Independent lab console · math cited & dated · verified Sept 29, 2026

Every planck, accounted for.

Quantus fees aren't guessed — they come from a runtime polynomial you can read: bytes × 100,000 plancks. This lab turns that polynomial, the wormhole exit fee, the 1% high-security fee, and the ~430 QTPS aggregation claim into instruments you can turn by hand. Every number shows its arithmetic; estimates are labeled as estimates.

Block target12 s
Tx budget / block3.75 MB
Length fee100k/B
Fee dev tax0%

Fee estimator

Three transfer modes, three fee models. 100% of fees and 100% of block rewards go to the miner — there is no dev tax (measured from docs/reference/tokenomics.md).

A realistic ML-DSA-87 transfer: 2,592 B public key + 4,627 B signature + call data.

WeightToFee = ScaledIdentityFee ≈ 0.1 planck per ps of ref_time. Actual ref_time is benchmark- and hardware-dependent — enter your own from a benchmark; the weight fee below is an estimate, not a protocol quote.

Optional tip on top of weight + length fees — also goes to the miner.

Length fee—
—
Weight fee estimate—
—
Tip—
Total → miner—
—
Existential deposit is 0.001 QTC — dust accounts below it get reaped. Length fee is exact from the runtime polynomial; the weight fee is a benchmark-dependent estimate.

Wormhole exit: 0.04% volume fee (4 bps). Settlement ceil-rounds per segment to whole quanta and small segments pay ≥ 1 quantum (0.01 QTC) — tiny exits pay proportionally more. The split below is per private segment; in public batches, floor(50% of the burn) is redirected to the aggregator instead of being burned.

Wormhole fee (0.04%)—
—
Burned (ceil 50% of fee)—
To miner (remainder)—
Privacy side-effect: the wormhole breaks the sender→receiver link (Tornado-Cash-like mechanism), but amounts and exit addresses remain visible.

High-security / reversible transfer: 1% volume fee, burned in full — buys the guardian account and delay-window protection.

Security fee — burned—
—
The 1% fee is burned, not paid to the miner. Standard weight + length fees still apply on top of the transfer itself.

Throughput visualizer

QTPS is arithmetic: transfers per block ÷ 12 s block time. All three Quantus figures are claimed design figures from docs/architecture.md — mainnet (Sept 9, 2026) has seen nothing near them yet. Bitcoin's quantum-secure figure is a claimed Quantus whitepaper figure, not a measured one.

For reference — classical baselines

Aggregation explorer

The answer to 7 KB transactions: batch them. Drag N and watch the naive on-chain footprint (N × 7,219 B) collapse against the aggregated mode's amortized cost (≈ 721 B/tx = 3.75 MB ÷ 5,200 transfers).

Naive on-chain size
—
—
Naive block budget
—
of 3.75 MB per 12 s block
Aggregated size
—
—
Compression
—
fewer bytes per transfer

Signature-size lab

Build a Quantus transaction out of its real parts — ML-DSA-87 public key 2,592 B + signature 4,627 B (measured from NIST FIPS 204 via docs/deep-dives/pqc.md) — against the ~98 B an ECDSA-style transfer costs.

Sources

Every figure above traces to one of these upstream files. Re-verified Sept 29, 2026; figures move — check the live chain before acting on them.

    Honest-label policy. The length fee is computed exactly from the runtime polynomial. The weight fee is a estimate (ScaledIdentityFee ≈ 0.1 planck per ps of ref_time — ref_time itself is benchmark/hardware-dependent). All QTPS figures are claimed design figures, not measured mainnet throughput. Bitcoin's quantum-secure ~1.1 TPS is a Quantus whitepaper claim; classical BTC (~7) and ETH (~15) are approx observed averages.