Skip to main content
This page specifies the Sei Giga protocol as defined in the Giga whitepaper v2.0 by Marsh, Landers, Jog, and Ranchal-Pedrosa (June 2026). It also includes implementation notes from the sei-chain v6.6 release and its Sei Mainnet activation (August 2026). The specification below is forward-looking and subject to change until the corresponding upgrades activate on the Sei network. For a conceptual introduction, start with the Sei Giga overview. For practical guidance, see the developer guide.

Protocol at a glance

Network and security model

The equations in the whitepaper use a replica-count model with n = 3f + 1, of which at most f replicas are Byzantine. The sei-chain implementation applies stake-weighted voting thresholds. When you reason about the live network, do not interpret f as a raw validator count. Under the whitepaper’s fault and cryptographic assumptions, even an extended network delay does not allow two conflicting proposals to receive valid commit certificates. The network may pause during a disruption and resume when message delays return within the protocol’s timing bounds.
  • Safety: no two conflicting proposals can both obtain a valid commit certificate in the same consensus slot. Attesting to two different divergence digests for the same finalized block will be slashable equivocation. This is because quorum intersection guarantees that at least one honest validator would have to sign both.
  • Censorship resistance: when a proposal reaches the availability threshold, at least one honest replica stores its data under the stated assumptions. The threshold is f + 1 replicas in the whitepaper model and stake-weighted in the implementation. A correct leader must then include the proposal in a future cut. This is designed to limit censorship to a finite delay. Users will also be able to submit a transaction to multiple validators at once (deduplicated at merge, with a partial tip refund).
  • Execution divergence: divergence below one-third of voting power can be isolated. Divergence beyond the Byzantine threshold is designed to pause the chain.
  • Staking: validators will continue to bond SEI and can be slashed for malicious behavior. The complete slashing schedule, reward functions, and tokenomics for Giga are deferred to future work. For today’s staking parameters, see Staking.

Consensus: Autobahn

Sei Giga will order transactions with Autobahn (Giridharan, Suri-Payer, Abraham, Alvisi, and Crooks, 2024), a BFT protocol that decouples data dissemination from ordering. The paper positions it between view-based and DAG-based protocols. View-based protocols (HotStuff, Tendermint) can stall during network “blips.” DAG-based protocols (Narwhal-style) can add good-case latency. Under the paper’s evaluated conditions, Autobahn combines an asynchronous data layer with partially synchronous ordering and reports DAG-class throughput at roughly half the latency.

Data dissemination: lanes and Proofs of Availability

  • Every validator r will maintain its own lane: an append-only, hash-chained sequence of transaction batches (called cars). A proposal is the tuple Prop = ⟨pos, batch, parentRef⟩, signed by r. Here, pos is the lane sequence number, and parentRef is the hash of the previous proposal in the same lane.
  • Validators that receive a proposal will verify that it extends the lane correctly and return a signed vote over its digest. When the proposer collects f + 1 matching votes, it will assemble a Proof of Availability (PoA), a certificate that the data is retrievable.
  • f + 1 is enough because any such quorum contains at least one correct replica that held the full data when it voted. That replica serves the data until all correct replicas have it. Giga’s design deliberately keeps the smaller quorum (instead of 2f + 1) because commitment itself triggers full replication along the execution path. A larger quorum would only add certification latency.
  • The latest proposal in a lane that holds a PoA is the lane’s tip. Lanes are hash-chained, so certifying a tip implicitly attests the availability of every earlier proposal in that lane. Earlier entries do not need to be certified again.
All validators will disseminate batches in parallel without waiting for consensus. The design aims to move dissemination off the ordering critical path and use aggregate validator bandwidth instead of one leader’s uplink. Actual bottlenecks depend on workload, network conditions, and implementation limits.

Ordering: cuts of tips

Consensus will periodically fix a global order by committing a cut, a vector of every lane’s current certified tip:
  1. Prepare. The slot’s leader (chosen by stake-weighted selection, as in Tendermint) will bundle the latest certified tips into a cut proposal. Replicas will validate the PoAs and broadcast prepare votes. At n - f votes, these votes form a PrepareQC.
  2. Commit. Replicas will exchange commit votes over the PrepareQC. In the whitepaper’s replica-count model, a CommitQC formed from n - f votes finalizes the cut.
  3. Pipelining. Slots will overlap. As soon as replicas see the Prepare message for slot s, they can begin slot s + 1. The next leader may start proposing while the previous cut is still in its commit phase. With quadratic communication and pipelining, the design targets an effective steady-state cadence of one committed cut per 1.5 network round trips. Tendermint uses three full rounds. This cadence is not a per-transaction finality guarantee.
Committing one cut will finalize every uncommitted proposal in every lane up to the referenced tips. A single consensus decision can therefore commit many blocks’ worth of data at once. For this reason, the whitepaper anticipates roughly 70 times higher block production than the single-proposer design (180 versus 2.5 blocks per second). Validators will vote on compact certificates only. A replica that is missing batch data will fetch it after commit, off the critical path.

Leader failure and recovery

If a leader fails to make progress, replicas will fall back to a standard view change. A timeout certificate will elect a new leader, and the protocol will resume. Lane dissemination is designed to continue during the view change. This confines most of the disruption to ordering latency. The Autobahn paper calls this “seamless” recovery from blips and contrasts it with the post-asynchrony recovery cost of chained-HotStuff-style protocols. Two consensus upgrades beyond launch are already specified:
  • Ambulance (arXiv 2606.25099) replaces the timeout race with a “protocol-rigged race” among replicas. Non-leader replicas do useful persistence work in parallel on candidate cuts built from the same certified tips. If a leader is only slow (I/O contention, garbage collection, routing trouble), the slot can finish from existing recovery state. It does not have to wait for a full timeout. Ambulance is planned as a core part of a future upgrade.
  • Hermes is a next-generation consensus protocol on the official roadmap. Its whitepaper has not been published yet.

Execution

Two finality notions

Giga will separate what consensus decides from what execution produces: Unless stated otherwise, latency claims in Giga materials refer to ordering finality. Under the protocol’s stated fault and cryptographic assumptions, ordering finality fixes the transaction sequence. State attestation finality adds a BFT-signed confirmation of the execution results. Execution happens between these two protocol signals. A receipt becomes available only after a node executes the ordered transaction. Ordering finality alone does not give an execution result.

Deterministic block transition

For each finalized block, the protocol specifies the canonical transition Apply(S_prev, context, block) → (S_new, receipts, gas, writeLog). Given the same pre-state, block context, ordered transactions, execution semantics, and serializable parallel schedule, conforming executors should derive byte-identical results without communicating. A transaction revert is itself an execution result and does not invalidate the rest of the block. Because of this intended determinism, execution can run off the consensus critical path. The execution client is deliberately narrow. It processes transactions and nothing else, with no tracing or log search on the hot path. Incoming blocks are pre-processed in parallel (parsing, sender recovery, signature verification), while exactly one block executes at a time. Receipt generation and indexing happen after execution, so block n + 1 can start while block n post-processes.

Parallel execution: Block-STM-style OCC

Within a block, transactions execute concurrently under optimistic concurrency control (the Block-STM approach):
  • A later transaction t_j depends on an earlier t_i when t_i’s write set overlaps t_j’s read or write set. The block’s total order keeps this dependency relation acyclic.
  • All transactions start to execute in parallel, and each buffers its writes privately. For each transaction, a validation phase checks whether any earlier-ordered transaction committed a write into its read or write set after it began. Conflicting transactions are rolled back and re-executed.
  • The committed result is provably identical to sequential execution in block order (a “valid parallel schedule”). When contention is low, most transactions commit on their first attempt. Under sustained contention, the engine may fall back to sequential execution with unchanged semantics. In sei-chain, the scheduler retries a transaction up to 10 times before it falls back to the sequential path.
Sei Labs measured that 64.85% of historical Ethereum transactions could have been parallelized under this model. Contract-design guidance for maximizing parallelism is in the developer guide.

Transaction encoding

Giga will replace nested RLP with a flat, length-prefixed encoding designed for single-pass, zero-copy decoding:
  • Fields (type, chain ID, sender, recipient, value, nonce, gas limit, signature, access list) appear in a fixed order.
  • Variable-length fields carry a one-byte length prefix.
  • A marker byte signals contract creation.
  • All remaining bytes are the calldata.
A parser reads each transaction in one pass, with no allocation-heavy tree construction. This matters at decode rates of hundreds of thousands of transactions per second.

EVM compatibility

Sei Giga’s EVM will be mostly equivalent to Ethereum mainnet. You will write contracts in standard Solidity or Vyper and deploy them with standard tooling.

Fee model

Storage

Giga’s storage layer is designed for petabyte-per-year data production at full 5-gigagas load, while validator hardware stays practical.

Flat state, RAM-first

  • Every account, storage slot, and global variable will map directly to an entry in a log-structured merge (LSM) tree. Writes will skip per-write Merkle path updates entirely. Flushes will therefore stay batched and sequential, and nothing will be re-hashed on the write path.
  • Frequently accessed state will be held in RAM, and reads will be served from memory in the common case. All disk writes will be asynchronous and will exist for durability only. An append-only write-ahead log (WAL) will protect them and will be replayed on crash recovery.
  • Storage will be tiered. Recent and hot data will sit on local high-performance SSDs. Historical data will move to a distributed columnar store built for analytical queries and audit workloads.

Lattice-hash divergence digests

There will be no state root. Instead, Giga will commit to execution results with a homomorphic multiset hash (LtHash, by Lewi, Kim, Maykov, and Weis): LH(X) = Σ h(x) mod q. Its collision resistance rests on lattice assumptions (short integer solution style). For each block n:
  • The committed multiset X_n will contain one record per surviving write (after intra-block last-write-wins resolution). It will also contain one record per transaction receipt (position-bound) and one gas-accounting record. Each record will be domain-separated by type tag and height.
  • The block digest is d_n = LH(X_n). Validators will attest to the compact commitment D_n = H(enc(n, d_n)). The full vector d_n will be exchanged only during disputes.
  • Disputes will resolve by bisection. The key space partitions into ranges whose chunk digests sum to the write component of d_n by construction. Divergent executors will therefore compare chunk digests and narrow the search. They will replay only the affected range to find the first divergent write, receipt, or gas discrepancy.
The homomorphism makes this practical. Digests update incrementally as writes commit, in any order, and no tree walk is involved.

Block Update Digests (BUDs)

BUDs will restore externally verifiable state proofs (the role eth_getProof plays on Ethereum). Their cost will be proportional to per-block update volume, not total state size:
  • Every state entry will carry an 8-byte last-modified height and a 1-byte serialization version. For each block n, the BUD U_n is the Merkle root over the lexicographically sorted leaves (key, newValue, n, prevHeight) of that block’s writes. Validators will attest U_n on the same delayed two-thirds voting-power schedule as the divergence digest.
  • A membership proof will be a Merkle path to an attested U_n. It will certify that key held value immediately after block n. It will also record when the key previously changed. Two proofs at heights a < b whose b-leaf records predecessor a will prove that the key was unmodified throughout (a, b).
  • SuperBUDs will aggregate BUDs over exponentially growing aligned windows (branching base e and maximum level L_max, both governance parameters). Provers will then cover long ranges with logarithmically many digests. The guaranteed proof window will be η = e^L_max blocks. Archive nodes can serve older claims, but those claims fall outside the protocol guarantee.
  • Touch transactions will rewrite only a key’s last-modified metadata. This will give long-untouched keys a fresh proof anchor. Deletions will leave tombstones, which anchor exclusion proofs and are garbage-collected after η.
  • At the activation height, a one-time synthetic write log will bootstrap every existing key. The system will reach steady state after η blocks. BUD trees deliberately use a classical hash, because the short proof window keeps classical collision resistance sufficient. The trees will also fall under the same post-quantum migration schedule as the rest of the protocol.
Light clients, bridges, and any external verifier will consume BUD proofs against attested digests instead of Merkle-Patricia proofs against a state root.

Networking and transaction ingress

  • Nodes will communicate over direct, authenticated point-to-point connections instead of network-wide gossip. Consensus messages, lane proposals, votes, and certificates will stream over dedicated channels with per-channel rate and size limits.
  • There will be no traditional public mempool. Before Sedna activates, RPC nodes will route complete signed transactions into validator lanes. After the later Sedna milestone activates, ingress will distribute coded symbol bundles across selected lanes. In the current implementation, EVM senders map deterministically to a validator shard. The implementation proxies eth_sendRawTransaction and pending-nonce queries to that shard’s owner.
  • For censorship resistance, users will be able to submit the same transaction to multiple validators. Admission will be rate-limited: each validator will include at most one copy of a given transaction per epoch. Duplicates will be dropped deterministically at merge time, and only one copy will execute. Unexecuted duplicates will pay the distribution fee and earn a partial tip refund.
  • Four node roles will exist:
    • Validators will run consensus and execution.
    • Full nodes will run RPC plus execution for the read path.
    • Light nodes will run RPC only.
    • Data nodes will serve recent data.

Sedna: private dissemination

Sedna is planned as Giga’s private dissemination layer, a later roadmap milestone after Autobahn mainnet. Senders would encode a committed transaction payload into verifiable rateless coded symbols and send addressed bundles to selected proposer lanes. Executors would reconstruct the payload after finalized symbols cross the decode threshold. The paper calls this “until-decode privacy.” Its guarantees depend on the coding parameters and the number of colluding lanes. The Sedna paper compares the design with threshold-encrypted mempools. It argues that the design can give similar pre-execution privacy without an extra decryption round, and with less per-lane bandwidth. The companion incentive mechanism PIVOT-K would concentrate a sender-funded bounty on bundles that trigger decoding and ratchet away from lanes that withhold.

MEV and fee design

Multi-Proposer architectures remove the single block-builder’s private ordering monopoly. However, they introduce their own MEV (maximal extractable value) channels, formalized in MEV in Multiple Concurrent Proposer Blockchains. These channels are same-tick duplicate stealing, proposer-to-proposer orderflow deals, and timing races around PoA latency. Same-tick duplicate stealing means copying a visible transaction into your own lane to win the merge. Giga’s countermeasures will live at the protocol level.

Deterministic merge rule

For each committed cut, every node will derive the executable sequence with the same pure function:
  1. Take each lane’s newly committed transactions, meaning those not in any previous cut, in their intra-lane order.
  2. Sort lanes in descending order of the maximum priority fee among their new transactions. Break ties by replica index.
  3. Concatenate the lanes and deduplicate by transaction hash. Only the first occurrence survives.
The merged order is designed to depend only on finalized lane contents, not on arrival timing, wall clocks, or a node’s post-consensus discretion. This is intended to reduce the opportunities for post-consensus reordering at the protocol level.

Socialised tips

All priority fees collected in an epoch (net of duplicate refunds) will be pooled. They will be distributed to validators pro rata by stake × liveness. Liveness will be the measured fraction of observable duties performed: consensus votes included in committed QCs, certified lane blocks produced, and signed state attestations. Governance will set the duty weighting. Payouts will be shared with delegators in the same way as block rewards.
  • Under the proposed fee design, copying a high-tip transaction into another lane would not capture its fee. This is intended to reduce the protocol-level revenue motive for duplicate stealing.
  • Validator revenue from the protocol would be independent of orderflow routing. This would reduce the protocol-level incentive to steer users to specific proposers.
  • Withholding or lazy participation will directly reduce a validator’s payout.
The whitepaper summarizes the design this way: the priority fee will buy ordering, not a relationship with a particular proposer. Side payments for intra-lane position are out of protocol scope for now and belong to the forthcoming fee-mechanism work.

Post-quantum migration

The proposed Giga architecture includes a survivability path for a sudden ECDSA break (“Q-day”) that is designed to avoid a chain-wide account reset:
  • Before a governance-set cutoff height, any account will be able to register a post-quantum verification key. The registration (scheme identifier, PQ public key, migration nonce, optional activation height) will be signed with the account’s current classical key.
  • During the transition window, the chain would accept classical or dual classical+PQ signatures. After the cutoff, accounts that had not registered a post-quantum key could no longer authorize transactions with their existing ECDSA key. The proposed path does not include public-key recovery or new classical EOAs after that point. Onboarding would continue through pre-registration, contract wallets, or a later native PQ account format.
  • The designated short-term scheme is ML-DSA (FIPS 204). The whitepaper states explicitly that this is an emergency path and is not fast enough for Giga’s throughput. Post-quantum cryptography at Giga scale is open research.

Performance claims and targets

The whitepaper publishes no fixed block gas limit, block size, or validator hardware specification for Giga. The roadmap’s Autobahn testnet milestone includes the final consensus specification. Figures you may see for today’s network (block times, gas limits) describe the current architecture, not the anticipated architecture under Giga.

Implementation snapshot (Sei v6.6 activation, August 2026)

Giga is implemented in the open in sei-protocol/sei-chain. There is no separate Giga repository. The mandatory v6.6 release brought the first Ares and Eidos components to Sei Mainnet at height 224201091 on August 4, 2026. Ares became the default execution path for upgraded nodes. Eidos migration remains phased and operator-controlled. Broader work continues, and later Giga components remain inactive: For exact keys and defaults, node operators should follow the node configuration reference, not this page.

Glossary

References

Disclaimer: The roadmap is subject to change based on development progress, market feedback, and other factors. Actual timelines, figures, and outcomes may vary.
Last updated August 2026, based on the Giga whitepaper v2.0 (June 29, 2026), the sei-chain v6.6 release, and the Sei Mainnet v6.6 activation.