Capacity & sizing
How much satellite do we actually need to buy?
This page does the arithmetic in public. It starts from the ledger's own numbers, derives the compute, power, storage and bandwidth one orbital node requires, checks that envelope against the published specifications of real third-party cubesat platforms, and ends with how many nodes and how much rented capacity each phase of the network needs.
Scope of the orbital tier
Put in orbit only what has to be in orbit.
The economics of this network depend on a narrow definition of the orbital workload. Everything below is what a node does — and, just as importantly, what it does not.
Checkpoint validation
Continuous, low duty cycleVerify the aggregate signature over each 10-second checkpoint and counter-sign it. This is the notarisation product: proof that a batch of transactions existed at a time, witnessed off-planet.
Store-and-forward transaction relay
Burst during passesAccept signed transactions from wallets and Connectivity Boxes with no terrestrial path, hold them, and inject them into the network on the next contact.
Independent time and position witness
Per checkpointAttach a GNSS-disciplined timestamp and orbital state to each anchor, so the record cannot be back-dated by anyone holding terrestrial infrastructure.
Cold survival copy of the chain head
Write-mostly archiveHold a pruned, self-verifying copy of the checkpoint chain so the ledger can be reconstructed after a terrestrial loss event.
Deliberately not in orbit
- Full transaction execution at peak throughput — terrestrial validators carry the peak; orbit carries the proof.
- The full historical archive — an unpruned chain grows at roughly 100 GB per day at design throughput and belongs in SuperFile Cloud.
- Customer-facing latency — a payment confirms terrestrially in seconds and is anchored in orbit afterwards.
- Heavy AI inference — that moves to orbital data-centre capacity only when it can be rented, in a later phase.
The ledger arithmetic
From transactions per second to bytes and watts.
Each row is an explicit planning assumption. Change one and the numbers below it move; nothing here is asserted without the calculation that produced it.
| Quantity | Value | How it is derived |
|---|---|---|
| Signed transaction, post-quantum | ≈ 2.8 kB raw / ≈ 300 B batched | A Dilithium-2 signature is 2,420 bytes. Inside a checkpoint, signatures aggregate and the per-transaction cost falls to roughly 300 bytes. |
| Design throughput, whole network | 5,000 tx/s sustained, 17,000 tx/s burst | Sustained figure is the planning number for the network as a whole across terrestrial and orbital validators. |
| Share of traffic routed via satellite | 5% ≈ 250 tx/s | Only users with no terrestrial path use the orbital relay. This is the number that sizes the radio, and it is small. |
| Relay bandwidth needed | ≈ 0.6 Mbps aggregate | 250 tx/s × 300 B ≈ 75 kB/s. A single S-band link at 2 Mbps carries the entire orbital relay load with margin. |
| Checkpoint rate and size | 8,640 / day × ≈ 4 kB | One checkpoint every 10 seconds: header, Merkle root and aggregate signature. Roughly 35 MB of chain state per node per day. |
| Pruned chain growth per node | ≈ 12.6 GB / year | Checkpoint chain only. Ten years of anchors is about 126 GB — one radiation-tolerant NAND module. |
| Rolling transaction cache | ≈ 45 GB (7 days) | 250 tx/s × 300 B held for a week, so a node can serve replay to a region that has been offline. |
| Storage specified per node | 256 GB | Pruned chain plus cache plus wear and redundancy margin. Well inside a single 1U slice. |
| Signature verification load | ≈ 0.5 CPU core at peak | A 1.5 GHz ARM core verifies on the order of 10,000 Dilithium signatures per second; a checkpoint of 50,000 transactions verifies in well under a second. |
One node, itemised
The resulting hardware envelope. This is the specification we take to a hosting provider.
Compute
Quad-core rad-tolerant ARM SoC, 4 GB ECC RAM
6 W average
Crypto acceleration
FPGA lattice-signature core (optional in phase 1)
2 W average
Storage
256 GB rad-tolerant NAND, triple-redundant metadata
1 W average
Radio use (payload share)
S-band, ≈ 2 Mbps during contact
8 W peak, duty-cycled
Thermal and margin
Conductive path to bus radiator, 30% reserve
1 W
Node total
≈ 1.2 kg, ≈ 1.5U (100 × 100 × 150 mm)
10 W orbit-average, 18 W peak
Orbit-average power of 10 W is about 240 watt-hours a day — comfortably inside the generation of a 6U bus with deployable panels, and a fraction of a 16U bus.
The result
The node fits inside every platform we would want to fly on.
10 watts, 1.2 kilograms and 1.5U against buses that publish 10–60 watts and 7–24 kilograms of payload capacity. The margin is the point: it means we are a welcome, low-risk tenant rather than a demanding one.
Platform fit
What each third-party platform could carry.
Capability figures are taken from public supplier datasheets and product pages current in 2026, and are indicative rather than contractual. Node counts assume the 10 W / 1.5U envelope above with 30 percent reserve.
Spire — LEMUR 3U software slot
Best first step5–10 W payload power · software-defined slot · no hardware to build
1 node
Fits the 10 W node with nothing to launch. Spire's Space as a Service sells exactly this: your flight software on their existing satellite. This is the cheapest credible first node and the natural way to re-fly the 2020 signature.
Spire — LEMUR 16U configuration
Scale-up on the same busUp to 24 kg / 16U class · high-rate downlink · on-orbit processing
3–4 nodes
Enough power and volume to host a redundant node pair plus the store-and-forward cache. Same operator as the 3U slot, so one integration effort covers both.
EnduroSat — 6U platform
Comfortable10–30 W average payload power · 7.2–7.8 kg · 197 × 197 × 225 mm
1–2 nodes
A commodity bus with a published interface document. One node uses a third of the available power and under a quarter of the payload volume, which leaves headroom for the radio and a second cold node.
EnduroSat — 16U platform
Best capacity per satellite25–60 W average payload power · 24 kg payload · 218 × 218 × 254 mm · up to 1 Gbps payload downlink
3–5 nodes
The most headroom per pound in the cubesat class. A gigabit-class downlink makes bulk archive sync possible, not just checkpoint anchoring, and there is power left for an inference accelerator later.
Loft Orbital — Hub on YAM / Longbow
Lowest execution riskESPA-class bus · standardised Hub payload interface · mission-managed operations
4–8 nodes
Our node ships as a qualified module against a documented interface, and Loft flies and operates it. Highest capacity per bus, and the route that removes the most programme risk — at a higher fixed price.
D-Orbit — ION carrier
Demonstration onlyHosted payload slots on an orbital transfer vehicle
1 node
A months-long in-orbit demonstration without committing to a bus. Right for proving the node, wrong for permanent capacity because ION missions are finite.
Iridium — Certus 9704 (ground side)
Wallet uplinkPole-to-pole messaging · tens of kbps · hosted-payload heritage on all 66 satellites
n/a — user link
Not a place to host the ledger, but the cheapest way for a wallet to reach it: a 300-byte batched transaction crosses a Certus link in a fraction of a second, anywhere on Earth.
Starlink / OneWeb / Amazon Leo
Bought connectivityMbps to Gbps ground backhaul, bought as a service
n/a — backhaul
These are the pipes for Connectivity Boxes and ground stations. We buy transit; we do not host nodes on them.
How many satellites
Coverage geometry, then consensus, then cost.
The instinct is to size the constellation from coverage. For an anchoring network that is the wrong starting point, and it is the difference between a $30M programme and a $6M one.
One satellite sees a 1,160 km circle
At 550 km altitude with a 25° minimum elevation mask, the usable ground footprint is roughly 580 km in radius. That is the geometric fact everything else follows from.
Continuous equatorial coverage would need ~35 satellites
The equator is 40,075 km around. Filling it continuously from a single low-inclination plane takes on the order of 35 spacecraft — a constellation programme, not a first raise.
Anchoring does not need continuity — it needs availability
A payment settles terrestrially in seconds and is anchored afterwards. With 8 satellites at ~20° inclination, an equatorial site gets 12–16 contacts a day and a worst-case gap under two hours, which meets the anchoring latency budget with room to spare.
Consensus sets the floor, not coverage
Byzantine fault tolerance needs 3f+1 nodes: 4 to survive one failure, 7 to survive two. Nodes must sit on independent buses, because two nodes on one satellite fail together. Eight nodes on eight buses is the smallest configuration that is genuinely fault-tolerant.
Four configurations, priced
Costs combine the node envelope above with published hosted-payload and rideshare pricing. They are planning ranges for the capital plan, not quotations, and every configuration is fundable on its own.
| Configuration | Nodes | What we buy | Indicative cost | What it gives us |
|---|---|---|---|---|
| A — Demonstration | 1 node | 1 software slot (Spire) or one ION mission | $0.2M – $0.6M one-off | Re-flies the 2020 in-orbit signature with post-quantum signing. No launch, no hardware, no constellation. |
| B — Minimum fault-tolerant quorum | 4 nodes | 4 software slots across 2 operators | $1.0M – $2.2M + ≈ $0.3M / yr | Survives one node loss. Enough to issue commercially meaningful notarisation with an orbital witness. |
| C — Equatorial anchor cluster | 8 nodes on 8 independent buses | Mixed: 4 software slots + 4 hosted modules on 6U/16U buses | $6M – $12M + ≈ $0.6M / yr | Survives two simultaneous failures, 12–16 contacts per day over the tropics. This is the target configuration of the plan. |
| D — Continuous coverage | 24–35 nodes | Dedicated and shared satellites, replenished from an equatorial range | $30M+ | Only funded once traffic, sovereign contracts and unit economics prove ownership beats renting. |
Rented capacity
Ground time and bandwidth, bought by the minute.
The orbital tier moves very little data, which is why the ground segment is a subscription rather than a construction project.
Downlink volume per satellite
≈ 250 MB / day
Checkpoint chain plus relayed transactions plus housekeeping. Tiny by Earth-observation standards, which is why pass time is cheap for us.
Contact time required
≈ 17 min / satellite / day
250 MB at 2 Mbps S-band. Spread over 4–6 short passes for latency, not for volume.
Ground segment cost, cluster C
$0.3M – $0.8M / yr
Leased pass time from commercial ground-station-as-a-service networks plus a software mission-operations centre. No teleport is built.
Terrestrial capacity per Connectivity Box
$50 – $250 / month
Starlink, OneWeb or Iridium transit sized to the site. Scales with revenue, not ahead of it.
Cost per anchored checkpoint
fractions of a cent
Cluster C runs 8,640 checkpoints a day. Against roughly $1.0M a year of orbital operating cost, each anchor costs well under a cent — and each anchor covers up to 50,000 transactions.
Sensitivity
What breaks the model, and what does not.
The sizing is deliberately conservative. These are the four assumptions most likely to be wrong, and what each one would actually cost us.
If satellite-routed traffic is 4× our estimate
1,000 tx/s over the relay is 2.4 Mbps. It fits the same S-band radio at a higher duty cycle and adds pass minutes, not satellites.
If post-quantum signatures get larger
Storage and bandwidth scale linearly and are both an order of magnitude below platform limits. A 3× signature growth still fits a 6U bus.
If a supplier withdraws
Every fit in the table above is met by at least three unrelated suppliers. The node is specified against a power and volume envelope, not against one vendor's bus.
If launch prices stop falling
Configurations A and B need no launch at all — they are software on satellites already in orbit. Launch cost only enters at configuration C.
Sizing FAQ
The engineering questions investors ask.
How can a whole blockchain run on 10 watts?
Because the orbital node does not run the whole blockchain. It validates and counter-signs one checkpoint every ten seconds and relays a few hundred transactions a second. Verifying a lattice signature costs on the order of a hundred microseconds of CPU time; the workload is tiny compared with the imaging and radar payloads these same buses fly every day.
Why 8 satellites rather than a full constellation?
Eight independent buses is the smallest configuration that tolerates two simultaneous node failures under Byzantine fault tolerance, and at ~20° inclination it already gives every equatorial site 12–16 contacts a day. Continuous coverage needs roughly 35 spacecraft and buys latency we do not need, because settlement happens on the ground in seconds and orbit anchors it afterwards.
Where do the platform numbers come from?
Public supplier datasheets and product pages as of 2026 — EnduroSat's 6U and 16U platform specifications, Spire's LEMUR and Space Services material, Loft Orbital's Hub interface documentation and Iridium's Certus module data. They are indicative planning figures, not quotations, and any real mission would be sized against a signed interface control document.
Is storage a problem after ten years?
No. The orbital node keeps a pruned, self-verifying checkpoint chain — about 12.6 GB a year. Ten years of anchors fits in 126 GB. The unpruned archive, which grows around 100 GB a day at design throughput, lives in SuperFile Cloud across sovereign terrestrial regions.
What is the cheapest path to a real, useful orbital node?
A software slot on a satellite that is already flying. No bus, no launch, no licence of our own, and a cost measured in hundreds of thousands rather than millions. Configuration A can be contracted and flown without any of the constellation capital in the plan.
Sources and basis: EnduroSat 6U and 16U platform specifications; Spire LEMUR platform and Space Services material; Loft Orbital Hub payload interface documentation; D-Orbit ION hosted-payload material; Iridium Certus 9704 module data; published rideshare pricing. All figures on this page are planning estimates derived from public information as of 2026 and are not quotations, offers or contractual commitments.




