Throughput, whole card
297,100/s
host-measured sustained · 4 K1 cores

Every verification retired end to end via PCIe DMA, on generated Nexa-Schnorr signatures.

Energy, per verification
—
not yet claimed

Unmeasured, so unclaimed — published once board power is instrumented.

Latency, per verification
82 µs
host-measured submit → verdict, via PCIe

Mean round trip at 98,614/s offered (90% of that configuration's sustained rate); p99 84 µs; unloaded 82 µs.

Blitz on the Ti375 devkit, 4 K1 cores, PCIe DMA · 2026-07-24. Latency: blitz_sw@5044966 bench/LATENCY_INTERIM.json · Ti375 devkit, 2 K1 cores (interim image) · 2026-08-09. Per-core-count figures and the K1 core's static-timing ceiling are on the K1 page; the gap between the measured figure and that ceiling is real-world DMA and windowing overhead.

Specifications

Form factor M.2 2280, M-key (22 × 80 mm)
Host OS Linux (kernel driver; source on GitLab)
Signature scheme Nexa/BCH Schnorr (not BIP-340)
Rated max power 8 W
Thermal management on-board monitoring with automatic throttling; an over-temperature fuse holds the FPGA in reset
Power protection input eFuse at the edge connector cuts power on overcurrent, latching off until a power cycle
Boot on-board flash, golden + two application images; bitstream updates load over PCIe — no JTAG or debug tools needed
FPGA Efinix Ti375 (Titanium)
Host interface PCIe 3.0 ×1 (8 GT/s)
Programming & debug USB (FT4232; JTAG + serial)

The card checks its own work

Blitz continuously tests itself. An independent on-card RISC-V auditor keeps checking the K1 engine against libsecp256k1 — the trusted reference library the ecosystem itself verifies with — for as long as the card runs. Software as the authority, hardware for the speed.

The auditor is open source, silicon-proven — and deliberately does exactly one job. The card's control loops live entirely outside it: nothing they do can break the audit loop. How the runtime auditor works →

Boots itself. Updates itself. Can't be bricked.

The card configures itself from on-board flash at power-on — no host software involved. Updates never overwrite the bitstream you're running: the new image arrives through the Blitz app, encrypted end to end, is written to a spare slot, and the card switches over only once it's confirmed good. A failed update simply leaves the old bitstream in place — and behind both slots sits a frozen golden image no update can overwrite, so the card always has a known-good state to boot into. The recovery path has passed full silicon bench tests — it ships exercised, not theoretical.

The mechanics — the application slots, the golden image, JTAG recovery, loading your own bitstreams — are in the FAQ →

An open platform, not a locked appliance

Blitz ships provisioned with the Node Labs decryption key, so it runs our encrypted production bitstreams out of the box. But the card is never locked: load any bitstream you build — volatile over USB-JTAG, or written to flash — whenever you want. Building on it has its own pages:

The first run is a beta batch

Near hardware cost, limited quantity, limited warranty — the point is getting cards into the field and proving them out. There's no list to join and nobody to talk to: when the batch opens, pricing and a way to buy appear right here.