NADO
NADO logo

Mine rewards from your phone.
Quantum-safe. Private by design.

A fair-launch, post-quantum blockchain you mine from a real device — an Android phone, a Windows PC with a TPM, a Ledger or a Trezor Safe. No rig, no install: open one link and you have the wallet, miner, explorer and shielded pool in a single page.

Collect Rewards View the code Join the Discord No app store, no signup, no seed-phrase ceremony — just a URL.
PoSEA — Proof of Secure Element Attestation: one device, one identity Post-quantum signatures Private transfers (zk-STARK) AIK Oracles — no certificate authority: the network issues the attestation Microsoft refuses Fair launch, no premine

A draw, not a race

NADO replaces the Proof-of-Work hash race with a deterministic, beacon-keyed weighted draw: one hash decides each block's producer, so faster hardware (ASICs, GPUs) confers no advantage and there is nothing to grind. A phone competes on equal terms with a datacenter — and can win a block even while its tab is closed, because every node builds the block itself and credits the winner by address.

Betanet — pre-mainnet, but not a sandbox. What you mine is real: balances persist across upgrades and carry forward to mainnet. Consensus is still hardening, so a genesis reroll remains possible — if it happens, balances are carried across and we say so openly.

AIK Oracles — the network issues the certificate Microsoft will not

A Windows PC proves its TPM through Microsoft's attestation service. For a large minority of machines that service answers 404: the chip is genuine and vendor-certified, Microsoft simply has no authority registered for it, and there is no appeal — on Linux no such service has ever existed. NADO's nodes do that job instead — AIK oracles. Three are drawn at random, each seals a secret to your chip's endorsement key, and only the real chip can open all three. What makes it a proof is the order the four messages land in, not a signature, so any node can re-check it offline, forever. No certificate authority, and no service to ask permission from.

PoSEA — Proof of Secure Element Attestation

PoSEA: every mining identity is a genuine device that proves itself to the network: a hardware attestation over a chain-chosen challenge, verified by every node against vendor roots pinned in the protocol. The device's factory certificate is then bound to that identity for the lease, so one device holds one identity at a time — every identity costs a real device, and a farm pays for each one it runs.

Why a device at all, and what the network sees

Identity management is the only useful weapon against miner centralisation. Every rule written per identity — a work proof, a waiting time, a per-address cap, a per-IP budget — costs a farm exactly what it costs an honest miner, per identity, and a farm makes identities for free. It has been the holy grail of every project that paid people rather than capital: NANO, Idena, Nyzo, NADO's own IP mining — each was gamed by identity farming. Without a real identity, identity farming is what opens the attack; NADO's identity is a physical secure element, bound to one wallet at a time.

It is not a passkey or a login. The wallet asks your phone or PC to create a throwaway hardware key and sign one challenge chosen by the chain. What every node verifies, offline, is the maker's certificate: "genuine Android", "genuine TPM", "genuine Ledger". No serial number, no account, no name leaves the device; the key is never used again; nothing is stored with your wallet key; no node ever contacts Google, Microsoft, Ledger or Trezor.

Holding, sending and receiving NADO need no device. Attestation is only for mining rewards. If you would rather not attest from the device you mine on, "Attest from another device" lets any phone or PC you trust vouch for the wallet.

🤖

Android 12+

Locked bootloader, Chrome: the phone's TEE or StrongBox key attestation, chained to Google's roots. Rooted or unlocked phones cannot attest.

🪟

Windows Hello

Windows Hello on a physical TPM 2.0, chained to Microsoft's TPM root — the TPM's own proof decides, so every Hello flavour (VBS included) is accepted; virtual TPMs are refused. When it will not attest, either a password manager took the prompt instead of Windows Hello, or the TPM never received its AIK certificate from Microsoft — then use the TPM enrolment helper below.

💻

PC with a TPM 2.0 (Windows or Linux)

No Windows Hello needed. Open the wallet on that PC and press Start collecting: when the browser cannot attest, the wallet offers its TPM enrolment helper for Windows or Linux, with your address already in it. Run it and the chip proves itself to the network's AIK oracles — no certificate authority, nothing to paste, and your key never leaves the browser.

Open the wallet →

🔐

Ledger

Nano S, Nano S Plus, Nano X, Stax and Flex, over WebHID: the device's factory-certified key vouches through Ledger's own genuineness handshake — you allow it on the device.

🔑

Trezor Safe

Safe 3, Safe 5 and Safe 7, over WebUSB: the secure element's per-device certificate, chained to the root key pinned for that model — you confirm on the device. Trezor One and Model T have no secure element and are refused.

Not accepted, because nothing in them identifies one device: virtual machines, emulators, software keys, Windows Hello without a TPM, FIDO2 security keys and Trezor One / Model T (batch certificates), and iPhone / iPad / Mac (Apple passkeys carry no attestation) — a Mac or iPhone user registers with a Ledger, a Trezor Safe or an Android phone instead.

How attestation and binding work →

Staking: no device, no pool — stake is weight

Savings (bonded stake) produce blocks on their own — nothing to attest, nothing to renew, and your weight is your stake, one for one. Capital is the Sybil resistance here; the device rule stays where it discriminates — the free lane and the presence dividend, which a staker with a device keeps earning on top.

🪙

Bond and forget

Bond 10 NADO or more from the Savings tab and your stake joins the bonded draw from the next epoch, ramping to full weight over 30 epochs (about 3 hours) — then one coin, one weight. No device, no lease, no renewal, no pool: coins stay in your account and unbond after a timelock.

📜

No pools

Staking pools existed for the weeks the bonded lane required a device; once it did not, a pool could only pay a delegator what solo staking pays, minus a fee, so they were retired. The code stays in git if a reason ever returns.

📈

Why plain stake

We measured every per-wallet rule on the live lane before dropping it. The device requirement idled a fifth of the stake and stopped only a whale with one phone. The knee curve was undone by splitting at the knee and shaped nobody's weight. Capital is the Sybil resistance of a bonded lane; what limits concentration on NADO is the 30 % of blocks and about half of all emission that go to attested devices, one per identity — something stake cannot buy.

Staking logic in the README →

Every node builds every block

There is no block proposer in NADO. A block is a pure function of the chain and the mempool — same parent, same transactions, same code — so every node computes the identical block itself. Nobody proposes, nobody waits for a leader, and nobody can hold a slot hostage. The only thing that can differ between nodes is the mempool, and the protocol keeps pools equal at the moment it matters.

🧮

Computed, not proposed

Winner, transaction set, weight and hash are all derived from committed state and the pool. No signature the chain depends on, no timestamp in the hash — no clock and no key can make two honest nodes disagree.

🤝

Pools that agree

Push gossip, per-second pull reconcile, an inclusion delay, and — right before building — a direct “what would you include?” exchange with peers. The mesh converges on the union of its next-block sets inside the slot.

⚖️

Ties favour the better pool

If two blocks still appear at one height, the one built from the more complete transaction set wins, deterministically — and the other side adopts it instantly, because the block carries the transaction it lacked.

See the next block as the network computes it →

Why NADO

Most "anyone-can-mine" coins get captured by specialized hardware, launch unfairly, aren't quantum-resistant, or still lean on trusted infrastructure. NADO targets all four at once.

📱

PoSEA: one device, one identity

Your device's secure hardware vouches for your identity once per lease and the network binds that device to it — no farm of virtual identities, no server pretending to be a phone.

🎯

Fair launch, no premine

Genesis mints zero coins. Every coin in existence was minted as a block reward — a brand-new, zero-coin miner earns from block 1. Balances carried across betanet rerolls were themselves mined as block rewards on earlier betanets.

💸

Everyone present earns

A presence dividend redistributes most of the open-lane reward to everyone showing up steadily — a stream, not a rare jackpot.

🔒

Post-quantum

ML-DSA-44 (NIST FIPS 204 / Dilithium) signatures, cross-validated between the browser and full nodes. Every signature the chain checks is ML-DSA-44; the only classical cryptography is the device makers' certificates, which attestation checks when a device registers.

🛡️

Shielded pool

Optional post-quantum zk-STARK privacy: prove a transfer on your own device so no one — not even a node — sees your amounts or keys.

⚙️

Consensus load that does not grow

Validator consensus traffic stays constant however many validators bond: a stake-sampled committee of 128 seats posts one merged duty per seat per epoch, and native ML-DSA verification checks each signature about 55× faster than pure Python.

🪶

Lightweight & reproducible

Consensus hashing is over canonical JSON, so a browser reproduces every address and transaction id byte-for-byte. No full node needed.

🎲

Randomness no single party chooses

Producers are drawn by a commit-reveal beacon any bonded validator can seed — every reveal adds another hand to the dice, so no single party chooses the draw.

🌍

Speaks your language

Wallet, miner and explorer fully localized in 16 languages — every log line, error and button, not just this page.

Settled by stake, not a zkVM

NADO settles its rollups with a bonded-stake quorum — a rollup ends up as secure as NADO itself, at near-zero cost.

⚡

10³–10⁶× lighter than a zkVM

NADO settles a rollup by running its VM at roughly native speed — it runs on a phone — and checking one bonded-stake vote on L1. A zkVM proving every executed instruction burns 10³–10⁶× more compute (GPU-class proving, seconds to minutes per batch) and adds a large prover-and-circuit stack to audit — all to remove one assumption NADO already relies on: that 2/3 of its bonded stake is honest.

Run a casino — it's already built, just bankroll it

The game contracts are already deployed and open to everyone — no allowlist, no approval, no gatekeeper. Opening a casino, prediction market, lottery or slot machine is one click: put up a bankroll and you're the house. You keep the edge — we take zero platform fee, ever. The only cost is NADO's network fee. That's the giveaway: the devs give up the revenue a normal platform would skim, so it's all yours.

🚀

Already deployed, permissionless

The contracts exist and are ungated — no team to email, no KYC, no listing fee. Bankroll one and it's live; the same rule for everyone.

🎰

You're the house — keep the edge

Fund a table and every losing stake plus the published house edge is yours. Set the odds or run it at cost — it's your machine, and the payouts come straight from your bankroll.

🪙

Zero platform fee — only the network fee

We skim nothing: no cut, no revenue share, no rent to a middleman. You pay NADO's tiny transaction fee and keep everything else — the devs give up the fees a normal platform would take.

A treasury that can't be hoarded

10% of every block reward funds an ecosystem treasury — but there is no founder wallet, no multisig, no one who controls it. It is spent only by a 2/3 stake vote of bonded holders, and 1% of the idle balance above the floor is burned every day. No one holds the keys, so it is almost as if the treasury doesn't exist as a power center — it's a rule, not a ruler.

🗳️

Nobody controls it

Fully on-chain, quorum-governed: bonded stakers propose and vote on every spend, right in the wallet. No admin key to capture, no privileged party to trust or corrupt.

🔥

Spend it or lose it

Every day, 1% of the treasury balance above a runway floor is burned. The funds are forced into the ecosystem by a stakeholder vote — or slowly destroyed. It can never just sit there.

⚖️

Yours anyway

It's emission miners and holders would receive regardless — redirected, by their own vote, into growth that lifts the whole network, not a founder's discretionary war chest.

Start in one tap

Onboarding is opening a link. Share it in a group chat: whoever opens it gets a wallet in the browser, attests their device once and starts collecting — and shares it again. That's the whole growth model.

Open the Interface

Go to get.nadochain.com on any phone or laptop. Nothing to install.

Generate a wallet

A post-quantum key is created in your browser and stored on your device — optionally password-encrypted.

Tap “Start collecting”

Your device attests itself with one prompt, which registers you on-chain for the free open lane. Leave the page open and it keeps collecting.

Send, explore, save

Send/receive, register a human-readable alias, browse the chain, and bond stake to earn the savings lane — all in the same page.

Govern

Bond stake, then vote in the Quorum tab on how the treasury funds the ecosystem — or lets it burn. The chain's money is governed by the people who hold it, not a founder.