Arxium

Verify without a node

Check what the chain says without trusting whoever served it.

Arx Verify checks Arxium evidence on your own machine. It has no chain code and needs no node or network connection. You fetch a file from any RPC, ours included, and check it locally. Whoever served the file can't make a false one pass. The browser verifier runs the same code as the arx-verify CLI as a WASM module. Your file is read in the page and never uploaded.

Prove a holder's state: state proofs

A state proof is an account's current record, including its attestation, claims and jurisdiction, together with a Merkle path to a certified block. Fetch one for the holder from the walkthrough:

curl -s -H "Authorization: Bearer $ARX_TOKEN" \
  $ARX_RPC/accounts/$HOLDER/proof > proof.json

Drop proof.json on arxium.network/verify, or run arx-verify state-proof proof.json:

VALID
key: account:arx1w86p…
height: 31
block_hash: 0xe519…ec0a
value: {"attested_by":"arx1lzn2…","claims":["Kyc"],"jurisdiction":"CH", …}
certified: yes

VALID means this value is what the chain's state held under that key at that height. The check covers the Merkle path and the block's commitment to its certificate. It doesn't check the certificate's BLS signatures against the validator set, so confirm block_hash at that height with a source you already trust, such as the Explorer or a second RPC.

Prove a validator misbehaved: fault evidence

Validators write a signed evidence file whenever they see a fault. Any node serves its files:

curl -s -H "Authorization: Bearer $ARX_TOKEN" $ARX_RPC/evidence          # list of ids
curl -s -H "Authorization: Bearer $ARX_TOKEN" $ARX_RPC/evidence/<id> > evidence.json

The verdict tells you what the file proves:

  • VALID, for equivocation or prevote/precommit equivocation. One validator signed two different blocks or votes at the same height and round. The verdict names its key as culpable_pubkey.
  • UNRESOLVED, for execution_disagreement. A validator re-executed a block, got a different state root and signed a dissent. Both signatures are real, so the dispute did happen. The file can't say which side was wrong, so this isn't a verdict of guilt.
  • Failure, which exits 1 in the CLI. The file is malformed or a signature doesn't check out. Treat it as no evidence at all.

An evidence file can come from any chain, including a throwaway one someone set up. Before relying on a VALID verdict, check that the file's genesis_hash matches the one arx query status printed for corechain-devnet. Most of the time /evidence is an empty list [], because nothing has gone wrong.