Blockchain Engineering Atlas
From state transitions to verifiable protocols.
An EVM-first atlas for protocols that modify shared state and assets under public, replicated, and adversarial execution — from ledger and bytecode to markets, proofs, settlement, and operations.
Follow every state change to settlement.
Start with replicated state and finality, trace EVM execution and storage, design contracts and signatures, prove invariants, then compose markets, L2 settlement, cross-chain messages, zero-knowledge proofs, and operations.
Prerequisites: Production software experience, TypeScript, basic distributed-systems and cryptography vocabulary, and willingness to reason about adversarial behavior. EVM internals and protocol economics are introduced progressively.
Statecraft Protocol · v0 → v11
A local/testnet-only protocol laboratory that grows from signed escrow into assets, accounts, governance, markets, lending, L2 messaging, proofs, and production operations. Every trust boundary stays visible.
State, signatures and escrow
- Modules
- Escrow · timeouts · pull payments · EIP-712
- Invariant
- A signed order executes at most once.
- New threat model
- Replay, reentrancy, stuck funds, timestamp boundaries.
- Artifact
- Signed Escrow and Commit-Reveal Auction specifications.
Asset layer
- Modules
- ERC-20 · permit · vesting · Merkle claims · membership
- Invariant
- Accounted assets equal valid minted and transferred supply.
- New threat model
- Non-standard tokens, fee-on-transfer, rebasing, allowance races.
- Artifact
- Merkle Distributor and safe asset adapter.
Programmable account
- Modules
- Batch calls · EIP-1271 · session keys · limits · recovery
- Invariant
- Delegated authority never exceeds its explicit scope.
- New threat model
- Module escalation, nonce confusion, malicious sponsorship, recovery capture.
- Artifact
- Modular Smart Account with a reproducible local flow.
Authority and governance
- Modules
- Roles · multisig · timelock · guardian · upgrades
- Invariant
- No governed action executes before its delay and authorization.
- New threat model
- Admin compromise, storage collision, governance capture, unsafe pause.
- Artifact
- Governed Treasury and immutable comparison.
Automated market maker
- Modules
- Pool · LP shares · swaps · fees · TWAP
- Invariant
- Adjusted reserves preserve the constant-product bound.
- New threat model
- Price manipulation, sandwiching, callback abuse, rounding leakage.
- Artifact
- Constant-Product AMM with manipulation lab.
Tokenized vault
- Modules
- Shares · previews · fees · strategy · emergency exit
- Invariant
- Every redeemable share maps to accounted assets under stated rounding.
- New threat model
- Donation and inflation attacks, loss concealment, queue insolvency.
- Artifact
- ERC-4626 Vault with a simulated strategy.
Lending and liquidations
- Modules
- Collateral · debt indexes · health · liquidations · bad debt
- Invariant
- Assets held cover accounted liabilities until an explicit insolvency state.
- New threat model
- Oracle manipulation, stale interest, bad debt, liquidation races.
- Artifact
- Collateralized Lending Market and local liquidator.
Oracle and automation layer
- Modules
- Feeds · staleness · deviations · circuit breakers · keepers
- Invariant
- Unsafe or unavailable prices fail closed and visibly.
- New threat model
- Stale data, decimals, sequencer downtime, fallback correlation.
- Artifact
- Oracle failure simulator and Verifiable Random Raffle.
Intent and auction execution
- Modules
- Signed intents · partial fills · solvers · batch settlement
- Invariant
- Fills respect authorization, remaining quantity, expiry, and slippage.
- New threat model
- Frontrunning, solver censorship, replay, surplus theft.
- Artifact
- Batch Intent Auction with ordering simulation.
L2 and cross-chain protocol
- Modules
- L1/L2 settlement · messages · per-chain accounting · recovery
- Invariant
- Each valid message changes destination state at most once.
- New threat model
- Finality mismatch, replay, bridge governance, partial failure.
- Artifact
- Cross-Chain State Mirror in a reproducible multi-chain lab.
Zero-knowledge extension
- Modules
- Circuit · membership proof · nullifier · Solidity verifier
- Invariant
- A valid credential proves eligibility without reusable disclosure.
- New threat model
- Under-constrained circuits, replay, toxic setup, metadata leakage.
- Artifact
- ZK Eligibility Registry with invalid-witness tests.
Production operations
- Modules
- Indexer · monitors · manifests · alerts · runbooks · drills
- Invariant
- Derived operational state reconciles with canonical on-chain events.
- New threat model
- RPC disagreement, missed reorgs, stale alerts, privileged drift.
- Artifact
- Protocol Operations Console and incident simulation.
Isolate the mechanism before integrating it.
Every project is local-only or testnet-only, names invariants and a threat model, and then feeds a Statecraft milestone.
Correctness is not the same as safety.
Every artifact distinguishes implementation, test evidence, invariant evidence, exploit history, patch status, audit status, and deployment environment.
Properties exercised
Stateful tests continuously exercise stated invariants; this is evidence, not an audit or proof of economic safety.
Authority disclosed
Owners, multisigs, timelocks, guardians, upgrade keys, oracle operators, and sequencers remain visible.
Research surface
Intents, interoperability, and proof systems carry dated status and explicit assumptions before integration.
No real funds
Every project runs on Anvil, controlled simulations, maintained testnets, or local forks with fake fixtures.
Trustless describes a bounded property, not the whole system.
Each component relocates trust; this table is a mental model, not a claim of uniform guarantees.
Different layers, different guarantees.
Execution, settlement, external data, derived state, and proofs solve different problems and carry different trust assumptions.
Orientation
Prerequisites, trust vocabulary, local/testnet-only policy, registries, and linear versus Statecraft-led reading paths.
Start Here
Scope, prerequisites, working method, and the safe path through the Blockchain Engineering Atlas.
Open branchMust Know
Non-negotiable mental models and safety rules for every protocol artifact in the atlas.
Open branchBlockchain Index
A map for engineering programmable state, economic protocols, proofs, settlement, and operations under adversarial execution.
Open branchLedger and Execution
Model replicated state, finality, EVM execution, gas, storage, and modular Solidity before composing financial behavior.
Blockchain State, Consensus & Finality
Replicated state machines, blocks, roots, consensus, fork choice, finality, data availability, reorgs, censorship, safety, and liveness.
EVM Execution, Gas & Storage
Bytecode, call frames, ABI, calldata, memory, persistent and transient storage, logs, reverts, opcodes, precompiles, and gas.
Solidity & Contract Architecture
Modern Solidity, state machines, composition, interfaces, libraries, deployment patterns, storage layout, and explicit module boundaries.
Standards, Identity and Authority
Treat tokens, signatures, smart accounts, roles, upgrades, and governance as explicit authority systems.
Tokens, Signatures & Contract Standards
ERC interfaces, approvals, permits, typed signatures, contract signatures, Merkle claims, replay protection, and hostile token behavior.
Smart Accounts & Wallet UX
EOAs, contract wallets, ERC-4337, EIP-7702, session keys, passkeys, sponsorship, recovery, permissions, and delegation risk.
Access Control, Upgrades & Governance
Roles, multisigs, timelocks, guardians, emergency powers, proxies, immutable alternatives, governance capture, and admin-key risk.
Correctness and Adversarial Engineering
Specify properties, fuzz state transitions, reproduce exploits, patch assumptions, and keep regression evidence.
Testing, Fuzzing & Formal Methods
Unit, fuzz, stateful, invariant, fork, differential, symbolic, SMT, model-based, gas, and failure-injection testing.
Smart Contract Security & Exploit Labs
Technical and economic exploits, vulnerable assumptions, exploit tests, patches, regression tests, incident containment, and limits of fixes.
On-chain Markets and Finance
Build accounting-first AMMs, lending, vaults, oracles, stable assets, and liquidation mechanisms with economic invariants.
Automated Market Makers & Liquidity
Constant-product pools, LP shares, fees, slippage, arbitrage, TWAP, concentrated liquidity, routing, hooks, and manipulation.
Lending, Collateral & Liquidations
Index accounting, utilization, LTV, health factors, liquidation incentives, insolvency, reserves, correlated risk, and bad debt.
Vaults, Yield & Tokenized Positions
ERC-4626 shares and assets, rounding, fees, donation attacks, strategy adapters, profit and loss, queues, and emergency exits.
Oracles, Automation & Randomness
External data, TWAPs, staleness, heartbeats, normalization, circuit breakers, fallback feeds, keepers, and verifiable randomness.
Stablecoins, RWAs & Permissioned Assets
Peg mechanisms, reserves, redemption, transfer controls, identity claims, tokenized real-world assets, custody, and legal/technical boundaries.
Execution Markets and Scaling
Study ordering markets, rollups, data availability, settlement, and cross-chain failure as one execution pipeline.
MEV, Mempools, Intents & Auctions
Transaction ordering, builders, searchers, private order flow, batch auctions, solvers, partial fills, surplus, censorship, and MEV-aware design.
Rollups, Data Availability & L2
Optimistic and validity rollups, sequencers, proofs, blobs, forced inclusion, settlement, withdrawals, upgrade keys, and escape hatches.
Cross-Chain Messaging & Bridges
Canonical and external bridges, message verification, replay protection, idempotency, finality mismatch, rate limits, wrapped assets, and recovery.
Proofs and Privacy
Build small auditable circuits and on-chain verifiers while exposing setup, privacy, replay, and constraint assumptions.
Always Active
Operate typed clients, reorg-safe indexers, monitors, manifests, alerts, runbooks, and invariant reports from v0.
Specifications before abstractions
The standards, networks, and tooling registries keep status, versions, trust assumptions, and change-sensitive facts explicit and reviewable.