hash; the fork activated at block 4,759,100 on 25 September 2025. The post-mortem says no exploitation or stolen funds were found.
- Implementation:shipped in catapult client v1.0.3.9 and REST gateway v2.5.1
- Release:breaking-fork release published 2025-09-23
- Activation:activated at block 4,759,100 on 2025-09-25 per the post-mortem; only version 3 aggregates accepted since
Sources: Symbol Community Web (reprint of the Symbol Syndicate's post) — Post-mortem: Aggregate Transaction Hash Collision Vulnerability (October 2025) (external site) · Symbol (GitHub) — Catapult Client v1.0.3.9 release notes (external site) · Symbol (GitHub) — Catapult client changelog (external site) · Symbol (GitHub) — symbol-bootstrap mainnet network preset (external site) · Symbol Community Web (community-run) — Symbol blockchain network upgrade (external site) · Symbol (GitHub) — Rest Gateway v2.5.1 release notes (external site)
Topics your AI can explain
Your AI can explain these topics for Symbol through the connection, with sources.
Known gaps
What this profile's review did not establish:
- Harvester and voter concentration were not measured: NodeWatch's voting-power and harvesting-power charts render in the browser and were not read, and no stake-share figures are given.
- The number of voting accounts and the total voting balance per epoch were not read.
- Who operates the symbol.fyi explorer and the nodewatch.symbol.tools deployment is not stated on either site.
- The domain symbolplatform.com, listed in the research pack as official, served unrelated online-casino content on 2026-09-29 and was not used; the Symbol Syndicate's blog posts are Notion pages that could not be read as text, so the October 2025 post-mortem is cited from a community reprint.
- Several docs.symbol.dev pages were last updated in 2021 or 2022 and differ from the live mainnet settings; values here were cross-checked against one mainnet node's settings.
- No transactions-per-second figure is published in the reviewed docs, and no observed throughput was measured.
- The light-client value rests on protocol design in the technical reference; no packaged light client that verifies finalization proofs was found or tested.
- No live deployment, contract address or operator of the core developers' bridge software was verified.
- Ledger's support article on Symbol could not be read as text. Ledger's app-symbol build file lists the Nano X, Nano S Plus, Stax, Flex and one further model, but which models Ledger Live's catalog offers the app for was not verified.
- Operator-run swap services, company-issued mosaics and any mosaics meant to track a currency were not surveyed.
- Absence of payment channels and of rollups settling to Symbol was not exhaustively verified.
- The current median fee multiplier, rental fees and circulating supply were not read; the inflation schedule comes from the mainnet preset.
- The 2021 treasury reissuance fork recorded in the mainnet preset was not reviewed.
- No maintained tool for hash-locked swaps between Symbol mainnet and another network was verified; the swap guide's worked example pairs the public chain with a private chain built on Symbol technology.
Sources
Oldest dated source check: Source checked Sep 29, 2026 Next check due Oct 29, 2026.
- Consensus (external site)
- Harvesting (external site)
- Block (external site)
- Transaction (external site)
- Aggregate Transaction (external site)
- Cross-Chain Swaps (external site)
- Multisig Account (external site)
- Mosaic (external site)
- Metadata (external site)
- Account Restriction (external site)
- Data Validation (external site)
- Plugin (external site)
- Reward Programs (external site)
- Running a node (external site)
- Retrieving your XYM from a post-launch opt-in (external site)
- How to use your Ledger device with Symbol Wallet (external site)
- The Symbol Handbook: Vision (external site)
- Symbol from NEM: Technical Reference, version 0.10.0.4 (29 July 2021) (external site)
- symbol-bootstrap mainnet network preset (fork heights and inflation schedule) (external site)
- symbol-bootstrap shared network preset (defaults the mainnet preset does not override) (external site)
- Transfer Transaction (external site)
- Shoestring node setup tool (external site)
- Symbol Block Explorer (external site)
- Symbol explorer default configuration (NodeWatch endpoint, API port, XYM divisibility) (external site)
- Seven Seas Explorer (NodeWatch): Symbol summary (external site)
- Bridge: two-way bridge between NEM/Symbol and Ethereum (README) (external site)
- Bridge version file (version.txt: 0.1.0) (external site)
- ledger-app-symbol repository (external site)
- app-symbol build manifest (ledger_app.toml) (external site)
- @ledgerhq/cryptoassets 13.56.0 currency list (external site)
- Symbol wallet (external site)
- USDC contract addresses (external site)
- Supported protocols (external site)
- DeFiLlama protocols API (external site)
Report an error
Found something wrong or out of date? Reporting is free, and every chain goes through the same process. Published corrections appear in the public log.
Funding disclosure
Funding disclosures appear here when an upkeep arrangement exists, in the form “Upkeep funded by [name]; verdicts unaffected.” The funder ledger has not been published yet. Neutrality & funding