Skip to content
ORBITRAONE

Validators and node operators

Secure the network that settles the markets.

Validators secure the settlement layer of ORBITRA ONE™. Under QSE, they accept explicit duties, prove the service they deliver and sign the transitions that make trades, transfers and contracts final.

  • Quorum-Staked Execution
  • Deterministic BFT finality
  • HSM and MPC key custody
  • Signed releases

Quorum-Staked Execution

Three forces. One final state.

QSE is a HotStuff-family BFT composition. Stake provides economic security, authority defines proposer and committee duties, and verified work measures availability, validation and service. It is not proof-of-work mining.

Illustration: Three forces — stake, authority and verified work — shape a validator set. Validators vote on the same state transition; once a configured Byzantine quorum has signed, their signatures form a quorum certificate and one state is finalized.
  1. StakeEconomic security and slashing exposure
  2. AuthorityProposer and committee duties
  3. WorkVerified availability, validation and service

Validator votes

Quorum certificate

Finalized state

7 / 10

Stake, authority and verified work flow into the validator set. Validators vote on the same state transition; once the configured Byzantine quorum has signed, the votes combine into a quorum certificate and the state is final — with no reorganization after finality under the stated fault model.

Roles

Every duty has an owner.

  1. 01

    Proposer

    Orders the transitions produced by VectorLanes into a proposal and sends it to the committee. Authority rotates the role according to validator policy.

  2. 02

    Committee member

    Re-executes each proposal, checks the resulting state root and signs a vote. When the configured quorum signs the same transition, the votes form a quorum certificate.

  3. 03

    Node operator

    Replays every finalized transition and serves state, history, index streams and proofs to applications, wallets and institutional systems.

Verified work

Service is measured, not assumed.

Stake alone does not define a validator’s role. QSE measures the work each operator actually performs and feeds it back into duties and rewards.

Availability
Participation when assigned: proposals delivered, votes cast, certificates signed
Validation
Correct re-execution of transitions and agreement with the finalized state root
Service quality
Quality of the network services an operator provides, such as serving state, history and proofs
Effect on duties
Measured service shapes future proposer and committee assignments
Effect on rewards
Rewards weigh measured service alongside stake; outcomes vary
Evidence
Measurements derive from signed protocol records that any participant can verify

Accountability

Exposure is explicit.

Stake creates slashing exposure for provable misbehavior, such as signing conflicting transitions. The evidence is verifiable by any participant, so penalties follow protocol rules rather than operator discretion.

Weak service is treated differently from misbehavior. Sustained gaps in availability or validation lower an operator’s verified-work measurements, which in turn shape future duties and rewards.

Client diversity protects the network from correlated failure. Formal specifications allow independent implementations, so a defect in one client need not become a defect of the network.

Illustration: Five concentric security layers — asset, protocol, application, market and operational security — surround the network, with Q-Switch drawn as a ring that spans all of them to show cryptographic agility across every layer.
  1. Asset securityMPC/HSM policies, delayed withdrawals, allowlists
  2. Protocol securityFormal specifications, client diversity, slashing
  3. Application securitySandboxing, capabilities, upgrade controls
  4. Market securitySurveillance, circuit breakers, oracle confidence
  5. Operational securityZero trust, segregation, signed releases
  6. Q-Switch · cryptographic agility across every layer

Security posture

Keys stay in the signer.

The validator security model keeps signing keys in hardware security modules or MPC signing services, apart from the host that runs the node. Separating keys from operations means a compromised machine cannot sign on its own.

Node software ships as signed releases that are verified before installation. When cryptographic standards evolve, Q-Switch rotates validator credentials through versioned signature suites and hybrid credentials rather than emergency re-keying.

  • HSM or MPC key custody
  • Signed, verifiable releases
  • Separate signing and operations roles
  • Versioned signature suites and key rotation
Illustration: Signature suites are versioned. An account moves from a classical suite to a hybrid credential that combines classical and post-quantum-ready signatures, rotates its keys and migrates its address without losing its history or assets.

Suite v1 · classical

Suite v2 · hybrid

Suite v3 · post-quantum ready

  1. 01Versioned suites
  2. 02Hybrid credentials
  3. 03Key rotation
  4. 04Address migration

Tooling

Built for the people who run the network.

Commands and configuration are covered in the developer documentation.

01

Operator client

One command-line client configures, runs and inspects a validator or node. Configuration comes from the environment; keys are referenced, never stored on the host.

02

Duty visibility

Assigned proposer and committee duties, quorum participation and missed duties, exposed for alerting.

03

Service telemetry

Availability, validation and service-quality measurements, exported to your own monitoring stack.

04

Release verification

Every release is signed, and the client checks signatures before an upgrade is staged.

Rewards

Validator rewards are potential, not promised.

Rewards depend on stake, duties performed, measured service quality and network parameters, and can be reduced by slashing. Operating a validator carries infrastructure, security and market risk. Validator services is one of the twelve AlphaStack channels; see the general risk disclosure.

Validator interest

Apply to operate.

Tell us about your infrastructure, your key-custody approach and your jurisdiction. Participation depends on eligibility and network parameters.

  1. 01Applications are reviewed for security posture and operational readiness.
  2. 02Eligible operators receive technical documentation and onboarding guidance.
  3. 03Stake, custody and jurisdiction requirements are confirmed before any duty is assigned.
  4. 04We never ask for private keys or seed phrases.

Never include passwords, private keys, seed phrases or identity documents.