CLPR
87 networks → Hedera
Verifier code for Ethereum, Bitcoin, Solana, the XRP Ledger and 83 more, checked by proofs, not promises.
CLPR lets ledgers verify each other with cryptographic proofs instead of bridges. ColdAI has submitted open-source verifier code that connects 87 networks to Hedera, and built CLPRouter so a message or payment can travel from any network to any other, through Hedera.
CLPR
Verifier code for Ethereum, Bitcoin, Solana, the XRP Ledger and 83 more, checked by proofs, not promises.
CLPRouter New
Multi-hop routing over CLPR: cheapest, fastest, most reliable or greenest, with ISO 20022, MiCA and energy filters.
01What is CLPR
CLPR, the Cross-Ledger Protocol (say “clipper”), lets two ledgers exchange messages by verifying each other's state proofs directly. No bridge sits in the middle: no outside validators to trust, no pool of locked funds.
An app sends a message. The sending ledger's CLPR Service adds it, in order, to the Channel's outbound queue.
An endpoint relays a bundle of queued messages with a proof of the sending ledger's state: its finality and the queue entries in it.
The receiving ledger's verifier checks the proof on-chain, delivers each message in order and answers with a response.
CLPR on GitHub, at LF Decentralized Trust (opens in a new tab)
Bridges ask you to trust someone in the middle. When they fail, they fail big.
0287 networks
To support Hedera and the whole Hiero ecosystem, ColdAI has submitted open-source CLPR verifier code for 87 networks, more than 85 of the top 100. Each verifier lets Hedera check that network's proofs itself.
The verifier checked real proofs from the network's mainnet or public testnet.
Same verifier code as a live-verified network of the same family.
Verifier code submitted; part of the proof path still waits on a public source or more work.
Submitted to LF Decentralized Trust's CLPR project for review; chain → Hedera direction. None of this is merged yet. The Hedera → chain direction waits on Hiero state proofs.
All 87 networks, A to Z
03CLPRouter New
Send anything from any network to any other — cheapest, fastest, most reliable or greenest — with ISO 20022, MiCA and energy filters.
A CLPR Channel joins exactly two ledgers. CLPRouter turns those Channels into a network: an application on top of CLPR, with no protocol change, that forwards a message hop by hop, sends a receipt back to the origin and settles or refunds the sender's escrow. A route is only as trusted as its weakest hop, and every hop re-checks the sender's rules on-chain.
Ethereum Hedera StellarOne Channel per ledger to the hub: 100 ledgers need 100 Channels, not 4,950 pairs.
Pick two networks, a mode and the rules your business needs, and watch the route trace through Hedera.
Filters: ISO 20022 · weakest hop sets the route's trust tier
Example values only. In CLPRouter the planner runs on the sender's side over a route graph of measured gas and calldata, and every hop re-checks the rules on-chain. Today the Hedera → destination leg waits on Hiero state proofs.
Five steps, with the money held at the origin until a receipt comes back.
The sender calls send() with the planned route, mode, filters, a deadline and an escrow. Before any value moves, the Router checks loops, hops, fees, disables, filters and the blacklist.
The message arrives over a CLPR Channel with its proof verified. The hop authenticates the previous Router, rejects replays, re-checks every rule, takes its fee and sends the next hop.
The destination Router hands the payload to the receiving app through onRouteMessage.
A receipt (DELIVERED, FAILED, EXPIRED or QUARANTINED) travels the reverse path. The origin checks it came back the exact way the route went out.
Delivered: the payee and the hops are paid. Failed or expired: the escrow is refunded. A blacklisted party: the funds go to the locked quarantine vault.
Choose how a route should travel, then add the rules every ledger on it must meet.
Lowest total fees in one quote currency: Connector margin, enqueue gas, the bundle share and execution gas.
Lowest expected time to delivery, measured at the 90th percentile.
Best chance of on-time delivery at a trust floor, with a disjoint fallback route.
Least estimated kgCO2e per message, from certified emissions figures.
The default: a weighted score of cost, time, reliability and carbon.
Every ledger on the route holds a valid ISO 20022 certification and runs an identified, operated Router.
Every ledger holds a valid MiCA certification, and its operated Router is run by an authorised crypto-asset service provider.
Every ledger holds a valid Energy certification with an emissions figure, optionally under a cap you set.
Filters combine with any mode and apply to every ledger on the route, origin and destination included:fastest + ISO 20022, greenest + MiCA + Energy. If nothing passes, the answer is “no compliant route”: the planner never falls back.
Payments speak the language banks already use. The payment's UETR is the route id and travels end to end; the payment message is encrypted to the destination institution, and only hashes and commitments go on-chain.
pacs.008 pacs.009 pacs.002 camt.056 pacs.004 camt.029pacs.002 ACSPACCC, EXPIRED → RJCT AB05, QUARANTINED → RJCT RR04No operator runs the routes. A provider with a narrow, public role can stop an exploit, but cannot take funds.
No admin key, no pause, no upgrade. New versions are deployed beside old ones, and each route names the version every hop must run.
Route planning runs on the sender's side. Anyone can run a Connector, relayer, indexer or regulated hop and earn fees.
Each hop authenticates the previous Router, rejects replays and re-checks filters, deadline, blacklist and fees before forwarding.
If an exploit tries to move stolen funds, the blacklisted account's routed funds are stopped and held in a locked vault, and both parties get a notice. Releases go only to the original sender, the original recipient, or a recovery address named after a public notice and challenge window, never to a committee member. A blacklist entry lapses unless the committee renews it (30 days recommended).
Solidity Routers, a provider registry and a quarantine vault; a TypeScript planner SDK with an ISO 20022 module; and optional indexer, status, quote and forward services. MIT-licensed.
import { plan, sampleGraph } from "@clprouter/sdk";
// Ethereum → Hedera → Stellar, cheapest ISO 20022 route
const quote = plan(sampleGraph(), {
origin: "eip155:1",
destination: "stellar:pubnet",
mode: "cheapest",
filters: { iso20022: true },
constraints: { maxHops: 3, deadlineS: 600 },
});
if (quote.ok) {
const { ledgers, totals, effectiveTrustTier } = quote.route;
// hops; cost, p90 time, success, kgCO2e; weakest hop
console.log(ledgers, totals, effectiveTrustTier);
}The planner adds no trust: a bad quote can make a route fail, but it cannot redirect funds.
04Next steps
We're not stopping at blockchains. Next, we aim to connect Hedera to the systems the world already runs on.
We aim to connect Hedera to the payment rails institutions already run, with ISO 20022 messages end to end.
We aim to reach central-bank settlement infrastructure, such as the European Central Bank's Pontes initiative.
We aim to link private Hiero networks to public Hedera through the same verified Channels.
We aim to bring permissioned enterprise ledgers into the same proof-checked routes.
05FAQ
What is ready, what is not, and who controls what.
Not yet. The verifier code for 87 networks is in open pull requests to LF Decentralized Trust's CLPR project, under review, and covers the chain → Hedera direction. The Hedera (Hiero) → chain direction waits on a Hiero state-proof source. CLPRouter is pre-release: built and tested locally, with testnet deployment in progress. Do not use it with real funds.
CLPRouter has had two internal audits, and their findings are being fixed with regression tests. There is no external audit yet. The CLPR verifier pull requests are being reviewed by the CLPR project.
No one owns it. Router contracts are immutable, with no admin key and no pause, and new versions are deployed beside old ones. Route planning runs on the sender's side. Anyone can run a Connector, relayer, indexer or regulated hop and earn fees, and every hop re-checks the sender's rules on-chain.
A k-of-n committee can certify networks for ISO 20022, MiCA and Energy, disable and re-enable a malicious route, and after an exploit blacklist an account so its routed funds go to a locked quarantine vault. It cannot change, pause or upgrade Routers, move funds anywhere but the vault, rewrite history or release vault funds to itself. Every action is public, signed and time-limited.
CLPR is the protocol: a Channel joins exactly two ledgers, which verify each other's proofs. CLPRouter is an application on top of CLPR, with no protocol change, that forwards a message hop by hop across Channels, returns a receipt and settles or refunds the sender's escrow.
CLPRouter is open source under the MIT licence, © 2026 ColdAI. CLPR itself is licensed separately under Apache-2.0 by LF Decentralized Trust.
ColdAIPushing Humanity Forward
CLPR is a project of LF Decentralized Trust. Network names and logos belong to their owners and identify the networks only. The route planner above is an illustrative example. Talk to ColdAI