Hardware
Blitz
An M.2 FPGA accelerator card powered by K1 compute cores, now on its fourth board spin. It fits a spare M.2 slot — or any PCIe slot with a cheap passive adapter — and it is yours to reprogram.
live — a real Ti375 FPGA on the bench in Vancouver, streamed 20×/s. Open the full viewer to push the card yourself and watch the die warm up.
Every verification retired end to end via PCIe DMA, on generated Nexa-Schnorr signatures.
Unmeasured, so unclaimed — published once board power is instrumented.
Mean round trip at 98,614/s offered (90% of that configuration's sustained rate); p99 84 µs; unloaded 82 µs.
Blitz on the Ti375 devkit, 4 K1 cores, PCIe DMA · 2026-07-24. Latency: blitz_sw@5044966 bench/LATENCY_INTERIM.json · Ti375 devkit, 2 K1 cores (interim image) · 2026-08-09. Per-core-count figures and the K1 core's static-timing ceiling are on the K1 page; the gap between the measured figure and that ceiling is real-world DMA and windowing overhead.
Specifications
The card checks its own work
Blitz continuously tests itself. An independent on-card RISC-V auditor keeps checking the K1 engine against libsecp256k1 — the trusted reference library the ecosystem itself verifies with — for as long as the card runs. Software as the authority, hardware for the speed.
The auditor is open source, silicon-proven — and deliberately does exactly one job. The card's control loops live entirely outside it: nothing they do can break the audit loop. How the runtime auditor works →
Boots itself. Updates itself. Can't be bricked.
The card configures itself from on-board flash at power-on — no host software involved. Updates never overwrite the bitstream you're running: the new image arrives through the Blitz app, encrypted end to end, is written to a spare slot, and the card switches over only once it's confirmed good. A failed update simply leaves the old bitstream in place — and behind both slots sits a frozen golden image no update can overwrite, so the card always has a known-good state to boot into. The recovery path has passed full silicon bench tests — it ships exercised, not theoretical.
The mechanics — the application slots, the golden image, JTAG recovery, loading your own bitstreams — are in the FAQ →
An open platform, not a locked appliance
Blitz ships provisioned with the Node Labs decryption key, so it runs our encrypted production bitstreams out of the box. But the card is never locked: load any bitstream you build — volatile over USB-JTAG, or written to flash — whenever you want. Building on it has its own pages:
The API is a file →
write() a 160-byte record, read() a verdict byte. The open-source driver, the frozen ABI, and the virtual card — on the software page.
Inside the bitstream →
The platform architecture — a swappable compute core behind a single fixed stream interface — drawn and explained on the Open Source page.
Open RTL →
MIT-licensed starting points, including a working open verification core; we also plan to publish a simplified board schematic.
The first run is a beta batch
Near hardware cost, limited quantity, limited warranty — the point is getting cards into the field and proving them out. There's no list to join and nobody to talk to: when the batch opens, pricing and a way to buy appear right here.