Launch · Submitted to LF Decentralized Trust's CLPR project for review (opens in a new tab)

Bridgeless.Hedera, connected.

CLPR lets ledgers verify each other with cryptographic proofs instead of bridges. ColdAI has submitted open-source verifier code that connects 87 networks to Hedera, and built CLPRouter so a message or payment can travel from any network to any other, through Hedera.

networks with verifier code
87
verified on live data
60
architecture families
6
routing modes
5
compliance filters
3

01What is CLPR

Ledgers that check each other

CLPR, the Cross-Ledger Protocol (say “clipper”), lets two ledgers exchange messages by verifying each other's state proofs directly. No bridge sits in the middle: no outside validators to trust, no pool of locked funds.

  • Created by the team behind Hedera (Hashgraph)
  • Donated to LF Decentralized Trust
  • Open source, built in the open
  1. 1Queue

    An app sends a message. The sending ledger's CLPR Service adds it, in order, to the Channel's outbound queue.

  2. 2Prove

    An endpoint relays a bundle of queued messages with a proof of the sending ledger's state: its finality and the queue entries in it.

  3. 3Verify

    The receiving ledger's verifier checks the proof on-chain, delivers each message in order and answers with a response.

CLPR on GitHub, at LF Decentralized Trust (opens in a new tab)

CLPR vs bridges

Bridges ask you to trust someone in the middle. When they fail, they fail big.

TopicBridgeCLPR
Who you trustBridgeMiddlemen: a small group of signers or an outside validator setCLPRDirect proofs of each ledger's own consensus, checked on-chain
Where the money sitsBridgePooled, locked funds: one honeypot for attackersCLPRNo pooled liquidity in the protocol
Ordering and receiptsBridgeBest effortCLPREvery message arrives in order, with a receipt
If someone misbehavesBridgeUsers carry the lossCLPRSlashable stake: misbehaving puts their own stake on the line

0287 networks

87 networks, one hub: Hedera

To support Hedera and the whole Hiero ecosystem, ColdAI has submitted open-source CLPR verifier code for 87 networks, more than 85 of the top 100. Each verifier lets Hedera check that network's proofs itself.

60Verified on live data

The verifier checked real proofs from the network's mainnet or public testnet.

16Covered

Same verifier code as a live-verified network of the same family.

11In progress

Verifier code submitted; part of the proof path still waits on a public source or more work.

Submitted to LF Decentralized Trust's CLPR project for review; chain → Hedera direction. None of this is merged yet. The Hedera → chain direction waits on Hiero state proofs.

Family
Status

All 87 networks, A to Z

  • AbstractEthereum & L2sCoveredzksync-era
  • AlgorandMove & other ledgersVerified on live dataalgorand-state-proofs
  • AnubisBFT & PoS L1sCoveredbsc-parlia-fast-finality
  • Arbitrum NovaEthereum & L2sCoveredarbitrum-nitro-bold
  • Arbitrum OneEthereum & L2sCoveredarbitrum-nitro-bold
  • ArcBFT & PoS L1sVerified on live dataarc-malachite
  • AuroraBFT & PoS L1sCoveredaurora-near
  • Avalanche C-ChainBFT & PoS L1sVerified on live dataavalanche-warp
  • BaseEthereum & L2sCoveredopstack-dispute-game
  • Bifrost NetworkPolkadot & SubstrateVerified on live datagrandpa
  • BitcoinBitcoin & BTC L2sIn progressbitcoin-spv
  • Bitcoin CashBitcoin & BTC L2sIn progressbitcoin-spv
  • BittensorPolkadot & SubstrateVerified on live datagrandpa
  • BlastEthereum & L2sVerified on live dataopstack-output-oracle
  • BNB Smart ChainBFT & PoS L1sVerified on live databsc-parlia-fast-finality
  • BOBEthereum & L2sVerified on live dataopstack-dispute-game
  • BOT ChainBFT & PoS L1sVerified on live databsc-parlia-fast-finality
  • CantonMove & other ledgersIn progresscanton-attested-operators
  • CardanoMove & other ledgersVerified on live datacardano-mithril
  • CeloEthereum & L2sCoveredopstack-dispute-game
  • ChainflipPolkadot & SubstrateVerified on live datagrandpa-pallet-accumulator
  • ConfluxBFT & PoS L1sIn progressconflux-pos-bls
  • CoreBFT & PoS L1sVerified on live databsc-parlia-fast-finality
  • CronosCosmos & CometBFTVerified on live datacometbft-light-client
  • dYdXCosmos & CometBFTIn progresscosmos-module-cometbft
  • EthereumEthereum & L2sVerified on live dataethereum-sync-committee
  • EtherlinkEthereum & L2sIn progresstezos · EtherlinkCementedState
  • FlareBFT & PoS L1sVerified on live dataavalanche-warp
  • FraxtalEthereum & L2sVerified on live dataopstack-output-oracle
  • FuelEthereum & L2sVerified on live dataruntimes · FuelVerifier
  • Gnosis ChainEthereum & L2sVerified on live dataeth-beacon-twin
  • GRX ChainBFT & PoS L1sVerified on live datasigner-replay
  • HydrationPolkadot & SubstrateVerified on live databeefy-parachain
  • HyperliquidMove & other ledgersVerified on live datahyperevm-attestors
  • ICPMove & other ledgersVerified on live dataicp · IcpVerifier
  • Immutable zkEVMBFT & PoS L1sVerified on live datasigner-replay
  • InitiaMove & other ledgersVerified on live dataruntimes · InitiaMoveVerifier
  • InjectiveCosmos & CometBFTVerified on live datacometbft-light-client
  • InkEthereum & L2sCoveredopstack-dispute-game
  • KaiaBFT & PoS L1sVerified on live datakaia-istanbul
  • KatanaEthereum & L2sVerified on live dataopstack-output-oracle
  • KavaCosmos & CometBFTVerified on live datacometbft-light-client
  • KUB ChainBFT & PoS L1sVerified on live datasigner-replay
  • LineaEthereum & L2sVerified on live datazkrollup · LineaRollupVerifier
  • MantleEthereum & L2sVerified on live dataopstack-output-oracle
  • MANTRACosmos & CometBFTVerified on live datacometbft-light-client
  • MegaETHEthereum & L2sVerified on live dataopstack-dispute-game
  • MezoCosmos & CometBFTVerified on live datacometbft-light-client
  • MixinMove & other ledgersVerified on live datamixin-kernel
  • MonadBFT & PoS L1sVerified on live datamonadbft
  • MorphEthereum & L2sVerified on live datazkrollup · L1RollupMptVerifier
  • MultiversXMove & other ledgersIn progressicpmvx · MvxMetachainVerifier
  • NEARBFT & PoS L1sVerified on live datanear-light-client
  • OP MainnetEthereum & L2sCoveredopstack-dispute-game
  • OsmosisCosmos & CometBFTCoveredcosmwasm-cometbft
  • PlasmaBFT & PoS L1sVerified on live dataplasmabft-committee
  • PlumeEthereum & L2sVerified on live dataarbitrum-nitro-bold
  • Polygon PoSCosmos & CometBFTVerified on live datapolygon-pos-heimdall
  • ProvenanceCosmos & CometBFTVerified on live datacosmwasm-cometbft
  • PulseChainEthereum & L2sVerified on live dataeth-beacon-twin
  • ReyaEthereum & L2sCoveredarbitrum-nitro-bold
  • RISEEthereum & L2sVerified on live dataopstack-dispute-game
  • Robinhood ChainEthereum & L2sCoveredarbitrum-nitro-bold
  • RoninEthereum & L2sVerified on live dataopstack-dispute-game
  • RootstockBitcoin & BTC L2sVerified on live datarootstock-merged-mining
  • ScrollEthereum & L2sVerified on live datazkrollup · L1RollupMptVerifier
  • SeiCosmos & CometBFTCoveredcometbft-light-client
  • SolanaBFT & PoS L1sIn progresssolana-alpenglow
  • SoneiumEthereum & L2sCoveredopstack-dispute-game
  • StableCosmos & CometBFTIn progresscometbft-light-client
  • StacksBitcoin & BTC L2sVerified on live datastacks-signers
  • StarknetEthereum & L2sVerified on live datastarknet
  • StellarMove & other ledgersVerified on live datastellar-scp
  • STRATOBFT & PoS L1sIn progressstrato-blockstanbul
  • TelosBFT & PoS L1sCoveredantelope-savanna
  • TezosMove & other ledgersVerified on live datatezos · TezosVerifier
  • THORChainCosmos & CometBFTVerified on live datacosmwasm-cometbft
  • TONBFT & PoS L1sVerified on live dataton-light-client
  • TRONBFT & PoS L1sVerified on live datatron-dpos-attestor
  • UnichainEthereum & L2sVerified on live dataopstack-dispute-game
  • VaultaBFT & PoS L1sIn progressantelope-savanna
  • World ChainEthereum & L2sCoveredopstack-dispute-game
  • X LayerEthereum & L2sVerified on live dataopstack-dispute-game
  • XPR NetworkBFT & PoS L1sVerified on live dataantelope-dpos
  • XRP LedgerMove & other ledgersVerified on live dataxrpl-validators
  • ZIGChainCosmos & CometBFTVerified on live datacosmwasm-cometbft
  • ZKsync EraEthereum & L2sVerified on live datazksync-era

See the code for 87 networks (opens in a new tab)

03CLPRouter New

CLPRouter

Send anything from any network to any other — cheapest, fastest, most reliable or greenest — with ISO 20022, MiCA and energy filters.

A CLPR Channel joins exactly two ledgers. CLPRouter turns those Channels into a network: an application on top of CLPR, with no protocol change, that forwards a message hop by hop, sends a receipt back to the origin and settles or refunds the sender's escrow. A route is only as trusted as its weakest hop, and every hop re-checks the sender's rules on-chain.

Ethereum Hedera StellarOne Channel per ledger to the hub: 100 ledgers need 100 Channels, not 4,950 pairs.

Plan a route

Pick two networks, a mode and the rules your business needs, and watch the route trace through Hedera.

Interactive demo Illustrative example: figures and certifications are made up
Mode
Filters every ledger on the route must pass
hop 1 · CLPR Channelhop 2 · CLPR Channel
EthereumOrigin
HederaHub
StellarDestination
Cheapest route · 2 hops via HederaLowest total fees in one quote currency
Est. fees
$0.44
p90 time
52 s
On time
98.3%
Emissions
0.0013 kgCO2e

Filters: ISO 20022 · weakest hop sets the route's trust tier

pacs.002 · ACCC · Settled UETR carried end to end; receipt returned Stellar → Hedera → Ethereum

Example values only. In CLPRouter the planner runs on the sender's side over a route graph of measured gas and calldata, and every hop re-checks the rules on-chain. Today the Hedera → destination leg waits on Hiero state proofs.

How a route travels

Five steps, with the money held at the origin until a receipt comes back.

  1. 1SendOrigin Router

    The sender calls send() with the planned route, mode, filters, a deadline and an escrow. Before any value moves, the Router checks loops, hops, fees, disables, filters and the blacklist.

  2. 2ForwardEach hop, e.g. Hedera

    The message arrives over a CLPR Channel with its proof verified. The hop authenticates the previous Router, rejects replays, re-checks every rule, takes its fee and sends the next hop.

  3. 3DeliverDestination Router

    The destination Router hands the payload to the receiving app through onRouteMessage.

  4. 4ReceiptBack along the route

    A receipt (DELIVERED, FAILED, EXPIRED or QUARANTINED) travels the reverse path. The origin checks it came back the exact way the route went out.

  5. 5Settle, refund or quarantineOrigin Router

    Delivered: the payee and the hops are paid. Failed or expired: the escrow is refunded. A blacklisted party: the funds go to the locked quarantine vault.

Modes and filters

Choose how a route should travel, then add the rules every ledger on it must meet.

Cheapest

Lowest total fees in one quote currency: Connector margin, enqueue gas, the bundle share and execution gas.

Fastest

Lowest expected time to delivery, measured at the 90th percentile.

Most reliable

Best chance of on-time delivery at a trust floor, with a disjoint fallback route.

Greenest

Least estimated kgCO2e per message, from certified emissions figures.

Balanced

The default: a weighted score of cost, time, reliability and carbon.

ISO 20022 native

Payments speak the language banks already use. The payment's UETR is the route id and travels end to end; the payment message is encrypted to the destination institution, and only hashes and commitments go on-chain.

  • Messages: pacs.008 pacs.009 pacs.002 camt.056 pacs.004 camt.029
  • Each forwarded hop maps to pacs.002 ACSP
  • Receipts map back: DELIVERED → ACCC, EXPIRED → RJCT AB05, QUARANTINED → RJCT RR04

Decentralised by default

No operator runs the routes. A provider with a narrow, public role can stop an exploit, but cannot take funds.

Immutable Routers

No admin key, no pause, no upgrade. New versions are deployed beside old ones, and each route names the version every hop must run.

Open to every operator

Route planning runs on the sender's side. Anyone can run a Connector, relayer, indexer or regulated hop and earn fees.

Rules re-checked at every hop

Each hop authenticates the previous Router, rejects replays and re-checks filters, deadline, blacklist and fees before forwarding.

The provider can k-of-n signatures · public · time-limited

  • Certify networks for ISO 20022, MiCA and Energy
  • Disable, then re-enable, a malicious route
  • After an exploit, blacklist an account: its routed funds go to a locked vault

The provider cannot enforced in the contracts

  • Change, pause or upgrade Routers
  • Move funds anywhere but the quarantine vault
  • Rewrite history or swap the registry
  • Release vault funds to itself

A quarantine vault for exploits

If an exploit tries to move stolen funds, the blacklisted account's routed funds are stopped and held in a locked vault, and both parties get a notice. Releases go only to the original sender, the original recipient, or a recovery address named after a public notice and challenge window, never to a committee member. A blacklist entry lapses unless the committee renews it (30 days recommended).

For developers

Solidity Routers, a provider registry and a quarantine vault; a TypeScript planner SDK with an ISO 20022 module; and optional indexer, status, quote and forward services. MIT-licensed.

Release
Pre-release (0.1.0). Do not use with real funds.
Contracts, SDK, services
Built and tested locally (146 Foundry tests, plus SDK and service suites); testnet deployment in progress
Security
Two internal audits completed; findings are being fixed with regression tests. No external audit yet
Hedera → other ledgers
Waits on a Hiero state-proof source
Provider
A real committee, its key ceremony and a legal review of the quarantine vault come before mainnet
Licence
MIT. CLPR itself is Apache-2.0, from LF Decentralized Trust
Quote a route with the planner SDK
import { plan, sampleGraph } from "@clprouter/sdk";

// Ethereum → Hedera → Stellar, cheapest ISO 20022 route
const quote = plan(sampleGraph(), {
  origin: "eip155:1",
  destination: "stellar:pubnet",
  mode: "cheapest",
  filters: { iso20022: true },
  constraints: { maxHops: 3, deadlineS: 600 },
});

if (quote.ok) {
  const { ledgers, totals, effectiveTrustTier } = quote.route;
  // hops; cost, p90 time, success, kgCO2e; weakest hop
  console.log(ledgers, totals, effectiveTrustTier);
}

The planner adds no trust: a bad quote can make a route fail, but it cannot redirect funds.

04Next steps

Beyond blockchains

We're not stopping at blockchains. Next, we aim to connect Hedera to the systems the world already runs on.

Institutional payment rails

We aim to connect Hedera to the payment rails institutions already run, with ISO 20022 messages end to end.

Central-bank infrastructure

We aim to reach central-bank settlement infrastructure, such as the European Central Bank's Pontes initiative.

Private Hiero networks

We aim to link private Hiero networks to public Hedera through the same verified Channels.

Permissioned ledgers

We aim to bring permissioned enterprise ledgers into the same proof-checked routes.

05FAQ

Straight answers

What is ready, what is not, and who controls what.

Is this live?

Not yet. The verifier code for 87 networks is in open pull requests to LF Decentralized Trust's CLPR project, under review, and covers the chain → Hedera direction. The Hedera (Hiero) → chain direction waits on a Hiero state-proof source. CLPRouter is pre-release: built and tested locally, with testnet deployment in progress. Do not use it with real funds.

Is it audited?

CLPRouter has had two internal audits, and their findings are being fixed with regression tests. There is no external audit yet. The CLPR verifier pull requests are being reviewed by the CLPR project.

Who runs the router?

No one owns it. Router contracts are immutable, with no admin key and no pause, and new versions are deployed beside old ones. Route planning runs on the sender's side. Anyone can run a Connector, relayer, indexer or regulated hop and earn fees, and every hop re-checks the sender's rules on-chain.

What does the provider control?

A k-of-n committee can certify networks for ISO 20022, MiCA and Energy, disable and re-enable a malicious route, and after an exploit blacklist an account so its routed funds go to a locked quarantine vault. It cannot change, pause or upgrade Routers, move funds anywhere but the vault, rewrite history or release vault funds to itself. Every action is public, signed and time-limited.

What is the difference between CLPR and CLPRouter?

CLPR is the protocol: a Channel joins exactly two ledgers, which verify each other's proofs. CLPRouter is an application on top of CLPR, with no protocol change, that forwards a message hop by hop across Channels, returns a receipt and settles or refunds the sender's escrow.

What licence?

CLPRouter is open source under the MIT licence, © 2026 ColdAI. CLPR itself is licensed separately under Apache-2.0 by LF Decentralized Trust.

Bridgeless. Hedera, connected.

ColdAIPushing Humanity Forward

CLPR is a project of LF Decentralized Trust. Network names and logos belong to their owners and identify the networks only. The route planner above is an illustrative example. Talk to ColdAI